Network element selection method, information transmission method, device and network element
The network element selection method improves slice authentication by using refined identifiers to select NSSAAF and AAA-S/AAA-P, addressing coarse-grained issues in existing technologies and enhancing traffic separation and user offloading.
Patent Information
- Application Number
- JP2024506783
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-08-03
- Filing Date
- 2022-07-28
- Publication Date
- 2025-08-07
- Estimated Expiration
- 2042-07-28
AI Technical Summary
The existing network element selection mechanisms in communication technology are too coarse-grained, leading to complex traffic configuration and inadequate slice authentication, especially with increasing traffic volume and user diversity, necessitating manual adjustments and coarse mapping relationships.
A network element selection method that utilizes S-NSSAI, SUPI, DNN, GPSI, SUCI, external and internal group IDs, and routing identifiers to refine NSSAAF and AAA-S/AAA-P selection, enabling precise traffic separation and authentication.
Enhances the granularity of network element selection, allowing for efficient traffic separation and authentication based on user equipment slices, improving maintenance efficiency and user level offloading.
Smart Images

Figure 0007720474000001 
Figure 0007720474000002 
Figure 0007720474000003
Abstract
Description
[Technical Field]
[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This disclosure claims priority to Chinese Patent Application No. 202110884566.5, filed in China on August 3, 2021, the entire contents of which are incorporated herein by reference. The present disclosure relates to the field of communication technology, and in particular to a network element selection method, an information transmission method, an apparatus, and a network element. [Background technology]
[0002] Regarding slice authentication and authorization, after the business operator completes identity authentication, it is also possible to allow industrial customers to flexibly control the access rights to related slices to meet the access control needs of vertical industries with high requirements for slice security.
[0003] In this function, the Access and Mobility Management Function (AMF) needs to interact with the Authentication, Authorization, and Accounting (AAA) server through the Network Slice-Specific Authentication and Authorization (NSSAAF). However, in current existing networks, the AMF can only query the Network Repository Function (NRF) for the NSSAAF used by the user based on local configuration or using the Mobile Country Code (MCC) + Mobile Network Code (MNC). In addition, the NSSAAF can only select the AAA-S / AAA-P based on the correspondence between the locally configured Single-Network Slice Selection Assistance Information (S-NSSAI) and the Service AAA (AAA-S) / Proxy AAA (AAA-P).
[0004] As traffic volume subsequently increases, the number of NSSAAF deployments also increases. If only local configuration is used, the amount of configuration work will increase significantly. In addition, when the deployment of network elements is changed, the relevant mapping relationships on all NSSAAFs in the entire network must be manually adjusted, which brings about extremely difficult maintenance. On the other hand, if MCC+MNC-based NRF queries are used, the granularity of MCC+MNC is too coarse, so the relevant mapping relationships must be configured on all NSSAAFs in the entire network, which requires a large amount of configuration and is disadvantageous to completing traffic configuration and separation on each NSSAAF network element based on slices.
[0005] Furthermore, as traffic volume increases, the number of AAA-S / AAA-Ps deployed by a single customer will also increase, and the users within this customer may be of different levels, i.e., two sets of users (e.g., gold users and general users). Therefore, it is also necessary to realize offloading different users to different AAA-S / AAA-P selections, which can reduce the traffic composition of AAA-S / AAA-P and also realize traffic separation of different users. However, the above-mentioned needs cannot be supported by the current existing network mechanism.
[0006] In summary, selecting NSSAAF based on local configuration or MCC+MNC and / or selecting AAA-S / AAA-P based on S-NSSAI is too coarse-grained and the traffic configuration is too complex, which will affect subsequent slice authentication. Summary of the Invention [Problem to be solved by the invention]
[0007] The objective of the embodiments of the present disclosure is to provide a network element selection method, information transmission method, device, and network element that solve the problem that the granularity of network element selection in related technologies is too coarse, which affects slice authentication. [Means for solving the problem]
[0008] In order to solve the above problem, an embodiment of the present disclosure provides a network element selection method executed by a first network element, the method comprising: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, A network element selection method is provided, which includes selecting a network slice specific authentication and authorization function (NSSAAF) network element according to first information including at least one of a routing identifier and a
[0009] In the above embodiment, selecting an NSSAAF network element according to the first information includes: sending a first request message to a second network element, the first request message including the first information; receiving a first response message sent from a second network element, the first response message including one or a set of NSSAAF Fully Qualified Domain Name (FQDN) and / or address information; selecting an NSSAAF in accordance with the first response message and a predetermined selection policy.
[0010] In the above embodiment, before selecting a Network Slice Specific Authentication and Authorization Function (NSSAAF) network element according to the first information, the method includes: It further includes obtaining contract information of the user equipment from a third network element, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0011] In the above embodiment, after selecting a Network Slice Specific Authentication and Authorization Function (NSSAAF) network element, the method includes: The method further includes sending an authorization request message including the target address information to a selected NSSAAF network element.
[0012] In the above embodiment, the approval request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0013] An embodiment of the present disclosure includes an information transmission method performed by a second network element, the method including: A first request message sent from a first network element, the first request message including the first information, the first information including: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, receiving a first request message including at least one of a routing identifier; There is further provided an information transmission method, including: sending a first response message to the first network element according to the first request message, the first response message including FQDN and / or address information of one or a set of NSSAAFs.
[0014] An embodiment of the present disclosure includes an information transmission method performed by a Network Slice Specific Authentication and Authorization Function (NSSAAF) network element, comprising: An information transmission method is further provided, which includes receiving an authorization request message sent from a first network element, the authorization request message including target address information which is address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0015] In the above embodiment, the approval request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0016] In the above embodiment, the method further comprises: The method further includes selecting a corresponding AAA server for the user equipment according to the target address information.
[0017] In the above embodiment, when the AAA server includes a fourth network element and a fifth network element, the method includes: The method further includes sending an AAA protocol message carrying the target address information to the fifth network element, and forwarding the AAA protocol message by the fifth network element to the fourth network element.
[0018] In the above embodiment, when the AAA server includes a fourth network element, the method includes: The method further includes sending an AAA protocol message carrying the target address information to the fourth network element.
[0019] In the above embodiment, the AAA protocol message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0020] In the above embodiment, the target address information is obtained by the first network element from subscription information of the user equipment sent from a third network element.
[0021] An embodiment of the present disclosure includes an information transmission method performed by a first network element, the method including: There is further provided an information transmission method, which includes sending an authorization request message to an NSSAAF network element, the target address information being address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0022] In the above embodiment, the approval request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0023] In the above embodiment, before sending the authorization request message to the NSSAAF network element, the method includes: It further includes obtaining contract information of the user equipment from a third network element, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0024] An embodiment of the present disclosure includes an information storage method performed by a third network element, the method comprising: There is also provided an information storage method, which includes storing contract information of a user equipment, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0025] In the above embodiment, the method further comprises: The method further includes sending subscription information of the user equipment to a first network element.
[0026] An embodiment of the present disclosure includes a network element selection device applied to a first network element, the network element selection device including: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, A network element selection device is further provided, which includes a selection module for selecting a network slice specific authentication and authorization function (NSSAAF) network element according to first information including at least one of a routing identifier and a routing identifier.
[0027] An embodiment of the present disclosure includes a first network element including a processor and a transceiver for transmitting and receiving data under control of the processor, the processor comprising: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, Further provided is a first network element for performing an operation of selecting a network slice specific authentication and authorization function (NSSAAF) network element according to first information including at least one of a routing identifier and a
[0028] In an embodiment of the present disclosure, there is provided an information transmission device applied to a second network element, comprising: A first request message sent from a first network element, the first request message including the first information, the first information including: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, a first receiving module for receiving a first request message including at least one of a routing identifier; An information transmission device is further provided, including: a first sending module for sending a first response message to the first network element according to the first request message, the first response message including FQDN and / or address information of one or a set of NSSAAFs.
[0029] An embodiment of the present disclosure also includes a second network element including a processor and a transceiver for transmitting and receiving data under control of the processor, the processor comprising: A first request message sent from a first network element, the first request message including the first information, the first information including: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, receiving a first request message including at least one of a routing identifier; and sending a first response message to the first network element according to the first request message, the first response message including FQDN and / or address information of one or a set of NSSAAFs.
[0030] An embodiment of the present disclosure includes an information transmission device applied to an NSSAAF network element, comprising: An information transmission device is further provided, which includes a second receiving module for receiving an authorization request message sent from the first network element, the authorization request message including target address information which is address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0031] An embodiment of the present disclosure includes an NSSAAF network element including a processor and a transceiver for transmitting and receiving data under control of the processor, the processor comprising: There is further provided an NSSAAF network element for performing an operation of receiving an authorization request message sent from the first network element, the authorization request message including target address information being address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0032] In an embodiment of the present disclosure, there is provided an information transmission device applied to a first network element, comprising: An information transmission device is further provided, which includes a second sending module for sending an authorization request message to an NSSAAF network element, the authorization request message including target address information, the target address information being address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0033] An embodiment of the present disclosure includes a first network element including a processor and a transceiver for transmitting and receiving data under control of the processor, the processor comprising: There is further provided a first network element for performing an operation of sending an authorization request message to an NSSAAF network element, the target address information being address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0034] An embodiment of the present disclosure includes an information storage device applied to a third network element, comprising: An information storage device is further provided, including a storage module for storing contract information of a user equipment, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0035] An embodiment of the present disclosure also provides a third network element including a processor and a transceiver for transmitting and receiving data under control of the processor, the processor comprising: A third network element is further provided, which is for performing an operation of storing contract information of a user equipment, the contract information carrying target address information being address information of one or a set of AAA servers corresponding to the network slice.
[0036] An embodiment of the present disclosure further provides a network element including a memory, a processor, and a program stored in the memory and operable on the processor, wherein when the program is executed by the processor, the network element selection method described above is realized, or when the program is executed by the processor, the information transmission method or information storage method described above is realized.
[0037] An embodiment of the present disclosure further provides a computer-readable storage medium storing a computer program, the program being configured to, when executed by a processor, realize the steps in the network element selection method described above, or to, when executed by a processor, realize the information transmission method or information storage method described above. [Effects of the Invention]
[0038] The above technical aspects of the present disclosure have at least the following beneficial effects. In the network element selection method, information transmission method, device, and network element according to the embodiments of the present disclosure, the AMF obtains the NSSAAF used by the current user equipment based on at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier, thereby fine-tuning the granularity of the NSSAAF selection, thereby enabling traffic separation on multiple NSSAAF network elements to be completed based on the slice of the user equipment. [Brief explanation of the drawings]
[0039] [Figure 1] FIG. 2 is a schematic diagram illustrating steps of a network element selection method according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a schematic diagram illustrating the interaction of network elements in a network element selection method according to an embodiment of the present disclosure. [Figure 3] 1 is a flowchart illustrating steps of an information transmission method according to an embodiment of the present disclosure. [Figure 4] 10 is a second flowchart illustrating steps of an information transmission method according to an embodiment of the present disclosure. [Figure 5] 10 is a third flowchart illustrating steps of an information transmission method according to an embodiment of the present disclosure. [Figure 6] FIG. 10 is a principle diagram illustrating a slice authentication flow according to an embodiment of the present disclosure. [Figure 7] FIG. 2 is a schematic diagram illustrating the structure of a network element selection device according to an embodiment of the present disclosure; [Figure 8] FIG. 1 is a schematic diagram illustrating the structure of a first network element according to an embodiment of the present disclosure. [Figure 9] 1 is a schematic diagram illustrating a structure of an information transmission device according to an embodiment of the present disclosure. [Figure 10] FIG. 10 is a schematic diagram illustrating the structure of a second network element according to an embodiment of the present disclosure. [Figure 11]FIG. 2 is a second schematic diagram illustrating the structure of an information transmission device according to an embodiment of the present disclosure. [Figure 12] FIG. 1 is a schematic diagram illustrating the structure of an NSSAAF network element according to an embodiment of the present disclosure. [Figure 13] FIG. 3 is a third schematic diagram illustrating the structure of an information transmission device according to an embodiment of the present disclosure. [Figure 14] FIG. 2 is a second schematic diagram illustrating the structure of a first network element according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0040] In order to make the problems to be solved, technical aspects and advantages of the present disclosure clearer, detailed descriptions will be given below with reference to the drawings and specific embodiments.
[0041] As shown in FIG. 1 , an embodiment of the present disclosure includes a network element selection method performed by a first network element, the method including: Network slice S-NSSAI and A home network identifier in the User Permanent Identifier (SUbscription Permanent Identifier (SUPI)); Data Network Name (DNN), A Generic Public Subscription Identifier (GPSI); and User Permanent Identifier (SUPI), and Subscription Concealed Identifier (SUCI), External Group ID, Internal Group ID, A network element selection method is provided, comprising step 101 of selecting a network slice specific authentication and authorization function (NSSAAF) network element according to first information including at least one of a routing indicator and a routing indicator.
[0042] Optionally, the first network element referred to in the embodiments of the present disclosure includes an Access and Mobility Management Function (AMF) network element, or a Session Management Function (SMF) network element, or other network elements with management functions.
[0043] In at least one embodiment of the present disclosure, step 101 includes: sending a first request message to a second network element, the first request message including the first information, the first request message being optionally used to request a query for local information from the second network element; receiving a first response message sent from a second network element, the first response message including one or a set of NSSAAF Fully Qualified Domain Name (FQDN) and / or address information, optionally, the second network element queries local information based on the first request message to obtain one or a set of NSSAAF FQDN and / or address information corresponding to the first information; selecting an NSSAAF in accordance with the first response message and a predetermined selection policy.
[0044] Optionally, the second network element referred to in the embodiments of the present disclosure includes a Network Repository Function (NRF) network element, or a Service Control Point (SCP) network element, or other network element having a repository function. For example, the address information of the NSSAAF includes the IP address of the NSSAAF.
[0045] Alternatively, the first request message may be referred to as a network capability discovery request (Nnrf_NFDiscovery_Request) message, and accordingly, the first response message may be referred to as a network capability discovery response (Nnrf_NFDiscovery_Response) message.
[0046] In one alternative embodiment, the first information includes: a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, At least one of the following is included:
[0047] For example, in FIG. 2, the following steps 21 to 23 are shown as an NSSAAF selection mode based on the first information. In step 21, the AMF sends a first request message to the NRF requesting local information query, the first request message carrying an S-NSSAI, a Public Land Mobile Network (PLMN) ID of the SUPI, a DNN, a GPSI, a SUPI, a SUCI, an external group ID, an internal group ID, and a routing identifier; In step 22, the NRF returns a first response message to the AMF containing the FQDN or IP address of one or a set of NSSAAFs; In step 23, the AMF selects the NSSAAF based on its local selection policy.
[0048] In at least one embodiment of the present disclosure, prior to step 101, the method further comprises: It further includes obtaining contract information of the user equipment from a third network element, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0049] In an embodiment of the present disclosure, the third network element adds target address information to the contract information, in which the network slice is identified by the S-NSSAI, that is, adds address information of the AAA server associated with the S-NSSAI to the contract information. The third network element returns the target address information associated with the slice to the first network element. The target address information is also referred to as NSSAAAaaAddress.
[0050] Optionally, the third network element referred to in the embodiments of the present disclosure includes a Unified Data Management (UDM) network element, or a Unified Data Repository (UDR) network element, or an Authentication Server Function (AUSF) network element, or other network element capable of storing subscription information of a user equipment.
[0051] After the user equipment passes authorization for the first time, the AMF determines whether to start slice-level authentication based on the user equipment's contract information obtained from the UDM or AUSF, which contract information carries the address information of the AAA server corresponding to the slice.
[0052] Continuing with the above example, in at least one embodiment of the present disclosure, after step 101, the method further comprises: The method further includes sending an authorization request message (which may be referred to as an Nnssaaf_NSSAA_Authenticate Request) containing the target address information to a selected NSSAAF network element, where the authorization request message is used to trigger a slice authentication flow.
[0053] Optionally, the authorization request message includes: a General Public User Identifier (GPSI); Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0054] Furthermore, the NSSAAF network element selects a corresponding AAA server for the user based on the target address information in the authorization request message, and performs the subsequent slice secondary authentication flow.
[0055] In summary, in an embodiment of the present disclosure, the AMF obtains the NSSAAF used by the current user equipment based on at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier, thereby fine-tuning the granularity of the NSSAAF selection, and thereby enabling traffic separation on multiple NSSAAF network elements to be completed based on the slice of the user equipment; further, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, thereby enabling the NSSAAF to select the corresponding AAA server based on the received AAA server address information, thereby fine-tuning the granularity of the AAA server selection and realizing offloading users of different levels to different AAA servers.
[0056] As shown in FIG. 3 , an embodiment of the present disclosure includes an information transmission method performed by a second network element, including: A first request message sent from a first network element, the first request message including the first information, the first information including: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN), a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, a step 301 of receiving a first request message including at least one of a routing identifier; There is further provided an information transmission method, including: sending 302 a first response message to the first network element according to the first request message, the first response message including FQDN and / or address information of one or a set of NSSAAFs.
[0057] Optionally, the first request message is used to request the NRF to query local information, and the second network element queries the local information based on the first request message to obtain one or a set of FQDN and / or address information of NSSAAFs corresponding to the first information. For example, the address information of the NSSAAF includes the IP address of the NSSAAF.
[0058] Optionally, the first network element referred to in the embodiments of the present disclosure includes an AMF network element, an SMF network element, or other network element with management functions.
[0059] Alternatively, the first request message may be referred to as a network capability discovery request (Nnrf_NFDiscovery_Request) message, and accordingly, the first response message may be referred to as a network capability discovery response (Nnrf_NFDiscovery_Response) message.
[0060] In one alternative embodiment, the first information includes: a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, At least one of the following is included:
[0061] In summary, in an embodiment of the present disclosure, the AMF obtains the NSSAAF used by the current user equipment based on at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier, thereby fine-tuning the NSSAAF selection, thereby enabling traffic separation on multiple NSSAAF network elements to be completed based on the user equipment slice.
[0062] As shown in FIG. 4, an embodiment of the present disclosure includes an information transmission method performed by a Network Slice Specific Authentication and Authorization Function (NSSAAF) network element, comprising: There is also provided an information transmission method, including step 401 of receiving an authorization request message (which may be referred to as an Nnssaaf_NSSAA_Authenticate Request) sent from a first network element, the authorization request message including target address information, which is address information of one or a set of AAA servers corresponding to a network slice requested by the user equipment. Optionally, the authorization request message is used to trigger a slice authentication flow.
[0063] Optionally, the target address information is also referred to as NSSAAAaaAddress.
[0064] Optionally, the authorization request message includes: a General Public User Identifier (GPSI); Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0065] Optionally, the first network element referred to in the embodiments of the present disclosure includes an AMF network element, an SMF network element, or other network element with management functions.
[0066] Wherein, the target address information is obtained by the first network element from the subscription information of the user equipment sent from the third network element.
[0067] Optionally, the third network element referred to in the embodiments of the present disclosure includes a UDM network element, a UDR network element, an AUSF network element, or other network elements that can store subscription information of user equipment.
[0068] Further, in the above embodiment of the present disclosure, the method further comprises: The method further includes selecting a corresponding AAA server for the user equipment according to the target address information.
[0069] In other words, the NSSAAF network element selects a corresponding AAA server for the user based on the target address information in the authorization request message, and performs the subsequent slice secondary authentication flow.
[0070] In the above embodiment of the present disclosure, when the AAA server includes a fourth network element and a fifth network element, the method includes: The method further includes sending an AAA protocol message carrying the target address information to the fifth network element, and forwarding the AAA protocol message by the fifth network element to the fourth network element. Among them, the fourth network element is an AAA-S server, ie, a service AAA server, which may also be directly called an AAA server, and the fifth network element is an AAA-P server, ie, a proxy AAA server.
[0071] Or, if the AAA server includes a fourth network element (in other words, does not include a proxy AAA server), the method may include: The method further includes sending an AAA protocol message carrying the target address information to the fourth network element. The fourth network element is an AAA-S server, ie, a service AAA server, which may also be referred to as an AAA server.
[0072] In one alternative embodiment, the AAA protocol message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0073] In summary, in an embodiment of the present disclosure, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, so that the NSSAAF can select the corresponding AAA server based on the received address information of the AAA server, thereby achieving finer granularity in the selection of AAA servers and offloading users of different levels to different AAA servers.
[0074] As shown in FIG. 5, an embodiment of the present disclosure includes an information transmission method performed by a first network element, including: There is further provided an information transmission method, including step 501 of sending an authorization request message (which may be referred to as Nnssaaf_NSSAA_Authenticate Request) to an NSSAAF network element, the authorization request message including target address information which is address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0075] Optionally, the authorization request message is used to trigger a slice authentication flow.
[0076] Optionally, the authorization request message includes: a General Public User Identifier (GPSI); Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0077] Furthermore, the NSSAAF network element selects a corresponding AAA server for the user based on the target address information in the authorization request message, and performs the subsequent slice secondary authentication flow.
[0078] In at least one embodiment of the present disclosure, before sending the authorization request message to the NSSAAF network element, the method further comprises: It further includes obtaining contract information of the user equipment from a third network element, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0079] In an embodiment of the present disclosure, the third network element adds target address information to the contract information, in which the network slice is identified by the S-NSSAI, that is, adds address information of the AAA server associated with the S-NSSAI to the contract information. The third network element returns the target address information associated with the slice to the first network element. The target address information is also referred to as NSSAAAaaAddress.
[0080] After the user equipment passes authorization for the first time, the AMF determines whether to start slice-level authentication based on the user equipment's contract information obtained from the UDM or AUSF, which contract information carries the address information of the AAA server corresponding to the slice.
[0081] In summary, in an embodiment of the present disclosure, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, so that the NSSAAF can select the corresponding AAA server based on the received address information of the AAA server, thereby achieving finer granularity in the selection of AAA servers and offloading users of different levels to different AAA servers.
[0082] An embodiment of the present disclosure includes an information storage method performed by a third network element, the method comprising: There is also provided an information storage method, which includes storing contract information of a user equipment, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0083] Optionally, the third network element referred to in the embodiments of the present disclosure includes a UDM network element, a UDR network element, an AUSF network element, or other network elements that can store subscription information of user equipment.
[0084] Optionally, in the embodiments of the present disclosure, the contract information of the user equipment not only carries relevant information in related technologies, but also carries address information of one or a set of AAA servers corresponding to the network slice, for example, the network slice may be the network slice that the user has contracted for.
[0085] In at least one embodiment of the present disclosure, the method comprises: The method further includes transmitting contract information of the user equipment to a first network element, so that the first network element can transmit address information of an AAA server corresponding to each network slice obtained from the contract information to the NSSAAF to assist the NSSAAF in selecting an AAA server.
[0086] In summary, in an embodiment of the present disclosure, the UDM or AUSFU sends contract information to the AMF, and the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via a related message, so that the NSSAAF can select the corresponding AAA server based on the received AAA server address information, thereby fine-tuning the granularity of AAA server selection and realizing offloading users of different levels to different AAA servers.
[0087] As shown in FIG. 6, the flow of slice authentication according to the embodiment of the present disclosure includes the following steps 61 to 70. In step 61, the User Equipment (UE) initiates a registration request in which the requested Network Slice Selection Assistance Information (NSSAI) and UE capability information are carried. In step 62, the UE passes authorization for the first time. In step 63, the AMF determines whether to initiate slice-level authentication based on the contract information, which includes address information of one or a set of AAA servers corresponding to the network slice. In step 64, the registration is successful and the authorized NSSAI and extended NSSAI are carried. In step 65, the AMF queries the NRF for the NSSAAF based on the first information, where the first information includes at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier. Step 66 involves non-access stratum mobility management transmission. In step 67, the AMF sends an authorization request message to the NSSAAF, where the authorization request message carries target address information, EAP information, GPSI, S-NSSAI, etc., and the target address information is the address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment. In step 68, the NSSAAF selects a corresponding AAA server based on the target address information. In step 69, the AMF turns on slice-based EAP authentication between the UE and the AAA-S. In step 70, according to the authentication result, the AMF initiates a UE Configuration Update to update the Allowed NSSAI.
[0088] In an embodiment of the present disclosure, the AMF obtains the NSSAAF used by the current user equipment based on at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier, thereby improving the granularity of the NSSAAF selection, and thereby enabling traffic separation on multiple NSSAAF network elements to be completed based on the slice of the user equipment; further, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, thereby enabling the NSSAAF to select the corresponding AAA server based on the received AAA server address information, thereby improving the granularity of the AAA server selection and enabling offloading of users of different levels to different AAA servers.
[0089] As shown in FIG. 7, an embodiment of the present disclosure includes a network element selection device applied to a first network element, Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, Further provided is a network element selection device including a selection module 701 for selecting a network slice specific authentication and authorization function (NSSAAF) network element according to first information including at least one of a routing identifier and a
[0090] In one alternative embodiment, the selection module: a first sub-module for sending a first request message to a second network element, the first request message including the first information; a second sub-module for receiving a first response message sent from a second network element, the first response message including one or a set of NSSAAF FQDN and / or address information; and a third sub-module for selecting an NSSAAF according to the first response message and a predetermined selection policy.
[0091] In one alternative embodiment, the first information includes: a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, At least one of the following is included:
[0092] In one alternative embodiment, the device comprises: It further includes an acquisition module for acquiring contract information of the user equipment from the third network element, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0093] In one alternative embodiment, the device comprises: The method further includes a third sending module for sending an authorization request message including the target address information to a selected NSSAAF network element.
[0094] In one alternative embodiment, the authorization request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0095] In an embodiment of the present disclosure, the AMF obtains the NSSAAF used by the current user equipment based on at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier, thereby improving the granularity of the NSSAAF selection, and thereby enabling traffic separation on multiple NSSAAF network elements to be completed based on the slice of the user equipment; further, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, thereby enabling the NSSAAF to select the corresponding AAA server based on the received AAA server address information, thereby improving the granularity of the AAA server selection and enabling offloading of users of different levels to different AAA servers.
[0096] It should be noted that as long as the network element selection device according to the embodiments of the present disclosure is a device capable of executing the above network element selection method, all embodiments of the above network element selection method are applicable to the device and can achieve the same or similar beneficial effects.
[0097] As shown in FIG. 8, an embodiment of the present disclosure provides a first network element including a processor 800 and a transceiver 810 for transmitting and receiving data under the control of the processor 800, wherein the processor 800: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, Further provided is a first network element for performing an operation of selecting a network slice specific authentication and authorization function (NSSAAF) network element according to first information including at least one of a routing identifier and a
[0098] In one alternative embodiment, the processor: sending a first request message to a second network element, the first request message including the first information; receiving a first response message sent from a second network element, the first response message including one or a set of NSSAAF FQDN and / or address information; It is further used to execute the first response message and select an NSSAAF according to a predetermined selection policy.
[0099] In one alternative embodiment, the first information includes: a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, At least one of the following is included:
[0100] In one alternative embodiment, the processor: It is further used to perform an operation of obtaining contract information of the user equipment from a third network element, the contract information carrying target address information which is the address information of one or a set of AAA servers corresponding to the network slice.
[0101] In one alternative embodiment, the processor: It is further used to perform an operation of sending an authorization request message containing the target address information to a selected NSSAAF network element.
[0102] In one alternative embodiment, the authorization request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0103] In an embodiment of the present disclosure, the AMF obtains the NSSAAF used by the current user equipment based on at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier, thereby improving the granularity of the NSSAAF selection, and thereby enabling traffic separation on multiple NSSAAF network elements to be completed based on the slice of the user equipment; further, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, thereby enabling the NSSAAF to select the corresponding AAA server based on the received AAA server address information, thereby improving the granularity of the AAA server selection and enabling offloading of users of different levels to different AAA servers.
[0104] It should be noted that, as long as the first network element according to the embodiments of the present disclosure is a network element capable of performing the above network element selection method, all embodiments of the above network element selection method are applicable to the first network element and can achieve the same or similar beneficial effects.
[0105] As shown in FIG. 9, an embodiment of the present disclosure includes an information transmission device applied to a second network element, A first request message sent from a first network element, the first request message including the first information, the first information including: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, a first receiving module 901 for receiving a first request message including at least one of a routing identifier; An information transmission device is further provided, including: a first sending module 902 for sending a first response message to the first network element according to the first request message, the first response message including FQDN and / or address information of one or a set of NSSAAFs.
[0106] In one alternative embodiment, the first information includes: a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, At least one of the following is included:
[0107] In an embodiment of the present disclosure, the AMF obtains the NSSAAF used by the current user equipment based on at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier, thereby fine-tuning the NSSAAF selection, thereby enabling traffic separation on multiple NSSAAF network elements to be completed based on the user equipment slice.
[0108] It should be noted that as long as the information transmission device according to the embodiments of the present disclosure is a device capable of performing the above information transmission method, all embodiments of the above information transmission method are applicable to the device and can achieve the same or similar beneficial effects.
[0109] As shown in FIG. 10 , an embodiment of the present disclosure provides a second network element including a processor 1000 and a transceiver 1010 for transmitting and receiving data under the control of the processor 1000, wherein the processor 1000: A first request message sent from a first network element, the first request message including the first information, the first information including: Network slice S-NSSAI and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN) and a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, receiving a first request message including at least one of a routing identifier; and sending a first response message to the first network element according to the first request message, the first response message including FQDN and / or address information of one or a set of NSSAAFs.
[0110] In one alternative embodiment, the first information includes: a General Public User Identifier (GPSI); User Permanent Identifier (SUPI), and User Secret Identifier (SUCI), and The external group ID, The internal group ID, At least one of the following is included:
[0111] In an embodiment of the present disclosure, the AMF obtains the NSSAAF used by the current user equipment based on at least one of the S-NSSAI, the home network identifier in the SUPI, the DNN, the GPSI, the SUPI, the SUCI, the external group ID, the internal group ID, and the routing identifier, thereby fine-tuning the NSSAAF selection, thereby enabling traffic separation on multiple NSSAAF network elements to be completed based on the user equipment slice.
[0112] It should be noted that, as long as the second network element according to the embodiments of the present disclosure is a second network element capable of performing the above information transmission method, all embodiments of the above information transmission method are applicable to the second network element and can achieve the same or similar beneficial effects.
[0113] As shown in FIG. 11, an embodiment of the present disclosure includes an information transmission device applied to an NSSAAF network element, An information transmission device is further provided, which includes a second receiving module 1100 for receiving an authorization request message sent from a first network element, the authorization request message including target address information which is address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0114] In one alternative embodiment, the authorization request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0115] In one alternative embodiment, the device comprises: It further includes a second selection module for selecting a corresponding AAA server for the user equipment according to the target address information.
[0116] As an optional embodiment, when the AAA server includes a fourth network element and a fifth network element, the device: The network device further includes a fourth sending module for sending an AAA protocol message carrying the target address information to the fifth network element, and forwarding the AAA protocol message by the fifth network element to a fourth network element.
[0117] In one alternative embodiment, when the AAA server includes a fourth network element, the device: The network element further includes a fifth sending module for sending an AAA protocol message carrying the target address information to the fourth network element.
[0118] In one alternative embodiment, the AAA protocol message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0119] In an embodiment of the present disclosure, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, allowing the NSSAAF to select the corresponding AAA server based on the received address information of the AAA server, thereby improving the granularity of AAA server selection and enabling offloading of users of different levels to different AAA servers.
[0120] It should be noted that as long as the information transmission device according to the embodiments of the present disclosure is a device capable of performing the above information transmission method, all embodiments of the above information transmission method are applicable to the device and can achieve the same or similar beneficial effects.
[0121] As shown in FIG. 12, an embodiment of the present disclosure provides an NSSAAF network element including a processor 1200 and a transceiver 1210 for transmitting and receiving data under the control of the processor 1200, wherein the processor 1200: There is further provided an NSSAAF network element for performing an operation of receiving an authorization request message sent from the first network element, the authorization request message including target address information being address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0122] In one alternative embodiment, the authorization request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0123] In one alternative embodiment, the processor: It is further used to perform an operation of selecting a corresponding AAA server for the user equipment according to the target address information.
[0124] In one alternative embodiment, when the AAA server includes a fourth network element and a fifth network element, the processor: It is further used to perform the operation of sending an AAA protocol message carrying the target address information to the fifth network element, and forwarding the AAA protocol message by the fifth network element to the fourth network element.
[0125] In one alternative embodiment, when the AAA server includes a fourth network element, the processor: It is further used to perform an operation of sending an AAA protocol message carrying the target address information to the fourth network element.
[0126] In one alternative embodiment, the AAA protocol message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0127] In an embodiment of the present disclosure, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, allowing the NSSAAF to select the corresponding AAA server based on the received address information of the AAA server, thereby improving the granularity of AAA server selection and enabling offloading of users of different levels to different AAA servers.
[0128] It should be noted that, as long as the NSSAAF network element according to the embodiments of the present disclosure is an NSSAAF network element capable of performing the above information transmission method, all embodiments of the above information transmission method are applicable to the NSSAAF network element and can achieve the same or similar beneficial effects.
[0129] As shown in FIG. 13 , an embodiment of the present disclosure includes an information transmission device applied to a first network element, An information transmission device is further provided, including a second sending module 1300 for sending an authorization request message to an NSSAAF network element, the authorization request message including target address information, the target address information being address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0130] In one alternative embodiment, the authorization request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0131] In one alternative embodiment, the device comprises: It further includes an acquisition module for acquiring contract information of the user equipment from the third network element, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0132] In an embodiment of the present disclosure, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, allowing the NSSAAF to select the corresponding AAA server based on the received address information of the AAA server, thereby improving the granularity of AAA server selection and enabling offloading of users of different levels to different AAA servers.
[0133] It should be noted that as long as the information transmission device according to the embodiments of the present disclosure is a device capable of performing the above information transmission method, all embodiments of the above information transmission method are applicable to the device and can achieve the same or similar beneficial effects.
[0134] As shown in FIG. 14, an embodiment of the present disclosure provides a first network element including a processor 1400 and a transceiver 1410 for transmitting and receiving data under the control of the processor 1400, wherein the processor 1400: There is further provided a first network element for performing an operation of sending an authorization request message to an NSSAAF network element, the target address information being address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
[0135] In one alternative embodiment, the authorization request message includes: GPSI and Network slice S-NSSAI and and Extensible Authentication Protocol (EAP) information.
[0136] In one alternative embodiment, the processor: It is further used to perform an operation of obtaining contract information of the user equipment from a third network element, the contract information carrying target address information which is the address information of one or a set of AAA servers corresponding to the network slice.
[0137] In an embodiment of the present disclosure, the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via an associated message, allowing the NSSAAF to select the corresponding AAA server based on the received address information of the AAA server, thereby improving the granularity of AAA server selection and enabling offloading of users of different levels to different AAA servers.
[0138] It should be noted that, as long as the first network element according to the embodiments of the present disclosure is a network element capable of performing the above information transmission method, all embodiments of the above information transmission method are applicable to the first network element and can achieve the same or similar beneficial effects.
[0139] An embodiment of the present disclosure includes an information storage device applied to a third network element, comprising: An information storage device is further provided, including a storage module for storing contract information of a user equipment, the contract information carrying target address information which is address information of one or a set of AAA servers corresponding to the network slice.
[0140] In one alternative embodiment, the device comprises: The fifth sending module is configured to send subscription information of the user equipment to a first network element.
[0141] In an embodiment of the present disclosure, the UDM or AUSFU sends contract information to the AMF, and the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via a related message, so that the NSSAAF can select the corresponding AAA server based on the received AAA server address information, thereby fine-tuning the granularity of AAA server selection and realizing offloading users of different levels to different AAA servers.
[0142] It should be noted that as long as the information storage device according to the embodiments of the present disclosure is a device capable of executing the above information storage method, all embodiments of the above information storage method are applicable to the device and can achieve the same or similar beneficial effects.
[0143] An embodiment of the present disclosure also provides a third network element including a processor and a transceiver for transmitting and receiving data under control of the processor, the processor comprising: A third network element is further provided, which is for performing an operation of storing contract information of a user equipment, the contract information carrying target address information being address information of one or a set of AAA servers corresponding to the network slice.
[0144] In one alternative embodiment, the processor: It is further used to perform an operation of sending subscription information of the user equipment to a first network element.
[0145] In an embodiment of the present disclosure, the UDM or AUSFU sends contract information to the AMF, and the AMF obtains the address information of the AAA server corresponding to each slice from the contract information and transmits it to the NSSAAF via a related message, so that the NSSAAF can select the corresponding AAA server based on the received AAA server address information, thereby fine-tuning the granularity of AAA server selection and realizing offloading users of different levels to different AAA servers.
[0146] It should be noted that, as long as the third network element according to the embodiments of the present disclosure is a third network element capable of performing the above information storage method, all embodiments of the above information storage method are applicable to the third network element and can achieve the same or similar beneficial effects.
[0147] The embodiments of the present disclosure further provide a network element, which is a first network element, a second network element, or an NSSAAF network element, and the network element includes a memory, a processor, and a computer program stored in the memory and operable on the processor, and when the program is executed by the processor, each step in the embodiment of the network element selection method described above, or each step in the embodiment of the information transmission method, or each step in the embodiment of the information storage method described above is realized, and the same technical effects can be achieved, but to avoid repetition, they will not be repeated here.
[0148] The embodiments of the present disclosure further provide a computer-readable storage medium storing a computer program, which, when executed by a processor, realizes the steps in the above-described network element selection method embodiment, the steps in the information transmission method embodiment, or the steps in the information storage method embodiment, and achieves the same technical effects, but to avoid repetition, will not be described again. The computer-readable storage medium may be, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.
[0149] Those skilled in the art will appreciate that embodiments of the present disclosure may be provided as a method, a system, or a computer program product. Accordingly, embodiments of the present disclosure may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product embodied in one or more computer-readable storage media (including, but not limited to, magnetic disk memory, optical memory, etc.) containing computer-usable program code.
[0150] The present disclosure is described with reference to flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processing device, or other programmable data processing device to form a machine, and the instructions executed by the processor of the computer or other programmable data processing device form an apparatus for implementing the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.
[0151] These computer program instructions may be stored on a computer-readable storage medium that can direct a computer or other programmable data processing device to operate in a particular manner, and the instructions stored on the computer-readable storage medium form an article of manufacture that includes an instruction apparatus that implements the functions specified in one or more flows of the flowcharts and / or one or more blocks of the block diagrams.
[0152] These computer program instructions may be loaded into a computer or other programmable data processing device and cause the computer or other programmable data processing device to perform a series of operational steps to form a computer-implemented process, the instructions executing on the computer or other programmable data processing device providing steps for implementing the functions specified in one or more flows of the flowcharts and / or one or more blocks of the block diagrams.
[0153] The above is a preferred embodiment of the present disclosure, and it should be noted that those skilled in the art may further make some improvements and modifications without departing from the principles described in the present disclosure, and these improvements and modifications should also be considered to be within the scope of protection of the present disclosure.
Claims
1. A network element selection method performed by a first network element, comprising: Single network slice selection assistance information (S-NSSAI) of a network slice; and a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN); a Universal Public User Identifier (GPSI); and A User Permanent Identifier (SUPI); and a User Secret Identifier (SUCI); and An external group ID; An internal group ID; selecting a Network Slice Specific Authentication and Authorization Function (NSSAAF) network element according to first information including at least one of: a routing identifier; selecting an NSSAAF network element according to the first information; sending a first request message to a second network element, the first request message including the first information; receiving a first response message sent from a second network element, the first response message including one or a set of fully qualified domain names (FQDNs) and / or address information of the NSSAAF; selecting an NSSAAF in accordance with the first response message and a predetermined selection policy; Before selecting an NSSAAF network element according to the first information, the method further comprises: Further comprising: obtaining contract information of the user equipment from a third network element, the contract information carrying target address information being address information of one or a set of authentication, authorization, and accounting (AAA) servers corresponding to the network slice; After selecting the NSSAAF network element, the method further comprises: The network element selection method further includes sending an authorization request message including the target address information to the selected NSSAAF network element.
2. The authorization request message includes: GPS and S-NSSAI of the network slice; and Extensible Authentication Protocol (EAP) information.
3. 1. A method of transmitting information performed by a second network element, comprising: A first request message sent from a first network element, the first request message including first information, the first information including: S-NSSAI of the network slice; a home network identifier in a user permanent identifier (SUPI); Data Network Name (DNN); a Universal Public User Identifier (GPSI); and A User Permanent Identifier (SUPI); and a User Secret Identifier (SUCI); and An external group ID; An internal group ID; receiving a first request message including at least one of a routing identifier; and sending a first response message to the first network element according to the first request message, the first response message including FQDN and / or address information of one or a set of NSSAAFs.
4. 1. An information transmission method performed by a Network Slice Specific Authentication and Authorization Function (NSSAAF) network element, comprising: An information transmission method including receiving an authorization request message sent from a first network element, the authorization request message including target address information which is address information of one or a set of AAA servers corresponding to a network slice requested by the user equipment.
5. The authorization request message includes: GPS and S-NSSAI of the network slice; and at least one of: Extensible Authentication Protocol (EAP) information; Or, The method of claim 4 , wherein the target address information is obtained by the first network element from subscription information of the user equipment sent from a third network element.
6. The method comprises: The method of claim 4 , further comprising: selecting a corresponding AAA server for the user equipment according to the target address information.
7. When the AAA server includes a fourth network element and a fifth network element, the method includes: sending an AAA protocol message carrying the target address information to the fifth network element; and forwarding the AAA protocol message by the fifth network element to a fourth network element; Or, When the AAA server includes a fourth network element, the method further comprises: The method of claim 6 , further comprising: sending an AAA protocol message carrying the target address information to the fourth network element.
8. The AAA protocol message includes: GPS and S-NSSAI of the network slice; 8. The method of claim 7, further comprising at least one of: Extensible Authentication Protocol (EAP) information;
9. 1. A method of transmitting information performed by a first network element, comprising: An information transmission method including sending an authorization request message to a network slice specific authentication and authorization function (NSSAAF) network element, the authorization request message including target address information that is address information of one or a set of AAA servers corresponding to the network slice requested by the user equipment.
10. The authorization request message includes: GPS and S-NSSAI of the network slice; and at least one of: Extensible Authentication Protocol (EAP) information; Or, Before sending the authorization request message to the NSSAAF network element, the method further comprises: The method of claim 9, further comprising: obtaining contract information for the user equipment from a third network element, the contract information carrying target address information that is address information of one or a set of AAA servers corresponding to the network slice.
11. A method of information storage performed by a third network element, comprising: Storing contract information for a user equipment, the contract information carrying target address information being address information of one or a set of AAA servers corresponding to the network slice; The method comprises: The information storage method further includes transmitting subscription information of the user equipment to a first network element.
12. A network element comprising a memory, a processor, and a program stored in the memory and operable on the processor, wherein when the program is executed by the processor, the network element selection method described in any one of claims 1 to 2 is realized.
13. A network element comprising a memory, a processor, and a program stored in the memory and operable on the processor, wherein when the program is executed by the processor, the information transmission method described in claim 3 is realized.
14. A network element comprising a memory, a processor, and a program stored in the memory and operable on the processor, wherein when the program is executed by the processor, an information transmission method described in any one of claims 4 to 8 is realized.
15. A network element comprising a memory, a processor, and a program stored in the memory and operable on the processor, wherein when the program is executed by the processor, an information transmission method described in any one of claims 9 to 10 is realized.
Citation Information
Patent Citations
Support group communications with shared downlink data
US20210105196A1
QOS mapping
WO2021090279A1