Master authentication methods for user equipment (UE), electronic device and storage medium

The first network element receives and processes the remaster authentication request, obtains the status of the UE and sends response indication information, which solves the problem of UE failing authentication in special scenarios, and improves the success rate of the main authentication process and the quality of network service.

WO2025091725A1PCT designated stage expired Publication Date: 2025-05-08ZTE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/079039
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-30
Filing Date
2024-02-28
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

In special scenarios, the user equipment UE may cause authentication failures to belong to the network element or visit the network element based on the original policy operation, affecting the network service quality and user experience.

Method used

By receiving the re-master authentication request message sent by the second network element, the first network element acquires the status of the UE, and determines the response indication information based on the status determination, and sends the re-master authentication response message to the second network element to ensure that the second network element performs corresponding operations according to the response indication information and adapts to the current status of the UE.

Benefits of technology

The success rate of the main authentication process of the user equipment UE is improved, the quality of network service and user experience is improved, and authentication failure caused by the UE in a special state is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024079039_08052025_PF_FP_ABST
    Figure CN2024079039_08052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides master authentication methods for a user equipment (UE), an electronic device and a storage medium, and relates to the technical field of communications. A master authentication method for a user equipment (UE) comprises: receiving a master reauthentication request message sent by a second network element, the master reauthentication request message carrying a UE identifier (S301); according to the UE identifier, acquiring the state of a corresponding UE (S302); according to the state of the UE, determining response indication information (S303); and sending a master reauthentication response message to the second network element, the master reauthentication response message carrying the response indication information, so that the second network element performs a corresponding operation according to the response indication information (S304).
Need to check novelty before this filing date? Find Prior Art

Description

Primary authentication method for user equipment UE, electronic device and storage medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application is based on the Chinese patent application with application number 202311429362.8 and application date of October 30, 2023, and claims the priority of the Chinese patent application. The entire content of the Chinese patent application is hereby incorporated into this application by reference. Technical Field

[0003] The embodiments of the present application relate to the field of communication technologies, and in particular to a primary authentication method for user equipment (UE), an electronic device, and a storage medium. Background Art

[0004] Currently, during the network registration process, user equipment (UE) submits a registration request to the home network through the visited network element. After receiving the registration request from the UE, the home network element decides whether to execute the primary authentication process triggered by the home network based on events or its own authentication policy. During the primary authentication process, the home network sends a re-primary authentication request to the visited network element. However, after the visited network element receives the re-primary authentication request, the UE may be in a special scenario, causing the home network element or the visited network element to fail authentication based on the original policy, thereby affecting the network service quality and reducing the user experience. How to trigger the primary authentication process when the UE is in a special scenario is a technical problem that needs to be solved.

[0005] Summary of the Invention

[0006] Embodiments of the present application provide a primary authentication method for user equipment (UE), an electronic device, and a storage medium.

[0007] In the first aspect, an embodiment of the present application provides a primary authentication method for a user equipment UE, which is applied to a first network element, and the method includes: receiving a re-master authentication request message sent by a second network element, the re-master authentication request message carrying a UE identifier; determining the UE based on the UE identifier, and obtaining the status of the UE; determining response indication information based on the status of the UE; and sending a re-master authentication response message to the second network element, the re-master authentication response message carrying the response indication information, so that the second network element performs corresponding operations according to the response indication information.

[0008] In the second aspect, an embodiment of the present application provides a primary authentication method for a user equipment UE, which is applied to a second network element. The method includes: sending a re-master authentication request message to a first network element, the re-master authentication request message carries a UE identifier, so that the first network element determines the UE based on the UE identifier, and determines the response indication information based on the status of the UE; receiving a re-master authentication response message sent by the first network element, the re-master authentication response message carries the determination response indication information; and performing corresponding operations according to the response indication information.

[0009] In a third aspect, an embodiment of the present application provides an electronic device, comprising: one or more processors; a memory on which one or more programs are stored, and when the one or more programs are executed by the one or more processors, the one or more processors implement the primary authentication method of the user equipment UE as described in the first aspect above, or the primary authentication method of the user equipment UE as described in the second aspect above.

[0010] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the primary authentication method of the user equipment UE as described in the first aspect above is implemented, or the primary authentication method of the user equipment UE as described in the second aspect above is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] The accompanying drawings are used to provide a further understanding of the technical solution of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application and do not constitute a limitation on the technical solution of the present application.

[0012] FIG1 is a diagram of a network system architecture provided by an embodiment of the present application;

[0013] FIG2 is a diagram of a network system architecture provided by another embodiment of the present application;

[0014] FIG3 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application;

[0015] FIG4 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0016] FIG5 is a schematic flow chart of a primary authentication method of a user equipment UE in some situations;

[0017] FIG6 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0018] FIG7 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0019] FIG8 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0020] FIG9 is a schematic flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0021] FIG10 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0022] FIG11 is a schematic flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0023] FIG12 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0024] FIG13 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0025] FIG14 is a schematic diagram of a flow chart of a primary authentication method for a user equipment UE provided in another embodiment of the present application;

[0026] FIG15 is a schematic diagram of the device structure of the electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0027] In order to make the purpose, technical solutions and advantages of this application more clearly understood, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the embodiments described herein are only used to explain this application and are not intended to limit this application.

[0028] It should be understood that in the description of the embodiments of the present application, if there is a description of "first", "second", etc., it is only for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features. "At least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that there may be three relationships. For example, A and / or B can indicate the existence of A alone, the existence of A and B at the same time, and the existence of B alone. A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any group of these items, including any group of single or plural items. For example, at least one of a, b and c can indicate: a, b, c, a and b, a and c, b and c, or a, b and c, where a, b, c can be single or multiple.

[0029] In addition, the technical features involved in each embodiment of the present application described below can be combined with each other as long as they do not conflict with each other.

[0030] The primary authentication method for the user terminal UE provided in the embodiment of the present application can be applied to various communication systems, such as: 5G communication system, or various future communication systems.

[0031] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0032] Before introducing the technical solution of the embodiment of the present application, the network architecture of the embodiment of the present application is first described. Please refer to Figure 1, which is a schematic diagram of a network system architecture provided by the embodiment of the present application. As shown in Figure 1, the network architecture consists of user equipment (UE), access network (RAN) and operator network. The operator network includes core network (CN) and data network (DN). The UE accesses the operator network through RAN. CN, as a bearer network, provides an interface to DN, providing communication connection, authentication, management, policy control and carrying of data services for UE. Among them, CN includes: Access and Mobility Management Function (AMF), Security Anchor Function (SEAF), Session Management Function (SMF), User Plane Function (UPF), Authentication Server Function (AUSF), Unified Data Management Function (UDM), Network Exposure Function (NEF), Application Function (AF), Network Slice Selection Function (NSSF), Policy Control Function (PCF), Network Function Repository Function (NRF), etc. In Figure 1, N1, N2, N3, N4 and N6 are interfaces between corresponding network elements; Namf, Nsmf, Nausf, Nudm, Nnef, Npcf, Naf, Nnssf and Nnrf are the services presented by AMF, SMF, AUSF, UDM, NEF, PCF, AF, NSSF and NRF respectively.

[0033] Please refer to Figure 2, which shows the network elements and their connection relationships mainly involved in the embodiment of the present application in the network architecture shown in Figure 1, including UE, AMF, UDM and NF, etc., wherein the UE includes a handheld device, a vehicle-mounted device, a wearable device or a computing device with wireless communication function. In some embodiments, the UE can be a mobile phone, a tablet computer or a computer with wireless transceiver function. The terminal device can also be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. The UE communicates with the AMF through the N1 interface, or communicates with the AMF through the RAN and N2 interfaces. The AMF is responsible for terminal access and mobility management, such as registration, connection, mobility, and reachability management. In practice, it encompasses the mobility management functions of the Mobility Management Entity (MME) within the Long Term Evolution (LTE) network framework, and adds access management capabilities. Furthermore, the SEAF provides primary authentication services. Current standards define the SEAF and AMF as a combined entity. Namf is the service-based interface provided by the AMF. The UDM is a control plane network element provided by the operator. It is responsible for generating authentication parameters and storing the operator's network's Subscriber Permanent Identifier (SUPI), registration information, credentials, and subscription data. Nudm is the service-based interface provided by the UDM. Furthermore, the Authentication Credential Repository and Processing Function (ARPF) resides within the UDM and is used to generate authentication parameters. A network function (NF) is a software module or entity in the network that performs specific network tasks or functions. The access and mobility management function (AAnF) is a network function NF in the core network responsible for managing the mobility of user equipment (UE), including UE handover, redirection, and registration. Naanf is the service-based interface provided by AAnf. The AUSF is a control plane network element provided by the operator and can be used to authenticate network subscribers in the operator network. Nausf is the service-based interface provided by AUSF.AMF / SEAF and AUSF can be located in the same network, for example, AMF / SEAF and AUSF are both located in the Home Public Land Mobile Network (HPLMN), referred to as the Home network; AMF / SEAF and AUSF can also be located in different networks, for example, SEAF / AMF is located in the Visited Public Land mobile Network (VPLMN), referred to as the Visited network, and AUSF is located in the Home network. If the UE is outside the coverage of the Home network, it cannot directly access the Home network to obtain services. At this time, if the UE is within the coverage of the Visited network, the UE needs to access the Visited network in order to obtain network services provided by the Visited network and the Home network.

[0034] Currently, during the network registration process, a user equipment (UE) submits a registration request to the home network through a visited network element. After receiving the registration request from the UE, the home network element decides whether to execute the primary authentication process triggered by the home network based on an event or its own authentication policy. During the primary authentication process, the home network sends a re-primary authentication request to the visited network element. However, after the visited network element receives the re-primary authentication request, the UE may be in a special scenario, causing the home network element or the visited network element to fail authentication based on the original policy, thereby affecting the network service quality and reducing the user experience. How to trigger the primary authentication process when the UE is in a special scenario is a technical problem that needs to be solved.

[0035] A primary authentication method as shown in FIG5 includes:

[0036] Step S501: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0037] Step S502: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides the UDM with a callback URI.

[0038] Step S503: The NF (eg, AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0039] Step S504: The UDM determines whether to perform the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMFs / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0040] Step S505: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0041] Step S506: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to AMF / SEAF via the callback URI provided by AMF / SEAF, which carries the UE's SUPI.

[0042] Step S507: After receiving the Nudm_UECM_Re-AuthenticationNotification message from the UDM, the AMF / SEAF determines whether to proceed with the primary authentication process based on its own local authentication policy and the UE status. If the AMF / SEAF determines that the primary authentication cannot be performed, the AMF / SEAF sends an authentication response message with the failure reason to the UDM. If the AMF / SEAF determines that the primary authentication can be performed, the AMF / SEAF confirms the re-primary authentication request sent by the UDM. If the AMF / SEAF confirms the re-primary authentication request sent by the UDM, but the AMF / SEAF cannot initiate the primary authentication of the UE (for example, the UE is unreachable), the AMF / SEAF sets the authentication pending flag.

[0043] During this period, when the UE reconnects to the same AMF / SEAF or becomes reachable again, the AMF / SEAF checks the authentication suspension flag and performs re-authentication if necessary. Once the UE re-authentication is completed, the AMF / SEAF resets the authentication suspension flag. When receiving an authentication response message with a failure reason sent from the AMF / SEAF, the UDM can detect whether an AMF / SEAF under another access mode is available. The UDM can select another available AMF / SEAF and retry to trigger the primary authentication.

[0044] Step S508: AMF / SEAF starts the main authentication process.

[0045] After AMF / SEAF receives the Nudm_UECM_Re-AuthenticationNotification message sent by UDM, there is still a problem that AMF / SEAF and UDM cannot perform operations correctly in multiple scenarios such as the UE is performing primary authentication, the UE is performing mobility registration, or the UE is performing handover, which seriously affects the service quality and reduces the user experience.

[0046] The embodiment of the present application first proposes a primary authentication method for a user equipment UE, which is applied to a first network element. Please see Figure 3. Figure 3 shows a primary authentication method for a user equipment UE provided by an embodiment of the present application. As shown in Figure 3, the primary authentication method for the user equipment UE includes but is not limited to steps S301 to S304.

[0047] Step S301: Receive a master authentication request message sent by a second network element, where the master authentication request message carries a UE identifier.

[0048] It can be understood that the first network element is a visited network network element, and the second network element is a home network element. In the main authentication process, the second network element sends a re-authentication request carrying a UE identifier to the first network element to request the first network element to execute the main authentication process of the UE, wherein the UE identifier can be the Subscriber Permanent Identifier (SUPI) of the user equipment in the operator network or other UE identifier that can uniquely identify the UE. The embodiments of the present application are not limited here.

[0049] Step S302: Acquire the corresponding UE status according to the UE identifier.

[0050] It can be understood that after receiving the re-authentication request message carrying the UE identifier, the first network element obtains the status of the corresponding user equipment UE based on the UE identifier carried in the re-authentication request message. In some embodiments, the status of the user equipment UE may be whether the user equipment is performing primary authentication (authentication), whether it is performing a mobility registration process (mobility registration) or whether it is performing a handover process (handover), etc., which may cause the first network element and the second network element to be unable to correctly perform the primary authentication operation. The embodiments of the present application are not limited here.

[0051] It should be noted that the user equipment UE sends various service requests carrying its own status information to the first network element to request the first network element to provide corresponding services. The first network element can obtain the UE status from the various service requests reported by the UE and record it using the UE identifier that can uniquely identify the user equipment. Alternatively, the first network element actively requests the user equipment UE to reply with its own status information and records it using the UE identifier that can uniquely identify the user equipment, so that the first network element can obtain the corresponding UE status from the corresponding UE status record information according to the UE identifier.

[0052] Step S303: Determine response indication information according to the status of the UE.

[0053] It should be understood that after obtaining the status of the corresponding UE according to the UE identifier, the first network element determines the response indication information according to the status of the UE, wherein the response indication information is determined by the UE status, and can be indication information for characterizing and confirming the re-authentication request message sent by the second network element, an error code for indicating that the UE is in a special state, or a reason value for indicating that the UE is in a special state, etc. Different response indication information is used to represent different UE states to instruct the second network element to perform subsequent corresponding operations under different UE states.

[0054] Step S304: Send a re-authentication response message to the second network element. The re-authentication response message carries response indication information, so that the second network element performs corresponding operations according to the response indication information.

[0055] It can be understood that after determining the response indication information according to the status of the UE, the first network element sends a re-master authentication response information carrying the response indication information to the second network element. After the second network element receives the re-master authentication response information sent by the first network element, the second network element can perform subsequent operations for the special UE status according to the response indication information carried in the re-master authentication response information, so that the subsequent operations of the network element can be adapted to the current status of the UE, avoiding the situation where the network element cannot correctly perform the corresponding main authentication operation when the UE is in a special status, resulting in authentication failure, and achieving the purpose of improving the success rate of the UE's main authentication process.

[0056] In some embodiments, the first network element is an access and mobility management function AMF network element or a security anchor function SEAF network element, and the second network element is a unified data management UDM network element.

[0057] It should be understood that the first network element is an AMF or SEAF network element, and the second network element is a UDM network element. In the UE main authentication process shown in Figure 4, when the user equipment UE registers with the network, the AMF / SEAF network element registers the UE to the UDM network element through the Nudm registration request Nudm_UECM_registration. The UDM network element determines whether to perform the main authentication process triggered by the home network based on the event or its own authentication policy. After that, the UDM network element sends a re-authentication request message to the AMF / SEAF, that is, the Nudm_UECM_Re-AuthenticationNotification message. The message carries the SUPI of the UE. After receiving the re-authentication request message sent by the UDM network element, the AMF / SEAF network element determines whether to execute the main authentication process of the UE. The AMF / SEAF network element obtains the status of the corresponding UE according to the SUPI of the UE. Then the AMF / SEAF network element determines the response indication information according to the status of the UE, and sends a re-authentication response message carrying the response indication information to the UDM network element, that is, Nudm_UECM_Re-AuthenticationNotification response message. The UDM network element performs corresponding operations according to the response indication information carried in the response message.

[0058] In some embodiments, determining the response indication information according to the state of the UE includes:

[0059] When the UE status is that the main authentication process is in progress, it is determined that the response indication information is confirmation request indication information.

[0060] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0061] A re-authentication response message is sent to the second network element, where the re-authentication response message carries confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

[0062] It can be understood that if the UE is performing the main authentication process when the first network element receives the re-master authentication request message sent by the second network element, the first network element determines that the response indication information is a confirmation request indication information and sends a re-master authentication response message carrying the confirmation request indication information to the second network element, that is, the first network element directly confirms the second network element's re-master authentication request in the re-master authentication response message sent to the second network element.

[0063] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, please refer to Figure 6. Figure 6 shows a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application. As shown in Figure 6, if AMF / SEAF is already performing a primary authentication process on the UE when it receives a re-authentication request message sent by UDM, AMF / SEAF replies to UDM with a Nudm_UECM_Re-AuthenticationNotification response message, and confirms the re-authentication request sent by UDM in the response message.

[0064] In an embodiment of the present application, if the first network element serving as a visited network network element receives a re-authentication request from the second network element serving as a home network element to instruct the first network element to perform primary authentication on the UE, and the UE is performing a primary authentication process, the first network element confirms the primary authentication request to the second network element, so that subsequent operations of the network element can adapt to the status of the UE performing the primary authentication process, thereby avoiding the situation where the visited network network element and the home network element encounter the situation where the UE is performing the primary authentication process and cannot correctly perform the corresponding primary authentication operation when executing the primary authentication process, thereby achieving the purpose of improving the success rate of the UE's primary authentication process.

[0065] In some embodiments, determining the response indication information according to the state of the UE includes:

[0066] When the UE is in the state of performing a mobility registration procedure, it is determined that the response indication information is first error indication information.

[0067] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0068] Send a re-authentication response message to the second network element, where the re-authentication response message carries the first error indication information, so that the second network element starts a timer according to the first error indication information, and re-sends the re-authentication request message according to the UE's latest first network element registration information after the timer expires.

[0069] It is understood that if the first network element receives a re-authentication request message sent by the second network element while the UE is performing a mobility registration procedure, the first network element determines that the response message is first error indication information and sends a re-authentication response message carrying the first error indication information to the second network element. When the second network element receives the re-authentication response message carrying the first error indication information, the second network element starts a timer and, after the timer expires, re-sends the re-authentication request message based on the UE's latest first network element registration information, i.e., the second network element re-sends the UE's re-authentication request message after a preset time interval. The receiving network element of the subsequent re-authentication request message is determined based on whether the UE sends a change after the mobility registration procedure. If the UE's latest first network element registration information indicates that the UE's first network element has not changed after the mobility registration procedure, the second network element re-sends the UE's re-authentication request message to the original first network element after a preset time interval. If the UE's latest first network element registration information indicates that the UE's first network element has changed after the mobility registration procedure, the second network element re-sends the UE's re-authentication request message to the changed first network element after a preset time interval.

[0070] It should be noted that the UE mobility registration process refers to when the user equipment UE moves from one service area to another service area, the UE initiates a registration request to the AMF of the new service area.

[0071] It should also be noted that the first error indication information is used to indicate the reason for the failure of the main authentication. It can be an error code used to characterize "the UE is performing a mobility registration process", such as TEMPORARY_REJECT_REGISTRATION_ONGOING, or it can be a reason value used to characterize "the UE is performing a mobility registration process", such as 1. That is to say, the first error indication information can be used to inform the second network element that "the UE is performing a mobility registration process". The embodiment of the present application does not limit the specific form of the first error indication information.

[0072] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, please refer to Figure 7. Figure 7 shows a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application. As shown in Figure 7, if the AMF / SEAF receives the re-authentication request message sent by the UDM while the UE is performing a mobility registration process, the AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, which includes an error code TEMPORARY_REJECT_REGISTRATION_ONGOING indicating the cause of failure, or includes other cause values ​​1 indicating that "the UE is performing a mobility registration process". When the UDM receives the response message and the response message includes an error code TEMPORARY_REJECT_REGISTRATION_ONGOING indicating the cause of failure, or includes other cause values ​​1 indicating that "the UE is performing a mobility registration process", the UDM starts a timer (for example, 1 second) and resends the re-authentication request message according to the UE's latest AMF / SEAF registration information after the timer expires.

[0073] In an embodiment of the present application, if the first network element serving as a visited network network element receives a re-master authentication request sent by a second network element serving as a home network element to instruct the first network element to perform master authentication on the UE, and the UE is performing a mobility registration process, the first network element sends a re-master authentication response message carrying first error indication information to the second network element. After receiving the re-master authentication response message carrying the first error indication information, the second network element resends the re-master authentication request message according to the UE's latest first network element registration information, so that subsequent operations of the network element can adapt to the state that the UE is performing a mobility registration process, thereby avoiding the situation where the visited network network element and the home network element encounter the situation that the UE is performing a mobility registration process and cannot correctly perform the corresponding master authentication operation when performing the master authentication process, thereby achieving the purpose of improving the success rate of the UE's master authentication process.

[0074] In some embodiments, determining the response indication information according to the state of the UE includes:

[0075] When the UE status is that the mobility registration procedure is in progress and the first network element does not change in the mobility registration procedure, it is determined that the response indication information is confirmation request indication information.

[0076] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0077] A re-authentication response message is sent to the second network element, where the re-authentication response message carries confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

[0078] It can be understood that if the UE is performing a mobility registration process when the first network element receives the re-authentication request message sent by the second network element, and the first network element does not change in the mobility registration process, the first network element determines that the response indication information is a confirmation request indication information and sends a re-authentication response message carrying the confirmation request indication information to the second network element, that is, the first network element directly confirms the re-authentication request of the second network element in the re-authentication response message replied to the second network element.

[0079] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, please refer to Figure 8. Figure 8 shows a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application. As shown in Figure 8, if the UE is performing a mobility registration process when the AMF / SEAF receives a re-authentication request message sent by the UDM, and the AMF / SEAF does not change after the UE executes the mobility registration process, the AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, and confirms the re-authentication request sent by the UDM in the response message.

[0080] In an embodiment of the present application, if the first network element serving as a visited network network element receives a re-master authentication request sent by the second network element serving as a home network element to instruct the first network element to perform master authentication on the UE, and the UE is performing a mobility registration process, and the first network element does not change during the mobility registration process, the first network element confirms the master authentication request to the second network element, so that subsequent operations of the network element can adapt to the state in which the UE is performing a mobility registration process, thereby avoiding the situation in which the visited network network element and the home network element encounter the situation in which the UE is performing a mobility registration process and cannot correctly perform the corresponding master authentication operation when executing the master authentication process, thereby achieving the purpose of improving the success rate of the UE's master authentication process.

[0081] In some embodiments, determining the response indication information according to the state of the UE includes:

[0082] When the UE is in the process of performing a mobility registration process and a first network element change event occurs during the mobility registration process, the response indication information is determined to be the second error indication information, the third error indication information or the fourth error indication information, wherein the first network element change event indicates that the UE switches access from the source first network element to the target first network element, and the first network element is the source first network element.

[0083] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0084] Sending a re-authentication response message to the second network element, where the re-authentication response message carries second error indication information, so that the second network element starts a timer according to the second error indication information and re-sends the re-authentication request message according to the latest first network element registration information of the UE after the timer expires;

[0085] or,

[0086] Sending a re-primary authentication response message to the second network element, where the re-primary authentication response message carries third error indication information, so that the second network element terminates the primary authentication process for the UE according to the third error indication information;

[0087] or,

[0088] A re-authentication response message is sent to the second network element, where the re-authentication response message carries the fourth error indication information, so that the second network element determines the target first network element according to the fourth error indication information, and sends the re-authentication response message to the target first network element after the mobility registration process is completed.

[0089] It can be understood that if the UE is performing a mobility registration process when the first network element receives the re-authentication request message sent by the second network element, and a first network element change event occurs in the mobility registration process and the current first network element is the source first network element in the first network element change event, the first network element determines that the response indication information is the second error indication information, the third error indication information or the fourth error indication information and sends a re-authentication response message carrying the corresponding error indication information to the second network element, and the second network element performs subsequent operations according to the type of error indication information carried in the re-authentication response message.

[0090] It should be noted that the second error indication information, the third error indication information, and the fourth error indication information are all used to indicate the reason for the failure of the primary authentication. Among them, the second error indication information may be an error code used to represent "the UE is performing a mobility registration process", such as TEMPORARY_REJECT_REGISTRATION_ONGOING; the third error indication information may be an error code used to represent "authentication not allowed", such as REAUTHENTICATION_NOT_ALLOWED; and the fourth error indication information may be a reason value used to represent "the UE is performing a mobility registration process and the first network element is about to change", such as 2. In other words, different error indication information can be used to inform the second network element of different reasons for the failure of the primary authentication. The embodiment of the present application does not limit the specific forms of the second error indication information, the third error indication information, and the fourth error indication information.

[0091] When the second network element receives a re-authentication response message carrying second error indication information sent by the first network element, the second network element starts a timer according to the second error indication information, and resends the re-authentication request message according to the UE's latest first network element registration information after the timer expires, that is, the second network element learns that the UE is performing a mobility registration process through the second error indication information carried in the re-authentication response message, and the second network element chooses to resend the UE's re-authentication request message after a preset time interval to continue the UE's primary authentication process.

[0092] When the second network element receives a re-authentication response message sent by the first network element and carrying the third error indication information, the second network element terminates the main authentication process for the UE according to the third error indication information, that is, the second network element learns that authentication is not allowed through the third error indication information carried in the re-authentication response message, and the second network element chooses to terminate the main authentication process for the UE. If a new registration request from the first network element is subsequently received, the second network element can decide whether to initiate a new main authentication process according to its own authentication policy.

[0093] When the second network element receives the re-master authentication response message carrying the fourth error indication information sent by the first network element, the second network element determines the target first network element based on the fourth error indication information, and sends the re-master authentication response message to the target first network element after the mobility registration process is completed. That is, the second network element learns through the fourth error indication information carried in the re-master authentication response message that the UE is performing a mobility registration process and the UE switches access from the source first network element to the target first network element. The second network element chooses to send the re-master authentication response message to the target first network element after the mobility registration process is completed to continue the UE's master authentication process.

[0094] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, refer to Figure 9, which shows a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application. As shown in Figure 9, when the source AMF / SEAF receives the re-authentication request message sent by the UDM, the UE is performing a mobility registration process, and the AMF / SEAF is about to change and the source AMF / SEAF receives the re-authentication request message sent by the UDM. The source AMF / SEAF may perform one of the following steps:

[0095] A. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing the error code TEMPORARY_REJECT_REGISTRATION_ONGOING indicating the cause of the failure.

[0096] B. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, which includes the error code REAUTHENTICATION_NOT_ALLOWED indicating the cause of the failure.

[0097] C. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing a cause value of 2 indicating that the UE is undergoing a mobility registration procedure and the AMF / SEAF is about to change.

[0098] Correspondingly, after receiving the Nudm_UECM_Re-AuthenticationNotification response message, UDM performs the subsequent process according to the error indication information carried in the response message:

[0099] A. If the response message includes the second error indication information, i.e., the error code TEMPORARY_REJECT_REGISTRATION_ONGOING, the UDM starts a timer (e.g., 1 second) and resends the re-authentication request message as in step S907 according to the UE's latest AMF / SEAF registration information after the timer expires;

[0100] B. If the response message contains the third error indication information, that is, the error code REAUTHENTICATION_NOT_ALLOWED, the UDM does not need to perform other operations, that is, the UDM terminates the main authentication process for the UE. If the UDM subsequently receives a new AMF registration request, the UDM can determine whether to initiate a new main authentication process based on its own authentication policy;

[0101] C. If the response message contains the fourth error indication information, that is, the other cause value 2 representing "UE is performing a mobility registration process and the AMF / SEAF is about to change", the UDM determines the changed target AMF / SEAF and sends a re-authentication request message to the target AMF / SEAF after the current mobility registration process ends.

[0102] In an embodiment of the present application, if a first network element serving as a visited network network element receives a re-master authentication request sent by a second network element serving as a home network element to instruct the first network element to perform master authentication on the UE, the UE is performing a mobility registration process, a first network element change event occurs in the mobility registration process and the current first network element is the source first network element in the first network element change event, then the first network element sends a re-master authentication response message carrying a second error indication information, a second error indication information or a third error indication information to the second network element, and the second network element performs corresponding operations according to the type of error indication information carried in the re-master authentication response message, so that subsequent operations of the network element can be adapted to the state that the UE is performing a mobility registration process, thereby avoiding the situation where the visited network network element and the home network element encounter a situation where the UE is performing a mobility registration process and the first network element has changed and cannot correctly perform the corresponding master authentication operation when performing the master authentication process, thereby achieving the purpose of improving the success rate of the UE's master authentication process.

[0103] In some embodiments, determining the response indication information according to the state of the UE includes:

[0104] When the UE is in the process of undergoing a mobility registration process and a first network element change event occurs during the mobility registration process, the response indication information is determined to be confirmation request indication information, wherein the first network element change event indicates that the UE switches access from the source first network element to the target first network element, and the first network element is the target first network element.

[0105] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0106] A re-authentication response message is sent to the second network element, where the re-authentication response message carries confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

[0107] It can be understood that if the UE is performing a mobility registration process when the first network element receives the re-authentication request message sent by the second network element, and a first network element change event occurs in the mobility registration process and the current first network element is the target first network element in the first network element change event, the first network element determines that the response indication information is a confirmation request indication information and sends a re-authentication response message carrying the confirmation request indication information to the second network element, that is, the first network element directly confirms the re-authentication request of the second network element in the re-authentication response message replied to the second network element.

[0108] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, please refer to Figure 10. Figure 10 shows a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application. As shown in Figure 10, if the target AMF / SEAF receives a re-authentication request message sent by UDM while the UE is performing a mobility registration process, the target AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, and confirms the re-authentication request sent by UDM in the response message.

[0109] In an embodiment of the present application, if the first network element serving as a visited network network element receives a re-master authentication request sent by the second network element serving as a home network element to instruct the first network element to perform master authentication on the UE, the UE is performing a mobility registration process, a first network element change event occurs in the mobility registration process and the current first network element is the target first network element in the first network element change event, then the first network element confirms the master authentication request to the second network element, so that subsequent operations of the network element can adapt to the state that the UE is performing a mobility registration process, thereby avoiding the situation where the visited network network element and the home network element encounter the situation that the UE is performing a mobility registration process and cannot correctly perform the corresponding master authentication operation when executing the master authentication process, thereby achieving the purpose of improving the success rate of the UE's master authentication process.

[0110] In some embodiments, determining the response indication information according to the state of the UE includes:

[0111] When the UE is in the state of performing a handover procedure, it is determined that the response indication information is fifth error indication information.

[0112] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0113] Send a re-authentication response message to the second network element, where the re-authentication response message carries the fifth error indication information, so that the second network element starts a timer according to the fifth error indication information, and re-sends the re-authentication request message according to the UE's latest first network element registration information after the timer expires.

[0114] It is understandable that if the first network element receives a re-authentication request message sent by the second network element while the UE is in the process of a handover procedure, the first network element determines that the response message is first error indication information and sends a re-authentication response message carrying fifth error indication information to the second network element. When the second network element receives the re-authentication response message carrying the fifth error indication information, the second network element starts a timer and, after the timer expires, re-sends the re-authentication request message based on the UE's latest first network element registration information, i.e., the second network element re-sends the UE's re-authentication request message after a preset time interval. The receiving network element of the subsequent re-authentication request message is determined based on whether the UE sends a change after the handover procedure. If the UE's latest first network element registration information indicates that the UE's first network element has not changed after the handover procedure, the second network element re-sends the UE's re-authentication request message to the original first network element after a preset time interval. If the UE's latest first network element registration information indicates that the UE's first network element has changed after the handover procedure, the second network element re-sends the UE's re-authentication request message to the changed first network element after a preset time interval.

[0115] It should be noted that the UE handover process refers to a process in which the user equipment UE switches from one serving cell to another serving cell.

[0116] It should also be noted that the fifth error indication information is used to indicate the reason for the failure of the main authentication. It can be an error code used to characterize "the UE is performing a handover process", such as TEMPORARY_REJECT_HANDOVER_ONGOING, or it can be a reason value used to characterize "the UE is performing a handover process", such as 3. That is to say, the fifth error indication information can be used to inform the second network element that "the UE is performing a handover process". The embodiment of the present application does not limit the specific form of the fifth error indication information.

[0117] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, please refer to Figure 11. Figure 11 shows a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application. As shown in Figure 11, if the AMF / SEAF receives the re-authentication request message sent by the UDM while the UE is performing a handover process, and regardless of whether the AMF / SEAF changes after the UE executes the handover process, the AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, which includes an error code TEMPORARY_REJECT_HANDOVER_ONGOING indicating the cause of failure, or includes other cause values ​​3 indicating that "the UE is performing a handover process". When the UDM receives the response message and the response message includes an error code TEMPORARY_REJECT_HANDOVER_ONGOING indicating the cause of failure, or includes other cause values ​​3 indicating that "the UE is performing a handover process", the UDM starts a timer (for example, 1 second) and resends the re-authentication request message according to the UE's latest AMF / SEAF registration information after the timer expires.

[0118] In an embodiment of the present application, if the first network element serving as a visited network network element receives a re-master authentication request sent by a second network element serving as a home network element to instruct the first network element to perform master authentication on the UE, and the UE is performing a switching process, the first network element sends a re-master authentication response message carrying the fifth error indication information to the second network element. After receiving the re-master authentication response message carrying the fifth error indication information, the second network element resends the re-master authentication request message according to the UE's latest first network element registration information, so that subsequent operations of the network element can adapt to the state in which the UE is performing a switching process, thereby avoiding the situation in which the visited network network element and the home network element encounter the situation in which the UE is performing a switching process and cannot correctly perform the corresponding master authentication operation when performing the master authentication process, thereby achieving the purpose of improving the success rate of the UE's master authentication process.

[0119] In some embodiments, determining the response indication information according to the state of the UE includes:

[0120] When the UE status is that a handover procedure is in progress and the first network element does not change during the handover procedure, it is determined that the response indication information is confirmation request indication information.

[0121] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0122] A re-authentication response message is sent to the second network element, where the re-authentication response message carries confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

[0123] It can be understood that if the UE is performing a switching process when the first network element receives the re-authentication request message sent by the second network element, and the first network element does not change during the switching process, the first network element determines that the response indication information is a confirmation request indication information and sends a re-authentication response message carrying the confirmation request indication information to the second network element, that is, the first network element directly confirms the re-authentication request of the second network element in the re-authentication response message replied to the second network element.

[0124] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, please refer to Figure 12. Figure 12 shows a flow chart of a master authentication method provided in an embodiment of the present application. As shown in Figure 12, if the UE is performing a switching process when the AMF / SEAF receives the re-master authentication request message sent by the UDM, and the AMF / SEAF does not change after the UE executes the switching process, the AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, and confirms the re-master authentication request sent by the UDM in the response message.

[0125] In an embodiment of the present application, if the first network element serving as a visited network network element receives a re-authentication request sent by the second network element serving as a home network element to instruct the first network element to perform primary authentication on the UE, and the UE is performing a switching process and the first network element does not change during the switching process, the first network element confirms the primary authentication request to the second network element, so that subsequent operations of the network element can adapt to the state in which the UE is performing a switching process, thereby avoiding the situation in which the visited network network element and the home network element encounter the situation in which the UE is performing a switching process and cannot correctly perform the corresponding primary authentication operation when executing the primary authentication process, thereby achieving the purpose of improving the success rate of the UE's primary authentication process.

[0126] In some embodiments, determining the response indication information according to the state of the UE includes:

[0127] When the UE is in the process of performing a switching process and a first network element change event occurs during the switching process, the response indication information is determined to be the sixth error indication information, the seventh error indication information or the eighth error indication information, wherein the first network element change event indicates that the UE switches access from the source first network element to the target first network element, and the first network element is the source first network element.

[0128] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0129] Sending a re-authentication response message to the second network element, where the re-authentication response message carries sixth error indication information, so that the second network element starts a timer according to the sixth error indication information and re-sends the re-authentication request message according to the latest first network element registration information of the UE after the timer expires;

[0130] or,

[0131] Sending a re-primary authentication response message to the second network element, where the re-primary authentication response message carries seventh error indication information, so that the second network element terminates the primary authentication process for the UE according to the seventh error indication information;

[0132] or,

[0133] A re-authentication response message is sent to the second network element, the re-authentication response message carries the eighth error indication information, so that the second network element determines the target first network element according to the eighth error indication information, and sends a re-authentication response message to the target first network element after the switching process is completed.

[0134] It can be understood that if the UE is performing a switching process when the first network element receives a re-authentication request message sent by the second network element, and a first network element change event occurs in the switching process and the current first network element is the source first network element in the first network element change event, the first network element determines that the response indication information is the sixth error indication information, the seventh error indication information or the eighth error indication information and sends a re-authentication response message carrying the corresponding error indication information to the second network element, and the second network element performs subsequent operations according to the type of error indication information carried in the re-authentication response message.

[0135] It should be noted that the sixth error indication information, the seventh error indication information, and the eighth error indication information are all used to indicate the reason for the failure of the primary authentication. Among them, the sixth error indication information may be an error code used to characterize "UE is performing a handover process", such as TEMPORARY_REJECT_HANDOVER_ONGOING; the seventh error indication information may be an error code used to characterize "authentication not allowed", such as REAUTHENTICATION_NOT_ALLOWED; the eighth error indication information may be a reason value used to characterize "UE is performing a handover process and the first network element is about to change", such as 4. In other words, different error indication information can be used to inform the second network element of different reasons for the failure of the primary authentication. The embodiment of the present application does not limit the specific forms of the sixth error indication information, the seventh error indication information, and the eighth error indication information.

[0136] When the second network element receives the re-authentication response message carrying the sixth error indication signal sent by the first network element, the second network element starts the timer according to the sixth error indication information, and resends the re-authentication request message according to the UE's latest first network element registration information after the timer expires. That is, the second network element learns that the UE is performing a switching process through the fifth error indication information carried in the re-authentication response message, and chooses to resend the UE's re-authentication request message after a preset time interval to continue the UE's main authentication process.

[0137] When the second network element receives the re-authentication response message carrying the seventh error indication information sent by the first network element, the second network element terminates the main authentication process for the UE according to the seventh error indication information, that is, the second network element learns that authentication is not allowed through the seventh error indication information carried in the re-authentication response message, and the second network element chooses to terminate the main authentication process for the UE. If a new registration request from the first network element is subsequently received, the second network element can decide whether to initiate a new main authentication process according to its own authentication policy.

[0138] When the second network element receives the re-authentication response message carrying the eighth error indication information sent by the first network element, the second network element determines the target first network element based on the eighth error indication information, and sends the re-authentication response message to the target first network element after the mobility registration process is completed. That is, the second network element learns through the eighth error indication information carried in the re-authentication response message that the UE is performing a switching process and the UE switches access from the source first network element to the target first network element. The second network element chooses to send the re-authentication response message to the target first network element after the switching process is completed to continue the UE's main authentication process.

[0139] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, refer to Figure 13. Figure 13 shows a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application. As shown in Figure 13, if the source AMF / SEAF receives the re-authentication request message sent by the UDM while the UE is performing a mobility registration process, the AMF / SEAF is about to change and the source AMF / SEAF receives the re-authentication request message sent by the UDM, the source AMF / SEAF may perform one of the following steps:

[0140] A. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing the error code TEMPORARY_REJECT_HANDOVER_ONGOING indicating the cause of the failure.

[0141] B. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, which includes the error code REAUTHENTICATION_NOT_ALLOWED indicating the cause of the failure.

[0142] C. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing a cause value of 4 indicating that the UE is undergoing a handover procedure and the AMF / SEAF is about to change.

[0143] Correspondingly, after receiving the Nudm_UECM_Re-AuthenticationNotification response message, UDM performs the subsequent process according to the error indication information carried in the response message:

[0144] A. If the response message contains the sixth error indication information, i.e., the error code TEMPORARY_REJECT_HANDOVER_ONGOING, the UDM starts a timer (e.g., 1 second) and resends the re-authentication request message as in step S1307 according to the UE's latest AMF / SEAF registration information after the timer expires;

[0145] B. If the response message contains the seventh error indication information, that is, the error code REAUTHENTICATION_NOT_ALLOWED, the UDM does not need to perform other operations, that is, the UDM terminates the main authentication process for the UE. If the UDM subsequently receives a new AMF registration request, the UDM can determine whether to initiate a new main authentication process based on its own authentication policy;

[0146] C. If the response message contains the eighth error indication information, that is, the other cause value 4 representing "UE is performing a handover process and the AMF / SEAF is about to change", the UDM determines the changed target AMF / SEAF and sends a re-authentication request message as in step S1307 to the target AMF / SEAF after the current handover process is completed.

[0147] In an embodiment of the present application, if a first network element serving as a visited network network element receives a re-master authentication request sent by a second network element serving as a home network element to instruct the first network element to perform master authentication on the UE, the UE is performing a switching process, a first network element change event occurs in the switching process, and the current first network element is the source first network element in the first network element change event, then the first network element sends a re-master authentication response message carrying a sixth error indication information, a seventh error indication information, or an eighth error indication information to the second network element, and the second network element performs corresponding operations according to the type of error indication information carried in the re-master authentication response message, so that subsequent operations of the network element can be adapted to the state in which the UE is performing a switching process, thereby avoiding the situation in which the visited network network element and the home network element encounter a situation in which the UE is performing a switching process and the first network element has changed and cannot correctly perform the corresponding master authentication operation when performing the master authentication process, thereby achieving the purpose of improving the success rate of the UE's master authentication process.

[0148] In some embodiments, determining the response indication information according to the state of the UE includes:

[0149] When the UE status is that a switching process is in progress and a first network element change event occurs during the switching process, the response indication information is determined to be confirmation request indication information, where the first network element change event indicates that the UE switches access from the source first network element to the target first network element, and the first network element is the target first network element.

[0150] Correspondingly, a re-authentication response message is sent to the second network element, where the re-authentication response message carries response indication information, so that the second network element performs a corresponding operation according to the response indication information, including:

[0151] A re-authentication response message is sent to the second network element, where the re-authentication response message carries confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

[0152] It can be understood that if the UE is performing a switching process when the first network element receives the re-authentication request message sent by the second network element, and a first network element change event occurs in the switching process and the current first network element is the target first network element in the first network element change event, the first network element determines that the response indication information is a confirmation request indication information and sends a re-authentication response message carrying the confirmation request indication information to the second network element, that is, the first network element directly confirms the re-authentication request of the second network element in the re-authentication response message replied to the second network element.

[0153] In some embodiments, taking the first network element as an AMF / SEAF network element and the second network element as a UDM network element as an example, please refer to Figure 14. Figure 14 shows a flow chart of a primary authentication method for a user equipment UE provided in an embodiment of the present application. As shown in Figure 14, if the target AMF / SEAF is performing a switching process when it receives a re-authentication request message sent by the UDM, the target AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, and confirms the re-authentication request sent by the UDM in the response message.

[0154] In an embodiment of the present application, if the first network element serving as a visited network network element receives a re-authentication request sent by the second network element serving as a home network element to instruct the first network element to perform primary authentication on the UE, the UE is performing a switching process, a first network element change event occurs during the switching process, and the current first network element is the target first network element in the first network element change event, then the first network element confirms the primary authentication request to the second network element, so that subsequent operations of the network element can be adapted to the state in which the UE is performing a switching process, thereby avoiding the situation in which the visited network network element and the home network element encounter a situation in which the UE is performing a switching process and cannot correctly perform the corresponding primary authentication operation when executing the primary authentication process, thereby achieving the purpose of improving the success rate of the UE's primary authentication process.

[0155] An embodiment of the present application also provides a primary authentication method for a user equipment UE, which is applied to a second network element. Please see Figure 4. Figure 4 shows a primary authentication method for a user equipment UE provided by an embodiment of the present application. As shown in Figure 4, the primary authentication method for the user equipment UE includes but is not limited to steps S401 to S403.

[0156] Step S401: Send a re-authentication request message to a first network element. The re-authentication request message carries a UE identifier, so that the first network element obtains the status of the corresponding UE according to the UE identifier and determines response indication information according to the UE status.

[0157] Step S402: Receive a master authentication re-response message sent by the first network element, where the master authentication re-response message carries response indication information.

[0158] Step S403: perform corresponding operations according to the response indication information.

[0159] In an embodiment of the present application, the second network element sends a re-authentication request message carrying a UE identifier to the first network element. The first network element obtains the status of the corresponding UE based on the UE identifier and determines the response indication information based on the status of the UE. The second network element receives the re-authentication response message carrying the response indication information sent by the first network element. The second network element performs corresponding operations based on the response indication information. The operation of the second network element can be adapted to the current status of the UE, thereby achieving the purpose of improving the success rate of the UE's primary authentication process, thereby improving the network service quality and user experience.

[0160] It should be noted that the description and technical effects of the main authentication method applied to the second network element provided in the embodiment of the present application can be referred to the description of the main authentication method applied to the first network element provided in the above embodiment, and will not be repeated here.

[0161] In some embodiments, performing corresponding operations according to the response indication information includes:

[0162] When the response indication information is confirmation request indication information, the main authentication process of the UE is executed.

[0163] In some embodiments, performing corresponding operations according to the response indication information includes:

[0164] When the response indication information is any one of the first error indication information, the second error indication information, the fifth error indication information, or the sixth error indication information, start the timer, and resend the re-authentication request message according to the latest first network element registration information of the UE after the timer expires; wherein,

[0165] The first error indication information indicates that the UE is in the process of performing a mobility registration procedure;

[0166] The second error indication information indicates that the UE is in a state of performing a mobility registration procedure, and a first network element change event occurs during the mobility registration procedure;

[0167] The fifth error indication information indicates that the UE is in the state of performing a handover procedure;

[0168] The sixth error indication information indicates that the UE is in a handover process and that a first network element change event occurs during the handover process.

[0169] In some embodiments, performing corresponding operations according to the response indication information includes:

[0170] If the response indication information is the third error indication information or the seventh error indication information, the main authentication process for the UE is terminated; wherein,

[0171] The third error indication information indicates that the UE is in a state of performing a mobility registration procedure, and a first network element change event occurs during the mobility registration procedure;

[0172] The seventh error indication information indicates that the UE is in a handover process and that a first network element change event occurs during the handover process.

[0173] In some embodiments, performing corresponding operations according to the response indication information includes:

[0174] In the case where the response indication information is the fourth error indication information or the eighth error indication information, determining the target first network element, and sending a re-authentication response message to the target first network element after the UE ends the mobility registration process or the handover process; wherein,

[0175] The fourth error indication information indicates that the UE is in a state of performing a mobility registration procedure, and a first network element change event occurs during the mobility registration procedure;

[0176] The eighth error indication information indicates that the UE is in a handover process and that a first network element change event occurs during the handover process.

[0177] In some embodiments, the first network element is an access and mobility management function AMF network element or a security anchor function SEAF network element, and the second network element is a unified data management UDM network element.

[0178] In an embodiment of the present application, when the first network element receives the re-authentication request message sent by the second network element, in a special scenario where the UE is performing primary authentication, the UE is performing a mobility registration process, or the UE is performing a handover process, the first network element determines the response indication information according to the status of the UE and sends the re-authentication response information carrying the response indication information to the second network element. The second network element performs corresponding operations according to the response indication information carried in the re-authentication response information. This can avoid the situation where, after the visited network network element receives the re-authentication request, the home network element or the visited network element cannot correctly perform the operation based on the local authentication policy due to the UE being in a special scenario, resulting in authentication failure, thereby improving service quality and user experience.

[0179] It should be noted that the embodiment of the present application describes a series of operations performed by the second network element based on various response indication information carried in the re-master authentication response information. Its description and technical effects can be found in the description of a master authentication method applied to the first network element provided in the embodiment of the present application, and will not be repeated here.

[0180] The following describes a primary authentication method for a user equipment UE provided by the present application through an embodiment.

[0181] Example 1

[0182] In the first embodiment, the AMF is already performing primary authentication on the UE when receiving the primary authentication message of the UDM. As shown in FIG6 , the primary authentication method includes:

[0183] Step S610: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0184] Step S620: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides a callback URL for the UDM.

[0185] Step S630: The NF (eg, AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0186] Step S640: The UDM determines whether to perform the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMFs / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0187] Step S650: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0188] Step S660: The UE starts the main authentication process. Step S660 can occur at any time between the end of step S620 and the start of step S670.

[0189] Step S670: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to AMF / SEAF, which includes the UE's SUPI.

[0190] Step S680: If the AMF / SEAF is already performing the primary authentication process for the UE when it receives the re-authentication request message sent by the UDM, that is, the UE status is in the primary authentication process, the AMF / SEAF replies with a Nudm_UECM_Re-AuthenticationNotification response message to the UDM and confirms the re-authentication request sent by the UDM in the response message.

[0191] Example 2

[0192] The second embodiment is a scenario in which the UE is performing a mobility registration process when the AMF receives the primary authentication message of the UDM. As shown in Figure 7, the primary authentication method includes:

[0193] Step S701: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0194] Step S702: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides a callback URL for the UDM.

[0195] In step S703, the NF (such as AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0196] Step S704: The UDM determines whether to execute the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMFs / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0197] Step S705: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0198] Step S706: The UE starts the mobility registration process. Step S706 can occur at any time between the end of step S702 and the start of step S707.

[0199] Step S707: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to AMF / SEAF, which includes the UE's SUPI.

[0200] Step S708: If the UE is performing a mobility registration procedure when the AMF / SEAF receives the Re-Authentication Request message sent by the UDM, and regardless of whether the AMF / SEAF changes after the UE performs the mobility registration procedure, the AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing the error code TEMPORARY_REJECT_REGISTRATION_ONGOING indicating the cause of the failure, or containing other cause value 1 indicating "UE is performing a mobility registration procedure";

[0201] Step S709: When the UDM receives the response message and the response message includes the error code TEMPORARY_REJECT_REGISTRATION_ONGOING indicating the cause of the failure, or includes a cause value 1 indicating that "the UE is in the process of mobility registration", the UDM starts a timer (for example, 1 second) and resends the re-authentication request message in step S707 according to the UE's latest AMF / SEAF registration information after the timer expires.

[0202] Step S710: AMF / SEAF starts the main authentication process.

[0203] Example 3

[0204] Embodiment 3 is a scenario in which the UE is performing a mobility registration process when the AMF receives the primary authentication message of the UDM, and the AMF does not change in this scenario. As shown in Figure 8, the primary authentication method includes:

[0205] Step S801: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0206] Step S802: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides a callback URL for the UDM.

[0207] Step S803: The NF (eg, AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0208] Step S804: The UDM determines whether to execute the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMF / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0209] Step S805: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0210] Step S806: The UE starts the mobility registration process. Step S806 can occur at any time between the end of step S802 and the start of step S807.

[0211] Step S807: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to AMF / SEAF, which includes the UE's SUPI.

[0212] Step S808: If the UE is performing a mobility registration procedure when the AMF / SEAF receives the re-authentication request message sent by the UDM, and the AMF / SEAF does not change after the UE performs the mobility registration procedure, the AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, and confirms the re-authentication request sent by the UDM in the response message;

[0213] Step S809: AMF / SEAF starts the main authentication process.

[0214] Example 4

[0215] Embodiment 4 is a scenario in which the UE is performing a mobility registration process when the AMF receives the primary authentication message of the UDM, and the AMF changes in this scenario. As shown in Figure 9, the primary authentication method includes:

[0216] Step S901: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0217] Step S902: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides the UDM with a callback URI.

[0218] Step S903: The NF (eg, AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0219] Step S904: The UDM determines whether to execute the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMF / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0220] Step S905: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0221] Step S906: The UE starts the mobility registration process. Step S906 can occur at any time between the end of step S902 and the start of step S907.

[0222] Step S907: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to the source AMF / SEAF, which includes the UE's SUP I.

[0223] Step S908: If the source AMF / SEAF receives the Reauthentication Request message from the UDM while the UE is in the process of a mobility registration procedure, and the AMF / SEAF is about to change and the source AMF / SEAF receives the Reauthentication Request message from the UDM, the source AMF / SEAF may perform one of the following steps:

[0224] A. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing the error code TEMPORARY_REJECT_REGISTRATION_ONGOING indicating the cause of the failure.

[0225] B. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, which includes the error code REAUTHENTICATION_NOT_ALLOWED indicating the cause of the failure.

[0226] C. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing a cause value of 2 indicating that the UE is undergoing a mobility registration procedure and the AMF / SEAF is about to change.

[0227] Step S909: After receiving the Nudm_UECM_Re-AuthenticationNotification response message, the UDM performs subsequent processes according to the error indication information carried in the response message:

[0228] A. If the response message includes the second error indication information, i.e., the error code TEMPORARY_REJECT_REGISTRATION_ONGOING, the UDM starts a timer (e.g., 1 second) and resends the re-authentication request message as in step S907 according to the UE's latest AMF / SEAF registration information after the timer expires;

[0229] B. If the response message contains the third error indication information, that is, the error code REAUTHENTICATION_NOT_ALLOWED, the UDM does not need to perform other operations, that is, the UDM terminates the main authentication process for the UE. If the UDM subsequently receives a new AMF registration request, the UDM can determine whether to initiate a new main authentication process based on its own authentication policy;

[0230] C. If the response message contains the fourth error indication information, i.e., the cause value 2 indicating that "UE is performing a mobility registration procedure and the AMF / SEAF is about to change", the UDM determines the changed target AMF / SEAF and sends a re-authentication request message as in step S907 to the target AMF / SEAF after the current mobility registration procedure ends;

[0231] Step S910: The UDM sends a re-authentication request message as in step S907 to the target AMF / SEAF.

[0232] Step S911: If the target AMF / SEAF can perform the primary authentication process for the UE, the target AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, and confirms the re-authentication request sent by the UDM in the response message;

[0233] Step S912: The target AMF / SEAF starts the main authentication process.

[0234] Example 5

[0235] Embodiment 5 is a scenario in which the UE is performing a mobility registration process when the AMF receives the primary authentication message of the UDM, and the AMF changes in this scenario. As shown in Figure 10, the primary authentication method includes:

[0236] Step S1001: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0237] Step S1002: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides the UDM with a callback URI.

[0238] Step S1003: The NF (such as AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0239] Step S1004: The UDM determines whether to execute the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMFs / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0240] Step S1005: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0241] Step S1006: The UE starts the mobility registration process. Step S1006 can occur at any time between the end of step S1002 and the start of step S1007.

[0242] Step S1007: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to the target AMF / SEAF, which includes the UE's SUP I.

[0243] Step S1008: If the target AMF / SEAF receives the re-authentication request message sent by the UDM while the UE is performing a mobility registration procedure, the target AMF / SEAF replies with a Nudm_UECM_Re-AuthenticationNotification response message to the UDM and confirms the re-authentication request sent by the UDM in the response message;

[0244] Step S1009: The target AMF / SEAF starts the main authentication process.

[0245] Example 6

[0246] Example 6 is a scenario in which the UE is performing a handover process when the AMF receives the primary authentication message of the UDM. As shown in Figure 11, the primary authentication method includes:

[0247] Step S1101: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0248] Step S1102: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides a callback URL for the UDM.

[0249] Step S1103: The NF (eg, AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0250] Step S1104: The UDM determines whether to execute the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMF / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0251] Step S1105: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0252] Step S1106: The UE starts the handover process. Step S1106 may occur in any time period from the end of step S1102 to the start of step S1107.

[0253] Step S1107: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to AMF / SEAF, which includes the UE's SUP I.

[0254] Step S1108: If the UE is performing a handover procedure when the AMF / SEAF receives the re-authentication request message sent by the UDM, and regardless of whether the AMF / SEAF will change after the UE performs the handover procedure, the AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing the error code TEMPORARY_REJECT_HANDOVER_ONGOING indicating the cause of the failure, or containing other cause value 3 indicating that "UE is performing a handover procedure";

[0255] Step S1109: When the UDM receives the response message and the response message includes the error code TEMPORARY_REJECT_HANDOVER_ONGOING indicating the cause of the failure, or includes other cause value 3 indicating that "UE is in the process of handover", the UDM starts a timer (for example, 1 second) and resends the re-authentication request message as in step S1107 according to the UE's latest AMF / SEAF registration information after the timer expires;

[0256] Step S1110: AMF / SEAF starts the main authentication process.

[0257] Example 7

[0258] Embodiment 7 is a scenario in which the UE is performing a handover process when the AMF receives the primary authentication message of the UDM, and in this scenario, the AMF does not occur. As shown in Figure 12, the primary authentication method includes:

[0259] Step S1201: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0260] Step S1202: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides a callback URL for the UDM.

[0261] Step S1203: The NF (eg, AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0262] Step S1204: The UDM determines whether to execute the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMFs / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0263] Step S1205: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0264] Step S1206: The UE starts the handover process. Step S1206 may occur in any time period from the end of step S1202 to the start of step S1207.

[0265] Step S1207: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to AMF / SEAF, which includes the UE's SUP I.

[0266] Step S1208: If the UE is performing a handover procedure when the AMF / SEAF receives the re-authentication request message sent by the UDM, and the AMF / SEAF does not change after the UE performs the handover procedure, the AMF / SEAF replies with a Nudm_UECM_Re-AuthenticationNotification response message to the UDM, and confirms the re-authentication request sent by the UDM in the response message;

[0267] Step S1209: AMF / SEAF starts the main authentication process.

[0268] Example 8

[0269] Embodiment 8 is a scenario in which the UE is performing a handover process when the AMF receives the primary authentication message of the UDM, and in this scenario, the AMF occurs, as shown in Figure 13, and the primary authentication method includes:

[0270] Step S1301: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0271] Step S1302: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides a callback URL for the UDM.

[0272] Step S1303: The NF (eg, AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0273] Step S1304: The UDM determines whether to execute the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMFs / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0274] Step S1305: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0275] Step S1306: The UE starts the handover process. Step S1306 may occur in any time period from the end of step S1302 to the start of step S1307.

[0276] Step S1307: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to the source AMF / SEAF, which includes the UE's SUP I.

[0277] Step S1308: If the source AMF / SEAF receives the Reauthentication Request message from the UDM while the UE is in the process of a mobility registration procedure, and the AMF / SEAF is about to change and the source AMF / SEAF receives the Reauthentication Request message from the UDM, the source AMF / SEAF may perform one of the following steps:

[0278] A. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing the error code TEMPORARY_REJECT_HANDOVER_ONGOING indicating the cause of the failure.

[0279] B. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, which includes the error code REAUTHENTICATION_NOT_ALLOWED indicating the cause of the failure.

[0280] C. The source AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message containing a cause value of 4 indicating that the UE is undergoing a handover procedure and the AMF / SEAF is about to change.

[0281] Step S1309: After receiving the Nudm_UECM_Re-AuthenticationNotification response message, the UDM performs subsequent processes according to the error indication information carried in the response message:

[0282] A. If the response message contains the sixth error indication information, i.e., the error code TEMPORARY_REJECT_HANDOVER_ONGOING, the UDM starts a timer (e.g., 1 second) and resends the re-authentication request message as in step S1307 according to the UE's latest AMF / SEAF registration information after the timer expires;

[0283] B. If the response message contains the seventh error indication information, that is, the error code REAUTHENTICATION_NOT_ALLOWED, the UDM does not need to perform other operations, that is, the UDM terminates the main authentication process for the UE. If the UDM subsequently receives a new AMF registration request, the UDM can determine whether to initiate a new main authentication process based on its own authentication policy;

[0284] C. If the response message contains the eighth error indication information, i.e., the cause value 4 indicating that "UE is in the process of handover and the AMF / SEAF is about to change", the UDM determines the changed target AMF / SEAF and sends a re-authentication request message as in step S1307 to the target AMF / SEAF after the current handover process is completed;

[0285] Step S1310: The UDM sends a re-authentication request message as in step S1307 to the target AMF / SEAF.

[0286] Step S1311: If the target AMF / SEAF can perform the primary authentication process for the UE, the target AMF / SEAF replies to the UDM with a Nudm_UECM_Re-AuthenticationNotification response message, and confirms the re-authentication request sent by the UDM in the response message;

[0287] Step S1312: The target AMF / SEAF starts the main authentication process.

[0288] Example 9

[0289] Embodiment 9 is a scenario in which the UE is performing a handover process when the AMF receives the primary authentication message of the UDM, and in this scenario, the AMF occurs, as shown in Figure 14, and the primary authentication method includes:

[0290] Step S1401: UDM pre-configures the operator authentication policy to determine when to trigger the main authentication process;

[0291] Step S1402: The UE registers with the network. The AMF / SEAF registers the UE with the UDM through Nudm_UECM_registration and provides a callback URL for the UDM.

[0292] Step S1403: The NF (eg, AAnF) determines whether to send a Nudm_UECM_AuthTrigger request to the UDM according to the operator's local authentication policy, so as to use the UDM service for primary authentication. The Nudm_UECM_AuthTrigger request includes the UE's SUPI.

[0293] Step S1404: The UDM determines whether to execute the primary authentication process triggered by the home network based on an event (e.g., NF request) or its own authentication policy. If different AMF / SEAFs are registered in the UDM for different access modes, the UDM shall select one AMF / SEAF to perform the primary authentication. The criteria for selecting the AMF / SEAF depends on the UDM's own authentication policy.

[0294] Step S1405: If the UDM determines whether to perform the home network-triggered primary authentication process based on the NF request, the UDM responds with a Nudm_UECM_AuthTrigger response to the NF.

[0295] Step S1406: The UE starts the handover process. Step S1406 may occur in any time period from the end of step S1402 to the start of step S1407.

[0296] Step S1407: UDM sends a Nudm_UECM_Re-AuthenticationNotification message to the target AMF / SEAF, which includes the UE's SUP I.

[0297] Step S1408: If the target AMF / SEAF receives the re-authentication request message sent by the UDM while the UE is in the process of handover, the target AMF / SEAF replies with a Nudm_UECM_Re-AuthenticationNotification response message to the UDM and confirms the re-authentication request sent by the UDM in the response message;

[0298] Step S1409: The target AMF / SEAF starts the main authentication process.

[0299] The embodiment of the present application further provides an electronic device, as shown in FIG15 , wherein the electronic device 1400 includes:

[0300] one or more processors 1410;

[0301] The memory 1420 stores one or more programs. When the one or more programs are executed by the one or more processors 1410, the one or more processors 1410 implement a primary authentication method for the user equipment UE.

[0302] The memory 1420 is a non-transient network system that can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory 1420 may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory 1420 may include a memory 1420 remotely located relative to the processor 1410, and these remote memories 1420 may be connected to the processor 1410 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0303] The memory 1420 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1420 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1420 and is called by the processor 1410 to execute the methods of the embodiments of this application.

[0304] The processor 1410 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.

[0305] In some embodiments, the electronic device further comprises:

[0306] Input / output interface, used to realize information input and output;

[0307] Communication interface, used to realize communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, Wi-Fi, Bluetooth, etc.);

[0308] A bus that transmits information between various components of the device (e.g., the processor 1410, memory 1420, input / output interfaces, and communication interfaces);

[0309] The processor 1410 , the memory 1420 , the input / output interface, and the communication interface can be communicatively connected to each other within the device via a bus.

[0310] An embodiment of the present application further provides a computer-readable storage medium storing computer-executable instructions for executing:

[0311] A primary authentication method for a user equipment UE as applied to a first network element; or

[0312] For example, a primary authentication method for a user equipment UE applied to a second network element.

[0313] An embodiment of the present application further provides a computer program product, including a computer program or computer instructions, wherein the computer program or computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium, and the processor executes the computer program or computer instructions, so that the computer device performs the following operations:

[0314] A primary authentication method for a user equipment UE as applied to a first network element; or

[0315] For example, a primary authentication method for a user equipment UE applied to a second network element.

[0316] An embodiment of the present application provides a primary authentication method, electronic device, and storage medium for a user equipment UE. A first network element receives a re-master authentication request message sent by a second network element, where the re-master authentication request message carries a UE identifier. The first network element determines the UE based on the UE identifier and obtains the status of the UE. Then, the first network element determines corresponding response indication information based on the status of the UE and sends a re-master authentication response message to the second network element. The re-master authentication response message carries the response indication information. The second network element performs corresponding operations based on the response indication information. The operation of the second network element can be adapted to the current status of the UE, thereby achieving the purpose of improving the success rate of the UE's primary authentication process, thereby improving network service quality and user experience.

[0317] The system architecture and application scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those skilled in the art will appreciate that with the evolution of the system architecture and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are equally applicable to similar technical problems.

[0318] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0319] Those skilled in the art will appreciate that all or some of the steps and systems in the method disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, and the computer-readable medium can include computer storage media (or non-transitory media) and communication media (or temporary media). As known to those skilled in the art, the term computer storage media is included in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data) and is volatile and non-volatile, removable, and non-removable. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory, or other memory technology, CD-ROM, digital versatile disks (DVD), or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage, or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, as is well known to those skilled in the art, communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0320] The above description of some embodiments of the present application with reference to the accompanying drawings does not limit the scope of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present application shall be within the scope of the present application.

Claims

1. A primary authentication method for a user equipment UE, applied to a first network element, the method comprising: receiving a re-authentication request message sent by the second network element, where the re-authentication request message carries a UE identifier; Acquire the status of the corresponding UE according to the UE identifier; Determine response indication information according to the state of the UE; Send a re-authentication response message to the second network element, where the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information.

2. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: When the UE is in the state of performing a main authentication process, determining that the response indication information is confirmation request indication information; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Send a re-primary authentication response message to the second network element, where the re-primary authentication response message carries the confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

3. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: In a case where the UE is in a state of performing a mobility registration procedure, determining that the response indication information is first error indication information; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Send a re-authentication response message to the second network element, where the re-authentication response message carries the first error indication information, so that the second network element starts a timer according to the first error indication information, and resends the re-authentication request message according to the UE's latest first network element registration information after the timer expires.

4. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: When the UE is in a state of performing a mobility registration procedure and the first network element does not change during the mobility registration procedure, determining that the response indication information is confirmation request indication information; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Send a re-primary authentication response message to the second network element, where the re-primary authentication response message carries the confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

5. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: In a case where the status of the UE is that a mobility registration process is in progress and a first network element change event occurs in the mobility registration process, determining that the response indication information is second error indication information, third error indication information or fourth error indication information, wherein the first network element change event indicates that the UE switches access from a source first network element to a target first network element, and the first network element is the source first network element; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Sending a re-authentication response message to the second network element, where the re-authentication response message carries the second error indication information, so that the second network element starts a timer according to the second error indication information, and re-sends the re-authentication request message according to the latest first network element registration information of the UE after the timer expires; or, Sending a re-primary authentication response message to the second network element, where the re-primary authentication response message carries the third error indication information, so that the second network element terminates the primary authentication process for the UE according to the third error indication information; or, Send a re-authentication response message to the second network element, where the re-authentication response message carries the fourth error indication information, so that the second network element determines the target first network element according to the fourth error indication information, and sends the re-authentication response message to the target first network element after the mobility registration process is completed.

6. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: In a case where the UE is in a state of performing a mobility registration process and a first network element change event occurs in the mobility registration process, determining that the response indication information is confirmation request indication information, wherein the first network element change event indicates that the UE switches access from a source first network element to a target first network element, and the first network element is the target first network element; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Send a re-primary authentication response message to the second network element, where the re-primary authentication response message carries the confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

7. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: When the state of the UE is that a handover procedure is in progress, determining that the response indication information is fifth error indication information; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Send a re-authentication response message to the second network element, where the re-authentication response message carries the fifth error indication information, so that the second network element starts a timer according to the fifth error indication information, and resends the re-authentication request message according to the UE's latest first network element registration information after the timer expires.

8. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: When the UE is in a state of performing a handover procedure and the first network element does not change during the handover procedure, determining that the response indication information is confirmation request indication information; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Send a re-primary authentication response message to the second network element, where the re-primary authentication response message carries the confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

9. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: When the state of the UE is that a handover process is in progress and a first network element change event occurs in the handover process, determining that the response indication information is sixth error indication information, seventh error indication information or eighth error indication information, wherein the first network element change event indicates that the UE switches access from a source first network element to a target first network element, and the first network element is the source first network element; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Sending a re-authentication response message to the second network element, where the re-authentication response message carries the sixth error indication information, so that the second network element starts a timer according to the sixth error indication information, and re-sends the re-authentication request message according to the latest first network element registration information of the UE after the timer expires; or, Sending a re-master authentication response message to the second network element, where the re-master authentication response message carries the seventh error indication information, so that the second network element terminates the master authentication process for the UE according to the seventh error indication information; or, A re-authentication response message is sent to the second network element, where the re-authentication response message carries the eighth error indication information, so that the second network element determines the target first network element according to the eighth error indication information, and sends the re-authentication response message to the target first network element after the switching process is completed.

10. The method according to claim 1, wherein: The determining the response indication information according to the state of the UE includes: In a case where the UE is in a state of performing a handover procedure and a first network element change event occurs in the handover procedure, determining that the response indication information is confirmation request indication information, wherein the first network element change event indicates that the UE switches access from a source first network element to a target first network element, and the first network element is the target first network element; The sending a re-authentication response message to the second network element, wherein the re-authentication response message carries the response indication information, so that the second network element performs a corresponding operation according to the response indication information, includes: Send a re-primary authentication response message to the second network element, where the re-primary authentication response message carries the confirmation request indication information, so that the second network element performs the primary authentication process of the UE according to the confirmation request indication information.

11. The method according to any one of claims 1 to 10, wherein: The first network element is an access and mobility management function AMF network element or a security anchor function SEAF network element, and the second network element is a unified data management UDM network element.

12. A primary authentication method for a user equipment UE, applied to a second network element, the method comprising: Sending a re-authentication request message to the first network element, where the re-authentication request message carries a UE identifier, so that the first network element obtains the status of the corresponding UE according to the UE identifier, and determines response indication information according to the status of the UE; receiving a re-authentication response message sent by the first network element, wherein the re-authentication response message carries the confirmation response indication information; Perform corresponding operations according to the response indication information.

13. The method according to claim 12, wherein: The performing corresponding operations according to the response indication information includes: In a case where the response indication information is confirmation request indication information, a main authentication process of the UE is executed.

14. The method according to claim 12, wherein: The performing corresponding operations according to the response indication information includes: When the response indication information is any one of the first error indication information, the second error indication information, the fifth error indication information or the sixth error indication information, a timer is started, and after the timer times out, the re-authentication request message is resent according to the latest first network element registration information of the UE; wherein, The first error indication information indicates that the state of the UE is that a mobility registration process is in progress; The second error indication information indicates that the status of the UE is that a mobility registration procedure is in progress, and a first network element change event occurs in the mobility registration procedure; The fifth error indication information indicates that the state of the UE is that a handover procedure is in progress; The sixth error indication information indicates that the UE is in a state of performing a handover procedure and that a first network element change event occurs during the handover procedure.

15. The method according to claim 12, wherein: The performing corresponding operations according to the response indication information includes: When the response indication information is the third error indication information or the seventh error indication information, the main authentication process for the UE is terminated; wherein, The third error indication information indicates that the status of the UE is that a mobility registration procedure is in progress, and a first network element change event occurs in the mobility registration procedure; The seventh error indication information indicates that the UE is in a state of performing a handover procedure and that a first network element change event occurs during the handover procedure.

16. The method according to claim 12, wherein: The performing corresponding operations according to the response indication information includes: In the case where the response indication information is the fourth error indication information or the eighth error indication information, determining the target first network element, and sending the re-authentication response message to the target first network element after the UE ends the mobility registration process or the switching process; wherein, The fourth error indication information indicates that the status of the UE is that a mobility registration procedure is in progress, and a first network element change event occurs in the mobility registration procedure; The eighth error indication information indicates that the UE is in a state of performing a handover procedure and that a first network element change event occurs during the handover procedure.

17. The method according to any one of claims 12 to 16, wherein: The first network element is an access and mobility management function AMF network element or a security anchor function SEAF network element, and the second network element is a unified data management UDM network element.

18. An electronic device, comprising: one or more processors; A memory having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement: The primary authentication method for a user equipment UE as claimed in any one of claims 1 to 11; or, A primary authentication method for a user equipment UE as described in any one of claims 12 to 17.

19. A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the computer program implements: The primary authentication method for a user equipment UE as claimed in any one of claims 1 to 11; or, A primary authentication method for a user equipment UE as described in any one of claims 12 to 17.

Citation Information

Patent Citations

  • Slice authentication method and device

    CN116193431A

  • Method and apparatus for service process for user equipment

    WO2021185316A1

  • Authentication method, method for sending information, processing method, and communication apparatus

    WO2023165407A1