Communication method and related apparatus
By configuring the subnet selection list and access network equipment broadcast subnet identification information on the terminal device, the problem of users of different operators accessing the same subnet is solved, and the service needs of subnet users are met and user experience is improved.
Patent Information
- Application Number
- PCT/CN2024/135071
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-04
- Filing Date
- 2024-11-27
- Publication Date
- 2025-06-12
AI Technical Summary
The prior art is difficult to enable subnet users belonging to different network operators to access the same subnet and cannot meet the business needs of subnet users.
By configuring the subnet selection list and access network device broadcast subnet identification information on the terminal device, the terminal device selects the subnet based on the selection list and broadcast information, and requests access from the access network device, thereby realizing subnet access to different operator users.
It enables subnet users belonging to different operators to access the same subnet, meet users' business needs and improve user experience.
Smart Images

Figure CN2024135071_12062025_PF_FP_ABST
Abstract
Description
Communication method and related device
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on December 4, 2023, with application number 202311654012.1 and application name “Communication Methods and Related Devices”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the field of communication technology, and in particular to a communication method and related devices. Background Art
[0003] In different locations, such as enterprises, campuses, and stadiums, users have different service requirements for communication networks. To improve user experience, dedicated networks can be deployed for different locations. Dedicated networks, also known as subnets, can provide better services for users. However, subnets only support access by subscribers of the operator that deployed them. How to connect users from different operators to the same subnet becomes a new technical challenge. Summary of the Invention
[0004] The embodiments of the present application provide a communication method and related devices, which aim to enable subnet users belonging to different network operators to access the same subnet in a scenario, thereby meeting the business needs of the subnet users.
[0005] In a first aspect, an embodiment of the present application provides a communication method, applied to a first terminal device, the method comprising:
[0006] Receive identification information of a first network from an access network device, and the access network device supports accessing a terminal device to the first network; when the first list of the first terminal device includes the identification information of the first network, send a first request message and the identification information of the first network to the access network device, the first request message is used to request access of the first terminal device to the first network, and the first list includes identification information of one or more non-public land mobile networks (PLMNs).
[0007] When the first terminal device selects a subnet based on the first list and the broadcast subnet identification information, there is no need to consider the PLMN ID configured in the user identification module SIM card loaded on the first terminal device and the PLMN ID broadcast by the access network. Even if the first terminal device and the access network device belong to different operators, the first terminal device can still initiate a request to the access network device to access the subnet.
[0008] In some implementations, the first terminal device includes a first logical interface, the first logical interface is used to access a non-PLMN network, and the first logical interface is configured with a first list.
[0009] When the first list of the first terminal device includes identification information of the first network, sending the first request message and the identification information of the first network to the access network device includes:
[0010] When the first logical interface is in an open state and the first list includes identification information of the first network, a first request message and the identification information of the first network are sent to the access network device.
[0011] Configuring the first list on the first logical interface used to access the first network can reduce the association between the first list and the subscriber identification module. The first terminal device includes a switch for controlling the first logical interface on or off. Turning this switch on and off can prevent the first terminal device from performing a network search when unable to access a subnet, thereby avoiding unnecessary energy consumption and saving energy for the first terminal device.
[0012] In some implementations, the method further includes:
[0013] Receive identification information of a third network from an access network device, the first list including the identification information of the third network; when the first list of the first terminal device includes the identification information of the first network, send a first request message and the identification information of the first network to the access network device, including: when the first list includes the identification information of the first network and the priority of the first network is higher than the priority of the third network, send the first request message and the identification information of the first network to the access network device.
[0014] According to the network priorities in the first list, a first network with a higher priority is selected as the network to be accessed, so that the network with the highest matching degree can be selected for the first terminal device.
[0015] In some implementations, the first request message includes a first identifier and / or a second identifier, the first identifier is an identifier of the first terminal device in the first network, the second identifier is an identifier of the terminal device in the second network, and the second network is a PLMN network.
[0016] In some implementations, the first terminal device includes a second logical interface, the second logical interface is used to access the second network, and the second identifier is associated with the second logical interface.
[0017] The first request message includes the second identifier, including:
[0018] When the first logical interface is associated with the second logical interface, or the first network is associated with the second logical interface, the first request message includes the second identifier.
[0019] In some implementations, the method further includes:
[0020] Send a first identifier and / or a second identifier, where the first identifier is the identifier of the first terminal device in the first network, and the second identifier is the identifier of the first terminal device in the second network, where the second network is a PLMN network.
[0021] In some implementations, before sending the first identifier and / or the second identifier, the method further includes:
[0022] Receive first information, where the first information is used to request an identification of the first terminal device in the first network; and / or receive second information, where the second information is used to request an identification of the first terminal device in the second network.
[0023] In some implementations, the first terminal device includes a second logical interface, the second logical interface is used to access the second network, and the second identifier is associated with the second logical interface.
[0024] Sending a second identifier includes:
[0025] In a case where the first logical interface is associated with the second logical interface, or the first network is associated with the second logical interface, the second identifier is sent.
[0026] When the first logical interface is associated with the second logical interface, or the first network is associated with the second logical interface, the second identifier may be determined through the second logical interface.
[0027] In some implementations, the method further includes:
[0028] First indication information is obtained, where the first indication information is used to indicate that the first logical interface is associated with the second logical interface, or the first indication information is used to indicate that the first network is associated with the second logical interface.
[0029] In some implementations, the first request message also includes third information, and the third information is used to indicate the network slice and / or logical network to which the first terminal device in the first network requests access.
[0030] The method also includes:
[0031] Receive fourth information, where the fourth information is used to indicate the network slices and / or logical networks that the first terminal device in the first network is allowed to access.
[0032] In some implementations, the method further includes:
[0033] A first session request message is sent, where the first session request message is used to request establishment of a session between the first terminal device and a user plane network element in the first network.
[0034] In some implementations, the first session request message includes an identifier of a network slice and / or logical network, where the network slice and / or logical network is the network slice and / or logical network to which the first terminal device in the first network requests access.
[0035] In some implementations, the first request message is further used to request access to a first service of a public land mobile network (PLMN) through the first network.
[0036] The method further includes:
[0037] Receive fifth information, the fifth information is used to indicate whether the first terminal device is allowed to access the first service of the PLMN through the first network; when the fifth information is used to indicate that the first terminal device is allowed to access the first service of the PLMN through the first network, the first session request message also includes information for indicating the first service.
[0038] Accessing the PLMN service through the first network can enable the single-mode terminal device to access the PLMN and the subnet at the same time, or access the PLMN service when there is no PLMN access network device at the current location.
[0039] In a second aspect, an embodiment of the present application provides a communication method, applied to a mobility management network element, the method comprising:
[0040] Receive a first request message from an access network device and identification information of a first network, where the first request message is used to request that the first terminal device be registered to the first network. The first network is a non-PLMN network, and the access network device and the mobility management network element support accessing the terminal device to the first network. According to the identification information of the first network, send a second request message to a control plane network element in the first network, where the second request message is used to request that the first terminal device be accessed to the first network. Receive a first response message from the control plane network element, where the first response message is used to indicate whether the first terminal device is allowed to access the first network.
[0041] In some implementations, sending the second request message to a control plane network element in the first network includes:
[0042] If the authentication for the first terminal device is successful, a second request message is sent to the control plane network element. The authentication for the first terminal device is based on a second identifier, which is the identifier of the first terminal device in the second network, and the second network is a PLMN network.
[0043] Performing SIM authentication on the first terminal device can improve the security of the first terminal device during access to the subnet.
[0044] In some implementations, the first request message includes the second identifier; or, the method further includes: sending a message for requesting an identifier of the first terminal device in the second network; and receiving the second identifier.
[0045] In some implementations, when authentication of the first terminal device is successful, sending the second request message to the control plane network element includes:
[0046] When the authentication of the first terminal device is successful, a first identifier is obtained, where the first identifier is the identifier of the first terminal device in the first network and the first identifier is the external identifier of the first terminal device; a second request message is sent to the control plane network element, where the second request message includes the first identifier.
[0047] In some implementations, the first request message includes a first identifier, which is an identifier of the first terminal device in the first network and an external identifier of the first terminal device.
[0048] Sending a second request message to a control plane network element in the first network includes:
[0049] If the verification of the first identifier is successful, a second request message is sent to the control plane network element.
[0050] In some implementations, the second request message includes at least one of the following: the first identifier, or information indicating that verification of the first identifier is successful.
[0051] In some implementations, before sending the second request message to the control plane network element, the method further includes:
[0052] A message for requesting an external identifier of a first terminal device is sent to a core network element in a second network, where the core network element in the second network is used to manage external identifiers of terminal devices belonging to the second network, and the second network is a network deployed by the operator to which the first terminal device belongs; the external identifier of the first terminal device is received from the core network element; verification of the first identifier is successful, including: the external identifier of the first terminal device from the core network element includes the first identifier.
[0053] In some implementations, before sending the second request message to the control plane network element, the method further includes:
[0054] Sending a message requesting verification of the first identifier to a core network element in a second network, where the core network element in the second network is used to manage the external identifier of the terminal device belonging to the second network, and the second network is a network deployed by the home operator of the first terminal device; receiving a second response message from the core network element, where the second response message is used to indicate the result of the verification of the first identifier; the verification of the first identifier is successful, including: the second response message is used to indicate the verification of the first identifier is successful.
[0055] When the first identifier is an external identifier of the first terminal device, verifying the legitimacy of the first identifier can improve the security of the first terminal device during access to the subnet.
[0056] In some implementations, the method further includes:
[0057] A first session request message is received from a first terminal device, where the first session request message is used to request establishment of a session between the first terminal device and a first user plane network element of a first network.
[0058] In some implementations, the method further includes:
[0059] According to the first session request message, a message is triggered that the second user plane network element allocates uplink tunnel information and downlink tunnel information for the session, and an interface exists between the second user plane network element and the access network device; first uplink tunnel information and first downlink tunnel information are received from the second user plane network element, where the first uplink tunnel information is used to send uplink data of the session to the second user plane network element, and the first downlink tunnel information is used to send downlink data of the session to the second user plane network element; a second session request message is sent to the control plane network element, where the second session request message is used to request establishment of a session between the first terminal device and the first user plane network element, and the second session request message includes the first downlink tunnel information; second uplink tunnel information is received from the control plane network element, where the second uplink tunnel information is used to send uplink data of the session to the first user plane network element; and the first uplink tunnel information is sent to the access network device.
[0060] In some implementations, the second request message includes a first terminal identifier, where the first terminal identifier is used to indicate the first terminal device in the mobility management network element.
[0061] In some implementations, the first response message includes a second terminal identifier, and the second terminal identifier is used to indicate the first terminal device in the control plane network element.
[0062] In some implementations, a downlink non-access stratum NAS message and a first terminal identifier are received from a control plane network element, and a downlink NAS message is sent to the first terminal device based on the first terminal identifier; and / or an uplink NAS message is received from the first terminal device, and an uplink NAS message and a second terminal identifier are sent to the control plane network element.
[0063] By indicating the first terminal device in different network elements through the first terminal identifier and the second terminal identifier, it is possible to prevent the first terminal device from leaking privacy information during the process of accessing the subnet.
[0064] In a third aspect, an embodiment of the present application provides a communication method, applied to a control plane network element in a first network, the method comprising:
[0065] Receive a second request message from a mobility management network element, where the second request message is used to request that the first terminal device be connected to the first network, and the mobility management network element supports connecting the terminal device to the first network; determine whether the first terminal device is allowed to access the first network based on the contract information of the first terminal device in the first network; and send a first response message to the mobility management network element, where the first response message is used to indicate whether the first terminal device is allowed to access the first network.
[0066] By authorizing and authenticating whether the first terminal device can access the first network through the control plane network element in the first network, the privacy of the contracted users in the first network can be protected, the management convenience of the contracted users in the first network can be improved, and interference between data in different subnets can be avoided.
[0067] In some implementations, the second request message is also used to request access to a first service of a public land mobile network PLMN through a first network, and the subscription information of the first terminal device in the first network includes second indication information, and the second indication information is used to indicate whether the first terminal device is allowed to access the PLMN service through the first network.
[0068] The method further includes:
[0069] Determine whether to allow the first terminal device to access the first service of the PLMN through the first network based on the second request message and the second indication information.
[0070] In some implementations, the first response message further includes third information, where the third information is used to indicate whether the first terminal device is allowed to access the first service of the PLMN through the first network.
[0071] In some implementations, before determining whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network, the method further includes:
[0072] The subscription information of the first terminal device in the first network is obtained based on the first identifier, where the first identifier is the identifier of the first terminal device in the first network.
[0073] In some implementations, the second request message includes the first identifier; or, the method further includes: sending a message for requesting an identifier of the first terminal device in the first network; and receiving the first identifier.
[0074] In some implementations, the first identifier is an external identifier of the first terminal device.
[0075] Acquiring subscription information of the first terminal device in the first network based on the first identifier includes:
[0076] When the verification of the first identifier is successful, the subscription information of the first terminal device in the first network is obtained based on the first identifier.
[0077] In some implementations, the verification of the first identifier is successful, including: the second request message further including information indicating that the verification of the first identifier is successful.
[0078] In some implementations, before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the method further includes:
[0079] A message for requesting an external identifier of a first terminal device is sent to a core network element in a second network, where the core network element in the second network is used to manage external identifiers of terminal devices belonging to the second network, and the second network is a network deployed by the operator to which the first terminal device belongs; the external identifier of the first terminal device is received from the core network element; verification of the first identifier is successful, including: the external identifier of the first terminal device from the core network element includes the first identifier.
[0080] In some implementations, before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the method includes:
[0081] Sending a message requesting verification of the first subscription identifier to a core network element in a second network, where the core network element in the second network is used to manage the external identifier of the terminal device belonging to the second network, and the second network is a network deployed by the home operator of the first terminal device; receiving a third response message from the core network element, where the third response message is used to indicate the result of the verification of the first identifier; the verification of the first identifier is successful, including: the third response message is used to indicate the verification of the first identifier is successful.
[0082] In some implementations, before the verification of the first identifier is successful, the method further includes:
[0083] The first terminal device is authenticated based on the second identifier, where the second identifier is the identifier of the first terminal device in the second network, and the second network is a network deployed by the home operator of the first terminal device.
[0084] In some implementations, authenticating the first terminal device based on the second identifier includes:
[0085] Obtain the second identifier of the first terminal device; send a first authentication request message to the core network element in the second network, the core network element in the second network is used to authenticate the terminal device belonging to the second network, the first authentication request message is used to request authentication of the first terminal device, and the first authentication request message includes the second identifier. Receive a first authentication response message from the core network element, the first authentication response message includes the first authentication information of the first terminal device; send a second authentication request message to the first terminal device according to the first authentication information; receive a second authentication response message from the first terminal device, the second authentication response message includes the second authentication information of the first terminal device; if the first authentication information contains verification information, authenticate the first terminal device based on the first authentication information verification information and the second authentication information;. Alternatively, send a third authentication request message to the core network element, the third authentication request message carries the second authentication information; receive a third authentication response message from the core network element, the third authentication response message is used to indicate the authentication result of the first terminal device
[0086] When there is no roaming agreement between the home operator of the mobility management network element and the home operator of the first terminal device, the control plane network element in the first network can request the home operator of the first terminal device to perform SIM authentication through the capability exposure interface.
[0087] In some implementations, obtaining the second identifier of the first terminal device includes: obtaining the second identifier from a second request message; or sending a message for requesting the identifier of the first terminal device in the second network; and receiving the second identifier.
[0088] In some implementations, before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the method further includes: authenticating the first terminal device using the first identifier.
[0089] In some implementations, using a first contract identifier to authenticate the first terminal device for access to the first network includes: when a preset condition is met, using the first contract identifier to authenticate the first terminal device, the preset condition includes at least one of the following conditions: the contract information of the first terminal device in the first network requires the use of the first identifier to authenticate the access of the first terminal device, the second request message does not include the verified first identifier, the first identifier is a private identifier in the first network, or the control plane network element requires the use of the first identifier to authenticate the terminal device accessing the first network.
[0090] In some implementations, the second request message also includes fifth information, which is used to indicate the location of the first terminal device. The contract information of the first terminal device in the first network includes third indication information, and the third indication information is used to indicate the area of the first network to which the first terminal device is allowed to access.
[0091] The step of determining whether to allow the first terminal device to access the first network according to the subscription information of the first terminal device in the first network includes:
[0092] When the location of the first terminal device belongs to the area indicated by the third indication information, it is determined that the first terminal device is allowed to access the first network.
[0093] In some implementations, the second request message also includes first information, the first information is used to indicate the network slice and / or logical network that the first terminal device in the first network requests to access, and the subscription information of the first terminal device in the first network includes fourth indication information, and the fourth indication information is used to indicate the network slice and / or logical network that the first terminal device in the first network is allowed to access.
[0094] The step of determining whether to allow the first terminal device to access the first network according to the subscription information of the first terminal device in the first network includes:
[0095] When the network slice and / or logical network requested for access in the first information is included in the network slice and / or logical network indicated by the fourth indication information as allowed for access, the network slice and / or logical network allowed for access by the first terminal device in the first network is determined.
[0096] In some implementations, the first response message also includes second information, where the second information is used to indicate the network slices and / or logical networks that the first terminal device in the first network is allowed to access.
[0097] In some implementations, the first response message includes a second terminal identifier, and the second terminal identifier is used to indicate the first terminal device in the control plane network element.
[0098] In some implementations, the method further includes:
[0099] Receive a second session request message from a mobility management network element, where the second session request message is used to request establishment of a session between a first terminal device and a first user plane network element of a first network, and the second session request message includes first downlink tunnel information, where the first downlink tunnel information is used to send downlink data of the session to a second user plane network element in a third network, where the third network is a network deployed by the home operator of the mobility management network element; send a third session request message to the first user plane network element based on the session subscription information of the first terminal device in the first network, where the third session request message is used to request the first user plane network element to allocate second uplink tunnel information for the session; receive second uplink tunnel information from the first user plane network element, where the second uplink tunnel information is used to send uplink data of the session to the first user plane network element; send a session response message to the mobility management network element, where the session response message is used to indicate session establishment, and the session response message includes the second uplink tunnel information.
[0100] In some implementations, the second session request message also includes sixth information, which is used to indicate the identifier of the network slice and / or logical network that the first terminal device in the first network requests to access, and the session subscription information of the first terminal device in the first network includes fifth indication information, which is used to indicate the network slice and / or logical network that the first terminal device in the first network is allowed to access.
[0101] Sending a third session request message to the first user plane network element according to the session subscription information of the first terminal device in the first network includes:
[0102] When the network slice and / or logical network requested for access in the sixth information is included in the network slice and / or logical network allowed for access indicated by the fifth indication information, a third session request message is sent to the first user plane network element.
[0103] In some implementations, the second session request message further includes information for instructing the first user plane network element to filter non-allowed data packets.
[0104] By configuring corresponding access rules, the access of the first terminal device to services in the first network can be controlled, thereby improving the controllability of the first terminal device when accessing the first network.
[0105] In some implementations, the second session request message further includes the first identifier or the second terminal identifier.
[0106] Before sending the third session request message to the first user plane network element according to the session subscription information of the first terminal device in the first network, the method further includes:
[0107] The session subscription information of the first terminal device in the first network is obtained based on the first identifier or the second terminal identifier.
[0108] In some implementations, the third session request message further includes information indicating that the first terminal device is allowed to access the first service of the PLMN.
[0109] In some implementations, the method further includes:
[0110] A third session request message is sent to the third user plane network element, where the third session request message is used to request the third user plane network element to allocate uplink tunnel information. The third session request message carries the service information of the first PLMN and the downlink tunnel information allocated by the first user plane network element. The third user plane network element belongs to the first PLMN.
[0111] In a fourth aspect, an embodiment of the present application provides a communication method, applied to an access network device, the method comprising:
[0112] Receive a first message from a first terminal device, trigger the establishment of a first connection based on the first message, the first connection is a connection between the first terminal device and a first mobility management network element; send a first connection identifier to the first terminal device, the first connection identifier is used to indicate the first connection.
[0113] Through the first connection identifier, the first terminal device can determine the corresponding first mobility management network element when performing NAS information interaction subsequently.
[0114] In some implementations, the first message includes sixth indication information, and the sixth indication information is used to indicate establishment of a connection between the first terminal device and the first mobility management network element.
[0115] Triggering establishment of the first connection according to the first message includes: triggering establishment of the first connection according to sixth indication information.
[0116] In some implementations, triggering establishment of the first connection according to the first message includes:
[0117] When the first message does not include the first connection identifier, establishment of the first connection is triggered.
[0118] In some implementations, triggering establishment of the first connection according to the first message includes:
[0119] When the first message includes the first connection identifier and the access network device does not save the correspondence between the first terminal device and the first connection identifier, establishment of the first connection is triggered.
[0120] In some implementations, the method further includes: allocating a first connection identifier to the first connection; and sending the first connection identifier to the first terminal device.
[0121] In some implementations, the method further includes:
[0122] Save the correspondence between the first terminal device and the first connection identifier.
[0123] In some implementations, the first message further includes information indicating the first network.
[0124] The method further includes:
[0125] A first mobility management network element is selected according to the first message, and the first mobility management network element supports access of the terminal device to the first network.
[0126] In some implementations, the first message further includes a first NAS message, and the first NAS message is an access request message or a service request message.
[0127] In some implementations, the first connection is used to forward messages between the first terminal device and the first network.
[0128] The method further includes:
[0129] Receive a second message from the first terminal device, trigger the establishment of a second connection according to the second message, the second connection is a connection between the first terminal device and the second mobility management network element, the second connection is used to forward messages between the first terminal device and the second network, the second network and the first network are different networks; send a second connection identifier to the first terminal device, the second connection identifier is used to indicate the second connection.
[0130] The first terminal device accesses different subnets and the main network through different mobile management network elements respectively, which can realize the decoupling of subnet access and main network access, avoid sharing mobile management network elements, and enhance the isolation between subnet access and main network access.
[0131] In some implementations, before receiving the first message from the first terminal device and receiving the second message from the first terminal device, the method further includes:
[0132] Establish a third connection between the first terminal device and the access network device; receive a first message from the first terminal device, including: receiving the first message from the first terminal device through the third connection; receive a second message from the first terminal device, including: receiving the second message from the first terminal device through the third connection.
[0133] In some implementations, the second message further includes a second NAS message, and the second NAS message is an access request message or a service request message.
[0134] In some implementations, the first connection is associated with at least one first user plane link, and the second connection is associated with at least one second user plane link, the first user plane link is used to transmit user plane data between the first terminal device and the first network, and the second user plane link is used to transmit user plane data between the first terminal device and the second network.
[0135] The method also includes:
[0136] In a case where there is no data transmission on at least one first user plane link and no data transmission on at least one second user plane link, the third connection is released.
[0137] Initiating the first terminal device to enter the idle state when there is no data to be sent can release the air interface and save energy for the first terminal device.
[0138] In a fifth aspect, an embodiment of the present application provides a communication method, applied to a first terminal device, comprising:
[0139] A first message is sent to the access network device, where the first message is used to trigger the establishment of a first connection, where the first connection is a connection between the first terminal device and the first mobility management network element; and a first connection identifier is received from the access network device, where the first connection identifier is used to indicate the first connection.
[0140] In some implementations, the first message includes sixth indication information, and the sixth indication information is used to indicate establishment of a connection between the first terminal device and the first mobility management network element.
[0141] In some implementations, sending the first message to the access network device includes:
[0142] Allocate a first connection identifier for the first connection; send a first message to the access network device, the first message including the first connection identifier
[0143] In some implementations, the first message also includes information for indicating the first network, and the first mobility management network element supports access of the terminal device to the first network.
[0144] In some implementations, the first message further includes a second NAS message, and the second NAS message is a registration request message or a service request message.
[0145] In some implementations, the first connection is used to forward messages between the first terminal device and the first network.
[0146] The method further includes:
[0147] A second message is sent to the access network device, where the second message is used to trigger the establishment of a second connection. The second connection is a connection between the first terminal device and the second mobility management network element. The second connection is used to forward messages between the first terminal device and the second network, where the second network and the first network are different networks. A second connection identifier is received from the access network device, where the second connection identifier is used to indicate the second connection.
[0148] In some implementations, sending the first message to the access network device includes:
[0149] Sending a first message to the access network device through a third connection, where the third connection is a connection between the first terminal device and the access network device; sending a second message to the access network device includes: sending the second message to the access network device through the third connection.
[0150] In a sixth aspect, an embodiment of the present application provides a communication device, the communication device including various functional modules for implementing any of the communication methods mentioned in the above implementations. Optionally, each module can be implemented in software and / or hardware.
[0151] In a seventh aspect, an embodiment of the present application provides a communication device, comprising a processor coupled to a memory and configured to execute instructions in the memory to implement any of the communication methods described in the above implementations. Optionally, the device further comprises a memory. Optionally, the device further comprises a communication interface, the processor coupled to the communication interface.
[0152] In an eighth aspect, an embodiment of the present application provides a computer-readable medium, which stores program code for execution by a device, and the program code includes a method for executing any one of the communication methods mentioned in the above implementation manner.
[0153] In a ninth aspect, an embodiment of the present application provides a computer program product, including a computer program, which implements any one of the communication methods mentioned in the above implementation methods when the computer program is executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS
[0154] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0155] FIG1 is a schematic diagram of a network architecture 100 provided in one embodiment of the present application;
[0156] FIG2 is a flow chart of a communication method provided by an embodiment of the present application;
[0157] FIG3 is a flow chart of a communication method provided in one embodiment of the present application;
[0158] FIG4 is a flow chart of a communication method provided by one embodiment of the present application;
[0159] FIG5 is a schematic diagram of a process of requesting an AUSF / UDM network element to perform identity authentication through a subnet control plane network element according to an embodiment of the present application;
[0160] FIG6 is a schematic diagram of a process of requesting an AUSF / UDM network element to perform identity authentication through a subnet control plane network element according to another embodiment of the present application;
[0161] FIG7 is a schematic diagram of a process for a terminal device to simultaneously access a subnet and a large network according to an embodiment of the present application;
[0162] FIG8 is a schematic diagram of a terminal device protocol stack provided by one embodiment of the present application;
[0163] FIG9 is a schematic diagram of a process for separately accessing a terminal device to a subnet and a large network according to an embodiment of the present application;
[0164] FIG10 is a schematic structural diagram of a communication device provided in one embodiment of the present application;
[0165] FIG11 is a schematic structural diagram of a communication device provided in another embodiment of the present application.
[0166] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0167] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0168] The technical solutions provided in the embodiments of the present application can be applied to various communication systems, such as new radio (NR) systems, long term evolution (LTE) systems, frequency division duplex (FDD) systems, time division duplex (TDD) systems, etc. The technical solutions provided in the embodiments of the present application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0169] In the above-mentioned communication system, the part operated by the operator can be called a public land mobile network (PLMN), which is used to provide land mobile communication services. Among them, PLMN can also be called an operator network, a large network, a public network, etc., and the operator operating the PLMN can be called a large network operator. The PLMN described in the embodiments of the present application can specifically be a network that meets the requirements of the third generation partnership project (3GPP) standards, referred to as a 3GPP network. The 3GPP network includes but is not limited to the fifth generation (5G) mobile communication network, the fourth generation (4G) mobile communication network, and other future communication networks, such as the sixth generation (6G) mobile communication network.
[0170] As 3GPP networks evolve from being oriented towards businesses (2B) to being oriented towards consumers (2C), a series of emerging technologies have emerged to support the deployment of networks within designated location areas (such as enterprises, campuses, shopping malls, parks, etc.), providing customized services to users within the area, and realizing the continuous expansion of 3GPP network application scenarios. Among them, the network serving users within the designated location area can be called a sub-network, the designated area can be called a sub-network location, users who access the subnet within the sub-network location can be called sub-network users, the owner or manager of the sub-network location can be called a sub-network tenant, the services provided by the sub-network to the sub-network users can be called sub-network services, and the operator who deploys the sub-network can be called a sub-network operator. The sub-network can also be called a private network, a dedicated network, etc., which is not limited in the embodiments of the present application.
[0171] The subnet operator and the main network operator can be the same or different. For example, a subnet tenant can directly entrust the main network operator to deploy the subnet. In this case, the main network operator is also the subnet operator for the corresponding subnet. A subnet tenant can also entrust a third-party operator to deploy the subnet. In this case, the subnet operator and the main network operator are different network operators.
[0172] In existing technologies, large network operators can deploy subnets using technologies such as slicing, multi-access edge computing (MEC), and local area data networks (LADN). However, only the contracted users of the large network operators can access the subnet through the access network equipment deployed by the large network operators, and users belonging to other operators cannot access the subnet. Large network operators can also use stand-alone non-public network (SNPN) technology to deploy subnets, but only dedicated terminal devices for the subnet, such as terminal devices that include the subnet's subscriber identity module (SIM) card, or terminal devices that can receive signals in a specific frequency band in the subnet, can access the subnet, which limits the application scope of the subnet.
[0173] To solve the above technical problems, the embodiments of the present application provide a communication method and related devices, which aim to enable subnet users belonging to different network operators to access the same subnet and meet the business needs of subnet users.
[0174] In an embodiment of the present application, a subnet selection list containing subnet identification information is configured on a terminal device, and the access network device broadcasts the identification information of the subnets it supports. The terminal device selects a subnet based on the subnet selection list and the broadcast subnet identification information, and requests access to the selected subnet from the access network device, thereby enabling subnet users belonging to different operators to access the same subnet.
[0175] Figure 1 is a schematic diagram of a network architecture 100 provided by one embodiment of the present application. As shown in Figure 1, network architecture 100 includes a terminal, access network equipment, PLMN 1 deployed by a large network operator (OP) 1, PLMN 2 deployed by a large network operator OP 2, and subnets deployed by subnet operators.
[0176] Among them, the terminal can also be called terminal equipment, user equipment (UE), mobile station (MS), mobile terminal (MT), etc., which can be an entity on the user side for receiving or transmitting signals, such as a mobile phone. The terminal device includes a handheld device, a vehicle-mounted device, a wearable device or a computing device with wireless communication function. Exemplarily, the terminal device can be a mobile phone, a tablet computer or a computer with wireless transceiver function. The terminal device can also be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. In the embodiment of the present application, the device for realizing the function of the terminal can be a terminal; it can also be a device that can support the terminal to realize the function, such as a chip system, a communication module, or a modem, etc., which can be installed in the terminal. In the embodiment of the present application, the chip system can be composed of a chip, or it can include a chip and other discrete devices. The embodiments of the present application do not limit the specific technology and specific device form adopted by the terminal device.
[0177] The access network equipment is deployed by operator OP 1 and is located within the subnet site. Its signal can cover the subnet site. Access network equipment includes but is not limited to: the next-generation base station (gNB) in 5G, evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved node B, or home node B, HNB), base band unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, etc.
[0178] Terminal devices can access the subnet through the access network equipment deployed by OP 1. Therefore, the access network equipment deployed by OP 1 can also be called the subnet access network equipment. Terminal devices can also access PLMN 1 deployed by OP 1 through this access network equipment. That is, the subnet and PLMN 1 deployed by OP 1 share this access network equipment.
[0179] PLMN 1 may include one or more of the following core network elements: a global mobility management (G-MM) element, a global session management (G-SM) element, and a global user plane function (G-UPF) element. PLMN 1 may include dedicated core network elements that provide services only to the subnet shown in Figure 1, or it may include shared core network elements that provide services to other subnets or even to the broader network services of OP 1.
[0180] Among them, the G-MM network element is mainly responsible for the access authentication, access authorization and mobility management of terminal devices. The G-MM network element can be the access and mobility management function (AMF) network element in the 5G communication system. The G-SM network element is used to support the access of terminal devices and is responsible for counting and supervising the large network resources used by terminal devices to access the subnet, such as resource usage, access duration, etc. The G-SM network element can be the session management function (SMF) network element in the 5G communication system. The G-UPF network element is responsible for forwarding subnet service data packets between terminal devices and subnets, and can also be used to collect subnet-related billing information such as traffic. The G-UPF network element can be the user plane function (UPF) network element in the 5G communication system.
[0181] OP 2 is the home operator of the terminal device (or OP 2 is the home operator of a SIM card / embedded SIM (eSIM) card included in the terminal device), so the subscription data between the terminal device and OP 2 is stored by the core network element in PLMN 2. For example, the unified data management (UDM) network element in PLMN 2 stores the subscription data (such as the key) of the terminal device.
[0182] The core network elements in PLMN 2 may include an authentication server function (AUSF) element and a UDM element. The UDM element is primarily responsible for managing user identities, subscription data, and authentication data. The AUSF element receives requests from the G-MM element to authenticate the terminal device and authenticates the terminal device by requesting an authentication vector from the UDM element.
[0183] The subnet operator is responsible for subnet deployment. In one possible implementation, the subnet operator is the same as the primary network operator. For example, operator OP1 is the subnet operator, and subnet tenants sign a subnet deployment agreement with OP1, which deploys subnets for them. In another possible implementation, the subnet operator is independent of the primary network operator. For example, subnet tenants sign a deployment agreement with the subnet operator, and the subnet operator leases resources from OP1 to deploy the subnet, such as OP1's access and core network equipment.
[0184] The subnet also includes the subnet's control plane network element, subnetwork subscription and policy management (SSPM) network element, and UPF network element. The control plane network element is equivalent to a comprehensive network element that integrates functions such as access authentication, access authorization, mobility management, session management, and authentication services. The SSPM network element is responsible for managing the contract data and policies between terminal devices and subnets, while the subnet's UPF network element is responsible for forwarding user-plane data between terminal devices and subnet services. The network elements in the above subnets can be deployed on-site in the subnet tenant's campus, in the operator's computer room that manages the subnet, or in OP 1's computer room.
[0185] Through the network architecture 100 of FIG1 , when a terminal device accesses a subnet, it can request the AUSF / UDM network element in the PLMN 2 to which it belongs to perform identity authentication, and the control plane network element of the subnet authorizes the terminal device to access.
[0186] Figure 2 is a flow chart of a communication method provided by an embodiment of the present application. As shown in Figure 2, the communication method may include S201 to S205.
[0187] S201: An access network device sends identification information of a first network to a first terminal device. Correspondingly, the first terminal device receives the identification information of the first network from the access network device.
[0188] As an example, the access network device may send identification information of the first network by broadcasting. The access network device has the ability to connect the terminal device to the first network. The first network may be a non-PLMN network.
[0189] The first terminal device is located in a subnet location covered by the broadcast signal of the access network device, and thus can receive the identification information of the first network broadcast by the access network device.
[0190] S202: When the first list in the first terminal device includes identification information of the first network, the first terminal device sends a first request message and the identification information of the first network to the access network device. The first request message is used to request that the first terminal device be connected to the first network. In response, the access network device receives the first request message and the identification information of the first network from the first terminal device.
[0191] As an example, a first list is configured in the first terminal device, and the first list includes identification information of one or more non-PLMNs, or the first list includes identification information of at least one subnet. The subnet involved in this application is a non-PLMN network.
[0192] The first list includes the identification information of the first network, which may indicate that the first network is a subnet with which the first terminal device has a contract, or that the first network is a subnet that is free of contract for the public, and therefore, the first terminal device can access the first network. In this case, the first terminal may send a first request message and the identification of the first network device to the access network device, wherein the first request message is used to request the access network device to connect the first terminal device to the network, and the identification information of the first network is used to notify the access network device to connect the first terminal device to the network.
[0193] It should be noted that “registering to the network” and “accessing the network” mentioned in the embodiments of the present application may have the same meaning.
[0194] S203: The access network device sends a first request message and identification information of the first network to the mobility management network element. Correspondingly, the mobility management network element receives the first request message and identification information of the first network from the access network device.
[0195] In this embodiment, the mobility management network element is a network element in the PLMN that is responsible for access authentication, access authorization, and mobility management of terminal devices.
[0196] After receiving the first request message and the identification information of the first network, the access network device can determine the mobility management network element of the first terminal device according to the identification information of the first network, and send the first request message and the identification information of the first network to the mobility management network element.
[0197] The access network device determines the implementation mode of the mobility management network element according to the identification information of the first network. Please refer to step S304 in the embodiment shown in FIG3 , which will not be described in detail here.
[0198] S204: The mobility management network element sends a second request message to the control plane network element in the first network based on the identification information of the first network, where the second request message is used to request that the first terminal device access the first network. Correspondingly, the control plane network element in the first network receives the second request message from the mobility management network element.
[0199] As an example, the mobility management network element may learn the association between the control plane network element and the identifier of the network to which it belongs, and thereby determine the control plane network element associated with the received identification information for identifying the network as the control plane network element in the first network.
[0200] The control plane network element in the first network is responsible for authorizing the terminal device to access the first network.
[0201] S205: The control plane network element sends a first response message to the mobility management network element, where the first response message is used to indicate whether the first terminal device is allowed to access the first network. Correspondingly, the mobility management network element receives the first response message from the control plane network element.
[0202] In this embodiment, the control plane network element determines whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network, and authorizes the first terminal device to access the first network if access is allowed.
[0203] An exemplary implementation manner in which the control plane network element determines whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network can refer to step S310 in the embodiment shown in Figure 3, which is not repeated here.
[0204] After determining whether the first terminal device is allowed to access the first network, the control plane network element may indicate to the mobility management network element via a first response message whether the first terminal device is allowed to access the first network.
[0205] In this embodiment, when the first list includes the identification information of the first network broadcast by the access network device, the first terminal device can directly select the cell of the subnet access network device for access without considering the large network operator to which it belongs, and share the same access network device with terminal devices belonging to other large network operators.
[0206] It can be understood that the communication method provided in this embodiment can be applied to the network architecture 100 shown in Figure 1. For example, the first terminal device can be a terminal device in the architecture, the first network can be a subnet therein, the mobility management network element can be a G-MM network element therein or an AMF network element under a 5G communication system, and the control plane network element in the first network can be a control plane network element in the subnet.
[0207] The embodiment shown in Figure 2 embodies the technical solution provided by the embodiment of the present application. When accessing a subnet through the above communication method, other network elements in the network architecture 100 are also required to participate. The specific subnet access process is introduced below.
[0208] Figure 3 is a flow chart of a communication method provided by an embodiment of the present application. The communication method proposed in this embodiment can be applied to the network architecture 100 shown in Figure 1. For example, a terminal device is used as the first terminal device, and an AMF network element is used as a mobility management network element, where OP 1 provides resources for subnet deployment, and OP 2 is the home operator of the terminal device. The communication method in Figure 2 is further described using 5G communication as a scenario. As shown in Figure 3, it specifically includes the following steps:
[0209] S300-1, terminal device configuration subnet selection list.
[0210] The subnet selection list, namely the first list, contains the subnet identifier of at least one subnet. The subnet identifier is equivalent to the identity identifier of the subnet, and the corresponding unique subnet can be determined by the subnet identifier. The corresponding subnets corresponding to the subnet identifiers in the subnet selection list are all subnets with which the terminal device has a contractual relationship or subnets that are exempt from contractual relationship with the public. In other words, the subnet selection list indicates the subnets that the terminal device can access, and the terminal device selects the subnet it desires to access based on the subnet identifiers therein.
[0211] In some implementations, the subnet selection list can indicate the priority of the terminal device in performing subnet selection. As an example, the subnet identifiers in the subnet selection list are sorted according to the priority of their corresponding subnets.
[0212] It should be noted that when a terminal device signs a contract with a subnet, a subnet signing identifier needs to be configured. The subnet signing identifier is equivalent to the identity identifier of the terminal device in the subnet. The subnet can determine the corresponding terminal device based on the subnet signing identifier, and the terminal device saves the subnet signing identifier corresponding to each subnet, that is, saves the correspondence between the subnet identifier and the subnet signing identifier. As an example, the subnet signing identifier can be the mobile station international ISDN number (MSISDN) of the terminal device, where ISDN is the abbreviation of integrated service digital network, and MSISDN can be simply understood as a telephone number in daily life. The subnet signing tag can also be the international mobile subscriber identity (IMSI) of the terminal device. In the 5G era, it can also correspond to the user permanent identifier (SUPI) or user hidden identifier (SUCI) of the terminal device. For some subnets, the subnet signing tag can also be the unique identifier of the terminal device in the corresponding subnet. For example, the work number of the terminal device in the enterprise can be used as the subnet signing identifier corresponding to the terminal device in the enterprise subnet.
[0213] It is understandable that a terminal device can use the same subnet subscription identifier in different subnets. For example, the terminal device can use an MSISDN as the subnet subscription identifier in subnet A. The terminal device can also use the same MSISDN as the subnet subscription identifier in subnet B. Subnet A and subnet B share the same MSISDN of the terminal device. It should be noted that one IMSI of a terminal device may correspond to multiple MSISDNs. When different subnets use different MSISDNs as subnet subscription identifiers, the terminal device needs to save the correspondence between all MSISDNs used as subnet subscription labels and the corresponding subnets. For example, if the IMSI of the terminal device corresponds to MSISDN 1 and MSISDN 2, the terminal device uses MSISDN 1 as the subnet subscription identifier for subnet A and MSISDN 2 as the subnet subscription identifier for subnet B. The terminal device needs to save the correspondence between MSISDN 1 and subnet A, and between MSISDN 2 and subnet B, respectively.
[0214] The terminal device can configure the subnet selection list and subnet signing identifier at the factory, or manually configure it, or receive the subnet selection list and subnet signing identifier via signaling when signing a contract with the subnet, and the terminal device saves them.
[0215] As one possible implementation, to support subnets, a new subnet logical interface, namely a first logical interface, is added to the terminal device. The subnet logical interface is used to connect the terminal device to the subnet. Accordingly, the subnet selection list is configured with the subnet logical interface, namely, the subnet logical interface. When different subnets correspond to different subnet subscription identifiers, the subnet subscription identifier can be included as a field in the subnet selection list.
[0216] S300-2, the access network device and the AMF network element interact with the subnet identifier.
[0217] Both access network devices and AMF network elements can support one or more different subnets. Therefore, access network devices and AMF network elements can configure the subnet identifiers corresponding to the subnets they support, and exchange their respective configured subnet identifiers during the initial signaling interaction (such as the "NG Setup" process).
[0218] There is no strict order between the above steps S300 - 1 and S300 - 2 , and the execution order of the two can be swapped at will.
[0219] S301: The access network device broadcasts a subnet identifier. Correspondingly, the terminal device receives the subnet identifier from the access network device.
[0220] Terminal devices need access to a subnet through an access network device. Considering that an access network device supports one or more different subnets, meaning that one or more subnets share the same access network device, the access network device broadcasts the subnet identifier corresponding to each supported subnet to the terminal device, allowing the terminal device to subsequently select a subnet, reducing unnecessary attempts and improving access efficiency. It is understood that in addition to supporting subnets, subnet access network devices also support large-network services. Therefore, the access network device also broadcasts the PLMN IDs it supports to the terminal device.
[0221] S302: The terminal device selects a subnet according to the subnet selection list and the subnet identifier broadcast by the access network device.
[0222] In this step, the dedicated subnet logical interface used by the terminal device to access the subnet is matched against a previously configured subnet selection list based on the subnet identifier broadcast by the access network device. If a subnet identifier identical to the subnet identifier broadcast by the access network device exists in the subnet selection list, it indicates that the terminal device can access the subnet corresponding to the subnet identifier through the access network device. The subnet identifier broadcast by the access network device and the subnet identifier in the subnet selection list both include the identifier of the first network, which is a subnet that the access network device supports the terminal device to access.
[0223] In some implementations, when the first logical interface is in an enabled state, the terminal device selects a subnet based on the subnet selection list and the subnet identifier broadcast by the access network device. As an example, when the first logical interface is in an enabled state, and the subnet selection list includes the identifier of the first network broadcast by the access network device, the terminal device selects the first network as the subnet to be accessed and sends the first request message and the identifier of the first network in step S303.
[0224] In some implementations, a subnet switch may be added to the terminal device to control the opening and closing of the first logical interface. The terminal device operator can turn on the subnet switch when the terminal device is near a subnet location. This avoids unnecessary energy consumption caused by the terminal device performing a network search when it cannot access the subnet, thereby saving energy for the terminal device.
[0225] In some implementations, when there are multiple subnet identifiers in the subnet selection list that are identical to the subnet identifier broadcast by the access network device, the terminal device selects the subnet indicated by the subnet identifier with the highest priority from the multiple identical subnet identifiers in the subnet selection list as the subnet to be accessed based on the priority indicated by the subnet identifier in the subnet selection list.
[0226] S303: The terminal device sends a first request message and identification information of the first network to the access network device. Correspondingly, the access network device receives the first request message and identification information of the first network from the terminal device.
[0227] The first request message is used to request that the terminal device be registered with (or accessed to) the first network. The first network is the subnet selected by the terminal device in step S302 based on the subnet selection list and the access network device broadcast. It should be noted that when there are multiple accessible subnets in step S302, the terminal device selects the first network from the multiple accessible subnets.
[0228] As an example, the terminal device receives identification information of a third network broadcast by an access network device. The identification information of the third network and the identification information of the first network are both included in the first list. The priority of the first network is higher than the priority of the third network. Therefore, the terminal device sends a first request message and the identification information of the first network to the access network device.
[0229] In some implementations, the first request message also includes a first identifier and / or a second identifier. The first identifier is the subnet subscription identifier of the terminal device in the first network, and is the corresponding identifier assigned by the first network to the terminal device. The first identifier can uniquely indicate the corresponding terminal device in the first network. The second identifier is the identifier of the terminal device in the second network, which is a PLMN network deployed by the terminal device's home operator OP 2. The identifier of the terminal device in the second network is any one of SUPI, SUCI, or IMSI. It is understood that the second identifier includes a PLMN ID, and the home operator of the terminal device can be determined through the PLMN ID included therein.
[0230] It should be noted that a terminal device may be equipped with multiple SIM cards belonging to different operators. Accordingly, the terminal device includes multiple large network logical interfaces for accessing the large network. Each of the multiple large network logical interfaces for accessing the large network corresponds one-to-one with a different SIM card. Therefore, each large network logical interface is associated with the second identifier indicated by its corresponding SIM card, and the large network logical interface is the second logical interface. For example, the terminal device is equipped with SIM 1 and SIM 2, where SIM 1 belongs to operator A and SIM 2 belongs to operator B, indicating that the terminal device is a subscriber of both operator A and operator B. The terminal device includes large network logical interface 1 and large network logical interface 2. Large network logical interface 1 is associated with SIM 1, and large network logical interface 2 is associated with SIM 2. The terminal device can obtain the identifier of the terminal device in the network deployed by operator A through large network logical interface 1, and can obtain the identifier of the terminal device in the network deployed by operator B through large network logical interface 2.
[0231] In specific implementation, the large network logical interface and the subnet logical interface may correspond to different physical modems, or may share a physical modem (eg, time-sharing).
[0232] In some implementations, when the first logical interface on the terminal device for accessing the subnet is associated with the second logical interface for accessing the main network, or when the first network is associated with the second logical interface for accessing the main network, the terminal device can determine the second identifier through the associated second logical interface for accessing the main network, so that the terminal device directly sends the second identifier to the access network device or carries the second identifier in the first request message.
[0233] It should be noted that the subnet selection list may also include first indication information, and the first indication information is used to indicate that the first logical interface for accessing the subnet is associated with the second logical interface for accessing the main network, or the first indication information indicates that the first network is associated with the second logical interface for accessing the main network. When the terminal device registers to the first network, the second identifier is used for identity authentication, so the first indication information can also be used to indicate or trigger the terminal device to send the second identifier when requesting to register to the first network. When the subnet selection list configured for the terminal device includes the first indication information, the terminal device can carry the second identifier in the first request message based on the first indication information.
[0234] As a possible implementation manner, in step S303, the terminal device may also directly send the first identifier and / or the second identifier to the access network device.
[0235] S304, the access network device selects the AMF network element according to the subnet identifier.
[0236] According to step S300-2, the access network device has clarified through signaling interaction that different AMF network elements support different subnets. Therefore, on the premise of determining that access registration to the first network is required, the access network device needs to select an AMF network element that supports the first network from multiple AMF network elements based on the subnet identification information corresponding to the first network.
[0237] In some implementations, the access network device can also query the network repository function (NRF) network element or the domain name system (DNS) according to the subnet identifier corresponding to the first network, thereby selecting the AMF network element that supports the first network.
[0238] S305: The access network device sends a first request message and identification information of the first network to the AMF network element. Correspondingly, the AMF network element receives the first request message and identification information of the first network from the access network device.
[0239] S306, the AMF network element requests the AUSF / UDM network element deployed by the operator to which the terminal device belongs to perform identity authentication.
[0240] In this step, in order to authenticate the terminal device, the AMF network element needs to obtain a second identifier of the terminal device, such as the SUCI or SUPI of the terminal device. In some implementations, the first request message in step S303 includes the second identifier, which may be the SUPI / SUCI of the terminal device, or the terminal device sends the second identifier to the access network device as the SUPI / SUCI corresponding to the terminal device.
[0241] If the first request message does not carry the second identifier, or the AMF network element does not receive the second identifier of the terminal device, the AMF network element may send first information to the terminal device, where the first information is used to request the identifier of the terminal device in the second network. As an example, the AMF network element sends an ID identity document (ID) request to the terminal device, requesting the SUPI / SUCI of the terminal device associated with the first network or the first logical interface.
[0242] It should be noted that since SUPI / SUCI is an identifier assigned by the network operator to the SIM card, authenticating the terminal device based on SUPI / SUCI is also called SIM authentication.
[0243] After determining that the home operator indicated by the terminal device is OP 2, the AMF network element sends a first authentication request message to the AUSF / UDM network element in the large network deployed by OP 2. The first authentication request message contains the SUPI / SUCI of the terminal device. The first authentication request message is used to request authentication of whether the terminal device is a subscriber of OP 2. When the AUSF / UDM network element deployed by OP 2 receives the first authentication request message, the AUSF / UDM network element generates an authentication vector based on the SUPI / SUCI and sends a first authentication response message to the AMF network element, which contains the authentication vector. Subsequently, the AMF network element further interacts with the terminal device and the AUSF / UDM network element according to existing identity authentication methods. If the authentication vector contains verification information, the AMF network element can confirm whether the terminal device is a subscriber of OP 2 through local verification after receiving the authentication response from the terminal device. Otherwise, the AMF network element can only send the authentication response of the terminal device to the AUSF / UDM network element and indicate the success or failure of the authentication by receiving the response information from the AUSF / UDM network element.
[0244] It can be understood that the AMF network element actually first sends a request for identity authentication to the AUSF network element, and the AUSF network element requests an authentication vector from the UDM network element, and the AUSF network element performs authentication processing on the terminal device based on the authentication vector. In the above process, both the AUSF network element and the UDM network element, the core network elements in the second network OP 2, participate in the identity authentication. Therefore, in the embodiment of the present application, it is uniformly described as requesting the AUSF / UDM network element to perform identity authentication.
[0245] If the identity authentication of the terminal device is successful in this step, that is, the AUSF / UDM network element deployed by OP 2 in the second network authenticates the terminal device as a subscriber of OP 2, the communication method proposed in this embodiment continues to execute step S307, and the AMF network element sends a second request message to the control plane network element of the first network. Otherwise, it means that the identity authentication of the terminal device fails, the terminal device cannot access the first network, and the AMF network element rejects the access of the terminal device (that is, sends a registration rejection message to the terminal device).
[0246] S307: The AMF network element sends a second request message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the second request message from the AMF network element.
[0247] In the above steps, the terminal device is registered (or accessed) to the first network based on the subnet identifier. Therefore, the subnet control plane network element in this step is the control plane network element in the first network, and the second request message is used to request the terminal device to access the first network.
[0248] In some implementations, the second request message may carry an indication that identity authentication has been performed, and the AMF network element can use this indication to convey the information that the terminal device is reliable to the control plane network element in the first network.
[0249] When the first request message in step S303 includes the first identifier of the terminal device, the second request message may also include the first identifier of the terminal device accordingly.
[0250] Optionally, when the first identifier of the terminal device is an external identifier of such terminal device, such as an MSISDN, before step S307, the communication method in this embodiment may further include the following step S307-0.
[0251] S307-0: Check whether the first subnet subscription identifier is a legal external identifier.
[0252] On the basis that the terminal device passes the OP 2 identity authentication, as an example, whether the first subnet subscription identifier is a legal external identifier can be verified based on two methods, one of which is:
[0253] The AMF network element requests the UDM network element deployed by OP 2 to obtain the external identifier of the terminal device. If the external identifier of the terminal device includes the first identifier carried in the first registration request message, the first identifier is verified successfully, indicating that it is a legal external identifier.
[0254] The second is:
[0255] The AMF network element sends the first subnet subscription identifier carried in the first registration request message to the UDM network element deployed by OP 2, and requests the UDM network element to verify whether it is a legal external identifier. The AMF network element indicates the verification result through the response information sent by the UDM network element.
[0256] It can be understood that when verifying whether the first identifier is a legal external identifier, the AMF network element can only send a second request message to the subnet control plane network element if it is determined that the first identifier is a legal external identifier.
[0257] In some implementations, when the first subnet subscription identifier in the first registration request message is verified as a valid external identifier, the second request message may also carry a verification indication message, which indicates that the first subnet subscription identifier has been verified. In one implementation, the second request message may carry a verified external identifier field (different from the first identifier sent by the terminal device in the first request message) as the verification indication information.
[0258] In some implementations, after the terminal device passes identity authentication, the AMF network element can obtain the external identifier of the terminal device from the second network deployed by OP 2, and carry the external identifier in the second request message. The external identifier is the first identifier of the terminal device.
[0259] It should be noted that in the above two methods, the AMF network element can directly interact with the UDM network element deployed by OP 2. In some implementation methods, the AMF network element can also interact with the AUSF network element deployed by OP 2. The AMF network element interacts indirectly with the UDM network element through the AUSF network element, thereby verifying whether the first subnet contract identifier is a legal external identifier.
[0260] The subnet subscription identifier of the terminal device in the first network is the basis for the control plane network element in the first network to further confirm the connection between the terminal device and the first network. When the first subnet subscription identifier is the external identifier of the terminal device, verifying its legality can avoid the subsequent access authentication process, thereby improving efficiency.
[0261] In some implementations, the AMF network element may assign a first terminal identifier to the terminal device, and the first terminal identifier is used to indicate the terminal device in the AMF network element. As an example, the first terminal identifier is a context identifier or a temporary identifier of the terminal device, which is used to indicate the context of the terminal device in the AMF network element. The AMF network element can determine a unique terminal device based on the context of the terminal device. The second request message may also include the first terminal identifier of the terminal device. In the subsequent access process, the subnet control plane network element may carry the first terminal identifier when performing signaling interaction with the AMF network element. The AMF network element can locate the context of the corresponding terminal device based on the first terminal identifier. Through the first terminal identifier, the security and privacy of the terminal device can be protected when the AMF network element performs signaling interaction with the subnet control plane network element, for example, avoiding the leakage of the terminal device's SIM card information (such as SUPI) to the subnet.
[0262] S308: The subnet control plane network element obtains the subscription information of the terminal device in the first network.
[0263] In this step, the control plane network element of the first network requests the SSPM network element to obtain the contract information between the terminal device and the first network according to the first identifier of the terminal device.
[0264] In another possible implementation, the first network is an open subnet in a public setting such as a shopping mall or cinema. In this case, the terminal device does not have a contractual relationship with the first network, so the second request message naturally does not contain the terminal device's subnet contract identifier in the first network. Accordingly, the first network has default contract information, which is intended for all terminal devices that wish to access the first network. Therefore, the control plane network element of the first network can directly obtain the default contract information, which is equivalent to the contract information of the terminal device in the first network.
[0265] S309: The subnet control plane network element performs access authentication on the terminal device.
[0266] In this step, the control plane network element of the first network verifies the identity of the terminal device based on the first identifier of the terminal device.
[0267] If the second request message does not carry the subnet subscription identifier of the first identifier of the terminal device in the first network, in a possible implementation, the control plane network element may request the terminal device to obtain its subnet subscription identifier in the first network.
[0268] As an example of access authentication, during the subnet access authentication process, the control plane network element can generate an access authentication message based on the first identifier subnet contract identifier, and transmit the access authentication message to the terminal device through the AMF network element. The access authentication message carries a random number. The terminal device calculates the random number in the access authentication message based on the locally stored key or the certificate shared with the first network to obtain a calculation result. The terminal device transmits the calculation result to the control plane network element through the AMF network element. The control plane network element calculates the random number in the access authentication message based on the key shared between the terminal device and the terminal device. If the obtained calculation result matches the calculation result returned by the terminal device, it indicates that the access authentication is successful, that is, the control plane network element authenticates that the terminal device has a contract relationship with the first network.
[0269] In some implementations, the control plane network element initiates access authentication for the terminal device only when preset conditions are met, and the preset conditions include at least one of the following conditions: the first identifier of the terminal device is a private identifier in the first network, the contract information of the terminal device in the first network requires access authentication for the terminal device, the first identifier is not included in the second request message, or the control plane network element requires access authentication for all terminal devices requesting access to the first network.
[0270] Among them, when the second request message in step S307 does not carry the first identifier of the terminal device, step S309 can be executed before step S308, that is, the control plane network element first requests the terminal device to obtain its subnet contract identifier in the first network, and the control plane network element performs access authentication on the terminal device. When the access authentication is successful, the contract information of the terminal device in the first network is obtained.
[0271] It should be noted that if the first identifier of the terminal device is an external identifier, the execution logic of the communication method in this embodiment is: in one possible implementation, after the terminal device passes the identity authentication in step S306, the second request message may carry an indication that the first subnet subscription identifier has been verified. In this case, step S309 is an optional step; in another possible implementation, the control plane network element of the first network directly performs access authentication on the terminal device based on the first identifier of the terminal device. In this case, step S306 is an optional step. In this implementation, if the control plane network element of the first network requires verification of whether the first subnet subscription identifier is a legal external identifier, since the external identifier of the terminal device is stored in the UDM network element deployed by OP 2, the terminal device needs to pass identity authentication before executing the verification method in step S307-0. In this case, S306 is a required step; in another possible implementation, the AMF network element is pre-configured with configuration information, and the configuration information indicates that when the terminal device requests access to any subnet or access to a specified first network, the terminal device is required to perform identity authentication. In this implementation, S306 is also a required step.
[0272] If, according to the preset conditions, the first identifier of the terminal device is a private identifier in the first network, the execution logic of the communication method in this embodiment is: the control plane network element of the first network directly authenticates the terminal device based on the first identifier of the terminal device. At this time, step S306 is an optional step. In addition, in step S309, it is also possible to synchronously verify whether the first identifier subnet contract identifier is a legal private identifier.
[0273] S310: The subnet control plane network element authorizes the terminal device according to the subscription information of the terminal device in the first network.
[0274] According to step S308, the default subscription information in the first network is for all terminal devices that desire to access the first network and have no subscription to the first network. Therefore, the default subscription information is equivalent to the subscription information of these terminal devices in the first network.
[0275] In this step, the contract information of the terminal device in the first network indicates the conditions for allowing the first network to authorize the terminal device to access. As an example, the contract information of the terminal device in the first network includes any of the above information, such as a list of cells allowing the terminal device to access the first network, a list of access network devices, and a tracking area identity (TAI). The control plane network element matches the location area information allowed for access according to the current location information of the terminal device with the location area information indicated by the contract information. If the current location information of the terminal device is included in the above area, the control plane network element approves the access authorization of the terminal device.
[0276] When the terminal device sends a first request message to the access network device, the access network device can obtain the current location information of the terminal device. Optionally, the current location information of the terminal device can be carried in the second request message in step S307. In some implementations, if the second request message does not carry the current location information of the terminal device, the control plane network element can request the access network device to obtain the information. In some implementations, the first request message in step S303 also includes second information, and the second information is used for the logical network and / or network slice that the terminal device in the first network requests to access. Accordingly, the second request message includes the terminal device's access request to the logical network and / or network slice. The subscription information of the terminal device in the first network includes the logical network and / or network slice information in the first network that allows the terminal device to access the first network. If the terminal device's access request for the logical network or network slice carried in the second request message matches the content in the subscription information, that is, the terminal device indicates in the subscription information in the first network that the logical network and / or network slice allowed for the terminal device to access in the first network includes the logical network and / or network slice requested to be accessed by the terminal device, the control plane network element approves the access authorization for the terminal device.
[0277] Among them, the logical network or network slice is equivalent to dividing the first network into network areas that provide different services. Different network areas correspond to different access rights. Only when the contract information of the terminal device in the first network indicates that the terminal device meets the access rights, can the terminal device access its target network area. For example: the first network is divided into network area A and network area B based on service classification, where the access right requirement of network area A is higher than that of network area B. The contract information of the terminal device in the first network indicates that the terminal device can only access network area B at most. Therefore, when the terminal device requests access to network area A in the access request message, its authorization cannot be passed, which will cause the terminal device to fail to access the first network.
[0278] S311: The subnet control plane network element sends an access response message to the AMF network element. Correspondingly, the AMF network element receives the access response message from the subnet control plane network element.
[0279] If step S311 authorizes the terminal device to access the first network, the access response information sent by the control plane network element in the first network to the AMF network element indicates that the terminal device is allowed to access the first network.
[0280] In some implementations, when the first network authorizes the terminal device to access the network slice and / or logical network in step S310, the access response information may also carry relevant information about the network slice and / or logical network that the terminal device is allowed to access.
[0281] In some implementations, after the control plane network element passes the authorization authentication of the terminal device in step S310, the control plane network element may assign a second terminal identifier to the terminal device. The second terminal identifier is used to indicate the terminal device in the control plane network element. As an example, the second terminal identifier is a context identifier of the terminal device, which is used to indicate the context of the terminal device in the control plane network element. The control plane network element can determine a unique terminal device based on the context of the terminal device. As a possible implementation, the second terminal identifier can also be a temporary identifier of the terminal device. When the second terminal identifier is a temporary identifier, the control plane network element registers the temporary identifier with the SSPM network element, and the SSPM network element saves the correspondence between the first identifier and the second terminal identifier of the terminal device.
[0282] It is understandable that the terminal device needs to establish a session with the UPF network element in the first network through the control plane network element in the subsequent process. Therefore, the access response message can carry the second terminal identifier of the terminal device so that the corresponding terminal device can be determined based on the second terminal identifier when the AMF network element interacts with the control plane network element.
[0283] S312, the AMF network element sends a first registration acceptance message to the terminal device, and accordingly, the terminal device receives the first registration acceptance message from the AMF network element.
[0284] In this step, the first registration acceptance message indicates that the terminal device is allowed to access and register to the first network. After receiving the first registration acceptance message, the terminal device is equivalent to being registered in the first network and can use the subnet services in the first network or access the subnet services in the first network after establishing a session. When the access response message carries relevant information about the network slice and / or logical network that the terminal device is allowed to access, the AMF can send the relevant information about the network slice and / or logical network to the terminal device.
[0285] In some implementations, the relevant information of the network slice and / or logical network that the terminal device is allowed to access can be encapsulated in a transparent container and sent to the AMF network element via an access response message, and then forwarded to the terminal device by the AMF network element in the first registration acceptance message.
[0286] S313: The terminal device sends a first session request message to the AMF network element. Correspondingly, the AMF network element receives the first session request message from the terminal device.
[0287] After the terminal device receives the first registration acceptance message from the AMF network element, it triggers the establishment of a PDU session. In this step, the terminal device sends a first session request message to the AMF network element, which is used to request the establishment of a session between the terminal device and the UPF network element in the first network.
[0288] In some implementations, when the first registration acceptance message includes relevant information about the network slice and / or logical network that the terminal device is allowed to access, accordingly, the first session request message is used to request establishment of a session between the terminal device in the first network and the network slice and / or logical network. The first session request message also includes an identifier of the requested network slice and / or logical network, and the requested network slice and / or logical network is one or more of the network switches and / or logical networks that the terminal device is allowed to access and included in the first registration acceptance message.
[0289] It is understandable that if the first registration acceptance message only indicates that the terminal device is allowed to access the first network, then the default session establishment is triggered in step S313.
[0290] It should be noted that when multiple sessions are allowed to be established, the first session request message sent by the terminal device to the AMF network element also includes a corresponding session identifier. The session identifier can be used to distinguish the session requested to be established by the first session request message from the established session.
[0291] S314, AMF network element selects SMF network element.
[0292] In this step, the AMF network element selects the SMF network element that supports the first network according to the identification information of the first network. It should be noted that when accessing the subnet in the aforementioned step, the AMF network element saves the identification information of the corresponding subnet, so the identification information of the first network is saved in the context of the AMF network element, and the AMF network element can select the SMF network element according to the saved identification information of the first network.
[0293] In some implementations, when the access network device can interact directly with the UPF network element in the first network and does not require the SMF network element to count session usage information, the communication method of this embodiment does not require the SMF network element, that is, this step is a non-essential step.
[0294] Optionally, the SMF network element can also be combined with the AMF network element. When the two are combined, it is equivalent to the function of the AMF network element integrating the session management network element. In this case, the AMF network element also does not need to select the SMF network element.
[0295] S315, the AMF network element requests the SMF network element to establish a session from the terminal device to the first network.
[0296] In this step, the AMF network element triggers the second UPF network element to allocate uplink tunnel information and downlink tunnel information for the session from the terminal device to the first network based on the first session request message. The second UPF network element is a UPF network element that supports connection to the first network, and there is an interface between the second UPF network element and the access network device.
[0297] In the case where the AMF network element and the SMF network element are separately provided, it can be seen from step S314 that the identification information of the first network is stored in the context of the AMF network element. Therefore, the AMF network element carries the identification information of the first network when requesting the SMF network element to establish a session. Similar to the selection of the AMF network element by the access network device in step S304, the SMF network element selects a UPF network element that supports connection to the first network based on the identification information of the first network. This UPF network element is the second UPF network element.
[0298] After receiving the session establishment request from the AMF network element, the SMF network element triggers the second UPF network element to allocate uplink tunnel information and downlink tunnel information, that is, the SMF network element requests the selected second UPF network element to allocate uplink tunnel information and downlink tunnel information, and sends the first uplink tunnel information and the first downlink tunnel information allocated by the second UPF network element to the AMF network element through the response message of the session establishment. The first uplink tunnel information is used to send the uplink data of the session to the second UPF network element from the access network, and the first downlink tunnel information is used for the session anchor point UPF network element (that is, the first UPF network element located in the first network) to send the downlink data of the session to the second UPF network element.
[0299] It can be understood that when the AMF network element and the SMF network element are co-installed or the SMF network element is not needed, the operation performed by the SMF network element in this step can be implemented by the AMF network element, that is, the AMF network element selects the second UPF network element through the identification information of the first network, and the AMF network element triggers the second UPF network element to allocate uplink tunnel information and downlink tunnel information, that is, the AMF network element requests it to allocate corresponding uplink tunnel information and downlink tunnel information.
[0300] S316: The AMF network element sends a second session request message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the second session request message from the AMF network element.
[0301] The second session request message is used to request establishment of a session between the terminal device and the UPF network element in the first network. The second session request message includes information about the first downlink tunnel allocated by the second UPF network element. When the first session request message includes an identifier of a network slice and / or logical network, the second session request message accordingly includes the identifier of the above network slice and / or logical network. The second session request message may also include the current location information of the terminal device.
[0302] The network element responsible for session processing in the first network may be co-located with the control plane network element of the first network, or may be separately located. Upon receiving a request message to establish a session, the network element responsible for session processing in the first network needs to obtain the session subscription information and / or session policy information of the terminal in order to establish the session.
[0303] Since the session subscription information and / or session policy information is stored in the SSPM network element, the network element responsible for session processing in the first network queries the SSPM network element based on the terminal identification information to obtain the terminal's session subscription information and / or session policy information. The method for obtaining the terminal identification is as follows:
[0304] In some implementations, the second session request message also includes the second terminal identifier assigned to the terminal device by the control plane network element in step S311. When the control plane network element of the first network is co-located with the session management network element of the first network, that is, the control plane network element of the first network integrates the functions of the session management network element of the first network, the control plane network element of the first network supports control of the UPF in the first network. Based on the second terminal identifier, the control plane network element can determine the terminal device corresponding to the second session request message and obtain session subscription information and / or session policy information.
[0305] It can be understood that when the first session request message in step S313 includes the first identifier of the terminal device, the second session request message may also include the first identifier of the terminal device. The control plane network element can also determine the terminal device corresponding to the second session request message based on the first identifier of the terminal device and obtain the session signing information.
[0306] In some implementations, when the control plane network element of the first network is separately provided from the session management network element of the first network, the control plane network element of the first network also needs to send a request message to the session management network element of the first network. The session management network element can determine the corresponding terminal device based on the first identifier included in the request message and obtain session subscription information and / or session policy information. For privacy and security reasons, the first identifier of the terminal device may not be included in the second request message. In this case, the session management network element in the first network determines the terminal device corresponding to the session based on the second terminal identifier of the terminal device. Specifically, if the control plane network element of the first network registers the second terminal identifier with the SSPM network element as shown in step S311, the session management network element in the first network can directly query the SSPM network element based on the second terminal identifier to obtain the terminal's session subscription data and / or session policy information.
[0307] In the embodiment shown in FIG. 3 of the present application, it is assumed that the control plane network element of the first network integrates the function of the session management network element of the first network.
[0308] S317: The subnet control plane network element obtains the session policy and / or session policy information.
[0309] In this step, the control plane network element of the first network obtains session subscription information and / or session policy information from the SSPM network element based on the first identifier or the second terminal identifier included in the second request message. The session subscription information may include information such as the network slices and logical subnet information allowed to be accessed by the terminal device in the first network, and the location range in which the terminal device is allowed to access a certain network slice or logical subnet. The session policy information may include quality of service (QoS) information corresponding to the session, such as the maximum bandwidth allowed for the session, scheduling priority, and other information.
[0310] It is understandable that since the SSPM network element stores the correspondence between the first identifier and the second terminal identifier of the terminal device, the control plane network element can also obtain the above information from the SSPM network element according to the second terminal identifier included in the second request message.
[0311] S318, the subnet control plane network element selects the subnet UPF network element.
[0312] The control plane network element of the first network or the session management network element of the first network can determine whether to allow the establishment of a session between the terminal device and the UPF network element in the first network based on the session subscription information obtained from the SSPM network element and the second session request message. When the session establishment is allowed, the control plane network element of the first network or the session management network element of the first network can select an appropriate UPF network element from the UPF network elements of the first network based on the network slice, logical subnet information, and location information of the terminal device included in the second session request message.
[0313] For example, a UPF network element that supports the network slice and logical subnet in the second session request message is selected, or a UPF network element close to the current location of the terminal device is selected. The UPF network element selected by the control plane network element or the session management network element of the first network is the first UPF network element in the first network.
[0314] S319, establish a session on the subnet UPF network element.
[0315] In this step, the control plane network element of the first network or the session management network element of the first network sends a third session request message to the first UPF network element in the first network. The third session request message is used to request that a session be established in the first UPF network element for the terminal device to the first network. The third session request message includes the first downlink tunnel information allocated by the second UPF network element. The first UPF network element sends downlink data to the second UPF network element based on the first downlink tunnel information. After receiving the third session request message, the first UPF network element in the first network allocates the second uplink tunnel information for the session of the terminal device, which is used to receive uplink data from the second UPF network element.
[0316] In some implementations, the third session request message may also include the configuration rules of the UPF network element. For example, when the first network only allows terminal devices to access specific network slices or logical subnets, the configuration rules of the UPF network element may be filtering rules. The UPF network element will discard all data packets whose source / destination addresses are non-allowed logical networks or network slices according to the configuration rules.
[0317] It is understandable that if the session contract information or session policy of the terminal device in the first network includes corresponding access rules, the UPF network element also needs to be configured according to the access rules. For example: the session policy restricts the terminal device from accessing specific websites, such as non-working websites, then the UPF network element filters or discards data packets with source / destination addresses of specific websites according to the configuration rules.
[0318] S320: The subnet control plane network element sends a session establishment response message to the AMF network element. Correspondingly, the AMF network element receives the session establishment response message from the subnet control plane network element.
[0319] In this step, the session establishment response message includes a non-access stratum (NAS) message for indicating to the terminal device that the session establishment is successful, and the session establishment response message also includes the second uplink tunnel information allocated by the first UPF network element in the first network.
[0320] In some implementations, after the control plane network element of the first network determines the corresponding QoS parameters according to the session policy information, the session establishment response message may further include the QoS parameters.
[0321] S321, the AMF network element requests the access network device to allocate session resources.
[0322] In this step, the AMF network element sends a message to the access network device requesting the allocation of session resources. The message includes a NAS message indicating that the session is successfully established, QoS parameter information corresponding to the session, and the first uplink tunnel information allocated by the second UPF network element. Based on the first uplink tunnel information, the access network device can send uplink data to the second UPF network element.
[0323] The access network device allocates corresponding wireless air interface resources to the session of the terminal device based on the QoS parameters, forwards the NAS message indicating that the session is successfully established to the terminal device, and sends a response message including the downlink tunnel information allocated by the access network device to the AMF network element.
[0324] S322, AMF network element updates the session.
[0325] After receiving the response message containing the downlink tunnel information allocated by the access network device, the AMF network element sends a session update request message to the second UPF network element through the SMF network element. The session update request message includes the downlink tunnel information allocated by the access network device and the second uplink tunnel information. Through the downlink tunnel information allocated by the access network device, the second UPF network element can send downlink data to the access network device, and through the second uplink tunnel information, the second UPF network element can send uplink data to the first UPF network element in the first network.
[0326] In this step, the uplink and downlink paths of the session between the terminal device and the first UPF network element in the first network can be opened through the session update, so that the terminal device can access the relevant services in the first network.
[0327] In this embodiment, when the terminal device selects a subnet based on the subnet selection list and the broadcast subnet identification information, there is no need to consider the PLMN ID configured in the SIM card loaded on the terminal device and the PLMN ID broadcast by the access network device. Therefore, even if the terminal device and the access network device belong to different operators, the terminal device can still initiate a request to the access network device to access the subnet.
[0328] The terminal device requests access to the first network from the AMF network element through the access network device. The control plane network element in the first network obtains the contract information between the terminal device and the first network, and determines whether the terminal device is allowed to access the first network based on the contract information. The terminal device is authorized and authenticated by the control plane network element of the newly set subnet in the architecture, and the control authority for access to the subnet can be handed over to the subnet tenant. The terminal device's home operator no longer needs to establish a PDU session with the subnet, so that terminal devices belonging to different operators can access the same subnet in the scenario, thereby providing convenience for subnet users.
[0329] In the embodiment shown in FIG3 above, in step S306, the AMF network element requests the home operator indicated by the terminal device to authenticate the terminal device, on the premise that a roaming agreement exists between the operator OP 1 and the operator OP 2 in the network architecture 100, and interface 1 serves as a roaming interface. The AMF network element deployed by OP 1 can initiate an identity authentication request to the AUSF / UDM network element deployed by OP 2 through interface 1. When there is no roaming agreement between the operator OP 1 and the operator OP 2, interface 1 does not exist in the network architecture 100. At this time, the subnet operator cooperates with the operator OP 1 and the operator OP 2. Interface 2 serves as the capability exposure interface of the operator OP 2 and can provide an interactive interface for identity authentication. The subnet control plane network element initiates an identity authentication request to the AUSF / UDM network element deployed by OP 2 through interface 2. The following introduces the communication method when there is no roaming agreement between the operator OP 1 and the operator OP 2.
[0330] FIG4 is a flow chart of a communication method provided by an embodiment of the present application. As shown in FIG4, steps S400 to S405 are consistent with the corresponding steps S300 to S305 in the above embodiment. The difference between the communication method in this embodiment and the following steps is:
[0331] S406: Request the AUSF / UDM network element of the operator to which the terminal device belongs to perform identity authentication through the subnet control plane network element.
[0332] In this step, since there is no roaming agreement between operator OP 1 and operator OP 2, the subnet control plane network element initiates an identity authentication request to the AUSF / UDM network element deployed by the home operator indicated by the terminal device through interface 2.
[0333] FIG5 is a schematic diagram of a process for requesting an AUSF / UDM network element to perform identity authentication through a subnet control plane network element according to an embodiment of the present application. As shown in FIG5 , the identity authentication process includes the following steps:
[0334] S501: The AMF network element sends a first authentication request message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the first authentication request message from the AMF network element.
[0335] In this identity authentication process, the first request message in step S405 already carries the SUPI / SUCI of the terminal device. Therefore, in this step, the first authentication request message sent by the AMF to the control plane network element of the first network includes the SUPI / SUCI of the terminal device.
[0336] S502: The subnet control plane network element sends a first authentication request message to the AUSF / UDM network element deployed by the operator to which the terminal device belongs. Correspondingly, the AUSF / UDM network element receives the first authentication request message from the subnet control plane network element.
[0337] According to the SUPI / SUCI of the terminal device, it can be determined that the home operator of the terminal device is OP 2, and a first authentication request message is sent to the AUSF / UDM network element deployed by OP 2.
[0338] S403: The AUSF / UDM network element deployed by the operator to which the terminal device belongs sends a first authentication response message to the AMF network element. Correspondingly, the AMF network element receives the first authentication response message from the AUSF / UDM network element.
[0339] In this step, the AUSF / UDM network element deployed by OP 2 generates an authentication vector based on the SUPI / SUCI carried in the first authentication request message, and carries the authentication vector in the first authentication response message. The AUSF / UDM network element deployed by OP 2 sends the first authentication response message to the control plane network element in the first network, and the control plane network element forwards the first authentication response message to the AMF network element.
[0340] S504: The AMF network element sends a second authentication request message to the terminal device. Correspondingly, the terminal device receives the second authentication request message from the AMF network element.
[0341] The AMF network element generates a second authentication request message of the non-access layer NAS based on the authentication vector in the received first authentication response message, and sends the second authentication request message to the terminal device, where the second authentication request message carries the authentication vector.
[0342] In some implementations, the first authentication request message also includes the first terminal identifier assigned to the terminal device by the AMF network element in the embodiment shown in Figure 3. Accordingly, the first authentication response message also includes the first terminal identifier. The AMF network element locates the context of the terminal device based on the first terminal identifier, thereby sending the second authentication request message in this step to the terminal device determined according to the first terminal identifier.
[0343] S505: The terminal device sends a second authentication response message to the AMF network element. Correspondingly, the AMF network element receives the second authentication response message from the terminal device.
[0344] The terminal device calculates and generates a second authentication response message based on the second authentication request message sent by the AMF network element. The second authentication response message includes authentication information calculated based on the authentication vector, and sends the second authentication response message to the AMF network element. As an example, the verification information can be a random number carried in the second authentication request message by the terminal device, and the terminal device obtains a digital signature based on the random number calculation.
[0345] S506, the AMF network element performs local verification based on the second authentication response message.
[0346] In this step, the AMF network element needs to perform verification based on the verification information carried in the second authentication response message. If the verification is successful, it indicates that the terminal device is a subscriber of the indicated home operator OP 2, and the identity authentication is successful. It should be noted that if the authentication vector in the first authentication response message does not contain verification information, the AMF network element cannot perform identity authentication and needs to execute the subsequent steps shown in Figure 5.
[0347] S507, the AMF network element sends a third authentication request message to the AUSF / UDM network element deployed by the operator to which the terminal device belongs. Correspondingly, the AUSF / UDM network element receives the third authentication request message from the AMF network element.
[0348] When the AMF network element cannot perform local verification, the AMF network element sends a third authentication request message to the control plane network element of the first network. The third authentication request message includes authentication information generated by the terminal device based on the authentication vector. The control plane network element forwards the third authentication request message to the AUSF / UDM network element deployed by OP 2.
[0349] In some implementations, the third authentication request message also includes a second terminal identifier assigned to the terminal device by the control plane network element of the first network in the embodiment shown in Figure 3. The control plane network element can locate the context of the terminal device based on the second terminal identifier, thereby forwarding the third authentication request message to the AUSF / UDM network element deployed by the operator OP 2 to which the terminal device belongs.
[0350] S508: The AUSF / UDM network element deployed by the operator to which the terminal device belongs sends a third authentication response message to the AMF network element. Correspondingly, the AMF network element receives the third authentication response message from the AUSF / UDM network element.
[0351] In this step, the AUSF / UDM network element deployed by OP 2 verifies the authentication information carried in the third authentication request message, generates a third authentication response message in response to the successful verification, and sends the third authentication response message to the control plane network element of the first network. The control plane network element forwards the third authentication response message to the AMF network element. The third authentication response message can also carry key information used to secure subsequent communications, such as the root key Kamf.
[0352] In some implementations, the control plane network element can also deduce the key information based on the key information sent by the AUSF / UDM network element and send the deduced key to the AMF network element, that is, the control plane network element does not simply forward.
[0353] In the identity authentication process shown in Figure 5, the first request message in step S405 already carries the SUPI / SUCI of the terminal device. If the first request message does not carry the SUPI / SUCI of the terminal device, the AMF network element needs to obtain the SUPI / SUCI from the terminal device before initiating the above process.
[0354] Figure 6 is a schematic diagram of a process for requesting an AUSF / UDM network element to perform identity authentication through a subnet control plane network element according to another embodiment of the present application. In the process shown in Figure 6, the AMF network element is responsible for forwarding authentication-related NAS messages between the terminal device and the subnet control plane network element. Specifically, the following steps are included:
[0355] S601: The subnet control plane network element sends an ID request message to the terminal device. Correspondingly, the terminal device receives the ID request message from the subnet control plane network element.
[0356] When the first request message does not carry the SUPI / SUCI of the terminal device, the control plane network element of the first network sends an ID request message to the AMF network element, which forwards the ID request message to the terminal device. The ID request message is used to request the SUPI / SUCI of the terminal device. The message may include the first terminal identifier to facilitate identification of the terminal device by the AMF network element.
[0357] S602: The terminal device sends an ID response message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the ID response message from the terminal device.
[0358] The terminal device sends an ID response message to the AMF network element, which forwards the ID response message to the control plane network element of the first network. The ID response message includes the terminal device's SUPI / SUCI. The message may also include the second terminal identifier so that the subnet control plane network element can identify the terminal device.
[0359] S603: The subnet control plane network element sends a first authentication request message to the AUSF / UDM network element deployed by the operator to which the terminal device belongs. Correspondingly, the AUSF / UDM network element receives the first authentication request message from the subnet control plane network element.
[0360] The control plane network element can determine that the home operator of the terminal device is OP 2 according to the SUPI / SUCI of the terminal device, and sends a first authentication request message to OP 2.
[0361] S604: The AUSF / UDM network element deployed by the operator to which the terminal device belongs sends a first authentication response message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the first authentication response message from the AUSF / UDM network element.
[0362] The AUSF / UDM network element deployed by OP 2 sends the first authentication response message to the control plane network element in the first network.
[0363] S605: The subnet control plane network element sends a second authentication request message to the terminal device. Correspondingly, the terminal device receives the second authentication request message from the subnet control plane network element.
[0364] The control plane network element of the first network generates a NAS second authentication request message based on the authentication vector in the received first authentication response message, and the control plane network element sends the second authentication request message to the AMF network element, and forwards the second authentication request message to the terminal device through the AMF network element. The second authentication request message carries the authentication vector.
[0365] In some implementations, the second authentication request message also includes the first terminal identifier assigned to the terminal device by the AMF network element in the embodiment shown in Figure 3. The AMF network element can locate the context of the terminal device based on the first terminal identifier, thereby forwarding the second authentication request message in this step to the terminal device determined according to the first terminal identifier.
[0366] S606: The terminal device sends a second authentication response message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the second authentication response message from the terminal device.
[0367] The terminal device calculates and generates a second authentication response message based on the second authentication request message sent by the control plane network element of the first network. The second authentication response message includes verification information calculated based on the authentication vector. The terminal device sends the second authentication response message to the AMF network element, and the second authentication response message is forwarded to the control plane network element through the AMF network element.
[0368] S607: The subnet control plane network element performs local verification according to the second authentication response message.
[0369] As in step S506, the control plane network element of the first network needs to perform authentication based on the authentication information carried in the second authentication response message. If the authentication is successful, it indicates that the terminal device is a subscriber of the indicated home operator OP 2, and identity authentication is successful. If the authentication vector in the first authentication response message of step S604 does not include the authentication information, the control plane network element cannot perform identity authentication and needs to execute the subsequent steps shown in Figure 6.
[0370] S608: The subnet control plane network element sends a third authentication request message to the AUSF / UDM network element deployed by the operator to which the terminal device belongs. Correspondingly, the AUSF / UDM network element receives the third authentication request message from the subnet control plane network element.
[0371] When the control plane network element of the first network cannot perform local verification, the control plane network element sends a third authentication request message to the AUSF / UDM network element deployed by OP 2. The third authentication request message includes authentication information generated by the terminal device according to the authentication vector.
[0372] In some implementations, when the AMF network element forwards the second authentication response message to the control plane network element in step S606, the second authentication response message carries the second terminal identifier assigned by the control plane network element to the terminal device. The control plane network element can locate the context of the terminal device based on the second terminal identifier, thereby sending a third authentication request message to the AUSF / UDM network element deployed by the operator OP 2 of the terminal device determined according to the second terminal identifier.
[0373] S609: The AUSF / UDM network element deployed by the operator to which the terminal device belongs sends a third authentication response message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the third authentication response message from the AUSF / UDM network element.
[0374] In this step, the AUSF / UDM network element deployed by OP 2 verifies the authentication information carried in the third authentication request message, generates a third authentication response message in response to the successful verification, and sends the third authentication response message to the control plane network element of the first network. The third authentication response message can also carry key information for security protection of subsequent communications.
[0375] In the embodiment shown in Figure 5 above, the AMF network element and the AUSF / UDM network element deployed by OP 2 are the entities that perform identity authentication, while in the embodiment shown in Figure 6, the control plane network element of the first network and the AUSF / UDM network element deployed by OP 2 are the entities that perform identity authentication.
[0376] Similar to the subnet access authentication process shown in FIG3 , after the terminal device passes identity authentication and confirms that the terminal device is a subscriber of the indicated home operator OP 2, the subnet control plane network element can further determine whether to allow the terminal device to access the subnet it desires to access based on the contract information between the terminal device and the subnet. As shown in FIG4 , the communication method in this embodiment further includes the following steps:
[0377] S407: The AMF network element sends a second request message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the second request message from the AMF network element.
[0378] In this step, the AMF network element sends a second request message to the control plane network element of the first network based on the subnet identifier. The second request message is used to request that the terminal device be connected to the first network. In some implementations, the first request message in step S403 may also carry the subnet subscription identifier corresponding to the first network. Accordingly, the second request message may also carry the subnet subscription identifier of the terminal device in the first subnet.
[0379] It should be noted that the execution order between step S406 and step S407 is changeable. If the authentication process of step S406 adopts the embodiment shown in Figure 5 to authenticate the terminal device, step S406 is executed before step S407. If the embodiment shown in Figure 6 performs identity authentication on the terminal device, step S407 precedes step S406.
[0380] Optionally, when the subnet subscription identifier is an external identifier of the terminal device, the communication method in this embodiment may further include step S408.
[0381] S408: Check whether the first subnet subscription identifier is a legal external identifier.
[0382] This step can verify whether the subnet signing identifier is a valid external identifier based on two methods:
[0383] The control plane network element of the first network requests the UDM network element deployed by OP 2 to obtain the external identifier of the terminal device. If the external identifier of the terminal device includes the subnet subscription identifier carried in the second request message, the subnet subscription identifier is verified successfully, indicating that it is a legal external identifier.
[0384] The second is:
[0385] The control plane network element of the first network sends the subnet subscription identifier carried in the second request message to the UDM network element deployed by OP 2, and requests the UDM network element to verify whether it is a legal external identifier. The control plane network element indicates the verification result through the response information sent by the UDM network element.
[0386] Similar to step S307-0 in the embodiment shown in Figure 3, the main difference is that when there is no roaming agreement between operator OP 1 and operator OP 2, the execution entity of checking whether the subnet subscription identifier is a legal external identifier in step S408 is the control plane network element of the first network and the AUSF / UDM network element deployed by OP 2.
[0387] S409: The subnet control plane network element obtains the subscription information of the terminal device in the first network.
[0388] S410: The subnet control plane network element performs access authentication on the terminal device.
[0389] S411: The subnet control plane network element authorizes and authenticates the terminal device according to the subscription information of the terminal device in the first network.
[0390] S412: The subnet control plane network element sends an access response message to the AMF network element. Correspondingly, the AMF network element receives the access response message from the subnet control plane network element.
[0391] Since the execution subject in steps S409 to S412 is the subnet control plane network element, steps S409 to S412 are consistent with steps S308 to S311 in the embodiment shown in FIG. 3 .
[0392] When step S406 uses the method of Figure 6 to authenticate the terminal device, the key Kamf can also be carried in the access response information. The AMF network element derives the NAS key and Kgnb based on Kamf to protect the NAS message and air interface message of the terminal device. The control plane network element can derive Kamf based on the key information received in step S609, or directly use the key information received in S609 as Kamf.
[0393] S413: The AMF network element sends a first registration acceptance message to the terminal device. Correspondingly, the terminal device receives the first registration acceptance message from the AMF network element.
[0394] This step is consistent with step S313 in Figure 3. In some implementations, on this basis, the AMF network element can also perform key deduction based on the key received in step S412 or the key received in step S408 (when S406 uses the method of Figure 5 to authenticate the terminal device), and perform operations such as starting the NAS security mode and sending the initial context of the terminal device to the access network device.
[0395] When the terminal device receives the first registration acceptance message from the AMF network element, it triggers the establishment of a PDU session. The process of establishing a session between the terminal device and the UPF network element in the first network in the embodiment shown in Figure 4 is consistent with the embodiment shown in Figure 3 and will not be repeated here.
[0396] In this embodiment, the AMF network element initiates an identity authentication request to the AUSF / UDM network element deployed by OP 2 through the subnet control plane network element, without considering whether there is a roaming agreement between the operator deploying the subnet and the operator to which the terminal device belongs, thereby expanding the usage scenarios of the communication method proposed in the embodiment of this application.
[0397] In the communication method proposed in the embodiments of the present application, a subnet switch can also be added to the terminal device. When the subnet switch is turned on, the terminal device can select a subnet based on a configured subnet selection list, allowing the terminal device to access a subnet on demand. The terminal device operator can turn on the subnet switch when the terminal device is near a subnet location, avoiding unnecessary energy consumption caused by network searches when the terminal device cannot access a subnet, thereby saving energy for the terminal device.
[0398] It is understandable that, in addition to the newly proposed subnet switch in the embodiment of the present application, there is also a large network switch on the existing terminal device. For example, the "mobile data" switch on the mobile terminal is equivalent to the large network switch. If the terminal device supports dual-mode or multi-mode technology, that is, it supports access to two or more networks through two or more access network devices at the same time, when the terminal device turns on the subnet switch and the large network switch at the same time, the terminal device can simultaneously access and register to the subnet and the large network through the large network access network device and the subnet access network device, thereby achieving access to the subnet services and the large network services respectively. In the existing technology, only when the terminal device supports dual-mode / multi-mode technology can it access and register to the subnet and the large network through different access network devices. The following describes how to access and register to the subnet and the large network at the same time through a single access network device.
[0399] Figure 7 is a schematic diagram of a process for a terminal device to simultaneously access and register with a subnet and a large network, provided by an embodiment of the present application. As shown in Figure 7, since the terminal device needs to access and register with both the subnet and the large network at the same time, and considering that the process for the terminal device to access and register with the subnet has been described in detail in the above embodiments, the process for the terminal device to access and register with the large network through the same access network device is based on the embodiment shown in Figure 3, and the content related to subnet access is not repeated here. Specifically, the process includes the following steps:
[0400] S700-1, terminal device configuration subnet selection list and PLMN selection list
[0401] The PLMN selection list includes at least one PLMN ID, through which the corresponding large network can be determined. The corresponding large networks corresponding to the PLMN IDs in the PLMN selection list are all large networks selectable by the terminal device, and the terminal device selects the large network it desires to access based on the PLMN ID.
[0402] S700-2, the access network device interacts with the AMF network element to exchange subnet identification and PLMN ID.
[0403] Both the access network equipment and the AMF network element support multiple different large networks. During the initial signaling interaction, the access network equipment and the AMF network element can exchange the PLMN IDs of the large networks they support.
[0404] S701: The access network device broadcasts a subnet identifier and a PLMN ID. Correspondingly, the terminal device receives the subnet identifier and the PLMN ID from the access network device.
[0405] S702: The terminal device selects a subnet and a large network based on the subnet selection list, the PLMN selection list and the broadcast.
[0406] In this step, the terminal device matches the PLMN broadcast by the access network device with the configured PLMN selection list. If the PLMN selection list contains the same PLMN ID as the one broadcast by the access network device, it indicates that the large network supported by the access network device matches the large network selectable by the terminal device, and the terminal device can access the large network corresponding to the PLMN ID through the access network device. Similarly, the PLMN selection list can also indicate the priority of the large network, and the terminal device can select the large network with the highest priority as the large network to be connected.
[0407] S703, the terminal device sends a first request message, identification information of the first network and the ID of the first PLMN to the access network device, and the access network device receives the first request message, identification information of the first network and the ID of the first PLMN from the terminal device.
[0408] The first request message is also used to request that the terminal device be connected to the first PLMN. The first PLMN is the PLMN selected by the terminal device in step S702. The terminal device sends the ID of the first PLMN to the access network device.
[0409] S704, the access network device selects an AMF network element based on the identification information of the first network and the ID of the first PLMN.
[0410] In this step, the AMF network element selected by the access network device needs to support both the subnet corresponding to the first network subnet identifier and the first PLMN.
[0411] S705: The access network device sends a first request message, identification information of the first network, and the ID of the first PLMN to the AMF network element. Correspondingly, the AMF network element receives the first request message, identification information of the first network, and the ID of the first PLMN from the access network device.
[0412] S706, the AMF network element requests the AUSF / UDM network element deployed by the operator to which the terminal device belongs to perform identity authentication.
[0413] In this step, when requesting to access the first PLMN, it is only necessary to request the AUSF / UDM network element deployed by the home operator indicated by the terminal device to perform identity authentication. After the terminal device passes the identity authentication, the terminal device can access the first PLMN through the subnet access network device.
[0414] It should be noted that the premise for the above terminal devices to access the subnet and the large network through the same access network device is that there is a roaming agreement between the large network operator OP 1 that deploys the subnet and the home operator OP 2 of the terminal device so that the terminal device can access the large network through the large network deployed by OP 1 (the access mode to the large network can be the home routing mode or the local drainage mode). Otherwise, even if the terminal device passes the identity authentication, the terminal device can only continue to access the subnet through the subnet control plane and cannot access the large network.
[0415] The method indicated in step S706 requires OP 1 to share the AMF network element with the subnet. For scenarios where OP 1 and the subnet share the AMF network element, if you need to access the services of the subnet and the large network at the same time, you need to continue to perform the following steps:
[0416] S707, subnet access authorization.
[0417] The part involving subnet access in this step is consistent with steps S307-0 to S312 in the embodiment shown in Figure 3, with the difference that the first network also provides the terminal device with the ability to access the first PLMN service. To this end, the contract information of the terminal device in the first network also includes service information allowing the terminal device to access the first PLMN service through the first network.
[0418] In this implementation, steps S700-1, S700-2, and the PLMN ID in step S701 may be omitted, and the first request information in S703 is further used to request access to a first service of the first PLMN through the first network. The control plane network element in the first network may determine, based on the subscription information of the terminal device in the first network, whether to allow the terminal device to access the first PLMN through the first network and service information of the first PLMN service that the terminal device is allowed to access through the first network (e.g., allowing it to access the IP Multimedia Subsystem (IMS) service of the first PLMN).
[0419] Correspondingly, the access response information sent by the subnet control plane network element to the AMF network element may also carry information indicating that the terminal device is allowed to access the first service of the first PLMN through the first network, and the AMF network element sends information to the terminal device indicating that the terminal device is allowed to access the first service of the first PLMN through the first network.
[0420] In some implementations, the information indicating that the terminal device is allowed to access the first service of the first PLMN through the first network can also be encapsulated in a transparent container, sent to the AMF network element through an access response message, and forwarded to the terminal device by the AMF network element in the first registration acceptance message.
[0421] For example, the subscription information of the terminal device in the first network may indicate that the terminal device is allowed to access the IMS service or Internet service of the first PLMN. Accordingly, the first registration accept message may indicate the IMS service of the first PLMN service that the terminal device is allowed to access.
[0422] It should be noted that allowing the terminal device to access the first PLMN through the first network means that the first network communicates with the first PLMN as a subnet, and the first PLMN opens the large network service for the first network. The terminal device can use the large network service provided by the first PLMN by accessing the first network when only the subnet switch is turned on and the large network switch is turned off.
[0423] S708: Session establishment.
[0424] The part involving subnet access in this step is consistent with steps S313 to S322 in the embodiment shown in FIG2 . In order to access the services of the PLMN through the first network, there are the following differences:
[0425] When the terminal device receives information indicating that the terminal device is allowed to access the first service of the first PLMN through the first network in step S707, the first session request message also includes information for indicating the first service. As an example, based on the service information of the PLMN that the terminal device is allowed to access indicated in the first registration accept message, for example: the IMS service that the terminal device is allowed to access in the first registration accept message, correspondingly, the first session request message includes the data network name (DNN) information and PLMN identifier corresponding to the IMS service. The PLMN identifier can be included in the DNN information, and the control plane network element of the first network can determine the service type of the PLMN that the terminal device wants to access based on the DNN information.
[0426] When a terminal device accesses the services of a PLMN through a first network, as an example, the session anchor point can be the first UPF network element in the first network. When the control plane network element of the first network configures the first UPF network element, it is necessary to configure corresponding rules so that the first UPF network element allows the terminal device to communicate with the specified PLMN. For example, the configuration rules allow the terminal device to communicate with the IMS network in the first PLMN.
[0427] In some implementations, the session anchor point can also be a specified PLMN. The control plane network element of the first network needs to select the SMF network element in the first PLMN and request the SMF network element to establish a session between the terminal device and the UPF network element in the first PLMN. That is, when the session anchor point is the first PLMN, the control plane network element in the first network also needs to establish a session between the first UPF network element in the first network and the UPF network element in the first PLMN.
[0428] For example: after a session of a terminal device is established, the control plane network element of the first network sends a large network session establishment request message to the SMF network element in the first PLMN. The message includes the DNN information corresponding to the IMS service and the second downlink tunnel information allocated by the first UPF network element. The SMF in the first PLMN selects a UPF network element that supports the service from the UPF network element of the first PLMN based on the DNN information corresponding to the IMS service, and requests the UPF network element in the first PLMN to allocate corresponding tunnel information. The UPF network element in the first PLMN transmits downlink data to the first UPF network element based on the second downlink tunnel information.
[0429] In this embodiment, the terminal device can access the subnet and the main network through the same access network device when the subnet switch and the main network switch are turned on at the same time. It can also use the main network services through the accessed subnet only when the subnet switch is turned on. For terminal devices that do not support dual-mode / multi-mode, it can improve the user experience and meet access needs.
[0430] In the embodiment shown in Figure 7, the terminal device needs to share the AMF network element when registering to the main network and the subnet at the same time. If the shared AMF network element when accessing the network is upgraded, it will affect both the subnet access and the main network access. To address this technical problem, the embodiment of the present application proposes a communication method to separate the subnet registration access and the main network registration access, thereby realizing decoupling control of the registration access process.
[0431] In order to realize separate registration access of the main network and the subnet, the embodiment of the present application provides two different mobile management network elements AMF 1 and AMF 2, wherein the terminal device accesses the subnet through AMF 1 and accesses the PLMN through AMF 2, that is, AMF 1 corresponds to the core network of the subnet, and AMF 2 corresponds to the core network of the PLMN. In some implementations, AMF 1 and AMF 2 can be the same mobile management network element. When AMF 1 and AMF 2 are the same AMF network element, two contexts of the terminal device are stored in the AMF network element, and different contexts are used for corresponding access to the subnet and access to the PLMN, that is, when AMF 1 and AMF 2 are set as the same AMF network element, the terminal device is also registered with the main network and the subnet respectively.
[0432] It can be understood that the AMF network element here is the name of the mobile management network element in the 5G communication system. In the future, there may be other naming methods for mobile management network elements. The AMF network element mentioned in this embodiment is only an exemplary description.
[0433] Since the terminal device may not be able to connect to two access network devices at the same time, the terminal device can only establish a radio resource control (RRC) layer connection with one access network device. The terminal device is connected to the AMF network elements of the two core networks through RRC. Figure 8 is a schematic diagram of the terminal device protocol stack provided by an embodiment of the present application. As shown in Figure 8, the first NAS signaling connection is the signaling connection between the terminal device and AMF 1, and the second NAS signaling connection is the signaling connection between the terminal device and AMF 2.
[0434] When a terminal device needs to send a service request, the terminal device's NAS layer generates a corresponding NAS message. This NAS message is first sent to the terminal device's RRC and then to the access network device via the RRC protocol. The access network device then sends the NAS message to the AMF network element via the interface protocol between the access network device and the AMF network element. Based on the routing information associated with the NAS message, the access network device can determine whether the NAS message is associated with AMF 1 or AMF 2, and then send the NAS message to the mobility management network element associated with the NAS message. The following, combined with Figure 8, explains in detail how to achieve decoupled control of the registration and access process.
[0435] Figure 9 is a schematic diagram of a process for a terminal device to separately access a subnet and a large network, provided by an embodiment of the present application. As shown in Figure 9, similar to the embodiment shown in Figure 7, the process for a terminal device to implement decoupled registration access is based on the embodiment shown in Figure 3, and the content related to subnet access is not repeated here. Specifically, it includes the following steps:
[0436] S900-1, terminal device configuration subnet selection list.
[0437] S900-2, access network equipment and AMF 1 interact with the subnet identifier.
[0438] S901: The access network device broadcasts a subnet identifier. Correspondingly, the terminal device receives the subnet identifier from the access network device.
[0439] S902: The terminal device selects a subnet based on the subnet selection list and the broadcast.
[0440] S903: The terminal device sends a first registration request message and identification information of the first network to the access network device. Correspondingly, the access network device receives the first registration request message and identification information of the first network from the terminal device.
[0441] S904, the access network device selects AMF 1 based on the identification information of the first network.
[0442] S905: The access network device sends a first registration request message and identification information of the first network to AMF 1. Correspondingly, AMF 1 receives the first registration request message and identification information of the first network from the access network device.
[0443] S906: The terminal device accesses the first network and establishes a session.
[0444] The above steps S900 to S905 are basically the same as steps S300 to S305 in the embodiment shown in Figure 3. Step S906 corresponds to steps S306 to S322 in the embodiment shown in Figure 3, connecting the terminal device to the subnet indicated by the first network subnet identifier and establishing a session between the terminal device and the first UPF network element in the first network. The specific process is not expanded here. The difference between the above steps and the embodiment shown in Figure 3 is that in step S903, after the access network device receives the first registration request message, it determines that the message is the first message sent to AMF 1.
[0445] As shown in Figure 8, when the terminal device needs to connect to the first network, a first NAS signaling connection is established between the terminal device and the AMF 1 serving the first network. The first NAS signaling connection is the first connection. The first NAS signaling connection is used to forward messages between the terminal device and AMF 1.
[0446] The first NAS signaling connection includes a connection between the terminal device and the access network device (i.e., an RRC connection) and a connection between the access network device and AMF 1. In the connection between the terminal device and the access network device, the first NAS signaling connection is associated with first routing information, which is the first connection identifier. After the first NAS signaling connection is established, the terminal device carries the first routing information when sending subsequent uplink NAS messages through the first NAS signaling connection, so that the access network device can determine the AMF 1 corresponding to the first NAS signaling connection based on the first routing information. When the access network device receives a downlink NAS message from AMF 1, it also carries the first routing information when sending a downlink NAS message to the terminal device, so that the terminal device can identify the NAS signaling connection corresponding to the NAS message.
[0447] When the terminal device registers to the first network for the first time (i.e., it has not registered to the first network before), or the connection state between the terminal device and the first network is idle (i.e., it has registered to the first network but the first NAS signaling connection between the terminal device and the first network has been released) and the terminal device needs to send a NAS message to the first network, the terminal device initiates the establishment of the first NAS signaling connection.
[0448] In some implementations, the first routing information is allocated by the terminal device. Accordingly, when the terminal device sends the first registration request message to the access network device in step S903, it also simultaneously sends the first routing information for associating with the first NAS signaling connection. It is understandable that if the terminal device sends the first routing information to the access network device, the access network device does not need to allocate the first routing information after receiving the initial NAS message (i.e., the first registration request message).
[0449] In some other implementations, the access network device allocates first routing information for the first NAS signaling connection and sends it to the terminal device. Accordingly, when the first registration request message is sent to the access network device in step S903, because the first routing information corresponding to the first NAS signaling connection has not yet been allocated, the terminal device does not send the first routing information associated with the first NAS signaling connection. After receiving the first registration request message, the access network device determines that the first NAS signaling connection needs to be established and allocates the first routing information.
[0450] Optionally, in step S903, when triggering the establishment of the first NAS signaling connection, the terminal device may also synchronously send an indication message for instructing the establishment of the first NAS signaling connection between the terminal device and the first network. The access network device may determine the need to establish the first NAS signaling connection based on the indication message.
[0451] Alternatively, the terminal device does not send the indication information, and the access network device may determine whether the first NAS signaling connection needs to be established based on the content of the message sent in step S903. As an example, the access network device may determine that the first NAS signaling connection needs to be established because the message sent in step S903 does not carry routing identifier information, or determine that the first NAS signaling connection needs to be established based on the first routing identifier information in the message in step S903. That is, when the access network device determines that there is no NAS signaling connection associated with the routing identifier information in the message in step S903, it determines that the first NAS signaling connection needs to be established.
[0452] It is understandable that after receiving the initial NAS message in S903, if the access network device determines that the first NAS signaling connection needs to be established, the access network device sends the first routing information to the terminal device. The access network device can send a dedicated RRC message to the terminal device after receiving the initial NAS message in S903, and the RRC message carries the first routing message. It can also carry the first routing information to the terminal device during the subsequent interaction with the terminal device in the process triggered by the initial NAS message in step S903 above. For example, the first routing information can be carried in the downlink RRC message of the first NAS message sent by AMF 1 to the terminal device or in the first downlink RRC message after AMF 1 sends the initial context of the terminal device to the access network device.
[0453] It should be noted that the access network device needs to save the first routing information in the context of the terminal device, and at the same time save the corresponding AMF 1 information in the context.
[0454] Through the above steps, the terminal device has been connected to the corresponding subnet. The following describes how the terminal device connects to the corresponding PLMN.
[0455] S907, the terminal device configures the PLMN selection list.
[0456] S908: The access network device broadcasts the PLMN ID. Correspondingly, the terminal device receives the PLMN ID from the access network device.
[0457] S909: The terminal device selects a large network based on the PLMN selection list and broadcast.
[0458] The above steps S907 to S909 are similar to steps S700 to S702 in the embodiment shown in FIG7 . In order to realize the decoupling operation of subnet access and large network access, this embodiment separates the execution operations related to large network access from the subnet access process and selects the PLMN independently.
[0459] S910: The terminal device sends a second registration request message and the ID of the first PLMN to the access network device. Correspondingly, the access network device receives the second registration request message and the ID of the first PLMN from the terminal device.
[0460] The second registration request message is used to request the terminal device to access the first PLMN. The first PLMN is the PLMN selected by the terminal device in step S909. The terminal device sends the ID of the first PLMN to the access network device.
[0461] It should be noted that the terminal device has been connected and registered to the subnet in steps S900 to S906, and the RRC connection of the terminal device, that is, the signaling connection between the terminal device and the access network device may be in a connected state. At this time, if the terminal device sends a second registration request message to the access network device, the RRC message needs to be enhanced so that the RRC message can also carry the second registration request message of the NAS layer and the ID information of the first PLMN when in the connected state.
[0462] Since this step is the first NAS message between the terminal device and the first PLMN, i.e., the initial NAS message, the terminal device needs to establish a second NAS connection with the AMF 2 serving the first PLMN. The second NAS signaling connection is the second connection. The second NAS signaling connection is used to forward messages between the terminal device and AMF 2.
[0463] The second NAS signaling connection includes a connection between the terminal device and the access network device (i.e., an RRC connection) and a connection between the access network device and AMF 2. In the connection between the terminal device and the access network device, the second NAS signaling connection is associated with second routing information, which is a second connection identifier. After the second NAS signaling connection is established, the terminal device carries the second routing information when sending subsequent uplink NAS messages through the second NAS signaling connection, so that the access network device can determine the AMF 2 corresponding to the second NAS signaling connection based on the second routing information. When the access network device receives a downlink NAS message from AMF 2, it also carries the second routing information when sending a downlink NAS message to the terminal device, so that the terminal device can identify the NAS signaling connection corresponding to the NAS message.
[0464] When the terminal device registers to the first PLMN for the first time (i.e., it has not been registered to the first PLMN before), or the connection state between the terminal device and the first PLMN is idle (i.e., it has been registered to the first PLMN but the second NAS signaling connection between the terminal device and the first PLMN has been released) and the terminal device needs to send a NAS message to the first PLMN, the terminal device initiates the establishment of the second NAS signaling connection.
[0465] In some implementations, the second routing information is allocated by the terminal device. Accordingly, when the terminal device sends the second registration request message to the access network device in step S910, it also simultaneously sends the second routing information for associating the second NAS signaling connection. It is understandable that if the terminal device sends the second routing information to the access network device, the access network device does not need to allocate the second routing information after receiving the initial NAS message (i.e., the second registration request message).
[0466] In some other implementations, the access network device allocates second routing information for the second NAS signaling connection and sends it to the terminal device. Accordingly, when the second registration request message is sent to the access network device in step S903, because the second routing information corresponding to the second NAS signaling connection has not yet been allocated, the terminal device does not send the second routing information associated with the second NAS signaling connection. After receiving the second registration request message, the access network device determines that a second NAS signaling connection needs to be established and allocates the second routing information.
[0467] Similar to step S903, in step S910, when triggering the establishment of the second NAS signaling connection, the terminal device may also synchronously send an indication message for instructing the establishment of the second NAS signaling connection between the terminal device and the first PLMN. The access network device may determine the need to establish the second NAS signaling connection based on the indication message.
[0468] Alternatively, the terminal device does not send the indication information, and the access network device may determine whether a second NAS signaling connection needs to be established based on the message sent in step S910. As an example, the access network device may determine that the NAS message in step S910 is an initial NAS message based on the absence of routing identifier information, thereby determining that a second NAS signaling connection needs to be established. Alternatively, based on the second routing identifier information in the message in step S910, when the access network device determines that there is no NAS signaling connection associated with the routing identifier information, it may determine that a second NAS signaling connection needs to be established.
[0469] It is understandable that after receiving the initial NAS message in S910, if the access network device determines that a second NAS signaling connection needs to be established, the access network device sends the second routing information to the terminal device. The access network device may send a dedicated RRC message to the terminal device after receiving the initial NAS message in S910, and the RRC message carries the second routing information. The access network device may also piggyback the second routing information during the subsequent interaction with the terminal device in the process triggered by the initial NAS message in step S910 above, and pass it to the terminal device. For example, the second routing information may be carried in the downlink RRC message of the first NAS message sent by AMF 2 to the terminal device or in the first downlink RRC message after AMF 2 sends the initial context of the terminal device to the access network device.
[0470] The access network device also needs to save the second routing information in the context of the terminal device, and also save the corresponding AMF 2 information in the context.
[0471] S911, the access network device selects AMF 2 based on the PLMN ID.
[0472] In this step, when a signaling connection already exists with AMF 1, the access network device selects a new mobility management network element for the terminal device based on the PLMN ID, and AMF 2 is the mobility management network element of the first PLMN indicated by the serving PLMN ID.
[0473] S912: The access network device sends a second registration request message and the ID of the first PLMN to AMF 2. Correspondingly, AMF 2 receives the second registration request message and the ID of the first PLMN from the access network device.
[0474] S913: The terminal device accesses the first PLMN and establishes a session.
[0475] In this step, the terminal device is connected to the first PLMN, and a session is established between the terminal device and the UPF network element in the first PLMN. The specific process of the terminal device connecting to the large network will not be expanded here.
[0476] S914: The context of the access network device saves the context of the first core network connection and the context of the second core network connection at the same time.
[0477] In this step, there is an RRC context in the access network device, which is associated with the context of the core network connection corresponding to different AMF network elements. The context of each core network connection includes:
[0478] Routing identifier information corresponding to the NAS signaling connection corresponding to the core network connection;
[0479] Information on the interface protocol between the access network device and the AMF network element. Taking 5G as an example, the information on the interface protocol may include: identifiers assigned by the access network device and the AMF network element to the terminal device respectively, such as the identifier (RAN UE NGAP ID) and AMF UE NGAP ID assigned by the radio access network (RAN) to the terminal device in the next generation application protocol (NGAP), the N2 link information associated with the signaling connection, and N2 link information such as the IP addresses of the AMF network element and the access network device.
[0480] The session context information of the core network connection may include any one of: a QoS parameter corresponding to the session, a tunnel identifier, a session identifier, etc.
[0481] S915: The access network device releases the RRC connection.
[0482] When the access network device detects that the core network connections corresponding to AMF 1 and AMF 2 of the terminal device have no data to send, the access network device can release the RRC connection with the terminal device, so that the terminal device enters the idle state. It should be noted that no data here refers to no signaling messages (such as NAS signaling) and user-plane data. In some implementations, the access network device may also simultaneously release all context information about the terminal device and the signaling link created for the terminal device between the access network device and AMF 1 and AMF 2. If a session is created, the access network device will also release the tunnel between the core network user-plane network element and the session.
[0483] Initiating the terminal device into idle state when there is no data to be sent can release the air interface and save energy for the terminal device.
[0484] After the terminal device enters the idle state in step S915, when the terminal device needs to use the subnet service again, the following steps need to be performed:
[0485] S916, the terminal device sends a message to the access network device and establishes an RRC connection.
[0486] In the idle state, the terminal device needs to first send a message to the access network device to establish an RRC connection with the access network device, so that the terminal device enters the RRC connection state from the idle state.
[0487] S917: The terminal device sends an initial NAS message to the access network device. Correspondingly, the access network device receives the initial NAS message from the terminal device.
[0488] In this step, the initial NAS message (such as a subnet service request message) sent by the terminal device to the access network device is used to activate the subnet connection. At this time, the terminal device can also send AMF 1 information or a first identifier (subnet identifier) to the access network device. Taking 5G as an example, the identifier of the AMF network element is the AMF network element identifier (globally unique AMF identifier, GUAMI), and the mobility management network element corresponding to GUAMI is AMF 1.
[0489] It should be noted that when the terminal device enters the idle state, it is equivalent to the first NAS signaling connection being released in step S915. In this step, the first NAS signaling connection will be re-established. The specific establishment process can be found in the aforementioned steps and will not be repeated here.
[0490] S918, the access network device selects AMF 1 according to GUAMI or network identifier (such as the first identifier).
[0491] Among them, the mobility management network element corresponding to GUAMI is AMF 1, so the access network device can select AMF 1 according to the GUAMI carried in the subnet service request message. After the access network device determines that the mobility management network element is AMF 1, it can activate the original connection with AMF 1. The activation process is not explained here.
[0492] It should be noted that the terminal device activated the subnet connection in steps S917 to S918. Similarly, when the terminal device needs to activate the connection with the PLMN, the terminal device can send a large network service request message to the access network device and send the GUAMI of AMF 2 for the access network device to select AMF 2 from the mobile management network element. The specific process is similar to steps S917 to S918 and will not be repeated here.
[0493] In this embodiment, the terminal device can separate subnet registration access from macro-network registration access, implement decoupling control of the registration access process, avoid sharing mobility management network elements, and enhance the isolation between subnet registration access and macro-network registration access.
[0494] Figure 10 is a schematic diagram of the structure of a communication device provided by an embodiment of the present application. As shown in Figure 10, the device 1000 of this embodiment may include: a communication module 1001 and a processing module 1002. It should be understood that the device 1000 is embodied in the form of a functional module. The term "module" may refer to a software module, or may refer to an application-specific integrated circuit, an electronic circuit, a processor (such as a shared processor, a dedicated processor, or a group processor, etc.) and memory for executing one or more software or firmware programs, a combined logic circuit, and / or other suitable components that support the described functions.
[0495] The apparatus 1000 has the function of implementing the various processes and / or steps implemented by the terminal device, access network device, and various network elements in any of the aforementioned method embodiments. The aforementioned functions may be implemented by software or by hardware executing the corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions.
[0496] Figure 11 is a schematic diagram of the structure of a communication device provided in another embodiment of the present application. The device 1100 shown in Figure 11 can be used to execute any of the aforementioned methods performed by the communication device.
[0497] As shown in Figure 11 , the apparatus 1100 of this embodiment includes a memory 1101, a processor 1102, a communication interface 1103, and a bus 1104. The memory 1101, the processor 1102, and the communication interface 1103 are connected to each other via the bus 1104.
[0498] The memory 1101 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1101 may store a program. When the program stored in the memory 1101 is executed by the processor 1102, the processor 1102 is configured to execute any of the aforementioned methods.
[0499] The processor 1102 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit, or one or more integrated circuits to execute related programs.
[0500] The processor 1102 may also be an integrated circuit chip with signal processing capabilities. In the implementation process, the various related steps in the embodiment of the present application may be completed by hardware integrated logic circuits in the processor 1102 or software instructions.
[0501] The processor 1102 may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The processor 1102 may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor.
[0502] The steps of the method disclosed in conjunction with the embodiments of the present application can be directly implemented as being executed by a hardware decoding processor, or can be implemented by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in memory 1101, and processor 1102 reads the information in memory 1101 and, in combination with its hardware, completes the functions required to be performed by the units included in the device of the present application.
[0503] The communication interface 1103 may use, but is not limited to, a transceiver or other transceiver device to implement communication between the apparatus 1100 and other devices or apparatuses.
[0504] The bus 1104 may include a path for transmitting information between various components of the device 1100 (eg, the memory 1101 , the processor 1102 , and the communication interface 1103 ).
[0505] An embodiment of the present application further provides a computer-readable storage medium, in which computer instructions are stored. When a processor executes the computer instructions, each step of the method in the above embodiment is implemented.
[0506] An embodiment of the present application further provides a computer program product, including computer instructions, which, when executed by a processor, implement the various steps of the method in the above embodiment.
[0507] It should be noted that the modules or components shown in the above embodiments may be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits, or one or more microprocessors, or one or more field programmable gate arrays. For another example, when a module is implemented by a processing element calling program code, the processing element may be a general-purpose processor, such as a central processing unit or other processor that can call program code, such as a controller. For another example, these modules may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0508] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, software modules or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).
[0509] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the contents disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0510] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A communication method, applied to a first terminal device or a chip in the first terminal device, characterized in that: The method comprises: Receiving identification information of a first network from an access network device, wherein the access network device supports accessing a terminal device to the first network; In a case where the first list of the first terminal device includes identification information of the first network, a first request message and identification information of the first network are sent to the access network device, wherein the first request message is used to request access of the first terminal device to the first network, and the first list includes identification information of one or more non-public land mobile networks PLMNs.
2. The method according to claim 1, characterized in that The first terminal device includes a first logical interface, the first logical interface is used to access a non-PLMN network, and the first logical interface is configured with the first list; The sending a first request message and the identification information of the first network to the access network device when the first list of the first terminal device includes the identification information of the first network includes: When the first logical interface is in an open state and the first list includes identification information of the first network, the first request message and the identification information of the first network are sent to the access network device.
3. The method according to claim 1 or 2, characterized in that: The method further comprises: receiving identification information of a third network from the access network device, wherein the first list includes the identification information of the third network; The sending a first request message and the identification information of the first network to the access network device when the first list of the first terminal device includes the identification information of the first network includes: In a case where the first list includes identification information of the first network and the priority of the first network is higher than the priority of the third network, the first request message and the identification information of the first network are sent to the access network device.
4. The method according to any one of claims 1 to 3, characterized in that The first request message includes a first identifier and / or a second identifier, the first identifier is an identifier of the first terminal device in the first network, the second identifier is an identifier of the terminal device in a second network, and the second network is a PLMN network.
5. The method according to claim 4, characterized in that The first terminal device includes a second logical interface, the second logical interface is used to access the second network, and the second identifier is associated with the second logical interface; The first request message includes the second identifier, including: When the first logical interface is associated with the second logical interface, or the first network is associated with the second logical interface, the first request message includes the second identifier.
6. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Send a second identifier, where the second identifier is the identifier of the first terminal device in a second network, and the second network is a PLMN network.
7. The method according to claim 6, characterized in that Before sending the second identifier, the method further includes: Receive first information, where the first information is used to request an identification of the first terminal device in the second network.
8. The method according to claim 6 or 7, characterized in that: The first terminal device includes a second logical interface, the second logical interface is used to access the second network, and the second identifier is associated with the second logical interface; The sending the second identifier includes: When the first logical interface is associated with the second logical interface, or the first network is associated with the second logical interface, the second identifier is sent.
9. The method according to claim 5 or 8, characterized in that: The method further comprises: Obtain first indication information, where the first indication information is used to indicate that the first logical interface is associated with the second logical interface, or the first indication information is used to indicate that the first network is associated with the second logical interface.
10. The method according to any one of claims 1 to 9, characterized in that The first request message also includes second information, where the second information is used to indicate the network slice and / or logical network that the first terminal device in the first network requests to access; The method further comprises: Receive third information, where the third information is used to indicate the network slices and / or logical networks that the first terminal device in the first network is allowed to access.
11. The method according to any one of claims 1 to 10, characterized in that: The method further comprises: A first session request message is sent, where the first session request message is used to request establishment of a session between the first terminal device and a user plane network element in the first network.
12. The method according to claim 11, characterized in that The first session request message includes an identifier of a network slice and / or a logical network, and the network slice and / or logical network is the network slice and / or logical network to which the first terminal device in the first network requests access.
13. The method according to any one of claims 1 to 12, characterized in that The first request message is also used to request access to a first service of a public land mobile network PLMN through the first network; Wherein, the method further comprises: receiving fourth information, where the fourth information is used to indicate whether the first terminal device is allowed to access the first service of the PLMN through the first network; In a case where the fourth information is used to indicate that the first terminal device is allowed to access a first service of the PLMN through the first network, the first session request message further includes information used to indicate the first service.
14. A communication method, applied to a mobile management network element, characterized in that: The method comprises: Receiving a first request message and identification information of a first network from an access network device, wherein the first request message is used to request that a first terminal device be connected to a first network, wherein the first network is a non-PLMN network, and the access network device and the mobility management network element support connecting the terminal device to the first network; Sending a second request message to a control plane network element in the first network according to the identification information of the first network, where the second request message is used to request that the first terminal device be connected to the first network; Receive a first response message from the control plane network element, where the first response message is used to indicate whether the first terminal device is allowed to access the first network.
15. The method according to claim 14, characterized in that The sending a second request message to a control plane network element in the first network includes: When the authentication of the first terminal device is successful, the second request message is sent to the control plane network element, and the authentication of the first terminal device is based on a second identifier, which is the identifier of the first terminal device in a second network, and the second network is a PLMN network.
16. The method according to claim 15, characterized in that The first request message includes the second identifier; or, The method further comprises: Sending a message for requesting an identification of the first terminal device in the second network; The second identifier is received.
17. The method according to claim 15 or 16, characterized in that The sending the second request message to the control plane network element when the authentication of the first terminal device is successful includes: When the authentication for the first terminal device is successful, obtaining a first identifier, where the first identifier is an identifier of the first terminal device in the first network, and the first identifier is an external identifier of the first terminal device; The second request message is sent to the control plane network element, where the second request message includes the first identifier.
18. The method according to any one of claims 14 to 16, characterized in that The first request message includes a first identifier, where the first identifier is an identifier of the first terminal device in the first network, and the first identifier is an external identifier of the first terminal device; The sending a second request message to a control plane network element in the first network includes: When the verification of the first identifier is successful, the second request message is sent to the control plane network element.
19. The method according to claim 18, characterized in that The second request message includes at least one of the following: the first identifier, or information indicating that the verification of the first identifier is successful.
20. The method according to any one of claims 17 to 19, characterized in that Before sending the second request message to the control plane network element, the method further includes: Sending a message for requesting an external identifier of the first terminal device to a core network element in a second network, where the core network element in the second network is used to manage the external identifier of the terminal device belonging to the second network, and the second network is a network deployed by a home operator of the first terminal device; Receiving an external identifier of the first terminal device from the core network element; The verification of the first identifier is successful, including: The external identifier of the first terminal device from the core network element includes the first identifier.
21. The method according to any one of claims 14 to 20, characterized in that The method further comprises: A first session request message is received from the first terminal device, where the first session request message is used to request establishment of a session between the first terminal device and a first user plane network element of the first network.
22. The method according to claim 21, characterized in that The method further comprises: triggering, according to the first session request message, a second user plane network element to allocate uplink tunnel information and downlink tunnel information for the session; receiving first uplink tunnel information and first downlink tunnel information from the second user plane network element, wherein the first uplink tunnel information is used to send uplink data of the session to the second user plane network element, and the first downlink tunnel information is used to send downlink data of the session to the second user plane network element; Sending a second session request message to the control plane network element, where the second session request message is used to request to establish a session between the first terminal device and the first user plane network element, and the second session request message includes the first downlink tunnel information; receiving second uplink tunnel information from the control plane network element, where the second uplink tunnel information is used to send uplink data of the session to the first user plane network element; Send the first uplink tunnel information to the access network device.
23. The method according to any one of claims 14 to 22, characterized in that The second request message includes a first terminal identifier, and the first terminal identifier is used to indicate the first terminal device in the mobility management network element.
24. The method according to claim 23, characterized in that The first response message includes a second terminal identifier, and the second terminal identifier is used to indicate the first terminal device in the control plane network element.
25. The method according to claim 24, characterized in that The method further comprises: receiving a downlink non-access layer NAS message and the first terminal identifier from the control plane network element, and sending the downlink NAS message to the first terminal device according to the first terminal identifier; and / or, Receive an uplink NAS message from the first terminal device, and send the uplink NAS message and the second terminal identifier to the control plane network element.
26. A communication method, applied to a control plane network element in a first network, characterized in that: The method comprises: receiving a second request message from a mobility management network element, where the second request message is used to request that a first terminal device be connected to the first network, and the mobility management network element supports connecting the terminal device to the first network; Determining whether to allow the first terminal device to access the first network according to the subscription information of the first terminal device in the first network; A first response message is sent to the mobility management network element, where the first response message is used to indicate whether the first terminal device is allowed to access the first network.
27. The method according to claim 26, characterized in that The second request message is further used to request access to a first service of the PLMN through the first network, the subscription information of the first terminal device in the first network includes second indication information, and the second indication information is used to indicate whether the first terminal device is allowed to access the service of the PLMN through the first network; The determining whether to allow the first terminal device to access the first network according to the subscription information of the first terminal device in the first network includes: Determine whether to allow the first terminal device to access the first service of the PLMN through the first network according to the second request message and the second indication information.
28. The method according to claim 27, characterized in that The first response message also includes third information, where the third information is used to indicate whether the first terminal device is allowed to access the first service of the PLMN through the first network.
29. The method according to any one of claims 26 to 28, characterized in that Before determining whether to allow the first terminal device to access the first network according to the subscription information of the first terminal device in the first network, the method further includes: The subscription information of the first terminal device in the first network is obtained based on a first identifier, where the first identifier is an identifier of the first terminal device in the first network.
30. The method according to claim 29, characterized in that The second request message includes the first identifier; or, The method further comprises: Sending a message for requesting an identification of the first terminal device in the first network; The first identifier is received.
31. The method according to claim 29 or 30, characterized in that The first identifier is an external identifier of the first terminal device; The acquiring, based on the first identifier, the subscription information of the first terminal device in the first network includes: When the verification of the first identifier is successful, the subscription information of the first terminal device in the first network is obtained based on the first identifier.
32. The method according to claim 31, characterized in that The verification of the first identifier is successful, including: The second request message also includes information indicating that verification of the first identifier is successful.
33. The method according to claim 31, characterized in that Before acquiring the subscription information of the first terminal device in the first network based on the first identifier, the method further includes: Sending a message for requesting an external identifier of the first terminal device to a core network element in a second network, where the core network element in the second network is used to manage the external identifier of the terminal device belonging to the second network, and the second network is a network deployed by a home operator of the first terminal device; Receiving an external identifier of the first terminal device from the core network element; The verification of the first identifier is successful, including: The external identifier of the first terminal device from the core network element includes the first identifier.
34. The method according to claim 32, characterized in that Before acquiring the subscription information of the first terminal device in the first network based on the first identifier, the method includes: Sending a message for requesting verification of the first subscription identifier to a core network element in a second network, where the core network element in the second network is used to manage an external identifier of a terminal device belonging to the second network, and the second network is a network deployed by a home operator of the first terminal device; receiving a third response message from the core network element, where the third response message is used to indicate a result of verification of the first identifier; The verification of the first identifier is successful, including: The third response message is used to indicate that the verification of the first identifier is successful.
35. The method according to any one of claims 31 to 34, characterized in that Before the verification of the first identifier succeeds, the method further includes: The first terminal device is authenticated based on a second identifier, where the second identifier is an identifier of the first terminal device in a second network, and the second network is a network deployed by a home operator of the first terminal device.
36. The method according to claim 35, characterized in that The authenticating the first terminal device based on the second identifier includes: Acquire the second identifier of the first terminal device; Sending a first authentication request message to a core network element in the second network, where the core network element in the second network is used to authenticate a terminal device belonging to the second network, where the first authentication request message is used to request authentication of the first terminal device, and where the first authentication request message includes the second identifier; Receiving a first authentication response message from the core network element, where the first authentication response message includes first authentication information of the first terminal device; Sending a second authentication request message to the first terminal device according to the first authentication information; receiving a second authentication response message from the first terminal device, wherein the second authentication response message includes second authentication information of the first terminal device; Authenticate the first terminal device based on the first authentication information and the second authentication information; or, Sending a third authentication request message to the core network element, where the third authentication request message carries the second authentication information; Receive a third authentication response message from the core network element, where the third authentication response message is used to indicate the authentication result of the first terminal device.
37. The method according to claim 36, characterized in that The acquiring the second identifier of the first terminal device includes: Acquire the second identifier from the second request message; or, Sending a message for requesting an identification of the first terminal device in the second network; The second identifier is received.
38. The method according to any one of claims 29 to 37, characterized in that Before acquiring the subscription information of the first terminal device in the first network based on the first identifier, the method further includes: The first terminal device is authenticated using the first identifier.
39. The method according to claim 38, characterized in that The using the first subscription identifier to perform access authentication on the first terminal device to access the first network includes: When the preset conditions are met, the first signing identifier is used to authenticate the first terminal device, and the preset conditions include at least one of the following conditions: the signing information of the first terminal device in the first network requires the use of the first identifier to authenticate access to the first terminal device, the second request message does not include the verified first identifier, the first identifier is a private identifier in the first network, or the control plane network element requires the use of the first identifier to authenticate the terminal device accessing the first network.
40. The method according to any one of claims 26 to 39, characterized in that The second request message also includes fifth information, where the fifth information is used to indicate the location of the first terminal device, and the subscription information of the first terminal device in the first network includes third indication information, where the third indication information is used to indicate an area of the first network that the first terminal device is allowed to access; The determining whether to allow the first terminal device to access the first network according to the subscription information of the first terminal device in the first network includes: In a case where the location of the first terminal device belongs to the area indicated by the third indication information, it is determined that the first terminal device is allowed to access the first network.
41. The method according to any one of claims 26 to 40, characterized in that The second request message also includes first information, where the first information is used to indicate the network slice and / or logical network that the first terminal device in the first network requests to access, and the subscription information of the first terminal device in the first network includes fourth indication information, where the fourth indication information is used to indicate the network slice and / or logical network that the first terminal device in the first network is allowed to access; The determining whether to allow the first terminal device to access the first network according to the subscription information of the first terminal device in the first network includes: When the network slice and / or logical network requested for access in the first information is included in the network slice and / or logical network allowed for access indicated by the fourth indication information, the network slice and / or logical network allowed for access by the first terminal device in the first network is determined.
42. The method according to claim 41, characterized in that The first response message also includes second information, and the second information is used to indicate the network slices and / or logical networks that the first terminal device in the first network is allowed to access.
43. The method according to any one of claims 26 to 42, characterized in that The first response message includes a second terminal identifier, and the second terminal identifier is used to indicate the first terminal device in the control plane network element.
44. The method according to any one of claims 40 to 43, characterized in that The method further comprises: receiving a second session request message from the mobility management network element, where the second session request message is used to request to establish a session between the first terminal device and the first user plane network element of the first network, where the second session request message includes first downlink tunnel information, where the first downlink tunnel information is used to send downlink data of the session to a second user plane network element in a third network, where the third network is a network deployed by a home operator of the mobility management network element; Sending, according to the session subscription information of the first terminal device in the first network, to the first user plane network element a message for requesting the first user plane network element to allocate uplink tunnel information for the session; receiving second uplink tunnel information from the first user plane network element, where the second uplink tunnel information is used to send uplink data of the session to the first user plane network element; Send the second uplink tunnel information to the mobility management network element.
45. The method according to claim 44, characterized in that The second session request message also includes sixth information, where the sixth information is used to indicate an identifier of a network slice and / or a logical network that the first terminal device in the first network requests to access, and the session subscription information of the first terminal device in the first network includes fifth indication information, where the fifth indication information is used to indicate a network slice and / or a logical network that the first terminal device in the first network is allowed to access; The sending a third session request message to the first user plane network element according to the session subscription information of the first terminal device in the first network includes: When the network slice and / or logical network requested for access in the sixth information is included in the network slice and / or logical network allowed for access indicated by the fifth indication information, the third session request message is sent to the first user plane network element.
46. The method according to claim 45, characterized in that The second session request message also includes information for instructing the first user plane network element to filter non-allowed data packets.
47. The method according to any one of claims 44 to 46, characterized in that The second session request message also includes the first identifier or the second terminal identifier; Before sending the third session request message to the first user plane network element according to the session subscription information of the first terminal device in the first network, the method further includes: The session subscription information of the first terminal device in the first network is obtained based on the first identifier or the second terminal identifier.
48. The method according to any one of claims 44 to 47, characterized in that The third session request message also includes information for indicating that the first terminal device is allowed to access the first service of the PLMN.
49. A communication method, applied to an access network device, characterized in that: The method comprises: receiving a first message from a first terminal device, and triggering establishment of a first connection according to the first message, where the first connection is a connection between the first terminal device and a first mobility management network element; A first connection identifier is sent to the first terminal device, where the first connection identifier is used to indicate the first connection.
50. The method according to claim 49, characterized in that The first message includes sixth indication information, where the sixth indication information is used to indicate establishing a connection between the first terminal device and the first mobility management network element; The triggering establishment of the first connection according to the first message includes: Establishment of the first connection is triggered according to the sixth indication information.
51. The method according to claim 49, characterized in that The triggering establishment of the first connection according to the first message includes: In a case where the first message does not include the first connection identifier, establishment of the first connection is triggered.
52. The method according to claim 49, characterized in that The triggering establishment of the first connection according to the first message includes: When the first message includes the first connection identifier and the access network device does not save the corresponding relationship between the first terminal device and the first connection identifier, establishment of the first connection is triggered.
53. The method according to any one of claims 49 to 51, characterized in that The method further comprises: assigning the first connection identifier to the first connection; Send the first connection identifier to the first terminal device.
54. The method according to any one of claims 49 to 53, characterized in that The method further comprises: Save the correspondence between the first terminal device and the first connection identifier.
55. The method according to any one of claims 49 to 54, characterized in that The first message further includes information for indicating the first network; The method further comprises: The first mobility management network element is selected according to the first message, and the first mobility management network element supports access of the terminal device to the first network.
56. The method according to any one of claims 49 to 55, characterized in that The first message also includes a first NAS message, and the first NAS message is an access request message or a service request message.
57. The method according to any one of claims 49 to 56, characterized in that The first connection is used to forward messages between the first terminal device and the first network; The method further comprises: receiving a second message from the first terminal device, and triggering establishment of a second connection according to the second message, where the second connection is a connection between the first terminal device and a second mobility management network element, and the second connection is used to forward messages between the first terminal device and a second network, where the second network and the first network are different networks; A second connection identifier is sent to the first terminal device, where the second connection identifier is used to indicate the second connection.
58. The method according to claim 57, characterized in that Before the receiving the first message from the first terminal device and the receiving the second message from the first terminal device, the method further includes: Establishing a third connection between the first terminal device and the access network device; The receiving a first message from a first terminal device includes: receiving the first message from the first terminal device through the third connection; The receiving a second message from the first terminal device includes: The second message is received from the first terminal device through the third connection.
59. The method according to claim 58, characterized in that The second message also includes a second NAS message, and the second NAS message is an access request message or a service request message.
60. The method according to claim 58 or 59, characterized in that The first connection is associated with at least one first user plane link, and the second connection is associated with at least one second user plane link, the first user plane link is used to transmit user plane data between the first terminal device and the first network, and the second user plane link is used to transmit user plane data between the first terminal device and the second network; The method further comprises: In a case where there is no data transmission on the at least one first user plane link and no data transmission on the at least one second user plane link, the third connection is released.
61. A communication method, applied to a first terminal device or a chip in the first terminal device, characterized in that: The method comprises: Sending a first message to an access network device, where the first message is used to trigger establishment of a first connection, where the first connection is a connection between the first terminal device and a first mobility management network element; A first connection identifier is received from the access network device, where the first connection identifier is used to indicate the first connection.
62. The method according to claim 61, characterized in that The first message includes sixth indication information, and the sixth indication information is used to indicate establishment of a connection between the first terminal device and the first mobility management network element.
63. The method according to claim 61, characterized in that The sending a first message to the access network device includes: assigning the first connection identifier to the first connection; A first message is sent to the access network device, where the first message includes the first connection identifier.
64. The method according to any one of claims 61 to 63, characterized in that The first message also includes information for indicating the first network, and the first mobility management network element supports access of the terminal device to the first network.
65. The method according to any one of claims 61 to 64, characterized in that The first message also includes a second NAS message, and the second NAS message is a registration request message or a service request message.
66. The method according to any one of claims 61 to 65, characterized in that The first connection is used to forward messages between the first terminal device and the first network; The method further comprises: Sending a second message to the access network device, where the second message is used to trigger the establishment of a second connection, where the second connection is a connection between the first terminal device and a second mobility management network element, where the second connection is used to forward messages between the first terminal device and a second network, where the second network and the first network are different networks; A second connection identifier is received from the access network device, where the second connection identifier is used to indicate the second connection.
67. The method according to claim 66, characterized in that The sending a first message to the access network device includes: The access network device sends the first message via a third connection, wherein the third connection is a connection between the first terminal device and the access network device The sending a second message to the access network device includes: The second message is sent to the access network device through the third connection.
68. A communication device, characterized in that: The communication device includes a functional module for implementing the communication method according to any one of claims 1 to 67.
69. A communication device, characterized in that: include: Processor and memory; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the communication device performs the communication method according to any one of claims 1 to 67.
70. A communication system, characterized in that: Includes mobile management network elements and control plane network elements; The mobility management network element is used to execute the communication method as described in any one of claims 14 to 25, and the control plane network element is used to execute the communication method as described in any one of claims 26 to 48.
71. The system according to claim 70, characterized in that The system further comprises a terminal device, wherein the terminal device is configured to execute the communication method according to any one of claims 1 to 13.
72. A communication system, characterized in that: It comprises an access network device and a terminal device, wherein the access network device is used to execute the communication method as described in any one of claims 49 to 60, and the terminal device is used to execute the communication method as described in any one of claims 61 to 67.
73. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the communication method according to any one of claims 1 to 67.
74. A computer program product, characterized in that It comprises a computer program, which, when executed by a processor, implements the communication method according to any one of claims 1 to 67.
Citation Information
Patent Citations
Communication method and related device
CN120111624A
Network selection and service continuity in non-public networks
CN112970291A
Communication method and device
WO2020087327A1
Method for data transmission, communication device, and communication system
WO2021073314A1
Methods and apparatuses for enabling a user equipment to register with multiple public land mobile networks and non-public networks using the same access type
WO2023285224A1