Communication method and related apparatus

By configuring a subnet selection list on the terminal device and broadcasting subnet identifier information on the access network device, the problem of users from different operators being unable to access the same subnet is solved, realizing the service requirement of users accessing the same subnet, improving access security and management convenience, and saving terminal device energy.

WO2025119062A9PCT designated stage Publication Date: 2026-05-21HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2024-11-27
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Users from different network operators cannot access the same subnet simultaneously, resulting in users being unable to meet their service needs.

Method used

By configuring a subnet selection list on the terminal device and broadcasting subnet identification information on the access network device, the terminal device is allowed to select and request access to the same subnet, reducing the association between the terminal device and the user identification module, prioritizing the selection of high-priority networks, and accessing them through logical interfaces.

Benefits of technology

This allows users from different operators to access the same subnet, meeting business needs, saving terminal equipment energy, improving access security and management convenience, and avoiding data interference.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024135071_21052026_PF_FP_ABST
    Figure CN2024135071_21052026_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a related apparatus. In the communication method provided in the present application, a first list configured by a first terminal device comprises a network identifier of at least one non-PLMN network, and when network identifier information broadcast by an access network device and received by the first terminal device is comprised in the first list, the first terminal device requests from the access network device an access to the broadcast non-PLMN network. By means of the method, there is no need to consider home operators of the first terminal device and the access network device, such that terminal devices belonging to different operators can share the access network device and access the same non-PLMN network.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods and related devices

[0001] This application claims priority to Chinese Patent Application No. 202311654012.1, filed on December 4, 2023, entitled "Communication Method and Related Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to a communication method and related apparatus. Background Technology

[0003] In different locations such as enterprises, campuses, and stadiums, users have different service needs for communication networks. To improve user experience, dedicated networks, also known as subnets, can be deployed for different locations, providing users with better services. However, subnets only support access for subscribers of the operator that deployed the subnet. How users belonging to different operators can access the same subnet becomes a new technical problem. Summary of the Invention

[0004] This application provides a communication method and related apparatus, which aims to enable subnet users belonging to different network operators to access the same subnet in a scenario, thereby meeting the service needs of the subnet users.

[0005] In a first aspect, embodiments of this application provide a communication method applied to a first terminal device, the method comprising:

[0006] The device receives identification information of a first network from an access network device, which supports accessing the terminal device to the first network. If the first list of the first terminal devices includes the identification information of the first network, the device sends a first request message and the identification information of the first network to the access network device. The first request message is used to request access to the first network for the first terminal device. The first list includes the identification information of one or more non-public land mobile networks (PLMNs).

[0007] When the first terminal device selects a subnet based on the first list and the broadcast subnet identifier information, it does not need to consider the PLMN ID configured in the SIM card installed on the first terminal device and the PLMN ID broadcast by the access network. Even if the first terminal device and the access network device belong to different operators, the first terminal device can still initiate a request to the access network device to access the subnet.

[0008] In some implementations, the first terminal device includes a first logical interface, which is used to access a non-PLMN network, and the first logical interface is configured with a first list.

[0009] If the first list of the first terminal devices includes the identification information of the first network, a first request message and the identification information of the first network are sent to the access network device, including:

[0010] When the first logical interface is in the open state and the first list includes the identification information of the first network, a first request message and the identification information of the first network are sent to the access network device.

[0011] By configuring the first list through the first logical interface used to access the first network, the correlation between the first list and the user identification module can be reduced. The first terminal device has a switch for controlling the opening and closing of the first logical interface. Turning this switch off can prevent the first terminal device from performing network searches when it cannot access the subnet, thus avoiding unnecessary energy consumption and saving energy for the first terminal device.

[0012] In some implementations, the method also includes:

[0013] Receive identification information of a third network from an access network device, wherein a first list includes identification information of the third network; when the first list of a first terminal device includes identification information of a first network, send a first request message and identification information of the first network to the access network device, including: when the first list includes identification information of the first network and the priority of the first network is higher than that of the third network, send a first request message and identification information of the first network to the access network device.

[0014] Based on the network priority in the first list, the first network with higher priority is selected as the network to be accessed, which can select the network with the highest matching degree for the first terminal device.

[0015] In some implementations, the first request message includes a first identifier and / or a second identifier, where the first identifier is the identifier of the first terminal device in a first network, and the second identifier is the identifier of the terminal device in a second network, where the second network is a PLMN network.

[0016] In some implementations, the first terminal device includes a second logical interface, which is used to access a second network, and a second identifier is associated with the second logical interface.

[0017] The first request message includes a second identifier, which includes:

[0018] When the first logical interface is associated with the second logical interface, or when the first network is associated with the second logical interface, the first request message includes the second identifier.

[0019] In some implementations, the method also includes:

[0020] Send a first identifier and / or a second identifier, wherein the first identifier is the identifier of the first terminal device in the first network, and the second identifier is the identifier of the first terminal device in the second network, wherein the second network is a PLMN network.

[0021] In some implementations, before sending the first identifier and / or the second identifier, the method further includes:

[0022] Receive first information, which is used to request the identifier of the first terminal device in the first network; and / or receive second information, which is used to request the identifier of the first terminal device in the second network.

[0023] In some implementations, the first terminal device includes a second logical interface, which is used to access a second network, and a second identifier is associated with the second logical interface.

[0024] Send the second identifier, including:

[0025] When the first logical interface is associated with the second logical interface, or when the first network is associated with the second logical interface, the second identifier is sent.

[0026] When the first logical interface is associated with the second logical interface, or when the first network is associated with the second logical interface, the second identifier can be determined through the second logical interface.

[0027] In some implementations, the method also includes:

[0028] Obtain first indication information, which is used to indicate that the first logical interface is associated with the second logical interface, or the first indication information is used to indicate that the first network is associated with the second logical interface.

[0029] In some implementations, the first request message also includes third information, which is used to instruct the first terminal device in the first network to request access to the network slice and / or logical network.

[0030] The method also includes:

[0031] Receive fourth information, which is used to indicate the network slices and / or logical networks that the first terminal device in the first network is allowed to access.

[0032] In some implementations, the method also includes:

[0033] Send a first session request message, which is used to request the establishment of a session between the first terminal device and the user plane network element in the first network.

[0034] In some implementations, the first session request message includes an identifier of a network slice and / or logical network, which is the network slice and / or logical network that the first terminal device in the first network requests access to.

[0035] In some implementations, the first request message is also used to request access to a first service of the Public Land Mobile Network (PLMN) through the first network.

[0036] The methods also include:

[0037] The first session request message receives a fifth message, which indicates whether the first terminal device is allowed to access the first service of the PLMN through the first network. If the fifth message indicates that the first terminal device is allowed to access the first service of the PLMN through the first network, the first session request message also includes information indicating the first service.

[0038] Accessing PLMN services through the first network allows single-mode terminal devices to simultaneously access both the PLMN and the subnet, or to access PLMN services even when there are no PLMN access network devices at the current location.

[0039] Secondly, embodiments of this application provide a communication method applied to a mobility management network element, the method comprising:

[0040] The system receives a first request message from an access network device and identification information of a first network. The first request message is used to request the first terminal device to register with the first network. The first network is a non-PLMN network, and the access network device and the mobility management network element support the terminal device to access the first network. Based on the identification information of the first network, the system sends a second request message to the control plane network element in the first network. The second request message is used to request the first terminal device to access the first network. The system also receives a first response message from the control plane network element. The first response message is used to indicate whether the first terminal device is allowed to access the first network.

[0041] In some implementations, a second request message is sent to the control plane network element in the first network, including:

[0042] If the authentication of the first terminal device is successful, a second request message is sent to the control plane network element. The authentication of the first terminal device is based on a second identifier, which is the identifier of the first terminal device in the second network, which is a PLMN network.

[0043] SIM authentication of the first terminal device can improve the security of the first terminal device during the subnet access process.

[0044] In some implementations, the first request message includes a second identifier; or, the method further includes: sending a message to request an identifier of the first terminal device in the second network; and receiving the second identifier.

[0045] In some implementations, upon successful authentication of the first terminal device, a second request message is sent to the control plane network element, including:

[0046] If the authentication of the first terminal device is successful, a first identifier is obtained. The first identifier is the identifier of the first terminal device in the first network and is an external identifier of the first terminal device. A second request message is sent to the control plane network element. The second request message includes the first identifier.

[0047] In some implementations, the first request message includes a first identifier, which is the identifier of the first terminal device in the first network, and the first identifier is an external identifier of the first terminal device.

[0048] Send a second request message to the control plane network elements in the first network, including:

[0049] If the verification of the first identifier is successful, a second request message is sent to the control plane network element.

[0050] In some implementations, the second request message includes at least one of the following: a first identifier, or information indicating successful verification of the first identifier.

[0051] In some implementations, the method further includes the following steps before sending the second request message to the control plane network element:

[0052] Send a message to a core network element in the second network to request an external identifier for the first terminal device. The core network element in the second network is used to manage the external identifiers of terminal devices belonging to the second network. The second network is a network deployed by the home operator of the first terminal device. Receive the external identifier of the first terminal device from the core network element. Successful verification of the first identifier includes: the external identifier of the first terminal device from the core network element includes the first identifier.

[0053] In some implementations, the method further includes the following steps before sending the second request message to the control plane network element:

[0054] Send a message to a core network element in the second network to request verification of the first identifier. The core network element in the second network is used to manage external identifiers of terminal devices belonging to the second network. The second network is a network deployed by the home operator of the first terminal device. Receive a second response message from the core network element. The second response message is used to indicate the result of the verification of the first identifier. Successful verification of the first identifier includes: the second response message indicating successful verification of the first identifier.

[0055] When the first identifier is an external identifier of the first terminal device, verifying the legality of the first identifier can improve the security of the first terminal device during the subnet access process.

[0056] In some implementations, the method also includes:

[0057] Receive a first session request message from a first terminal device. The first session request message is used to request the establishment of a session between the first terminal device and a first user plane network element of the first network.

[0058] In some implementations, the method also includes:

[0059] Based on the first session request message, a message is triggered in the second user plane network element to allocate uplink tunnel information and downlink tunnel information for the session. An interface exists between the second user plane network element and the access network device. The device receives first uplink tunnel information and first downlink tunnel information from the second user plane network element. The first uplink tunnel information is used to send uplink data of the session to the second user plane network element, and the first downlink tunnel information is used to send downlink data of the session to the second user plane network element. A second session request message is sent to the control plane network element. The second session request message is used to request the establishment of a session between the first terminal device and the first user plane network element. The second session request message includes the first downlink tunnel information. The device receives second uplink tunnel information from the control plane network element. The second uplink tunnel information is used to send uplink data of the session to the first user plane network element. Finally, the device sends the first uplink tunnel information to the access network device.

[0060] In some implementations, the second request message includes a first terminal identifier, which is used to indicate a first terminal device in the mobility management network element.

[0061] In some implementations, the first response message includes a second terminal identifier, which is used to indicate the first terminal device in the control plane network element.

[0062] In some implementations, a downlink non-access stratum (NAS) message and a first terminal identifier are received from a control plane network element, and a downlink NAS message is sent to a first terminal device based on the first terminal identifier; and / or, an uplink NAS message is received from the first terminal device, and an uplink NAS message and a second terminal identifier are sent to the control plane network element.

[0063] By using a first terminal identifier and a second terminal identifier to indicate the first terminal device in different network elements, it is possible to prevent the first terminal device from leaking privacy information during the process of accessing the subnet.

[0064] Thirdly, embodiments of this application provide a communication method applied to a control plane network element in a first network, the method comprising:

[0065] The system receives a second request message from a mobility management network element, which requests access to the first network for the first terminal device. The mobility management network element supports access to the first network for the terminal device. The system determines whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network. The system sends a first response message to the mobility management network element, which indicates whether access to the first network for the first terminal device is allowed.

[0066] By authorizing and authenticating the access of the first terminal device to the first network through the control plane network elements in the first network, the privacy of the contracted users in the first network can be protected, the management convenience of the contracted users in the first network can be improved, and interference between data in different subnets can be avoided.

[0067] In some implementations, the second request message is also used to request access to a first service of the Public Land Mobile Network (PLMN) through the first network. The subscription information of the first terminal device in the first network includes second indication information, which is used to indicate whether the first terminal device is allowed to access the PLMN's services through the first network.

[0068] The methods also include:

[0069] Based on the second request message and the second instruction information, determine whether to allow the first terminal device to access the first service of the PLMN through the first network.

[0070] In some implementations, the first response message also includes third information, which indicates whether the first terminal device is allowed to access the first service of the PLMN through the first network.

[0071] In some implementations, before determining whether to allow the first terminal device to access the first network based on its subscription information in the first network, the method further includes:

[0072] The first identifier is used to obtain the subscription information of the first terminal device in the first network. The first identifier is the identifier of the first terminal device in the first network.

[0073] In some implementations, the second request message includes a first identifier; or, the method further includes: sending a message to request an identifier of the first terminal device in the first network; and receiving the first identifier.

[0074] In some implementations, the first identifier is an external identifier of the first terminal device.

[0075] Based on the first identifier, the subscription information of the first terminal device in the first network is obtained, including:

[0076] If the verification of the first identifier is successful, the subscription information of the first terminal device in the first network is obtained based on the first identifier.

[0077] In some implementations, successful verification of the first identifier includes: the second request message also includes information indicating successful verification of the first identifier.

[0078] In some implementations, before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the method further includes:

[0079] Send a message to a core network element in the second network to request an external identifier for the first terminal device. The core network element in the second network is used to manage the external identifiers of terminal devices belonging to the second network. The second network is a network deployed by the home operator of the first terminal device. Receive the external identifier of the first terminal device from the core network element. Successful verification of the first identifier includes: the external identifier of the first terminal device from the core network element includes the first identifier.

[0080] In some implementations, before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the following steps are taken:

[0081] Send a message to a core network element in the second network to request verification of the first subscription identifier. The core network element in the second network is used to manage external identifiers of terminal devices belonging to the second network. The second network is a network deployed by the home operator of the first terminal device. Receive a third response message from the core network element. The third response message is used to indicate the result of the verification of the first identifier. Successful verification of the first identifier includes: the third response message indicating successful verification of the first identifier.

[0082] In some implementations, the method further includes the following steps before successful verification of the first identifier:

[0083] The first terminal device is authenticated based on the second identifier, which is the identifier of the first terminal device in the second network. The second network is the network deployed by the home operator of the first terminal device.

[0084] In some implementations, the first terminal device is authenticated based on the second identifier, including:

[0085] The system acquires a second identifier of the first terminal device; sends a first authentication request message to a core network element in the second network, whereby the core network element authenticates terminal devices belonging to the second network, and the first authentication request message requests authentication of the first terminal device, including the second identifier. It then receives a first authentication response message from the core network element, which includes first authentication information of the first terminal device; sends a second authentication request message to the first terminal device based on the first authentication information; receives a second authentication response message from the first terminal device, which includes second authentication information of the first terminal device; and, if the first authentication information includes verification information, authenticates the first terminal device based on the first authentication information, the verification information, and the second authentication information. Alternatively, it sends a third authentication request message to the core network element, which carries the second authentication information; and receives a third authentication response message from the core network element, which indicates the authentication result of the first terminal device.

[0086] When there is no roaming agreement between the home operator of the mobile management network element and the home operator of the first terminal device, the control plane network element in the first network can request the home operator of the first terminal device to perform SIM authentication through the capability open interface.

[0087] In some implementations, obtaining the second identifier of the first terminal device includes: obtaining the second identifier from a second request message; or, sending a message to request the identifier of the first terminal device in a second network; and receiving the second identifier.

[0088] In some implementations, before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the method further includes: authenticating the first terminal device using the first identifier.

[0089] In some implementations, using a first subscription identifier to perform access authentication for a first terminal device to access the first network includes: when a preset condition is met, using the first subscription identifier to authenticate the first terminal device, the preset condition includes at least one of the following conditions: the subscription information of the first terminal device in the first network requires the use of the first identifier to authenticate the first terminal device; the second request message does not include the verified first identifier; the first identifier is a private identifier in the first network; or, the control plane network element requires the terminal device accessing the first network to be authenticated using the first identifier.

[0090] In some implementations, the second request message also includes fifth information, which indicates the location of the first terminal device. The subscription information of the first terminal device in the first network includes third indication information, which indicates the area of ​​the first network that the first terminal device is allowed to access.

[0091] The process of determining whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network includes:

[0092] If the location of the first terminal device falls within the area indicated by the third indication information, it is determined that the first terminal device is allowed to access the first network.

[0093] In some implementations, the second request message further includes first information, which is used to instruct the first terminal device in the first network to request access to a network slice and / or logical network. The subscription information of the first terminal device in the first network includes fourth indication information, which is used to instruct the first terminal device in the first network to allow access to the network slice and / or logical network.

[0094] The process of determining whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network includes:

[0095] If the network slice and / or logical network requested for access in the first information is included in the network slice and / or logical network that is allowed to be accessed indicated by the fourth indication information, then the network slice and / or logical network that the first terminal device in the first network is allowed to access is determined.

[0096] In some implementations, the first response message also includes second information, which is used to indicate the network slices and / or logical networks that the first terminal device in the first network is allowed to access.

[0097] In some implementations, the first response message includes a second terminal identifier, which is used to indicate the first terminal device in the control plane network element.

[0098] In some implementations, the method also includes:

[0099] The system receives a second session request message from a mobility management network element (MLE), which requests the establishment of a session between the first terminal device and a first user plane network element in the first network. The second session request message includes first downlink tunnel information, which is used to send downlink data of the session to a second user plane network element in a third network. The third network is a network deployed by the home operator of the MLE. Based on the session subscription information of the first terminal device in the first network, the system sends a third session request message to the first user plane network element, which requests the first user plane network element to allocate second uplink tunnel information for the session. The system also receives the second uplink tunnel information from the first user plane network element, which is used to send uplink data of the session to the first user plane network element. Finally, the system sends a session response message to the MLE, which indicates session establishment and includes the second uplink tunnel information.

[0100] In some implementations, the second session request message also includes a sixth piece of information, which is used to indicate the identifier of the network slice and / or logical network that the first terminal device in the first network requests to access. The session subscription information of the first terminal device in the first network includes a fifth indication information, which is used to indicate the network slice and / or logical network that the first terminal device in the first network is allowed to access.

[0101] Based on the session subscription information of the first terminal device in the first network, a third session request message is sent to the first user plane network element, including:

[0102] If the network slice and / or logical network requested for access in the sixth information is included in the network slice and / or logical network that the fifth indication information indicates is allowed to be accessed, a third session request message is sent to the first user plane network element.

[0103] In some implementations, the second session request message also includes information for instructing the first user plane network element to filter unauthorized data packets.

[0104] By configuring the corresponding access rules, the access of the first terminal device to services in the first network can be controlled, thereby improving the controllability of the first terminal device when accessing the first network.

[0105] In some implementations, the second session request message also includes a first identifier or a second terminal identifier.

[0106] Before sending a third session request message to the first user plane network element based on the session subscription information of the first terminal device in the first network, the method further includes:

[0107] The session subscription information of the first terminal device in the first network is obtained based on the first identifier or the second terminal identifier.

[0108] In some implementations, the third session request message also includes information indicating permission for the first terminal device to access the first service of the PLMN.

[0109] In some implementations, the method also includes:

[0110] A third session request message is sent to the third user plane network element. The third session request message is used to request the third user plane network element to allocate uplink tunnel information. The third session request message carries the service information of the first PLMN and the downlink tunnel information allocated by the first user plane network element. The third user plane network element belongs to the first PLMN.

[0111] Fourthly, embodiments of this application provide a communication method applied to an access network device, the method comprising:

[0112] Receive a first message from the first terminal device, trigger the establishment of a first connection based on the first message, the first connection being a connection between the first terminal device and the first mobility management network element; send a first connection identifier to the first terminal device, the first connection identifier being used to indicate the first connection.

[0113] The first connection identifier enables the first terminal device to identify the corresponding first mobility management network element during subsequent NAS information exchange.

[0114] In some implementations, the first message includes a sixth instruction message, which is used to instruct the establishment of a connection between the first terminal device and the first mobility management network element.

[0115] The establishment of the first connection is triggered based on the first message, including: the establishment of the first connection is triggered based on the sixth instruction information.

[0116] In some implementations, the establishment of the first connection is triggered based on the first message, including:

[0117] If the first connection identifier is not included in the first message, the establishment of the first connection is triggered.

[0118] In some implementations, the establishment of the first connection is triggered based on the first message, including:

[0119] If the first message includes a first connection identifier and the access network device does not save the correspondence between the first terminal device and the first connection identifier, the establishment of the first connection is triggered.

[0120] In some implementations, the method further includes: assigning a first connection identifier to the first connection; and sending the first connection identifier to the first terminal device.

[0121] In some implementations, the method also includes:

[0122] Save the correspondence between the first terminal device and the first connection identifier.

[0123] In some implementations, the first message also includes information for instructing the first network.

[0124] The methods also include:

[0125] Select the first mobility management network element based on the first message. The first mobility management network element supports connecting terminal devices to the first network.

[0126] In some implementations, the first message also includes a first NAS message, which is an access request message or a service request message.

[0127] In some implementations, the first connection is used to forward messages between the first terminal device and the first network.

[0128] The methods also include:

[0129] The system receives a second message from the first terminal device and triggers the establishment of a second connection based on the second message. The second connection is a connection between the first terminal device and the second mobility management network element. The second connection is used to forward messages between the first terminal device and the second network. The second network and the first network are different networks. The system sends a second connection identifier to the first terminal device. The second connection identifier is used to indicate the second connection.

[0130] The first terminal device accesses different subnets and main networks through different mobile management network elements, which can decouple subnet access and main network access, avoid sharing mobile management network elements, and enhance the isolation between subnet access and main network access.

[0131] In some implementations, before receiving a first message from the first terminal device and before receiving a second message from the first terminal device, the method further includes:

[0132] Establish a third connection between the first terminal device and the access network device; receive a first message from the first terminal device, including receiving the first message from the first terminal device through the third connection; receive a second message from the first terminal device, including receiving the second message from the first terminal device through the third connection.

[0133] In some implementations, the second message also includes a second NAS message, which is an access request message or a service request message.

[0134] In some implementations, the first connection is associated with at least one first user plane link, and the second connection is associated with at least one second user plane link. The first user plane link is used to transmit user plane data between the first terminal device and the first network, and the second user plane link is used to transmit user plane data between the first terminal device and the second network.

[0135] The method also includes:

[0136] Release the third connection if there is no data transmission on at least one first user plane link and no data transmission on at least one second user plane link.

[0137] When no data is being transmitted, the first terminal device can be put into an idle state, which can release the air interface and save energy for the first terminal device.

[0138] Fifthly, embodiments of this application provide a communication method applied to a first terminal device, comprising:

[0139] Send a first message to the access network device, the first message being used to trigger the establishment of a first connection, the first connection being a connection between the first terminal device and the first mobility management network element; receive a first connection identifier from the access network device, the first connection identifier being used to indicate the first connection.

[0140] In some implementations, the first message includes a sixth instruction message, which is used to instruct the establishment of a connection between the first terminal device and the first mobility management network element.

[0141] In some implementations, a first message is sent to the access network device, including:

[0142] Assign a first connection identifier to the first connection; send a first message to the access network device, the first message including the first connection identifier.

[0143] In some implementations, the first message also includes information for instructing the first network, and the first mobility management element supports accessing the terminal device to the first network.

[0144] In some implementations, the first message also includes a second NAS message, which is a registration request message or a service request message.

[0145] In some implementations, the first connection is used to forward messages between the first terminal device and the first network.

[0146] The methods also include:

[0147] Send a second message to the access network device. The second message is used to trigger the establishment of a second connection. The second connection is a connection between the first terminal device and the second mobility management network element. The second connection is used to forward messages between the first terminal device and the second network. The second network and the first network are different networks. Receive a second connection identifier from the access network device. The second connection identifier is used to indicate the second connection.

[0148] In some implementations, a first message is sent to the access network device, including:

[0149] Sending a first message through a third connection to the access network device, wherein the third connection is a connection between the first terminal device and the access network device; sending a second message to the access network device, including: sending a second message to the access network device through the third connection.

[0150] Sixthly, embodiments of this application provide a communication device, which includes functional modules for implementing any of the communication methods mentioned in the above implementations. Optionally, each module can be implemented by software and / or hardware.

[0151] In a seventh aspect, embodiments of this application provide a communication device including a processor coupled to a memory, which can be used to execute instructions in the memory to implement any of the communication methods mentioned in the above implementations. Optionally, the device further includes a memory. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface.

[0152] Eighthly, embodiments of this application provide a computer-readable medium storing program code for execution by a device, the program code including any of the communication methods mentioned in the above implementations.

[0153] Ninthly, embodiments of this application provide a computer program product, including a computer program, which, when executed by a processor, implements any of the communication methods mentioned in the above implementations. Attached Figure Description

[0154] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0155] Figure 1 is a schematic diagram of the network architecture 100 provided in one embodiment of this application;

[0156] Figure 2 is a flowchart illustrating a communication method provided in one embodiment of this application;

[0157] Figure 3 is a flowchart illustrating a communication method provided in one embodiment of this application;

[0158] Figure 4 is a flowchart illustrating a communication method provided in one embodiment of this application;

[0159] Figure 5 is a schematic diagram of the process of requesting identity authentication from an AUSF / UDM network element through a subnet control plane network element according to an embodiment of this application;

[0160] Figure 6 is a schematic diagram of the process of requesting identity authentication from an AUSF / UDM network element through a subnet control plane network element according to another embodiment of this application;

[0161] Figure 7 is a schematic diagram of the process by which a terminal device simultaneously accesses a subnet and a mainnet according to an embodiment of this application;

[0162] Figure 8 is a schematic diagram of a terminal device protocol stack provided in an embodiment of this application;

[0163] Figure 9 is a schematic diagram of the process of a terminal device separately accessing a subnet and a mainnet according to an embodiment of this application;

[0164] Figure 10 is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0165] Figure 11 is a schematic diagram of the structure of a communication device provided in another embodiment of this application.

[0166] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0167] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0168] The technical solutions provided in this application can be applied to various communication systems, such as new radio (NR) systems, long term evolution (LTE) systems, frequency division duplex (FDD) systems, and time division duplex (TDD) systems. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.

[0169] In the aforementioned communication system, the portion operated by the operator can be referred to as the Public Land Mobile Network (PLMN), used to provide terrestrial mobile communication services. The PLMN can also be called an operator network, a large network, or a public network, and the operator running the PLMN can be called a large network operator. The PLMN described in this application embodiment can specifically be a network conforming to the 3rd Generation Partnership Project (3GPP) standard, abbreviated as 3GPP network. 3GPP networks include, but are not limited to, 5th-generation (5G) mobile communication networks, 4th-generation (4G) mobile communication networks, and other future communication networks, such as 6th-generation (6G) mobile communication networks.

[0170] As 3GPP networks evolve from a business-to-business (2B) to a consumer-to-consumer (2C) model, a series of emerging technologies have arisen, supporting the deployment of networks in designated locations (such as enterprises, campuses, shopping malls, parks, etc.) to provide customized services to users within those areas, thus continuously expanding the application scenarios of 3GPP networks. The network serving users within a designated location area can be called a sub-network, the designated area can be called a sub-network location, users accessing the sub-network within a sub-network location can be called sub-network users, the owner or manager of the sub-network location can be called a sub-network tenant, the services provided by the sub-network to its users can be called sub-network services, and the operator deploying the sub-network can be called a sub-network operator. A sub-network can also be called a private network, dedicated network, etc., but this application does not limit the specific terminology used in its embodiments.

[0171] The subnet operator and the main network operator can be the same or different. For example, a subnet tenant can directly entrust the main network operator to deploy the subnet; in this case, the main network operator is also the subnet operator for the corresponding subnet. Alternatively, a subnet tenant can entrust a third-party operator to deploy the subnet; in this case, the subnet operator and the main network operator are different network operators.

[0172] In existing technologies, large network operators can deploy subnets using technologies such as network slicing, multi-access edge computing (MEC), and local area data networks (LADN). However, in this case, only subscribers of the large network operator can access the subnet through the access network equipment deployed by the large network operator; users belonging to other operators cannot access it. Large network operators can also deploy subnets using stand-alone non-public network (SNPN) technology, but only dedicated terminal equipment for the subnet, such as terminal equipment including a subscriber identity module (SIM) card for the subnet, or terminal equipment capable of receiving signals in specific frequency bands within the subnet, can access the subnet. This limits the application scope of the subnet.

[0173] To address the aforementioned technical problems, embodiments of this application provide a communication method and related apparatus, which aim to enable subnet users belonging to different network operators to access the same subnet and meet the service needs of subnet users.

[0174] This application embodiment configures a subnet selection list containing subnet identification information on the terminal device, and the access network device broadcasts the identification information of the subnets it supports. The terminal device selects a subnet according to the subnet selection list and the broadcast subnet identification information, and requests access to the selected subnet from the access network device, so that users belonging to subnets of different operators can access the same subnet.

[0175] Figure 1 is a schematic diagram of a network architecture 100 provided in an embodiment of this application. As shown in Figure 1, the network architecture 100 includes a terminal, access network equipment, PLMN 1 deployed by a large network operator (OP) 1, PLMN 2 deployed by a large network operator (OP) 2, and a subnet deployed by a subnet operator.

[0176] The term "terminal" can also refer to terminal equipment, user equipment (UE), mobile station (MS), mobile terminal (MT), etc., and can be an entity on the user side used to receive or transmit signals, such as a mobile phone. Terminal equipment includes handheld devices, in-vehicle devices, wearable devices, or computing devices with wireless communication capabilities. For example, a terminal device can be a mobile phone, tablet computer, or computer with wireless transceiver capabilities. Terminal equipment can also be virtual reality (VR) terminal equipment, augmented reality (AR) terminal equipment, wireless terminals in industrial control, wireless terminals in autonomous driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in smart cities, wireless terminals in smart homes, etc. In this application embodiment, the device used to implement the terminal's functions can be the terminal itself; it can also be a device capable of supporting the terminal in implementing these functions, such as a chip system, communication module, or modem, which can be installed in the terminal. In this application embodiment, the chip system can be composed of chips or can include chips and other discrete components. The embodiments of this application do not limit the specific technology or device form used in the terminal device.

[0177] Access network equipment is deployed by operator OP1 and located within the subnet area, with its signal capable of covering the subnet area. Access network equipment includes, but is not limited to: next-generation base stations (gnode B, gNB) in 5G, evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved node B, or home node B, HNB), base band unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, etc.

[0178] Terminal devices can access the subnet through the access network device deployed in OP1; therefore, the access network device deployed in OP1 can also be called the subnet access network device. Terminal devices can also access PLMN 1 deployed in OP1 through this access network device, meaning that the subnet and PLMN 1 deployed in OP1 share this access network device.

[0179] PLMN 1 may include one or more of the following core network elements: global mobility management (G-MM) elements, global session management (G-SM) elements, and global user plane function (G-UPF) elements. PLMN 1 may include dedicated core network elements that provide services only to the subnets shown in Figure 1, or shared core network elements that provide services to other subnets or even the main network services of OP1.

[0180] Among them, G-MM network elements are mainly responsible for terminal equipment access authentication, access authorization, and mobility management. G-MM network elements can be access and mobility management function (AMF) network elements in 5G communication systems. G-SM network elements are used to support terminal equipment access and are responsible for statistics and monitoring of the network resources used by terminal equipment to access the subnet, such as resource usage and access duration. G-SM network elements can be session management function (SMF) network elements in 5G communication systems. G-UPF network elements are responsible for forwarding subnet service data packets between terminal equipment and the subnet, and can also be used to collect subnet-related billing information such as traffic. G-UPF network elements can be user plane function (UPF) network elements in 5G communication systems.

[0181] OP2 is the home operator of the terminal device (or OP2 is the home operator of a SIM card / embedded SIM (eSIM) card included in the terminal device). Therefore, the subscription data between the terminal device and OP2 is stored by the core network elements in PLMN 2. For example, the unified data management (UDM) network elements in PLMN 2 store the subscription data (such as keys) of the terminal device.

[0182] The core network elements in PLMN 2 can include authentication server function (AUSF) network elements and UDM network elements. The UDM network element is mainly responsible for the management of user identifiers, subscription data, and authentication data. The AUSF network element is used to receive authentication requests from G-MM network elements for terminal devices and performs authentication processing on the terminal devices by requesting authentication vectors from the UDM network element.

[0183] The subnet operator is responsible for the deployment of the subnet. In one possible implementation, the subnet operator is the same as the main network operator; for example, operator OP1 is the subnet operator, and subnet tenants sign subnet deployment agreements with OP1, which then deploys the subnets for the tenants. In another possible implementation, the subnet operator is independent of the main network operator; for example, subnet tenants sign deployment agreements with the subnet operator, which leases resources from OP1 to deploy the subnet, such as leasing access network and core network equipment from OP1.

[0184] The subnet also includes control plane network elements, subnetwork subscription and policy management (SSPM) network elements, and UPF network elements. The control plane network element is essentially a comprehensive network element integrating functions such as access authentication, access authorization, mobility management, session management, and authentication services. The SSPM network element is responsible for managing the subscription data and policies between terminal devices and the subnet. The UPF network element is responsible for forwarding user plane data between terminal devices and subnet services. These network elements can be deployed in-house within the subnet tenant's campus, or in the operator's data center managing the subnet, or in the OP1 data center.

[0185] With the network architecture 100 shown in Figure 1, when a terminal device accesses a subnet, it can request the AUSF / UDM network element in its home PLMN 2 to perform identity authentication, and the control plane network element of the subnet will authorize the terminal device to access.

[0186] Figure 2 is a flowchart illustrating a communication method provided in an embodiment of this application. As shown in Figure 2, the communication method may include steps S201 to S205.

[0187] S201, the access network device sends the identification information of the first network to the first terminal device. Correspondingly, the first terminal device receives the identification information of the first network from the access network device.

[0188] As an example, the access network device can broadcast the identification information of the first network, and the access network device has the ability to connect terminal devices to the first network, which can be a non-PLMN network.

[0189] The first terminal device is located within the subnet covered by the broadcast signal of the access network device, and therefore can receive the identification information of the first network broadcast by the access network device.

[0190] S202, when the first list in the first terminal device includes the identification information of the first network, the first terminal device sends a first request message and the identification information of the first network to the access network device. The first request message is used to request that the first terminal device be connected to the first network. Accordingly, the access network device receives the first request message and the identification information of the first network from the first terminal device.

[0191] As an example, the first terminal device is configured with a first list, which includes identification information of one or more non-PLMNs, or in other words, the first list includes identification information of at least one subnet. The subnets involved in this application are non-PLMN networks.

[0192] The first list includes the identification information of the first network, which may indicate that the first network is a subnet with a contractual relationship with the first terminal device, or that the first network is a subnet open to the public without a contract. Therefore, the first terminal device can access the first network. In this case, the first terminal can send a first request message and the identification information of the first network device to the access network device. The first request message is used to request the access network device to connect the first terminal device to the network, and the identification information of the first network is used to inform the access network device to connect the first terminal device to the network.

[0193] It should be noted that "register to the network" and "access the network" mentioned in the embodiments of this application can have the same meaning.

[0194] S203, the access network device sends a first request message and the identification information of the first network to the mobility management element. Correspondingly, the mobility management element receives the first request message and the identification information of the first network from the access network device.

[0195] In this embodiment, the mobility management network element is the network element in the PLMN responsible for access authentication, access authorization, and mobility management of terminal devices.

[0196] After receiving the first request message and the identification information of the first network, the access network device can determine the mobility management network element of the first terminal device based on the identification information of the first network, and send the first request message and the identification information of the first network to the mobility management network element.

[0197] The access network device determines the implementation method of the mobility management network element based on the identification information of the first network. You can refer to step S304 in the embodiment shown in Figure 3, which will not be repeated here.

[0198] S204, the mobility management network element sends a second request message to the control plane network element in the first network based on the identification information of the first network. The second request message is used to request that the first terminal device access the first network. Correspondingly, the control plane network element in the first network receives the second request message from the mobility management network element.

[0199] As an example, a mobility management network element can learn the association between a control plane network element and the identifier of its network, thereby identifying the control plane network element associated with the received identification information used to identify the network as a control plane network element in the first network.

[0200] The control plane network element in the first network is responsible for authorizing terminal devices to access the first network.

[0201] S205, the control plane network element sends a first response message to the mobility management network element. The first response message indicates whether the first terminal device is allowed to access the first network. Correspondingly, the mobility management network element receives the first response message from the control plane network element.

[0202] In this embodiment, the control plane network element determines whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network. If access is allowed, the first terminal device is authorized to access the first network.

[0203] An exemplary implementation of the control plane network element determining whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network can be found in step S310 of the embodiment shown in Figure 3, which will not be repeated here.

[0204] After determining whether to allow the first terminal device to access the first network, the control plane network element can indicate to the mobility management network element whether to allow the first terminal device to access the first network through a first response message.

[0205] In this embodiment, when the first list includes the identification information of the first network broadcast by the access network device, the first terminal device can directly select the cell of the subnet access network device for access without considering its affiliated major network operator, and share the same access network device with terminal devices belonging to other major network operators.

[0206] It is understood that the communication method provided in this embodiment can be applied to the network architecture 100 shown in Figure 1. For example, the first terminal device can be a terminal device in this architecture, the first network can be a subnet therein, the mobility management network element can be a G-MM network element or an AMF network element under a 5G communication system, and the control plane network element in the first network can be a control plane network element in the subnet.

[0207] The embodiment shown in Figure 2 illustrates the technical solution provided by the embodiments of this application. When accessing the subnet through the above communication method, other network elements in the network architecture 100 also need to participate. The specific subnet access process is described below.

[0208] Figure 3 is a flowchart illustrating a communication method provided in an embodiment of this application. The communication method proposed in this embodiment can be applied to the network architecture 100 shown in Figure 1, for example, using a terminal device as the first terminal device and an AMF network element as a mobility management network element, where OP1 provides resources for subnet deployment and OP2 is the home operator of the terminal device. The communication method in Figure 2 is further described using 5G communication as a scenario. As shown in Figure 3, the specific steps include:

[0209] S300-1, Terminal Equipment Configuration Subnet Selection List.

[0210] The subnet selection list, also known as the first list, contains subnet identifiers for at least one subnet. These subnet identifiers act as unique identifiers for each subnet, identifying it as a distinct entity. The subnets corresponding to these identifiers are either subnets with a contractual relationship with the terminal device or subnets that are open to the public without a contract. In other words, the subnet selection list indicates the subnets that the terminal device can access. The terminal device selects the desired subnet based on the subnet identifiers listed.

[0211] In some implementations, the subnet selection list can indicate the priority of the terminal device in selecting a subnet. As an example, the subnet identifiers in the subnet selection list are sorted according to the priority of their corresponding subnets.

[0212] It's important to note that when a terminal device signs a contract with a subnet, it also needs to configure a subnet contract identifier. This identifier acts as the terminal device's identity within the subnet. The subnet uses this identifier to identify the corresponding terminal device. The terminal device stores the subnet contract identifier for each subnet, thus maintaining the correspondence between subnet identifiers. As an example, the subnet contract identifier can be the terminal device's Mobile Station International ISDN number (MSISDN), where ISDN stands for Integrated Services Digital Network. MSISDN can be simply understood as a telephone number in everyday life. The subnet contract identifier can also be the terminal device's International Mobile Subscriber Identity (IMSI). In the 5G era, it can also correspond to the terminal device's Subscription Permanent Identifier (SUPI) or Subscription Concealed Identifier (SUCI). For some subnets, the subnet contract identifier can also be a unique identifier for the terminal device within that subnet. For example, the terminal device's employee ID within a company can be used as the subnet contract identifier for the terminal device within the company's subnet.

[0213] It is understandable that a terminal device can use the same subnet subscription identifier in different subnets. For example, a terminal device can use an MSISDN as the subnet subscription identifier in subnet A, and it can also use the same MSISDN as the subnet subscription identifier in subnet B. Subnet A and subnet B share the same MSISDN of the terminal device. It should be noted that one IMSI of a terminal device may correspond to multiple MSISDNs. When different subnets use different MSISDNs as subnet subscription identifiers, the terminal device needs to maintain the mapping relationship between all MSISDNs used as subnet subscription identifiers and their corresponding subnets. For example, if the terminal device's IMSI corresponds to MSISDN 1 and MSISDN 2, and the terminal device uses MSISDN 1 as the subnet subscription identifier for subnet A and MSISDN 2 as the subnet subscription identifier for subnet B, the terminal device needs to maintain the mapping relationship between MSISDN 1 and subnet A, and MSISDN 2 and subnet B, respectively.

[0214] The terminal device can be configured with a subnet selection list and a subnet subscription identifier at the factory, or it can be configured manually, or it can receive the subnet selection list and subnet subscription identifier via signaling when signing a contract with a subnet and save them.

[0215] As one possible implementation, to support subnets, a new subnet logical interface, namely the first logical interface, is added to the terminal device. This subnet logical interface is used to connect the terminal device to the subnet. Correspondingly, the aforementioned subnet selection list and the subnet logical interface are configured with the subnet selection list. When different subnets correspond to different subnet subscription identifiers, the subnet subscription identifier can be included as a field in the subnet selection list.

[0216] S300-2, Subnet identifier exchanged between access network equipment and AMF network elements.

[0217] Both access network devices and AMF network elements can support one or more different subnets. Therefore, access network devices and AMF network elements can configure the subnet identifiers corresponding to the subnets they support and exchange their respective configured subnet identifiers during the initial signaling interaction (such as the "NG Setup" process).

[0218] There is no strict order between steps S300-1 and S300-2 above; their execution order can be arbitrarily interchanged.

[0219] S301, the access network device broadcasts the subnet identifier. Correspondingly, the terminal device receives the subnet identifier from the access network device.

[0220] Terminal devices need to access the subnet through access network equipment. Considering that the access network equipment supports one or more different subnets (i.e., one or more subnets share the same access network equipment), the access network equipment broadcasts the subnet identifier corresponding to each supported subnet to the terminal device. This allows the terminal device to select a subnet subsequently, reducing unnecessary attempts and improving access efficiency. It is understandable that, in addition to supporting subnets, the subnet access network equipment also supports main network services; therefore, the access network equipment also broadcasts the PLMN IDs it supports to the terminal device.

[0221] S302, the terminal device selects a subnet based on the subnet selection list and the subnet identifier broadcast by the access network device.

[0222] In this step, the dedicated subnet logical interface on the terminal device used for accessing the subnet matches the subnet identifier broadcast by the access network device with the previously configured subnet selection list. If a subnet identifier identical to the one broadcast by the access network device exists in the subnet selection list, it indicates that the terminal device can access the subnet corresponding to the subnet identifier through the access network device. Both the subnet identifier broadcast by the access network device and the subnet identifier in the subnet selection list contain the identifier of the first network, which is a subnet that the access network device supports the terminal device to access.

[0223] In some implementations, when the first logical interface is enabled, the terminal device selects a subnet based on the subnet selection list and the subnet identifier broadcast by the access network device. As an example, when the first logical interface is enabled, and the subnet selection list includes the identifier information of the first network broadcast by the access network device, the terminal device selects the first network as the subnet to be accessed, and sends a first request message and the identifier information of the first network in step S303.

[0224] In some implementations, a subnet switch can be added to the terminal device. This subnet switch controls the opening or closing of the first logical interface. The operator of the terminal device can turn on the subnet switch when the terminal device is near a subnet location, preventing unnecessary energy consumption caused by the terminal device performing network searches when it cannot access the subnet, thus saving energy for the terminal device.

[0225] In some implementations, when there are multiple subnet identifiers in the subnet selection list that are the same as the subnet identifier broadcast by the access network device, the terminal device selects the subnet indicated by the highest priority subnet identifier from among the multiple identical subnet identifiers as the subnet to be accessed, according to the priority indicated by the subnet identifiers in the subnet selection list.

[0226] S303, the terminal device sends a first request message and the identification information of the first network to the access network device. Correspondingly, the access network device receives the first request message and the identification information of the first network from the terminal device.

[0227] The first request message is used to request the terminal device to register (or access) to the first network, which is the subnet selected by the terminal device in step S302 based on the subnet selection list and the broadcast by the access network device. It should be noted that when multiple accessible subnets exist in step S302, the terminal device selects the first network from among the multiple accessible subnets.

[0228] As an example, the terminal device receives the identification information of a third network broadcast by the access network device. The identification information of the third network and the identification information of the first network are both included in the first list. The first network has a higher priority than the third network. Therefore, the terminal device sends a first request message and the identification information of the first network to the access network device.

[0229] In some implementations, the first request message also includes a first identifier and / or a second identifier. The first identifier is the subnet subscription identifier of the terminal device in the first network, a corresponding identifier assigned to the terminal device by the first network, which uniquely indicates its corresponding terminal device within the first network. The second identifier is the identifier of the terminal device in the second network, which is the PLMN network deployed by the terminal device's home operator OP2. The identifier of the terminal device in the second network is any one of SUPI, SUCI, or IMSI. It is understood that the second identifier contains a PLMN ID, which allows the determination of the terminal device's home operator.

[0230] It should be noted that a terminal device may contain multiple SIM cards belonging to different operators. Correspondingly, the terminal device includes multiple network logical interfaces for accessing the network. Each of these network logical interfaces corresponds one-to-one with a different SIM card. Therefore, each network logical interface is associated with the second identifier indicated by its corresponding SIM card; the network logical interface is also known as the second logical interface. For example, if the terminal device contains SIM 1 and SIM 2, where SIM 1 belongs to operator A and SIM 2 belongs to operator B, this indicates that the terminal device is a subscriber to both operator A and operator B. The terminal device includes network logical interface 1 and network logical interface 2. Network logical interface 1 is associated with SIM 1, and network logical interface 2 is associated with SIM 2. The terminal device can obtain its identifier in the network deployed by operator A through network logical interface 1, and its identifier in the network deployed by operator B through network logical interface 2.

[0231] In practice, the main network logical interface and the subnet logical interface can correspond to different physical modems, or they can share a single physical modem (e.g., time-sharing).

[0232] In some implementations, when the first logical interface on the terminal device used for accessing the subnet is associated with the second logical interface used for accessing the main network, or when the first network is associated with the second logical interface used for accessing the main network, the terminal device can determine the second identifier through the associated second logical interface used for accessing the main network, so that the terminal device can directly send the second identifier to the access network device or carry the second identifier in the first request message.

[0233] It should be noted that the subnet selection list may also include first indication information. This first indication information indicates that a first logical interface for accessing the subnet is associated with a second logical interface for accessing the main network; alternatively, it indicates that the first network is associated with a second logical interface for accessing the main network. When a terminal device registers with the first network, it uses a second identifier for authentication. Therefore, the first indication information can also be used to instruct or trigger the terminal device to send the second identifier when requesting to register with the first network. When the subnet selection list configured on the terminal device includes the first indication information, the terminal device can carry the second identifier in the first request message based on the first indication information.

[0234] As one possible implementation, in step S303, the terminal device can also directly send the first identifier and / or the second identifier to the access network device.

[0235] S304, Access network equipment selects AMF network element based on subnet identifier.

[0236] As can be seen from step S300-2, the access network device has clarified through signaling interaction that different AMF network elements support different subnets. Therefore, under the premise that it is determined that it needs to access and register with the first network, the access network device needs to select the AMF network element that supports the first network from multiple AMF network elements according to the subnet identifier information corresponding to the first network.

[0237] In some implementations, the access network device can also query the network repository function (NRF) element or the domain name system (DNS) based on the subnet identifier corresponding to the first network, thereby selecting the AMF element that supports the first network.

[0238] S305, the access network device sends a first request message and the identification information of the first network to the AMF network element. Correspondingly, the AMF network element receives the first request message and the identification information of the first network from the access network device.

[0239] S306, the AMF network element requests the AUSF / UDM network element deployed by the operator to which the terminal device belongs to perform identity authentication.

[0240] In this step, in order to authenticate the terminal device, the AMF network element needs to obtain the terminal device's second identifier, such as the terminal device's SUCI or SUPI. In some implementations, the first request message in step S303 includes the second identifier, which can be the terminal device's SUPI / SUCI; alternatively, the terminal device sends the second identifier, which is the SUPI / SUCI corresponding to the terminal device, to the access network device.

[0241] If the first request message does not carry the second identifier, or if the AMF network element does not receive the second identifier of the terminal device, the AMF network element may send first information to the terminal device. The first information is used to request the identification of the terminal device in the second network. As an example, the AMF network element sends an ID document (ID) request to the terminal device to request the SUPI / SUCI of the terminal device associated with the first network or the first logical interface.

[0242] It should be noted that since SUPI / SUCI are identifiers assigned to SIM cards by network operators, authenticating terminal devices based on SUPI / SUCI is also known as SIM authentication.

[0243] After determining that the terminal device's indicated home operator is OP2, the AMF network element sends a first authentication request message to the AUSF / UDM network element in the OP2 deployed network. This first authentication request message contains the terminal device's SUPI / SUCI and is used to request authentication of whether the terminal device is a subscribed user of OP2. When the AUSF / UDM network element in OP2 receives the first authentication request message, it generates an authentication vector based on the SUPI / SUCI and sends a first authentication response message to the AMF network element, which contains the authentication vector. Subsequently, the AMF network element, the terminal device, and the AUSF / UDM network element interact further according to existing authentication methods. If the authentication vector contains verification information, the AMF network element can confirm whether the terminal device is a subscribed user of OP2 through local verification after receiving the terminal device's authentication response. Otherwise, the AMF network element can only send the terminal device's authentication response to the AUSF / UDM network element and indicate authentication success or failure by receiving response information from the AUSF / UDM network element.

[0244] It is understandable that the AMF network element first sends an authentication request to the AUSF network element, which then requests an authentication vector from the UDM network element. The AUSF network element then performs authentication processing on the terminal device based on the authentication vector. In the above process, both the AUSF and UDM network elements, the core network elements in the two second networks OP2, participate in identity authentication. Therefore, in this embodiment, it is uniformly described as requesting the AUSF / UDM network elements to perform identity authentication.

[0245] If the terminal device's authentication is successful in this step, meaning the AMF / UDM network element deployed in OP2 in the second network authenticates the terminal device as a subscribed user of OP2, then the communication method proposed in this embodiment continues to execute step S307, whereby the AMF network element sends a second request message to the control plane network element of the first network. Otherwise, it indicates that the terminal device's authentication has failed, the terminal device cannot access the first network, and the AMF network element rejects the terminal device's access (i.e., sends a registration rejection message to the terminal device).

[0246] S307, the AMF network element sends a second request message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the second request message from the AMF network element.

[0247] In the aforementioned steps, the terminal device is registered (or accessed) to the first network based on the subnet identifier. Therefore, the subnet control plane network element in this step is the control plane network element in the first network. The second request message is used to request the terminal device to access the first network.

[0248] In some implementations, the second request message may carry an indication that authentication has been performed, through which the AMF network element can convey information that the terminal device is reliable to the control plane network element in the first network.

[0249] When the first request message in step S303 includes the first identifier of the terminal device, the second request message may also include the first identifier of the terminal device.

[0250] Optionally, when the first identifier of the terminal device is an external identifier of the terminal device such as MSISDN, the communication method in this embodiment may further include the following step S307-0 before step S307.

[0251] S307-0 verifies whether the first subnet's contract identifier is a valid external identifier.

[0252] Based on the terminal device's OP2 authentication, as an example, the validity of the first subnet subscription identifier can be verified in two ways: one is...

[0253] The AMF network element requests the external identifier of the terminal device from the UDM network element deployed in OP 2. If the external identifier of the terminal device contains the first identifier carried in the first registration request message, the first identifier is successfully verified, indicating that it is a valid external identifier.

[0254] The second is:

[0255] The AMF network element sends the first subnet subscription identifier carried in the first registration request message to the UDM network element deployed in OP2, and requests the UDM network element to verify whether it is a valid external identifier. The AMF network element indicates the verification result through the response information sent by the UDM network element.

[0256] Understandably, when verifying whether the first identifier is a valid external identifier, the AMF network element can only send the second request message to the subnet control plane network element if the first identifier is determined to be a valid external identifier.

[0257] In some implementations, when the first subnet subscription identifier in the first registration request message is verified as a valid external identifier, the second request message may also carry a verification indication message, which indicates that the first subnet subscription identifier has been verified. In one implementation, the verification indication information can be provided by carrying a verified external identifier field (distinct from the first identifier sent by the terminal device in the first request message) in the second request message.

[0258] In some implementations, after the terminal device passes authentication, the AMF network element can obtain the external identifier of the terminal device from the second network deployed in OP2 and carry the external identifier in the second request message. The external identifier is the first identifier of the terminal device.

[0259] It should be noted that in the above two methods, the AMF network element can interact directly with the UDM network element deployed in OP2. In some implementations, the AMF network element can also interact with the AUSF network element deployed in OP2. The AMF network element interacts indirectly with the UDM network element through the AUSF network element, thereby verifying whether the first subnet signing identifier is a valid external identifier.

[0260] The subnet subscription identifier of the terminal device in the first network is the basis for the control plane network elements in the first network to further confirm the connection between the terminal device and the first network. When the first subnet subscription identifier is an external identifier of the terminal device, verifying its legality can eliminate the need for subsequent access authentication processes, thereby improving efficiency.

[0261] In some implementations, the AMF network element can assign a first terminal identifier to the terminal device. This first terminal identifier is used to indicate the terminal device within the AMF network element. As an example, the first terminal identifier can be a context identifier or temporary identifier for the terminal device, used to indicate the context of the terminal device within the AMF network element. The AMF network element can uniquely identify the terminal device based on its context. The second request message may also include the first terminal identifier of the terminal device. During subsequent access procedures, when the subnet control plane network element interacts with the AMF network element via signaling, it can carry the first terminal identifier. Based on the first terminal identifier, the AMF network element can locate the context of the corresponding terminal device. Through the first terminal identifier, the security and privacy of the terminal device can be protected when the AMF network element interacts with the subnet control plane network element via signaling, for example, by preventing the leakage of the terminal device's SIM card information (such as SUPI) to the subnet.

[0262] S308, Subnet control plane network elements obtain the subscription information of terminal devices in the first network.

[0263] In this step, the control plane network element of the first network requests the subscription information between the terminal device and the first network from the SSPM network element based on the first identifier of the terminal device.

[0264] In another possible implementation, the first network is an open subnet in public settings such as shopping malls or cinemas. In this case, the terminal device has no subscription relationship with the first network, so the second request message naturally does not contain the subnet subscription identifier of the terminal device in the first network. Correspondingly, the first network has default subscription information, which is available to all terminal devices that wish to access the first network. Therefore, the control plane network elements of the first network can directly obtain the default subscription information, which is equivalent to the subscription information of the terminal device in the first network.

[0265] S309, the subnet control plane network elements perform access authentication for terminal devices.

[0266] In this step, the control plane network element of the first network verifies the identity of the terminal device based on the first identifier of the terminal device.

[0267] If the second request message does not carry the terminal device's first identifier and its subnet subscription identifier in the first network, in one possible implementation, the control plane network element may request the terminal device to obtain its subnet subscription identifier in the first network.

[0268] As an example of access authentication, during the subnet access authentication process, the control plane network element can generate an access authentication message based on the first identifier subnet subscription identifier. This message is then transmitted to the terminal device via the AMF network element. The access authentication message carries a random number. The terminal device calculates the random number in the access authentication message using a locally stored key or a certificate shared with the first network, obtaining the calculation result. The terminal device then transmits the calculation result to the control plane network element via the AMF network element. The control plane network element calculates the random number in the access authentication message using the key shared with the terminal device. If the obtained calculation result matches the calculation result returned by the terminal device, it indicates successful access authentication, meaning the control plane network element authenticates that the terminal device has a subscription relationship with the first network.

[0269] In some implementations, the control plane network element initiates access authentication for the terminal device only when preset conditions are met. The preset conditions include at least one of the following: the first identifier of the terminal device is a private identifier in the first network; the subscription information of the terminal device in the first network requires access authentication for the terminal device; the second request message does not include the first identifier; or, the control plane network element requires access authentication for all terminal devices requesting access to the first network.

[0270] In step S307, if the second request message does not carry the first identifier of the terminal device, step S309 can be executed before step S308. That is, the control plane network element first requests the terminal device to obtain its subnet subscription identifier in the first network. After the control plane network element performs access authentication on the terminal device, the subscription information of the terminal device in the first network is obtained after the access authentication is successful.

[0271] It should be noted that if the first identifier of the terminal device is an external identifier, the execution logic of the communication method in this embodiment is as follows: In one possible implementation, after the terminal device passes the authentication in step S306, the second request message may carry an indication that the first subnet subscription identifier has been verified. In this case, step S309 is an optional step. In another possible implementation, the control plane network element of the first network directly performs access authentication on the terminal device based on the first identifier of the terminal device. In this case, step S306 is an optional step. In this implementation, if the control plane network element of the first network requires verification of whether the first subnet subscription identifier is a valid external identifier, since the external identifier of the terminal device is stored in the UDM network element deployed in OP2, the terminal device needs to pass the authentication before executing the verification method in step S307-0. In this case, S306 is a mandatory step. In yet another possible implementation, the AMF network element is pre-configured with configuration information. The configuration information indicates that when the terminal device requests access to any subnet or access to the specified first network, the terminal device is required to undergo authentication. In this implementation, S306 is also a mandatory step.

[0272] If the first identifier of the terminal device is a private identifier in the first network according to the preset conditions, the execution logic of the communication method in this embodiment is as follows: the control plane network element of the first network directly authenticates the terminal device according to the first identifier of the terminal device. At this time, step S306 is an optional step. In addition, in step S309, it is also possible to simultaneously verify whether the first identifier subnet subscription identifier is a legitimate private identifier.

[0273] S310, the subnet control plane network element authorizes the terminal device based on the terminal device's subscription information in the first network.

[0274] As can be seen from step S308, the default subscription information in the first network is for all terminal devices that wish to access the first network but have no subscription in the first network. Therefore, the default subscription information is equivalent to the subscription information of these terminal devices in the first network.

[0275] In this step, the subscription information of the terminal device in the first network indicates the conditions under which the first network authorizes the terminal device to access. As an example, the subscription information of the terminal device in the first network includes any of the following information: a list of cells that allow the terminal device to access the first network, a list of access network devices, and a tracing area identity (TAI). The control plane network element matches the current location information of the terminal device with the location area information that the subscription information indicates is allowed to access. If the current location information of the terminal device is included in the above areas, the control plane network element authorizes the terminal device to access.

[0276] When a terminal device sends a first request message to an access network device, the access network device can obtain the current location information of the terminal device. Optionally, the current location information of the terminal device can be carried in the second request message in step S307. In some implementations, if the second request message does not carry the current location information of the terminal device, the control plane network element can request the access network device to obtain the information. In some implementations, the first request message in step S303 also includes second information, which is used by the terminal device in the first network to request access to the logical network and / or network slice. Accordingly, the second request message includes the terminal device's access request to the logical network and / or network slice. The terminal device's subscription information in the first network includes information on logical networks and / or network slices in the first network that allow the terminal device to access. If the terminal device's access request for a logical network or network slice carried in the second request message matches the content in the subscription information, that is, when the terminal device's subscription information in the first network indicates that the logical networks and / or network slices in the first network that allow the terminal device to access include the logical networks and / or network slices that the terminal device requests to access, the control plane network element authorizes the terminal device to access.

[0277] In this context, a logical network or network slice essentially divides the first network into network areas providing different services. Different network areas correspond to different access permissions. A terminal device can only access its target network area if its subscription information within the first network indicates that it meets the access permissions. For example, the first network might be divided into network area A and network area B based on service classification. Network area A has higher access permission requirements than network area B. If the terminal device's subscription information within the first network indicates that it can only access network area B at most, then when the terminal device requests access to network area A in its access request message, its authorization will fail, resulting in the terminal device failing to access the first network.

[0278] S311, the subnet control plane element sends access response information to the AMF element. Correspondingly, the AMF element receives the access response information from the subnet control plane element.

[0279] If step S311 authorizes the terminal device to access the first network, the access response information sent by the control plane network element in the first network to the AMF network element indicates that the terminal device is allowed to access the first network.

[0280] In some implementations, when the first network-authorized terminal device accesses a network slice and / or logical network in step S310, the access response information may also carry relevant information about the network slice and / or logical network that the terminal device is allowed to access.

[0281] In some implementations, after the control plane network element successfully authorizes and authenticates the terminal device in step S310, the control plane network element can assign a second terminal identifier to the terminal device. This second terminal identifier is used to indicate the terminal device within the control plane network element. As an example, the second terminal identifier can be a context identifier for the terminal device, used to indicate the context of the terminal device within the control plane network element. The control plane network element can uniquely identify the terminal device based on its context. Alternatively, the second terminal identifier can be a temporary identifier for the terminal device. When the second terminal identifier is temporary, the control plane network element registers this temporary identifier with the SSPM network element, which stores the correspondence between the terminal device's first identifier and the second terminal identifier.

[0282] It is understandable that the terminal device needs to establish a session with the UPF network element in the first network through the control plane network element in the subsequent process. Therefore, the access response message can carry the second terminal identifier of the terminal device so that the AMF network element can determine the corresponding terminal device based on the second terminal identifier when interacting with the control plane network element.

[0283] S312, the AMF network element sends a first registration acceptance message to the terminal device, and correspondingly, the terminal device receives the first registration acceptance message from the AMF network element.

[0284] In this step, the first registration acceptance message indicates that the terminal device is allowed to register with the first network. After receiving the first registration acceptance message, the terminal device is equivalent to being registered with the first network and can use subnet services in the first network or access subnet services in the first network after establishing a session. When the access response information carries information about the network slice and / or logical network that the terminal device is allowed to access, the AMF can send the relevant information about the network slice and / or logical network to the terminal device.

[0285] In some implementations, information about the network slices and / or logical networks that the terminal device is allowed to access can be encapsulated in a transparent container and sent to the AMF network element through the access response information, and then forwarded to the terminal device by the AMF network element in the first registration acceptance message.

[0286] S313, the terminal device sends a first session request message to the AMF network element. Correspondingly, the AMF network element receives the first session request message from the terminal device.

[0287] After receiving the first registration acceptance message from the AMF network element, the terminal device triggers the establishment of a PDU session. In this step, the terminal device sends a first session request message to the AMF network element, which is used to request the establishment of a session between the terminal device and the UPF network element in the first network.

[0288] In some implementations, when the first registration acceptance message includes information about the network slice and / or logical network that the terminal device is allowed to access, a first session request message is used to request the establishment of a session between the terminal device in the first network and the network slice and / or logical network. The first session request message also includes the identifier of the requested network slice and / or logical network, which is one or more of the network switching and / or logical networks that the terminal device is allowed to access in the first registration acceptance message.

[0289] It is understandable that if the first registration acceptance message only indicates that the terminal device is allowed to access the first network, then the default session establishment is triggered in step S313.

[0290] It should be noted that when multiple sessions are allowed to be established, the first session request message sent by the terminal device to the AMF network element also includes a corresponding session identifier. The session identifier can be used to distinguish between the session requested to be established in the first session request message and the sessions that have already been established.

[0291] S314, AMF network element is selected as SMF network element.

[0292] In this step, the AMF network element selects the SMF network element that supports the first network based on the identification information of the first network. It should be noted that when accessing the subnet in the aforementioned steps, the AMF network element stores the identification information of the corresponding subnet. Therefore, the AMF network element's context stores the identification information of the first network, and the AMF network element can select the SMF network element based on the stored identification information of the first network.

[0293] In some implementations, when the access network device can directly interact with the UPF network element in the first network and does not require the SMF network element to collect session usage information, the communication method of this embodiment does not require the SMF network element, that is, this step is not a necessary step.

[0294] Optionally, the SMF network element can also be co-located with the AMF network element. When the two are co-located, it is equivalent to the AMF network element integrating the function of the session management network element. In this case, the AMF network element also does not need to select the SMF network element.

[0295] S315, the AMF network element requests the SMF network element to establish a session between the terminal device and the first network.

[0296] In this step, the AMF network element triggers the second UPF network element to allocate uplink tunnel information and downlink tunnel information for the session from the terminal device to the first network according to the first session request message. The second UPF network element is a UPF network element that supports connection to the first network, and there is an interface between the second UPF network element and the access network device.

[0297] When the AMF and SMF network elements are separate, as shown in step S314, the AMF network element stores the identification information of the first network in its context. Therefore, when the AMF network element requests the SMF network element to establish a session, it carries the identification information of the first network. Similar to the selection of the AMF network element by the access network device in step S304, the SMF network element selects a UPF network element that supports connection to the first network based on the identification information of the first network. This UPF network element is the second UPF network element.

[0298] After receiving a session establishment request from the AMF network element, the SMF network element triggers the second UPF network element to allocate uplink tunnel information and downlink tunnel information. That is, the SMF network element requests the selected second UPF network element to allocate uplink tunnel information and downlink tunnel information, and sends the first uplink tunnel information and the first downlink tunnel information allocated by the second UPF network element to the AMF network element through the session establishment response message. The first uplink tunnel information is used for the access network to send uplink data of the session to the second UPF network element, and the first downlink tunnel information is used for the session anchor UPF network element (i.e., the first UPF network element located in the first network) to send downlink data of the session to the second UPF network element.

[0299] It is understandable that when the AMF network element and the SMF network element are co-located or the SMF network element is not needed, the operation performed by the SMF network element in this step can be delegated to the AMF network element. That is, the AMF network element selects the second UPF network element through the identification information of the first network, and the AMF network element triggers the second UPF network element to allocate uplink tunnel information and downlink tunnel information. In other words, the AMF network element requests the allocation of the corresponding uplink tunnel information and downlink tunnel information.

[0300] S316, the AMF network element sends a second session request message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the second session request message from the AMF network element.

[0301] The second session request message is used to request the establishment of a session between the terminal device and a UPF network element in the first network. The second session request message includes the first downlink tunnel information allocated by the second UPF network element. When the first session request message includes the identifier of a network slice and / or logical network, the second session request message accordingly includes the identifier of the aforementioned network slice and / or logical network. The second session request message may also include the current location information of the terminal device.

[0302] In the first network, the network element responsible for session processing can be co-located with the control plane network element of the first network, or it can be separate. When the network element responsible for session processing in the first network receives a request message to establish a session, it needs to obtain the terminal's session subscription information and / or session policy information in order to establish a session.

[0303] Since session subscription information and / or session policy information are stored in the SSPM network element, the network element responsible for session processing in the first network queries the SSPM network element based on the terminal's identification information to obtain the terminal's session subscription information and / or session policy information. The method for obtaining the terminal identifier is as follows:

[0304] In some implementations, the second session request message also includes a second terminal identifier assigned to the terminal device by the control plane network element in step S311. When the control plane network element of the first network is co-located with the session management network element of the first network, that is, when the control plane network element of the first network integrates the functions of the session management network element of the first network, the control plane network element of the first network supports control of the UPF in the first network. Based on the second terminal identifier, the control plane network element can determine the terminal device corresponding to the second session request message and obtain session subscription information and / or session policy information.

[0305] It is understandable that when the first session request message in step S313 includes the first identifier of the terminal device, the second session request message can also include the first identifier of the terminal device. The control plane network element can also determine the terminal device corresponding to the second session request message and obtain the session subscription information based on the first identifier of the terminal device.

[0306] In some implementations, when the control plane network element and the session management network element of the first network are separate, the control plane network element of the first network also needs to send a request message to the session management network element. The session management network element can determine the corresponding terminal device based on the first identifier included in the request message and obtain session subscription information and / or session policy information. For privacy and security considerations, the second request message may not include the first identifier of the terminal device. In this case, the session management network element in the first network determines the terminal device corresponding to the session based on the second terminal identifier of the terminal device. Specifically, if the control plane network element of the first network registers the second terminal identifier with the SSPM network element as shown in step S311, the session management network element in the first network can directly query the SSPM network element based on the second terminal identifier to obtain the terminal's session subscription data and / or session policy information.

[0307] In the embodiment shown in Figure 3 of this application, it is assumed that the control plane network element of the first network integrates the functions of the session management network element of the first network.

[0308] S317, Subnet control plane elements obtain session policies and / or session policy information.

[0309] In this step, the control plane network element of the first network obtains session subscription information and / or session policy information from the SSPM network element based on the first identifier or the second terminal identifier included in the second request message. The session subscription information may include information such as the network slices and logical subnets that the terminal device in the first network is allowed to access, and the location range within which the terminal device is allowed to access a particular network slice or logical subnet. The session policy information may include the quality of service (QoS) information corresponding to the session, such as the maximum allowed bandwidth and scheduling priority for the session.

[0310] It is understandable that, since the SSPM network element stores the correspondence between the first identifier and the second terminal identifier of the terminal device, the control plane network element can also obtain the above information from the SSPM network element based on the second terminal identifier included in the second request message.

[0311] S318, Subnet control plane network element selection subnet UPF network element.

[0312] Based on the session subscription information and the second session request message obtained from the SSPM network element, the control plane network element or the session management network element of the first network can determine whether to allow the establishment of a session between the terminal device and the UPF network element in the first network. Once the session is allowed, the control plane network element or the session management network element of the first network can select a suitable UPF network element from the UPF network elements in the first network based on the network slice, logical subnet information, and the location information of the terminal device included in the second session request message.

[0313] For example, select a UPF network element that supports network slices and logical subnets in the second session request message, or select a UPF network element that is close to the current location of the terminal device. The UPF network element selected by the control plane network element or the session management network element of the first network is the first UPF network element in the first network.

[0314] S319, establish a session on the subnet UPF element.

[0315] In this step, the control plane element or session management element of the first network sends a third session request message to the first UPF element in the first network. This third session request message requests the establishment of a session between the terminal device and the first network within the first UPF element. The message includes first downlink tunnel information allocated by the second UPF element. The first UPF element then sends downlink data to the second UPF element based on this first downlink tunnel information. Upon receiving the third session request message, the first UPF element allocates second uplink tunnel information for the terminal device's session, enabling it to receive uplink data from the second UPF element.

[0316] In some implementations, the third session request message may also include the configuration rules of the UPF network element. For example, when the first network only allows terminal devices to access specific network slices or logical subnets within it, the configuration rules of the UPF network element can be filtering rules. The UPF network element will discard all data packets whose source / destination addresses are not allowed logical networks or network slices according to the configuration rules.

[0317] It is understandable that if the terminal device includes corresponding access rules in the session subscription information or session policy in the first network, the UPF network element also needs to be configured according to the access rules. For example, if the session policy restricts the terminal device from accessing specific websites, such as non-working websites, the UPF network element will filter or discard data packets with source / destination addresses of specific websites according to the configured rules.

[0318] S320, the subnet control plane element sends a session establishment response message to the AMF element. Correspondingly, the AMF element receives the session establishment response message from the subnet control plane element.

[0319] In this step, the session establishment response message includes a non-access stratum (NAS) message to indicate to the terminal device that the session establishment was successful, and also includes second uplink tunnel information allocated by the first UPF network element in the first network.

[0320] In some implementations, after the control plane network element of the first network determines the corresponding QoS parameters based on the session policy information, the session establishment response message may also include the QoS parameters.

[0321] S321, the AMF network element requests the access network device to allocate session resources.

[0322] In this step, the AMF network element sends a message to the access network device to request the allocation of session resources. The message includes a NAS message indicating that the session has been successfully established, QoS parameter information corresponding to the session, and the first uplink tunnel information allocated by the second UPF network element. Based on the first uplink tunnel information, the access network device can send uplink data to the second UPF network element.

[0323] The access network device allocates corresponding radio air interface resources for the terminal device's session based on QoS parameters, forwards the NAS message indicating successful session establishment to the terminal device, and sends a response message including downlink tunnel information allocated by the access network device to the AMF network element.

[0324] S322, AMF network element performs session update.

[0325] Upon receiving a response message containing downlink tunnel information allocated by the access network device, the AMF network element sends a session update request message to the second UPF network element through the SMF network element. The session update request message includes the downlink tunnel information and the second uplink tunnel information allocated by the access network device. Using the downlink tunnel information allocated by the access network device, the second UPF network element can send downlink data to the access network device; using the second uplink tunnel information, the second UPF network element can send uplink data to the first UPF network element in the first network.

[0326] In this step, the uplink and downlink paths of the session between the terminal device and the first UPF network element in the first network can be established through session update, so that the terminal device can access the relevant services in the first network.

[0327] In this embodiment, when the terminal device selects a subnet based on the subnet selection list and the broadcast subnet identifier information, it does not need to consider the PLMN ID configured in the SIM card installed on the terminal device and the PLMN ID broadcast by the access network device. Therefore, even if the terminal device and the access network device belong to different operators, the terminal device can still initiate a request to access the subnet to the access network device.

[0328] Terminal devices request access registration to the first network from the AMF network element through the access network device. The control plane network element in the first network obtains the subscription information between the terminal device and the first network, and determines whether to allow the terminal device to access the first network based on the subscription information. By authorizing and authenticating terminal devices through the control plane network element of the newly set subnet in the architecture, the control authority for accessing the subnet can be handed over to the subnet tenant. It is no longer necessary for the terminal device's home operator to establish a PDU session with the subnet, allowing terminal devices belonging to different operators to access the same subnet within the scenario, thus providing convenience for subnet users.

[0329] In the embodiment shown in Figure 3 above, in step S306, the AMF network element requests the home operator indicated by the terminal device to authenticate the terminal device. This is predicated on the existence of a roaming protocol between operator OP1 and operator OP2 in network architecture 100. Interface 1 serves as the roaming interface, and the AMF network element deployed by OP1 can initiate an authentication request to the AUSF / UDM network element deployed by OP2 through interface 1. When there is no roaming protocol between operator OP1 and operator OP2, interface 1 is not present in network architecture 100. In this case, the subnet operator cooperates with both operator OP1 and operator OP2. Interface 2 serves as the capability open interface for operator OP2, providing an interactive interface for authentication. The subnet control plane network element initiates an authentication request to the AUSF / UDM network element deployed by OP2 through interface 2. The communication method when there is no roaming protocol between operator OP1 and operator OP2 is described below.

[0330] Figure 4 is a flowchart illustrating a communication method provided in an embodiment of this application. As shown in Figure 4, steps S400 to S405 are consistent with steps S300 to S305 in the above embodiments. The difference in the communication method in this embodiment lies in the following steps:

[0331] S406 requests the AUSF / UDM network element of the operator to perform identity authentication through the subnet control plane network element.

[0332] In this step, since there is no roaming protocol between operator OP1 and operator OP2, the subnet control plane network element initiates an authentication request through interface 2 to the AUSF / UDM network element deployed by the home operator indicated by the terminal device.

[0333] Figure 5 is a schematic diagram of a process for requesting identity authentication from an AUSF / UDM network element through a subnet control plane network element according to an embodiment of this application. As shown in Figure 5, the identity authentication process includes the following steps:

[0334] S501, the AMF network element sends a first authentication request message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the first authentication request message from the AMF network element.

[0335] In this identity authentication process, the first request message in step S405 already carries the SUPI / SUCI of the terminal device. Therefore, in this step, the first authentication request message sent by the AMF to the control plane network element of the first network contains the SUPI / SUCI of the terminal device.

[0336] In step S502, the subnet control plane element sends a first authentication request message to the AUSF / UDM network element deployed by the terminal equipment's home operator. Correspondingly, the AUSF / UDM network element receives the first authentication request message from the subnet control plane element.

[0337] Based on the SUPI / SUCI of the terminal device, the owner operator of the terminal device can be determined to be OP2, and the first authentication request message is sent to the AUSF / UDM network element deployed in OP2.

[0338] S403, the AUSF / UDM network element deployed by the terminal equipment's home operator sends a first authentication response message to the AMF network element. Correspondingly, the AMF network element receives the first authentication response message from the AUSF / UDM network element.

[0339] In this step, the AUSF / UDM network element deployed in OP2 generates an authentication vector based on the SUPI / SUCI carried in the first authentication request message, and carries the authentication vector in the first authentication response message. The AUSF / UDM network element deployed in OP2 sends the first authentication response message to the control plane network element in the first network, and the control plane network element forwards the first authentication response message to the AMF network element.

[0340] S504, the AMF network element sends a second authentication request message to the terminal device. Correspondingly, the terminal device receives the second authentication request message from the AMF network element.

[0341] The AMF network element generates a second authentication request message for the non-access stratum (NAS) based on the authentication vector in the received first authentication response message, and sends the second authentication request message to the terminal device. The second authentication request message carries the authentication vector.

[0342] In some implementations, the first authentication request message also includes a first terminal identifier assigned to the terminal device by the AMF network element in the embodiment shown in Figure 3. Correspondingly, the first authentication response message also includes the first terminal identifier. The AMF network element locates the context of the terminal device based on the first terminal identifier, and then sends the second authentication request message in this step to the terminal device determined based on the first terminal identifier.

[0343] S505, the terminal device sends a second authentication response message to the AMF network element. Correspondingly, the AMF network element receives the second authentication response message from the terminal device.

[0344] The terminal device calculates and generates a second authentication response message based on the second authentication request message sent by the AMF network element. The second authentication response message contains authentication information calculated based on the authentication vector. The terminal device sends the second authentication response message to the AMF network element. As an example, the verification information can be a digital signature calculated by the terminal device based on the random number carried in the second authentication request message.

[0345] S506, the AMF network element performs local verification based on the second authentication response message.

[0346] In this step, the AMF network element needs to verify the identity based on the verification information carried in the second authentication response message. Successful verification indicates that the terminal device is a subscribed user of its designated home operator OP2, and identity authentication is successful. It should be noted that if the authentication vector in the first authentication response message does not contain verification information, the AMF network element cannot achieve identity authentication and needs to execute the subsequent steps shown in Figure 5.

[0347] In step S507, the AMF network element sends a third authentication request message to the AUSF / UDM network element deployed by the terminal equipment's home operator. Correspondingly, the AUSF / UDM network element receives the third authentication request message from the AMF network element.

[0348] When the AMF network element is unable to perform local authentication, the AMF network element sends a third authentication request message to the control plane network element of the first network. The third authentication request message contains authentication information generated by the terminal device based on the authentication vector. The control plane network element forwards the third authentication request message to the AUSF / UDM network element deployed in OP2.

[0349] In some implementations, the third authentication request message also includes a second terminal identifier assigned to the terminal device by the control plane network element of the first network in the embodiment shown in Figure 3. The control plane network element can locate the context of the terminal device based on the second terminal identifier, and then forward the third authentication request message to the AUSF / UDM network element deployed by the operator OP2 to which the terminal device belongs.

[0350] In S508, the AUSF / UDM network element deployed by the terminal equipment's home operator sends a third authentication response message to the AMF network element. Correspondingly, the AMF network element receives the third authentication response message from the AUSF / UDM network element.

[0351] In this step, the AUSF / UDM network element deployed in OP2 verifies the authentication information carried in the third authentication request message. Based on the successful verification, a third authentication response message is generated and sent to the control plane network element of the first network. The control plane network element forwards the third authentication response message to the AMF network element. The third authentication response message may also carry key information for security protection of subsequent communications, such as the root key Kamf.

[0352] In some implementations, the control plane network element can also deduce based on the key information sent by the AFS / UDM network element and send the deduced key to the AMF network element, meaning that the control plane network element does not simply forward the key.

[0353] In the identity authentication process shown in Figure 5, the first request message in step S405 carries the SUPI / SUCI of the terminal device. If the first request message does not carry the SUPI / SUCI of the terminal device, the AMF network element needs to obtain the SUPI / SUCI from the terminal device before initiating the above process.

[0354] Figure 6 is a schematic diagram of a process for requesting authentication from an AMF / UDM network element through a subnet control plane network element according to another embodiment of this application. In the process shown in Figure 6, the AMF network element is responsible for forwarding authentication-related NAS messages between the terminal device and the subnet control plane network element. Specifically, it includes the following steps:

[0355] S601, the subnet control plane element sends an ID request message to the terminal device. Correspondingly, the terminal device receives the ID request message from the subnet control plane element.

[0356] When the first request message does not carry the SUPI / SUCI of the terminal device, the control plane network element of the first network sends an ID request message to the AMF network element. The AMF network element forwards the ID request message to the terminal device. The ID request message is used to request the SUPI / SUCI of the terminal device. This message may include the first terminal identifier so that the AMF network element can identify the terminal device.

[0357] S602, the terminal device sends an ID response message to the subnet control plane element. Correspondingly, the subnet control plane element receives the ID response message from the terminal device.

[0358] The terminal device sends an ID response message to the AMF network element, which then forwards the message to the control plane network element of the first network. The ID response message contains the terminal device's SUPI / SUCI. This message may include a second terminal identifier so that the subnet control plane network element can identify the terminal device.

[0359] S603, the subnet control plane network element sends a first authentication request message to the AUSF / UDM network element deployed by the terminal equipment's home operator. Correspondingly, the AUSF / UDM network element receives the first authentication request message from the subnet control plane network element.

[0360] The control plane network element can determine the home operator of the terminal device as OP2 based on the SUPI / SUCI of the terminal device, and sends the first authentication request message to OP2.

[0361] S604, the AUSF / UDM network element deployed by the terminal equipment's home operator sends a first authentication response message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the first authentication response message from the AUSF / UDM network element.

[0362] The AUSF / UDM network element deployed in OP 2 sends the first authentication response message to the control plane network element in the first network.

[0363] S605, the subnet control plane element sends a second authentication request message to the terminal device. Correspondingly, the terminal device receives the second authentication request message from the subnet control plane element.

[0364] The control plane network element of the first network generates a NAS second authentication request message based on the authentication vector in the received first authentication response message. The control plane network element sends the second authentication request message to the AMF network element, and the AMF network element forwards the second authentication request message to the terminal device. The second authentication request message carries the authentication vector.

[0365] In some implementations, the second authentication request message also includes a first terminal identifier assigned to the terminal device by the AMF network element in the embodiment shown in Figure 3. The AMF network element can locate the context of the terminal device based on the first terminal identifier, and then forward the second authentication request message in this step to the terminal device determined based on the first terminal identifier.

[0366] S606, the terminal device sends a second authentication response message to the subnet control plane element. Correspondingly, the subnet control plane element receives the second authentication response message from the terminal device.

[0367] The terminal device calculates and generates a second authentication response message based on the second authentication request message sent by the control plane network element of the first network. The second authentication response message contains verification information calculated based on the authentication vector. The terminal device sends the second authentication response message to the AMF network element and forwards the second authentication response message to the control plane network element through the AMF network element.

[0368] S607, the subnet control plane network element performs local verification based on the second authentication response message.

[0369] Similar to step S506, the control plane network element of the first network needs to verify the identity based on the verification information carried in the second authentication response message. Successful verification indicates that the terminal device is a subscribed user of the indicated home operator OP2, and identity authentication is successful. If the authentication vector in the first authentication response message of step S604 does not contain verification information, the control plane network element cannot achieve identity authentication and needs to execute the subsequent steps shown in Figure 6.

[0370] S608, the subnet control plane network element sends a third authentication request message to the AUSF / UDM network element deployed by the terminal equipment's home operator. Correspondingly, the AUSF / UDM network element receives the third authentication request message from the subnet control plane network element.

[0371] When the control plane network element of the first network is unable to perform local authentication, the control plane network element sends a third authentication request message to the AUSF / UDM network element deployed in OP2. The third authentication request message contains authentication information generated by the terminal device based on the authentication vector.

[0372] In some implementations, when the AMF network element forwards the second authentication response message to the control plane network element in step S606, the second authentication response message carries the second terminal identifier assigned by the control plane network element to the terminal device. The control plane network element can locate the context of the terminal device based on the second terminal identifier, and then send a third authentication request message to the AUSF / UDM network element deployed by the home operator OP2 of the terminal device determined according to the second terminal identifier.

[0373] S609, the AUSF / UDM network element deployed by the terminal equipment's home operator sends a third authentication response message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the third authentication response message from the AUSF / UDM network element.

[0374] In this step, the AUSF / UDM network element deployed in OP2 verifies the authentication information carried in the third authentication request message, generates a third authentication response message based on successful verification, and sends the third authentication response message to the control plane network element of the first network. The third authentication response message may also carry key information for security protection of subsequent communications.

[0375] In the embodiment shown in Figure 5 above, the AMF network element and the AUSF / UDM network element deployed in OP2 are the main entities performing identity authentication, while in the embodiment shown in Figure 6, the control plane network element of the first network and the AUSF / UDM network element deployed in OP2 are the main entities performing identity authentication.

[0376] Similar to the subnet access authentication process shown in Figure 3, after the terminal device passes identity authentication and is confirmed to be a subscribed user of its designated home operator OP2, the subnet control plane network element can further determine whether to allow the terminal device to access the subnet it wishes to access based on the subscription information between the terminal device and the subnet, as shown in Figure 4. The communication method in this embodiment also includes the following steps:

[0377] S407, the AMF network element sends a second request message to the subnet control plane network element. Correspondingly, the subnet control plane network element receives the second request message from the AMF network element.

[0378] In this step, the AMF network element sends a second request message to the control plane network element of the first network based on the subnet identifier. The second request message is used to request that the terminal device access the first network. In some implementations, the first request message in step S403 may also carry a subnet subscription identifier corresponding to the first network. Correspondingly, the second request message may also carry the subnet subscription identifier of the terminal device in the first subnet.

[0379] It should be noted that the execution order between steps S406 and S407 is variable. If the authentication process of step S406 uses the embodiment shown in Figure 5 to authenticate the terminal device, step S406 is executed before step S407. If the embodiment shown in Figure 6 is used to authenticate the terminal device, step S407 is executed before step S406.

[0380] Optionally, when the subnet subscription identifier is an external identifier of the terminal device, the communication method in this embodiment may further include step S408.

[0381] S408 checks whether the first subnet's contract identifier is a valid external identifier.

[0382] This step can verify whether the subnet subscription identifier is a valid external identifier in two ways, one of which is:

[0383] The control plane network element of the first network requests the external identifier of the terminal device from the UDM network element deployed in OP2. If the external identifier of the terminal device contains the subnet subscription identifier carried in the second request message, the subnet subscription identifier is successfully verified, indicating that it is a valid external identifier.

[0384] The second is:

[0385] The control plane element of the first network sends the subnet subscription identifier carried in the second request message to the UDM element deployed in OP2, and requests the UDM element to verify whether it is a valid external identifier. The control plane element indicates the verification result through the response information sent by the UDM element.

[0386] Similar to step S307-0 in the embodiment shown in Figure 3, the main difference is that when there is no roaming agreement between operator OP1 and operator OP2, the execution subject for verifying whether the subnet subscription identifier is a valid external identifier in step S408 is the control plane network element of the first network and the AUSF / UDM network element deployed by OP2.

[0387] S409, Subnet control plane network elements obtain the subscription information of terminal devices in the first network.

[0388] S410, the subnet control plane network element performs access authentication for terminal equipment.

[0389] S411, the subnet control plane network element authorizes and authenticates the terminal device based on the terminal device's subscription information in the first network.

[0390] S412, the subnet control plane element sends access response information to the AMF element. Correspondingly, the AMF element receives the access response information from the subnet control plane element.

[0391] Since the execution subject in steps S409 to S412 is the subnet control plane network element, steps S409 to S412 are consistent with steps S308 to S311 in the embodiment shown in Figure 3.

[0392] When the terminal device is authenticated in step S406 using the method shown in Figure 6, the access response information can also carry the key Kamf. The AMF network element deduces the NAS key and Kgnb based on Kamf in order to protect the NAS messages and air interface messages of the terminal device. The control plane network element can deduce Kamf based on the key information received in step S609, or directly use the key information received in S609 as Kamf.

[0393] S413, the AMF network element sends a first registration acceptance message to the terminal device. Correspondingly, the terminal device receives the first registration acceptance message from the AMF network element.

[0394] This step is the same as step S313 in Figure 3. In some implementations, the AMF network element can also perform key deduction based on the key received in step S412 or the key received in step S408 (when the terminal device is authenticated in step 5 in S406), and perform operations such as starting NAS security mode and sending the initial context of the terminal device to the access network device.

[0395] When the terminal device receives the first registration acceptance message from the AMF network element, it triggers the establishment of a PDU session. The process of establishing a session between the terminal device and the UPF network element in the first network in the embodiment shown in Figure 4 is the same as that in the embodiment shown in Figure 3, and will not be described again here.

[0396] In this embodiment, the AMF network element initiates an authentication request to the AUSF / UDM network element deployed in OP2 through the subnet control plane network element. It does not need to consider whether there is a roaming agreement between the operator deploying the subnet and the operator to which the terminal device belongs, thus expanding the application scenarios of the communication method proposed in this application embodiment.

[0397] In the communication method proposed in this application embodiment, a subnet switch can also be added to the terminal device. When the subnet switch is turned on, the terminal device can select a subnet according to the configured subnet selection list, enabling the terminal device to access the subnet as needed. The operator of the terminal device can turn on the subnet switch when the terminal device is near a subnet location, avoiding unnecessary energy consumption caused by the terminal device performing network searches when it cannot access the subnet, thus saving energy for the terminal device.

[0398] It is understood that, in addition to the subnet switch newly proposed in this application embodiment, existing terminal devices also have a mainnet switch, such as the "mobile data" switch on a mobile terminal, which is equivalent to a mainnet switch. If the terminal device supports dual-mode or multi-mode technology, that is, it supports accessing two or more networks simultaneously through two or more access network devices, when the terminal device simultaneously turns on the subnet switch and the mainnet switch, the terminal device can simultaneously access and register to the subnet and the mainnet through both the mainnet access network device and the subnet access network device, thereby enabling separate access to subnet services and mainnet services. In the prior art, access and registration to the subnet and the mainnet can only be achieved through different access network devices when the terminal device supports dual-mode / multi-mode technology. The following describes how to simultaneously access and register to the subnet and the mainnet through a single access network device.

[0399] Figure 7 is a schematic diagram illustrating the process of a terminal device simultaneously accessing and registering to a subnet and a main network according to an embodiment of this application. As shown in Figure 7, since the terminal device needs to simultaneously access and register to both the subnet and the main network, and considering that the process of the terminal device accessing and registering to the subnet has been described in detail in the above embodiments, the process of the terminal device accessing and registering to the main network through the same access network device is based on the embodiment shown in Figure 3. The content involving subnet access will not be repeated, and specifically includes the following steps:

[0400] S700-1, Terminal Equipment Configuration Subnet Selection List and PLMN Selection List

[0401] The PLMN selection list contains at least one PLMN ID, which identifies the corresponding network. All networks corresponding to the PLMN IDs in the PLMN selection list are selectable by the terminal device. The terminal device selects the desired network to connect to based on the PLMN ID.

[0402] S700-2, access network equipment exchanges subnet identifiers and PLMN IDs with AMF network elements.

[0403] Both the access network equipment and the AMF network element support multiple different large networks. During the initial signaling interaction, the access network equipment and the AMF network element can exchange the PLMN IDs of the large networks they support, which are configured respectively.

[0404] S701, the access network device broadcasts the subnet identifier and PLMN ID. Correspondingly, the terminal device receives the subnet identifier and PLMN ID from the access network device.

[0405] S702, the terminal device selects a subnet and a main network based on the subnet selection list, the PLMN selection list, and broadcasts.

[0406] In this step, the terminal device matches the PLMN broadcast by the access network device with the configured PLMN selection list. If a PLMN ID exists in the PLMN selection list that matches the PLMN ID broadcast by the access network device, it indicates that the network supported by the access network device matches the network selectable by the terminal device, and the terminal device can access the network corresponding to the PLMN ID through the access network device. Similarly, the PLMN selection list can also indicate the priority of the network, and the terminal device can select the network with the highest priority as the network to be accessed.

[0407] S703, the terminal device sends a first request message, the identification information of the first network, and the ID of the first PLMN to the access network device, and the access network device receives the first request message, the identification information of the first network, and the ID of the first PLMN from the terminal device.

[0408] The first request message is also used to request that the terminal device be connected to the first PLMN, which is the PLMN selected by the terminal device in step S702. The terminal device sends the ID of the first PLMN to the access network device.

[0409] S704, the access network device selects the AMF network element based on the identification information of the first network and the ID of the first PLMN.

[0410] In this step, the AMF network element selected by the access network device needs to support both the subnet corresponding to the first network subnet identifier and the first PLMN.

[0411] S705, the access network device sends a first request message, the identification information of the first network, and the ID of the first PLMN to the AMF network element. Correspondingly, the AMF network element receives the first request message, the identification information of the first network, and the ID of the first PLMN from the access network device.

[0412] S706, the AMF network element requests the AUSF / UDM network element deployed by the operator to which the terminal device belongs to perform identity authentication.

[0413] In this step, when requesting access to the first PLMN, it is only necessary to request the AUSF / UDM network element deployed by the home operator indicated by the terminal device to perform identity authentication. Once the terminal device passes the identity authentication, the terminal device can access the first PLMN through the subnet access network device.

[0414] It should be noted that the prerequisite for the above terminal devices to access the subnet and the main network through the same access network device is that there is a roaming protocol between the main network operator OP1 that deploys the subnet and the terminal device's home operator OP2 so that the terminal device can access the main network through the main network deployed by OP1 (the access mode of the main network can be the home routing mode or the local routing mode). Otherwise, even if the terminal device passes the identity authentication, the terminal device can only continue to access the subnet through the subnet control plane and cannot access the main network.

[0415] The method indicated in step S706 requires OP1 to share the AMF network element with the subnet. For scenarios that do not support OP1 sharing the AMF network element with the subnet, if it is necessary to access both the subnet's services and the main network's services simultaneously, the following steps must be performed:

[0416] S707, Subnet Access Authorization.

[0417] The part involving subnet access in this step is the same as steps S307-0 to S312 in the embodiment shown in Figure 3. The difference is that the first network also provides the terminal device with the ability to access the first PLMN service. Therefore, the subscription information of the terminal device in the first network also includes service information that allows the terminal device to access the first PLMN service through the first network.

[0418] In this implementation, the PLMN ID in steps S700-1, S700-2, and S701 can be omitted, and the first request information in S703 is also used to request access to the first service of the first PLMN through the first network. The control plane network element in the first network can determine whether to allow the terminal device to access the first PLMN through the first network and the service information that allows the terminal device to access the first PLMN service through the first network (e.g., allowing it to access the IP Multimedia Subsystem (IMS) service of the first PLMN) based on the terminal device's subscription information in the first network.

[0419] Correspondingly, the access response information sent by the subnet control plane network element to the AMF network element may also carry information indicating that the terminal device is allowed to access the first service of the first PLMN through the first network. The AMF network element sends the information indicating that the terminal device is allowed to access the first service of the first PLMN through the first network to the terminal device.

[0420] In some implementations, the information indicating permission for the terminal device to access the first service of the first PLMN through the first network can also be encapsulated in a transparent container, sent to the AMF network element through the access response information, and then forwarded to the terminal device by the AMF network element in the first registration acceptance message.

[0421] For example, the subscription information of the terminal device in the first network can indicate that the terminal device is allowed to access the IMS service or Internet service of the first PLMN. Correspondingly, the first registration acceptance message can indicate the IMS service of the first PLMN that the terminal device is allowed to access.

[0422] It should be noted that allowing terminal devices to access the first PLMN through the first network means that the first network communicates with the first PLMN as a subnet, and the first PLMN opens the main network services to the first network. When the terminal device only turns on the subnet switch and turns off the main network switch, it can use the main network services provided by the first PLMN by accessing the first network.

[0423] S708, Session established.

[0424] The part involving subnet access in this step is the same as steps S313 to S322 in the embodiment shown in Figure 2. However, in order to access the PLMN's services through the first network, the following differences also exist:

[0425] When the terminal device receives information in step S707 indicating that it is allowed to access a first service of the first PLMN through the first network, the first session request message also includes information indicating the first service. As an example, based on the service information of the PLMN that the terminal device is allowed to access in the first registration acceptance message, for example, if the first registration acceptance message indicates that the terminal device is allowed to access the IMS service of the PLMN, then the first session request message includes the data network name (DNN) information corresponding to the IMS service and the PLMN identifier. The PLMN identifier can be included in the DNN information, and the control plane network elements of the first network can determine the type of PLMN service that the terminal device wants to access based on the DNN information.

[0426] When a terminal device accesses a PLMN service through the first network, as an example, the session anchor point can be the first UPF network element in the first network. When configuring the first UPF network element, the control plane network element of the first network needs to configure corresponding rules to allow the terminal device to communicate with the specified PLMN. For example, the configuration rules can allow the terminal device to communicate with the IMS network in the first PLMN.

[0427] In some implementations, the session anchor point can also be a specified PLMN. The control plane network element of the first network needs to select the SMF network element in the first PLMN and request the SMF network element to establish a session between the terminal device and the UPF network element in the first PLMN. That is, when the session anchor point is the first PLMN, the control plane network element in the first network also needs to establish a session between the first UPF network element in the first network and the UPF network element in the first PLMN.

[0428] For example, after a session is established for a terminal device, the control plane network element of the first network sends a large network session establishment request message to the SMF network element in the first PLMN. This message includes the DNN information corresponding to the IMS service and the second downlink tunnel information allocated by the first UPF network element. The SMF in the first PLMN selects a UPF network element that supports the service from the UPF network elements in the first PLMN based on the DNN information corresponding to the IMS service, and requests the UPF network element in the first PLMN to allocate the corresponding tunnel information. The UPF network element in the first PLMN transmits downlink data to the first UPF network element based on the second downlink tunnel information.

[0429] In this embodiment, the terminal device can access both the subnet and the main network through the same access network device when both the subnet switch and the main network switch are turned on simultaneously. Alternatively, it can use the main network service through the accessed subnet only when the subnet switch is turned on. For terminal devices that do not support dual-mode / multi-mode, this can improve the user experience and meet access requirements.

[0430] In the embodiment shown in Figure 7, when a terminal device registers to both the main network and the subnet simultaneously, it needs to share the AMF network element. If the shared AMF network element is upgraded when accessing the network, it will affect both subnet access and main network access. To address this technical problem, this application proposes a communication method that separates subnet registration access from main network registration access, thereby achieving decoupled control of the registration access process.

[0431] To achieve separate registration and access between the main network and subnets, this application provides two different mobility management network elements, AMF 1 and AMF 2. Terminal devices access the subnet through AMF 1 and the PLMN through AMF 2. That is, AMF 1 corresponds to the core network of the subnet, and AMF 2 corresponds to the core network of the PLMN. In some implementations, AMF 1 and AMF 2 can be the same mobility management network element. When AMF 1 and AMF 2 are the same AMF element, this AMF element stores two contexts for the terminal device. These different contexts are used for accessing the subnet and accessing the PLMN, respectively. In other words, even when AMF 1 and AMF 2 are combined into the same AMF element, the terminal device still registers separately to the main network and the subnet.

[0432] It is understood that the AMF network element here is the name for the mobility management network element in the 5G communication system. In the future, there may be other naming methods for mobility management network elements. The AMF network element mentioned in this embodiment is only an exemplary description.

[0433] Since the terminal device may not be able to connect to two access network devices at the same time, the terminal device can only establish a radio resource control (RRC) layer connection with one access network device. The terminal device connects to the AMF network elements of the two core networks through RRC. Figure 8 is a schematic diagram of the terminal device protocol stack provided in an embodiment of this application. As shown in Figure 8, the first NAS signaling connection is the signaling connection between the terminal device and AMF 1, and the second NAS signaling connection is the signaling connection between the terminal device and AMF 2.

[0434] When a terminal device needs to send a service request, its NAS layer generates a corresponding NAS message. This NAS message is first sent to the terminal device's RRC (Redirect Router Control), and then forwarded to the access network device via the RRC protocol. The access network device then sends the NAS message to the AMF (Activity Management Element) via the interface protocol between the access network device and the AMF. Based on the routing information associated with the NAS message, the access network device can determine whether the NAS message is associated with AMF 1 or AMF 2, and thus send the NAS message to the mobility management element associated with the NAS message. The following section, with reference to Figure 8, explains in detail how the decoupled control of the registration and access process is achieved.

[0435] Figure 9 is a schematic diagram illustrating the process of a terminal device separately accessing a subnet and a main network according to an embodiment of this application. As shown in Figure 9, similar to the embodiment shown in Figure 7, the process of the terminal device implementing decoupled registration access is based on the embodiment shown in Figure 3. The content involving subnet access will not be repeated, but specifically includes the following steps:

[0436] S900-1, Terminal Equipment Configuration Subnet Selection List.

[0437] S900-2, access network equipment exchanges subnet identifiers with AMF 1.

[0438] S901, the access network device broadcasts the subnet identifier. Correspondingly, the terminal device receives the subnet identifier from the access network device.

[0439] S902, the terminal device selects a subnet based on the subnet selection list and broadcast.

[0440] In step S903, the terminal device sends a first registration request message and the identification information of the first network to the access network device. Correspondingly, the access network device receives the first registration request message and the identification information of the first network from the terminal device.

[0441] S904, the access network device selects AMF 1 based on the identification information of the first network.

[0442] S905, the access network device sends a first registration request message and the identification information of the first network to AMF 1. Correspondingly, AMF 1 receives the first registration request message and the identification information of the first network from the access network device.

[0443] S906, the terminal device connects to the first network and establishes a session.

[0444] The steps S900 to S905 above are basically the same as steps S300 to S305 in the embodiment shown in Figure 3. Step S906 corresponds to steps S306 to S322 in the embodiment shown in Figure 3, which connects the terminal device to the subnet indicated by the first network subnet identifier and establishes a session between the terminal device and the first UPF network element in the first network. The specific process will not be elaborated here. The difference between the above steps and the embodiment shown in Figure 3 is that after the access network device receives the first registration request message in step S903, it determines that the message is the first message sent to AMF 1.

[0445] As shown in Figure 8, when a terminal device needs to connect to the first network, a first NAS signaling connection is established between the terminal device and AMF 1, which serves the first network. This first NAS signaling connection is also known as the first connection. The first NAS signaling connection is used to forward messages between the terminal device and AMF 1.

[0446] The first NAS signaling connection includes the connection between the terminal device and the access network device (i.e., the RRC connection) and the connection between the access network device and AMF 1. In the connection between the terminal device and the access network device, the first NAS signaling connection is associated with first routing information, which is the first connection identifier. After the first NAS signaling connection is established, the terminal device carries the first routing information when sending subsequent uplink NAS messages through the first NAS signaling connection, so that the access network device can determine the AMF 1 corresponding to the first NAS signaling connection based on the first routing information. When the access network device receives a downlink NAS message from AMF 1, it also carries the first routing information when sending the downlink NAS message to the terminal device, so that the terminal device can identify the NAS signaling connection corresponding to the NAS message.

[0447] When a terminal device registers with the first network for the first time (i.e., it has not registered with the first network before), or when the connection state between the terminal device and the first network is idle (i.e., it has registered with the first network but the first NAS signaling connection between the terminal device and the first network has been released) and the terminal device needs to send a NAS message to the first network, the terminal device initiates the establishment of the first NAS signaling connection.

[0448] In some implementations, the first routing information is allocated by the terminal device. Accordingly, when the terminal device sends the first registration request message to the access network device in step S903, it will also simultaneously send the first routing information used to associate the first NAS signaling connection. It is understood that if the terminal device sends the first routing information to the access network device, the access network device does not need to allocate the first routing information again after receiving the initial NAS message (i.e., the first registration request message).

[0449] In some other implementations, the access network device allocates first routing information for the first NAS signaling connection and sends it to the terminal device. Correspondingly, when the terminal device sends the first registration request message to the access network device in step S903, it will not send the first routing information associated with the first NAS signaling connection since the first routing information corresponding to the first NAS signaling connection has not yet been allocated. After receiving the first registration request message, the access network device determines that a first NAS signaling connection needs to be established and allocates the first routing information.

[0450] Optionally, in step S903, when triggering the establishment of the first NAS signaling connection, the terminal device may also synchronously send an indication message to indicate the establishment of the first NAS signaling connection between the terminal device and the first network. The access network device can determine whether the first NAS signaling connection needs to be established based on this indication message.

[0451] Alternatively, if the terminal device does not send an indication message, the access network device can determine whether a first NAS signaling connection needs to be established based on the message content sent in step S903. As an example, the access network device can determine whether a first NAS signaling connection needs to be established if the message sent in step S903 does not carry routing identification information, or it can determine whether a first NAS signaling connection needs to be established based on the first routing identification information in the message of step S903. That is, when the access network device determines that there is no NAS signaling connection associated with the routing identification information in the message of step S903, it determines that a first NAS signaling connection needs to be established.

[0452] Understandably, after receiving the initial NAS message from S903, if the access network device determines that a first NAS signaling connection needs to be established, it sends first routing information to the terminal device. The access network device can send a dedicated RRC message to the terminal device after receiving the initial NAS message from S903, carrying the first routing information. Alternatively, the first routing information can be piggybacked onto the terminal device during subsequent interactions with it in the process triggered by the initial NAS message from S903, for example, in the downlink RRC message of the first NAS message sent by AMF 1 to the terminal device, or in the first downlink RRC message after AMF 1 sends the initial context of the terminal device to the access network device.

[0453] It should be noted that the access network device needs to save the first routing information in the context of the terminal device, and at the same time save the corresponding AMF 1 information in the context.

[0454] After completing the above steps, the terminal device has been connected to the corresponding subnet. The following describes how the terminal device connects to the corresponding PLMN.

[0455] S907, Terminal device configuration PLMN selection list.

[0456] S908, the access network device broadcasts the PLMN ID. Correspondingly, the terminal device receives the PLMN ID from the access network device.

[0457] S909: Terminal devices select the main network based on the PLMN selection list and broadcasts.

[0458] Steps S907 to S909 above are similar to steps S700 to S702 in the embodiment shown in Figure 7. In this embodiment, in order to achieve the decoupling operation of subnet access and main network access, the relevant execution operations of main network access are separated from the subnet access process, and the PLMN is selected independently.

[0459] S910, the terminal device sends a second registration request message and the ID of the first PLMN to the access network device. Correspondingly, the access network device receives the second registration request message and the ID of the first PLMN from the terminal device.

[0460] The second registration request message is used to request the terminal device to connect to the first PLMN, which is the PLMN selected by the terminal device in step S909. The terminal device sends the ID of the first PLMN to the access network device.

[0461] It should be noted that the terminal device has already registered to the subnet in steps S900 to S906, and the RRC connection of the terminal device, that is, the signaling connection between the terminal device and the access network device, may be in the connected state. At this time, if the terminal device sends a second registration request message to the access network device, the RRC message needs to be enhanced so that the RRC message can also carry the second registration request message of the NAS layer and the ID information of the first PLMN in the connected state.

[0462] Since this step involves the first NAS message between the terminal device and the first PLMN (i.e., the initial NAS message), the terminal device needs to establish a second NAS connection with AMF 2, which serves the first PLMN. This second NAS signaling connection is the second connection. The second NAS signaling connection is used to forward messages between the terminal device and AMF 2.

[0463] The second NAS signaling connection includes the connection between the terminal device and the access network device (i.e., the RRC connection) and the connection between the access network device and AMF 2. In the connection between the terminal device and the access network device, the second NAS signaling connection is associated with second routing information, which is the second connection identifier. After the second NAS signaling connection is established, the terminal device carries the second routing information when sending subsequent uplink NAS messages through the second NAS signaling connection, so that the access network device can determine the AMF 2 corresponding to the second NAS signaling connection based on the second routing information. When the access network device receives a downlink NAS message from AMF 2, it also carries the second routing information when sending the downlink NAS message to the terminal device, so that the terminal device can identify the NAS signaling connection corresponding to the NAS message.

[0464] When a terminal device registers with the first PLMN for the first time (i.e., it has not registered with the first PLMN before), or when the connection between the terminal device and the first PLMN is in an idle state (i.e. it has registered with the first PLMN but the second NAS signaling connection between the terminal device and the first PLMN has been released) and the terminal device needs to send a NAS message to the first PLMN, the terminal device initiates the establishment of the second NAS signaling connection.

[0465] In some implementations, the second routing information is allocated by the terminal device. Accordingly, when the terminal device sends the second registration request message to the access network device in step S910, it will also simultaneously send the second routing information used to associate the second NAS signaling connection. It is understood that if the terminal device sends the second routing information to the access network device, the access network device does not need to allocate the second routing information again after receiving the initial NAS message (i.e., the second registration request message).

[0466] In some implementations, the access network device allocates second routing information for the second NAS signaling connection and sends it to the terminal device. Correspondingly, when the second registration request message is sent to the access network device in step S903, since the second routing information corresponding to the second NAS signaling connection has not yet been allocated, the terminal device will not send the second routing information associated with the second NAS signaling connection. After receiving the second registration request message, the access network device determines that a second NAS signaling connection needs to be established and allocates the second routing information.

[0467] Similar to step S903, in step S910, when triggering the establishment of the second NAS signaling connection, the terminal device can also synchronously send an indication message to indicate the establishment of the second NAS signaling connection between the terminal device and the first PLMN. The access network device can determine whether the second NAS signaling connection needs to be established based on this indication message.

[0468] Alternatively, if the terminal device does not send this indication information, the access network device can determine whether a second NAS signaling connection needs to be established based on the message sent in step S910. As an example, the access network device can determine that the NAS message is an initial NAS message because it does not carry routing identification information in step S910, thus determining that a second NAS signaling connection needs to be established. Alternatively, based on the second routing identification information in the message of step S910, when the access network device determines that there is no NAS signaling connection associated with that routing identification information, it determines that a second NAS signaling connection needs to be established.

[0469] Understandably, after receiving the initial NAS message from S910, if the access network device determines that a second NAS signaling connection needs to be established, it sends second routing information to the terminal device. The access network device can send a dedicated RRC message to the terminal device after receiving the initial NAS message from S910, carrying the second routing information. Alternatively, the second routing information can be piggybacked onto the terminal device during subsequent interactions with it in the process triggered by the initial NAS message from S910, for example, in the downlink RRC message of the first NAS message sent by AMF 2 to the terminal device, or in the first downlink RRC message after AMF 2 sends the initial context of the terminal device to the access network device.

[0470] Access network devices also need to store the second routing information in the context of terminal devices, and at the same time store the corresponding AMF 2 information in the context.

[0471] S911, the access network equipment selects AMF 2 based on the PLMN ID.

[0472] In this step, if a signaling connection with AMF 1 already exists, the access network device selects a new mobility management network element for the terminal device based on the PLMN ID, and AMF 2 is the mobility management network element of the first PLMN indicated by the serving PLMN ID.

[0473] In step S912, the access network device sends a second registration request message and the ID of the first PLMN to AMF 2. Correspondingly, AMF 2 receives the second registration request message and the ID of the first PLMN from the access network device.

[0474] S913, the terminal device connects to the first PLMN and establishes a session.

[0475] In this step, the terminal device is connected to the first PLMN, and a session is established between the terminal device and the UPF network element in the first PLMN. The specific process of the terminal device connecting to the main network will not be elaborated here.

[0476] S914, the context of the access network device simultaneously stores the context of the first core network connection and the context of the second core network connection.

[0477] In this step, an RRC context exists in the access network device, and this RRC context is associated with the core network connection context corresponding to different AMF network elements. The context of each core network connection includes:

[0478] The routing identifier information corresponding to the NAS signaling connection of this core network connection;

[0479] Information on the interface protocol between the access network device and the AMF network element. Taking 5G as an example, the information on this interface protocol may include: the identifiers assigned to the terminal device by the access network device and the AMF network element respectively, such as the identifier (RAN UE NGAP ID) and AMF UE NGAP ID assigned to the terminal device by the radio access network (RAN) in the next generation application protocol (NGAP); the N2 link information associated with the signaling connection; and the N2 link information such as the IP addresses of the AMF network element and the access network device.

[0480] The session context information of the core network connection may include any one of the following: the QoS parameters corresponding to the session, the tunnel identifier, the session identifier, etc.

[0481] S915, access network equipment releases RRC connection.

[0482] When the access network device detects that neither AMF 1 nor AMF 2 of the terminal device are transmitting data in the core network, the access network device can release the RRC connection with the terminal device, allowing the terminal device to enter an idle state. It should be noted that "no data" here refers to the absence of signaling messages (such as NAS signaling) and user plane data. In some implementations, the access network device may also simultaneously release all context information about the terminal device and the signaling links created between the access network device and AMF 1 and AMF 2 for the terminal device. If a session has been created, the access network device will also release the tunnel between the access network device and the core network user plane elements of that session.

[0483] Entering an idle state when no data is being transmitted can release the air interface and save energy for the terminal device.

[0484] After the terminal device enters the idle state in step S915, when the terminal device needs to reuse the subnet service, the following steps must be performed:

[0485] S916, the terminal device sends a message to the access network device and establishes an RRC connection.

[0486] In the idle state, the terminal device needs to send a message to the access network device to establish an RRC connection with the access network device, so that the terminal device can enter the RRC connection state from the idle state.

[0487] S917, the terminal device sends an initial NAS message to the access network device. Correspondingly, the access network device receives the initial NAS message from the terminal device.

[0488] In this step, the terminal device sends an initial NAS message (such as a subnet service request message) to the access network device to activate the subnet connection. At this time, the terminal device can also send AMF 1 information or a first identifier (subnet identifier) ​​to the access network device. Taking 5G as an example, the identifier of the AMF network element is the AMF network element identifier (globally unique AMF identifier, GUAMI), and the mobility management network element corresponding to GUAMI is AMF 1.

[0489] It should be noted that when the terminal device enters the idle state, it is equivalent to the first NAS signaling connection being released in step S915. The first NAS signaling connection will be re-established in this step. For the specific establishment process, please refer to the aforementioned steps, which will not be repeated here.

[0490] S918, access network devices select AMF 1 based on GUAMI or network identifier (such as the first identifier).

[0491] In this context, the mobility management network element corresponding to GUAMI is AMF 1. Therefore, the access network equipment can select AMF 1 based on the GUAMI carried in the subnet service request message. After the access network equipment determines that the mobility management network element is AMF 1, it can activate the existing connection with AMF 1. The activation process will not be described in detail here.

[0492] It should be noted that in steps S917 to S918, the terminal device activates the subnet connection. Similarly, when the terminal device needs to activate the connection with the PLMN, the terminal device can send a large network service request message to the access network device and send the GUAMI of AMF 2, which is used by the access network device to select AMF 2 from the mobility management network element. The specific process is similar to steps S917 to S918, and will not be described in detail here.

[0493] In this embodiment, the terminal device can separate subnet registration access and main network registration access, thereby achieving decoupled control of the registration access process, avoiding sharing of mobility management network elements, and enhancing the isolation between subnet registration access and main network registration access.

[0494] Figure 10 is a schematic diagram of the structure of a communication device provided in an embodiment of this application. As shown in Figure 10, the device 1000 of this embodiment may include a communication module 1001 and a processing module 1002. It should be understood that the device 1000 is embodied in the form of functional modules. The term "module" may refer to a software module, or it may refer to application-specific integrated circuits, electronic circuits, processors (e.g., shared processors, proprietary processors, or group processors, etc.) and memories for executing one or more software or firmware programs, combined logic circuits, and / or other suitable components that support the described functions.

[0495] The aforementioned device 1000 has the function of implementing the various processes and / or steps implemented by the terminal device, access network device, and various network elements in any of the aforementioned method embodiments; the aforementioned functions can be implemented by software or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functions.

[0496] Figure 11 is a schematic diagram of a communication device provided in another embodiment of this application. The device 1100 shown in Figure 11 can be used to perform any of the methods described above that are executed by the communication device.

[0497] As shown in Figure 11, the device 1100 of this embodiment includes: a memory 1101, a processor 1102, a communication interface 1103, and a bus 1104. The memory 1101, the processor 1102, and the communication interface 1103 are interconnected via the bus 1104.

[0498] The memory 1101 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1101 may store a program, and when the program stored in the memory 1101 is executed by the processor 1102, the processor 1102 performs any of the aforementioned methods.

[0499] The processor 1102 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit, or one or more integrated circuits for executing relevant programs.

[0500] The processor 1102 can also be an integrated circuit chip with signal processing capabilities. In implementation, the various related steps in the embodiments of this application can be completed by the integrated logic circuitry in the hardware of the processor 1102 or by instructions in software form.

[0501] The processor 1102 described above can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0502] The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory 1101. Processor 1102 reads the information in memory 1101 and, in conjunction with its hardware, completes the functions required by the units included in the device of this application.

[0503] The communication interface 1103 can use, but is not limited to, transceivers to enable communication between the device 1100 and other devices or apparatuses.

[0504] Bus 1104 may include a pathway for transmitting information between various components of device 1100 (e.g., memory 1101, processor 1102, communication interface 1103).

[0505] This application also provides a computer-readable storage medium storing computer instructions, which, when executed by a processor, implement the steps of the methods described above.

[0506] This application also provides a computer program product, including computer instructions that, when executed by a processor, implement the various steps in the methods described above.

[0507] It should be noted that the modules or components shown in the above embodiments can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more microprocessors, or one or more field-programmable gate arrays (FPGAs). Furthermore, when a module is implemented by a processing element calling program code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling program code, such as a controller. Moreover, these modules can be integrated together to implement a system-on-a-chip (SoC).

[0508] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, software modules, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., a solid-state disk (SSD)).

[0509] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0510] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A communication method, applied to a first terminal device or a chip in the first terminal device, characterized in that, The method includes: Receive identification information from a first network from an access network device, wherein the access network device supports connecting a terminal device to the first network; If the first list of the first terminal device includes the identification information of the first network, a first request message and the identification information of the first network are sent to the access network device. The first request message is used to request the first terminal device to access the first network. The first list includes the identification information of one or more non-public terrestrial mobile networks (PLMNs).

2. The method of claim 1, wherein, The first terminal device includes a first logical interface, which is used to access a non-PLMN network, and the first logical interface is configured with the first list. When the first list of the first terminal device includes the identification information of the first network, sending a first request message and the identification information of the first network to the access network device includes: When the first logical interface is enabled and the first list includes the identification information of the first network, the first request message and the identification information of the first network are sent to the access network device.

3. The method according to claim 1 or 2, characterized in that, The method further includes: Receive identification information of a third network from the access network device, wherein the first list includes the identification information of the third network; When the first list of the first terminal device includes the identification information of the first network, sending a first request message and the identification information of the first network to the access network device includes: If the first list includes the identification information of the first network and the priority of the first network is higher than that of the third network, the first request message and the identification information of the first network are sent to the access network device.

4. The method according to any one of claims 1 to 3, characterized in that, The first request message includes a first identifier and / or a second identifier, wherein the first identifier is the identifier of the first terminal device in the first network, and the second identifier is the identifier of the terminal device in a second network, wherein the second network is a PLMN network.

5. The method of claim 4, wherein, The first terminal device includes a second logical interface, which is used to access the second network, and the second identifier is associated with the second logical interface; The first request message includes the second identifier, including: When the first logical interface is associated with the second logical interface, or when the first network is associated with the second logical interface, the first request message includes the second identifier.

6. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Send a second identifier, which is the identifier of the first terminal device in the second network, the second network being a PLMN network.

7. The method of claim 6, wherein, Before sending the second identifier, the method further includes: Receive first information, which is used to request the identifier of the first terminal device in the second network.

8. The method according to claim 6 or 7, characterized in that, The first terminal device includes a second logical interface, which is used to access the second network, and the second identifier is associated with the second logical interface; Sending the second identifier includes: The second identifier is sent when the first logical interface is associated with the second logical interface, or when the first network is associated with the second logical interface.

9. The method according to claim 5 or 8, characterized in that, The method further includes: Obtain first indication information, which is used to indicate that the first logical interface is associated with the second logical interface, or the first indication information is used to indicate that the first network is associated with the second logical interface.

10. The method according to any one of claims 1 to 9, characterized in that, The first request message also includes second information, which is used to instruct the first terminal device in the first network to request access to the network slice and / or logical network; The method further includes: Receive third information, which is used to indicate the network slices and / or logical networks that the first terminal device in the first network is allowed to access.

11. The method according to any one of claims 1 to 10, characterized in that, The method further includes: Send a first session request message, which is used to request the establishment of a session between the first terminal device and the user plane network element in the first network.

12. The method of claim 11, wherein, The first session request message includes an identifier of a network slice and / or logical network, wherein the network slice and / or logical network is the network slice and / or logical network that the first terminal device in the first network requests to access.

13. The method according to any one of claims 1 to 12, characterized in that, The first request message is also used to request access to a first service of the Public Land Mobile Network (PLMN) through the first network. The method further includes: Receive fourth information, the fourth information being used to indicate whether the first terminal device is allowed to access the first service of the PLMN through the first network; In cases where the fourth information is used to indicate permission for the first terminal device to access the first service of the PLMN through the first network, the first session request message also includes information for indicating the first service.

14. A communication method applied to a mobile management network element, characterized in that, The method includes: The system receives a first request message from an access network device and identification information of a first network. The first request message is used to request that a first terminal device be connected to the first network. The first network is a non-PLMN network. The access network device and the mobility management network element support connecting the terminal device to the first network. Based on the identification information of the first network, a second request message is sent to the control plane network element in the first network. The second request message is used to request that the first terminal device be connected to the first network. The system receives a first response message from the control plane network element, the first response message indicating whether the first terminal device is allowed to access the first network.

15. The method of claim 14, wherein, Sending the second request message to the control plane network element in the first network includes: If the authentication of the first terminal device is successful, a second request message is sent to the control plane network element. The authentication of the first terminal device is based on a second identifier, which is the identifier of the first terminal device in a second network, and the second network is a PLMN network.

16. The method of claim 15, wherein, The first request message includes the second identifier; or, The method further includes: Send a message requesting the identifier of the first terminal device in the second network; Receive the second identifier.

17. The method according to claim 15 or 16, characterized in that, The step of sending the second request message to the control plane network element when the authentication of the first terminal device is successful includes: If the authentication of the first terminal device is successful, a first identifier is obtained. The first identifier is the identifier of the first terminal device in the first network. The first identifier is an external identifier of the first terminal device. Send the second request message to the control plane network element, the second request message including the first identifier.

18. The method of any one of claims 14-16, wherein, The first request message includes a first identifier, which is the identifier of the first terminal device in the first network and is an external identifier of the first terminal device; Sending the second request message to the control plane network element in the first network includes: If the verification of the first identifier is successful, the second request message is sent to the control plane network element.

19. The method of claim 18, wherein, The second request message includes at least one of the following: the first identifier, or information indicating that the verification for the first identifier was successful.

20. The method of any one of claims 17-19, wherein, Before sending the second request message to the control plane network element, the method further includes: A message is sent to a core network element in the second network to request an external identifier for the first terminal device. The core network element in the second network is used to manage the external identifiers of terminal devices belonging to the second network. The second network is a network deployed by the operator to which the first terminal device belongs. Receive an external identifier from the first terminal device of the core network element; The successful verification of the first identifier includes: The external identifier of the first terminal device from the core network element includes the first identifier.

21. The method according to any one of claims 14 to 20, characterized in that, The method further includes: A first session request message is received from the first terminal device, the first session request message being used to request the establishment of a session between the first terminal device and a first user plane network element of the first network.

22. The method of claim 21, wherein, The method further includes: Based on the first session request message, the second user plane network element is triggered to allocate uplink tunnel information and downlink tunnel information for the session; Receive first uplink tunnel information and first downlink tunnel information from the second user plane network element. The first uplink tunnel information is used to send uplink data of the session to the second user plane network element, and the first downlink tunnel information is used to send downlink data of the session to the second user plane network element. Send a second session request message to the control plane network element. The second session request message is used to request the establishment of a session between the first terminal device and the first user plane network element. The second session request message includes the first downlink tunnel information. Receive second uplink tunnel information from the control plane network element, the second uplink tunnel information being used to send uplink data of the session to the first user plane network element; The first uplink tunnel information is sent to the access network device.

23. The method of any one of claims 14 to 22, wherein, The second request message includes a first terminal identifier, which is used to indicate the first terminal device in the mobility management network element.

24. The method of claim 23, wherein, The first response message includes a second terminal identifier, which is used to indicate the first terminal device in the control plane network element.

25. The method of claim 24, wherein, The method further includes: Receive a downlink non-access stratum (NAS) message from the control plane network element and the first terminal identifier, and send the downlink NAS message to the first terminal device according to the first terminal identifier; and / or, Receive an uplink NAS message from the first terminal device, and send the uplink NAS message and the second terminal identifier to the control plane network element.

26. A communication method applied to a control plane network element in a first network, comprising: The method includes: The system receives a second request message from a mobility management network element, the second request message being used to request that the first terminal device be connected to the first network, the mobility management network element supporting the connection of terminal devices to the first network; Determine whether to allow the first terminal device to access the first network based on the first terminal device's subscription information in the first network; A first response message is sent to the mobility management network element, the first response message being used to indicate whether the first terminal device is allowed to access the first network.

27. The method of claim 26, wherein, The second request message is also used to request access to the first service of the PLMN through the first network. The subscription information of the first terminal device in the first network includes second indication information, which is used to indicate whether the first terminal device is allowed to access the PLMN's service through the first network. The step of determining whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network includes: Based on the second request message and the second indication information, determine whether to allow the first terminal device to access the first service of the PLMN through the first network.

28. The method of claim 27, wherein, The first response message also includes third information, which indicates whether the first terminal device is allowed to access the first service of the PLMN through the first network.

29. The method of any one of claims 26-28, wherein, Before determining whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network, the method further includes: The first terminal device's subscription information in the first network is obtained based on the first identifier, where the first identifier is the identifier of the first terminal device in the first network.

30. The method of claim 29, wherein, The second request message includes the first identifier; or, The method further includes: Send a message requesting the identifier of the first terminal device in the first network; Receive the first identifier.

31. The method of claim 29 or 30, wherein, The first identifier is an external identifier of the first terminal device; The step of obtaining the subscription information of the first terminal device in the first network based on the first identifier includes: If the verification of the first identifier is successful, the subscription information of the first terminal device in the first network is obtained based on the first identifier.

32. The method of claim 31, wherein, The successful verification of the first identifier includes: The second request message also includes information indicating that the verification for the first identifier was successful.

33. The method of claim 31, wherein, Before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the method further includes: A message is sent to a core network element in the second network to request an external identifier for the first terminal device. The core network element in the second network is used to manage the external identifiers of terminal devices belonging to the second network. The second network is a network deployed by the operator to which the first terminal device belongs. Receive an external identifier from the first terminal device of the core network element; The successful verification of the first identifier includes: The external identifier of the first terminal device from the core network element includes the first identifier.

34. The method of claim 32, wherein, Before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the process includes: A message is sent to a core network element in the second network to request verification of the first subscription identifier. The core network element in the second network is used to manage the external identifiers of terminal devices belonging to the second network. The second network is the network deployed by the owner operator of the first terminal device. Receive a third response message from the core network element, the third response message being used to indicate the result of the verification against the first identifier; The successful verification of the first identifier includes: The third response message is used to indicate that the verification of the first identifier was successful.

35. The method of any one of claims 31-34, wherein, Before the verification of the first identifier is successful, the method further includes: The first terminal device is authenticated based on a second identifier, which is the identifier of the first terminal device in a second network, and the second network is the network deployed by the home operator of the first terminal device.

36. The method of claim 35, wherein, The authentication of the first terminal device based on the second identifier includes: Obtain the second identifier of the first terminal device; A first authentication request message is sent to a core network element in the second network. The core network element in the second network is used to authenticate terminal devices belonging to the second network. The first authentication request message is used to request authentication of the first terminal device. The first authentication request message includes the second identifier. Receive a first authentication response message from the core network element, wherein the first authentication response message includes the first authentication information of the first terminal device; A second authentication request message is sent to the first terminal device based on the first authentication information; Receive a second authentication response message from the first terminal device, wherein the second authentication response message includes the second authentication information of the first terminal device; The first terminal device is authenticated based on the first authentication information and the second authentication information; or... Send a third authentication request message to the core network element, wherein the third authentication request message carries the second authentication information; The system receives a third authentication response message from the core network element, the third authentication response message being used to indicate the authentication result of the first terminal device.

37. The method of claim 36, wherein, Obtaining the second identifier of the first terminal device includes: Obtain the second identifier from the second request message; or, Send a message requesting the identifier of the first terminal device in the second network; Receive the second identifier.

38. The method of any one of claims 29-37, wherein, Before obtaining the subscription information of the first terminal device in the first network based on the first identifier, the method further includes: The first identifier is used to authenticate the first terminal device.

39. The method of claim 38, wherein, The step of using the first subscription identifier to perform access authentication for the first terminal device to access the first network includes: When preset conditions are met, the first subscription identifier is used to authenticate the first terminal device. The preset conditions include at least one of the following: the subscription information of the first terminal device in the first network requires the first identifier to be used for access authentication of the first terminal device; the second request message does not include the verified first identifier; the first identifier is a private identifier in the first network; or the control plane network element requires the terminal device accessing the first network to be authenticated using the first identifier.

40. The method of any one of claims 26-39, wherein, The second request message also includes fifth information, which is used to indicate the location of the first terminal device. The subscription information of the first terminal device in the first network includes third indication information, which is used to indicate the area of ​​the first network that the first terminal device is allowed to access. The step of determining whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network includes: If the location of the first terminal device falls within the area indicated by the third indication information, it is determined that the first terminal device is allowed to access the first network.

41. The method of any one of claims 26-40, wherein, The second request message also includes first information, which is used to indicate that the first terminal device in the first network requests access to the network slice and / or logical network. The subscription information of the first terminal device in the first network includes fourth indication information, which is used to indicate that the first terminal device in the first network is allowed to access the network slice and / or logical network. The step of determining whether to allow the first terminal device to access the first network based on the subscription information of the first terminal device in the first network includes: If the network slice and / or logical network requested for access in the first information is included in the network slice and / or logical network that the fourth indication information indicates is allowed to be accessed, then determine the network slice and / or logical network that the first terminal device in the first network is allowed to access.

42. The method of claim 41, wherein, The first response message also includes second information, which indicates the network slices and / or logical networks that the first terminal device in the first network is allowed to access.

43. The method of any one of claims 26-42, wherein, The first response message includes a second terminal identifier, which is used to indicate the first terminal device in the control plane network element.

44. The method of any one of claims 40-43, wherein, The method further includes: The system receives a second session request message from the mobility management network element. The second session request message is used to request the establishment of a session between the first terminal device and the first user plane network element of the first network. The second session request message includes first downlink tunnel information. The first downlink tunnel information is used to send downlink data of the session to the second user plane network element in the third network. The third network is a network deployed by the home operator of the mobility management network element. Based on the session subscription information of the first terminal device in the first network, a message is sent to the first user plane network element to request the first user plane network element to allocate uplink tunnel information for the session. Receive second uplink tunnel information from the first user plane network element, the second uplink tunnel information being used to send uplink data of the session to the first user plane network element; The second uplink tunnel information is sent to the mobility management network element.

45. The method of claim 44, wherein, The second session request message also includes a sixth piece of information, which is used to indicate the identifier of the network slice and / or logical network that the first terminal device in the first network requests to access. The session subscription information of the first terminal device in the first network includes a fifth indication information, which is used to indicate the network slice and / or logical network that the first terminal device in the first network is allowed to access. The step of sending a third session request message to the first user plane network element based on the session subscription information of the first terminal device in the first network includes: If the network slice and / or logical network requested for access in the sixth information is included in the network slice and / or logical network that the fifth indication information indicates is allowed to be accessed, the third session request message is sent to the first user plane network element.

46. The method of claim 45, wherein, The second session request message also includes information for instructing the first user plane network element to filter unauthorized data packets.

47. The method of any one of claims 44-46, wherein, The second session request message also includes the first identifier or the second terminal identifier; Before sending a third session request message to the first user plane network element based on the session subscription information of the first terminal device in the first network, the method further includes: The session subscription information of the first terminal device in the first network is obtained based on the first identifier or the second terminal identifier.

48. The method of any one of claims 44-47, wherein, The third session request message also includes information indicating that the first terminal device is allowed to access the first service of the PLMN.

49. A communication method applied to an access network device, comprising: The method includes: Receive a first message from a first terminal device, and trigger the establishment of a first connection based on the first message. The first connection is a connection between the first terminal device and the first mobility management network element. Send a first connection identifier to the first terminal device, the first connection identifier being used to indicate the first connection.

50. The method of claim 49, wherein, The first message includes a sixth instruction, which is used to instruct the establishment of a connection between the first terminal device and the first mobility management network element. The step of triggering the establishment of the first connection based on the first message includes: The establishment of the first connection is triggered according to the sixth instruction information.

51. The method of claim 49, wherein, The step of triggering the establishment of the first connection based on the first message includes: If the first connection identifier is not included in the first message, the establishment of the first connection is triggered.

52. The method of claim 49, wherein, The step of triggering the establishment of the first connection based on the first message includes: If the first message includes the first connection identifier and the access network device does not save the correspondence between the first terminal device and the first connection identifier, the establishment of the first connection is triggered.

53. The method of any one of claims 49-51, wherein, The method further includes: Assign the first connection identifier to the first connection; Send the first connection identifier to the first terminal device.

54. The method of any one of claims 49-53, wherein, The method further includes: Save the correspondence between the first terminal device and the first connection identifier.

55. The method of any one of claims 49-54, wherein, The first message also includes information for instructing the first network; The method further includes: The first mobility management network element is selected based on the first message, and the first mobility management network element supports the access of terminal devices to the first network.

56. The method of any one of claims 49-55, wherein, The first message also includes a first NAS message, which is an access request message or a service request message.

57. The method of any one of claims 49-56, wherein, The first connection is used to forward messages between the first terminal device and the first network; The method further includes: The system receives a second message from the first terminal device and triggers the establishment of a second connection based on the second message. The second connection is a connection between the first terminal device and the second mobility management network element. The second connection is used to forward messages between the first terminal device and the second network. The second network and the first network are different networks. A second connection identifier is sent to the first terminal device, the second connection identifier being used to indicate the second connection.

58. The method of claim 57, wherein, Before receiving the first message from the first terminal device, and before receiving the second message from the first terminal device, the method further includes: Establish a third connection between the first terminal device and the access network device; The receiving of the first message from the first terminal device includes: The first message is received from the first terminal device via the third connection; The receiving of the second message from the first terminal device includes: The second message is received from the first terminal device through the third connection.

59. The method of claim 58, wherein, The second message also includes a second NAS message, which is an access request message or a service request message.

60. The method of claim 58 or 59, wherein, The first connection is associated with at least one first user plane link, and the second connection is associated with at least one second user plane link. The first user plane link is used to transmit user plane data between the first terminal device and the first network, and the second user plane link is used to transmit user plane data between the first terminal device and the second network. The method further includes: If no data is transmitted on at least one first user plane link and no data is transmitted on at least one second user plane link, the third connection shall be released. 61.A communication method applied to a first terminal device or a chip in the first terminal device, comprising: The method includes: Send a first message to the access network device. The first message is used to trigger the establishment of a first connection. The first connection is the connection between the first terminal device and the first mobility management network element. The first connection identifier is received from the access network device, and the first connection identifier is used to indicate the first connection.

62. The method of claim 61, wherein, The first message includes a sixth instruction, which is used to instruct the establishment of a connection between the first terminal device and the first mobility management network element.

63. The method of claim 61, wherein, Sending the first message to the access network device includes: Assign the first connection identifier to the first connection; Send a first message to the access network device, the first message including the first connection identifier.

64. The method of any one of claims 61-63, wherein, The first message also includes information for instructing the first network, wherein the first mobility management element supports accessing the terminal device to the first network.

65. The method of any one of claims 61-64, wherein, The first message also includes a second NAS message, which is a registration request message or a service request message.

66. The method of any one of claims 61-65, wherein, The first connection is used to forward messages between the first terminal device and the first network; The method further includes: Send a second message to the access network device. The second message is used to trigger the establishment of a second connection. The second connection is a connection between the first terminal device and the second mobility management network element. The second connection is used to forward messages between the first terminal device and the second network. The second network and the first network are different networks. The second connection identifier is received from the access network device, the second connection identifier being used to indicate the second connection.

67. The method of claim 66, wherein, Sending the first message to the access network device includes: The first message is sent via a third connection between the access network device and the first terminal device. Sending the second message to the access network device includes: The second message is sent to the access network device through the third connection.

68. A communications device, characterized by The communication device includes a functional module for implementing the communication method as described in any one of claims 1 to 67.

69. A communications device, characterized by include: Processor and memory; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the communication device to perform the communication method as described in any one of claims 1 to 67.

70. A communication system, characterized by Including mobility management network elements and control plane network elements; The mobility management network element is used to perform the communication method as described in any one of claims 14 to 25, and the control plane network element is used to perform the communication method as described in any one of claims 26 to 48.

71. The system of claim 70, wherein, The system further includes a terminal device for performing the communication method as described in any one of claims 1 to 13.

72. A communication system, characterized by It includes an access network device and a terminal device, wherein the access network device is used to perform the communication method as described in any one of claims 49 to 60, and the terminal device is used to perform the communication method as described in any one of claims 61 to 67.

73. A computer-readable storage medium, comprising: The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the communication method as described in any one of claims 1 to 67.

74. A computer program product, characterised in that, comprising computer program which, when executed by a processor, implements the communication method of any one of claims 1 to 67.