Method and device for allocating temporary identifier to terminal

WO2025123980A1PCT designated stage expired Publication Date: 2025-06-19HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/128431
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-13
Filing Date
2024-10-30
Publication Date
2025-06-19

Smart Images

  • Figure CN2024128431_19062025_PF_FP_ABST
    Figure CN2024128431_19062025_PF_FP_ABST
Patent Text Reader

Abstract

A method and device for allocating a temporary identifier to a terminal. The method comprises: an access network device allocates a first temporary identifier to a terminal, and sends a first message to an AMF network element, the first message comprising the first temporary identifier; once the first message is received, the AMF network element acquires a SUPI of the terminal in a UDM network element, and establishes a correspondence between the first temporary identifier and the SUPI of the terminal; and then the access network device can communicate with a core network element on the basis of the first temporary identifier. In embodiments of the present application, the access network device communicates with the core network element on the basis of the first temporary identifier of the terminal, and the core network element can map the first temporary identifier into the SUPI of the terminal, preventing the access network device from acquiring the SUPI of the terminal, and ensuring the privacy and security of the terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for allocating temporary terminal identification

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on December 13, 2023, with application number 202311708317.6 and application name "A method and device for allocating temporary terminal identification", the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of communication technology, and in particular to a method and device for allocating temporary terminal identifiers. Background Art

[0004] In the N2 interface architecture, access network devices can access core network elements of other control planes only through the access and mobility management function (AMF) network element relay. Under the N2 interface service-oriented architecture, access network devices can access each core network element in one hop. Because the core network element can only identify the terminal through the terminal's user permanent identifier (SUPI). If the access network device obtains the terminal's SUPI, it communicates with the core network element based on the terminal's SUPI. When the access network device is untrustworthy, the terminal's privacy information may be leaked, posing certain security risks to the terminal.

[0005] Summary of the Invention

[0006] Embodiments of the present application provide a method and apparatus for allocating a temporary identifier to a terminal, thereby allocating a temporary identifier to a terminal, preventing an access network device from obtaining the terminal's SUPI, and ensuring the privacy and security of the terminal.

[0007] In a first aspect, a method for allocating a temporary identifier for a terminal is provided, which is applied to an access network device and includes: allocating a first temporary identifier for the terminal; sending a first message to an access and mobility management function network element, wherein the first message includes the first temporary identifier, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to a first core network network element.

[0008] Through the above design, the access network device allocates a first temporary identifier to the terminal, the AMF network element can allocate a second temporary identifier to the terminal, and the access network device communicates with the first core network network element based on the first temporary identifier and the second temporary identifier, which can prevent the access network device from obtaining the SUPI of the terminal, thereby ensuring the privacy and security of the terminal.

[0009] In one possible design, the first temporary identifier is also used to identify the terminal in a message sent by the first core network element to the access network device.

[0010] In a possible design, it also includes: receiving a second message from the access and mobility management function network element, the second message including a second temporary identifier of the terminal, and the second temporary identifier is used to identify the terminal in the message sent by the first core network network element to the access network device.

[0011] In a possible design, it also includes: sending a third message to the first core network element, the third message including the first temporary identifier; receiving a fourth message from the first core network element, the fourth message including the first temporary identifier or the second temporary identifier.

[0012] In one possible design, the third message also includes identification information of the access and mobility management function network element.

[0013] On the second aspect, a method for allocating a temporary identifier of a terminal is provided, which is applied to an access and mobility management function network element, including: receiving a first message from an access network device, the first message including a first temporary identifier of the terminal, and the first temporary identifier being used to identify the terminal in a message sent by the access network device to a first core network network element.

[0014] In one possible design, the first temporary identifier is also used to identify the terminal in a message sent by the first core network element to the access network device.

[0015] In one possible design, it also includes: allocating a second temporary identifier to the terminal, the second temporary identifier being used to identify the terminal in a message sent by the first core network element to the access network device; and sending a second message to the access network device, the second message including the second temporary identifier.

[0016] In one possible design, the method further includes: sending a fifth message to the first core network element, wherein the fifth message includes: the user permanent identifier SUPI of the terminal and the first temporary identifier. Optionally, the fifth message also includes the second temporary identifier. Optionally, the fifth message also includes identification information of the access network device that allocates the first temporary identifier.

[0017] Through the above design, the AMF network element configures the correspondence between the temporary identifier of the terminal and the SUPI of the terminal to the first core network network element. When the first core network network element receives a message from the access network device, it can obtain the temporary identifier included in the message and map the temporary identifier to the SUPI of the terminal. The first core network network element and the access network device can communicate through the temporary identifier of the terminal, and the first core network network element can map the temporary identifier of the terminal to the SUPI of the terminal, thereby preventing the access network device from obtaining the SUPI of the terminal and ensuring the privacy and security of the terminal.

[0018] In a possible design, it also includes: receiving a request message from a first core network network element, the request message including the first temporary identifier; determining the SUPI of the terminal based on the correspondence between the first temporary identifier and the SUPI of the terminal; and sending a response message to the first core network network element, the response message including the SUPI of the terminal.

[0019] Through the above design, when the first core network network element receives a message from the access network device, it can obtain the temporary identifier of the terminal in the message and send the temporary identifier to the AMF network element to request the SUPI of the terminal corresponding to the temporary identifier from the AMF network element. The AMF network element sends the SUPI of the terminal to the first core network network element, thereby realizing communication between the first core network network element and the access network device through the temporary identifier of the terminal, avoiding the access network device from obtaining the SUPI of the terminal, and ensuring the privacy and security of the terminal.

[0020] In one possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal. Optionally, the request message also includes identification information of the access network device that allocates the first temporary identifier.

[0021] In one possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal. Optionally, the request message also includes the second temporary identifier.

[0022] In one possible design, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal. Optionally, the request message also includes identification information of the access network device that allocates the first temporary identifier.

[0023] The third aspect is a corresponding method of the first and second aspects. For beneficial effects, please refer to the description of the first aspect. A communication method is provided, which is applied to a first core network network element, including: receiving a third message from an access network device, the third message including a first temporary identifier of the terminal, the first temporary identifier being used to identify the terminal in a message sent by the access network device to the first core network network element; and sending a fourth message to the access network device, the fourth message including the first temporary identifier or the second temporary identifier.

[0024] In one possible design, when the fourth message includes the first temporary identifier, the first temporary identifier is also used to identify the terminal in the message sent by the access network device to the first core network network element.

[0025] In one possible design, when the fourth message includes the second temporary identifier, the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device.

[0026] In a possible design, the method further includes: determining the SUPI of the terminal according to a correspondence between the first temporary identifier and the user permanent identifier SUPI of the terminal.

[0027] In one possible design, the further includes: receiving a fifth message from an access and mobility management function network element, the fifth message including: the SUPI of the terminal and the first temporary identifier; and determining a correspondence between the first temporary identifier and the SUPI of the terminal.

[0028] In one possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0029] In one possible design, the fifth message also includes identification information of the access network device that allocates the first temporary identifier.

[0030] In one possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

[0031] In one possible design, the fifth message also includes the second temporary identifier.

[0032] In one possible design, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0033] In one possible design, the fifth message also includes identification information of the access network device that allocates the first temporary identifier.

[0034] In one possible design, the third message also includes identification information of the access and mobility management function network element, and also includes: sending a request message to the access and mobility management function network element according to the identification information of the access and mobility management function network element, wherein the request message includes the first temporary identifier; and receiving a response message from the access and mobility management function network element, wherein the response message includes the SUPI of the terminal.

[0035] In one possible design, the request message also includes identification information of the access network device that allocates the first temporary identifier.

[0036] In one possible design, the response message also includes a first temporary identifier of the terminal.

[0037] In one possible design, the request message and the response message also include the second temporary identifier.

[0038] In a fourth aspect, a method for allocating a temporary identifier of a terminal is provided, which is applied to a second core network network element and includes: receiving a sixth message from an access network device, the sixth message including a third temporary identifier of the terminal, and the third temporary identifier being used to identify the terminal in a message sent by the access network device to the second core network network element; after the terminal passes network security authentication, sending a seventh message to the access network device, the seventh message including a fourth temporary identifier, and the fourth temporary identifier being used to identify the terminal in a message sent by the second core network network element to the access network device.

[0039] Through the above design, the access network device allocates a third temporary identifier to the terminal, and the second core network network element allocates a fourth temporary identifier to the terminal. The access network device communicates with the second core network element based on the third temporary identifier and the fourth temporary identifier. The access network device can avoid obtaining the SUPI of the terminal, thereby ensuring the privacy and security of the terminal.

[0040] The fifth aspect is a corresponding method of the fourth aspect. For the beneficial effects, please refer to the description of the fourth aspect. A method for allocating terminal temporary identifiers is provided. The method is applied to an access network device, including: sending a sixth message to a second core network network element, the sixth message including the third temporary identifier of the terminal, and the third temporary identifier is used to identify the terminal in the message sent by the access network device to the second core network network element; after the terminal passes the network security authentication, receiving a seventh message from the second core network network element, the seventh message including the fourth temporary identifier, and the fourth temporary identifier is used to identify the terminal in the message sent by the second core network network element to the access network device.

[0041] In a sixth aspect, a device is provided that can implement the method of the first or fifth aspect. For example, the device includes means for performing the corresponding method of the first or fifth aspect. The device can be implemented through hardware, software, or hardware executing the corresponding software implementation.

[0042] In one possible design, the device includes a unit that performs the first or fifth aspect described above.

[0043] In one possible design, the device includes a processor, which is used to execute the method of the first aspect or the fifth aspect above.

[0044] In one possible design, the device includes a processor and an interface circuit, the interface circuit is used to receive signals from other devices outside the device and transmit them to the processor or send signals from the processor to other devices outside the device, and the processor is used to implement the method in the first or fifth aspect above through logic circuits or executing code instructions.

[0045] In one possible design, the device includes a processor and a memory, and the processor is used to execute a computer program or instruction stored in the memory, so that the device implements the method of the first aspect or the fifth aspect above.

[0046] Optionally, the device may be the first device, or a module or unit (for example, a chip, or a chip system, or a circuit) in the first device that corresponds one-to-one to the method / operation / step / action described in the first aspect or the fifth aspect, or may be capable of being used in combination with the first device.

[0047] In a seventh aspect, a device is provided that can implement the method of the third or fourth aspect. For example, the device includes means for executing the corresponding method of the third or fourth aspect. The device can be implemented through hardware, software, or hardware executing the corresponding software implementation.

[0048] In one possible design, the device includes a unit that performs the third aspect or the fourth aspect described above.

[0049] In one possible design, the device includes a processor, which is used to execute the method of the third aspect or the fourth aspect above.

[0050] In one possible design, the device includes a processor and an interface circuit, the interface circuit is used to receive signals from other devices outside the device and transmit them to the processor or send signals from the processor to other devices outside the device, and the processor is used to implement the method in the third or fourth aspect above through logic circuits or execution code instructions.

[0051] In one possible design, the device includes a processor and a memory, and the processor is used to execute a computer program or instruction stored in the memory, so that the device implements the method of the third aspect or the fourth aspect above.

[0052] Optionally, the device may be a second device, or a module or unit (for example, a chip, or a chip system, or a circuit) in the second device that corresponds one-to-one to executing the method / operation / step / action described in the third aspect or the fourth aspect, or may be capable of being used in combination with the second device.

[0053] In an eighth aspect, a device is provided that can implement the method of the second aspect. For example, the device includes means for executing the method of the second aspect. The device can be implemented in hardware, software, or by executing the corresponding software implementation in hardware.

[0054] In one possible design, the apparatus includes a unit for executing the second aspect described above.

[0055] In one possible design, the device includes a processor, which is used to execute the method of the second aspect above.

[0056] In one possible design, the device includes a processor and an interface circuit, the interface circuit is used to receive signals from other devices outside the device and transmit them to the processor or send signals from the processor to other devices outside the device, and the processor is used to implement the method in the above-mentioned second aspect through logic circuits or executing code instructions.

[0057] In one possible design, the device includes a processor and a memory, and the processor is used to execute a computer program or instruction stored in the memory, so that the device implements the method of the second aspect above.

[0058] Optionally, the device may be a third device, or a module or unit (for example, a chip, or a chip system, or a circuit) in the third device that corresponds one-to-one to executing the method / operation / step / action described in the second aspect, or may be capable of being used in conjunction with the third device.

[0059] In the ninth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is executed on a computer, the computer implements the method of any one of the first to fifth aspects above.

[0060] In a tenth aspect, a computer program product is provided, comprising a computer program or instructions, which enables the method of any one of the first to fifth aspects to be executed when the computer program or instructions are executed by a computer.

[0061] In the eleventh aspect, a chip is provided, comprising a processor, wherein the processor is coupled to a memory and is configured to execute a computer program or instruction stored in the memory, so that the chip implements the method of any one of the first to fifth aspects above.

[0062] In a twelfth aspect, a communication system is provided, comprising: a first communication device and a second communication device; wherein the first communication device is configured to implement the method of the first aspect, and the second communication device is configured to implement the method of the third aspect. Optionally, the system further comprises a second communication device configured to implement the method of the second aspect. Alternatively, the first communication device is configured to implement the method of the fourth aspect, and the second communication device is configured to implement the method of the fifth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] FIG1 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;

[0064] FIG2 is an N2 interface architecture provided in an embodiment of the present application;

[0065] FIG3 is an N2 interface service architecture provided in an embodiment of the present application;

[0066] FIG4 is a schematic diagram of a process provided by an embodiment of the present application;

[0067] 5 and 6 are flowcharts of specific implementations of the flowchart shown in FIG4 ;

[0068] FIG7 is another schematic diagram of a process flow provided in an embodiment of the present application;

[0069] FIG8 is a flowchart of a specific implementation of the flowchart shown in FIG7 ;

[0070] 9 and 10 are schematic structural diagrams of the device provided in the embodiments of the present application. DETAILED DESCRIPTION

[0071] In order to make the purpose, technical solutions and advantages of this application more clear, the application will be further described in detail below with reference to the accompanying drawings. The specific operation methods and functional descriptions in the method embodiments can also be applied to the device embodiments or system embodiments.

[0072] The various numbers and terms such as "first" and "second" used in the embodiments of this application are merely for convenience of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily indicate the order in which they are executed. The order in which the processes are executed is determined by their functions and internal logic.

[0073] In the embodiments of this application, unless otherwise specified, the number of nouns refers to "singular or plural," that is, "one or more." "At least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural.

[0074] FIG1 shows a possible, non-limiting system schematic diagram. As shown in FIG1 , a communication system 10 includes a terminal 100 , a radio access network (RAN) 200 , and a core network (CN) 300 .

[0075] The terminal 100 may also be referred to as a terminal device, user equipment (UE), mobile station, mobile terminal, etc. The terminal can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IOT), virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, etc. The terminal can be a mobile phone, head-mounted display device, tablet computer, computer with wireless transceiver function, wearable device, vehicle, drone, helicopter, airplane, ship, robot, robotic arm, smart home device, etc. The embodiments of the present application do not limit the device form of the terminal.

[0076] RAN 200 includes at least one RAN node. Terminal 100 can be connected to the RAN node wirelessly. The RAN node is connected to core network 300 wirelessly or via a wired connection. The core network equipment in core network 300 and the RAN nodes in RAN 200 can be separate physical devices, or they can be a single physical device that integrates the logical functions of the core network device and the logical functions of a wireless access device.

[0077] RAN 200 may be a cellular system related to the Third Generation Partnership Project (3GPP), such as a fourth-generation (4G) mobile communication system, a fifth-generation (5G) mobile communication system, or a future-oriented evolutionary system, such as a sixth-generation (6G) mobile communication system. RAN 200 may also be an open access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. RAN 200 may also be a communication system that integrates two or more of the above systems.

[0078] In one possible scenario, the RAN node may be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), a next generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system. The RAN node may be a macro base station, a micro base station or an indoor station, a relay node or a donor node, or a wireless controller in a CRAN scenario. Optionally, the RAN node may also be a server, a wearable device, a vehicle or an on-board device, etc. For example, the access network device in the vehicle to everything (V2X) technology may be a road side unit (RSU). All or part of the functions of the RAN node in the embodiment of the present application may also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (e.g., a cloud platform). The RAN node in the embodiment of the present application may also be a logical node, a logical module, or software that can implement all or part of the functions of the RAN node.

[0079] In another possible scenario, multiple RAN nodes collaborate to assist the terminal in achieving wireless access, and different RAN nodes respectively implement part of the functions of the base station. For example, the RAN node can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0080] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0081] RAN nodes, sometimes also referred to as access network equipment, RAN entities, or access nodes, constitute part of a communication system and are used to help terminals achieve wireless access. In the subsequent description of this application, unless otherwise specified, "access network equipment" is used for description. The multiple RAN nodes in RAN200 can be nodes of the same type or different types. In the access network service-oriented architecture, "access network equipment" can also be replaced by access network function (ANF) network elements.

[0082] The core network 300 includes one or more core network elements. For example, as shown in FIG1 , the core network 300 includes data plane function elements, such as user plane function (UPF) elements, and control plane function elements, such as access and mobility management function (AMF) elements, session management function (SMF) elements, policy control function (PCF) elements, and unified data management (UDM) elements. Optionally, the access and mobility management function element can be replaced with an access management function element or a registration management function element.

[0083] It is understandable that there is no restriction on the names of the various network elements in the core network 300. For example, in the 5G communication system, the network element that implements the signaling processing part is called the AMF network element. In the 6G communication system, the network element that implements the above functions can also be called other names, etc., without limitation. In the subsequent description, the names of the various network elements in 5G are mainly used as examples to describe the scheme of the embodiment of the present application. Optionally, the core network 300 may also include other control plane function network elements. For example, a network exposure function (NEF) network element, an application function (AF) network element, a network slice selection function (NSSF) network element, an authentication server function (AUSF) network element, a network repository function (NRF) network element, a unified data storage function (UDR) network element, a network data analytics function (NWDAF) network element, or a location management function (LMF) network element, etc.

[0084] It can be understood that access network equipment and core network network elements can be called communication devices. For example, access network equipment can be understood as communication devices with base station functions, and core network network elements can be understood as communication devices with core network functions. For example, AMF network elements can be understood as communication devices with AMF functions.

[0085] In a network architecture, the interface between the access network device and the AMF network element is the N2 interface. The access network device accesses other core network elements of the control plane function through the AMF network element relay. For example, as shown in Figure 2, the access network device accesses the UDM network element, SMF network element, PCF network element, AUSF network element, or LMF network element through the AMF network element relay. This network architecture is called the N2 interface architecture. Among them, the access network device and the AMF network element communicate based on the temporary identifier of the terminal. In the core network, the AMF network element communicates with other core network elements based on the user permanent identifier (SUPI) of the terminal. After the terminal passes the security authentication, the AMF network element obtains the SUPI of the terminal in the UDM network element, and the AMF network element establishes a corresponding relationship between the temporary identifier of the terminal and the SUPI of the terminal. In the uplink communication, the AMF network element maps the temporary identifier of the terminal to the SUPI of the terminal based on the corresponding relationship between the temporary identifier of the terminal and the SUPI of the terminal. In downlink communications, the AMF network element maps the terminal's SUPI to the terminal's temporary identifier based on the correspondence between the terminal's temporary identifier and the terminal's SUPI. For example, an access network device requests the LMF network element to locate a terminal. In one possible implementation, the access network device may send a request message to the AMF network element, including the terminal's temporary identifier. The AMF network element, acting as a relay, maps the terminal's temporary identifier to the terminal's SUPI. The AMF network element forwards the request message, including the terminal's SUPI, to the LMF. Upon receiving the request message, the LMF obtains the terminal's SUPI from the request message. The LMF network element locates the terminal based on the terminal's SUPI and obtains a positioning result. Furthermore, the LMF network element relays the positioning result to the access network device via the AMF network element. In one possible implementation, the LMF network element may send the positioning result and the terminal's SUPI to the AMF network element. The AMF network element may map the terminal's SUPI to the terminal's temporary identifier. The AMF network element sends the positioning result and the terminal's temporary identifier to the access network device. In this solution, the access network device and the AMF network element communicate based on the temporary identifier of the terminal, and the AMF network element and other core network elements communicate based on the SUPI of the terminal. The access network device cannot obtain the SUPI of the terminal, ensuring the privacy and security of the terminal.

[0086] In another network architecture, the access network device can access each core network element in one hop, that is, the access network device communicates directly with the core network element without being relayed and / or forwarded by the AMF element. For example, as shown in Figure 1, the access network device can communicate directly with the AMF element, SMF element, PCF element, or UDM element shown in Figure 1. Alternatively, as shown in Figure 3, the access network device can communicate directly with the UDM element, SMF element, PCF element, AUSF element, LMF element, or AMF element shown in Figure 3. The network architecture shown in Figure 1 or Figure 3 is called the N2 interface service-oriented architecture. The core network element identifies the terminal by the terminal's SUPI. In one possible implementation, the access network device can obtain the terminal's SUPI and communicate with the core network element based on the terminal's SUPI. For example, the message sent by the access network device to the core network element carries the terminal's SUPI, and the core network element performs corresponding operations on the corresponding terminal based on the terminal's SUPI. If the access network device is untrustworthy, obtaining the terminal's SUPI may result in the leakage of the terminal's private information, posing a security risk to the terminal.

[0087] In view of this, embodiments of the present application provide a method and apparatus for allocating a temporary identifier for a terminal. The method includes: an access network device allocating a first temporary identifier for a terminal and sending a first message to an AMF network element, the first message including the first temporary identifier. Upon receiving the first message, the AMF network element obtains the terminal's SUPI from the UDM network element and establishes a correspondence between the first temporary identifier and the terminal's SUPI. Subsequently, the access network device may communicate with a core network element based on the first temporary identifier. For example, the message sent by the access network device to the core network element may carry the terminal's first temporary identifier. Based on the correspondence between the first temporary identifier and the terminal's SUPI, the core network element maps the first temporary identifier to the terminal's SUPI. The core network element performs corresponding operations based on the terminal's SUPI. In embodiments of the present application, the access network device communicates with the core network element based on the terminal's first temporary identifier. The core network element may map the first temporary identifier to the terminal's SUPI, thereby preventing the access network device from obtaining the terminal's SUPI and ensuring the terminal's privacy and security.

[0088] As shown in FIG4 , the embodiment of the present application provides a flow chart, including:

[0089] Step 400: The access network device allocates a first temporary identifier to the terminal.

[0090] For example, when the terminal is in a radio resource control (RRC) connected state or an inactive state, a first temporary identifier is allocated to the terminal when the access network device and the AMF network element exchange associated messages of the terminal for the first time.

[0091] Step 410: The access network device sends a first message to the AMF network element, and the AMF network element receives the first message from the access network device.

[0092] For example, the first message includes a first temporary identifier. When the AMF network element receives the first message, it can trigger the corresponding network element to perform network security verification on the terminal. When the terminal passes the network security verification, the AMF network element can obtain the SUPI of the terminal in the UDM network element. The AMF network element establishes and stores the correspondence between the first temporary identifier and the SUPI of the terminal. Optionally, the "correspondence" described in the embodiment of the present application can be replaced with "association relationship" or "mapping relationship", etc. The first message may be the relevant information of the terminal that the access network device and the AMF network element interact for the first time. For example, the first message is the registration request message of the terminal, and the second message below is the registration response message of the terminal.

[0093] Optionally, since the first temporary identifier is allocated by the access network device, it may happen that different access network devices allocate the same temporary identifier to different terminals, that is, the first temporary identifier may not be able to uniquely identify a terminal. In order to achieve the purpose of uniquely identifying a terminal, the AMF network element can obtain the identification information of the access network device, such as the identity document (ID) of the access network device, the uniform resource locator (URL) address of the access network device, or the transport network layer (TNL) address of the access network device. Optionally, the ID of the access device may be reported by the access network device, for example, the first message also includes the ID of the access network device. The AMF network element establishes and stores the correspondence between the first temporary identifier, the information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0094] In another possible implementation, after the terminal passes network security verification, the AMF network element may allocate a second temporary identifier to the terminal. The AMF network element establishes and stores a correspondence between the first temporary identifier, the second temporary identifier, and the terminal's SUPI. Furthermore, optionally, the AMF network element may also obtain identification information of the access network device that allocates the first temporary identifier, and the AMF network element establishes and stores a correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the terminal's SUPI.

[0095] Step 420: The AMF network element sends a second message to the access network device, and the access network device receives the second message from the AMF network element. Step 420 is optional and the AMF network element does not need to perform step 420.

[0096] For example, the second message is a response message to the first message, and the second message includes the first temporary identifier or the second temporary identifier. There is no restriction on whether the second message includes other information. For example, when the second message includes the first temporary identifier, it also includes the second temporary identifier. Alternatively, when the second message includes the second temporary identifier, it also includes the first temporary identifier.

[0097] For example, the interface between the AMF network element and the access network device is the N2 interface, and the first message and the second message can be referred to as the terminal-related N2 interface message. The first temporary identifier is allocated by the access network device to the terminal, the terminal is represented as UE, and the access network device is represented as CU. The first temporary identifier can be represented as UE-CU-specific temporary identifier (specific temp ID). The second temporary identifier is allocated by the core network (CN) network element AMF network element, and the second temporary identifier can be represented as UE-CN-specific temporary identifier.

[0098] In one possible implementation, the first temporary identifier is used to identify the terminal in a message sent by the access network device to the first core network device. There are no restrictions on whether the first temporary identifier is used for other purposes. For example, the first temporary identifier is also used to identify the terminal in a message sent by the first core network device to the access network device.

[0099] For example, in a scenario where the AMF network element does not allocate a second temporary identifier for the terminal: the first temporary identifier of the terminal is used in both uplink and downlink communications. For example, during uplink communication, the message sent by the access network device to the first core network network element includes the first temporary identifier. The first core network network element can determine the SUPI of the terminal based on the first temporary identifier. The process of the first core network network element determining the SUPI of the terminal is described below. During downlink communication, the message sent by the first core network device to the access network device includes the first temporary identifier. The access network device can identify the terminal based on the first temporary identifier. At this time, optionally, the second message includes the first temporary identifier.

[0100] For example, in a scenario where the AMF network element allocates a second temporary identifier to a terminal, the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device. That is, the second temporary identifier is used to identify the terminal during downlink communication. In this case, the second message includes the second temporary identifier to notify the access network device of the second temporary identifier allocated by the AMF network element.

[0101] In one possible implementation, the second temporary identifier is also used to identify the terminal in the message sent by the access network device to the first core network network element, that is, the second temporary identifier is used to identify the terminal in uplink communication and downlink communication. At this time, the first temporary identifier is used to identify the terminal in uplink communication and downlink communication. At this time, during the uplink communication and downlink communication process, a temporary identifier pair consisting of the first temporary identifier and the second temporary identifier is used to identify the terminal. For example, during the uplink communication process, the message sent by the access network device to the first core network network element includes the first temporary identifier and the second temporary identifier. During the downlink communication process, the message sent by the first core network network element to the access network device includes the first temporary identifier and the second temporary identifier. At this time, the second message includes the first temporary identifier and the second temporary identifier. When the access network device receives the second message, it establishes and stores the correspondence between the first temporary identifier and the second temporary identifier.

[0102] It is understandable that the access network device may include a CU and a DU. The "access network device" in the embodiment of the present application can be replaced with "CU". For example, the CU allocates a first temporary identifier to the terminal, the CU sends a first message to the AMF network element, and the AMF network element sends a second message to the CU, etc.

[0103] For example, the "first temporary identifier" or "first temporary identifier and second temporary identifier" in the embodiment of the present application is valid within a valid area. The valid area may refer to the public land mobile network (PLMN), registration area (RA), or tracking area (TA) of the terminal. Taking PLMN as an example, the "first temporary identifier" or "first temporary identifier and second temporary identifier" can identify the terminal within the PLMN range of the terminal. Beyond the PLMN range of the terminal, the "first temporary identifier" or "first temporary identifier and second temporary identifier" becomes invalid and can no longer identify the terminal.

[0104] It is understood that the application scenario in the embodiments of the present application may be: the access network device accesses the first core network element in a single hop, that is, the access network device can communicate directly with the first core network element without being forwarded by the AMF element. Of course, the solutions in the embodiments of the present application can also be applied to other scenarios without limitation. The "first core network element" in the embodiments of the present application may be a core network element other than the AMF element.

[0105] Through the above design, the access network device allocates a first temporary identifier to the terminal, the AMF network element can allocate a second temporary identifier to the terminal, and the access network device communicates with the first core network network element based on the first temporary identifier and the second temporary identifier, which can prevent the access network device from obtaining the SUPI of the terminal, thereby ensuring the privacy and security of the terminal.

[0106] The following further describes how, when the first core network element receives a message from the access network device, it determines the SUPI of the terminal according to the first temporary identifier included in the message.

[0107] [An example]

[0108] The AMF network element receives the first message from the access network device, establishes and stores a correspondence between the first temporary identifier and the terminal's SUPI. The AMF network element configures the correspondence between the first temporary identifier and the terminal's SUPI to the first core network network element via a fifth message. Upon receiving the message from the access network device, the first core network network element determines the terminal's SUPI based on the first temporary identifier included in the message and the correspondence between the first temporary identifier and the terminal's SUPI configured by the AMF network element.

[0109] As shown in FIG5 , an embodiment of the present application provides a flowchart, which is a specific implementation of the flowchart shown in FIG4 , including:

[0110] Step 500: The access network device allocates a first temporary identifier to the terminal.

[0111] Step 510: The access network device sends a first message to the AMF network element, and the AMF network element receives the first message from the access network device, where the first message includes a first temporary identifier.

[0112] Optionally, in step 520, the AMF network element sends a second message to the access network device, and the access network device receives the second message from the AMF network element.

[0113] For the specific implementation process of steps 500 to 520, please refer to the description of steps 400 to 420 in Figure 4.

[0114] Step 530: The AMF network element sends the fifth message to the first core network network element, and the first core network network element receives the fifth message from the AMF network element.

[0115] In one possible implementation, the fifth message is used by the AMF network element to configure, for the first core network network element, a correspondence between the first temporary identifier of the terminal and the terminal's SUPI. The fifth message is a terminal-related configuration message. The fifth message includes the first temporary identifier and the terminal's SUPI. Upon receiving the fifth message, the first core network element obtains the first temporary identifier and the terminal's SUPI from the fifth message. The first core network element establishes a correspondence between the first temporary identifier and the terminal's SUPI.

[0116] Optionally, since the first temporary identifier is allocated by the access network device, it may happen that different access network devices allocate the same temporary identifier to different terminals, that is, the first temporary identifier may not be able to uniquely identify a terminal. In order to achieve the purpose of uniquely identifying a terminal, the fifth message also includes: identification information of the access network device that allocates the first temporary identifier. The correspondence between the first temporary identifier and the SUPI of the terminal established by the first core network network element is specifically: the correspondence between the first temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal. At this time, it is considered that the correspondence configured by the AMF network element to the first core network network element through the fifth message is specifically: the correspondence between the first temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0117] In another possible implementation, after the terminal passes network security authentication, the AMF network element may further allocate a second temporary identifier to the terminal. The process of the AMF network element allocating the second temporary identifier to the terminal is described in FIG4 . The correspondence between the first temporary identifier and the terminal's SUPI established by the first core network element is specifically: a correspondence between the first temporary identifier, the second temporary identifier, and the terminal's SUPI. In this possible implementation, the fifth message includes at least the first temporary identifier and the terminal's SUPI. The first core network element may determine, based on stored temporary identifier pairs, the second temporary identifier corresponding to the first temporary identifier included in the fifth message, and further establish a correspondence between the first temporary identifier, the second temporary identifier, and the terminal's SUPI. Alternatively, the fifth message also includes the second temporary identifier, and the first core network element may obtain the second temporary identifier from the fifth message. In this case, the correspondence configured by the AMF network element to the first core network element via the fifth message is considered to be: a correspondence between the first temporary identifier, the second temporary identifier, and the terminal's SUPI.

[0118] Optionally, the correspondence between the first temporary identifier, the second temporary identifier, and the terminal's SUIPI established by the first core network element is specifically: the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the terminal's SUPI. Optionally, the fifth message also includes the identification information of the access network device that allocates the first temporary identifier. In this case, it is considered that the correspondence configured by the AMF network element to the first core network element through the fifth message is specifically: the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the terminal's SUPI.

[0119] For example, as shown in FIG5 , the fifth message includes a terminal information list, where the terminal information list includes: the terminal's SUPI, identification information of the access network device that allocates the first temporary identifier, and the terminal's temporary identifier (e.g., the terminal's first temporary identifier, or the terminal's first temporary identifier and second temporary identifier).

[0120] Step 540: The access network device sends a third message to the first core network network element, and the first core network network element receives the third message from the access network device.

[0121] For example, the first core network element may be another core network element other than the AMF element, such as a UDM element, an SMF element, a PCF element, an AUSF element, or an LMF element. The interface between the access network device and the first core network element may be an Nx interface, and the third message may be an Nx message related to the terminal. The third message includes the first temporary identifier, and there is no restriction on whether the third message includes other information. For example, the third message may also include a second temporary identifier or identification information of the access network device.

[0122] In one possible implementation, upon receiving the third message, the first core network element obtains the first temporary identifier in the third message. Based on the correspondence between the first temporary identifier and the terminal's SUPI, the first core network element determines the terminal's SUPI. Alternatively, the first core network element may further obtain identification information of the access network device. For example, because the access network device communicates with the first core network element, the first core network element may obtain identification information such as the URL address of the access network device. Alternatively, the third message also includes identification information of the access network device, and the first core network element may obtain the identification information of the access network device in the third message. Based on the correspondence between the first temporary identifier, identification information of the access network device that allocates the first temporary identifier, and the terminal's SUPI, the first core network element determines the terminal's SUPI.

[0123] In another possible implementation, upon receiving the third message, the first core network element obtains the first temporary identifier in the third message. Optionally, the third message also includes a second temporary identifier, and the first core network element obtains the second temporary identifier in the third message. Alternatively, the first core network element obtains the second temporary identifier corresponding to the first temporary identifier based on a stored temporary identifier pair. The first core network element determines the SUPI of the terminal based on the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal. Alternatively, the first core network element further obtains identification information of an access network device, and the first core network element determines the SUPI of the terminal based on the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0124] For example, as shown in Figure 5, the third message includes identification information of the access network device and a temporary identifier of the terminal. The temporary identifier may include a first temporary identifier, or the temporary identifier includes a first temporary identifier and a second temporary identifier.

[0125] After the first core network element obtains the SUPI of the terminal, it performs corresponding operations on the terminal based on the SUPI of the terminal. For example, the first core network element is an LMF network element, and the access network device requests the LMF network element to locate the terminal. The third message may be a positioning request message related to the terminal. Upon receiving the positioning request message, the LMF network element determines the SUPI of the terminal based on information such as the first temporary identifier of the terminal included in the positioning request message. The LMF network element performs a positioning operation on the terminal corresponding to the SUPI and obtains a positioning result. Furthermore, the LMF network element may send the positioning result to the access network device. For example, the fourth message in step 550 below may be a positioning response message, which includes the positioning result of the terminal. Furthermore, in order to enable the access network device to identify the terminal corresponding to the positioning result, the positioning response message may also include information such as the first temporary identifier or the second temporary identifier of the terminal.

[0126] Step 550: The first core network element sends a fourth message to the access network device, and the access network device receives the fourth message from the first core network element.

[0127] For example, the fourth message is a response message to the third response, and the fourth message may be an Nx message related to the terminal. The fourth message includes the first temporary identifier or the second temporary identifier. For example, the fourth message includes the first temporary identifier, and there is no restriction on whether the fourth message includes other information. For example, the fourth message does not include other information, or the fourth message also includes the second temporary identifier. Alternatively, the fourth message includes the second temporary identifier, and there is no restriction on whether the fourth message includes other information. For example, the fourth message does not include other information, or the fourth message also includes the first temporary identifier.

[0128] In one possible implementation, the terminal is assigned a temporary identifier, namely, a first temporary identifier, and the fourth message includes the first temporary identifier. Upon receiving the fourth message, the access network device may determine the terminal to which the fourth message specifically corresponds based on the first temporary identifier included in the fourth message.

[0129] In another possible implementation, the terminal is assigned two temporary identifiers: a first temporary identifier assigned by the access network device and a second temporary identifier assigned by the AMF network element. In a scenario where the first temporary identifier is used for uplink communication and the second temporary identifier is used for downlink communication, the third message includes the first temporary identifier and the fourth message includes the second temporary identifier. Alternatively, in scenarios where temporary identifiers are used to identify the terminal in both uplink and downlink communication, both the third and fourth messages include the first and second temporary identifiers.

[0130] For example, the first temporary identifier is allocated by the access network device to the terminal, and the first temporary identifier can be represented by: terminal-access network device-specific temporary identifier. For example, the terminal is represented by UE, the access network device is represented by CU, and the first temporary identifier is specifically UE-CU-specific temporary identifier. The second temporary identifier is allocated by the core network element AMF network element to the terminal, and the second temporary identifier is represented by: terminal-core network (CN)-specific temporary identifier. For example, the second temporary identifier is specifically UE-CN-specific temporary identifier.

[0131] It is understandable that, in the scenario of Figure 5, the access network device proactively initiates communication as an example. Communication between the access network device and the first core network element can also be proactively initiated by the first core network element. For example, the first core network element obtains the terminal's SUPI and, based on the stored correspondence between the temporary identifier and the terminal's SUPI, obtains the terminal's temporary identifier. The message sent by the first core network element to the access network device includes the terminal's temporary identifier, which can be the first temporary identifier, the second temporary identifier, or both.

[0132] Through the above design, the AMF network element configures the correspondence between the temporary identifier of the terminal and the SUPI of the terminal to the first core network network element. When the first core network network element receives the message from the access network device, it can obtain the temporary identifier included in the message and map the temporary identifier to the SUPI of the terminal. The first core network network element and the access network device can communicate through the temporary identifier of the terminal, and the first core network network element can map the temporary identifier of the terminal to the SUPI of the terminal, thereby preventing the access network device from obtaining the SUPI of the terminal and ensuring the privacy and security of the terminal.

[0133] Another example

[0134] When the first core network network element receives the third message from the access network device, it may send the first temporary identifier and other information included in the third message to the AMF network element. The AMF network element determines the SUPI of the terminal based on the stored correspondence, and sends the SUPI of the terminal to the first core network network element. The first core network network element may perform corresponding operations according to the SUPI of the terminal.

[0135] As shown in FIG6 , an embodiment of the present application provides a flowchart, which is a specific implementation of the flowchart shown in FIG4 , including:

[0136] Step 600: The access network device allocates a first temporary identifier to the terminal.

[0137] Step 610: The access network device sends a first message to the AMF network element, and the AMF network element receives the first message from the access network device, where the first message includes a first temporary identifier.

[0138] Optionally, in step 620, the AMF network element sends a second message to the access network device, and the access network device receives the second message from the AMF network element.

[0139] For the specific implementation process of steps 600 to 620, please refer to the description of steps 400 to 420 in FIG. 4 .

[0140] Step 630: The access network device sends a third message to the first core network network element, and the first core network network element receives the third message from the access network device.

[0141] For example, as shown in Figure 6, the third message includes the first temporary identifier of the terminal and the identification information of the AMF network element. For example, the identification information of the AMF network element can be the ID of the AMF network element or the URL address of the AMF network element. There is no restriction on whether the third message includes other information. For example, the third message also includes the second temporary identifier. The third message also includes identification information of the access network device, etc.

[0142] Step 640: The first core network network element sends a request message to the AMF network element according to the identification information of the AMF network element, and the AMF network element receives the request message from the first core network network element.

[0143] For example, the request message is used to request the AMF network element to retrieve the terminal's SUPI. The request message may be a retrieval request. The request message includes a first temporary identifier. Whether the request message includes other information is not restricted. For example, the request message also includes a second temporary identifier. The request message also includes identification information of the access network device that allocated the first temporary identifier. Since the access network device that sent the third message in step 630 is the access network device that allocated the first temporary identifier, the identification information of the access network device that allocated the first temporary identifier is the identification information of the access network device that sent the third message.

[0144] Step 650: The AMF network element sends a response message to the first core network element, and the first core network element receives the response message from the AMF network element.

[0145] For example, the response message includes the terminal's SUPI. In one possible implementation, upon receiving the request message, the AMF network element obtains the first temporary identifier from the request message. The AMF network element determines the terminal's SUPI based on a stored correspondence between the first temporary identifier and the terminal's SUPI. Alternatively, in another possible implementation, the request message also includes identification information of the access network device. Upon receiving the request message, the AMF network element obtains the first temporary identifier and identification information of the access network device from the request message. The AMF network element determines the terminal's SUPI based on a stored correspondence between the first temporary identifier, the identification information of the access network device that allocated the first temporary identifier, and the terminal's SUPI. Alternatively, in another possible implementation, upon receiving the request message, the AMF network element obtains a second temporary identifier. For example, upon obtaining the first temporary identifier from the request message, the AMF network element obtains the second temporary identifier corresponding to the first temporary identifier based on a stored temporary identifier pair. Alternatively, the request message also includes the second temporary identifier, and the AMF network element obtains the second temporary identifier from the request message. The AMF network element determines the terminal's SUPI based on the stored correspondence between the first temporary identifier, the second temporary identifier, and the terminal's SUPI. Optionally, the request message further includes identification information of the access network device. The AMF network element determines the terminal's SUPI based on the stored correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the terminal's SUPI. The AMF network element sends a response message including the terminal's SUPI to the first core network network element. Upon receiving the response message, the first core network network element obtains the terminal's SUPI from the response message and performs corresponding operations based on the terminal's SUPI.

[0146] Step 660: The first core network element sends a fourth message to the access network device, and the access network device receives the fourth message from the first core network element.

[0147] For example, the fourth message may be a response message to the third message, and both the third message and the fourth message contain information related to the terminal. The fourth message may include the first temporary identifier or the second temporary identifier, etc. There is no restriction on whether the fourth message includes other information.

[0148] It can be understood that in the scenario of Figure 6, the example of the access network device actively initiating communication is taken. The communication between the access network device and the first core network network element can also be actively initiated by the first core network network element. For example, the first core network network element obtains the SUPI of the terminal, sends the SUPI of the terminal to the AMF network element, and the AMF network element maps the SUPI of the terminal to a temporary identifier of the terminal, and sends the temporary identifier of the terminal to the first core network network element. The message sent by the first core network network element to the access network device includes the temporary identifier of the terminal, which can be the first temporary identifier, the second temporary identifier, or the first temporary identifier and the second temporary identifier.

[0149] Through the above design, when the first core network network element receives a message from the access network device, it can obtain the temporary identifier of the terminal in the message and send the temporary identifier to the AMF network element to request the SUPI of the terminal corresponding to the temporary identifier from the AMF network element. The AMF network element sends the SUPI of the terminal to the first core network network element, thereby realizing communication between the first core network network element and the access network device through the temporary identifier of the terminal, avoiding the access network device from obtaining the SUPI of the terminal, and ensuring the privacy and security of the terminal.

[0150] An embodiment of the present application also provides a method and apparatus for allocating a temporary identifier, wherein: when an access network device and a core network element first exchange relevant information about a terminal, the access network device allocates a temporary identifier to the terminal. The temporary identifier is used to identify the terminal in uplink communications, i.e., the temporary identifier is used to identify the terminal in messages sent by the access network device to the core network element. After the terminal passes network security authentication, the core network element allocates another temporary identifier to the terminal. The temporary identifier is used to identify the terminal in downlink communications, i.e., the another temporary identifier is used to identify the terminal in messages sent by the core network element to the access network device.

[0151] As shown in FIG7 , a flow chart is provided, including:

[0152] Step 710: The access network device sends a sixth message to the second core network network element, and the second core network network element receives the sixth message from the access network device.

[0153] For example, the access network device may allocate a third temporary identifier to the terminal when first exchanging relevant information about the terminal with the second core network element, and the sixth message may include the third temporary identifier. The third temporary identifier is used to identify the terminal during uplink communication, that is, the third temporary identifier is used to identify the terminal in the message sent by the access network device to the second core network element. There is no restriction on whether the terminal is in an RRC connected state or an inactive state. There is no restriction on whether the sixth message also includes other information. The interface between the access network device and the second core network element is an Nx interface, and the sixth and seventh messages can be referred to as terminal-related Nx messages.

[0154] Step 720: The authentication and authorization network element performs network security authentication on the terminal.

[0155] In one possible implementation, the authentication and authorization network element may be an identity function (IDF) network element of the terminal, or a UDM network element and an AUSF network element, or a newly defined network element, etc., without limitation. After authentication and authorization, the legitimacy of the terminal can be determined. If both authentication and authorization are passed, the terminal is determined to be legal; if at least one of the authentication and authorization fails, the terminal is determined to be illegal. When the terminal is legal, the second core network network element may allocate a fourth temporary identifier to the terminal, and notify the access network device of the fourth temporary identifier through the seventh message below. The fourth temporary identifier is used to identify the terminal in downlink communication, that is, the fourth temporary identifier is used to identify the terminal in the message sent by the second core network network element to the access network device. Further, the second core network network element requests the SUPI of the terminal from the AMF network element, establishes and stores the correspondence between the third temporary identifier, the fourth temporary identifier and the SUPI of the terminal. Furthermore, the sixth message also includes identification information of the access network device that assigned the third temporary identifier. The second core network element may establish and store a correspondence between the third temporary identifier, the fourth temporary identifier, the identification information of the access network device that assigned the third temporary identifier, and the terminal's SUPI. Alternatively, the second core network element may obtain the identification information of the access network device through other means. For example, because the second core network element and the access network device can communicate, the second core network element may obtain identification information such as the URL address of the access network device. Alternatively, if the terminal is not legitimate, the process is terminated and the third and fourth temporary identifiers are no longer enabled. That is, in this embodiment of the present application, the third and fourth temporary identifiers are only enabled if the terminal has undergone network security authentication and is legitimate. Optionally, the "authentication and authorization" process in this embodiment of the present application may be a conventional "authentication and authorization" process or a simplified "authentication and authorization" process, without limitation.

[0156] Step 730: The second core network element sends the seventh message to the access network device, and the access network device receives the seventh message from the second core network element.

[0157] For example, the seventh message includes a fourth temporary identifier. There is no restriction on whether the seventh message includes other information. For example, the seventh message also includes a third temporary identifier. In one possible implementation, the third temporary identifier is allocated by the access network device and is used to identify the terminal in the message sent by the access network device to the second core network network element. The terminal is represented as UE, the access network device is represented as CU, the second core network network element is represented as NFx, and the third temporary identifier is represented as UE-CU-NFx-specific temporary identifier. The fourth temporary identifier is allocated by the second core network network element and is used to identify the terminal in the message sent by the second core network network element to the access network device. The fourth temporary identifier is represented as UE-NFx-CU specific temporary identifier.

[0158] In one possible implementation, the second core network element may be another element other than the AMF element. The application scenario of the present embodiment may be: an access network device accesses the second core network element in a single hop, meaning that the access network device can communicate directly with the second core network element without forwarding through the AMF element. Of course, the solution of the present embodiment can also be applied to scenarios other than the above-described scenario, without limitation. Through the interactions of steps 710 to 730, the access network device and the second core network element can both obtain the third temporary identifier and the fourth temporary identifier of the terminal. Thereafter, the access network device and the second core network element can communicate based on the third temporary identifier and the fourth temporary identifier. It will be understood that, although the third temporary identifier is used to identify the terminal during uplink communications and the fourth temporary identifier is used to identify the terminal during downlink communications, there is no limitation on whether the third temporary identifier and the fourth temporary identifier can be used for other purposes. For example, the third temporary identifier can also identify the terminal during downlink communications, and the fourth temporary identifier can also identify the terminal during uplink communications. For example, the third temporary identifier and the fourth temporary identifier constitute a temporary identifier pair, and the temporary identifier pair identifies the terminal during both uplink and downlink communications. For example, during uplink communications, the access network device sends an eighth message to the second core network element, where the eighth message includes the third temporary identifier and the fourth temporary identifier. The second core network element determines the terminal's SUPI based on the correspondence between the third temporary identifier, the fourth temporary identifier, and the terminal's SUPI, and performs a corresponding operation based on the terminal's SUPI. The second core network element sends a ninth message to the access network device, where the ninth message includes the third temporary identifier, the fourth temporary identifier, and the like.

[0159] For example, the "third temporary identifier and fourth temporary identifier" in the embodiments of the present application are valid within a valid area. The valid area may refer to the terminal's PLMN, RA, or TA, etc. Taking the PLMN as an example, the "third temporary identifier and fourth temporary identifier" can identify the terminal within the terminal's PLMN range. Outside the terminal's PLMN range, the "third temporary identifier and fourth temporary identifier" become invalid and can no longer identify the terminal.

[0160] Through the above design, the access network device allocates a third temporary identifier to the terminal, and the second core network network element allocates a fourth temporary identifier to the terminal. The access network device communicates with the second core network element based on the third temporary identifier and the fourth temporary identifier. The access network device can avoid obtaining the SUPI of the terminal, thereby ensuring the privacy and security of the terminal.

[0161] As shown in FIG8 , the embodiment of the present application further provides a flowchart, which is a specific implementation of the flowchart shown in FIG7 , including:

[0162] Step 810: The access network device sends N2 message 1 to the AMF network element, and the AMF network element receives N2 message 2 from the access network device.

[0163] For example, the interface between the access network device and the AMF network element is the N2 interface, and the messages exchanged between the access network device and the AMF network element are described as N2 messages. When the access network device and the AMF network element exchange relevant information of the terminal for the first time, the access network device allocates a temporary identifier A to the terminal. The temporary identifier A can be expressed as UE-access network device-AMF network element-specific temporary identifier. N2 message 1 includes temporary identifier A.

[0164] Step 820: The authentication and authorization network element performs network security authentication on the terminal.

[0165] In one possible implementation, after the terminal passes network security authentication, the AMF network element assigns another temporary identifier B to the terminal. This temporary identifier B can be expressed as UE-AMF network element-access network device-specific temporary identifier. The temporary identifiers assigned by the access network device and the AMF network element can form a temporary identifier pair, that is, temporary identifier A and temporary identifier B constitute a temporary identifier pair. The AMF network element obtains the terminal's SUPI from the UDM network element. The AMF network element establishes and stores the correspondence between temporary identifiers A, temporary identifier B, and the terminal's SUPI.

[0166] Step 830: The AMF network element sends N2 message 2 to the access network device, and the access network device receives N2 message 2 from the AMF network element.

[0167] For example, N2 message 2 is a response message to N2 message 1, and N2 message 2 includes temporary identifier B. Optionally, N2 message 2 also includes temporary identifier A. The AMF network element and the access network device can communicate based on temporary identifier A and temporary identifier B.

[0168] Step 840: The access network device sends an Nx message 1 to the second core network element, and the second core network element receives the Nx message 1 from the access network device.

[0169] For example, the interface between the access network device and the second core network element is an Nx interface, and the messages exchanged between the access network device and the second core network element are called Nx messages. When the access network device and the second core network element first exchange information related to the terminal, the access network device assigns a temporary identifier C to the terminal. The temporary identifier C can be represented as UE-access network device-second core network element-specific temporary identifier. Nx message 1 includes the temporary identifier C.

[0170] Step 850: The authentication and authorization network element performs network security authentication on the terminal.

[0171] In one possible implementation, the authentication and authorization network element may perform simplified network security authentication on the terminal. After network security authentication is successful, the second core network element assigns a temporary identity D to the terminal. This temporary identity D may be represented as UE-second core network element-access network device-specific temporary identity. Temporary identity C and temporary identity D constitute a temporary identity pair. The second core network element may be a network element other than the AMF network element. The second core network element may obtain the terminal's SUPI from the AMF network element. The second core network element establishes and stores a correspondence between the temporary identity C, temporary identity D, and the terminal's SUPI.

[0172] Step 860: The second core network element sends an Nx message 2 to the access network device, and the access network device receives the Nx message 2 from the second core network element.

[0173] For example, Nx message 2 includes temporary identifier D. Optionally, Nx message 2 also includes temporary identifier C. The second core network element and the access network device can communicate based on temporary identifiers C and D. It will be appreciated that Nx message 1 and Nx message in the embodiment of the present application are specific implementations of the sixth and seventh messages in the process of FIG. 7 . Temporary identifiers C and D are specific implementations of the third and fourth temporary identifiers in the process of FIG. 7 .

[0174] Through the above design, the access network device and the second core network element can communicate based on the allocated temporary identifier, which can prevent the access network device from obtaining the terminal's SUPI, thereby ensuring the privacy and security of the terminal.

[0175] It is understood that in the embodiments of the present application:

[0176] 1. Focus on describing the differences between different processes. The descriptions of different processes can refer to each other.

[0177] 2. In each process, the order of different steps is not limited. For example, step 530 in Figure 5 can be performed after step 520, or step 530 can be performed before step 520. In addition, each process can include fewer steps or more steps than the flowchart or text description.

[0178] 3. In the processes of Figures 4 to 8, the access network device, AMF network element, or core network element is used as an example to describe the execution subject. It can be understood that in each process, the function of the access network device can be implemented by the access network device, or by a module (such as a chip or circuit) in the access network device, or by a logical node, logical module or software that can fully or partially implement the function of the access network device. The function of the AMF network element or core network element can be implemented by the AMF network element or core network element, or by a module (such as a chip or circuit) in the AMF network element or core network element.

[0179] 4. In the embodiment of the present application, "(such as an AMF network element) receives information from (such as an access network device)" can be understood as the source end of the information is the AMF network element, and the destination end is the access network device, which may include the AMF network element directly or indirectly receiving information from the access network device. The information may be processed as necessary between the source and destination ends of the information transmission, such as format changes, but the destination end can understand the valid information from the source end. Similar expressions in this application can be understood similarly and will not be repeated here.

[0180] In the embodiments provided by the present application above, the methods provided by the embodiments of the present application are introduced from the perspective of the interaction between the access network device, the AMF network element and the core network element. In order to realize the various functions in the methods provided by the embodiments of the present application, the access network device, the AMF network element or the core network element, etc., may include hardware structures and / or software modules, and realize the above functions in the form of hardware structures, software modules, or hardware structures plus software modules. Whether a certain function among the above functions is executed in the form of hardware structures, software modules, or hardware structures plus software modules depends on the design constraints of the specific application of the technical solution.

[0181] Figures 9 and 10 are schematic diagrams of the structures of possible communication devices provided in the embodiments of the present application. These communication devices can implement one or more corresponding functions in the above-mentioned method embodiments. For example, the functions implemented by the access network device, AMF network element or core network element, etc., may thus achieve the beneficial effects possessed by the above-mentioned method embodiments. In the embodiment of the present application, the communication device may be an access network device in RAN200 as shown in Figure 1, or a core network element in the core network 300, or a module (such as a chip) applied to the access network device or the core network element.

[0182] As shown in Figure 9, the communication device 900 includes a processing unit 910 and a transceiver unit 920. The communication device 900 is used to implement the functions of the access network device, AMF network element or core network element in any of the method embodiments shown in Figures 4 to 8 above.

[0183] Optionally, the transceiver unit 920 may also be referred to as an output unit, an interface unit, or a communication unit. In one possible implementation, the transceiver unit 920 includes at least one of a transmitting unit and a receiving unit. The transmitting unit and the receiving unit may be integrated together or may be two independent units.

[0184] When the communication device 900 is used to implement the functions of the access network devices in FIG. 4 to FIG. 6 , specifically:

[0185] The processing unit 910 is used to allocate a first temporary identifier to the terminal; the transceiver unit 920 is used to send a first message to the access and mobility management function network element, wherein the first message includes the first temporary identifier, and the first temporary identifier is used to identify the terminal in the message sent by the access network device to the first core network network element.

[0186] In one possible design, the first temporary identifier is also used to identify the terminal in a message sent by the first core network element to the access network device.

[0187] In one possible design, it also includes: a transceiver unit 920, which is also used to receive a second message from the access and mobility management function network element, the second message includes a second temporary identifier of the terminal, and the second temporary identifier is used to identify the terminal in the message sent by the first core network network element to the access network device.

[0188] In a possible design, it also includes: a transceiver unit 920, which is also used to send a third message to the first core network element, the third message including the first temporary identifier, and receive a fourth message from the first core network element, the fourth message including the first temporary identifier or the second temporary identifier.

[0189] In one possible design, the third message also includes identification information of the access and mobility management function network element.

[0190] When the communication device 900 is used to implement the functions of the AMF network element in Figures 4 to 6, specifically:

[0191] The transceiver unit 920 is used to receive a first message from an access network device, where the first message includes a first temporary identifier of the terminal, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to a first core network network element.

[0192] In one possible design, the first temporary identifier is also used to identify the terminal in a message sent by the first core network element to the access network device.

[0193] In one possible design, the processing unit 910 is used to assign a second temporary identifier to the terminal, and the second temporary identifier is used to identify the terminal in the message sent by the first core network network element to the access network device; the transceiver unit 920 is also used to send a second message to the access network device, and the second message includes the second temporary identifier.

[0194] In one possible design, the transceiver unit 920 is also used to send a fifth message to the first core network element, and the fifth message includes: the user permanent identification SUPI of the terminal and the first temporary identification.

[0195] In one possible design, the fifth message also includes the second temporary identifier.

[0196] In one possible design, the fifth message also includes identification information of the access network device that allocates the first temporary identifier.

[0197] In one possible design, it also includes: a transceiver unit 920, which is further used to receive a request message from a first core network network element, wherein the request message includes the first temporary identifier; the processing unit 910, which is further used to determine the SUPI of the terminal based on the correspondence between the first temporary identifier and the SUPI of the terminal; the transceiver unit 920 is further used to send a response message to the first core network network element, wherein the response message includes the SUPI of the terminal.

[0198] In one possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0199] In one possible design, the request message also includes identification information of the access network device that allocates the first temporary identifier.

[0200] In one possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

[0201] In one possible design, the request message also includes the second temporary identifier.

[0202] In one possible design, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0203] In one possible design, the request message also includes identification information of the access network device that allocates the first temporary identifier.

[0204] When the communication device 900 is used to implement the functions of the first core network element in FIG. 5 or FIG. 6 , specifically:

[0205] The transceiver unit 920 is used to receive a third message from the access network device, where the third message includes a first temporary identifier of the terminal, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to the first core network network element; the processing unit 910 is used to generate a fourth message; the transceiver unit 920 is also used to send a fourth message to the access network device, where the fourth message includes the first temporary identifier or the second temporary identifier.

[0206] In one possible design, when the fourth message includes the first temporary identifier, the first temporary identifier is also used to identify the terminal in the message sent by the access network device to the first core network network element.

[0207] In one possible design, when the fourth message includes the second temporary identifier, the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device.

[0208] In a possible design, the processing unit 910 is further configured to determine the SUPI of the terminal according to a correspondence between the first temporary identifier and the user permanent identifier SUPI of the terminal.

[0209] In one possible design, the transceiver unit 920 is further used to receive a fifth message from the access and mobility management function network element, where the fifth message includes: the SUPI of the terminal and the first temporary identifier; and the processing unit 910 is used to determine the correspondence between the first temporary identifier and the SUPI of the terminal.

[0210] In one possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0211] In one possible design, the fifth message also includes identification information of the access network device that allocates the first temporary identifier.

[0212] In one possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

[0213] In one possible design, the fifth message also includes the second temporary identifier.

[0214] In one possible design, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0215] In one possible design, the fifth message also includes identification information of the access network device that allocates the first temporary identifier.

[0216] In one possible design, the third message also includes identification information of the access and mobility management function network element. The processing unit 910 is further used to send a request message to the access and mobility management function network element according to the identification information of the access and mobility management function network element, where the request message includes the first temporary identifier; the transceiver unit 920 is further used to receive a response message from the access and mobility management function network element, where the response message includes the SUPI of the terminal.

[0217] In one possible design, the request message also includes identification information of the access network device that allocates the first temporary identifier.

[0218] In one possible design, the response message also includes a first temporary identifier of the terminal.

[0219] In one possible design, the request message and the response message also include the second temporary identifier.

[0220] When the communication device 900 is used to implement the functions of the second core network element in FIG. 7 or FIG. 8 , specifically:

[0221] The transceiver unit 920 is used to receive a sixth message from the access network device, the sixth message including the third temporary identifier of the terminal, and the third temporary identifier is used to identify the terminal in the message sent by the access network device to the second core network network element; the processing unit 910 is used to generate a seventh message; the transceiver unit 920 is also used to send a seventh message to the access network device after the terminal passes the network security authentication, the seventh message including the fourth temporary identifier, and the fourth temporary identifier is used to identify the terminal in the message sent by the second core network network element to the access network device.

[0222] When the communication device 900 is used to implement the functions of the access network device in FIG. 7 and FIG. 8 , specifically:

[0223] The processing unit 910 is used to generate a sixth message; the transceiver unit 920 is used to send the sixth message to the second core network network element, wherein the sixth message includes a third temporary identifier of the terminal, and the third temporary identifier is used to identify the terminal in the message sent by the access network device to the second core network network element; the transceiver unit 920 is also used to receive a seventh message from the second core network network element after the terminal passes network security authentication, wherein the seventh message includes a fourth temporary identifier, and the fourth temporary identifier is used to identify the terminal in the message sent by the second core network network element to the access network device.

[0224] For a more detailed description of the processing unit 910 and the transceiver unit 920, reference may be made to the descriptions in FIG. 4 to FIG. 8 in the above method embodiments, which will not be repeated here.

[0225] It is understood that the division of units in the embodiments of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods. In addition, the various functional units in the embodiments of the present application can be integrated into a physical device (for example, a processor), or each functional unit can be a separate physical device, or two or more units can be integrated into a unit for implementation. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional modules.

[0226] As shown in Figure 10, communication device 1000 includes a processor 1010 and an interface circuit 1020. Processor 1010 and interface circuit 1020 are coupled to each other. It will be appreciated that interface circuit 1020 may be a transceiver or an input / output interface. Optionally, communication device 1000 may further include a memory 1030 for storing instructions executed by processor 1010, input data required by processor 1010 to execute instructions, or data generated by processor 1010 after executing instructions.

[0227] When the communication device 1000 is used to implement the methods shown in FIG. 4 to FIG. 8 , the processor 1010 is used to implement the functions of the processing unit 910 , and the interface circuit 1020 is used to implement the functions of the transceiver unit 920 .

[0228] When the above-mentioned communication device is a module applied to an access network device, the module implements the functions of the access network device in the above-mentioned method embodiments. The module receives information from other modules in the access network device (such as a radio frequency module or antenna), and the information is sent by the terminal to the access network device; or the module sends information to other modules in the access network device (such as a radio frequency module or antenna), and the information is sent by the access network device to the terminal.

[0229] When the communication device is a module applied to a core network element (e.g., an AMF element, a first core network element, or a second core network element), the module implements the functions of the core network element in the above-mentioned method embodiments. The module receives information from other modules in the core network element (e.g., a radio frequency module or an antenna), where the terminal sends information to the core network element; or the module sends information to other modules in the core network element (e.g., a radio frequency module or an antenna), where the core network element sends information to the terminal.

[0230] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0231] The memory in the embodiments of the present application can be a random access memory (RAM), a flash memory, a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a register, a hard disk, a mobile hard disk, a CD-ROM, or any other form of storage medium known in the art.

[0232] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions that can be executed by a processor. The software instructions can be composed of corresponding software modules, and the software modules can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk, mobile hard disk, CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. The storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC.

[0233] An embodiment of the present application also provides a communication device, which includes a processor and a memory, the processor and the memory are coupled, and the processor is used to implement the functions of the access network device, AMF network element or first core network element in Figures 4 to 6, or to implement the functions of the access network device or second core network element in Figure 7 or 8.

[0234] An embodiment of the present application also provides a communication device, including a processor, which is used to implement the functions of the access network device, AMF network element or first core network element in Figures 4 to 6, or to implement the functions of the access network device or second core network element in Figure 7 or 8.

[0235] The present application also provides a computer-readable storage medium storing instructions, which may also be referred to as computer programs, computer program codes, etc. The instructions are executed on a computer, causing the computer to execute the functions of the access network device, AMF network element, or first core network network element in Figures 4 to 6 of the above method embodiments, or the functions of the access network device or second core network network element in Figures 7 or 8.

[0236] An embodiment of the present application also provides a computer program product, including a computer program or instructions. When the computer program or instructions are run on a computer, the functions of the access network device, AMF network element or first core network network element in Figures 4 to 6 are implemented, or the functions of the access network device or second core network element in Figure 7 or 8 are implemented.

[0237] The embodiment of the present application also provides a chip, which includes a processor, the processor is coupled to a memory, and the processor is used to execute a computer program or instruction stored in the memory, so that the functions of the access network device, AMF network element or first core network network element in Figures 4 to 6 are implemented, or the functions of the access network device or second core network network element in Figures 7 or 8 are implemented.

[0238] An embodiment of the present application further provides a communication system, including a first communication device and a second communication device.

[0239] The first communication device and the second communication device can be used to implement the functions of the access network device and the AMF network element in Figures 4 to 6, respectively. Furthermore, a third communication device is included to implement the functions of the first core network network element in Figure 5 or Figure 6; or the first communication device and the second communication device are used to implement the functions of the access network device and the second core network network element in Figure 7 or Figure 8, respectively.

[0240] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.

[0241] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

Claims

1. A method for allocating a temporary terminal identifier, characterized in that: The method is applied to access network equipment, including: Allocating a first temporary identifier to the terminal; A first message is sent to an access and mobility management function network element, where the first message includes the first temporary identifier, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to the first core network network element.

2. The method according to claim 1, characterized in that The first temporary identifier is also used to identify the terminal in a message sent by the first core network element to the access network device.

3. The method according to claim 1, characterized in that Also includes: Receive a second message from the access and mobility management function network element, where the second message includes a second temporary identifier of the terminal, and the second temporary identifier is used to identify the terminal in a message sent by the first core network network element to the access network device.

4. The method according to any one of claims 1 to 3, characterized in that Also includes: Sending a third message to the first core network element, where the third message includes the first temporary identifier; A fourth message is received from the first core network element, where the fourth message includes the first temporary identifier or the second temporary identifier.

5. The method according to claim 4, characterized in that The third message also includes identification information of the access and mobility management function network element.

6. A method for allocating a temporary terminal identifier, characterized in that: The method is applied to an access and mobility management function network element, comprising: A first message is received from an access network device, where the first message includes a first temporary identifier of a terminal, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to a first core network network element.

7. The method according to claim 6, characterized in that The first temporary identifier is also used to identify the terminal in a message sent by the first core network element to the access network device.

8. The method according to claim 6, characterized in that Also includes: Allocate a second temporary identifier for the terminal, where the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device; A second message is sent to the access network device, where the second message includes the second temporary identifier.

9. The method according to any one of claims 6 to 8, characterized in that Also includes: Send a fifth message to the first core network element, where the fifth message includes: a user permanent identity SUPI of the terminal and the first temporary identity.

10. The method according to claim 9, characterized in that The fifth message also includes the second temporary identifier.

11. The method according to claim 9 or 10, characterized in that The fifth message also includes identification information of the access network device that allocates the first temporary identifier.

12. The method according to any one of claims 6 to 8, characterized in that Also includes: receiving a request message from a first core network element, where the request message includes the first temporary identifier; determining the SUPI of the terminal according to a correspondence between the first temporary identifier and the SUPI of the terminal; Send a response message to the first core network element, where the response message includes the SUPI of the terminal.

13. The method according to claim 12, characterized in that The correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

14. The method according to claim 13, characterized in that The request message also includes identification information of the access network device that allocates the first temporary identifier.

15. The method according to claim 12, characterized in that The correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

16. The method according to claim 15, characterized in that The request message also includes the second temporary identifier.

17. The method according to claim 15 or 16, characterized in that The correspondence between the first temporary identifier, the second temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

18. The method according to claim 17, characterized in that The request message also includes identification information of the access network device that allocates the first temporary identifier.

19. A communication method, characterized in that: The method is applied to a first core network element, comprising: receiving a third message from an access network device, the third message including a first temporary identifier of a terminal, the first temporary identifier being used to identify the terminal in a message sent by the access network device to a first core network network element; A fourth message is sent to the access network device, where the fourth message includes the first temporary identifier or the second temporary identifier.

20. The method of claim 19, wherein: When the fourth message includes the first temporary identifier, the first temporary identifier is also used to identify the terminal in a message sent by the access network device to the first core network element.

21. The method of claim 19, wherein: When the fourth message includes the second temporary identifier, the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device.

22. The method according to any one of claims 19 to 21, characterized in that Also includes: Determine the SUPI of the terminal according to the correspondence between the first temporary identifier and the user permanent identifier SUPI of the terminal.

23. The method of claim 22, wherein: Also includes: receiving a fifth message from an access and mobility management function network element, the fifth message including: a SUPI of the terminal and the first temporary identity; Determine a correspondence between the first temporary identifier and the SUPI of the terminal.

24. The method according to claim 22 or 23, characterized in that The correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, identification information of an access network device that allocates the first temporary identifier, and the SUPI of the terminal.

25. The method of claim 24, wherein: The fifth message also includes identification information of the access network device that allocates the first temporary identifier.

26. The method according to claim 22 or 23, characterized in that The correspondence between the first temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

27. The method of claim 26, wherein: The fifth message also includes the second temporary identifier.

28. The method according to claim 26 or 27, characterized in that The correspondence between the first temporary identifier, the second temporary identifier and the SUPI of the terminal includes: a correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

29. The method of claim 28, wherein: The fifth message also includes identification information of the access network device that allocates the first temporary identifier.

30. The method according to any one of claims 19 to 21, characterized in that The third message also includes identification information of the access and mobility management function network element, and also includes: Sending a request message to the access and mobility management function network element according to the identification information of the access and mobility management function network element, where the request message includes the first temporary identification; receiving a response message from the access and mobility management function network element, where the response message includes the SUPI of the terminal.

31. The method of claim 30, wherein: The request message also includes identification information of the access network device that allocates the first temporary identifier.

32. The method according to claim 30 or 31, characterized in that The response message also includes a first temporary identifier of the terminal.

33. The method according to any one of claims 30 to 32, characterized in that The request message and the response message further include the second temporary identifier.

34. A communication device, characterized in that: The method comprises a unit for implementing the method according to any one of claims 1 to 5, or a unit for implementing the method according to any one of claims 6 to 18, or a unit for implementing the method according to any one of claims 19 to 33.

35. A communication device, characterized in that: The device comprises a processor coupled to a memory, wherein the processor is configured to execute instructions so that the device executes the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 18, or the method according to any one of claims 19 to 33.

36. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, which are executed on a computer to cause the computer to execute the method of any one of claims 1 to 5, or any one of claims 6 to 18, or any one of claims 19 to 33.

Citation Information

Patent Citations

  • Method for determining terminal state, core network device and access network device

    CN110351897A

  • Communication method and device

    CN112218287A

  • Communication system, method, device and storage medium

    CN116456400A

  • Communication related to network slice

    US20230074413A1

  • Method and apparatus for allocating registration area

    WO2018205145A1