Communication method and related device

Through the communication method of accessing the mobility management device, the terminal device is allowed to access the target network without an external authentication protocol, which solves the problem that the terminal device cannot access or obtains other services except emergency services, and realizes that the terminal device can obtain some services provided by the target network.

WO2025130424A1PCT designated stage expired Publication Date: 2025-06-26HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/130798
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-21
Filing Date
2024-11-08
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

When the contract data of the terminal device does not belong to the target network, and there is no external authentication agreement between the home network of the terminal device and the target network, the terminal device cannot access the target network, or it cannot obtain other services provided by the target network except for emergency services.

Method used

Provided is a communication method, which is performed by the access and mobility management device, the method includes receiving a request message from the terminal device, determining based on the identification information of the terminal device that its contract data does not belong to the target network, and there is no external authentication protocol, determining the context information of the terminal device, and sending a response message to the terminal device, indicating that access to the target network is allowed.

Benefits of technology

In the absence of an external authentication protocol, terminal devices are allowed to access the target network and obtain some services provided by the target network, solving the problem that terminal devices cannot access or obtain other services other than emergency services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024130798_26062025_PF_FP_ABST
    Figure CN2024130798_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a related device. The method comprises: receiving a first request message, the first request message being used for requesting a terminal device to access a target network; on the basis of the identifier information of the terminal device, determining that subscription data of the terminal device does not belong to the target network and there is no external authentication protocol between a home network of the terminal device and the target network; determining context information of the terminal device, the context information comprising first indication information, and the first indication information being used for indicating that the terminal device accesses the target network under the condition that authentication is not performed; and sending a first response message to the terminal device, the first response message being used for instructing to allow the terminal device to access the target network. According to the method, when the subscription data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the terminal device is allowed to access the target network so as to acquire some of services provided by the target network.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and related equipment

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on December 21, 2023, with application number 202311782224.8, and priority to the Chinese patent application entitled “A Communication Method and Related Equipment”, all contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communications, and more particularly, to a communication method, a communication device, a communication system, a computer-readable storage medium, and a chip. Background Art

[0003] A non-public network (NPN) is a network that provides services to specific users, distinct from the public network. NPNs can include standalone NPNs (SNPNs) and public network integrated NPNs (PNI-NPNs). SNPNs are independent of the public land mobile network (PLMN) and are operated independently by SNPN operators. PNI-NPNs rely on the PLMN and are operated by traditional operators. In the prior art, there are three ways for a terminal device to access a target network to obtain services. The first is when the terminal device's subscription data belongs to the target network. In this case, the terminal device directly registers to access the target network. The second is when an external authentication agreement exists between the terminal device's home network and the target network. In this case, the terminal device accesses the target network through external authentication. The third is when the terminal device's subscription data does not belong to the target network and there is no external authentication agreement between the terminal device's home network and the target network. The terminal device accesses the target network through emergency registration. In this case, the terminal device can only access emergency services, such as making emergency calls. Therefore, when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the terminal device's home network and the target network, the terminal device cannot access the target network, or cannot obtain other services provided by the target network except emergency services, such as browsing the goods sold in the mall or browsing the service information provided in the mall.

[0004] Therefore, how to allow the terminal device to access the target network and obtain services provided by the target network when the terminal device's subscription data does not belong to the target network and there is no external authentication protocol between the terminal device's home network and the target network becomes an urgent problem to be solved.

[0005] Summary of the Invention

[0006] The present application provides a communication method, a communication device, a communication system, a computer-readable storage medium and a chip, which can allow a terminal device to access a target network and obtain services provided by the target network when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the terminal device's home network and the target network.

[0007] In a first aspect, a communication method is provided. The method is performed by an access and mobility management device and includes: receiving a first request message from a terminal device; determining, based on identification information of the terminal device, that subscription data of the terminal device does not belong to a target network and that no external authentication protocol exists between a home network of the terminal device and the target network; determining context information of the terminal device; and sending a first response message to the terminal device, the first response message being used to indicate that the terminal device is allowed to access the target network.

[0008] The first request message includes identification information of the terminal device, and the first request message is used to request the terminal device to access the target network. The context information of the terminal device includes first indication information, and the first indication information is used to indicate that the terminal device is accessing the target network without authentication.

[0009] In an embodiment of the present application, when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the access and mobility management device determines the context information of the terminal device and sets the first indication information in the context information, thereby indicating that the terminal device is allowed to access the target network without authentication to obtain some services provided by the target network.

[0010] In conjunction with the first aspect, in certain implementations of the first aspect, when a first service exists in the target network, a first response message is sent. The first service is a service that the first terminal device is permitted to access in the target network. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network. Alternatively, when the first service does not exist in the target network, a second response message is sent, where the second response message is used to indicate that the terminal device is not permitted to access the target network.

[0011] In an embodiment of the present application, the access and mobility management device may determine whether to allow the terminal device to access the target network based on whether there is a service in the target network that the first terminal device is allowed to access. If there is a service in the target network that the first terminal device is allowed to access, the access and mobility management device may allow the terminal device to access the target network without authentication.

[0012] In combination with the first aspect, in certain implementations of the first aspect, when the time of receiving the first request message falls within the target time period, a first response message is sent. The target time period includes the time when the first service in the target network is allowed to be obtained. The first service is a service that the first terminal device in the target network is allowed to obtain. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network. Alternatively, when the time of receiving the first request message does not fall within the target time period, a second response message is sent, and the second response message is used to indicate that the terminal device is not allowed to access the target network.

[0013] In an embodiment of the present application, the access and mobility management device may determine whether to allow the terminal device to access the target network based on whether the time at which the first request message is received falls within the time period during which the first service is permitted to be obtained. If the time at which the first request message is received falls within the time period during which the first service is permitted to be obtained, the access and mobility management device may allow the terminal device to access the target network without performing authentication.

[0014] In combination with the first aspect, in some implementations of the first aspect, the first response message also includes session parameters and / or first indication information available to the terminal device, where the session parameters are used by the terminal device to request services provided by the target network.

[0015] In an embodiment of the present application, the access and mobility management device may send first indication information and / or session parameters available to the terminal device to the terminal device through a first response message, thereby facilitating establishment of a session for the terminal device.

[0016] In conjunction with the first aspect, in certain implementations of the first aspect, a second request message is sent to a session management device. The second request message is used to request establishment of a first session for the terminal device, where the first session is used for the terminal device to obtain a second service. The second service is a service that the first terminal device is permitted to obtain in the target network. The second request message includes first indication information. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network.

[0017] Exemplarily, the first service includes at least one service, and the at least one service includes the second service.

[0018] In an embodiment of the present application, the access and mobility management device may send a second request message to the session management device to request establishment of a session for the terminal device. By carrying the first indication information in the second request message, the session management device may determine the type of the terminal device and, when establishing a session for the terminal device, impose restrictions on the quality of service (QoS) requirements of the session, such as limiting the bandwidth of the session to a lower level, or limiting the packet loss rate or latency of the session to a higher level, thereby reducing the resources occupied by the terminal device.

[0019] In combination with the first aspect, in certain implementations of the first aspect, a third request message is received, where the third request message is used to request establishment of a first session for a terminal device; when the session parameters available to the terminal device correspond to a second service, a second request message is sent to a session management device, where the session parameters are used by the terminal device to request acquisition of the service provided by the target network; when the session parameters available to the terminal device do not correspond to the second service, a third response message is sent to the terminal device, where the third response message is used to indicate that establishment of the first session for the terminal device is not allowed.

[0020] In an embodiment of the present application, the access and mobility management device can determine whether to establish a session for the terminal device based on whether the session parameters available to the terminal device correspond to the services that the first terminal device is allowed to obtain, and then restrict the terminal device to prevent the terminal device from obtaining services that it is not allowed to obtain.

[0021] In combination with the first aspect, in some implementations of the first aspect, the second request message also includes session parameters available to the terminal device, and / or the third request message includes the first indication information and / or session parameters available to the terminal device.

[0022] In an embodiment of the present application, the terminal device may directly send a third request message including the first indication information and / or available session parameters, and the access and mobility management device may send the third request message as the second request message to the session management device. Alternatively, the third request message sent by the terminal device does not include the first indication information, and the access and mobility management device may determine the first indication information based on the context information of the terminal device, thereby adding the first indication information to the third request message, generating a second request message, and sending it to the session management device. Alternatively, the third request message sent by the terminal device does not include the available session parameters, and the access and mobility management device may add the available session parameters to the third request message, thereby generating a second request message, and sending it to the session management device. Alternatively, the third request message sent by the terminal device does not include the first indication information and the available session parameters, and the access and mobility management device may add the first indication information and the available session parameters to the third request message, thereby generating a second request message, and sending it to the session management device.

[0023] In a second aspect, a communication method is provided. The method is performed by a session management device and includes: receiving a second request message from an access and mobility management device, the second request message being used to request establishment of a first session for a terminal device, the first session being used for the terminal device to obtain a second service, the second service being a service permitted to be obtained by the first terminal device in a target network, the second request message including first indication information, the first indication information being used to indicate that the terminal device is accessing the target network without authentication, subscription data of the terminal device and the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the terminal device and the first terminal device and the target network; and establishing the first session for the terminal device according to the second request message.

[0024] In an embodiment of the present application, when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the session management device can establish a session for the terminal device based on the first indication information in the second request message, thereby allowing the terminal device to access the target network without authentication and obtain some of the services provided by the target network.

[0025] In combination with the second aspect, in some implementations of the second aspect, the second request message further includes session parameters available to the terminal device, and the session parameters are used by the terminal device to request services provided by the target network.

[0026] In the embodiment of the present application, the session management device may establish a session for the terminal device based on the session parameters available to the terminal device included in the second request message.

[0027] In conjunction with the second aspect, in certain implementations of the second aspect, when the session parameters available to the terminal device correspond to the second service, a first session is established for the terminal device. When the session parameters available to the terminal device do not correspond to the second service, a fourth response message is sent, where the fourth response message is used to indicate that establishment of the first session for the terminal device is not permitted.

[0028] In an embodiment of the present application, the session management device can determine whether to establish a session for the terminal device based on whether the session parameters available to the terminal device correspond to the services that the first terminal device is allowed to obtain, and then restrict the terminal device to prevent the terminal device from obtaining services that it is not allowed to obtain.

[0029] In combination with the second aspect, in some implementations of the second aspect, the fourth response message includes session parameters corresponding to the second service.

[0030] In an embodiment of the present application, although the session management device refuses to establish a session for the terminal device, it can send a fourth response message including session parameters corresponding to the second service to the access and mobility management device, thereby facilitating the use of correct session parameters when subsequently establishing a session for the terminal device.

[0031] In conjunction with the second aspect, in certain implementations of the second aspect, a first session is established for the terminal device based on the first QoS information. The first QoS information is used to indicate a QoS requirement for the first session, where the QoS requirement for the first session is lower than a QoS requirement corresponding to the second service obtained by the second terminal device. The subscription data of the second terminal device belongs to the target network, or an external authentication protocol exists between the home network of the second terminal device and the target network.

[0032] In an embodiment of the present application, the session management device can establish a first session for the terminal device, and the QoS requirement of the first session is lower than the QoS requirement corresponding to the second service obtained by the second terminal device, thereby restricting the session corresponding to the terminal device, thereby preventing the terminal device from occupying more resources.

[0033] In combination with the second aspect, in certain implementations of the second aspect, a fourth request message is sent to the policy management device, the fourth request message is used to request first policy information, and the fourth request message includes first indication information; the first policy information is received from the policy management device, and the first policy information is used to generate first QoS information.

[0034] In an embodiment of the present application, the session management device may send a request message including first indication information to the policy management device, thereby obtaining first policy information, and then establishing a session for the terminal device according to the first policy information.

[0035] According to a third aspect, a communication method is provided. The method is performed by an access network device and includes: sending a first request message to an access and mobility management device, the first request message including identification information of a terminal device, the first request message being used to request the terminal device to access a target network; and receiving a first response message from the access and mobility management device, the first response message being used to indicate that the terminal device is allowed to access the target network. The subscription data of the terminal device does not belong to the target network, and there is no external authentication protocol between the terminal device's home network and the target network.

[0036] In an embodiment of the present application, when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the access and mobility management device can send a first response message to the access network device, thereby indicating that the terminal device is allowed to access the target network to obtain some of the services provided by the target network.

[0037] In combination with the third aspect, in some implementations of the third aspect, the first response message includes first indication information, and the first indication information is used to indicate that the terminal device accesses the target network without authentication.

[0038] In an embodiment of the present application, when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the access and mobility management device can send a first indication message to the access network device, thereby indicating that the terminal device is allowed to access the target network without authentication.

[0039] In combination with the third aspect, in certain implementations of the third aspect, a fifth request message is received from an access and mobility management device; and a first access network (AN) resource is allocated to the terminal device based on the first indication information and information of the first session.

[0040] Among them, the fifth request message includes information about the first session. The first session is used for the terminal device to obtain the second service, and the second service belongs to the service that the first terminal device is allowed to obtain in the target network. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network. The first AN resources are lower than the AN resources corresponding to the second terminal device, and the first AN resources include physical resources and / or logical resources corresponding to the terminal device. The subscription data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

[0041] In an embodiment of the present application, the access network device allocates a first AN resource to the terminal device based on the first indication information, thereby restricting the terminal device and preventing the terminal device from occupying more resources.

[0042] In combination with the third aspect, in some implementations of the third aspect, the fifth request message also includes first indication information.

[0043] In an embodiment of the present application, the access network device can obtain the first indication information through the first response message, or can obtain the first indication information through the fifth request message, thereby allocating fewer resources to the terminal device according to the first indication information.

[0044] In combination with the third aspect, in certain implementations of the third aspect, the first response message further includes session parameters available to the terminal device, where the session parameters are used by the terminal device to request services provided by the target network.

[0045] In combination with the third aspect, in certain implementations of the third aspect, first indication information and / or session parameters available to the terminal device are sent to the terminal device, where the session parameters are used by the terminal device to request services provided by the target network.

[0046] In an embodiment of the present application, the access network device may send a first response message to the terminal device, so that the terminal device obtains the first indication information and / or available session parameters.

[0047] In a fourth aspect, a communication method is provided. The method is performed by a terminal device and includes: sending a first request message to an access network device, the first request message including identification information of the terminal device, the first request message being used to request the terminal device to access a target network; and receiving a first response message from the access network device, the first response message being used to indicate that the terminal device is allowed to access the target network, the subscription data of the terminal device does not belong to the target network, and there is no external authentication protocol between the terminal device's home network and the target network.

[0048] In an embodiment of the present application, when the subscription data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the access and mobility management device sends a first response message to the terminal device, thereby indicating that the terminal device is allowed to access the target network to obtain some of the services provided by the target network.

[0049] In combination with the fourth aspect, in some implementations of the fourth aspect, the first response message includes first indication information, and the first indication information is used to indicate that the terminal device accesses the target network without authentication.

[0050] In an embodiment of the present application, when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the access and mobility management device can send a first indication message to the terminal device, thereby indicating that the terminal device is allowed to access the target network without authentication.

[0051] In combination with the fourth aspect, in certain implementations of the fourth aspect, a third request message is sent to the access network device, the third request message is used to request establishment of a first session for the terminal device, the first session is used for the terminal device to obtain a second service, the second service belongs to a service that the first terminal device is allowed to obtain in the target network, the contract data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network, and the third request message includes first indication information.

[0052] In an embodiment of the present application, the terminal device can send a request message including first indication information to the access network device, thereby requesting to establish a session to obtain services provided by the target network.

[0053] In combination with the fourth aspect, in certain implementations of the fourth aspect, the second service is obtained through the first session, the service quality QoS requirement of the first session is lower than the QoS requirement corresponding to the second service obtained by the second terminal device, the contract data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

[0054] In the embodiment of the present application, the terminal device can obtain the second service through the first session with lower QoS requirements, thereby limiting the session of the terminal device and preventing the terminal device from occupying more resources.

[0055] In combination with the fourth aspect, in certain implementations of the fourth aspect, data is transmitted to the access network device through the first AN resource, the first AN resource is lower than the AN resource corresponding to the second terminal device, the first AN resource includes the physical resources and / or logical resources corresponding to the terminal device, the contract data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

[0056] In an embodiment of the present application, the terminal device transmits data with the access network device through fewer AN resources, thereby limiting the session of the terminal device and preventing the terminal device from occupying more resources.

[0057] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first response message also includes session parameters available to the terminal device, and / or the third request message also includes session parameters available to the terminal device, which are used by the terminal device to request the services provided by the target network.

[0058] In the embodiment of the present application, the terminal device can obtain available session parameters, thereby carrying the available session parameters in the session establishment request, thereby facilitating the request to establish a session.

[0059] In a fifth aspect, a communication device is provided. The communication device is applied to an access and mobility management device. The device includes: a transceiver module for receiving a first request message from a terminal device; a processing module for determining, based on identification information of the terminal device, that the terminal device's subscription data does not belong to a target network and that there is no external authentication protocol between the terminal device's home network and the target network; the processing module is further configured to determine context information of the terminal device; and the transceiver module is further configured to send a first response message to the terminal device, the first response message being used to indicate that the terminal device is allowed to access the target network.

[0060] The first request message includes identification information of the terminal device, and the first request message is used to request the terminal device to access the target network. The context information of the terminal device includes first indication information, and the first indication information is used to indicate that the terminal device is accessing the target network without authentication.

[0061] In an embodiment of the present application, when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the communication device determines the context information of the terminal device and sets the first indication information in the context information, thereby indicating that the terminal device is allowed to access the target network without authentication to obtain some services provided by the target network.

[0062] In combination with the fifth aspect, in certain implementations of the fifth aspect, the transceiver module is specifically configured to send a first response message when a first service exists in the target network. The first service is a service that the first terminal device in the target network is allowed to obtain. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network. Alternatively, the transceiver module is specifically configured to send a second response message when the first service does not exist in the target network, and the second response message is used to indicate that the terminal device is not allowed to access the target network.

[0063] In combination with the fifth aspect, in certain implementations of the fifth aspect, the transceiver module is specifically used to send a first response message when the time of receiving the first request message belongs to the target time period. The target time period includes the time when the first service in the target network is allowed to be acquired. The first service is a service that the first terminal device in the target network is allowed to acquire. The contract data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network. Alternatively, the transceiver module is specifically used to send a second response message when the time of receiving the first request message does not belong to the target time period, and the second response message is used to indicate that the terminal device is not allowed to access the target network.

[0064] In combination with the fifth aspect, in certain implementations of the fifth aspect, the first response message also includes session parameters and / or first indication information available to the terminal device, where the session parameters are used by the terminal device to request services provided by the target network.

[0065] In conjunction with the fifth aspect, in certain implementations of the fifth aspect, the transceiver module is further configured to send a second request message to the session management device. The second request message is used to request establishment of a first session for the terminal device, where the first session is used for the terminal device to obtain a second service. The second service is a service that the first terminal device is permitted to obtain in the target network. The second request message includes first indication information. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network.

[0066] Exemplarily, the first service includes at least one service, and the at least one service includes the second service.

[0067] In combination with the fifth aspect, in certain implementations of the fifth aspect, the transceiver module is further used to: receive a third request message, which is used to request establishment of a first session for the terminal device; when the session parameters available to the terminal device correspond to the second service, send a second request message to the session management device, which session parameters are used by the terminal device to request acquisition of the service provided by the target network; when the session parameters available to the terminal device do not correspond to the second service, send a third response message to the terminal device, which third response message is used to indicate that establishment of the first session for the terminal device is not allowed.

[0068] In combination with the fifth aspect, in certain implementations of the fifth aspect, the second request message also includes session parameters available to the terminal device, and / or the third request message includes the first indication information and / or session parameters available to the terminal device.

[0069] In a sixth aspect, a communication device is provided. The communication device is applied to a session management device, and includes: a transceiver module, configured to receive a second request message from an access and mobility management device, the second request message being used to request establishment of a first session for a terminal device, the first session being used for the terminal device to obtain a second service, the second service being a service permitted to be obtained by the first terminal device in a target network, the second request message including first indication information, the first indication information being used to indicate that the terminal device is accessing the target network without authentication, the subscription data of the terminal device and the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the terminal device and the first terminal device and the target network; and a processing module, configured to establish the first session for the terminal device based on the second request message.

[0070] In an embodiment of the present application, when the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the communication device can establish a session for the terminal device based on the first indication information in the second request message, thereby allowing the terminal device to access the target network without authentication and obtain some of the services provided by the target network.

[0071] In combination with the sixth aspect, in certain implementations of the sixth aspect, the second request message also includes session parameters available to the terminal device, and the session parameters are used by the terminal device to request services provided by the target network.

[0072] In conjunction with the sixth aspect, in certain implementations of the sixth aspect, the processing module is further configured to establish the first session for the terminal device when the session parameters available for the terminal device correspond to the second service. The transceiver module is further configured to send a fourth response message when the session parameters available for the terminal device do not correspond to the second service, the fourth response message being configured to indicate that establishment of the first session for the terminal device is not permitted.

[0073] In combination with the sixth aspect, in certain implementations of the sixth aspect, the fourth response message includes session parameters corresponding to the second service.

[0074] In conjunction with the sixth aspect, in certain implementations of the sixth aspect, the processing module is further configured to establish a first session for the terminal device based on the first QoS information. The first QoS information is used to indicate a QoS requirement for the first session, where the QoS requirement for the first session is lower than a QoS requirement corresponding to the second service obtained by the second terminal device. The subscription data of the second terminal device belongs to the target network, or an external authentication protocol exists between the home network of the second terminal device and the target network.

[0075] In combination with the sixth aspect, in certain implementations of the sixth aspect, the transceiver module is specifically used to: send a fourth request message to the policy management device, the fourth request message is used to request first policy information, and the fourth request message includes first indication information; receive first policy information from the policy management device, and the first policy information is used to generate first QoS information.

[0076] In a seventh aspect, a communication device is provided. The communication device is applied to an access network device and includes: a sending module for sending a first request message to an access and mobility management device, the first request message including identification information of a terminal device, the first request message being used to request the terminal device to access a target network; and a receiving module for receiving a first response message from the access and mobility management device, the first response message being used to indicate that the terminal device is allowed to access the target network. The subscription data of the terminal device does not belong to the target network, and there is no external authentication protocol between the terminal device's home network and the target network.

[0077] In an embodiment of the present application, when the subscription data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the access and mobility management device can send a first response message to the communication device, thereby indicating that the terminal device is allowed to access the target network to obtain some of the services provided by the target network.

[0078] In combination with the seventh aspect, in some implementations of the seventh aspect, the first response message includes first indication information, and the first indication information is used to indicate that the terminal device accesses the target network without authentication.

[0079] In combination with the seventh aspect, in certain implementations of the seventh aspect, the device also includes a processing module, wherein the receiving module is also used to receive a fifth request message from the access and mobility management device; the processing module is used to allocate a first AN resource to the terminal device based on the first indication information and the information of the first session.

[0080] Among them, the fifth request message includes information about the first session. The first session is used for the terminal device to obtain the second service, and the second service belongs to the service that the first terminal device is allowed to obtain in the target network. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network. The first AN resources are lower than the AN resources corresponding to the second terminal device, and the first AN resources include physical resources and / or logical resources corresponding to the terminal device. The subscription data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

[0081] In combination with the seventh aspect, in some implementations of the seventh aspect, the fifth request message also includes first indication information.

[0082] In combination with the seventh aspect, in certain implementations of the seventh aspect, the first response message also includes session parameters available to the terminal device, and the session parameters are used by the terminal device to request services provided by the target network.

[0083] In combination with the seventh aspect, in certain implementations of the seventh aspect, the sending module is further used to send first indication information and / or session parameters available to the terminal device to the terminal device, and the session parameters are used by the terminal device to request to obtain services provided by the target network.

[0084] In an eighth aspect, a communication device is provided. The communication device is applied to a terminal device and includes: a sending module for sending a first request message to an access network device, the first request message including identification information of the communication device, the first request message being used to request the communication device to access a target network; and a receiving module for receiving a first response message from the access network device, the first response message being used to indicate that the communication device is allowed to access the target network, the subscription data of the communication device does not belong to the target network, and there is no external authentication protocol between the home network of the communication device and the target network.

[0085] In an embodiment of the present application, when the subscription data of the communication device does not belong to the target network and there is no external authentication protocol between the home network of the communication device and the target network, the access and mobility management device sends a first response message to the communication device, thereby indicating that the communication device is allowed to access the target network to obtain some of the services provided by the target network.

[0086] In combination with the eighth aspect, in certain implementations of the eighth aspect, the first response message includes first indication information, and the first indication information is used to indicate that the communication device accesses the target network without authentication.

[0087] In combination with the eighth aspect, in certain implementations of the eighth aspect, the sending module is further used to send a third request message to the access network device, the third request message is used to request to establish a first session for the communication device, the first session is used for the communication device to obtain a second service, the second service belongs to a service that the first terminal device in the target network is allowed to obtain, the contract data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network, and the third request message includes first indication information.

[0088] In combination with the eighth aspect, in certain implementations of the eighth aspect, the device also includes a processing module, which is used to obtain a second service through a first session. The quality of service QoS requirement of the first session is lower than the QoS requirement corresponding to the second service obtained by the second terminal device. The contract data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

[0089] In combination with the eighth aspect, in certain implementations of the eighth aspect, the device also includes a processing module, which is used to transmit data to the access network device through a first AN resource, the first AN resource is lower than the AN resource corresponding to the second terminal device, the first AN resource includes physical resources and / or logical resources corresponding to the communication device, the contract data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

[0090] In combination with the eighth aspect, in certain implementations of the eighth aspect, the first response message also includes session parameters available to the communication device, and / or the third request message also includes session parameters available to the communication device, which are used by the communication device to request the services provided by the target network.

[0091] In a ninth aspect, a communication device is provided. The communication device includes at least one processor and a communication interface, wherein the communication interface is used for the communication device to exchange information with other communication devices, and when program instructions are executed in the at least one processor, the communication device performs the method described in the first aspect or any possible implementation of the first aspect.

[0092] In a tenth aspect, a communication device is provided. The communication device includes at least one processor and a communication interface, wherein the communication interface is used for the communication device to exchange information with other communication devices, and when program instructions are executed in the at least one processor, the communication device performs the method described in the second aspect or any possible implementation of the second aspect.

[0093] In an eleventh aspect, a communication device is provided. The communication device includes at least one processor and a communication interface, wherein the communication interface is used for the communication device to exchange information with other communication devices. When program instructions are executed in the at least one processor, the communication device performs the method described in the third aspect or any possible implementation of the third aspect.

[0094] In a twelfth aspect, a communication device is provided. The communication device includes at least one processor and a communication interface, wherein the communication interface is used for the communication device to exchange information with other communication devices, and when program instructions are executed in the at least one processor, the communication device performs the method described in the fourth aspect or any possible implementation of the fourth aspect.

[0095] In a thirteenth aspect, a communication system is provided, which includes the communication device according to the ninth aspect, the communication device according to the tenth aspect, the communication device according to the eleventh aspect, and the communication device according to the twelfth aspect.

[0096] In the fourteenth aspect, a computer program product is provided, which includes program instructions. When the computer program product is run on a computer, it enables the computer to execute the method described in any possible implementation of any of the first, second, third, and fourth aspects above.

[0097] In the fifteenth aspect, a computer-readable storage medium is provided, which stores program code for execution by a device. When the program code is executed, the method described in any possible implementation of any of the first, second, third, and fourth aspects above is executed.

[0098] In the sixteenth aspect, a chip is provided, which includes at least one processor. When program instructions are executed by the at least one processor, the method described in any possible implementation of any of the first, second, third, and fourth aspects above is executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0099] FIG1 is a schematic block diagram of a communication system according to an embodiment of the present application.

[0100] FIG2 is a schematic block diagram of a communication system according to another embodiment of the present application.

[0101] FIG3 is a schematic block diagram of a communication system according to another embodiment of the present application.

[0102] FIG4 is a schematic flow chart of a registration method for a terminal device.

[0103] FIG5 is a schematic flow chart of a session establishment method of a terminal device.

[0104] FIG6 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0105] FIG7 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0106] FIG8 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0107] FIG9 is a schematic flowchart of a communication method according to another embodiment of the present application.

[0108] FIG10 is a schematic structural diagram of a communication device 1000 according to an embodiment of the present application.

[0109] FIG11 is a schematic structural block diagram of a communication device 1100 according to an embodiment of the present application. DETAILED DESCRIPTION

[0110] The technical solution in this application will be described below with reference to the accompanying drawings.

[0111] The embodiments of the present application will present various aspects, embodiments, or features around a system including multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these solutions may also be used.

[0112] Additionally, in the embodiments of this application, words such as "exemplary" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.

[0113] The business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of technology and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0114] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in yet other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0115] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: including the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0116] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: global system for mobile communications (GSM) system, code division multiple access (CDMA) system, wideband code division multiple access (WCDMA) system, general packet radio service (GPRS), long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, universal mobile telecommunication system (UMTS), world-wide interoperability for microwave access (WiMAX) communication system, fourth generation (4G) system, fifth generation (5G) system and next generation wireless communication system or new radio (NR), etc. The technical solutions of the embodiments of the present application can also be applied to various NPNs, such as SNPN or PNI-NPN, etc.

[0117] The terminal device in the embodiments of the present application may also be referred to as: user equipment (UE), mobile station (MS), mobile terminal (MT), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent or user device, etc.

[0118] The terminal device may be a device that provides voice / data connectivity to users, such as a handheld device or vehicle-mounted device with wireless connection function. At present, some examples of terminals are: mobile phones, tablet computers, laptop computers, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, terminal devices in 5G networks or future evolved public land mobile communication networks (PLMNs). The terminal equipment in the network (PLMN), etc., is not limited to this in the embodiments of the present application.

[0119] As an example and not a limitation, in the embodiment of the present application, the terminal device may also be a wearable device. Wearable devices may also be called wearable smart devices, which are a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0120] In addition, in the embodiment of the present application, the terminal device can also be a terminal device in the Internet of Things (IoT) system. IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.

[0121] In addition, the access network device in the embodiment of the present application can be a transmission reception point (TRP), an evolved NodeB (eNB or eNodeB) in the LTE system, a home base station (for example, home evolved NodeB, or home Node B, HNB), a base band unit (BBU), or a wireless controller in a cloud radio access network (CRAN) scenario, or the access network device can be a relay station, an access point, a vehicle-mounted device, a wearable device, and an access network device in a 5G network or an access network device in a future evolved public land mobile network (PLMN) network, etc. It can be an access point (AP) in a WLAN, or a gNB in ​​a new radio system (NR) system, and the embodiment of the present application is not limited. In a network structure, the access network device may include a centralized unit (CU) node, a distributed unit (DU) node, or a radio access network (RAN) device including a CU node and a DU node, or a RAN device including a control plane CU node (CU-CP node) and a user plane CU node (CU-UP node) and a DU node.

[0122] In an embodiment of the present application, a terminal device or each network device includes a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also called main memory). The operating system can be any one or more computer operating systems that implement business processing through processes, such as a Linux operating system, a Unix operating system, an Android operating system, an iOS operating system, or a Windows operating system. The application layer includes applications such as browsers, address books, word processing software, and instant messaging software. In addition, the embodiment of the present application does not specifically limit the specific structure of the execution subject of the method provided in the embodiment of the present application. As long as it is possible to communicate according to the method provided in the embodiment of the present application by running a program that records the code of the method provided in the embodiment of the present application, for example, the execution subject of the method provided in the embodiment of the present application can be a network device, or a functional module in the network device that can call and execute a program.

[0123] In addition, various aspects or features of the present application can be implemented as methods, apparatuses, or articles of manufacture using standard programming and / or engineering techniques. The term "article of manufacture" as used in this application encompasses a computer program that can be accessed from any computer-readable device, carrier, or medium. For example, computer-readable media may include, but are not limited to: magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes, etc.), optical disks (e.g., compact discs (CDs), digital versatile discs (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memories (EPROMs), cards, sticks, or key drives, etc.). In addition, the various storage media described herein may represent one or more devices and / or other machine-readable media for storing information. The term "machine-readable medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.

[0124] To facilitate understanding of the embodiments of the present application, several terms involved in the present application are first briefly explained.

[0125] 1. SNPN

[0126] SNPN is not dependent on PLMN, but is operated by SNPN operators. In other words, the SNPN core network is independent of the PLMN network, that is, the SNPN core network is independently operated by the SNPN. When a terminal device wants to access the SNPN, it needs to enter the SNPN access mode.

[0127] 2. PNI-NPN

[0128] The PNI-NPN network relies on the PLMN network and is operated by traditional operators. In other words, the PNI-NPN is actually the PLMN, but the PLMN provides special slices and / or data networks to provide NPN services. This means that not all terminal devices can access these NPN services. Only those terminal devices that pass slice authentication and / or secondary authentication (the authentication process during session establishment) can access these NPN services. Simply put, the PNI-NPN uses slices to isolate public network services from private network services, thereby providing private network services to private network users.

[0129] 3. External Authentication

[0130] For SNPN, the terminal device is allowed to use the certificate of the certificate holder for authentication, thereby accessing the SNPN. For example, for the SNPN shown in Figure 2 or Figure 3, the terminal device uses the certificate of the certificate holder (credentials holder) to authenticate and access the SNPN. For example, the credentials holder can be a PLMN, such as the home PLMN (HPLMN) of the terminal device, that is, the terminal device itself has the subscription data of the HPLMN. There is a corresponding external authentication protocol between the HPLMN and the SNPN of the terminal device, which allows the terminal device to access the SNPN using the subscription data of the HPLMN. When the terminal device has the subscription data of the HPLMN and there is a corresponding external authentication protocol between the HPLMN and the SNPN of the terminal device, the terminal device can carry the user subscription concealed identifier (SUCI) corresponding to the HPLMN subscription data when accessing the SNPN. The SNPN can retrieve the HPLMN of the terminal device through the home network information in the SUCI, select the corresponding authentication server function (AUSF) network element / unified data management function (UDM) network element to complete the authentication, so that the terminal device can successfully access the SNPN to obtain services.

[0131] 4. Emergency business

[0132] Emergency services are network support for terminal devices to establish emergency Internet Protocol (IP) Multimedia Subsystem (IMS) sessions. Emergency services can be obtained by normally registered terminal devices or emergency registered terminal devices. Terminal devices can be in a normal registration state or a state where access to services is restricted. When a terminal device performs an emergency registration, during the registration process, the terminal device reports the registration type as an emergency registration. At this time, the access and mobility management function (AMF) device can allow the terminal device to continue the registration process without performing the main authentication or if the main authentication fails, so that the terminal device can access the network. At this time, the terminal device is only allowed to obtain emergency services, such as emergency sessions such as dialing 110.

[0133] Figure 1 is a schematic diagram of a communication system according to an embodiment of the present application. The communication system 100 in Figure 1 includes a terminal device 110, an access network device 120, an access and mobility management device 130, and a session management device 140. In some embodiments, the communication system 100 in Figure 1 may also include a policy management device 150.

[0134] Among them, the access and mobility management device 130 and the session management device 140 are core network devices. For example, the terminal device 110 can access the target network through the access network device 120 to achieve data transmission. The access and mobility management device 130 can receive a request forwarded by the access network device 120 to connect the terminal device 110 to the target network, and request the session management device 140 to establish a session for the terminal device 110 to obtain services provided by the target network. The policy management device 150 can provide the session management device 140 with policy information corresponding to the session, thereby determining the quality of service requirements of the session.

[0135] Access network equipment 120 provides network access for authorized users in a specific area and can utilize transmission tunnels of varying quality based on user level and service requirements. The network element in access network equipment 120 manages radio resources, provides access services to terminal devices, and forwards control signals and user data between terminal devices and the core network. Access network equipment 120 can also be understood as a base station in a traditional network. The interface between access network equipment 120 and access and mobility management device 130 is the N2 interface, and messages transmitted over this N2 interface are called N2 messages.

[0136] The access and mobility management device 130 may also be referred to as an access and mobility management function (AMF) entity, an access and mobility management device, an access and mobility management network element, an access management device, or a mobility management device. The access and mobility management device 130 is a type of core network device, mainly used for mobility management and access management, etc., and may be used to implement other functions of the mobility management entity (MME) function except session management. For example, access authorization (or authentication), registration of user equipment, mobility management, tracking area update process, reachability detection, selection of session management network element, mobile state transition management and other functions. For example, in 5G, the access and mobility management network element may be an access and mobility management function network element. In future communications, such as 6G, the access and mobility management network element may still be an AMF network element, or have other names, which are not limited in this application. When the access and mobility management network element is an AMF network element, the AMF may provide Namf services.

[0137] The session management device 140 may also be referred to as a session management function (SMF) network element, which mainly performs session management, IP address allocation and management, selection of endpoints for manageable user plane functions, policy control, or charging function interfaces, and downlink data notification.

[0138] The policy management device 150 can also be called a policy control function (PCF) network element, policy control network element, policy control function network element, policy control device, policy control function entity, etc. It is mainly responsible for policy control functions such as billing for sessions and business flow levels, quality of service (QoS) bandwidth guarantee and mobility management, UE policy decision-making, etc., as well as providing a unified policy framework for network behavior management, providing policy rules for control plane functions, and obtaining registration information related to policy decisions.

[0139] Figure 2 is a schematic diagram of the SNPN architecture 200. The SNPN 200 in Figure 2 includes a UE 201, a RAN 202, a user plane function (UPF) 203, a data network (DN) 204, an AMF 205, an SMF 206, a network slice admission control function (NSACF) 207, a network slice selection function (NSSF) 208, a unified data management function (UDM) 209, a network exposure function (NEF) 210, a network repository function (NRF) 211, a PCF 212, an application layer function (AF) 213, an AUSF 214, and a network slice-specific authentication and authorization function (NSSAAF) 215.

[0140] 1 , RAN 202 is similar to the access network device 120 in FIG1 , AMF 205 is similar to the access and mobility management device 130 in FIG1 , SMF 206 is similar to the session management device 140 in FIG1 , and PCF 212 is similar to the policy management device 150 in FIG1 .

[0141] UPF 203 can also be called user plane equipment, user plane functional network element, user plane network element, user plane functional entity. UPF 203 mainly includes the following functions: data packet routing and transmission, packet detection, service usage reporting, QoS processing, legal monitoring, uplink packet detection, downlink data packet storage and other user plane related functions.

[0142] The DN 204 is used to provide a network for transmitting data, such as the Internet.

[0143] NSACF 207 is mainly used to monitor the number of UEs registered on each network slice and the number of data protocol unit (PDU) sessions established on each network slice.

[0144] NSSF 208 is used to select network slices.

[0145] The UDM 209, also known as a unified data management network element, unified data management entity, or data management device, is a type of core network device. The UDM 209 is primarily responsible for processing terminal device identification, access authentication, registration, and mobility management.

[0146] NEF 210 can also be called network open device, network open functional entity, network open functional network element, network capability open functional entity, network capability open functional device, network capability open functional network element, network capability open device, etc. It is mainly used to support the opening of capabilities and events, such as securely opening the services and capabilities provided by the 3rd Generation Partnership Project (3GPP) network functions to the outside world.

[0147] NRF 211 can also be called a network storage device, a network storage function network element, or a network storage function entity, and is mainly used to support service discovery functions. A network element discovery request is received from a network element function or a service communication proxy (SCP), and the network element discovery request information can be fed back. At the same time, NRF 211 is also responsible for maintaining information about available network functions and the services they each support. NRF 211 can also be understood as a network storage device. Among them, the discovery process is a process in which the required network function (NF) uses NRF to implement addressing of a specific NF or a specific service. NRF provides the IP address or fully qualified domain name (FQDN) or unified resource identifier (URI) of the corresponding NF instance or NF service instance. In addition, NRF can also implement a cross-PLMN discovery process by providing a network identifier (such as a PLMN identifier). In order to implement addressing and discovery of network element functions, each network element needs to be registered in NRF, and some network element functions can be registered in NRF during first operation. The network storage function device can be a core network device.

[0148] The AF 213 primarily interacts with the 3GPP core network to provide services, such as influencing data routing decisions, policy control functions, or providing third-party services to the network. It can be understood as a third-party server, such as an application server on the Internet, providing relevant service information, including providing service quality requirements information corresponding to the service to the PCF and sending user plane data information of the service to the PSA-UPF. The AF can be a service provider (CP).

[0149] AUSF 214 can also be called an authentication service function network element, an authentication service function entity, an authentication service device, or an authentication device, and is mainly used for user authentication, etc. AUSF 214 can also be understood as an authentication device. The authentication service function network element is used to perform authentication, that is, authentication between the UE and the operator network. After receiving an authentication request initiated by a subscriber, the authentication service function network element can authenticate and / or authorize the subscriber through the authentication information and / or authorization information stored in the unified data management network element, or generate authentication and / or authorization information of the subscriber through the unified data management network element. The authentication service function network element can feedback authentication information and / or authorization information to the subscriber.

[0150] In one possible implementation, the authentication service function network element may be co-located with the unified data management network element. In a 5G communication system, the authentication service function network element may be an authentication server function (AUSF) network element. In future communication systems, the unified data management may still be AUSF, or may have other names, which are not limited in the embodiments of the present application.

[0151] The NSSAAF 215 is responsible for the security authentication and access control of network slices. The NSSAAF 215 is used to support authentication and authorization of specific network slices with an authentication authorization accounting (AAA) server or AAA proxy, and to support access to the SNPN using credentials from a credentials holder (CH) that is authenticated by the AAA server.

[0152] AAA server 216, also known as an authentication and authorization server, authentication and authorization device, authentication device, or authentication, authorization, and accounting device, is a server program that processes user access requests and provides authentication, authorization, and accounting services. AAA server 216 typically works in conjunction with network access control, gateway servers, databases, and user information directories. The network connection server interface that collaborates with AAA server 216 is Remote Authentication Dial-In User Service (RADIUS).

[0153] AMF 205 or SMF 206 transmits information through different interfaces with NSACF 207, NSSF 208, UDM 209, NEF 210, NRF 211, AF 213, AUSF 214, and NSSAAF 215. UE 201 can authenticate access to SNPN 200 through AAA server 216 of the CH.

[0154] Figure 3 is a schematic block diagram of SNPN 300. SNPN 300 in Figure 3 includes UE 301, RAN 302, UPF 303, DN 304, AMF 305, SMF 306, NSACF 307, NSSF 308, NEF 309, NRF 310, PCF 311, and AF 312. CH includes NSSAAF 314, UDM 315, NRF 316, and AUSF 317. Some network elements in SNPN 300 transmit information with some network elements in CH via a security edge protection proxy (SEPP). UE 301 in Figure 3 authenticates access to SNPN 300 through AUSF 317 and UDM 315 of the CH. The various network elements or devices in Figure 3 are similar to the corresponding network elements or devices in Figure 2 and are not described in detail here.

[0155] Figure 4 is a schematic flowchart of a terminal device registration method. The UE in Figure 4 is similar to terminal device 110 in Figure 1 , the RAN in Figure 4 is similar to access network device 120 in Figure 1 , the AMF in Figure 4 is similar to access and mobility management device 130 in Figure 1 , the AUSF in Figure 4 is similar to AUSF 214 in Figure 2 , and the UDM in Figure 4 is similar to UDM 209 in Figure 2 . The method in Figure 4 includes the following steps.

[0156] S410: Send a registration request message to the RAN.

[0157] The UE sends a registration request message to the RAN, which includes the registration type and the terminal device's identification information. The terminal device's identification information includes any of the following: SUCI, 5G globally unique temporary identifier (5G-GUTI), permanent equipment identity (PEI)

[0158] Optionally, the registration request message also includes a data network name (DNN) of a local area data network (LADN) requested by the terminal device.

[0159] Optionally, the registration type includes the following:

[0160] (1) Initial registration: The registration process initiated when the UE is in the deregistered state.

[0161] (2) Mobility registration update: A registration process initiated when the UE moves.

[0162] (3) Periodic registration update: When the UE is in the registered state, the registration process is initiated due to the expiration of the periodic registration update timer.

[0163] (4) Emergency registration: A registration procedure initiated when the UE is in a service-restricted state.

[0164] Regarding the UE's identification information, when the UE has a valid 5G-GUTI, the 5G-GUTI is carried in the registration request. The 5G-GUTI is a temporary identity assigned by the AMF serving it. If the UE does not have a valid 5G-GUTI, the SUCI is carried. In an emergency registration, if the UE does not have a valid 5G-GUTI and a subscription permanent identifier (SUPI), the PEI is carried. The fact that the UE does not have a valid SUPI indicates that the UE does not have a SUCI, and the SUCI is an encrypted SUPI.

[0165] S420, select a suitable AMF.

[0166] The RAN selects an appropriate AMF based on the received registration request message.

[0167] S430: Send a registration request message to the AMF.

[0168] The RAN forwards the Registration Request message sent by the UE to the AMF.

[0169] S440, select a suitable AUSF for authentication.

[0170] AMF selects the appropriate AUSF to perform security processes such as authentication.

[0171] S450: Perform authentication.

[0172] UE, AMF, AUSF, UDM, etc. interact to complete security processes such as authentication.

[0173] S460: Request the UDM for the UE's subscription data.

[0174] After the UE and the network have successfully authenticated each other, the AMF interacts with the UDM to obtain the UE's subscription data. The AMF sends a request message to the UDM to request that the UDM deliver the subscription data.

[0175] S470: Send the UE's subscription data to the AMF.

[0176] After receiving the request from AMF, UDM sends the UE's subscription data to AMF.

[0177] S480: Send an N2 message to the RAN.

[0178] The AMF sends an N2 message to the RAN via the N2 interface. The N2 message includes a non-access stratum (NAS) message. The NAS message includes a registration acceptance message. The registration acceptance message includes the LADN DNN information requested by the UE or the DNN information to which the UE has subscribed.

[0179] S490: Send a registration acceptance message to the UE.

[0180] The RAN forwards the NAS message sent by the AMF to the UE, which includes the registration accept message.

[0181] Figure 5 is a schematic flowchart of a method for establishing a session for a terminal device. The UE in Figure 5 is similar to terminal device 110 in Figure 1 , the RAN in Figure 5 is similar to access network device 120 in Figure 1 , the AMF in Figure 5 is similar to access and mobility management device 130 in Figure 1 , the SMF in Figure 5 is similar to session management device 140 in Figure 1 , and the PCF in Figure 5 is similar to policy management device 150 in Figure 1 . The UPF in Figure 5 is similar to UPF 203 in Figure 2 . The method in Figure 5 includes the following steps.

[0182] S501, send a PDU session establishment request message to AMF.

[0183] The UE sends a PDU session establishment request message to the AMF. The PDU session establishment request message is a NAS message. The PDU session establishment request message carries parameters such as the PDU session identification (session ID), request type (request type), UE requested data network name (UE requested DNN), and single network slice selection assistance information (S-NSSAI). Among them, when the request type is LADN PDU request (request), the PDU session establishment request is used to request the establishment of a LADN session. DNN is the corresponding LADN DNN.

[0184] S502: Select a suitable SMF.

[0185] The AMF selects the appropriate SMF based on the received PDU session establishment request message.

[0186] S503: Send a PDU session creation session context request message to the SMF.

[0187] The AMF sends a PDU session creation session context request message to the SMF. The PDU session creation session context request message includes parameters such as the UE's SUPI, the LADN DNN requested by the UE, the PDU session identifier, and the LADN PDU request.

[0188] S504: Acquire session management contract data.

[0189] The SMF obtains the session management subscription data from the UDM, where the subscription data may include information on whether to allow the establishment of a local area network session (LADN PDU session). Step S504 is an optional step, that is, step S504 may not be performed.

[0190] S505: Send a PDU session creation session context response message to the AMF. The SMF feeds back the PDU session creation session context response message to the AMF.

[0191] S506: Execute the PDU session authentication or authorization process. Step S506 is an optional step, that is, step S506 may not be executed.

[0192] S507: Select PCF and establish session policy association.

[0193] If dynamic policy and charging control (PCC) rules are required, the SMF selects the PCF and establishes a session policy association. Step S507 is an optional step, that is, step S507 may not be performed.

[0194] Specifically, the SMF sends a session management (SM) policy association establishment request message to the PCF, and the PCF sends an SM policy association establishment response message to the SMF.

[0195] S508, select a suitable UPF. SMF selects a suitable UPF.

[0196] S509, SMF initiates a session policy update to PCF.

[0197] If the PCF subscribes to events from the SMF, such as a UE time zone change or location change, the SMF can report the change information to the PCF, and the PCF can dynamically update the UE's session policy based on the reported event. Step S509 is optional, i.e., step S509 may not be performed.

[0198] S510, SMF establishes N4 connection with UPF.

[0199] Specifically, the SMF sends N4 rules to the UPF, including packet detection rules (PDR), forwarding action rules (FAR) and other rules.

[0200] S511: Send an N1N2 message transfer message to the AMF.

[0201] The SMF sends an N1N2 message transfer message (Namf_Communication_N1N2MessageTransfer) to the AMF. This N1N2 message transfer message includes information such as the session identifier, N2 interface session management information (N2 SM information), and the N1 interface session management container (N1 SM container). The SMF sends the N2 SM information to the RAN via the AMF. This N2 SM information includes information such as the UPF tunnel endpoint identifier, which indicates the destination address of the uplink data. The SMF sends the information in the N1 SM container to the UE via the AMF. Specifically, the AMF sends an NAS message to the UE, which includes the information in the N1 SM container.

[0202] S512: Send an N2 PDU session request message to the RAN.

[0203] The AMF sends an N2 PDU Session Request message to the RAN. The N2 PDU Session Request message includes the N2 SM information and the NAS message to be sent to the UE. The NAS message includes the session identifier and the N1 SM container.

[0204] S513: RAN establishes air interface resources with UE.

[0205] The RAN establishes air interface resources with the UE and sends a NAS message to the UE, which includes a PDU session establishment accept message.

[0206] S514: Send an N2 PDU session response message to the AMF.

[0207] The RAN sends an N2 PDU Session Response message to the AMF. This message includes the tunnel endpoint identifier on the RAN side, which indicates the destination address of the downlink data. This tunnel endpoint identifier is subsequently sent to the UPF via the AMF and SMF.

[0208] S515: Send a PDU session update session context request to the SMF.

[0209] AMF sends the message sent by RAN to SMF via PDU session update session context request.

[0210] S516: The SMF sends the RAN-side AN tunnel endpoint identification information to the UPF through the N4 session modification process. The UPF sends a response message to the SMF to confirm that the session update is complete.

[0211] S517: Send a PDU session update session context response message to the AMF. The SMF sends a PDU session update session context response message to the AMF.

[0212] In the communication method shown in Figures 4 and 5, the premise for the terminal device to access the target network is that the terminal device has the subscription data of the target network, or there is an external authentication protocol between the home network of the terminal device and the target network. When the subscription data of the terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the terminal device and the target network, the terminal device can only access the target network through emergency registration to obtain emergency services, such as making emergency calls. Therefore, an embodiment of the present application provides a communication method, which enables the terminal device to access the target network as a temporary UE and obtain services when the subscription data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network. In some embodiments, the target network can also restrict the temporary UE so that the services obtained by the temporary UE are different from those obtained by ordinary UEs, or the services obtained by the temporary UE are less than those obtained by ordinary UEs. The subscription data of the ordinary UE belongs to the target network, or there is an external authentication protocol between the home network of the ordinary UE and the target network.

[0213] FIG6 is a schematic flow chart of a communication method provided in an embodiment of the present application. The method in FIG6 is applied to the communication system 100 shown in FIG1 , or to the SNPN in FIG2 or FIG3 . The UE in FIG6 is similar to the terminal device 110 in FIG1 , and the AMF in FIG6 is similar to the access and mobility management device 130 in FIG1 . The method in FIG6 includes the following steps.

[0214] S610: Send a first request message to the AMF.

[0215] The terminal device sends a first request message to the AMF. Correspondingly, the AMF receives the first request message from the terminal device. The first request message includes identification information of the terminal device. The first request message is used to request the terminal device to access the target network.

[0216] In some embodiments, the target network is an NPN network.The identification information of the terminal device includes a SUCI of the terminal device.

[0217] In some embodiments, the terminal device sends a first request message to the RAN, and the RAN forwards the first request message to the AMF. The RAN is similar to the access network device 120 in Figure 1.

[0218] In some embodiments, the first request message is a registration request message.

[0219] In some embodiments, the terminal device sends the AN parameters and the registration request message to the RAN.

[0220] S620: Determine, based on the identification information of the terminal device, that the subscription data of the terminal device does not belong to the target network, and that there is no external authentication protocol between the home network of the terminal device and the target network.

[0221] After receiving the first request message, the AMF determines whether the subscription data of the terminal device belongs to the target network based on the identification information of the terminal device. If not, it determines whether there is an external authentication protocol between the home network of the terminal device and the target network.

[0222] When the contract data of the terminal device belongs to the target network, or there is an external authentication agreement between the home network of the terminal device and the target network, the AMF executes the registration process in Figure 4 and sends a fifth response message to the terminal device, which is used to indicate that the terminal device is allowed to access the target network.

[0223] In some embodiments, the AMF sends the fifth response message to the RAN, and the RAN forwards the fifth response message to the terminal device.

[0224] When the subscription data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the AMF performs steps S630 and S640.

[0225] Optionally, the AMF determines whether the contract data of the terminal device belongs to the target network based on the identification information of the terminal device. When it is determined that the contract data of the terminal device does not belong to the target network, the AMF queries the AUSF and / or UDM in the home network of the terminal device, or queries the AAA server in the home network of the terminal device based on the information of the home network included in the identification information of the terminal device. If the AUSF and / or UDM corresponding to the target network are found, it means that an external authentication protocol exists between the home network of the terminal device and the target network. If the AUSF and / or UDM corresponding to the target network are not found, it means that there is no external authentication protocol between the home network of the terminal device and the target network. Similarly, if the AAA server corresponding to the target network is found, it means that there is an external authentication protocol between the home network of the terminal device and the target network. If the AAA server corresponding to the target network is not found, it means that there is no external authentication protocol between the home network of the terminal device and the target network.

[0226] S630: Determine the context information of the terminal device.

[0227] When the terminal device's subscription data does not belong to the target network and there is no external authentication agreement between the terminal device's home network and the target network, the AMF determines the terminal device's context information. The terminal device's context information includes first indication information. The first indication information is used to indicate that the terminal device is accessing the target network without authentication.

[0228] In some embodiments, the AMF creates context information for the terminal device and sets the first indication information in the context information of the terminal device. The first indication information includes at least one bit.

[0229] Exemplarily, when the first indication information is included in the context information of the terminal device, it indicates that the terminal device is allowed to access the target network and obtain some services provided by the target network.

[0230] Exemplarily, some of the services provided by the target network include emergency services and other services except emergency services.

[0231] Exemplarily, the first terminal device and the second terminal device are permitted to access different services after accessing the target network. Alternatively, the first terminal device is permitted to access fewer services after accessing the target network than the second terminal device is permitted to access after accessing the target network. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication agreement between the home network of the first terminal device and the target network. The subscription data of the second terminal device belongs to the target network, or there is an external authentication agreement between the home network of the second terminal device and the target network.

[0232] In some embodiments, after the AMF determines the context information of the terminal device, it stores the context information of the terminal device.

[0233] In some embodiments, the AMF determines available session parameters of the terminal device. The available session parameters of the terminal device are used by the terminal device to request services provided by the target network.

[0234] Exemplarily, the session parameters available to the terminal device include network slice information and / or DNN information.

[0235] Exemplarily, the AMF pre-configures session parameters available to the first terminal device, and determines that the session parameters available to the terminal device are the session parameters available to the first terminal device.

[0236] Exemplarily, after the AMF determines the session parameters available for the terminal device, it stores the session parameters available for the terminal device.

[0237] Optionally, when the first service exists in the target network, the AMF determines context information of the terminal device, where the context information includes first indication information. When the first service does not exist in the target network, the AMF sends a second response message to the terminal device, where the second response message is used to indicate that the terminal device is not allowed to access the target network. The first service is a service that the first terminal device is allowed to access.

[0238] Optionally, when the time of receiving the first request message falls within the target time period, the AMF determines the context information of the terminal device, where the context information includes the first indication information. When the time of receiving the first request message does not fall within the target time period, the AMF sends a second response message to the terminal device, where the second response message is used to indicate that the terminal device is not allowed to access the target network. That is, when the time of receiving the first request message does not fall within the target time period, the AMF may not determine the context information of the terminal device. The target time period includes the time when the first service in the target network is allowed to be acquired.

[0239] In some embodiments, the target time period is information pre-configured by the AMF.

[0240] For example, assuming that the time period during which the first service provided by the target network is allowed to be obtained is 10:00-20:00, then the target time period is 10:00-20:00. When the AMF receives the first request message within the target time period and the first service exists in the target network, the AMF determines the context message of the terminal device, and the context message includes the first indication information. When the AMF receives the first request message outside the target time period, or when the first service does not exist in the target network, the AMF sends a second response message to the terminal device.

[0241] In some embodiments, the AMF sends the second response message to the RAN, and the RAN forwards the second response message to the terminal device.

[0242] S640: Send a first response message to the UE.

[0243] If the terminal device's subscription data does not belong to the target network and there is no external authentication agreement between the terminal device's home network and the target network, the AMF sends a first response message to the terminal device. The terminal device receives the first response message in response. The first response message indicates that the terminal device is allowed to access the target network.

[0244] In some embodiments, the first response message includes first indication information and / or session parameters available to the terminal device. The first indication information is used to indicate that the terminal device accesses the target network without authentication.

[0245] In some embodiments, the AMF sends the first response message to the RAN, and the RAN forwards the first response message to the terminal device.

[0246] In some embodiments, the first response message is a registration acceptance message.

[0247] Optionally, when the first service exists in the target network, the AMF sends the first response message to the terminal device. When the first service does not exist in the target network, the AMF sends a second response message to the terminal device, where the second response message is used to indicate that the terminal device is not allowed to access the target network. The first service is a service that the first terminal device is allowed to access.

[0248] Optionally, when the time of receiving the first request message falls within the target time period, the AMF sends the first response message to the terminal device. When the time of receiving the first request message does not fall within the target time period, the AMF sends a second response message to the terminal device, where the second response message is used to indicate that the terminal device is not allowed to access the target network. The target time period includes the time during which the first service in the target network is allowed to be acquired.

[0249] For example, assuming that the time period during which the first service provided by the target network is allowed to be obtained is 10:00-20:00, then the target time period is 10:00-20:00. When the AMF receives the first request message within the target time period and the first service exists in the target network, the AMF sends the first response message to the terminal device. When the AMF receives the first request message outside the target time period, or when the first service does not exist in the target network, the AMF sends a second response message to the terminal device.

[0250] Optionally, before the AMF sends the first response message to the terminal device, the AMF sends a second request message to the SMF. The second request message is used to request establishment of a first session for the terminal device. The SMF is similar to the session management device 140 in Figure 1. For details, see the method in Figure 9.

[0251] The AMF in Figure 6 can determine whether the subscription data of the terminal device belongs to the target network based on the identification information of the terminal device, and determine whether there is an external authentication protocol between the home network of the terminal device and the target network. If the subscription data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the AMF determines the context information of the terminal device and sets the first indication information in the context information, thereby indicating that the terminal device is allowed to access the target network without authentication to obtain some services provided by the target network.

[0252] Optionally, after step S640 , the method in FIG. 7 may continue to be executed.

[0253] FIG7 is a schematic flow chart of a communication method provided in an embodiment of the present application. The method in FIG7 is applied to the communication system 100 shown in FIG1 , or to the SNPN in FIG2 or FIG3 . The UE in FIG7 is similar to the terminal device 110 in FIG1 , the RAN in FIG7 is similar to the access network device 120 in FIG1 , the AMF in FIG7 is similar to the access and mobility management device 130 in FIG1 , the SMF in FIG7 is similar to the session management device 140 in FIG1 , the UPF in FIG7 is similar to the UPF 203 in FIG2 , and the PCF in FIG7 is similar to the policy management device 150 in FIG1 . The method in FIG7 includes the following steps.

[0254] S710: Send a third request message to the AMF.

[0255] After receiving the first response message in step S640, the terminal device sends a third request message to the AMF. Correspondingly, the AMF receives the third request message. The subscription data of the terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the terminal device and the target network. The third request message is used to request the establishment of a first session for the terminal device. The first session is used for the terminal device to obtain a second service, and the second service belongs to a service that the first terminal device is allowed to obtain in the target network. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network.

[0256] Exemplarily, the first service includes at least one service, and the at least one service includes the second service.

[0257] In some embodiments, the target network is an NPN network.

[0258] In some embodiments, the terminal device sends a third request message to the RAN, and the RAN sends the third request message to the AMF.

[0259] In some embodiments, the third request message is a session establishment request message.

[0260] Exemplarily, the third request message is similar to the PDU session establishment request message in step S501.

[0261] In some embodiments, the third request message includes first indication information and / or session parameters available to the terminal device. The first indication information is used to indicate that the terminal device is accessing the target network without authentication. The session parameters available to the terminal device are used by the terminal device to request services provided by the target network.

[0262] Exemplarily, the session parameters available to the terminal device include network slice information and / or DNN information.

[0263] S721: Determine that the session parameters available to the UE correspond to the second service.

[0264] After receiving the third request message, the AMF determines, based on the session parameters available to the terminal device, whether the available session parameters correspond to the second service.

[0265] In some embodiments, the AMF obtains the session parameters available to the terminal device through the third request message. Alternatively, the AMF obtains the session parameters available to the terminal device through stored information. That is, the AMF has saved the session parameters available to the terminal device.

[0266] Optionally, the AMF determines, based on the available session parameters of the terminal device, the service corresponding to the available session parameters, and determines whether the service corresponding to the available session parameters is the second service in the target network. If the service corresponding to the available session parameters is the second service in the target network, the available session parameters of the terminal device correspond to the second service. If the service corresponding to the available session parameters is not the second service in the target network, the available session parameters of the terminal device do not correspond to the second service.

[0267] When the session parameters available to the terminal device correspond to the second service, the AMF executes step S722.

[0268] When the session parameters available to the terminal device do not correspond to the second service, the AMF sends a third response message to the terminal device, where the third response message is used to indicate that the first session is not allowed to be established for the terminal device.

[0269] In some embodiments, the AMF sends the third response message to the RAN, and the RAN sends the third response message to the terminal device.

[0270] Optionally, step S721 is optional. After the AMF completes step S721, the AMF executes step S722, and the SMF no longer executes step S723. Alternatively, if the AMF does not execute step S721, the AMF directly executes step S722, and the SMF executes step S723. In other words, both the AMF and the SMF can determine whether the session parameters available to the terminal device correspond to the second service, but only one of the AMF or the SMF is required to determine this; both the AMF and the SMF do not need to perform this determination.

[0271] S722: Send a second request message to the SMF.

[0272] The AMF sends a second request message to the SMF, and correspondingly, the SMF receives the second request message. The second request message is used to request to establish a first session for the terminal device.

[0273] In some embodiments, the second request message includes the first indication information and / or session parameters available to the terminal device.

[0274] In some embodiments, the second request message is a session establishment request message.

[0275] When the third request message includes the first indication information and / or the session parameters available to the terminal device, the AMF may directly send the third request message as the second request message to the SMF. Alternatively, the AMF may execute step S721 and then send the third request message as the second request message to the SMF.

[0276] When the third request message does not include the first indication information and / or the session parameters available for the terminal device, the AMF may directly add the first indication information and / or the session parameters available for the terminal device to the third request message to generate a second request message, thereby sending the second request message to the SMF. Alternatively, after executing step S721, the AMF may add the first indication information and / or the session parameters available for the terminal device to the third request message to generate a second request message, thereby sending the second request message to the SMF.

[0277] S723: Determine that the session parameters available to the UE correspond to the second service.

[0278] After receiving the second request message, the SMF determines whether the available session parameters correspond to the second service based on the available session parameters of the terminal device.

[0279] In some embodiments, the SMF obtains the session parameters available to the terminal device through the second request message. Alternatively, the SMF obtains the session parameters available to the terminal device through stored information. That is, the SMF has saved the session parameters available to the terminal device.

[0280] Exemplarily, the SMF pre-configures session parameters available to the first terminal device, and uses the session parameters available to the first terminal device as the session parameters available to the terminal device.

[0281] Optionally, the SMF determines, based on the available session parameters of the terminal device, a service corresponding to the available session parameters, and determines whether the service corresponding to the available session parameters is a second service in the target network. When the service corresponding to the available session parameters is the second service in the target network, the available session parameters of the terminal device correspond to the second service. When the service corresponding to the available session parameters is not the second service in the target network, the available session parameters of the terminal device do not correspond to the second service.

[0282] When the session parameters available to the terminal device correspond to the second service, the SMF executes step S740.

[0283] When the session parameters available to the terminal device do not correspond to the second service, the SMF sends a fourth response message to the terminal device, where the fourth response message is used to indicate that the first session is not allowed to be established for the terminal device.

[0284] In some embodiments, the fourth response message may further include session parameters of the service that the terminal device is allowed to obtain. For example, the fourth response message may also include session parameters corresponding to the second service.

[0285] In some embodiments, the SMF sends the fourth response message to the AMF, and the AMF sends the fourth response message to the terminal device through the RAN.

[0286] Optionally, step S723 is an optional step. If the AMF has already executed step S721, the SMF no longer executes step S723. If the AMF has not executed step S721, the SMF executes step S723.

[0287] S731: Send a fourth request message to the PCF.

[0288] When the session parameters available to the terminal device correspond to the second service, the SMF sends a fourth request message to the PCF, and correspondingly, the PCF receives the fourth request message. The fourth request message is used to request the first policy information, and the fourth request message includes the first indication information.

[0289] S732: Determine first policy information according to the first indication information.

[0290] After receiving the fourth request message, the PCF determines the first policy information based on the first indication information in the fourth request message. The first policy information is used to generate first QoS information, which is used to indicate the QoS requirement of the first session. The QoS requirement of the first session is lower than the QoS requirement corresponding to the second service obtained by the second terminal device. The subscription data of the second terminal device belongs to the target network, or an external authentication protocol exists between the home network of the second terminal device and the target network.

[0291] For example, the QoS requirement of the first session includes any one or more of a first bandwidth, a first packet loss rate, and a first latency. The first bandwidth is lower than a bandwidth corresponding to when the second terminal device obtains the second service. The first packet loss rate is higher than a packet loss rate corresponding to when the second terminal device obtains the second service. The first latency is greater than a latency corresponding to when the second terminal device obtains the second service.

[0292] In some embodiments, the PCF pre-configures the first terminal device to obtain policy information corresponding to the service in the target network, thereby determining the first policy information based on the pre-configured policy information and the first indication information.

[0293] S733: Send the first policy information to the SMF.

[0294] The PCF sends the first policy information to the SMF, and correspondingly, the SMF receives the first policy information.

[0295] S740: Establish a first session for the UE.

[0296] The SMF establishes a first session for the terminal device according to the first QoS information, where the first QoS information is generated according to the first policy information.

[0297] In some embodiments, the SMF obtains the first policy information according to steps S731 to S733. Alternatively, the SMF pre-configures the first terminal device to obtain policy information corresponding to the service in the target network, thereby determining the first policy information based on the pre-configured policy information and the first indication information. In other words, steps S731, S732, and S733 are optional and may not be performed.

[0298] Optionally, after step S740 , steps S510 to S517 in FIG. 5 may be performed.

[0299] When the contract data of the terminal device does not belong to the target network and there is no external authentication protocol between the home network of the terminal device and the target network, the method in Figure 7 allows the terminal device to access the target network without authentication and obtain some of the services provided by the target network, and can allocate lower QoS parameters to the session corresponding to the terminal device, so that the terminal device is restricted in obtaining services and occupies fewer resources.

[0300] Alternatively, after step S630, the method in FIG. 8 may continue to be executed. Alternatively, step S640 may be replaced by steps S810, S820, and S830 in FIG. 8. Alternatively, after step S740 in FIG. 7, steps S860, S870, and S880 in FIG. 8 may continue to be executed. Alternatively, after step S740 and step S510, steps S860, S870, and S880 in FIG. 8 may continue to be executed. Alternatively, after step S740, steps S510-S512 in FIG. 5, step S880 in FIG. 8, and steps S514-S517 in FIG. 5 may continue to be executed.

[0301] FIG8 is a schematic flow chart of a communication method provided in an embodiment of the present application. The method of FIG8 is applied to the communication system 100 shown in FIG1 , or to the SNPN in FIG2 or FIG3 . The UE in FIG8 is similar to the terminal device 110 in FIG1 , the RAN in FIG8 is similar to the access network device 120 in FIG1 , the AMF in FIG8 is similar to the access and mobility management device 130 in FIG1 , the UPF in FIG8 is similar to the UPF 203 in FIG2 , and the SMF in FIG8 is similar to the session management device 140 in FIG1 . The method of FIG8 includes the following steps.

[0302] S810: Send a first response message to the RAN.

[0303] If the terminal device's subscription data does not belong to the target network and there is no external authentication agreement between the terminal device's home network and the target network, the AMF sends a first response message to the RAN, and the RAN receives the first response message. The first response message and the target network are described in step S640.

[0304] S820: Save the first indication information.

[0305] Optionally, after receiving the first indication information, the RAN saves the first indication information. For the first indication information, see the description in step S630. Step S820 is an optional step, that is, step S820 may not be performed.

[0306] In some embodiments, the first response message includes the first indication information. In other words, after receiving the first response message, the RAN saves the first indication information in the first response message.

[0307] In some embodiments, the first response message does not include the first indication information. In other words, after receiving the first response message, the RAN receives the first indication information from the AMF and saves the first indication information.

[0308] S830: Send a first response message to the UE.

[0309] The RAN forwards the first response message to the UE, and correspondingly, the UE receives the first response message.

[0310] S840: Send a third request message to the AMF. The implementation of step S840 is similar to step S710 and is not repeated here.

[0311] S850: Send a second request message to the SMF. The implementation of step S850 is similar to that of step S722 and will not be repeated here.

[0312] Optionally, referring to the description of step S722 in FIG7 , step S721 may be performed before step S850 , or step S723 may be performed after step S850 .

[0313] Optionally, when the session parameters available to the terminal device correspond to the second service, the SMF, after receiving the second request message, sends an N4 session establishment request message to the UPF. This UPF is similar to UPF 203 in Figure 2. After receiving the N4 session establishment request message, the UPF sends an N4 session establishment response message to the SMF. The N4 session establishment response message includes core network tunnel information.

[0314] S860: Send a sixth response message to AMF.

[0315] When the session parameters available to the terminal device correspond to the second service, the SMF sends a sixth response message to the AMF. Correspondingly, the AMF receives the sixth response message. The sixth response message is used to indicate that the first session is allowed to be established for the terminal device. The first session is described in S710.

[0316] In some embodiments, the sixth response message is a session establishment response message. Optionally, the sixth response message includes core network tunnel information.

[0317] Exemplarily, the sixth response message is similar to the N1N2 message transmission message in step S511.

[0318] S870: Send a fifth request message to the RAN.

[0319] After receiving the sixth response message, the AMF sends a fifth request message to the RAN. Correspondingly, the RAN receives the fifth request message. The fifth request message includes information about the first session.

[0320] In some embodiments, the fifth request message is an N2 PDU session request message. The N2 PDU session request message includes N2SM information and a NAS message, wherein the NAS message includes a session identifier and an N1 SM Container.

[0321] In some embodiments, the fifth request message also includes first indication information.

[0322] S880. Allocate a first AN resource to the terminal device according to the first indication information and the information of the first session.

[0323] After receiving the fifth request message, the RAN allocates the first AN resource to the terminal device according to the first indication information and the information of the first session in the fifth request message.

[0324] In some embodiments, the first AN resources are lower than the AN resources corresponding to the second terminal device. The first AN resources include physical resources and / or logical resources corresponding to the terminal device. The subscription data of the second terminal device belongs to the target network, or an external authentication agreement exists between the home network of the second terminal device and the target network.

[0325] In some embodiments, the RAN obtains the first indication information by executing step S820. Alternatively, the RAN obtains the first indication information through the fifth request message, that is, the fifth request message includes the first indication information.

[0326] Optionally, after step S880 , steps S514 to S517 in FIG. 5 may be performed.

[0327] When the contract data of the terminal device does not belong to the target network, and there is no external authentication agreement between the terminal device's home network and the target network, the method in Figure 8 allows the terminal device to access the target network without authentication and obtain some of the services provided by the target network, and lower AN resources can be allocated to the terminal device, so that the terminal device is restricted in obtaining services and occupies fewer resources.

[0328] Optionally, after step S630 , the method in FIG. 9 may continue to be executed.

[0329] FIG9 is a schematic flow chart of a communication method provided in an embodiment of the present application. The method of FIG9 is applied to the communication system 100 shown in FIG1 , or to the SNPN in FIG2 or FIG3 . The UE in FIG9 is similar to the terminal device 110 in FIG1 , the RAN in FIG9 is similar to the access network device 120 in FIG1 , the AMF in FIG9 is similar to the access and mobility management device 130 in FIG1 , the SMF in FIG9 is similar to the session management device 140 in FIG1 , and the UPF in FIG9 is similar to the UPF 203 in FIG2 . The method of FIG9 includes the following steps.

[0330] S910: Send a second request message to the SMF.

[0331] If the AMF determines that the subscription data of the terminal device does not belong to the target network and there is no external authentication agreement between the terminal device's home network and the target network, the AMF directly sends a second request message to the SMF. Correspondingly, the SMF receives the second request message. For the target network, see the description in S610. For the second request message, see the description in step S722.

[0332] In some embodiments, the AMF does not need to perform step S721 before performing step S910. After the SMF receives the second request message, it does not need to perform step S723.

[0333] Optionally, when the first service exists in the target network, the AMF sends the second request message to the SMF. When the first service does not exist in the target network, the AMF sends a second response message to the terminal device, where the second response message is used to indicate that the terminal device is not allowed to access the target network. The first service is a service that the first terminal device is allowed to obtain. The subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network.

[0334] Optionally, when the time of receiving the first request message falls within the target time period, the AMF sends the second request message to the SMF. When the time of receiving the first request message does not fall within the target time period, the AMF sends a second response message to the terminal device, where the second response message is used to indicate that the terminal device is not allowed to access the target network. The target time period includes the time when the first service in the target network is allowed to be obtained.

[0335] For example, assuming that the time period during which the first service provided by the target network is allowed to be obtained is 10:00-20:00, then the target time period is 10:00-20:00. When the AMF receives the first request message within the target time period and the first service exists in the target network, the AMF sends the second request message to the SMF. When the AMF receives the first request message outside the target time period, or when the first service does not exist in the target network, the AMF sends a second response message to the terminal device.

[0336] Optionally, after the SMF receives the second request message, steps S731 to S732 in FIG. 7 may be executed.

[0337] S920: Establish a first session for the UE.

[0338] In some embodiments, the SMF establishes a first session for the terminal device according to the first QoS information. At this time, the specific implementation of step S920 is similar to the implementation of step S740 and will not be repeated here.

[0339] In some embodiments, the SMF establishes a first session for the terminal device based on the second QoS information. The second QoS information is used to indicate the corresponding QoS requirements when the second terminal device obtains the second service. The subscription data of the second terminal device belongs to the target network, or an external authentication protocol exists between the home network of the second terminal device and the target network.

[0340] Optionally, step S510 in FIG. 5 may be performed after step S920 .

[0341] S930: Send a sixth response message to the AMF. The specific implementation of step S930 is similar to that of step S860 and is not repeated here.

[0342] S940: Send a fifth request message to the RAN. The specific implementation of step S940 is similar to that of step S870, and will not be repeated here.

[0343] S950: Allocate a first AN resource to the terminal device according to the first indication information and the information of the first session. The specific implementation of step S950 is similar to that of step S880 and will not be repeated here. Step S950 is optional, that is, step S950 may not be performed.

[0344] Optionally, steps S514 to S517 in FIG. 5 may be performed after step S950 .

[0345] S960: Send a first response message to the UE. The specific implementation of step S960 is similar to that of step S640 and will not be repeated here.

[0346] When the terminal device's subscription data does not belong to the target network, and there is no external authentication protocol between the terminal device's home network and the target network, the method in FIG9 allows the terminal device to access the target network without authentication, obtain some of the services provided by the target network, and proactively establish a session 9 for the terminal device during the terminal device's registration process. The method in FIG9 can also assign lower QoS parameters to the session corresponding to the terminal device, or allocate lower AN resources to the terminal device, thereby limiting the terminal device's access to services and occupying fewer resources.

[0347] Figures 10 and 11 are schematic diagrams of the structures of possible communication devices provided in embodiments of the present application. These communication devices can be used to implement the functions of the terminal device, access network device, access and mobility management device, and session management device in the above-mentioned method embodiments, thereby also achieving the beneficial effects of the above-mentioned method embodiments. In the embodiments of the present application, the communication device can be the terminal device 110, access network device 120, access and mobility management device 130, session management device 140, or policy management device 150 shown in Figure 1.

[0348] As shown in Figure 10, the communication device 1000 includes a processing unit 1010 and a transceiver unit 1020. The communication device 1000 is used to implement the functions of the UE, RAN, AMF, SMF or PCF in the method embodiments shown in Figures 6 to 9 above.

[0349] When the communication device 1000 is used to implement the UE functionality in the method embodiment shown in FIG6 , the processing unit 1010 is configured to determine a first request message. The transceiver unit 1020 is configured to send the first request message to the AMF and receive a first response message from the AMF. The transceiver unit 1020 is configured to execute step S610 in FIG6 . The first request message and first response message are similar to those in FIG6 and are not further described here.

[0350] In some embodiments, when the communication device 1000 is used to implement the function of AMF in the method embodiment shown in Figure 6: the transceiver unit 1020 is used to receive a first request message. The processing unit 1010 is used to determine, based on the identification information of the terminal device, that the contract data of the terminal device does not belong to the target network, and that there is no external authentication protocol between the home network of the terminal device and the target network. The processing unit 1010 is also used to determine the context information of the terminal device. The processing unit 1010 is used to execute steps S620 and S630. The transceiver unit 1020 is also used to send a first response message to the terminal device. The transceiver unit 1020 is used to execute step S640. The target network and context information are similar to the target network and context information in Figure 6, and will not be repeated here.

[0351] In some embodiments, when the communication device 1000 is used to implement the function of the UE in the method embodiment shown in FIG. 7 : the transceiver unit 1020 is used to perform step S710 .

[0352] In some embodiments, when the communication device 1000 is used to implement the AMF function in the method embodiment shown in FIG7 : the processing unit 1010 is used to perform step S721 . The transceiver unit 1020 is used to perform step S722 .

[0353] In some embodiments, when the communication device 1000 is used to implement the SMF function in the method embodiment shown in FIG7 : the processing unit 1010 is used to execute steps S723 and S740 , and the transceiver unit 1020 is used to execute step S731 .

[0354] In some embodiments, when the communication device 1000 is used to implement the PCF function in the method embodiment shown in FIG7 : the processing unit 1010 is used to execute step S732 , and the transceiver unit 1020 is used to execute step S733 .

[0355] In some embodiments, when the communication device 1000 is used to implement the function of the UE in the method embodiment shown in FIG8 : the transceiver unit 1020 is used to perform step S840 .

[0356] In some embodiments, when the communication device 1000 is used to implement the RAN function in the method embodiment shown in FIG8 : the processing unit 1010 is used to execute steps S820 and S880 , and the transceiver unit 1020 is used to execute step S830 .

[0357] In some embodiments, when the communication device 1000 is used to implement the AMF function in the method embodiment shown in Figure 8: the transceiver unit 1020 is used to perform steps S810, S850, and S870.

[0358] In some embodiments, when the communication device 1000 is used to implement the function of the SMF in the method embodiment shown in FIG8 : the transceiver unit 1020 is used to perform step S860 .

[0359] In some embodiments, when the communication device 1000 is used to implement the RAN function in the method embodiment shown in FIG9 : the processing unit 1010 is used to execute step S950 , and the transceiver unit 1020 is used to execute step S960 .

[0360] In some embodiments, when the communication device 1000 is used to implement the AMF function in the method embodiment shown in Figure 8: the transceiver unit 1020 is used to perform steps S910 and S940.

[0361] In some embodiments, when the communication device 1000 is used to implement the SMF function in the method embodiment shown in FIG8 : the processing unit 1010 is used to execute step S920 , and the transceiver unit 1020 is used to execute step S930 .

[0362] For a more detailed description of the processing unit 1010 and the transceiver unit 1020 , reference may be made to the relevant descriptions in the method embodiments shown in FIG. 6 to FIG. 9 .

[0363] As shown in Figure 11, communication device 1100 includes a processor 1110 and an interface circuit 1120. Processor 1110 and interface circuit 1120 are coupled to each other. It will be appreciated that interface circuit 1120 may be a transceiver or an input / output interface. Optionally, communication device 1100 may further include a memory 1130 for storing instructions executed by processor 1110, input data required by processor 1110 to execute instructions, or data generated by processor 1110 after executing instructions.

[0364] When the communication device 1100 is used to implement the methods shown in FIG. 6 to FIG. 9 , the processor 1110 is used to implement the functions of the processing unit 1010 , and the interface circuit 1120 is used to implement the functions of the transceiver unit 1020 .

[0365] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0366] The steps of the method disclosed in the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.

[0367] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0368] According to the method provided in the embodiments of the present application, the present application also provides a computer program product, which includes: computer program code, which, when the computer program code runs on a computer, enables the computer to execute the various steps or processes executed by the terminal device, session management device, access and mobility management device or access network device in the embodiments shown in Figures 6 to 9.

[0369] According to the method provided in the embodiments of the present application, the present application also provides a computer-readable storage medium, which stores program code. When the program code runs on a computer, the computer executes the various steps or processes performed by the terminal device, session management device, access and mobility management device or access network device in the embodiments shown in Figures 6 to 9.

[0370] According to the method provided in the embodiment of the present application, the present application also provides a communication system, which includes the aforementioned terminal device, access network device, access and mobility management device and session management device.

[0371] According to the method provided in the embodiments of the present application, the present application also provides a chip, comprising at least one processor. The at least one processor is configured to execute program instructions. When the program instructions are executed by the at least one processor, the chip executes the steps or processes performed by the terminal device, session management device, access and mobility management device, or access network device in the embodiments shown in Figures 6 to 9.

[0372] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a high-density digital video disc (DVD)), or a semiconductor medium (eg, a solid state disc (SSD)).

[0373] The devices in the above-mentioned apparatus embodiments correspond completely to the devices in the method embodiments, and the corresponding modules or units perform the corresponding steps. For example, the transceiver unit (transceiver) performs the receiving or sending steps in the method embodiments, and the other steps except sending and receiving can be performed by the processing unit (processor). The functions of the specific units can be referred to the corresponding method embodiments. There can be one or more processors.

[0374] As used in this specification, the terms "component," "module," "system," and the like are used to represent computer-related entities, hardware, firmware, a combination of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a computing device and a computing device can be a component. One or more components can reside in a process and / or an execution thread, and a component can be located on one computer and / or distributed between two or more computers. In addition, these components can be executed from various computer-readable storage media having various data structures stored thereon. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component between a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).

[0375] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0376] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0377] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0378] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0379] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0380] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0381] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A communication method, characterized in that: The method is performed by an access and mobility management device, and the method includes: receiving a first request message from a terminal device, where the first request message includes identification information of the terminal device, and the first request message is used to request the terminal device to access a target network; Determining, based on the identification information of the terminal device, that the subscription data of the terminal device does not belong to the target network, and that there is no external authentication protocol between the home network of the terminal device and the target network; Determine context information of the terminal device, where the context information includes first indication information, and the first indication information is used to indicate that the terminal device accesses the target network without authentication; A first response message is sent to the terminal device, where the first response message is used to indicate that the terminal device is allowed to access the target network.

2. The method according to claim 1, characterized in that The sending a first response message to the terminal device includes: When there is a first service in the target network, sending the first response message, the first service is a service that the first terminal device is allowed to obtain, the subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network; or, When the first service does not exist in the target network, a second response message is sent, where the second response message is used to indicate that the terminal device is not allowed to access the target network.

3. The method according to claim 1 or 2, characterized in that: The sending a first response message to the terminal device includes: sending the first response message when the time of receiving the first request message belongs to a target time period, the target time period includes a time when a first service in the target network is allowed to be obtained, the first service is a service that a first terminal device is allowed to obtain, the subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network; or, When the time of receiving the first request message does not belong to the target time period, a second response message is sent, where the second response message is used to indicate that the terminal device is not allowed to access the target network.

4. The method according to any one of claims 1 to 3, characterized in that The first response message also includes session parameters available to the terminal device and / or the first indication information, where the session parameters are used by the terminal device to request the service provided by the target network.

5. The method according to any one of claims 1 to 4, characterized in that The method further comprises: A second request message is sent to the session management device, where the second request message is used to request to establish a first session for the terminal device, where the first session is used for the terminal device to obtain a second service, where the second service belongs to a service that the first terminal device is allowed to obtain in the target network, where the second request message includes the first indication information, the contract data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network.

6. The method according to claim 5, characterized in that The sending a second request message to the session management device includes: receiving a third request message, where the third request message is used to request to establish a first session for the terminal device; When the session parameters available to the terminal device correspond to the second service, sending the second request message to the session management device, wherein the session parameters are used by the terminal device to request to obtain the service provided by the target network; When the session parameters available to the terminal device do not correspond to the second service, a third response message is sent to the terminal device, where the third response message is used to indicate that establishment of the first session for the terminal device is not allowed.

7. The method according to claim 6, characterized in that The second request message also includes session parameters available to the terminal device, and / or the third request message includes the first indication information and / or session parameters available to the terminal device.

8. A communication method, characterized in that: The method is performed by a session management device, and the method includes: receiving a second request message from an access and mobility management device, where the second request message is used to request to establish a first session for a terminal device, where the first session is used for the terminal device to obtain a second service, where the second service belongs to a service that the first terminal device is allowed to obtain in a target network, and the second request message includes first indication information, where the first indication information is used to indicate that the terminal device accesses the target network without authentication, that subscription data of the terminal device and the first terminal device do not belong to the target network, and that there is no external authentication protocol between the home network of the terminal device and the first terminal device and the target network; Establish the first session for the terminal device according to the second request message.

9. The method according to claim 8, characterized in that The second request message also includes session parameters available to the terminal device, where the session parameters are used by the terminal device to request the service provided by the target network.

10. The method according to claim 9, characterized in that The establishing the first session for the terminal device according to the second request message includes: When the session parameters available to the terminal device correspond to the second service, establishing the first session for the terminal device; When the session parameters available to the terminal device do not correspond to the second service, a fourth response message is sent, where the fourth response message is used to indicate that establishment of the first session for the terminal device is not allowed.

11. The method according to any one of claims 8 to 10, characterized in that The establishing the first session for the terminal device includes: The first session is established for the terminal device according to the first quality of service QoS information, the first QoS information is used to indicate the QoS requirement of the first session, the QoS requirement of the first session is lower than the QoS requirement corresponding to the second service obtained by the second terminal device, the contract data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

12. The method according to claim 11, characterized in that The method further comprises: Sending a fourth request message to the policy management device, where the fourth request message is used to request the first policy information, and the fourth request message includes the first indication information; The first policy information is received from the policy management device, where the first policy information is used to generate the first QoS information.

13. A communication method, characterized in that: The method is performed by an access network device, and the method includes: Sending a first request message to an access and mobility management device, where the first request message includes identification information of a terminal device, and the first request message is used to request the terminal device to access a target network; Receive a first response message from the access and mobility management device, wherein the first response message is used to indicate that the terminal device is allowed to access the target network, the subscription data of the terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the terminal device and the target network.

14. The method according to claim 13, characterized in that The method further comprises: receiving a fifth request message from the access and mobility management device, the fifth request message including information of a first session, the first session being used by the terminal device to obtain a second service, the second service belonging to a service that the first terminal device is allowed to obtain in the target network, the subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network; According to the first indication information and the information of the first session, a first access network AN resource is allocated to the terminal device, the first AN resource is lower than the AN resource corresponding to the second terminal device, the first AN resource includes the physical resources and / or logical resources corresponding to the terminal device, the contract data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

15. The method according to claim 14, characterized in that The fifth request message also includes the first indication information.

16. The method according to any one of claims 13 to 15, characterized in that The first response message includes first indication information and / or session parameters available to the terminal device, the first indication information is used to indicate that the terminal device accesses the target network without authentication, and the session parameters are used by the terminal device to request the service provided by the target network.

17. The method according to any one of claims 13 to 16, characterized in that The method further comprises: Sending first indication information and / or session parameters available to the terminal device to the terminal device, wherein the session parameters are used by the terminal device to request the service provided by the target network.

18. A communication method, characterized in that: The method is performed by a terminal device, and the method includes: Sending a first request message to an access network device, where the first request message includes identification information of the terminal device, and the first request message is used to request the terminal device to access a target network; Receive a first response message from the access network device, where the first response message is used to indicate that the terminal device is allowed to access the target network, the contract data of the terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the terminal device and the target network.

19. The method according to claim 18, characterized in that The method further comprises: Send a third request message to the access network device, the third request message is used to request to establish a first session for the terminal device, the first session is used for the terminal device to obtain a second service, the second service belongs to the target network in which the first terminal device is allowed The acquired service, the subscription data of the first terminal device does not belong to the target network, and there is no external authentication protocol between the home network of the first terminal device and the target network, and the third request message includes first indication information.

20. The method according to claim 19, characterized in that The method further comprises: The second service is obtained through the first session, the service quality QoS requirement of the first session is lower than the QoS requirement corresponding to the second terminal device obtaining the second service, the contract data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

21. The method according to claim 19 or 20, characterized in that The method further comprises: Data is transmitted to the access network device through the first access network AN resources, the first AN resources are lower than the AN resources corresponding to the second terminal device, the first AN resources include physical resources and / or logical resources corresponding to the terminal device, the contract data of the second terminal device belongs to the target network, or there is an external authentication protocol between the home network of the second terminal device and the target network.

22. The method according to any one of claims 18 to 21, characterized in that The first response message includes first indication information and / or session parameters available to the terminal device, the first indication information is used to indicate that the terminal device accesses the target network without authentication, and the session parameters are used by the terminal device to request the service provided by the target network.

23. A communication device, characterized in that: Comprising means for performing the method as claimed in any one of claims 1 to 22.

24. A communication device, characterized in that: The communication device comprises: at least one processor and a communication interface, wherein the communication interface is used for the communication device to exchange information with other communication devices, and when program instructions are executed in the at least one processor, the communication device executes the method as described in any one of claims 1 to 7.

25. A communication device, characterized in that: The communication device comprises: at least one processor and a communication interface, wherein the communication interface is used for the communication device to exchange information with other communication devices, and when the program instructions are executed in the at least one processor, the communication device executes the method as described in any one of claims 8 to 12.

26. A communication device, characterized in that: The communication device comprises: at least one processor and a communication interface, wherein the communication interface is used for the communication device to exchange information with other communication devices, and when the program instructions are executed in the at least one processor, the communication device executes the method as described in any one of claims 13 to 17.

27. A communication device, characterized in that: The communication device comprises: at least one processor and a communication interface, wherein the communication interface is used for the communication device to exchange information with other communication devices, and when the program instructions are executed in the at least one processor, the communication device executes the method as described in any one of claims 18 to 22.

28. A communication system, characterized in that: The communication system includes the communication device according to claim 24, the communication device according to claim 25, the communication device according to claim 26, and the communication device according to claim 27.

29. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a program code for execution by a device, and when the program code is executed, the method according to any one of claims 1 to 22 is performed.

30. A chip, characterized in that: The chip includes at least one processor, and when program instructions are executed by the at least one processor, the method according to any one of claims 1 to 22 is executed.

Citation Information

Patent Citations

  • Communication method and related equipment

    CN120201519A

  • Communication method and communication device

    CN113630843A

  • Network registration method and device and readable storage medium

    CN117221868A

  • Communication method, terminal device, and radio access network device

    WO2022001964A1

  • Method for selecting SNPN, terminal, apparatus, and storage medium

    WO2023066074A1