Access control method, and cloud terminal, communication system and storage medium
By acquiring card data from cloud terminals within the operator's trusted security domain, activating user instances and interacting with non-3GPP access gateways, the problem of user equipment lacking non-3GPP access is solved, and effective non-3GPP access and service tunnel establishment is achieved to meet user needs.
Patent Information
- Application Number
- PCT/CN2024/117092
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-16
- Filing Date
- 2024-09-05
- Publication Date
- 2025-07-24
AI Technical Summary
In the existing communication systems, user equipment lacks non-3GPP access functions, resulting in the inability to realize non-3GPP access through the application layer simulation terminal module, and card data is not appropriate to be transmitted in the public network, affecting network registration and session establishment.
Set up a cloud terminal in the operator's trusted security domain, obtain card data through the cloud terminal, activate user instances and interact with non-3GPP access gateways, simulate non-3GPP access of terminal modules, and realize U2N communication.
In the case where the terminal lacks non-3GPP access capabilities, effective non-3GPP access is achieved. The user equipment and the core network signaling interaction are carried out through cloud terminal agents, and the service tunnel is established between the user equipment and the non-3GPP access gateway to meet the user's business needs.
Smart Images

Figure CN2024117092_24072025_PF_FP_ABST
Abstract
Description
Access control method, cloud terminal, communication system and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] The present disclosure is based on and claims priority to an application with CN application number 202410063446.2 and filing date January 16, 2024. The disclosure content of the CN application is hereby incorporated into the present disclosure as a whole. Technical Field
[0003] The present disclosure relates to the field of communications, and in particular to an access control method, a cloud terminal, a communication system, and a storage medium. Background Art
[0004] Near-area U2N (UE to Network) communication corresponds to the 3GPP (3rd Generation Partnership Project) ProSe (Proximity Service) standardization project. Support for this function requires the support of the network and terminal modules.
[0005] Summary of the Invention
[0006] In a first aspect of the present disclosure, an access control method is provided, which is executed by a cloud terminal, comprising: reading card data of an identity card corresponding to an identifier of the user device according to an access request sent by the user device; activating a cloud user instance corresponding to the user device, wherein the user instance has a mapping relationship with the card data and access network AN parameters; selecting a non-3GPP access gateway; and triggering the user instance to interact with the non-3GPP access gateway according to a registration request sent by the user device to select an access and mobility management function entity.
[0007] In some embodiments, after selecting the access and mobility management function entity, the user instance is triggered to act as a user equipment agent to perform network registration through the non-3GPP access gateway and the access and mobility management function entity; if the network registration is successful, the user instance is triggered to send a registration success message to the user equipment so that the user equipment establishes a communication connection with the non-3GPP access gateway and accesses the core network through the communication connection.
[0008] In some embodiments, triggering the user instance to perform network registration through the non-3GPP access gateway and the access and mobility management function entity includes: triggering the user instance to complete non-access layer NAS registration of non-3GPP access through the non-3GPP access gateway and the access and mobility management function entity, and establishing an Internet Security Protocol IPSec signaling security association SA between the user instance and the non-3GPP access gateway.
[0009] In some embodiments, triggering the user instance to complete NAS registration of non-3GPP access through the non-3GPP access gateway and the access and mobility management function entity includes: triggering the user instance to send the identification information in the card data to the access and mobility management function entity through the non-3GPP access gateway according to a query request sent by the access and mobility management function entity through the non-3GPP access gateway, wherein the access and mobility management function entity sends the query request after receiving the registration request message sent by the non-3GPP access gateway; triggering the user instance to interact with the non-3GPP access gateway, the access and mobility management function entity and the authentication server function authentication server function entity to authenticate the user instance; triggering the user instance to authenticate the NAS security mode command message sent by the access and mobility management function entity through the non-3GPP access gateway; triggering the user instance to send the EAP success message sent by the non-3GPP access gateway to the user equipment to indicate that the EAP-5G session is completed; triggering the user instance to establish the IPSec signaling SA with the non-3GPP access gateway.
[0010] In some embodiments, the identification information in the card data includes a hidden user identifier (SUCI) or a permanent user identifier (SUPI).
[0011] In some embodiments, triggering the user instance to interact with the non-3GPP access gateway includes: triggering the user instance to perform an Internet Key Exchange (IKE) initial exchange with the non-3GPP access gateway; triggering the user instance to send an IKE authentication message to the non-3GPP access gateway for initiating an IKE authentication exchange; triggering the user instance to initiate an Extended Authentication Protocol (EAP)-5G session based on the IKE authentication response sent by the non-3GPP access gateway; triggering the user instance to send an IKE authentication request to the non-3GPP access gateway, wherein the IKE authentication request includes the AN parameters, so that the non-3GPP access gateway selects the access and mobility management function entity based on the AN parameters and local policies.
[0012] In some embodiments, the registration success message includes a non-3GPP access gateway IP address and a non-3GPP access gateway key, which is used to trigger the user device to establish one or more session sub-SAs between the user device and the non-3GPP access gateway, and to direct traffic to the corresponding session sub-SA when accessing the service.
[0013] In some embodiments, the non-3GPP access gateway is a non-3GPP access gateway corresponding to the current location of the user equipment.
[0014] In some embodiments, the non-3GPP access gateway includes a non-3GPP network interconnection function N3IWF entity.
[0015] In some embodiments, based on the service request sent by the user equipment, the user instance is triggered to execute the protocol data unit PDU session establishment process by interacting with the non-3GPP access gateway, the access and mobility management function entity and the user equipment; the PDU session establishment completion message sent by the non-3GPP access gateway is forwarded to the user equipment; the PDU session establishment success message sent by the access and mobility management function entity through the non-3GPP access gateway is forwarded to the user equipment, so that the user equipment can divert the service traffic to the corresponding session sub-SA according to the service scheduling policy.
[0016] In some embodiments, triggering the user instance to execute the PDU session establishment process includes: triggering the user instance to send a PDU session establishment request to the access and mobility management function entity through the non-3GPP access gateway, so that the access and mobility management function entity interacts with the core network network element to establish an initial session on the core network side; forwarding the IKE creation sub-SA request sent by the non-3GPP access gateway to the user equipment, and forwarding the IKE creation sub-SA response sent by the user equipment to the non-3GPP access gateway, so as to establish one or more IPSec sub-SAs for the PDU session between the user equipment and the non-3GPP access gateway.
[0017] In some embodiments, the access and mobility management function entity interacts with the core network network element to complete the session establishment on the core network side based on the N2 PDU session response sent by the non-3GPP access gateway, and sends the PDU session establishment success message to the user instance through the non-3GPP access gateway.
[0018] In a second aspect of the present disclosure, a cloud terminal is provided, comprising: a memory; and a processor coupled to the memory, wherein the processor is configured to execute the method described in any of the above embodiments based on instructions stored in the memory.
[0019] In a third aspect of the present disclosure, a communication system is provided, comprising: a cloud terminal as described in any of the above embodiments; a user device, configured to send an access request to the cloud terminal, establish a communication connection with a non-3GPP access gateway selected by the user instance based on a registration success message sent by the user instance in the cloud terminal, and access a core network through the communication connection; the non-3GPP access gateway, configured to interact with the user instance to select an access and mobility management function entity; and the access and mobility management function entity, configured to interact with the user instance, the non-3GPP access gateway, and the core network to complete network registration of the user instance.
[0020] In some embodiments, the non-3GPP access gateway is configured to establish an IPSec signaling SA between the user instance and the non-3GPP access gateway when the user instance completes NAS registration through the non-3GPP access gateway and the access and mobility management function entity.
[0021] In some embodiments, the non-3GPP access gateway is configured to send a registration request message to the access and mobility management function entity, and according to the initialization context establishment request sent by the access and mobility management function entity, send an EAP success message to the user equipment through the user instance, and establish the IPSec signaling SA with the user instance; the access and mobility management function entity is configured to send a query request to the user instance through the non-3GPP access gateway according to the registration request message to obtain identification information in the card data corresponding to the user instance, interact with the non-3GPP access gateway, the user instance and the authentication server function entity to authenticate the user instance, send a NAS security mode command to the user instance through the non-3GPP access gateway if the authentication is successful, and send the initialization context establishment request to the non-3GPP access gateway according to the NAS security mode completion message sent by the user instance.
[0022] In some embodiments, the non-3GPP access gateway is further configured to allocate an IPSec tunnel endpoint address on the user equipment side during the process of establishing the IPSec signaling SA with the user instance.
[0023] In some embodiments, the identification information in the card data includes a hidden user identifier (SUCI) or a permanent user identifier (SUPI).
[0024] In some embodiments, the non-3GPP access gateway is configured to perform an IKE initial exchange with the user instance, and send an IKE authentication response to the user instance based on the IKE authentication message sent by the user instance, so as to trigger the user instance to initiate an EAP-5G session, and upon receiving the IKE authentication request sent by the user instance, select the access and mobility management function entity based on the AN parameters and local policy included in the IKE authentication request.
[0025] In some embodiments, the user equipment is configured to establish one or more session sub-SAs between the user equipment and the non-3GPP access gateway according to the registration success message, and to direct traffic to corresponding session sub-SAs when accessing services.
[0026] In some embodiments, the non-3GPP access gateway is a non-3GPP access gateway corresponding to the current location of the user equipment.
[0027] In some embodiments, the user device is configured to send a service request to the user instance, receive a PDU session establishment completion message sent by the non-3GPP access gateway through the user instance, receive a PDU session establishment success message sent by the access and mobility management function entity through the user instance, and direct the service traffic to the corresponding session sub-SA according to the service scheduling policy.
[0028] In some embodiments, the access and mobility management function entity is configured to interact with the core network network element to establish an initial session on the core network side based on the PDU session establishment request sent by the user instance through the non-3GPP access gateway, and send the N2 PDU session request to the non-3GPP access gateway; the non-3GPP access gateway is configured to determine the number of IPSec sub-SAs based on local policies and a predetermined QoS profile, and for each IPSec sub-SA, send an IKE create sub-SA request to the user equipment through the user instance, and establish the IPSec sub-SA of the PDU session based on the IKE create sub-SA response sent by the user equipment through the user instance.
[0029] In some embodiments, the non-3GPP access gateway is configured to reallocate the tunnel endpoint IP address on the user equipment side when establishing the first IPSec sub-SA of the PDU session.
[0030] In some embodiments, the access and mobility management function entity is configured to interact with the core network network element to complete the session establishment on the core network side based on the N2 PDU session response sent by the non-3GPP access gateway, and send the PDU session establishment success message to the user equipment through the non-3GPP access gateway and the user instance.
[0031] According to a fourth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and when the instructions are executed by a processor, the method described in any of the above embodiments is implemented.
[0032] According to a fifth aspect of an embodiment of the present disclosure, a computer program is provided, comprising computer instructions, wherein when the computer instructions are executed by a processor, the method described in any of the above embodiments is implemented.
[0033] Other features and advantages of the present disclosure will become apparent from the following detailed description of exemplary embodiments of the present disclosure with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0035] FIG1 is a schematic structural diagram of a communication system according to an embodiment of the present disclosure;
[0036] FIG2 is a schematic structural diagram of a communication system according to another embodiment of the present disclosure;
[0037] FIG3 is a schematic flow chart of an access control method according to an embodiment of the present disclosure;
[0038] FIG4 is a schematic flow chart of an access control method according to another embodiment of the present disclosure;
[0039] FIG5 is a schematic diagram of the structure of a cloud terminal according to an embodiment of the present disclosure;
[0040] FIG6 is a schematic structural diagram of a communication system according to an embodiment of the present disclosure;
[0041] FIG7 is a schematic flow chart of an access control method according to another embodiment of the present disclosure;
[0042] FIG8 is a schematic flow chart of an access control method according to another embodiment of the present disclosure;
[0043] FIG9 is a flowchart of an access control method according to another embodiment of the present disclosure. DETAILED DESCRIPTION
[0044] The following will be combined with the drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all the embodiments. The following description of at least one exemplary embodiment is actually only illustrative and is in no way intended to limit the present disclosure and its application or use. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present disclosure.
[0045] Unless specifically stated otherwise, the relative arrangement of components and steps, the numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present disclosure.
[0046] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship.
[0047] Technologies, methods and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, such technologies, methods and equipment should be considered part of the authorization specification.
[0048] In all examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not limiting. Therefore, other examples of the exemplary embodiments may have different values.
[0049] It should be noted that like reference numerals and letters refer to like items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0050] The inventors note that among ProSe solutions, the least impactful on the network is the Layer 3 (Layer 3) non-3GPP access solution, which is limited by terminal functionality. Operators attempt to simulate the implementation of the terminal module's non-3GPP access functionality through an app. However, because the user device's application layer cannot access card data, and card data is not suitable for transmission over public networks, simulating the terminal module's non-3GPP access functionality through an app is impossible.
[0051] In the existing communication system, as shown in Figure 1, there can be multiple hops between the remote UE and the first-level relay UE. The remote UE and the relay UE rely on the communication module of the terminal (i.e., user equipment) to implement the non-3GPP registration and session establishment process of the network to ensure that they exist with independent identities in the network. In Figure 1, the module supports the signaling interaction related to the network behavior (such as registration, session establishment, etc.) of the terminal non-3GPP access through NAS (Non-Access Stratum) signaling, and supports the establishment of sessions and the routing of traffic in accordance with the URSP (UE Route Selection Policy) rules. Since the vast majority of terminals (modules) currently do not support the non-3GPP access function, the communication system shown in Figure 1 cannot be implemented.
[0052] The relevant devices and interfaces in Figure 1 are as follows:
[0053] UE (User Equipment) is an access terminal of a mobile network and an object for implementing mobility management and session management in the mobile network.
[0054] Remote UE: In a terminal-to-network near-area relay network, a terminal located at the end that accesses the Internet through a relay UE.
[0055] Relay UE: In the terminal-to-network near-area relay networking, a UE that directly connects to the mobile network and provides a relay Internet access channel for downstream UEs. Among them, L3 relay UE refers to a UE whose relay function is located at L3 of the protocol stack (such as the IP layer).
[0056] Level 1 relay UE: A UE that directly connects to the mobile network and provides Internet access for downstream UEs.
[0057] UPF (User Plane Function): A network function in the 5G core network that executes user plane policies and forwards user data.
[0058] NG-RAN (Next Generation-Radio Access Network): usually refers to the base station of a 5G network.
[0059] N3IWF (Non-3GPP InterWorking Function): An access point for non-3GPP access to a mobile network, providing base station-like functionality.
[0060] Cloud Terminal: Executes signaling interactions related to user device network behavior (e.g., registration, session establishment, etc.) through the NAS signaling proxy, and supports passing IPSec (Internet Protocol Security) channel information to the user device's ProSe APP to establish an IPSec (sub)SA (Security Association) between the terminal and the N3IWF.
[0061] Cloud Terminal Client (ProSe APP): This is the client corresponding to the cloud terminal installed on the user's device. It receives channel information and traffic rules from the cloud terminal, establishes an IPSec channel with the N3IWF, and calls different tunnel interfaces according to the traffic rules. For example, there are various implementation methods for the APP: application-layer software, module implementation, or implementation at the non-module level of the terminal (such as the operating system).
[0062] NWu interface: The interface between the cloud terminal and the N3IWF, used to establish a secure tunnel so that the control plane and user plane can interact securely between the cloud terminal user instance and the 5G core network.
[0063] URSP: This policy describes the mapping between terminal applications, terminal behaviors using the applications, and network parameters.
[0064] The present disclosure provides an access control solution, which sets up a cloud terminal in the operator's trusted security domain and uses the cloud terminal to obtain corresponding card data, thereby realizing the non-3GPP access function of the APP simulation terminal module without transmitting the card data in the public network.
[0065] For example, as shown in Figure 2, a cloud terminal is set up within the operator's trusted security domain. This cloud terminal can directly obtain card data from the operations backend. A ProSe app is installed or activated on the user device. Remote UEs and primary relay UEs interact with the cloud terminal through the ProSe app. The cloud terminal supports ProSe-based U2N communication functions by simulating non-3GPP access to the terminal module at the application layer.
[0066] It should be noted that the app's identity corresponds to the card data bound to the user instance in the cloud terminal. When the app is implemented at the application layer and the UE's login phone number is not the local number (this situation may occur with any login method other than one-click login), the card data may not be the card data corresponding to the local terminal module. Whether this situation is allowed depends on the operator's operating policy.
[0067] Figure 3 is a flow chart of an access control method according to an embodiment of the present disclosure. In some embodiments, the following access control method is executed by a cloud terminal.
[0068] In step 301, according to an access request sent by a user device, card data of an identity card corresponding to an identification of the user device is read.
[0069] In step 302, a cloud user instance corresponding to the user device is activated, wherein the user instance has a mapping relationship with the card data and AN (Access Network) parameters.
[0070] In some embodiments, the AN parameters may be obtained from card data, pre-configured, or mapped from card data. For example, the AN parameters include GUAMI (Globally Unique AMF Identifier), PLMN ID (Public Land Mobile Network Identifier), etc.
[0071] In step 303, a non-3GPP access gateway is selected.
[0072] For example, the non-3GPP access gateway includes an N3IWF entity.
[0073] In some embodiments, the selected non-3GPP access gateway is a non-3GPP access gateway corresponding to the current location of the user equipment.
[0074] In step 304, according to the registration request sent by the user equipment, the user instance is triggered to interact with the non-3GPP access gateway to select an access and mobility management function entity.
[0075] In some embodiments, the registration request includes a user equipment identifier (UE APP ID) for network registration operations of the user instance.
[0076] In some embodiments, triggering interaction between a user instance and a non-3GPP access gateway includes the following steps:
[0077] 1) Triggering the user instance to perform an IKE (Internet Key Exchange) initial exchange (IKE_SA_INIT) with the non-3GPP access gateway.
[0078] 2) Trigger the user instance to send an IKE authentication message (IKE_AUTH Req(UE ID, without AUTH)) to the non-3GPP access gateway to initiate an IKE authentication exchange, where UE ID is the user network identifier in the user instance, which can be SUPI (Subscription Permanent Identifier) or SUCI (Subscription Concealed Identifier). UE ID can be equivalent to UE APP ID, or have a one-to-one correspondence.
[0079] 3) Based on the IKE authentication response (IKE_AUTH Res(EAP-Req / 5G-Start)) sent by the non-3GPP access gateway, the user instance is triggered to initiate an EAP (Extensible Authentication Protocol)-5G session.
[0080] 4) Trigger the user instance to send an IKE authentication request (IKE_AUTH Req(EAP-Res / 5G-NAS / AN-Params,NAS-PDU[Registration Request])) to the non-3GPP access gateway. The IKE authentication request includes AN parameters, allowing the non-3GPP access gateway to select an access and mobility management function entity based on the AN parameters and local policies. In addition, the IKE authentication request also includes a registration request for subsequent registration procedures.
[0081] In step 305, the user instance is triggered to act as a user equipment agent and perform network registration through a non-3GPP access gateway and an access and mobility management function entity.
[0082] In some embodiments, the user instance is triggered to complete NAS registration of non-3GPP access through the non-3GPP access gateway and the access and mobility management function entity, and an IPSec signaling SA is established between the user instance and the non-3GPP access gateway.
[0083] In some embodiments, triggering a user instance to complete NAS registration through a non-3GPP access gateway and an access and mobility management function entity comprises the following steps:
[0084] 1) According to the query request sent by the access and mobility management function entity through the non-3GPP access gateway, the user instance is triggered to send the identification information in the card data to the access and mobility management function entity through the non-3GPP access gateway.
[0085] It should be noted here that the access and mobility management function entity sends a query request upon receiving a registration request message sent by a non-3GPP access gateway.
[0086] In some embodiments, the identification information in the card data includes SUCI or SUPI.
[0087] 2) Triggering the user instance to interact with the non-3GPP access gateway, the access and mobility management function entity, and the authentication server function entity to authenticate the user instance.
[0088] 3) Triggering the user instance to authenticate the NAS Security Mode Command message sent by the access and mobility management function entity through the non-3GPP access gateway.
[0089] It should be noted here that, in the case of authenticating the user instance, the access and mobility management function entity sends a NAS security mode command message to the non-3GPP access gateway.
[0090] 4) Trigger the user instance to send the EAP success message sent by the non-3GPP access gateway to the user equipment to indicate that the EAP-5G session is completed.
[0091] It should be noted here that, when the NAS security mode command is authenticated successfully, the access and mobility management function entity sends an initialization context establishment request to the non-3GPP access gateway so that the non-3GPP access gateway sends an EAP success message.
[0092] 5) Trigger the user instance to establish an IPSec signaling SA with the non-3GPP access gateway.
[0093] It should be noted here that, in the process of establishing the IPSec signaling SA, an IPSec tunnel endpoint address on the user equipment side is allocated, and this address is an inner IP address.
[0094] In step 306, if the network registration is successful, the user instance is triggered to send a registration success message to the user equipment, so that the user equipment establishes a communication connection with the non-3GPP access gateway and accesses the core network through the communication connection.
[0095] In some embodiments, the registration success message includes the non-3GPP access gateway IP address and the non-3GPP access gateway key, which is used to trigger the user device to establish one or more session sub-SAs between the user device and the non-3GPP access gateway, and to direct traffic to the corresponding session sub-SA when accessing the service, that is, the IPSec tunnel corresponding to the sub-SA.
[0096] Figure 4 is a flow chart of an access control method according to another embodiment of the present disclosure. In some embodiments, the following access control method is executed by a cloud terminal.
[0097] It should be noted here that before executing the following steps, the user instance in the cloud terminal has already established an IPSec signaling SA with the non-3GPP access gateway during the registration process.
[0098] In step 401, according to the service request sent by the user equipment, the user instance is triggered to perform a PDU (Protocol Data Unit) session establishment process by interacting with the non-3GPP access gateway, the access and mobility management function entity and the user equipment.
[0099] In some embodiments, triggering a user instance to execute a PDU session establishment process includes the following steps:
[0100] 1) The triggering user instance sends a PDU session establishment request to the access and mobility management function entity through the non-3GPP access gateway, so that the access and mobility management function entity interacts with the core network element to establish an initial session on the core network side.
[0101] It should be noted that the access and mobility management function interacts with the core network element to establish the initial session on the core network side and sends the N2 PDU session request to the non-3GPP access gateway. The non-3GPP access gateway determines the number of IPSec child SAs based on local policies and a predefined QoS profile and sends an IKE Create Child SA Request (IKE_Create_Child SA Req) to the user equipment for each IPSec child SA via a user instance.
[0102] 2) Forward the IKE create child SA request sent by the non-3GPP access gateway to the user equipment, and forward the IKE create child SA response (IKE_Create_Child SA Res) sent by the user equipment to the non-3GPP access gateway, so as to establish one or more IPSec child SAs for the PDU session between the user equipment and the non-3GPP access gateway.
[0103] It should be noted that when the non-3GPP access gateway establishes the first IPSec sub-SA of a PDU session, it reallocates the tunnel endpoint IP address (i.e., the inner IP address) on the user equipment side. However, for other IPSec sub-SAs, it does not need to reallocate the tunnel endpoint IP address on the user equipment side.
[0104] In step 402, the PDU session establishment completion message sent by the non-3GPP access gateway is forwarded to the user equipment.
[0105] It should be noted here that after the PDU session establishment process is completed, the non-3GPP access gateway sends a PDU session establishment completion message to the user equipment through the user instance.
[0106] In step 403, the PDU session establishment success message sent by the access and mobility management function entity through the non-3GPP access gateway is forwarded to the user equipment, so that the user equipment can guide the service traffic to the corresponding session sub-SA according to the service scheduling policy.
[0107] It should be noted here that after the PDU session establishment process is completed, the non-3GPP access gateway also sends an N2 PDU session response to the access and mobility management function entity. The access and mobility management function entity interacts with the core network element to complete the session establishment on the core network side, and then sends a PDU session establishment success message to the user equipment through the non-3GPP access gateway and the user instance.
[0108] FIG5 is a schematic diagram of the structure of a cloud terminal according to an embodiment of the present disclosure. As shown in FIG5 , the cloud terminal includes a memory 51 and a processor 52 .
[0109] The memory 51 is used to store instructions. The processor 32 is coupled to the memory 51 . The processor 52 is configured to execute the method involved in any embodiment of FIG. 3 or FIG. 4 based on the instructions stored in the memory.
[0110] As shown in Figure 5, the cloud terminal also includes a communication interface 53 for exchanging information with other devices. At the same time, the cloud terminal also includes a bus 54 through which the processor 52, the communication interface 53, and the memory 51 communicate with each other.
[0111] The memory 51 may include high-speed RAM memory or non-volatile memory, such as at least one disk storage device. The memory 51 may also be a memory array. The memory 51 may also be divided into blocks, and the blocks may be combined into virtual volumes according to certain rules.
[0112] Furthermore, the processor 52 may be a central processing unit (CPU), or may be an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the present disclosure.
[0113] The present disclosure also relates to a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and when the instructions are executed by a processor, the method involved in any one of the embodiments in FIG. 3 or FIG. 4 is implemented.
[0114] Figure 6 is a schematic diagram of the structure of a communication system according to an embodiment of the present disclosure. As shown in Figure 6, the communication system includes a user equipment 61, a cloud terminal 62, a non-3GPP access gateway 63, and an access and mobility management function entity 64. The cloud terminal 62 is the cloud terminal involved in any of the embodiments in Figure 5.
[0115] The user equipment 61 is configured to send an access request to the cloud terminal 62, establish a communication connection with the non-3GPP access gateway 63 selected by the user instance 621 according to the registration success message sent by the user instance 621 in the cloud terminal 62, and access the core network through the communication connection.
[0116] The non-3GPP access gateway 63 is configured to interact with the user instance 621 to select the access and mobility management function entity 64 .
[0117] For example, the non-3GPP access gateway 63 includes an N3IWF entity.
[0118] In some embodiments, the non-3GPP access gateway 63 is configured to perform an IKE initial exchange with the user instance 621, and send an IKE authentication response to the user instance 621 based on the IKE authentication message sent by the user instance 621, so as to trigger the user instance 621 to initiate an EAP-5G session, and upon receiving the IKE authentication request sent by the user instance 621, select the access and mobility management function entity 64 based on the AN parameters and local policy included in the IKE authentication request.
[0119] For example, the non-3GPP access gateway 63 is a non-3GPP access gateway corresponding to the current location of the user equipment 61 .
[0120] The access and mobility management function entity 64 is configured to interact with the user instance 621 , the non-3GPP access gateway 63 and the core network to complete the network registration of the user instance.
[0121] In some embodiments, the non-3GPP access gateway 63 is configured to establish an IPSec signaling SA between the user instance 621 and the non-3GPP access gateway 63 when the user instance 621 completes NAS registration for non-3GPP access through the non-3GPP access gateway 63 and the access and mobility management function entity 64.
[0122] In some embodiments, the non-3GPP access gateway 63 is configured to send a registration request message to the access and mobility management function entity 64, send an EAP success message to the user equipment 61 through the user instance 621 based on the initialization context establishment request sent by the access and mobility management function entity 64, and establish an IPSec signaling SA with the user instance 621.
[0123] The access and mobility management function entity 64 is configured to send a query request to the user instance 621 through the non-3GPP access gateway 63 according to the registration request message to obtain the identification information in the card data corresponding to the user instance 621, and interact with the non-3GPP access gateway 63, the user instance 621 and the authentication server function entity to authenticate the user instance 621. If the authentication is successful, the NAS security mode command is sent to the user instance 621 through the non-3GPP access gateway 63, and the initialization context establishment request is sent to the non-3GPP access gateway 63 according to the NAS security mode completion message sent by the user instance 621.
[0124] In some embodiments, the identification information in the card data includes SUCI or SUPI.
[0125] In some embodiments, the non-3GPP access gateway 63 is further configured to allocate an IPSec tunnel endpoint address on the user equipment side during the process of establishing an IPSec signaling SA with the user instance 621 .
[0126] In some embodiments, the user equipment 61 is configured to establish one or more session sub-SAs between the user equipment and the non-3GPP access gateway 63 according to the registration success message, and direct traffic to the corresponding session sub-SAs when accessing services.
[0127] In some embodiments, the user equipment 61 is configured to send a service request to the user instance 621, receive a PDU session establishment completion message sent by the non-3GPP access gateway 63 through the user instance 621, receive a PDU session establishment success message sent by the access and mobility management function entity 64 through the user instance 621, and direct the service traffic to the corresponding session sub-SA according to the service scheduling policy.
[0128] In some embodiments, the access and mobility management function entity 64 is configured to interact with the core network network element to establish an initial session on the core network side based on the PDU session establishment request sent by the user instance 621 through the non-3GPP access gateway 63, and send the N2 PDU session request to the non-3GPP access gateway 63.
[0129] The non-3GPP access gateway 63 is configured to determine the number of IPSec sub-SAs based on local policies and a predetermined QoS profile, and for each IPSec sub-SA, send an IKE create sub-SA request to the user device 61 through the user instance 621, and establish the IPSec sub-SA of the PDU session based on the IKE create sub-SA response sent by the user device 61 through the user instance 621.
[0130] It should be noted that the non-3GPP access gateway 63 is configured to reallocate the tunnel endpoint IP address on the user equipment side when establishing the first IPSec sub-SA of a PDU session, but does not need to reallocate the tunnel endpoint IP address on the user equipment side for other IPSec sub-SAs.
[0131] In some embodiments, the access and mobility management function entity 64 is configured to interact with the core network network element to complete the session establishment on the core network side based on the N2 PDU session response sent by the non-3GPP access gateway 63, and send a PDU session establishment success message to the user equipment 61 through the non-3GPP access gateway 63 and the user instance 621.
[0132] The solutions provided by the present disclosure are described below through specific embodiments.
[0133] Example 1:
[0134] As shown in Figure 7, the remote UE triggers the cloud terminal to perform network registration on behalf of the remote UE. For example, the non-3GPP access gateway is the N3IWF() entity.
[0135] In step 70a, the L3 relay UE establishes a session with the cloud terminal. The APP in the L3 relay UE has been authorized and configured with discovery parameters, and will guide the relay traffic.
[0136] In step 70b, the remote UE has obtained service authorization and has configured discovery parameters.
[0137] In step 71 , a discovery process is performed between the remote UE and the L3 relay UE, and the remote UE selects the L3 relay UE as a connection relay for accessing the mobile network.
[0138] In step 72, the remote UE establishes a point-to-point communication connection with the L3 relay UE, and the L3 relay UE allocates an IP address / prefix to the remote UE.
[0139] In step 73, the remote UE accesses the cloud terminal. The cloud terminal queries the card data corresponding to the mobile phone number corresponding to the UE APP ID (if not previously available, it is synchronized from the operation background), activates the corresponding user instance, and the user instance has a mapping relationship with the card data and AN parameters. The cloud terminal selects the appropriate N3IWF entity based on the UE location provided by the remote UE.
[0140] In step 74, the remote UE initiates a registration request (including the UE APP ID) to trigger the network registration operation of the corresponding user instance.
[0141] At step 75, the user instance initiates the IKE initial exchange (IKE_SA_INIT).
[0142] In step 76, the user instance sends an IKE_AUTH request message to initiate an IKE_AUTH exchange (IKE_AUTH Req(UE Id, without AUTH)), where UE Id is the user network identifier in the cloud terminal instance, which can be SUPI, SUCI, etc.
[0143] In step 77, the N3IWF returns an IKE_AUTH response message to notify the user instance to initiate an EAP-5G session (IKE_AUTH Res(EAP-Req / 5G-Start)).
[0144] In step 78 , the user instance sends an IKE_AUTH request (IKE_AUTH Req(EAP-Res / 5G-NAS / AN-Params,NAS-PDU[Registration Request])), which includes an EAP-Response / 5G-NAS packet carrying Access Network parameters (AN parameters) and a Registration Request message.
[0145] In step 79, the N3IWF selects an AMF based on the received AN parameters and local policy.
[0146] In step 710, the user instance acts as a proxy UE, executes IKE and authentication processes with the network, completes the UE registration process, establishes an IPSec signaling SA with the N3IWF, and saves the security context of the cloud terminal instance.
[0147] In step 711, the user instance returns a registration success message to the remote UE, which carries the security context of the cloud terminal instance, such as the N3IWF IP address, encryption key, etc.
[0148] In step 712, one or more session sub-SAs are established between the user instance and the N3IWF.
[0149] In step 713, the remote UE directs traffic to the session sub-SA according to the session policy.
[0150] Example 2
[0151] Step 710 in the above-mentioned embodiment 1 includes the following steps.
[0152] In step 81, N3IWF forwards the request received from the cloud terminal user instance to the selected AMF, that is, N3IWF sends information (N2 msg (Registration Request)) to AMF.
[0153] In step 82a, the AMF sends a query request (N2 msg (Identity Req.)) to the N3IWF.
[0154] In step 82b, the N3IWF sends a query message (IKE_AUTH Req / Res (EAP-Req / Res / 5G-NAS / NAS-PDU [Identity Req.])) to the user instance of the cloud terminal.
[0155] In step 82c, the user instance sends the identification information in the card data to the N3IWF using the IKE authentication response (IKE_AUTH Req / Res(EAP-Req / Res / 5G-NAS / NAS-PDU[Identity Res.])).
[0156] For example, the identification information in the card data includes SUCI or SUPI.
[0157] In step 82d, N3IWF sends the identification information in the card data to AMF using the query response (N2 msg(Identity Res.)).
[0158] In step 83a, the AMF sends a challenge message (AAA Key Request) to the Authentication Server Function (AUSF), which includes the identification information SUCI or SUPI in the card data.
[0159] In step 83b, the AUSF sends a key response message (AAA msg (EAP / AKA-Challenge)) to the AMF.
[0160] In step 83c, the AMF sends an authentication request (N2 msg(Auth.Request[EAP / AKA-Challenge])) to the N3IWF.
[0161] In step 83d, the N3IWF sends an authentication request (IKE_AUTH Res(EAP-Req / 5G-NAS / NAS-PDU[Auth.Request[EAP / AKA-Challenge]]) to the user instance.
[0162] In step 83e, the user instance sends an authentication response (IKE_AUTH Req(EAP-Res / 5G-NAS / NAS-PDU[Auth.Response[EAP / AKA-Challenge]])) to the N3IWF.
[0163] In step 83f, N3IWF sends an authentication response (N2 msg(Auth.Response[EAP / AKA-Challenge])) to AMF.
[0164] In step 83g, the AMF sends a challenge message (AAA msg (EAP / AKA-Challenge)) to the AUSF.
[0165] In step 83h, the AUSF sends a key response message (AAA KeyResponse(SEAF key, EAP-Success)) to the AMF.
[0166] It should be noted that in steps 83a-83h above, the AUSF sends the anchor key (SEAF key) to the AMF, which uses the anchor key to derive the NAS security key and the N3IWF security key (N3IWF key). The user instance also derives the anchor key (SEAF key) and uses the anchor key to derive the NAS security key and the N3IWF security key (N3IWF key). The N3IWF key is used when the user instance and N3IWF subsequently establish an IPsec SA.
[0167] In step 84a, the AMF sends a security mode command (N2 msg (Security Mode Command [EAP-Success])) to the N3IWF.
[0168] In step 84b, the N3IWF sends an authentication request (IKE_AUTH Res(EAP-Req / 5G-NAS / NAS-PDU[NAS Security Mode Command[EAP-Success]])) to the user instance.
[0169] In step 84c, the user instance sends an authentication response (IKE_AUTH Req (EAP-Res / 5G-NAS / NAS-PDU [Security Mode Complete])) to the N3IWF.
[0170] In step 84d, N3IWF sends the security mode completion message (N2 msg([NAS Security Mode Complete])) to AMF.
[0171] It should be noted that in steps 84a-84d, the AMF sends a NAS Security Mode Command request to the N3IWF, which carries the EAP-Success message. The N3IWF forwards the NAS Security Mode Command message to the cloud user instance in an EAP / 5G-NAS packet. After the cloud user instance completes EAP-AKA authentication, it forwards the NAS Security Mode Complete message to the AMF via the N3IWF.
[0172] In step 85a, the AMF sends an initial context setup request (Initial Context Setup Req (N3IWF key)) to the N3IWF.
[0173] In step 85b, the N3IWF sends an EAP success message (IKE_AUTH Res(EAP-Success)) to the cloud terminal user instance.
[0174] It should be noted here that by sending EAP-Success to the cloud terminal user instance, it indicates that the EAP-5G session is completed and no more EAP-5G data packets are exchanged.
[0175] In step 86a, the user instance and the N3IWF establish a signaling IPsec SA using the N3IWF key. During this process, the user device's IPsec tunnel endpoint address, which is the inner IP address, is assigned. The signaling IPsec SA is configured to operate in tunnel mode.
[0176] In step 86b, N3IWF sends an initial context setup response (Initial Context Setup Res) to AMF.
[0177] In step 87, the AMF sends a NAS registration accept message (N2 msg (NAS Registration Accept)) to the N3IWF.
[0178] Example 3
[0179] As shown in Figure 9, the remote UE triggers the cloud terminal to act as an agent for the remote UE to establish a session process. For example, the non-3GPP access gateway is the N3IWF entity.
[0180] In step 90 , as a prerequisite, the user instance in the cloud terminal has established an IPSec signaling SA with the N3IWF during the registration process.
[0181] In step 91, the remote UE initiates a service request (including the UE APP ID), triggering the corresponding user instance to initiate a session establishment operation.
[0182] In step 92, the user instance sends a PDU session request to the AMF.
[0183] In step 93a, the AMF interacts with the core network element to complete the session establishment on the core network side.
[0184] In step 93b, the AMF sends the N2 PDU Session Request to the N3IWF.
[0185] In step 94, the N3IWF determines the number of IPSec sub-SAs and the QoS profile associated with each IPSec sub-SA based on the local policy and the predetermined QoS profile.
[0186] In step 95a, the N3IWF sends an IKE create child SA request (IKE_Create_Child SA Req) to the user instance.
[0187] It should be noted that the IKE request to create a sub-SA includes the QFI (QoS Flow ID) of the sub-SA, the IP address of the sub-SA peer, and the like.
[0188] In step 95b, the user instance sends an IKE create child SA request (IKE_Create_Child SA Req) to the remote UE.
[0189] In step 95c, the remote UE sends an IKE create child SA response (IKE_Create_Child SA Res) to the user instance.
[0190] In step 95d, the user instance sends an IKE create sub-SA response to the N3IWF to establish a corresponding IPSec sub-SA for the PDU session between the remote UE and the N3IWF entity.
[0191] In addition, the N3IWF entity reallocates the tunnel endpoint IP address on the user equipment side, ie, the inner IP address.
[0192] It should be noted that if there is only one IPSec child SA, only steps 95a-95d need to be executed, and steps 96a-96d need not be executed. If there are multiple IPSec child SAs, in addition to steps 95a-95d, steps 96a-96d are repeated until all IPSec child SAs are processed.
[0193] In step 96a, the N3IWF sends an IKE create child SA request (IKE_Create_Child SA Req) to the user instance.
[0194] It should be noted that the IKE request to create a sub-SA includes the QFI (QoS Flow ID) of the sub-SA, the IP address of the sub-SA peer, and the like.
[0195] In step 96b, the user instance sends an IKE create child SA request (IKE_Create_Child SA Req) to the remote UE.
[0196] In step 96c, the remote UE sends an IKE create child SA response (IKE_Create_Child SA Res) to the user instance.
[0197] In step 96d, the user instance sends an IKE create sub-SA response to the N3IWF to establish a corresponding IPSec sub-SA for the PDU session between the remote UE and the N3IWF entity.
[0198] It should be noted that, during the execution of steps 96a to 96d, the N3IWF entity does not need to reallocate the tunnel endpoint IP address on the user equipment side.
[0199] In step 97, the N3IWF sends a PDU session establishment completion message to the user instance.
[0200] It should be noted here that the PDU session establishment completion message includes the service scheduling policy on the user equipment side, the UE session IP address and other contents.
[0201] At step 98, the user instance sends a PDU session establishment complete message to the remote UE.
[0202] In step 99, the N3IWF sends the N2 PDU session response to the AMF.
[0203] In step 910, the AMF interacts with the core network element to complete the session establishment on the core network side.
[0204] In step 911, the AMF sends a PDU session establishment success message to the N3IWF entity.
[0205] It should be noted that the PDU session establishment success message includes the UE session IP address assigned by the network.
[0206] In step 912, the N3IWF sends a PDU session establishment success message to the remote UE.
[0207] In step 913, the remote UE guides each service traffic to the corresponding session sub-SA according to the service scheduling policy.
[0208] By implementing the above embodiments of the present disclosure, the following beneficial effects can be achieved:
[0209] 1. When the terminal lacks non-3GPP access capability, it can effectively realize non-3GPP access of the terminal.
[0210] 2. The signaling interaction between the user equipment and the core network is through the cloud terminal agent, and the user equipment does not need to call the terminal module card data.
[0211] 3. The service tunnel is still established between the user device and the non-3GPP access gateway, and application and traffic scheduling still occur on the user device, meeting the user's need to use relays to facilitate services, matching the original intention of relay networking, and retaining the user's habit of using services.
[0212] In some embodiments, the functional units described above may be implemented as general-purpose processors, programmable logic controllers (PLC), digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or any appropriate combination thereof, for performing the functions described in the present disclosure.
[0213] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.
[0214] The description of the present disclosure is provided for purposes of illustration and description and is not intended to be exhaustive or to limit the disclosure to the disclosed form. Many modifications and variations will be apparent to those skilled in the art. The embodiments are selected and described in order to better illustrate the principles and practical applications of the present disclosure and to enable those skilled in the art to understand the present disclosure and design various embodiments with various modifications suitable for specific applications.
Claims
1. An access control method, executed by a cloud terminal, includes: Reading card data of an identity card corresponding to the identifier of the user equipment according to an access request sent by the user equipment; Activating a cloud user instance corresponding to the user equipment, where the user instance has a mapping relationship with the card data and access network AN parameters; Selecting a non-3GPP access gateway; Triggering the interaction between the user instance and the non-3GPP access gateway according to a registration request sent by the user equipment to select an access and mobility management function entity.
2. The access control method according to claim 1, further includes: After selecting the access and mobility management function entity, triggering the user instance to act as a user equipment proxy to perform network registration through the non-3GPP access gateway and the access and mobility management function entity; If the network registration is successful, triggering the user instance to send a registration success message to the user equipment so that the user equipment establishes a communication connection with the non-3GPP access gateway and accesses the core network through the communication connection.
3. The access control method according to claim 2, wherein, Triggering the user instance to perform network registration through the non-3GPP access gateway and the access and mobility management function entity includes: Triggering the user instance to complete non-access stratum NAS registration for non-3GPP access through the non-3GPP access gateway and the access and mobility management function entity, and establishing an Internet Protocol Security IPSec signaling security association SA between the user instance and the non-3GPP access gateway.
4. The access control method according to claim 3, wherein, Triggering the user instance to complete NAS registration for non-3GPP access through the non-3GPP access gateway and the access and mobility management function entity includes: According to a query request sent by the access and mobility management function entity through the non-3GPP access gateway, triggering the user instance to send the identification information in the card data to the access and mobility management function entity through the non-3GPP access gateway, where the access and mobility management function entity sends the query request when receiving a registration request message sent by the non- 3GPP access gateway; Triggering the user instance to interact with the non-3GPP access gateway, the access and mobility management function entity, and the authentication server function entity to authenticate the user instance; Triggering the user instance to authenticate a NAS security mode command message sent by the access and mobility management function entity through the non-3GPP access gateway; Triggering the user instance to send an EAP success message sent by the non-3GPP access gateway to the user equipment to indicate the completion of the EAP-5G session; Triggering the user instance to establish the IPSec signaling SA with the non-3GPP access gateway.
5. The access control method according to claim 4, wherein, The identification information in the card data includes a Subscriber Concealed Identifier SUCI or a Subscriber Permanent Identifier SUPI.
6. The access control method according to claim 1, wherein, Triggering the user instance to interact with the non-3GPP access gateway includes: Trigger the Internet Key Exchange (IKE) initial exchange between the user instance and the non-3GPP access gateway; Trigger the user instance to send an IKE authentication message for initiating an IKE authentication exchange to the non-3GPP access gateway; According to the IKE authentication response sent by the non-3GPP access gateway, trigger the user instance to initiate an Extensible Authentication Protocol (EAP)-5G session; Trigger the user instance to send an IKE authentication request to the non-3GPP access gateway, where the IKE authentication request includes the AN parameter, so that the non-3GPP access gateway selects the access and mobility management function entity according to the AN parameter and the local policy.
7. The access control method according to claim 2, wherein, The registration success message includes the non-3GPP access gateway IP address and the non-3GPP access gateway key, which are used to trigger the user equipment to establish one or more session sub-SAs between the user equipment and the non-3GPP access gateway, and divert the traffic to the corresponding session sub-SAs when accessing services.
8. The access control method according to claim 1, wherein, The non-3GPP access gateway is the non-3GPP access gateway corresponding to the current location of the user equipment.
9. The access control method according to claim 1, wherein, The non-3GPP access gateway includes a non-3GPP network interworking function (N3IWF) entity.
10. The access control method according to any one of claims 1-9 further includes: According to the service request sent by the user equipment, trigger the user instance to execute a protocol data unit (PDU) session establishment process by interacting with the non-3GPP access gateway, the access and mobility management function entity, and the user equipment; Forward the PDU session establishment completion message sent by the non-3GPP access gateway to the user equipment; Forward the PDU session establishment success message sent by the access and mobility management function entity through the non-3GPP access gateway to the user equipment, so that the user equipment diverts the service traffic to the corresponding session sub-SAs according to the service scheduling policy.
11. The access control method according to claim 10, wherein, Triggering the user instance to execute the PDU session establishment process includes: Trigger the user instance to send a PDU session establishment request to the access and mobility management function entity through the non-3GPP access gateway, so that the access and mobility management function entity interacts with the core network element to establish an initial session on the core network side; Forward the IKE create sub-SA request sent by the non-3GPP access gateway to the user equipment, and forward the IKE create sub-SA response sent by the user equipment to the non-3GPP access gateway, so as to establish one or more Internet Protocol Security (IPSec) sub-SAs for the PDU session between the user equipment and the non-3GPP access gateway.
12. The access control method according to claim 10, wherein, When the access and mobility management function entity interacts with the core network element according to the N2 PDU session response sent by the non-3GPP access gateway to complete the session establishment on the core network side, it sends the PDU session establishment success message to the user instance through the non-3GPP access gateway.
13. A cloud terminal, comprising: A memory; A processor, coupled to the memory, the processor being configured to execute based on instructions stored in the memory to implement the access control method according to any one of claims 1-12.
14. A communication system, comprising: The cloud terminal according to claim 13; A user equipment, configured to send an access request to the cloud terminal, establish a communication connection with a non-3GPP access gateway selected by the user instance according to the registration success message sent by the user instance in the cloud terminal, and access the core network through the communication connection; The non-3GPP access gateway, configured to interact with the user instance to select an access and mobility management function entity; The access and mobility management function entity, configured to interact with the user instance, the non-3GPP access gateway and the core network to complete the network registration of the user instance.
15. The communication system according to claim 14, wherein, The non-3GPP access gateway is configured to establish an IPSec signaling SA between the user instance and the non-3GPP access gateway when the user instance completes NAS registration through the non-3GPP access gateway and the access and mobility management function entity.
16. The communication system according to claim 15, wherein, The non-3GPP access gateway is configured to send a registration request message to the access and mobility management function entity, send an EAP success message to the user equipment through the user instance according to the initialization context establishment request sent by the access and mobility management function entity, and establish the IPSec signaling SA with the user instance; The access and mobility management function entity is configured to send a query request to the user instance through the non-3GPP access gateway according to the registration request message to obtain the identification information in the card data corresponding to the user instance, authenticate the user instance by interacting with the non-3GPP access gateway, the user instance and the authentication server function entity, send the NAS security mode command to the user instance through the non-3GPP access gateway in case of successful authentication, and send the initialization context establishment request to the non-3GPP access gateway according to the NAS security mode completion message sent by the user instance.
17. The communication system according to claim 16, wherein, The non-3GPP access gateway is further configured to allocate an IPSec tunnel endpoint address on the user equipment side during the process of establishing the IPSec signaling SA with the user instance.
18. The communication system according to claim 16, wherein, The identification information in the card data includes a Subscriber Concealed Identifier (SUCI) or a Subscriber Permanent Identifier (SUPI).
19. The communication system according to claim 14, wherein the non-3GPP access gateway is configured to perform an IKE initial exchange with the user instance, send an IKE authentication response to the user instance according to the IKE authentication message sent by the user instance, so as to trigger the user instance to initiate an EAP-5G session, and select the access and mobility management function entity according to the AN parameter and the local policy included in the IKE authentication request when receiving the IKE authentication request sent by the user instance.
20. The communication system according to claim 14, wherein the user equipment is configured to establish one or more session sub-SAs between the user equipment and the non-3GPP access gateway according to the registration success message, and divert traffic to the corresponding session sub-SA when accessing services.
21. The communication system according to claim 14, wherein the non-3GPP access gateway is the non-3GPP access gateway corresponding to the current location of the user equipment.
22. The communication system according to any one of claims 14-21, wherein the user equipment is configured to send a service request to the user instance, receive a PDU session establishment completion message sent by the non-3GPP access gateway through the user instance, receive a PDU session establishment success message sent by the access and mobility management function entity through the user instance, and divert service traffic to the corresponding session sub-SA according to the service scheduling policy.
23. The communication system according to claim 22, wherein the access and mobility management function entity is configured to interact with the core network element according to the PDU session establishment request sent by the user instance through the non-3GPP access gateway to establish an initial session on the core network side, and send an N2 PDU session request to the N3IWF entity; the non-3GPP access gateway is configured to determine the number of IPSec sub-SAs according to the local policy and a predetermined QoS profile, and for each IPSec sub-SA, send an IKE create sub-SA request to the user equipment through the user instance, and establish the IPSec sub-SA of the PDU session according to the IKE create sub-SA response sent by the user equipment through the user instance.
24. The communication system according to claim 23, wherein the non-3GPP access gateway is configured to reallocate the tunnel endpoint IP address on the user equipment side when establishing the first IPSec sub-SA of the PDU session.
25. The communication system according to claim 23, wherein the access and mobility management function entity is configured to interact with the core network element according to the N2 PDU session response sent by the non-3GPP access gateway to complete the session establishment on the core network side, and send the PDU session establishment success message to the user equipment through the non-3GPP access gateway and the user instance.
26. A computer-readable storage medium, wherein, A computer-readable storage medium stores computer instructions, which, when executed by a processor, implement the access control method according to any one of claims 1-12.
27. A computer program, comprising computer instructions, which, when executed by a processor, implement the access control method according to any one of claims 1-12.
Citation Information
Patent Citations
Relocation access gateway
CN115362754A
Method for selecting non-credit non-3GPP (3rd Generation Partnership Project) network, user terminal and communication system
CN116801276A
Access control method, cloud terminal, communication system and storage medium
CN117915489A
Methods and apparatuses for determination of non-3GPP interworking function (n3IWF)
US20230308990A1