Communication method, apparatus and system

By establishing a direct NAS session between the terminal device and the first network element and the second network element in the 5G system, the problems of low NAS message transmission efficiency and inflexible network architecture are solved, and efficient and secure NAS message transmission is achieved, which is suitable for 5G mobile communication systems.

WO2025157191A1PCT designated stage Publication Date: 2025-07-31HUAWEI TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/074053
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-27
Filing Date
2025-01-22
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

In 5G mobile communication system, NAS message transmission efficiency between the terminal device and the core network element is low, and the existing solution does not comply with the principle of functional decoupling between network elements of the service architecture, resulting in inflexible network architecture and difficult to meet the needs of low latency and messages not leaving the park.

Method used

After the terminal device establishes a first NAS session with the first network element, it establishes a second NAS session with the second network element to directly transmit NAS messages to avoid transit through the first network element, realizes direct transmission of NAS messages, improves transmission efficiency, and protects message transmission security through a security mechanism between the second network element and the terminal device.

Benefits of technology

It improves the transmission efficiency of NAS messages, enhances the flexibility and security of the network architecture, and meets the needs of low latency and messages not leaving the park.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025074053_31072025_PF_FP_ABST
    Figure CN2025074053_31072025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to the technical field of communications. Disclosed are a communication method, apparatus and system, which can improve the transmission efficiency of NAS messages. The method comprises: a terminal device sends a first request message to a first network element by means of a first NAS session, the first NAS session being used for transmitting an NAS message between the terminal device and the first network element; then, the terminal device receives an identifier of a second NAS session, the second NAS session being used for transmitting an NAS message between the terminal device and a second network element, and furthermore, the terminal device can send a first NAS message to the second network element by means of the second NAS session on the basis of the identifier of the second NAS session.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, device and system

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 27, 2024, with application number 202410125338.3 and application name “Communication Methods, Devices and Systems”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technologies, and in particular to communication methods, devices, and systems. Background Art

[0003] In the 5th generation (5G) mobile communication system, information can be transmitted between terminal devices and core network (CN) elements through non-access stratum (NAS) messages.

[0004] Currently, NAS messages between terminal devices and core network elements are transmitted through the access and mobility management function (AMF) element. That is, the AMF element transmits the NAS message to the target core network element. This NAS message transmission method is inefficient. Summary of the Invention

[0005] The embodiments of the present application provide a communication method, apparatus, and system that can improve the transmission efficiency of NAS messages.

[0006] The embodiments of this application adopt the following technical solutions:

[0007] In a first aspect, a communication method is provided. The method can be executed by a terminal device, or by a component of the terminal device (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can implement all or part of the terminal device functions. The following description takes the terminal device as an example of the execution subject of the method. The method includes: the terminal device sends a first request message to the first network element through a first NAS session, and the first NAS session is used to transmit NAS messages between the terminal device and the first network element. Then, the terminal device receives an identifier of a second NAS session, and the second NAS session is used to transmit NAS messages between the terminal device and the second network element. Furthermore, the terminal device can also send the first NAS message to the second network element through the second NAS session based on the identifier of the second NAS session.

[0008] Regarding the first request message, in one possible scenario, the first request message is used to request a service. In another possible scenario, the first request message is used to request a service and also to request establishment of a NAS session between the terminal device and the second network element. In another possible scenario, the first request message is used to request establishment of a NAS session between the terminal device and the second network element.

[0009] If the first request message requests a service, the service is provided by the second network element. If the first request message requests the establishment of a NAS session between the terminal device and the second network element (the first request message is used to request a service and is also used to request the establishment of a NAS session between the terminal device and the second network element, or the first request message is used to request the establishment of a NAS session between the terminal device and the second network element), the second NAS session is the NAS session actually established between the terminal device and the second network element in response to the request in the first request message.

[0010] Based on the communication method provided in the embodiments of the present application, a terminal device can establish a second NAS session with a second network element after having already established a first NAS session with a first network element. This allows NAS messages to be directly transmitted between the terminal device and the second network element via the second NAS session. This improves the transmission efficiency of NAS messages compared to a solution in which NAS messages are relayed by the first network element. In addition, in this solution, the NAS messages transmitted between the second network element and the terminal device are independent of the first network element. This not only aligns with the principle of functional decoupling between network elements and improves the flexibility of the network architecture, but also enhances the security of NAS message transmission.

[0011] In one possible implementation, when the first request message requests establishment of a NAS session between the terminal device and the second network element, the first request message includes an identifier of the second NAS session. In this implementation, the first request message can be considered to request establishment of the second NAS session. Optionally, the identifier of the second NAS session included in the first request message may be allocated by the terminal device for the second NAS session.

[0012] Based on this solution, the terminal device can inform the first network element of the identifier of the second NAS session requested to be established through the first request message.

[0013] In one possible implementation, the method further includes: the terminal device receiving first indication information, the first indication information being used to instruct the terminal device to activate a security mode for the second NAS session. The security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session. Then, the terminal device activates the security mode for the second NAS session according to the first indication information.

[0014] Based on this solution, the terminal device can enable a security mode for the second NAS session to protect NAS messages transmitted through the second NAS session and prevent the NAS messages transmitted through the second NAS session from being tampered with.

[0015] In a possible implementation, the method further includes: the terminal device generating a key for a second NAS session based on the root key of the first NAS session and the identifier of the second NAS session, where the key for the second NAS session includes at least one of the following keys: a key for encrypting NAS messages transmitted through the second NAS session, or a key for integrity protection of NAS messages transmitted through the second NAS session.

[0016] Based on this solution, the terminal device can locally generate the key for the second NAS session, avoiding the risk of key theft that may occur when obtaining the key from other devices, and protecting the security of the key.

[0017] In one possible implementation, the terminal device activates a security mode for the second NAS session according to the first indication information, including: the terminal device verifies the first indication information using a key of the second NAS session; the key of the second NAS session includes at least one of the following keys: a key used for encrypting NAS messages transmitted through the second NAS session, or a key used for integrity protection of NAS messages transmitted through the second NAS session. If the verification succeeds, the terminal device activates the security mode.

[0018] Based on this solution, the terminal device can reactivate the security mode if the security verification of the first indication information is passed, thereby further ensuring the security of the second NAS session in the security mode.

[0019] In one possible implementation, the terminal device sends a first request message to the first network element through the first NAS session, including: the terminal device sends a second message to the access network device, and the second message includes the first request message. Optionally, the second message may be a radio resource control (RRC) message. In this implementation, the second message is sent through the radio bearer corresponding to the first NAS session, and / or the second message includes an identifier of the first NAS session. The radio bearer corresponding to the first NAS session or the identifier of the first NAS session is used by the access network device to determine that the destination network element of the first request message is the first network element, that is, to determine to send the first request message to the first network element. That is, after receiving the second message, the access network device can determine to send the first request message to the first network element based on the radio bearer corresponding to the first NAS session and / or the identifier of the first NAS session.

[0020] Based on this solution, when a terminal device sends a message to a destination network element through a NAS session, it can send the NAS session identifier through the wireless bearer corresponding to the NAS session, and / or together, so that the access network device responsible for relaying the message can determine the destination network element corresponding to the message and realize the transmission of the message through the NAS session.

[0021] In one possible implementation, the terminal device sends a first NAS message to the second network element through the second NAS session, including: the terminal device sends a first message to the access network device, and the first message includes the first NAS message. Optionally, the first message may be an RRC message. In this implementation, the first message is sent through the radio bearer corresponding to the second NAS session, and / or the first message includes an identifier of the second NAS session. The radio bearer corresponding to the second NAS session or the identifier of the second NAS session is used by the access network device to determine that the destination network element of the first NAS message is the second network element, that is, to determine to send the first NAS message to the second network element. That is, after receiving the first message, the access network device can determine to send the first NAS message to the second network element based on the radio bearer corresponding to the second NAS session and / or the identifier of the second NAS session.

[0022] Based on this solution, when a terminal device sends a NAS message to a destination network element through a NAS session, it can send the NAS session identifier through the radio bearer corresponding to the NAS session, and / or together, so that the access network device responsible for relaying the message can determine the destination network element corresponding to the message, thereby realizing message transmission through the NAS session.

[0023] In a possible implementation manner, the first request message includes first information, and the first information is used to select the second network element from network elements providing services.

[0024] Based on this solution, a second network element suitable for establishing a second NAS session can be selected from network elements providing services based on the first information.

[0025] In one possible implementation, the method further includes: the terminal device receiving second information from the access network device, where the second information is used to configure one or more radio bearers corresponding to the second NAS session. The terminal device sending the first NAS message to the second network element through the second NAS session includes: the terminal device sending the first NAS message to the second network element through the radio bearer corresponding to the second NAS session.

[0026] Based on this solution, a corresponding radio bearer can be configured for the second NAS session, and the terminal device can send NAS messages via the radio bearer corresponding to the second NAS session. Correspondingly, the access network device can determine the NAS session corresponding to the NAS message by receiving the radio bearer of the NAS message.

[0027] In one possible implementation, the second NAS session includes one or more quality of service (QoS) flows, and the terminal device sends a first NAS message to the second network element through the second NAS session, including: the terminal device sends the first NAS message to the second network element through a radio bearer corresponding to the first QoS flow. The first NAS message corresponds to the first QoS flow, and the one or more QoS flows include the first QoS flow.

[0028] Based on this solution, by configuring corresponding radio bearers for the QoS flows included in the second NAS session, NAS messages transmitted through the second NAS session can be distributed and transmitted through different radio bearers based on the corresponding QoS flows, thereby preventing message congestion that may be caused by all NAS messages transmitted through the second NAS session being mixed and transmitted in the same channel.

[0029] In one possible implementation, the method further includes: the terminal device receiving a mapping rule, the mapping rule including a correspondence between the first NAS message and the first QoS flow; and the terminal device receiving third information from the access network device, the third information being used to configure a radio bearer corresponding to the first QoS flow.

[0030] Based on this solution, the terminal device can determine which QoS flow the NAS message to be sent corresponds to based on the mapping rule, and further determine the radio bearer corresponding to the QoS flow based on the third information.

[0031] On the second aspect, a communication method is provided, which can be executed by a first network element, or by a component of the first network element (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can implement all or part of the functions of the first network element. The following is an illustration of the method using the first network element as an example of the execution subject. The method includes: the first network element receives a first request message from a terminal device through a first NAS session, wherein the first NAS session is a NAS session established between the terminal device and the first network element, and is used to transmit NAS messages between the terminal device and the first network element. The first network element triggers the establishment of a second NAS session, and the second NAS session is used to transmit NAS messages between the terminal device and the second network element.

[0032] Regarding the first request message, in one possible scenario, the first request message is used to request a service. In another possible scenario, the first request message is used to request a service and also to request establishment of a NAS session between the terminal device and the second network element. In another possible scenario, the first request message is used to request establishment of a NAS session between the terminal device and the second network element.

[0033] If the first request message requests a service, the service is provided by the second network element. If the first request message requests the establishment of a NAS session between the terminal device and the second network element (the first request message is used to request a service and is also used to request the establishment of a NAS session between the terminal device and the second network element, or the first request message is used to request the establishment of a NAS session between the terminal device and the second network element), the second NAS session is the NAS session actually established between the terminal device and the second network element in response to the request in the first request message.

[0034] Based on the communication method provided in the embodiments of the present application, a terminal device can establish a second NAS session with a second network element after having already established a first NAS session with a first network element. This allows NAS messages to be directly transmitted between the terminal device and the second network element via the second NAS session. This improves the transmission efficiency of NAS messages compared to a solution in which NAS messages are relayed by the first network element. In addition, in this solution, the NAS messages transmitted between the second network element and the terminal device are independent of the first network element. This not only aligns with the principle of functional decoupling between network elements and improves the flexibility of the network architecture, but also enhances the security of NAS message transmission.

[0035] In one possible implementation, the method further includes: the first network element sending an identifier of the second NAS session to the second network element. Optionally, the identifier of the second NAS session may be allocated by the terminal device for the second NAS session, or may be allocated by the first network element for the second NAS session.

[0036] In one possible implementation, the method further includes: determining, by the first network element, based on the subscription information of the terminal device, whether to allow establishment of a NAS session between the terminal device and the second network element. The first network element triggering establishment of the second NAS session includes: triggering establishment of the second NAS session by the first network element if the subscription information of the terminal device indicates that establishment of the NAS session between the terminal device and the second network element is allowed.

[0037] Based on this solution, the first network element can decide whether to allow the establishment of the second NAS session based on the contract information of the terminal device. In other words, the first network element can authorize the establishment of the second NAS session based on the contract information of the terminal device to prevent unauthorized NAS sessions from causing unsafe impacts on the system.

[0038] Optionally, the subscription information of the terminal device indicates that establishment of a NAS session between the terminal device and the second network element is allowed, including: the subscription information of the terminal device indicates that creation of a NAS session between the terminal device and the second network element is allowed for the service requested by the first request message.

[0039] Based on this solution, the first network element can determine whether to establish a second NAS session for the service requested by the first request message according to the subscription information of the terminal device.

[0040] In one possible implementation, the method further includes: the first network element sending a fifth request message to the second network element, the fifth request message being used to request a service; the first network element receiving fourth information from the second network element, the fourth information being used to instruct establishment of a second NAS session; and the first network element triggering establishment of the second NAS session, including: the first network element triggering establishment of the second NAS session based on the fourth information.

[0041] Based on this solution, the second network element may decide to establish a second NAS session, and the first network element may trigger the establishment of the second NAS session under the instruction of the second network element.

[0042] In a possible implementation, the method further includes: the first network element selects a second network element from network elements providing services based on the first information; wherein the first request message includes the first information, or the contract information of the terminal device includes the first information.

[0043] Based on this solution, the first network element can select, from the network elements that can provide services, a network element suitable for establishing a second NAS session with the terminal device as the second network element based on the first information.

[0044] In a possible implementation, the first network element triggers establishment of the second NAS session, including: the first network element sends a second request message to the second network element, where the second request message is used to request establishment of the second NAS session.

[0045] Based on this solution, the first network element may trigger the establishment of the second NAS session by sending a request message to the second network element.

[0046] In one possible implementation, the second request message includes a root key of the second NAS session. The root key of the second NAS session is used to generate a key for the second NAS session. The key for the second NAS session includes at least one of the following keys: a key for encrypting NAS messages transmitted through the second NAS session, or a key for integrity protection of NAS messages transmitted through the second NAS session.

[0047] Based on this solution, the key of the second NAS session can be used to securely protect the NAS messages transmitted through the second NAS session, thereby preventing the NAS messages transmitted through the second NAS session from being tampered with.

[0048] In a possible implementation, the method further includes: the first network element generating a root key for the second NAS session according to the root key of the first NAS session and the identifier of the second NAS session.

[0049] This solution provides a method for generating a root key for a second NAS session.

[0050] In one possible implementation, the second request message also includes security capability information of the terminal device, where the security capability information is used to indicate one or more encryption algorithms supported by the terminal device, and / or one or more integrity protection algorithms supported by the terminal device. The security capability information is used to determine the security algorithm corresponding to the second NAS session, where the security algorithm includes at least one of the following algorithms: an encryption algorithm for encrypting NAS messages transmitted through the second NAS session, or an integrity protection algorithm for integrity protection of NAS messages transmitted through the second NAS session.

[0051] Based on this solution, the second network element can obtain the security capability information of the terminal device through the second request message, and determine the security algorithm corresponding to the second NAS session based on the security capability information of the terminal device to protect the NAS message transmitted through the second NAS session.

[0052] In one possible implementation, the method further includes: the first network element receiving first indication information from the second network element, the first indication information being used to instruct the terminal device to activate a security mode for the second NAS session. The security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session. The first network element sends the first indication information to the terminal device.

[0053] Based on this solution, the first indication information can be used to instruct the terminal device to enable a security mode for the second NAS session, thereby protecting the NAS messages transmitted through the second NAS session and preventing the NAS messages transmitted through the second NAS session from being tampered with.

[0054] In a possible implementation, the method further includes: the first network element sending a third request message to the access network device, where the third request message is used to request establishment of a second NAS session, and the third request message includes an identifier of the second NAS session.

[0055] Based on this solution, a direct connection channel can be established between the access network device and the second network element to establish the second NAS session.

[0056] In one possible implementation, the method further includes: the first network element receiving second indication information from the second network element, where the second indication information indicates establishment of a second NAS session; and the first network element sending a third request message to the access network device, including: the first network element sending the third request message to the access network device according to the second indication information.

[0057] Based on this solution, the first network element may request the access network device to establish a second NAS session according to the instruction of the second network element.

[0058] In a possible implementation manner, the method further includes: the first network element sending an identifier of the second NAS session to the terminal device.

[0059] In a possible implementation, the second request message includes address information of the access network device and a first identifier, the address information of the access network device is used to send a message to the access network device, and the first identifier is used to indicate the context of the terminal device in the access network device.

[0060] Based on this solution, the address information and the first identifier of the access network device can be sent to the second network element, so that the second network element can subsequently send a NAS message through the second NAS session based on the address information and the first identifier of the access network device.

[0061] In a possible implementation, before the first network element sends the second request message to the second network element, the method further includes: the first network element receiving a first identifier from the access network device.

[0062] Based on this solution, the context identifier of the terminal device in the access network device can be allocated by the access network device.

[0063] On the third aspect, a communication method is provided, which can be executed by a second network element, or by a component of the second network element (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can implement all or part of the functions of the second network element. The following is an illustration of the second network element as the execution subject of the method, and the method includes: the second network element receives a second request message from the first network element, the second request message is used to request the establishment of a second NAS session, and the second NAS session is used to transmit NAS messages between the terminal device and the second network element. In addition, there exists a first NAS session for transmitting NAS messages between the first network element and the terminal device. Then, the second network element sends a first response message to the first network element for the second request message.

[0064] Based on the communication method provided in the embodiments of the present application, a terminal device can establish a second NAS session with a second network element after having already established a first NAS session with a first network element. This allows NAS messages to be directly transmitted between the terminal device and the second network element via the second NAS session. This improves the transmission efficiency of NAS messages compared to a solution in which NAS messages are relayed by the first network element. In addition, in this solution, the NAS messages transmitted between the second network element and the terminal device are independent of the first network element. This not only aligns with the principle of functional decoupling between network elements and improves the flexibility of the network architecture, but also enhances the security of NAS message transmission.

[0065] In a possible implementation, the first response message includes a third request message, where the third request message is used to request the access network device to establish a second NAS session. The third request message includes address information of the second network element and an identifier of the second NAS session.

[0066] Based on this solution, the second network element can request the access network device to establish a second NAS session through the first network element.

[0067] In one possible implementation, the first response message includes second indication information, where the second indication information instructs the access network device to establish a second NAS session. The second indication information is used to trigger the first network element to send a third request message to the access network device, where the third request message is used to request establishment of the second NAS session.

[0068] Based on this solution, the second network element may instruct the first network element to request the access network device to establish a second NAS session. Under the instruction of the second network element, the first network element may request the access network device to establish a second NAS session.

[0069] In a possible implementation, the method further includes: the second network element sending a third request message to the access network device, where the third request message is used to request the access network device to establish a second NAS session, and the third request message includes address information of the second network element and an identifier of the second NAS session.

[0070] Based on this solution, the second network element can directly request the access network device to establish a second NAS session.

[0071] In one possible implementation, the second request message includes address information of the access network device and a first identifier, where the first identifier is used to indicate a context of the terminal device in the access network device. The second network element sends a third request message to the access network device, including: the second network element sends the third request message to the access network device based on the address information and the first identifier of the access network device.

[0072] In a possible implementation, the method further includes: the second network element sending a second response message to the terminal device through the third request message, where the second response message is used to indicate that the second NAS session is successfully established, and the second response message includes an identifier of the second NAS session.

[0073] Based on this solution, the second network element can notify the terminal device that the second NAS session is successfully established through the second response message.

[0074] In one possible implementation, before the second network element receives the second request message from the first network element, the method further includes: the second network element receiving a fifth request message from the first network element, the fifth request message being used to request a service provided by the second network element; and the second network element sending, based on the fifth request message, fourth information to the first network element, the fourth information being used to indicate establishment of a second NAS session.

[0075] Based on this solution, the second network element can proactively decide to establish a second NAS session based on the service requested by the terminal device, and instruct the first network element to establish the second NAS session, thereby triggering the establishment of the second NAS session.

[0076] In a possible implementation, the method further includes: the second network element receiving a third response message from the access network device, the third response message including address information of the access network device and a second identifier; the second identifier is used to indicate the context of the second NAS session in the access network device.

[0077] Based on this solution, the second network element can obtain the address information and the second identifier of the access network device, so that when a NAS message is subsequently sent through the second NAS session, the NAS message can be sent directly to the terminal device through the access network device according to the address information and the second identifier of the access network device.

[0078] In a possible implementation, the first response message includes an identifier of the second NAS session.

[0079] In one possible implementation, the method further includes: the second network element sending first indication information to the first network element, where the first indication information is used to instruct the terminal device to activate a security mode for the second NAS session, where the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.

[0080] Alternatively, the method further includes: the second network element sending first indication information to the terminal device through the second NAS session, where the first indication information is used to instruct the terminal device to activate a security mode for the second NAS session; the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.

[0081] Based on this solution, the first indication information can be used to instruct the terminal device to enable a security mode for the second NAS session, thereby protecting the NAS messages transmitted through the second NAS session and preventing the NAS messages transmitted through the second NAS session from being tampered with.

[0082] In one possible implementation, the method further includes: the second network element obtaining a key for a second NAS session, where the key for the second NAS session includes at least one of the following: a key for encryption and a key for integrity protection. The second network element uses the key for the second NAS session to perform at least one of the following on the first indication information: encryption or integrity protection. The second network element sends the first indication information to the terminal device.

[0083] Based on this solution, the second network element can process the first indication information accordingly using the key of the second NAS session to verify whether the terminal device receiving the first indication information has the same key of the second NAS session.

[0084] In one possible implementation, the second network element obtains the key for the second NAS session, including: the second network element generates the key for the second NAS session based on the root key of the second NAS session, wherein the second request message includes the root key of the second NAS session, or the subscription information of the terminal device includes the root key of the second NAS session.

[0085] This solution provides multiple ways to obtain the key for the second NAS session.

[0086] In one possible implementation, the method further includes: obtaining, by the second network element, security capability information of the terminal device, where the security capability information is used to indicate one or more encryption algorithms supported by the terminal device and / or one or more integrity protection algorithms supported by the terminal device. The second network element determines, based on the security capability information of the terminal device, a security algorithm corresponding to the second NAS session; wherein the security algorithm includes one or more of the following algorithms: an encryption algorithm used to encrypt NAS messages transmitted through the second NAS session, or an integrity protection algorithm used to perform integrity protection on NAS messages transmitted through the second NAS session.

[0087] Based on this solution, the second network element can determine an algorithm suitable for security protection of NAS messages transmitted through the second NAS session according to the algorithms supported by the terminal device.

[0088] In a possible implementation manner, the second request message includes security capability information, and / or the subscription information of the terminal device includes security capability information.

[0089] In one possible implementation, the second NAS session includes one or more QoS flows, and the method further includes: the second network element sends a mapping rule to the terminal device, where the mapping rule includes a correspondence between a NAS message transmitted through the second NAS session and each QoS flow in the one or more QoS flows.

[0090] Based on this solution, the second network element can send a mapping rule to the terminal device, so that when the terminal device sends a NAS message through the second NAS session, it can determine the QoS flow corresponding to the NAS message.

[0091] In one possible implementation, the second NAS session includes one or more QoS flows, and the method further includes: the second network element sends a fourth request message to the access network device, where the fourth request message is used to request configuration of a radio bearer corresponding to each QoS flow in the one or more QoS flows.

[0092] Based on this solution, by configuring corresponding radio bearers for the QoS flows included in the second NAS session, NAS messages transmitted through the second NAS session can be distributed and transmitted through different radio bearers based on the corresponding QoS flows, thereby preventing message congestion that may be caused by all NAS messages transmitted through the second NAS session being mixed and transmitted in the same channel.

[0093] In one possible implementation, the method further includes: the second network element sending, through a second NAS session, a second NAS message and identification information of a second QoS flow corresponding to the second NAS message. The identification information of the second QoS flow is used by the access network device to determine and send the second NAS message to the terminal device through the second NAS session.

[0094] Based on this solution, the second network element can indicate the identification information of the QoS flow corresponding to the NAS message to the access network device, so that the access network device can determine, based on the identification information of the QoS flow, that the QoS flow corresponding to the NAS message is one of the QoS flows included in the second NAS session, and then send the second NAS message to the terminal device through the second NAS session.

[0095] In a fourth aspect, a communication method is provided. The method can be executed by an access network device, or by a component of the access network device (e.g., a processor, chip, or chip system), or by a logic module or software that implements all or part of the functions of the access network device. The following description uses the access network device as an example of the execution subject of the method. The method includes: the access network device receives a third NAS message from a terminal device. The access network device determines that the third NAS message belongs to a third NAS session, where the third NAS session is a NAS session between the terminal device and a third network element. In other words, the access network device determines that the destination network element of the third NAS message is the third network element. Consequently, the access network device sends the third NAS message to the third network element.

[0096] Based on the communication method provided in the embodiments of the present application, after receiving a NAS message from a terminal device, the access network device can distinguish the NAS session corresponding to the received NAS message, thereby transmitting the NAS message to the correct destination network element, thereby directly transmitting the NAS message through the NAS session and improving the transmission efficiency of the NAS message.

[0097] In one possible implementation, the access network device receiving the third NAS message from the terminal device includes: the access network device receiving the third NAS message and an identifier of a third NAS session from the terminal device. In this implementation, the access network device determining, based on the third NAS session to which the third NAS message belongs, includes: the access network device determining, based on the identifier of the third NAS session, that the third NAS message belongs to the third NAS session.

[0098] Optionally, in this implementation, the access network device may determine the destination network element of the third NAS message based on the identifier of the third NAS session and the first correspondence. The first correspondence is used to indicate that the identifier of the third NAS session corresponds to the destination network element of the third NAS message. For example, the first correspondence may include a correspondence between the identifier of the third NAS session and information about the destination network element of the third NAS message (such as identifier information and address information of the third network element).

[0099] Based on this solution, a method is provided for an access network device to determine a destination network element of a third NAS message: the method is based on an identifier of a third NAS session.

[0100] In one possible implementation, the access network device determining that the third NAS message belongs to the third NAS session includes: the access network device determining, based on a radio bearer used to transmit the third NAS message, that the third NAS message belongs to the third NAS session. For example, before receiving the third NAS message, the access network device may configure a corresponding radio bearer for the third NAS session. Thus, after receiving the third NAS message, the access network device may determine that the third NAS message belongs to the third NAS session based on the radio bearer used to transmit the third NAS message being the radio bearer corresponding to the third NAS session.

[0101] Optionally, in this implementation, the access network device may determine the destination network element of the third NAS message based on the radio bearer used to transmit the third NAS message and the second correspondence; wherein the second correspondence is used to indicate that the radio bearer used to transmit the third NAS message corresponds to the destination network element of the third NAS message. For example, the second correspondence may include a correspondence between the radio bearer used to transmit the third NAS message, an identifier of the third NAS session, and information of the destination network element of the third NAS message (such as identifier information and address information of the third network element).

[0102] Based on this solution, another method for the access network device to determine the destination network element of the third NAS message is provided: determining based on the radio bearer that transmits the third NAS message.

[0103] In one possible implementation, the method further includes: the access network device receiving a fourth NAS message from the third network element. The access network device determining that the fourth NAS message belongs to the third NAS session. The access network device sending the fourth NAS message and an identifier of the third NAS session to the terminal device, and / or sending the fourth NAS message to the terminal device via a radio bearer corresponding to the third NAS session.

[0104] Based on this solution, when the access network device forwards a NAS message sent to a terminal device, the terminal device can use the NAS session identifier and / or the radio bearer corresponding to the NAS session to enable the terminal device to determine the NAS session corresponding to the NAS message.

[0105] Optionally, in this implementation, the access network device receiving the fourth NAS message from the third network element may include: the access network device receiving the fourth NAS message and an identifier of a third NAS session from the third network element. Based on this, the access network device determining that the fourth NAS message belongs to the third NAS session includes: the access network device determining, based on the identifier of the third NAS session, that the fourth NAS message belongs to the third NAS session.

[0106] Optionally, in this implementation, the access network device receiving the fourth NAS message from the third network element may include: the access network device receiving the fourth NAS message and a third identifier from the third network element, where the third identifier is used to indicate a context of a third NAS session in the access network device. Based on this, the access network device determining that the fourth NAS message belongs to the third NAS session includes: the access network device determining, based on the third identifier, that the fourth NAS message belongs to the third NAS session.

[0107] Based on the communication method provided in the embodiments of the present application, after receiving a NAS message from a core network element, the access network device can also determine the NAS session corresponding to the NAS message. One possible method is that the core network element sends the identifier of the NAS session together with the NAS message to the access network device, and the access network device can directly determine the NAS session corresponding to the NAS message based on the identifier of the NAS session. Another possible method is that the core network element sends the identifier of the context of the NAS session in the access network device together with the NAS message to the access network device, and the access network device can determine the NAS session corresponding to the NAS message based on the context of the NAS session in the access network device.

[0108] In a possible implementation, the method further includes: the access network device receiving a fourth NAS message and an identifier of a third NAS session from a third network element, and the access network device sending the fourth NAS message and the identifier of the third NAS session to the terminal device.

[0109] Based on this solution, the access network device can directly forward the fourth NAS message and the identifier of the third NAS session from the third network element to the terminal device.

[0110] Optionally, in this implementation, the access network device may further determine, according to the identifier of the third NAS session, that the fourth NAS message belongs to the third NAS session.

[0111] In one possible implementation, the method further includes: the access network device receiving a third request message, the third request message being used to request the establishment of a third NAS session, where the third NAS session is used to transmit NAS messages between the terminal device and a third network element. The access network device then sends a third response message to the third network element, the third response message including address information of the access network device and a third identifier, where the third identifier indicates the context of the third NAS session in the access network device. Optionally, the third request message may include an identifier for the third NAS session and address information of the third network element. In this case, the access network device may send the third response message to the third network element based on the address information of the third network element.

[0112] Based on this solution, in order to establish the third NAS session, the access network device can allocate a context identifier (i.e., a third identifier) ​​for the third NAS session, and send its own address information and the context identifier of the third NAS session to the third network element, thereby establishing a direct connection channel between the access network device and the third network element.

[0113] In one possible implementation, the method further includes: the access network device receiving a fourth request message from the third network element, the fourth request message being used to request configuration of a radio bearer corresponding to each of the one or more QoS flows included in the third NAS session. The access network device configuring, based on the fourth request message, a radio bearer corresponding to each QoS flow.

[0114] Based on this solution, the access network device can configure corresponding radio bearers for the QoS flows included in the third NAS session, so that NAS messages transmitted through the third NAS session can be transmitted through different radio bearers based on the corresponding QoS flows, thereby preventing message congestion that may be caused by all NAS messages transmitted through the third NAS session being mixed and transmitted in the same channel.

[0115] In one possible implementation, the method further includes: the access network device receiving a fourth NAS message and identification information of a QoS flow corresponding to the fourth NAS message from a third network element, wherein the one or more QoS flows included in the third NAS session include the QoS flow corresponding to the fourth NAS message. Furthermore, the access network device determines, based on the identification information of the QoS flow corresponding to the fourth NAS message, a radio bearer corresponding to the fourth NAS message, and sends the fourth NAS message to the terminal device via the radio bearer.

[0116] Based on this solution, if the access network device determines that the QoS flow corresponding to the received downlink NAS message is one of the QoS flows included in the NAS session, the access network device can further send a downlink NAS message to the terminal device through the radio bearer corresponding to the QoS flow based on the correspondence between the configured QoS flow and the radio bearer, so that the terminal device can determine the QoS flow corresponding to the downlink NAS message based on the radio bearer on which the downlink NAS message is received.

[0117] In a fifth aspect, a communication method is provided, which can be executed by an access network device, or by a component of the access network device (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can realize all or part of the functions of the access network device. The following is an illustration of the method using the access network device as the execution subject, and the method includes: the access network device receives a fourth request message from the second network element, and the fourth request message is used to request the configuration of a radio bearer corresponding to each QoS flow in one or more QoS flows included in the second NAS session. The second NAS session is used to transmit NAS messages between the terminal device and the second network element. Furthermore, the access network device configures a corresponding radio bearer for each QoS flow based on the fourth request message. Then, the access network device sends a third message to the terminal device, and the third information is used to configure the radio bearer corresponding to each QoS flow.

[0118] Based on this solution, the access network device can configure corresponding radio bearers for the QoS flows included in the second NAS session, so that NAS messages transmitted through the second NAS session can be transmitted through different radio bearers based on the corresponding QoS flows, thereby preventing message congestion caused by all NAS messages transmitted through the second NAS session being mixed and transmitted in the same channel.

[0119] In one possible implementation, the fourth request message further includes a mapping rule, where the mapping rule includes a correspondence between the NAS message transmitted via the second NAS session and each QoS flow. In this implementation, the method further includes: the access network device sending the mapping rule to the terminal device.

[0120] Based on this solution, the terminal device can determine which QoS flow the NAS message to be sent corresponds to based on the mapping rule, and further determine the radio bearer corresponding to the QoS flow based on the third information.

[0121] In one possible implementation, the method further includes: the access network device receiving a first NAS message from the terminal device. Subsequently, the access network device determines, based on a radio bearer used to transmit the first NAS message, that the first NAS message corresponds to a first QoS flow and that the second NAS session includes the first QoS flow, and thereby sends the first NAS message and identification information of the first QoS flow to the second network element.

[0122] Based on this solution, the access network device can determine the QoS flow corresponding to the NAS message and the destination network element of the NAS message based on the radio bearer of the received NAS message. When the terminal device sends a NAS message to the destination network element of the NAS message, it can also send the identification information of the QoS flow to indicate the QoS flow corresponding to the NAS message.

[0123] In one possible implementation, the method further includes: receiving, by the access network device, a first NAS message and identification information of a first QoS flow corresponding to the first NAS message from the terminal device, wherein the second NAS session includes the first QoS flow; and sending, by the access network device, the first NAS message and the identification information of the first QoS flow to the second network element.

[0124] Based on this solution, if the terminal device sends the identification information of the QoS flow corresponding to the NAS message when sending the NAS message, the access network device can directly determine the session corresponding to the NAS message and the destination network element of the NAS message based on the identification information of the QoS flow corresponding to the NAS message, thereby sending the NAS message and the identification information of the QoS flow corresponding to the NAS message to the destination network element of the NAS message.

[0125] In one possible implementation, the method further includes: the access network device receiving a second NAS message and identification information of a second QoS flow corresponding to the second NAS message from the second network element. The access network device determines a radio bearer corresponding to the second QoS flow based on the identification information of the second QoS flow. The access network device sends the second NAS message to the terminal device via the radio bearer corresponding to the second QoS flow.

[0126] Based on this solution, after receiving a downlink NAS message, the access network device can send the NAS message to the terminal device through the radio bearer corresponding to the downlink NAS message, so that the terminal device can determine the QoS flow corresponding to the NAS message based on the radio bearer of the received NAS message.

[0127] In a sixth aspect, a communication device is provided for implementing the various methods described above. The communication device includes modules, units, or means corresponding to the methods described above. The modules, units, or means may be implemented in hardware, software, or by hardware executing corresponding software implementations. The hardware or software includes one or more modules or units corresponding to the functions described above.

[0128] In some possible designs, the communication device may include a transceiver module and a processing module. The transceiver module, which may also be referred to as a transceiver unit, is configured to implement the sending and / or receiving functions described in the first, second, third, fourth, or fifth aspects and any possible implementations thereof. The transceiver module may be comprised of a transceiver circuit, a transceiver, a transceiver, or a communication interface. The processing module may be configured to implement the processing functions described in the first, second, third, fourth, or fifth aspects and any possible implementations thereof.

[0129] In some possible designs, the transceiver module includes a sending module and a receiving module, which are respectively used to implement the sending and receiving functions in the above-mentioned first aspect, second aspect, third aspect, fourth aspect or fifth aspect and any possible implementation methods thereof.

[0130] In the seventh aspect, a communication device is provided, comprising: a processor and a communication interface; the communication interface is used to communicate with a module outside the communication device; the processor is used to execute a computer program or instruction so that the communication device executes any of the methods described above.

[0131] In an eighth aspect, a communication device is provided, comprising: at least one processor; the processor is configured to execute a computer program or instruction stored in a memory, so that the communication device performs the method of any of the above aspects. In one possible implementation, the memory may be coupled to the processor, or may be independent of the processor. In another possible implementation, the communication device further includes the memory. Optionally, the memory and the processor are integrated.

[0132] In aspects 5 to 8, the communication device may be the terminal device in the first aspect or any implementation of the first aspect, or a device including the terminal device, or a device included in the terminal device, such as a chip. Alternatively, the communication device may be the first network element in the second aspect or any implementation of the second aspect, or a device including the first network element, or a device included in the first network element, such as a chip. Alternatively, the communication device may be the second network element in the third aspect or any implementation of the third aspect, or a device including the second network element, or a device included in the second network element, such as a chip. Alternatively, the communication device may be the access network device in the fourth aspect or any implementation of the fourth aspect, or the fifth aspect or any implementation of the fifth aspect, or a device including the access network device, or a device included in the access network device, such as a chip or a chip system.

[0133] In the ninth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is run on a communication device, the communication device can execute any of the above aspects or any of its implementation methods.

[0134] In a tenth aspect, a computer program product comprising instructions is provided, which, when executed on a communication device, enables the communication device to execute the method of any of the above aspects or any of its implementations.

[0135] In the eleventh aspect, a communication device is provided (for example, the communication device may be a chip or a chip system), which includes a processor for implementing the functions involved in any of the above aspects or any of its implementation methods.

[0136] In some possible designs, the communication device includes a memory for storing necessary program instructions and data.

[0137] In some possible designs, when the device is a chip system, it can be composed of a chip, or it can also include a chip and other discrete devices.

[0138] It can be understood that when the communication device provided in any one of the sixth to eighth aspects is a chip, the above-mentioned sending action / function can be understood as output, and the above-mentioned receiving action / function can be understood as input.

[0139] Among them, the technical effects brought about by any implementation method in the sixth to eleventh aspects can refer to the technical effects brought about by the corresponding implementation methods in the first to fifth aspects, and will not be repeated here.

[0140] It should be noted that various possible implementations of any of the above aspects can be combined under the premise that the solutions are not contradictory.

[0141] In a twelfth aspect, a communication system is provided, comprising a first network element and a second network element. The first network element is configured to execute the method of the second aspect or any implementation thereof. The second network element is configured to execute the method of the third aspect or any implementation thereof.

[0142] In some possible designs, the communication system also includes a terminal device, which is further used to execute the method of the above-mentioned first aspect or any implementation method of the above-mentioned first aspect.

[0143] In some possible designs, the communication system also includes an access network device, which is used to execute the method of the fourth aspect above, or any implementation method of the fourth aspect above, or the fifth aspect above, or any implementation method of the fifth aspect above. BRIEF DESCRIPTION OF THE DRAWINGS

[0144] FIG1 is a schematic diagram of the current NAS message transmission mechanism;

[0145] FIG2 is a schematic diagram of the architecture of a communication system applicable to an embodiment of the present application;

[0146] FIG3 is an interactive diagram of a communication method provided in an embodiment of the present application;

[0147] FIG4 is a schematic diagram of an exemplary process of a communication method provided in an embodiment of the present application;

[0148] FIG5 is an interactive diagram of another communication method provided in an embodiment of the present application;

[0149] FIG6 is an interactive diagram of another communication method provided in an embodiment of the present application;

[0150] FIG7 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0151] FIG8 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0152] In order to facilitate understanding of the technical solutions of the embodiments of the present application, a brief introduction to the relevant technologies of the present application is first given as follows.

[0153] 1. NAS message transmission mechanism in 5G:

[0154] 5G introduces a service-oriented architecture in the core network control plane. The network functions of the service-oriented control plane, such as AMF network elements, session management function (SMF) network elements, and other network elements, are based on service-oriented interfaces. Based on the service-oriented interface, each core network control plane network element can communicate directly with each other. However, the interface used between the terminal device or access network (AN) device and the core network is still a non-service-oriented interface. Among them, the terminal device communicates with the AMF network element through the N1 interface, and the access network device communicates with the AMF network element through the N2 interface. At present, NAS messages between terminal devices and core network network elements, and messages between access network devices and core network elements (which can be called N2 messages) all need to be transmitted through the AMF network element.

[0155] NAS messages include different types. The NAS message used for mobility management (MM) between the terminal device and the AMF network element can be called NAS-MM (NAS for mobility management). The NAS message used for session management (SM) between the terminal device and the SMF network element can be called NAS-SM (NAS for session management) message. Short messages (SMS) are transmitted between the terminal device and the short message service function (SMSF) network element via NAS messages. The policy information (policy) of the terminal device, etc. is transmitted between the terminal device and the policy control function (PCF) network element via NAS messages.

[0156] For example, the current NAS message transmission mechanism is shown in Figure 1. NAS messages are transmitted between terminal devices and AMF network elements using the NAS protocol. The NAS messages sent by the terminal device to the AMF network element may include not only messages sent to the AMF network element (e.g., NAS-MM messages), but also messages destined for other network elements, such as NAS-SM messages sent to SMF network elements, SMS messages sent to SMSF network elements, information related to terminal device policies sent to PCF network elements, and information related to location services (LCS) sent to the location management function (LMF). The terminal device transmits the NAS message to the AMF network element. After receiving the NAS message, the AMF network element forwards the information required to be sent to other network elements via the interface between the AMF and the corresponding network element. For example, the AMF network element sends the NAS-MM message in the NAS message to the SMF network element via the N11 / Nsmf interface. The AMF network element sends the SMS message in the NAS message to the SMSF network element via the N20 / Nsmf interface. The AMF network element sends the terminal device policy-related information in the NAS message to the PCF network element through the N15 / Npcf interface. The AMF network element sends the LCS-related information in the NAS message to the LMF network element through the NL1 / Nlmf interface.

[0157] Similarly, N2 messages between access network devices and core network elements also need to be transferred through AMF network elements. For example, N2 messages between access network devices and SMF network elements, namely N2 SM (N2 session management) messages, need to be transmitted through AMF network elements.

[0158] However, this approach, where both NAS and N2 messages are transmitted by the AMF network element, presents the following issues. First, this approach makes other core network elements dependent on the AMF network element, which is inconsistent with the principle of functional decoupling between network elements in a service-oriented architecture. For example, when new N2 and / or NAS message types are added, this approach also requires corresponding enhancements to the AMF network element. Second, AMF network elements are typically deployed at a higher location. When the target core network element for N2 / NAS messages (such as the SMF / LMF network element) is deployed at the edge, forwarding the N2 / NAS messages by the AMF network element can cause message detours and fail to meet the requirements of some low-latency scenarios. Furthermore, some scenarios require that messages not leave the campus. When the AMF network element is deployed in the operator network, while access network equipment, SMF / LMF, and other network elements are deployed within the campus, if messages are forwarded by the AMF network element, the requirement of messages not leaving the campus cannot be met, potentially posing security risks.

[0159] Based on the above problems, the embodiments of the present application provide a communication method, device and system that can improve the transmission efficiency of NAS messages, and can also improve the flexibility of the network architecture and the security of NAS message transmission.

[0160] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Among them, in the description of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B; "and / or" in the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.

[0161] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information (such as the first indication information or the second indication information below) is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein the other information and the information to be indicated have an association relationship. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.

[0162] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0163] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. The sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.

[0164] In an embodiment of the present application, "pre-definition", "pre-defined", "pre-configured" or "pre-configured" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device. For example, it can be burned into the device when the device leaves the factory. The embodiment of the present application does not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, which is not limited by the embodiment of the present application.

[0165] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.

[0166] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.

[0167] The technical solution provided in this application can be used in various communication systems, which can be a third generation partnership project (3GPP) communication system, for example, a 4th generation (4G) mobile communication system, a long term evolution (LTE) system, a 5G mobile communication system and its evolution system, a non-terrestrial network (NTN), a multiple-input multiple-output (MIMO) system, a vehicle to everything (V2X) system, a LTE and new radio (NR) hybrid networking system, or a device to device (D2D) system, a machine to machine (M2M) communication system, an Internet of Things (IoT), or a future-oriented evolution system. In addition, the term "system" and "network" can be used interchangeably.

[0168] It should be noted that the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0169] FIG2 is a schematic diagram of the architecture of a possible, non-limiting communication system applicable to embodiments of the present application. As shown in FIG2 , the communication system 10 includes at least one access network device 100 and at least one terminal device 101 ( FIG2 uses an access network device and a terminal device as an example). The communication system 10 also includes core network elements: a first network element 102 and at least one second network element 103 ( FIG2 uses a second network element as an example).

[0170] The terminal device 101 can be wirelessly connected to the access network device 100. The access network device 100 can be wired or wirelessly connected to the first network element 102 and the second network element 103. The first network element 102 and the second network element 103 can be wired or wirelessly connected.

[0171] Optionally, the communication system 10 may further include other network elements or devices not shown, such as wireless relay devices and / or wireless backhaul devices, etc., which are not specifically limited in the embodiments of the present application.

[0172] In the communication system 10, a NAS session (referred to as a first NAS session) may be established between a first network element and a terminal device. After the first network element and the terminal device establish the first NAS session, the terminal device may further establish a NAS session (referred to as a second NAS session) with a second network element based on the technical solution provided in this application. NAS messages may then be transmitted between the terminal device and the second network element via the second NAS session without the need for the first network element to relay the NAS messages.

[0173] The specific implementation and technical effects of the technical solution provided in this application will be described in detail in the subsequent method embodiments and will not be elaborated here.

[0174] The embodiments of the present application do not impose specific restrictions on the first network element or the second network element. Exemplarily, the first network element may be an AMF network element in a 5G system, or a network element in a future communication system. Wherein, if the first network element is an AMF network element, a first NAS session is established between the terminal device and the first network element, which is equivalent to the terminal device communicating with the first network element through the N1 interface. The second network element may be any network element different from the first network element, for example, it may be an SMF network element, a PCF network element, an SMSF network element or an LMF network element in a 5G system, or it may be a network element in a future communication system, such as an artificial intelligent (AI) agent network element. Wherein, it can be understood that if the second network element is not an AMF network element, the establishment of a second NAS session between the terminal device and the second network element can be considered as communication between the terminal device and the second network element through a new interface.

[0175] The access network device in the embodiment of the present application refers to a RAN node (or device) that connects a terminal device to a wireless network. In some network architectures, the access network device may be a base station. Currently, examples of some access network devices include: the next generation node B (gNB), a transmission reception point (TRP), an evolved node B (eNodeB / eNB), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home evolved node B (HNB), a base band unit (BBU), or a wireless fidelity (Wifi) access point (AP).

[0176] In addition, in a network structure, multiple access network devices collaborate to assist terminal devices in achieving wireless access, and different access network devices respectively implement part of the functions of the base station. For example, the access network device can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0177] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open access network (open RAN, O-RAN or ORAN), CU may also be called O-CU (open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0178] All or part of the functions of the access network device in this application may also be implemented through software functions running on hardware, or through virtualization functions instantiated on a platform (such as a cloud platform). The access network device in this application may also be a logical node, logical module, or software that can implement all or part of the functions of the access network device.

[0179] The terminal device in the embodiments of the present application may also be referred to as a terminal, user equipment (UE), mobile station (MS), or mobile terminal, and is a device with wireless transceiver capabilities. The terminal device can be widely used in various scenarios, such as V2X, machine-type communication (MTC), IoT, virtual reality (VR), augmented reality (AR), industrial control, self-driving, remote medical surgery, smart grid, smart home, smart office, smart bracelet, and smart city. Currently, some examples of terminal devices include mobile phones, tablet computers, computers with wireless transceiver capabilities, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, and smart home appliances. The embodiments of the present application do not limit the device form factor of the terminal device.

[0180] The core network network element in the embodiment of the present application refers to the equipment in the core network that provides service support for the terminal equipment, such as AMF network element, SMF network element, etc., which are not listed here one by one. The specific functions of these core network network elements can be referred to the existing protocols and will not be repeated here.

[0181] In the embodiment of the present application, a network element may also be referred to as an entity or a functional entity. For example, a first network element may also be referred to as a first entity or a first functional entity.

[0182] The communication method provided in the embodiment of the present application will be described in detail below with reference to FIG2 .

[0183] It should be noted that the names of the messages between the network elements or the names of the parameters in the messages in the following embodiments of the present application are only examples, and other names may be used in specific implementations. The embodiments of the present application do not specifically limit this.

[0184] It is understood that in the embodiments of the present application, each network element may perform some or all of the steps in the embodiments of the present application. These steps or operations are merely examples, and the embodiments of the present application may also perform other operations or variations of various operations. In addition, the steps may be performed in a different order than those presented in the embodiments of the present application, and it is possible that not all operations in the embodiments of the present application need to be performed.

[0185] As shown in Figure 3, a communication method is provided for an embodiment of the present application. Figure 3 illustrates the method by taking the terminal device and the first network element as the execution subjects of the interaction diagram as an example, but the present application does not limit the execution subjects of the interaction diagram. For example, the first network element in Figure 3 may also be a module such as a chip, a chip system, or a processor applied to the first network element, or a logical node, a logical module, or software that can realize all or part of the functions of the first network element; the second network element in Figure 3 may also be a module such as a chip, a chip system, or a processor applied to the first network element, or a logical node, a logical module, or software that can realize all or part of the functions of the second network element; the terminal device in Figure 3 may also be a module such as a chip, a chip system, or a processor applied to the terminal device, or a logical node, a logical module, or software that can realize all or part of the functions of the terminal device.

[0186] As shown in FIG3 , the communication method includes steps S301 to S303:

[0187] S301: A terminal device sends a first request message to a first network element via a first NAS session. The first request message is used to request a service. In response, the first network element receives the first request message. The service requested by the first request message is provided by a second network element. The first NAS session is used to transmit NAS messages between the terminal device and the first network element.

[0188] S302: The first network element triggers the establishment of a second NAS session, wherein the second NAS session is used to transmit NAS messages between the terminal device and the second network element.

[0189] S303: A second NAS session is established between the second network element and the terminal device.

[0190] It should be understood that the first NAS session is an exemplary name for a NAS session established between a first network element and a terminal device in the embodiments of this application. Similarly, the second NAS session is an exemplary name for a NAS session established between a second network element and a terminal device. Other names may be used in specific implementations and are not specifically limited in the embodiments of this application. For example, the first NAS session may also be referred to as a NAS primary session, and the second NAS session may also be referred to as a NAS subsession.

[0191] Based on the communication method provided in the embodiment of the present application, the terminal device can establish a second NAS session with the second network element after having established a first NAS session with the first network element. Compared with the solution in which the NAS message is relayed by the first network element, the transmission efficiency of the NAS message is improved. In addition, in this solution, the NAS message transmitted between the second network element and the terminal device does not depend on the first network element. It can not only match the principle of functional decoupling between network elements and improve the flexibility of the network architecture, but also improve the security of NAS message transmission. For example, when the first network element is deployed in the operator network and the second network element and the access network equipment are deployed in the park, the present solution is used to transmit the NAS message between the terminal device and the second network element. This can meet the requirement that the message does not leave the park, and improves the security of the NAS message compared to the solution in which the NAS message is relayed by the first network element.

[0192] The following is an introduction to S301-S303 respectively.

[0193] In S301, the first request message is transmitted via the first NAS session. That is, before the terminal device sends the first request message, a first NAS session is established between the terminal device and the first network element.

[0194] The first NAS session established between the terminal device and the first network element can be understood as a communication connection established between the terminal device and the access network device, such as a radio resource control (RRC) connection, and a communication connection established between the access network device and the first network element, such as a signaling connection, so that the access network device forwards NAS messages between the terminal device and the first network element.

[0195] The establishment of the first NAS session is described below.

[0196] Optionally, the establishment of the first NAS session may be triggered by a first NAS session establishment request message sent by the terminal device to the first network element.

[0197] Optionally, after triggering the establishment of the first NAS session, the first network element may determine whether to allow the establishment of the first NAS session. For example, the first network element may authenticate and authorize the terminal device (for example, authentication and authorization may be performed based on the contract information of the terminal device) to determine whether to allow the terminal device to establish the first NAS session.

[0198] Optionally, during the process of establishing the first NAS session, the first network element may enable security for the first NAS session. For methods of enabling security for the first NAS session, reference may be made to the NAS security mode-related procedures between the AMF network element (corresponding to the first network element) and the terminal device in the prior art, such as a NAS security mode command.

[0199] In one possible scenario, the process for establishing the first NAS session can refer to an existing registration process, such as the registration process in a 5G system. In other words, the terminal device can initiate the establishment of the first NAS session through the registration process. In this case, the registration request message sent by the terminal device is equivalent to the first NAS session establishment request message, which can request the establishment of the first NAS session. The registration process can be specifically referred to in existing standard protocols and will not be detailed here.

[0200] Optionally, the first NAS session may be identified by identification information (hereinafter referred to as the identifier of the first NAS session). In one possible implementation, the identifier of the first NAS session may be allocated by the terminal device, and the terminal device may send the identifier of the first NAS session to the first network element. For example, the terminal device may carry the identifier of the first NAS session in the first NAS session establishment request message. In another possible implementation, the identifier of the first NAS session may be allocated by the first network element, and the first network element may send the identifier of the first NAS session to the terminal device. For example, the first network element may carry the identifier of the first NAS session in a response message to the first NAS session establishment request message and send it to the terminal device.

[0201] Furthermore, the first network element may send the correspondence between the identifier of the first NAS session and the information of the first network element to the access network device. The access network device may store the received correspondence in the context of the terminal device for subsequent forwarding of NAS messages between the first network element and the terminal device (i.e., messages that need to be transmitted through the first NAS session). The specific implementation of the access network device forwarding NAS messages between the first network element and the terminal device based on the correspondence will be described later and will not be elaborated here.

[0202] The information of the first network element may include address information of the first network element, such as a fully qualified domain name (FQDN) or an Internet Protocol (IP) address of the first network element, and identification information indicating the context of the first NAS session in the first network element, such as a character string.

[0203] Exemplarily, if the interface between the access network device and the first network element is a service-based interface, the information of the first network element may be a uniform resource locator (URL), the host name of the URL being the FQDN or IP address of the first network element, and the URL including identification information indicating the context of the first NAS session in the first network element. If the interface between the access network device and the first network element is based on the stream control transmission protocol (SCTP), the information of the first network element may include address information of the first network element (e.g., an IP address) and an identifier indicating the context of the first NAS session in the first network element, such as a next generation application protocol (NGAP) user equipment identification number (NGAP UE ID) assigned by the first network element. In the above example, the identification information indicating the context of the first NAS session in the first network element may also be identification information of the terminal device, such as a temporary identifier assigned by the first network element to the terminal device.

[0204] Optionally, the access network device may configure a corresponding radio bearer (RB) for the first NAS session. The first NAS session may correspond to one or more radio bearers. In one possible implementation, the access network device may assign corresponding identification information (hereinafter referred to as an RB identifier) ​​to each radio bearer corresponding to the first NAS session. For example, the RB identifier may be a media access control (MAC) layer channel identifier (MAC channel ID).

[0205] Optionally, the access network device may further send information for configuring a radio bearer corresponding to the first NAS session to the terminal device. After receiving the information, the terminal device may subsequently send a NAS message to the first network element via the radio bearer corresponding to the first NAS session.

[0206] Optionally, if the access network device also obtains the correspondence between the identifier of the first NAS session and the information of the first network element, the access network device can save the correspondence between the identifier of the first NAS session, the information of the first network element and the radio bearer corresponding to the first NAS session.

[0207] In one possible scenario, the radio bearer corresponding to the first NAS session can be used by the access network device to forward NAS messages between the first network element and the terminal device. The specific implementation will be introduced later and will not be expanded here.

[0208] The above describes the establishment of the first NAS session. After the first NAS session is established, the terminal device sends a first request message to the first network element via the first NAS session. It is understood that sending the first request message via the first NAS session includes: the terminal device sending the first request message to the access network device, and the access network device, after receiving the first request message, sending the first request message to the first network element.

[0209] In conjunction with the above description of the method for transmitting the NAS message through the first NAS session, the terminal device may send the first request message through the first NAS session in the following possible manner:

[0210] The terminal device sends an RRC message to the access network device, where the RRC message includes the first request message. Furthermore, the RRC message is sent via the radio bearer corresponding to the first NAS session, and / or the RRC message includes an identifier of the first NAS session. The access network device may determine to send the first request message to the first network element based on the radio bearer corresponding to the first NAS session and / or the identifier of the first NAS session. For details, please refer to the above description and will not be elaborated here.

[0211] After receiving the first request message, the first network element can determine the second network element based on the first request message. Specifically, the first network element determines one or more network elements that can provide services based on the first request message. Further, the first network element determines a network element to provide services to the terminal device. The network element that actually provides services to the terminal device is the second network element.

[0212] In S302, after the first network element receives the first request message, the first network element may trigger the establishment of a second NAS session, where the second NAS session is used to transmit NAS messages between the terminal device and the second network element. In other words, the first network element may trigger the establishment of a second NAS session between the second network element and the terminal device.

[0213] The second NAS session established between the terminal device and the second network element can be understood as follows: a communication connection, such as an RRC connection, is established between the terminal device and the access network device; and a communication connection, such as a signaling connection, is established between the access network device and the second network element. As a result, the access network device forwards NAS messages between the terminal device and the second network element, and the first network element does not need to forward NAS messages between the terminal device and the second network element.

[0214] The following describes how to trigger the establishment of a second NAS session.

[0215] In the embodiment of the present application, the first request message may include the following three situations. The following describes the specific implementation of the first network element triggering the establishment of the second NAS session in combination with different situations:

[0216] Case 1: The first request message is used to request a service, and does not request to establish a NAS session between the terminal device and the second network element.

[0217] In case 1, the service can be any type of network service, and the embodiment of the present application does not limit this.

[0218] For example, the first request message may be a protocol data unit (PDU) session establishment request. In this case, the second network element may be an SMF network element. Alternatively, the first request message may be a UE policy session establishment request. In this case, the second network element may be a PCF network element. Alternatively, the first request message may be a positioning request message. In this case, the second network element may be an LMF network element. Alternatively, the first request message may request an AI service. In this case, the second network element may be a network element capable of providing AI services, such as an AI proxy network element.

[0219] In one possible implementation of Case 1, the first network element may determine that a second NAS session needs to be established and trigger the establishment of the second NAS session based on at least one of the following information: the subscription information of the terminal device, the deployment location of the first network element, and so on. For example, the subscription information of the terminal device includes the subscription information of the service requested by the first request message, and the subscription information of the service indicates that the NAS message corresponding to the service does not leave the campus. The first network element may determine that a second NAS session needs to be established based on its own deployment location not being in the campus, so as to facilitate direct transmission of NAS messages between the second network element and the terminal device. In this example, the first network element may select a network element deployed within the campus as the second network element for the second NAS session.

[0220] In another possible implementation of scenario 1, after receiving the first request message, the first network element may send a fifth request message (which may be the first request message or a request message generated by the first network element to request a service) to the second network element. Based on the fifth request message, the second network element may determine that a second NAS session needs to be established and send fourth information to the first network element, where the fourth information is used to instruct the first network element to establish the second NAS session. In this implementation, the first network element may trigger the establishment of the second NAS session based on the fourth information.

[0221] For example, assuming the first request message is a positioning request message, after receiving the first request message, the second network element determines that a second NAS session needs to be established to facilitate transmission of the terminal device's location information via the second NAS session. Based on this, the second network element sends a fourth message to the first network element, instructing it to establish the second NAS session.

[0222] Case 2: The first request message is used to request a service, and the first request message is also used to request establishment of a NAS session between the terminal device and the second network element. For example, the first request message includes instruction information requesting establishment of a second NAS session.

[0223] In case 2, the service requested by the first request message can refer to the above introduction to case 1, which will not be repeated here.

[0224] In scenario 2, the first network element may determine, based on the first request message, that it needs to provide the service and also determine that it needs to establish a second NAS session. That is, in this implementation, the first network element may trigger the establishment of the second NAS session based on the first request message. For example, the first network element may determine that it needs to establish the second NAS session based on the instruction information included in the first request message requesting the establishment of the second NAS session.

[0225] In case 1 or case 2, after the second NAS session is established, the NAS message transmitted through the second NAS session can be a NAS message related to the service (i.e., the service requested by the first request message), that is, the second NAS session provides a NAS signaling channel between the terminal device and the second network element for the service.

[0226] In case 3, the first request message is used to request the establishment of a NAS session between the terminal device and the second network element. In case 3, the first request message may also be referred to as a second NAS session establishment request message. In case 3, the second NAS session is used to provide a NAS signaling channel between the terminal device and the second network element. The NAS signaling channel is used to transmit NAS messages related to the service provided by the second network element.

[0227] In the third scenario, the first network element may directly determine, based on the first request message, that a second NAS session needs to be established and trigger the establishment of the second NAS session.

[0228] The above describes different situations of the first request message and how to trigger the establishment of the second NAS session in different situations. In addition, the embodiment of the present application also provides some optional solutions related to triggering the establishment of the second NAS session.

[0229] Optionally, the first request message may further indicate the type of the second NAS session. For example, the first request message may include information indicating the type of the second NAS session. The type of the second NAS session may correspond to the service provided by the second network element. For example, the second NAS session type may be a session-type NAS session. In this case, the corresponding service (i.e., the service provided by the second network element) is a session service (e.g., the second network element is an SMF network element and can provide a service for establishing a PDU session). For another example, the second NAS session type may be a positioning-type NAS session. In this case, the corresponding service is a positioning service (e.g., the second network element is an LMF network element and can provide a positioning service).

[0230] Optionally, the first request message may further include other relevant information of the second NAS session. The first network element does not process this information, but sends it to the second network element (for example, it may be sent to the second network element together with the second request message described later). Exemplarily, when the first request message is used to request establishment of a PDU session, the first request message may include information such as a session and service continuity (SSC) mode and an IP address type of the PDU session.

[0231] Optionally, for determining the second network element, the first network element may select the second network element from network elements that can provide services based on the first information. The first information may also be referred to as network element selection information. The embodiments of the present application do not limit the first information. For example, the first network element may determine the first information from the information included in the first request message, or the first network element may determine the first information from the contract information of the terminal device, or the first network element may determine the first information from relevant information of the terminal device (such as the location information of the terminal device), etc.

[0232] For example, if the first request message requests to establish a PDU session, the first information may be the data network name (DNN), slice identifier, and other information included in the first request message. The first network element may select a suitable SMF network element as the second network element based on the first information.

[0233] For another example, when the contract information of the terminal device includes the first information, if the first request message includes the first information, the first network element may select a suitable network element as the second network element based on the intersection of the first information in the contract information of the terminal device and the first information included in the first request message. Optionally, the first information in the contract information of the terminal device may include default network element selection information. If the first request message does not include the first information, the first network element may select a suitable network element as the second network element based on the default network element selection information in the contract information of the terminal device. In one possible case, the first information in the contract information of the terminal device may correspond to the type of NAS session. The first network element may determine the first information of the contract corresponding to the type of the second NAS session based on the type of the second NAS session, and further select the second network element based on the corresponding first information of the contract.

[0234] For another example, the first network element may select, based on the location information of the terminal device, a network element that is closer to the location of the terminal device from the network elements that can provide services as the second network element.

[0235] Optionally, before the first network element triggers establishment of the second NAS session, the first network element may determine whether establishment of the second NAS session is permitted. If the first network element determines that establishment of the second NAS session is permitted, the first network element triggers establishment of the second NAS session and continues with subsequent processes. If the first network element determines that establishment of the second NAS session is not permitted, establishment of the second NAS session is not triggered.

[0236] Optionally, when the first request message requests establishment of a second NAS session (for example, the first request message is a second NAS session establishment request message, or the first request message includes indication information requesting establishment of a second NAS session), and the first network element determines that establishment of the second NAS session is not allowed, the first network element may send a response message to the terminal device indicating that establishment of the second NAS session failed.

[0237] Regarding determining whether to allow establishment of the second NAS session, in one possible implementation, the first network element may determine whether to allow establishment of the second NAS session based on the subscription information of the terminal device. For example, the subscription information of the terminal device may include the type of NAS sessions allowed to be established, and the first request message sent by the terminal device to the first network element indicates the type of the second NAS session. If the first network element determines that the type of the second NAS session is one of the allowed types of NAS sessions, then the first network element may determine to allow establishment of the second NAS session; if not, then the first network element may determine not to allow establishment of the second NAS session.

[0238] For another example, the subscription information of the terminal device may include information indicating services for which NAS sessions are permitted to be established. The first network element determines, based on the first request message and the subscription information of the terminal device, whether a NAS session can be established for the service requested by the terminal device. If the first network element determines that a NAS session can be established for the service requested by the terminal device, then the first network element may determine that establishment of the second NAS session is permitted. If the first network element determines that a NAS session cannot be established for the service requested by the terminal device, then the first network element may determine that establishment of the second NAS session is not permitted.

[0239] The above describes how to trigger the establishment of the second NAS session. The following describes the subsequent process after triggering the second NAS session.

[0240] Optionally, if the first network element triggers establishment of a second NAS session, the first network element may send a second request message to the second network element. The second request message may also be referred to as a second NAS session establishment request, which is used to request establishment of the second NAS session. Alternatively, it can be understood that the first network element sends the second request message to the second network element to trigger establishment of the second NAS session.

[0241] Optionally, the second request message may also request the service requested by the first request message, such as requesting to establish a PDU session, requesting information related to LCS, etc.

[0242] In one possible scenario, if the first network element receives the fourth information from the second network element, the first network element may not need to send the second request message to the second network element. In this case, after the first network element triggers the establishment of the second NAS session based on the fourth information, it can directly request the access network device to establish the second NAS session. For example, the fourth information may include information used to generate a third request message, such as the address information of the second network element, identification information for indicating the context of the second NAS session in the second network element, and other information. The first network element can generate a third request message based on the fourth information and send it to the access network device. The third request message requests the establishment of a second NAS session. For details, please refer to the introduction of establishing a direct transmission channel between the second network element and the access network device below, which will not be expanded here. In this case, the first network element can also send an identifier of the second NAS session to the second network element.

[0243] Alternatively, after the first network element receives the fourth information from the second network element, the first network element may also send a second request message to the second network element.

[0244] Optionally, the first network element may obtain an identifier of the second NAS session and send the identifier of the second NAS session to the second network element, where the identifier of the second NAS session is used to identify the second NAS session. For example, the second request message may include the identifier of the second NAS session, or the first network element may send the second request message together with the identifier of the second NAS session to the second network element.

[0245] In one possible implementation, the identifier of the second NAS session can be allocated by the terminal device. In this implementation, the terminal device can send the identifier of the second NAS session to the first network element, which then sends the identifier of the second NAS session to the second network element. For example, the first request message sent by the terminal device to the first network element includes the identifier of the second NAS session. For another example, the terminal device sends the identifier of the second NAS session together with the first request message to the first network element.

[0246] In another possible implementation, the identifier of the second NAS session may also be allocated by the first network element. After determining that the second NAS session needs to be established (for example, the first network element determines that the second NAS session needs to be established based on the first request message or the fourth information), the first network element may allocate the second NAS session identifier for the second NAS session.

[0247] It is understood that in order to determine the corresponding NAS session based on the NAS session identifier, in the embodiment of the present application, the NAS session and the NAS session identifier are in a one-to-one correspondence. In other words, when the terminal device or the first network element assigns an identifier to the NAS session, it is necessary to ensure the uniqueness of the identifier of each NAS session.

[0248] The following describes the specific implementation of establishing the second NAS session between the second network element and the terminal device in S303.

[0249] If the first network element sends a second request message to the second network element, after receiving the second request message, the second network element may determine to establish a second NAS session based on the second request message. Further, the second network element sends a first response message to the first network element in response to the second request message.

[0250] Among them, the first response message can have different uses in different situations, which will be introduced in combination with different situations in the following embodiments and will not be expanded here.

[0251] Optionally, after the second network element determines to establish a second NAS session (for example, the second network element determines to establish a second NAS session based on the first request message, or the second network element receives the second request message), it can obtain quality of service (QoS) information corresponding to the second NAS session, such as at least one of the following: QoS level (such as scheduling priority, QoS scale value (qos class identifier, QCI), 5G QoS identifier (5G QoS identifier, 5QI) or similar information used to indicate scheduling priority), maximum bandwidth, whether mapped to a data radio bearer (DRB) indication, or guaranteed bandwidth and other information, wherein the mapping to the DRB indication is used to indicate that the message of the second NAS session is transmitted through the DRB.

[0252] Among them, in one possible implementation, the second network element can determine the QoS information corresponding to the type of the second NAS session from the subscription information of the terminal device. The embodiment of the present application does not limit how the second network element determines the type of the second NAS session. For example, the second request message may include the type of the second NAS session. For another example, the second network element can determine the type of the corresponding NAS session based on the services it can provide. For example, if the second network element is an SMF network element and can establish a PDU session, then the second network element can determine the type of the second NAS session as "PDU session" or "NAS session established for PDU session".

[0253] It is understood that in order to establish the second NAS session, a direct transmission channel for NAS messages needs to be established between the second network element and the access network device. The following describes the specific implementation of establishing the direct transmission channel between the second network element and the access network device, taking the scenario in which the second network element receives the second request message as an example.

[0254] In a first possible implementation, the first response message sent by the second network element to the first network element includes a third request message. The third request message is used to request the access network device to establish a second NAS session. The third request message includes at least one of the following: address information of the second network element, identification information allocated by the second network element for the second NAS session and indicating the context of the second NAS session in the second network element, or an identifier of the second NAS session. Exemplarily, when the interface between the second network element and the access network device is a service-based interface, the identification information indicating the context of the second NAS session in the second network element may be a string or an identifier set by the second network element. When the interface between the second network element and the access network device is an SCTP interface, the identification information may be NGAP UE ID information allocated by the second network element. After receiving the first response message, the first network element forwards the third request message therein to the access network device. Based on the third request message, the access network device determines to establish a communication connection with the second network element. Furthermore, the access network device may store the correspondence between the identifier of the second NAS session and the address information of the second network element.

[0255] In a second possible implementation, the first response message sent by the second network element to the first network element includes second indication information, where the second indication information is used to indicate that the access network device needs to establish a second NAS session. After receiving the first response message, the first network element generates a third request message based on the second indication information and sends the third request message to the access network device. In this implementation, the first response message also includes information used to generate the third request message. The third request message can be described above for details. Based on the third request message, the access network device determines to establish a communication connection with the second network element. Furthermore, the access network device can store the correspondence between the identifier of the second NAS session and the address information of the second network element.

[0256] In a third possible implementation, the second network element directly sends a third request message to the access network device ("directly" means without being relayed by the first network element). For details about the third request message, refer to the above description. Based on the third request message, the access network device determines to establish a communication connection with the second network element. Furthermore, the access network device may store the correspondence between the identifier of the second NAS session and the address information of the second network element.

[0257] Optionally, in this implementation, the second request message sent by the first network element to the second network element may include the address information of the access network device (for example, the IP address of the access network device) and the first identifier, wherein the first identifier is used to indicate the context of the terminal device in the access network device. The second network element may determine the access network device based on the address information of the access network device, thereby directly sending a third request message to the access network device. The third request message may include the first identifier. After the access network device receives the third request message, it may save the correspondence between the identifier of the second NAS session and the address information of the second network element in the context of the terminal device based on the third request message. For example, the access network device may determine the context of the terminal device based on the first identifier in the third request message.

[0258] Optionally, in this implementation, the first identifier obtained by the first network element may be sent to the first network element by the access network device. For example, the access network device may allocate the first identifier for the context of the terminal device and send it to the first network element during the process of establishing the first NAS session.

[0259] Optionally, in the aforementioned multiple implementations of establishing a direct transmission channel between the second network element and the access network device, in addition to the address information of the second network element and the identifier of the second NAS session, the third request message may further include quality of service (QoS) information of the second NAS session. Accordingly, in the second implementation, the second network element is further required to send the QoS information of the second NAS session to the first network element via the first response message, so that the first network element can generate the third request message.

[0260] Furthermore, after the access network device receives the third request message and determines to establish a communication connection with the second network element, the access network device may send a third response message to the second network element in response to the third request message. The third response message includes address information of the access network device and a second identifier, where the second identifier is used to indicate the context of the second NAS session in the access network device. For example, the second identifier may be a string, or may be a RAN NGAP UE ID allocated by the access network device for the second NAS session.

[0261] The second network element may store the correspondence between the second identifier, the identifier of the second NAS session, and the address information of the access network device.

[0262] Regarding the access network device sending a third response message to the second network element, in the first and second possible implementation methods of establishing a direct transmission channel between the second network element and the access network device, the third response message can be sent to the second network element via the first network element. In the third possible implementation method, the third response message can be sent directly by the access network device to the second network element (without passing through the first network element).

[0263] At this point, a second NAS session is established between the terminal device and the second network element. NAS messages can be transmitted between the terminal device and the second network element through the access network device without the first network element relaying the NAS messages.

[0264] Optionally, if the second network element directly sends a third request message to the access network device to establish the second NAS session, the second network element may send a first response message to the first network element indicating that the second NAS session is successfully established after receiving the third response message.

[0265] Optionally, after receiving the third request message, the access network device may also allocate an interface identifier for the interface associated with the second NAS session between the access network device and the second network element. Furthermore, the access network device may also send the interface identifier to the second network element via a third response message, and the second network element may subsequently use the interface identifier to send downlink NAS messages. The interface identifier may correspond to the second identifier, or the interface identifier may be the second identifier.

[0266] For example, when the interface between the second network element and the access network device is a service-based interface, the interface identifier may be a URL that includes the address of the access network device and the second identifier. For another example, when the interface between the second network element and the access network device is an SCTP-based interface, the interface identifier may be a RAN NGAP UE ID assigned by the access network device for the second NAS session. The RAN NGAP UE ID may indicate the context of the second NAS session in the access network device.

[0267] Optionally, after receiving the third request message, the access network device may configure one or more corresponding radio bearers for the second NAS session. Each radio bearer corresponding to the second NAS session may have a corresponding RB identifier, such as a MAC channel ID.

[0268] The embodiments of the present application do not limit the specific implementation of the access network device configuring the corresponding radio bearer for the second NAS session. For example, if the third request message includes QoS information of the second NAS session, the access network device may configure the corresponding radio bearer for the second NAS session based on the QoS information of the second NAS session.

[0269] Optionally, the access network device may send, to the terminal device, second information for configuring a radio bearer corresponding to the second NAS session. After receiving the second information, the terminal device may subsequently send a NAS message to the second network element via the radio bearer corresponding to the second NAS session.

[0270] It is understood that the method for establishing a second NAS session between a terminal device and a second network element in the above embodiment can also be applied to establishing other NAS sessions between a terminal device and other network elements. In other words, a terminal device can establish different second NAS sessions with multiple second network elements.

[0271] The above describes the interaction between the access network device, the second network element and the first network element in the process of establishing the second NAS session. In addition, the first network element or the second network element can send a second NAS session establishment success indication or a second NAS session establishment indication to the terminal device to notify the terminal device of the establishment of the second NAS session. The second NAS session establishment success indication is used to indicate that the second NAS session is successfully established, and the second NAS session establishment indication is used to indicate the establishment of the second NAS session. In addition, the second NAS session establishment success indication or the second NAS session establishment indication is sent to the terminal device together with the identifier of the second NAS session. That is, in S303, the terminal device can receive at least one of the second NAS session establishment success indication or the second NAS session establishment indication, as well as the identifier of the second NAS session. The terminal device can determine that the second NAS session is successfully established based on the second NAS session establishment success indication and the identifier of the second NAS session. Alternatively, the terminal device can determine that a second NAS session needs to be established based on the second NAS session establishment indication and the identifier of the second NAS session.

[0272] According to the three different situations of the first request message in S301, the terminal device receives different indication information (i.e., the second NAS session establishment success indication or the second NAS session establishment indication), which are respectively described below:

[0273] In case 1, the terminal device does not request to establish the second NAS session. In this case, during the establishment of the second NAS session, the first network element or the second network element sends a second NAS session establishment indication to the terminal device, that is, the terminal device needs to be notified to establish the second NAS session.

[0274] In case 2 and case 3, the terminal device requests to establish a second NAS session. In these two cases, after the second NAS session is successfully established, the first network element or the second network element sends a second NAS session establishment success indication to the terminal device.

[0275] If the second network element sends an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device, in one possible implementation, when the second network element sends a third request message to the access network device (for example, the first network element forwards the third request message from the second network element to the access network device, or the second network element directly sends the third request message to the access network device), the second network element can send a second response message to the terminal device through the third request message. That is, the third request message includes the second response message that needs to be sent to the terminal device. After receiving the third request message, the access network device sends the second response message therein to the terminal device. The second response message includes an identifier of the second NAS session and at least one of the following: an indication of successful establishment of the second NAS session or an indication of establishment of the second NAS session.

[0276] If the first network element sends an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device, in one possible implementation, the first network element may, after receiving the first response message, send an indication of successful establishment of the second NAS session or an indication of establishment of a second NAS session to the terminal device based on the first response message. For example, the first response message indicates that the second NAS session is successfully established, and the first network element determines to send an indication of successful establishment of the second NAS session or an indication of establishment of a second NAS session to the terminal device based on the first response message. For another example, the first response message includes indication information instructing the terminal device to be notified of the successful establishment of the second NAS session, and the first network element sends an indication of successful establishment of the second NAS session or an indication of establishment of a second NAS session to the terminal device based on the indication information. When the first network element sends the indication of successful establishment of the second NAS session or an indication of establishment of a second NAS session to the terminal device, the first network element sends the indication of successful establishment of the second NAS session or the indication of establishment of a second NAS session together with an identifier of the second NAS session to the access network device, and the access network device sends the indication of successful establishment of the second NAS session or the indication of establishment of a second NAS session together with the identifier of the second NAS session to the terminal device. In another possible implementation, after receiving the fourth information, the first network element may send an indication of successful establishment of the second NAS session or a second NAS session establishment indication to the terminal device.

[0277] After the second NAS session is successfully established, NAS messages can be transmitted between the terminal device and the second network element through the second NAS session.

[0278] Optionally, in an uplink transmission scenario, after S303, S304 may be included:

[0279] S304: The terminal device sends a first NAS message to the second network element through the second NAS session according to the identifier of the second NAS session (the first NAS message may be any NAS message sent through the second NAS session).

[0280] Among them, the terminal device sends the first NAS message to the second network element through the second NAS session, including: the terminal device sends the first NAS message to the access network device, and the access network device forwards the first NAS message to the second network element. Specifically, when the terminal device sends the RRC message including the first NAS message to the access network device, it also sends the identifier of the second NAS session, and / or the terminal device determines the radio bearer corresponding to the second NAS session according to the identifier of the second NAS session, and sends the first NAS message to the access network device through the radio bearer. After receiving the first NAS message, the access network device can determine that the first NAS message is the NAS message corresponding to the second NAS session according to the identifier of the second NAS session or the radio bearer for receiving the first NAS message, and send the first NAS message to the second network element corresponding to the second NAS session. For details, please refer to the description of the uplink message transmission scenario of the third NAS session below.

[0281] Optionally, in a downlink transmission scenario, after S303, S305 may be included:

[0282] S305. The second network element sends a second NAS message to the terminal device through the second NAS session.

[0283] S305 includes: the second network element sending a second NAS message to the access network device, and the access network device forwarding the second NAS message to the terminal device. Specifically, when sending the second NAS message to the access network device, the second network element performs at least one of the following: sending the identifier of the second NAS session, sending the second identifier, or sending the second NAS message via an interface associated with the second NAS session. After receiving the second NAS message, the access network device may determine that the second NAS message corresponds to the second NAS session based on at least one of the following: the identifier of the second NAS session, the second identifier, or the identifier of the interface receiving the second NAS message. When sending the second NAS message to the terminal device, the access network device may send the identifier of the second NAS session and / or send the second NAS message to the terminal device via the radio bearer corresponding to the second NAS session. After receiving the second NAS message, the terminal device may determine that the second NAS session corresponds to the second NAS message based on the identifier of the second NAS session and / or the radio bearer receiving the second NAS message. For details, see the description of downlink message transmission of the third NAS session below.

[0284] It is understandable that, in the embodiment of the present application, a first NAS session is established between the terminal device and the first network element, and a second NAS session is also established between the terminal device and the second network element. Furthermore, the terminal device may also establish other NAS sessions with other network elements. When transmitting messages via NAS sessions, the access network device is required to forward NAS messages. Therefore, in scenarios where NAS messages are transmitted via NAS sessions, the access network device needs to determine the session to which the received NAS message belongs. In an uplink transmission scenario, the access network device can determine the NAS session to which the NAS message belongs based on the NAS session identifier received when receiving the NAS message and / or the radio bearer over which the NAS message is received, and further determine the destination network element of the NAS message based on the session to which the NAS message belongs, thereby forwarding the NAS message to the destination network element. In a downlink transmission scenario, after receiving the NAS message, the access network device can determine the session to which the NAS message belongs based on at least one of the following: an identifier of the received NAS session, an identifier indicating the context of the NAS session in the access network device, or an identifier of the interface through which the NAS message is received, and send the NAS message to the terminal device via the NAS session to which the NAS message belongs.

[0285] The following describes how an access network device determines the NAS session to which a NAS message belongs and sends the NAS message to the destination network element (NE) or terminal device, divided into uplink and downlink transmission scenarios.

[0286] In an uplink transmission scenario, after the terminal device sends a third NAS message (the third NAS message can be any NAS message) through a third NAS session (the third NAS session can be any NAS session established between the terminal device and the first network element, the second network element, or another network element), the access network device receives the third NAS message from the terminal device. The access network device can determine that the third NAS message belongs to the third NAS session and determine the destination network element of the third NAS message (the destination network element of the third NAS message can be referred to as the third network element), and then send the third NAS message to the destination network element.

[0287] In one possible implementation, the terminal device sends the identifier of the third NAS session together with the third NAS message to the access network device. After receiving the identifier of the third NAS session and the third NAS message, the access network device determines the destination network element of the third NAS message based on the identifier of the third NAS session and the first correspondence. The first correspondence is used to indicate that the identifier of the third NAS session corresponds to the destination network element of the third NAS message. For example, the first correspondence may include a correspondence between the identifier of the third NAS session and information of the destination network element of the third NAS message (e.g., identification information, address information, etc.). Furthermore, the access network device sends the third NAS message to the destination network element of the third NAS message.

[0288] When the terminal device sends the third NAS message and the identifier of the third NAS session to the access network device, the third NAS message and the identifier of the third NAS session may be carried in the same RRC message. Alternatively, the identifier of the third NAS session may be included as a non-encrypted field in the header of the third NAS message.

[0289] In another possible implementation, when the terminal device sends the third NAS message, the third NAS message can be sent to the access network device through the radio bearer corresponding to the third NAS session. After receiving the third NAS message, the access network device can determine the destination network element of the third NAS message based on the radio bearer used to transmit the third NAS message and the second correspondence. The second correspondence is used to indicate that the radio bearer used to transmit the third NAS message corresponds to the destination network element of the third NAS message. For example, the second correspondence may include a correspondence between an identifier of the radio bearer used to transmit the third NAS message, an identifier of the third NAS session, and information of the destination network element of the third NAS message (such as identifier information, address information, etc.). Further, the access network device sends the third NAS message to the destination network element of the third NAS message.

[0290] Among them, if the access network device determines the destination network element of the third NAS message through the RB identifier of the radio bearer used to transmit the third NAS message and the second correspondence, the access network device can determine the RB identifier based on the MAC channel ID of the third NAS message. Alternatively, the terminal device can carry the RB identifier in the message header that encapsulates the third NAS message. For example, when the third NAS message is encapsulated using the service data adaptation protocol (SDAP), the RB identifier can be carried in the SDAP header.

[0291] In a downlink transmission scenario, a third network element (the third network element is a network element that has established a third NAS session with the terminal device) sends a fourth NAS message (the fourth NAS message can be any NAS message) through the third NAS session. In one possible implementation, the third network element can send the fourth NAS message together with information that can indicate the third NAS session (such as an identifier of the third NAS session or a third identifier, the third identifier is used to indicate the context of the third NAS session in the access network device. Optionally, the third identifier can correspond to the identifier of the interface associated with the third NAS session. For details, please refer to the above introduction to the access network device allocating an interface identifier to the interface associated with the second NAS session). The access network device can determine the third NAS session to which the fourth NAS message belongs based on the information indicating the third NAS session, and thus send the fourth NAS message to the terminal device.

[0292] Among them, when the third network element sends the fourth NAS message together with the information that can indicate the third NAS session to the access network device, the fourth NAS message and the information that can indicate the third NAS session can be carried in the same signaling message and sent, or the identifier of the third NAS session can be used as a non-encrypted field in the fourth NAS message header.

[0293] In another possible implementation, the third network element sends a fourth NAS message to the access network device via the interface associated with the third NAS session. After receiving the fourth NAS message, the access network device can determine the third NAS session to which the fourth NAS message belongs based on the identifier of the interface through which the fourth NAS message was received, and then send the fourth NAS message to the terminal device. Optionally, in this implementation, when the third network element sends the fourth NAS message, it can also send information indicating the third NAS session.

[0294] Regarding the access network device sending the fourth message to the terminal device, in one possible implementation, the access network device may send the identifier of the third NAS session together with the fourth NAS message to the terminal device. Correspondingly, after receiving the fourth NAS message and the identifier of the third NAS session, the terminal device may determine the third NAS session to which the fourth NAS message belongs based on the identifier of the third NAS session.

[0295] Specifically, when the third network element sends the identifier of the third NAS session together with the fourth NAS message to the access network device, if the identifier of the third NAS session is an unencrypted field in the fourth NAS message header, the access network device may directly forward the fourth NAS message to the terminal device. If the fourth NAS message and the identifier of the third NAS session are carried in the same signaling message and sent, the access network device may carry the fourth NAS message and the identifier of the third NAS session in the same RRC message and send it to the terminal device. When the third network element sends the third identifier together with the fourth NAS message to the access network device, or when the third network element sends the fourth NAS message through the interface associated with the third NAS session, the access network device may determine the identifier of the third NAS session based on the third identifier or the identifier of the interface receiving the fourth NAS message (for example, the context of the third NAS session includes the identifier of the third NAS session, or for example, the access network device stores a correspondence between the identifier of the interface of the fourth NAS message and the identifier of the third NAS session), and send the identifier of the third NAS session together with the fourth NAS message to the terminal device (for example, using the identifier of the third NAS session as an unencrypted field in the fourth NAS message header, or carrying the fourth NAS message and the identifier of the third NAS session in the same RRC message).

[0296] Regarding the access network device sending the fourth message to the terminal device, in another possible implementation, the access network device may send the fourth NAS message to the terminal device via the radio bearer corresponding to the third NAS session. Correspondingly, the terminal device may determine the third NAS session to which the fourth NAS message belongs based on the correspondence between the radio bearer transmitting the fourth NAS message and the third NAS session.

[0297] Optionally, in an uplink transmission scenario or a downlink transmission scenario, at least two of the following implementation methods may work simultaneously: an implementation method of transmitting NAS messages based on an identifier of a NAS session, an implementation method of transmitting NAS messages based on a radio bearer corresponding to a NAS session, or an implementation method of transmitting NAS messages based on an interface associated with a NAS session. For example, if the terminal device simultaneously adopts an implementation method of transmitting NAS messages based on an identifier of a NAS session and an implementation method of transmitting NAS messages based on a radio bearer corresponding to a NAS session, when the terminal device sends a third NAS message, it always sends the third NAS message together with the identifier of the third NAS session. At the same time, the terminal device determines the radio bearer used to send the third NAS message based on the correspondence between the third NAS session and the radio bearer. Similarly, when the access network device sends a fourth NAS message, it always sends the fourth NAS message together with the identifier of the third NAS session. At the same time, the access network device determines the radio bearer used to send the fourth NAS message based on the correspondence between the third NAS session and the radio bearer. For another example, if the third network element adopts both an implementation method of transmitting NAS messages based on a NAS session identifier and an implementation method of transmitting NAS messages based on a radio bearer corresponding to the NAS session, when the third network element sends a fourth NAS message, it always sends the fourth NAS message together with information indicating the third NAS session. At the same time, the third network element sends the fourth NAS message through the interface associated with the third NAS session.

[0298] Based on the above embodiment, a possible process for establishing a second NAS session between the terminal device and the second network element may be shown in FIG4 , including the following steps:

[0299] S401: A terminal device sends a first request message through a first NAS session, requesting to establish a second NAS session, the first request message including a second NAS session identifier allocated by the terminal device for the second NAS session. Accordingly, the access network device receives the first request message.

[0300] Prior to S401, a first NAS session is established between the terminal device and the first network element. Optionally, as shown in S400, the terminal device and the first network element may initiate the establishment of the first NAS session through a registration process, and the first network element may authenticate and authorize the terminal device to determine whether to allow the terminal device to establish the first NAS session.

[0301] S402: The access network device sends a first request message to the first network element. Correspondingly, the first network element receives the first request message.

[0302] Optionally, if the first request message further includes an identifier of the first NAS session, the access network device may determine that the destination network element of the first request message is the first network element based on the identifier of the first NAS session.

[0303] Optionally, if the first request message is sent through the radio bearer corresponding to the first NAS session, the access network device may determine that the destination network element of the first request message is the first network element based on the radio bearer used to transmit the first request message.

[0304] S403: The first network element determines that establishment of the second NAS session is allowed, and selects a second network element.

[0305] Optionally, the first network element may determine whether to allow establishment of the second NAS session based on the subscription information of the terminal device.

[0306] Optionally, the first network element may select the second network element according to the first information. Exemplarily, the subscription information of the terminal device and / or the second NAS session establishment request may include the first information.

[0307] S404: The first network element sends a second request message to the second network element, where the second request message requests to establish a second NAS session and includes an identifier of the second NAS session. Correspondingly, the second network element receives the second request message.

[0308] S405: The second network element obtains subscription information related to the second NAS session, such as QoS information corresponding to the second NAS session.

[0309] S406. The second network element sends a first response message to the first network element in response to the second request message.

[0310] Optionally, the first response message may indicate whether the second NAS sub-session is established successfully.

[0311] Optionally, if the first response message indicates that the second NAS session establishment fails, the first network element may send a response message indicating that the second NAS session establishment fails to the terminal device, and the process ends.

[0312] S407: The second network element sends a third request message to the access network device, requesting the establishment of a second NAS session. The third request message includes an identifier of the second NAS session and information about the second network element (e.g., address information of the second network element). In response, the access network device receives the third request message. The third request message includes a second response message sent to the terminal device, indicating that the second NAS session was successfully established. The second response message includes an identifier of the second NAS session.

[0313] Optionally, as shown in S407a, the second network element may send a third request message to the access network device through the first network element. Exemplarily, the second network element may carry the third request message in a response message to the second NAS session establishment request in S406. After receiving the response message, the first network element forwards the third request message to the access network device.

[0314] Alternatively, as shown in S407b, the second network element may directly send a third request message to the access network device. In this manner, the second request message in S404 also includes the address information of the access network device and the first identifier (used to indicate the context of the terminal device in the access network device). The second network element sends the third request message to the access network device based on the address information of the access network device, and the third request message also includes the first identifier.

[0315] S408. The access network device sends a second response message to the terminal device. Correspondingly, the terminal device receives the second response message.

[0316] Optionally, the access network device may further send second information to the terminal device, where the second information is used to configure a radio bearer corresponding to the second NAS session. The terminal device determines the radio bearer corresponding to the second NAS session based on the second information.

[0317] S409: The access network device sends a third response message to the second network element in response to the third request message. Accordingly, the second network element receives the third response message. The third response message includes information about the access network device (e.g., address information) and a second identifier assigned by the access network device to the second NAS session. The second identifier is used to indicate the context of the second NAS session in the access network device.

[0318] After S409, the second NAS session between the terminal device and the second network element is established. The terminal device and the second network element can directly transmit NAS messages through the access network device without being forwarded through the first network element.

[0319] For example, in an uplink transmission scenario, after S409, the following steps may be included:

[0320] S410: The terminal device sends a first NAS message via a second NAS session. Correspondingly, the access network device receives the first NAS message.

[0321] When the terminal device sends the first NAS message, it may also send the identifier of the second NAS session, and / or the terminal device may send the first NAS message through the radio bearer corresponding to the second NAS session.

[0322] S411: The access network device determines that the first NAS message belongs to the second NAS session and, based on a stored correspondence between the second NAS session and the second network element (e.g., a correspondence between the identifier of the second NAS session and the address information of the second network element), sends the first NAS message to the second network element. In response, the second network element receives the first NAS message.

[0323] For a specific implementation of the access network device determining that the first NAS message belongs to the second NAS session, reference may be made to the above description of the access network device determining that the third NAS message belongs to the third NAS session, which will not be elaborated here.

[0324] For example, in a downlink transmission scenario, after S409, the following steps may be included:

[0325] S412: The second network element sends a second NAS message through the second NAS session. Correspondingly, the access network device receives the second NAS message.

[0326] When the second network element sends the second NAS message, it may also send the identifier of the second NAS session and / or the second identifier.

[0327] S413: The access network device determines that the second NAS message belongs to the second NAS session, and sends the second NAS message to the terminal device. Correspondingly, the terminal device receives the second NAS message.

[0328] For the specific implementation of the access network device determining that the second NAS message belongs to the second NAS session and sending the second NAS message to the terminal device, please refer to the above introduction of the access network device determining that the fourth NAS message belongs to the third NAS session and sending the fourth NAS message to the terminal device, which will not be elaborated here.

[0329] In addition, embodiments of the present application also provide another communication method. Based on this communication method, a security mode can be activated for a NAS session established between a terminal device and a core network element, protecting the security of NAS messages transmitted through the NAS session and preventing tampering of NAS messages transmitted through NAS messages. This communication method is described below, using the activation of security mode for a second NAS session as an example.

[0330] FIG5 illustrates the method by taking a terminal device and a second network element as the execution subjects of the interaction diagram as an example, but the present application does not limit the execution subjects of the interaction diagram. For example, the second network element in FIG5 may also be a module applied to the second network element, such as a chip, a chip system, or a processor, or a logical node, a logical module, or software that can implement all or part of the functions of the second network element; the terminal device in FIG5 may also be a module applied to the terminal device, such as a chip, a chip system, or a processor, or a logical node, a logical module, or software that can implement all or part of the functions of the terminal device.

[0331] As shown in FIG5 , the communication method includes the following steps:

[0332] S501: A second network element sends first indication information to a terminal device. In response, the terminal device receives the first indication information, where the first indication information is used to instruct the terminal device to activate a security mode for a second NAS session. The security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.

[0333] S502. The terminal device activates (also referred to as starts) a security mode for the second NAS session according to the first indication information.

[0334] The following is an introduction to S501-S502.

[0335] In S501, the second network element may send the first indication information to the terminal device during the process of establishing the second NAS session, or the second network element may send the second indication information to the terminal device after the second NAS session is established.

[0336] Wherein, for sending the first indication information to the terminal device, the second network element may send the first indication information to the terminal device through the first network element and the access network device. Alternatively, the second network element may send the first indication information to the terminal device through the access network device.

[0337] For example, the second network element may carry the first indication information in a first response message sent to the first network element. After receiving the first response message, the first network element sends the first indication information therein to the terminal device.

[0338] For another example, after the second NAS session is established, the second network element may send the first indication information to the terminal device through the second NAS session. Correspondingly, after receiving the first indication information, the access network device sends the first indication information to the terminal device.

[0339] Optionally, to transmit NAS messages in secure mode, the second network element may obtain a key for the second NAS session. The key for the second NAS session includes at least one of the following: a key used to encrypt NAS messages transmitted via the second NAS session (it is understood that this key may also be used to decrypt NAS messages transmitted via the second NAS session), or a key used to integrity protect NAS messages transmitted via the second NAS session. If secure mode is activated for the second NAS session, the second network element may use the key for the second NAS session to perform corresponding processing on NAS messages transmitted via the second NAS session.

[0340] Regarding obtaining the key for the second NAS session, in a possible implementation, the second network element may generate the key for the second NAS session according to the root key of the second NAS session and a preset rule.

[0341] The embodiments of the present application do not limit the specific implementation of the second network element obtaining the root key of the second NAS session. For example, the second request message may include the root key of the second NAS session. Alternatively, the subscription information of the terminal device may include the root key of the second NAS session.

[0342] Among them, if the second request message includes the root key of the second NAS session, the root key of the second NAS session included in the second request message can be deduced (or generated) by the first network element based on the root key of the first NAS session (or called the root key of the first network element) and the identifier of the second NAS session. For example, assuming that the first network element is an AMF network element, the root key of the first NAS session can be Kamf or Kseaf. The specific process of the AMF network element deducing the root key of the second NAS session based on the root key of the first NAS session can refer to the existing key deduction process. Alternatively, the first network element can obtain the root key of the second NAS session from the authentication network element. For example, the authentication network element can be an authentication server function (AUSF) network element. The AUSF network element can generate the root key of the second NAS session and send it to the first network element.

[0343] Optionally, if the second network element obtains the key for the second NAS session, before sending the first indication information, the second network element may use the key for the second NAS session to perform corresponding processing on the first indication information, namely, perform at least one of the following: encryption or integrity protection. In this case, the terminal device may use the key for the second NAS session to verify the first indication information, as described in detail in S502 and will not be further elaborated here.

[0344] Optionally, the second network element may obtain security capability information of the terminal device, where the security capability information is used to indicate one or more of the following algorithms supported by the terminal device: an encryption algorithm (i.e., an algorithm for encrypting NAS messages) or an integrity protection algorithm (i.e., an algorithm for integrity protection of NAS messages). The second network element may determine the security algorithm corresponding to the second NAS session based on the security capability information of the terminal device. The security algorithm includes one or more of the following algorithms: an algorithm for encryption or an algorithm for integrity protection.

[0345] The embodiment of the present application does not limit the specific implementation of the second network element obtaining the security capability information of the terminal device. For example, the second request message may include the security capability information, and / or the subscription information of the terminal device may include the security capability information.

[0346] In S502 , optionally, in order to transmit a NAS message in a secure mode, the terminal device may obtain a key for the second NAS session.

[0347] In one possible implementation, the terminal device may generate a key for the second NAS session based on the root key of the first NAS session, the identifier of the second NAS session, and a preset rule. The root key of the first NAS session may be generated locally on the terminal device.

[0348] Optionally, if the terminal device obtains the key of the second NAS session, and the second network element uses the key of the second NAS session to perform at least one of the following on the first indication information: encryption or integrity protection, after receiving the first indication information, the terminal device can use the key of the second NAS session to verify the first indication information. If the verification is successful, the terminal device activates the security mode. If the verification fails, the terminal device does not activate the security mode.

[0349] Optionally, after S502, the following steps may be further included:

[0350] The terminal device sends a response message to the second network element for the first indication information, where the response message is used to indicate that the terminal device has activated the security mode for the second NAS session.

[0351] It can be understood that S501-S502 are introduced by taking the activation of the security mode for the second NAS session as an example. The method for activating the security mode for the NAS session provided in the embodiment of the present application can be applied not only to the second NAS session, but can also be adaptively applied to other NAS sessions, such as the first NAS session. The embodiment of the present application does not limit this. For example, if the security mode is activated for the first NAS session, the first network element can send an indication message to the terminal device to instruct the terminal device to activate the security mode for the first NAS session, and the terminal device activates the security mode for the first NAS session according to the indication message. Among them, the first network element can send the indication message to the terminal device during the establishment of the first NAS session or after the establishment of the first NAS session is completed. For details, please refer to the above introduction to S501-S502, which will not be expanded here.

[0352] In addition, embodiments of the present application also provide another communication method. Based on this communication method, a corresponding radio bearer can be configured for the QoS flows included in a NAS session established between a terminal device and a core network element, thereby avoiding problems such as information congestion and increased latency that may occur when different QoS flows included in the NAS session are transmitted over the same radio bearer. This communication method is described below, using the configuration of a corresponding radio bearer for a QoS flow included in a second NAS session as an example.

[0353] FIG6 illustrates the method by taking the access network device, the terminal device, and the second network element as the execution subjects of the interaction diagram as an example, but the present application does not limit the execution subjects of the interaction diagram. For example, the second network element in FIG6 may also be a module applied to the second network element, such as a chip, a chip system, or a processor, or a logical node, a logical module, or software that can realize all or part of the functions of the second network element; the access network device in FIG6 may also be a module applied to the access network device, such as a chip, a chip system, or a processor, or a logical node, a logical module, or software that can realize all or part of the functions of the access network device; the terminal device in FIG6 may also be a module applied to the terminal device, such as a chip, a chip system, or a processor, or a logical node, a logical module, or software that can realize all or part of the functions of the terminal device.

[0354] As shown in FIG6 , the communication method includes the following steps:

[0355] S601: A second network element sends a fourth request message to an access network device. Accordingly, the access network device receives the fourth request message, wherein the fourth request message is used to request configuration of a radio bearer corresponding to each of one or more QoS flows included in a second NAS session.

[0356] The QoS flow included in the second NAS session refers to a QoS flow configured by the second network element for the second NAS session and to which a NAS message transmitted through the second NAS session can be mapped.

[0357] In S601, the second network element may send a fourth request message to the access network device during the establishment of the second NAS session. Exemplarily, the fourth request message may be carried in the third request message.

[0358] Alternatively, the second network element may also send a fourth request message to the access network device after the second NAS session is established.

[0359] In S601, the fourth request message may include the following information: identification information of each QoS flow in one or more QoS flows included in the second NAS session, and QoS parameters corresponding to each QoS flow, such as QoS level, 5QI, maximum bandwidth, and other information.

[0360] The one or more QoS flows included in the second NAS session may be all QoS flows included in the second NAS session, or may be some QoS flows included in the second NAS session. In other words, based on the fourth request message, the access network device may configure a corresponding radio bearer for each QoS flow in all QoS flows included in the second NAS session, or may configure a corresponding radio bearer for each QoS flow in some QoS flows included in the second NAS session.

[0361] Optionally, the fourth request message may further include a mapping rule for an uplink NAS message, wherein the mapping rule includes a correspondence between an uplink NAS message transmitted through the second NAS session and each QoS flow. In this case, after receiving the fourth request message, the access network device may send the mapping rule to the terminal device, so that when the terminal device subsequently sends a NAS message through the second NAS session, it can determine the QoS flow corresponding to the NAS message.

[0362] S602: The access network device configures a corresponding radio bearer for each of the one or more QoS flows included in the second NAS session according to the fourth request message.

[0363] Among them, the one or more QoS flows included in the second NAS session and the configured radio bearers can be in a one-to-one correspondence, that is, among the one or more QoS flows included in the second NAS session, different QoS flows correspond to different radio bearers. Alternatively, it can be a many-to-one relationship, that is, multiple QoS flows are mapped to one radio bearer. For example, the access network device maps all QoS flows in the one or more QoS flows included in the second NAS session to one radio bearer. For another example, the access network device maps some QoS flows in the one or more QoS flows included in the second NAS session to one radio bearer, and other QoS flows are mapped to other radio bearers.

[0364] S603: The access network device sends third information to the terminal device, where the third information is used to configure a radio bearer corresponding to each of the one or more QoS flows included in the second NAS session.

[0365] Correspondingly, after receiving the third information, the terminal device can determine the correspondence between each of the one or more QoS flows included in the second NAS session and the configured radio bearer based on the third information. Subsequently, the terminal device can send an uplink NAS message through the radio bearer corresponding to the QoS flow corresponding to the uplink NAS message based on the correspondence between the QoS flow and the radio bearer. Alternatively, the terminal device can determine the QoS flow corresponding to the downlink NAS message based on the radio bearer on which the downlink NAS message is received.

[0366] Optionally, after S603, in an uplink transmission scenario, that is, when the terminal device sends a NAS message through the second NAS session, the QoS flow corresponding to the NAS message may be indicated.

[0367] Exemplarily, after S603, the following steps may be included:

[0368] The terminal device sends the first NAS message and identification information of the first QoS flow corresponding to the first NAS message through the second NAS session. In response, the access network device receives the first NAS message and identification information of the first QoS flow. The first QoS flow is a QoS flow among one or more QoS flows included in the second NAS session. Further, the access network device sends the first NAS message and identification information of the first QoS flow to the second network element.

[0369] Optionally, after S603, in the uplink transmission scenario, when the terminal device sends a NAS message through the second NAS session, it can determine the radio bearer corresponding to the QoS flow corresponding to the NAS message, and thus send the NAS message through the radio bearer corresponding to the QoS flow. After receiving the NAS message, the access network device can determine the QoS flow corresponding to the NAS message based on the radio bearer used to transmit the NAS message, so that when sending the NAS message to the second network element, it can indicate the QoS flow corresponding to the NAS message.

[0370] Exemplarily, after S603, the following steps may be included:

[0371] The terminal device sends the first NAS message via the second NAS session. The access network device receives the first NAS message. The access network device determines, based on the radio bearer used to transmit the first NAS message, that the first NAS message corresponds to the first QoS flow. The access network device sends the first NAS message and identification information of the first QoS flow to the second network element.

[0372] Optionally, after S603, in a downlink transmission scenario, that is, when the second network element sends a NAS message through the second NAS session, the QoS flow corresponding to the NAS message may be indicated. After receiving the NAS message, the access network device may determine the QoS flow corresponding to the NAS message and the radio bearer corresponding to the QoS flow, thereby sending the NAS message to the terminal device through the radio bearer corresponding to the QoS flow.

[0373] Exemplarily, after S603, the following steps may be included:

[0374] The second network element sends a second NAS message and identification information of the second QoS flow corresponding to the second NAS message via a second NAS session. In response, the access network device receives the second NAS message and the identification information of the second QoS flow. The second QoS flow is a QoS flow from one or more QoS flows included in the second NAS session. Based on the identification information of the second QoS flow, the access network device determines the radio bearer corresponding to the second QoS flow. Furthermore, the access network device sends the second NAS message to the terminal device via the radio bearer corresponding to the second QoS flow.

[0375] In which, in an uplink transmission scenario or a downlink transmission scenario, if the terminal device or the second network element sends a NAS message and identification information of the QoS flow corresponding to the NAS message together, the identification information of the QoS flow can be included in the unencrypted header of the NAS message, or can be included in one message and sent together with the NAS message.

[0376] It can be understood that S601-S603 are introduced by taking the configuration of a wireless bearer for each QoS flow included in the second NAS session as an example. The method for configuring a wireless bearer for each QoS flow included in a NAS session provided in the embodiment of the present application can be applied not only to the second NAS session, but can also be adaptively applied to other NAS sessions, such as the first NAS session. The embodiment of the present application does not limit this. For example, if a wireless bearer is configured for each QoS flow included in the first NAS session, the first network element can send a request message to the access network device requesting the configuration of a wireless bearer corresponding to each QoS flow included in the first NAS session. The access network device configures the wireless bearer corresponding to each QoS flow included in the first NAS session based on the request message. Among them, the first network element can send the request message to the access network device during the establishment of the first NAS session or after the establishment of the first NAS session is completed. For details, please refer to the above introduction to S601-S603, which will not be expanded here.

[0377] Optionally, in the above embodiments, the embodiment shown in FIG. 3 , the embodiment shown in FIG. 5 and the embodiment shown in FIG. 6 may be applied independently or in combination, and the embodiments of the present application do not limit this.

[0378] It can be understood that the processes shown in Figures 3 to 6 above are only logical schematic processes provided to facilitate understanding of the embodiments of the present application, and do not represent the actual timing of the embodiments of the present application. The embodiments of the present application do not limit the timing between different steps in the processes shown in Figures 3 to 6.

[0379] The above description primarily describes the solutions provided by the embodiments of the present application from the perspective of interaction between various network elements. Accordingly, the embodiments of the present application also provide a communication device for implementing the various methods described above. The communication device may be the first network element, second network element, access network device, or terminal device described in the method embodiments described above, or a device comprising the first network element, second network element, access network device, or terminal device described above, or a component usable with the first network element, second network element, access network device, or terminal device described above. It will be understood that, to implement the aforementioned functions, the communication device includes hardware structures and / or software modules corresponding to each function. Those skilled in the art will readily appreciate that, in conjunction with the various exemplary units and algorithm steps described in the embodiments disclosed herein, the present application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0380] In the embodiment of the present application, the communication device can be divided into functional modules according to the above method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be understood that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.

[0381] Figure 7 shows a schematic diagram of the structure of a communication device 700. The communication device 700 includes a processing module 701 and a transceiver module 702. Optionally, the communication device 700 may also include a storage module 703. The transceiver module 702, also known as a transceiver unit, is used to implement transceiver functions and may be, for example, a transceiver circuit, a transceiver, a transceiver, or a communication interface.

[0382] Taking the communication device 700 as the terminal device in the above embodiment as an example, in a possible implementation manner:

[0383] Transceiver module 702 is configured to send a first request message to a first network element via a first NAS session. The first NAS session is used to transmit NAS messages between a terminal device and the first network element. The first request message is used to request a service; alternatively, the first request message is used to request a service and also to request establishment of a second NAS session; alternatively, the first request message is used to request establishment of a second NAS session. Transceiver module 702 is further configured to receive an identifier of a second NAS session, where the second NAS session is used to transmit NAS messages between the terminal device and the second network element. Transceiver module 702 is further configured to send the first NAS message to the second network element via the second NAS session based on the identifier of the second NAS session.

[0384] Optionally, the transceiver module 702 is further configured to receive first indication information, where the first indication information is used to instruct the terminal device to activate a security mode for the second NAS session. The security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session. The processing module 701 is configured to activate the security mode for the second NAS session based on the first indication information.

[0385] Optionally, the processing module 701 is further configured to generate a key for a second NAS session based on the root key of the first NAS session and the identifier of the second NAS session, where the key for the second NAS session includes at least one of the following keys: a key for encrypting NAS messages transmitted through the second NAS session, or a key for integrity protection of NAS messages transmitted through the second NAS session.

[0386] Optionally, the processing module 701 activates the security mode for the second NAS session according to the first indication information, including: verifying the first indication information using a key of the second NAS session; wherein the key of the second NAS session includes at least one of the following keys: a key used for encrypting NAS messages transmitted through the second NAS session, or a key used for integrity protection of NAS messages transmitted through the second NAS session. If the verification succeeds, the security mode is activated.

[0387] Optionally, the transceiver module 702 sends the first request message to the first network element through the first NAS session, including: sending an RRC message to the access network device, the RRC message including the first request message. The RRC message is sent through the radio bearer corresponding to the first NAS session, and / or the RRC message includes an identifier of the first NAS session. The radio bearer corresponding to the first NAS session or the identifier of the first NAS session is used by the access network device to determine whether to send the first request message to the first network element.

[0388] Optionally, the transceiver module 702 sends the first NAS message to the second network element through the second NAS session, including: sending an RRC message to the access network device, where the RRC message includes the first NAS message. The RRC message is sent through a radio bearer corresponding to the second NAS session, and / or the RRC message includes an identifier of the second NAS session. The radio bearer corresponding to the second NAS session or the identifier of the second NAS session is used by the access network device to determine whether to send the first NAS message to the second network element.

[0389] Optionally, the transceiver module 702 is further configured to receive second information from the access network device, where the second information is used to configure one or more radio bearers corresponding to the second NAS session. The transceiver module 702 sending the first NAS message to the second network element through the second NAS session includes: sending the first NAS message to the second network element through the radio bearer corresponding to the second NAS session.

[0390] Optionally, the second NAS session includes one or more QoS flows, and the transceiver module 702 sends the first NAS message to the second network element through the second NAS session, including: sending the first NAS message to the second network element through the radio bearer corresponding to the first QoS flow. The first NAS message corresponds to the first QoS flow, and the one or more QoS flows include the first QoS flow.

[0391] Optionally, the transceiver module 702 is further configured to receive a mapping rule, the mapping rule including a correspondence between the first NAS message and the first QoS flow. The transceiver module 702 is further configured to receive third information from the access network device, the third information being used to configure a radio bearer corresponding to the first QoS flow.

[0392] Taking the communication device 700 as the first network element in the above embodiment as an example, in a possible implementation manner:

[0393] The transceiver module 702 is configured to receive a first request message from a terminal device via a first NAS session. The first NAS session is a NAS session established between the terminal device and a first network element and is used to transmit NAS messages between the terminal device and the first network element. The first request message is used to request a service; alternatively, the first request message is used to request a service and also to request the establishment of a second NAS session; alternatively, the first request message is used to request the establishment of the second NAS session. The processing module 701 is configured to trigger the establishment of the second NAS session, which is used to transmit NAS messages between the terminal device and the second network element.

[0394] Optionally, the processing module 701 is further configured to obtain an identifier of the second NAS session. The transceiver module 702 is further configured to send the identifier of the second NAS session to the second network element.

[0395] Optionally, the processing module 701 is further configured to determine whether to allow establishment of the second NAS session based on the subscription information of the terminal device. The processing module 701 triggers establishment of the second NAS session, including: triggering establishment of the second NAS session when the first network element determines that establishment of the second NAS session is allowed.

[0396] Optionally, the processing module 701 triggers establishment of the second NAS session, including: triggering establishment of the second NAS session when the subscription information of the terminal device indicates creation of the second NAS session for the service.

[0397] Optionally, the transceiver module 702 is further configured to send a fifth request message to the second network element. The transceiver module 702 is further configured to receive fourth information from the second network element, where the fourth information is used to instruct establishment of a second NAS session. The processing module 701 triggers establishment of the second NAS session, including: triggering establishment of the second NAS session based on the fourth information.

[0398] Optionally, the processing module 701 is further used to select a second network element from network elements providing services based on the first information; wherein the first request message includes the first information, or the contract information of the terminal device includes the first information.

[0399] Optionally, the processing module 701 triggers establishment of the second NAS session, including: sending a second request message to the second network element through the transceiver module 702, where the second request message is used to request establishment of the second NAS session.

[0400] Optionally, the processing module 701 is further configured to generate a root key for the second NAS session according to the root key of the first NAS session and the identifier of the second NAS session.

[0401] Optionally, the transceiver module 702 is further configured to receive first indication information from the second network element, where the first indication information is configured to instruct the terminal device to activate a security mode for the second NAS session. The security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session. The first network element sends the first indication information to the terminal device.

[0402] Optionally, the transceiver module 702 is further configured to send a third request message to the access network device, where the third request message is used to request establishment of a second NAS session, and the third request message includes an identifier of the second NAS session.

[0403] Optionally, the transceiver module 702 is further configured to receive second indication information from the second network element, where the second indication information indicates establishing a second NAS session. The transceiver module 702 sends a third request message to the access network device, including: sending the third request message to the access network device according to the second indication information.

[0404] Optionally, the transceiver module 702 is further configured to send an identifier of the second NAS session to the terminal device.

[0405] Optionally, the transceiver module 702 is further configured to receive a first identifier from an access network device.

[0406] Taking the communication device 700 as the second network element in the above embodiment as an example, in a possible implementation manner:

[0407] The transceiver module 702 is configured to receive a second request message from the first network element, where the second request message is used to request the establishment of a second NAS session, which is used to transmit NAS messages between the terminal device and the second network element. Furthermore, a first NAS session for transmitting NAS messages exists between the first network element and the terminal device. The transceiver module 702 is further configured to send a first response message to the first network element in response to the second request message.

[0408] Optionally, the transceiver module 702 is further configured to send a third request message to the access network device, where the third request message is used to request the access network device to establish a second NAS session. The third request message includes address information of the second network element and an identifier of the second NAS session.

[0409] Optionally, the transceiver module 702 sends the third request message to the access network device, including: sending the third request message to the access network device according to the address information and the first identifier of the access network device.

[0410] Optionally, the transceiver module 702 is further configured to send a second response message to the terminal device through the third request message, where the second response message is used to indicate that the second NAS session is successfully established, and the second response message includes an identifier of the second NAS session.

[0411] Optionally, the transceiver module 702 is further configured to receive a fifth request message from the first network element, the fifth request message being used to request a service. The transceiver module 702 is further configured to send fourth information to the first network element according to the fifth request message, the fourth information being used to instruct establishment of a second NAS session.

[0412] Optionally, the transceiver module 702 is further configured to receive a third response message from the access network device, where the third response message includes address information of the access network device and a second identifier; the second identifier is used to indicate the context of the second NAS session in the access network device.

[0413] Optionally, the transceiver module 702 is further used to send a first indication message to the first network element, where the first indication message is used to instruct the terminal device to activate a security mode for the second NAS session, where the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.

[0414] Optionally, the transceiver module 702 is further used to send first indication information to the terminal device through the second NAS session, where the first indication information is used to instruct the terminal device to activate a security mode for the second NAS session; the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.

[0415] Optionally, processing module 701 is further configured to obtain a key for a second NAS session, where the key for the second NAS session includes at least one of the following: an encryption key and a key for integrity protection. Processing module 701 is further configured to use the key for the second NAS session to perform at least one of the following on the first indication information: encryption or integrity protection. Transceiver module 702 is further configured to send the first indication information to the terminal device.

[0416] Optionally, the processing module 701 obtains the key of the second NAS session, including: generating the key of the second NAS session based on the root key of the second NAS session, wherein the second request message includes the root key of the second NAS session, or the subscription information of the terminal device includes the root key of the second NAS session.

[0417] Optionally, processing module 701 is further configured to obtain security capability information of the terminal device, where the security capability information indicates one or more of the following algorithms supported by the terminal device: an encryption algorithm or an integrity protection algorithm. Processing module 701 is further configured to determine, based on the security capability information of the terminal device, a security algorithm corresponding to the second NAS session; wherein the security algorithm includes one or more of the following algorithms: an algorithm for encryption or an algorithm for integrity protection.

[0418] Optionally, the second NAS session includes one or more QoS flows, and the transceiver module 702 is further used to send a mapping rule to the terminal device, where the mapping rule includes a correspondence between the NAS message transmitted through the second NAS session and each QoS flow in the one or more QoS flows.

[0419] Optionally, the second NAS session includes one or more QoS flows, and the transceiver module 702 is further configured to send a fourth request message to the access network device, where the fourth request message is used to request configuration of a radio bearer corresponding to each of the one or more QoS flows.

[0420] Optionally, the transceiver module 702 is further configured to send, through a second NAS session, a second NAS message and identification information of a second QoS flow corresponding to the second NAS message. The identification information of the second QoS flow is used by the access network device to determine and send the second NAS message to the terminal device through the second NAS session.

[0421] Taking the communication device 700 as the access network device in the above embodiment as an example, in a possible implementation manner:

[0422] The transceiver module 702 is configured to receive a third NAS message from a terminal device. The processing module 701 is configured to determine a destination network element for the third NAS message based on a third NAS session to which the third NAS message belongs. The transceiver module 702 is further configured to send the third NAS message to the destination network element.

[0423] Optionally, the transceiver module 702 receives a third NAS message from the terminal device, including: receiving the third NAS message from the terminal device and an identifier of a third NAS session to which the third NAS message belongs. The processing module 701 determines a destination network element of the third NAS message based on the third NAS session to which the third NAS message belongs, including: determining the destination network element of the third NAS message based on the identifier of the third NAS session and a first correspondence; wherein the first correspondence includes a correspondence between the identifier of the third NAS session and the destination network element of the third NAS message.

[0424] Optionally, the processing module 701 determines, according to the third NAS session to which the third NAS message belongs, a destination network element of the third NAS message, including: determining the destination network element of the third NAS message according to a radio bearer used to transmit the third NAS message and a second correspondence; wherein the second correspondence includes a correspondence between the radio bearer used to transmit the third NAS message, the third NAS session to which the third NAS message belongs, and the destination network element of the third NAS message.

[0425] Optionally, the transceiver module 702 is further configured to receive a fourth NAS message and an identifier of a third NAS session to which the fourth NAS message belongs from a third network element. The processing module 701 is further configured to determine the third NAS session to which the fourth NAS message belongs based on the identifier of the third NAS session.

[0426] Optionally, the transceiver module 702 is further configured to receive a fourth NAS message and a third identifier from a third network element, where the third identifier is used to indicate a context of a third NAS session to which the fourth NAS message belongs in the access network device. The processing module 701 is further configured to determine, based on the third identifier, the third NAS session to which the fourth NAS message belongs.

[0427] Optionally, the transceiver module 702 is further configured to send a fourth NAS message and an identifier of the third NAS session to the terminal device, and / or send the fourth NAS message to the terminal device through the radio bearer corresponding to the third NAS session.

[0428] Optionally, the transceiver module 702 is further configured to receive a third request message, the third request message being used to request establishment of a third NAS session, the third request message including an identifier of the third NAS session and address information of a third network element, the third NAS session being used to transmit NAS messages between the terminal device and the third network element. The transceiver module 702 is further configured to send a third response message to the third network element based on the address information of the third network element, the third response message including address information of the access network device and a third identifier, the third identifier being used to indicate a context of the third NAS session in the access network device.

[0429] Optionally, the transceiver module 702 is further configured to receive a fourth request message from a third network element, where the fourth request message is used to request configuration of a radio bearer corresponding to each of the one or more QoS flows included in the third NAS session. The processing module 701 is further configured to configure a corresponding radio bearer for each QoS flow based on the fourth request message.

[0430] Optionally, the transceiver module 702 is further configured to receive a fourth NAS message and identification information of a QoS flow corresponding to the fourth NAS message from a third network element, wherein the one or more QoS flows included in the third NAS session include the QoS flow corresponding to the fourth NAS message. The processing module 701 is further configured to determine a radio bearer corresponding to the fourth NAS message based on the identification information of the QoS flow corresponding to the fourth NAS message. The transceiver module 702 is further configured to send the fourth NAS message to the terminal device via the radio bearer.

[0431] Taking the communication device 700 as the access network device in the above embodiment as an example, in another possible implementation:

[0432] The transceiver module 702 is configured to receive a fourth request message from the second network element, requesting configuration of a radio bearer corresponding to each of one or more QoS flows included in the second NAS session. The second NAS session is used to transmit NAS messages between the terminal device and the second network element. The processing module 701 is configured to configure a corresponding radio bearer for each QoS flow based on the fourth request message. The transceiver module 702 is further configured to send third information to the terminal device, configured to configure a radio bearer corresponding to each QoS flow.

[0433] Optionally, the fourth request message further includes a mapping rule, where the mapping rule includes a correspondence between a NAS message transmitted through the second NAS session and each QoS flow. The transceiver module 702 is further configured to send the mapping rule to the terminal device.

[0434] Optionally, the transceiver module 702 is further configured to receive a first NAS message from the terminal device. The processing module 701 is further configured to determine, based on the radio bearer used to transmit the first NAS message, that the first NAS message corresponds to the first QoS flow and that the second NAS session includes the first QoS flow. The transceiver module 702 is further configured to send the first NAS message and identification information of the first QoS flow to the second network element.

[0435] Optionally, the transceiver module 702 is further configured to receive a first NAS message and identification information of a first QoS flow corresponding to the first NAS message from the terminal device, wherein the second NAS session includes the first QoS flow. Optionally, the transceiver module 702 is further configured to send the first NAS message and the identification information of the first QoS flow to the second network element.

[0436] Optionally, the transceiver module 702 is further configured to receive a second NAS message from the second network element and identification information of a second QoS flow corresponding to the second NAS message. The processing module 701 is further configured to determine a radio bearer corresponding to the second QoS flow based on the identification information of the second QoS flow. The transceiver module 702 is further configured to send the second NAS message to the terminal device via the radio bearer corresponding to the second QoS flow.

[0437] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0438] Alternatively, the modules in FIG7 may also be referred to as units. For example, the processing module may be referred to as a processing unit, and the transceiver module may be referred to as a transceiver unit. In addition, in the embodiment shown in FIG7 , the names of the units may not be those shown in the figure. For example, the transceiver module may also be referred to as a communication module or a communication unit.

[0439] If the various units in Figure 7 are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (processor) to execute all or part of the steps of the method described in each embodiment of the present application. The storage medium for storing computer software products includes: various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0440] In the embodiment of the present application, the communication device 700 is presented in the form of various functional modules divided in an integrated manner. The "module" here can refer to an application-specific integrated circuit (ASIC), a circuit, a processor and memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.

[0441] In a simple embodiment, those skilled in the art may appreciate that the communication device 700 may take the form of the communication device shown in FIG. 8 .

[0442] As shown in Figure 8, the communication device 800 includes one or more processors 801, a communication line 802, and at least one communication interface (Figure 8 is only an example of including a communication interface 804 and a processor 801 for illustration), and may optionally also include a memory 803.

[0443] The processor 801 may be a general-purpose central processing unit (CPU), a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the program of the present application.

[0444] The communication line 802 may include a path for connecting different components.

[0445] The communication interface 804 may be a transceiver module for communicating with other devices or communication networks, such as Ethernet, RAN, terminals, and wireless local area networks (WLANs). For example, the transceiver module may be a device such as a transceiver or a transceiver. Alternatively, the communication interface 804 may be a transceiver circuit or input / output interface within the processor 801, for implementing signal input and output to the processor.

[0446] The memory 803 may be a device having a storage function. For example, it may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via a communication line 802. The memory may also be integrated with the processor.

[0447] The memory 803 is used to store computer-executable instructions for executing the solution of the present application, and the execution is controlled by the processor 801. The processor 801 is used to execute the computer-executable instructions stored in the memory 803, thereby implementing the communication method provided in the embodiment of the present application.

[0448] Alternatively, optionally, in an embodiment of the present application, the processor 801 may also perform processing-related functions in the communication method provided in the following embodiments of the present application, and the communication interface 804 is responsible for communicating with other devices or communication networks, which is not specifically limited in the embodiments of the present application.

[0449] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, which is not specifically limited in the embodiments of the present application.

[0450] In a specific implementation, as an embodiment, the processor 801 may include one or more CPUs, such as CPU0 and CPU1 in FIG8 .

[0451] In a specific implementation, as an embodiment, the communication device 800 may include multiple processors, such as the processor 801 and the processor 807 in FIG8 . Each of these processors may be a single-core processor or a multi-core processor. The processors herein may include, but are not limited to, at least one of the following: a CPU, a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor, and other types of computing devices that run software. Each computing device may include one or more cores for executing software instructions to perform calculations or processing.

[0452] In a specific implementation, as an embodiment, the communication device 800 may further include an output device 805 and an input device 806. The output device 805 communicates with the processor 801 and can display information in a variety of ways. For example, the output device 805 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 806 communicates with the processor 801 and can receive user input in a variety of ways. For example, the input device 806 can be a mouse, a keyboard, a touch screen device, or a sensor device.

[0453] The communication device 800 described above may sometimes also be referred to as a communication device, which may be a general-purpose device or a dedicated device. For example, the communication device 800 may be any of the network elements described above, an access network device, or a device having a similar structure as shown in FIG8 . The embodiments of the present application do not limit the type of the communication device 800 .

[0454] In addition, the composition structure shown in Figure 8 does not constitute a limitation on the communication device. In addition to the components shown in Figure 8, the communication device 800 may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0455] Optionally, the functions / implementation processes of the transceiver module 702 and the processing module 701 in FIG7 may be implemented by the processor 801 in the communication device 800 shown in FIG8 calling computer-executable instructions stored in the memory 803. Alternatively, the functions / implementation processes of the processing module 701 in FIG7 may be implemented by the processor 801 in the communication device 800 shown in FIG8 calling computer-executable instructions stored in the memory 803, and the functions / implementation processes of the transceiver module 702 in FIG7 may be implemented by the communication interface 804 in the communication device 800 shown in FIG8.

[0456] It should be understood that one or more of the above modules or units can be implemented by software, hardware, or a combination of the two. When any of the above modules or units is implemented in software, the software exists in the form of computer program instructions and is stored in a memory, and a processor can be used to execute the program instructions and implement the above method flow. The processor can be built into an SoC or ASIC, or it can be an independent semiconductor chip. In addition to the core used to execute software instructions to perform calculations or processing within the processor, it can further include necessary hardware accelerators, such as FPGAs, programmable logic devices (PLDs), or logic circuits that implement dedicated logic operations.

[0457] When the above modules or units are implemented in hardware, the hardware can be any one or any combination of a CPU, a microprocessor, a DSP chip, an MCU, an artificial intelligence processor, an ASIC, a SoC, an FPGA, a PLD, a dedicated digital circuit, a hardware accelerator or a non-integrated discrete device, which can run the necessary software or not rely on the software to execute the above method flow.

[0458] Optionally, an embodiment of the present application further provides a communication device (for example, the communication device may be a chip or a chip system), which includes a processor for implementing the method in any of the above method embodiments. In one possible design, the communication device also includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the communication device to execute the method in any of the above method embodiments. Of course, the memory may not be in the communication device. When the communication device is a chip system, it may be composed of a chip, or it may include a chip and other discrete devices, which is not specifically limited in the embodiment of the present application.

[0459] Optionally, an embodiment of the present application also provides a computer-readable storage medium, which stores a computer program or instruction. When the computer program or instruction is run on a communication device, the communication device can execute the method described in any of the above method embodiments or any of its implementation methods.

[0460] Optionally, an embodiment of the present application further provides a communication system, which includes multiple devices described in the above method embodiment, for example, a first network element, a second network element, an access network device and a terminal device.

[0461] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more media integrated therein. The available media may be magnetic media (eg, floppy disks, hard disks, magnetic tapes), optical media (eg, DVDs), or semiconductor media (eg, solid state drives (SSDs)).

[0462] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit may implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0463] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the scope of the present application. Thus, the present application is intended to encompass such modifications and variations as fall within the scope of the claims of the present application and their equivalents.

Claims

1. A communication method, characterized in that: The method comprises: Sending a first request message to a first network element through a first non-access stratum session, where the first request message is used to request a service provided by a second network element, and the first non-access stratum session is used to transmit non-access stratum messages between a terminal device and the first network element; receiving an identifier of a second non-access stratum session, where the second non-access stratum session is used to transmit non-access stratum messages between the terminal device and the second network element; According to the identifier of the second non-access stratum session, a first non-access stratum message is sent to the second network element through the second non-access stratum session.

2. The method according to claim 1, characterized in that The first request message is also used to request the establishment of a non-access layer session between the terminal device and the second network element.

3. The method according to claim 2, characterized in that The first request message includes an identifier of the second non-access stratum session.

4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: receiving first indication information, where the first indication information is used to instruct the terminal device to activate a security mode for the second non-access stratum session; the security mode includes one or more of the following: encrypting non-access stratum messages transmitted through the second non-access stratum session, or performing integrity protection on non-access stratum messages transmitted through the second non-access stratum session; Activate the security mode for the second non-access layer session according to the first indication information.

5. The method according to claim 4, characterized in that The method further comprises: A key for a second non-access stratum session is generated based on the root key of the first non-access stratum session and the identifier of the second non-access stratum session, where the key for the second non-access stratum session includes at least one of the following keys: a key for the encryption, or a key for the integrity protection.

6. The method according to claim 4 or 5, characterized in that The activating the security mode for the second non-access stratum session according to the first indication information includes: Verify the first indication information using a key of the second non-access stratum session; wherein the key of the second non-access stratum session includes at least one of the following keys: a key used for the encryption, or a key used for the integrity protection; If the verification is successful, the security mode is activated.

7. The method according to any one of claims 1 to 6, characterized in that The sending the first non-access stratum message to the second network element through the second non-access stratum session includes: A first message is sent to an access network device, where the first message includes the first non-access layer message; the first message is sent through the radio bearer corresponding to the second non-access layer session, and / or the first message includes an identifier of the second non-access layer session; the radio bearer corresponding to the second non-access layer session or the identifier of the second non-access layer session is used by the access network device to determine whether to send the first non-access layer message to the second network element.

8. The method according to any one of claims 1 to 7, characterized in that The sending the first request message to the first network element through the first non-access layer session includes: A second message is sent to the access network device, where the second message includes the first request message; the second message is sent through the radio bearer corresponding to the first non-access layer session, and / or the second message includes an identifier of the first non-access layer session, and the radio bearer corresponding to the first non-access layer session or the identifier of the first non-access layer session is used by the access network device to determine to send the first request message to the first network element.

9. The method according to any one of claims 1 to 8, characterized in that The first request message includes first information, where the first information is used to select the second network element from network elements providing services.

10. The method according to any one of claims 1 to 9, characterized in that The method further comprises: receiving second information from an access network device, where the second information is used to configure one or more radio bearers corresponding to the second non-access stratum session; The sending of the first non-access stratum message to the second network element through the second non-access stratum session includes: The first non-access stratum message is sent to the second network element through the radio bearer corresponding to the second non-access stratum session.

11. The method according to any one of claims 1 to 10, characterized in that The second non-access stratum session includes one or more quality of service flows, and the sending the first non-access stratum message to the second network element through the second non-access stratum session includes: A first non-access stratum message is sent to the second network element through a radio bearer corresponding to a first quality of service flow, wherein the first non-access stratum message corresponds to a first quality of service flow, and the one or more quality of service flows include the first quality of service flow.

12. The method according to claim 11, characterized in that The method further comprises: receiving a mapping rule, where the mapping rule includes a correspondence between the first non-access stratum message and the first quality of service flow; Receive third information from the access network device, where the third information is used to configure a radio bearer corresponding to the first quality of service flow.

13. A communication method, characterized in that: The method comprises: A first network element receives a first request message from a terminal device through a first non-access stratum session, where the first request message is used to request a service provided by a second network element, and the first non-access stratum session is used to transmit non-access stratum messages between the terminal device and the first network element; The first network element triggers the establishment of a second non-access layer session, and the second non-access layer session is used to transmit non-access layer messages between the terminal device and the second network element.

14. The method according to claim 13, wherein: The method further comprises: The first network element sends an identifier of the second non-access layer session to the second network element.

15. The method according to claim 14, characterized in that The identifier of the second non-access layer session is allocated by the terminal device for the second non-access layer session, or is allocated by the first network element for the second non-access layer session.

16. The method according to claim 13 or 14, characterized in that The first request message is also used to request the establishment of a non-access layer session between the terminal device and the second network element.

17. The method according to claim 16, characterized in that The first network element triggering establishment of a second non-access layer session includes: In a case where the subscription information of the terminal device indicates that establishment of a non-access stratum session between the terminal device and the second network element is allowed, the first network element triggers establishment of the second non-access stratum session.

18. The method according to claim 17, characterized in that The subscription information of the terminal device indicates that the establishment of a non-access layer session between the terminal device and the second network element is allowed, including: the subscription information of the terminal device indicates that the establishment of a non-access layer session between the terminal device and the second network element is allowed for the service requested by the first request message.

19. The method according to any one of claims 13 to 15, characterized in that: The method further comprises: The first network element sends a fifth request message to the second network element, where the fifth request message is used to request the service; The first network element receives fourth information from the second network element, where the fourth information is used to indicate establishment of the second non-access stratum session; The first network element triggering establishment of a second non-access layer session includes: The first network element triggers establishment of the second non-access layer session according to the fourth information.

20. The method according to any one of claims 13 to 19, characterized in that: The method further comprises: The first network element selects the second network element from the network elements providing the service based on the first information; wherein the first request message includes the first information, or the contract information of the terminal device includes the first information.

21. The method according to any one of claims 13 to 20, characterized in that: The first network element triggering establishment of a second non-access layer session includes: The first network element sends a second request message to the second network element, where the second request message is used to request establishment of the second non-access layer session.

22. The method according to claim 21, characterized in that The second request message includes a root key of the second non-access stratum session, where the root key of the second non-access stratum session is used to generate a key of the second non-access stratum session, and the key of the second non-access stratum session includes at least one of the following keys: a key for encrypting a non-access stratum message transmitted through the second non-access stratum session, or a key for integrity protection of a non-access stratum message transmitted through the second non-access stratum session.

23. The method according to claim 22, characterized in that The method further comprises: The first network element generates a root key for the second non-access stratum session according to the root key for the first non-access stratum session and the identifier of the second non-access stratum session.

24. The method according to any one of claims 21 to 23, characterized in that The second request message also includes security capability information of the terminal device, where the security capability information is used to indicate one or more encryption algorithms supported by the terminal device and / or one or more integrity protection algorithms supported by the terminal device. The security capability information is used to determine the security algorithm corresponding to the second non-access layer session, and the security algorithm includes at least one of the following algorithms: an encryption algorithm for encrypting non-access layer messages transmitted through the second non-access layer session, or an integrity protection algorithm for performing integrity protection on non-access layer messages transmitted through the second non-access layer session.

25. The method according to any one of claims 21 to 24, characterized in that The method further comprises: The first network element receives first indication information from the second network element, where the first indication information is used to instruct the terminal device to activate a security mode for the second non-access stratum session; wherein the security mode includes one or more of the following: encrypting a non-access stratum message transmitted through the second non-access stratum session, or performing integrity protection on a non-access stratum message transmitted through the second non-access stratum session; The first network element sends the first indication information to the terminal device.

26. The method according to any one of claims 21 to 25, characterized in that The second request message includes address information of the access network device and a first identifier, where the address information of the access network device is used to send a message to the access network device, and the first identifier is used to indicate the context of the terminal device in the access network device.

27. The method according to claim 26, characterized in that Before the first network element sends the second request message to the second network element, the method further includes: The first network element receives the first identifier from the access network device.

28. The method according to any one of claims 13 to 27, characterized in that The method further comprises: The first network element sends a third request message to the access network device, where the third request message is used to request establishment of the second non-access stratum session, and the third request message includes an identifier of the second non-access stratum session.

29. The method according to claim 28, characterized in that The method further comprises: The first network element receives second indication information from the second network element, where the second indication information indicates establishment of the second non-access stratum session; The first network element sending a third request message to the access network device includes: The first network element sends the third request message to the access network device according to the second indication information.

30. The method according to any one of claims 13 to 29, characterized in that The method further comprises: The first network element sends an identifier of the second non-access layer session to the terminal device.

31. A communication method, characterized in that: The method comprises: The second network element receives a second request message from the first network element, where the second request message is used to request establishment of a second non-access stratum session; the second non-access stratum session is used to transmit non-access stratum messages between the terminal device and the second network element; and a first non-access stratum session for transmitting non-access stratum messages exists between the first network element and the terminal device; The second network element sends a first response message to the first network element for the second request message.

32. The method according to claim 31, wherein The first response message includes a third request message, where the third request message is used to request the access network device to establish the second non-access layer session, and the third request message includes address information of the second network element and an identifier of the second non-access layer session.

33. The method according to claim 31, characterized in that The first response message includes second indication information, the second indication information instructs the access network device to establish the second non-access layer session, the second indication information is used to trigger the first network element to send a third request message to the access network device, and the third request message is used to request the establishment of the second non-access layer session.

34. The method according to claim 31, wherein The method further comprises: The second network element sends a third request message to the access network device, where the third request message is used to request the access network device to establish the second non-access layer session. The third request message includes address information of the second network element and an identifier of the second access layer session.

35. The method according to claim 34, wherein The second request message includes address information of the access network device and a first identifier, where the first identifier is used to indicate the context of the terminal device in the access network device; The second network element sending a third request message to the access network device includes: The second network element sends the third request message to the access network device according to the address information of the access network device and the first identifier.

36. The method according to claim 34 or 35, characterized in that The method further comprises: The second network element sends a second response message to the terminal device through the third request message, where the second response message is used to indicate that the second non-access layer session is successfully established, and the second response message includes an identifier of the second non-access layer session.

37. The method according to any one of claims 31 to 36, characterized in that Before the second network element receives the second request message from the first network element, the method further includes: The second network element receives a fifth request message from the first network element, where the fifth request message is used to request a service provided by the second network element; The second network element sends fourth information to the first network element according to the fifth request message, where the fourth information is used to indicate establishment of the second non-access layer session.

38. The method according to any one of claims 31 to 37, characterized in that The method further comprises: The second network element receives a third response message from the access network device, where the third response message includes address information and a second identifier of the access network device, where the second identifier is used to indicate a context of the second non-access layer session in the access network device.

39. The method according to any one of claims 31 to 38, wherein: The first response message includes an identifier of the second non-access stratum session.

40. The method according to any one of claims 31 to 39, characterized in that The method further comprises: The second network element sends first indication information to the first network element, and the first indication information is used to instruct the terminal device to activate a security mode for the second non-access layer session; the security mode includes one or more of the following: encrypting non-access layer messages transmitted through the second non-access layer session, or performing integrity protection on non-access layer messages transmitted through the second non-access layer session.

41. The method according to any one of claims 31 to 39, wherein: The method further comprises: The second network element sends first indication information to the terminal device through the second non-access layer session, and the first indication information is used to instruct the terminal device to activate a security mode for the second non-access layer session; the security mode includes one or more of the following: encrypting non-access layer messages transmitted through the second non-access layer session, or performing integrity protection on non-access layer messages transmitted through the second non-access layer session.

42. The method according to claim 40 or 41, characterized in that The method further comprises: The second network element obtains a key for the second non-access stratum session, where the key for the second non-access stratum session includes at least one of the following keys: a key for the encryption and a key for the integrity protection; The second network element uses the key of the second non-access layer session to perform at least one of the following on the first indication information: the encryption or the integrity protection.

43. The method according to claim 42, characterized in that The second network element obtaining a key for a second non-access layer session includes: The second network element generates a key for the second non-access layer session based on the root key of the second non-access layer session, wherein the second request message includes the root key of the second non-access layer session, or the contract information of the terminal device includes the root key of the second non-access layer session.

44. The method according to any one of claims 40 to 43, wherein: The method further comprises: The second network element obtains security capability information of the terminal device, where the security capability information is used to indicate one or more encryption algorithms supported by the terminal device and / or one or more integrity protection algorithms supported by the terminal device; The second network element determines the security algorithm corresponding to the second non-access layer session based on the security capability information of the terminal device; wherein the security algorithm includes one or more of the following algorithms: an encryption algorithm used for the encryption, or an integrity protection algorithm used for the integrity protection.

45. The method according to claim 44, characterized in that The second request message includes the security capability information, and / or the subscription information of the terminal device includes the security capability information.

46. The method according to any one of claims 31 to 45, characterized in that The second non-access stratum session includes one or more quality of service flows, and the method further includes: The second network element sends a mapping rule to the terminal device, where the mapping rule includes a correspondence between a non-access layer message transmitted through the second non-access layer session and each of the one or more quality of service flows.

47. The method according to any one of claims 31 to 46, wherein: The second non-access stratum session includes one or more quality of service flows, and the method further includes: The second network element sends a fourth request message to the access network device, where the fourth request message is used to request configuration of a radio bearer corresponding to each quality of service flow in the one or more quality of service flows.

48. The method according to claim 46 or 47, characterized in that The method further comprises: The second network element sends a second non-access layer message and identification information of a second quality of service flow corresponding to the second non-access layer message through the second non-access layer session, wherein the identification information of the second quality of service flow is used by the access network device to determine and send the second non-access layer message to the terminal device through the second non-access layer session.

49. A communication method, characterized in that: The method further comprises: The access network device receives a third non-access layer message from the terminal device; The access network device determines that the third non-access stratum message belongs to a third non-access stratum session, where the third non-access stratum session is a non-access stratum session between the terminal device and a third network element; The access network device sends the third non-access layer message to the third network element.

50. The method according to claim 49, wherein The access network device receives a third non-access layer message from the terminal device, including: The access network device receives the third non-access stratum message and the identifier of the third non-access stratum session from the terminal device; The access network device determining that the third non-access stratum message belongs to a third non-access stratum session includes: The access network device determines, according to the identifier of the third non-access stratum session, that the third non-access stratum message belongs to the third non-access stratum session.

51. The method according to claim 50, characterized in that The method further comprises: The access network device determines that the destination network element of the third non-access layer message is the third network element based on the identifier of the third non-access layer session and the first corresponding relationship; wherein the first corresponding relationship includes the correspondence between the identifier of the third non-access layer session and the information of the destination network element of the third non-access layer message.

52. The method according to claim 49, wherein The access network device determining that the third non-access stratum message belongs to a third non-access stratum session includes: The access network device determines, according to a radio bearer used to transmit the third non-access stratum message, that the third non-access stratum message belongs to the third non-access stratum session.

53. The method according to claim 52, characterized in that The method further comprises: The access network device determines, based on the radio bearer used to transmit the third non-access layer message and the second corresponding relationship, that the destination network element of the third non-access layer message is the third network element; wherein the second corresponding relationship includes the correspondence between the radio bearer used to transmit the third non-access layer message, the identifier of the third non-access layer session, and the information of the destination network element of the third non-access layer message.

54. The method according to any one of claims 49 to 53, wherein: The method further comprises: The access network device receives a fourth non-access layer message from the third network element; Determining, by the access network device, that the fourth non-access stratum message belongs to the third non-access stratum session; The access network device sends the fourth non-access stratum message and the identifier of the third non-access stratum session to the terminal device; and / or, The access network device sends the fourth non-access layer message to the terminal device through the radio bearer corresponding to the third non-access layer session.

55. The method according to claim 54, characterized in that The access network device receives a fourth non-access layer message from the third network element, including: The access network device receives the fourth non-access stratum message and the identifier of the third non-access stratum session from the third network element; The access network device determining that the fourth non-access stratum message belongs to the third non-access stratum session includes: The access network device determines, according to the identifier of the third non-access stratum session, that the fourth non-access stratum message belongs to the third non-access stratum session.

56. The method according to claim 54, wherein The access network device receives a fourth non-access layer message from the third network element, including: The access network device receives a fourth non-access stratum message and a third identifier from the third network element; the third identifier is used to indicate the context of the third non-access stratum session in the access network device; The access network device determining that the fourth non-access stratum message belongs to the third non-access stratum session includes: The access network device determines, according to the third identifier, that the fourth non-access stratum message belongs to the third non-access stratum session.

57. The method according to any one of claims 49 to 56, wherein: The method further comprises: The access network device receives a third request message, where the third request message is used to request establishment of the third non-access stratum session, where the third non-access stratum session is used to transmit non-access stratum messages between the terminal device and the third network element; The access network device sends a third response message to the third network element; the third response message includes the address information of the access network device and the third identifier, and the third identifier is used to indicate the context of the third non-access layer session in the access network device.

58. The method according to claim 57, wherein The method further comprises: The access network device receives a fourth request message from the third network element; the fourth request message is used to request configuration of a radio bearer corresponding to each of the one or more quality of service flows included in the third non-access layer session; The access network device configures a radio bearer corresponding to each quality of service flow according to the fourth request message.

59. The method according to claim 58, characterized in that The method further comprises: The access network device receives a fourth non-access stratum message and identification information of a quality of service flow corresponding to the fourth non-access stratum message from the third network element, wherein the one or more quality of service flows include a quality of service flow corresponding to the fourth non-access stratum message; The access network device determines, according to identification information of the quality of service flow corresponding to the fourth non-access stratum message, a radio bearer corresponding to the fourth non-access stratum message; The access network device sends the fourth non-access layer message to the terminal device through the radio bearer corresponding to the fourth non-access layer message.

60. A communication method, characterized in that: The method comprises: The access network device receives a fourth request message from the second network element, where the fourth request message is used to request configuration of a radio bearer corresponding to each of one or more quality of service flows included in a second non-access stratum session, where the second non-access stratum session is used to transmit non-access stratum messages between the terminal device and the second network element; The access network device configures a corresponding radio bearer for each quality of service flow according to the fourth request message; The access network device sends third information to the terminal device, where the third information is used to configure the radio bearer corresponding to each quality of service flow.

61. The method according to claim 60, characterized in that The fourth request message further includes a mapping rule, where the mapping rule includes a correspondence between a non-access stratum message transmitted through the second non-access stratum session and each quality of service flow; The method further comprises: The access network device sends the mapping rule to the terminal device.

62. The method according to claim 60 or 61, characterized in that The method further comprises: The access network device receives a first non-access layer message from the terminal device; The access network device determines, according to a radio bearer used to transmit the first non-access stratum message, that the first non-access stratum message corresponds to a first quality of service flow, and that the second non-access stratum session includes the first quality of service flow; The access network device sends the first non-access layer message and identification information of the first quality of service flow to the second network element.

63. The method according to claim 60 or 61, characterized in that The method further comprises: The access network device receives a first non-access stratum message from the terminal device and identification information of a first quality of service flow corresponding to the first non-access stratum message, wherein the second non-access stratum session includes the first quality of service flow; The access network device sends the first non-access layer message and identification information of the first quality of service flow to the second network element.

64. The method according to any one of claims 60 to 63, wherein: The method further comprises: The access network device receives, from the second network element, a second non-access stratum message and identification information of a second quality of service flow corresponding to the second non-access stratum message; The access network device determines, according to the identification information of the second quality of service flow, a radio bearer corresponding to the second quality of service flow; The access network device sends the second non-access layer message to the terminal device through the radio bearer corresponding to the second quality of service flow.

65. A communication device, characterized in that The communication device comprises a module or unit for executing the method of any one of claims 1-12, or claims 13-30, or claims 31-48, or claims 49-59, or claims 60-64.

66. A communication device, characterized in that The communication device includes: a processor; the processor is configured to execute a computer program or instruction stored in a memory, so that the communication device performs the method according to any one of claims 1-12, or claims 13-30, or claims 31-48, or claims 49-59, or claims 60-64.

67. A computer-readable storage medium, characterized in that A computer program or instruction is stored thereon, which, when executed by a computer, causes the computer to perform the method of any one of claims 1-12, or claims 13-30, or claims 31-48, or claims 49-59, or claims 60-64.

68. A communication system, characterized in that The communication system includes a first network element and a second network element; wherein the first network element is used to execute the method according to any one of claims 13 to 30; and the second network element is used to execute the method according to any one of claims 31 to 48.

69. The communication system according to claim 68, characterized in that The communication system also includes an access network device; wherein the access network device is used to execute the method described in any one of claims 49-59, or the access network device is used to execute the method described in any one of claims 60-64.

Citation Information

Patent Citations

  • Communication method, device and system

    CN120390316A

  • Addressing method, communication device and system

    CN111918279A

  • Method, device and system for configuring radio bearer

    CN113518315A

  • Communication method and device

    CN115334494A

  • User plane connection establishment method and device

    CN117136627A