Method for wireless communication and communication device
Patent Information
- Application Number
- PCT/CN2024/074779
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-30
- Publication Date
- 2025-08-07
Smart Images

Figure CN2024074779_07082025_PF_FP_ABST
Abstract
Description
Wireless communication method and communication device Technical Field
[0001] The present application relates to the field of communication technology, and more specifically, to a wireless communication method and communication device. Background Art
[0002] In related technologies, a terminal device accesses the 3rd Generation Partnership Project (3GPP) core network based on its identifier for registration, authentication, or policy configuration. In some scenarios, the same terminal device can be used by multiple users. Different users may require different services. However, in current technologies, the core network cannot identify different users of the same terminal device, making it impossible to register, authenticate, or configure policies for different users.
[0003] Summary of the Invention
[0004] The present application provides a wireless communication method and a communication device. The following introduces various aspects of the present application.
[0005] In a first aspect, a method for wireless communication is provided, including: a terminal device sends a first message to a first network element, the first message includes a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0006] In a second aspect, a method for wireless communication is provided, including: a first network element receives a first message sent by a terminal device, the first message includes a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0007] According to a third aspect, a method for wireless communication is provided, including: a second network element receives a sixth message sent by a first network element, the sixth message being used to request the second network element to authenticate a first identifier, the first identifier being one of one or more user identifiers corresponding to the identifier of the terminal device.
[0008] In a fourth aspect, a method for wireless communication is provided, including: a third network element receives a seventh message sent by a first network element, the seventh message is used to determine a policy corresponding to a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0009] In the fifth aspect, a method for wireless communication is provided, including: a fourth network element receives an eighth message sent by a first network element, the eighth message is used to determine the contract information corresponding to a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0010] In the sixth aspect, a terminal device is provided, including: a sending unit, used to send a first message to a first network element, the first message includes a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0011] In the seventh aspect, a communication device is provided, which is a first network element, and the communication device includes: a receiving unit, used to receive a first message sent by a terminal device, the first message includes a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0012] In the eighth aspect, a communication device is provided, which is a second network element, and the communication device includes: a receiving unit, used to receive a sixth message sent by the first network element, and the sixth message is used to request the second network element to authenticate the first identifier, and the first identifier is one of one or more user identifiers corresponding to the identifier of the terminal device.
[0013] In the ninth aspect, a communication device is provided, which is a third network element, and the communication device includes: a receiving unit, used to receive a seventh message sent by the first network element, the seventh message is used to determine the policy corresponding to the first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0014] In the tenth aspect, a communication device is provided, which is a fourth network element, and the communication device includes: a receiving unit, used to receive an eighth message sent by the first network element, the eighth message is used to determine the contract information corresponding to the first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0015] In the eleventh aspect, a communication device is provided, comprising a processor, a memory, and a communication interface, wherein the memory is used to store one or more computer programs, and the processor is used to call the computer program in the memory so that the communication device executes part or all of the steps in the methods of the above aspects.
[0016] In a twelfth aspect, a chip is provided, which includes a processor, and the processor can call a program from a memory so that a device equipped with the chip executes some or all of the steps described in the above-mentioned various aspects of the method.
[0017] In a thirteenth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and the computer program enables a communication device to execute part or all of the steps in the methods of the above aspects.
[0018] In a fourteenth aspect, a computer program product is provided, wherein the computer program product includes a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a communication device to perform some or all of the steps of the methods of the above aspects. In some implementations, the computer program product may be a software installation package.
[0019] In the fifteenth aspect, a computer program is provided, characterized in that the computer program enables a computer to execute part or all of the steps in the methods of the above-mentioned various aspects of the embodiments of the present application.
[0020] A first identifier is introduced in an embodiment of the present application, wherein the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers. In this way, the terminal device can send a first message containing the first identifier to the first network element so that the core network can identify the user corresponding to the first identifier, thereby realizing user-granular registration, authentication or policy configuration, etc. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] FIG1 is a schematic diagram of a wireless communication system to which an embodiment of the present application is applicable.
[0022] FIG2 is a flowchart of a UE policy configuration process applicable to an embodiment of the present application.
[0023] FIG3 a is a schematic diagram of a usage scenario applicable to an embodiment of the present application.
[0024] FIG3 b is a schematic diagram of another usage scenario applicable to the embodiment of the present application.
[0025] FIG3 c is a schematic diagram of another usage scenario to which the embodiment of the present application is applicable.
[0026] FIG4 is a flow chart of a wireless communication method according to an embodiment of the present application.
[0027] FIG5 is a flow chart of a wireless communication method provided in another embodiment of the present application.
[0028] FIG6 is a flowchart of a wireless communication method provided in another embodiment of the present application.
[0029] FIG7 is a flow chart of a wireless communication method provided in another embodiment of the present application.
[0030] FIG8 is a flowchart of a wireless communication method provided in yet another embodiment of the present application.
[0031] FIG9 is a flowchart of a wireless communication method provided in another embodiment of the present application.
[0032] FIG10 is a flow chart of a wireless communication method provided in yet another embodiment of the present application.
[0033] FIG11 is a schematic diagram of the structure of a terminal device provided in an embodiment of the present application.
[0034] FIG12 is a schematic structural diagram of a communication device provided in an embodiment of the present application.
[0035] FIG13 is a schematic structural diagram of a communication device provided in another embodiment of the present application.
[0036] FIG14 is a schematic structural diagram of a communication device provided in yet another embodiment of the present application.
[0037] FIG15 is a schematic structural diagram of a communication device provided in yet another embodiment of the present application.
[0038] FIG. 16 is a structural diagram of a communication device provided in another embodiment of the present application. DETAILED DESCRIPTION
[0039] The technical solutions in this application will be described below in conjunction with the accompanying drawings. To facilitate understanding of this application, the following first introduces the architecture applicable to the embodiments of this application, the communication processes involved, and terminology.
[0040] The technical solutions of the embodiments of the present application can be applied to various wireless communication systems, such as: global system of mobile communication (GSM) system, code division multiple access (CDMA) system, wideband code division multiple access (WCDMA) system, general packet radio service (GPRS) system, long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, advanced long term evolution (LTE-A) system, new radio (NR) system, NR system evolution system, LTE-based access to unlicensed spectrum (LTE-U) system, NR-U system, universal mobile telecommunication system (UMTS), world-wide interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wireless Fidelity) system. fidelity, WiFi), next generation communication systems or other communication systems, etc.
[0041] FIG1 is a schematic diagram of a wireless communication system to which an embodiment of the present application is applicable. As shown in Figure 1, the fifth generation (5G) system or new radio (NR) network architecture released by the 3rd Generation Partnership Project (3GPP) standard group includes: terminal equipment (also known as "user equipment (UE)" 101, access network equipment supporting 3GPP technology 102 (including radio access network (RAN) or access network (AN)), user plane function (UPF) network element 105, access and mobility management function (AMF) network element 103, session management function (SMF) network element 104, policy control function (PCF) network element 106, application function (AF) network element 109, data network (DN) 108, network slice selection function (NSSF) 111, authentication server function (AUSF) 110, unified data management function (UDF) network element 111, and the like. management, UDM)107.
[0042] It should be noted that the network architecture shown in Figure 1 does not constitute a limitation on the 5G network architecture. In specific implementations, the 5G network architecture may include more or fewer network elements than shown, or may combine certain network elements. In addition, in Figure 1, the AN or RAN is represented in the form of (R)AN.
[0043] The terminal device 101 may be user equipment (UE), a terminal, a handheld terminal, a laptop computer, a subscriber unit, a cellular phone, a smart phone, a wireless data card, a personal digital assistant (PDA), a tablet computer, a wireless modem, a handheld device, a laptop computer, a cordless phone, or a wireless local loop (WLL) station, a machine type communication (MTC) terminal, a handheld device with wireless communication capabilities, a computing device, a processing device connected to a wireless modem, an unmanned aerial vehicle (UAV), an in-vehicle device, a wearable device, a terminal in the Internet of Things (IoT), a virtual reality device, a terminal device in a future communication system (e.g., 6G) network, a terminal in a future evolved public land mobile network (PLMN), etc. The wearable device may be, for example, a watch, a bracelet, or glasses based on augmented reality (AR) / virtual reality (VR) technology.
[0044] The access network device 102 is an access device that connects terminal devices to the network architecture wirelessly. It is primarily responsible for radio resource management, quality of service (QoS) management, data compression and encryption, etc. on the air interface side. Examples include NodeBs, evolved eNodeBs, base stations in 5G mobile communication systems or new radio (NR) communication systems, and base stations in future mobile communication systems.
[0045] AMF network element 103, SMF network element 104, UPF network element 105, and PCF network element 106 are network elements of the 3GPP core network (referred to as core network elements). UPF network element 105 can be called a user plane function network element, which is mainly responsible for the transmission of user data. Other network elements can be called control plane function network elements, which are mainly responsible for authentication, authorization, registration management, session management, mobility management, and policy control to ensure reliable and stable transmission of user data.
[0046] The AMF network element 103 (or "AMF" for short) can be used to manage the access of terminal devices to the core network, such as: location update of terminal devices, registration network, access control, mobility management of terminal devices, attachment and detachment of terminal devices, etc. The AMF network element can also provide storage resources of the control plane for the session while providing services for the session of the terminal device, so as to store the session identifier, the SMF network element identifier associated with the session identifier, etc. The functions related to this application may be the management of access authorization\authentication. When the terminal device registers to the service network, the AMF network element of the service network sends an initial authentication request to the AUSF network element of the home network, and receives the authentication vector from the AUSF network element of the home location to complete the authentication of the terminal device in the service network. After the terminal device passes the authentication in the service network, the AMF network element initiates the registration process, and the AMF network element obtains the user contract data from the UDM network element.
[0047] The SMF network element 104 (or "SMF" for short) can be used to select a user plane network element for a terminal device, redirect a user plane network element for a terminal device, allocate an Internet Protocol (IP) address for a terminal device, establish a bearer (also called a session) between the terminal device and the UPF network element, modify and release the session, and control QoS.
[0048] The UPF network element 105 (or simply "UPF") can be used to forward and receive data from terminal devices. For example, the UPF network element can receive service data from the data network and transmit it to the terminal device through the access network device; the UPF network element can also receive user data from the terminal device through the access network device and forward it to the data network. Among them, the transmission resources allocated and scheduled by the UPF network element for the terminal device are managed and controlled by the SMF network element. The bearer between the terminal device and the UPF network element may include: a user plane connection between the UPF network element and the access network device, and the establishment of a channel between the access network device and the terminal device. Among them, the user plane connection is a quality of service (QoS) flow that can be established between the UPF network element and the access network device to transmit data.
[0049] The PCF network element 106 (or simply "PCF") is used to provide policies, such as QoS policy, slice selection policy, UE policy, etc., to the AMF network element 103 and the SMF network element 104. In some implementations, the PCF can manage the issuance and update of policies.
[0050] The UDM network element 107 (or "UDM" for short) includes functions such as generating and storing user subscription data, managing authentication data, and supporting interaction with external third-party servers. During the registration process, the UDM network element can return the subscription data after receiving the registration message sent by the AMF.
[0051] DN network element 108 can provide data services to users, such as IP Multimedia Service (IMS) networks and the Internet. DN 108 can contain multiple application servers (ASs) that provide different application services, such as carrier services, Internet access, or third-party services. ASs can implement the functions of AF network elements.
[0052] The AF network element 109 (or simply "AF") is used to interact with the 3GPP core network elements to support application-affected data routing, access network exposure functions, and interact with the PCF network elements for policy control.
[0053] The AUSF network element 110 (or "AUSF" for short) is used to receive the request from AMF 103 to authenticate the terminal device, request the key from UDM 107, and then forward the issued key to AMF 103 for authentication processing.
[0054] NSSF network element 111 (or simply "NSSF") is used for network slice selection and supports the following functions: selecting a set of network slice instances to serve the UE; determining the allowed network slice selection assistance information (NSSAI) and, when necessary, determining the mapping to the contracted single-network slice selection assistance information (S-NSSAI); determining the configured NSSAI and, when necessary, determining the mapping to the contracted S-NSSAI; determining the set of AMFs that may be used to query the UE, or determining a list of candidate AMFs based on the configuration.
[0055] It should be understood that each network element in Figure 1 can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). It should be noted that the network architecture shown in the above figure is only an example of the network elements included in the entire network architecture. In the embodiments of the present application, the network elements included in the entire network architecture are not limited.
[0056] In order for the terminal device to access the 3GPP core network (referred to as the core network) and enjoy the services provided by the core network, the communication message between the terminal device and the network elements of the core network may include the terminal device's identification to facilitate the identification of the terminal device and registration, authentication or policy configuration for the terminal device.
[0057] In an embodiment of the present application, the identifier of the terminal device is an identifier used to indicate the identity of the terminal device. In some embodiments, the identifier of the terminal device is stored in a subscriber identity module (SIM) or a universal subscriber identity module (USIM).
[0058] The embodiments of the present application do not specifically limit the type of identifier of the terminal device, as long as it can be used to identify the terminal device. As an example, the identifier of the terminal device can be an international mobile subscriber identity (IMSI), a subscriber permanent identifier (SUPI), or an identifier determined based on the SUPI.
[0059] As an example, the identifier determined based on the SUPI may be a user concealed identifier (SUCI) or a globally unique temporary UE Identity (GUTI). The SUCI may be understood as a privacy-protected SUPI.
[0060] For ease of understanding, the policy configuration for the identification of a terminal device in the related art is exemplarily described below with reference to FIG. 2 .
[0061] UE policy configuration process
[0062] Figure 2 is a flow chart of a UE policy configuration process applicable to an embodiment of the present application. The method shown in Figure 2 includes steps S210 to S260.
[0063] In step S210 , the PCF determines whether to update the UE policy.
[0064] It should be noted that if the PCF does not intend to update the UE policy, step S210 may not be included in the process shown in Figure 2. If the PCF does determine that the UE policy is to be updated, step S210 will be included in the process shown in Figure 2. In addition, if the PCF determines that the UE policy is to be updated, the process shown in Figure 2 is also referred to as the "UE configuration update (UCU)" process.
[0065] In step S220, the PCF sends a communication service request to the AMF.
[0066] In some implementations, the uplink service request may carry the terminal device identifier (hereinafter referred to as the UE identifier) and a container containing relevant information about the UE policy. For example, the content of the UE policy or the UE policy identifier, etc. In some embodiments, the terminal device identifier is carried in the container.
[0067] The communication service request can be transmitted via N1 and N2 messages. Therefore, the communication service request can also be expressed as "Namf_Communication_N1N2 Message Transfer".
[0068] In step S230, the network triggers a service request so that the network can communicate with the UE. The service request may include an identifier of the UE.
[0069] In step S240, the AMF sends the UE policy to the UE.
[0070] In some implementations, the UE policy may be encapsulated in a container, which may be a container sent by the PCF to the AMF. Accordingly, after receiving the container, the AMF may transparently transmit the container directly to the UE. Transparent transmission may be understood as the AMF not being aware of or modifying the container.
[0071] In other implementations, the above-mentioned UE policy or container can be sent by the AMF to the UE through a downlink non-access stratum (NAS) message (or downlink NAS message).
[0072] In step S250, the UE sends the UE policy transmission result to the AMF.
[0073] In some implementations, the UE policy transmission result is used to indicate whether the UE successfully receives the UE policy. The UE policy transmission result may include an identifier of the UE.
[0074] In step S260, the AMF sends an N1 message notification (expressed as "Namf_N1MessageNotify") to the PCF to inform the PCF of the above UE policy transmission result.
[0075] In some implementations, the above-mentioned N1 message notification can be called "Manage UE policy complete message".
[0076] It should be noted that the above steps S220 and S260 may include two messages, namely a request and a response to the request. The method shown in FIG2 only shows the requests of the two steps, and does not show the two responses to the above two requests.
[0077] In addition, as described above, the PCF can send a container to the UE to transmit the UE policy. Conversely, the UE can also send a container to the PCF through the container. At this time, the container can be sent by the UE to the AMF through an uplink NAS message, and then transparently transmitted by the AMF to the PCF.
[0078] In the process shown in Figure 2, to convey UE policy, a "UE policy container" cause value is introduced into downlink NAS and uplink NAS messages. For example, the UE policy container cause value can be added to the payload container. Accordingly, after obtaining the UE policy container cause value, the AMF can perform a transparent transmission function to transparently transmit the container to the UE or PCF.
[0079] UE Strategy
[0080] UE policy may include UE route selection policy (URSP) and access network discovery and selection policy (ANDSP), etc. URSP is taken as an example below.
[0081] The URSP may indicate the binding relationship between application data and a protocol data unit (PDU) session. In addition, the URSP may also indicate what type of PDU session the UE needs to establish to transmit the application data. Typically, the URSP may include one or more URSP rules.
[0082] URSP rules may include one or more of the following information: rule precedence, traffic descriptor (TD), application descriptors, IP descriptors, domain descriptors, non-IP descriptors, data network name (DNN), connection capabilities, and route selection descriptor (RSD) list.
[0083] It should be noted that each URSP rule in a URSP has a different rule priority. In other words, different URSP rules in a URSP correspond to different rule priorities.
[0084] It can be seen from the above-mentioned embodiments of UE policy configuration that, in related technologies, communication messages between a terminal device and a core network generally include an identifier of the terminal device to identify the terminal device or perform policy configuration for the terminal device.
[0085] However, with the development and popularization of electronic devices, there are many different types of terminal devices available for consumers to use, and each type of terminal device has its own advantages. In view of this, there may be the following three scenarios: Scenario 1, the same user can have multiple terminal devices (as shown in Figure 3a); Scenario 2, the same terminal device can have multiple users (as shown in Figure 3b); Scenario 3, multiple terminal devices can have multiple users, where each terminal device has one or more users (as shown in Figure 3c).
[0086] Based on the above scenarios, it can be known that the following scenarios will appear in these scenarios: a terminal device can be used by multiple users. It should be understood that in the embodiment of the present application, the user of the terminal device can be a person or an electronic device, and the embodiment of the present application does not make specific limitations on this. For example, when the same terminal device (for example, a mobile phone) is used by multiple people, the multiple people can serve as multiple users corresponding to the terminal device. For another example, when the same terminal device is connected to the 3GPP network as a gateway (GW) by multiple electronic devices, the multiple electronic devices can serve as multiple users corresponding to the terminal device. As an example, when a tablet computer and a laptop computer are both connected to the core network through a mobile phone as a GW, the tablet computer and the laptop computer can be multiple users corresponding to the mobile phone.
[0087] Different users of the same terminal device may require different services when accessing the core network. However, as previously mentioned, in current technology, terminal devices and core network elements register, authenticate, or configure policies for terminal devices based on communication messages containing the terminal device's identifier. In other words, in current technology, the core network can only distinguish between different terminal devices, but cannot identify the user using the terminal device. Consequently, registration, authentication, or policy configuration for different users cannot be performed.
[0088] In view of this, an embodiment of the present application introduces a first identifier, wherein the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers. In the wireless communication method proposed in an embodiment of the present application, the terminal device can send a first message containing the first identifier to a network element of the core network, so that the core network can identify the user corresponding to the first identifier, thereby realizing user-granular registration, authentication or policy configuration, etc.
[0089] The wireless communication method according to an embodiment of the present application is described below with reference to FIG4 . The method shown in FIG4 includes step S410 .
[0090] In step S410, the terminal device sends a first message to the first network element.
[0091] In this embodiment of the present application, the first message includes a first identifier. The terminal device identifier corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers. For example, the first identifier may be the identifier corresponding to the user currently using the terminal device. The user identifier may be referred to as a user ID (user identifier or user identity), and the user identifier is used to identify a specific user using the terminal device.
[0092] The embodiments of this application do not specifically limit the type of user identifier. As an example, the user identifier may be a username. The username may be, for example, the user's name or email address. The user's name may be a person's name or a device name. As another example, the user identifier may be a biometric feature of the user. The biometric feature may be, for example, a face, fingerprint, or pupil.
[0093] As an implementation manner, the identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on the SUPI.
[0094] The first network element may be any network element in the core network. As an example, the first network element may be a network element used to enable a terminal device to access the core network. For example, the first network element may be an AMF.
[0095] The first message may be a NAS message. The embodiment of the present application does not specifically limit the purpose of the first message, as long as the first message is a message sent by the terminal device to the first network element.
[0096] As an example, the first message may be used to authenticate the first identifier.
[0097] As an implementation manner, the first message is a first registration request message.
[0098] As an implementation manner, the first message is a response message to the authentication request message sent by the first network element.
[0099] As an implementation manner, the authentication request message is a first registration reply message.
[0100] As an implementation manner, the first message further includes authentication information of the first identifier.
[0101] As an implementation, the authentication information includes one or more of the following: a user name; a password; a first key, determined based on biometric information of a user of the terminal device, and an authentication parameter generated based on the first key.
[0102] As an implementation, the method further includes: the terminal device receiving a second message sent by the first network element. The second message includes one or more of the following: a second identifier, the second identifier being an identifier used after the first identifier is successfully authenticated; and an authentication result indicating whether the authentication of the first identifier succeeded or failed.
[0103] In some embodiments, the second message may include a second identifier. Whether the second message includes the second identifier indicates whether the authentication of the first identifier is successful. If the second message includes the second identifier, the authentication is successful; if the second message does not include the second identifier, the authentication is unsuccessful. The second identifier is similar to a token or certificate. Subsequent access by the user using a terminal device only requires the second identifier and does not require re-authentication.
[0104] In some embodiments, the second message may include an authentication result. If the authentication is successful, the authentication result indicates that the authentication of the first identifier is successful; if the authentication fails, the authentication result indicates that the authentication of the first identifier fails.
[0105] As an implementation manner, the second message is a first registration reply message.
[0106] As an implementation manner, the second message is generated after the first network element authenticates the first identifier.
[0107] As an implementation manner, the second message may be obtained by the first network element through the second network element.
[0108] As an implementation method, the method also includes: the first network element sends a sixth message to the second network element, and the sixth message is used to request the second network element to authenticate the first identifier; and / or the first network element receives a reply message to the sixth message sent by the second network element, and the reply message to the sixth message includes one or more of the following: a second identifier, the second identifier is an identifier used after the first identifier is successfully authenticated; an authentication result, used to indicate whether the authentication of the first identifier is successful or failed.
[0109] As an implementation manner, the second network element is a network element of a core network, or the second network element is an authentication server that is communicatively connected to the core network.
[0110] In some embodiments, after the first identifier is authenticated, the first network element may also obtain subscription information or policy information corresponding to the first identifier.
[0111] As an implementation manner, the method further includes: the first network element sending a seventh message to a third network element, where the seventh message is used to determine a policy corresponding to the first identifier.
[0112] As an implementation method, the seventh message includes the first identifier after authentication, and the method also includes: the first network element receives a reply message to the seventh message sent by the third network element, and the reply message of the seventh message includes the policy corresponding to the first identifier.
[0113] As an implementation method, the seventh message includes the identification of the terminal device after authentication, and the method also includes: the first network element receives a reply message to the seventh message sent by the third network element, and the reply message of the seventh message includes the policies corresponding to the one or more user identifications; after the first identification is successfully authenticated, the first network element determines the policy corresponding to the first identification from the policies corresponding to the one or more user identifications.
[0114] As an implementation manner, the third network element is a policy control function PCF network element.
[0115] As another implementation manner, the method further includes: the first network element sending an eighth message to the fourth network element, where the eighth message is used to determine the contract information corresponding to the first identifier.
[0116] As an implementation method, the eighth message includes the first identifier after authentication, and the method also includes: the first network element receives a reply message to the eighth message sent by the fourth network element, and the reply message to the eighth message includes the contract information corresponding to the first identifier.
[0117] As an implementation method, the eighth message includes the identification of the terminal device after authentication, and the method also includes: the first network element receives a reply message to the eighth message from the fourth network element, and the reply message of the eighth message includes the contract information corresponding to the one or more user identifications; after the first identification is successfully authenticated, the first network element determines the contract information corresponding to the first identification from the contract information corresponding to the one or more user identifications.
[0118] As an implementation method, the fourth network element is a unified data management function UDM network element.
[0119] As another example, the first message is used to request verification of the first identifier.
[0120] As previously mentioned, after authenticating the first identifier, if the first identifier is successfully authenticated, the terminal device can obtain the second identifier through a second message. In some cases, the user needs to authenticate again. To avoid repeated authentication during identity verification, the terminal device can also verify the second identifier through a third message.
[0121] As an implementation manner, the method further includes: the terminal device sending a third message to the first network element, the third message being used to verify the second identifier. Optionally, the third message may include the second identifier.
[0122] In some embodiments, the first network element may send a verification request message to a network element capable of verifying the second identifier based on the third message. The verification request message may include the second identifier. The network element capable of verifying the second identifier is typically the same as the network element capable of authentication, that is, the network element capable of verifying the second identifier is the second network element. This embodiment of the present application does not specifically limit the process by which the second network element verifies the second identifier.
[0123] As an example, an identifier list is stored in the second network element, and the verification process can be that the second network element searches the storage list to see whether there is a second identifier that has been stored. If so, it indicates that the second identifier verification is successful; if not, it indicates that the second identifier verification fails.
[0124] As another example, the second network element stores a first identifier and a second identifier corresponding to the first identifier. The verification process may be that the second network element compares the second identifier in the verification request message to see whether it is the same as the stored second identifier corresponding to the first identifier. If they are the same, it indicates that the second identifier verification is successful. If they are not the same, it indicates that the second identifier verification has failed.
[0125] As an implementation method, the third message is triggered based on one or more of the following: switching from a third identifier to a first identifier, where the third identifier is one of one or more user identifiers; the user corresponding to the first identifier has not used the terminal device within a first period of time; the terminal device initiates a periodic registration update; the network device instructs the terminal device to send a second identifier.
[0126] As an implementation manner, the periodic registration update includes one or more of the following: a periodic registration update for the identifier of the terminal device; and a periodic registration update for the first identifier.
[0127] As an implementation manner, the second identifier includes the first identifier; or, the second identifier does not include the first identifier, and the third message includes the first identifier.
[0128] As an implementation manner, the third message is a second registration request message.
[0129] As an implementation method, the method also includes: the terminal device receives a fourth message sent by the first network element, and the fourth message includes a verification result of the second identifier.
[0130] As an implementation manner, the fourth message is a second registration reply message.
[0131] As another example, the first message is used to request the core network to update the policy of the terminal device to the policy corresponding to the first identifier.
[0132] As an implementation manner, the first message is used to request that the policy of the terminal device be updated to the policy corresponding to the first identifier.
[0133] As an implementation manner, the first message includes a policy container of the terminal device, and the first identifier is carried in the policy container.
[0134] As an implementation manner, the first message is also used to verify the second identifier, and the second identifier is an identifier used after the first identifier is successfully authenticated.
[0135] As an implementation manner, the method further includes: the terminal device receives a fifth message sent by the first network element, and the fifth message is used to update the policy of the terminal device to the policy corresponding to the first identifier.
[0136] In some embodiments, the fifth message may be obtained by the first network element from the second network element.
[0137] The wireless communication method provided in the embodiment of the present application can send a first message containing a first identifier to a first network element through a terminal device, so that the core network can identify the user corresponding to the first identifier, thereby realizing user-granular registration, authentication or policy configuration, etc.
[0138] For ease of understanding, the following describes how the embodiments of the present application perform authentication, registration, or UE policy update for the first identifier.
[0139] Example 1 (Authentication)
[0140] As shown in FIG5 , the wireless communication method described in the embodiment of the present application includes steps S510 - S520 .
[0141] In step S510, the terminal device sends a first message to the first network element.
[0142] The first message is used to authenticate the first identifier. The embodiment of the present application does not specifically limit the type of the first message.
[0143] As an implementation, the first message may be a first registration request message as shown in Figure 6. The first registration request message may be triggered by step S601 in Figure 6. As shown in step S601: a user corresponding to a first identifier (hereinafter referred to as user 1) initiates initial registration using a terminal device.
[0144] The initial registration may be, for example, a registration initiated by user 1 when the terminal is turned on for the first time, or a registration sent when a new user (user 1) uses the terminal device. A new user may be understood as a user who has never registered with the terminal device.
[0145] In some embodiments, the first message may further include an identifier of the terminal device. The identifier of the terminal device may be the SUPI, SUCI, or IMSI described above. Optionally, the first message is further used to authenticate the identifier of the terminal device.
[0146] Optionally, the first message may further include a first capability. The first capability is used to indicate that the terminal device supports relevant capabilities based on user granularity (i.e., first identifier granularity), such as user information collection, user identifier authentication, user-granular policy configuration, and user-granular parameter configuration.
[0147] Optionally, the first capability may be sent to the first network element as a NAS capability.
[0148] Optionally, the first capability may be that the terminal device reports to the first network element after the first network element requires the terminal device to report.
[0149] As another implementation manner, the first message may be a response message (or a reply message of the authentication request message) sent by the first network element as shown in FIG. 7 .
[0150] In some embodiments, the first message may further include authentication information of the first identifier. The authentication information of the first identifier may be understood as information used to authenticate the first identifier.
[0151] As an example, the authentication information of the first identifier includes one or more of the following: a user name, a password, a first secret key, and an authentication parameter generated based on the first secret key.
[0152] The user name can be the person's name or device name as mentioned above.
[0153] The password can be a password associated with the user name. For example, the password can be the password that the user enters when logging in with the user name.
[0154] The first key may be determined based on biometric information of a user of the terminal device. Biometric information includes biometric information such as fingerprint and face. As an example, the first key may be a key generated by combining the biometric information with configured auxiliary parameters.
[0155] The authentication parameters generated based on the first secret key can be used to send to the network side for authentication in a subsequent method.
[0156] In some implementations, the first identifier and the authentication information may be encapsulated in a container or an Extensive Authentication Protocol (EAP) message.
[0157] In step S520, the terminal device receives the second message sent by the first network element.
[0158] The second message is a message sent by the first network element to the terminal device after authenticating the first identifier. The second message includes one or more of the following: a second identifier and an authentication result. The second identifier is used after the first identifier is successfully authenticated. As an example, the second identifier is similar to a token or certificate. Subsequent access by the user using the terminal device only requires the second identifier and does not require re-authentication. The authentication result indicates whether the authentication of the first identifier succeeded or failed.
[0159] In some embodiments, the second message may be the authentication reply message shown in FIG. 7 .
[0160] In other embodiments, the second message is the first registration reply message as shown in Figure 6. By setting the second message as the first registration reply message, the first identifier can be authenticated based on the existing registration process, so that the impact of the first identifier authentication on the existing architecture can be controlled.
[0161] In the wireless communication method provided in the embodiments of the present application, a terminal device can send a first message (including the first identifier) to a first network element for authenticating a first identifier, and receive a second message from the first network element including a second identifier and / or an authentication result. This achieves authentication at the user identifier granularity.
[0162] The embodiment of the present application does not specifically limit the network element that generates the second identifier and / or authentication result.
[0163] As an example, the second identifier and / or the authentication result may be generated by a first network element having an authentication function.
[0164] As another example, the second identifier and / or the authentication result may be received by the first network element from the second network element. The second network element may be a network element having an authentication function and different from the first network element.
[0165] As an example, the second network element may be a network element with an authentication function (referred to as authentication function) within the core network. For example, the second network element may be an AUSF.
[0166] As another example, the second network element may be a network element with an authentication function outside the core network (referred to as an authentication server). For example, the second network element may be an authentication server that is communicatively connected to the core network.
[0167] In view of this, as shown in FIG5 , the wireless communication method provided in the embodiment of the present application further includes steps S530 and / or S540.
[0168] Step S530: The first network element sends a sixth message to the second network element.
[0169] The sixth message includes the first identifier and the authentication message, and the sixth message is used to request the second network element to authenticate the first identifier.
[0170] Step S540: The first network element receives a reply message to the sixth message sent by the second network element.
[0171] The reply message to the sixth message is generated after the second network element performs authentication on the first identifier, and the reply message to the sixth message includes one or more of the following: the second identifier and the authentication result.
[0172] In some embodiments, the second network element may include an authentication function and an authentication server. In view of this, the wireless communication method provided in the embodiments of the present application may include: the first network element first sending a sixth message to one of the authentication function and the authentication server and / or receiving a reply message to the sixth message sent by one of the authentication function and the authentication server; if the authentication result in the reply message to the sixth message indicates that the authentication failed, the first network element continues to send the sixth message to the other of the authentication function and the authentication server and / or receives a reply message to the sixth message sent by the other of the authentication function and the authentication server.
[0173] The embodiment of the present application can achieve double protection of authentication at the user identification granularity by setting up two different network elements with authentication functions, thereby avoiding user registration failure caused by authentication failure of a single network element with authentication function.
[0174] In some embodiments, as shown in FIG. 7 , before step S530 , the method may further include step S710 : the first network element determines to perform authentication of the first identifier on the terminal device.
[0175] As an example, the first network element may determine to perform authentication of the first identifier based on the first capability reported by the terminal device, indication information sent by other network elements (such as the authentication function AUSF) and / or the local configuration of the first network element.
[0176] As mentioned above, the first message may be a response message to the authentication request message sent by the first network element. In view of this, as shown in FIG7 , after step S710 , the wireless communication method includes steps S720 and S730 .
[0177] In step S720: the first network element sends an authentication request message to the terminal device.
[0178] The authentication request message is used to request authentication of the first identifier. In some embodiments, the authentication request message may be a first registration reply message.
[0179] In step S730: the terminal device sends a response message to the authentication request message to the first network element.
[0180] The response message to the authentication request message is the first message mentioned above, and the response message to the authentication request message may include the first identifier and authentication information of the first identifier.
[0181] As previously described, the authentication based on the sixth message provided in the embodiments of the present application can be implemented in two network elements with authentication capabilities. The embodiments of the present application do not specifically limit the network element with authentication capabilities that interacts with the first network element first. The network element with authentication capabilities that interacts with the first network element first can be determined based on priority or interaction efficiency.
[0182] As an example, the network element with an authentication function that first interacts with the first network element may be the authentication function. In view of this, as shown in Figure 7, the communication method in the embodiment of the present application further includes the following steps.
[0183] In step S740: the first network element sends an authentication request to the authentication function.
[0184] In step S750: the first network element receives an authentication reply message sent by the authentication function.
[0185] If the authentication reply message indicates that the authentication is successful, the authentication ends. At this time, the authentication reply message sent by the authentication function includes the second identifier.
[0186] If the authentication reply message indicates that the authentication fails, steps S760 and S770 are executed.
[0187] In step S760: the first network element sends an authentication request to the authentication server.
[0188] In step S770: the first network element receives the authentication reply message sent by the authentication server.
[0189] At this time, the authentication reply message sent by the authentication server includes the authentication result. If the authentication result indicates that the authentication is successful, the authentication reply message sent by the authentication server includes the authentication result and the second identifier. In some embodiments, the restoration message of the authentication request can also be called an authentication reply message.
[0190] The authentication request is used to authenticate the first identifier. In some embodiments, the authentication request includes the first identifier.
[0191] It should be noted that the authentication request in steps S740-S770 may be the sixth message mentioned above, and the authentication reply message in steps S740-S770 may be a reply message to the sixth message mentioned above.
[0192] In step S780: the first network element sends an authentication reply message to the terminal device.
[0193] The authentication reply message may be the second message mentioned above.
[0194] In the embodiment of the present application, by setting the network element with the authentication function that first interacts with the first network element as the authentication function, the authentication efficiency of the first identifier can be guaranteed. In addition, if the authentication function within the core network does not have the ability to authenticate the first identifier, the first identifier can be authenticated by an authentication server outside the core network, thereby ensuring that the first identifier can be authenticated.
[0195] In some embodiments, the sixth message also includes an external ID of the terminal device. The external ID of the terminal device can be the communication number corresponding to the subscriber identity module (SIM) or universal subscriber identity module (USIM) of the terminal device. For example, the external ID of the terminal device can be a mobile phone number.
[0196] The above authentication is usually performed during the registration process of the terminal device, that is, authentication is a part of the registration. The wireless communication method for registering based on the first identifier in the embodiment of the present application is described in detail below with reference to FIG6 .
[0197] Example 2 (Registration)
[0198] Referring to FIG. 6 , the method includes steps S610 to S619 .
[0199] In step S610, the terminal device sends a first registration request message to the first network element.
[0200] The first registration request message may include an identifier of the terminal device, and the first registration request is used to perform initial registration on the terminal device.
[0201] In some embodiments, the first registration request message may be the first message described above.
[0202] In some embodiments, the first message is also used to authenticate the identity of the terminal device.
[0203] In some embodiments, the first message is also used to authenticate the first identifier.
[0204] Optionally, the core network may authenticate the first identifier after authenticating the identifier of the terminal device.
[0205] In some embodiments, step S601 may be included before step S610: a user corresponding to the first identifier (referred to as user 1 ) initiates initial registration using a terminal device.
[0206] The initial registration may be, for example, a registration initiated by user 1 when the terminal is turned on for the first time, or a registration sent when a new user (user 1) uses the terminal device. A new user may be understood as a user who has never registered with the terminal device.
[0207] In step S620, the first network element triggers a first authentication process according to the first registration request message.
[0208] The first authentication process (authentication and key agreement) may be an authentication process based on the identity of the terminal device. For example, the first authentication process may be an authentication process based on SUPI, SUCI, or IMSI.
[0209] In step S630, the first network element triggers a second authentication process.
[0210] The second authentication process may be an authentication process based on the first identifier. In other words, the second authentication process may be the process described above for authenticating the first identifier.
[0211] In some embodiments, before step S630, the wireless communication method includes step S631, where the terminal device receives a first registration reply message sent by the first network element.
[0212] The first registration reply message may include an authentication result obtained after authenticating the terminal device's identifier and / or an identifier generated after authenticating the terminal device's identifier. The identifier generated after authenticating the terminal device's identifier may be an identifier used after successful authentication of the terminal device's identifier. For example, the identifier generated after authenticating the terminal device's identifier may be an identifier used for identity verification during subsequent registrations.
[0213] As an example, if the identifier of the terminal device is SUPI, the identifier GUTI is generated after authenticating the identifier of the terminal device.
[0214] In some embodiments, the first registration reply message may include an authentication request message.
[0215] In some embodiments, after step S630, the method may further include step S632: the terminal device receives a first registration reply message sent by the first network element.
[0216] The first registration reply message may further include the second message. In other words, the first registration reply message includes the authentication result and / or the second identifier generated after authenticating the first identifier.
[0217] Optionally, step S631 may not occur. In this case, the first registration reply message in step S632 includes the first registration reply message in step S631.
[0218] Optionally, as shown in FIG6 , if the authentication result obtained after executing the first authentication process indicates that the identification of the terminal device has been successfully authenticated, the wireless communication method may further include step S621 and step S622 .
[0219] In step S621, the first network element sends a policy request to the third network element.
[0220] The policy request is used to determine the policy corresponding to the first identifier. The policy corresponding to the first identifier can be a UE policy and / or a network element policy. The policy request includes the authenticated terminal device identifier. The policy request is also used to request the policy corresponding to the terminal device identifier, where the policy corresponding to the terminal device identifier includes policies corresponding to one or more user identifiers corresponding to the terminal device identifier.
[0221] In some embodiments, the policy request may be the seventh message described above.
[0222] In step S622, the first receiving device sends policy information corresponding to the identifier of the terminal device from the third network element.
[0223] The policy information corresponding to the identifier of the terminal device includes policies corresponding to one or more user identifiers.
[0224] In some embodiments, the policy information corresponding to the identifier of the terminal device may be a reply message to the seventh message described above.
[0225] Accordingly, optionally, after step S630, if the authentication result obtained after executing the second authentication process indicates that the first identifier is successfully authenticated, the wireless communication method may further include: the first network element determining a policy corresponding to the first identifier from policies corresponding to one or more user identifiers. For example, the policy corresponding to the first identifier may be searched from one or more user identifiers using the first identifier.
[0226] Optionally, if the authentication result obtained after executing the first authentication process indicates that the identification of the terminal device has been successfully authenticated, as shown in FIG6 , the wireless communication method may further include step S623 and step S624.
[0227] In step S623, the first network element sends a subscription request to the fourth network element.
[0228] The contract signing request includes the authenticated terminal device identifier and is also used to request contract signing information corresponding to the terminal device identifier, which includes contract signing information corresponding to one or more user identifiers corresponding to the terminal device identifier.
[0229] In some embodiments, the signing request may be the eighth message described above.
[0230] In step S624, the first network element receives the subscription information corresponding to the identifier of the terminal device from the fourth network element.
[0231] The contract information corresponding to the terminal device identifier includes contract information corresponding to one or more user identifiers.
[0232] In some embodiments, the contract information corresponding to the identifier of the terminal device is a reply message to the eighth message.
[0233] Accordingly, optionally, after step S630, if the authentication result obtained after executing the second authentication process indicates that the first identifier is successfully authenticated, the wireless communication method may further include: the first network element determining the contract information corresponding to the first identifier from the contract information corresponding to the one or more user identifiers. For example, the contract information corresponding to the first identifier may be searched from the one or more user identifiers using the first identifier.
[0234] In some embodiments, the above steps S621 to S624 may not be performed before the second authentication but may be performed after the second authentication.
[0235] As an implementation manner, as shown in FIG6 , if the authentication result obtained after executing the second authentication process indicates that the first identifier has successfully passed the authentication, the wireless communication method may further include step S621 ′ and step S622 ′.
[0236] In step S621', the first network element sends a policy request to the third network element.
[0237] The policy request is used to determine the policy corresponding to the first identifier. The policy request includes the authenticated first identifier. The policy request is used to request the policy corresponding to the first identifier.
[0238] In some embodiments, the policy request may be the seventh message described above.
[0239] In step S622', the first network element receives policy information corresponding to the first identifier sent by the third network element.
[0240] The policy information corresponding to the first identifier includes the policy corresponding to the first identifier.
[0241] In some embodiments, the policy corresponding to the first identifier may be a reply message to the seventh message described above.
[0242] Optionally, if the authentication result obtained after executing the second authentication process indicates that the first identifier has been successfully authenticated, the wireless communication method may further include step S623' and step S624'.
[0243] In step S623', the first network element sends a subscription request to the fourth network element.
[0244] The contract signing request is used to determine the contract signing information corresponding to the first identifier. The contract signing request includes the authenticated first identifier. The contract signing request is used to request the contract signing information corresponding to the first identifier.
[0245] In some embodiments, the signing request may be the eighth message described above.
[0246] In step S624', the first network element receives the subscription information corresponding to the first identifier from the fourth network element.
[0247] In some embodiments, the contract signing information corresponding to the first identifier may be a reply message to the eighth message described above.
[0248] Accordingly, optionally, after step S630, if the authentication result obtained after executing the second authentication process indicates that the first identifier is successfully authenticated, the wireless communication method may further include: the first network element determining the contract information corresponding to the first identifier from the contract information corresponding to the one or more user identifiers. For example, the contract information corresponding to the first identifier may be searched from the one or more user identifiers using the first identifier.
[0249] In the embodiment of the present application, the third network element is a network element in the core network that can configure or store policies, for example, the third network element can be a PCF. The fourth network element can be a network element in the core network that can configure or store subscription data, for example, the fourth network element is a UDM.
[0250] In some embodiments, after the first identifier is registered and authenticated, the first identifier may also be verified.
[0251] As an example, the first message is also used to verify the second identifier. In view of this, the first message may also include the second identifier.
[0252] As another example, the terminal device may verify the second identifier based on the third message including the second identifier. This will be described in detail below with reference to FIG8 .
[0253] In the wireless communication method provided in the embodiment of the present application, the first network element can obtain the subscription information or policy information corresponding to the first identifier by sending the seventh message or the eighth message, thereby achieving the acquisition of subscription information or policy information at the user identifier granularity.
[0254] Example 3 (Verification)
[0255] As shown in FIG8 , the wireless communication method may include steps S810 - S820 .
[0256] In step S810: the terminal device sends a third message to the first network element.
[0257] The third message may include the second identifier. The third message is used to verify the second identifier.
[0258] In some embodiments, as shown in FIG8 , before step S810, the method may further include step S811: the terminal device triggers the verification process. In other words, the third message may be generated after the verification process is triggered.
[0259] Optionally, the conditions for triggering the verification process are one or more of the following (i.e., the third message is triggered based on one or more of the following): switching from the third identifier to the first identifier, where the third identifier is one of one or more user identifiers; the user corresponding to the first identifier has not used the terminal device within a first period of time; the terminal device initiates a periodic registration update; the network device instructs the terminal device to send the second identifier. As an example, the periodic registration update includes one or more of the following: a periodic registration update for the identifier of the terminal device; a periodic registration update for the first identifier.
[0260] In some embodiments, if the second identifier does not include information of the first identifier, the third message may further include the first identifier.
[0261] In some embodiments, the third message may be a second registration request. A second registration request may be understood as a registration request message sent when registering again after completing an initial registration. Accordingly, the third message may also include an identifier of the terminal device or an identifier generated after authenticating the identifier of the terminal device, such as a GUTI.
[0262] In step S820: the terminal device receives the fourth message sent by the first network element.
[0263] The fourth message includes a verification result of the second identifier. In some embodiments, the fourth message is a second registration reply message. The second registration reply message is a reply message corresponding to the second registration request message.
[0264] The embodiment of the present application does not specifically limit the network element for verifying the second identifier, and it can be the same as the network element for authenticating the first identifier described above. For easier understanding, this is explained in conjunction with FIG8 .
[0265] In view of this, as shown in Figure 8, the communication method in the embodiment of the present application further includes the following steps.
[0266] In step S830: the first network element may send a verification request message to the authentication function.
[0267] The verification request message may include the second identifier, or the verification request message may include the first identifier and the second identifier.
[0268] In step S840: the first network element receives a reply message to the verification request message sent by the authentication function.
[0269] If the reply message to the verification request message indicates that the verification is successful, the verification ends.
[0270] If the reply message to the verification request message indicates that the verification has failed, steps S850 and S860 are executed.
[0271] In step S850: the first network element sends a verification request message to the verification server.
[0272] In step S860: the first network element receives a reply message to the verification request message sent by the verification server.
[0273] At this time, the reply message to the verification request message sent by the verification server includes a verification result. The verification result may indicate whether the second identifier verification succeeds or fails.
[0274] Different User IDs can correspond to different UE policies. Therefore, when the user using the terminal changes (i.e., the User ID changes), or when the first identity authentication is completed, the UE can initiate a registration update process to trigger the core network to configure an updated UE policy. In view of this, in some embodiments, after the first identity is registered, the UE policy can also be updated for the first identity. This is exemplified below with reference to Figure 9.
[0275] In the wireless communication method provided in the embodiment of the present application, the terminal device can send a third message for verifying the second identifier to the first network element (the first message includes the second identifier), and receive a fourth message from the first network element containing the verification result of the second identifier. This achieves verification at the user identifier granularity.
[0276] Example 4 (Updating UE Policy)
[0277] As shown in FIG9 , the wireless communication method includes the following steps.
[0278] In step S910, the terminal device sends a first message to the first network element.
[0279] The first message includes a first identifier, and the first message is used to request that the policy of the terminal device be updated to the policy corresponding to the first identifier
[0280] In some embodiments, the first message may be the first registration request message described above.
[0281] In other embodiments, the first message is also used to verify the second identifier, which is an identifier used after the first identifier is successfully authenticated. For example, the first message can be the second registration request message described above.
[0282] In some embodiments, the first message includes a policy container of the terminal device, and the first identifier is carried in the policy container.
[0283] In some embodiments, the wireless communication method may further include: the terminal device receives a fifth message sent by the first network element.
[0284] The fifth message is used to update the policy of the terminal device to the policy corresponding to the first identifier.
[0285] In some embodiments, the terminal device receiving the fifth message sent by the first network element may be a step in triggering the UCU process. As an example, as shown in FIG9 , after step S910, the method further includes steps S911 and S912.
[0286] In step S911: the first network element forwards the first message to the third network element.
[0287] In some embodiments, the first message forwarded by the first network element to the third network element may be a policy association modification request message.
[0288] In some embodiments, the first message includes a policy container of the terminal device, the first identifier is carried in the policy container, and the first network element may forward the policy container of the terminal device to the third network element.
[0289] In step S912, the third network element initiates a UCU process according to the received first identifier, and configures an updated UE policy for the UE.
[0290] In some embodiments, the updated UE policy may be included in a policy container of the terminal device. Optionally, the policy container of the terminal device may also carry a first identifier to indicate that the updated UE policy is for the corresponding first identifier.
[0291] Among them, step S912 may include the terminal device receiving the fifth message sent by the first network element.
[0292] The embodiment of the present application does not provide a detailed introduction to the UCU process initiated by the third network element. For details, please refer to the UCU process described above. The difference from the UCU process described above is that the interactive messages involved in the UCU process in the embodiment of the present application can all include the first identifier.
[0293] In the wireless communication method provided in an embodiment of the present application, a terminal device can send a first message including a first identifier to a first network element, and receive a fifth message from the first network element via the first message. The fifth message can be used to update the terminal device's policy to the policy corresponding to the first identifier. This implements UE policy updates at the user identifier granularity.
[0294] Example 5 (updating UE policy and combining verification)
[0295] In some embodiments, updating UE policy can be combined with verification. As an example, as shown in FIG10 , the method includes the following steps.
[0296] In step S1011: the terminal device triggers the verification process
[0297] In step S1010: the terminal device sends a second registration request message to the first network element.
[0298] The second registration request message is used to verify the second identifier and update the policy of the terminal device. The second registration request message may include a policy container for the terminal device and the second identifier. Optionally, the second registration request message may also include the first identifier. The first identifier is carried in the policy container, or the policy container is associated with the first identifier. In some embodiments, the second registration request message may be the first message or the second message described above.
[0299] In step S1020: the first network element may send a verification request message to the authentication function.
[0300] The verification request message includes the second identifier.
[0301] In step S1030: the first network element receives a reply message to the verification request message sent by the authentication function.
[0302] If the reply message to the verification request message indicates that the verification is successful, the verification ends.
[0303] If the reply message to the verification request message indicates that the verification has failed, step S1040 and step S1050 are executed.
[0304] In step S1040: the first network element sends a verification request message to the verification server.
[0305] In step S1050: the first network element receives a reply message to the verification request message sent by the verification server.
[0306] If the reply message to the verification request message indicates that the second identifier has successfully passed the verification, step S1060 is executed: the first network element forwards the policy container of the terminal device in the second registration request message to the third network element.
[0307] In some embodiments, the policy container of the terminal device forwarded by the first network element to the third network element may be carried in a policy association modification request message.
[0308] As mentioned above, the first identifier may be carried in a policy container. Accordingly, the first network element may directly forward the policy container of the terminal device in the second registration request message to the third network element.
[0309] Alternatively, the policy container does not carry the first identifier. Accordingly, the first network element may forward the policy container and the first identifier of the terminal device to the third network element.
[0310] In step S1070: the third network element initiates a UCU process according to the received first identifier.
[0311] The wireless communication method provided in the embodiment of the present application enables the terminal device to obtain the UE policy corresponding to the first identifier when performing verification based on the second identifier. This not only enables user-granular verification and UE policy updates, but also effectively utilizes the verification process, thereby improving the communication efficiency of the communication system.
[0312] In some embodiments, updating the UE policy can be combined with registration. As an example, as shown in Figure 6, the method may include step S640: the third network element triggers a UCU process based on the first identifier obtained from the first network element to configure the UE policy for the terminal device. That is, during the UCU process, the UE policy (e.g., URSP policy) corresponding to the first identifier of the third network element is included in a policy container (UE policy container) of the terminal device and forwarded to the terminal device via the first network element.
[0313] It should be noted that step S640 may be a process independently initiated by the third network element, and may have no sequential relationship with other steps in FIG. 6 .
[0314] The wireless communication method provided in the embodiment of the present application enables the terminal device to obtain the UE policy corresponding to the first identifier based on the initial registration of the first identifier. This not only enables user-granular initial registration and UE policy updates, but also effectively utilizes the initial registration process, thereby improving the communication efficiency of the communication system.
[0315] By executing the embodiment of the present application, it is possible to implement verification when different users log in on the same terminal (UE / USIM) and distinguish the user IDs of different users. In addition, the embodiment of the present application can also use the existing verification mechanism to enable the 5G network to identify the User ID through the participation of the 5G network. In addition, the embodiment of the present application can make full use of the existing processes and mechanisms, and the impact on the existing architecture is controllable.
[0316] The method embodiment of the present application is described in detail above in conjunction with Figures 1 to 10. The device embodiment of the present application is described in detail below in conjunction with Figures 11 to 16. It should be understood that the description of the method embodiment corresponds to the description of the device embodiment. Therefore, for parts not described in detail, reference can be made to the above method embodiment.
[0317] FIG11 is a schematic diagram of a terminal device according to an embodiment of the present application. The terminal device 1100 shown in FIG11 includes a sending unit 1110 .
[0318] The sending unit 1110 is used to send a first message to the first network element, where the first message includes a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0319] In some implementations, the first message is used to authenticate the first identifier.
[0320] In some implementations, the first message is a first registration request message.
[0321] In some implementations, the first message is a response message to an authentication request message sent by the first network element.
[0322] In some implementations, the authentication request message is a first registration reply message.
[0323] In some implementations, the first message also includes authentication information of the first identifier.
[0324] In some implementations, the authentication information includes one or more of the following: a user name; a password; a first key determined based on biometric information of a user of the terminal device; and an authentication parameter generated based on the first key.
[0325] In some implementations, the terminal device 1100 also includes: a receiving unit, used to receive a second message sent by the first network element, the second message including one or more of the following: a second identifier, the second identifier being an identifier used after the first identifier is successfully authenticated; an authentication result, used to indicate whether the authentication of the first identifier is successful or failed.
[0326] In some implementations, the second message is a first registration reply message.
[0327] In some implementations, the sending unit 1110 is further configured to: send a third message to the first network element, where the third message is used to verify the second identifier.
[0328] In some implementations, the third message is triggered based on one or more of the following: switching from a third identifier to the first identifier, the third identifier being one of the one or more user identifiers; the user corresponding to the first identifier not using the terminal device within a first time period; the terminal device initiating a periodic registration update; the network device instructing the terminal device to send the second identifier.
[0329] In some implementations, the periodic registration update includes one or more of the following: a periodic registration update for the identifier of the terminal device; a periodic registration update for the first identifier.
[0330] In some implementations, the second identifier includes the first identifier; or, the second identifier does not include the first identifier, and the third message includes the first identifier.
[0331] In some implementations, the third message is a second registration request message.
[0332] In some implementations, the receiving unit is further configured to: receive a fourth message sent by the first network element, where the fourth message includes a verification result of the second identifier.
[0333] In some implementations, the fourth message is a second registration reply message.
[0334] In some implementations, the first message is used to request that the policy of the terminal device be updated to the policy corresponding to the first identifier.
[0335] In some implementations, the first message includes a policy container of the terminal device, and the first identifier is carried in the policy container.
[0336] In some implementations, the first message is further used to verify a second identifier, where the second identifier is an identifier used after the first identifier is successfully authenticated.
[0337] In some implementations, the receiving unit is further used to: receive a fifth message sent by the first network element, where the fifth message is used to update the policy of the terminal device to the policy corresponding to the first identifier.
[0338] In some implementations, the first network element is an access and mobility management function AMF network element.
[0339] In some implementations, the identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on the SUPI.
[0340] Figure 12 is a schematic diagram of the structure of a communication device according to an embodiment of the present application, wherein the communication device is a first network element. The communication device 1200 shown in Figure 12 includes a receiving unit 1210, configured to receive a first message sent by a terminal device, wherein the first message includes a first identifier, wherein the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0341] In some implementations, the first message is used to authenticate the first identifier.
[0342] In some implementations, the first message is a first registration request message.
[0343] In some implementations, the first message is a response message to an authentication request message sent by the first network element.
[0344] In some implementations, the authentication request message is a first registration reply message.
[0345] In some implementations, the first message also includes authentication information of the first identifier.
[0346] In some implementations, the authentication information includes one or more of the following: a user name; a password; a first key determined based on biometric information of a user of the terminal device; and an authentication parameter generated based on the first key.
[0347] In some implementations, the communication device further includes: a sending unit for sending a second message to the terminal device, the second message including one or more of the following: a second identifier, the second identifier being an identifier used after the first identifier is successfully authenticated; an authentication result for indicating whether the authentication of the first identifier is successful or failed.
[0348] In some implementations, the second message is a first registration reply message.
[0349] In some implementations, the receiving unit 1210 is further configured to: receive a third message sent by the terminal device, where the third message is used to verify the second identifier.
[0350] In some implementations, the third message is triggered based on one or more of the following: switching from a third identifier to the first identifier, the third identifier being one of the one or more user identifiers; the user corresponding to the first identifier not using the terminal device within a first time period; the terminal device initiating a periodic registration update; the network device instructing the terminal device to send the second identifier.
[0351] In some implementations, the periodic registration update includes one or more of the following: a periodic registration update for the identifier of the terminal device; a periodic registration update for the first identifier.
[0352] In some implementations, the second identifier includes the first identifier; or, the second identifier does not include the first identifier, and the third message includes the first identifier.
[0353] In some implementations, the third message is a second registration request message.
[0354] In some implementations, the sending unit is further configured to send a fourth message to the terminal device, where the fourth message includes a verification result of the second identifier.
[0355] In some implementations, the fourth message is a second registration reply message.
[0356] In some implementations, the first message is used to request that the policy of the terminal device be updated to the policy corresponding to the first identifier.
[0357] In some implementations, the first message includes a policy container of the terminal device, and the first identifier is carried in the policy container.
[0358] In some implementations, the first message is further used to verify a second identifier, where the second identifier is an identifier used after the first identifier is successfully authenticated.
[0359] In some implementations, the sending unit is further used to: send a fifth message to the terminal device, where the fifth message is used to update the policy of the terminal device to the policy corresponding to the first identifier.
[0360] In some implementations, the sending unit is also used to send a sixth message to the second network element, and the sixth message is used to request the second network element to authenticate the first identifier; and / or the receiving unit 1210 is also used to receive a reply message to the sixth message sent by the second network element, and the reply message to the sixth message includes one or more of the following: a second identifier, the second identifier is an identifier used after the first identifier is successfully authenticated; an authentication result, used to indicate whether the authentication of the first identifier is successful or failed.
[0361] In some implementations, the second network element is a network element of a core network, or the second network element is an authentication server in communication with the core network.
[0362] In some implementations, the sending unit is further used to: send a seventh message to a third network element, where the seventh message is used to determine a policy corresponding to the first identifier.
[0363] In some implementations, the seventh message includes the first identifier after authentication, and the receiving unit 1210 is further used to: receive a reply message to the seventh message sent by the third network element, and the reply message to the seventh message includes a policy corresponding to the first identifier.
[0364] In some implementations, the seventh message includes the identifier of the terminal device after authentication, and the receiving unit 1210 is further used to: receive a reply message to the seventh message sent by the third network element, the reply message of the seventh message including the policies corresponding to the one or more user identifiers; and after the first identifier is successfully authenticated, determine the policy corresponding to the first identifier from the policies corresponding to the one or more user identifiers.
[0365] In some implementations, the third network element is a policy control function PCF network element.
[0366] In some implementations, the sending unit is further used to: send an eighth message to the fourth network element, where the eighth message is used to determine the contract information corresponding to the first identifier.
[0367] In some implementations, the eighth message includes the first identifier after authentication, and the receiving unit 1210 is further used to: receive a reply message to the eighth message sent by the fourth network element, and the reply message to the eighth message includes the contract information corresponding to the first identifier.
[0368] In some implementations, the eighth message includes the identifier of the terminal device after authentication, and the receiving unit 1210 is also used to: receive a reply message to the eighth message from the fourth network element, the reply message to the eighth message including the contract information corresponding to the one or more user identifiers; and after the first identifier is successfully authenticated, determine the contract information corresponding to the first identifier from the contract information corresponding to the one or more user identifiers.
[0369] In some implementations, the fourth network element is a unified data management function (UDM) network element.
[0370] In some implementations, the first network element is an access and mobility management function AMF network element.
[0371] In some implementations, the identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on the SUPI.
[0372] Figure 13 is a schematic diagram of the structure of a communication device according to an embodiment of the present application, wherein the communication device is a second network element. The communication device 1300 shown in Figure 13 includes a receiving unit 1310, configured to receive a sixth message sent by a first network element, wherein the sixth message is configured to request the second network element to authenticate a first identifier, wherein the first identifier is an identifier of the terminal device corresponding to one of one or more user identifiers.
[0373] In some implementations, the communication device 1300 also includes: a sending unit, used to send a reply message to the sixth message to the first network element, and the reply message to the sixth message includes one or more of the following: a second identifier, which is an identifier used after the first identifier is successfully authenticated; an authentication result, used to indicate whether the authentication of the first identifier is successful or failed.
[0374] In some implementations, the second network element is a network element of a core network, or the second network element is an authentication server in communication with the core network.
[0375] In some implementations, the first network element is an access and mobility management function AMF network element.
[0376] In some implementations, the identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on the SUPI.
[0377] Figure 14 is a schematic diagram of the structure of a communication device according to an embodiment of the present application, wherein the communication device is a third network element. The communication device 1400 shown in Figure 14 includes a receiving unit 1410, configured to receive a seventh message sent by the first network element, wherein the seventh message is configured to determine a policy corresponding to a first identifier, wherein the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0378] In some implementations, the seventh message includes the authenticated first identifier, and the communications device further includes:
[0379] A sending unit is used to send a reply message of the seventh message to the first network element, where the reply message of the seventh message includes a policy corresponding to the first identifier.
[0380] In some implementations, the seventh message includes an identifier of the authenticated terminal device, and the communications device further includes:
[0381] a sending unit, configured to send a reply message to the seventh message to the first network element, where the reply message to the seventh message includes policies corresponding to the one or more user identifiers;
[0382] After the first identifier is successfully authenticated, the first network element determines a policy corresponding to the first identifier from policies corresponding to the one or more user identifiers.
[0383] In some implementations, the third network element is a policy control function PCF network element.
[0384] In some implementations, the first network element is an access and mobility management function AMF network element.
[0385] In some implementations, the identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on the SUPI.
[0386] Figure 15 is a schematic diagram of the structure of a communication device according to an embodiment of the present application, wherein the communication device is a fourth network element. The communication device 1500 shown in Figure 15 includes a receiving unit 1510, configured to receive an eighth message sent by a first network element, wherein the eighth message is configured to determine the contract information corresponding to the first identifier, wherein the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
[0387] In some implementations, the eighth message includes the authenticated first identifier, and the communications device further includes:
[0388] A sending unit is used to send a reply message of the eighth message to the first network element, where the reply message of the eighth message includes the contract information corresponding to the first identifier.
[0389] In some implementations, the eighth message includes the identifier of the terminal device after authentication, and the sending unit is also used to send a reply message of the eighth message to the first network element, and the reply message of the eighth message includes the contract information corresponding to the one or more user identifiers.
[0390] In some implementations, the fourth network element is a unified data management function (UDM) network element.
[0391] In some implementations, the first network element is an access and mobility management function AMF network element.
[0392] In some implementations, the identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on the SUPI.
[0393] Figure 16 is a schematic block diagram of a communication device according to an embodiment of the present application. The dashed lines in Figure 16 indicate that the unit or module is optional. The device 1600 may be used to implement the method described in the above method embodiment. The device 1600 may be a chip, a terminal, or a network device.
[0394] The device 1600 may include one or more processors 1610. The processor 1610 may support the device 1600 to implement the method described in the above method embodiment. The processor 1610 may be a general-purpose processor or a special-purpose processor. For example, the processor may be a central processing unit (CPU). Alternatively, the processor may be another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.
[0395] The apparatus 1600 may further include one or more memories 1620. The memories 1620 store programs that can be executed by the processor 1610, causing the processor 1610 to perform the methods described in the above method embodiments. The memories 1620 may be independent of the processor 1610 or integrated into the processor 1610.
[0396] The apparatus 1600 may further include a transceiver 1630. The processor 1610 may communicate with other devices or chips via the transceiver 1630. For example, the processor 1610 may transmit and receive data with other devices or chips via the transceiver 1630.
[0397] The present application also provides a computer-readable storage medium for storing a program. The computer-readable storage medium can be applied to a terminal or network device provided in the present application, and the program enables a computer to execute the method performed by the terminal or network device in each embodiment of the present application.
[0398] The present application also provides a computer program product. The computer program product includes a program. The computer program product can be applied to a terminal or network device provided in the present application, and the program causes a computer to execute the method performed by the terminal or network device in each embodiment of the present application.
[0399] The embodiments of the present application also provide a computer program. The computer program can be applied to the terminal or network device provided in the embodiments of the present application, and the computer program enables a computer to execute the method performed by the terminal or network device in each embodiment of the present application.
[0400] It should be understood that the terms "service" and "application" are used interchangeably in this application. Furthermore, the term "terminal" used in this application may include one or more USIM cards. Of course, in this application, a terminal may include one or more UE functions to access different networks.
[0401] It should be understood that the terms "system" and "network" in this application can be used interchangeably. In addition, the terms used in this application are only used to explain the specific embodiments of this application and are not intended to limit this application. The terms "first", "second", "third", and "fourth" in the specification and claims of this application and the accompanying drawings are used to distinguish different objects rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions.
[0402] In the embodiments of this application, the term "indication" may refer to a direct indication, an indirect indication, or an indication of an association. For example, "A indicates B" may refer to a direct indication of B, e.g., B can obtain information through A; it may refer to an indirect indication of B, e.g., A indicates C, e.g., B can obtain information through C; or it may refer to an association between A and B.
[0403] In the embodiment of the present application, "B corresponding to A" means that B is associated with A and B can be determined based on A. However, it should be understood that determining B based on A does not mean determining B based solely on A, but B can also be determined based on A and / or other information.
[0404] In the embodiments of the present application, the term "corresponding" may indicate a direct or indirect correspondence between the two, or an association relationship between the two, or a relationship between indication and indication, configuration and configuration, etc.
[0405] In the embodiments of the present application, "pre-definition" or "pre-configuration" may be implemented by pre-storing corresponding codes, tables, or other methods that can be used to indicate relevant information in a device (e.g., a terminal device and a network device). The present application does not limit the specific implementation method. For example, pre-definition may refer to information defined in a protocol.
[0406] In the embodiments of the present application, the “protocol” may refer to a standard protocol in the communications field, for example, it may include an LTE protocol, an NR protocol, and related protocols used in future communication systems, and the present application does not limit this.
[0407] In the embodiments of this application, the term "and / or" is simply a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0408] In various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0409] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0410] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0411] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0412] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital versatile disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).
[0413] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A wireless communication method, characterized in that: include: The terminal device sends a first message to the first network element, where the first message includes a first identifier, where the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
2. The method according to claim 1, characterized in that The first message is used to authenticate the first identifier.
3. The method according to claim 2, characterized in that The first message is a first registration request message.
4. The method according to claim 2, characterized in that The first message is a response message to the authentication request message sent by the first network element.
5. The method according to claim 4, characterized in that The authentication request message is a first registration reply message.
6. The method according to any one of claims 2 to 5, characterized in that The first message also includes authentication information of the first identifier.
7. The method according to claim 6, characterized in that The authentication information includes one or more of the following: username; password; A first secret key is determined based on biometric information of a user of the terminal device; An authentication parameter generated based on the first secret key.
8. The method according to any one of claims 2 to 7, characterized in that The method further comprises: The terminal device receives a second message sent by the first network element, where the second message includes one or more of the following: A second identifier, where the second identifier is used after the first identifier is successfully authenticated; The authentication result is used to indicate whether the authentication of the first identifier is successful or failed.
9. The method according to claim 8, characterized in that The second message is a first registration reply message.
10. The method according to claim 8 or 9, characterized in that The method further comprises: The terminal device sends a third message to the first network element, where the third message is used to verify the second identifier.
11. The method according to claim 10, characterized in that The third message is triggered based on one or more of the following: Switching from a third identifier to the first identifier, the third identifier being one of the one or more user identifiers; The user corresponding to the first identifier has not used the terminal device within a first period of time; The terminal device initiates periodic registration update; The network device instructs the terminal device to send the second identifier.
12. The method according to claim 11, characterized in that The periodic registration update includes one or more of the following: Periodic registration and update of the identification of the terminal device; Periodic registration updates for the first identifier.
13. The method according to any one of claims 10 to 12, characterized in that: The second identifier includes the first identifier; or The second identifier does not include the first identifier, and the third message includes the first identifier.
14. The method according to any one of claims 10 to 13, characterized in that The third message is a second registration request message.
15. The method according to any one of claims 10 to 14, characterized in that The method further comprises: The terminal device receives a fourth message sent by the first network element, and the fourth message includes a verification result of the second identifier.
16. The method according to claim 15, characterized in that The fourth message is a second registration reply message.
17. The method according to any one of claims 1 to 16, characterized in that The first message is used to request that the policy of the terminal device be updated to the policy corresponding to the first identifier.
18. The method according to any one of claims 1 to 17, characterized in that: The first message includes a policy container of the terminal device, and the first identifier is carried in the policy container.
19. The method according to claim 17 or 18, characterized in that The first message is also used to verify a second identifier, where the second identifier is an identifier used after the first identifier is successfully authenticated.
20. The method according to any one of claims 1 to 19, characterized in that The method further comprises: The terminal device receives a fifth message sent by the first network element, where the fifth message is used to update the policy of the terminal device to the policy corresponding to the first identifier.
21. The method according to any one of claims 1 to 20, characterized in that The first network element is an access and mobility management function AMF network element.
22. The method according to any one of claims 1 to 21, characterized in that The identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on SUPI.
23. A wireless communication method, characterized in that: include: The first network element receives a first message sent by a terminal device, where the first message includes a first identifier. The identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
24. The method according to claim 23, wherein The first message is used to authenticate the first identifier.
25. The method according to claim 24, characterized in that The first message is a first registration request message.
26. The method according to claim 24, characterized in that The first message is a response message to the authentication request message sent by the first network element.
27. The method according to claim 26, characterized in that The authentication request message is a first registration reply message.
28. The method according to any one of claims 24 to 27, characterized in that The first message also includes authentication information of the first identifier.
29. The method according to claim 28, characterized in that The authentication information includes one or more of the following: username; password; A first secret key is determined based on biometric information of a user of the terminal device; An authentication parameter generated based on the first secret key.
30. The method according to any one of claims 24 to 29, characterized in that The method further comprises: The first network element sends a second message to the terminal device, where the second message includes one or more of the following: A second identifier, where the second identifier is used after the first identifier is successfully authenticated; The authentication result is used to indicate whether the authentication of the first identifier is successful or failed.
31. The method according to claim 30, wherein The second message is a first registration reply message.
32. The method according to claim 30 or 31, characterized in that The method further comprises: The first network element receives a third message sent by the terminal device, where the third message is used to verify the second identifier.
33. The method according to claim 32, characterized in that The third message is triggered based on one or more of the following: Switching from a third identifier to the first identifier, the third identifier being one of the one or more user identifiers; The user corresponding to the first identifier has not used the terminal device within a first period of time; The terminal device initiates periodic registration update; The network device instructs the terminal device to send the second identifier.
34. The method according to claim 33, wherein The periodic registration update includes one or more of the following: Periodic registration and update of the identification of the terminal device; Periodic registration updates for the first identifier.
35. The method according to any one of claims 32 to 34, characterized in that: The second identifier includes the first identifier; or The second identifier does not include the first identifier, and the third message includes the first identifier.
36. The method according to any one of claims 32 to 35, characterized in that The third message is a second registration request message.
37. The method according to any one of claims 32 to 36, characterized in that The method further comprises: The first network element sends a fourth message to the terminal device, where the fourth message includes a verification result of the second identifier.
38. The method according to claim 37, wherein The fourth message is a second registration reply message.
39. The method according to any one of claims 23 to 38, characterized in that The first message is used to request that the policy of the terminal device be updated to the policy corresponding to the first identifier.
40. The method according to any one of claims 23 to 39, characterized in that The first message includes a policy container of the terminal device, and the first identifier is carried in the policy container.
41. The method according to claim 39 or 40, characterized in that The first message is also used to verify a second identifier, where the second identifier is an identifier used after the first identifier is successfully authenticated.
42. The method according to any one of claims 23 to 41, characterized in that The method further comprises: The first network element sends a fifth message to the terminal device, where the fifth message is used to update the policy of the terminal device to the policy corresponding to the first identifier.
43. The method according to any one of claims 23 to 42, characterized in that The method further comprises: The first network element sends a sixth message to the second network element, where the sixth message is used to request the second network element to authenticate the first identifier; and / or The first network element receives a reply message to the sixth message sent by the second network element, wherein the reply message to the sixth message includes One or more of the following: A second identifier, where the second identifier is used after the first identifier is successfully authenticated; The authentication result is used to indicate whether the authentication of the first identifier is successful or failed.
44. The method according to claim 43, wherein The second network element is a network element of a core network, or the second network element is an authentication server in communication connection with the core network.
45. The method according to any one of claims 23 to 44, characterized in that The method further comprises: The first network element sends a seventh message to the third network element, where the seventh message is used to determine a policy corresponding to the first identifier.
46. The method according to claim 45, characterized in that The seventh message includes the authenticated first identifier, and the method further includes: The first network element receives a reply message to the seventh message sent by the third network element, where the reply message to the seventh message includes a policy corresponding to the first identifier.
47. The method according to claim 45, wherein The seventh message includes the authenticated identifier of the terminal device, and the method further includes: The first network element receives a reply message to the seventh message sent by the third network element, where the reply message to the seventh message includes policies corresponding to the one or more user identifiers; After the first identifier is successfully authenticated, the first network element determines a policy corresponding to the first identifier from policies corresponding to the one or more user identifiers.
48. The method according to any one of claims 45 to 47, characterized in that The third network element is a policy control function PCF network element.
49. The method according to any one of claims 23 to 48, characterized in that The method further comprises: The first network element sends an eighth message to the fourth network element, where the eighth message is used to determine the contract information corresponding to the first identifier.
50. The method according to claim 49, wherein The eighth message includes the authenticated first identifier, and the method further includes: The first network element receives a reply message to the eighth message sent by the fourth network element, where the reply message to the eighth message includes the contract information corresponding to the first identifier.
51. The method according to claim 49, wherein The eighth message includes the authenticated identifier of the terminal device, and the method further includes: The first network element receives a reply message to the eighth message from the fourth network element, where the reply message to the eighth message includes subscription information corresponding to the one or more user identifiers; After the first identifier is successfully authenticated, the first network element determines the contract information corresponding to the first identifier from the contract information corresponding to the one or more user identifiers.
52. The method according to any one of claims 49 to 51, characterized in that The fourth network element is a unified data management function UDM network element.
53. The method according to any one of claims 23 to 52, characterized in that The first network element is an access and mobility management function AMF network element.
54. The method according to any one of claims 23 to 53, characterized in that The identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on SUPI.
55. A wireless communication method, characterized in that: include: The second network element receives a sixth message sent by the first network element, where the sixth message is used to request the second network element to authenticate the first identifier, where the first identifier is one of one or more user identifiers corresponding to the identifier of the terminal device.
56. The method according to claim 55, characterized in that The method further comprises: The second network element sends a reply message to the sixth message to the first network element, where the reply message to the sixth message includes one or more of the following: A second identifier, where the second identifier is used after the first identifier is successfully authenticated; The authentication result is used to indicate whether the authentication of the first identifier is successful or failed.
57. The method according to claim 55 or 56, characterized in that The second network element is a network element of a core network, or the second network element is an authentication server in communication connection with the core network.
58. The method according to any one of claims 55 to 57, characterized in that The first network element is an access and mobility management function AMF network element.
59. The method according to any one of claims 55 to 58, characterized in that The identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on SUPI.
60. A wireless communication method, characterized in that: The method comprises: The third network element receives the seventh message sent by the first network element, where the seventh message is used to determine the policy corresponding to the first identifier, where the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
61. The method according to claim 60, characterized in that The seventh message includes the authenticated first identifier, and the method further includes: The third network element sends a reply message to the seventh message to the first network element, where the reply message to the seventh message includes a policy corresponding to the first identifier.
62. The method according to claim 60, wherein The seventh message includes the authenticated identifier of the terminal device, and the method further includes: The first network element receives a reply message to the seventh message sent by the third network element, where the reply message to the seventh message includes policies corresponding to the one or more user identifiers; After the first identifier is successfully authenticated, the first network element determines a policy corresponding to the first identifier from policies corresponding to the one or more user identifiers.
63. The method according to any one of claims 60 to 62, characterized in that The third network element is a policy control function PCF network element.
64. The method according to any one of claims 60 to 63, characterized in that The first network element is an access and mobility management function AMF network element.
65. The method according to any one of claims 60 to 64, characterized in that The identifier of the terminal device is SUPI or an identifier determined based on SUPI.
66. A wireless communication method, characterized in that: The method further comprises: The fourth network element receives the eighth message sent by the first network element, where the eighth message is used to determine the contract information corresponding to the first identifier. The identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
67. The method according to claim 66, characterized in that The eighth message includes the authenticated first identifier, and the method further includes: The fourth network element sends a reply message to the eighth message to the first network element, where the reply message to the eighth message includes the contract information corresponding to the first identifier.
68. The method according to claim 66, characterized in that The eighth message includes the authenticated identifier of the terminal device, and the method further includes: The fourth network element sends a reply message to the eighth message to the first network element, where the reply message to the eighth message includes the subscription information corresponding to the one or more user identifiers.
69. The method according to any one of claims 66 to 68, characterized in that The fourth network element is a unified data management function UDM network element.
70. The method according to any one of claims 66 to 69, characterized in that The first network element is an access and mobility management function AMF network element.
71. The method according to any one of claims 66 to 70, characterized in that The identifier of the terminal device is SUPI or an identifier determined based on SUPI.
72. A terminal device, characterized in that: include: A sending unit is used to send a first message to a first network element, where the first message includes a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
73. The terminal device according to claim 72, characterized in that The first message is used to authenticate the first identifier.
74. The terminal device according to claim 73, characterized in that The first message is a first registration request message.
75. The terminal device according to claim 73, characterized in that The first message is a response message to the authentication request message sent by the first network element.
76. The terminal device according to claim 75, characterized in that The authentication request message is a first registration reply message.
77. The terminal device according to any one of claims 73 to 76, characterized in that The first message also includes authentication information of the first identifier.
78. The terminal device according to claim 77, characterized in that The authentication information includes one or more of the following: username; password; A first secret key is determined based on biometric information of a user of the terminal device; An authentication parameter generated based on the first secret key.
79. The terminal device according to any one of claims 73 to 78, characterized in that The terminal device further includes: A receiving unit, configured to receive a second message sent by the first network element, where the second message includes one or more of the following: A second identifier, where the second identifier is used after the first identifier is successfully authenticated; The authentication result is used to indicate whether the authentication of the first identifier is successful or failed.
80. The terminal device according to claim 79, characterized in that The second message is a first registration reply message.
81. The terminal device according to claim 79 or 80, characterized in that The sending unit is further configured to: A third message is sent to the first network element, where the third message is used to verify the second identifier.
82. The terminal device according to claim 81, characterized in that The third message is triggered based on one or more of the following: Switching from a third identifier to the first identifier, the third identifier being one of the one or more user identifiers; The user corresponding to the first identifier has not used the terminal device within a first period of time; The terminal device initiates periodic registration update; The network device instructs the terminal device to send the second identifier.
83. The terminal device according to claim 82, characterized in that The periodic registration update includes one or more of the following: Periodic registration and update of the identification of the terminal device; Periodic registration updates for the first identifier.
84. The terminal device according to any one of claims 81 to 83, characterized in that: The second identifier includes the first identifier; or The second identifier does not include the first identifier, and the third message includes the first identifier.
85. The terminal device according to any one of claims 81 to 84, characterized in that The third message is a second registration request message.
86. The terminal device according to any one of claims 81 to 85, characterized in that The receiving unit is further configured to: Receive a fourth message sent by the first network element, where the fourth message includes a verification result of the second identifier.
87. The terminal device according to claim 86, characterized in that The fourth message is a second registration reply message.
88. The terminal device according to any one of claims 72 to 87, characterized in that The first message is used to request that the policy of the terminal device be updated to the policy corresponding to the first identifier.
89. The terminal device according to any one of claims 72 to 88, characterized in that: The first message includes a policy container of the terminal device, and the first identifier is carried in the policy container.
90. The terminal device according to claim 88 or 89, characterized in that: The first message is also used to verify a second identifier, where the second identifier is an identifier used after the first identifier is successfully authenticated.
91. The terminal device according to any one of claims 72 to 90, characterized in that The receiving unit is further configured to: Receive a fifth message sent by the first network element, where the fifth message is used to update the policy of the terminal device to the policy corresponding to the first identifier.
92. The terminal device according to any one of claims 72 to 91, characterized in that The first network element is an access and mobility management function AMF network element.
93. The terminal device according to any one of claims 72 to 92, characterized in that The identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on SUPI.
94. A communication device, characterized in that The communication device is a first network element, and the communication device includes: The receiving unit is used to receive a first message sent by a terminal device, where the first message includes a first identifier, the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
95. The communication device according to claim 94, characterized in that The first message is used to authenticate the first identifier.
96. The communication device according to claim 95, characterized in that The first message is a first registration request message.
97. The communication device according to claim 95, characterized in that The first message is a response message to the authentication request message sent by the first network element.
98. The communication device according to claim 97, characterized in that The authentication request message is a first registration reply message.
99. The communication device according to any one of claims 95 to 98, characterized in that The first message also includes authentication information of the first identifier.
100. The communication device according to claim 99, characterized in that The authentication information includes one or more of the following: username; password; The first secret key is determined based on biometric information of a user of the terminal device.
101. The communication device according to any one of claims 95 to 100, characterized in that The communication device further includes: A sending unit, configured to send a second message to the terminal device, where the second message includes one or more of the following: A second identifier, where the second identifier is used after the first identifier is successfully authenticated; The authentication result is used to indicate whether the authentication of the first identifier is successful or failed.
102. The communication device according to claim 101, characterized in that The second message is a first registration reply message.
103. The communication device according to claim 101 or 102, characterized in that The receiving unit is further configured to: Receive a third message sent by the terminal device, where the third message is used to verify the second identifier.
104. The communication device according to claim 103, characterized in that The third message is triggered based on one or more of the following: Switching from a third identifier to the first identifier, the third identifier being one of the one or more user identifiers; The user corresponding to the first identifier has not used the terminal device within a first period of time; The terminal device initiates periodic registration update; The network device instructs the terminal device to send the second identifier.
105. The communication device according to claim 104, characterized in that The periodic registration update includes one or more of the following: Periodic registration and update of the identification of the terminal device; Periodic registration updates for the first identifier.
106. The communication device according to any one of claims 103 to 105, characterized in that: The second identifier includes the first identifier; or The second identifier does not include the first identifier, and the third message includes the first identifier.
107. The communication device according to any one of claims 103 to 106, characterized in that The third message is a second registration request message.
108. The communication device according to any one of claims 103 to 107, characterized in that The sending unit is further configured to: A fourth message is sent to the terminal device, where the fourth message includes a verification result of the second identifier.
109. The communication device according to claim 108, characterized in that The fourth message is a second registration reply message.
110. The communication device according to any one of claims 94 to 109, characterized in that The first message is used to request that the policy of the terminal device be updated to the policy corresponding to the first identifier.
111. The communication device according to any one of claims 94 to 110, characterized in that The first message includes a policy container of the terminal device, and the first identifier is carried in the policy container.
112. The communication device according to claim 110 or 111, characterized in that The first message is also used to verify a second identifier, where the second identifier is an identifier used after the first identifier is successfully authenticated.
113. The communication device according to any one of claims 94 to 112, characterized in that The sending unit is further configured to: A fifth message is sent to the terminal device, where the fifth message is used to update the policy of the terminal device to the policy corresponding to the first identifier.
114. The communication device according to any one of claims 94 to 113, characterized in that The sending unit is further configured to send a sixth message to the second network element, where the sixth message is used to request the second network element to authenticate the first identifier; and / or The receiving unit is further configured to receive a reply message to the sixth message sent by the second network element, where the reply message to the sixth message includes one or more of the following: A second identifier, where the second identifier is used after the first identifier is successfully authenticated; The authentication result is used to indicate whether the authentication of the first identifier is successful or failed.
115. The communication device according to claim 114, characterized in that The second network element is a network element of a core network, or the second network element is an authentication server in communication connection with the core network.
116. The communication device according to any one of claims 94 to 115, characterized in that The sending unit is further configured to: A seventh message is sent to the third network element, where the seventh message is used to determine a policy corresponding to the first identifier.
117. The communication device according to claim 116, characterized in that The seventh message includes the authenticated first identifier, and the receiving unit is further configured to: A reply message to the seventh message sent by the third network element is received, where the reply message to the seventh message includes a policy corresponding to the first identifier.
118. The communication device according to claim 116, characterized in that The seventh message includes the authenticated identifier of the terminal device, and the receiving unit is further configured to: receiving a reply message to the seventh message sent by the third network element, where the reply message to the seventh message includes policies corresponding to the one or more user identifiers; as well as After the first identifier is successfully authenticated, a policy corresponding to the first identifier is determined from policies corresponding to the one or more user identifiers.
119. The communication device according to any one of claims 116 to 118, characterized in that The third network element is a policy control function PCF network element.
120. The communication device according to any one of claims 94 to 119, characterized in that The sending unit is further configured to: An eighth message is sent to the fourth network element, where the eighth message is used to determine the contract information corresponding to the first identifier.
121. The communication device according to claim 120, characterized in that The eighth message includes the authenticated first identifier, and the receiving unit is further configured to: Receive a reply message to the eighth message sent by the fourth network element, where the reply message to the eighth message includes the contract information corresponding to the first identifier.
122. The communication device according to claim 120, characterized in that The eighth message includes the authenticated identifier of the terminal device, and the receiving unit is further configured to: receiving a reply message to the eighth message from the fourth network element, where the reply message to the eighth message includes subscription information corresponding to the one or more user identifiers; as well as After the first identifier is successfully authenticated, the contract information corresponding to the first identifier is determined from the contract information corresponding to the one or more user identifiers.
123. The communication device according to any one of claims 120 to 122, characterized in that The fourth network element is a unified data management function UDM network element.
124. The communication device according to any one of claims 94 to 123, characterized in that The first network element is an access and mobility management function AMF network element.
125. The communication device according to any one of claims 94 to 124, characterized in that The identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on SUPI.
126. A communication device, characterized in that The communication device is a second network element, and the communication device includes: A receiving unit is used to receive a sixth message sent by the first network element, where the sixth message is used to request the second network element to authenticate the first identifier, where the first identifier is one of one or more user identifiers corresponding to the identifier of the terminal device.
127. The communication device according to claim 126, characterized in that The communication device further includes: a sending unit, configured to send a reply message to the sixth message to the first network element, where the reply message to the sixth message includes one or more of the following: A second identifier, where the second identifier is used after the first identifier is successfully authenticated; The authentication result is used to indicate whether the authentication of the first identifier is successful or failed.
128. The communication device according to claim 126 or 127, characterized in that The second network element is a network element of a core network, or the second network element is an authentication server in communication connection with the core network.
129. The communication device according to any one of claims 126 to 128, characterized in that The first network element is an access and mobility management function AMF network element.
130. The communication device according to any one of claims 126 to 129, characterized in that The identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on SUPI.
131. A communication device, characterized in that The communication device is a third network element, and the communication device includes: A receiving unit is used to receive a seventh message sent by the first network element, where the seventh message is used to determine a policy corresponding to a first identifier, where the identifier of the terminal device corresponds to one or more user identifiers, and where the first identifier is one of the one or more user identifiers.
132. The communication device according to claim 131, characterized in that The seventh message includes the authenticated first identifier, and the communication device further includes: A sending unit is used to send a reply message of the seventh message to the first network element, where the reply message of the seventh message includes a policy corresponding to the first identifier.
133. The communication device according to claim 131, characterized in that The seventh message includes the identifier of the authenticated terminal device, and the communication device further includes: a sending unit, configured to send a reply message to the seventh message to the first network element, where the reply message to the seventh message includes policies corresponding to the one or more user identifiers; After the first identifier is successfully authenticated, the first network element determines a policy corresponding to the first identifier from policies corresponding to the one or more user identifiers.
134. The communication device according to any one of claims 131 to 133, characterized in that The third network element is a policy control function PCF network element.
135. The communication device according to any one of claims 131 to 134, characterized in that The first network element is an access and mobility management function AMF network element.
136. The communication device according to any one of claims 131 to 135, characterized in that The identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on SUPI.
137. A communication device, characterized in that The communication device is a fourth network element, and the communication device includes: A receiving unit is used to receive an eighth message sent by a first network element, where the eighth message is used to determine the contract information corresponding to the first identifier, where the identifier of the terminal device corresponds to one or more user identifiers, and the first identifier is one of the one or more user identifiers.
138. The communication device according to claim 137, characterized in that The eighth message includes the authenticated first identifier, and the communication device further includes: The sending unit sends a reply message of the eighth message to the first network element, where the reply message of the eighth message includes the contract information corresponding to the first identifier.
139. The communication device according to claim 137, characterized in that The eighth message includes the identifier of the terminal device after authentication, and the sending unit is further used to send a reply message of the eighth message to the first network element, and the reply message of the eighth message includes the contract information corresponding to the one or more user identifiers.
140. The communication device according to any one of claims 137 to 139, characterized in that The fourth network element is a unified data management function UDM network element.
141. The communication device according to any one of claims 137 to 140, characterized in that The first network element is an access and mobility management function AMF network element.
142. The communication device according to any one of claims 137 to 141, characterized in that The identifier of the terminal device is an International Mobile Subscriber Identity (IMSI), a User Permanent Identifier (SUPI), or an identifier determined based on SUPI.
143. A communication device, characterized in that It includes a transceiver, a memory and a processor, the memory is used to store a program, the processor is used to call the program in the memory and control the transceiver to receive or send a signal so that the communication device performs one of the following: the method according to any one of claims 1 to 22, the method according to any one of claims 23 to 54, the method according to any one of claims 55 to 59, the method according to any one of claims 60 to 65, and the method according to any one of claims 66 to 71.
144. A chip, characterized in that It includes a processor for calling a program from a memory so that a device equipped with the chip performs one of the following: a method according to any one of claims 1 to 22, a method according to any one of claims 23 to 54, a method according to any one of claims 55 to 59, a method according to any one of claims 60 to 65, or a method according to any one of claims 66 to 71.
145. A computer-readable storage medium, characterized in that A program is stored thereon, the program causing the computer to execute one of the following: the method according to any one of claims 1 to 22, the method according to any one of claims 23 to 54, the method according to any one of claims 55 to 59, the method according to any one of claims 60 to 65, or the method according to any one of claims 66 to 71.
146. A computer program product, characterized in that The method comprises a program that causes a computer to perform one of the following: a method according to any one of claims 1 to 22, a method according to any one of claims 23 to 54, a method according to any one of claims 55 to 59, a method according to any one of claims 60 to 65, or a method according to any one of claims 66 to 71.
147. A computer program, characterized in that The computer program causes a computer to perform one of the following: a method according to any one of claims 1 to 22, a method according to any one of claims 23 to 54, a method according to any one of claims 55 to 59, a method according to any one of claims 60 to 65, or a method according to any one of claims 66 to 71.
Citation Information
Patent Citations
Communication method, device and system
CN112954768A
User identifier access method and communication device
CN113055879A
Method and apparatus for performing proxy authentication for access permission by terminal in wireless communication system
WO2020091281A1
Cross-network switching authentication method, and apparatus
WO2023206035A1