Communication method and communication apparatus
By acquiring the user ID and establishing a user-side connection based on it, the problem that QoS is not related to user accounts in the prior art is solved, flexible QoS guarantee is achieved according to the needs of users or applications, and the accuracy and flexibility of service quality are improved.
Patent Information
- Application Number
- PCT/CN2024/126858
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-30
- Filing Date
- 2024-10-23
- Publication Date
- 2025-08-07
AI Technical Summary
In the prior art, the quality of network service (QoS) guarantee of terminal devices has nothing to do with user accounts, resulting in the inability to flexibly adjust according to the needs of specific users or applications.
By obtaining the user ID, establishing a user-plane connection based on the user ID, using policy information to determine whether a new user-plane connection is needed, and providing an accurate authentication server during the authentication process, realizing granular QoS guarantee based on the user ID.
QoS guarantee is achieved based on the granularity of user identification, ensuring that the service quality needs of different users or applications are accurately met, and improving the flexibility and accuracy of QoS.
Smart Images

Figure CN2024126858_07082025_PF_FP_ABST
Abstract
Description
Communication method and communication device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on January 30, 2024, with application number 202410138091.9 and invention name "Communication Method and Communication Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of wireless communication technology, and in particular to a communication method and a communication device. Background Art
[0004] Currently, when users use terminal devices (such as mobile phones) to play games or watch videos, even if they are logged into their personal user accounts, the quality of service (QoS) provided by the network to the terminal device is related to the terminal device's subscription data, such as the subscription data corresponding to the terminal device's mobile phone number, and is not related to the logged-in application account. For example, if user A logs into a game on their phone using user account 1, the QoS provided by the network is based on the subscription data of the phone. If user B later logs into the same game on the same phone using user account 2, the network will also provide the same QoS.
[0005] The above QoS guarantee method is not applicable in some scenarios.
[0006] Summary of the Invention
[0007] The present application provides a communication method and a communication device for achieving flexible QoS guarantee.
[0008] In a first aspect, an embodiment of the present application provides a communication method, which can be performed by a terminal device or a module (such as a chip) applied to the terminal device. The method includes: obtaining a first user identifier, where the first user identifier represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account used to access an application on the terminal device; determining that a new user plane connection needs to be established based on the first user identifier, and then sending a connection establishment request, where the connection establishment request is used to request the establishment of a user plane connection based on the first user identifier.
[0009] The above solution establishes a user plane connection based on the granularity of the user identifier. The QoS guarantee of the user plane connection is related to the user identifier. The user identifier can represent the user using the terminal device, or represent the first device connected to the terminal device, or represent the user account used to access the application on the terminal device, thereby realizing QoS guarantee based on the granularity of the user identifier, thereby achieving flexible QoS guarantee.
[0010] In one possible implementation method, determining the need to establish a new user plane connection based on the first user identifier includes: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including a second user identifier, the second user identifier in the service flow information matching the first user identifier, and the routing information including the second user identifier; judging whether a user plane connection matching the second user identifier has been established based on the second user identifier in the routing information; if a user plane connection matching the second user identifier has not been established, determining that a new user plane connection needs to be established based on the first user identifier.
[0011] The above solution can accurately determine whether a new user plane connection is needed based on policy information, which helps to implement QoS guarantee based on user identification, thereby achieving flexible QoS guarantee.
[0012] In a possible implementation method, the method further includes: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including a second user identifier, the second user identifier in the service flow information matching the first user identifier, and the routing information including the second user identifier; judging, based on the second user identifier in the routing information, whether a user plane connection matching the second user identifier has been established; if the established user plane connection includes a user plane connection matching the second user identifier, using the user plane connection matching the second user identifier to transmit data corresponding to the first user identifier.
[0013] The above solution can accurately determine whether a new user plane connection is needed based on policy information, which helps to implement QoS guarantee based on user identification, thereby achieving flexible QoS guarantee.
[0014] In a possible implementation method, the routing information further includes at least one of the following information: domain name information in the first user identifier, domain name information in the second user identifier, or application information corresponding to the first user identifier.
[0015] In one possible implementation method, determining the need to create a new user plane connection based on the first user identifier includes: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including first domain name information, the first domain name information in the service flow information matches the second domain name information in the first user identifier, the routing information including indication information, the indication information indicating that different user plane connections are established for user identifiers that do not match each other; judging whether a user plane connection matching the first user identifier has been established based on the indication information in the routing information; if a user plane connection matching the first user identifier has not been established, determining that a new user plane connection needs to be created based on the first user identifier.
[0016] The above solution can accurately determine whether a new user plane connection is needed based on policy information, which helps to implement QoS guarantee based on user identification, thereby achieving flexible QoS guarantee.
[0017] In a possible implementation method, the method also includes: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including first domain name information, the first domain name information in the service flow information matches the second domain name information in the first user identifier, the routing information including indication information, the indication information indicating that different user plane connections are established for user identifiers that do not match each other; judging whether a user plane connection matching the first user identifier has been established based on the indication information in the routing information; if the established user plane connection includes a user plane connection matching the first user identifier, using the user plane connection matching the first user identifier to transmit data corresponding to the first user identifier.
[0018] The above solution can accurately determine whether a new user plane connection is needed based on policy information, which helps to implement QoS guarantee based on user identification, thereby achieving flexible QoS guarantee.
[0019] In a possible implementation method, the routing information further includes at least one of the following information: the first domain name information, the second domain name information, or application information corresponding to the first user identifier.
[0020] In one possible implementation method, the determination of the need to establish a new user plane connection based on the first user identifier includes: determining the policy information corresponding to the first user identifier, the policy information including an instruction to establish different user plane connections for user identifiers that do not match each other; judging whether a user plane connection matching the first user identifier has been established based on the policy information; if a user plane connection matching the first user identifier has not been established, determining that a new user plane connection needs to be established based on the first user identifier.
[0021] The above solution can accurately determine whether a new user plane connection is needed based on policy information, which helps to implement QoS guarantee based on user identification, thereby achieving flexible QoS guarantee.
[0022] In one possible implementation method, the method further includes: determining policy information corresponding to the first user identifier, the policy information indicating that different user plane connections are established for mutually mismatched user identifiers; judging, based on the indication information in the routing information, whether a user plane connection matching the first user identifier has been established; if the established user plane connection includes a user plane connection matching the first user identifier, using the user plane connection matching the first user identifier to transmit data corresponding to the first user identifier.
[0023] The above solution can accurately determine whether a new user plane connection is needed based on policy information, which helps to implement QoS guarantee based on user identification, thereby achieving flexible QoS guarantee.
[0024] In a possible implementation method, the policy information includes service flow information and routing information, the service flow information includes first information, the first information matches any user identifier, and the routing information includes the indication information.
[0025] In one possible implementation method, the routing selection information also includes at least one of second information, third information or fourth information, the second information indicates that the first user identifier is sent to the network, the third information indicates that the domain name information in the first user identifier is sent to the network, and the fourth information indicates that application information corresponding to the first user identifier is sent to the network.
[0026] In a possible implementation method, the connection establishment request further includes a first parameter, where the first parameter is used to determine an authentication server, and the authentication server is used to perform authentication on the first user identifier.
[0027] In the above solution, the terminal device provides the first parameter to the network side, so that the network side determines the authentication server for providing authentication for the terminal device based on the first parameter, thereby accurately determining the authentication server and helping to ensure the accuracy of authentication.
[0028] In a possible implementation method, the connection establishment request is carried in a NAS message, and the NAS message further includes a first parameter, where the first parameter is used to determine an authentication server, and the authentication server is used to authenticate the first user identifier.
[0029] In the above solution, the terminal device provides the first parameter to the network side, so that the network side determines the authentication server for providing authentication for the terminal device based on the first parameter, thereby accurately determining the authentication server and helping to ensure the accuracy of authentication.
[0030] In a possible implementation method, the first parameter includes one or more of the following information: the first user identifier, domain name information in the first user identifier, identification information of the authentication server, or application information corresponding to the first user identifier.
[0031] In one possible implementation method, the application information includes one or more of the following information: identification information of the application, identification information of the application server, identification information of the application function service, identification information of the application function, identification information of the authentication server, or the domain name corresponding to the application.
[0032] In a possible implementation method, obtaining the first user identifier includes: obtaining the first user identifier from an application on the terminal device; or obtaining the first user identifier from the first device.
[0033] In a second aspect, an embodiment of the present application provides a communication method, which can be executed by a first network element or a module (such as a chip) applied to the first network element. The first network element is a session management network element or a policy control network element. The method includes: receiving a first parameter from a terminal device, the first parameter including one or more of the following information: a first user identifier, domain name information in the first user identifier, or application information corresponding to the first user identifier; wherein the first user identifier represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account used to access an application on the terminal device; based on the first parameter, determining an authentication server, the authentication server being used to perform authentication on the first user identifier.
[0034] In the above solution, the terminal device provides the first parameter to the first network element, and the first network element determines the authentication server for providing authentication for the terminal device based on the first parameter, thereby accurately determining the authentication server and helping to ensure the accuracy of authentication.
[0035] In one possible implementation method, determining the authentication server based on the first parameter includes: sending a first request to a unified data management network element or a unified database network element, the first request including the first parameter; receiving a first response from the unified data management network element or the unified database network element, the first response including the identification information of the authentication server.
[0036] In one possible implementation method, determining the authentication server based on the first parameter includes: determining the identification information of the authentication server corresponding to the first parameter based on pre-configuration information, and the pre-configuration information includes the correspondence between the first parameter and the identification information of the authentication server.
[0037] In a possible implementation method, the first network element is a policy control network element; the method further includes: sending identification information of the authentication server to a session management network element.
[0038] In a possible implementation method, the method further includes: sending indication information to the session management network element, where the indication information instructs to perform authentication.
[0039] In a possible implementation method, the method further includes: after successful authentication, receiving the first user identifier from the authentication server.
[0040] In the above solution, after successful authentication, the authentication server provides the first user identifier to the first network element, thereby ensuring the security of the first user identifier.
[0041] In a third aspect, an embodiment of the present application provides a communication device, which may be a terminal device or a module (such as a chip) for a terminal device. The device has the function of implementing any implementation method of the first aspect described above. The function may be implemented by hardware or by executing corresponding software implementations in hardware. The hardware or software includes one or more modules corresponding to the above functions.
[0042] In a fourth aspect, an embodiment of the present application provides a communication device, which may be a first network element or a module (such as a chip) for the first network element. The device has the function of implementing any implementation method of the second aspect described above. The function may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0043] In a fifth aspect, an embodiment of the present application provides a communication device, comprising a unit or means for executing each step of any implementation method in the above-mentioned first to second aspects.
[0044] In a sixth aspect, an embodiment of the present application provides a communication device, comprising a processor and an interface circuit, wherein the processor is configured to communicate with other devices via the interface circuit and execute any of the implementation methods in the first to second aspects above. The processor comprises one or more.
[0045] In a seventh aspect, an embodiment of the present application provides a communication device, comprising a processor, the processor being configured to call a program to execute any of the implementation methods in the first to second aspects above. The processor may be one or more.
[0046] Optionally, the communication device may further include a memory, which is coupled to the processor and may be located inside or outside the device.
[0047] In an eighth aspect, an embodiment of the present application provides a communication device, comprising a processor; when the device is running, the processor executes computer instructions to enable the device to execute any implementation method in the above-mentioned first to second aspects.
[0048] Optionally, the communication device may further include a memory for storing the computer instructions.
[0049] In the ninth aspect, an embodiment of the present application further provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are run by a communication device, any implementation method in the above-mentioned first to second aspects is executed.
[0050] In the tenth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, which, when run on a communication device, enables any implementation method in the above-mentioned first to second aspects to be executed.
[0051] In the eleventh aspect, an embodiment of the present application further provides a chip system, comprising: a processor for executing any implementation method in the above-mentioned first to second aspects. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 is a schematic diagram of a 5G network architecture based on a service-oriented architecture;
[0053] FIG2( a ) is a flow chart of a communication method according to an embodiment of the present application;
[0054] FIG2( b ) is a flow chart of a communication method according to an embodiment of the present application;
[0055] 3 to 7 are flow charts of a communication method according to an embodiment of the present application;
[0056] FIG8 is a schematic diagram of a communication device provided in an embodiment of the present application;
[0057] FIG9 is a schematic diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0058] To meet the challenges of wireless broadband technology and maintain the leading edge of the 3rd Generation Partnership Project (3GPP) network, the 3GPP standards group has developed a next-generation mobile communications network system architecture, known as the fifth-generation (5G) network architecture. This architecture not only supports access to the 5G core network (CN) using 3GPP-defined radio access technologies (such as Long Term Evolution (LTE) and 5G Radio Access Network (RAN)), but also supports access to the core network using non-3GPP access technologies via the non-3GPP interworking function (N3IWF) or the next-generation packet data gateway (ngPDG).
[0059] Figure 1 is a schematic diagram of a 5G network architecture based on a service-oriented architecture. The 5G network architecture shown in Figure 1 may include access network equipment and core network equipment. Terminal equipment accesses the data network (DN) through access network equipment and core network equipment. The core network equipment includes but is not limited to some or all of the following network elements: authentication server function (AUSF) network element, unified data management (UDM) network element, unified data repository (UDR) network element, network repository function (NRF) network element, network exposure function (NEF) network element, application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, and user plane function (UPF) network element.
[0060] The terminal device can be user equipment (UE), a mobile station, a mobile terminal device, etc. The terminal device can be widely used in various scenarios, for example, device-to-device (D2D), vehicle to everything (V2X) communication, machine-type communication (MTC), Internet of Things (IOT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, etc. The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a wearable device, a vehicle, an urban air vehicle (such as an unmanned aerial vehicle, a helicopter, etc.), a ship, a robot, a robotic arm, a smart home device, etc. For the sake of convenience, this application uses UE as an example of a terminal device for illustration, and any UE appearing in any subsequent position can be replaced by a terminal device.
[0061] Access network equipment can be wireless access network equipment or wired access network equipment. Wireless access network equipment includes 3GPP access network equipment, untrusted non-3GPP access network equipment, and trusted non-3GPP access network equipment. 3GPP access network equipment includes, but is not limited to, evolved NodeBs (eNodeBs) in LTE, next-generation NodeBs (gNBs) in 5G mobile communication systems, base stations in future mobile communication systems, or modules or units that perform some of the functions of base stations, such as centralized units (CUs) and distributed units (DUs). Untrusted non-3GPP access network equipment includes, but is not limited to, untrusted non-3GPP access gateways or N3IWFs, untrusted wireless local area network (WLAN) access points (APs), switches, and routers. Trusted non-3GPP access network equipment includes, but is not limited to, trusted non-3GPP access gateways, trusted WLAN APs, switches, and routers. Wired access network equipment includes, but is not limited to, wireline access gateways, fixed-line network equipment, switches, and routers. For ease of explanation, this application uses a base station as an example of an access network device, and any base station appearing at any subsequent location can be replaced by an access network device.
[0062] Base stations and UEs can be fixed or mobile. They can be deployed on land, indoors or outdoors, handheld or vehicle-mounted; on water; or in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of base stations and UEs.
[0063] The AMF network element performs functions such as mobility management and access authentication / authorization. It is also responsible for transferring user policies between the UE and the PCF.
[0064] The SMF network element includes functions such as performing session management, executing control policies issued by the PCF network element, selecting the UPF network element, or allocating the UE's Internet Protocol (IP) address.
[0065] The UPF network element includes functions such as user plane data forwarding, session / flow-level billing statistics, or bandwidth limitation.
[0066] UDM network elements include functions such as executing and managing contract data or user access authorization.
[0067] UDR includes functions for accessing data such as contract data, policy data, or application data.
[0068] NEF network element is used to support the opening of capabilities and events.
[0069] The AF network element communicates application-side requirements to the network, such as Quality of Service (QoS) requirements or user status event subscriptions. The AF can be a third-party functional entity or an application service deployed by an operator, such as the IP Multimedia Subsystem (IMS) voice call service. AF network elements include those within the core network (i.e., the operator's AF network element) and third-party AF network elements (such as an enterprise's application server).
[0070] The PCF network element includes policy control functions such as billing for sessions and service flow levels, QoS bandwidth guarantee and mobility management, or UE policy decision-making. PCF network elements include access and mobility management policy control function (AM PCF) network element and session management policy control function (SM PCF) network element. Among them, the AM PCF network element is used to formulate AM policy and user policy for UE. The AM PCF network element can also be called a policy control network element that provides services for UE (PCF for a UE). The SM PCF network element is used to formulate session management policy (SMpolicy) for the session. The SM PCF network element can also be called a policy control network element that provides services for protocol data unit (PDU) sessions ((PCF for a PDU session))).
[0071] NRF network elements can be used to provide network element discovery functions, providing network element information corresponding to the network element type based on requests from other network elements. NRF network elements also provide network element management services, such as network element registration, update, deregistration, or network element status subscription and push.
[0072] The AUSF network element is responsible for authenticating users to determine whether users or devices are allowed to access the network.
[0073] A DN is a network located outside of a carrier network. A carrier network can connect to multiple DNs, and a variety of services can be deployed on the DN, providing UEs with data and / or voice services. For example, a DN is the private network of a smart factory. Sensors installed in the workshop can be UEs. The DN houses a control server for these sensors, which can provide services to the sensors. The sensors can communicate with the control server, receive instructions from the control server, and transmit collected sensor data to the control server based on the instructions. Another example is a DN that is a company's internal office network. An employee's mobile phone or computer can be a UE, allowing them to access information and data resources on the company's internal office network.
[0074] In Figure 1, Nausf, Npcf, Nudr, Nudm, Naf, Namf, Nsmf, Nnef, and Nnrf are the service-based interfaces (SBIs) provided by the aforementioned AUSF, PCF, UDR, UDM, AF, AMF, SMF, NEF, and NRF, respectively, and are used to invoke corresponding service-based operations. N1, N2, N3, N4, and N6 are interface serial numbers, and their meanings are as follows:
[0075] 1) N1: The interface between the AMF network element and the UE, which can be used to deliver non-access stratum (NAS) signaling (such as QoS rules from the AMF network element) to the UE.
[0076] 2) N2: The interface between the AMF network element and the base station, which can be used to transmit radio bearer control information from the core network side to the base station.
[0077] 3) N3: The interface between the base station and the UPF network element, mainly used to transmit uplink and downlink user plane data between the base station and the UPF network element.
[0078] 4) N4: The interface between the SMF network element and the UPF network element, which can be used to transmit information between the control plane and the user plane, including controlling the issuance of forwarding rules, QoS rules, traffic statistics rules, etc. for the user plane and reporting information on the user plane.
[0079] 5) N6: The interface between UPF network element and DN, used to transmit uplink and downlink user data flows between UPF network element and DN.
[0080] It is understood that the above-mentioned network element or function can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the above-mentioned network element or function can be implemented by a single device, or by multiple devices, or can be a functional module within a single device, and this is not specifically limited in the embodiments of the present application.
[0081] The session management network element, policy control network element, unified data management network element, and unified database network element in this application can be the SMF network element, PCF network element, UDM network element, and UDR network element in Figure 1, respectively, or they can be network elements with the functions of the above-mentioned SMF network element, PCF network element, UDM network element, and UDR network element in future communications such as 6G networks. This application is not limited to this. In the embodiments of this application, an example is given of the SMF network element, PCF network element, UDM network element, and UDR network element as the session management network element, policy control network element, unified data management network element, and unified database network element, respectively, and the SMF network element, PCF network element, UDM network element, and UDR network element are referred to as SMF, PCF, UDM, and UDR, respectively.
[0082] To facilitate understanding of the present invention, the background involved in the present invention is first described below.
[0083] 1. User equipment routing selection policy (URSP) rules
[0084] URSP rules are used by the UE to determine whether a new PDU session needs to be created for a new service flow. The URSP rules include at least one service flow descriptor (traffic descriptor, TD) and a route selection descriptor (route selection descriptor, RSD) corresponding to each TD. Among them, the TD contains information for matching service flows. For example, the TD contains one or more of an application descriptor (such as one or more operating system identifiers (OSId) or operating system application identifiers (OSAppId)), an IP descriptor (such as a destination IP triplet), a non-IP descriptor (such as media access control (MAC) address information), a domain name (such as a fully qualified domain name (FQDN)), a data network name (DNN) or connection capability information.
[0085] The UE can use the TD in the URSP rule to match the information of the service flow. When the information of the service flow matches a TD in a certain URSP rule, the RSD corresponding to the TD in the URSP rule is determined, and the parameters of the PDU session to be established are determined based on the RSD. If there is a PDU session that matches the parameters in the established PDU session, the established PDU session is reused to transmit the service flow. If there is no PDU session that matches the parameters in the established PDU session, a new PDU session is created and the new PDU session is used to transmit the service flow.
[0086] 2. Secondary authentication (also known as secondary authentication)
[0087] Secondary authentication refers to the authentication that a UE needs to perform again when it wants to access a specific network after successfully accessing the 5G network. The authentication performed by AUSF and UDM when the UE accesses the 5G network is called primary authentication, primary authentication, primary authentication, or one-time authentication.
[0088] The purpose of secondary authentication is to ensure the security of special networks. For example, if a bank employee wants to access the bank's internal network on a mobile phone, it is best to perform secondary authentication. Only after passing the authentication can the business be accessed.
[0089] During secondary authentication, the UE must provide special user credentials. These credentials are not from the operator but rather are a credential between the UE and a specific network (such as an enterprise network). These credentials are typically issued by the enterprise network. Secondary authentication occurs between the UE and an authentication server (e.g., an Authentication, Authorization, and Accounting (AAA) server). An AAA server is also called a DN-AAA server.
[0090] To provide more flexible QoS guarantees, embodiments of the present application provide corresponding solutions. Referring to Figure 2(a), a flow chart of a communication method provided in an embodiment of the present application is shown. This method can be executed by a UE or a module (e.g., a chip) of the UE. The following description uses the UE executing this method as an example.
[0091] The method comprises the following steps:
[0092] Step 201a: The UE obtains a first user identity.
[0093] In one implementation method, a first user identifier represents a user using a UE. Based on this implementation method, different users use different user identifiers, and each user identifier is used to represent a user. Exemplarily, the UE is a shared terminal that different users can log in to. The user identifier may include a user account, or a user account and a user password. For example, if the user identifier of user 1 is user identifier 1, user 1 can use user identifier 1 to log in to the UE and access applications on the UE. For example, if the user identifier of user 2 is user identifier 2, user 2 can use user identifier 2 to log in to the UE and access applications on the UE.
[0094] In another implementation method, the first user identifier represents the first device connected to the UE. For example, the UE is a mobile phone, and the first device is a wearable device that can be connected to the mobile phone (such as a smart watch, bracelet, etc.). In the present invention, the first device connected to the UE can be a 3GPP device or a non-3GPP device. This application does not limit it. It is uniformly described here and will not be repeated elsewhere. Based on this implementation method, different first devices use different user identifiers, and each user identifier is used to represent a first device. For example, if the user identifier of smart watch 1 is user identifier 1, then smart watch 1 can use user identifier 1 to connect to the mobile phone. For example, if the user identifier of smart watch 2 is user identifier 2, then smart watch 2 can use user identifier 2 to connect to the mobile phone. For example, if the user identifier of smart bracelet 1 is user identifier 3, then smart bracelet 1 can use user identifier 3 to connect to the mobile phone. For example, if the user identifier of smart bracelet 2 is user identifier 4, then smart bracelet 2 can use user identifier 4 to connect to the mobile phone.
[0095] In another implementation method, the first user identifier represents a user account used to access the application on the UE. Based on this implementation method, for a specific application, different user identifiers can be used to access the application, that is, the user identifier refers to the user identifier associated with the specific application. The user identifier can include a user account, or a user account and a user password. For example, user identifier 1, user identifier 2, user identifier 3, etc. can all be used to log in to a video app.
[0096] Exemplarily, step 201a may specifically be: the UE obtains the first user identifier from an application on the UE, or obtains the first user identifier from a first device connected to the UE, for example, obtaining the first user identifier from the first device via wireless fidelity (WiFi).
[0097] For example, in an embodiment of the present application, the user identifier may include domain information and / or a user name. The domain information may include, for example, information about the domain where the authentication server is located, such as the FQDN or realm part. The user name is used to distinguish different users. The user identifier may include, for example, the first user identifier described herein or the second user identifier described later.
[0098] Step 202a: The UE determines that a new user plane connection needs to be established based on the first user identity, and then sends a connection establishment request.
[0099] The connection establishment request is used to request establishment of a user plane connection based on the first user identifier.
[0100] Exemplarily, the user plane connection may be a protocol data unit (PDU) session, or other types of connections, which are not limited in this application.
[0101] The above solution establishes a user plane connection based on the user identifier, and the QoS guarantee of the user plane connection is related to the user identifier. The user identifier can represent the user using the terminal device, or represent the first device connected to the terminal device, or represent the user account used to access the application on the terminal device, thereby realizing QoS guarantee based on the granularity of the user identifier, thereby realizing flexible QoS guarantee.
[0102] In one implementation method, when a user identifier represents a user using a UE, after a user logs in to the UE using the user identifier, the QoS guarantees used for accessing different applications on the UE are all related to the contract data corresponding to the user identifier, and when different users log in to the UE using different user identifiers, the QoS guarantees used for accessing applications on the UE are related to the user currently using the UE. For example, when user 1 logs in to the UE using user identifier 1 and accesses an application on the UE, regardless of the application being accessed, the corresponding QoS guarantees are used based on the contract data corresponding to user identifier 1. For example, when user 2 logs in to the UE using user identifier 2 and accesses an application on the UE, regardless of the application being accessed, the corresponding QoS guarantees are used based on the contract data corresponding to user identifier 2.
[0103] In another implementation, when a user identifier represents a first device connected to a UE, after a first device uses the user identifier to connect to the UE, the QoS guarantees applied to the services of the first device are related to the first device connected to the UE. For example, after smartwatch 1 uses user identifier 1 to connect to a mobile phone, the QoS guarantees applied to the services of smartwatch 1 are related to smartwatch 1. For example, after smartwatch 2 uses user identifier 2 to connect to a mobile phone, the QoS guarantees applied to the services of smartwatch 2 are related to smartwatch 2.
[0104] In another implementation method, when the user identifier represents a user account used to access an application on the UE, after a certain user account is used to log in to the application, QoS protection is performed according to the contract data corresponding to the user account, and when different user accounts are used to log in to the same application, the corresponding QoS protection is performed according to the contract data corresponding to the different user accounts. For example, after using user account 1 to log in to a video APP, the corresponding QoS protection is performed according to the contract data corresponding to user account 1. For example, after using user account 2 to log in to the same video APP, the corresponding QoS protection is performed according to the contract data corresponding to user account 2.
[0105] As an implementation method, after the above step 201a, the UE determines the policy information corresponding to the first user identifier, and determines whether it is necessary to create a new user plane connection based on the first user identifier based on the policy information. If a new user plane connection needs to be created based on the first user identifier, step 202a is executed, that is, a connection establishment request is sent. If a new user plane connection is not required based on the first user identifier, the data corresponding to the first user identifier can be transmitted using an already established user plane connection.
[0106] The following describes the specific implementation of the UE determining whether a new user plane connection needs to be established based on the first user identity, with respect to different implementation methods of the policy information.
[0107] In implementation method 1, the policy information includes service flow information and routing information, the service flow information includes the second user identifier, and the routing information includes the second user identifier. Optionally, the routing information may further include at least one of the following: domain name information in the first user identifier, domain name information in the second user identifier, or application information corresponding to the first user identifier.
[0108] If the UE determines that the second user identifier in the service flow information matches the first user identifier, it obtains the routing information corresponding to the service flow information and determines, based on the second user identifier in the routing information, whether a user plane connection matching the second user identifier has been established. If a user plane connection matching the second user identifier has not been established, it is determined that a new user plane connection needs to be created based on the first user identifier, and the data corresponding to the first user identifier can be subsequently transmitted using the new user plane connection. If the established user plane connections include a user plane connection matching the second user identifier, the user plane connection matching the second user identifier is used to transmit the data corresponding to the first user identifier.
[0109] The second user identifier matches the first user identifier, for example, the second user identifier is the same as the first user identifier, or has a corresponding relationship with the first user identifier, or the second user identifier and the first user identifier contain the same information, such as the same domain name information.
[0110] In a second implementation method, the policy information includes service flow information and routing information, the service flow information includes first domain name information, and the routing information includes indication information indicating that different user plane connections are to be established for mutually mismatched user identifiers. Optionally, the routing information may further include at least one of the following: the first domain name information, the second domain name information in the first user identifier, or application information corresponding to the first user identifier.
[0111] In one possible implementation, not matching each other includes being completely different or not completely the same. "Completely different" here means that the information contained in the two user identifiers is completely different. "Not completely the same" here means that the information contained in the two user identifiers is partially the same but not the same. In other words, if the information contained in the two user identifiers is completely the same, then the two user identifiers match each other. For example, user identifier 1 consists of domain information 1 and user name 1, and user identifier 2 consists of domain information 2 and user name 2. If domain information 1 and domain information 2 are the same, and user name 1 and user name 2 are the same, then user identifier 1 and user identifier 2 are completely the same, and therefore user identifier 1 and user identifier 2 match each other. If domain information 1 and domain information 2 are the same, but user name 1 and user name 2 are different, then user identifier 1 and user identifier 2 are not completely the same, and therefore user identifier 1 and user identifier 2 do not match each other. If domain information 1 and domain information 2 are different, but user name 1 and user name 2 are the same, then user identifier 1 and user identifier 2 are not completely the same, and therefore user identifier 1 and user identifier 2 do not match each other. If domain information 1 is different from domain information 2, and user name 1 is different from user name 2, user ID 1 is completely different from user ID 2, and therefore user ID 1 and user ID 2 do not match each other.
[0112] In another possible implementation, mutual mismatch refers to non-correspondence, and correspondingly, mutual matching refers to correspondence. The "correspondence" here refers to the existence of a corresponding relationship or mapping relationship between the two user identifiers. Exemplarily, if user identifier 1 and user identifier 2 have a corresponding relationship, that is, "correspondence", then the same user plane connection can be established for the user identifier 1 and user identifier 2. If user identifier 1 and user identifier 2 do not have a corresponding relationship, that is, "non-correspondence", then different user plane connections can be established for the user identifier 1 and user identifier 2. It should be noted that whether two user identifiers match is not necessarily related to whether the information of the two user identifiers is the same. That is, if the two user identifiers match each other, the information contained in the two user identifiers may be exactly the same, may be completely different, or may not be exactly the same. If the two user identifiers do not match each other, the information contained in the two user identifiers may also be exactly the same, may be completely different, or may not be exactly the same.
[0113] The explanation of "mutual mismatch" here can be applied to any embodiment of the present application. It is explained here uniformly and will not be repeated later.
[0114] The UE determines that the first domain name information in the service flow information matches the second domain name information in the first user identifier, then obtains the routing information corresponding to the service flow information, and determines whether a user plane connection matching the first user identifier has been established based on the indication information in the routing information. If a user plane connection matching the first user identifier has not been established, it is determined that a new user plane connection needs to be created based on the first user identifier, and the newly created user plane connection can be used to subsequently transmit data corresponding to the first user identifier. If the established user plane connections include a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit data corresponding to the first user identifier.
[0115] The second domain name information matches the first domain name information, for example, the second domain name information is the same as the first domain name information, or has a corresponding relationship with the first domain name information, or the second domain name information and the first domain name information contain the same information.
[0116] In a third implementation method, the policy information indicates that different user plane connections are established for mutually mismatched user identifiers.
[0117] After the UE obtains the first user identifier, it determines, based on the policy information, whether a user plane connection matching the first user identifier has been established. If a user plane connection matching the first user identifier has not been established, it is determined that a new user plane connection needs to be established based on the first user identifier, and the newly established user plane connection can be used to subsequently transmit data corresponding to the first user identifier. If the established user plane connections include a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit data corresponding to the first user identifier.
[0118] Exemplarily, the policy information includes service flow information and routing information, the service flow information includes first information, the first information matches any user identifier, and the routing information includes the above-mentioned indication information. Based on this method, after the UE obtains the first user identifier, it determines that the first user identifier matches the first information in the service flow information, then obtains the routing information corresponding to the service flow information, and judges whether a user plane connection matching the first user identifier has been established based on the indication information in the routing information. If a user plane connection matching the first user identifier has not been established, it is determined that a new user plane connection needs to be created based on the first user identifier, and the newly created user plane connection can be used to transmit data corresponding to the first user identifier subsequently. If the established user plane connection includes a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit data corresponding to the first user identifier.
[0119] Optionally, in addition to the indication information, the routing selection information may also include at least one of the second information, the third information or the fourth information, wherein the second information indicates that the first user identifier is sent to the network, the third information indicates that the domain name information in the first user identifier is sent to the network, and the fourth information indicates that application information corresponding to the first user identifier is sent to the network.
[0120] Illustratively, the policy information in the above implementation methods 1 to 3 may be URSP, the service flow information in the policy information may be TD in URSP, and the routing information in the policy information may be RSD in URSP.
[0121] As an implementation method, the connection establishment request in step 202a includes a first parameter, which is used to determine an authentication server, which is used to authenticate the first user identifier. The authentication server can be an AAA server or an AUSF network element.
[0122] As another implementation method, the connection establishment request in step 202a is carried in a NAS message. In addition to the connection establishment request, the NAS message also includes a first parameter. The first parameter is used to identify an authentication server, which is used to authenticate the first user identifier. The authentication server can be an AAA server or an AUSF network element.
[0123] Exemplarily, the first parameter includes one or more of the following information: the first user identifier, domain name information in the first user identifier, identification information of the authentication server, or application information corresponding to the first user identifier. Optionally, the information included in the first parameter may come from the above-mentioned policy information.
[0124] In an embodiment of the present application, the application information corresponding to the first user identifier includes one or more of the following information: identification information of the application (for example, it can be APP ID, APPaddress or APPdomain), identification information of the application server (for example, it can be APP server ID, APP server address or APP serverdomain), identification information of the application function service (for example, it can be AF service ID), identification information of the application function (for example, it can be AF ID, AF address or AF domain), identification information of the authentication server (for example, it can be AAA server ID, AAA server address, AAA serverdomain, AUSFID or AUSFaddress) or the domain name corresponding to the application.
[0125] To achieve the selection of the correct authentication server, an embodiment of the present application provides a corresponding solution. Referring to Figure 2(b), a flow chart of a communication method provided in an embodiment of the present application is shown. The method is executed by a first network element or a module (e.g., a chip) of the first network element. The following description uses the first network element executing the method as an example. The first network element is an SMF or PCF.
[0126] The method comprises the following steps:
[0127] Step 201b: The first network element receives a first parameter from the UE.
[0128] As an implementation method, the first parameter is carried in a connection establishment request, and the connection establishment request is used to request establishment of a user plane connection based on the first user identifier. For example, the UE sends a NAS message to the AMF, and the NAS message includes a session management container (SM container), and the session management container includes a connection establishment request, and the connection establishment request includes the first parameter, and the connection establishment request is used to request establishment of a user plane connection based on the first user identifier. The AMF sends the session management container to the SMF. If the first network element is the SMF, the SMF can obtain the first parameter from the connection establishment request; if the first network element is the PCF, the PCF receives the first parameter sent by the SMF after the SMF obtains the first parameter from the connection establishment request.
[0129] As another implementation method, the UE sends an NAS message to the AMF. The NAS message includes a session management container, the session management container includes a first parameter and a connection establishment request, and the connection establishment request is used to request establishment of a user plane connection based on the first user identifier. The AMF sends the session management container to the SMF. If the first network element is the SMF, the SMF may obtain the first parameter from the session management container. If the first network element is the PCF, the PCF receives the first parameter from the SMF after the SMF obtains the first parameter from the session management container.
[0130] Exemplarily, the first parameter includes one or more of the following information: a first user identifier, domain name information in the first user identifier, or application information corresponding to the first user identifier. For the specific meanings of the first user identifier and the application information corresponding to the first user identifier, reference can be made to the description in the embodiment of FIG. 2( a ) above.
[0131] Step 202b: The first network element determines the authentication server according to the first parameter.
[0132] The authentication server is used to authenticate the first user identifier. The authentication server may be an AAA server or an AUSF network element.
[0133] In one implementation method, step 202b may specifically include: the first network element sends a first request to the UDM, the first request including a first parameter; the UDM determines an authentication server based on the first parameter; and the UDM sends a first response to the first network element, the first response including identification information of the authentication server. The identification information of the authentication server may include an identification of the authentication server, address information of the authentication server, or domain name information of the authentication server.
[0134] In another implementation method, step 202b can specifically be: the first network element sends a first request to the UDR, the first request includes a first parameter, the UDR determines the authentication server based on the first parameter, and then the UDR sends a first response to the first network element, the first response includes identification information of the authentication server.
[0135] In another implementation method, step 202b can specifically be: the first network element sends a first request to the NRF, the first request includes a first parameter, the NRF determines the authentication server based on the first parameter, and then the NRF sends a first response to the first network element, the first response includes identification information of the authentication server.
[0136] In another implementation method, when the first network element is SMF, step 202b can specifically be: the first network element sends a first request to the PCF, the first request includes a first parameter, the PCF determines the authentication server based on the first parameter, and then the PCF sends a first response to the first network element, the first response includes identification information of the authentication server.
[0137] In another implementation method, step 202b may specifically be: the first network element determines identification information of the authentication server corresponding to the first parameter based on local pre-configuration information, where the pre-configuration information includes a correspondence between the first parameter and the identification information of the authentication server.
[0138] Exemplarily, the first network element is PCF. After PCF determines the identification information of the authentication server based on any of the aforementioned methods (that is, after step 202b), it can send the identification information of the authentication server to SMF, so that SMF cooperates with the authentication server to authenticate the first user identity based on the identification information of the authentication server.
[0139] Exemplarily, if the first network element is a PCF, the PCF may send, while sending the identification information of the authentication server to the SMF, an instruction to perform authentication. Of course, if the PCF does not send the instruction to the SMF, the SMF may also determine that authentication needs to be performed based on the received identification information of the authentication server. That is, the identification information of the authentication server may be used to implicitly indicate the execution of authentication.
[0140] As an implementation method, after successful authentication, the authentication server may send the first user identifier to the first network element. Based on this method, the first parameter may not include the first user identifier or may include an incomplete first user identifier. After successful authentication, the authentication server then provides the first user identifier to the first network element, thereby ensuring the security of the first user identifier.
[0141] In the above solution, the UE provides the first parameter to the first network element, so that the first network element determines the authentication server for providing authentication for the UE based on the first parameter, thereby accurately determining the authentication server and helping to ensure the accuracy of authentication.
[0142] It should be noted that the embodiment of FIG. 2( a ) and the embodiment of FIG. 2( b ) can be implemented separately or in combination, and this application does not limit this.
[0143] To facilitate understanding of the embodiments of Figures 2(a) and 2(b), the embodiments of Figures 2(a) and 2(b) are specifically described below in conjunction with the embodiments of Figures 3 to 7. In the embodiments of Figures 3 to 7 below, the AAA server is used as a specific example of the authentication server, and the PDU session is used as a specific example of the user plane connection for description. It should be noted that, in the embodiments of Figures 3 to 7 below, any AAA server can be replaced with an authentication service function (Authentication Server Function, AUSF) or other types of authentication servers, and accordingly, the information related to the AAA server is also replaced with information related to the AUSF, such as replacing the identification information of the AAA server with the identification information of the AUSF, and so on. Moreover, in the embodiments of Figures 3 to 7 below, the PDU session can be replaced with other types of user plane connections.
[0144] Figure 3 is a flowchart of a communication method provided by an embodiment of the present application. In this method, the first user identifier is assigned by the application, and the identification information of the AAA server is determined by the SMF, and the AAA server is the AAA server in the DN.
[0145] The method comprises the following steps:
[0146] Step 301: UE obtains policy information.
[0147] For example, during the UE registration process or after the UE registration process is completed, the PCF sends policy information to the UE through the AMF.
[0148] For the meaning of the policy information, please refer to the description in the embodiment of FIG2( a ).
[0149] Step 302: The UE obtains a first user identifier.
[0150] Exemplarily, the UE obtains the first user identifier from an application on the UE, or obtains the first user identifier from other UEs connected to the UE, for example, obtains the first user identifier from other UEs via WiFi.
[0151] Step 303: The UE determines, according to the policy information, that a new PDU session needs to be established based on the first user identifier.
[0152] For the specific implementation of this step, please refer to the description in the embodiment of Figure 2(a) above.
[0153] In step 304, the UE sends a PDU Session Establishment Request to the AMF. In response, the AMF receives the PDU Session Establishment Request.
[0154] Exemplarily, the UE sends a NAS message to the AMF through the base station, where the NAS message includes a PDU session establishment request.
[0155] As an implementation method, in step 304, the UE further sends a first parameter to the AMF. The first parameter is used to determine the AAA server. For example, the first parameter may be included in a PDU session establishment request. In another example, the first parameter may be included in a NAS message, i.e., the NAS message includes the first parameter and the PDU session establishment request.
[0156] For the specific content of the first parameter, please refer to the description in the embodiment of Figure 2(a) above.
[0157] Exemplarily, the PDU session establishment request may also include a PDU session identifier (PDU session ID), slice information (such as single network slice selection assistance information (S-NSSAI)) and a data network name (data network name, DNN).
[0158] Step 305: AMF sends a session context establishment request to SMF. Correspondingly, SMF receives the session context establishment request.
[0159] Exemplarily, the session context establishment request may be Nsmf_PDUSession_CreateSMContext Request.
[0160] The session context establishment request includes UE identification information (eg, user permanent identifier (SUPI)) and a PDU session establishment request.
[0161] As an implementation method, if in the above step 304, the UE also carries the first parameter in the PDU session establishment request, the SMF can obtain the first parameter from the PDU session establishment request.
[0162] As another implementation method, if in step 304 above, the UE also carries the first parameter in the NAS message sent to the AMF, the session context establishment request may include the first parameter, that is, the session context establishment request includes the UE identification information, the PDU session establishment request, and the first parameter. Thus, the SMF can obtain the first parameter from the session context establishment request.
[0163] Step 306: The SMF determines to perform authentication and determines the AAA server according to the first parameter.
[0164] The authentication here can be secondary authentication or primary authentication, which is not limited in this application.
[0165] In one possible implementation, the SMF directly determines the AAA server based on the first parameter. For example, if the first parameter includes the first user identifier or domain name information in the first user identifier, the SMF may determine the AAA server corresponding to the domain name information based on the domain name information in the first user identifier. For another example, if the first parameter includes identification information of the AAA server, the SMF may determine the AAA server based on the identification information of the AAA server.
[0166] In another possible implementation, the SMF requests the UDM to obtain the identification information of the AAA server. The specific implementation process of the UDM storing the identification information of the AAA server can be referred to the description of the embodiment of FIG5 . Regarding the specific implementation of the SMF requesting the UDM to obtain the identification information of the AAA server, reference can be made to the relevant description of the embodiment of FIG5 .
[0167] Step 307: N4 session is established.
[0168] This step 307 is an optional step. When there is no existing N4 session that can be used to transmit messages between the SMF and the DN, the SMF selects the UPF and triggers the establishment of the N4 session.
[0169] Step 308: Authentication is performed between the UE and the AAA server.
[0170] Exemplarily, authentication is performed between the UE and the AAA server via the AMF, SMF, and UPF. Upon successful authentication, the AAA server sends a message indicating successful authentication to the SMF. For detailed information on the authentication process between the UE and the AAA server, please refer to the relevant description of the prior art and will not be repeated here.
[0171] In one possible implementation, to ensure security and privacy, the first parameter may not include the first user identifier or may include an incomplete first user identifier. Instead, during the authentication process, the UE provides the first user identifier to the AAA server. After successful authentication, the AAA server sends the first user identifier to the SMF. The SMF then obtains the corresponding QoS requirement information based on the first user identifier and completes the subsequent session establishment process based on the QoS requirement information to achieve QoS assurance.
[0172] Step 309: When the authentication is successful, SMF continues to complete the subsequent session establishment process.
[0173] In the above scheme, it is possible to establish a PDU session based on the granularity of the user identifier, thereby achieving differentiated QoS guarantees based on the granularity of the user identifier, thereby improving the precision and flexibility of the QoS guarantee. In addition, for the scenario where multiple AAA servers are deployed in the same DN, this scheme provides a first parameter to the SMF by the UE, so that the SMF determines the AAA server used to provide authentication for the UE from multiple AAA servers in the same DN based on the first parameter, thereby accurately determining the AAA server used for authentication. In addition, it is also possible to implement the sending of the first user identifier by the AAA server to the SMF after successful authentication, rather than the UE sending the first user identifier directly to the SMF, thereby improving the security and privacy of the user identifier.
[0174] FIG4 is a flow chart of a communication method provided by an embodiment of the present application. In this method, a first user identifier is assigned by an application, and the PCF determines identification information of an AAA server and sends the identification information of the AAA server to the SMF. The AAA server is the AAA server in the DN. The method includes the following steps:
[0175] Steps 401 to 405 are the same as steps 301 to 305 in the embodiment of FIG. 3 .
[0176] Step 406: The SMF sends a policy association establishment request to the PCF. Correspondingly, the PCF receives the policy association establishment request.
[0177] The policy association establishment request is used to request to obtain session-related policies.
[0178] Exemplarily, the policy association establishment request may be an SM Policy Association Establishment Request.
[0179] The policy association establishment request includes a second parameter, which is used to determine the AAA server and is obtained based on the first parameter.
[0180] The second parameter may include one or more of the following information 1) to 4):
[0181] 1) UE identification information.
[0182] 2) First user identification.
[0183] 3) Domain name information in the first user identifier.
[0184] 4) Application information corresponding to the first user identifier.
[0185] Step 407: The PCF determines the AAA server according to the second parameter.
[0186] In one possible implementation, the PCF directly determines the AAA server based on the second parameter. For example, if the second parameter includes the first user identifier or domain name information in the first user identifier, the PCF may determine the AAA server corresponding to the domain name information based on the domain name information in the first user identifier. For another example, if the second parameter includes identification information of the AAA server, the PCF may determine the AAA server based on the identification information of the AAA server.
[0187] In another possible implementation, the PCF requests the UDR to obtain the identification information of the AAA server. The specific implementation process of the UDR storing the identification information of the AAA server can be referenced to the description of the embodiments in FIG5 or FIG6 . For the specific implementation of the PCF requesting the UDR to obtain the identification information of the AAA server, reference can be referenced to the relevant description of the embodiments in FIG5 or FIG6 .
[0188] Step 408: PCF sends a policy association establishment response to SMF. Correspondingly, SMF receives the policy association establishment response.
[0189] If the PCF determines that authentication needs to be performed, the identification information of the AAA server is carried in the policy association establishment response. Optionally, the policy association establishment response further includes indication information, and the indication information is used to instruct the execution of authentication.
[0190] Step 409: N4 session is established.
[0191] This step 409 is an optional step. When there is no existing N4 session that can be used to transmit messages between the SMF and the DN, the SMF selects the UPF and triggers the establishment of the N4 session.
[0192] Step 410: Authentication is performed between the UE and the AAA server.
[0193] Wherein, if the above-mentioned policy association establishment response contains instruction information for instructing to perform authentication, the SMF determines that authentication needs to be performed based on the instruction information. If the above-mentioned policy association establishment response does not contain instruction information for instructing to perform authentication, the SMF determines that authentication needs to be performed based on the identification information of the AAA server.
[0194] Exemplarily, authentication is performed between the UE and the AAA server via the AMF, SMF, and UPF. Upon successful authentication, the AAA server sends a message indicating successful authentication to the SMF. For detailed information on the authentication process between the UE and the AAA server, please refer to the relevant description of the prior art and will not be repeated here.
[0195] In one possible implementation, to ensure security and privacy, the first parameter in step 404 may not include the first user identifier or may include an incomplete first user identifier. Instead, during the authentication process, the UE provides the first user identifier to the AAA server. After successful authentication, the AAA server sends the first user identifier to the SMF. The SMF then obtains corresponding QoS requirement information based on the first user identifier and completes the subsequent session establishment process based on the QoS requirement information to achieve QoS assurance.
[0196] Step 411: When the authentication is successful, SMF continues to complete the subsequent session establishment process.
[0197] In the above scheme, it is possible to establish a PDU session based on the granularity of the user identifier, thereby achieving differentiated QoS guarantees based on the granularity of the user identifier, thereby improving the precision and flexibility of the QoS guarantee. In addition, for the scenario where multiple AAA servers are deployed in the same DN, the scheme is that the UE provides a first parameter to the SMF, and then the SMF provides a second parameter to the PCF, so that the PCF determines the AAA server used to provide authentication for the UE from multiple AAA servers in the same DN based on the second parameter, thereby achieving accurate determination of the AAA server used for authentication. In addition, it is also possible to implement that after successful authentication, the AAA server sends the first user identifier to the SMF, rather than the UE sending the first user identifier directly to the SMF, thereby improving the security and privacy of the user identifier.
[0198] FIG5 is a flow chart of a communication method provided in an embodiment of the present application, which can implement storing the identification information of the AAA server in the UDM and / or UDR. The method includes the following steps:
[0199] Step 501: The AF sends a request message to the NEF, and the NEF receives the request message accordingly.
[0200] Exemplarily, the request message may be a parameter provision establishment request (eg, Nnef_ParameterProvision_Create Request), or may be a parameter provision update request (eg, Nnef_ParameterProvision_Update Request).
[0201] The request message includes one or more of the following: identification information of the application function (e.g., AF ID or AF address), a first user identifier, user configuration information, service configuration information, identification information of the AAA server (e.g., AAA server ID or AAA server address), or identification information of the UE (e.g., SUPI). The user configuration information includes the first user identifier and identification information of the AAA server, and optionally also includes QoS requirements. The service configuration information includes identification information of the AAA server, as well as identification information of the application function and / or identification information of the application function service.
[0202] Step 502: NEF sends a request message to UDM. Correspondingly, UDM receives the request message.
[0203] Exemplarily, the request message may be a parameter provision establishment request (eg, Nudm_ParameterProvision_Create Request), or may be a parameter provision update request (eg, Nudm_ParameterProvision_Update Request).
[0204] The request message includes one or more of identification information of the application function, the first user identification, user configuration information, service configuration information, identification information of the AAA server, or identification information of the UE.
[0205] As a first implementation method, the UDM determines the contract data corresponding to the identification information of the UE, and determines the user configuration information in the contract data. Based on this first implementation method, in step 306 of the embodiment of Figure 3, the SMF determines the AAA server according to the first parameter. For example, it can be: the SMF sends a query request to the UDM, and the query request includes the identification information of the UE and the first user identifier. The UDM determines the contract data corresponding to the identification information of the UE according to the identification information of the UE, and then the UDM determines the user configuration information corresponding to the first user identifier from the contract data according to the first user identifier, and sends the identification information of the AAA server contained in the user configuration information to the SMF. Alternatively, the SMF sends a query request to the UDM, and the query request includes the identification information of the UE. The UDM determines the contract data corresponding to the identification information of the UE according to the identification information of the UE, and sends the contract data to the SMF. The SMF determines the user configuration information corresponding to the first user identifier from the contract data according to the first user identifier, and determines the identification information of the AAA server contained in the user configuration information.
[0206] As a second implementation method, the UDM determines the user configuration information corresponding to the user identifier based on the user identifier. Based on this second implementation method, in step 306 of the embodiment of Figure 3, the SMF determines the AAA server based on the first parameter. For example, it can be: the SMF sends a query request to the UDM, the query request includes the first user identifier, the UDM determines the user configuration information corresponding to the first user identifier based on the first user identifier, and sends the identification information of the AAA server contained in the user configuration information to the SMF. Alternatively, the SMF sends a query request to the UDM, the query request includes the first user identifier, the UDM determines the user configuration information corresponding to the first user identifier based on the first user identifier, and then the UDM sends the user configuration information to the SMF, and the SMF determines the identification information of the AAA server contained in the user configuration information.
[0207] As a third implementation method, the UDM determines the service configuration information based on the service identification information. Based on this third implementation method, in step 306 of the embodiment of Figure 3, the SMF determines the AAA server based on the first parameter. For example, it can be: the SMF sends a query request to the UDM, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDM determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service based on the identification information of the application function and / or the identification information of the application function service, and sends the identification information of the AAA server contained in the service configuration information to the SMF. Alternatively, the SMF sends a query request to the UDM, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDM determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service based on the identification information of the application function and / or the identification information of the application function service. Then, the UDM sends the service configuration information to the SMF, and the SMF determines the identification information of the AAA server contained in the service configuration information.
[0208] As a fourth implementation method, the UDM stores association information between the identification information of the AAA server and the index information. The index information includes one or more of the following information: identification information of the application function, the first user identification, or the identification information of the UE. Based on this fourth implementation method, in step 306 of the embodiment of FIG3 , the SMF determines the AAA server based on the first parameter. For example, the SMF sends a query request to the UDM, the query request includes the index information, and the UDM determines the identification information of the AAA server corresponding to the index information based on the index information and sends the identification information of the AAA server to the SMF.
[0209] In step 503, the UDM stores part of the information in the UDR.
[0210] This step 503 is an optional step.
[0211] As a first implementation method, UDM stores user configuration information in UDR.
[0212] Based on the first implementation method, in step 306 of the embodiment of Figure 3, the SMF determines the AAA server based on the first parameter. For example, the following may be: the SMF sends a query request to the UDM, the query request including the first user identifier, the UDM sends a query request to the UDR, the query request including the first user identifier, the UDR obtains the user configuration information corresponding to the first user identifier based on the first user identifier, sends the identification information of the AAA server included in the user configuration information to the UDM, and the UDM then sends the identification information of the AAA server to the SMF. Alternatively, the SMF sends a query request to the UDM, the query request including the first user identifier, the UDM sends a query request to the UDR, the query request including the first user identifier, the UDR determines the user configuration information corresponding to the first user identifier based on the first user identifier, the UDR then sends the user configuration information to the UDM, the UDM then sends the user configuration information to the SMF, and the SMF determines the identification information of the AAA server included in the user configuration information.
[0213] Based on the first implementation method, in step 407 of the embodiment of Figure 4, the PCF determines the AAA server based on the second parameter. For example, it can be: the PCF sends a query request to the UDR, the query request includes the UE's identification information and the first user identifier, the UDR determines the contract data corresponding to the UE's identification information based on the UE's identification information, and then the UDR determines the user configuration information corresponding to the first user identifier in the contract data based on the first user identifier, and sends the identification information of the AAA server contained in the user configuration information to the PCF. Alternatively, the PCF sends a query request to the UDR, the query request includes the UE's identification information, the UDR obtains the contract data corresponding to the UE's identification information based on the UE's identification information, and then the UDR sends the contract data to the PCF, the PCF determines the user configuration information corresponding to the first user identifier in the contract data based on the first user identifier, and determines the identification information of the AAA server contained in the user configuration information.
[0214] As the second implementation method, UDM stores the service configuration information in UDR.
[0215] Based on the second implementation method, in step 306 of the embodiment of Figure 3, the SMF determines the AAA server according to the first parameter. For example, it can be: SMF sends a query request to UDM, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDM sends a query request to UDR, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDR determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service based on the identification information of the application function and / or the identification information of the application function service, and sends the identification information of the AAA server contained in the service configuration information to the UDM, and the UDM then sends the identification information of the AAA server to the SMF. Alternatively, the SMF sends a query request to the UDM, which includes the identification information of the application function and / or the identification information of the application function service. The UDM sends a query request to the UDR, which includes the identification information of the application function and / or the identification information of the application function service. The UDR determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service based on the identification information of the application function and / or the identification information of the application function service. Then the UDR sends the service configuration information to the UDM, the UDM sends the service configuration information to the SMF, and the SMF determines the identification information of the AAA server contained in the service configuration information.
[0216] Based on the second implementation method, in step 407 of the embodiment of FIG4 , the PCF determines the AAA server based on the second parameter. For example, the PCF sends a query request to the UDR, the query request including the identification information of the application function and / or the identification information of the application function service, the UDR determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service based on the identification information of the application function and / or the identification information of the application function service, and sends the identification information of the AAA server contained in the service configuration information to the PCF. Alternatively, the PCF sends a query request to the UDR, the query request including the identification information of the application function and / or the identification information of the application function service, the UDR determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service based on the identification information of the application function and / or the identification information of the application function service, and then the UDR sends the service configuration information to the PCF, and the PCF determines the identification information of the AAA server contained in the service configuration information.
[0217] As a third implementation method, the UDM stores the association information between the identification information of the AAA server and the index information in the UDR, wherein the index information includes one or more of the following information: identification information of the application function, the first user identification, or identification information of the UE.
[0218] Based on the third implementation method, in step 306 of the embodiment of Figure 3, the SMF determines the AAA server according to the first parameter. For example, it can be: SMF sends a query request to UDM, and the query request includes index information. The UDM sends a query request to UDR, and the query request includes index information. The UDR determines the identification information of the AAA server corresponding to the index information based on the index information and sends the identification information of the AAA server to the UDM. The UDM then sends the identification information of the AAA server to the SMF.
[0219] Based on the third implementation method, in step 407 of the embodiment of Figure 4, the PCF determines the AAA server according to the second parameter. For example, it can be: the PCF sends a query request to the UDR, the query request includes index information, and the UDR determines the identification information of the AAA server corresponding to the index information from the UDR according to the index information and sends the identification information of the AAA server to the PCF.
[0220] Step 504: UDM sends a response message to NEF, and NEF receives the response message accordingly.
[0221] The response message may be a parameter provision establishment response (eg, Nudm_ParameterProvision_CreateResponse), or a parameter provision update response (eg, Nudm_ParameterProvision_Update Response).
[0222] Step 505: The NEF sends a response message to the AF, and the AF receives the response message accordingly.
[0223] Exemplarily, the response message may be a parameter provision establishment response (eg, Nnef_ParameterProvision_Create Response), or may be a parameter provision update response (eg, Nnef_ParameterProvision_Update Response).
[0224] The above solution can realize the storage of the identification information of the AAA server in the UDM and / or UDR, so that the SMF can request the UDM to determine the identification information of the AAA server, and / or the PCF can request the UDR to determine the identification information of the AAA server.
[0225] FIG6 is a flow chart of a communication method provided in an embodiment of the present application, which can implement storing the identification information of the AAA server in the UDR. The method includes the following steps:
[0226] Step 601: The AF sends a request message to the NEF, and the NEF receives the request message accordingly.
[0227] Exemplarily, the request message may be a service parameter creation request (eg, Nnef_ServiceParameter_Create Request), or may be a service parameter update request (eg, Nnef_ServiceParameter_Update Request).
[0228] The request message includes service description information and service parameters corresponding to the service description information.
[0229] Among them, the service description information is used to indicate the service, for example, the service description information includes at least one of the following information: identification information of the application (such as APP ID or APP address), identification information of the application server (such as APP server ID or APP server address), identification information of the application function service (such as AF service ID) or identification information of the application function (such as AF ID or AF address).
[0230] The service parameters are used to indicate parameter information corresponding to the service. For example, the service parameters include identification information of the AAA server. Optional service parameters also include at least one of the first user identification, domain name information, or identification information of the UE.
[0231] Step 602: The NEF stores the service description information and the service parameters corresponding to the service description information in the UDR.
[0232] Exemplarily, in step 407 of the embodiment of Figure 4, the PCF determines the AAA server based on the second parameter. For example, it can be: the PCF sends a query request to the UDR, and the query request includes at least one of the UE's identification information, the first user identification, the domain name information, the application's identification information, the application server's identification information, the application function service's identification information, or the application function's identification information. The UDR determines the AAA server's identification information in the service parameters based on the query request, and sends the AAA server's identification information to the PCF.
[0233] Step 603: The NEF sends a response message to the AF, and the AF receives the response message accordingly.
[0234] Exemplarily, the response message may be a service parameter creation response (eg, Nnef_ServiceParameter_Create Response), or a service parameter update response (eg, Nnef_ServiceParameter_Update Response).
[0235] The above solution can store the identification information of the AAA server in the UDR, so that the PCF can request the UDR to determine the identification information of the AAA server.
[0236] Figure 7 is a flow chart of a communication method provided by an embodiment of the present application. In this method, the first user identifier is assigned by the operator, and the SMF determines the identification information of the AAA server based on local configuration. The AAA server is not the AAA server in the DN, but an AAA server deployed by the operator. The AAA server is not related to the application service. The method includes the following steps:
[0237] Steps 701 to 705 are the same as steps 301 to 305 in the embodiment of FIG. 3 .
[0238] Step 706: The SMF determines that the PDU session requested by the UE is a session established for the user identity managed by the operator and determines to perform authentication, and then determines the identification information of the AAA server according to the first parameter.
[0239] The SMF is preconfigured with a correspondence between the first parameter and the identification information of the AAA server. Therefore, after obtaining the first parameter, the SMF can determine the identification information of the corresponding AAA server based on the first parameter. The AAA server here can refer to the AAA server deployed by the operator. For example, the SMF can determine that the AAA server needs to perform authentication based on the user identity included in the session establishment request, and select the corresponding AAA server to perform the authentication process.
[0240] Step 707: N4 session is established.
[0241] This step 709 is an optional step. When there is no existing N4 session that can be used to transmit messages between the SMF and the DN, the SMF selects the UPF and triggers the establishment of the N4 session.
[0242] Step 708: Authentication is performed between the UE and the AAA server.
[0243] Exemplarily, authentication is performed between the UE and the AAA server via the AMF, SMF, and UPF. Upon successful authentication, the AAA server sends a message indicating successful authentication to the SMF. For detailed information on the authentication process between the UE and the AAA server, please refer to the relevant description of the prior art and will not be repeated here.
[0244] In one possible implementation, to ensure security and privacy, the first parameter may not include the first user identifier or may include an incomplete first user identifier. Instead, during the authentication process, the UE provides the first user identifier to the AAA server. After successful authentication, the AAA server sends the first user identifier to the SMF. The SMF then obtains the corresponding QoS requirement information based on the first user identifier and completes the subsequent session establishment process based on the QoS requirement information to achieve QoS assurance.
[0245] Step 709: When the authentication is successful, SMF continues to complete the subsequent session establishment process.
[0246] In the above solution, it is possible to establish a PDU session based on the granularity of the user identifier, thereby achieving differentiated QoS guarantees based on the granularity of the user identifier, thereby improving the precision and flexibility of the QoS guarantee. In addition, for scenarios where operators deploy multiple AAA servers, this solution requires the UE to provide a first parameter to the SMF, and then the SMF determines the AAA server used to provide authentication for the UE based on the pre-configured information and the first parameter, thereby accurately determining the AAA server used for authentication. In addition, it is also possible to have the AAA server send the first user identifier to the SMF after successful authentication, rather than the UE sending the first user identifier directly to the SMF, thereby improving the security and privacy of the user identifier.
[0247] It is understood that, in order to implement the functions in the above embodiments, the terminal device or the first network element includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in combination with the units and method steps of the various examples described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0248] Figures 8 and 9 are schematic diagrams of the structures of communication devices provided in embodiments of the present application. These communication devices can be used to implement the functions of the terminal device or the first network element in the above-mentioned method embodiments, thereby also achieving the beneficial effects of the above-mentioned method embodiments. In the embodiments of the present application, the communication device can be a terminal device or a first network element, or a module (such as a chip) applied to the terminal device or the first network element.
[0249] The communication device 800 shown in Figure 8 includes a processing unit 810 and a transceiver unit 820. The communication device 800 is used to implement the functions of the terminal device or the first network element in the above method embodiment.
[0250] When the communication device 800 is used to implement the functions of the terminal device in the above method embodiment, the processing unit 810 is used to obtain a first user identifier, which represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account used to access an application on the terminal device; determines that a new user plane connection needs to be created based on the first user identifier; and the transceiver unit 820 is used to send a connection establishment request, which is used to request to establish a user plane connection based on the first user identifier.
[0251] In one possible implementation method, the processing unit 810 is used to determine whether a new user plane connection needs to be established based on the first user identifier, specifically including: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including a second user identifier, the second user identifier in the service flow information matches the first user identifier, and the routing information includes the second user identifier; judging whether a user plane connection matching the second user identifier has been established based on the second user identifier in the routing information; if a user plane connection matching the second user identifier has not been established, determining that a new user plane connection needs to be established based on the first user identifier.
[0252] In one possible implementation method, the processing unit 810 is further used to determine whether a new user plane connection needs to be established based on the first user identifier, specifically including: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including a second user identifier, the second user identifier in the service flow information matches the first user identifier, and the routing information includes the second user identifier; judging whether a user plane connection matching the second user identifier has been established based on the second user identifier in the routing information; if the established user plane connection includes a user plane connection matching the second user identifier, using the user plane connection matching the second user identifier to transmit data corresponding to the first user identifier.
[0253] In a possible implementation method, the routing information further includes at least one of the following information: domain name information in the first user identifier, domain name information in the second user identifier, or application information corresponding to the first user identifier.
[0254] In one possible implementation method, the processing unit 810 is used to determine whether a new user plane connection needs to be established based on the first user identifier, specifically including: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including first domain name information, the first domain name information in the service flow information matches the second domain name information in the first user identifier, the routing information including indication information, and the indication information indicating that different user plane connections are established for user identifiers that do not match each other; judging whether a user plane connection matching the first user identifier has been established based on the indication information in the routing information; if a user plane connection matching the first user identifier has not been established, determining that a new user plane connection needs to be established based on the first user identifier.
[0255] In one possible implementation method, the processing unit 810 is further used to determine policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including first domain name information, the first domain name information in the service flow information matches the second domain name information in the first user identifier, and the routing information includes indication information, the indication information indicating that different user plane connections are established for user identifiers that do not match each other; based on the indication information in the routing information, it is determined whether a user plane connection matching the first user identifier has been established; if the established user plane connection includes a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit data corresponding to the first user identifier.
[0256] In a possible implementation method, the routing information further includes at least one of the following information: the first domain name information, the second domain name information, or application information corresponding to the first user identifier.
[0257] In one possible implementation method, the processing unit 810 is used to determine whether a new user plane connection needs to be established based on the first user identifier, specifically including: determining the policy information corresponding to the first user identifier, the policy information including an instruction to establish different user plane connections for user identifiers that do not match each other; judging whether a user plane connection matching the first user identifier has been established based on the policy information; if a user plane connection matching the first user identifier has not been established, determining that a new user plane connection needs to be established based on the first user identifier.
[0258] In one possible implementation method, the processing unit 810 is further used to determine policy information corresponding to the first user identifier, where the policy information indicates that different user plane connections are established for mutually mismatched user identifiers; based on the indication information in the routing information, determine whether a user plane connection matching the first user identifier has been established; if the established user plane connection includes a user plane connection matching the first user identifier, then use the user plane connection matching the first user identifier to transmit data corresponding to the first user identifier.
[0259] In a possible implementation method, the policy information includes service flow information and routing information, the service flow information includes first information, the first information matches any user identifier, and the routing information includes the indication information.
[0260] In one possible implementation method, the routing selection information also includes at least one of second information, third information or fourth information, the second information indicates that the first user identifier is sent to the network, the third information indicates that the domain name information in the first user identifier is sent to the network, and the fourth information indicates that application information corresponding to the first user identifier is sent to the network.
[0261] In a possible implementation method, the connection establishment request further includes a first parameter, where the first parameter is used to determine an authentication server, and the authentication server is used to perform authentication on the first user identifier.
[0262] In a possible implementation method, the connection establishment request is carried in a NAS message, and the NAS message further includes a first parameter, where the first parameter is used to determine an authentication server, and the authentication server is used to authenticate the first user identifier.
[0263] In a possible implementation method, the first parameter includes one or more of the following information: the first user identifier, domain name information in the first user identifier, identification information of the authentication server, or application information corresponding to the first user identifier.
[0264] In one possible implementation method, the application information includes one or more of the following information: identification information of the application, identification information of the application server, identification information of the application function service, identification information of the application function, identification information of the authentication server, or the domain name corresponding to the application.
[0265] In a possible implementation method, the processing unit 810 is configured to obtain the first user identifier, specifically including: obtaining the first user identifier from an application on the terminal device; or obtaining the first user identifier from the first device.
[0266] When the communication device 800 is used to implement the function of the first network element in the above-mentioned method embodiment, the transceiver unit 820 is used to receive a first parameter from the terminal device, and the first parameter includes one or more of the following information: a first user identifier, domain name information in the first user identifier, or application information corresponding to the first user identifier; wherein the first user identifier represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account used to access an application on the terminal device; the processing unit 810 is used to determine an authentication server based on the first parameter, and the authentication server is used to perform authentication on the first user identifier.
[0267] In one possible implementation method, the processing unit 810 is used to determine the authentication server based on the first parameter, specifically including: sending a first request to a unified data management network element or a unified database network element through the transceiver unit 820, wherein the first request includes the first parameter; and receiving a first response from the unified data management network element or the unified database network element, wherein the first response includes the identification information of the authentication server.
[0268] In one possible implementation method, the processing unit 810 is used to determine the authentication server based on the first parameter, specifically including: determining the identification information of the authentication server corresponding to the first parameter based on pre-configuration information, and the pre-configuration information includes the correspondence between the first parameter and the identification information of the authentication server.
[0269] In a possible implementation method, the first network element is a policy control network element; the transceiver unit 820 is further configured to send identification information of the authentication server to the session management network element.
[0270] In a possible implementation method, the transceiver unit 820 is further configured to send indication information to the session management network element, where the indication information instructs execution of authentication.
[0271] In a possible implementation method, the transceiver unit 820 is further configured to receive the first user identifier from the authentication server after successful authentication.
[0272] A more detailed description of the processing unit 810 and the transceiver unit 820 can be directly obtained by referring to the relevant description in the above method embodiment, and will not be repeated here.
[0273] The communication device 900 shown in Figure 9 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It is understood that the interface circuit 920 can be a transceiver or an input / output interface. Optionally, the communication device 900 may also include a memory 930 for storing instructions executed by the processor 910, or storing input data required by the processor 910 to execute instructions, or storing data generated after the processor 910 executes instructions.
[0274] When the communication device 900 is used to implement the above method embodiment, the processor 910 is used to implement the functions of the above processing unit 810 , and the interface circuit 920 is used to implement the functions of the above transceiver unit 820 .
[0275] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0276] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk, mobile hard disk, CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in an access network device or a terminal device. Of course, the processor and storage medium can also exist in the access network device or the terminal device as discrete components.
[0277] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, an access network device, a terminal device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
[0278] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0279] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next related objects are in an "or" relationship; in the formulas of this application, the character " / " indicates that the previous and next related objects are in a "division" relationship.
[0280] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.
Claims
1. A communication method, characterized in that: Applied to a terminal device or a module of a terminal device, the method includes: Obtaining a first user identifier, where the first user identifier represents a user using a terminal device, or represents a first device connected to the terminal device, or represents a user account used to access an application on the terminal device; If it is determined that a new user plane connection needs to be established based on the first user identifier, a connection establishment request is sent, where the connection establishment request is used to request establishment of a user plane connection based on the first user identifier.
2. The method according to claim 1, wherein The determining that a new user plane connection needs to be established based on the first user identifier includes: Determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including a second user identifier, the second user identifier in the service flow information matching the first user identifier, and the routing information including the second user identifier; determining, according to the second user identifier in the routing information, whether a user plane connection matching the second user identifier has been established; If a user plane connection matching the second user identifier is not established, it is determined that a new user plane connection needs to be created based on the first user identifier.
3. The method according to claim 1, wherein The method further comprises: Determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including a second user identifier, the second user identifier in the service flow information matching the first user identifier, and the routing information including the second user identifier; determining, according to the second user identifier in the routing information, whether a user plane connection matching the second user identifier has been established; If the established user plane connections include a user plane connection matching the second user identifier, the user plane connection matching the second user identifier is used to transmit data corresponding to the first user identifier.
4. The method according to claim 3, wherein The routing information further includes at least one of the following information: domain name information in the first user identifier, domain name information in the second user identifier, or application information corresponding to the first user identifier.
5. The method according to claim 1, wherein The determining that a new user plane connection needs to be established based on the first user identifier includes: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including first domain name information, the first domain name information in the service flow information matching second domain name information in the first user identifier, and the routing information including indication information indicating that different user plane connections be established for mutually mismatched user identifiers; determining, according to the indication information in the routing information, whether a user plane connection matching the first user identifier has been established; If a user plane connection matching the first user identifier is not established, it is determined that a new user plane connection needs to be created based on the first user identifier.
6. The method according to claim 1, wherein The method further comprises: determining policy information corresponding to the first user identifier, the policy information including service flow information and routing information, the service flow information including first domain name information, the first domain name information in the service flow information matching second domain name information in the first user identifier, and the routing information including indication information indicating that different user plane connections be established for mutually mismatched user identifiers; determining, according to the indication information in the routing information, whether a user plane connection matching the first user identifier has been established; If the established user plane connections include a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit data corresponding to the first user identifier.
7. The method according to claim 5 or 6, wherein: The routing information further includes at least one of the following information: the first domain name information, the second domain name information, or application information corresponding to the first user identifier.
8. The method according to claim 1, wherein The determining that a new user plane connection needs to be established based on the first user identifier includes: determining policy information corresponding to the first user identifier, the policy information including an instruction to establish different user plane connections for mutually mismatched user identifiers; determining, according to the policy information, whether a user plane connection matching the first user identifier has been established; If a user plane connection matching the first user identifier is not established, it is determined that a new user plane connection needs to be created based on the first user identifier.
9. The method according to claim 1, wherein The method further comprises: determining policy information corresponding to the first user identifier, the policy information indicating establishing different user plane connections for mutually mismatched user identifiers; determining, according to the indication information in the routing information, whether a user plane connection matching the first user identifier has been established; If the established user plane connections include a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit data corresponding to the first user identifier.
10. The method according to claim 8 or 9, characterized in that The policy information includes service flow information and routing information. The service flow information includes first information, and the first information matches any user identifier. The routing information includes the indication information.
11. The method according to claim 10, wherein The routing information also includes at least one of second information, third information or fourth information, the second information indicates that the first user identifier is sent to the network, the third information indicates that the domain name information in the first user identifier is sent to the network, and the fourth information indicates that application information corresponding to the first user identifier is sent to the network.
12. The method according to any one of claims 1 to 11, characterized in that The connection establishment request further includes a first parameter, where the first parameter is used to determine an authentication server, and the authentication server is used to perform authentication on the first user identifier.
13. The method according to any one of claims 1 to 11, characterized in that The connection establishment request is carried in a non-access stratum (NAS) message. The NAS message further includes a first parameter, where the first parameter is used to determine an authentication server. The authentication server is used to authenticate the first user identifier.
14. The method according to claim 12 or 13, wherein: The first parameter includes one or more of the following information: the first user identifier, domain name information in the first user identifier, identification information of the authentication server, or application information corresponding to the first user identifier.
15. The method according to claim 4, 7, 11 or 14, wherein: The application information includes one or more of the following information: The identification information of the application, the identification information of the application server, the identification information of the application function service, the identification information of the application function, the identification information of the authentication server or the domain name corresponding to the application.
16. The method according to any one of claims 1 to 15, characterized in that The obtaining of the first user identifier includes: Acquire the first user identifier from an application on the terminal device; or The first user identifier is obtained from the first device.
17. A communication method, characterized in that: Applied to a first network element or a module of the first network element, the method includes: receiving a first parameter from a terminal device, the first parameter including one or more of the following information: a first user identifier, domain name information in the first user identifier, or application information corresponding to the first user identifier; wherein the first user identifier represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account used to access an application on the terminal device; An authentication server is determined according to the first parameter, and the authentication server is used to perform authentication on the first user identifier.
18. The method according to claim 17, wherein The determining the authentication server according to the first parameter includes: Sending a first request to a unified data management network element or a unified database network element, where the first request includes the first parameter; A first response is received from the unified data management network element or the unified database network element, where the first response includes identification information of the authentication server.
19. The method according to claim 17, wherein The determining the authentication server according to the first parameter includes: The identification information of the authentication server corresponding to the first parameter is determined according to pre-configuration information, wherein the pre-configuration information includes a correspondence between the first parameter and the identification information of the authentication server.
20. The method according to any one of claims 17 to 19, characterized in that The first network element is a policy control network element; the method further includes: Sending identification information of the authentication server to the session management network element.
21. The method according to claim 20, wherein The method further comprises: Sending instruction information to the session management network element, wherein the instruction information instructs to perform authentication.
22. The method according to any one of claims 17 to 21, characterized in that The method further comprises: After successful authentication, the first user identifier is received from the authentication server.
23. A communication device, characterized in that: The method comprises a module for executing the method according to any one of claims 1 to 16, or executing the method according to any one of claims 17 to 22.
24. A communication device, characterized in that: The device comprises a processor and an interface circuit, wherein the processor is configured to communicate with other devices via the interface circuit and execute the method according to any one of claims 1 to 16, or execute the method according to any one of claims 17 to 22.
25. A computer program product, characterized in that The computer program product comprises instructions, which, when executed on a processor, cause the processor to execute the method according to any one of claims 1 to 16 or the method according to any one of claims 17 to 22.
26. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by the communication device, the method described in any one of claims 1 to 16 or the method described in any one of claims 17 to 22 is implemented.
Citation Information
Patent Citations
Bearer establishment method and device, electronic equipment and storage medium
CN114286450A
Network function creation method and communication device
CN116419238A
User plane IP address allocation method and system, and user plane convergence network element
CN116866308A
Communication method and communication apparatus
WO2022183497A1
Method and apparatus for establishing user plane connection
WO2022205244A1