Communication method and apparatus
Through the interaction between user plane network elements and session management network elements, a secure channel is directly established by bypassing the NAS layer, solving the problem of high cost of establishing user plane connections by non-3GPP access, and achieving a lower-cost access method.
Patent Information
- Application Number
- PCT/CN2024/138147
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-07
- Filing Date
- 2024-12-10
- Publication Date
- 2025-08-14
AI Technical Summary
In the prior art, the cost of establishing user-plane connections for non-3GPP access is high, and N3G access gateways are required to be deployed and terminals need to support NAS message transmission, resulting in an increase in the deployment cost of network and terminal devices.
Through the user-plane network element interacting with the session management network element, a secure channel is directly established by bypassing the NAS layer. After the user-plane network element obtains terminal information, select the session of the session management network element or session management network element, and pass the authentication authentication information to trigger the terminal's authentication authentication, and establish a secure channel only after the authentication is passed.
It realizes the establishment of non-3GPP access user plane connections at lower cost, avoids the deployment of N3G access gateways and terminal support for NAS messages, and reduces the deployment cost of network and terminal devices.
Smart Images

Figure CN2024138147_14082025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on February 7, 2024, with application number 202410175792.X and application name “Communication Method and Device,” the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and in particular to a communication method and device. Background Art
[0003] Currently, the core network (CN) of fifth-generation (5G) mobile communications, also known as 5GC, supports non-3GPP (non-3GPP) access, referred to as N3G access, such as untrusted non-3GPP access and trusted non-3GPP access. Specifically, untrusted non-3GPP access includes untrusted wireless local area network (WLAN) access, trusted non-3GPP access includes trusted WLAN access, and wired network access includes fixed home network access. Regardless of the type of non-3GPP access, the network needs to deploy an N3G access gateway for non-3GPP access, such as the non-3GPP interworking function (N3IWF). This allows user equipment (UE) to access the network through the N3G access gateway, which then establishes the UE's user plane connection.
[0004] However, establishing user-plane connections via the N3G access gateway is relatively costly. This means the network must deploy an N3G access gateway, and the UE must support the transmission of non-access-stratum (NAS) messages over N3G. Therefore, establishing user-plane connections for non-3GPP access at a lower cost is an urgent issue. Summary of the Invention
[0005] The embodiments of the present application provide a communication method and apparatus for establishing a user plane connection for non-3GPP access at a lower cost.
[0006] To achieve the above objectives, this application adopts the following technical solutions:
[0007] In a first aspect, a communication method is provided, the method comprising: a user plane network element serving a first terminal receives information of the first terminal from the first terminal; the user plane network element determines a session management network element serving the first terminal based on the information of the first terminal, or / and determines a session between the user plane network element and the session management network element; the user plane network element sends authentication information or first information of the first terminal to the session management network element, or the user plane network element transmits the authentication information or first information of the first terminal through a session; the session management network element receives the authentication information or first information of the first terminal from the user plane network element, or the session management network element receives the authentication information or first information of the first terminal transmitted by the session; the session management network element triggers authentication of the first terminal based on the authentication information or first information of the first terminal; and if the authentication of the first terminal passes, the user plane network element establishes a secure channel with the first terminal. The user plane network element described herein may also be a security gateway function, or a security gateway function deployed integrally with the user plane network element, or an access network element function, or an access gateway function deployed integrally with the user plane network element, which is not limited herein.
[0008] It can be seen from this that after the user plane network element obtains the information of the first terminal, it can select a session management network element or select the session corresponding to the session management network element, and the user plane network element and the session management network element can transmit the authentication information or the first information of the first terminal in the authentication and authorization. If the authentication and authorization of the first terminal is passed, the user plane network element establishes a secure channel with the first terminal, that is, bypassing the N3G access gateway and directly establishing a user plane connection. In this way, the network does not need to deploy an N3G access gateway, and the terminal does not need to support the transmission of non-access layer NAS messages in N3G, thereby achieving user plane connection establishment for non-3GPP access at a lower cost.
[0009] It can also be seen that, unlike the prior art in which the authentication and certification of the first terminal is triggered through the NAS layer (such as the access and mobility management network element), the embodiment of the present application can trigger the authentication and certification of the first terminal by the user plane network element instructing the session management network element, which bypasses the NAS layer, or does not transmit NAS messages, so that the terminal does not support the transmission of non-access layer NAS messages in N3G, thereby achieving user plane connection establishment for non-3GPP access at a lower cost.
[0010] In a possible design, the information of the first terminal includes at least one of address information of the first terminal, temporary identification information of the first terminal, permanent identification information of the first terminal, and service information of the first terminal.
[0011] Among them, the address information of the first terminal may be the IP address of the first terminal, and the IP address may be the IP address of the terminal side obtained by the first terminal in the protocol data unit PDU session established by the first terminal on the 3GPP side. The temporary identification information of the first terminal may be the 5G global unique temporary UE identifier GUTI obtained by the first terminal from the 3GPP side. The permanent identification information of the first terminal may be the user permanent identifier SUPI or the user hidden identifier SUCI of the first terminal. The service information of the first terminal may be at least one of the data network name DNN or slice information.
[0012] Furthermore, the first information is first indication information, which is used to instruct the session management network element to initiate authentication and certification of the first terminal. That is, the first indication information can be a new information element, which is used to explicitly instruct the session management network element to initiate authentication and certification of the first terminal, thereby achieving decoupling from existing information elements and providing a more flexible indication method. Alternatively, the first information is permanent identification information of the first terminal or temporary identification information of the first terminal, which is used to implicitly indicate the triggering of authentication and certification of the first terminal, that is, to reuse existing information elements to reduce indication overhead.
[0013] Furthermore, the session management network element triggers authentication of the first terminal according to the first information, including: the session management network element sends the identification information of the first terminal to the authentication network element serving the first terminal; or the session management gateway generates an EAP message (such as EAP Response / identity or EAP The session management network element sends the EAP message to the authentication network element; the authentication network element receives the identification information of the first terminal from the session management network element, or the authentication network element receives the EAP message from the session management network element and obtains the identification information of the first terminal from the EAP message; the authentication network element obtains the authentication vector of the first terminal from the data management network element serving the first terminal based on the identification information of the first terminal; the authentication network element authenticates the first terminal based on the authentication vector; when the authentication network element successfully authenticates the first terminal, the authentication network element sends at least one of authentication success information and a security key to the session management network element; the session management network element receives at least one of the authentication success information and the security key from the session management network element; and the session management network element sends at least one of the authentication success information and the security key to the user plane network element.
[0014] Alternatively, the session management network element triggers authentication of the first terminal according to the first information, including: the session management network element sends the identification information of the first terminal to the data management network element serving the first terminal, or the session management gateway generates an EAP message, the above EAP message includes the identification information of the first terminal, the session management network element sends the EAP message to the data management network element; the data management network element receives the identification information of the first terminal from the session management network element; the data management network element receives the EAP message from the session management network element and obtains the identification information of the first terminal from the EAP message; the data management network element generates the authentication of the first terminal according to the first terminal The authentication network element receives the authentication vector of the first terminal from the data management network element; the authentication network element authenticates the first terminal according to the authentication vector; when the authentication network element successfully authenticates the first terminal, the authentication network element sends at least one of authentication success information and a security key to the session management network element; the session management network element receives at least one of authentication success information and a security key from the session management network element; and the session management network element sends at least one of authentication success information and a security key to the user plane network element.
[0015] It can be seen that the session management network element can trigger the authentication of the first terminal by interacting with the authentication network element, or it can trigger the authentication of the first terminal by directly interacting with the data management network element. The specific implementation method is not restricted and can be flexibly selected according to actual conditions.
[0016] Furthermore, the method described in the first aspect may further include: the user plane network element receiving at least one of authentication success information and a security key from the session management network element; and the user plane network element determining, based on at least one of the authentication success information and the security key, that the first terminal's authentication is successful. On this basis, the user plane network element establishing a secure channel with the first terminal includes: the user plane network element using the security key to establish the secure channel between the user plane network element and the first terminal. In other words, the user plane network element may only establish the secure channel with the first terminal if it determines that the first terminal's authentication is successful, thereby avoiding the security risks associated with establishing the secure channel if the first terminal's authentication fails.
[0017] In one possible design scheme, the user plane network element determines the session management network element serving the first terminal based on the information of the first terminal, including: the user plane network element obtains the service information of the first terminal; the user plane network element selects the session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
[0018] In one possible design scheme, the user plane network element determines the session management network element serving the first terminal based on the information of the first terminal, including: the user plane network element determines the service information of the first terminal based on the configuration of the user plane network element, and selects the session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
[0019] It can be seen that if the first terminal provides service information, the user-plane network element can prioritize selecting a suitable session management network element based on the service information provided by the first terminal. If the first terminal does not provide service information, the user-plane network element can also select a session management network element that the user-plane network element considers appropriate based on pre-configured information, thereby improving the success rate of selecting the session management network element and avoiding process failure due to failure in selecting the session management network element.
[0020] Optionally, the method of the first aspect may further include: the user-plane network element receiving, from at least one session management network element, service information supported by the at least one session management network element, to ensure that the selected session management network element supports the service information of the first terminal, thereby avoiding process failure due to lack of support by the session management network element. The at least one session management network element includes a session management network element serving the first terminal.
[0021] In a possible design scheme, the method described in the first aspect may also include: when the authentication of the first terminal is passed, the session management network element generates a session context of the first terminal based on the session subscription information related to the service information of the first terminal obtained from the data management network element, and the session context of the first terminal is used to manage the session of the first terminal. The session of the first terminal is carried by a secure channel, thereby realizing session management in non-3GPP access conditions to ensure the reliability of the service.
[0022] In a possible design scheme, the method described in the first aspect may also include: when the authentication process of the first terminal passes, the data management network element sends the identifier of the access and mobility management network element serving the first terminal to the session management network element; the session management network element receives the identifier of the access and mobility management network element from the data management network element; the session management network element sends the access information of the first terminal to the access and mobility management network element based on the identifier of the access and mobility management network element, and the access information of the first terminal is used to indicate at least one of the following: the access type of the first terminal is non-Third Generation Partnership Project 3GPP access, or the status of the first terminal is a connected state or an activated state; the connection state of the first terminal indicates that the first terminal establishes a connection with the network, but the network cannot transmit the user plane data of the first terminal, and the activation state of the first terminal indicates that the network can transmit the user plane data of the first terminal.
[0023] In a possible design scheme, the method described in the first aspect may also include: when the authentication process of the first terminal passes, the data management network element sends the access information of the first terminal to the access and mobility management network element serving the first terminal, and the access information of the first terminal is used to indicate at least one of the following: the access type of the first terminal is non-Third Generation Partnership Project 3GPP access, or the status of the first terminal is a connected state or an activated state; the connection state of the first terminal indicates that the first terminal establishes a connection with the network, but the network cannot transmit the user-plane data of the first terminal, and the activation state of the first terminal indicates that the network can transmit the user-plane data of the first terminal.
[0024] It can be seen that in the case of non-3GPP access, the network (such as the access and mobility management network element) can track and manage the status of the first terminal, and only provide the user plane data of the service to the first terminal when the first terminal is in an activated state, which can avoid redundant transmission and ensure data security.
[0025] According to a second aspect, a communication method is provided, which includes: a user plane network element serving a first terminal receives information of the first terminal from the first terminal; the user plane network element determines a session management network element serving the first terminal based on the information of the first terminal, or / and determines a session between the user plane network element and the session management network element; the user plane network element sends authentication information or first information of the first terminal to the session management network element, or the user plane network element transmits the authentication information or first information of the first terminal through the session, wherein the authentication information or first information of the first terminal is used for authentication of the first terminal; if the authentication of the first terminal is passed, the user plane network element establishes a secure channel with the first terminal.
[0026] In a possible design, the information of the first terminal includes at least one of address information of the first terminal, temporary identification information of the first terminal, permanent identification information of the first terminal, and service information of the first terminal.
[0027] Optionally, the first information is first indication information, or the first information is permanent identification information of the first terminal or temporary identification information of the first terminal, and the first indication information is used to instruct the session management network element to initiate authentication of the first terminal.
[0028] Optionally, the method described in the second aspect may also include: the user plane network element receives at least one of the authentication success information and the security key from the session management network element, and the security key is a key determined in the authentication of the first terminal; the user plane network element determines that the authentication of the first terminal is passed based on the authentication success information and at least one of the security key.
[0029] Furthermore, the user plane network element establishes a secure channel with the first terminal, including: the user plane network element uses a security key to establish a user plane secure channel with the first terminal.
[0030] In one possible design scheme, the user plane network element determines the session management network element serving the first terminal based on the information of the first terminal, including: the user plane network element obtains the service information of the first terminal; the user plane network element selects the session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
[0031] In one possible design scheme, the user plane network element determines the session management network element serving the first terminal based on the information of the first terminal, including: the user plane network element determines the service information of the first terminal based on the configuration of the user plane network element, and selects the session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
[0032] Optionally, the method described in the second aspect may further include: the user plane network element receiving service information supported by at least one session management network element from at least one session management network element, where the at least one session management network element includes a session management network element serving the first terminal.
[0033] It can be understood that the technical effects of the method described in the second aspect can also refer to the relevant introduction of the method described in the first aspect above, and will not be repeated here.
[0034] According to a third aspect, a communication method is provided, comprising: a session management network element serving a first terminal receives authentication information or first information of the first terminal from a user plane network element serving the first terminal, or the session management network element receives authentication information or first information of the first terminal transmitted by a session between the user plane network element and the session management network element; the session management network element triggers authentication of the first terminal based on the authentication information or first information of the first terminal.
[0035] Optionally, the first information is first indication information, or the first information is permanent identification information of the first terminal or temporary identification information of the first terminal, and the first indication information is used to instruct the session management network element to initiate authentication of the first terminal.
[0036] Optionally, the session management network element triggers authentication of the first terminal based on the first information, including: the session management network element sends the identification information of the first terminal to the authentication network element serving the first terminal, or the session management network element generates an EAP message and sends the EAP message to the authentication network element, the EAP message including the identification information of the first terminal; wherein the identification information of the first terminal is used to trigger the authentication network element to authenticate the first terminal; when the authentication network element successfully authenticates the first terminal, the session management network element receives at least one of authentication success information and a security key from the authentication network element, the security key being a key determined in the authentication of the first terminal; and the session management network element sends at least one of authentication success information and a security key to the user plane network element.
[0037] In a possible design scheme, the method described in the third aspect may further include: the session management network element sending service information supported by the session management network element to the user plane network element.
[0038] In a possible design scheme, the method described in the third aspect may also include: when the authentication of the first terminal is passed, the session management network element generates a session context of the first terminal based on the session subscription information related to the service information of the first terminal obtained from the data management network element, and the session context of the first terminal is used to manage the session of the first terminal, and the session of the first terminal is carried by a secure channel.
[0039] In a possible design scheme, the method described in the third aspect may also include: when the authentication process of the first terminal passes, the session management network element receives the identifier of the access and mobility management network element from the data management network element; the session management network element sends the access information of the first terminal to the access and mobility management network element based on the identifier of the access and mobility management network element, and the access information of the first terminal is used to indicate at least one of the following: the access type of the first terminal is non-Third Generation Partnership Project 3GPP access, or the status of the first terminal is a connected state or an activated state; the connection state of the first terminal indicates that the first terminal establishes a connection with the network, but the network cannot transmit the user plane data of the first terminal, and the activation state of the first terminal indicates that the network can transmit the user plane data of the first terminal.
[0040] It can be understood that the technical effects of the method described in the third aspect can also refer to the relevant introduction of the method described in the first aspect above, and will not be repeated here.
[0041] In a fourth aspect, a communication method is provided, the method including: an authentication network element serving a first terminal receives identification information of the first terminal from a session management network element serving the first terminal; or, the authentication network element receives an EAP message from the session management network element, the EAP message includes identification information of the first terminal, and the authentication network element obtains the identification information of the first terminal from the EAP message; the authentication network element obtains an authentication vector of the first terminal from a data management network element serving the first terminal based on the identification information of the first terminal; the authentication network element authenticates the first terminal based on the authentication vector; when the authentication network element successfully authenticates the first terminal, the authentication network element sends at least one of authentication success information and a security key to the session management network element, and the security key is used to establish a secure channel for the first terminal.
[0042] It can be understood that the technical effects of the method described in the fourth aspect can also refer to the relevant introduction of the method described in the first aspect above, and will not be repeated here.
[0043] In a fifth aspect, a communication device is provided, which includes a module for executing the method described in any one of the first to fourth aspects.
[0044] In one possible design solution, the communication device described in the fifth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the fifth aspect to communicate with other communication devices.
[0045] In one possible design, the communication device described in the fifth aspect may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store instructions related to the method of any one of the first to fourth aspects.
[0046] In an embodiment of the present application, the communication device described in the fifth aspect may be a network device, or a chip (system) or other parts or components that can be set in the network device, or a device that includes the network device.
[0047] It can be understood that the technical effects of the device described in the fifth aspect can also refer to the relevant introduction of the method in any one of the first to fourth aspects above, and will not be repeated here.
[0048] In a sixth aspect, a communication device is provided, comprising: a processor coupled to a memory, the processor configured to execute instructions stored in the memory, so that the communication device executes the method described in any one of the first to fourth aspects.
[0049] In one possible design solution, the communication device described in the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the sixth aspect to communicate with other communication devices.
[0050] In an embodiment of the present application, the communication device described in the sixth aspect can be the network device described in any one of the first to fourth aspects, or a chip (system) or other parts or components that can be set in the network device, or a device that includes the network device.
[0051] In addition, the technical effects of the communication device described in the sixth aspect can refer to the technical effects of the methods described in any one of the first to fourth aspects, and will not be repeated here.
[0052] In a seventh aspect, a communication device is provided, comprising: a processor and a memory; the memory is used to store instructions, and when the processor executes the instructions, the communication device executes the method described in any one of the first to fourth aspects.
[0053] In one possible design solution, the communication device described in the seventh aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the sixth aspect to communicate with other communication devices.
[0054] In an embodiment of the present application, the communication device described in the seventh aspect can be the network device described in any one of the first to fourth aspects, or a chip (system) or other parts or components that can be set in the network device, or a device that includes the network device.
[0055] In addition, the technical effects of the communication device described in the seventh aspect can refer to the technical effects of the methods described in any one of the first to fourth aspects, and will not be repeated here.
[0056] In an eighth aspect, a chip is provided, comprising: a controller and an interface circuit, wherein the controller is used to interact with other devices through the interface circuit to execute the method described in any one of the first to fourth aspects.
[0057] In a ninth aspect, a communication system is provided, comprising at least one of the following: a user plane network element for executing the method described in the second aspect, a session management network element for executing the method described in the third aspect, or an authentication network element for executing the method described in the fourth aspect.
[0058] In a tenth aspect, a computer-readable storage medium is provided, which includes a computer program or instruction stored therein, and when the computer program or instruction is executed, the method described in any one of the first to fourth aspects is executed.
[0059] In an eleventh aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed, enables the method described in any one of the first to fourth aspects to be executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Figure 1 is a schematic diagram of the 5GS architecture.
[0061] Figure 2 is a second schematic diagram of the 5GS architecture;
[0062] FIG3 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;
[0063] FIG4 is a flow chart of a communication method according to an embodiment of the present application;
[0064] FIG5 is a second flow chart of the communication method provided in an embodiment of the present application;
[0065] FIG6 is a third flow chart of the communication method provided in an embodiment of the present application;
[0066] FIG7 is a fourth flow chart of a communication method according to an embodiment of the present application;
[0067] FIG8 is a first structural diagram of a communication device provided in an embodiment of the present application;
[0068] FIG9 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0069] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless network (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, fourth-generation (4G) mobile communication systems, such as long-term evolution (LTE) systems, world-wide interoperability for microwave access (WiMAX) communication systems, fifth-generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as 5.5G and sixth-generation (6G) mobile communication systems.
[0070] For ease of understanding, the technical terms involved in the embodiments of this application are first introduced below.
[0071] 1. 5G mobile communication system (abbreviated as 5G system (5G system, 5GS)):
[0072] Figure 1 is a schematic diagram of the 5GS architecture. As shown in Figure 1, the 5GS includes an access network (AN) and a CN, and may also include terminals.
[0073] The terminal may be one or more. A terminal may be a terminal with transceiver functions, or may be a chip or chip system provided in the terminal. The terminal may also be referred to as UE, access terminal, subscriber unit (subscriber unit), user station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user equipment. The terminal in the embodiments of the present application can be a mobile phone, a cellular phone, a smart phone, a tablet computer, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handheld device (handset), a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart home device (for example, a refrigerator, a television, an air conditioner, an electric meter, etc.), an intelligent robot, a robotic arm, a workshop equipment, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a vehicle-mounted terminal, a roadside unit with terminal function, or a wireless terminal in a smart city. The terminal device of the present application may also be an onboard module, onboard module, onboard component, onboard chip or onboard unit built into a vehicle as one or more components or units. The terminal device may also be other devices with terminal functions, for example, the terminal device may also be a device that functions as a terminal in D2D communication.
[0074] The embodiments of this application do not limit the device form factor of the terminal. The device used to implement the functions of the terminal device can be the terminal device; it can also be a device that supports the terminal device to implement the functions, such as a chip system. The device can be installed in the terminal device or used in conjunction with the terminal device. In the embodiments of this application, the chip system can be composed of chips or include chips and other discrete devices.
[0075] The AN is used to implement access-related functions. It can provide network access for authorized users in a specific area and determine transmission links of varying quality to transmit user data based on user level and service requirements. The AN forwards control signals and user data between terminals and the CN. The AN may include access network equipment, also known as radio access network (RAN) equipment. The CN is primarily responsible for maintaining mobile network subscription data and providing terminal functions such as session management, mobility management, policy management, and security authentication. CN mainly includes the following network elements: user plane function (UPF) network element, authentication service function (AUSF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, network slice selection function (NSSF) network element, network exposure function (NEF) network element, network function repository function (NRF) network element, policy control function (PCF) network element, unified data management (UDM) network element, unified data repository (UDR), and application function (AF).
[0076] RAN equipment, that is, access network devices can be one or more. The access network device can be a device with wireless transceiver functions, or it can be a chip or chip system provided on the device, located in the access network (AN) of the communication system, to provide access services for the terminal. For example, the access network device can be called a radio access network device (RAN) device, which can specifically be a next-generation mobile communication system, such as a 6G access network device, such as a 6G base station, or in the next-generation mobile communication system, the access network device can also have other naming methods, which are all covered within the scope of protection of the embodiments of this application, and this application does not impose any limitations on this. Alternatively, the access network device may include 5G, such as a gNB in a new radio (NR) system, or one or a group of antenna panels (including multiple antenna panels) of a base station in 5G, or a network node constituting a gNB, a transmission and reception point (TRP or TP), or a transmission measurement function (TMF), such as a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), a radio unit (RU), an RSU with base station functions, a wired access gateway, or a 5G core network element. Alternatively, the access network device may include an access point (AP) in a wireless fidelity (WiFi) system, a wireless relay node, a wireless backhaul node, various types of macro base stations, micro base stations (also known as small cells), relay stations, access points, wearable devices, vehicle-mounted devices, and the like.
[0077] Among them, the CU and DU can be set separately, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU) or a remote radio head (RRH). It can be understood that the network device can be a CU node, a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into a network device in the access network RAN, or the CU can be divided into a network device in the core network CN, and there is no limitation here.
[0078] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0079] The UPF network element is mainly responsible for user data processing (forwarding, receiving, billing, etc.). For example, the UPF network element can receive user data from the data network (DN) and forward the user data to the terminal through the access network equipment. The UPF network element can also receive user data from the terminal through the access network equipment and forward the user data to the DN. The DN network element refers to the operator network that provides data transmission services to users. For example, the Internet Protocol (IP) Multimedia Service (IMS), the Internet, etc. The DN can be an operator's external network or a network controlled by the operator, which is used to provide business services to terminal devices.
[0080] The AUSF network element is mainly used to perform terminal security authentication.
[0081] The AMF network element is mainly used for mobility management in mobile networks, such as user location update, user network registration, and user handover.
[0082] The SMF network element is primarily used for session management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating IP addresses to users and selecting the UPF network element that provides packet forwarding.
[0083] The PCF network element mainly supports providing a unified policy framework to control network behavior, provides policy rules to the control layer network function, and is responsible for obtaining user subscription information related to policy decisions. The PCF network element can provide policies such as quality of service (QoS) policy and slice selection policy to the AMF network element and SMF network element.
[0084] The NSSF network element is mainly used to select network slices for terminals.
[0085] NEF network elements are mainly used to support the opening of capabilities and events.
[0086] UDM network elements are mainly used to store user data, such as subscription data, authentication / authorization data, etc.
[0087] The UDR network element is mainly used to store structured data, including contract data and policy data, externally exposed structured data, and application-related data.
[0088] The AF mainly supports interaction with the CN to provide services, such as influencing data routing decisions, policy control functions, or providing some third-party services to the network side. Optionally, the AF can provide a personal identification number (PIN) service, also known as a PIN-AF.
[0089] When 5GC (5G core network) supports non-trusted non-3GPP (N3G for short) access, the architecture of 5GS is shown in Figure 2, where N3IWF is also called non-trusted non-3GPP access gateway, such as non-trusted WLAN access gateway, to support non-trusted WLAN access technology.
[0090] In addition, 5GC can also support trusted non-3GPP access and / or wired network access. Among them, trusted non-3GPP networks include trusted WLAN networks, and wired networks include fixed home network access, etc. The network side architecture is similar to the non-trusted non-3GPP access architecture. For example, N3IWF can be replaced with a trusted WLAN access gateway (trusted non-3GPP gateway function, TNGF), or replaced with a wired network access gateway (wireline access gateway function, W-AGF). The access network equipment between the UE and the above-mentioned access gateway (such as TNGF or W-AGF) includes WLAN AP, wired network access network equipment (fixed access network, FAN), switches, routers, etc.
[0091] N3G access technologies include WLAN access technology and wired access technology. WLAN access technology corresponds to WLAN APs deployed in campuses or WLAN AP hotspots deployed in public places, and wired access technology corresponds to wired access deployed in home networks. In addition, WLAN access technology can be divided into trusted WLAN and untrusted WLAN. In summary, non-3GPP access technologies include trusted non-3GPP access, untrusted non-3GPP access, trusted WLAN access, untrusted WLAN access, wired access or fixed-line access. Whether it is trusted non-3GPP access or untrusted non-3GPP access, the core network side can support the point-to-point interface protocol shown in Figure 2, or support the service-based interface consistently adopted by the 3GPP access core network architecture shown in Figure 1.
[0092] As can be seen, when a terminal device accesses 5GC via non-3GPP access technologies, it must go through a non-3GPP access gateway, also known as the N3WIF network element. This means that the terminal device must support the interaction protocol with the non-3GPP access gateway, and operators must also deploy the non-3GPP access gateway simultaneously after deploying the non-3GPP access point, which significantly increases network deployment costs. Especially for future toB campus scenarios, industry users hope to achieve 5G cellular network coverage in the campus with lower network construction costs while also supporting coverage with non-3GPP access technologies. Therefore, a more simplified non-3GPP access solution for 5GC is needed. In addition to UEs that support 5GC access (supporting SIM cards and NAS modules), there are other terminal devices (xdevices, which do not support NAS modules or SIM cards). xdevices typically support non-3GPP access technologies such as WLAN or wired networks. For these xdevices, similar to UEs, a non-3GPP access gateway must be deployed, and the xdevice must proxy support for the NAS module on the non-3GPP access gateway, resulting in higher deployment costs for the non-3GPP access gateway.
[0093] In response to the above technical problems, the embodiments of the present application propose the following technical solutions.
[0094] The technical solution in this application will be described below with reference to the accompanying drawings.
[0095] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein there is an association relationship between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can also be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.
[0096] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0097] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. The sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device by sending configuration information to the receiving device.
[0098] In this application, "sending information" can be understood as one device sending information to another device, or as one logic module within a device sending information to another logic module. For example, "a network device sending information" can be understood as a network device sending information to another device (such as a terminal or other network device), or as logic module 1 within a network device sending information to logic module 2 within the network device.
[0099] In this application, "receiving information" can be understood as one device receiving information from another device, or it can also be understood as a logic module within a device receiving information from another logic module. For example, "a network device receiving information" can be understood as the network device receiving information from another device (such as a terminal or other network device), or it can be understood as logic module 1 in the network device receiving information from logic module 2 in the network device.
[0100] In this application, "sending information to... (e.g., a terminal)" or the related illustrations in the accompanying drawings can be understood as the destination end of the information being the terminal. This can include sending information to the terminal directly or indirectly. "Receiving information from... (e.g., a terminal)" or "receiving information from... (e.g., a terminal)" or "receiving information sent by (e.g., a terminal)", or the related illustrations in the accompanying drawings can be understood as the source end of the information being the terminal, which can include receiving information from the terminal directly or indirectly. The information may be processed as necessary between the source end and the destination end of the information transmission, such as format changes, etc., but the destination end can understand the valid information from the source end. Similar expressions in this application can be understood similarly and will not be repeated here.
[0101] "Pre-definition" or "pre-configuration" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.
[0102] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.
[0103] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.
[0104] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated with each other are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0105] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0106] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail using a communication system as an example.
[0107] As shown in Figure 3, the communication system can be applied to the above-mentioned 5GS, and mainly includes: terminals, user plane network elements, session management networks, and authentication network elements.
[0108] The terminal may be a terminal that supports access through non-3GPP. For ease of understanding, the terminal that supports access through non-3GPP is defined as an xDevice, or it may be replaced by other possible expressions, without limitation. The identifier of the xDevice, or the xDevice ID, may be used to select a network element (such as a UPF network element) for the user plane for the xDevice. Specifically, it may be a user equipment identifier used when the xDevice accesses through non-3GPP, or used to identify a device that supports (or uses) non-3GPP access, such as a subscription permanent identifier (SUPI), a subscription concealed identifier (SUCI), or a 5G temporary identifier (5G-globally unique temporary UE identity, 5G-GUTI), or a user equipment identifier in the format of a network access identifier (NAI). NAI may be based on an existing defined format, such as a user equipment identifier or a domain name. The user equipment identifier may also be the above-mentioned SUPI, SUCI or 5G-GUTI, or other types of user equipment identifiers, without limitation.
[0109] It is understood that if the x-device supports both non-3GPP and 3GPP access, then the x-device can be understood as a conventional terminal (i.e., a terminal that supports 3GPP access), or the x-device and the terminal are the same device, and the x-device identifier is the terminal identifier, such as the UE ID. If the x-device only supports non-3GPP access, then the x-device cannot generally be understood as a conventional terminal, or the x-device and the terminal are different devices, and the x-device identifier and the terminal identifier may also be different identifiers. For example, the x-device does not support a NAS module or a SIM card; it typically supports non-3GPP access technologies such as WLAN or wired access.
[0110] In addition, the device form of the terminal can refer to the relevant introduction in the above 5GS, which will not be repeated here.
[0111] The user plane network element can be the UPF network element in the above-mentioned 5GS, for details, please refer to the relevant introduction above, or it can be a network element used to implement the corresponding functions of the user plane in the future communication system, and there is no limitation on this. In addition, the user plane network element described in this article can also be a security gateway function, or a security gateway function deployed in conjunction with the user plane network element, or an access network element function, or an access gateway function deployed in conjunction with the user plane network element, and there is no limitation on this in this article.
[0112] The session management network element can be the SMF network element in the above-mentioned 5GS, for details, please refer to the above-mentioned relevant introduction, or it can be a network element used to implement the corresponding function of session management in the future communication system, which is not limited to this.
[0113] The data management network element can be the UDM network element in the above-mentioned 5GS, for details, please refer to the above-mentioned relevant introduction, or it can be a network element used to implement the corresponding function of data management in the future communication system, which is not limited to this.
[0114] The authentication network element may be the AUSF network element in the above-mentioned 5GS, for details please refer to the above-mentioned related introduction, or it may be a network element used to implement the corresponding functions of the application in the future communication system, and there is no limitation on this.
[0115] In this communication system, after obtaining information about the first terminal, the user-plane network element can select a session management network element or a session corresponding to the session management network element. The user-plane network element and the session management network element can then transmit the authentication information of the first terminal during authentication. If the authentication of the first terminal is successful, the user-plane network element establishes a secure channel with the first terminal, bypassing the N3G access gateway and directly establishing a user-plane connection. This eliminates the need for the network to deploy an N3G access gateway, and the terminal can also disallow the transmission of non-access stratum (NAS) messages over N3G. This allows for the establishment of user-plane connections for non-3GPP access at a lower cost.
[0116] The communication method and device of the embodiment of the present application are further introduced below in conjunction with the accompanying drawings. It can be understood that the present application uses the network device and the terminal as the execution subject of the interactive schematic as an example for illustration, but the present application does not limit the execution subject of the interactive schematic. For example, the method executed by the network device in the present application can also be executed by a module (such as a chip, a chip system, or a processor) applied to the network device, and can also be implemented by a logical node, a logical module or software that can realize all or part of the functions of the network device; the method executed by the terminal in the present application can also be executed by a module (such as a chip, a chip system, or a processor) applied to the terminal, and can also be implemented by a logical node, a logical module or software that can realize all or part of the functions of the terminal.
[0117] The following will specifically describe the interaction process between each network element / device in the above communication system through a method embodiment in conjunction with Figures 4 to 7. The communication method provided in the embodiment of the present application can be applied to the above communication system and specifically applied to various scenarios mentioned in the above communication system, which will be described in detail below.
[0118] Figure 4 is a flow chart of a communication method according to an embodiment of the present application. The communication method is applicable to the above communication system and mainly involves interaction between a first terminal, a user plane network element, and a session management network element.
[0119] S401: A user plane network element receives information of a first terminal from the first terminal.
[0120] S402: The user plane network element determines a session management network element based on the information of the first terminal, or / and determines a session between the user plane network element and the session management network element.
[0121] S403: The user plane network element sends authentication information or first information to the session management network element, or the user plane network element transmits the authentication information or first information via the session. The session management network element receives the authentication information or first information from the user plane network element, or the session management network element receives the authentication information or first information of the first terminal transmitted via the session.
[0122] S404: The session management network element triggers authentication of the first terminal according to the authentication information of the first terminal or the first information.
[0123] S405: When the authentication of the first terminal is successful, the user plane network element establishes a secure channel with the first terminal.
[0124] Each step in S401-S405 is defined below.
[0125] S401:
[0126] The user plane network element can be a user plane network element serving the first terminal, which can be understood as the user plane network element that provides user plane services to the first terminal when the first terminal accesses the 5GC through non-3GPP this time, or it can also be understood as the user plane network element selected by the network to provide user plane services to the first terminal when the first terminal accesses the 5GC through 3GPP in advance.
[0127] The first terminal may be a terminal supporting non-3GPP access, such as a terminal in which an x device and a UE are jointly provided.
[0128] The information of the first terminal may include at least one of the address information of the first terminal, the temporary identification information of the first terminal, the permanent identification information of the first terminal, or the service information of the first terminal. The address information of the first terminal may be the IP address of the first terminal, and the IP address may be the IP address of the terminal side obtained in the protocol data unit (PDU) session established by the first terminal on the 3GPP side. The temporary identification information of the first terminal may be the 5G GUTI obtained by the first terminal from the 3GPP side through registration, or it may be other identification information. The permanent identification information of the first terminal may be the SUPI or SUCI of the first terminal, that is, information obtained on the 3GPP side, or it may be other identification information. The service information of the first terminal may be the DNN or slice information obtained by the first terminal on the 3GPP side, such as at least one of the network slice selection assistance information (NSSAI).
[0129] In the embodiment of the present application, the information of the first terminal may also be replaced by other names, such as NAI.
[0130] The user plane network element may receive the information of the first terminal from the first terminal through a layer 2 connection established with the first terminal.
[0131] For example, the first terminal may obtain the address information of the user-plane network element in advance, such as the IP address of the user-plane network element. For example, the first terminal may obtain the address information of the user-plane network element from the network through prior 3GPP access, or the address information of the user-plane network element may be pre-configured locally on the first terminal in a manner predefined by the protocol, or the first terminal may obtain the address information of the user-plane network element from other devices, such as from other terminals or WLAN APs. It will be understood that the above are merely examples, and the embodiments of the present application do not limit how the first terminal obtains the address information of the user-plane network element.
[0132] The first terminal can initiate a layer 2 connection to the user plane network element based on the address information of the user plane network element, such as the establishment of an IPsec tunnel. For example, the first terminal can send an (internet key exchange, IKE) network key exchange initialization request (IKE_INIT Req) message to the user plane network element, and receive an IKE initialization response message from the user plane network element in response to the IKE initialization request message. At this time, the first terminal and the user plane network element can align the relevant parameters of the IPsec tunnel, that is, to establish an IPsec tunnel. For details, please refer to the relevant introduction in the prior art and will not be repeated here. In this way, the first terminal can send the information of the first terminal to the user plane network element through the IPsec tunnel. At this time, the information of the first terminal can be carried in the IKE authentication request (IKEAUTH Req) message #1, or can also be carried in any other possible message. The embodiment of the present application does not limit the message name. Accordingly, the user plane network element can receive the information of the first terminal through the IPsec tunnel.
[0133] S402:
[0134] The session management network element may be a session management network element serving the first terminal, which may be understood as a session management network element providing session management services to the first terminal when the first terminal accesses the first terminal through non-3GPP this time.
[0135] The session between the user plane network element and the session management network element (denoted as session management network element #2) can be an N4 session, such as a packet forwarding control protocol (PFCP) session, or can be any possible type of session, such as a new session defined in the future, and the specific implementation is not limited. The N4 session can be established when the first terminal accesses in advance through 3GPP and associated with information of the first terminal, such as associating an N4 session identifier with the IP address of the first terminal, or can be associated in other ways, which are not specifically limited.
[0136] It can be understood that for S402, if the user-plane network element chooses to discover a new session management network element, the new session management network element may be different from the session management network element that has previously established a session. If the user-plane network element chooses to reuse an existing session, the user-plane network element does not perform session management network element discovery, which are introduced below.
[0137] Method 1: Discover a new session management network element.
[0138] In one possible implementation, if the first terminal provides the service information of the first terminal, the user plane network element may give priority to the service information of the first terminal and select the session management network element. For example, the user plane network element may obtain the service information of the first terminal, such as at least one of DNN and NSSAI. The user plane network element may select the session management network element that supports the service information of the first terminal as the session management network element serving the first terminal. For example, the service information of the UE includes DNN#1 and NSSAI#1, SMF network element#1 supports DNN#1 and NSSAI#2, SMF network element#1 supports DNN#2 and NSSAI#2, SMF network element#3 supports DNN#1 and NSSAI#1, and the UPF network element selects SMF network element#3 as the SMF network element serving the UE.
[0139] In another possible implementation, if the first terminal does not provide relevant information about the first terminal's service, such as the aforementioned DNN and / or NSSAI, the user plane network element may select a session management network element based on local configuration. For example, the user plane network element may determine the service information of the first terminal based on the local configuration of the user plane network element. For example, the user plane network element may determine locally configured service information, such as at least one of the DNN and NSSAI, as the service information of the first terminal. The user plane network element may then select a session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
[0140] After the user plane network element selects the session management network element, the user plane network element may also establish a session, such as an N4 session, with the selected session management network element. The specific implementation method may be the existing technology and is not limited in the embodiments of the present application. In addition, the embodiments of the present application do not limit the N4 session mentioned below. It can be understood that it is an existing N4 session reused in the following method 2, or it can also be a newly established N4 session in method 1.
[0141] It is also understood that the information about which session management network elements support which services can be predefined or preconfigured locally in the user plane network element, or can also be provided by the session management network element. For example, the user plane network element can receive information about services supported by at least one session management network element from at least one session management network element to ensure that the selected session management network element supports the service information of the first terminal, thereby avoiding process failure due to lack of support from the session management network element. The at least one session management network element includes the aforementioned session management network element serving the first terminal.
[0142] It can be seen that if the first terminal provides service information, the user-plane network element can prioritize selecting a suitable session management network element based on the service information provided by the first terminal. If the first terminal does not provide service information, the user-plane network element can also select a session management network element that the user-plane network element considers appropriate based on pre-configured information, thereby improving the success rate of selecting the session management network element and avoiding process failure due to failure in selecting the session management network element.
[0143] Method 2: Reuse existing session management network elements.
[0144] Since the N4 session can be associated with certain information of the first terminal, the user-plane network element can determine that the information of the first terminal is associated with the N4 session when it obtains the information of the first terminal. Taking the identifier of the N4 session and the IP address of the first terminal as an example, when the user-plane network element obtains the IP address of the first terminal from the information of the first terminal, the user-plane network element can traverse the association relationship and determine that the IP address of the first terminal is associated with the identifier of the N4 session, that is, determine the N4 session. In this way, the user-plane network element determines that the N4 session can be used to transmit relevant information of the first terminal in the future, such as transmitting it to session management network element #1.
[0145] After the process of mode 1 or the process of mode 2, the user plane network element sends first information to the session management network element, instructing the session management network element to initiate an authentication process of the first terminal.
[0146] The first information may be first indication information, and the first indication information may be used to instruct the session management network element to initiate an authentication and certification process for the first terminal. For example, the first indication information is a new information element, such as an information element of one or more bits, which explicitly instructs the session management network element to initiate an authentication and certification process for the first terminal through specific values or value combinations of these bits, so as to achieve decoupling from existing information elements, and the indication method may be more flexible. Alternatively, the first information is identification information of the first terminal, such as the permanent identification information of the first terminal or the temporary identification information of the first terminal mentioned above. In other words, the user plane network element may pass the identification of the first terminal received from the first terminal to the session management network element as the first information, so as to implicitly indicate the triggering of the authentication and certification process of the first terminal through the identification information of the first terminal, that is, to reuse existing information elements to reduce indication overhead.
[0147] It should be understood that the above are only some exemplary implementations of the first information, and the first information can also be implemented in other ways. For example, the first information includes the first indication information and the identifier of the first terminal, which are used to jointly instruct the session management network element to initiate the authentication process of the first terminal. In addition,
[0148] For example, after the process of mode 1, the user plane network element may send the first information to the session management network element. Accordingly, the session management network element receives the first information from the user plane network element. In this case, the first information may be carried in any possible message transmitted between the user plane network element and the session management network element. For another example, after the process of mode 2, the user plane network element transmits the first information through the N4 session. Accordingly, the session management network element receives the first information transmitted by the N4 session. In this case, the first information may be carried in any possible message that can be transmitted through the N4 session, such as PFCP Notification Report Message #1 / PFCP Session Request Message #1, etc., or may be carried in any other possible message. This embodiment of the present application does not limit the message name.
[0149] After receiving the first information, the session management network element can trigger the authentication process of the first terminal according to the first information. Optionally, the session management network element can trigger the authentication process of the first terminal through the authentication network element or through the data management network element, which are described below.
[0150] Method A:
[0151] The session management network element may send identification information of the first terminal to the authentication network element serving the first terminal, as will be described in detail below.
[0152] The authentication network element serving the first terminal refers to the authentication network element that can provide authentication and authorization services to the first terminal. For example, the session management network element can select an authentication network element that can provide services to the first terminal based on the identification information of the first terminal, such as the identification information of the first terminal obtained from the user plane network element as mentioned above. The specific selection method is not limited in the embodiment of the present application. The session management network element can send an extended authentication protocol (EAP) message #1 or an authentication request (Auth request) message #1 carrying the identification information of the first terminal to the authentication network element, such as the identification information of the first terminal is carried in EAP message #1, EAP message #1 is carried in authentication message #1, or it can be in any other possible message. The embodiment of the present application does not limit the message name.
[0153] The authentication network element may receive identification information of the first terminal from the session management network element, and obtain an authentication vector of the first terminal from the data management network element serving the first terminal based on the identification information of the first terminal, as described in detail below.
[0154] The data management network element serving the first terminal refers to the data management network element that stores the contract data of the first terminal. For example, the authentication network element can query the data management network element that stores the contract data of the first terminal based on the identification information of the first terminal, such as the identification information of the first terminal obtained from the session management network element as mentioned above. The specific query method is not limited in the embodiment of this application. The authentication network element can send the identification information of the first terminal to the data management network element to request the data management network element to provide information related to the authentication of the first terminal. In this case, the identification information of the first terminal can be carried in any possible message sent by the authentication network element to the data management network element. The embodiment of this application does not limit the message name.
[0155] The data management network element may obtain an authentication vector, or security parameter, of the first terminal from the subscription data of the first terminal based on the identification information of the first terminal. Specifically, the authentication vector may be 5G HEAV or EAP AKA'AV. The data management network element may send the authentication vector of the first terminal to the authentication network element. The authentication vector may be carried in any possible message sent by the data management network element to the authentication network element. This embodiment of the present application does not limit the message name.
[0156] After receiving the authentication vector of the first terminal, the authentication network element authenticates the first terminal according to the authentication vector of the first terminal, which is described in detail below.
[0157] The authentication network element may send the authentication and authentication information (recorded as authentication and authentication information #1) in the authentication and authentication vector for the terminal to authenticate the network to the first terminal. For example, the authentication network element may send an EAP message #2 (such as an EAP request / challenge message) or authentication message #2 carrying authentication and authentication information #1 to the session management network element. For example, authentication and authentication information #1 is carried in EAP message #2, EAP message #2 is carried in authentication message #2, or it may be any other possible message. The embodiment of the present application does not limit the message name. In addition, the authentication and authentication information #1 can refer to the relevant introduction of 5G AKK or EAP AKA', which will not be repeated here.
[0158] After receiving authentication information #1, the session management network element may send any possible message carrying authentication information #1 to the user plane network element. Alternatively, authentication information #1 may be delivered via the N4 session. For example, authentication information #1 may be carried in EAP message #2, which may be carried in PFCP Notification Report message #2 / PFCP Session Response message #1 of the N4 session. Alternatively, authentication information #1 may be carried in any other possible message. This embodiment of the present application does not limit the message name. Accordingly, the user plane network element receives authentication information #1 from the session management network element.
[0159] After receiving the authentication information #1, the user-plane network element can send the authentication information #1 to the first terminal through the IPsec tunnel between the user-plane network element and the first terminal. For example, the authentication information #1 is carried in EAP message #2, and the EAP message #2 can be carried in IKE authentication response (IKEAUTH ANS) message #1, or can be carried in any other possible message. The embodiment of the present application does not limit the message name. Accordingly, the first terminal receives the authentication information #1 from the user-plane network element and uses the authentication information #1 to authenticate the network. For specific implementation, please refer to the relevant introduction of 5G AKK or EAP AKA', which will not be repeated here.
[0160] Method B:
[0161] The session management network element may send the identification information of the first terminal to the data management network element serving the first terminal. For example, the session management network element may query the data management network element storing the subscription data of the first terminal based on the identification information of the first terminal, such as the identification information of the first terminal obtained from the session management network element as described above. The specific query method is not limited in this embodiment of the present application. The session management network element may send any possible message carrying the identification information of the first terminal to the data management network element. This embodiment of the present application does not limit the message name.
[0162] The data management network element can receive the identification information of the first terminal from the session management network element, and send the authentication vector of the first terminal to the authentication network element serving the first terminal based on the identification information of the first terminal. Correspondingly, the authentication network element can receive the authentication vector of the first terminal from the data management network element, and authenticate the first terminal based on the authentication vector of the first terminal. The specific implementation can also refer to the relevant introduction of the above-mentioned method A, which will not be repeated here.
[0163] It can be seen that the session management network element can trigger the authentication process of the first terminal by interacting with the authentication network element, or it can trigger the authentication process of the first terminal by directly interacting with the data management network element. There is no restriction on the specific implementation method, and it can be flexibly selected according to actual conditions.
[0164] S403-S404:
[0165] The session management network element may trigger authentication of the first terminal according to the authentication information #2, as will be described in detail below.
[0166] When the first terminal passes the authentication network, the first terminal can return the authentication information of the first terminal (recorded as authentication information #2) for network authentication of the first terminal. The authentication information #2 can also refer to the relevant introduction of 5G AKK or EAP AKA', which will not be repeated here. The first terminal can send authentication information #2 to the user plane network element through the IPsec tunnel between the first terminal and the user plane network element. For example, the authentication information #2 can be carried in EAP message #3 (such as EAP request / challenge message), and EAP message #3 can be carried in IKE authentication request message #2, or it can be carried in any other possible message. The embodiment of the present application does not limit the message name. Accordingly, the user plane network element receives authentication information #2 from the first terminal.
[0167] After receiving authentication information #2, the user-plane network element may send any possible message carrying authentication information #2 to the session management network element. Alternatively, authentication information #2 may be delivered via the N4 session. For example, authentication information #2 may be carried in EAP message #3, which may be carried in PFCP Notification Report message #3 / PFCP Session Request message #2 of the N4 session. Alternatively, authentication information #2 may be carried in any other possible message. This embodiment of the present application does not limit the message name. Accordingly, the session management network element receives authentication information #2 from the user-plane network element.
[0168] After receiving authentication information #2, the session management network element may send an EAP message #3 or authentication message #3 carrying authentication information #2 to the authentication network element. For example, authentication information #2 may be carried in EAP message #3, EAP message #3 may be carried in authentication message #3, or any other possible message. This embodiment of the present application does not limit the message name. Accordingly, the authentication network element receives authentication information #2 from the session management network element and uses authentication information #2 to authenticate the first terminal. For specific implementation, please refer to the relevant introduction of 5G AKK or EAP AKA' and will not be repeated here.
[0169] When the authentication network element successfully authenticates the first terminal, the authentication network element sends at least one of authentication success information and a security key to the session management network element, which is described in detail below.
[0170] The authentication success information may be EAP message #4, such as an EAP success message, indicating that the authentication of the first terminal is successful.
[0171] The security key may be a key determined during the authentication process of the first terminal and may be used to subsequently ensure the security of user plane transmission. For example, the authentication network element may derive a security key based on the security vector of the first terminal when the authentication of the first terminal passes. The security vector may be a security certificate, public key, or private key of the first terminal, pre-configured in the subscription data of the first terminal. The security vector may be transmitted to the authentication network element by being carried in the authentication vector of the first terminal, or may be sent separately by the data management network element to the authentication network element, without limitation to the specific implementation.
[0172] The authentication network element may send an authentication message #4 to the session management network element, carrying at least one of authentication success information and a security key. For example, if the authentication success information is EAP message #4, the security key may be carried in EAP message #4, which may be carried in authentication message #4, or both the security key and EAP message #4 may be carried in authentication message #4. Alternatively, the authentication message may be carried in any other possible message. This embodiment of the present application does not limit the message name. Accordingly, the session management network element receives at least one of the authentication success information and the security key from the session management network element.
[0173] When at least one of the authentication success information and the security key is received, the session management network element may send the authentication success information and the security key to the user plane network element. For example, the session management network element may send any possible message carrying at least one of the authentication success information and the security key to the user plane function. Alternatively, at least one of the authentication success information and the security key may be transmitted via the N4 session. For example, taking EAP message #4 as an example, the security key may be carried in EAP message #4, which may be carried in PFCP Notification Report Message #4 / PFCP Session Response Message #2. Alternatively, both the security key and EAP message #4 may be carried in PFCP Notification Report Message #4 / PFCP Session Response Message #2. Alternatively, any other possible message may be used. This embodiment of the present application does not limit the message names. Accordingly, the user plane network element may receive at least one of the authentication success information and the security key from the session management network element.
[0174] It can be seen that, unlike the prior art in which the authentication and certification process of the first terminal is triggered through the NAS layer (such as the access and mobility management network element), the embodiment of the present application can trigger the authentication and certification process of the first terminal by the user plane network element instructing the session management network element, which bypasses the NAS layer, or does not transmit NAS messages, so that the terminal does not support the transmission of non-access layer NAS messages in N3G, thereby achieving user plane connection establishment for non-3GPP access at a lower cost.
[0175] S405:
[0176] The secure channel may be an IPSec secure channel, or may be any other possible secure channel, without specific limitation.
[0177] The user plane network element can determine that the authentication of the first terminal is passed based on at least one of the authentication success information and the security key. The user plane network element can use the security key to establish a secure channel between the user plane network element and the first terminal. For example, since the first terminal can deduce the security key based on the security vector of the first terminal, when the user plane network element obtains the security key, the first terminal and the user plane network element can both use the security key to communicate, which means that the IPSec secure channel is successfully established. Of course, since the user plane network element establishes a secure channel with the first terminal only when it is determined that the authentication of the first terminal is passed, the security risks brought about by establishing a secure channel when the authentication of the first terminal fails are avoided.
[0178] In summary, after obtaining the information of the first terminal, the user plane network element can select a session management network element or a session corresponding to the session management network element, and the user plane network element and the session management network element can transmit the authentication information of the first terminal in the authentication process. If the authentication of the first terminal is successful, the user plane network element establishes a secure channel with the first terminal, that is, bypassing the N3G access gateway and directly establishing a user plane connection. In this way, the network does not need to deploy an N3G access gateway, and the terminal does not need to support the transmission of non-access layer NAS messages in N3G, thereby achieving user plane connection establishment for non-3GPP access at a lower cost.
[0179] In a first possible design solution, in combination with S401 to S405 above, the method further includes:
[0180] When the authentication process of the first terminal passes, the session management network element may further generate a session context of the first terminal according to the session subscription information related to the service information of the first terminal obtained from the data management network element.
[0181] The session subscription information may include one or more of the following: identification information of the first terminal, DNN, PDU session type, QoS parameters, and billing policy. The session context of the first terminal may include session subscription information and may also include other information, which may be based on existing technologies and is not limited thereto. The session context of the first terminal is used to manage the session of the first terminal, such as the PDU session. The session of the first terminal may be carried by a secure channel, thereby implementing session management in non-3GPP access scenarios to ensure service reliability.
[0182] For example, the user plane network element may also send service information of the first terminal, such as DNN and / or slice information, to the session management network element. The service information of the first terminal and the above-mentioned first information may be carried in the same message, such as being included in the first information; alternatively, the service information of the first terminal and the first information may be transmitted separately. In this case, the transmission method of the service information of the first terminal is similar to that of the first information, which can be understood by reference and will not be repeated here. Accordingly, the session management network element receives the service information of the first terminal from the user plane network element.
[0183] The session management network element may also send the service information of the first terminal and the identifier of the session management network element to the authentication network element. The authentication network element receives the service information of the first terminal and the identifier of the session management network element from the session management network element, and sends the service information of the first terminal and the identifier of the session management network element to the data management network element. The transmission method is similar to that of the identifier information of the first terminal, which can be understood by reference and will not be described in detail here. Alternatively, the session management network element may also directly send the service information of the first terminal and the identifier of the session management network element to the data management network element.
[0184] When the data management network element receives the service information of the first terminal, the data management network element may also obtain session subscription information related to the service information of the first terminal (such as DNN and / or slice information) from the subscription data of the first terminal based on the service information of the first terminal, namely, one or more of the aforementioned identification information of the first terminal, DNN, PDU session type, QoS parameters, and charging policy. Furthermore, the data management network element may also store the identifier of the session management network element. When the authentication of the first terminal is successful, the data management network element may send the session subscription information to the session management network element based on the identifier of the session management network element. In this case, the session subscription information may be carried in any possible message sent by the data management network element to the session management network element. This embodiment of the present application does not limit the message name. The authentication of the first terminal may be notified to the data management network element by the authentication network element, or the data management network element may subscribe to the authentication network element. The specific implementation is not limited. Accordingly, the session management network element may determine that the authentication of the first terminal is successful based on at least one of the authentication success information and the security key. Therefore, the session management network element may generate a session context for the first terminal based on the session subscription information.
[0185] In a second possible design solution, in combination with the above S401-S405, the method further includes:
[0186] If the authentication process of the first terminal passes, the data management network element may also send the identifier of the access and mobility management network element serving the first terminal to the session management network element. The access and mobility management network element may be the access and mobility management network element that the first terminal registered with the network when accessing through 3GPP in advance. In this case, the identifier of the access and mobility management network element may be stored in the subscription data of the first terminal. In this way, if the authentication process of the first terminal passes, the data management network element may subsequently obtain the identifier of the access and mobility management network element from the subscription data of the first terminal, and send the identifier of the access and mobility management network element to the session management network element through any possible message exchanged between the data management network element and the session management network element. Accordingly, the session management network element may receive the identifier of the access and mobility management network element from the data management network element.
[0187] When the session management network element receives the identifier of the access and mobility management network element, the session management network element may send at least one of the identification information of the first terminal and the mobility management information of the first terminal to the access and mobility management network element according to the identifier of the access and mobility management network element.
[0188] The mobility management information of the first terminal may be used to indicate at least one of the following: the access type of the first terminal is non-3GPP access, or the status of the first terminal is connected or activated. For example, the mobility management information of the first terminal may include access type indication information. The access type indication information may be an information element of one or more bits, which is combined with the identification information of the first terminal to indicate whether the access type of the first terminal is 3GPP access or non-3GPP access by combining the values of the bits. In the case of non-3GPP access, it may further indicate whether the access type is WLAN access technology, trusted / untrusted WLAN access technology, or wired access technology. The mobility management information of the first terminal may include status indication information. The status indication information may also be an information element of one or more bits, which is combined with the identification information of the first terminal to indicate whether the status of the first terminal is connected or activated by combining the values of the bits. The connection status of the first terminal indicates that the first terminal has established a connection with the network, but the network cannot transmit the user plane data of the first terminal, that is, the user plane data of the first terminal can be truncated or discarded by the user plane network element. The activation state of the first terminal indicates that the network can transmit the user plane data of the first terminal, that is, the user plane data of the first terminal can be delivered to the first terminal or the data network by the user plane network element.
[0189] It can be seen that in the case of non-3GPP access, the network (such as the access and mobility management network element) can track and manage the status of the first terminal, and only provide the user plane data of the service to the first terminal when the first terminal is in an activated state, which can avoid redundant transmission and ensure data security.
[0190] The session management network element may send at least one of the identification information of the first terminal and the mobility management information of the first terminal to the access and mobility management network element through any possible message exchanged between the session management network element and the access and mobility management network element. Correspondingly, the access and mobility management network element may receive at least one of the identification information of the first terminal and the mobility management information of the first terminal from the session management network element. The access and mobility management network element may save the mobility management information of the first terminal in the context of the first terminal using the identification information of the first terminal, thereby enabling real-time tracking and management of the connection status of the first terminal.
[0191] In a third possible design solution, in combination with the above S401-S405, the method further includes:
[0192] If the first terminal passes the authentication process, the data management network element may directly send at least one of the first terminal's identification information and the first terminal's mobility management information to the access and mobility management network element serving the first terminal. For specific implementation methods, refer to the relevant introduction to the second possible design solution above and will not be repeated here. Additionally, the data management network element may also send the session management network element's identifier to the access and mobility management network element for storage.
[0193] The above describes the arrangement process of the communication method provided by the embodiment of the present application in conjunction with Figure 4. The following describes in detail the specific process of the communication method provided by the embodiment of the present application in a specific scenario in conjunction with Figures 5 to 7.
[0194] Scenario 1:
[0195] Figure 5 is a second flow chart of the communication method provided in an embodiment of the present application. The communication method is applicable to the above-mentioned communication system, and mainly involves the interaction between the UE (the above-mentioned first terminal), the UPF network element (the above-mentioned user plane network element), the SMF network element (the above-mentioned session management network element), the AUSF network element (the above-mentioned authentication network element) / UDM network element (the above-mentioned data management network element), etc.
[0196] In scenario 1, the UE can act as an x device, or the UE and the x device are the same device. The UE can configure / obtain the IP address of the UPF network element in advance. In this way, when the UE accesses 5GC through non-3GPP, it does not need to interact with NAS, and can directly use the IP address of the UPF network element to communicate with the UPF network element. The UPF network element instructs the SMF network element to trigger the AUSF network element to authenticate the UE, so that a secure channel can be established between the UE and the UPF network element through authentication. In this way, not only can the network deployment cost be reduced, that is, the network side does not need to deploy an access gateway for non-3GPP access, but also the UE implementation cost can be reduced, that is, the UE does not need to support NAS transmission in N3G, which facilitates the commercial use of non-3GPP access 5GC features in existing networks.
[0197] Specifically, as shown in FIG5 , the process of the communication method is as follows:
[0198] S500a, the SMF network element sends a registration request message to the UPF network element.
[0199] The registration request message may include the identifier of the SMF network element and the service information supported by the SMF network element, such as DNN and / or slice information. The UPF network element can save the identifier of the SMF network element and the service information supported by the SMF network element locally in the UPF network element according to the registration request message to realize the registration of the SMF network element to the UPF network element.
[0200] S500b, the UPF network element sends a registration response message to the SMF network element.
[0201] The registration response message can be used to indicate the success / failure of the SMF network element to register with the UPF network element.
[0202] It is understood that S500a-S500b can be performed separately by different SMF network elements, that is, multiple SMF network elements can be registered with the UPF network element. In addition, S500a-S500b are optional steps. For example, the UPF network element can also pre-configure the identifiers of each SMF network element and the service information supported by each SMF network element. Of course, S500a-S500b can also refer to the relevant introduction in S402 above, which will not be repeated here.
[0203] S501a, the UE sends an IKE initialization request message to the UPF network element.
[0204] S501b, the UPF network element sends an IKE initialization response message to the UE.
[0205] Among them, S501a-S501b are used to establish an IPsec tunnel between the UE and the UPF network element. For specific implementation, please refer to the relevant introduction in the above S401 and will not be repeated here.
[0206] S502, the UE sends an IKE authentication request message #1 to the UPF network element.
[0207] IKE Authentication Request Message #1 is carried in the IPsec tunnel. IKE Authentication Request Message #1 may include the UE's NAI and, optionally, at least one of the UE's DNN and slice information. The NAI may be used to identify the UE, such as including at least one of the UE's permanent identifier (such as SUPI or SUCI), device identifier (such as IMEI, MAC address, or other hardware device identifier), or temporary identifier (such as 5G-GUTI or other temporary identifier).
[0208] On this basis, the UPF network element can select the SMF network element that supports the DNN and / or slice information based on the DNN and / or slice information provided by the UE, or, if the UE does not provide the DNN and / or slice information, the UPF network element can select the SMF network element that supports the DNN and / or slice information based on the locally pre-configured DNN and / or slice information. For the specific implementation, please refer to the relevant introduction of method 1 in S402 above, which will not be repeated here.
[0209] S503, the UPF network element sends PFCP notification report message #1 to the SMF network element.
[0210] PFCP notification report message #1 may include the UE's NAI to instruct the SMF network element to initiate authentication of the UE. Optionally, it may also include at least one of the UE's DNN and slice information. For specific implementation, please refer to the relevant introduction after method 1 and method 2 in the above S402, which will not be repeated here.
[0211] S504, the SMF network element sends authentication message #1 to the AUSF network element.
[0212] Authentication message #1 may include EAP message #1, which may include the NAI of the UE. Optionally, at least one of the DNN and slice information of the UE, and the identifier of the SMF network element may also be carried in the EAP message #1 or the authentication message #1. For specific implementation, please refer to the relevant introduction of method A in S402 above, which will not be repeated here.
[0213] S505, the AUSF network element obtains the UE's authentication vector from the UDM network element.
[0214] The UE's authentication vector is the authentication vector of the first terminal. The specific implementation of S505 may refer to the relevant introduction of the method A in S402 above, which will not be repeated here.
[0215] S506, the AUSF network element sends authentication message #2 to the SMF network element.
[0216] Authentication message #2 may include EAP message #2, which may include the UE's authentication information, namely the aforementioned authentication information #1. For specific implementation, reference may be made to the relevant introduction to method A in S402 above, which will not be repeated here.
[0217] S507, the SMF network element sends PFCP notification report message #2 to the UPF network element.
[0218] The PFCP notification report message # may include an EAP message #2, and the EAP message #2 may include the UE's authentication information #1. For specific implementation, reference may be made to the relevant introduction to the method A in S402 above, which will not be repeated here.
[0219] S508, the UPF network element sends an IKE authentication response message #1 to the UE.
[0220] IKE authentication response message #1 is a response message to the aforementioned IKE authentication request message #1. The IKE authentication response message may include EAP message #2. The EAP message #2 may include the UE's authentication information, i.e., the aforementioned authentication information #1. For specific implementation, please refer to the relevant description of method A in S402 above, which will not be repeated here.
[0221] S509, the UE authenticates the network.
[0222] The UE may use the received authentication information #1 to authenticate the network. For specific implementation, reference may be made to the related introduction of S403 above, which will not be repeated here.
[0223] S510, the UE sends an IKE authentication request message #2 to the UPF network element.
[0224] IKE Authentication Request Message #2 is carried in the IPsec tunnel and may include the UE's authentication information, namely, the aforementioned Authentication Information #2. For example, IKE Authentication Request Message #2 may include EAP Message #3, which may include Authentication Information #2, to request the network to authenticate the UE. For detailed implementation, please refer to the description of S403 above and will not be repeated here.
[0225] S511, UPF network element sends PFCP notification report message #3 to SMF network element.
[0226] PFCP notification report message #3 may include authentication information #2. For example, PFCP notification report message #3 includes EAP message #3, which may include authentication information #2. For specific implementation, please refer to the relevant introduction of S403 above, which will not be repeated here.
[0227] S512, the SMF network element sends authentication message #3 to the AUSF network element.
[0228] The authentication message #3 may include an EAP message #3, and the EAP message #3 may include the authentication information #2. For a specific implementation, reference may be made to the related introduction of S403 above, which will not be repeated here.
[0229] S513, the AUSF network element authenticates the UE.
[0230] The AUSF network element may use the received authentication information #2 to authenticate the UE. For specific implementation, reference may be made to the related introduction of S403 above, which will not be repeated here.
[0231] S514, the UDM network element saves the identifier of the SMF network element.
[0232] Among them, S513 is an optional step. When the UDM network element learns that the UE authentication is successful, S513 is executed. Otherwise, if the UDM network element learns that the UE authentication fails, the UDM network element can release the identifier of the SMF network element received in advance.
[0233] S515, the UDM network element sends the UE's session subscription information to the SMF network element.
[0234] S516, the SMF network element generates a session context for the UE.
[0235] The UDM network element can send the UE's session subscription information to the SMF network element based on the identifier of the SMF network element saved in S514, so that the SMF network element can generate the UE's session context accordingly. The specific implementation can also refer to the relevant introduction in the first possible design scheme mentioned above, which will not be repeated here.
[0236] It can also be understood that the embodiment of the present application does not limit the triggering timing of S515. The UDM network element can trigger S515 at any possible time after the UE authentication is passed, without specific limitation.
[0237] S517, the AUSF network element sends authentication message #4 to the SMF network element.
[0238] S518, the SMF network element sends PFCP notification report message #4 to the UPF network element.
[0239] The authentication message #4 and the PFCP notification report message #4 may include an EAP success message and the UE's security key. For specific implementation, please refer to the above description of S404 and will not be repeated here.
[0240] In addition, the execution order between S514 to S516 and S517 is not limited.
[0241] S519, the UPF network element sends an IKE authentication response message #2 to the UE.
[0242] IKE Authentication Response Message #2 is a response message to IKE Authentication Request Message #2. The IKE Authentication Response Message may include an EAP Success message to inform the UE that the UE has successfully authenticated. The UE can then establish an IPSec secure connection with the UPF network element using the security key. For details on how to do this, refer to the description of S405 above and will not be repeated here.
[0243] S520, the UDM network element obtains the identifier of the AMF network element.
[0244] S521, the UDM network element sends the AMF network element identifier to the SMF network element.
[0245] S522, the SMF network element sends the UE's mobility management information to the AMF network element.
[0246] The AMF network element is the AMF network element that the UE registers when accessing through 3GPP. The specific implementation of S520-S522 can refer to the relevant introduction of the second possible design scheme mentioned above, which will not be repeated here. Of course, S520-S522 are optional steps. For example, they can be replaced by UDM network elements or the UE mobility management information can be sent directly to the AMF network element. The specific implementation can refer to the relevant introduction of the third possible design scheme mentioned above, which will not be repeated here.
[0247] Scenario 2:
[0248] Figure 6 is a flow chart of the communication method provided in the embodiment of the present application. The communication method is applicable to the above communication system, and mainly involves the interaction between UE, x device, UPF network element, SMF network element, AUSF network element / UDM network element, etc.
[0249] In scenario 2, the UE and device x are different devices. Device x can pre-configure / obtain the IP address of the UPF network element. Therefore, when device x accesses 5GC via a non-3GPP network, it can communicate directly with the UPF network element using the UPF network element's IP address without requiring NAS interaction. The UPF network element instructs the SMF network element to trigger the AUSF network element to authenticate the device x, establishing a secure channel between the device x and the UPF network element. However, device x cannot transmit user-plane data over this secure channel. Later, if the UE instructs the network to allow user-plane data transmission from device x, device x can transmit user-plane data over the secure channel with the UPF network element.
[0250] Specifically, as shown in FIG6 , the process of the communication method is as follows:
[0251] S600: The UDM network element configures the subscription data of the x device in the subscription data of the UE.
[0252] For example, the UE's subscription data may use a UE identifier, such as a SUPI, as an index to associate the UE's SUPI with the subscription data of the x-device. Specifically, the association may be with the user identifier (User ID) of the x-device in the subscription data of the x-device, i.e., identification information of the user using the x-device, such as a username, account number, password, etc., or any other possible identifier, without specific limitation. The user identifier of the x-device may be associated with other data in the subscription data of the x-device, such as the device identifier of the x-device, i.e., used to identify the x-device itself, an access technology indicator (e.g., non-3GPP access and / or 3GPP access), an authentication vector, a PDU session type, a DNN, QoS parameters, a charging policy, etc.
[0253] It is understood that the user identifier of device x and / or the device identifier of device x can be collectively expressed as the NAI of device x. The NAI of device x mentioned below, unless otherwise specified, can be understood as the user identifier of device x and / or the device identifier of device x.
[0254] The above parameters are used to represent the corresponding contract data when this User ID accesses 5GC.
[0255] S601, device x accesses through the user plane and performs authentication.
[0256] It can be understood that S601 is to execute the above-mentioned S500a-S522, that is, the UE in Figure 5 is replaced with the x device in Figure 6, and the contract data of the UE is replaced with the contract data of the x device. For details, please refer to the relevant introduction of Figure 5 and will not be repeated here.
[0257] S602: The UDM network element marks the x device as being in a connected state.
[0258] The UDM network element may mark the x device as being in a connected state in the subscription data of the x device.
[0259] The connection state indicates that the x device has established a connection with the network, but the network cannot transmit the user plane data of the x device, that is, the user plane data of the x device can be truncated or discarded by the UPF network element. For details, please refer to the relevant introduction of the second possible design scheme, which will not be repeated here.
[0260] Afterwards, the UE can activate the x device on the network side. This can be achieved through two methods: S603-S608 and S609-S617, which are introduced below.
[0261] S603: The UE obtains the NAI of the device x.
[0262] This embodiment of the application does not limit how the UE obtains the NAI of device x. For example, the UE can obtain the NAI of device x by scanning the device's QR code, or the user can directly enter the NAI of device x on the UE, such as a user name, account number, or password.
[0263] S604: The UE sends a NAS message to the AMF network element.
[0264] The AMF network element is the AMF network element serving the UE. The NAS message carries the UE identifier and the NAI of the x-device, indicating that the network needs to activate the x-device. The NAS message can be an uplink NAS transport message or any other NAS message, without limitation.
[0265] S605: The AMF network element sends the UE identifier and the NAI of the x device to the UDM network element.
[0266] The UE identifier and the NAI of the x device may be carried in any possible message sent by the AMF network element to the UDM network element, without any specific limitation.
[0267] It can be understood that the above S604-S605 is one implementation, and the NAI of device x can also be passed to the UDM network element through SMF network element #1. For example, SMF network element #1 is the SMF network element serving the UE. The UE sends a PDU session establishment or update request message carrying the UE identifier and the NAI of device x to the SMF network element. The PDU session establishment or update request message can be first passed to the AMF network element by carrying a NAS message. The AMF network element sends the PDU session establishment or update request message to SMF network element #1. After that, SMF network element #1 sends the UE identifier and the NAI of device x to the UDM network element.
[0268] S606: The UDM network element marks the x device as being in an activated state.
[0269] The activated state indicates that the x device has established a connection with the network, and the network can transmit user plane data of the x device. For details, please refer to the relevant introduction of the second possible design solution, which will not be repeated here.
[0270] The UDM network element can query the UE's subscription data based on the UE identifier obtained from the AMF network element or SMF network element #1, and further query the subscription data of the x device from the UE's subscription data based on the NAI of the x device obtained from the AMF network element or SMF network element #1. In this way, the UDM network element can determine that the x device needs to be activated based on the NAI of the x device provided by the UE, and thus mark the x device as activated in the subscription data of the x device, so that subsequent services can be carried out.
[0271] S607, the UDM network element sends a session context update request (Update SM context) message to the SMF network element #2.
[0272] SMF network element #2 is the SMF network element serving device x. The context update request message carries the NAI of device x and, optionally, user plane activation indication information. This user plane activation indication information can be used to indicate that user plane data of device x can be transmitted. The UDM network element can obtain the identity of SMF network element #2 from the subscription data of device x and send a session context update request message to SMF network element #2.
[0273] S608, SMF network element #2 sends a PFPC update message to the UPF network element.
[0274] The PFPC update message carries the NAI of the x device and, optionally, may also carry user plane activation indication information.
[0275] Based on the received NAI of device x, SMF network element #2 can search the session context of device x and determine the UPF network element connected to device x. SMF network element #2 then sends a PFPC update message to the UPF network element. At this point, the UPF network element can determine that device x is activated based on the NAI of device x and the user plane activation indication information, and allow service data packets from device x, i.e., user plane data, to pass through. For example, the UPF network element can forward data packets from device x to other UPF network elements / devices, or send them to the DN via the N6 interface. In other words, if device x has not yet been successfully activated, such as when a secure channel has been established between the UPF network element and device x, the UPF network element will not forward service data packets from device x. Even if data packets are received, they will be stored or discarded.
[0276] Optionally, the user plane activation indication information is optional. For example, the UPF network element can activate the x device by default based on the NAI of the x device received from the SMF network element #2.
[0277] S609: The UDM network element sends an AF request message #1 to the AF.
[0278] AF Request Message #1 can carry the NAI of device x and information indicating that the device is in a connected state (referred to as a status indication), jointly indicating that device x is in a connected state. Based on AF Request Message #1, the AF can mark the state of device x as connected. The UDM network element can send AF Request Message #1 directly to the AF, or it can send AF Request Message #1 to the AF through an NEF network element.
[0279] It can be understood that AF request message #1 is an exemplary name and can also be replaced by any possible message.
[0280] S610, the AF sends an AF response message #1 to the UDM network element.
[0281] The AF response message #1 may respond to the AF request message #1, indicating that the AF has successfully stored the status of the x device.
[0282] It can be understood that AF response message #1 is an exemplary name and can also be replaced by any possible message.
[0283] S611: UE obtains the NAI of device x.
[0284] This embodiment of the application does not limit how the UE obtains the NAI of device x. For example, the UE can obtain the NAI of device x by scanning the device's QR code, or the user can directly enter the NAI of device x on the UE, such as a user name, account number, or password.
[0285] S612: The UE sends an APP message to the AF.
[0286] The AF is an AF serving the x device, such as an AF related to the service of the x device, or in other words, an AF providing the service of the x device.
[0287] The APP message carries the UE identifier (e.g., the UE's external identifier, such as a generic public subscription identifier (GPSI), which may be the UE's telephone number, such as a mobile station international ISDN number (MSISDN)), the NAI of the x device, and activation indication information #1. Activation indication information #1 may be used to indicate the activation state. That is, the AF may mark the state of the x device as activated based on the NAI of the x device and activation indication information #1.
[0288] S613: The AF sends an AF request message #2 to the UDM network element.
[0289] The AF request message #2 may include the UE identifier, the NAI of the x device, and activation indication information #2. The activation indication information #2 may be used to indicate the activation state and may have the same function as the activation indication information #2.
[0290] S614, the UDM network element sends an AF response message #2 to the AF.
[0291] The AF response message #2 may respond to the AF request message #2, indicating that the UDM network element has successfully stored the status of the x device.
[0292] It can be understood that AF response message #2 is an exemplary name and can be replaced by any possible message.
[0293] S615: The UDM network element marks the x device as being in an activated state.
[0294] The UDM network element can query the UE's subscription data based on the UE identifier in the AF request message #2, and further query the subscription data of the x device from the UE's subscription data based on the NAI of the x device in the AF request message #2. The UDM network element determines that the x device needs to be activated based on the activation indication information #2 in the AF request message #2, thereby marking the x device as activated in the subscription data of the x device so that subsequent services can be carried out.
[0295] It can be understood that AF response message #2 is an exemplary name and can be replaced by any possible message.
[0296] S616, the UDM network element sends a session context update request message to the SMF network element #2.
[0297] S617, SMF network element #2 sends a PFPC update message to the UPF network element.
[0298] Among them, S616-S617 can refer to the relevant introduction of S607-S608 above, which will not be repeated here.
[0299] It is understood that the above steps S600-S617 can also be summarized as the following process:
[0300] When the authentication process of the first terminal (x device) passes, the data management network element (UDM network element) adjusts the state of the first terminal to the connected state.
[0301] The data management network element can receive the identifier (NAI) of the first terminal sent by the second terminal (UE); the data management network element can determine whether the subscription data of the second terminal contains the subscription data of the first terminal based on the identifier of the first terminal; if the subscription data of the second terminal contains the subscription data of the first terminal, the data management network element adjusts the status of the first terminal to an activated state. The data management network element can send user plane activation indication information to the session management network element (SMF network element #2); the session management network element can receive user plane activation indication information from the data management network element; the session management network element can send user plane activation indication information to the user plane network element (UPF network element); the user plane network element can receive user plane activation indication information from the session management network element; in response to the user plane activation indication information, the user plane network element can transmit the user plane data of the first terminal through a user plane secure connection.
[0302] Optionally, the data management network element receives the identifier of the first terminal sent by the second terminal from the access and mobility management network element (AMF network element #1) or application function (AF) serving the second terminal.
[0303] Scenario 3:
[0304] Figure 7 is a flow chart 4 of the communication method provided in an embodiment of the present application. The communication method is applicable to the above communication system, and mainly involves the interaction between UE, x device, UPF network element, SMF network element, AUSF network element / UDM network element, etc.
[0305] In scenario 3, the UE and the x-device are different devices. The x-device can pre-configure / obtain the UPF network element's IP address and security vector through the UE. This allows the x-device to access the 5GC via a non-3GPP protocol without requiring NAS interaction. Instead, it can directly communicate with the UPF network element using the UPF network element's IP address. The UPF network element instructs the SMF network element to trigger the AUSF network element to authenticate the x-device. At this point, the x-device can authenticate the security vector previously obtained from the UE, thereby establishing a secure channel between the x-device and the UPF network element.
[0306] Specifically, as shown in FIG7 , the process of the communication method is as follows:
[0307] S700: The UDM network element configures the subscription data of the x device in the subscription data of the UE.
[0308] The specific implementation of S700 may refer to the related introduction of S600 above, which will not be repeated here.
[0309] S701: Device x establishes a connection with UE.
[0310] The x device can establish a connection with the UE through WLAN access technology or wired direct connection, which is not limited in this application.
[0311] S702: The UE obtains the NAI of device x.
[0312] This embodiment of the application does not limit how the UE obtains the NAI of device x. For example, the UE may obtain the NAI of device x by scanning the device's QR code, or the user may directly enter the NAI of device x, such as a user name, account number, or password, on the UE. Alternatively, the UE may obtain the NAI of device x by connecting to the device x. Alternatively, the NAI of device x may be preconfigured on the UE.
[0313] S703, the UE sends a NAS message to the AMF network element.
[0314] S704: The AMF network element sends the UE identifier and the NAI of the x device to the UDM network element.
[0315] The specific implementation of S703-S704 may refer to the related introduction of S604-S605 above, which will not be repeated here.
[0316] S705: The UDM network element marks the x device as being in a connected state.
[0317] The UDM network element can query the UE's subscription data based on the UE identifier, and further query the subscription data of device x from the UE's subscription data based on the NAI of device x obtained from the AMF network element or SMF network element #1. In this way, the UDM network element can determine that device x is connected to the UE based on the NAI of device x provided by the UE, and thus mark device x as connected in the subscription data of device x, indicating that device x is connected to the 5GC through the UE.
[0318] It can be understood that the following S706-S707 and S708-S710 can be an "or" relationship, that is, the UDM network element can send the UPF network element information and / or the configuration information of the x device to the UE through the control plane or the user plane respectively, which is described in detail below.
[0319] S706, the UDM network element sends the UPF network element information and / or the configuration information of the x device to the AMF network element.
[0320] The UPF network element information may include at least one of the UPF network element's fully qualified domain name (FQDN), the UPF network element's IP address, or the UPF network element's identifier. The x-device configuration information may include at least one of the x-device's NAI or security vector. The UDM network element may obtain the UPF network element information and the x-device configuration information by querying the x-device's subscription data.
[0321] The UDM network element can directly send the UPF network element information and / or the configuration information of the x device to the AMF network element, or the UDM network element can first send the UPF network element information and / or the configuration information of the x device to the SMF network element, and the SMF network element forwards the UPF network element information and / or the configuration information of the x device to the AMF network element, which can be carried in the corresponding message, without specific limitation.
[0322] S707: The AMF network element sends a NAS message to the UE.
[0323] The NAS message may be any possible NAS message, carrying information of the UPF network element and / or configuration information of the x device.
[0324] S708, the UDM network element sends the UPF network element information and / or the configuration information of the x device to the SMF network element.
[0325] Among them, the information of the UPF network element and / or the configuration information of the x device sent by the UDM network element to the SMF network element can be carried in any possible message sent by the UDM network element to the SMF network element, without specific limitation.
[0326] S709, the SMF network element sends the UPF network element information and / or the configuration information of the x device to the UPF network element.
[0327] Among them, the information of the UPF network element and / or the configuration information of the x device sent by the SMF network element to the UPF network element can be carried in any possible message sent by the SMF network element to the UPF network element, without specific limitation.
[0328] S710, the UPF network element sends the UPF network element information and / or the configuration information of the x device to the UE.
[0329] The UPF network element can send a PMF message to the UE through the UE's PDU session user plane channel. The PMF message includes at least one of the UPF network element information and the configuration information of the x device.
[0330] S711, the UE sends the UPF network element information and / or the configuration information of the x device to the x device.
[0331] The UE may send at least one of the information of the UPF network element and the configuration information of the X device to the X device through a connection with the X device.
[0332] S712, device x accesses the user plane and performs authentication.
[0333] It can be understood that S712 is to execute the above-mentioned S500a-S522, that is, the UE in Figure 5 is replaced by the x device in Figure 7, and the contract data of the UE is replaced by the contract data of the x device. For details, please refer to the relevant introduction of Figure 7 and will not be repeated here.
[0334] Afterwards, the UDM network element may mark the x device as being in an activated state and instruct the UPF network element. For details, please refer to the relevant introduction of S606 to S608 above, which will not be repeated here.
[0335] It is understandable that the above steps S700 to S712 can also be summarized as the following process:
[0336] The data management network element (UDM network element) may receive an identifier (NAI) of the first terminal (x device) sent by the second terminal (UE). Based on the identifier of the first terminal, the UDM network element may send at least one of the security vector of the first terminal (configuration information of the x device) and the address of the user plane network element (information of the UPF network element) to the second terminal.
[0337] For example, the data management network element may receive the identifier of the first terminal sent by the second terminal from an access and mobility management network element (AMF network element) serving the second terminal. The data management network element may determine, based on the identifier of the first terminal, whether the subscription data of the second terminal includes the subscription data of the first terminal. If the subscription data of the second terminal includes the subscription data of the first terminal, the data management network element may obtain at least one of a security vector and an address of a user plane network element from the subscription data of the first terminal. The data management network element may send at least one of the security vector and the address of the user plane network element to the second terminal. For example, the data management network element may send at least one of the security vector and the address of the user plane network element to the second terminal via the access and mobility management network element. Alternatively, the data management network element may send at least one of the security vector and the address of the user plane network element to the second terminal via a user plane network element (UPF network element).
[0338] Optionally, in response to receiving the identifier of the first terminal sent by the second terminal, the data management network element adjusts the state of the first terminal to a connected state.
[0339] The communication method provided in the embodiment of the present application is described in detail above in conjunction with Figures 4 to 7. The communication device for executing the communication method provided in the embodiment of the present application is described in detail below in conjunction with Figures 8 to 9.
[0340] Figure 8 is a structural diagram of a communication device according to an embodiment of the present application. As shown in Figure 8 , the communication device 800 includes a transceiver module 801 and a processing module 802. For ease of illustration, Figure 8 only shows the main components of the communication device.
[0341] The communication device 800 can be applied to the communication methods of Figures 4-7 to implement corresponding functions. For example, the transceiver module 801 can implement the transceiver functions of the communication methods of Figures 4-7, and the processing module 802 can implement other functions of the communication methods of Figures 5-7 except the transceiver functions.
[0342] Optionally, the transceiver module 801 may include a sending module (not shown in FIG8 ) and a receiving module (not shown in FIG8 ). The sending module is used to implement the sending function of the communication device 800 , and the receiving module is used to implement the receiving function of the communication device 800 .
[0343] Optionally, the communication device 800 may further include a storage module (not shown in FIG8 ) that stores a program or instruction. When the processing module 802 executes the program or instruction, the communication device 800 may perform the functions of the method shown in FIG4-FIG7 above.
[0344] It can be understood that the communication device 800 can be a network device, a chip (system) or other parts or components that can be set in the network device, or a device that includes a network device. This application does not limit this.
[0345] In addition, the technical effects of the communication device 800 can refer to the technical effects of the above-mentioned communication method, which will not be repeated here.
[0346] Figure 9 is a second structural diagram of a communication device provided in an embodiment of the present application. Exemplarily, the communication device may be a terminal, or a chip (system) or other component or assembly that can be provided in a terminal. As shown in Figure 9, the communication device 900 may include a processor 901. Optionally, the communication device 900 may further include a memory 902 and / or a transceiver 903. The processor 901 is coupled to the memory 902 and the transceiver 903, such as by a communication bus.
[0347] The following is a detailed introduction to the various components of the communication device 900 in conjunction with FIG9 :
[0348] The processor 901 is the control center of the communication device 900 and can be a single processor or a collective term for multiple processing elements. For example, the processor 901 can be one or more central processing units (CPUs), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0349] Optionally, the processor 901 may execute various functions of the communication device 900 by running or executing software programs stored in the memory 902 and calling data stored in the memory 902, such as executing the communication methods shown in Figures 4 to 7 above.
[0350] In a specific implementation, as an embodiment, the processor 901 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG. 9 .
[0351] In a specific implementation, as an embodiment, the communication device 900 may also include multiple processors, such as the processor 901 and the processor 904 shown in FIG9 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0352] The memory 902 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 901. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0353] Optionally, the memory 902 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 902 can be integrated with the processor 901 or exist independently and be coupled to the processor 901 through the interface circuit of the communication device 900 (not shown in Figure 9). This embodiment of the present application does not specifically limit this.
[0354] Transceiver 903 is used for communication with other communication devices. For example, if communication device 900 is a terminal, transceiver 903 can be used to communicate with a network device or another terminal device. For another example, if communication device 900 is a network device, transceiver 903 can be used to communicate with a terminal or another network device.
[0355] Optionally, the transceiver 903 may include a receiver and a transmitter (not shown separately in FIG9 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0356] Optionally, the transceiver 903 may be integrated with the processor 901 or exist independently and be coupled to the processor 901 through an interface circuit (not shown in FIG. 9 ) of the communication device 900 . This embodiment of the present application does not specifically limit this.
[0357] It is understandable that the structure of the communication device 900 shown in FIG9 does not constitute a limitation on the communication device, and an actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0358] In addition, the technical effects of the communication device 900 can refer to the technical effects of the methods described in the above method embodiments, and will not be repeated here.
[0359] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0360] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0361] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0362] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0363] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0364] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0365] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0366] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0367] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0368] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0369] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0370] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0371] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that: The method comprises: A user plane network element serving a first terminal receives information of the first terminal from the first terminal; The user plane network element determines, based on the information of the first terminal, a session management network element serving the first terminal, or / and determines a session between the user plane network element and the session management network element; The user plane network element sends the authentication information or the first information of the first terminal to the session management network element, or the user plane network element transmits the authentication information or the first information of the first terminal through the session; The session management network element receives the authentication information of the first terminal or the first information from the user plane network element, or the session management network element receives the authentication information of the first terminal or the first information transmitted by the session; The session management network element triggers authentication of the first terminal according to the authentication information of the first terminal or the first information; When the authentication of the first terminal is passed, the user plane network element establishes a secure channel with the first terminal.
2. The method according to claim 1, characterized in that The information of the first terminal includes at least one of address information of the first terminal, temporary identification information of the first terminal, permanent identification information of the first terminal, and service information of the first terminal.
3. The method according to claim 1, characterized in that The first information is first indication information, or the first information is permanent identification information of the first terminal or temporary identification information of the first terminal, and the first indication information is used to instruct the session management network element to initiate an authentication process for the first terminal.
4. The method according to claim 1 or 3, characterized in that The session management network element triggering authentication of the first terminal according to the first information includes: The session management network element sends the identification information of the first terminal to the authentication network element serving the first terminal; or the session management network element generates an EAP message, the EAP message includes the identification information of the first terminal, and the session management network element sends the EAP message to the authentication network element; The authentication network element receives the identification information of the first terminal from the session management network element, or the authentication network element receives the EAP message from the session management network element and obtains the identification information of the first terminal from the EAP message; The authentication network element obtains, according to the identification information of the first terminal, an authentication vector of the first terminal from a data management network element serving the first terminal; The authentication network element authenticates the first terminal according to the authentication vector; When the authentication network element successfully authenticates the first terminal, the authentication network element sends at least one of authentication success information and a security key to the session management network element; The session management network element receives at least one of the authentication success information and the security key from the authentication network element; At least one of the authentication success information and the security key sent by the session management network element to the user plane network element.
5. The method according to claim 4, characterized in that The method further comprises: The user plane network element receives at least one of the authentication success information and the security key from the session management network element; The user plane network element determines that the authentication of the first terminal is successful based on the authentication success information and at least one of the security key.
6. The method according to claim 5, characterized in that The user plane network element establishing a secure channel with the first terminal includes: The user plane network element uses the security key to establish a secure channel between the user plane network element and the first terminal.
7. The method according to any one of claims 1 to 6, characterized in that The user plane network element determines, based on the information of the first terminal, a session management network element serving the first terminal, including: The user plane network element obtains service information of the first terminal; The user plane network element selects a session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
8. The method according to any one of claims 1 to 6, characterized in that The user plane network element determines, based on the information of the first terminal, a session management network element serving the first terminal, including: The user plane network element determines the service information of the first terminal based on the configuration of the user plane network element, and selects a session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
9. The method according to claim 7 or 8, characterized in that The method further comprises: The user plane network element receives service information supported by at least one session management network element from the at least one session management network element, where the at least one session management network element includes a session management network element serving the first terminal.
10. A communication method, characterized in that: The method comprises: A user plane network element serving a first terminal receives information of the first terminal from the first terminal; The user plane network element determines, based on the information of the first terminal, a session management network element serving the first terminal, or / and determines a session between the user plane network element and the session management network element; The user plane network element sends the authentication information or the first information of the first terminal to the session management network element, or the user plane network element transmits the authentication information or the first information of the first terminal through the session, wherein the authentication information or the first information of the first terminal is used for authentication of the first terminal; When the authentication of the first terminal is passed, the user plane network element establishes a secure channel with the first terminal.
11. The method according to claim 10, characterized in that The information of the first terminal includes at least one of address information of the first terminal, temporary identification information of the first terminal, permanent identification information of the first terminal, and service information of the first terminal.
12. The method according to claim 10, characterized in that The first information is first indication information, or the first information is permanent identification information of the first terminal or temporary identification information of the first terminal, and the first indication information is used to instruct the session management network element to initiate an authentication process for the first terminal.
13. The method according to claim 10 or 12, characterized in that The method further comprises: The user plane network element receives at least one of authentication success information and a security key from the session management network element, where the security key is a key determined in the authentication process of the first terminal; The user plane network element determines that the authentication of the first terminal is successful based on the authentication success information and at least one of the security key.
14. The method according to claim 13, characterized in that The user plane network element establishing a secure channel with the first terminal includes: The user plane network element uses the security key to establish a secure channel between the user plane network element and the first terminal.
15. The method according to any one of claims 10 to 14, characterized in that The user plane network element determines, based on the information of the first terminal, a session management network element serving the first terminal, including: The user plane network element obtains service information of the first terminal; The user plane network element selects a session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
16. The method according to any one of claims 10 to 14, characterized in that The user plane network element determines, based on the information of the first terminal, a session management network element serving the first terminal, including: The user plane network element determines the service information of the first terminal based on the configuration of the user plane network element, and selects a session management network element that supports the service information of the first terminal as the session management network element serving the first terminal.
17. The method according to claim 15 or 16, characterized in that The method further comprises: The user plane network element receives service information supported by at least one session management network element from the at least one session management network element, where the at least one session management network element includes a session management network element serving the first terminal.
18. A communication method, characterized in that: The method comprises: A session management network element serving a first terminal receives authentication information or first information of the first terminal from a user plane network element serving the first terminal, or the session management network element receives authentication information or first information of the first terminal transmitted through a session between the user plane network element and the session management network element; The session management network element triggers authentication of the first terminal according to the authentication information of the first terminal or the first information.
19. The method according to claim 18, characterized in that The first information is first indication information, or the first information is permanent identification information of the first terminal or temporary identification information of the first terminal, and the first indication information is used to instruct the session management network element to initiate an authentication process for the first terminal.
20. The method according to claim 18 or 19, characterized in that The session management network element triggering authentication of the first terminal according to the first information includes: The session management network element sends the identification information of the first terminal to the authentication network element serving the first terminal; or the session management network element generates an EAP message and sends the EAP message to the authentication network element, wherein the EAP message includes the identification information of the first terminal; wherein the identification information of the first terminal is used to trigger the authentication network element to authenticate the first terminal; When the authentication network element successfully authenticates the first terminal, the session management network element receives at least one of the authentication success information and a security key from the authentication network element; the security key is a key determined in the authentication process of the first terminal; At least one of the authentication success information and the security key sent by the session management network element to the user plane network element.
21. The method according to any one of claims 18 to 20, characterized in that The method further comprises: The session management network element sends service information supported by the session management network element to the user plane network element.
22. A communication device, characterized in that: The apparatus comprises: a module for performing the method according to any one of claims 1-21.
23. A communication device, characterized in that: The communication device comprises: a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the communication device executes the method according to any one of claims 1 to 21.
24. A communication system, characterized in that: The system includes at least one of the following: a user plane network element for executing the method according to any one of claims 10 to 17, and a session management network element for executing the method according to any one of claims 18 to 21.
25. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a computer program or instructions, which, when executed on a computer, causes the computer to perform the method according to any one of claims 1 to 21.
26. A computer program product, characterized in that The computer program product comprises a computer program or instructions, which, when executed on a computer, causes the computer to perform the method according to any one of claims 1 to 21.
Citation Information
Patent Citations
Communication method and device
CN120456017A
Terminal authentication method and device and storage medium
CN114615665A
Communication method and device
CN116939588A