Communication method and related apparatus

By performing refined authentication of target objects on the UE through the AAA server, the problem of insufficient DN access security in scenarios where the UE is associated with multiple users is solved. Secondary authentication of target objects is achieved, ensuring that only authorized objects can access the DN, thereby improving security.

WO2025167627A1PCT designated stage Publication Date: 2025-08-14HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/073874
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-08
Filing Date
2025-01-22
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Existing technologies cannot effectively guarantee the security of data network (DN) access in scenarios where user equipment (UE) is associated with multiple users. Existing secondary authentication methods cannot ensure the security of unauthorized UE access to DN.

Method used

The AAA server performs refined authentication of target objects, including secondary authentication of accounts, applications or connected devices on the UE, uses the target identifier to determine whether access to the DN is allowed, and triggers the secondary authentication process by combining subscription data and association policies to ensure that only objects that pass authentication can access the DN.

Benefits of technology

This enhances the security of accessing the DN, ensuring that only authorized objects can access the data network and preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025073874_14082025_PF_FP_ABST
    Figure CN2025073874_14082025_PF_FP_ABST
Patent Text Reader

Abstract

A communication method and a related apparatus, which relate to the technical field of communications. The method comprises: receiving first request information, wherein the first request information is used for indicating any one of a PDU session establishment request, a PDU session modification request or an authentication request; a target object comprises any one of a first user, a first device and a first application; and the first request information further comprises first indication information, the first indication information is used for indicating a target identifier of the target object, and the target identifier of the target object is used for determining whether to perform secondary authentication on the target object. Therefore, an AAA server can perform authentication on the target object, thereby ensuring that only the target object passing the authentication can access a DN, and thus improving the security of accessing the DN.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and related device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on February 8, 2024, with application number 202410179410.0 and application name “Communication Methods and Related Devices”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a communication method and related devices. Background Art

[0003] In fifth-generation (5G) communication systems, when a user equipment (UE) registers with the network, it needs to perform initial authentication with the authentication server function (AUSF) based on the network access credentials. After the UE registers with the network, it can also access the data network (DN) by establishing a protocol data unit (PDU) session. During the UE's PDU session, the authentication, authorization, and accounting (AAA) server (AAA server) authenticates the UE, which can be called secondary authentication.

[0004] The purpose of secondary authentication is to ensure network security and prevent unauthorized UEs from accessing the DN. However, in scenarios where a UE is associated with multiple users, existing solutions cannot guarantee the security of accessing the DN. Summary of the Invention

[0005] An embodiment of the present application provides a communication method and related devices, which enable the AAA server to authenticate the target object (for example, an account on the UE, an application on the UE, or a device connected to the UE), thereby ensuring that only the target object that has passed the authentication can access the DN, thereby improving the security of access to the DN.

[0006] In this application, "DN receiving information" can be understood as the AAA server receiving information. "DN sending information" can be understood as the AAA server sending information. "DN performing secondary authentication" can be understood as the AAA server performing secondary authentication. It should be understood that this application does not limit the format for storing authentication results; for example, it can be a table, data structure, etc. For example, in this application, the first authentication result can be a first authentication result table, and the second authentication result can be a second authentication result table.

[0007] In the first aspect, an embodiment of the present application provides a communication method, which can be executed by a network unit (communication device). The network unit can be a device, or a chip (system) or circuit for a device, and this application does not limit this. The network unit receives a first request message, and the first request message is used to indicate any one of a PDU session establishment request (the target object requests to establish a PDU session), a PDU session modification request (the target object requests to modify a PDU session), or an authentication request (the target object requests the AAA server to authenticate it). The target object includes any one of a first user, a first device, and a first application. Therefore, the first request message also includes a first indication message, and the first indication message is used to indicate a target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0008] In an embodiment of the present application, the network unit can be an SMF or a DN (AAA server). When the network unit receives the first request information, it can determine whether to perform secondary authentication on the target object based on the target identifier of the target object. When it is determined that the target object is to be secondary authenticated, the secondary authentication process is triggered, and when the authentication is successful, a target PDU session is established or the target PDU session is modified. The above-mentioned target PDU session is used to connect the UE and the DN. The above-mentioned target object is associated with the UE, including any one of the first user, the first device and the first application. Among them, the UE can be understood as a user device accessing the 3GPP network. When the target object is the first user, the first user can be an account on the UE. When the target object is the first device, the first device can be a non-3GPP device connected to the UE (or an external device of the UE). When the target object is the first application, the first application can be an application on the UE. Therefore, the embodiment of the present application can determine whether the target object can access the DN by performing secondary authentication on the target object, thereby preventing unauthorized target objects from accessing the DN, thereby improving the security of accessing the DN.

[0009] In one possible implementation, when the first request information indicates a PDU session establishment request or a PDU session modification request, the network unit is an SMF. Accordingly, the target identifier of the target object includes a user identifier (User ID) of the target object and / or an EAP ID of the target object.

[0010] When the target trigger condition is met, the above-mentioned SMF sends a second request message, and the second request message is used to request authentication information about the target object from the UE, and the authentication information is used for the AAA server to perform secondary authentication on the target object. The above-mentioned target trigger condition includes a first trigger condition and a second trigger condition. Among them, the first trigger condition is used to determine whether it is necessary to perform secondary authentication on the target object, for example, it can be based on the subscription data of the target object or the association policy of the DN. The second trigger condition is used to determine whether to perform secondary authentication, for example, it can be judged by the existing authentication result (first authentication result) whether the target object has been successfully authenticated, and it will be secondary authenticated if the authentication result of the target object is a failure. For another example, if the first request is used to indicate the establishment of a PDU session, the target object is secondary authenticated.

[0011] In the above embodiment, the network unit is SMF, the first request information is used to indicate a PDU session establishment request or a PDU session modification request, and the target identifier of the target object includes the User ID of the target object and / or the EAP ID of the target object. When the SMF determines that a secondary authentication of the target object is required based on the subscription data of the target object or the association policy of the DN, the SMF further determines whether to perform a secondary authentication of the target object based on the target identifier. For example, when the first authentication result indicates that the authentication result corresponding to the target identifier is failed, the authentication result corresponding to the target identifier does not exist in the first authentication result, or when the first request information is used to indicate a PDU session establishment request, the target object is secondary authenticated. The first authentication result includes the authentication result corresponding to the User ID and / or the authentication result corresponding to the EAP ID. The authentication result includes success or failure, and the authentication result of failure can also be understood as invalidation, disallowance, or the first authentication result does not include the authentication result of the target object.

[0012] In this embodiment, when the first request is used to indicate a PDU session establishment request and the target identifier of the target object satisfies the first trigger condition, a secondary authentication can be performed on the target object, thereby ensuring the security of the target object's access to the DN. When the first request is used to indicate a PDU session modification request and the target identifier of the target object satisfies the first trigger condition, by determining whether the authentication result corresponding to the target identifier of the target object in the first authentication result is a failure, or by determining whether there is an authentication result corresponding to the target identifier of the target object in the first authentication result, it is determined whether a secondary authentication should be performed on the target object, thereby also ensuring the security of the target object's access to the DN.

[0013] In another possible implementation, the SMF receives first response information to the second request information.

[0014] This implementation includes two cases:

[0015] Case 1: The target identifier of the target object indicated by the first indication information is the user identifier of the target object. In this case, the first response information includes the EAP ID of the target object.

[0016] Case 2: The target identifier of the target object indicated by the first indication information is the user identifier of the target object and the EAP ID of the target object. In this case, the first response information may not include the EAP ID of the target object.

[0017] In case one, whether to perform secondary authentication on the target object is determined based on the target object's user identifier. If the determination result is that the target object is to be secondary authenticated, the SMF then requests the UE for relevant information for secondary authentication (e.g., the target object's EAP ID). This avoids the situation where secondary authentication is not required for the target object but the relevant information for authentication is carried, thereby reducing the overhead of transmission resources. In case two, the first request message includes the target object's user identifier and EAP ID, which can implement multiple methods for determining whether to perform secondary authentication on the target object, such as querying the first authentication result based on the target object's user identifier. Another example is querying the first authentication result based on the EAP ID. If the determination result is that the target object is to be secondary authenticated, the SMF does not need to request the target object's EAP ID from the UE and can directly use the EAP ID carried in the first request message for secondary authentication, thereby increasing the authentication speed.

[0018] Optionally, the first response information also includes an authentication algorithm, etc.

[0019] In another possible implementation, the first authentication result further includes an authentication result corresponding to the EAP ID, and the second trigger condition further includes that the authentication result corresponding to the EAP ID of the target object in the first authentication result is failure.

[0020] In this embodiment of the present application, the first authentication result also includes the authentication result corresponding to the EAP ID. Based on the authentication result corresponding to the target object's EAP ID, a determination can be made as to whether to perform secondary authentication on the target object. For example, if the authentication result corresponding to the target object's EAP ID is a failure, secondary authentication of the target object is performed. For another example, if the authentication result corresponding to the target object's EAP ID is a success, secondary authentication is not required, and the target object is allowed access to the DN.

[0021] In another possible implementation, when the first request information indicates an authentication request, the network element is an AAA server, and the target identifier of the target object includes the target object's user identifier and the target object's EAP ID. In this case, the AAA server stores a second authentication result for the target PDU session, which includes an authentication result corresponding to the user identifier and / or an authentication result corresponding to the EAP ID. Therefore, upon receiving the first request information, the AAA server can determine whether to perform a second authentication on the target object based on the target object's user identifier and / or the target object's EAP ID. For example, if the authentication result corresponding to the target object's EAP ID in the second authentication result is a failure, it indicates that a second authentication is required for the target object. For another example, if the authentication result corresponding to the target object's user identifier in the second authentication result is a failure, it indicates that a second authentication is required for the target object. Furthermore, if the AAA server determines that a second authentication is required for the target object, it sends a third request information, which instructs the SMF to further determine whether to perform a second authentication on the target object.

[0022] The first request information further includes a target PDU session identifier. The AAA server can determine the SMF associated with the EAP id based on the target PDU session identifier and send the third request information to the SMF.

[0023] The third request information includes the target PDU session identifier and the user identifier of the target object. Optionally, the third request information also includes the EAP ID of the target object.

[0024] In the embodiment of the present application, the AAA server receives the first request information and determines whether to perform secondary authentication on the target object based on the second authentication result, thereby providing more implementation methods for triggering secondary authentication of the target object. In addition, in the embodiment of the present application, the first request message received by the AAA server is transmitted via the application layer between the UE and the AAA server, thus reducing the pressure on core network transmission resources.

[0025] In another possible implementation, when the SMF receives the third request information, the SMF determines whether to perform a secondary authentication on the target object based on the subscription data of the target object and the user identifier of the target object, or the SMF determines whether to perform a secondary authentication on the target object based on the association policy of the DN and the user identifier of the target object.

[0026] Optionally, when the AAA server is located in the core network (e.g., the core network of the fifth generation mobile communication system (5GC)), the SMF determines whether to perform secondary authentication of the target object based on the target object's subscription data and the target object's user identity. When the AAA server is located outside the core network, the SMF determines whether to perform secondary authentication of the target object based on the association policy of the DN and the target object's user identity.

[0027] In another possible implementation, the AAA server receives a fourth request message requesting secondary authentication. In response, the AAA server sends a second response message to the fourth request message, the second response message indicating the authentication result of the secondary authentication. The fourth request message includes the target PDU session identifier and the EAP ID of the target object. The second response message includes the target PDU session identifier, the EAP ID of the target object, and the authentication result. The authentication result may be success or failure.

[0028] In the implementation manner of the present application, the AAA server receives the fourth request information and performs secondary authentication on the target object based on the EAP ID of the target object and related authentication information, so that the AAA server can perform secondary authentication on the target object, thereby improving the security of accessing the DN.

[0029] In another possible implementation, the AAA server updates the second authentication result based on the authentication result of the secondary authentication.

[0030] In the implementation manner of the present application, the AAA server updates the above-mentioned second authentication result based on the authentication result of the secondary authentication, so that the AAA server can determine whether to perform secondary authentication on the new target object based on the updated second authentication result, thereby ensuring that only the target object that has passed the authentication can access the DN, thereby improving the security of accessing the DN.

[0031] In another possible implementation, the SMF sends a fourth request message requesting secondary authentication. Accordingly, the SMF receives a second response message to the fourth request message, where the second response message indicates the authentication result of the secondary authentication. The fourth request message includes the target PDU session identifier and the EAP ID of the target object, and the second response message includes the target PDU session identifier, the EAP ID of the target object, and the authentication result of the secondary authentication.

[0032] In this embodiment of the present application, the fourth request information sent by the SMF includes the EAP ID of the target object, meaning that the SMF requests secondary authentication of the target object, thereby ensuring that only authenticated target objects can access the DN, thereby improving the security of access to the DN. Accordingly, the second response includes the target object's authentication result, indicating whether the target object is allowed to access the DN. For example, a successful authentication result indicates that the target object is allowed to access the DN. For another example, a failed authentication result indicates that the target object is not allowed to access the DN.

[0033] In another possible implementation, when the first request information is used to indicate a PDU session establishment request, the SMF creates a first authentication result based on the authentication result of the secondary authentication. When the first request information is used to indicate a PDU session modification request or an authentication request, the SMF updates the first authentication result based on the secondary authentication result.

[0034] In the implementation mode of the present application, SMF updates the above-mentioned first authentication result based on the authentication result of the secondary authentication, so that SMF can determine whether to perform secondary authentication on the new target object based on the updated first authentication result, thereby ensuring that only the target object that passes the authentication can access the DN, thereby improving the security of access to the DN.

[0035] In another possible implementation, when all authentication results included in the first authentication result are failures, the SMF releases the target session.

[0036] In the implementation manner of the present application, the first authentication result includes authentication results that are all failed, which is used to indicate that any target object associated with the target PDU session cannot access the DN. In this case, the target PDU session does not transmit data between the UE and the DN, and the idle session needs to be released in time.

[0037] On the second aspect, an embodiment of the present application provides a communication method, which can be executed by an SMF. The SMF can be a device, or a chip (system) or circuit for a device, and this application does not limit this. The SMF receives a first request message, and the first request message is used to indicate a PDU session establishment request (the target object requests to establish a PDU session) or a PDU session modification request (the target object requests to modify a PDU session). The target object includes any one of the first user, the first device, and the first application. Therefore, the first request message also includes a first indication message, and the first indication message is used to indicate the target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0038] In one possible implementation, when the target trigger condition is met, the SMF sends a second request message, and the second request message is used to request authentication information about the target object from the UE, and the authentication information is used for the AAA server to perform secondary authentication on the target object. The target trigger condition includes a first trigger condition and a second trigger condition. Among them, the first trigger condition is used to determine whether a secondary authentication of the target object is required, for example, it can be based on the subscription data of the target object or the association policy of the DN. The second trigger condition is used to determine whether a secondary authentication is required, for example, it can be determined by the existing authentication result (first authentication result) whether the target object has been successfully authenticated, and a secondary authentication is performed on the target object if the authentication result of the target object is a failure. For another example, if the first request is used to indicate the establishment of a PDU session, the target object is authenticated secondary.

[0039] In another possible implementation, the SMF receives first response information for the second request information. If the target identifier of the target object indicated by the first indication information is the user identifier of the target object, the first response information includes the EAP ID of the target object. If the target identifier of the target object indicated by the first indication information is the user identifier and EAP ID of the target object, the first response information may not include the EAP ID of the target object.

[0040] Optionally, the first response information also includes an authentication algorithm, etc.

[0041] In another possible implementation, the first authentication result further includes an authentication result corresponding to the EAP ID, and the second trigger condition further includes that the authentication result corresponding to the EAP ID of the target object in the first authentication result is failure.

[0042] In another possible implementation, when the SMF receives the third request information, the SMF determines whether to perform a secondary authentication on the target object based on the subscription data of the target object and the user identifier of the target object, or the SMF determines whether to perform a secondary authentication on the target object based on the association policy of the DN and the user identifier of the target object.

[0043] Optionally, when the AAA server is located in the 5GC, the SMF determines whether to perform secondary authentication on the target object based on the target object's subscription data and the target object's user identity. When the AAA server is located outside the 5GC, the SMF determines whether to perform secondary authentication on the target object based on the association policy of the DN and the target object's user identity.

[0044] In another possible implementation, the SMF sends a fourth request message requesting secondary authentication. Accordingly, the SMF receives a second response message to the fourth request message, where the second response message indicates the authentication result of the secondary authentication. The fourth request message includes the target PDU session identifier and the EAP ID of the target object, and the second response message includes the target PDU session identifier, the EAP ID of the target object, and the authentication result of the secondary authentication.

[0045] In another possible implementation, when the first request information is used to indicate a PDU session establishment request, the SMF creates a first authentication result based on the authentication result of the secondary authentication. When the first request information is used to indicate a PDU session modification request or an authentication request, the SMF updates the first authentication result based on the secondary authentication result.

[0046] In another possible implementation, when all authentication results included in the first authentication result are failures, the SMF releases the target session.

[0047] On the third aspect, an embodiment of the present application provides a communication method, which can be executed by an AAA server. The AAA server can be a device, or a chip (system) or circuit for a device, and this application does not limit this. The AAA server receives a first request message, and the first request message is used to indicate an authentication request (the target object requests the AAA server to authenticate it). The target object includes any one of the first user, the first device, and the first application. Therefore, the first request message also includes a first indication message, and the first indication message is used to indicate the target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0048] In one possible implementation, the target identifier of the target object includes a user identifier and an EAP ID of the target object. The AAA server stores a second authentication result for the target PDU session, where the second authentication result includes an authentication result corresponding to the user identifier and / or an authentication result corresponding to the EAP ID. Furthermore, if the AAA server determines that secondary authentication is required for the target object, it sends a third request message, which instructs the SMF to further determine whether to perform secondary authentication for the target object.

[0049] The first request information further includes a target PDU session identifier. The AAA server can determine the SMF associated with the EAP id based on the target PDU session identifier and send the third request information to the SMF.

[0050] The third request information includes the target PDU session identifier and the user identifier of the target object. Optionally, the third request information also includes the EAP ID of the target object.

[0051] In another possible implementation, the AAA server receives a fourth request message requesting secondary authentication. In response, the AAA server sends a second response message to the fourth request message, the second response message indicating the authentication result of the secondary authentication. The fourth request message includes the target PDU session identifier and the EAP ID of the target object. The second response message includes the target PDU session identifier, the EAP ID of the target object, and the authentication result. The authentication result may be success or failure.

[0052] In another possible implementation, the AAA server updates the second authentication result based on the authentication result of the secondary authentication.

[0053] In a fourth aspect, an embodiment of the present application provides a communication method, which can be executed by a UE. The UE can be a device, or a chip (system) or circuit for a device, and this application does not limit this. The UE sends a first request message, and the first request message is used to indicate any one of a PDU session establishment request (the target object requests to establish a PDU session), a PDU session modification request (the target object requests to modify a PDU session), or an authentication request (the target object requests the AAA server to authenticate it). The target object includes any one of a first user, a first device, and a first application. Therefore, the first request message also includes a first indication message, and the first indication message is used to indicate the target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0054] In another possible implementation, the UE further receives a second request message and returns a first response to the second request message. For example, when the SMF determines to perform secondary authentication on the target object, the SMF sends a second request message, and the corresponding UE receives the second request message, where the second request message is used to request authentication information about the target object from the UE. The UE sends a first response based on the second request message, where the first response includes authentication information related to the target object.

[0055] Optionally, the first response includes different content based on the target identifier of the target object in the first request information. For example, if the target identifier of the target object is the user identifier of the target object, the first response includes the EAP ID of the target object. For another example, if the target identifier of the target object is the user identifier of the target object and the EAP ID of the target object, the first response may not include the EAP ID of the target object.

[0056] The technical effects brought about by the above-mentioned second to fourth aspects and any possible implementation methods can refer to the introduction of the technical effects corresponding to the first aspect and the corresponding implementation methods.

[0057] In a fifth aspect, an embodiment of the present application provides a communication device, which includes a module or unit for executing any method described in the first aspect.

[0058] In one possible design, the apparatus includes:

[0059] The communication unit is used to receive a first request message, where the first request message is used to indicate any one of a PDU session establishment request (the target object requests to establish a PDU session), a PDU session modification request (the target object requests to modify a PDU session), or an authentication request (the target object requests the AAA server to authenticate it). The target object includes any one of a first user, a first device, and a first application. Therefore, the first request message also includes first indication information, where the first indication information is used to indicate a target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0060] The method performed by the above-mentioned communication unit can refer to the method corresponding to the above-mentioned first aspect, and will not be repeated here.

[0061] Regarding the technical effects brought about by the fifth aspect and any possible implementation method, please refer to the introduction of the technical effects corresponding to the first aspect and the corresponding implementation method.

[0062] In a sixth aspect, an embodiment of the present application provides a communication device, which includes a module or unit for executing the method as described in any one of the second aspects.

[0063] In one possible design, the apparatus includes:

[0064] A communication unit is configured to receive a first request message, wherein the first request message is configured to indicate a PDU session establishment request (the target object requests to establish a PDU session) or a PDU session modification request (the target object requests to modify a PDU session). The target object includes any one of the first user, the first device, and the first application. Therefore, the first request message also includes first indication information, wherein the first indication information is configured to indicate a target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0065] The method performed by the above-mentioned communication unit can refer to the method corresponding to the above-mentioned second aspect, which will not be repeated here.

[0066] Regarding the technical effects brought about by the sixth aspect and any possible implementation method, please refer to the introduction of the technical effects corresponding to the second aspect and the corresponding implementation method.

[0067] In a seventh aspect, an embodiment of the present application provides a communication device, which includes a module or unit for executing the method described in any one of the third aspects.

[0068] In one possible design, the apparatus includes:

[0069] The communication unit is configured to receive a first request message indicating an authentication request (a target object requests an AAA server to authenticate it). The target object includes any one of a first user, a first device, and a first application. Therefore, the first request message also includes first indication information indicating a target identifier of the target object, thereby indicating that the first request message is associated with the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0070] The method performed by the above-mentioned communication unit can refer to the method corresponding to the above-mentioned third aspect, which will not be repeated here.

[0071] Regarding the technical effects brought about by the seventh aspect and any possible implementation method, please refer to the introduction of the technical effects corresponding to the third aspect and the corresponding implementation method.

[0072] In an eighth aspect, an embodiment of the present application provides a communication device, which includes a module or unit for executing the method described in any one of the third aspects.

[0073] In one possible design, the apparatus includes:

[0074] A communication unit is used to send a first request message, where the first request message is used to indicate any one of a PDU session establishment request (the target object requests to establish a PDU session), a PDU session modification request (the target object requests to modify a PDU session), or an authentication request (the target object requests the AAA server to authenticate it). The target object includes any one of a first user, a first device, and a first application. Therefore, the first request message also includes first indication information, where the first indication information is used to indicate a target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0075] The method performed by the above-mentioned communication unit can refer to the method corresponding to the above-mentioned fourth aspect, which will not be repeated here.

[0076] Regarding the technical effects brought about by the eighth aspect and any possible implementation method, please refer to the introduction of the technical effects corresponding to the fourth aspect and the corresponding implementation method.

[0077] Optionally, in the communication device described in any one of the fifth to eighth aspects and any possible implementation manner:

[0078] In one implementation, the communication apparatus is a communication device. When the communication apparatus is a communication device, the communication unit may be a transceiver or an input / output interface; and the processing unit may be at least one processor. Alternatively, the transceiver may be a transceiver circuit. Alternatively, the input / output interface may be an input / output circuit.

[0079] In another implementation, the communication device is a chip (system) or circuit used in a communication device. When the communication device is a chip (system) or circuit used in a communication device, the communication unit may be a communication interface (input / output interface), interface circuit, output circuit, input circuit, pin, or related circuit on the chip (system) or circuit; and the processing unit may be at least one processor, processing circuit, or logic circuit.

[0080] In a ninth aspect, an embodiment of the present application provides a communication device, comprising a processor. The processor is coupled to a memory and can be configured to execute instructions in the memory to implement the method of any of the first to fourth aspects and any possible implementation methods described above. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, the processor being coupled to the communication interface.

[0081] In a tenth aspect, an embodiment of the present application provides a communication device, comprising: a logic circuit and a communication interface. The communication interface is configured to receive or send information; the logic circuit is configured to receive or send information via the communication interface, so that the communication device executes the method of any one of the first to fourth aspects and any possible implementation thereof.

[0082] In the eleventh aspect, an embodiment of the present application provides a computer-readable storage medium, which is used to store a computer program (also referred to as code, or instructions); when the computer program is run on a computer, the method of any one of the above-mentioned aspects from the first to the fourth aspect and any possible implementation method is implemented.

[0083] In the twelfth aspect, an embodiment of the present application provides a computer program product, which includes: a computer program (also referred to as code, or instructions); when the computer program is run, it enables the computer to execute any one of the above-mentioned aspects 1 to 4 and any possible implementation method.

[0084] In a thirteenth aspect, an embodiment of the present application provides a chip, comprising a processor configured to execute instructions. When the processor executes the instructions, the chip performs the method of any one of the first to fourth aspects and any possible implementation methods described above. Optionally, the chip further comprises a communication interface configured to receive or transmit signals.

[0085] In the fourteenth aspect, an embodiment of the present application provides a communication system, which includes at least one communication device as described in aspects four to eight, or the communication device described in aspect nine, or the communication device described in aspect ten, or the chip described in aspect thirteen.

[0086] In the fifteenth aspect, an embodiment of the present application provides a communication system, which includes at least one of a UE, an SMF, and an AAA server, the SMF being used to execute the method of the second aspect and any possible implementation method, the AAA server being used to execute the method of the third aspect and any possible implementation method, and the UE being used to execute the method of the fourth aspect and any possible implementation method.

[0087] In addition, in the process of executing the method described in any one of the first to fourth aspects and any possible implementation methods, the process of sending information and / or receiving information in the above method can be understood as the process of the processor outputting information and / or the process of the processor receiving input information. When outputting information, the processor can output the information to the transceiver (or communication interface, or sending module) so that it can be transmitted by the transceiver. After the information is output by the processor, it may also need to undergo other processing before it reaches the transceiver. Similarly, when the processor receives input information, the transceiver (or communication interface, or sending module) receives the information and inputs it into the processor. Furthermore, after the transceiver receives the information, the information may need to undergo other processing before it is input into the processor.

[0088] Based on the above principles, for example, the sending of information mentioned in the above method can be understood as the processor outputting information. For another example, the receiving of information can be understood as the processor receiving input information.

[0089] Optionally, for the operations such as transmission, sending and receiving involved in the processor, if there is no special explanation, or if they do not conflict with their actual functions or internal logic in the relevant description, they can be more generally understood as processor output, reception, input and other operations.

[0090] Optionally, in the process of executing the method described in any aspect of the first to fourth aspects and any possible implementation method, the processor may be a processor specifically used to execute these methods, or a processor that executes these methods by executing computer instructions in a memory, such as a general-purpose processor. The memory may be a non-transitory memory, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or may be separately provided on different chips. The embodiments of the present application do not limit the type of memory and the configuration of the memory and the processor.

[0091] In a possible implementation, the at least one memory is located outside the device.

[0092] In yet another possible implementation, the at least one memory is located within the device.

[0093] In another possible implementation, part of the at least one memory is located inside the device, and another part of the memory is located outside the device.

[0094] In this application, the processor and the memory may also be integrated into one device, that is, the processor and the memory may also be integrated together. BRIEF DESCRIPTION OF THE DRAWINGS

[0095] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0096] FIG1 is a schematic diagram of a network service architecture of a 5G mobile communication system provided in an embodiment of the present application;

[0097] FIG2 is a schematic diagram of a roaming architecture for home access roaming provided in an embodiment of the present application;

[0098] FIG3 is a schematic diagram of a roaming architecture for local access roaming provided in an embodiment of the present application;

[0099] FIG4 is a schematic diagram of URSP matching provided in an embodiment of the present application;

[0100] FIG5 is a flow chart of a communication method provided in an embodiment of the present application;

[0101] FIG6 is a flow chart of another communication method provided in an embodiment of the present application;

[0102] FIG7 is a flow chart of another communication method provided in an embodiment of the present application;

[0103] FIG8 is a flow chart of another communication method provided in an embodiment of the present application;

[0104] FIG9 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0105] FIG10 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0106] FIG11 is a schematic diagram of the structure of a chip provided in an embodiment of the present application. DETAILED DESCRIPTION

[0107] In order to make the purpose, technical solutions and advantages of this application clearer, the embodiments of this application will be described below in conjunction with the drawings in the embodiments of this application.

[0108] The terms "first" and "second" in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units that are inherent to the process, method, product, or device.

[0109] The “embodiment” mentioned herein means that the specific features, structures or characteristics described in conjunction with the embodiment may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It can be understood explicitly and implicitly by those skilled in the art that in the various embodiments of the present application, unless otherwise specified and there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form a new embodiment according to their inherent logical relationship.

[0110] It should be understood that in the present application, "at least one (item)" refers to one or more, "more than one" refers to two or more, "at least two (items)" refers to two or three and more than three, and "and / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0111] It should be noted that in this application, "indication" can include direct indication, indirect indication, explicit indication, and implicit indication. When describing that a certain indication information is used to indicate A, it can be understood that the indication information carries A, directly indicates A, or indirectly indicates A.

[0112] In this application, the information indicated by the indication information is referred to as the information to be indicated. In specific implementations, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or an index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, where the other information is associated with the information to be indicated. Alternatively, only a portion of the information to be indicated can be indicated, while the rest of the information to be indicated is known or agreed upon in advance. For example, the indication of specific information can be achieved by using a pre-agreed (e.g., protocol-specified) order of the various information, thereby reducing indication overhead to a certain extent. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or transmission timing of these sub-information can be the same or different. The specific transmission method is not limited in this application. The transmission period and / or transmission timing of these sub-information can be pre-defined, for example, according to a protocol, or can be configured by the transmitting device sending configuration information to the receiving device.

[0113] It should be noted that in this application, "send" can be understood as "output" and "receive" can be understood as "input". "Send information to A", where "to A" only indicates the direction of information transmission, A is the destination, and does not limit "sending information to A" to direct transmission on the air interface. "Sending information to A" includes sending information directly to A, and also includes sending information indirectly to A through a transmitter, so "sending information to A" can also be understood as "outputting information to A". Similarly, "receiving information from A" indicates that the source of the information is A, including receiving information directly from A, and also including receiving information indirectly from A through a receiver, so "receiving information from A" can also be understood as "inputting information from A".

[0114] First, a brief introduction to the implementation environment and application scenarios of the embodiments of the present application is given.

[0115] The communication method provided in the embodiments of the present application can be applied to a communication system of the 3GPP access type, as well as a communication system of the non-3GPP access type.

[0116] Among them, 3GPP access types may include the following access technologies: Long Term Evolution (LTE) technology corresponding to 4G cellular networks, New Radio (NR) technology corresponding to 5G cellular networks, and satellite access methods defined by 3GPP (including low-orbit satellites, medium-orbit satellites, and synchronous satellites).

[0117] Exemplarily, FIG1 shows the interaction relationship between network functions (NFs) and entities and the corresponding interfaces using the network service architecture of a 5G mobile communication system as an example.

[0118] The network functions and entities included in the service-based architecture (SBA) of the 5G system mainly include: terminal equipment, access network (AN) or radio access network (RAN), UPF, AAA server, AMF, session management function (SMF), network exposure function (NEF), UDM, network storage function (NF repository function, NRF), time sensitive communication and time synchronization function (TSCTSF), application function (AF), PCF, binding support function (BSF), unified data repository function (UDR), operation administration and maintenance (OAM), AUSF (not shown in Figure 1), network slice selection function (NSSF) (not shown in Figure 1), network slice admission control function (NSACF) (not shown in Figure 1) and network slice selection authentication and authorization function (NSSAAF) (not shown in Figure 1), etc.

[0119] Among them, UE, (R)AN, UPF and DN are generally referred to as user plane network functions and entities (or user plane network elements or user plane channels), and the other parts are generally referred to as control plane network functions and entities (or control plane network elements). The control plane network element is defined by 3GPP as the processing function in a network. The control plane network element has 3GPP-defined functional behaviors and 3GPP-defined interfaces. NF can be a network element running on dedicated hardware, or a software instance running on dedicated hardware, or a virtual function instantiated on a suitable platform, such as being implemented on a cloud infrastructure.

[0120] The following is a detailed introduction to the main functions of each network element.

[0121] UE: terminal equipment, including but not limited to: user equipment, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal equipment, mobile terminal equipment, user terminal equipment, wireless communication equipment, user agent, user device, cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication function, computing device, processing device connected to a wireless modem, vehicle-mounted device, wearable device, terminal equipment in the Internet of Things, home appliances, virtual reality equipment, terminal equipment in the future 5G network or terminal equipment in the future evolved public land mobile network (PLMN), etc.

[0122] (R)AN: (R)AN can be either AN or RAN. Specifically, RAN can be various forms of radio access network equipment, such as base stations, macro base stations, micro base stations (also known as small stations), relay stations, access points, distributed unit-control units (DU-CU), etc. In addition, the above-mentioned base stations can also be wireless controllers in the cloud radio access network (CRAN) scenario, or relay stations, access points, vehicle-mounted devices, wearable devices, or network equipment in the future evolved public land mobile network (PLMN). (R)AN is mainly responsible for wireless resource management, quality of service (QoS) management, data compression and encryption, etc. on the air interface side. The AN may be a non-3GPP access network, such as a trusted non-3GPP access network (TNAN), a trusted WLAN access network (TWAN), a non-trusted non-3GPP wireless access network, a wired access network (WAN), or a wired 5G access network (W-5GAN). The access network device corresponding to the trusted non-3GPP access network may be a trusted non-3GPP gateway function (TNGF); the access network device corresponding to the trusted WLAN access network may be a trusted WLAN interworking function (TWIF); the access network device corresponding to the non-trusted non-3GPP access network may be a non-3GPP interworking function (N3IWF); and the access network device corresponding to the wired access network or the wired 5G access network may be a wired-access gateway function (W-AGF). In systems using different wireless access technologies, the names of devices with base station functions may vary. For example, in the fifth generation (5G) system, it is called gNB; in the LTE system, it is called evolved NodeB (eNB or eNodeB); in the third generation (3G) system, it is called Node B, etc.

[0123] UPF: User plane function, mainly responsible for user data processing (forwarding, receiving, billing, etc.). For example, UPF can receive user data from the data network (DN) and forward the user data to the terminal through the access network equipment. UPF can also receive user data from the terminal through the access network equipment and forward the user data to the DN. DN refers to the operator network that provides data transmission services to users. For example, the Internet Protocol (IP) Multimedia Service (IMS), the Internet, etc. DN can be an operator's external network or a network controlled by the operator, used to provide business services to the terminal. In the protocol data unit (PDU) session, the UPF directly connected to the DN through N6 is also called the protocol data unit session anchor (PSA).

[0124] AAA server is a server used to authenticate, authorize and account for the UE during the process of establishing / modifying a PDU session.

[0125] A DN is a network located outside of a carrier network. A carrier network can connect to multiple DNs, and a variety of services can be deployed on the DN, providing data and / or voice services to terminal devices. For example, a DN is the private network of a smart factory. Sensors installed in the workshop can be terminal devices. The DN houses a sensor control server, which provides services to the sensors. Sensors can communicate with the control server, receive instructions from the control server, and transmit collected sensor data to the control server based on the instructions. Another example is a DN that is a company's internal office network. An employee's mobile phone or computer can be a terminal device, allowing them to access information and data resources on the company's internal office network.

[0126] AMF: can also be called mobility management function, mobility management entity, access and mobility management device, access and mobility management entity. AMF entity can also be called access and mobility management function, access and mobility management device, access and mobility management network element, access management device, mobility management device, etc. It is a type of core network equipment, mainly used for mobility management and access management, etc. It can be used to implement other functions of the mobility management entity (MME) function except session management, such as lawful interception, or access authorization (or authentication), user equipment registration, mobility management, tracking area update process, reachability detection, selection of session management network element, mobile state transition management and other functions. For example, in 5G, the access and mobility management network element can be an access and mobility management function AMF network element. In future communications, such as 6G, the access and mobility management network element can still be an AMF network element, or have other names, which are not limited in this application. When the access and mobility management network element is an AMF network element, the AMF can provide Namf services.

[0127] SMF: Session Management Function, responsible for handling user services such as session establishment, modification, and release, as well as interaction with user plane functions. Specific functions include allocating Internet Protocol (IP) addresses to users and selecting the UPF that provides packet forwarding capabilities.

[0128] NEF: Network Exposure Function, responsible for exposing 5G network capabilities and events to the outside world and receiving relevant external information, allowing third-party applications and services to access and utilize 5G network functions and resources. It is responsible for handling the security authentication and authorization of third-party applications and services, ensuring that only authorized applications and services can access and utilize 5G network functions and resources.

[0129] UDM: Unified data management, user contract management, access authorization, authentication information generation, etc.

[0130] NRF network elements can be used to provide network element discovery capabilities, providing network element information corresponding to the network element type based on requests from other network elements. NRF also provides network element management services such as network element registration, update, and deregistration, as well as network element status subscription and push.

[0131] TSCTSF: Its main function is to associate the time synchronization service request of NF consumers with the AF session of PCF; detect the availability of 5GS bridge information of Ethernet and IP type PDU sessions reported by PCF, and realize deterministic forwarding management capabilities within the 5G system.

[0132] AF: Communicates application-side requirements to the network, such as QoS requirements or user status event subscriptions. The AF can be a third-party functional entity or an application server deployed by the operator. The UE can send requests to the AF to obtain specific applications and services.

[0133] PCF: Policy Control Function, responsible for generating UE access policies and QoS flow control policies. It makes decisions and adjusts network policies based on network operator policies and user needs. It dynamically adjusts policy rules based on different scenarios and requirements to meet the needs of different users and applications.

[0134] BSF: It can provide BSF service registration / deregistration / update, NRF connection detection, session binding information creation, UE information acquisition, and session binding information query for duplicate IP addresses.

[0135] UDR: Contains access functions for executing subscription data, policy data, application data, and other types of data.

[0136] OAM (Operation and Administration) refers to the division of network management tasks into three categories based on the actual needs of carriers' network operations: operations, administration, and maintenance. Operations primarily involve analysis, forecasting, planning, and configuration of daily network and service operations. Maintenance primarily involves day-to-day operational activities such as testing and troubleshooting the network and its services.

[0137] AUSF is used to perform the main authentication, that is, the authentication between the terminal device and the operator network. After the authentication service network element receives the authentication request initiated by the contracted user, it can authenticate and / or authorize the contracted user through the authentication information and / or authorization information stored in the unified data management network element, or generate the authentication and / or authorization information of the contracted user through the unified data management network element. The authentication service network element can feedback the authentication information and / or authorization information to the contracted user. In one implementation method, the authentication service network element can also be co-located with the unified data management network element. In a 5G communication system, the authentication service network element can be an authentication server function (AUSF) network element. In future communication systems, unified data management can still be an AUSF network element, or it can have other names, which are not limited in this application.

[0138] Among them, the functions of other network elements included in Figure 1 can be referred to the relevant descriptions in conventional technologies and will not be repeated here.

[0139] Optionally, the names of the network elements and the names of the interfaces between the network elements in Figure 1 are only examples. In a specific implementation, the names of the network elements or the interfaces between the network elements may be other names, or the network elements may be referred to as entities. This embodiment of the present application does not specifically limit this. All or part of the network elements in Figure 1 may be physical entity network elements or virtualized network elements, which is not limited here.

[0140] In Figure 1, Nnef, Nudm, Nnrf, Ntsctsf, Namf, Naf, Nsmf, Npcf, Nbsf, and Nudr are service-oriented interfaces provided by the NEF, UDM, NRF, TSCTSF, AMF, AF, SMF, PCF, BSF, and UDR, respectively, for invoking corresponding service-oriented operations. N1, N2, N3, N4, and N6 are interface serial numbers, and their meanings are as follows:

[0141] N1: The interface between AMF and terminal devices, which can be used to deliver NAS signaling (such as QoS rules from AMF) to terminal devices.

[0142] N2: The interface between AMF and access network equipment, which can be used to transmit radio bearer control information from the core network side to the access network equipment.

[0143] N3: The interface between the access network equipment and UPF, mainly used to transmit uplink and downlink user plane data between the access network equipment and UPF.

[0144] N4: The interface between SMF and UPF can be used to transmit information between the control plane and the user plane, including controlling the issuance of forwarding rules, QoS rules, traffic statistics rules, etc. for the user plane and reporting information to the user plane.

[0145] N6: Interface between UPF and DN, used to transmit uplink and downlink user data flows between UPF and DN.

[0146] Furthermore, the communication methods provided in the embodiments of the present application can be applied to both non-roaming and roaming communication systems. For non-roaming communication systems, reference is made to Figure 1 above. For roaming communication systems, reference is made to Figures 2 and 3 below. Optionally, the system in each scenario can be based on a service-based interface or a reference point. Detailed descriptions of the service-based interface and reference point systems can be found in the prior art and will not be repeated here.

[0147] The 3GPP standard defines two roaming modes for users to access a visited location, namely home-routed roaming and local breakout roaming.

[0148] In the roaming architecture, the functions of some network elements and some interfaces between network elements (N1, N2, N3, N4, and N6) can be found in the relevant description of the architecture shown in Figure 1 and will not be repeated here. The meanings of sequence numbers N5, N7, N8, N9, N10, N11, N15, N16, N20, N21, and N24 in the roaming architecture are as follows:

[0149] N5: The interface between AF and PCF, used for issuing application service requests and reporting network events.

[0150] N7: Interface between PCF and SMF, used to deliver PDU session granularity and service data flow granularity control policy.

[0151] N8: Interface between AMF and UDM, used by AMF to obtain access and mobility management related subscription data and authentication data from UDM, and AMF to register UE current mobility management related information with UDM.

[0152] N9: Used for user plane data forwarding between UPFs.

[0153] N10: Interface between SMF and UDM, used by SMF to obtain session management-related subscription data from UDM, and for SMF to register UE current session-related information with UDM.

[0154] N11: The interface between SMF and AMF, used to transmit PDU session tunnel information between AN and UPF, transmit control messages sent to UE, transmit radio resource control information sent to AN, etc.

[0155] N15: Interface between PCF and AMF, used to deliver UE policies and access control related policies.

[0156] N16: Interface between V-SMF and H-SMF.

[0157] N20: Interface between short messaging service function (SMSF) and AMF.

[0158] N21: Interface between SMSF and UDM.

[0159] N24: Interface between V-PCF and H-PCF.

[0160] In the roaming architecture, some network elements are divided into two parts. One part is located in the home public land mobile network (HPLMN), and the other part is located in the visited public land mobile network (VPLMN). When the terminal is in a roaming scenario, it can use the network elements deployed in the visited location and the home location to obtain the corresponding network services. For example, in Figure 2, the PCF is divided into V-PCF (i.e., the PCF in the visited location) and H-PCF (i.e., the PCF in the home location). Similarly, the SMF is divided into V-SMF and H-SMF.

[0161] See Figure 2 for the roaming architecture for home access roaming. In this roaming architecture, the AMF and H-SMF are located in the visited and home locations, respectively. Session management functions are performed by the home H-SMF, which supports interaction with the UDM / H-PCF. Furthermore, in real-world scenarios, the H-PCF to which the V-PCF connects and the H-PCF to which the H-SMF connects may not be the same PCF entity.

[0162] Figure 3 shows the roaming architecture for local access roaming. In this roaming architecture, both the AMF and SMF are located in the visited location. Session management functions are performed by the SMF in the visited location. Furthermore, in real-world scenarios, the V-PCF to which the AMF connects and the V-PCF to which the SMF connects may not be the same PCF entity. Figure 3 includes the SMSF. The SMSF communicates with the UDM via N21 and with the AMF via N20.

[0163] In addition, the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0164] Next, we introduce the relevant technical terms in this application:

[0165] 1. Initial authentication: In this application, initial authentication refers to the process of UE registering with the network. For example, the UE authenticates with the authentication server function (AUSF) or the authentication credential repository and processing function (ARPF) based on the network credentials. That is, the UE and the serving network perform two-way authentication and establish a non-access stratum (NAS) security context with the access and mobility management function (AMF).

[0166] 2. Network Slice Types and Characteristics: A physical network can be abstractly divided into multiple network slices, each of which forms an end-to-end logical network. Network slices are logically isolated and do not affect each other. Typically, network slices are categorized into various types to meet different communication requirements. These include, but are not limited to, enhanced mobile broadband (eMBB), massive machine type connection (mMTC), and ultra-high reliability and low latency connection (ultra-reliability and low latency connection (uRLLC). Different types of network slices have different network characteristics. For example, eMBB network slices are required to support high-bandwidth, low-latency services; mMTC network slices are required to support massive access with low bandwidth; and uRLLC slices are required to have high reliability and low latency. Therefore, supported application services, end-to-end latency, and maximum single-terminal data rate are all characteristic attributes of network slices, and these characteristics depend on the slice design.

[0167] 3. Single network slice selection assistance information (S-NSSAI) is used to uniquely represent a network slice.

[0168] 4. PDU Session: A session service that establishes PDU connectivity between the UE and the data network (DN), identified by a PDUSessionID. During the process of establishing a PDU session with the DN, the AAA server can authenticate the UE. This authentication is referred to as secondary authentication in this application. It should be noted that secondary authentication is an optional step during the PDU session establishment process.

[0169] 5. User Equipment Route Selection Policy (URSP): refers to the UE's routing policy, which is issued to the UE by the Policy Control Function (PCF) or generated based on the UE's local pre-definition. It is used to enable the UE to select matching network resources for the service / application, that is, to determine whether an application / service can be associated with an established PDU session, whether non-3GPP access can be used, or whether a new PDU session needs to be established.

[0170] The structure of URSP is shown in Table 1 below:

[0171] Table 1

[0172] URSP mainly includes the traffic descriptor (Trafficdescriptor) in Table 1 above and one or more route selection descriptors (RouteSelectionDescriptors, RSD) (displayed in bold). Among them, Trafficdescriptor is used to match with service information (application identifier or flow identifier or service identifier, etc.). For example, the terminal modem matches the application identifier (APPID) provided by the application layer with the traffic descriptors in each URSP rule according to the priority of the one or more URSP rules mentioned above from high to low. There are many types of Trafficdescriptors, such as Applicationdescriptors in Table 1 above (such as operating system identifier (OSId) + application identifier (OSAppId), for example, WeChat under the Android operating system can be expressed as android+com.wechat), IPdescriptors (such as the destination IP address corresponding to the initiated service).

[0173] Among them, the structure of RSD is shown in Table 2 below:

[0174] Table 2

[0175] RSD includes information such as DNN, S-NSSAI, and SSCmode.

[0176] 5. URSP matching: When the UE determines that a specific service / application needs to be initiated, it first matches the service / application to be initiated with the TrafficDescriptor in the URSP rule according to the priority order of the URSP rule.

[0177] If a specific URSP rule is matched (the URSP rule may also be a default URSP rule (also called a wildcard URSP rule), such as if TrafficDescriptor is in match-all form), the UE must also determine the slice S-NSSAI required for the service based on the current RSD of the URSP rule, and determine whether the slice S-NSSAI belongs to the AllowedNSSAI of the current network. Specifically, in a roaming scenario, the terminal needs to determine whether the slice S-NSSAI belongs to the current AllowedNSSAI of the visited network. In a non-roaming scenario, the terminal needs to determine whether the slice S-NSSAI is within the current AllowedNSSAI of the home network. If the S-NSSAI is not in the AllowedNSSAI, the UE will continue to match subsequent URSP rules or subsequent RSDs based on the URSP priority / RSD priority until it is determined that the slice S-NSSAI allowed for the service appears in the AllowedNSSAI and the slice S-NSSAI is accepted by the network side. For example, if the UE determines that the URSP rule corresponding to the application ID initiating the service is unavailable, it can continue matching the URSP rule with the lowest priority, i.e., the URSP rule whose Traffic Descriptor is in the match-all format as shown in Figure 4. The URSP rule that the UE ultimately matches is called the target URSP rule. The RSD that the UE ultimately matches is called the target RSD.

[0178] Next, the UE determines whether there is an existing PDU session that meets the definition of the target RSD.

[0179] If the DNN, S-NSSAI, SSCmode and other information corresponding to the existing PDU session are consistent with the information included in the target RSD, it means that the existing PDU session is consistent with the current service requirements. The UE can choose to initiate a PDU session modification request (for example, it can be PDUSessionModificationRequest) based on the existing PDU session, so as to establish a new quality of service flow (quality of service, QoS flow) on the existing PDU session and carry the service through the newly created QoS flow.

[0180] The PDU session modification request message can be carried by N1SMContainer. The PDU session modification request includes (or carries) PDUSessionID, packet filters, requested QoS parameters, etc. Among them, PDUSessionID is used by AMF to associate with the specific session context, and the terminal's N1SMContainer is transparently transmitted by AMF to SMF.

[0181] If the existing PDUSession(s) cannot match the RSD information of the URSP, the UE will initiate a PDU session establishment request for the service / application and carry the newly allocated PDUSessionID, DNN in the RSD, S-NSSAI, N1SMContainer (SSCmode, PDUSessionType) and other parameters in the session establishment request message. Among them, the newly allocated PDUSessionID is used to identify the PDU session corresponding to the PDU session establishment request, DNN+S-NSSAI is used as the parameter for the AMF to select the SMF entity for the PDU session establishment request, and N1SMContainer is transparently transmitted by the AMF to the selected SMF.

[0182] The UE modifies / establishes a PDU session to enable data communication between the UE and the DN. In some scenarios, in order to meet the DN's requirements for network security, the AAA server will authenticate the UE (called secondary authentication). Only when the secondary authentication is successful will the PDU session requested by the UE be established / modified. For example, the SMF uses the UE's device identifier (for example, the user permanent identifier (SUPI)) to query the subscription data from the unified data management (UDM). The SMF determines whether the UE's PDU session establishment request is allowed based on the contract data and local policy. If the UE's PDU session request is not allowed, the request is rejected through SM-NAS signaling, the process is terminated, and it is determined whether the UE is allowed to be secondary authenticated. When the UE's PDU session request is allowed and secondary authentication is required, the SMF also needs to check whether the UE is successfully authenticated by the same DN or the same AAA server (used to determine whether the UE needs to be secondary authenticated). If the UE is not successfully authenticated or the UE is not authenticated, the subsequent secondary authentication operation is performed. It should be noted that when the UE requests to modify the PDU session, the SMF does not initiate a secondary authentication request.

[0183] During the secondary authentication process, the UE sends authentication information to the AAA server, and the AAA server uses a preset authentication method and feeds back the authentication result. For example, when the AAA server is located in the 5GC and can be directly accessed, the UE can send the authentication information to the AAA server through the SMF, or the SMF sends the authentication information to the AAA server through the user plane function (UPF). If the AAA server is not located in the 5GC, the SMF needs to pass the authentication information to the AAA server through the UPF. Among them, the authentication method is, for example, through the extensible authentication protocol (EAP). The authentication information may include DN-specific identity, authentication algorithm (EAP), etc. In the EAP framework, DN-specific identity can also be called EAP ID, and the EAP ID includes the UE's identifier.

[0184] It should be noted that the UEs shown in the above USRP matching are all UEs registered with the network, that is, UEs that have completed initial authentication. This type of UE can also be referred to as the 3rd Generation Partnership Project (3GPP) type device (hereinafter referred to as UE). During the above secondary authentication process, authentication is performed at the granularity of the UE, that is, secondary authentication is mainly used by the AAA server to determine whether the UE is allowed access. However, with the development of technology, the functions of UEs have gradually diversified. Different people can use different personal accounts to log in to the same UE, multiple applications can be loaded on a UE, and a UE can be associated with multiple devices (i.e., non-3GPP devices that access the core network through the UE). Due to the diversity of accounts, applications, or devices associated with the UE, the above secondary authentication method cannot ensure the access security of every account, application, or non-3GPP device associated with the UE. Therefore, the above secondary authentication method cannot meet the network security requirements of the DN.

[0185] In view of this, the present application provides a communication method that can provide different authentication granularities by refining the authentication granularity, refining the storage granularity of the authentication results, modifying the conditions for triggering secondary authentication, and providing multiple subjects for triggering secondary authentication. This allows the AAA server to authenticate subjects of different granularities, thereby meeting the DN's network security requirements in various scenarios.

[0186] It should be noted that the authentication results in this application can be in the form of tables, data structures, etc. In this application, the authentication results are exemplarily saved in the form of tables. For example, the first authentication result can be a first authentication result table, and the second authentication result can be a second authentication result table.

[0187] Referring to FIG5 , FIG5 is a flow chart of a communication method provided by the present application, which includes but is not limited to the following steps:

[0188] S501. UE sends first request information to a network unit. Correspondingly, the network unit receives the first request information.

[0189] The UE is a device registered with the network. For example, the network accessed by the UE is a communication system of the 3GPP access type, including LTE, NR, or satellite access defined by 3GPP. For example, the UE performs primary authentication by sending network access credentials to the AUSF / ARPF, and establishes a NAS security context between the UE and the AMF if the authentication is successful, thereby completing the registration.

[0190] The above-mentioned first request information is used to indicate any one of a PDU session establishment request (the target object requests to establish a PDU session) or a PDU session modification request (the target object requests to modify the PDU session) or an authentication request (the target object requests the AAA server to authenticate it). The target object includes any one of a first user, a first device and a first application. The first request information also includes first indication information, and the first indication information is used to indicate the target identifier of the target object, thereby indicating that the first request information is related to the target object. The first user can be understood as a person who uses the UE. For example, the user can use the UE through an account, fingerprint recognition, face recognition, etc. The first device can be understood as a device that accesses the network through the UE, for example, an external device of the UE. The first application can be any application that is installed on the UE and has the need to access the network.

[0191] It should be noted that the first indication information in this application is used to indicate the target identifier of the target object, and should not be understood as indicating the target identifier of the target object associated with the UE. This is because the AAA server in this application is used to perform secondary authentication on the target object and is unrelated to the UE. Therefore, when the AAA server performs secondary authentication on the target object, it does not need to know whether the target object accesses the network through the UE. Alternatively, it can be understood that the target object accessing the network through different UEs will not affect the authentication result of the AAA server.

[0192] The above network unit is an SMF or an AAA server. The contents indicated by the first request information and the first indication information of different network units may be different, for example, including the following situations.

[0193] Case 1: The network unit is SMF.

[0194] In this case, the first request information is used to indicate a PDU session establishment request or a PDU session modification request. The first indication information is used to indicate a target identifier of a target object, which may be a user identifier (User ID) of the target object and / or a DN-specific identity (DN-specific identity) within the DN area of ​​the target object, also known as an EAP ID.

[0195] The PDU session establishment request is used to request the establishment of a target PDU session, and the PDU session modification request is used to request the modification of a target PDU session. The target PDU session identifier may be obtained through URSP matching.

[0196] Case 2: The network unit is an AAA server.

[0197] In this case, the first request information indicates an authentication request, specifically, a request to the AAA server to determine whether to perform secondary authentication on the target object. For example, the server determines whether the target object's authentication result is a failure using the second authentication result table stored in the AAA server. If so, subsequent authentication steps are performed. For details, please refer to the following related content and are not described in detail here. The first indication information indicates the target object's target identifier, which can be the target object's User ID or EAP ID.

[0198] It should be noted that the network unit in the communication method shown in Figure 5 is SMF, and subsequent steps S502-S506 are all described exemplarily based on the network unit being SMF. For the case where the network unit is an AAA server, please refer to the subsequent description of Figures 7 and 8, which will not be described in detail here.

[0199] S502: The network unit sends second request information, and correspondingly, the UE receives the second request information.

[0200] The second request information is used to request authentication information, and the authentication information is used for secondary authentication of the target object.

[0201] In a possible implementation, when a target trigger condition is met, the network unit sends the second request information, wherein the target trigger condition includes a first trigger condition and a second trigger condition.

[0202] The above-mentioned first trigger condition includes any one of the following: the network unit determines to perform secondary authentication based on the subscription data of the target object and the user identification of the target object, or the network unit determines to perform secondary authentication based on the association policy of the DN and the user identification of the target object. Among them, the subscription data of the target object and the association policy of the DN are both used to determine whether it is necessary to perform secondary authentication on the target object. The specific implementation can refer to the relevant existing technology and this application does not limit this. Next, the first trigger condition is exemplified by the association policy of the DN. For example, the AAA server will configure different credit levels (level 1, level 2, level 3, etc.) for different target objects, and set target objects with a credit level lower than the specified level (for example, level 2) to require secondary authentication. It can be understood that the first trigger condition is used to determine whether secondary authentication is allowed for the target object.

[0203] The above-mentioned second trigger condition includes any one of the following: the authentication result corresponding to the user identifier of the target object in the first authentication result table of the target PDU session is a failure, or the first request information is used to indicate a PDU session establishment request. The first authentication result table is used to store the authentication result corresponding to the user identifier of the target object, and its authentication result can be success (success) / failure (failure, the authentication result may also be invalid, not allowed, or the first authentication result table does not include the authentication result of the target object. In the case where the first request information is used to indicate a PDU session establishment request, the first authentication result table may not have been created yet. Therefore, in this case, the target object must not have been successfully authenticated, and the network unit can initiate a secondary authentication request for the target object to the AAA server.

[0204] Optionally, when the first indication information is further used to indicate the EAP ID of the target object, the second trigger condition further includes that the authentication result corresponding to the EAP ID of the target object in the first authentication result table of the target PDU session is failure.

[0205] In one possible implementation, when the AAA server is located in the core network (e.g., 5GC), the first trigger condition is that the network unit determines to perform secondary authentication based on the target object's subscription data and the target object's user identifier. When the AAA server is located outside the core network, the first trigger condition is that the network unit determines to perform secondary authentication based on the DN association policy and the target object's user identifier.

[0206] S503: The UE sends first response information to the second request information. Correspondingly, the network unit receives the first response information to the second request information.

[0207] Depending on the content indicated by the first indication information, the first response information may also include different information, specifically including the following two situations:

[0208] Case 1: The first indication information is used to indicate the user identifier of the target object.

[0209] In this case, the first response information includes the EAP ID of the target object and other authentication information (such as authentication algorithm, etc.).

[0210] Case 2: The first indication information is used to indicate the user identifier of the target object and the EAP ID of the target object.

[0211] In this case, the first response information may not include the EAP ID of the target object, that is, the first response information includes other authentication information (such as authentication algorithm, etc.) in addition to the EAP ID of the target object.

[0212] S504: The network unit sends fourth request information, and correspondingly, the AAA server receives the fourth request information.

[0213] The fourth request information is used to request secondary authentication of the target object, and includes the target PDU session identifier, the EAP ID of the target object, and other authentication information.

[0214] S505: The AAA server sends second response information to the fourth request information. Correspondingly, the network unit receives the second response information.

[0215] The second response information includes information such as the target PDU session identifier, the EAP ID of the target object, and the authentication result.

[0216] S506. The network unit creates / updates a first authentication result table.

[0217] In a case where the first request information is used to indicate a PDU session establishment request, the network element creates a first authentication result table.

[0218] When the first request information indicates a PDU session modification request, the network unit updates the first authentication result table. The specific updating method will be exemplarily described below and will not be described in detail here.

[0219] In this application, the network unit receives a first request message from the UE, and the first indication information in the first request message is used to indicate the target identifier of the target object. Therefore, the AAA server can perform a secondary authentication on the target object to determine whether the target object can access the DN, thereby ensuring that only the target object that has passed the authentication can access the DN, thereby improving the security of access to the DN.

[0220] In addition, when a new target object in the UE initiates a PDU session modification request, the AAA server may still perform a secondary authentication on it to ensure that only the target object that has passed the authentication can access the DN, thereby improving the security of access to the DN.

[0221] Please refer to Figure 6, which is a flowchart of another communication method provided in an embodiment of the present application, and is used to exemplify the above-mentioned "Case 1, the network unit is an SMF." It is understood that the steps in the embodiment of the present application can be regarded as reasonable variations or supplements to the embodiment in Figure 5 above; alternatively, it is understood that the communication method in the embodiment of the present application can also be regarded as an embodiment that can be executed independently, and this application does not limit this.

[0222] The communication method includes but is not limited to the following steps:

[0223] S601. The UE sends a PDU session establishment / modification request to the AMF. Correspondingly, the AMF receives the PDU session establishment / modification request from the UE.

[0224] It can be understood that whether the UE sends a PDU session establishment request or modification request to the AMF depends on whether there is an existing PDU session that conforms to the target RSD definition. If there is a PDU session that conforms to the target RSD definition, the UE sends a PDU session modification request to the AMF (exemplarily, it can be a PDU Session Establishment Request). If there is no PDU session that conforms to the target RSD definition, the UE sends a PDU session establishment request to the AMF (exemplarily, it can be a PDU Session Modification Request).

[0225] The information carried in the PDU session establishment / modification request includes the target PDU session identifier (PDU Session ID), S-NSSAI and the user identifier (User ID) of the target object. Optionally, the PDU session establishment / modification request also carries the EAP ID of the target object.

[0226] S602. AMF sends a request to establish / update a session management (SM) context to SMF. Correspondingly, SMF receives a request to establish / update an SM context from AMF.

[0227] It can be understood that the establishment / update SM context request refers to establishing the SM context of the target PDU session (exemplarily, it can be Nsmf PDU Session_CreateSMContext Request), or updating the SM context of the target PDU session (exemplarily, it can be Nsmf PDU Session_UpdateSMContext Request). The SM context includes relevant parameters of the target PDU session, such as the type of PDU session, SSD mode, etc.

[0228] In one possible implementation, the information sent by AMF to SMF depends on the information received by AMF.

[0229] Exemplarily, when the AMF receives a PDU session establishment request, the AMF sends a request to the SMF to establish an SM context. When the AMF receives a PDU session modification request, the AMF sends a request to the SMF to update the SM context.

[0230] Exemplarily, when the AMF receives a PDU session establishment / modification request including a session identifier (PDU Session ID), S-NSSAI, and a user identifier (User ID) of the target object, the establishment / update SM context request includes the PDU Session ID, S-NSSAI, and the user identifier (User ID) of the target object. Optionally, when the AMF receives a PDU session establishment / modification request also including the EAP ID of the target object, the establishment / update SM context request also includes the EAP ID of the target object.

[0231] Exemplarily, when the AMF receives a PDU session modification request, the SM context update request also includes the SM context identifier (SM Context ID) that needs to be updated.

[0232] In a possible application scenario, in the roaming architecture of home access roaming (as shown in Figure 2 above), SMF includes V-SMF and H-SMF. AMF sends an establishment / update SM context request to SMF, which means that AMF sends an establishment / update SM context request to V-SMF, and V-SMF then sends the establishment / update SM context request to H-SMF for establishing / updating PDU session.

[0233] S603A (optional): SMF requests subscription data of the target object from UDM. Correspondingly, UDM receives the request from SMF.

[0234] Exemplarily, when the SMF receives an update / establishment SM context request, the SMF requests the subscription data of the target object from the UDM. For example, the SMF requests the subscription data of the target object from the UDM through a Nudm_SDM_Get operation.

[0235] S603B (optional): UDM sends subscription data of the target object to SMF. Correspondingly, SMF receives the subscription data from UDM.

[0236] It should be noted that, when the AAA server is located in the core network (e.g., 5GC), the above steps S603A and S603B are performed. When the AAA server is located outside the core network (, the SMF can determine whether secondary authentication of the target object is allowed based on the DN association policy. For a specific description, please refer to the relevant description in step S604 below.

[0237] S604. The SMF (H-SMF) determines whether to perform secondary authentication on the target object.

[0238] In a possible implementation, the SMF determines whether to perform secondary authentication on the target object, including determining whether secondary authentication on the target object is allowed and whether secondary authentication on the target object is required.

[0239] Among them, SMF can determine whether to allow secondary authentication of the target object in any of the following ways.

[0240] Method 1: The SMF (H-SMF) queries the UDM for the target object's subscription data based on the target object's user identifier (as shown in steps S603A and S603B). For example, the SMF (H-SMF) obtains the target object's relevant subscription data from the UDM and determines whether secondary authentication of the target object is allowed based on the subscription data.

[0241] Method 2: The SMF (H-SMF) determines whether to allow secondary authentication for the target object based on the DN-associated policy. For example, the AAA server may configure different credit levels (level 1, level 2, level 3, etc.) for different target objects and set secondary authentication requirements for target objects with a credit level lower than the specified level (for example, level 2).

[0242] It should be noted that when the AAA server is located in the core network (e.g., 5GC), the above method 1 is used to determine whether secondary authentication of the target object is allowed. When the AAA server is located outside the core network, the above method 2 is used to determine whether secondary authentication of the target object is allowed.

[0243] If the SMF (H-SMF) determines that secondary authentication of the target object is not allowed according to the above method 1 or method 2, the SMF (H-SMF) rejects the PDU session establishment / modification request shown in S601 through SM-NAS signaling.

[0244] If the SMF (H-SMF) determines that secondary authentication of the target object is permitted according to the above-described method 1 or method 2, the SMF (H-SMF) will further determine whether the corresponding authentication result of the target object is a failure. If the corresponding authentication result of the target object is a failure, the SMF (H-SMF) will execute the following steps (e.g., S605, S606, S607, S608, and S609). Specifically, the SMF (H-SMF) may determine whether the corresponding authentication result of the target object is a failure (equivalent to determining whether secondary authentication of the target object is required) by querying the first authentication result table. The first authentication result table may include authentication results corresponding to user identifiers and / or authentication results corresponding to EAP IDs, as shown in Tables 3, 4, and 5.

[0245] Please refer to Table 3, which is an exemplary authentication result table provided in this application.

[0246] Table 3

[0247] As shown in Table 3, the authentication result corresponding to the user identifier of the first object in the target PDU session is successful, and the authentication result corresponding to the user identifier of the second object is failed. For example, if the target object is the first object shown in Table 3, then secondary authentication of the target object is not required. If the target object is the second object shown in Table 3, then secondary authentication of the target object is required.

[0248] Optionally, when the first authentication result table does not include the authentication result of the user identifier of the target object, it is also necessary to perform secondary authentication on the target object.

[0249] Please refer to Table 4, which is another authentication result table provided as an example in this application.

[0250] Table 4

[0251] As shown in Table 4, the authentication result corresponding to the EAP ID of the first object in the target PDU session is successful, while the authentication result corresponding to the EAP ID of the second object is failed. For example, if the target object is the first object shown in Table 3, secondary authentication of the target object is not required. If the target object is the second object shown in Table 3, secondary authentication of the target object is required.

[0252] Optionally, when the first authentication result table does not include the authentication result of the EAP ID of the target object, it is also necessary to perform secondary authentication on the target object.

[0253] Please refer to Table 5, which is another authentication result table provided as an example in this application.

[0254] Table 5

[0255] As shown in Table 5, Table 5 includes both authentication results corresponding to user identifiers and authentication results corresponding to EAP IDs. If the first authentication result table is as shown in Table 5, the authentication result corresponding to the target object's user identifier or EAP ID can be queried to determine whether to perform secondary authentication on the target object. The specific determination method can be found in Tables 3 and 4 above and is not further detailed here.

[0256] By determining whether to perform secondary authentication on the target object based on different user identifiers and / or EAP IDs of the same PDU session identifier, the authentication granularity can be refined to ensure that only the target object that has passed the authentication can access the DN, thereby improving the security of access to the DN.

[0257] S605 (optional): SMF sends a response to the request to establish an SM context to AMF. Accordingly, AMF receives a response to the request to establish an SM context from SMF.

[0258] If the information received by the SMF does not establish an SM context request, the SMF sends a response to the SM context request to establish the SM context to the AMF (exemplarily, it can be Nsmf PDU Session_CreateSMContext Request). The response to the SM context request includes the SM Context ID.

[0259] Similarly, in the roaming architecture of home access roaming (as shown in Figure 2 above), SMF sends a response to the request to establish an SM context to AMF, which means that V-SMF sends a response to the request to establish an SM context to AMF.

[0260] It should be noted that, when it is determined in step S604 that the target object is to be authenticated twice, steps S605 to S609 and related steps are executed.

[0261] S606. SMF requests authentication information from UE.

[0262] The requested authentication information is used for secondary authentication, and the authentication information includes information such as EAP ID and authentication algorithm.

[0263] According to the information carried in the PDU session establishment / modification request in S601, the SMF requests different authentication information from the UE.

[0264] For example, if the EAP ID of the target object is included in the PDU session establishment / modification request, the EAP ID of the target object may not be included in the authentication information requested by the SMF to the UE. If the EAP ID of the target object is not included in the PDU session establishment / modification request, the EAP ID of the target object may be included in the authentication information requested by the SMF to the UE.

[0265] In the roaming architecture for home access roaming (as shown in Figure 2 above), the SMF requests authentication information from the UE. This means that the H-SMF sends an instruction requesting authentication information to the V-SMF, and then the V-SMF requests authentication information from the UE. In response, the UE sends the authentication information to the V-SMF, and the V-SMF sends the authentication information to the H-SMF.

[0266] S607: The SMF (H-SMF) sends a secondary authentication request (for example, an Authentication / Authorization Request) to the AAA server. Correspondingly, the AAA server receives the secondary authentication request.

[0267] The secondary authentication request sent by the SMF (H-SMF) to the AAA server includes the target PDU session identifier, the EAP ID of the target object, and authentication information.

[0268] Depending on whether the AAA server is in the core network, the SMF (H-SMF) will send the secondary authentication request to the AAA server in different ways. For example, when the AAA server is located in the core network (such as 5GC), the SMF (H-SMF) can transparently transmit the secondary authentication request to the AAA server through the UPF, or the SMF (H-SMF) can directly send the secondary authentication request to the AAA server. When the AAA server is located outside the core network, the SMF (H-SMF) must transparently transmit the secondary authentication request to the AAA server through the UPF.

[0269] S608: The AAA server sends a response to the secondary authentication request (for example, an Authentication / Authorization Response) to the SMF (H-SMF). Correspondingly, the SMF (H-SMF) receives the response to the secondary authentication request.

[0270] The secondary authentication response sent by the AAA server to the SMF (H-SMF) includes information such as the EAP ID of the target object and the authentication result.

[0271] Similarly, depending on whether the AAA server is in the core network, the AAA server will send the secondary authentication result to the SMF (H-SMF) in different ways. For example, when the AAA server is located in the core network (such as 5GC), the AAA server can transparently transmit the secondary authentication result to the SMF (H-SMF) through the UPF, or the AAA server can directly send the secondary authentication result to the SMF (H-SMF). When the AAA server is located outside the core network, the AAA server must transparently transmit the secondary authentication result to the SMF (H-SMF) through the UPF.

[0272] S609. The SMF (H-SMF) creates / updates a first authentication result table.

[0273] Exemplarily, the SMF (H-SMF) may create a first authentication result table based on the authentication result returned by the AAA server, as shown in Table 4.

[0274] Table 6

[0275] As shown in Table 6, the authentication result corresponding to the user identifier of the target object and the EAP ID of the target object is success.

[0276] Exemplarily, the SMF may also update the first authentication result table based on the authentication result returned by the AAA server, where the first authentication result table is, for example, the authentication result table shown in Table 3, Table 4 or Table 5 above.

[0277] For example, assuming that the first authentication result table is Table 5 and the target object is the second object shown in Table 5, updating the first authentication result table will be described as an example. Specifically, if the AAA server returns a failed authentication result for the target object, there is no need to update the authentication result table shown in Table 5. If the AAA server returns a successful authentication result for the target object, the authentication result table shown in Table 5 is updated to the table shown in Table 7.

[0278] Table 7

[0279] The first authentication result table is used to save the authentication result corresponding to the target object, so that when the target object initiates a PDU session modification request, the SMF can determine whether to perform a secondary authentication on the target object based on the first authentication result table, thereby ensuring the security of access to the DN.

[0280] In one possible implementation, the authentication result has a certain timeliness, that is, when the authentication result of the target object is successful, the AAA server needs to authenticate the target object once every specified period of time to determine whether the target object is allowed to access the DN.

[0281] In another possible implementation, if all authentication results in the first authentication result table are failures, the SMF (H-SMF) releases the target PDU session. It can be understood that the first authentication result is the authentication result table corresponding to the target PDU session. If all authentication results in the first authentication result table are failures, the target PDU session does not transmit data between the UE and the DN, and the idle session needs to be released in a timely manner.

[0282] Exemplarily, when the first authentication result table is Table 5 and the target object is the first object shown in Table 5, if the authentication result of the AAA server for the first object is failure, then the authentication results in the first authentication result table are all failures, and the SMF (H-SMF) will release the target PDU session.

[0283] In this embodiment, by refining the authentication granularity (for example, performing secondary authentication on the target object) and refining the granularity of saving the authentication results (for example, saving the first authentication result table), the SMF can judge different objects in the same PDU session and determine whether to perform secondary authentication on them, thereby ensuring that only the target objects that have passed the authentication can access the DN, thereby improving the security of access to the DN.

[0284] Please refer to FIG7 , which is a flowchart of another communication method provided by the present application. The communication method includes but is not limited to the following steps:

[0285] S701. A UE sends first request information. Correspondingly, a network unit receives the first request information.

[0286] For the relevant introduction of UE and the first request information, please refer to the description of step S501 above, which will not be repeated here.

[0287] It should be noted that, in the communication method shown in FIG. 7 , the network unit is an AAA server, and subsequent steps S702 - S708 are all described exemplarily with the network unit being the AAA server.

[0288] It is understandable that, when a target PDU session exists between the UE and the AAA server, the UE can send information to the AAA server via the application layer. Therefore, the premise for executing this solution is that a target PDU session exists between the UE and the DN.

[0289] For example, when the UE matches a target PDU session based on the URSP, and the target PDU session is a PDU session between the UE and the DN, the UE sends an authentication request to the AAA server through the application layer. The authentication request includes information such as the target PDU session identifier, the user identifier of the target object, and the EAP ID of the target object.

[0290] S702. The network unit sends a third request message, and correspondingly, the SMF receives the third request message.

[0291] The third request information is used to instruct the SMF to determine whether to perform secondary authentication on the target object.

[0292] In one possible implementation, if the network unit determines that the target object requires secondary authentication, the network unit sends a third request message to the SMF. Exemplarily, the network unit may determine whether the target object requires secondary authentication based on the second authentication result table. For example, if the authentication result of the target object in the second authentication result table is a failure, secondary authentication of the target object is required. For another example, if the second authentication result table does not include the authentication result of the target object, secondary authentication of the target object is also required.

[0293] When the SMF receives the third request information, it can determine whether to allow the target object to be secondary authenticated by any of the following items. For example, the SMF determines to perform secondary authentication based on the subscription data of the target object and the user identifier of the target object, or the SMF determines to perform secondary authentication based on the association policy of the DN and the user identifier of the target object. Among them, the subscription data of the target object and the association policy of the DN are both used to determine whether the target object needs to be secondary authenticated. The specific implementation can refer to the relevant existing technology and this application does not limit this. For an introduction to how the SMF determines whether to allow the target object to be secondary authenticated, please refer to the corresponding statement in the above step S502, which will not be repeated here.

[0294] S703. The SMF sends a second request message, and correspondingly, the UE receives the second request message.

[0295] The second request information is used to request authentication information, which is used for secondary authentication of the target object. For an introduction to the second request information, please refer to the relevant description in step S502 above, and no further details will be given here.

[0296] Exemplarily, when secondary authentication of the target object is allowed (determined by step S702), the SMF sends a second request message to the UE.

[0297] S704. The UE sends first response information to the second request information. Correspondingly, the SMF receives the first response information to the second request information.

[0298] The first response information includes authentication information used for secondary authentication. For an introduction to the first response, please refer to the relevant description of step S503 above, which will not be repeated here.

[0299] S705. The SMF sends a fourth request message, and correspondingly, the network unit receives the fourth request message.

[0300] The fourth request information is used to request secondary authentication of the target object, and includes the target PDU session identifier, the EAP ID of the target object, and other authentication information.

[0301] S706. The network unit sends second response information to the fourth request information. Correspondingly, the SMF receives the second response information.

[0302] The second response information includes information such as the target PDU session identifier, the EAP ID of the target object, and the authentication result.

[0303] S707: The network unit updates the second authentication result table. The specific updating method can refer to the relevant description of the above step S608 and will not be repeated here.

[0304] S708: The SMF updates the first authentication result table. The specific updating method can refer to the relevant description of the above step S608 and will not be repeated here.

[0305] In this application, the network unit receives a first request message from the UE, and the first indication information in the first request message is used to indicate the target identifier of the target object. Therefore, the AAA server can perform a secondary authentication on the target object to determine whether the target object can access the DN, thereby ensuring that only the target object that has passed the authentication can access the DN, thereby improving the security of access to the DN.

[0306] In addition, compared to the above-mentioned FIG. 5 in which the network unit is the SMF, the network unit in this solution is the AAA server, which provides more methods for performing secondary authentication for the target object.

[0307] Refer to Figure 8, which is a flowchart of another communication method provided in an embodiment of the present application, and is used to exemplify the aforementioned "Case 2, where the network unit is an AAA server." It is understood that the steps in the embodiments of the present application can be considered as reasonable variations or supplements to the embodiments in Figures 5 or 7 above; alternatively, it is understood that the communication method in the embodiments of the present application can also be considered as an independently executable embodiment, and this application does not limit this.

[0308] The communication method includes but is not limited to the following steps:

[0309] S801. The UE sends an authentication request to the AAA server. Correspondingly, the AAA server receives the authentication request from the UE.

[0310] The UE sends an authentication request to the AAA server through the application layer. The authentication request includes information such as the target PDU session identifier, the user identifier of the target object, and the EAP ID of the target object.

[0311] Exemplarily, the UE matches a target PDU session through the USRP, and the target PDU session is a PDU session between the UE and the AAA server, then the UE sends an authentication request to the AAA server through the application layer.

[0312] S802: The AAA server determines whether secondary authentication of the target object is required.

[0313] In a possible implementation, the AAA server determines whether secondary authentication is required for the target object based on the second authentication result table of the target PDU session.

[0314] The second authentication result table may be, for example, the authentication result table shown in Table 3, Table 4, or Table 5. That is, the second authentication result table includes the authentication result corresponding to the target object's user identifier and / or the authentication result corresponding to the target object's EAP ID. For information on how the AAA server determines whether secondary authentication of the target object is required based on the second authentication result table, refer to the description of how the SMF determines whether secondary authentication of the target object is required based on the first authentication result table in step S604 above, and will not be repeated here.

[0315] S803. The AAA server sends target indication information to the SMF. Correspondingly, the SMF receives the target indication information from the AAA server. The target indication information is used to instruct the SMF to determine whether to allow secondary authentication of the target object.

[0316] The target indication information includes a target PDU session identifier, a user identifier of a target object, an EAP ID of a target object, and the like.

[0317] Illustratively, in S802, if the AAA server determines, based on the second authentication result table, that secondary authentication of the target object is required, the AAA server sends target indication information to the SMF. For example, the second authentication result table indicates that the authentication result corresponding to the target object is a failure, or the second authentication result table does not include the authentication result corresponding to the target object, or the second authentication result table does not indicate that the authentication result corresponding to the target object is a success. The authentication result corresponding to the target object may be an authentication result corresponding to the user identifier of the target object, or may be an authentication result corresponding to the EAP ID of the target object.

[0318] Depending on whether the AAA server is in the core network, the AAA server will send the target indication information to the SMF in different ways. For example, when the AAA server is in the core network (such as 5GC), the AAA server can transparently transmit the target indication information to the SMF through the UPF, or the AAA server can directly send the target indication information to the AAA server. When the AAA server is outside the core network, the SMF must transparently transmit the target indication information to the AAA server through the UPF.

[0319] In a possible application scenario, in a roaming architecture of home access roaming (as shown in FIG. 2 above), the AAA server sending the target indication information to the SMF means that the AAA server sends the target indication information to the H-SMF.

[0320] S804A (optional): SMF requests subscription data of the target object from UDM. Correspondingly, UDM receives the request from SMF.

[0321] Exemplarily, when the SMF receives an update / establishment SM context request, the SMF requests the subscription data of the target object from the UDM. For example, the SMF requests the subscription data of the target object from the UDM through a Nudm_SDM_Get operation.

[0322] S804B (optional): UDM sends the subscription data of the target object to SMF. Correspondingly, SMF receives the subscription data from UDM.

[0323] It should be noted that when the AAA server is located in the core network (e.g., 5GC), the above steps S804A and S804B are performed. When the AAA server is located outside the core network, the SMF can determine whether to allow secondary authentication of the target object based on the DN association policy. For a detailed description, please refer to the relevant description of step S805 below.

[0324] S805. The SMF (H-SMF) determines whether secondary authentication of the target object is allowed.

[0325] SMF can determine whether to allow secondary authentication of the target object in any of the following ways.

[0326] Method 1: The SMF (H-SMF) queries the UDM for the target object's subscription data based on the target object's user identifier (as shown in steps S804A and S804B). For example, the SMF (H-SMF) obtains the target object's relevant subscription data from the UDM and determines whether secondary authentication of the target object is allowed based on the subscription data.

[0327] Method 2: The SMF (H-SMF) determines whether to allow secondary authentication for the target object based on the DN-associated policy. For example, the AAA server may configure different credit levels (level 1, level 2, level 3, etc.) for different target objects and set secondary authentication requirements for target objects with a credit level lower than the specified level (for example, level 2).

[0328] It should be noted that when the AAA server is located in the core network (e.g., 5GC), the above method 1 is used to determine whether secondary authentication of the target object is allowed. When the AAA server is located outside the core network, the above method 2 is used to determine whether secondary authentication of the target object is allowed.

[0329] If the SMF (H-SMF) determines that secondary authentication of the target object is not allowed according to the above method 1 or method 2, the SMF (H-SMF) rejects the authentication request shown in S801 through SM-NAS signaling. If the SMF (H-SMF) determines that secondary authentication of the target object is allowed according to the above method 1 or method 2, the SMF (H-SMF) requests authentication information from the UE (as in step S805).

[0330] S806. The SMF (H-SMF) requests authentication information from the UE.

[0331] The requested authentication information is used for secondary authentication and includes information such as the EAP ID and authentication algorithm. Since the target indication information in S803 includes the EAP ID of the target object, the authentication information sent by the UE to the SMF (H-SMF) may not include the EAP ID of the target object.

[0332] In the roaming architecture for home access roaming (as shown in Figure 2 above), the SMF requests authentication information from the UE. This means that the H-SMF sends an instruction requesting authentication information to the V-SMF, and then the V-SMF requests authentication information from the UE. In response, the UE sends the authentication information to the V-SMF, and the V-SMF sends the authentication information to the H-SMF.

[0333] S807: The SMF (H-SMF) sends a secondary authentication request (for example, an Authentication / Authorization Request) to the AAA server. Correspondingly, the AAA server receives the secondary authentication request.

[0334] The secondary authentication request sent by the SMF (H-SMF) to the AAA server includes the target PDU session identifier, the target object's EAP ID, authentication information, etc. For the specific implementation, please refer to the description of step S606 above, which will not be repeated here.

[0335] S808: The AAA server sends a response to the secondary authentication request (for example, Authentication / AuthorizationResponse) to the SMF (H-SMF). Correspondingly, the SMF (H-SMF) receives the response to the secondary authentication request.

[0336] For the specific implementation method, please refer to the relevant description of step S607 above, which will not be repeated here.

[0337] S809: The AAA server updates the second authentication result table.

[0338] For the specific implementation of the AAA server updating the second authentication result table according to the authentication result of the target object, reference may be made to the relevant description of the SMF updating the first authentication result table according to the authentication result of the target object in S608 above, which will not be repeated here.

[0339] The second authentication result table is used to store the authentication result corresponding to the target object, so that when the UE initiates an authentication request, the AAA server can determine whether a secondary authentication is required for the target object based on the second authentication result table, thereby ensuring the security of the access DN.

[0340] S810. The SMF (H-SMF) updates the first authentication result table.

[0341] For the specific implementation of SMF (H-SMF) updating the first authentication result table according to the authentication result of the target object, reference may be made to the relevant description of SMF updating the first authentication result table according to the authentication result of the target object in S608 above, which will not be repeated here.

[0342] The first authentication result table is used to save the authentication result corresponding to the target object, so that when the UE initiates a PDU session modification request, the SMF can determine whether to perform a secondary authentication on the target object based on the first authentication result table, thereby ensuring the security of access to the DN.

[0343] In one possible implementation, the authentication result has a certain timeliness, that is, when the authentication result of the target object is successful, the AAA server needs to authenticate the target object once every specified period of time to determine whether the target object is allowed to access the DN.

[0344] In another possible implementation, if all authentication results in the first authentication result table are failures, the SMF (H-SMF) releases the target PDU session. It can be understood that the first authentication result is the authentication result table corresponding to the target PDU session. If all authentication results in the first authentication result table are failures, the target PDU session does not transmit data between the UE and the AAA server, and the network side needs to release the idle session. Releasing the target PDU session can save network resources.

[0345] Exemplarily, when the first authentication result table is Table 5 and the target object is the first object shown in Table 5, if the authentication result of the AAA server for the first object is failure, then the authentication results in the first authentication result table are all failures, and the SMF (H-SMF) will release the target PDU session.

[0346] In this embodiment, the AAA server determines whether to perform secondary authentication on the target object based on the second authentication result table, providing more implementation methods for triggering secondary authentication of the target object. In addition, the authentication request received by the AAA server is transmitted via the application layer between the UE and the AAA server. Therefore, this embodiment of the application can reduce the pressure on core network transmission resources.

[0347] The above describes in detail the methods of the embodiments of the present application. The following provides an apparatus for implementing any method in the embodiments of the present application. For example, an apparatus is provided that includes units (or means) for implementing each step performed by the device in any of the above methods.

[0348] As shown in Figure 9, the communication device 90 may include a communication unit 901 and a processing unit 902. The communication unit 901 and the processing unit 902 may be software, hardware, or a combination of software and hardware.

[0349] The communication unit 901 can implement a sending function and / or a receiving function, and can also be described as a transceiver unit. The communication unit 901 can also be a unit that integrates an acquisition unit and a transmission unit, wherein the acquisition unit is used to implement the receiving function and the transmission unit is used to implement the transmission function. Optionally, the communication unit 901 can be used to receive information sent by other devices, and can also be used to send information to other devices.

[0350] In one possible design, the communication device 90 may correspond to the first host node in the method embodiments shown in Figures 5, 6, 7, and 8 above. For example, the communication device 90 may be an SMF or a chip in the SMF. The communication device 90 may include a unit for executing the operations performed by the SMF in the method embodiments shown in Figures 5, 6, 7, and 8 above, and each unit in the communication device 90 is respectively for implementing the operations performed by the SMF in the method embodiments shown in Figures 5, 6, 7, and 8 above. The description of each unit is as follows:

[0351] Communication unit 901 is used to receive a first request message, where the first request message is used to indicate any one of a PDU session establishment request (the target object requests to establish a PDU session), a PDU session modification request (the target object requests to modify a PDU session), or an authentication request (the target object requests the AAA server to authenticate it). The target object includes any one of a first user, a first device, and a first application. Therefore, the first request message also includes first indication information, where the first indication information is used to indicate a target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0352] In one possible design, the device further includes:

[0353] The processing unit 902 is configured to generate second request information, where the second request information is used to request authentication information about a target object from the UE, and the authentication information is used for the AAA server to perform secondary authentication on the target object.

[0354] Specifically, when the target trigger condition is met, the processing unit 902 generates a second request message. The target trigger condition includes a first trigger condition and a second trigger condition. Among them, the first trigger condition is used to determine whether a secondary authentication of the target object is required, for example, it can be based on the subscription data of the target object or the association policy of the DN. The second trigger condition is used to determine whether a secondary authentication is required, for example, it can be determined through an existing authentication result table (first authentication result table) whether the target object has been successfully authenticated, and a secondary authentication is performed on the target object if the authentication result of the target object is a failure. For another example, if the first request is used to indicate the establishment of a PDU session, the target object is authenticated twice.

[0355] Optionally, the first authentication result table further includes authentication results corresponding to the EAP ID, and the second trigger condition further includes that the authentication result corresponding to the EAP ID of the target object in the first authentication result table is failure.

[0356] The processing unit 902 is further configured to send second request information.

[0357] In one possible implementation, the device includes:

[0358] The communication unit 901 is used to receive third request information, where the third request information is used to instruct the SMF to further determine whether to perform secondary authentication on the target object.

[0359] The processing unit 902 is configured to determine whether to perform secondary authentication on the target object based on the target object's subscription data and the target object's user ID, or determine whether to perform secondary authentication on the target object based on the DN association policy and the target object's user ID.

[0360] In one possible implementation, the device includes:

[0361] The communication unit 901 is configured to receive a first response message to the second request message. The first response message may include the EAP ID of the target object or may not include the EAP ID of the target object. Optionally, the first response message may also include an authentication algorithm, etc.

[0362] In one possible implementation, the device includes:

[0363] The communication unit 901 is configured to send fourth request information, where the fourth request information is used to request secondary authentication.

[0364] The communication unit 901 is further configured to receive second response information to the fourth request information, where the second response is used to indicate an authentication result of the secondary authentication.

[0365] The processing unit 902 is configured to update the first authentication result table based on the authentication result of the secondary authentication.

[0366] The processing unit 902 is further configured to release the target PDU session when all authentication results in the first authentication result table are failures.

[0367] In another possible design of the communication device 90 shown in FIG9 , the communication device 90 may correspond to the AAA server in the method embodiments shown in FIG5 , FIG6 , FIG7 , and FIG8 . For example, the communication device 90 may be an AAA server or a chip in the AAA server. The communication device 90 may include a unit for executing the operations performed by the AAA server in the method embodiments shown in FIG5 , FIG6 , FIG7 , and FIG8 , and each unit in the communication device 90 is respectively for implementing the operations performed by the AAA server in the method embodiments shown in FIG5 , FIG6 , FIG7 , and FIG8 . The description of each unit is as follows:

[0368] The communication unit 901 is configured to receive an authentication request from a UE, wherein the authentication request is used to request the AAA server to determine whether a secondary authentication of a target object is required. The authentication request includes a target identifier of the target object, wherein the target object includes any one of a first user, a first device, and a first application.

[0369] The processing unit 902 is configured to determine whether a secondary authentication is required for the target object based on the target identifier of the target object.

[0370] or,

[0371] The communication unit 901 is used to send a third request message, where the third request message is used to instruct the SMF to further determine whether to perform secondary authentication on the target object.

[0372] In one possible implementation, the device includes:

[0373] The communication unit 901 is configured to receive fourth request information, where the fourth request information is used to request secondary authentication.

[0374] The processing unit 902 is configured to perform secondary authentication on the target object based on the fourth request information and generate an authentication result.

[0375] or,

[0376] The communication unit 901 is further configured to send second response information to the fourth request information, where the second response is used to indicate an authentication result of the secondary authentication.

[0377] The processing unit 902 is further configured to update the second authentication result table based on the authentication result of the secondary authentication.

[0378] The methods executed by the communication unit 901 and the processing unit 902 can refer to the methods corresponding to the above Figures 5, 6, 7, and 8, and will not be repeated here.

[0379] Regarding the technical effects brought about by any of the above designs and any possible implementation methods, please refer to the introduction of the technical effects of the corresponding methods in Figures 5, 6, 7, and 8 above, which will not be repeated here.

[0380] Optionally, in the communication device described in any of the foregoing designs and any of the possible implementations:

[0381] In one implementation, the communication apparatus is a communication device. When the communication apparatus is a communication device, the communication unit may be a transceiver or an input / output interface; and the processing unit may be at least one processor. Alternatively, the transceiver may be a transceiver circuit. Alternatively, the input / output interface may be an input / output circuit.

[0382] In another implementation, the communication device is a chip (system) or circuit used in a communication device. When the communication device is a chip (system) or circuit used in a communication device, the communication unit may be a communication interface (input / output interface), interface circuit, output circuit, input circuit, pin, or related circuit on the chip (system) or circuit; and the processing unit may be at least one processor, processing circuit, or logic circuit.

[0383] According to an embodiment of the present application, each unit in the device shown in Figure 9 can be separately or all merged into one or several other units to constitute, or one (some) unit therein can also be split into multiple smaller units in function to constitute, which can achieve the same operation without affecting the realization of the technical effects of the embodiments of the present application. The above-mentioned units are divided based on logical functions. In practical applications, the functions of a unit can also be implemented by multiple units, or the functions of multiple units can be implemented by one unit. In other embodiments of the present application, other units can also be included based on electronic equipment. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented by collaboration of multiple units.

[0384] It should be noted that the implementation of each unit may also refer to the corresponding description of the method embodiments shown in the above-mentioned Figures 5, 6, 7, and 8.

[0385] In the communication device 90 described in Figure 9, the AAA server can authenticate the target object (for example, an account on the UE, an application on the UE, or a device connected to the UE) to ensure that only the target object that has passed the authentication can access the DN, thereby improving the security of access to the DN.

[0386] Please refer to FIG10 , which is a schematic structural diagram of a communication device provided in an embodiment of the present application.

[0387] It should be understood that the communication device 100 shown in Figure 10 is only an example. The communication device of the embodiment of the present application may also include other components, or include components with similar functions to the various components in Figure 10, or not necessarily include all the components in Figure 10.

[0388] The communication device 100 includes a communication interface 1001 and at least one processor 1002 .

[0389] The communication device 100 may correspond to any node or device in the SMF, AAA server, or UE. The communication interface 1001 is used to send and receive signals, and at least one processor 1002 executes program instructions, so that the communication device 100 implements the corresponding process of the method executed by the corresponding device in the above method embodiment.

[0390] In one possible design, the communication device 100 may correspond to the first host node in the method embodiments shown in Figures 5, 6, 7, and 8 above. For example, the communication device 100 may be an SMF or a chip in the SMF. The communication device 100 may include components for executing the operations performed by the SMF in the above method embodiments, and each component in the communication device 100 is respectively for implementing the operations performed by the SMF in the above method embodiments. Specifically, it may be as follows:

[0391] The communication interface 1001 is used to receive a first request message, where the first request message is used to indicate any one of a PDU session establishment request (the target object requests to establish a PDU session), a PDU session modification request (the target object requests to modify a PDU session), or an authentication request (the target object requests the AAA server to authenticate it). The target object includes any one of a first user, a first device, and a first application. Therefore, the first request message also includes first indication information, where the first indication information is used to indicate a target identifier of the target object, thereby indicating that the first request message is related to the target object. The target identifier of the target object is used to determine whether to perform secondary authentication on the target object.

[0392] In one possible design, the device further includes:

[0393] Processor 1002 is configured to generate second request information, where the second request information is used to request authentication information about a target object from the UE, and the authentication information is used for secondary authentication of the target object by the AAA server.

[0394] Specifically, when the target trigger condition is met, the processor 1002 generates a second request message. The target trigger condition includes a first trigger condition and a second trigger condition. The first trigger condition is used to determine whether a secondary authentication of the target object is required, for example, it can be based on the subscription data of the target object or the association policy of the DN. The second trigger condition is used to determine whether a secondary authentication is required, for example, it can be determined through an existing authentication result table (first authentication result table) whether the target object has been successfully authenticated, and a secondary authentication is performed on the target object if the authentication result of the target object is a failure. For another example, if the first request is used to indicate the establishment of a PDU session, the target object is authenticated twice.

[0395] Optionally, the first authentication result table further includes authentication results corresponding to the EAP ID, and the second trigger condition further includes that the authentication result corresponding to the EAP ID of the target object in the first authentication result table is failure.

[0396] Processor 1002 is further configured to send second request information.

[0397] In one possible implementation, the device includes:

[0398] The communication interface 1001 is used to receive third request information, where the third request information is used to instruct the SMF to further determine whether to perform secondary authentication on the target object.

[0399] Processor 1002 is configured to determine whether to perform secondary authentication on the target object based on the target object's subscription data and the target object's user identifier, or determine whether to perform secondary authentication on the target object based on the DN association policy and the target object's user identifier.

[0400] In one possible implementation, the device includes:

[0401] The communication interface 1001 is configured to receive a first response message to the second request message. The first response message may include the EAP ID of the target object or may not include the EAP ID of the target object. Optionally, the first response message may also include an authentication algorithm, etc.

[0402] In one possible implementation, the device includes:

[0403] The communication interface 1001 is used to send fourth request information, where the fourth request information is used to request secondary authentication.

[0404] The communication interface 1001 is further configured to receive second response information to the fourth request information, where the second response is used to indicate an authentication result of the secondary authentication.

[0405] The processor 1002 is configured to update the first authentication result table based on the authentication result of the secondary authentication.

[0406] The processor 1002 is further configured to release the target PDU session when all authentication results in the first authentication result table are failures.

[0407] In another possible design, the communication device 100 may correspond to the AAA server in the method embodiments shown in Figures 5, 6, 7, and 8. For example, the communication device 100 may be an AAA server or a chip within the AAA server. The communication device 100 may include components for executing the operations performed by the AAA server in the method embodiments described above, and each component in the communication device 100 is configured to implement the operations performed by the AAA server in the method embodiments described above. Specifically, the operations may be as follows:

[0408] The communication interface 1001 is configured to receive an authentication request from a UE, wherein the authentication request is used to request the AAA server to determine whether a secondary authentication of a target object is required. The authentication request includes a target identifier of the target object, wherein the target object includes any one of a first user, a first device, and a first application.

[0409] The processor 1002 is configured to determine whether secondary authentication is required for the target object based on the target identifier of the target object.

[0410] or,

[0411] The communication interface 1001 is used to send a third request message, where the third request message is used to instruct the SMF to further determine whether to perform secondary authentication on the target object.

[0412] In one possible implementation, the device includes:

[0413] The communication interface 1001 is used to receive fourth request information, where the fourth request information is used to request secondary authentication.

[0414] The processor 1002 is configured to perform secondary authentication on the target object based on the fourth request information and generate an authentication result.

[0415] or,

[0416] The communication interface 1001 is further configured to send a second response message to the fourth request message, where the second response message indicates an authentication result of the secondary authentication.

[0417] The processor 1002 is further configured to update the second authentication result table based on the authentication result of the secondary authentication.

[0418] Regarding the technical effects brought about by any of the above designs and any possible implementation methods, please refer to the introduction of the technical effects of the corresponding methods in Figures 5, 6, 7, and 8 above, which will not be repeated here.

[0419] In the communication device 100 described in Figure 10, the AAA server can authenticate the target object (for example, an account on the UE, an application on the UE, or a device connected to the UE) to ensure that only the target object that has passed the authentication can access the DN, thereby improving the security of access to the DN.

[0420] For the case where the communication device may be a chip or a chip system, reference may be made to the schematic structural diagram of the chip shown in FIG11 .

[0421] As shown in Figure 11 , chip 110 includes a processor 1101 and an interface 1102. There may be one or more processors 1101, and there may be multiple interfaces 1102. It should be noted that the functions corresponding to processor 1101 and interface 1102 can be implemented through hardware design, software design, or a combination of hardware and software, without limitation.

[0422] Optionally, the chip 110 may further include a memory 1103 , which is used to store necessary program instructions and data.

[0423] In the present application, processor 1101 may be configured to call from memory 1103 a program for implementing the communication method provided in one or more embodiments of the present application in one or more devices or nodes in a UE, SMF, or AAA server, and execute the instructions contained in the program. Interface 1102 may be configured to output the execution results of processor 1101. In the present application, interface 1102 may be specifically configured to output various messages or information from processor 1101.

[0424] Regarding the communication method provided by one or more embodiments of the present application, reference may be made to the embodiments shown in Figures 5, 6, 7, and 8 above, which will not be repeated here.

[0425] The processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0426] The memory in the embodiments of the present application is used to provide storage space, in which data such as an operating system and computer programs can be stored. The memory includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).

[0427] According to the method provided in the embodiment of the present application, the embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program runs on one or more processors, the method shown in Figures 5, 6, 7, and 8 can be implemented.

[0428] According to the method provided in the embodiment of the present application, the embodiment of the present application also provides a computer program product, which includes a computer program. When the computer program runs on a processor, it can implement the methods shown in Figures 5, 6, 7, and 8 above.

[0429] An embodiment of the present application also provides a system, which includes at least one communication device 90 or communication device 100 or chip 110 as described above, and is used to execute the steps executed by the corresponding device in any of the embodiments of Figures 5, 6, 7, and 8.

[0430] An embodiment of the present application also provides a system, which includes at least one of a UE, an SMF, and an AAA server. The first host node is used to execute the steps executed by the first host node in any of the above-mentioned Figures 5, 6, 7, and 8. The UE is used to execute the steps executed by the UE in any of the above-mentioned Figures 5, 6, 7, and 8. The SMF is used to execute the steps executed by the SMF in any of the above-mentioned Figures 5, 6, 7, and 8. The AAA server is used to execute the steps executed by the AAA server in any of the above-mentioned Figures 5, 6, 7, and 8.

[0431] An embodiment of the present application further provides a processing device, including a processor and an interface; the processor is used to execute the method in any of the above method embodiments.

[0432] It should be understood that the above-mentioned processing device can be a chip. For example, the processing device can be a field programmable gate array (FPGA), a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, a system on chip (SoC), a central processing unit (CPU), a network processor (NP), a digital signal processing circuit (DSP), a microcontroller unit (MCU), a programmable logic device (PLD) or other integrated chip. The various methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.

[0433] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0434] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a high-density digital video disc (DVD)), or a semiconductor medium (eg, a solid state disc (SSD)).

[0435] The units in the above-mentioned various apparatus embodiments completely correspond to the electronic devices in the method embodiments, and the corresponding modules or units perform the corresponding steps. For example, the communication unit (transceiver) performs the receiving or sending steps in the method embodiments, and other steps except sending and receiving can be performed by the processing unit (processor). The functions of the specific units can be referred to the corresponding method embodiments. Among them, there can be one or more processors.

[0436] It is understood that in the embodiments of the present application, the electronic device can perform some or all of the steps in the embodiments of the present application. These steps or operations are merely examples, and the embodiments of the present application can also perform other operations or variations of various operations. In addition, the various steps can be performed in a different order than those presented in the embodiments of the present application, and it is possible that not all operations in the embodiments of the present application need to be performed.

[0437] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0438] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0439] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0440] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0441] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0442] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.

[0443] The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.

Claims

1. A communication method, characterized in that: The method comprises: The network unit receives first request information, where the first request information is used to indicate a protocol data unit PDU session establishment request, a PDU session modification request, or an authentication request; the PDU session establishment request is used to request establishment of a target PDU session, and the PDU session modification request is used to request modification of the target PDU session, where the target PDU session is used to connect a user equipment UE and a data network DN; The first request information includes first indication information, where the first indication information is used to indicate a target identifier of a target object, where the target object includes any one of a first user, a first device, and a first application; and the target object is associated with the UE; The authentication request is used to request triggering of secondary authentication of the target object; The target identifier of the target object is used to determine whether to perform the secondary authentication.

2. The method according to claim 1, characterized in that In a case where the first request information is used to indicate the PDU session establishment request or the PDU session modification request, the network unit is a session management function SMF; the target identifier of the target object includes a user identifier of the target object and / or a specific identity identifier EAP ID within a data network area of the target object; When the target trigger condition is met, the SMF sends a second request message, where the second request message is used to request authentication information, and the authentication information is used for the secondary authentication; The target trigger condition includes a first trigger condition and a second trigger condition; The first trigger condition includes any one of the following: the SMF determines to perform the secondary authentication based on the subscription data of the target object and the user identifier of the target object, or the SMF determines to perform the secondary authentication based on the association policy of the DN and the user identifier of the target object; The second trigger condition includes: the authentication result corresponding to the user identifier of the target object in the first authentication result of the target PDU session is failed, or the first request information is used to indicate the PDU session establishment request; The first authentication result includes an authentication result corresponding to the user identifier.

3. The method according to claim 2, characterized in that The method further includes: the SMF receiving first response information of the second request information; In a case where the target identifier of the target object is the user identifier of the target object, the first response information includes the EAP ID of the target object.

4. The method according to claim 2 or 3, characterized in that The first authentication result also includes an authentication result corresponding to the EAP ID; The second trigger condition also includes that the authentication result corresponding to the EAP ID of the target object in the first authentication result is failure.

5. The method according to claim 1, wherein In the case where the first request information is used to indicate the authentication request, the network unit is the DN; the target identifier of the target object includes the user identifier of the target object and the EAP ID of the target object, and the first request information further includes the target PDU session identifier; If the authentication result corresponding to the EAP ID of the target object in the second authentication result of the target PDU session is a failure, the DN sends a third request information, where the third request information is used to instruct the SMF to determine whether to perform the secondary authentication; The second authentication result includes an authentication result corresponding to the EAP ID; and the third request information includes the target PDU session identifier, the user identifier of the target object, and the EAP ID of the target object.

6. The method according to claim 5, characterized in that The method further comprises: The DN receives fourth request information, where the fourth request information is used to request the secondary authentication; The DN sends a second response message to the fourth request message, where the second response message is used to indicate an authentication result of the secondary authentication; The fourth request information includes the target PDU session identifier and the EAP ID of the target object; the second response information includes the target PDU session identifier, the EAP ID of the target object and the authentication result of the secondary authentication, and the authentication result of the secondary authentication includes success or failure.

7. The method according to claim 6, characterized in that Before the DN receives the fourth request information, the method further includes: The SMF receives the third request information; The SMF determines to perform the secondary authentication based on the subscription data of the target object and the user identifier of the target object, or the SMF determines to perform the secondary authentication based on the association policy of the DN and the user identifier of the target object.

8. The method according to claim 6 or 7, characterized in that The method further comprises: The DN updates the second authentication result based on the authentication result of the secondary authentication.

9. The method according to any one of claims 2 to 8, characterized in that: The method further comprises: The SMF sends a fourth request message, where the fourth request message is used to request the secondary authentication; The SMF receives second response information of the fourth request information, where the second response information is used to indicate an authentication result of the secondary authentication; The fourth request information includes the target PDU session identifier and the EAP ID of the target object; the second response information includes the target PDU session identifier, the EAP ID of the target object and the authentication result of the secondary authentication, and the authentication result of the secondary authentication includes success or failure.

10. The method according to claim 9, characterized in that In a case where the first request information is used to indicate the PDU session establishment request, the SMF creates a first authentication result based on the authentication result of the secondary authentication; The first authentication result includes an authentication result corresponding to the user identifier of the target object and / or the EAP ID of the target object; In the case where the first request information is used to indicate the PDU session modification request or authentication request, the SMF updates the first authentication result based on the authentication result of the secondary authentication.

11. The method according to any one of claims 2 to 4 or claim 10, characterized in that When all authentication results included in the first authentication result are failures, the SMF releases the target PDU session.

12. A communication device, characterized in that: comprising a logic circuit and an interface, wherein the logic circuit and the interface are coupled; The interface is used to input data to be processed, the logic circuit processes the data to be processed according to the method according to any one of claims 1 to 11 to obtain processed data, and the interface is used to output the processed data.

13. A computer-readable storage medium, characterized in that include: The computer-readable storage medium is used to store instructions or computer programs; when the instructions or the computer program are executed, the method according to any one of claims 1 to 11 is implemented.

14. A computer program product, characterized in that include: instructions or computer programs; When the instructions or the computer program are executed, the method according to any one of claims 1 to 11 is performed.

15. A communication system, characterized in that: include: UE, SMF and DN; The UE is used to send first request information, where the first request information is used to indicate a PDU session establishment request or a PDU session modification request; The PDU session establishment request is used to request establishment of a target PDU session, and the PDU session modification request is used to request modification of the target PDU session, where the target PDU session is used to connect the UE and the DN; The first request information includes first indication information, where the first indication information is used to indicate a target identifier of a target object, where the target object includes any one of a first user, a first device, and a first application; and the target object is associated with the UE; The target identification of the target object includes the user identification of the target object and / or the EAP ID of the target object; The SMF receives the first request information and determines whether to perform secondary authentication on the target object based on the target identifier of the target object; If the SMF determines to perform the secondary authentication, the SMF sends a fourth request message, where the fourth request message is used to request the secondary authentication; The DN receives the fourth request information and sends a second response information to the fourth request information, where the second response information is used to indicate the authentication result of the secondary authentication; the authentication result of the secondary authentication includes success or failure; The fourth request information and the second response information include the EAP ID of the target object.

16. The communication system according to claim 15, wherein: In a case where the first request information is used to indicate a PDU session establishment request, the SMF establishes a first authentication result, where the first authentication result includes an authentication result corresponding to the user identifier and / or an authentication result corresponding to the EAP ID; In a case where the first request information is used to indicate a PDU session modification request, the SMF modifies the first authentication result.

17. A communication system, characterized in that: include: UE, SMF and DN; The UE is used to send first request information, where the first request information is used to indicate an authentication request; The first request information includes first indication information, the first indication information is used to indicate a target identifier of a target object, the target object includes any one of a first user, a first device, and a first application; the target object is associated with the UE; the authentication request is used to request triggering secondary authentication of the target object; the target identifier of the target object includes a user identifier of the target object and an EAP ID of the target object; The DN receives the first request information and determines whether to perform the secondary authentication based on the EAP ID of the target object; If the authentication result corresponding to the EAP ID of the target object in the second authentication result of the target PDU session is a failure, the DN sends a third request information, where the third request information is used to instruct the SMF to determine whether to perform the secondary authentication; The second authentication result includes an authentication result corresponding to the EAP ID; The SMF receives the third request information, where the first request information and the third request information include the target identifier of the target object; If the SMF determines to perform the secondary authentication, the SMF sends a fourth request message, where the fourth request message is used to request the secondary authentication; The DN receives the fourth request information and sends a second response information to the fourth request information, where the second response information is used to indicate the authentication result of the secondary authentication; the authentication result of the secondary authentication includes success or failure; The fourth request information and the second response information include the EAP ID of the target object.

18. The communication system according to claim 17, wherein: The SMF updates the first authentication result based on the authentication result of the secondary authentication, and the DN updates the second authentication result based on the authentication result of the secondary authentication; The first authentication result includes an authentication result corresponding to the user identifier and / or an authentication result corresponding to the EAP ID.

Citation Information

Patent Citations

  • Protocol data unit session authentication method, system and related equipment

    CN114640994A

  • Authentication method and system in 5G network

    CN117241265A

  • Authentication and authorization method and apparatus

    US20230087407A1

  • Method and apparatus for performing secondary authentication / authorization for terminal device in communication network

    WO2023185737A1