Method and apparatus for establishing user-based session in wireless communication system
By integrating user profile-based authentication in the AMF, wireless communication systems can deliver customized network services that match the current user's preferences, addressing the limitations of subscriber-centric service delivery.
Patent Information
- Application Number
- PCT/KR2025/004458
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-04
- Filing Date
- 2025-04-03
- Publication Date
- 2025-10-09
AI Technical Summary
Existing wireless communication systems struggle to provide customized network services based on the actual user preferences, as they rely solely on subscriber information, which may not align with the current user's needs, leading to suboptimal service delivery.
Implementing a method and device that utilize user profile-based authentication in the Access and Mobility Management Function (AMF) to identify and authenticate users, allowing for personalized network services by incorporating user profiles alongside subscriber information.
Enables the provision of tailored network services that align with the current user's preferences, enhancing user experience and service efficiency by ensuring that network settings are optimized for the actual user's requirements.
Smart Images

Figure KR2025004458_09102025_PF_FP_ABST
Abstract
Description
Method and device for establishing a user-based session in a wireless communication system
[0001] The present disclosure relates to a wireless communication system, and more particularly, to a method and device for authenticating a user for establishing a user-based session. In particular, the present disclosure relates to a method and device for authenticating a requesting user when establishing a user profile-based data session for user data transmission.
[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in the sub-6GHz band, such as 3.5 gigahertz (3.5GHz), but also in the ultra-high frequency band (Above 6GHz), also called millimeter wave (mmWave), such as 28GHz and 39GHz. In addition, for 6G mobile communication technology, which is called the system after 5G communication (Beyond 5G), implementation in the terahertz (THz) band (for example, 3 THz band at 95GHz) is being considered to achieve a transmission speed that is 50 times faster than 5G mobile communication technology and ultra-low latency that is reduced to one-tenth.
[0003] In the early stages of 5G mobile communication technology, the goal is to support services and satisfy performance requirements for ultra-wideband services (eMBB: enhanced Mobile Broadband), ultra-reliable / ultra-low-latency communications (URLLC: Ultra-Reliable Low-Latency Communications), and massive Machine-Type Communications (mMTC). These include beamforming and massive MIMO (Massive MIMO) to alleviate path loss of radio waves in ultra-high frequency bands and increase the transmission distance of radio waves, support for various numerologies (such as operation of multiple sub-carrier intervals) and dynamic operation of slot formats for efficient use of ultra-high frequency resources, initial access technology to support multi-beam transmission and wideband, definition and operation of BWP (Bidth Part), new channel coding methods such as LDPC (Low Density Parity Check) codes for large-capacity data transmission and polar codes for reliable transmission of control information, L2 pre-processing, and specific services. Standardization has been progressed for network slicing, which provides specialized, dedicated networks.
[0004] Currently, discussions are underway to improve and enhance the initial 5G mobile communication technology in consideration of the services that 5G mobile communication technology was intended to support, and physical layer standardization is in progress for technologies such as V2X (Vehicle-to-Everything) to help autonomous vehicles make driving decisions and increase user convenience based on their own location and status information transmitted by vehicles, NR-U (New Radio Unlicensed) for the purpose of system operation that complies with various regulatory requirements in unlicensed bands, NR terminal low power consumption technology (UE Power Saving), Non-Terrestrial Network (NTN), which is direct terminal-satellite communication to secure coverage in areas where communication with terrestrial networks is impossible, and Positioning.
[0005] In addition, standardization of wireless interface architecture / protocols is in progress for technologies such as intelligent factories (IIoT: Industrial Internet of Things) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) to provide nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement technology including Conditional Handover and Dual Active Protocol Stack (DAPS) handover, and 2-step random access (2-step RACH for NR) to simplify random access procedures. Standardization is also in progress for system architecture / services such as 5G baseline architecture (e.g., Service-based Architecture: SBA, Service-based Interface: SBI) for grafting Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) that provides services based on the location of the terminal.
[0006] When such 5G mobile communication systems are commercialized, an explosive increase in connected devices will be connected to the communication network, which will require enhanced functions and performance of 5G mobile communication systems and integrated operation of connected devices. To this end, new research will be conducted on improving 5G performance and reducing complexity, supporting AI services, supporting metaverse services, and drone communications by utilizing eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).
[0007] In addition, the development of these 5G mobile communication systems includes new waveforms to ensure coverage in the terahertz band of 6G mobile communication technology, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas, metamaterial-based lenses and antennas to improve the coverage of terahertz band signals, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), Reconfigurable Intelligent Surface (RIS) technology, as well as full duplex technology to improve the frequency efficiency and system network of 6G mobile communication technology, satellite, and AI (Artificial Intelligence) from the design stage and internalize end-to-end AI support functions to realize system optimization, and ultra-high-performance communication and computing resources to realize services with complexity that exceeds the limits of terminal computing capabilities. It could serve as a basis for the development of next-generation distributed computing technologies.
[0008] The present disclosure provides a method and device for authenticating a requesting user when establishing a user profile-based data session in a wireless communication system.
[0009] The technical problems to be achieved in the present invention are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present invention belongs from the description below.
[0010] According to one embodiment of the present disclosure, a method for communication by an access and mobility management function (AMF) in a wireless communication system is disclosed. The method may include the steps of: obtaining a list of user profiles from a unified data management (UDM); receiving a message for a protocol data unit (PDU) session establishment request from a user equipment (UE), wherein the message for the PDU session establishment request includes a user identifier; identifying a user profile associated with the user identifier from the list of user profiles; and determining whether the user identifier is allowed for the UE based on the identified user profile.
[0011] According to one embodiment of the present disclosure, a device for an access and mobility management function (AMF) in a wireless communication system is disclosed. The device includes a transceiver; and at least one processor connected to the transceiver. The at least one processor may be configured to obtain a list of user profiles from a unified data management (UDM), receive a message for a protocol data unit (PDU) session establishment request from a user equipment (UE), wherein the message for the PDU session establishment request includes a user identifier, identify a user profile associated with the user identifier from the list of user profiles, and determine whether the user identifier is allowed for the UE based on the identified user profile.
[0012] One embodiment of the present invention provides a device and method capable of effectively providing a service in a wireless communication system.
[0013] The effects that can be obtained from the present invention are not limited to the effects mentioned above, and other effects not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.
[0014] FIG. 1 is a diagram showing an example of a configuration of a wireless communication system according to an embodiment of the present disclosure, and FIG. 1 exemplifies the configuration of a 5G system.
[0015] Figure 2 is a diagram for explaining a user identifier and a user profile.
[0016] FIGS. 3a, 3b and 3c are diagrams illustrating a user profile-based PDU session creation procedure according to one embodiment of the present disclosure.
[0017] FIG. 4 is a diagram showing the configuration of a terminal according to an embodiment of the present disclosure.
[0018] FIG. 5 is a diagram illustrating a configuration of a base station or network entity according to an embodiment of the present disclosure.
[0019] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the attached drawings. It should be noted that, where possible, identical components are represented by identical reference numerals throughout the attached drawings. Furthermore, detailed descriptions of well-known functions and configurations that may obscure the gist of the present invention will be omitted.
[0020] In describing the embodiments herein, descriptions of technical details that are well known in the technical field to which the present disclosure pertains and are not directly related to the present invention will be omitted. This is to avoid obscuring the gist of the present disclosure by omitting unnecessary explanations and to convey the gist more clearly.
[0021] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size. Identical or corresponding components in each drawing are assigned the same reference numbers.
[0022] The advantages and features of the present disclosure, and the methods for achieving them, will become clearer with reference to the embodiments described in detail below together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. The embodiments are provided only to ensure that the disclosure of the present disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Like reference numerals refer to like elements throughout the specification.
[0023] Furthermore, when describing the present disclosure, detailed descriptions of related functions or configurations will be omitted if they are deemed to unnecessarily obscure the gist of the present disclosure. Furthermore, the terms described below are defined based on the functions of the present disclosure and may vary depending on the intent or custom of the user or operator. Therefore, their definitions should be based on the content throughout this specification.
[0024] Hereinafter, the base station is an entity that performs resource allocation of a terminal, and may be at least one of a gNode B (gNB), an eNode B (eNB), a Node B, a BS (Base Station), a wireless access unit, a base station controller, or a node on a network. The terminal may include a UE (User Equipment), an MS (Mobile Station), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing a communication function. In the present disclosure, the downlink (DL) refers to a wireless transmission path of a signal transmitted from a base station to a terminal, and the uplink (UL) refers to a wireless transmission path of a signal transmitted from a terminal to a base station. In addition, although LTE, LTE-A, or 5G systems may be described below as examples, embodiments of the present disclosure may also be applied to other communication systems having similar technical backgrounds or channel types. For example, this may include the fifth-generation mobile communication technology (5G, new radio, NR) developed after LTE-A. The term "5G" below may also encompass existing LTE, LTE-A, and other similar services. Furthermore, the present disclosure may be applied to other communication systems with some modifications, as determined by a person with skilled technical knowledge, without significantly departing from the scope of the present disclosure.
[0025] At this time, it will be understood that each block of the processing flow diagrams and combinations of the flow diagrams can be performed by computer program instructions. These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flow diagram block(s). These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flow diagram block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).
[0026] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.
[0027] Here, the term '~ unit' used in the present embodiment means a software or hardware component such as an FPGA or ASIC, and the '~ unit' performs certain roles. However, the '~ unit' is not limited to software or hardware. The '~ unit' may be configured to be on an addressable storage medium and may be configured to regenerate one or more processors. Thus, as an example, the '~ unit' includes components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and '~ units' may be combined into a smaller number of components and '~ units' or further separated into additional components and '~ units'. In addition, the components and '~ units' may be implemented to regenerate one or more CPUs within a device or a secure multimedia card. Additionally, in the embodiment, '~bu' may include one or more processors.
[0028] Wireless communication systems are evolving from providing voice-oriented services in the early days to broadband wireless communication systems that provide high-speed, high-quality packet data services, such as communication standards such as 3GPP's HSPA (High Speed Packet Access), LTE (Long Term Evolution or E-UTRA (Evolved Universal Terrestrial Radio Access)), LTE-Advanced (LTE-A), LTE-Pro, 3GPP2's HRPD (High Rate Packet Data), UMB (Ultra Mobile Broadband), and IEEE's 802.16e.
[0029] As a representative example of the above broadband wireless communication system, the LTE system adopts the Orthogonal Frequency Division Multiplexing (OFDM) method in the downlink (DL) and the Single Carrier Frequency Division Multiple Access (SC-FDMA) method in the uplink (UL). The uplink refers to a wireless link in which a terminal (User Equipment (UE) or Mobile Station (MS)) transmits data or control signals to a base station (eNode B, gNode B, or base station (BS)), and the downlink refers to a wireless link in which a base station transmits data or control signals to a terminal. The above multiple access method can distinguish the data or control information of each user by allocating and operating the time-frequency resources for transmitting data or control information to each user so that they do not overlap, that is, so as to achieve orthogonality.
[0030] As the future communications system beyond LTE, 5G communication systems must be able to freely reflect the diverse needs of users and service providers. Therefore, they must support services that simultaneously satisfy these diverse requirements. Services being considered for 5G communication systems include enhanced Mobile Broadband (eMBB), massive Machine Type Communication (mMTC), and Ultra-Reliable Low Latency Communication (URLLC).
[0031] eMBB aims to provide data transmission rates that are significantly higher than those supported by existing LTE, LTE-A, or LTE-Pro. For example, in a 5G communication system, eMBB must be able to support a peak data rate of 20 Gbps in the downlink and a peak data rate of 10 Gbps in the uplink from the perspective of a single base station. Furthermore, 5G communication systems must simultaneously provide the peak data rate and an increased user-perceived data rate for terminals. To meet these requirements, improvements in various transmission and reception technologies, including improved multi-input, multi-output (MIMO) transmission technology, are required. Furthermore, while LTE transmits signals using a maximum transmission bandwidth of 20 MHz in the 2 GHz band, 5G communication systems can meet the data transmission rates required by 5G communication systems by using a wider frequency bandwidth than 20 MHz in the 3-6 GHz or higher 6 GHz band.
[0032] At the same time, mMTC is being considered to support application services such as the Internet of Things (IoT) in 5G communication systems. To efficiently provide the IoT, mMTC requires supporting large-scale terminal connections within a cell, improved terminal coverage, improved battery life, and reduced terminal costs. The IoT requires the ability to support a large number of terminals (e.g., 1,000,000 terminals / km^2) within a cell, as it provides communication capabilities through the attachment of various sensors and devices. Furthermore, terminals supporting mMTC are likely to be located in shadow areas, such as basements, beyond cell coverage due to the nature of the service, and thus may require wider coverage than other services provided by 5G communication systems. Terminals supporting mMTC must be inexpensive, and since frequent battery replacement is unlikely, they may require extremely long battery lifespans, such as 10 to 15 years.
[0033] Finally, URLLC refers to cellular-based wireless communication services used for specific mission-critical purposes. Examples include remote control of robots or machinery, industrial automation, unmanned aerial vehicles (UAVs), remote health care, and emergency alerts. Therefore, URLLC communications must offer extremely low latency and high reliability. For example, services supporting URLLC must meet air interface latency requirements of less than 0.5 milliseconds and a packet error rate (PER) of less than 10^-5. Therefore, for services supporting URLLC, 5G systems must provide shorter transmission time intervals (TTIs) than other services, and design requirements may require the allocation of extensive resources in the frequency band to ensure communication link reliability.
[0034] The three 5G services—eMBB, URLLC, and mMTC—can be multiplexed and transmitted within a single system. To meet the differing requirements of each service, different transmission and reception techniques and parameters can be used. Of course, 5G is not limited to the three services described above.
[0035] In this disclosure, phrases such as "A and / or B", "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can each include any one of the items listed together in that phrase, or all possible combinations thereof. Terms such as "first", "second", or "first" or "second" may be used merely to distinguish the corresponding component from other corresponding components and do not limit the corresponding components in any other respect (e.g., importance or order).
[0036] Hereinafter, the base station is an entity that performs resource allocation of a terminal, and may be at least one of a Node B, a BS (Base Station), an eNB (eNode B), a gNB (gNode B), a wireless access unit, a base station controller, or a node on a network. The terminal may include a UE (User Equipment), an MS (Mobile Station), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing a communication function. In addition, the embodiments of the present disclosure may be applied to other communication systems having a similar technical background or channel form to the embodiments of the present disclosure described below. In addition, the embodiments of the present disclosure may be applied to other communication systems through some modifications without significantly departing from the scope of the present disclosure at the discretion of a person having skilled technical knowledge.
[0037] In the present disclosure, network technology may refer to standard specifications defined by the International Telecommunication Union (ITU) or 3GPP (e.g., TS 23.501, TS 23.502, TS 23.503, etc.), and components included in the network structure of FIG. 1 may each mean a physical entity, or may mean software performing an individual function, or hardware combined with software. Reference symbols shown as Nx, such as N1, N2, N3, ... in the drawings, represent known interfaces between NFs in a 5G core network (CN), and since a related description may refer to the standard specification (TS 23.501), a detailed description will be omitted.
[0038] In the following description, terms used to identify connection nodes, terms referring to network entities (NEs) or network functions (NFs), terms referring to messages, terms referring to interfaces between network entities, terms referring to various identification information, etc. are provided as examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects having equivalent technical meanings may be used.
[0039] For convenience of explanation, some terms and names defined in the 3rd generation partnership project long-term evolution (3GPP) standards may be used. However, the present disclosure is not limited to these terms and names, and can be equally applied to systems conforming to other standards.
[0040] FIG. 1 is a diagram showing an example of a configuration of a wireless communication system according to an embodiment of the present disclosure, and FIG. 1 exemplifies the configuration of a 5G system.
[0041] Referring to FIG. 1, a 5G network may include at least one of the network entities (NE) or network functions (NF) described below.
[0042] (R)AN ((Radio) Access Network) is an entity that performs wireless resource allocation of a terminal, and may be at least one of an eNode B, a Node B, a BS (Base Station), an NG-RAN (Next Generation Radio Access Network), a 5G-AN (5G Access Network), a 5G NR (5G New Radio), a radio access unit, a base station controller, or a node on a network.
[0043] The terminal may include a UE (User Equipment), NG UE (Next Generation UE), MS (Mobile Station), cellular phone, smartphone, computer, IoT (Internet of Things) device, or multimedia system capable of performing communication functions.
[0044] Furthermore, while the embodiments of the present disclosure are described below using a 5G system as an example, the embodiments of the present disclosure can also be applied to other communication systems with similar technical backgrounds. Furthermore, the embodiments of the present disclosure can be applied to other communication systems with some modifications, as determined by a person skilled in the art, without significantly departing from the scope of the present disclosure.
[0045] As wireless communication systems evolve from 4G to 5G, a new core network (CN) called the Next Generation Core (NG Core) or 5GC (5G Core Network) is being defined. This new core network virtualizes all existing network entities (NEs) into network functions (NFs). According to one embodiment of the present disclosure, a network function may refer to a network entity, a network component, or a network resource.
[0046] According to one embodiment of the present disclosure, 5GC may include NFs illustrated in FIG. 1. Of course, the present invention is not limited to the example illustrated in FIG. 1, and 5GC may include more or fewer NFs than the NFs illustrated in FIG. 1.
[0047] The Access and Mobility Management Function (AMF) may be a network function that manages the access and mobility of a terminal (UE). For example, AMF may perform network functions such as terminal registration, connection, reachability, mobility management, access verification, authentication, and mobility event generation.
[0048] A Session Management Function (SMF) may be a network function that manages a Packet Data Network (PDN) connection provided to a user equipment (UE). A PDN connection may be referred to as a Protocol Data Unit (PDU) Session. For example, an SMF may perform network functions such as session management through the establishment, modification, and release of sessions and the maintenance of tunnels between the User Plane Function (UPF) and the RAN, selection and control of the User Plane (UPF), control of traffic processing in the UPF, and control of charging data collection.
[0049] PCF (Policy Control Function) may be a network function that applies the mobile carrier's service policy, charging policy, and PDU Session policy to the terminal.
[0050] Unified Data Management (UDM) can be a network function that stores subscriber information. For example, UDM can perform functions such as generating authentication information for 3GPP security, processing user identifiers (User IDs), managing a list of network functions supporting UEs, and managing subscription information.
[0051] The Network Exposure Function (NEF) may provide information about a terminal to a server outside the 5G network. Additionally, NEF may provide the information necessary for 5G network services and store it in the Unified Data Repository (UDR).
[0052] The User Plane Function (UPF) may function as a gateway that transmits user data (PDU) to the Data Network (DN). More specifically, the UPF may process data so that it can transmit data transmitted by a terminal to an external network or transmit data received from an external network to the terminal. For example, the UPF may perform network functions such as serving as an anchor between Radio Access Technologies (RATs), packet routing and forwarding, packet inspection, user plane policy application, traffic usage report generation, and buffering.
[0053] NRF (Network Repository Function) can store the profiles of NFs and perform the function of discovering NFs.
[0054] AUSF (Authentication Server Function) can perform terminal authentication in 3GPP access networks and non-3GPP access networks.
[0055] NSSF (Network Slice Selection Function) can perform the function of selecting a Network Slice Instance provided to a terminal.
[0056] The Network Data Analytics Function (NWDAF) collects data from multiple NFs (Network Functions) to ensure efficient operation of the 5GC network. This data is analyzed using a machine learning (ML) model, and the results are provided to the NFs, helping them provide efficient network services.
[0057] An Application Function (AF) can communicate with a network operator to enable external servers (Application Servers) to utilize network services provided by the network operator. Depending on the deployment entity, AFs can be categorized as internal AFs and external AFs. Internal AFs deployed by network operators can communicate directly with network functions (NFs) within the network operator. AFs deployed by third-party service providers (3rd-party service providers) must go through an NEF to communicate with NFs within the network operator.
[0058] DN (Data Network) can be a data network where terminals transmit and receive data to use network operator services or third-party services.
[0059] The terminal may include an IoT device. The IoT device may include a device that does not use battery power or operates with very little power, and such IoT devices are referred to as ambient IoT devices (or simply Ambient IoT).
[0060] In the 3GPP system, a conceptual link connecting NFs within a 5G system is defined as a reference point. The following illustrates a reference point included in the 5G system architecture depicted in Figure 1.
[0061] - N1: Reference point between UE and AMF
[0062] - N2: Reference point between (R)AN and AMF
[0063] - N3: Reference point between (R)AN and UPF
[0064] - N4: Reference point between SMF and UPF
[0065] - N5: Reference point between PCF and AF
[0066] - N6: Reference point between UPF and DN
[0067] - N7: Reference point between SMF and PCF
[0068] - N8: Reference point between UDM and AMF
[0069] - N9: Reference point between two core UPFs
[0070] - N10: Reference point between UDM and SMF
[0071] - N11: Reference point between AMF and SMF
[0072] - N12: Reference point between AMF and AUSF
[0073] - N13: Reference points between UDM and AUSF
[0074] - N14: Reference point between two AMFs
[0075] Additionally, in 3GPP systems, the 5G system architecture may include service-based interfaces such as the following examples.
[0076] - Nnssf: Service-based interface by NSSF
[0077] - Nnssaaf: Service-based interface by NSSAAF (Network Slice-Specific Authentication and Authorization Function)
[0078] - Nnef: Service-based interface by NEF
[0079] - Nausf: Service-based interface by AUSF
[0080] - Nnrf: Service-based interface by NRF
[0081] - Namf: Service-based interface by AMF
[0082] - Npcf: Service-based interface by PCF
[0083] - Nsmf: Service-based interface by SMF
[0084] - Nupf: Service-based interface by UPF
[0085] - Nudm: Service-based interface by UDM
[0086] - Naf: Service-based interface by AF
[0087] - Nasaf: Service-based interface by AUSF
[0088] - Neasdf: Service-based interface by EASDF (Edge Application Server Discovery Function)
[0089] - Nnwdaf: Service-based interface by NWDAF
[0090] According to one embodiment of the present disclosure, mobile communication service providers intend to use a user identifier (UI) that identifies the actual user using the terminal in order to provide network services customized to the actual user of the terminal. This is because the terminal subscriber and the actual user using the terminal may be different, and thus providing a customized service based on the terminal subscriber information may differ from the service desired by the actual user using the terminal. Accordingly, a user profile (UI) including information on the actual user using the terminal is additionally stored on the network, and the user ID of the current user using the terminal is provided to the network, so that a customized network service can be provided to the actual terminal user based on the user profile information identified by the UI.
[0091] In this disclosure, a method for authenticating a requesting user when requesting user profile-based PDU session setup is proposed in order to provide the user with the above-described actual terminal user-customized service.
[0092] Figure 2 illustrates a user identifier and a user profile.
[0093] Scenarios for using user IDs can be broadly divided into two categories. The first scenario involves multiple human users on a terminal, while the other involves multiple devices connected to a single terminal. In the first scenario, the terminal could be a variety of devices, including not only mobile phones but also cars, TVs, and public computers.
[0094] In the embodiment of FIG. 2, when User 1 uses a terminal, the subscriber of the terminal may not be User 1. For example, the subscriber may be User 1's father or mother. In this case, the subscriber information (Subscription Data) based on the subscriber's name may differ from the preferences of User 1, who is currently using the terminal. If a customized network service is provided based on existing subscriber information, this may cause a significant gap between the network service desired by User 1, the current terminal user. For example, the subscriber's primary services may be Internet surfing and office-related applications, while User 1's primary services may be games.
[0095] To overcome the limitations of the subscriber information-based network customization service described above, a user ID and user profile-based, terminal-specific network service has been proposed. To achieve this, the network can store not only subscriber information but also user profile information, which is information about the users using the terminal. Furthermore, a user ID, which distinguishes the current terminal user, can be provided to the network in addition to the subscriber ID. This allows the network to be optimized for the services currently preferred by the terminal user based on subscriber information and user profiles.
[0096] In the embodiment of FIG. 2, when User 1, a child, uses a terminal, network setting values can be set to be optimized for the game service preferred by User 1 by referring to a user profile including subscriber information and User 1 information.
[0097] Table 1 shows an example of AM (Access and Mobility Management) information among user profile information for providing terminal user-tailored services.
[0098] User Profile data typeFieldDescriptionUser Profile_AMUser IdentifierIdentify the User and the associated User Profile.Security CredentialUsed for authentication / authorization of the User.UI-AMBRThe maximum aggregated uplink and downlink MBRs to be shared across all Non-GBR QoS Flows according to the User.UI-Slice-MBR(s)List of maximum aggregated uplink and downlink MBRs to be shared across all GBR and Non-GBR QoS Flows related to the same S-NSSAI according to the User. There is a single uplink and a single downlink value per S-NSSAI.UI-Subscribed S-NSSAIsThe Network Slices that the UE subscribes to. In the roaming case, it indicates the subscribed Network Slices applicable to the Serving PLMN.For a subscribed S-NSSAI subject to NSAC for the registered number of UE, the applicable NSAC admission mode is included.Slice Usage Policy informationIncludes:- indication the S-NSSAI is on demand; and- slice deregistration inactivity timer value.The AMF uses this information.S-NSSAIs subject to Network Slice-Specific Authentication and AuthorizationThe Subscribed S-NSSAIs marked as subject to NSSAA when the User is registered. When present, the GPSI list shall include at least one GPSI.Network Slice validity time informationOptionally, if the Subscribed S-NSSAI is temporarily available network slice, one validity time is associated with this S-NSSAI.UI-Charging CharacteristicsIt contains the Charging Characteristics.This information, when provided, shall override any corresponding predefined information at the AMF.UI-PCF Selection Assistance infoList of combination of DNN and S-NSSAI that indicates that the same PCF for the User needs to be selected for AM Policy Control and SM Policy ControlList of associated SUPI(s)List of SUPI(s) in HPLMN which is associated the User.List of associated PEI(s)Optionally, List of PEI(s) in HPLMN which is associated the User.
[0099] Profile information that includes the user's AM-related information among the user profiles. The user ID (User Identifier) is an ID that identifies the user for whom the user profile is related.
[0100] Security Credential is a value used for user authentication / authorization when a user registers on a network.
[0101] UI-AMBR represents per-user AMBR.
[0102] UI-Slice-MBR(s) represents user-specific Slice-MBR(s).
[0103] UI-Subscribed S-NSSAIs represents the S-NSSAIs subscribed per user.
[0104] Slice Usage Policy information shows policy information about the Slice subscribed to by each user.
[0105] S-NSSAIs subject to Network Slice-Specific Authentication and Authorization contain information for authentication / authorization when using a subscribed Slice for each user.
[0106] Network Slice validity time information contains validity time information about the Slice subscribed to by each user.
[0107] UI-Charging Characteristics may contain information about the charges for a specific user to use a network service, as the network services provided to each user may differ.
[0108] UI-PCF Selection Assistance info may include information about PCF selection for each user, as PCF selection for each user may differ due to different QoS for each user in order to provide customized services for each user.
[0109] The List of associated SUPI(s) may include a list of subscriber IDs (i.e. SUPIs) of terminals registered as a user when the user is a user of multiple terminals registered with the same network operator.
[0110] The list of associated PEI(s) may include a list of terminal IDs (i.e. PEIs) of terminals registered as a user when the user is a user of multiple terminals registered with the same network operator.
[0111] Table 2 shows an example of SM (Session Management) information among user profile information for providing terminal user customized services.
[0112] User Profile data typeFieldDescriptionUser Profile_SMUser IdentifierIdentify the User and the associated User Profile.Subscribed DNN listList of the subscribed DNNs for the S-NSSAI.UI-Slice Usage Policy informationIncludes:- indication the S-NSSAI is on demand; and- PDU Session inactivity timer value.The SMF uses this information.UI-Subscribed QoS profileThe QoS Flow level QoS parameter values (5QI and ARP) for the DNN, S-NSSAI.UI-Charging CharacteristicsIt contains Charging Characteristics.This information, when provided, shall override any corresponding predefined information at the SMF.UI-Session-AMBRThe maximum aggregated uplink and downlink MBRs to be shared across all Non-GBR QoS Flows in each PDU Session, which are established for the DNN, S-NSSAI.UI-Secondary authentication indicationIndicates that whether the Secondary authentication / authorization is required for PDU Session Establishment or PDN Connection Establishment.AF-AAA Server UE IP address allocation indicationIndicates that whether the SMF is required to request the UE IP address from the AF-AAA Server for PDU Session Establishment or PDN Connection Establishment.AF-AAA Server addressing / credential informationIf at least one of secondary AF-AAA authentication, AF-AAA authorization or AF-AAA UE IP address allocation is required by User Profile data, the User Profile data may also contain AF-AAA Server addressing and AF-specific credential information.
[0113] This is the profile information that includes the user's SM-related information among the user profiles. The user ID is an ID that identifies the user for whom the user profile is related.
[0114] Subscribed DNN list is a list of DNNs subscribed to by S-NSSAI per user.
[0115] UI-Slice Usage Policy information shows policy information about the Slice subscribed to by each user.
[0116] UI-Subscribed QoS Profile contains per-user subscribed QoS profiles.
[0117] UI-Charging Characteristics may contain information about the charges for a specific user to use a network service, as the network services provided to each user may differ.
[0118] UI-Session-AMBR represents the user-specific Session-AMBR.
[0119] UI-Secondary authentication indication indicates whether secondary authentication is required for accessing the subscribed DNN for each user.
[0120] The AF-AAA Server UE IP address allocation indication indicates whether a UE IP address is requested from the AF used by each user.
[0121] AF-AAA Server addressing / credential information contains information for UI-Secondary authentication indication when a user subscribes to a DNN.
[0122] The present disclosure does not limit user profile information to the user profile information described above. Additional information may be included in the user profile information, as needed.
[0123] FIGS. 3a, 3b and 3c are diagrams illustrating a user profile-based PDU session creation procedure according to one embodiment of the present disclosure.
[0124] In step 0, a terminal may perform a registration procedure with a network. During the network registration procedure, the AMF may receive user profile information (e.g., a list of user profiles) of all (or at least one) users of the terminal from the UDM. The received Access and Mobility (AM)-related user profile information may include: a list of User Identifiers, one or more device IDs (i.e., permanent equipment identifiers (PEIs)) associated with the user profile, and a list of User Credentials for corresponding User Identifiers. In addition, various other information may be included in the AM user profile information.
[0125] In Step 1a, a user can log in to the terminal using a User Identifier. The terminal user login behavior may vary depending on the terminal implementation.
[0126] In step 1b, the terminal can determine the user profile associated with the User Identifier.
[0127] In step 2, when a new service data flow occurs and there is no suitable PDU session created to transmit this flow, the UE performs a new PDU session creation procedure. To do this, it transmits a PDU Session Establishment Request message to the network. This message can be transmitted to the SMF via the AMF. The UL NAS Transport message including the PDU Session Establishment Request message can include: S-NSSAI(s), [Alternative S-NSSAI], UE Requested DNN, PDU Session ID, Request type, and Old PDU Session ID. The PDU Session Establishment Request message transmitted to the SMF can be configured to include the following information: PDU Session ID, Requested PDU Session Type, Requested SSC mode, 5GSM Capability, Protocol Configuration Option (PCO), SM PDU DN Request Container, Number Of Packet Filters, Header Compression Configuration, UE Integrity Protection Maximum Data Rate, Always-on PDU Session Requested, Redundancy Sequence Number (RSN), Connection Capabilities, and PDU Session Pair ID.To create a user profile-based PDU session, the terminal may additionally add a User Identifier and a User Credential associated with the User Identifier to the UL NAS Transport message transmitted to the AMF.
[0128] In step 3, AMF can determine the current user profile information from the List of User Profiles data received from UDM during the terminal network registration procedure using the User Identifier received from the terminal.
[0129] In step 5, the AMF can determine whether the user can use the terminal by referring to the List of PEIs included in the user profile information. In addition, the AMF can perform user authentication and authorization by comparing the User Credential information received from the terminal with the User Credential information included in the user profile information received from the UDM. If the user can use the terminal and user authentication / authorization is successful, the AMF can set an Active User timer and store it in the UE context. While the Active User timer is valid, the user authentication / authorization procedure can be omitted when the user requests a new user profile-based PDU session establishment. In other words, the terminal does not need to include the User Credential in the profile-based PDU session establishment request message. If the Active User timer expires, the user authentication / authorization procedure can be performed when the user requests a new user profile-based PDU session establishment. In other words, the terminal can include the User Credential in the profile-based PDU session establishment request message. Even if the Active User timer expires, the current user's information (i.e., user profile-based PDU session information, etc.) is not deleted.
[0130] In another embodiment, when the Active User timer expires, the current user's information (e.g., user profile-based PDU session information, etc.) may be deleted. To prevent the current user's information from being deleted, the terminal may send a user Authentication / Authorization request message including the User Identifier and User Credential to the AMF (step 4) before the Active User timer expires, so that the AMF may perform the user Authentication / Authorization procedure to reset the Active User timer.
[0131] If the User Profile-based PDU Session Establishment Request message transmitted by the terminal includes the User Identifier of a different user from the current user and the User Credential of the corresponding User, the AMF may consider the current user to have logged out and perform the User Authentication / Authorization procedure for the new user even if the configured Active User timer is valid. If the User Authentication / Authorization procedure for the new user is successful, the AMF may set the Active User timer for the new user and delete the Active User timer for the previous user. In addition, the AMF may request the SMF to release or deactivate all configured User Profile-based PDU sessions of the previous user.
[0132] If the above-described user Authentication / Authorization fails, the AMF may cancel the user profile-based PDU session establishment request procedure. In another embodiment, the terminal may change the PDU session establishment request to a general PDU session establishment instead of a user profile-based PDU session establishment request because the terminal's Authentication / Authorization was successful during the network registration procedure, and may continue the PDU session establishment procedure.
[0133] In step 6, the AMF receives the PDU Session Establishment Request message and selects an appropriate SMF. The AMF may consider the following information to select an SMF: DNN, S-NSSAI, Access Technology, Support for CP CIoT 5GS Optimization, Subscription information from UDM, Local operator policies, Load conditions of candidate SMFs, UE location, Service Area of SMFs, Target DNAI, etc.
[0134] In step 7, AMF sends the Nsmf_PDUSession_CreateSMContext Request message to the selected SMF. This message may contain the following information:SUPI, selected DNN, UE requested DNN, S-NSSAI(s), PDU Session ID, AMF ID, Request Type, [PCF ID, Same PCF Selection Indication], Priority Access, Small Data Rate Control Status, N1 SM Container (PDU Session Establishment Request), User location information, Access Type, RAT Type, Permanent Equipment Identifier (PEI), Generic Public Subscription Identifier (GPSI), UE presence in LADN service area, Subscription For PDU Session Status Notification, DNN Selection Mode, Trace Requirements, Control Plane CIoT 5GS Optimization indication, Control Plane Only indicator, Satellite Backhaul Category (Satellite backhaul category), GEO Satellite ID, [PVS FQDN(s) and / or PVS IP address(es), Onboarding Indication], Disaster Roaming service indication.For user profile-based PDU session setup, AMF may include a User Profile Identifier in the Nsmf_PDUSession_CreateSMContext Request that can distinguish the user profile received from the UDM. Alternatively, AMF may include a User Identifier in the above message to enable SMF to distinguish the user profile.
[0135] In step 8, if the subscriber information corresponding to the requested SUPI, DNN, and S-NSSAI does not exist in the SMF, the SMF sends a Nudm_SDM_Get message to the UDM to request the UE's Session Management Subscription data. This message may include the following information: SUPI, Session Management Subscription data, selected DNN, S-NSSAI of HPLMN, Serving PLMN ID, and Network Identifier (NID). In case of user profile-based PDU session establishment, the SMF may request the User Profile data from the UDM / UDR using the User Profile Identifier or User Identifier received from the AMF.
[0136] In step 9, SMF sends the Nsmf_PDUSession_CreateSMContext Response message or the Nsmf_PDUSession_UpdateSMContext Response message to AMF. This message may contain the following information: Cause, SM Context ID, or N1 SM container (PDU Session Rejection Cause).
[0137] If Secondary Authentication / Authorization is required in step 10, the SMF can perform the PDU Session establishment authentication / authorization procedure with the DN-AAA Server.
[0138] In step 11, if dynamic PCC is applied to the PDU Session, the SMF can select a PCF and establish an SM Policy Association. The SMF may consider the following information to select a PCF for the PDU Session it creates: local operator policies, DNN, S-NSSAI, SUPI, PCF selected for UE, PCF Group ID provided by AMF, PCF Set ID, Same PCF Selection Indication. The SMF establishes an SM Policy Association with the PCF and requests default PCC Rules for the PDU Session. In case of user profile-based PDU Session establishment, the SMF may include the User Profile Identifier or User Identifier in the message it sends to the PCF (e.g., the message for SM Policy Association or the message for requesting default PCC Rules).
[0139] In Step 12, the SMF can perform the PCF and SM Policy Association setup procedure. This procedure allows the SMF to receive default PCC Rules from the PCF that apply to the PDU session it creates. In the case of user profile-based PDU session setup, the PCF can send the SMF the User Profile Identifier or the User Profile-based PDU session Policy Control information associated with the User Identifier.
[0140] In step 13, the SMF selects a UPF to serve the PDU session being created. The SMF may consider the following information to select a UPF: UPF's dynamic load, UPF location available at SMF, DNN, PDU Session Type, SSC mode, UE subscription profile, DNAI, S-NSSAI, Access technology, Information related to user plane topology, Support for UPF allocation of IP address / prefix, Support for high latency communication.
[0141] In step 14, the SMF can perform the SM Policy Association Modification procedure. This procedure allows the PCF to update its policy with the SMF. It can also generate a PCC rule based on the URSP rule for the PDU Session.
[0142] In steps 15a and 15b, the establishment and modification of N4 sessions can be performed between the SMF and the selected UPF. To this end, the SMF can transmit the following information to the UPF: packet detection, enforcement, and reporting rules.
[0143] In step 16, the SMF sends a Namf_Communication_N1N2MessageTransfer message to the AMF. This message may contain the following information: PDU Session ID, N2 SM information (PDU Session ID, QFI(s), QoS Profile(s), CN Tunnel Info, S-NSSAI from the Allowed NSSAI, Session-AMBR, PDU Session Type, User Plane Security Enforcement information, UE Integrity Protection Maximum Data Rate, RSN, PDU Session Pair ID, TL-Container), N1 SM container (PDU Session Establishment Accept / Reject)).
[0144] The N1 SM Container (PDU Session Establishment Accept) message included in this message may contain the following information: [QoS Rule(s) and QoS Flow level QoS parameters if needed for the QoS Flow(s) associated with the QoS rule(s)], selected SSC mode, S-NSSAI(s), UE Requested DNN, allocated IPv4 address, interface identifier, Session-AMBR, selected PDU Session Type, [Reflective QoS Timer] (if available), [P-CSCF address(es)], [Control Plane Only indicator], [Header Compression Configuration], [Always-on PDU Session Granted], [Small Data Rate Control] [Small Data Rate Control parameters], [Small Data Rate Control Status], [Serving PLMN Rate Control], [PVS FQDN(s) and / or PVS IP address(es)]). In case of user profile-based PDU session establishment, AMF may send the Active User timer to the terminal by including the Active User timer in the message.
[0145] In step 17, AMF may send a NAS message to (R)AN containing N2 SM information and a PDU Session Establishment Accept message.
[0146] In step 18, (R)AN may transmit a NAS message including a PDU Session Establishment Accept message received from AMF to the terminal.
[0147] In step 19, (R)AN may send an N2 PDU Session Response message to AMF. This message may contain the following information: PDU Session ID, Cause, N2 SM information (PDU Session ID, AN Tunnel Info, List of accepted / rejected QFI(s), User Plane Enforcement Policy Notification, TL-Container, established QoS Flows status (active / not active) for QoS monitoring configuration for congestion information, established QoS Flows status (active / not active) for ECN marking for L4S, PDU Set Based Handling Support Indication).
[0148] In step 20, AMF sends the Nsmf_PDUSession_UpdateSMContext Request message to SMF. This message may contain the following information: SM Context ID, N2 SM information, and Request Type.
[0149] In steps 21a and 21b, the SMF and UPF exchange N4 Session Modification Request / Response messages. If a specific UPF feature is not supported due to UP resource issues, the UPF feature is disabled. If the PDU session establishment is rejected, the N4 session for the corresponding PDU session may also be released.
[0150] In step 22, the SMF registers the PDU session-related information with the UDM using the Nudm_UECM_Registration message. This message may include the following information: SUPI, DNN, HPLMN's S-NSSAI, PDU session ID, SMF identity, Serving Node PLMN ID, [NID].
[0151] At step 23, SMF may send an Nsmf_PDUSession_UpdateSMContext Response message to AMF.
[0152] In step 24, if the PDU Session Establishment procedure is not successful, the SMF can notify the AMF by sending the Nsmf_PDUSession_SMContextStatusNotify message.
[0153] If the PDU Session Type requested for creation in step 25 is IPv6 or IPv4v6, SMF can create an IPv6 Router Advertisement message and transmit it to the terminal.
[0154] If 5GS Bridge / Router information is available at step 26, SMF can initiate SM Policy Association Modification procedure to PCF.
[0155] In step 27, if the PDU Session Establishment procedure fails, the SMF may disable notification service for changes in Session Management Subscription data.
[0156] FIG. 4 is a diagram showing the configuration of a terminal according to an embodiment of the present disclosure.
[0157] A terminal according to one embodiment of the present disclosure may include a processor (420) that controls the overall operation of the terminal, a transceiver (400) including a transmitter and a receiver, and a memory (410). Of course, the present invention is not limited to the above example, and the terminal may include more or fewer components than those illustrated in FIG. 4.
[0158] According to one embodiment of the present disclosure, a transceiver (400) can transmit and receive signals with network entities or other terminals. The signals transmitted and received with network entities may include control information and data. In addition, the transceiver (400) can receive signals via a wireless channel, output them to a processor (420), and transmit the signals output from the processor (420) via the wireless channel.
[0159] According to one embodiment of the present disclosure, the processor (420) can control the terminal to perform any one of the operations described above. Meanwhile, the processor (420), the memory (410), and the transceiver (400) do not necessarily have to be implemented as separate modules, and of course, they can be implemented as a single component in the form of a single chip. In addition, the processor (420) and the transceiver (400) can be electrically connected. In addition, the processor (420) can be an Application Processor (AP), a Communication Processor (CP), a circuit, an application-specific circuit, or at least one processor.
[0160] According to one embodiment of the present disclosure, the memory (410) can store data such as basic programs, application programs, and setting information for the operation of the terminal. In particular, the memory (410) provides the stored data upon request of the processor (420). The memory (410) can be configured as a storage medium or a combination of storage media such as a ROM, a RAM, a hard disk, a CD-ROM, and a DVD. In addition, there can be a plurality of memories (410). In addition, the processor (420) can perform the above-described embodiments based on a program for performing the above-described embodiments of the present disclosure stored in the memory (410).
[0161] FIG. 5 is a diagram illustrating a configuration of a base station or network entity according to an embodiment of the present disclosure.
[0162] A network entity according to one embodiment of the present disclosure may include a processor (520) that controls the overall operation of the network entity, a transceiver (500) including a transmitter and a receiver, and a memory (510). Of course, the present invention is not limited to the above example, and the network entity may include more or fewer components than those illustrated in FIG. 5.
[0163] According to one embodiment of the present disclosure, a transceiver (500) can transmit and receive signals with at least one of other network entities or terminals. The signals transmitted and received with at least one of other network entities or terminals may include control information and data.
[0164] According to one embodiment of the present disclosure, the processor (520) can control a network entity to perform any one of the operations described above. Meanwhile, the processor (520), the memory (510), and the transceiver (500) do not necessarily have to be implemented as separate modules, and of course, they can be implemented as a single component in the form of a single chip. In addition, the processor (520) and the transceiver (500) can be electrically connected. In addition, the processor (520) can be an Application Processor (AP), a Communication Processor (CP), a circuit, an application-specific circuit, or at least one processor.
[0165] According to one embodiment of the present disclosure, the memory (510) can store data such as basic programs, application programs, and setting information for the operation of a network entity. In particular, the memory (510) provides the stored data upon request of the processor (520). The memory (510) can be configured as a storage medium or a combination of storage media such as a ROM, a RAM, a hard disk, a CD-ROM, and a DVD. In addition, there can be a plurality of memories (510). In addition, the processor (520) can perform the above-described embodiments based on a program for performing the above-described embodiments of the present disclosure stored in the memory (510).
[0166] It should be noted that the aforementioned configuration diagrams, examples of control / data signal transmission methods, examples of operational procedures, and configuration diagrams are not intended to limit the scope of the present disclosure. That is, not all components, entities, or operational steps described in the embodiments of the present disclosure should be construed as essential components for implementing the disclosure, and implementations may be made within a scope that does not detract from the essence of the disclosure even if only some components are included. Furthermore, each embodiment may be combined and operated as needed. For example, parts of the methods proposed in the present disclosure may be combined to operate network entities and terminals.
[0167] The operations of the base station or terminal described above can be realized by providing a memory device storing the corresponding program code in any component within the base station or terminal device. That is, the control unit of the base station or terminal device can execute the operations described above by reading and executing the program code stored in the memory device using a processor or CPU (Central Processing Unit).
[0168] The various components and modules of the entity, base station or terminal device described in this specification may be operated using hardware circuits, such as logic circuits based on complementary metal oxide semiconductors, firmware, software and / or hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates and application-specific semiconductors.
[0169] When implemented in software, a computer-readable storage medium storing one or more programs (software modules) may be provided. The one or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. The one or more programs include instructions that cause the electronic device to execute methods according to the embodiments described in the claims or specification of the present disclosure.
[0170] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read only memory (ROM), electrically erasable programmable read only memory (EEPROM), magnetic disc storage device, compact disc ROM (CD-ROM), digital versatile discs (DVDs) or other forms of optical storage device, magnetic cassette. Or, they may be stored in a memory configured as a combination of some or all of these. In addition, each configuration memory may be included in multiple numbers.
[0171] Additionally, the program may be stored in an attachable storage device that is accessible via a communication network such as the Internet, an intranet, a local area network (LAN), a wide local area network (WLAN), a storage area network (SAN), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure via an external port. Additionally, a separate storage device on the communication network may be connected to a device performing an embodiment of the present disclosure.
[0172] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed in the singular or plural form, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Components expressed in the plural form may be composed of singular elements, or components expressed in the singular form may be composed of plural elements.
[0173] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is obvious that various modifications are possible without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be determined not only by the scope of the following claims but also by equivalents of the scope of the claims. In other words, it will be apparent to those skilled in the art to which the present disclosure pertains that other modifications based on the technical idea of the present disclosure are possible. In addition, each of the above embodiments can be combined and operated with each other as needed. For example, parts of the methods proposed in the present disclosure can be combined with each other to operate a base station and a terminal. In addition, although the above embodiments have been presented based on a 5G, NR system, other modifications based on the technical idea of the above embodiments can be implemented with other systems such as LTE, LTE-A, and LTE-A-Pro systems.
[0174] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.
Claims
1. A method for communication by AMF (access and mobility management function) in a wireless communication system, A step of obtaining a list of user profiles from UDM (unified data management); A step of receiving a message for a PDU (protocol data unit) session establishment request from a user equipment (UE), wherein the message for the PDU session establishment request includes a user identifier; A step of identifying a user profile associated with the user identifier from the list of user profiles; and A step of determining whether the user identifier is allowed for the UE based on the identified user profile, method.
2. In paragraph 1, The step of determining whether the user identifier is allowed for the user includes the step of determining whether the user identifier is allowed for the UE based on a list of permanent equipment identifiers (PEIs) included in the identified user profile. method.
3. In paragraph 1, If the user identifier included in the message for the PDU session establishment request is different from the user identifier for the current user, the method further includes the step of releasing the PDU sessions associated with the current user if the user identifier is authenticated. method.
4. In paragraph 1, A step of performing an authentication and authorization procedure for a user associated with the user identifier based on the user credential information included in the PDU session setup message and the user credential information included in the identified user profile; and If the authentication and authorization for the user is successful, further comprising the step of setting an active user timer for the user, While the above active user timer is running, authentication and authorization procedures for other PDU session establishments related to the above user are omitted. method.
5. In paragraph 4, While the active user timer for the user is running, receiving a message including the user identifier and the user credentials for the user from the UE; and Further comprising the step of resetting the active timer based on receiving a message including the user identifier and the user credentials for the user while the active user timer for the user is running. method.
6. In paragraph 4, Further comprising the step of transmitting a message to the UE including information about an active user timer for the user; method.
7. In paragraph 4, Further comprising the step of canceling the PDU session setup procedure for the user if the authentication and authorization for the user fails. method.
8. In paragraph 1, Further comprising the step of transmitting a message for establishing a PDU session to the SMF (session management function), The message for establishing the PDU session includes at least one of a user profile identifier for the identified user profile and the user identifier. method.
9. In paragraph 1, It further includes a step of transmitting a message for SM (session management) policy association with PCF (policy control function), The message for linking the above SM policy includes a user profile identifier for the identified user profile and at least one of the user identifiers. method.
10. In paragraph 9, Further comprising the step of receiving, from the PCF, a user profile identifier for the user profile or PDU session policy control information associated with the user identifier. method.
11. As a device of AMF (access and mobility management function) in a wireless communication system, Transmitter and receiver; and At least one processor coupled to the transceiver, wherein the at least one processor comprises: Obtain a list of user profiles from UDM (unified data management), Receive a message for a PDU (protocol data unit) session setup request from a user equipment (UE), wherein the message for the PDU session setup request includes a user identifier; Identifying a user profile associated with the user identifier from the list of user profiles; and configured to determine whether the user identifier is allowed for the UE based on the identified user profile; device.
12. In paragraph 11, wherein said at least one processor is configured to determine whether said user identifier is allowed for said UE based on a list of permanent equipment identifiers (PEIs) included in said identified user profile; device.
13. In paragraph 11, If the user identifier included in the message for the PDU session establishment request is different from the user identifier for the current user, the at least one processor is configured to release the PDU sessions associated with the current user if the user identifier is authenticated. device.
14. In paragraph 11, At least one processor of the above: Performing authentication and authorization procedures for a user associated with the user identifier based on the user credential information included in the PDU session setup message and the user credential information included in the identified user profile; and If the authentication and authorization for the above user is successful, it is further configured to set an active user timer for the above user, While the above active user timer is running, authentication and authorization procedures for other PDU session establishments related to the above user are omitted. device.
15. In paragraph 11, wherein said at least one processor is further configured to operate according to the method of any one of claims 5 to 10; device.
Citation Information
Patent Citations
Accessing a mobile communication network using a user identifier
US20220345887A1
KR20230019930A