Communication method, device, and storage medium

By introducing various network functions and terminal modules into the communication system to perform authentication and authorization for user access services, the problem of the inability of existing technologies to effectively support end-user authentication and authorization is solved, thereby improving the security of the communication system.

WO2025213348A1PCT designated stage Publication Date: 2025-10-16BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/086684
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-08
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

Existing communication security architectures cannot effectively support end-user authentication and authorization, resulting in insufficient communication security.

Method used

By introducing the first network function, the second network function, the third network function, the first terminal and the user identity recognition module, authentication and authorization of user access to services are performed, and the security architecture is enhanced to support user authentication and authorization.

Benefits of technology

It achieves safe and reliable authentication and authorization of user access to services, and improves the security of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024086684_16102025_PF_FP_ABST
    Figure CN2024086684_16102025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a communication method, a device, and a storage medium. The method is executed by a first network function. The method comprises: performing authentication and / or authorization while a subscriber accesses a service, wherein the subscriber is a subscriber associated with a subscription relationship of a first terminal, and the first network function is a network function in a home network (HN) of the first terminal. A communication mechanism of the technical solution provided by the embodiments of the present disclosure can enhance a security architecture to support authentication and authorization of subscribers.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, apparatus, and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, apparatus, and storage medium. BACKGROUND

[0002] In the technical field of communication, the user to be identified can be a personal user using a terminal with a clear subscription, or an application running on a terminal or connected via a terminal, or a personal user of a device behind a gateway terminal. The related security architecture supports authentication and authorization of terminals with a subscription identifier for establishing a connection, but does not support authentication and authorization of users on or behind terminals.

[0003] SUMMARY

[0004] It is necessary to study how to enhance the security architecture to support authentication and authorization of users.

[0005] Embodiments of the present disclosure provide a communication method, a first network function, a second network function, a third network function, a first terminal, a user identity module, a communication system, and a storage medium.

[0006] According to a first aspect of embodiments of the present disclosure, a communication method is provided, the method being performed by a first network function, and the method comprising:

[0007] performing authentication and / or authorization of a user accessing a service;

[0008] wherein the user is associated with a subscription relationship with a first terminal, and the first network function is a network function in a home network HN of the first terminal.

[0009] According to a second aspect of embodiments of the present disclosure, a communication method is provided, the method being performed by a second network function, and the method comprising:

[0010] performing authentication and / or authorization of a user accessing a service;

[0011] wherein the user is associated with a subscription relationship with a first terminal, and the second network function is an application layer network function or a third party function.

[0012] According to a third aspect of embodiments of the present disclosure, a communication method is provided, the method being performed by a third network function, and the method comprising:

[0013] performing authentication and / or authorization of a user accessing a service;

[0014] wherein the user is associated with a subscription relationship with a first terminal, and the third network function is a network function in a service network SN.

[0015] According to a fourth aspect of the embodiments of the present disclosure, a communication method is provided, the method is performed by a first terminal, and the method comprises:

[0016] receiving third information sent by a third network function;

[0017] The first terminal is a terminal having a subscription relationship; and the third information is used to indicate at least one of the following:

[0018] a first credential, the first credential being a credential required for a user to access a network and / or for a service in the network to authenticate the user, the user being a user using the first terminal;

[0019] a second credential, the second credential being a credential required for a user to access a network and / or for a service in the network to authenticate the user,

[0020] the user being a user using a device associated with the first terminal.

[0021] According to a fifth aspect of the embodiments of the present disclosure, a communication method is provided, the method is performed by a user identity module, and the method comprises:

[0022] performing a second operation;

[0023] The second operation is an operation associated with authentication and / or authorization of a user accessing a service; and the user is a user associated with a subscription relationship of a first terminal.

[0024] According to a sixth aspect of the embodiments of the present disclosure, a communication method is provided, the method further comprises:

[0025] a first network function sends fourth information to a third network function, the fourth information being used to indicate an identity authentication result of a user accessing a service, the user being a user associated with a subscription relationship of a first terminal;

[0026] Alternatively, the third network function sends third information to the first terminal;

[0027] The first terminal is a terminal having a subscription relationship; and the third information is used to indicate at least one of the following:

[0028] a first credential, the first credential being a credential required for a user to access a network and / or for a service in the network to authenticate the user,

[0029] the user being a user using the first terminal;

[0030] a second credential, the second credential being a credential required for authenticating the user in a network accessed by the user and / or a service in the network,

[0031] According to a seventh aspect of embodiments of the disclosure, a first network function is provided, the first network function comprising:

[0032] a processing module configured to:

[0033] perform authentication and / or authorization of a user accessing a service,

[0034] wherein the user is a user associated with a subscription relationship of a first terminal, and the first network function is a network function in a home network HN of the first terminal.

[0035] According to an eighth aspect of embodiments of the disclosure, a second network function is provided, the second network function comprising:

[0036] a processing module configured to:

[0037] perform authentication and / or authorization of a user accessing a service,

[0038] wherein the user is a user associated with a subscription relationship of a first terminal, and the second network function is an application layer network function or a third party function.

[0039] According to a ninth aspect of embodiments of the disclosure, a third network function is provided, the third network function comprising:

[0040] a processing module configured to:

[0041] perform authentication and / or authorization of a user accessing a service,

[0042] wherein the user is a user associated with a subscription relationship of a first terminal, and the third network function is a network function in a service network SN.

[0043] According to a tenth aspect of embodiments of the disclosure, a first terminal is provided, the first terminal comprising:

[0044] a transceiver module configured to:

[0045] receive third information transmitted by a third network function,

[0046] wherein the first terminal is a terminal having a subscription relationship, and the third information is used to indicate at least one of:

[0047] a first credential, the first credential being a credential required for authenticating the user in a network accessed by the user and / or a service in the network,

[0048] the user is a user using the first terminal;

[0049] a second credential, the second credential being a credential required for authenticating the user in a network accessed by the user and / or a service in the network, the user being a user using a device associated with the first terminal.

[0050] According to a eleventh aspect of the embodiments of the present disclosure, a subscriber identity module is provided, the subscriber identity module comprising:

[0051] a processing module configured to:

[0052] perform a second operation;

[0053] wherein the second operation is an operation associated with authenticating and / or authorizing a user accessing a service, the user being a user associated with a subscription relationship of a first terminal

[0054] According to a twelfth aspect of the embodiments of the present disclosure, a communication system is provided, the communication system comprising a first network function, a second network function, a third network function, a first terminal and a subscription subscriber identity module, wherein the first network function is configured to perform the communication method of the first aspect; the second network function is configured to perform the communication method of the second aspect; the third network function is configured to perform the communication method of the third aspect; the first terminal is configured to perform the communication method of the fourth aspect; and the subscription subscriber identity module is configured to perform the communication method of the fifth aspect.

[0055] According to a thirteenth aspect of the embodiments of the present disclosure, a first network function is provided, the first network function comprising:

[0056] one or more processors;

[0057] wherein the first network function is configured to perform the communication method of the first aspect.

[0058] According to a fourteenth aspect of the embodiments of the present disclosure, a second network function is provided, the second network function comprising:

[0059] one or more processors;

[0060] wherein the second network function is configured to perform the communication method of the second aspect.

[0061] According to a fifteenth aspect of the embodiments of the present disclosure, a third network function is provided, the third network function comprising:

[0062] one or more processors;

[0063] The third network function is configured to perform the communication method of the third aspect.

[0064] According to a sixteenth aspect of the embodiments of the present disclosure, a first terminal is provided, and the first terminal comprises:

[0065] one or more processors;

[0066] The first terminal is configured to perform the communication method of the fourth aspect.

[0067] According to a seventeenth aspect of the embodiments of the present disclosure, a subscriber identity module is provided, and the subscriber identity module comprises:

[0068] one or more processors;

[0069] The subscriber identity module is configured to perform the communication method of the fifth aspect.

[0070] According to an eighteenth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, when the instructions are run on a communication device, the communication device performs the communication method provided by the first aspect, the second aspect or the third aspect.

[0071] The communication mechanism of the technical solution provided by the embodiments of the present disclosure can enhance the security architecture to support the authentication and authorization of users.

[0072] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0073] The accompanying drawings incorporated in and forming a part of the specification illustrate the embodiments consistent with the present disclosure and serve to explain the principles of the embodiments of the present disclosure together with the specification.

[0074] FIG. 1a is a schematic diagram of an architecture of a communication system according to an exemplary embodiment;

[0075] FIG. 1b is a schematic diagram of a communication architecture according to an exemplary embodiment;

[0076] FIG. 2a is a schematic diagram of a communication method according to an exemplary embodiment;

[0077] FIG. 2b is a schematic diagram of a communication method according to an exemplary embodiment;

[0078] FIG. 3a is a schematic diagram of a communication method according to an exemplary embodiment;

[0079] FIG. 3b is a flow diagram illustrating a communication method according to an example embodiment;

[0080] FIG. 4a is a flow diagram illustrating a communication method according to an example embodiment;

[0081] FIG. 5a is a flow diagram illustrating a communication method according to an example embodiment;

[0082] FIG. 5b is a flow diagram illustrating a communication method according to an example embodiment;

[0083] FIG. 6a is a flow diagram illustrating a communication method according to an example embodiment;

[0084] FIG. 6b is a flow diagram illustrating a communication method according to an example embodiment;

[0085] FIG. 7a is a flow diagram illustrating a communication method according to an example embodiment;

[0086] FIG. 7b is a flow diagram illustrating a communication method according to an example embodiment;

[0087] FIG. 8a is a flow diagram illustrating a communication method according to an example embodiment;

[0088] FIG. 9a is a structural diagram of a first network function according to an example embodiment;

[0089] FIG. 9b is a structural diagram of a second network function according to an example embodiment;

[0090] FIG. 9c is a structural diagram of a third network function according to an example embodiment;

[0091] FIG. 9d is a structural diagram of a first terminal according to an example embodiment;

[0092] FIG. 9e is a structural diagram of a subscriber identity module according to an example embodiment;

[0093] FIG. 10a is a structural diagram of a UE according to an example embodiment;

[0094] FIG. 10b is a structural diagram of a communication device according to an example embodiment. DETAILED DESCRIPTION

[0095] The embodiments of the present disclosure provide a communication method, a first network function, a second network function, a third network function, a first terminal, a subscriber identity module, a communication system, and a storage medium.

[0096] In a first aspect, embodiments of the present disclosure provide a communication method, the method is performed by a first network function, the method comprises:

[0097] performing authentication and / or authorization of a user accessing a service;

[0098] wherein the user is associated with a subscription relationship of a first terminal, and the first network function is a network function in a home network HN of the first terminal.

[0099] In the above embodiments, the authentication and / or authorization of the user accessing the service associated with the subscription relationship of the first terminal can be performed, so that the communication mechanism of the user accessing the service is more secure and reliable.

[0100] In combination with the embodiments of the first aspect, in some embodiments, the service is a slice service.

[0101] In combination with the embodiments of the first aspect, in some embodiments, the user is one of:

[0102] a first type of user, the first type of user being a user using a second terminal and connecting to a network through the first terminal;

[0103] a second type of user, the second type of user being a user connecting to a network using the first terminal.

[0104] In combination with the embodiments of the first aspect, in some embodiments, performing authentication and / or authorization of a user accessing a service comprises:

[0105] performing authentication and / or authorization of a user accessing a service based on an identifier and / or user configuration information of the user.

[0106] In the above embodiments, the authentication and / or authorization of the user accessing the service can be performed based on the identifier and / or user configuration information of the user.

[0107] In combination with the embodiments of the first aspect, in some embodiments, the method further comprises at least one of:

[0108] checking the user configuration information;

[0109] storing the user configuration information;

[0110] updating the user configuration information.

[0111] In the above embodiments, the checking, storing and / or updating of the user configuration information can be implemented.

[0112] In combination with the embodiments of the first aspect, in some embodiments, the method further comprises:

[0113] performing a first operation on the first information;

[0114] The first information includes at least one of:

[0115] The identifier of the user;

[0116] User configuration information associated with the identifier;

[0117] The first operation includes at least one of:

[0118] activating the first information;

[0119] deactivating the first information;

[0120] suspending use of the first information.

[0121] In the above embodiments, the first information can be activated, deactivated, or suspended.

[0122] In combination with the embodiments of the first aspect, in some embodiments, the performing the first operation on the first information includes:

[0123] sending second information to the first terminal;

[0124] The second information is used to indicate at least one of:

[0125] activating the first information;

[0126] deactivating the first information;

[0127] suspending use of the first information.

[0128] In the above embodiments, the first information can be activated, deactivated, or suspended by sending the second information.

[0129] In combination with the embodiments of the first aspect, in some embodiments, the method further includes:

[0130] sending third information to a third network function;

[0131] The third information is used to indicate at least one of:

[0132] a first credential, the first credential being a credential required by a network accessed by a user and / or a service in the network to authenticate the user,

[0133] The user is a user using the first terminal;

[0134] a second credential, the second credential being a credential required by a network accessed by a user and / or a service in the network to authenticate the user,

[0135] The user is a user using a device associated with the first terminal.

[0136] In the above embodiment, the third information can be used to send, to the third network function, a credential required for authenticating the user using the first terminal to access the network and / or a service in the network, and / or a credential required for authenticating the user using a device associated with the first terminal to access the network and / or a service in the network.

[0137] With reference to the embodiments of the first aspect, in some embodiments, the method further includes:

[0138] Performing identity authentication of the user with the second network function.

[0139] In the above embodiment, the first network function and the second network function can jointly implement the identity authentication of the user.

[0140] With reference to the embodiments of the first aspect, in some embodiments, the method further includes:

[0141] Sending user configuration information to an application server or the first terminal used by the user.

[0142] In the above embodiment, the user configuration information can be sent to an application server or a terminal used by the user.

[0143] With reference to the embodiments of the first aspect, in some embodiments, the user configuration information includes information necessary for providing the service and / or information agreed by the user to be disclosed when the user registers the service.

[0144] With reference to the embodiments of the first aspect, in some embodiments, the method further includes:

[0145] Determining the user to be authenticated, the user to be authenticated being a user that has established an association between an identifier of the user based on a service-related authentication policy.

[0146] In the above embodiment, the user to be authenticated can be determined as a user that has established an association between an identifier of the user based on a service-related authentication policy.

[0147] With reference to the embodiments of the first aspect, in some embodiments, the method further includes:

[0148] Sending fourth information to the third network function, the fourth information being used to indicate a result of the identity authentication of the user.

[0149] In the above embodiment, the fourth information can be used to send, to the third network function, the result of the identity authentication of the user.

[0150] In a second aspect, embodiments of the present disclosure provide a communication method, the method is performed by a second network function, the method comprises:

[0151] performing authentication and / or authorization of a user accessing a service;

[0152] wherein the user is associated with a subscription relationship with a first terminal, and the second network function is an application layer network function or a third party function.

[0153] With reference to the embodiments of the second aspect, in some embodiments, the performing authentication and / or authorization of the user accessing the service comprises:

[0154] performing identity authentication of the user with a first network function.

[0155] With reference to the embodiments of the second aspect, in some embodiments, the user is one of:

[0156] a first type of user, the first type of user being a user connecting to a network using a second terminal and through the first terminal;

[0157] a second type of user, the second type of user being a user connecting to the network using the first terminal.

[0158] In a third aspect, embodiments of the present disclosure provide a communication method, the method is performed by a third network function, the method comprises:

[0159] performing authentication and / or authorization of a user accessing a service;

[0160] wherein the user is associated with a subscription relationship with a first terminal, and the third network function is a network function in a service network (SN).

[0161] With reference to the embodiments of the third aspect, in some embodiments, the method further comprises:

[0162] receiving third information sent by a first network function;

[0163] wherein the third information is used to indicate at least one of:

[0164] a first credential, the first credential being a credential required for a user to access a network and / or for the network to authenticate the user, the user being a user using the first terminal;

[0165] a second credential, the second credential being a credential required for a user to access a network and / or for the network to authenticate the user, the user being a user using a device associated with the first terminal.

[0166] In some embodiments, the method further comprises:

[0167] sending the third information to the first terminal.

[0168] In some embodiments, the method further comprises:

[0169] receiving fourth information sent by a first network function;

[0170] The fourth information is used to indicate an identity authentication result of a user of the service, and the user is a user associated with a subscription relationship of the first terminal.

[0171] In some embodiments, the method further comprises:

[0172] sending the fourth information to the first terminal.

[0173] In some embodiments, the service is a slice service.

[0174] In some embodiments, the user is one of:

[0175] a first type of user, the first type of user being a user using a second terminal and connecting to a network through the first terminal;

[0176] a second type of user, the second type of user being a user connecting to a network using the first terminal.

[0177] In some embodiments, the method further comprises at least one of:

[0178] determining that the identity authentication result indicates that the user is authenticated successfully, and allowing the user to access the service;

[0179] determining that the identity authentication result indicates that the user is authenticated unsuccessfully, and refusing the user to access the service.

[0180] In some embodiments, the method further comprises:

[0181] limiting a user indicated by an identifier of the user to use a service of a network to which the third network function belongs.

[0182] In a fourth aspect, the embodiments of the present disclosure provide a communication method, the method being performed by a first terminal, and the method comprising:

[0183] receiving third information sent by a third network function;

[0184] The first terminal is a terminal with a subscription relationship; the third information is used to indicate at least one of the following:

[0185] The first credential is a credential required for a user to access a network and / or for a service in the network to authenticate the user,

[0186] The user is a user using the first terminal;

[0187] The second credential is a credential required for a user to access a network and / or for a service in the network to authenticate the user,

[0188] The user is a user using a device associated with the first terminal.

[0189] In some embodiments, the service is a slice service.

[0190] In some embodiments, the receiving the third information sent by the first network function comprises:

[0191] The third information sent by the first network function is received based on subscription information associated with an identifier of the user;

[0192] The user is a user associated with a subscription relationship of the first terminal.

[0193] In some embodiments, the user is one of the following:

[0194] The first type of user is a user using a second terminal and connecting to a network through the first terminal;

[0195] The second type of user is a user connecting to a network using the first terminal.

[0196] In some embodiments, the method further comprises at least one of the following:

[0197] The user accesses the network is authenticated based on the credential;

[0198] The user accesses a service in the network is authenticated based on the credential.

[0199] In some embodiments, the method further comprises:

[0200] An operation associated with authentication and / or authorization of a user accessing a service performed by the first network function is performed;

[0201] The user is a user associated with a subscription relationship of the first terminal.

[0202] With reference to the embodiments of the fourth aspect, in some embodiments, the method further includes at least one of:

[0203] storing the user configuration information of the user;

[0204] updating the user configuration information of the user.

[0205] With reference to the embodiments of the fourth aspect, in some embodiments, the method further includes:

[0206] receiving second information sent by the first network function;

[0207] wherein the second information is used for at least one of:

[0208] activating the first information;

[0209] deactivating the first information;

[0210] suspending the use of the first information;

[0211] wherein the first information includes at least one of:

[0212] an identifier of the user using the first terminal;

[0213] an identifier of the user using a device associated with the first terminal;

[0214] user configuration information associated with the identifier.

[0215] With reference to the embodiments of the fourth aspect, in some embodiments, the method further includes:

[0216] receiving fourth information sent by a third network function;

[0217] wherein the fourth information is used to indicate an identity authentication result of a user accessing a service, and the user is a user associated with a subscription relationship of a first terminal.

[0218] In a fifth aspect, the embodiments of the present disclosure provide a communication method, the method is performed by a user identity identification module, and the method includes:

[0219] performing a second operation;

[0220] wherein the second operation is an operation associated with authentication and / or authorization of a user accessing a service; and the user is a user associated with a subscription relationship of a first terminal.

[0221] With reference to the embodiments of the fifth aspect, in some embodiments, the service is a slice service.

[0222] In some embodiments, the user is one of:

[0223] a first type of user, the first type of user being a user using a second terminal and connecting to the network through the first terminal;

[0224] a second type of user, the second type of user being a user connecting to the network using the first terminal.

[0225] In some embodiments, the method further comprises at least one of:

[0226] storing user configuration information of the user;

[0227] updating the user configuration information of the user.

[0228] In a sixth aspect, the embodiments of the present disclosure provide a communication method, the method further comprising:

[0229] the first network function sending fourth information to the third network function, the fourth information being used to indicate an identity authentication result of a user accessing a service, the user being a user associated with a subscription relationship of a first terminal;

[0230] Alternatively, the third network function sends third information to the first terminal;

[0231] wherein the first terminal is a terminal having a subscription relationship; and the third information is used to indicate at least one of:

[0232] a first credential, the first credential being a credential required by a network accessed by a user and / or a service in the network for authenticating the user,

[0233] the user being a user using the first terminal;

[0234] a second credential, the second credential being a credential required by a network accessed by a user and / or a service in the network for authenticating the user, the user being a user using a device associated with the first terminal.

[0235] In a seventh aspect, the embodiments of the present disclosure provide a first network function, the first network function comprising:

[0236] a processing module configured to:

[0237] perform authentication and / or authorization of a user accessing a service;

[0238] wherein the user is a user associated with a subscription relationship of a first terminal, and the first network function is a network function in a home network HN of the first terminal.

[0239] In an eighth aspect, the embodiments of the present disclosure provide a second network function, the second network function comprising:

[0240] a processing module configured to:

[0241] perform authentication and / or authorization of a user accessing a service;

[0242] wherein the user is a user associated with a subscription relationship of a first terminal, and the second network function is an application layer network function or a third party function.

[0243] In a ninth aspect, the embodiments of the present disclosure provide a third network function, the third network function comprising:

[0244] a transceiver module configured to:

[0245] perform authentication and / or authorization of a user accessing a service;

[0246] wherein the user is a user associated with a subscription relationship of a first terminal, and the third network function is a network function in a service network SN.

[0247] In a tenth aspect, the embodiments of the present disclosure provide a first terminal, the first terminal comprising:

[0248] a transceiver module configured to:

[0249] receive third information sent by a third network function;

[0250] wherein the first terminal is a terminal having a subscription relationship; and the third information is used to indicate at least one of:

[0251] a first credential, the first credential being a credential required by a network accessed by a user and / or a service in the network for authenticating the user,

[0252] the user being a user using the first terminal;

[0253] a second credential, the second credential being a credential required by a network accessed by a user and / or a service in the network for authenticating the user, the user being a user using a device associated with the first terminal.

[0254] In an eleventh aspect, the embodiments of the present disclosure provide a user identity recognition module, the user identity recognition module comprising:

[0255] a processing module configured to:

[0256] perform a second operation;

[0257] The second operation is an operation associated with performing authentication and / or authorization related to user access services.

[0258] In a twelfth aspect, the embodiments of the present disclosure provide a communication system, comprising a first network function, a second network function, a third network function, a first terminal and a subscription user identity module, wherein the first network function is configured to perform the communication method of the first aspect; the second network function is configured to perform the communication method of the second aspect; the third network function is configured to perform the communication method of the third aspect; the first terminal is configured to perform the communication method of the fourth aspect; and the subscription user identity module is configured to perform the communication method of the fifth aspect.

[0259] In a thirteenth aspect, the embodiments of the present disclosure provide a first network function, comprising:

[0260] one or more processors;

[0261] The first network function is configured to perform the communication method of the first aspect.

[0262] In a fourteenth aspect, the embodiments of the present disclosure provide a second network function, comprising:

[0263] one or more processors;

[0264] The second network function is configured to perform the communication method of the second aspect.

[0265] In a fifteenth aspect, the embodiments of the present disclosure provide a third network function, comprising:

[0266] one or more processors;

[0267] The third network function is configured to perform the communication method of the third aspect.

[0268] In a sixteenth aspect, the embodiments of the present disclosure provide a first terminal, comprising:

[0269] one or more processors;

[0270] The first terminal is configured to perform the communication method of the fourth aspect.

[0271] In a seventeenth aspect, the embodiments of the present disclosure provide a user identity module, comprising:

[0272] one or more processors;

[0273] The user identity recognition module is configured to perform the communication method of the fifth aspect.

[0274] In an eighteenth aspect, the embodiments of the present disclosure provide a storage medium, wherein the storage medium stores instructions, when the instructions run on a communication device, cause the communication device to perform the communication method described in the optional implementation manners of the first aspect, the second aspect, the third aspect, the fourth aspect and / or the fifth aspect.

[0275] In a nineteenth aspect, the embodiments of the present disclosure provide a program product, when the program product is executed by a communication device, causes the communication device to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect and / or the fifth aspect.

[0276] In a twentieth aspect, the embodiments of the present disclosure provide a computer program, when the computer program runs on a computer, causes the computer to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect and / or the fifth aspect.

[0277] In a twenty-first aspect, the embodiments of the present disclosure provide a chip or a chip system. The chip or the chip system includes processing circuitry configured to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect and / or the fifth aspect.

[0278] It can be understood that the first network function, the second network function, the third network function, the first terminal, the communication system, the storage medium, the program product, the computer program, the chip or the chip system are all used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method, which will not be repeated here.

[0279] The embodiments of the present disclosure provide a communication method, a first network function, a second network function, a third network function, a first terminal, a communication system and a storage medium. In some embodiments, the terms of the communication method and the information processing method, the information transmission method can be replaced with each other, and the terms of the communication system and the information processing system can be replaced with each other.

[0280] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing part of the steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, part or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with optional implementation manners of other embodiments arbitrarily.

[0281] In each embodiment of the present disclosure, the terms and / or descriptions between the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0282] The terms used in the embodiments of the present disclosure are only for the purpose of describing the specific embodiments, and not as a limitation on the present disclosure.

[0283] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "said", "preceding", "this" and the like, can represent "one and only one", and can also represent "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, and can also be understood as plural expression.

[0284] In the embodiments of the present disclosure, "a plurality of" means two or more.

[0285] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple" and the like can be replaced with each other.

[0286] In some embodiments, "at least one of A, B", "A and / or B", "in one case A, in another case B", "responsive to case A, responsive to case B" and the like, can be interpreted to include both cases, A and B, in some embodiments, A (A is performed regardless of B), in some embodiments, B (B is performed regardless of A), in some embodiments, selected from the group consisting of A and B (the selection between A and B is an option), in some embodiments, A and B (both A and B are performed).

[0287] In some embodiments, "A or B" and the like, can be interpreted to include both cases, A and B, in some embodiments, A (A is performed regardless of B), in some embodiments, B (B is performed regardless of A), in some embodiments, selected from the group consisting of A and B (the selection between A and B is an option).

[0288] In some embodiments, the prefix words "first", "second" and the like in the disclosure do not limit the position, order, priority, number or content of the described objects, and the description of the described objects should be referred to the context of the claims or embodiments, and should not be construed as redundant limitations. For example, the described objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified by them are in the same message or not, nor limit the order of "first field" and "second field". For another example, the described objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the number of the described objects is not limited by the ordinal words, and can be one or more. For example, "first device", where the number of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the described objects are "devices", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different; for another example, the described objects are "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.

[0289] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0290] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0291] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above", and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "fewer than", "fewer than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below", and the like can be replaced with each other.

[0292] In some embodiments, the apparatuses and devices can be interpreted as entities, and can also be interpreted as virtual, and the names thereof are not limited to the names described in the embodiments, and in some cases can also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", and the like.

[0293] In some embodiments, "network" can be interpreted as an apparatus included in the network, for example, an access network device, a core network device, and the like.

[0294] In some embodiments, an “access network device (AN device)” can also be referred to as a “radio access network device (RAN device),” a “base station (BS),” a “radio base station,” a “fixed station,” and in some embodiments can also be understood as a “node,” an “access point,” a “transmission point (TP),” a “reception point (RP),” a “transmission / reception point (TRP),” a “panel,” an “antenna panel,” an “antenna array,” a “cell,” a “macro cell,” a “small cell,” a “femto cell,” a “pico cell,” a “sector,” a “cell group,” a “serving cell,” a “carrier,” a “component carrier,” a “bandwidth part (BWP),” and the like.

[0295] In some embodiments, a "terminal" or "terminal device" can be referred to as a "user equipment" (UE), a "user terminal," a "mobile station" (MS), a "mobile terminal" (MT), a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wireless communication device, a remote device, a mobile subscriber station, an access terminal, a mobile terminal, a wireless terminal, a remote terminal, a handset, a user agent, a mobile client, a client, and / or the like.

[0296] In some embodiments, data, information and / or the like can be obtained in compliance with laws and regulations of a country where the data, information and / or the like is obtained.

[0297] In some embodiments, data, information and / or the like can be obtained after consent of a user.

[0298] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, and any column can also be implemented as an independent embodiment.

[0299] FIG. 1a is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.

[0300] As shown in FIG. 1a, the communication system 100 includes a terminal 101 and a network device 102.

[0301] In some embodiments, the network device 102 can be a network function, for example, a first network function, a second network function, a third network function, and / or the like.

[0302] In some embodiments, the terminal includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet (Pad), a wireless transceiver-equipped computer, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, and the like, but is not limited thereto.

[0303] In some embodiments, the access network device can be at least one of a node or a device that accesses a terminal to a wireless network, and can include an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, and the like, but is not limited thereto.

[0304] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, in which case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0305] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, with some of the protocol layers being controlled by the CU and the rest of the protocol layers or all of the protocol layers being distributed in the DUs and controlled by the CU, but is not limited thereto.

[0306] In some embodiments, the core network device can be one device including one or more network elements, or can be multiple devices or device groups including all or part of the one or more network elements. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next-generation core (NGC).

[0307] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art can know that, as the system architecture evolves and new business scenarios appear, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0308] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1a or part of the subject, but are not limited thereto. The subjects shown in FIG. 1a are exemplary, and the communication system can include all or part of the subjects in FIG. 1a, or other subjects other than those in FIG. 1a. The number and form of each subject is arbitrary, and the connection relationship between the subjects is exemplary. The subjects can be connected or not connected, and the connection can be in any manner, can be direct connection or indirect connection, and can be wired connection or wireless connection.

[0309] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).

[0310] In some embodiments, current mobile networks are subscription-centric, which enables mobile operators to protect access to the network and respect legal obligations. From a use case perspective, this is sufficient when a user typically has one phone and one subscription and uses only some services provided by the operator, such as phone and Short Message Service (SMS). However, a person can have different kinds of devices (e.g., phone, tablet, and / or laptop) to access various operator and non-operator services, some of which can belong to the user and some of which can be shared with others or belong to another party. Things are getting more and more connected (e.g., sensors, gateways, actuators, etc.) and there is a wide variety of relationships between the owner of a thing, the subscriber, and the actual user of the thing.

[0311] In some embodiments, each service typically performs its own identity verification, typically based on a username and password. But it becomes more and more cumbersome for a user to manage different credentials for more and more services. So-called identity providers address this problem by providing identity information to entities and authenticating to the services of these entities. This mechanism can be used on top of any data connection, but integration or interworking with the operator network provides additional advantages.

[0312] In some embodiments, identifying users and distinguishing user identities in the operator network (provided by some external party or the operator) would enable the operator to provide enhanced user experience and optimized performance, as well as to provide services to devices that do not belong to the 3GPP network. Network settings and customized services can be adjusted according to the needs of the user, independent of the subscription used to establish the connection. By acting as an identity provider, the operator can take additional information from the network into account to charge based on the user’s identifier and provide differentiated services.

[0313] In some embodiments, the user to be identified can be the individual user using a terminal with a specific subscription, or the application running on the terminal or connected via the terminal, or the individual user of the device behind a gateway terminal. The 3GPP security architecture supports authentication and authorization of terminals with a subscription identifier used to establish the connection, but does not support authentication and authorization of the user on (using) or behind the terminal. Therefore, it is necessary to investigate how to enhance the 3GPP security architecture to support authentication and authorization of the user.

[0314] In some embodiments, please refer to FIG. 1b, a 3GPP security architecture is shown, which is composed of User Application, Provider Application, Mobile Equipment (ME), Universal Subscriber Identity Module (USIM), Serving Network (SN), Home Network (HN), etc.

[0315] In some embodiments, the 3GPP security framework includes Network Access Security (I), Network Domain Security (II), User Domain Security (III), Application Domain Security (IV), and Service-based Architecture (SBA) Domain Security (V).

[0316] In some embodiments, the functions of Network Access Security (I) include a set of security functions that enable terminals to securely authenticate and access services over a network, including 3GPP access and non-3GPP access, prevent attacks on the (radio) interface, and secure context transfer from the Serving Network (SN) to the Access Network (AN) to enable access security.

[0317] In some embodiments, the functions of Network Domain Security (II) include a set of security functions that enable network nodes to securely exchange signaling data and user plane data.

[0318] In some embodiments, the functions of User Domain Security (III) include a set of security functions that ensure the security of user access to the mobile equipment.

[0319] In some embodiments, Application Domain Security (IV) includes a set of security functions that enable applications in the user domain and application domain to securely exchange messages. Application domain security is beyond the scope of 3GPP.

[0320] In some embodiments, the functions of Service-based Architecture (SBA) Domain Security (V) include a set of security functions that enable network functions of the SBA architecture to securely communicate within the service network domain and with other network domains.

[0321] The above security domains mainly support network access security and connection security.

[0322] FIG. 2a is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 2a, the embodiments of the present disclosure relate to a communication method for a communication system 100, the method comprising:

[0323] Step S2101: The first terminal, the user identity module, the first network function, the second network function and / or the third network function perform authentication and authorization of the user to access the service.

[0324] In some embodiments, the first terminal is a terminal capable of directly accessing the network or a terminal with gateway function.

[0325] In some embodiments, the user identity module can be a global subscriber identity module (USIM).

[0326] In some embodiments, the user identity module can be a subscriber identity module.

[0327] In some embodiments, the first network function is a network function of a home network (HN).

[0328] In some embodiments, the first network function is a network function in the home network (HN) of the first terminal, for example, a user authentication and authorization function (UAAF).

[0329] In some embodiments, the second network function is a network function participating in authentication and / or authorization as a third party.

[0330] In some embodiments, the second network function is an application layer network function or a third party function.

[0331] In some embodiments, the user is a user associated with a subscription relationship of the first terminal.

[0332] In some embodiments, the subscription relationship indicates a subscription relationship between a communication network user and a network operator.

[0333] In some embodiments, the service is an operator and / or non-operator deployed service.

[0334] In some embodiments, the operator deployed service is a slice service.

[0335] In some embodiments, the non-operator deployed service is a slice service.

[0336] In some embodiments, the user is a first type of user, the first type of user being a user using a second terminal and connecting to the network through the first terminal.

[0337] In some embodiments, the user is a second type of user, the second type of user being a user connecting to the network using the first terminal.

[0338] In some embodiments, the first network function performs authentication and / or authorization of the user to access services based on the identifier of the user and / or the user configuration information.

[0339] In some embodiments, the first network function performs authentication and / or authorization of the user to access services based on the identifier of the user.

[0340] In some embodiments, the first network function performs authentication and / or authorization of the user to access services based on the user configuration information.

[0341] In some embodiments, the first terminal authenticates the user to access the network and / or services in the network based on the credential.

[0342] In some embodiments, the first terminal performs operations associated with the authentication and / or authorization of the user to access services performed by the first network function.

[0343] In some embodiments, the first network function and the second network function perform identity authentication of the user.

[0344] In some embodiments, the user identity identification module performs the second operation.

[0345] In some embodiments, the second operation is an operation associated with the authentication and / or authorization of the user to access services.

[0346] In some embodiments, the user identity identification module performs an operation associated with the authentication and / or authorization of the user to access services.

[0347] In some embodiments, the first network function confirms the user to be authenticated.

[0348] In some embodiments, the user to be authenticated is a user that has established an association with the identifier of the user based on a service-related authentication policy.

[0349] Step S2102: The first network function, the first terminal, and / or the user identity identification module checks, stores, and / or updates the user configuration information.

[0350] In some embodiments, the first network function, the first terminal, and / or the user identity identification module checks the user configuration information.

[0351] In some embodiments, the first network function, the first terminal and / or the user identity module stores and user configuration information.

[0352] In some embodiments, the first network function, the first terminal and / or the user identity module updates user configuration information.

[0353] In some embodiments, the first network function sends the user configuration information to an application server.

[0354] In some embodiments, the first network function sends the user configuration information to the first terminal used by the user.

[0355] In some embodiments, the user configuration information comprises information necessary for providing the service.

[0356] In some embodiments, the user configuration information comprises information agreed to be disclosed by the user when registering the service.

[0357] Step S2103: The first network function performs a first operation on the first information.

[0358] In some embodiments, the first information comprises at least one of:

[0359] an identifier of the user;

[0360] user configuration information associated with the identifier.

[0361] In some embodiments, the first information comprises at least one of:

[0362] a first identifier of the user using the first terminal;

[0363] a second identifier of the user using a device associated with the first terminal;

[0364] user configuration information associated with the first identifier;

[0365] user configuration information associated with the second identifier.

[0366] In some embodiments, the device associated with the first terminal can be a second terminal. For example, the first terminal is a UE, and the second terminal is a wearable device, e.g. a watch, which accesses the network through the UE.

[0367] In some embodiments, the first operation comprises activating, deactivating or suspending the use of the first information.

[0368] In some embodiments, the first operation comprises at least one of:

[0369] activating the first information;

[0370] deactivating the first information;

[0371] suspending use of the first information.

[0372] In some embodiments, the first network function sends second information to the first terminal.

[0373] In some embodiments, the first terminal receives the second information sent by the first network function.

[0374] In some embodiments, the second information is used to indicate at least one of the following:

[0375] In some embodiments, the second information is used to indicate at least one of the following:

[0376] activating the first information;

[0377] deactivating the first information;

[0378] suspending use of the first information.

[0379] In some embodiments, the first terminal activates the first information after receiving the second information sent by the first network function.

[0380] In some embodiments, the first terminal deactivates the first information after receiving the second information sent by the first network function.

[0381] In some embodiments, the first terminal suspends use of the first information after receiving the second information sent by the first network function.

[0382] Step S2104: The first network function sends third information to a third network function.

[0383] In some embodiments, the third network function receives the third information sent by the first network function.

[0384] In some embodiments, the third network function is a network function of a serving network (SN).

[0385] In some embodiments, the third network function is a network function in a serving network SN.

[0386] In some embodiments, the third information sent by the first network function is received based on subscription information associated with an identifier of a user, wherein the user is associated with a subscription relationship of the first terminal.

[0387] In some embodiments, the third information is used to indicate the credential required for authenticating a user using the first terminal to access the network and / or services in the network.

[0388] In some embodiments, the third information is used to indicate the credential required for authenticating a user using the device associated with the first terminal to access the network and / or services in the network.

[0389] In some embodiments, the third information is used to indicate the credential required for authenticating a user using the first terminal to access the network and / or services in the network, and the credential required for authenticating a user using the device associated with the first terminal to access the network and / or services in the network.

[0390] In some embodiments, the third information is used to indicate at least one of:

[0391] a first credential, the first credential being a credential required for authenticating a user using the first terminal to access the network and / or services in the network;

[0392] a second credential, the second credential being a credential required for authenticating a user using the device associated with the first terminal to access the network and / or services in the network.

[0393] Step S2105: The third network function sends the third information to the first terminal.

[0394] In some embodiments, the first terminal receives the third information sent by the third network function.

[0395] Step S2106: The first network function sends the fourth information to the third network function.

[0396] In some embodiments, the third network function receives the fourth information sent by the first network function.

[0397] In some embodiments, the fourth information is used to indicate the authentication result of the user.

[0398] Step S2107: The third network function sends the fourth information to the first terminal.

[0399] In some embodiments, the first terminal receives the fourth information sent by the third network function,

[0400] In some embodiments, the third network function sends the fourth information to the first terminal after receiving the fourth information.

[0401] Step S2108: The third network function performs whether to allow access to services.

[0402] In some embodiments, the third network function performs whether the user of the first terminal or the user of the device associated with the first terminal accesses the service.

[0403] In some embodiments, based on the identity authentication result, the third network function performs whether the user of the first terminal or the user of the device associated with the first terminal accesses the service.

[0404] In some embodiments, the third network function determines that the identity authentication result indicates that the user authentication is successful, and the third network function allows the user to access the service.

[0405] In some embodiments, the third network function determines that the identity authentication result indicates that the user authentication is successful, and the third network function allows the user of the first terminal or the user of the device associated with the first terminal to access the service.

[0406] In some embodiments, the third network function determines that the identity authentication result indicates that the user authentication fails, and the third network function denies the user to access the service.

[0407] In some embodiments, the third network function determines that the identity authentication result indicates that the user authentication fails, and the third network function denies the user of the first terminal or the user of the device associated with the first terminal to access the service.

[0408] In some embodiments, the third network function limits the user indicated by the identifier of the user to use the service of the network to which the third network function belongs.

[0409] In order to better understand the embodiments of the present disclosure, the technical solutions of the present disclosure are further described below through an exemplary embodiment:

[0410] Please refer to FIG. 2b, a new layer is added in the above-mentioned 3GPP security architecture, for example, an identity management layer (Identity Management Stratum).

[0411] In some embodiments, the function of the user identification security (VI) includes a set of security functions that enable the user on or behind the terminal to be authenticated and authorized through the network, including the user of the non-3GPP device (for example, the second terminal) on and behind the terminal (3GPP device, for example, the first terminal).

[0412] In some embodiments, the function of the user identification security (VI) includes VI-a, VI-b, VI-c and / or VI-d.

[0413] In some embodiments, the functions of VI-a include enabling a User Authentication and Authorization Function (UAAF) to authenticate and authorize a user to access operator and non-operator deployed (i.e. external non-3GPP) services by checking the user’s User Profile, which is stored in the home network and / or USIM and updated by the home network and / or the user.

[0414] Note that the User Profile includes at least one of the following: the user’s identifier, associated security credentials, subscription relationship, associated device (identified by the subscription relationship and device identifier), the associated device’s capability to support authentication, and / or authentication policy information (for authenticating the user to access different services or slices, etc.) required for different services and slices.

[0415] In some embodiments, the functions of VI-a include enabling the user to activate, deactivate, and suspend the use of the user’s identifier and related settings in the user’s User Profile for each device or terminal.

[0416] In some embodiments, the functions of VI-b include enabling secure provisioning of credentials to a terminal or non-3GPP device connected via a gateway terminal to enable the terminal or non-3GPP device to access the network and its services according to a 3GPP subscription relationship that has been linked to the user’s identity.

[0417] In some embodiments, the functions of VI-c include enabling the 3GPP system to interwork with third party network entities to authenticate the user’s identity.

[0418] In some embodiments, the functions of VI-c include enabling the 3GPP system to expose the user’s profile information (e.g. the content of the user’s profile information, authorization, or authentication results) to a service, which is only necessary for providing the service and has been agreed by the user when registering for the service.

[0419] In some embodiments, the functions of VI-c include enabling a service to request the 3GPP network to authenticate only the users of the service for which the association between the user’s identifier and the user has been established according to the service’s specified authentication policy.

[0420] In some embodiments, the functions of VI-d include enabling the 3GPP system to allow a terminal to access a slice based on a successful user identity authentication, or to deny a terminal to access a slice based on an unsuccessful user identity authentication.

[0421] In some embodiments, the functions of VI-d include enabling the 3GPP network to restrict the use of the user’s identifier, including in roaming scenarios.

[0422] In some embodiments, connectivity in the user identification domain is protected by the security domains I, II and V.

[0423] In some embodiments, the term "information" can be mutually replaced with the terms "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "data", and the like.

[0424] In some embodiments, the term "send" can be mutually replaced with the terms "transmit", "report", "transport", and the like.

[0425] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101 to S2108. For example, step S2102 can be implemented as an independent embodiment, step S2104 can be implemented as an independent embodiment, step S2105 can be implemented as an independent embodiment, step S2106 can be implemented as an independent embodiment, step S2107 can be implemented as an independent embodiment, and step S2108 can be implemented as an independent embodiment. For example, step S2101, step S2104, step S2105 in combination with step S2108 can be implemented as an independent embodiment, step S2101 in combination with step S2104, step S2105, step S2106, step S2107, and step S2108 can be implemented as an independent embodiment, step S2101 in combination with step S2102, step S2104, step S2105, and step S2108 can be implemented as an independent embodiment, step S2101 in combination with step S2103, step S2104, step S2105, and step S2108 can be implemented as an independent embodiment, step S2101 in combination with step S2102, step S2103, step S2104, step S2105, and step S2108 can be implemented as an independent embodiment, but not limited thereto. It should be noted that each step can be independently implemented, or in the case of no contradiction, the order can be arbitrarily exchanged and freely combined for implementation.

[0426] FIG. 3a is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3a, the embodiments of the present disclosure relate to a communication method, which is performed by a first network function, and the above-mentioned method comprises:

[0427] Step S3101: performing authentication and authorization of user access service.

[0428] In some embodiments, the first network function is a network function in a home network HN of the first terminal.

[0429] In some embodiments, the optional implementation of step S3101 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a. The details are not described here again.

[0430] Step S3102: checking, storing and / or updating the user configuration information.

[0431] In some embodiments, the optional implementation of step S3102 can refer to the optional implementation of step S2102 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a. The details are not described here again.

[0432] Step S3103: performing a first operation on the first information.

[0433] In some embodiments, the optional implementation of step S3103 can refer to the optional implementation of step S2103 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a. The details are not described here again.

[0434] Step S3104: sending third information to a third network function.

[0435] In some embodiments, the optional implementation of step S3104 can refer to the optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a. The details are not described here again.

[0436] Step S3105: sending fourth information to the third network function.

[0437] In some embodiments, the optional implementation of step S3105 can refer to the optional implementation of step S2106 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a. The details are not described here again.

[0438] The communication method related to the embodiments of the present disclosure can include at least one of steps S3101 to S3105. For example, step S3101 can be implemented as an independent embodiment, step S3102 can be implemented as an independent embodiment, step S3103 can be implemented as an independent embodiment, step S3104 can be implemented as an independent embodiment, and step S3105 can be implemented as an independent embodiment. For example, step S3101 in combination with step S3104 can be implemented as an independent embodiment, step S3101 in combination with step S3104 and step S3105 can be implemented as an independent embodiment, step S3101 in combination with step S3102 and step S3104 can be implemented as an independent embodiment, step S3101 in combination with step S3103 and step S3104 can be implemented as an independent embodiment, and step S3101 in combination with step S3102, step S3103 and step S3104 can be implemented as an independent embodiment, but the present disclosure is not limited thereto. It should be noted that each step can be independently implemented, or in the case of no contradiction, the order can be arbitrarily exchanged and combined.

[0439] FIG. 3b is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3b, the embodiments of the present disclosure relate to a communication method, which is performed by a first network function, and the above method comprises:

[0440] Step S3201: performing authentication and / or authorization of user access to a service.

[0441] In some embodiments, the user is a user associated with a subscription relationship of the first terminal.

[0442] In some embodiments, the first network function is a network function in a home network HN of the first terminal.

[0443] In some embodiments, the optional implementation of step S3201 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be described here.

[0444] In some embodiments, the service is a service deployed by an operator and / or a non-operator.

[0445] In some embodiments, the service is a slice service.

[0446] In some embodiments, the user is one of:

[0447] The first type of user is a user who uses a second terminal and connects to the network through the first terminal;

[0448] a second type of user, the second type of user being a user connected to the network using the first terminal.

[0449] In some embodiments, the method further comprises:

[0450] performing authentication and / or authorization of the user for the service based on the identity of the user and / or the user configuration information.

[0451] In some embodiments, the method further comprises at least one of:

[0452] checking the user configuration information;

[0453] storing the user configuration information;

[0454] updating the user configuration information.

[0455] In some embodiments, the method further comprises:

[0456] performing a first operation on first information;

[0457] wherein the first information comprises at least one of:

[0458] an identifier of the user;

[0459] user configuration information associated with the identifier;

[0460] wherein the first operation comprises at least one of:

[0461] activating the first information;

[0462] deactivating the first information;

[0463] suspending use of the first information.

[0464] In some embodiments, the performing a first operation on first information comprises:

[0465] sending second information to the first terminal;

[0466] wherein the second information is used to indicate at least one of:

[0467] activating the first information;

[0468] deactivating the first information;

[0469] suspending use of the first information.

[0470] In some embodiments, the method further comprises:

[0471] sending third information to a third network function;

[0472] The third information is used to indicate at least one of the following:

[0473] The first credential is a credential required by a network accessed by a user and / or a service in the network to authenticate the user,

[0474] The user is a user using the first terminal;

[0475] The second credential is a credential required by a network accessed by a user and / or a service in the network to authenticate the user,

[0476] The user is a user using a device associated with the first terminal.

[0477] In some embodiments, the method further comprises:

[0478] Performing identity authentication of the user with a second network function.

[0479] In some embodiments, the method further comprises:

[0480] Sending user configuration information to an application server or the first terminal used by the user.

[0481] In some embodiments, the user configuration information includes information necessary to provide the service and / or information agreed by the user to be disclosed when registering the service.

[0482] In some embodiments, the method further comprises:

[0483] Determining a user to be authenticated;

[0484] The user to be authenticated is a user who has established an association between an identifier of the user based on a service-related authentication policy.

[0485] In some embodiments, the method further comprises:

[0486] Sending fourth information to a third network function;

[0487] The fourth information is used to indicate the result of identity authentication of the user.

[0488] FIG. 4a is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4a, the present embodiment relates to a communication method, which is performed by a second network device, and the above-mentioned method comprises:

[0489] Step S4101: performing authentication and authorization of a user accessing a service.

[0490] In some embodiments, the second network function is an application layer network function or a third party function.

[0491] In some embodiments, the optional implementation of step S4101 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which are not described herein again.

[0492] In some embodiments, the performing authentication and / or authorization of the user accessing the service comprises:

[0493] performing identity authentication of the user with the first network function.

[0494] In some embodiments, the service is a service deployed by an operator and / or a non-operator.

[0495] In some embodiments, the service is a slice service.

[0496] In some embodiments, the user is one of:

[0497] a first type of user, the first type of user being a user using a second terminal and connecting to a network through the first terminal;

[0498] a second type of user, the second type of user being a user connecting to a network using the first terminal.

[0499] FIG. 5a is a flow diagram of a communication method according to some embodiments of the present disclosure. As shown in FIG. 5a, the embodiments of the present disclosure relate to a communication method, which is performed by a third network function, and the above method comprises:

[0500] Step S5101: performing authentication and authorization of a user accessing a service.

[0501] In some embodiments, the third network function is a network function in a service network (SN).

[0502] In some embodiments, the optional implementation of step S5101 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which are not described herein again.

[0503] Step S5102: receiving third information sent by a first network function.

[0504] In some embodiments, the optional implementation of step S5102 can refer to the optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which are not described herein again.

[0505] Step S5103: receiving fourth information sent by the first network function.

[0506] In some embodiments, the optional implementation of step S5103 can refer to the optional implementation of step S2106 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0507] Step S5104: sending the fourth information to the first terminal.

[0508] In some embodiments, the optional implementation of step S5104 can refer to the optional implementation of step S2107 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0509] Step S5105: performing whether to allow access to the service.

[0510] In some embodiments, the optional implementation of step S5105 can refer to the optional implementation of step S2108 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0511] The communication method related to the embodiments of the present disclosure can include at least one of steps S5101 to S5105. For example, step S5101 can be implemented as an independent embodiment, step S5102 can be implemented as an independent embodiment, step S5103 can be implemented as an independent embodiment, step S5104 can be implemented as an independent embodiment, and step S5105 can be implemented as an independent embodiment. For example, step S5101 in combination with step S5102 can be implemented as an independent embodiment, step S5101 in combination with step S5103, step S5104 can be implemented as an independent embodiment, step S5101 in combination with step S5102, step S5103, step S5104 can be implemented as an independent embodiment, step S5101 in combination with step S5102, step S5103, step S5104, step S5105 can be implemented as an independent embodiment, or can be implemented in any order and freely combined without contradiction.

[0512] FIG. 5b is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 5b, the embodiments of the present disclosure relate to a communication method, which is performed by a third network function, and the above-mentioned method comprises:

[0513] Step S5201: performing authentication and authorization of a user accessing a service.

[0514] In some embodiments, the user is a user associated with a subscription relationship of the first terminal.

[0515] In some embodiments, the third network function is a network function in a service network SN.

[0516] In some embodiments, the optional implementation of step S5201 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which are not described herein again.

[0517] In some embodiments, the method further comprises:

[0518] receiving third information sent by the first network function;

[0519] The third information is used to indicate at least one of the following:

[0520] a first credential, the first credential being a credential required for a user to access a network and / or for the user to be authenticated for a service in the network, the user being a user using the first terminal;

[0521] a second credential, the second credential being a credential required for a user to access a network and / or for the user to be authenticated for a service in the network, the user being a user using a device associated with the first terminal.

[0522] In some embodiments, the method further comprises:

[0523] sending the third information to the first terminal.

[0524] In some embodiments, the method further comprises:

[0525] receiving fourth information sent by the first network function;

[0526] The fourth information is used to indicate an identity authentication result of a user accessing a service, the user being a user associated with a subscription relationship of the first terminal.

[0527] In some embodiments, the method further comprises:

[0528] sending the fourth information to the first terminal.

[0529] In some embodiments, the service is a service deployed by an operator and / or a non-operator.

[0530] In some embodiments, the service is a slice service.

[0531] In some embodiments, the user is one of the following:

[0532] a first type of user, the first type of user being a user using a second terminal and connecting to a network through the first terminal;

[0533] a second type of user, the second type of user being a user connecting to a network using the first terminal.

[0534] In some embodiments, the method further comprises at least one of:

[0535] determining that the identity authentication result indicates that the user authentication is successful, and allowing the user to access the service;

[0536] determining that the identity authentication result indicates that the user authentication is failed, and rejecting the user to access the service.

[0537] In some embodiments, the method further comprises:

[0538] limiting the user indicated by the identifier of the user to use the service of the network to which the third network function belongs.

[0539] FIG. 6a is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 6a, the embodiment of the present disclosure relates to a communication method, which is performed by a first terminal, and the above method comprises:

[0540] Step S6101: performing authentication and authorization of user accessing a service.

[0541] In some embodiments, the optional implementation of step S6101 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0542] Step S6102: checking, storing and / or updating user configuration information.

[0543] In some embodiments, the optional implementation of step S6102 can refer to the optional implementation of step S2102 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0544] Step S6103: receiving third information sent by the first terminal.

[0545] In some embodiments, the optional implementation of step S6103 can refer to the optional implementation of step S2105 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0546] Step S6104: receiving fourth information sent by the third network function.

[0547] In some embodiments, the optional implementation of step S6104 can refer to the optional implementation of step S2107 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0548] The communication method related to the embodiments of the present disclosure can include at least one of steps S6101 to S6104. For example, step S6101 can be implemented as an independent embodiment, step S6102 can be implemented as an independent embodiment, step S6103 can be implemented as an independent embodiment, and step S6104 can be implemented as an independent embodiment. For example, step S6101 in combination with step S6102 can be implemented as an independent embodiment, step S6101 in combination with step S6103 can be implemented as an independent embodiment, step S6101 in combination with step S6102 and step S6103 can be implemented as an independent embodiment, and step S6101 in combination with step S6102, step S6103 and step S6104 can be implemented as an independent embodiment, but the present disclosure is not limited thereto. It should be noted that each step can be implemented independently, or in the case of no contradiction, the order can be arbitrarily exchanged and combined freely.

[0549] FIG. 6b is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 6b, the embodiments of the present disclosure relate to a communication method, which is performed by a first terminal, and the above method comprises:

[0550] Step S6201: receiving third information sent by a third network function.

[0551] In some embodiments, the first terminal is a terminal having a subscription relationship; the third information is used to indicate at least one of the following:

[0552] a first credential, the first credential being a credential required for a user to access a network and / or for a service in the network to authenticate the user,

[0553] the user being a user using the first terminal;

[0554] a second credential, the second credential being a credential required for a user to access a network and / or for a service in the network to authenticate the user, the user being a user using a device associated with the first terminal.

[0555] In some embodiments, the optional implementation of step S6201 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be described here.

[0556] In some embodiments, the service is a service deployed by an operator and / or a non-operator.

[0557] In some embodiments, the service is a slice service.

[0558] In some embodiments, the receiving of the third information sent by the first network function comprises:

[0559] receiving the third information sent by the first network function based on subscription information associated with an identifier of the user;

[0560] wherein the user is a user associated with a subscription relationship of the first terminal.

[0561] In some embodiments, the user is one of:

[0562] a first type of user, the first type of user being a user using a second terminal and connecting to the network through the first terminal;

[0563] a second type of user, the second type of user being a user connecting to the network using the first terminal.

[0564] In some embodiments, the method further comprises at least one of:

[0565] authenticating the user to access the network based on the credential;

[0566] authenticating the user to access services in the network based on the credential.

[0567] In some embodiments, the method further comprises:

[0568] performing an operation associated with authentication and / or authorization of user access to services performed by the first network function;

[0569] wherein the user is a user associated with a subscription relationship of the first terminal.

[0570] In some embodiments, the method further comprises at least one of:

[0571] storing user configuration information of the user;

[0572] updating user configuration information of the user.

[0573] In some embodiments, the method further comprises at least one of:

[0574] activating the first information;

[0575] deactivating the first information;

[0576] suspending use of the first information;

[0577] wherein the first information comprises at least one of:

[0578] an identifier of the user;

[0579] user configuration information associated with the identifier.

[0580] In some embodiments, the method further comprises:

[0581] receiving fourth information sent by a third network function;

[0582] The fourth information is used to indicate an identity authentication result of a user accessing a service, and the user is associated with a subscription relationship of a first terminal.

[0583] FIG. 7a is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 7a, the embodiment of the present disclosure relates to a communication method, which is performed by a user identity recognition module, and the above method comprises:

[0584] Step S7101: performing authentication and authorization of a user accessing a service.

[0585] In some embodiments, the optional implementation of step S7101 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0586] Step S7102: checking, storing and / or updating user configuration information.

[0587] In some embodiments, the optional implementation of step S7102 can refer to the optional implementation of step S2102 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.

[0588] The communication method related to the embodiments of the present disclosure can comprise at least one of steps S7101 to S7102. For example, step S7101 can be implemented as an independent embodiment, and step S7102 can be implemented as an independent embodiment. For example, step S7101 in combination with step S7102 can be implemented as an independent embodiment, and step S7101 in combination with step S7102 can be implemented as an independent embodiment, but not limited thereto. It should be noted that each step can be independently implemented, or can be arbitrarily exchanged in order and freely combined for implementation without contradiction.

[0589] FIG. 7b is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 7b, the embodiment of the present disclosure relates to a communication method, which is performed by a user identity recognition module, and the above method comprises:

[0590] Step S7201: performing a second operation.

[0591] In some embodiments, the second operation is an operation associated with performing authentication and / or authorization of a user accessing a service, and the user is associated with a subscription relationship of a first terminal.

[0592] In some embodiments, the optional implementation of step S7201 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related by FIG. 2a, which are not described herein again.

[0593] In some embodiments, the service is a service deployed by an operator and / or a non-operator.

[0594] In some embodiments, the service is a slice service.

[0595] In some embodiments, the user is one of the following:

[0596] A first type of user, the first type of user being a user using a second terminal and connecting to the network through the first terminal;

[0597] A second type of user, the second type of user being a user connecting to the network using the first terminal.

[0598] In some embodiments, the method further comprises at least one of the following:

[0599] Storing user configuration information of the user;

[0600] Updating the user configuration information of the user.

[0601] FIG. 8a is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 8a, the embodiment of the present disclosure relates to a communication method, which is used for a communication system 100, and the method comprises one of the following steps:

[0602] Step S8101: The first network function sends fourth information to the third network function.

[0603] In some embodiments, the fourth information is used to indicate an identity authentication result of a user accessing a service, the user being a user associated with a subscription relationship of the first terminal.

[0604] The optional implementation of step S8101 can refer to the optional implementation of step S2106 in FIG. 2a and other associated parts in the embodiments related by FIG. 2a, which are not described herein again.

[0605] Step S8102: The third network function sends the fourth information to the first terminal.

[0606] In some embodiments, the fourth information is used to indicate an identity authentication result of a user accessing a service, the user being a user associated with a subscription relationship of the first terminal.

[0607] The optional implementation of step S8102 can refer to the optional implementation of step S2107 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which are not described herein again.

[0608] In some embodiments, the above method can include the method of the above-mentioned communication system side, terminal side, network device side, and the like, which are not described herein again.

[0609] In order to better understand the embodiments of the present disclosure, the technical solutions of the present disclosure are further described below through some exemplary embodiments:

[0610] In some embodiments, the functions of the first network function (for example, 3GPP HN side) include at least one of the following:

[0611] The HN NF should be able to authenticate and authorize user access to operator and non-operator deployed (i.e. external non-3GPP) services;

[0612] The HN NF should be able to check, store and update the user profile of the user;

[0613] The HN NF should be able to support the activation, deactivation and suspension of the related settings in the user identifier and user profile information of the user using each device or UE;

[0614] The HN NF should be able to securely provide credentials to the UE or non-3GPP device connected via the gateway UE to enable the UE or non-3GPP device to access the network and its services;

[0615] The HN NF should be able to interwork with third party network entities to authenticate the user identity;

[0616] The HN NF should be able to expose user profile information (e.g. content of the user profile information, authorization / authentication result) to services, which is only necessary to provide the service and the user has agreed upon when registering for the service;

[0617] The HN NF should be able to restrict services to request the network to only authenticate users for a service for which the user has established an association of the user identifier with the user according to the specified authentication policy of the service;

[0618] The HN NF should be able to provide the user identity authentication result to the service network to allow the UE to access the slice.

[0619] In some embodiments, the functions of the third network function (for example, 3GPP SN side) include at least one of the following:

[0620] The SN NF should be able to allow the UE to access the slice based on a successful user identity authentication, or reject the UE to access the slice based on an unsuccessful user identity authentication;

[0621] The SN NF should be able to restrict the use of the user's identifier, including in roaming scenarios.

[0622] In some embodiments, the functions of the first terminal include at least one of:

[0623] The UE should be able to receive provisioned credentials to access the network and its services according to the 3GPP subscription relationship that has been linked to the user identity;

[0624] The UE should be able to support authentication and authorization of the user to access operator and non-operator deployed (i.e. external non-3GPP) services;

[0625] The UE should be able to store and update the user's user profile information;

[0626] The UE should be able to support the activation, deactivation and suspension of the user's identifier and related settings in the user profile information per UE by the user.

[0627] In some embodiments, the functions of the user identity module (e.g. USIM) include at least one of:

[0628] The USIM should be able to support authentication and authorization of the user to access operator and non-operator deployed (i.e. external non-3GPP) services.

[0629] The USIM should be able to store and update the user's user profile.

[0630] The embodiments of the present disclosure also propose an apparatus for implementing any of the above methods, for example, an apparatus is proposed, which includes units or modules for implementing the steps performed by the terminal in any of the above methods. For another example, another apparatus is proposed, which includes units or modules for implementing the steps performed by the network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0631] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize any of the above methods or realize the functions of each unit or module of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of logical relationship of elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured through a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be all implemented in the form of processor calling software, or all implemented in the form of hardware circuit, or part implemented in the form of processor calling software and the remaining part implemented in the form of hardware circuit.

[0632] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0633] FIG. 9a is a structural schematic diagram of the first network function 9100 according to an embodiment of the present disclosure. As shown in FIG. 9a, the first network function 9100 can include at least one of a transceiver module 9101, a processing module 9102, and the like. Optionally, the transceiver module is configured to perform at least one of the communication steps, such as transmitting and / or receiving, performed by the first network function 9100 in any of the above methods, and details are not described herein. Optionally, the processing module is configured to perform at least one of the other steps performed by the first network function 9100 in any of the above methods, and details are not described herein.

[0634] FIG. 9b is a structural schematic diagram of the second network function 9200 according to an embodiment of the present disclosure. As shown in FIG. 9b, the second network function 9200 can include at least one of a transceiver module 9201, a processing module 9202, and the like. Optionally, the transceiver module is configured to perform at least one of the communication steps (e.g., sending and / or receiving) performed by the second network function 9200 in any of the methods above. In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be replaced by a transceiver. Optionally, the processing module is configured to perform at least one of the other steps performed by the second network function 9200 in any of the methods above.

[0635] FIG. 9c is a structural schematic diagram of the third network function 9300 according to an embodiment of the present disclosure. As shown in FIG. 9c, the third network function 9300 can include at least one of a transceiver module 9301, a processing module 9302, and the like. Optionally, the transceiver module is configured to perform at least one of the communication steps (e.g., sending and / or receiving) performed by the third network function 9300 in any of the methods above. In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be replaced by a transceiver. Optionally, the processing module is configured to perform at least one of the other steps performed by the third network function 9300 in any of the methods above.

[0636] FIG. 9d is a structural schematic diagram of the first terminal 9400 according to an embodiment of the present disclosure. As shown in FIG. 9d, the first terminal 9400 can include at least one of a transceiver module 9401, a processing module 9402, and the like. Optionally, the transceiver module is configured to perform at least one of the communication steps (e.g., sending and / or receiving) performed by the first terminal 9400 in any of the methods above. In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be replaced by a transceiver. Optionally, the processing module is configured to perform at least one of the other steps performed by the first terminal 9400 in any of the methods above.

[0637] FIG. 9e is a structural schematic diagram of the user identity identification module 9500 according to an embodiment of the present disclosure. As shown in FIG. 9e, the user identity identification module 9500 can include at least one of a transceiver module 9501, a processing module 9502, and the like. Optionally, the transceiver module is configured to perform at least one of the communication steps (e.g., sending and / or receiving) performed by the user identity identification module 9500 in any of the above methods, details of which are not described herein again. In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be replaced by a transceiver. Optionally, the processing module is configured to perform at least one of the other steps performed by the user identity identification module 9500 in any of the above methods, details of which are not described herein again.

[0638] In some embodiments, the processing module can be a module or can include a plurality of sub-modules. Optionally, the plurality of sub-modules perform all or part of the steps required to be performed by the processing module, respectively. Optionally, the processing module can be replaced by a processor.

[0639] FIG. 10a is a structural schematic diagram of a communication device 8100 according to an embodiment of the present disclosure. The communication device 8100 can be a network device (e.g., an access network device, a core network device, or the like), a terminal (e.g., a user equipment or the like), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 8100 can be used to implement the methods described in the above method embodiments, details of which can be referred to the descriptions in the above method embodiments.

[0640] As shown in FIG. 10a, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general purpose processor or a special purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be configured to process communication protocols and communication data, and the central processing unit can be configured to control the communication device (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, or the like), execute programs, and process data of the programs. The communication device 8100 is configured to implement any of the above methods.

[0641] In some embodiments, the communication device 8100 further includes one or more memories 8102 configured to store instructions. Optionally, all or part of the memory 8102 can also be located outside the communication device 8100.

[0642] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceiver 8103 performs at least one of the communication steps of transmitting and / or receiving in the above-described methods, and the processor 8101 performs at least one of the other steps.

[0643] In some embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms of transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms of transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms of receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.

[0644] In some embodiments, the communication device 8100 can include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected with the memory 8102, and the interface circuit 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0645] The communication device 8100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by FIG. 10a. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) other, etc.

[0646] FIG. 10b is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 10b can be referred to, but is not limited thereto.

[0647] The chip 8200 includes one or more processors 8201, and the chip 8200 is configured to execute any of the above methods.

[0648] In some embodiments, the chip 8200 further includes one or more interface circuits 8202. Optionally, the interface circuits 8202 are connected with the memory 8203, and the interface circuits 8202 can be configured to receive signals from the memory 8203 or other devices, and the interface circuits 8202 can be configured to send signals to the memory 8203 or other devices. For example, the interface circuits 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201.

[0649] In some embodiments, the interface circuits 8202 perform at least one of the communication steps (for example, step S2101, step S3101, but not limited thereto) in the above-described methods, and the processor 8201 performs at least one of the other steps.

[0650] In some embodiments, the interface circuits, interfaces, transceiver pins, transceivers, and the like can be replaced with each other.

[0651] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Optionally, all or part of the memories 8203 can be outside the chip 8200.

[0652] The present disclosure further proposes a storage medium, and the above-mentioned storage medium stores instructions, and when the above-mentioned instructions run on the communication device 8100, the communication device 8100 executes any one of the above methods. Optionally, the above-mentioned storage medium is an electronic storage medium. Optionally, the above-mentioned storage medium is a computer readable storage medium, but not limited thereto, and it can also be a storage medium readable by other devices. Optionally, the above-mentioned storage medium can be a non-transitory storage medium, but not limited thereto, and it can also be a transitory storage medium.

[0653] The present disclosure further proposes a program product, and the above-mentioned program product is executed by the communication device 8100, so that the communication device 8100 executes any one of the above methods. Optionally, the above-mentioned program product is a computer program product.

[0654] The present disclosure further proposes a computer program, and when it runs on a computer, it makes the computer execute any one of the above methods.

Claims

1. A communication method, characterized in that: The method is performed by a first network function, and the method includes: Perform authentication and / or authorization of user access to services; The user is a user associated with a contract relationship with the first terminal, and the first network function is a network function in a home network HN of the first terminal.

2. The method according to claim 1, characterized in that The service is a slicing service.

3. The method according to claim 1, characterized in that The user is one of the following: A first type of user, wherein the first type of user is a user who uses a second terminal and connects to the network through the first terminal; The second type of user is a user who uses the first terminal to connect to the network.

4. The method according to claim 1, wherein Perform authentication and / or authorization of user access to services, including: Based on the user identifier and / or user configuration information, authentication and / or authorization of the user to access the service is performed.

5. The method according to claim 4, characterized in that The method further comprises at least one of the following: Checking the user configuration information; Storing the user configuration information; The user configuration information is updated.

6. The method according to claim 1, characterized in that The method further comprises: performing a first operation on the first information; The first information includes at least one of the following: an identifier of the user; User configuration information associated with the identifier; The first operation includes at least one of the following: activating the first information; deactivating the first information; The use of the first information is suspended.

7. The method according to claim 6, characterized in that The performing of the first operation on the first information includes: sending second information to the first terminal; The second information is used to indicate at least one of the following: activating the first information; deactivating the first information; The use of the first information is suspended.

8. The method according to claim 1, characterized in that The method further comprises: sending third information to the third network function; The third information is used to indicate at least one of the following: The first credential is a credential required for authenticating the user to the network accessed by the user and / or the services in the network. The user is a user using the first terminal; The second credential is: a credential required for a network accessed by the user and / or a service in the network to authenticate the user, and the user is a user who uses a device associated with the first terminal.

9. The method according to claim 1, characterized in that The method further comprises: Authenticating the user is performed with the second network function.

10. The method according to claim 1, characterized in that The method further comprises: Send user configuration information to an application server or the first terminal.

11. The method according to claim 10, characterized in that The user configuration information includes information necessary for providing the service and / or information that the user agrees to disclose when registering for the service.

12. The method according to claim 1, characterized in that The method further comprises: The user to be authenticated is determined, where the user to be authenticated is a user for whom an association has been established with a user identifier based on a service-related authentication policy.

13. The method according to claim 1, wherein The method further comprises: Sending fourth information to the third network function, where the fourth information is used to indicate an identity authentication result of the user.

14. A communication method, characterized in that: The method is performed by a second network function, and the method includes: Perform authentication and / or authorization of user access to services; The user is a user associated with the contract relationship of the first terminal, and the second network function is an application layer network function. Or third-party functionality.

15. The method according to claim 14, characterized in that The method further comprises: Authenticating the user is performed with the first network function.

16. The method according to claim 14, characterized in that The service is a slicing service.

17. The method according to claim 14, characterized in that The user is one of the following: A first type of user, wherein the first type of user is a user who uses a second terminal and connects to the network through the first terminal; The second type of user is a user who uses the first terminal to connect to the network.

18. A communication method, characterized in that: The method is performed by a third network function, and the method includes: Perform authentication and / or authorization of user access to services; The user is a user associated with a contract relationship with the first terminal, and the third network function is a network function in the service network SN.

19. The method according to claim 18, characterized in that The method further comprises: receiving third information sent by the first network function; The third information is used to indicate at least one of the following: a first credential, where the first credential is a credential required for authenticating the user to a network accessed by the user and / or a service in the network, where the user is a user using the first terminal; The second credential is: a credential required for a network accessed by the user and / or a service in the network to authenticate the user, and the user is a user who uses a device associated with the first terminal.

20. The method according to claim 19, characterized in that The method further comprises: Send the third information to the first terminal.

21. The method according to claim 18, wherein The method further comprises: Fourth information sent by the first network function is received, where the fourth information is used to indicate an identity authentication result of a user accessing the service.

22. The method according to claim 21, characterized in that The method further comprises: Send the fourth information to the first terminal.

23. The method according to claim 18, wherein The service is a slicing service.

24. The method according to claim 18, wherein The user is one of the following: A first type of user, wherein the first type of user is a user who uses a second terminal and connects to the network through the first terminal; The second type of user is a user who uses the first terminal to connect to the network.

25. The method according to claim 18, wherein The method further comprises at least one of the following: Determining that the identity authentication result indicates that the user authentication is successful, and allowing the user to access the service; Determining that the identity authentication result indicates that the user authentication has failed, and denying the user access to the service.

26. The method according to claim 18, wherein The method further comprises: A user indicated by the user identifier is restricted from using services of the network to which the third network function belongs.

27. A communication method, characterized in that: The method is performed by a first terminal, and includes: receiving third information sent by the third network function; The first terminal is a terminal with a contract relationship; and the third information is used to indicate at least one of the following: The first credential is a credential required for authenticating the user to the network accessed by the user and / or the services in the network. The user is a user using the first terminal; The second credential is: a credential required for a network accessed by the user and / or a service in the network to authenticate the user, and the user is a user who uses a device associated with the first terminal.

28. The method according to claim 27, characterized in that The service is a slicing service.

29. The method according to claim 27, characterized in that The receiving the third information sent by the first network function includes: receiving, based on subscription information associated with an identifier of a user, the third information sent by the first network function; The user is a user associated with a contract relationship with the first terminal.

30. The method according to claim 29, wherein The user is one of the following: A first type of user, wherein the first type of user is a user who uses a second terminal and connects to the network through the first terminal; The second type of user is a user who uses the first terminal to connect to the network.

31. The method according to claim 27, wherein The method further comprises at least one of the following: authenticating the user to access the network based on the credentials; The user is authenticated to access services in the network based on the credentials.

32. The method according to claim 27, wherein The method further comprises: performing operations associated with authentication and / or authorization of user access to services performed by the first network function; The user is a user associated with the contract relationship with the first terminal.

33. The method according to claim 27, wherein The method further comprises at least one of the following: Storing user configuration information of the user; Update user configuration information of the user.

34. The method according to claim 27, wherein The method further comprises: receiving second information sent by the first network function; The second information is used to indicate at least one of the following: Activate the first message; Deactivate First Message; Suspend the use of First Information; The first information includes at least one of the following: an identifier of the user; User configuration information associated with the identifier.

35. The method according to claim 27, wherein The method further comprises: receiving fourth information sent by the third network function; The fourth information is used to indicate an identity authentication result of a user accessing a service, and the user is a user associated with a contract relationship with the first terminal.

36. A communication method, characterized in that: The method is performed by a user identity recognition module, and includes: performing a second operation; The second operation is an operation associated with performing authentication and / or authorization of a user to access a service; and the user is a user associated with a contract relationship with the first terminal.

37. The method according to claim 36, wherein The service is a slicing service.

38. The method according to claim 36, wherein The user is one of the following: A first type of user, wherein the first type of user is a user who uses a second terminal and connects to the network through the first terminal; The second type of user is a user who uses the first terminal to connect to the network.

39. The method according to claim 36, wherein The method further comprises at least one of the following: Storing user configuration information of the user; Update user configuration information of the user.

40. A communication method, characterized in that: The method further comprises: The first network function sends fourth information to the third network function, where the fourth information is used to indicate an identity authentication result of a user accessing the service, where the user is a user associated with a contract relationship with the first terminal; Alternatively, the third network function sends third information to the first terminal; The first terminal is a terminal with a contract relationship; and the third information is used to indicate at least one of the following: The first credential is a credential required for authenticating the user to the network accessed by the user and / or the services in the network. The user is a user using the first terminal; The second credential is: a credential required for a network accessed by the user and / or a service in the network to authenticate the user, and the user is a user who uses a device associated with the first terminal.

41. A first network function, characterized in that The first network function includes: The processing module is configured to: Perform authentication and / or authorization of user access to services; The user is a user associated with a contract relationship with the first terminal, and the first network function is a network function in a home network HN of the first terminal.

42. A second network function, characterized in that The second network function includes: The processing module is configured to: Perform authentication and / or authorization of user access to services; The user is a user associated with a contract relationship with the first terminal, and the second network function is an application layer network function or a third-party function.

43. A third network function, characterized in that The third network function includes: The processing module is configured to: Perform authentication and / or authorization of user access to services; The user is a user associated with a contract relationship with the first terminal, and the third network function is a network function in the service network SN.

44. A first terminal, characterized in that: The first terminal includes: The transceiver module is configured as follows: receiving third information sent by the third network function; The first terminal is a terminal with a contract relationship; and the third information is used to indicate at least one of the following: The first credential is a credential required for authenticating the user to the network accessed by the user and / or the services in the network. The user is a user using the first terminal; The second credential is: a credential required for a network accessed by the user and / or a service in the network to authenticate the user, and the user is a user who uses a device associated with the first terminal.

45. A user identity recognition module, characterized in that: The user identification module includes: The processing module is configured to: performing a second operation; The second operation is an operation associated with performing authentication and / or authorization of a user to access a service; and the user is a user associated with a contract relationship with the first terminal.

46. ​​A communication system, characterized in that The communication system includes a first network function, a second network function, a third network function, a first terminal and a user identity identification module, wherein the first network function is configured as the communication method described in any one of claims 1 to 13; the second network function is configured as the communication method described in any one of claims 14 to 17; the third network function is configured as the communication method described in any one of claims 18 to 26; the first terminal is configured as the communication method described in any one of claims 27 to 35; and the user identity identification module is configured as the communication method described in any one of claims 36 to 39.

47. A first network function, characterized in that The first network function includes: one or more processors; The first network function is used to execute the communication method described in any one of claims 1 to 13.

48. A second network function, characterized in that The second network function includes: one or more processors; The second network function is used to execute the communication method described in any one of claims 14 to 17.

49. A third network function, characterized in that The third network function includes: one or more processors; The third network function is configured to execute the communication method according to any one of claims 18 to 26.

50. A first terminal, characterized in that: The first terminal includes: one or more processors; The first terminal is used to execute the communication method according to any one of claims 27 to 35.

51. A user identity recognition module, characterized in that: The user identification module includes: one or more processors; Wherein, the user identity recognition module is used to execute the communication method described in any one of claims 36 to 39.

52. A storage medium, characterized in that The storage medium stores instructions, which, when executed on a communication device, enable the communication device to execute the communication method described in any one of claims 1 to 13, claims 14 to 17, claims 18 to 26, claims 27 to 35, and / or claims 36 to 39.

Citation Information

Patent Citations

  • Electrically-heating type smoking articles

    KR1020230151445A

  • Slice authentication method and apparatus

    US20230048066A1

  • Slice service verification method and apparatus

    US20230102604A1

  • Identity layer for IoT devices

    US20230164555A1

  • Communication method and apparatus

    WO2023011069A1