Communication method and communication apparatus
By storing the correspondence between terminal information and security credentials, and using security credentials generated by 3GPP access for non-3GPP access authentication, the terminal security and efficiency issues in the ATSSS-lite scenario are resolved, ensuring the security and user experience of non-3GPP access.
Patent Information
- Application Number
- PCT/CN2025/101149
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-04
- Filing Date
- 2025-06-16
- Publication Date
- 2026-01-08
AI Technical Summary
In the ATSSS-lite scenario, how can we ensure the security of terminals accessing networks through non-3GPP networks, especially when N3IWF or TNGF are not used, to ensure that terminal information is not leaked and to reduce signaling overhead and processing latency?
By storing the correspondence between terminal information and security credentials, and using the security credentials generated during 3GPP access for authentication, security authentication can be performed directly during non-3GPP access, reducing signaling overhead and lowering the risk of information leakage.
It enables efficient secure authentication in non-3GPP access networks, reduces the risk of information leakage, reduces processing latency, and improves user experience.
Smart Images

Figure CN2025101149_08012026_PF_FP_ABST
Abstract
Description
Communication method and communication apparatus
[0001] This application claims priority to the Chinese patent application No. 202410895341.3, filed on July 4, 2024, and entitled "Communication method and communication apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of wireless communication, and more particularly, to a communication method and a communication apparatus. BACKGROUND
[0003] In an access traffic steering, switching, splitting (ATSSS) scenario, both 3rd generation partnership project (3GPP) access and non-3GPP access are allowed, where a non-3GPP interWorking function (N3IWF) or a trusted non-3GPP gateway function (TNGF) is used on the non-3GPP access to establish a connection with a core network.
[0004] An access traffic steering, switching, splitting (ATSSS-lite) scenario simplifies the ATSSS scenario, where the N3IWF or the TNGF is no longer used on the non-3GPP access to establish a connection with the core network, but a non-3GPP user plane is established directly through a non-3GPP network access node such as a wireless fidelity (WiFi) network to connect with a user plane function (UPF) network element. However, in the ATSSS-lite scenario, how to ensure the security of the terminal through the non-3GPP access network is a problem to be considered. SUMMARY
[0005] The present application provides a communication method and a communication apparatus, which can ensure the security of the terminal through the non-3GPP access network.
[0006] In a first aspect, a communication method is provided. The method can be performed by a user plane network element. In the absence of special description, the "user plane network element" in the present application can refer to the user plane network element itself (for example, a UPF), a component in the user plane network element (for example, a communication module, a processor, a circuit, a chip, or a chip system, etc.), or a logic module or software capable of realizing all or part of the functions of the user plane network element.
[0007] The method comprises: in a process of establishing a session for a terminal through a 3GPP access, storing a correspondence between information of the terminal and a security credential, the security credential being used for security authentication of the terminal in a process of accessing a non-3GPP access network, the session being used for 3GPP access and non-3GPP access; in the process of accessing the non-3GPP access network by the terminal, receiving an authentication request message from the terminal, the authentication request message comprising the information of the terminal; determining the security credential according to the information of the terminal and the correspondence; and performing security authentication on the terminal according to the security credential.
[0008] Optionally, the terminal supports ATSSS-lite, that is, the terminal can simultaneously use one 3GPP access network and one non-3GPP access network, and a border node is no longer used on the non-3GPP access.
[0009] Based on the above scheme, in a process of establishing a session for a terminal through a 3GPP access, a user plane network element can store a correspondence between information of the terminal and a security credential, the security credential indicating that the terminal can perform secure communication through the 3GPP access. Further, in a process of accessing a non-3GPP access network by the terminal, the terminal can send an authentication request message carrying the information of the terminal to the user plane network element to request the user plane network element to perform security authentication on the terminal. In this way, the user plane network element can retrieve the security credential from the locally stored correspondence based on the information of the terminal, and then perform security authentication on the terminal using the security credential. This implementation does not need to allocate or bind a new security credential identifier for the security credential, but can determine the corresponding security credential by transferring the information of the terminal and retrieving the correspondence, and then complete the security authentication, so that the terminal can perform secure communication through the non-3GPP access in the case that the security authentication is passed.
[0010] In addition, identity verification of the terminal in the non-3GPP access network using the security credential obtained in the process of using the 3GPP access network can not only reduce unnecessary signaling overhead, but also reduce the risk of leakage of the information of the terminal. By storing the correspondence, the security credential can be obtained based on the stored correspondence in the subsequent non-3GPP access process, and security authentication can be performed, which can reduce processing delay and improve user experience. Determining the security credential based on the information of the terminal and the correspondence can not only protect the information of the terminal, but also guarantee secure communication of the terminal through the non-3GPP access network.
[0011] In some implementations of the first aspect, the information of the terminal comprises at least one of: an internet protocol (IP) address of the terminal associated with the non-3GPP access; an IP address of the terminal associated with the 3GPP access; a public network IP address of the user plane network element; information obtained based on a security processing of an identifier of the terminal and an identifier of the session; an IP address of the terminal associated with the session; or a globally unique temporary UE identity (GUTI) of the terminal.
[0012] In some implementations of the first aspect, the security credential is generated according to a security context of the 3GPP access, or the security credential is randomly generated.
[0013] Optionally, the security credential can be a key, or a token or verification information related to the token, or a message authentication code (MAC) or verification information related to the MAC, etc.
[0014] In some implementations of the first aspect, storing the correspondence between the information of the terminal and the security credential comprises: storing the correspondence between the information of the terminal and the security credential according to the indication information, wherein the indication information indicates that the session is a session in an ATSSS-lite scenario.
[0015] Based on the above scheme, the user plane network element can know, according to the obtained indication information, that the session is a session in an ATSSS-lite scenario, and then store the correspondence, or in other words, the indication information can trigger the user plane network element to store the corresponding information, so as to facilitate subsequent acquisition of the security credential and security authentication based on the stored correspondence in the subsequent non-3GPP access process, which can reduce processing delay and improve user experience.
[0016] In some implementations of the first aspect, the method further comprises: before the terminal accesses the non-3GPP access network, sending the information of the terminal to the terminal, wherein the information of the terminal can comprise at least one of: an IP address of the terminal associated with the non-3GPP access, an IP address of the terminal associated with the 3GPP access, an IP address of the terminal associated with the session, or a public network IP address of the user plane network element.
[0017] Based on the above scheme, when the terminal accesses through the non-3GPP access network, the terminal can send an authentication request message to the user plane network element based on the public network IP address of the user plane network element, so that the terminal and the user plane network element can establish a non-3GPP user plane. In addition, the terminal can transmit data to the user plane network element based on at least one of the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, or the IP address of the terminal associated with the session.
[0018] In some implementations of the first aspect, the information of the terminal is sent to the terminal, including: sending the information of the terminal to the terminal according to the indication information; wherein the indication information indicates that the session is a session in an ATSSS-lite scenario.
[0019] Based on the above scheme, the user plane network element can know that the session is a session in an ATSSS-lite scenario according to the acquired indication information, and then send the information of the terminal to the terminal, or in other words, the indication information can trigger the user plane network element to send the information of the terminal to the terminal, so that the terminal can send an authentication request message according to the received information of the terminal in subsequent non-3GPP access.
[0020] In some implementations of the first aspect, the information of the terminal is sent to the terminal, including: sending the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the session, and the IP address of the terminal associated with the 3GPP access to the terminal according to that the session uses a multi-path transmission control protocol (TCP) (multi-path TCP, MPTCP) function and / or a multi-path quick user datagram protocol (UDP) internet connection protocol (quick UDP internet connection, QUIC) (multi-path QUIC, MPQUIC) function.
[0021] In some implementations of the first aspect, the authentication request message includes the information of the terminal, including: the authentication request message includes a data packet and / or a first information element, the destination address and / or the source address of the data packet is the information of the terminal, and the first information element includes the information of the terminal.
[0022] At this time, the information of the terminal carried in the first information element includes one or more of the following: the IP address associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, the IP address of the terminal associated with the session, or the public network IP address of the user plane network element.
[0023] In some implementations of the first aspect, the first information element can be an IDi information element in an IKE_AUTH_Request message of an internet key exchange (IKEv2) protocol, or a Pre_shared_key information element in a Client Hello message of a transport layer security (TLS) protocol.
[0024] Based on the technical solution described above, by multiplexing the IDi information element in the current IKEv2 protocol IKE_AUTH_Request message, or multiplexing the Pre_shared_key information element in the current TLS protocol Client Hello message, that is, using the message data structure in the current protocol to deliver the terminal information, the current message format can be changed without increasing the complexity.
[0025] In some implementations of the first aspect, determining the security credential according to the terminal information and the corresponding relationship comprises: in a case where the source address and / or the destination address of the data packet are the same as the terminal information carried in the first information element, determining the security credential according to the terminal information and the corresponding relationship.
[0026] Based on the above scheme, in a case where the authentication request message includes the data packet and the first information element, the user plane network element first judges whether the data packet and the first information element match, for example, judges whether the source address (such as an IP address associated with a non-3GPP access, or an IP address of a terminal associated with a 3GPP access, or an IP address of a terminal associated with a session) of the data packet matches the IP address associated with the non-3GPP access, or the IP address of the terminal associated with the 3GPP access, or the IP address of the terminal associated with the session carried in the first information element, and further judges whether the destination address of the data packet matches the public network IP address of the user plane network element carried in the first information element. Only in a case where the data packet and the first information element match, the security credential is determined based on the terminal information and the corresponding relationship stored locally. Through multiple verifications, the network security can be guaranteed, the leakage of the terminal information can be avoided, and potential security risks can be avoided.
[0027] In some implementations of the first aspect, the method further comprises: in a case where the security authentication of the terminal is passed, sending an authentication response message, the authentication response message including the terminal information.
[0028] In some implementations of the first aspect, the terminal information includes information obtained by performing security processing based on the identifier of the terminal and the identifier of the session, and before storing the corresponding relationship between the terminal information and the security credential, the method further comprises: obtaining the information obtained by performing security processing based on the identifier of the terminal and the identifier of the session.
[0029] It can be understood that the information processed based on the terminal identifier and the session identifier is information processed based on the terminal identifier on the session identifier, or information processed based on the session identifier on the terminal identifier, or information processed based on the terminal identifier and the session identifier. As an example, the information processed based on the terminal identifier and the session identifier can be a key ID (KID), or a connection ID, or a certificate subject name, and the present application does not exclude other security processing methods.
[0030] In some implementations of the first aspect, the information processed based on the terminal identifier and the session identifier is obtained by: receiving the information processed based on the terminal identifier and the session identifier from the session management network element; or receiving the terminal identifier and the session identifier from the session management network element; and determining the information processed based on the terminal identifier and the session identifier according to the terminal identifier and the session identifier.
[0031] In some implementations of the first aspect, the method further comprises: deleting the information processed based on the terminal identifier and the session identifier and the security credential after the terminal is securely authenticated.
[0032] Based on the above scheme, by deleting the information processed based on the terminal identifier and the session identifier and the security credential, the uniqueness and security of the terminal information and the corresponding security credential can be ensured. Because the terminal identifier or the session identifier can be reused for different sessions, the information processed based on the terminal identifier and the session identifier can also be reused, so that different sessions of the same terminal can be linked, and there is a certain degree of privacy risk. Therefore, after the secure authentication of the terminal is completed, the user plane network element can delete the information processed based on the terminal identifier and the session identifier and the corresponding security credential.
[0033] In some implementations of the first aspect, the terminal information includes a GUTI of the terminal, and before storing the correspondence between the terminal information and the security credential, the method further comprises: receiving the GUTI of the terminal and the security credential from the session management network element.
[0034] Optionally, in order to ensure the uniqueness of the terminal identity and protect the user privacy, the network side can update the GUTI of the terminal in real time for different sessions of the terminal, so that the terminal can use different GUTIs for 3GPP access and / or non-3GPP access, and the user plane network element updates the correspondence in real time, that is, stores the correspondence between the updated GUTI of the terminal and the security credential.
[0035] In a second aspect, a communication method is provided. The method can be performed by a terminal. Unless specifically stated, the "terminal" in this application can refer to the terminal itself (for example, a user equipment (UE)), a component (for example, a communication module, a processor, a circuit, a chip, or a chip system) in the terminal, or a logic module or software that can realize all or part of the terminal functions.
[0036] The method includes: establishing a session for the terminal through 3GPP access, the session being used for 3GPP access and non-3GPP access of the terminal; sending an authentication request message to a user plane network element in the process of accessing the network through non-3GPP access, the authentication request message including information of the terminal, the information of the terminal being used to determine a security credential for security authentication of the non-3GPP access of the terminal; and receiving an authentication response message in the case that the security authentication of the non-3GPP access of the terminal is passed.
[0037] Based on the above technical solution, the terminal requests the network side to establish a session for the terminal through 3GPP access, and requests the user plane network element to perform security authentication by sending the information of the terminal in the process of accessing the network through non-3GPP access, so that the network side can verify the information of the terminal and then complete the security authentication. Not only can the risk of leakage of terminal information be reduced, but also the security of the terminal accessing the network through non-3GPP access can be ensured.
[0038] In some implementations of the second aspect, the information of the terminal includes at least one of: an IP address of the terminal associated with the non-3GPP access; an IP address of the terminal associated with the session; an IP address of the terminal associated with the 3GPP access; a public IP address of the user plane network element; information obtained by performing security processing based on an identifier of the terminal and an identifier of the session; or a global unique temporary UE identifier (GUTI) of the terminal.
[0039] In some implementations of the second aspect, the authentication request message including the information of the terminal includes: the authentication request message includes a data packet and / or a first information element, a destination address and / or a source address of the data packet are the information of the terminal, and the first information element includes the information of the terminal.
[0040] In some implementations of the second aspect, the first information element can be: an IDi information element in an IKE_AUTH_Request message of an IKEv2 protocol, or a Pre_shared_key information element in a Client Hello message of a Transport Layer Security (TLS) protocol.
[0041] In some implementations of the second aspect, in the process of establishing the session for the terminal through the 3GPP access, the method further includes: sending indication information, the indication information indicating that the session is a session in an ATSSS-lite scenario.
[0042] In some implementations of the second aspect, in the process of establishing the session for the terminal through the 3GPP access, according to the session using a multi-path transmission control protocol (MPTCP) function and / or a multi-path quick user datagram protocol internet connection (MPQUIC) function, the method receives an IP address of the terminal associated with the non-3GPP access from a user plane network element, an IP address of the terminal associated with the session, and an IP address of the terminal associated with the 3GPP access.
[0043] The beneficial effects and possible designs related to the second aspect can be referred to the related description in the first aspect, and will not be repeated here.
[0044] In a third aspect, a communication method is provided. The method can be performed by a user plane network element. Unless specifically stated, the "user plane network element" in the present application can refer to the user plane network element itself (e.g., a UPF), a component (e.g., a communication module, a processor, a circuit, a chip, or a chip system) in the user plane network element, or a logic module or software capable of realizing all or part of the functions of the user plane network element.
[0045] The method includes: in a process of establishing a session for a terminal through a 3GPP access, storing a correspondence between information of the terminal and an N4 session identifier, the session being used for the 3GPP access and a non-3GPP access, and the N4 session identifier being associated with the session; in a process of the terminal accessing a non-3GPP access network, receiving an authentication request message from the terminal, the authentication request message including the information of the terminal; determining the N4 session identifier according to the information of the terminal and the correspondence; and sending an authentication indication and the N4 session identifier to a session management network element, the authentication indication being used to indicate that the terminal is subjected to a security authentication.
[0046] Based on the above scheme, in the process of establishing a session for a terminal accessing through a 3GPP, the user plane network element can store the correspondence between the information of the terminal and the N4 session identifier generated in the process of the terminal accessing the network through the 3GPP. Further, in the process of the terminal accessing the network through a non-3GPP, the user plane network element can send an authentication request message carrying the information of the terminal to request security authentication for the terminal. In this way, the user plane network element can determine the N4 session identifier based on the information of the terminal to retrieve the locally stored correspondence, and then request the session management network element to perform security authentication for the terminal, which not only protects the identity information of the terminal, but also guarantees the secure communication of the terminal through the non-3GPP.
[0047] In addition, using the N4 session identifier obtained in the process of using the 3GPP access network to perform identity verification for the terminal in the non-3GPP access network not only can reduce unnecessary signaling overhead, but also can reduce the risk of disclosure of terminal information. By storing the correspondence, the N4 session identifier can be obtained based on the stored correspondence in the subsequent non-3GPP access process, and the session management network element is requested to perform security authentication for the terminal, which can reduce the processing delay and improve the user experience.
[0048] In some implementations of the third aspect, the authentication request message includes the information of the terminal, including: the authentication request message includes a data packet and / or a first information element, the destination address and / or the source address of the data packet is the information of the terminal, and the first information element includes the information of the terminal.
[0049] At this time, the information of the terminal carried in the first information element includes one or more of the following: an IP address associated with the non-3GPP access, an IP address of the terminal associated with the 3GPP access, and an IP address of the terminal associated with the session; or a public IP address of the user plane network element.
[0050] In some implementations of the third aspect, determining the N4 session identifier according to the information of the terminal and the correspondence includes: in the case that the source address and / or the destination address of the data packet is the same as the information of the terminal (for example, the IP address associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, or the IP address of the terminal associated with the session) carried in the first information element, determining the N4 session identifier according to the information of the terminal and the correspondence.
[0051] Based on the above scheme, in a case where the authentication request message includes the data packet and the first information element, the user plane network element first judges whether the data packet and the first information element match, for example, judges whether the source address of the data packet matches the IP address associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, or the IP address of the terminal associated with the session carried in the first information element, and further judges whether the destination address of the data packet matches the public network IP address of the user plane network element carried in the first information element, and only in a case where both match, the N4 session identifier is further determined based on the information of the terminal to retrieve the corresponding relationship stored locally, so that network security can be ensured, and leakage of the information of the terminal and potential security risks can be avoided.
[0052] In some implementations of the third aspect, before storing the corresponding relationship between the information of the terminal and the N4 session identifier, the method further includes: establishing an N4 session with the session management network element, and receiving the N4 session identifier from the session management network element.
[0053] In some implementations of the third aspect, storing the corresponding relationship between the information of the terminal and the N4 session identifier includes: storing the corresponding relationship between the information of the terminal and the N4 session identifier according to the indication information, wherein the indication information indicates that the session is a session in a simplified access traffic steering, switching, and splitting ATSSS-lite scenario.
[0054] In some implementations of the third aspect, the information of the terminal includes at least one of the following: an IP address of the terminal associated with the non-3GPP access; an IP address of the terminal associated with the 3GPP access; an IP address of the terminal associated with the session; a public network IP address of the user plane network element; information obtained by performing security processing based on an identifier of the terminal and an identifier of the session; or a global unique temporary UE identifier GUTI of the terminal.
[0055] In some implementations of the third aspect, the method further includes: in a case where the security authentication of the non-3GPP access of the terminal is passed, receiving a first key from the authentication server function or the session management network element, the first key being used to protect the secure communication between the terminal and the user plane network element.
[0056] In some implementations of the third aspect, the authentication indication and the N4 session identifier are carried in an N4 session message; and / or, the first key is carried in the N4 session message.
[0057] In some implementations of the third aspect, the method further includes: sending, to the terminal, information of the terminal before the terminal accesses the non-3GPP access network, where the information of the terminal can be at least one of an IP address of the terminal associated with the non-3GPP access, an IP address of the terminal associated with the 3GPP access, or an IP address of the terminal associated with the session, or a public network IP address of the user plane network element.
[0058] In a fourth aspect, a communication method is provided. The method can be performed by a session management network element. Unless specifically stated, the "session management network element" in the present application can refer to the session management network element itself (for example, SMF), a component (for example, a communication module, a processor, a circuit, a chip, or a chip system) in the session management network element, or a logic module or software that can implement all or part of the functions of the session management network element.
[0059] The method includes: establishing an N4 session with a user plane network element in a process of establishing a session for a terminal accessing a 3GPP access network, and sending an N4 session identifier to the user plane network element, where the session is used for the 3GPP access and a non-3GPP access, and the N4 session identifier is associated with the session; receiving an authentication indication and the N4 session identifier from the user plane network element in a process of the terminal accessing the non-3GPP access network, where the authentication indication is used to indicate a security authentication of the terminal; determining a network access identifier (NAI) of the terminal according to the N4 session identifier; and sending an authentication request message to an authentication server function according to the authentication indication, where the authentication request message includes the NAI.
[0060] Based on the above scheme, in a process of establishing a session for a terminal accessing a 3GPP access network, the session management network element establishes an N4 session with a user plane network element, and sends an N4 session identifier to the user plane network element, that is, the N4 session identifier is generated in the process of the terminal accessing the 3GPP access network. Further, after receiving the authentication indication and the N4 session identifier from the user plane network element, the NAI of the terminal can be determined according to the N4 session identifier, thereby reducing the processing delay and improving the user experience. Further, the NAI is sent to the authentication server function to request a security authentication of the terminal, which not only protects the identity information of the terminal, but also guarantees the secure communication of the terminal accessing the non-3GPP access network.
[0061] In some implementations of the fourth aspect, determining the NAI of the terminal according to the N4 session identifier includes: determining an identifier of the terminal according to the N4 session identifier; and determining the NAI according to the identifier of the terminal.
[0062] In some implementations of the fourth aspect, the authentication indication and the N4 session identifier are carried in an N4 session message.
[0063] The beneficial effects and possible designs related to the fourth aspect can be referred to the related description in the third aspect, which will not be repeated here.
[0064] In a fifth aspect, a communication method is provided. The method can be performed by a terminal. Unless specifically stated, the "terminal" in the present application can refer to the terminal itself (e.g., UE), or a component (e.g., a communication module, a processor, a circuit, a chip, or a chip system, etc.) in the terminal, or a logic module or software that can realize all or part of the terminal functions.
[0065] The method comprises: establishing a session for the terminal through a third generation partnership project (3GPP) access request, the session being used for 3GPP access and non-3GPP access of the terminal; sending an authentication request message to a user plane network element in a process of accessing through the non-3GPP access network; and receiving an authentication response message in a case where security authentication of the non-3GPP access of the terminal is passed.
[0066] In some implementations of the fifth aspect, the authentication request message comprises a data packet and / or a first information element, a destination address and / or a source address of the data packet being information of the terminal, and the first information element comprising information of the terminal.
[0067] In some implementations of the fifth aspect, the information of the terminal comprises at least one of: an IP address of the terminal associated with the non-3GPP access; an IP address of the terminal associated with the 3GPP access; a public network IP address of the user plane network element; information obtained based on security processing of an identifier of the terminal and an identifier of the session; an IP address of the terminal associated with the session; or a globally unique temporary UE identifier (GUTI) of the terminal.
[0068] In some implementations of the fifth aspect, the first information element is: an IDi information element in an IKE_AUTH_Requst message of an Internet Key Exchange (IKE) version 2 (IKEv2) protocol; or a Pre_shared_key information element in a Client Hello message of a Transport Layer Security (TLS) protocol.
[0069] In some implementations of the fifth aspect, in the process of establishing the session for the terminal through the 3GPP access request, the method further comprises: sending indication information, the indication information indicating that the session is a session in an ATSSS-lite scenario.
[0070] In some implementations of the fifth aspect, in the process of establishing a session for the terminal through the 3GPP access, the process includes: receiving, from the user plane network element, an IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the session, and the IP address of the terminal associated with the 3GPP access according to that the session uses a multi-path transmission control protocol (MPTCP) function and / or a multi-path quick user datagram protocol internet connection (MPQUIC) function.
[0071] The beneficial effects and possible designs related to the fifth aspect can be referred to the related description in the third aspect, which will not be repeated here.
[0072] The sixth aspect provides a communication method. The method can be applied to a system side. The system includes a user plane network element. The user plane network element can refer to the user plane network element itself, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system) in the user plane network element, or a logic module or software that can realize all or part of the functions of the user plane network element. The user plane network element is configured to execute the method in the first aspect and any possible implementation manner thereof.
[0073] The method can include: in the process of establishing a session for a terminal through a third generation partnership project (3GPP) access, storing, by a user plane network element, a correspondence between information of the terminal and a security credential, the security credential being used for security authentication of the terminal in a process of accessing a non-3GPP access network, and the session being used for the 3GPP access and the non-3GPP access; in the process of the terminal accessing the non-3GPP access network, receiving, by the user plane network element, an authentication request message from the terminal, the authentication request message including the information of the terminal; determining, by the user plane network element, the security credential according to the information of the terminal and the correspondence; and performing, by the user plane network element, security authentication on the terminal according to the security credential.
[0074] Optionally, the system further includes a terminal. The terminal can refer to the terminal itself, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system) in the terminal, or a logic module or software that can realize all or part of the functions of the terminal. The terminal can be configured to execute the method in the second aspect and any possible implementation manner thereof.
[0075] Optionally, the system further includes a session management network element and / or a mobility management network element.
[0076] In a seventh aspect, a communication method is provided. The method can be applied to a system side. The system includes a user plane network element, a session management network element, and an authentication server function. The "user plane network element, session management network element, and authentication server function" can refer to the user plane network element, session management network element, and authentication server function themselves, can refer to constituent components (for example, communication modules, processors, circuits, chips, or chip systems, etc.) of the user plane network element, session management network element, and authentication server function, or can refer to logic modules or software capable of implementing all or part of the user plane network element, session management network element, and authentication server function.
[0077] The method can include: in a process of establishing a session for a terminal through a 3GPP access, storing, by the user plane network element, a correspondence between information of the terminal and an N4 session identifier, the session being for the 3GPP access and a non-3GPP access, the N4 session identifier being associated with the session; in a process in which the terminal accesses a network through the non-3GPP access, receiving, by the user plane network element, an authentication request message from the terminal, the authentication request message including the information of the terminal, determining, according to the information of the terminal and the correspondence, the N4 session identifier, and sending, by the user plane network element, an authentication indication and the N4 session identifier to the session management network element, the authentication indication being used to indicate that the terminal is to be authenticated securely; determining, by the session management network element, a NAI of the terminal according to the N4 session identifier, sending, by the session management network element, an authentication request message to the authentication server function according to the authentication indication, the authentication request message including the NAI, and performing, by the authentication server function, secure authentication on the terminal according to the NAI.
[0078] Optionally, the user plane network element is configured to perform the method in the third aspect and any possible implementation manner thereof.
[0079] Optionally, the session management network element is configured to perform the method in the fourth aspect and any possible implementation manner thereof.
[0080] Optionally, the system further includes a terminal, which can be configured to perform the method in the fifth aspect and any possible implementation manner thereof.
[0081] In an eighth aspect, a communication apparatus is provided, which is configured to perform the method in any one of the first aspect to the fifth aspect and any possible implementation manner thereof. Specifically, the apparatus can include units and / or modules for performing the method in any one of the first aspect to the fifth aspect and any possible implementation manner thereof, such as a processing unit and / or a communication unit.
[0082] In an implementation form, the apparatus is a communication device (e.g., a terminal, e.g., a user plane network element, e.g., a session management network element). When the apparatus is a communication device, the communication unit can be a transceiver, or an input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.
[0083] In another implementation form, the apparatus is a chip, chip system or circuit or communication module for a communication device (e.g., a terminal, e.g., a user plane network element, e.g., a session management network element). When the apparatus is a chip, chip system or circuit for a communication device, the communication unit can be an input / output interface, interface circuit, output circuit, input circuit, pin or related circuitry, etc. on the chip, chip system or circuit; the processing unit can be at least one processor, processing circuit or logic circuit, etc.
[0084] In a ninth aspect, a communication apparatus is provided, comprising at least one processor configured to cause the communication apparatus to perform the method in any one of the first aspect to the fourth aspect, or any possible implementation of the aspects.
[0085] In some implementation forms, the at least one processor is coupled with at least one memory storing the computer program or instructions. Optionally, the communication apparatus further comprises the at least one memory. Optionally, the at least one processor and the at least one memory are integrated together.
[0086] In a tenth aspect, a chip or chip system is provided, comprising a processor and a communication interface configured to receive information and / or data to be processed and send the information and / or data to be processed to the processor, the processor configured to process the information and / or data to be processed, so that a communication apparatus in which the chip is installed performs the method in any one of the first aspect to the fourth aspect, or any possible implementation of the aspects.
[0087] In an eleventh aspect, a communication system is provided, comprising a user plane network element configured to perform the method in the first aspect and any possible implementation of the aspect.
[0088] Optionally, the communication system can further comprise a terminal configured to perform the method in the second aspect and any possible implementation of the aspect.
[0089] Optionally, the communication system can further comprise a session management network element and / or a mobility management network element.
[0090] In a twelfth aspect, a communication system is provided, comprising a user plane network element configured to perform the method according to the third aspect and any possible implementation thereof, and a session management network element configured to perform the method according to the fourth aspect and any possible implementation thereof.
[0091] Optionally, the communication system can further comprise a terminal configured to perform the method according to any of the fifth aspect and any possible implementation thereof.
[0092] Optionally, the communication system can further comprise a mobility management network element and / or an authentication server function configured to derive the NAI from the.
[0093] In a thirteenth aspect, a computer-readable storage medium is provided, having stored thereon computer instructions that, when executed on a computer, cause the method according to any of the first aspect to the fifth aspect, or any possible implementation of these aspects, to be performed.
[0094] In a fourteenth aspect, a computer program product is provided, comprising computer program code that, when executed on a computer, causes the method according to any of the first aspect to the fifth aspect, or any possible implementation of these aspects, to be performed.
[0095] The technical effects of the technical solutions of the sixth aspect to the fourteenth aspect can refer to the descriptions of the corresponding technical effects of the first aspect to the fifth aspect, and will not be described again. BRIEF DESCRIPTION OF DRAWINGS
[0096] FIG. 1 is a schematic diagram of an ATSSS architecture network architecture.
[0097] FIGS. 2 to 4 are schematic diagrams of network architectures suitable for embodiments of the present application.
[0098] FIG. 5 is a schematic diagram of a multi-access PDU (MA PDU) session for one 3GPP access and one NIN3A suitable for embodiments of the present application.
[0099] FIG. 6 is a schematic diagram of a communication method according to an embodiment of the present application.
[0100] FIG. 7 is a schematic diagram of a steering function suitable for embodiments of the present application.
[0101] FIG. 8 is a schematic diagram of a communication method according to an embodiment of the present application.
[0102] FIG. 9 is a schematic diagram of a communication method according to an embodiment of the present application.
[0103] FIG. 10 is a schematic diagram of a communication method according to an embodiment of the present application.
[0104] FIG. 11 is a schematic block diagram of a communication apparatus according to an embodiment of the present application.
[0105] FIG. 12 is a schematic block diagram of another communication apparatus according to an embodiment of the present application.
[0106] FIG. 13 is a schematic block diagram of a chip system according to an embodiment of the present application.
[0107] FIG. 14 is a schematic block diagram of another chip system according to an embodiment of the present application. DETAILED DESCRIPTION
[0108] The technical solutions in the present application will be described below with reference to the drawings.
[0109] Before introducing the solutions in the present application, the following points are explained.
[0110] (1) In the present application, "indication" can include direct indication, indirect indication, explicit indication, implicit indication, etc. When describing that certain indication information indicates A, it can be understood that the indication information carries A, carries an identifier of A, carries B having a correlation relationship with A, carries an identifier of B having a correlation relationship with A, etc. In other words, if the receiving side of certain indication information can determine A according to the indication information, it can be described that the indication information indicates A, and the specific determination manner is not limited. When it is understood that the indication information carries A, "indication" can be replaced by "includes", and at this time, similar to the expression "sending / receiving indication information, the indication information indicates A", it can be replaced by "sending / receiving A".
[0111] The information indicated by the indication information is referred to as to-be-indicated information. In the specific implementation process, there are many ways to indicate the to-be-indicated information, for example but not limited to, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or an index of the to-be-indicated information, etc. The to-be-indicated information can also be indirectly indicated by indicating other information, where the other information has a correlation relationship with the to-be-indicated information. The to-be-indicated information can also be indicated only by a part of the to-be-indicated information, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of a specific information can also be realized by means of the arrangement order of each information agreed in advance (for example, a protocol stipulates), thereby reducing the indication overhead to a certain extent. In addition, the to-be-indicated information can be sent as a whole, or can be sent separately in multiple sub-information, and the sending period and / or sending occasion of these sub-information can be the same or different.
[0112] (2) In this application, the expression " / " is used to indicate that the objects before and after are in an "or" relationship; for example, A / B can mean: A or B. The expression "and / or" is used to indicate that the objects before and after are in a relationship of either "and" or "or"; for example, A and / or B can mean the following: A exists alone, B exists alone, A and B exist simultaneously, where A and B can be single or multiple. "At least one of the following" or similar expressions are used to indicate any combination of the listed items; for example, at least one of A, B and / or C can mean the following: A exists alone, B exists alone, C exists alone, A and B exist simultaneously, B and C exist simultaneously, A and C exist simultaneously, A, B and C exist simultaneously, where A, B, and C can be single or multiple.
[0113] (3) In this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, which may include direct transmission via the air interface or indirect transmission by other units or modules via the air interface. "Receive information from YY" can be understood as the source of the information being YY, which may include direct reception from YY via the air interface or indirect reception from YY by other units or modules via the air interface. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface. In other words, sending and receiving can occur between devices, such as between network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.
[0114] (4) In this application, unless otherwise specified or logically conflicting, the terms and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0115] (5) In this application, "first," "second," or "#1," "#2" are merely for descriptive convenience and are used to distinguish objects, and are not intended to limit the scope of the embodiments of this application. They are not used to describe the order or sequence of features. It should be understood that such described objects can be interchanged where appropriate so as to describe solutions other than those in the embodiments of this application.
[0116] (6) In this application, "predefined" can mean a standard protocol predefined, or it can mean a pre-agreed or pre-negotiated agreement between devices. Here, "protocol" can refer to a standard protocol in the field of communications, such as fifth-generation (5G) protocols. thFor example, the communication system can be a 5th generation (5G) or new radio (NR) system, a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD) system, or the like. The communication system can also be a future communication system. The communication system can also be a device to device (D2D) communication system, a vehicle-to-everything (V2X) communication system, a machine to machine (M2M) communication system, a machine type communication (MTC) system, an internet of things (IoT) communication system, or the like. The communication system can also be a non-terrestrial network (NTN) system, such as an inter-satellite communication system or a satellite communication system.
[0117] (7) In this application, the words "exemplary", "for example", and the like are used to mean example, illustration, or description. Any embodiment or design solution described as "exemplary" in this application should not be interpreted as being more preferred or having more advantages than other embodiments or design solutions. Rather, the word "exemplary" is used to present concepts in a concrete manner. In this application, "of", "corresponding", and "corresponding" can be used interchangeably at times. It should be noted that when the distinction is not emphasized, the meanings expressed are consistent.
[0118] First, a communication system to which the present application is applicable will be introduced.
[0119] The technical solutions provided in this application can be applied to various communication systems, such as a 5th generation (5G) or new radio (NR) system, a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD) system, and the like. The technical solutions provided in this application can also be applied to future communication systems. The technical solutions provided in this application can also be applied to device to device (D2D) communication, vehicle-to-everything (V2X) communication, machine to machine (M2M) communication, machine type communication (MTC), and internet of things (IoT) communication systems. The technical solutions provided in this application can also be applied to non-terrestrial network (NTN) systems such as inter-satellite communication and satellite communication.
[0120] As an example, a satellite communication system includes a satellite base station and a terminal device. The satellite base station provides communication services for the terminal device. The satellite base station can also communicate with a base station. The satellite can act as a base station or a terminal device. The satellite can refer to a drone, a hot air balloon, a low earth orbit satellite, a medium earth orbit satellite, a high earth orbit satellite, or the like. The satellite can also refer to a non-ground base station or a non-ground device, and the like.
[0121] As an example, V2X communication can include vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, vehicle-to-pedestrian (V2P) communication, vehicle-to-network (V2N) communication.
[0122] In a communication system, a part operated by an operator can be referred to as a public land mobile network (PLMN), and can also be referred to as an operator network, etc. The PLMN is a network established and operated for the purpose of providing public land mobile communication services to the public, and is mainly a public network in which a mobile network operator (MNO) provides mobile broadband access services to users. The PLMN described in the embodiments of the present application can be specifically a network conforming to the requirements of the 3GPP standard, referred to as a 3GPP network. The 3GPP network generally includes but is not limited to a 5G network, a 4th-generation (4G) network, and other future communication systems.
[0123] A device in a communication system can send a signal to another device or receive a signal from another device. The signal can include information, signaling, or data, etc. The device can also be replaced by an entity, a network entity, a communication device, a communication module, a node, a communication node, etc. The embodiments of the present application are described by taking the device as an example.
[0124] Next, the network architecture suitable for the embodiments of the present application is introduced in conjunction with FIGS. 1 to 4.
[0125] First, two concepts are introduced.
[0126] 1. Protocol data unit (PDU) session: an association between a UE and a DN, used to provide a PDU connection service, or in other words, to provide a user plane connection from the UE to the DN. The network (such as a 5G network) provides a data exchange service for the UE and the DN, which can be referred to as a PDU connection service. The UE obtains the PDU connection service by initiating a PDU session establishment request to the network. The network side provides the PDU connection service by maintaining a PDU session for the UE.
[0127] A PDU session can be identified by a PDU session identifier (PDU session ID). Since a PDU session is UE level, each PDU session identifier can also correspond to a terminal device.
[0128] 2. Access technology: indicates the access technology used by the terminal device to access the communication device, or in other words, the access technology used by the terminal device to establish a communication connection with the communication device.
[0129] As an example, the access technology may, for example, include NR, evolved universal mobile telecommunication system (UMTS) terrestrial radio access network (E-UTRAN), Multefire, 3GPP access technology, non-3GPP access technology, 4G cellular access technology, 5G cellular access technology, trusted or untrusted WiFi access technology, fixed network or wired access technology, etc. In this regard, no limitation is made.
[0130] Among them, the access network using non-3GPP access technology (or also referred to as non-3GPP access network) can include but is not limited to: WiFi network, WLAN, MulteFire network, wired network (for example: wireless and wireline convergence (WWC) network), or home base station network.
[0131] Among them, the access network using 3GPP access technology (or also referred to as 3GPP access network) can include but is not limited to: LTE network, NR network, 5G network, or subsequent evolved mobile communication network.
[0132] The network architecture is introduced below.
[0133] Figure 1 is a schematic diagram of an access traffic steering, switching, splitting (ATSSS) architecture.
[0134] ATSSS: also known as access traffic steering, switching, splitting, is an optional feature of the 5G network, which can be supported by the UE and the 5GC network.
[0135] ATSSS feature enables multi-access PDU connectivity service that can use one 3GPP access network and one non-3GPP access network simultaneously, and two independent N3 / N9 tunnels between PDU session anchor (PSA) and RAN / AN to exchange PDUs between UE and data network. Multi-access PDU connectivity service can be realized by establishing a multi-access PDU session (MA PDU session), i.e. a PDU session with user plane resources on both access networks. This assumes that the single network slice selection assistance information (S-NSSAI) of the PDU session allows both 3GPP access and non-3GPP access.
[0136] When the UE is registered over 3GPP and non-3GPP access, or when the UE is registered over one access only, the UE can request a MA PDU session. A MA PDU session is a PDU session that provides PDU connectivity service, which can use one access (e.g. 3GPP access or non-3GPP access) at a time, or both 3GPP access and non-3GPP access simultaneously.
[0137] After the MA PDU session is established, when user plane resources are available on both access networks, the UE applies the network-provided policy (i.e. ATSSS rules) and considers local conditions (e.g. network interface availability, signal loss conditions, user preference, etc.) to decide how to allocate uplink traffic on both access networks. Similarly, the UPF anchor point of the MA PDU session applies the network-provided policy (i.e. N4 rules) and feedback information received from the UE over the user plane (e.g. access network unavailability or availability) to decide how to allocate downlink traffic on both N3 / N9 tunnels and both access networks. When only one access network has user plane resources, the UE applies the ATSSS rules and considers local conditions that trigger the establishment or activation of user plane resources on the other access.
[0138] The type of MA PDU session can be one of the following types: IPv4, IPv6, IPv4v6 and Ethernet, unstructured type is not supported.
[0139] As shown in FIG. 1, the UE supports one or more steering functionalities, as shown in FIG. 1: i.e. a multi-path transmission control protocol (MPTCP) functionality, a multi-path quick user datagram protocol internet connection protocol (MPQUIC) functionality, and an access traffic steering, switching, splitting low layer (ATSSS-low layer, ATSSS-LL) functionality. Each steering functionality in the UE, according to ATSSS rules provided by the network, allows steering, switching and splitting of traffic flows across 3GPP access and non-3GPP access. The UPF can support an MPTCP proxy functionality that communicates with the MPTCP functionality in the UE by using the MPTCP protocol. The UPF can support an MPQUIC proxy functionality that communicates with the MPQUIC functionality in the UE by using the QUIC protocol and its multi-path extension. The UPF can support an ATSSS-LL functionality that is similar to the ATSSS-LL functionality defined for the UE. No user plane protocol can be defined between the ATSSS-LL functionality in the UE and the ATSSS-LL functionality in the UPF. In addition, the UPF supports a performance measurement function (PMF) that can be used by the UE to measure performance on the user plane of 3GPP access and / or on the user plane of non-3GPP access.
[0140] For other network elements in FIG. 1, refer to the related description in FIG. 2.
[0141] FIG. 2 is a schematic diagram of a network architecture applicable to embodiments of the present application. As shown in FIG. 2, the network architecture takes the 5th generation system (5GS) as an example. As an example, the network architecture includes three parts, which are: a terminal device part, a data network (DN) part, and an operator network PLMN part. The operator network PLMN part can include but is not limited to a (radio) access network ((R)AN) and a core network (CN) part.
[0142] The network elements of each part are briefly introduced as follows.
[0143] 1、terminal device part, including user equipment (UE). UE can also be called terminal or terminal device, which can access the above-mentioned communication system and has corresponding communication function device or module. UE can include various devices with wireless communication function, which can be used to connect people, things, machines, etc. Terminal device can be widely used in various scenarios, such as: cellular communication, D2D, V2X, point to point, M2M, MTC, IoT, virtual reality (VR), augmented reality (AR), industrial control, automatic driving, remote medical treatment, smart power grid, smart furniture, smart office, smart wear, smart traffic, smart city unmanned aerial vehicle, robot, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery, etc. Terminal device can be a terminal in any of the above scenarios, such as MTC terminal, IoT terminal, etc. Terminal device can be 3GPP standard UE, terminal, fixed device, mobile station device or mobile device, subscriber unit, handheld device, vehicle-mounted device, wearable device, cellular phone, smart phone, session initiation protocol (SIP) phone, wireless data card, personal digital assistant (PDA), computer, tablet computer, notebook computer, wireless modem, handset, laptop computer, computer with wireless transceiver function, smart book, vehicle, satellite, global positioning system (GPS) device, target tracking device, aircraft (such as unmanned aerial vehicle, helicopter, multi-helicopter, four-helicopter or airplane, etc.), ship, remote control device smart home device, industrial device, transport vehicle with wireless communication function, communication module, road side unit (RSU) with terminal function, or device built in the above device (such as communication module, modem or chip in the above device, etc.), or other processing device connected to wireless modem.
[0144] It should be understood that in some scenarios, UE can also be used to act as a base station. For example, UE can act as a scheduling entity which provides sidelink signals between UEs in V2X, D2D or P2P scenarios, etc.
[0145] In the embodiments of the present application, the device for implementing the function of the terminal device, i.e., the terminal device, can be a terminal device or a device capable of supporting the terminal device to implement the function, such as a chip system or a chip or a circuit or a communication module (i.e., a communication module performing a communication function), which can be installed in the terminal device. In the embodiments of the present application, the chip system can be composed of a chip or can include a chip and other discrete devices. In addition, the device can also be configured with program instructions for performing corresponding communication functions.
[0146] 2. Data network part, which can include a DN, for providing a network for transmitting data. For example, a network of an operator service (such as an IP multimedia subsystem (IMS)), an Internet network, a network of a third party service, etc. The DN can also be referred to as a packet data network (PDN), which is usually a network outside the operator network, such as a third party network.
[0147] 3. (R)AN part, which can include one or more access network elements or access network devices. The access network can provide access functions for authorized users in a specific area, including radio access network (RAN) devices and AN devices. The RAN device is mainly a wireless network device of the 3GPP network, and the AN device can be an access network device defined by non-3GPP.
[0148] The access network can be an access network using different access technologies. There are two types of current wireless access technologies: 3GPP access technology (such as the wireless access technology used in 3G, 4G or 5G systems) and non-3GPP (non-3GPP) access technology.
[0149] Among them, the 3GPP access technology refers to the access technology conforming to the 3GPP standard specification, for example, the access network device in the 5G system is called the next generation NodeB (gNB) or RAN.
[0150] The non-3GPP access technology refers to an access technology that does not conform to the 3GPP standard specification, for example, an air interface technology represented by an access point (AP) in WiFi, worldwide interoperability for microwave access (WiMAX), a code division multiple access (CDMA) network, and the like. An access network device (AN device) can allow a terminal device and a 3GPP core network to be interconnected and communicated using a non-3GPP technology.
[0151] The access network device in the embodiments of the present application can be a device or a module with corresponding communication functions. The access network device can be a device for communicating with a terminal device, and the access network device can also be referred to as a network device or a wireless access network device, for example, the access network device can be a base station. The access network device in the embodiments of the present application can refer to a RAN node (or device) for accessing a terminal device to a wireless network. The base station can broadly cover various names in the following or be replaced by the following names, such as: Node B (NodeB), evolved Node B (eNB), gNB, relay station, access point, transmitting and receiving point (TRP), transmission point, primary station, secondary station, motor slide retainer (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node, or the like, or a combination thereof. The base station can also refer to a communication module, modem, or chip for being arranged in the foregoing device or apparatus. The base station can also be a mobile switching center and a device assuming a base station function in D2D, V2X, M2M communication, a network side device in a future network, a device assuming a base station function in a future communication system, etc. The base station can support networks of the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form of the network device.
[0152] A base station can be fixed, or mobile. For example, a helicopter or an unmanned aerial vehicle (UAV) can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, a helicopter or an unmanned aerial vehicle can be configured to act as a device that communicates with another base station.
[0153] In some deployments, the access network device mentioned in the embodiments of the present application can be a device including a CU, or a DU, or including a CU and a DU, or a control plane CU node (central unit-control plane (CU-CP)) and a user plane CU node (central unit-user plane (CU-UP)), and a DU node.
[0154] In some deployments, a plurality of RAN nodes cooperate to assist a terminal device to implement wireless access, and different RAN nodes respectively implement part of the functions of a base station. For example, the RAN node can be a CU, a DU, a CU-CP, a CU-UP, or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can also be included in the same network element, such as a BBU. The RU can be included in a radio frequency device or a radio frequency unit, such as an RRU, an AAU, or an RRH.
[0155] In different systems, the CU (or CU-CP and CU-UP), DU, or RU can also have different names, but those skilled in the art can understand their meanings. For example, the wireless access network can also be an open radio access network (O-RAN) architecture, in which the CU can also be referred to as an open CU (O-CU), the DU can also be referred to as an open DU (O-DU), the CU-CP can also be referred to as an open CU-CP (O-CU-CP), the CU-UP can also be referred to as an open CU-UP (O-CU-UP), and the RU can also be referred to as an open RU (O-RU). Any of the CU (or CU-CP, CU-UP), DU, and RU in the present application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0156] In the embodiments of the present application, the device for implementing the function of the access network device can be the access network device, or can be a device capable of supporting the access network device to implement the function, such as a chip system or a chip or a circuit or a communication module (i.e., a communication module performing a communication function), which can be installed in the access network device. In the embodiments of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices. In addition, program instructions for performing corresponding communication functions can also be configured in the device. In the embodiments of the present application, only the device for implementing the function of the access network device is taken as an example to illustrate the access network device, and the scheme of the embodiments of the present application is not limited.
[0157] The access network device and the terminal device can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; can also be deployed on the water surface; and can also be deployed on airplanes, balloons and satellites in the air. The scenarios in which the access network device and the terminal device are located are not limited in the embodiments of the present application.
[0158] 4. The CN part can include but is not limited to the following network functions (NFs): network slice selection function (NSSF), network slice specific authentication and authorization function (NSSAAF), authentication server function (AUSF), unified data management (UDM), network exposure function (NEF), NF repository function (NRF), policy control function (PCF), application function (AF), access and mobility management function (AMF), session management function (SMF), user plane function (UPF), and signaling control point (SCP). The network elements are briefly introduced as follows.
[0159] 1) UPF network element: used for packet routing and forwarding, quality of service (QoS) processing of user plane data, etc. User data can access the DN through this network element. In the embodiments of the present application, the functions of the user plane network element can be implemented.
[0160] 2) AMF network element: mainly used for mobility management and access management, etc., and can be used to implement functions other than session management in the mobility management entity (MME) function, such as access authorization / authentication functions, etc.
[0161] 3) SMF network element: mainly used for session management, IP address allocation and management of terminal devices, selection and management of user plane functions, termination of policy control and charging function interfaces, and downlink data notification, etc.
[0162] 4) PCF network element: used for a unified policy framework for guiding network behavior, providing policy rule information for network elements (such as AMF, SMF network elements, etc.) or terminal devices, etc.
[0163] 5) NRF network element: used to save the description information of network function entities and their provided services, and support service discovery, network element entity discovery, etc.
[0164] 6) NEF network element: used to enable third parties to use network-provided services, support network exposure of its capabilities, event and data analysis, transfer of information from external applications to PLMN security equipment, conversion of internal and external interaction information, etc.
[0165] 7) UDM network element: used for unified data management, 5G user data management, processing of user identification, access authentication, registration, or mobility management, etc.
[0166] 8) UDR network element: used to provide UDM with functions of saving and obtaining subscription data, provide PCF with functions of saving and obtaining policy data, save and obtain user NF group ID (group ID) information, etc.
[0167] 9) AF network element: used to provide corresponding services by interacting with other NFs in the PLMN, such as providing roaming UE visit network selection information, guiding data flow routing, accessing NEF, etc.
[0168] 10) AUSF network element: used for primary authentication, i.e., authentication between UE (subscribed user) and operator network.
[0169] Nnssf, Nnef, Nnrf, Npcf, Nudm, Nudr, Naf, Nausf, Namf, Nsmf, Neasdf, Nnssaaf, Nnsacf, N1, N2, N3, N4, and N6 in FIG. 2 are interface sequence numbers. For example, the meanings of the above interface sequence numbers can refer to the meanings defined in the 3GPP standard protocol, and the meanings of the above interface sequence numbers are not limited in the present application. It should be noted that the interface names between the network functions in FIG. 2 are only an example, and the interface names of the system architecture in the specific implementation can also be other names, which are not limited in the present application. In addition, the names of the messages (or signaling) transmitted between the above network elements are also only an example, and do not constitute any limitation on the functions of the messages themselves.
[0170] It should be noted that in the architecture shown in FIG. 2, the interface between (R)AN and CN can also be referred to as NG interface (not shown in the figure), and (R)AN and CN are connected through the NG interface. The NG interface can include NG-C interface and NG-U interface, wherein the NG-C interface is a control plane interface, and the connection parties are (R)AN and AMF, which are used to transmit control plane data; the NG-U interface is a user plane interface, and the connection parties are (R)AN and UPF, which are used to transmit user plane data.
[0171] The network elements such as AMF, SMF, UPF, NEF, AUSF, NRF, PCF, UDM, etc. shown in FIG. 2 can be understood as network elements in the core network for realizing different functions, which can be combined as needed into network slices. These core network network elements can be independent devices, or can be integrated into the same device to realize different functions, and the specific form of the above network elements is not limited in the present application. In addition, the above network elements or functions can be physical entities in a hardware device, or software instances running on a dedicated hardware, or virtualized functions instantiated on a shared platform (for example, a cloud platform). Simply speaking, an NF can be realized by hardware or software.
[0172] In addition, the above naming is only defined for the purpose of distinguishing different functions, and should not constitute any limitation on the present application. The present application does not exclude the possibility of using other names in 5G networks and future other networks. For example, in future networks, part or all of the above network elements can use the terms in 5G, or other names, etc.
[0173] FIG. 3 and FIG. 4 are schematic diagrams of network architecture applicable to embodiments of the present application. The architecture shown in FIG. 3 and FIG. 4 is a simplified ATSSS (ATSSS-lite). The architecture shown in FIG. 3 is applicable to a non-roaming scenario, and the architecture shown in FIG. 4 is applicable to a roaming scenario. The ATSSS-lite scenario is based on the ATSSS scenario, but does not use N3IWF or TNGF to establish a connection with the core network over non-3GPP access, but instead establishes a non-3GPP user plane directly with a user plane network element (such as a UPF) through a WiFi network or IP access. The ATSSS-lite can also be referred to by other names, for example, the ATSSS-lite can also be referred to as ATSSS-Ph4, or gateway-less ATSSS, or lightweight ATSSS, etc. Alternatively, in later evolution, the scenario in which the UE accesses the core network through non-3GPP access without a gateway (such as without a TNGF and N3IWF), or the scenario in which the UE accesses the core network through non-3GPP access without a gateway (or the ATSSS scenario) can be directly referred to as ATSSS. The specific name is not limited in the present application, and the name does not limit the scope of protection of the embodiments of the present application. The embodiments of the present application are described using ATSSS-lite for ease of description.
[0174] As shown in FIG. 3 or FIG. 4, the ATSSS-lite architecture is similar to the ATSSS architecture, the UE accesses the network through 3GPP access and non-3GPP access, and performs traffic switching, steering and offloading on both paths, and can still use a multi-access PDU session to carry traffic data on both paths, and still use ATSSS rules for traffic switching, steering and offloading. The difference from the ATSSS architecture is that the ATSSS-lite architecture proposes a gateway-less architecture, such as a TNGF (for trusted non-3GPP access) or N3IWF (for untrusted non-3GPP access), through which the UE accesses the core network through non-3GPP access. The UE is connected to the UPF through an internet interface (such as denoted as Nx). It can be understood that in the ATSSS-lite architecture, the session (i.e., the multi-access PDU session) name when the UE accesses the network through 3GPP access and non-3GPP access can be referred to as a MA PDU session, or an ATSSS-lite session, or other names, which are not limited.
[0175] In FIG. 4, for the sake of distinction, the PCF in the home public land mobile network (home PLMN, HPLMN) is denoted as home PCF (hPCF or H-PCF), the SMF in the HPLMN is denoted as home SMF (hSMF or H-SMF), the SMF in the visited public land mobile network (visited PLMN, VPLMN) is denoted as visited SMF (vSMF or V-SMF), the UPF in the HPLMN is denoted as home UPF (hUPF or H-UPF), and the UPF in the visited public land mobile network (visited PLMN, VPLMN) is denoted as visited UPF (vUPF or V-UPF). The introductions of the network elements in FIG. 3 and FIG. 4 can refer to the previous explanations, and will not be repeated here.
[0176] As an example, for the ATSSS-lite architecture, in order to establish a secure connection through a non-3GPP access, the UE can establish an IPSec security association with the UPF using an IKEv2 message; or the UE can not establish any IPSec connection with the 5G core network, and the UE can connect to the UPF through a new interface Nx over a public IP network, and the Nx interface uses the secure transmission layer TLS protocol for secure connection; or the MPQUIC control function is used between the UE and the UPF, without an underlying IPSec layer and without a gateway (such as N3IWF or TNGF), and in this case, a MA PDU session needs to be established and managed through a 3GPP access.
[0177] FIG. 5 is a schematic diagram of a MA PDU session applied to one 3GPP access and one non-integrated non-3GPP access (NIN3A) suitable for embodiments of the present application. The ATSSS-Lite architecture introduces the concept of non-integrated non-3GPP access (NIN3A), which means a non-3GPP access without using a border node (such as TNGF or N3IWF). Specifically, NIN3A can represent a type of non-3GPP access network, which means a non-3GPP access network that provides a direct IP connection between the UE and the UPF, without the need for intermediate network functions (such as N3IWF and TNGF). When the UE accesses in the NIN3A manner, the data flow of the UE can be routed to the operator service through the access.
[0178] As shown in FIG. 5, the UE is connected to the UPF through the interface Nx through the public IP network. The traffic processing is similar to that in the ATSSS architecture, except that the non-3GPP access branch of the MA PDU session is replaced by a secure connection over the NIN3A. It is assumed that the UPF serving as the ATSSS-Lite connection anchor supports the Nx interface. The UPF can process the traffic according to the traffic processing rules provided by the SMF.
[0179] In the conventional non-3GPP access scenario, the UE establishes a connection with the core network through non-3GPP access, and needs to pass through a border node. For trusted non-3GPP access, the connection with the core network can be established through the TNGF; for untrusted non-3GPP access, the connection with the core network can be established through the N3IWF. In other words, whether the non-3GPP access is trusted or untrusted, an internet protocol security (IPsec) channel needs to be established between the UE and the border node (such as the TNGF or the N3IWF), and then the hop-by-hop security mechanism from the UE to the border node and from the border node to the core network is used to establish a secure channel for the user plane or the control plane of the entire system. According to the ATSSS-lite architecture, the non-3GPP network access node needs to be connected with the user plane function network element, and in the ATSSS-lite scenario, the N3IWF and the TNGF on the non-3GPP access are no longer used. In this case, the UE can be provided with a public IP address of the UPF, so as to facilitate the user plane establishment of the UE through the non-3GPP access.
[0180] For the ATSSS-lite architecture, security authentication needs to be performed between the UE and the network side during the non-3GPP access. As an example, the UE and the UPF can perform security authentication through a pre-shared key (PSK), which is derived through the 3GPP security context in the PDU session establishment process on the 3GPP access, or is randomly generated by the UPF; or, based on the EAP-5G authentication process, the UE performs security authentication using a long-term key K of the UE; or, the UE sends a subscription concealed identifier (SUCI) to identify the identity of the network side, and triggers the network side to derive a key based on the SUPI context corresponding to the SUCI, for security authentication of the UE. However, in the above process, user information may be leaked, and there is a security risk.
[0181] In view of this, the present application proposes a communication method and a communication device to avoid leakage of user information and reduce potential security risks, so as to realize secure communication of the non-3GPP access network.
[0182] The communication method provided by the embodiments of the present application will be described in detail below with reference to the drawings. The embodiments provided by the present application can be applied to the communication system described above. It should be understood that the embodiments shown below do not particularly limit the specific structure of the execution subject of the method provided by the embodiments of the present application, as long as the execution subject can communicate according to the method provided by the embodiments of the present application by running the code or program recording the method provided by the embodiments of the present application. For example, the method provided by the embodiments of the present application can be executed by a terminal and a user plane network element, and further optionally, can also be executed by a session management network element and an authentication server function. In the case where it is not particularly stated, the execution subject in the present application, such as a terminal, can refer to a terminal, a component (such as a communication module, a processor, a circuit, a chip (such as a modem chip, also known as a baseband chip, or a SoC chip or a SIP chip containing a modem core), or a chip system, etc.) in the terminal, or can also be a logical module or software that can realize all or part of the functions of the terminal.
[0183] First, the related scheme of the user plane network element performing security authentication on the terminal will be described by taking Figs. 6 to 10 as examples. The scheme can be applied to the following scenario: ATSSS-lite scenario, that is, one terminal can use one 3GPP access network and one non-3GPP access network at the same time; no longer use a border node (such as a TNGF or a N3IWF) on the non-3GPP access. For example, the user plane network element sends the public IP address of the UPF or the IP address of the UE to the terminal, and after receiving the authentication request message from the terminal, the user plane network element retrieves the security credential corresponding to the information of the terminal, and performs security authentication on the terminal using the security credential.
[0184] Fig. 6 is a schematic diagram of a communication method 600 provided by an embodiment of the present application. As shown in Fig. 6, the terminal and the user plane network element are taken as the execution subject to interact, and the method includes the following steps, and the parts not described in detail can refer to the related description of the existing protocol.
[0185] S610, the terminal requests to establish a session for the terminal through the 3GPP access.
[0186] In the present application, the session is used for 3GPP access and non-3GPP access, for example, the MAPDU session described above, and the specific implementation manner can refer to the related description of the existing session establishment process for the terminal, which is not described here.
[0187] Optionally, in the process of establishing a session for the terminal through the 3GPP access, or before the terminal accesses the non-3GPP access network, the terminal can obtain the information of the terminal, so as to facilitate the terminal to subsequently request to access the non-3GPP access network based on the information of the terminal, that is, the method 600 further includes the following step S601.
[0188] S601, the terminal acquires terminal information of the terminal.
[0189] The terminal information, which can also be referred to as terminal corresponding terminal information, indicates information related to the terminal or for the terminal (or for the session). The terminal information, which can also be referred to as terminal corresponding terminal information, indicates information related to the terminal or for the terminal (or for the session).
[0190] Exemplarily, the terminal information includes at least one of the following: an IP address of the terminal associated with the non-3GPP access, an IP address of the terminal associated with the 3GPP access, a public network IP address of a user plane network element, information obtained by performing security processing based on an identifier of the terminal and an identifier of the session, an IP address of the terminal associated with the session of the terminal, or a globally unique temporary UE identifier (GUTI) of the terminal, and the specific meanings are shown as follows.
[0191] (1) the IP address of the terminal associated with the non-3GPP access;
[0192] The IP address of the terminal associated with the non-3GPP access refers to an IP address related to the terminal through the non-3GPP access, which can also be referred to as the IP address of the terminal on the non-3GPP access. For example, when the terminal sends data, the source address of the data can be the IP address of the terminal on the non-3GPP access. The IP address of the terminal on the non-3GPP access can be the entire information of the IP address of the terminal on the non-3GPP access, or can also be the IP address prefix of the terminal on the non-3GPP access, which is not limited. It can be understood that the IP address of the terminal on the non-3GPP access can be replaced by the IP address prefix of the terminal on the non-3GPP access. For ease of description, the IP address of the terminal on the non-3GPP access is described in this application.
[0193] (2) the IP address of the terminal associated with the 3GPP access;
[0194] The IP address of the terminal associated with the 3GPP access refers to an IP address related to the terminal through the 3GPP access, which can also be referred to as the IP address of the terminal on the 3GPP access. For example, when the terminal sends data, the source address of the data can be the IP address of the terminal on the 3GPP access. The IP address of the terminal on the 3GPP access can be the entire information of the IP address of the terminal on the 3GPP access, or can also be the IP address prefix of the terminal on the 3GPP access, which is not limited. It can be understood that the IP address of the terminal on the 3GPP access can be replaced by the IP address prefix of the terminal on the 3GPP access. For ease of description, the IP address of the terminal on the 3GPP access is described in this application.
[0195] (3) an IP address of the terminal associated with the session of the terminal;
[0196] The IP address of the terminal associated with the session of the terminal refers to an IP address allocated by the network side for the session of the terminal, which can also be referred to as an IP address corresponding to the session of the terminal. For example, when the terminal sends data, if the data belongs to a session, the source address of the data can be the IP address associated with the session. The IP address of the terminal associated with the session of the terminal can be all information of the IP address of the terminal associated with the session of the terminal, or can also be an IP address prefix of the terminal associated with the session of the terminal, which is not limited. It can be understood that the IP address of the terminal associated with the session of the terminal can be replaced by the IP address prefix of the terminal associated with the session of the terminal. For ease of description, the present application is described by the IP address of the terminal associated with the session of the terminal.
[0197] (4) a public network IP address of a user plane network element, for example, a public network IP address of a UPF;
[0198] The public network IP address of the UPF refers to an IP address related to the UPF, or in other words, a UPF IP address used to establish an IPSec channel with the terminal, or in other words, a UPF IP address used to establish a TLS channel or (MP)QUIC connection with the terminal. For example, the UPF can provide the terminal with the public network IP address of the UPF, and subsequently, when the terminal sends information (such as a data packet) to the UPF through a non-3GPP access, the terminal can send the information to the UPF based on the public network IP address of the UPF. The public network IP address of the user plane network element can be all information of the public network IP address of the user plane network element, or can also be a public network IP address prefix of the user plane network element, which is not limited. It can be understood that the public network IP address of the user plane network element can be replaced by the public network IP address prefix of the user plane network element. For ease of description, the present application is described by the public network IP address of the user plane network element.
[0199] Optionally, the present application does not limit the network element that allocates the public network IP address of the UPF. For example, the UPF or the SMF or other core network elements can allocate the public network IP address of the UPF. For ease of description, the present application is exemplarily described by taking the UPF allocating the public network IP address of the UPF as an example.
[0200] As an example, the public network IP address of the UPF can include the following several cases.
[0201] The first possible case is that the public network IP address of the UPF is session granularity.
[0202] In this case, the UPF allocates a UPF IP address for each session of the terminal, in other words, each session corresponds to a UPF public network address. Based on this, the UPF IP address can uniquely identify a certain session corresponding to a terminal, and can associate the traffic of the session corresponding to the terminal on the non-3GPP access.
[0203] In this case, the public network IP address of the UPF in the information of the terminal can be the public network IP address of the UPF for each session.
[0204] The second possible case is that the public network IP address of the UPF is multiplexed.
[0205] In this case, the UPF allocates a UPF public network IP address for multiple sessions of the terminal, in other words, multiple sessions or multiple terminals share (i.e., multiplex) a UPF public network IP address. In this case, the session can be further identified by the IP address of the terminal. The IP address of the terminal includes: the IP address of the terminal on the non-3GPP access and / or the IP address of the terminal on the 3GPP access.
[0206] FIG. 7 is a schematic diagram of a steering function suitable for embodiments of the present application.
[0207] For example, for a terminal or a session of the terminal, the IP address of the terminal on the non-3GPP access and the IP address of the terminal on the 3GPP access can be allocated, and then a unique session can be identified by the IP address of the terminal on the non-3GPP access.
[0208] For example, as shown in FIG. 7, the steering function is MPTCP, for a terminal or a session of the terminal, the IP address IP@1 of the terminal on the non-3GPP access and the IP address IP@2 of the terminal on the 3GPP access can be allocated, and then a unique session can be identified by the IP address IP@1 of the terminal on the non-3GPP access or the IP address IP@2 of the terminal on the 3GPP access.
[0209] For example, as shown in FIG. 7, the steering function is MPQUIC, for a terminal or a session of the terminal, the IP address IP@4 of the terminal on the non-3GPP access and the IP address IP@5 of the terminal on the 3GPP access can be allocated, and then a unique session can be identified by the IP address IP@4 of the terminal on the non-3GPP access or the IP address IP@5 of the terminal on the 3GPP access.
[0210] For example, for a terminal or a session of the terminal, an IP address can be allocated, and the terminal uses the IP address on the non-3GPP access and the 3GPP access, and then a unique session can be identified by the IP address.
[0211] For example, as shown in FIG. 7, the steering function is ATSSS-LL, and an IP address IP@3 can be allocated to the terminal or the session of the terminal, in other words, the terminal uses IP@3 on the non-3GPP access and on the 3GPP access, and at this time, the unique session can be identified by IP@3.
[0212] In the embodiments of the present application, the network element for allocating the IP address of the terminal on the non-3GPP access and the IP address of the terminal on the 3GPP access is not limited. For example, the UPF allocates the IP address of the terminal on the non-3GPP access and the IP address of the terminal on the 3GPP access to the terminal. For another example, the network element other than the UPF allocates the IP address of the terminal on the non-3GPP access and the IP address of the terminal on the 3GPP access to the terminal. In addition, the network element for allocating the IP address of the terminal on the non-3GPP access and the network element for allocating the IP address of the terminal on the 3GPP access can be the same or different, and the present application is not limited in this regard.
[0213] (5) information obtained based on the security processing of the identifier of the terminal and the identifier of the session;
[0214] The identifier of the session can be used to identify the session. For example, the identifier of the session is the identifier (identify, ID) of the PDU session of the terminal (PDU session ID).
[0215] The identifier of the terminal can be used to identify the terminal. For example, the identifier of the terminal includes any of the following: generic public subscription identifier (GPSI), GUTI, NAI, subscription permanent identifier (SUPI), or SUCI.
[0216] The information obtained by performing security processing on the terminal identifier and the session identifier can be understood as: the information is obtained by performing security processing on the terminal identifier and the session identifier, or the information is obtained by performing security processing on the session identifier and the terminal identifier, or the information is obtained by performing security processing on the terminal identifier and the session identifier at the same time. As an example, the information obtained by performing security processing on the terminal identifier and the session identifier can be a KID, or a connection ID, or a certificate subject name, for example, a KID or a connection ID is obtained by performing XOR processing on the GPSI of the UE and the PDU session ID, wherein the KID corresponds to a key, and the connection ID corresponds to a token, both of which can be used for security authentication of the terminal, and the present application does not exclude other security processing manners.
[0217] (6) GUTI of the terminal;
[0218] The GUTI of the terminal can be used to identify the terminal. In the embodiments of the present application, the GUTI is a session-granularity terminal identifier, that is, one GUTI of the terminal corresponds to each session. It can be understood that, in order to ensure the uniqueness of the terminal identity and protect user privacy, the network side can update the GUTI of the terminal in real time for different sessions of the terminal, so that the terminal can use different GUTIs for 3GPP access and / or non-3GPP access.
[0219] The terminal obtains the information of the terminal, including but not limited to the following implementation manners.
[0220] In an implementation manner, the terminal obtains the information of the terminal, including: the user plane network element sends the information of the terminal to the terminal, and correspondingly, the terminal receives the information of the terminal from the user plane network element, at this time, the information of the terminal includes at least one of: the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, the IP address associated with the session of the terminal, or the public IP address of the user plane network element.
[0221] In another implementation manner, the terminal obtains the information of the terminal, including: the terminal itself determines the information of the terminal, at this time, the information of the terminal includes at least one of: information obtained by performing security processing on the terminal identifier and the session identifier, or the GUTI of the terminal.
[0222] The user plane network element sends the information of the terminal to the terminal, including but not limited to the following implementation manners.
[0223] As an implementation form, the user plane network element sends the information of the terminal to the terminal according to the indication information. In other words, the indication information can be used to directly or indirectly indicate (or trigger) the user plane network element to send the information of the terminal to the terminal.
[0224] It can be understood that the specific content indicated by the indication information is not limited in the embodiments of the present application. For example, the indication information indicates an ATSSS-lite scenario; or the indication information indicates that the terminal supports ATSSS-lite; or the indication information indicates that the session of the terminal is a session in the ATSSS-lite scenario, for example, the MAPDU session described above; or the indication information indicates that the terminal does not use a border node (such as a TNGF or a N3IWF) to establish a connection with a core network (such as a UPF) on a non-3GPP access; or the indication information indicates that the terminal accesses the network in a NIN3A manner. The indication information can also be referred to as an ATSSS-lite indicator, and is described below as an ATSSS-lite indicator for convenience.
[0225] For example, the indication information directly or indirectly indicates that the session of the terminal is a session in the ATSSS-lite scenario.
[0226] In an example, the indication information is implemented by at least one bit. For example, it is assumed that 1 bit is used to indicate whether the session of the terminal is a session in the ATSSS-lite scenario. If the bit is set to "0", it indicates that the session of the terminal is a session in the ATSSS-lite scenario; if the bit is set to "1", it indicates that the session of the terminal is not a session in the ATSSS-lite scenario.
[0227] In another example, the indication information is implemented by a specific field. For example, if the user plane network element receives the specific field, it indicates that the session of the terminal is a session in the ATSSS-lite scenario; if the user plane network element does not receive the field, it indicates that the session of the terminal is not a session in the ATSSS-lite scenario.
[0228] In another example, the indication information is indirectly implemented by other information. For example, when the session management network element sends a key to the user plane network element, or when the session management network element sends an identifier of the terminal and / or an identifier of the session to the user plane network element, it indicates that the session of the terminal is a session in the ATSSS-lite scenario.
[0229] It can be understood that the above examples are only exemplary descriptions of the forms of the indication information for the convenience of understanding, and other schemes are not excluded.
[0230] Optionally, before the user plane network element sends the information of the terminal to the terminal, the method 600 further includes: the user plane network element receiving indication information. For example, the terminal sends the indication information to the user plane network element; for another example, the session management network element sends the indication information to the user plane network element; for yet another example, the terminal sends information #1 to the session management network element, and the session management network element sends the indication information to the user plane network element based on the information #1, where the information #1 can indicate that the terminal supports ATSSS-lite; for yet another example, the user plane network element receives the indication information from the terminal, for example, in a process of establishing a session for a terminal through a 3GPP access, the terminal sends a PDU session establishment request carrying an ATSSS-lite indication to a mobile management network element through an access network device, the mobile management network element sends a session management SM context creation request carrying the ATSSS-lite indication to the session management network element, and the session management network element sends the ATSSS-lite indication to the user plane network element through an N4 session.
[0231] As another implementation manner, based on that the session uses an MPTCP function and / or an MPQUIC function, the user plane network element sends the information of the terminal to the terminal, for example, an IP address of the terminal associated with a non-3GPP access, an IP address of the terminal associated with the session, and an IP address of the terminal associated with a 3GPP access. In other words, the session using the MPTCP function and / or the MPQUIC function can be used to directly or indirectly indicate (or trigger) the user plane network element to send the IP address of the terminal to the terminal.
[0232] Optionally, the steering function used by the session, for example, the MPTCP function and / or the MPQUIC function, can be protocol predefined or preconfigured, or can be indicated or configured by the session management network element through signaling, which is not limited in the present application.
[0233] In the embodiments of the present application, the user plane network element sending the information of the terminal to the terminal can be that the user plane network element directly sends the information of the terminal to the terminal, or can be that the user plane network element indirectly sends the information of the terminal to the terminal, for example, the user plane network element sends the information of the terminal to the terminal through other network elements (such as a session management network element, a mobility management network element, a network access device, etc.), which is not limited.
[0234] S620, in a process of establishing a session for a terminal through a 3GPP access, the user plane network element stores a correspondence between the information of the terminal and a security credential.
[0235] The security credential is used for security authentication in a process of the terminal through a non-3GPP access network.
[0236] Optionally, there is no sequence between step S620 and step S601, for example, step S620 can be performed first, and then step S601 is performed; or, step S601 can be performed first, and then step S620 is performed; or, step S620 and step S601 can be performed at the same time, which is not limited.
[0237] In the present application, the security credential can be generated according to the security context of 3GPP access. For example, the mobility management network element infers the key K AMF deduced from the security context corresponding to the terminal based on the received ATSSS-lite indication, and then sends the security credential K UPF to the session management network element, and the session management network element forwards the security credential K UPF to the user plane network element; for another example, the mobility management network element infers the key K UPF for the session management corresponding to the terminal according to the ATSSS-lite indication, and then sends the key K SM to the session management network element, and the session management network element infers the security credential K SM for the session according to the key K SM , and sends the security credential K UPF to the user plane network element. UPF
[0238] In the present application, the security credential can also be randomly generated. For example, the user plane network element randomly selects a key K UPF from the key space according to the ATSSS-lite indication, and associates the key K UPF with the information of the terminal corresponding to the session of the terminal, or the user plane network element issues a random token token according to the ATSSS-lite indication, and associates the token with the information of the terminal corresponding to the session of the terminal.
[0239] Optionally, the security credential in the present application can be a key key; or, it can be a token token, or verification information related to the token; or, it can be a MAC, or verification information related to the MAC, etc. The verification information related to the token refers to information for verifying the token, which can include a public key for verifying the digital signature of the token, or a certificate, etc. The verification information related to the MAC refers to information for verifying the MAC generated by the terminal, which can include a key for verifying the MAC generated by the terminal. Considering that the verification information related to the MAC can be used to verify the MAC generated by the terminal, the verification information related to the MAC can also be referred to as information for verifying the MAC generated by the terminal.
[0240] Optionally, the subject performing the generation of the security credential is not limited in the present application, and can be a user plane network element, or can also be a session management network element, or can also be another network element (such as a mobility management network element) or a server (such as a network management function (such as operation administration and maintenance (OAM))), and the like, which is not limited.
[0241] For the user plane network element to store the correspondence between the terminal information and the security credential, the following implementation manners are included but not limited to.
[0242] As an implementation manner, the user plane network element can store the correspondence between the terminal information and the security credential according to the indication information. In other words, the indication information can be used to directly or indirectly indicate (or trigger) the user plane network element to store the correspondence between the terminal information and the security credential. The specific meaning and form of the indication information can refer to the related description of step S601 above, which will not be described here.
[0243] Optionally, before the user plane network element stores the correspondence between the terminal information and the security credential, the method 600 further includes that the user plane network element receives indication information, and the specific implementation manner can refer to the related description of step S601 above, which will not be described here.
[0244] Optionally, before step S620 is performed, the method 600 further includes that the user plane network element obtains the terminal information, including but not limited to the following implementation manners.
[0245] The first implementation manner is that the user plane network element allocates the terminal information for the terminal.
[0246] The second implementation manner is that the user plane network element receives the terminal information.
[0247] The third implementation manner is that the user plane network element allocates and receives the terminal information for the terminal. For example, the terminal information includes first part information and second part information, and the user plane network element can allocate the first part information for the terminal and receive the second part information.
[0248] Based on the above implementation manners, the obtaining of the terminal information is exemplarily described.
[0249] Example one, the terminal information includes at least one of the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the session, or the IP address of the terminal associated with the 3GPP access, that is, the user plane network element obtains at least one of the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, or the IP address of the terminal associated with the session.
[0250] For example, the IP address of the terminal on the non-3GPP access, and / or the IP address of the terminal associated with the 3GPP access, can be allocated by the user plane network element for the terminal; or can be allocated by the UDM, the SMF, the RADIUS, or the LNS server for the terminal, and forwarded to the user plane network element, and the specific allocation manner can refer to the description of the existing related scheme.
[0251] Example two, the information of the terminal includes the public network IP address of the user plane network element, that is, the user plane network element obtains the public network IP address of the user plane network element.
[0252] For example, the public network IP address of the user plane network element can be allocated by the user plane network element for the terminal, and the specific allocation manner can refer to the description of the existing related scheme.
[0253] Example three, the information of the terminal includes information (for example, information #2) obtained by performing security processing based on the identifier of the terminal and the identifier of the session, that is, the user plane network element obtains the information #2.
[0254] For example, the user plane network element receives the information #2 from the session management network element, and optionally, the information #2 can be generated by the session management network element.
[0255] For another example, the user plane network element receives the identifier of the terminal and the identifier of the session, for example, from the session management network element, and then determines the information #2 according to the identifier of the terminal and the identifier of the session.
[0256] For another example, the user plane network element allocates the identifier of the terminal and / or the identifier of the session for the terminal, and then determines the information #2 according to the identifier of the terminal and the identifier of the session.
[0257] For another example, the user plane network element allocates the identifier of the terminal and / or the identifier of the session for the terminal, and then sends the identifier of the terminal and / or the identifier of the session to the session management network element, generates the information #2 by the session management network element, and forwards to the user plane network element.
[0258] Example four, the information of the terminal includes the GUTI of the terminal, that is, the user plane network element obtains the GUTI of the terminal.
[0259] For example, the user plane network element receives the GUTI of the terminal from the session management network element. The GUTI can be generated by the mobile management network element, forwarded to the session management network element, and then sent to the user plane network element by the session management network element.
[0260] Optionally, before step S620 is performed, the method 600 further includes: the user plane network element obtains a security credential, including but not limited to the following implementation manners.
[0261] In a first implementation, the user plane network element receives the security credential, for example, the user plane network element receives the security credential from the session management network element.
[0262] In a second implementation, the user plane network element generates the security credential, for example, by 3GPP security context generation, or random generation.
[0263] S630, in the process of the terminal accessing the non-3GPP access network, the terminal sends an authentication request message to the user plane network element, and correspondingly, the user plane network element receives the authentication request message from the terminal, the authentication request message including the terminal information, the terminal information being used to determine the security credential for security authentication of the non-3GPP access of the terminal.
[0264] Exemplarily, the authentication request message can be an IKE_AUTH_Request message of the IKEv2 protocol, or a Client Hello message of the TLS protocol.
[0265] The terminal information, or the terminal information corresponding to the terminal, represents information related to the terminal or for the terminal (or the session).
[0266] Exemplarily, the terminal information includes at least one of the following: the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, the IP address of the terminal associated with the session, the public IP address of the user plane network element, information obtained based on security processing of the identifier of the terminal and the identifier of the session, or the GUTI of the terminal. For specific interpretation, reference can be made to the related description of the terminal information above, which will not be described here.
[0267] It can be understood that the terminal information is similar to the terminal information, except that the terminal information is the terminal information stored at the user plane network element, or the information used by the user plane network element to determine the security credential for security authentication of the terminal. The terminal information is the terminal information carried by the terminal when sending the authentication request message. Taking the public IP of the user plane network element as an example, the public IP of the user plane network element included in the terminal information is IP address #1, and the public IP of the user plane network element included in the terminal information is IP address #2. The IP address #1 and the IP address #2 can be the same or different. The specific judgment process will be described below, which will not be described here.
[0268] For the terminal sending the authentication request message to the user plane network element, the following modes are included but not limited to.
[0269] As an implementation, the terminal sends, to the user plane network element, an authentication request message carrying the information of the terminal based on the ATSSS-lite indication. Optionally, the ATSSS-lite indication can be predefined or preconfigured by a protocol, or determined by the terminal according to whether the terminal supports ATSSS-lite.
[0270] As another implementation, the terminal sends, to the user plane network element, an authentication request message carrying the information of the terminal based on at least one of the public network IP address of the user plane received in step S601, the IP address of the terminal associated with the non-3GPP access, or the IP address of the terminal associated with the session.
[0271] The following is an example description of the authentication request message including the information of the terminal.
[0272] As an example, the authentication request message includes a data packet and / or a first information element, wherein the destination address and / or the source address of the data packet is the information of the terminal, or the first information element includes the information of the terminal. That is, the information of the terminal can be carried in the data packet, or it can be outside the data packet, which is not limited.
[0273] The first information element can be an IDi information element in an IKE_AUTH_Requst message of an IKEv2 protocol, or the first information element can be a Pre_shared_key information element in a Client Hello message of a TLS protocol. By multiplexing the IDi information element in the current IKEv2 protocol IKE_AUTH_Requst message, or multiplexing the Pre_shared_key information element in the current TLS protocol Client Hello message, that is, using the message data structure in the current protocol to transfer the information of the terminal, the current message format can be changed without increasing the complexity.
[0274] The following is an example description of the authentication request message including the information of the terminal.
[0275] Example one, the destination address of the data packet is the information of the terminal, which can mean that the destination address of the data packet is the public network IP address of the user plane network element. Specifically, the terminal can send a data packet to the user plane network element based on the public network IP address of the user plane network element received in step S601 when accessing through the non-3GPP access network; or if the terminal receives a public network IP address prefix of the user plane network element in step S601, the destination address of the data packet can be an IP address constructed based on the public network IP address prefix of the UPF.
[0276] In the example two, the information that the source address of the data packet is the terminal can refer to that the source address of the data packet is the IP address of the terminal associated with the 3GPP access. Specifically, the terminal can send the data packet to the user plane network element when passing through the non-3GPP access network based on the IP address of the terminal associated with the 3GPP access received in step S601; or if the terminal receives the IP address prefix of the terminal associated with the 3GPP access in step S601, the source address of the data packet can be the IP address constructed based on the IP address prefix of the terminal associated with the 3GPP access.
[0277] In the example three, the information that the source address of the data packet is the terminal can refer to that the source address of the data packet is the IP address of the terminal associated with the non-3GPP access. Specifically, the terminal can send the data packet to the user plane network element when passing through the non-3GPP access network based on the IP address of the terminal associated with the non-3GPP access received in step S601; or if the terminal receives the IP address prefix of the terminal associated with the non-3GPP access in step S601, the source address of the data packet can be the IP address constructed based on the IP address prefix of the terminal associated with the non-3GPP access.
[0278] In the example four, the information that the source address of the data packet is the terminal can refer to that the source address of the data packet is the IP address of the terminal associated with the session. Specifically, the terminal can send the data packet to the user plane network element when passing through the non-3GPP access network based on the IP address of the terminal associated with the session received in step S601; or if the terminal receives the IP address prefix of the terminal associated with the session in step S601, the source address of the data packet can be the IP address constructed based on the IP address prefix of the terminal associated with the session.
[0279] It can be understood that the above examples are only examples given for the convenience of understanding, and the above examples can be implemented independently or in combination. For example, the example one and the example two are combined, which means that the source address of the data packet carried in the authentication request message is the IP address of the terminal associated with the 3GPP access, and the destination address is the public IP address of the user plane network element; or the example one and the example three are combined, which means that the source address of the data packet carried in the authentication request message is the IP address of the terminal associated with the non-3GPP access, and the destination address is the public IP address of the user plane network element; or the example one and the example four are combined, which means that the source address of the data packet carried in the authentication request message is the IP address of the terminal associated with the session, and the destination address is the public IP address of the user plane network element, which is not limited.
[0280] In S640, the user plane network element determines the security credential according to the information of the terminal and the stored corresponding relationship.
[0281] It can be understood that the user plane network element determines the security credential according to the information of the terminal and the stored corresponding relationship, which means that the user plane network element retrieves the locally stored corresponding relationship based on the information of the terminal to obtain the security credential. Alternatively, if the corresponding security credential is not found after retrieving the locally stored corresponding relationship based on the information of the terminal, the user plane network element can reject the terminal through the non-3GPP access network.
[0282] Alternatively, if the data packet and the first information element are carried in the authentication request message in the above step S630, the user plane network element judges or verifies whether the destination address and / or the source address of the data packet are the same as the information of the terminal carried in the first information element before performing step S640.
[0283] That is, for the case that the data packet and the first information element are carried in the authentication request message, the user plane network element can first judge whether the data packet matches the first information element, and then perform step S640 in the matching case.
[0284] As an example, the user plane network element judges whether the source address and / or the destination address of the data packet match the information of the terminal carried in the first information element. For example, the user plane network element judges whether the destination address of the data packet matches the public network IP address of the user plane carried in the first information element; or the user plane network element judges whether the source address of the data packet, such as the IP address of the terminal associated with the non-3GPP access, matches the IP address of the terminal associated with the non-3GPP access carried in the first information element; or the user plane network element judges whether the source address of the data packet, such as the IP address of the terminal associated with the 3GPP access (i.e. IP#4), matches the IP address of the terminal associated with the 3GPP access carried in the first information element.
[0285] Further, in the case that the data packet matches the first information element, i.e. in the case that the source address and / or the destination address of the data packet match the information of the terminal carried in the first information element, the user plane network element determines the security credential according to the information of the terminal and the stored corresponding relationship, and then completes the security authentication of the terminal based on the security credential.
[0286] It can be understood that the above examples are only examples given for the convenience of understanding, and other schemes are not excluded, such as that the first information element also carries the identifier of the terminal and / or the identifier of the session, and the data packet also carries the identifier of the terminal and / or the identifier of the session, at which time the user plane network element can also judge whether the identifier of the terminal and / or the identifier of the session carried in the data packet and the first information element match, etc.
[0287] S650, the user plane network element performs security authentication on the terminal according to the security credential.
[0288] The specific implementation manner can refer to the related description of the existing security authentication process for the terminal, and will not be described here for the sake of brevity.
[0289] Optionally, in a case that the security authentication of the terminal by the user plane network element is passed, the user plane network element can feed back the authentication result to the terminal, so as to facilitate the terminal to subsequently perform the security authentication on the user plane network element, and realize the bidirectional authentication. That is, the method 600 can further include the following step S602.
[0290] Optionally, assuming that the terminal information includes the information obtained by performing the security processing based on the identifier of the terminal and the identifier of the session, after the security authentication of the non-3GPP access of the terminal is completed, the user plane network element can delete the information obtained by performing the security processing based on the identifier of the terminal and the identifier of the session, and the corresponding security credential. This is because the identifier of the terminal (for example, GPSI) or the identifier of the session (for example, PDU session ID) can be reused for different sessions, and the information obtained by performing the security processing based on the identifier of the terminal and the identifier of the session can also be reused, so that different sessions of the same terminal can be linked, and therefore there is a certain degree of privacy risk. Therefore, after the security authentication of the terminal is completed, the user plane network element can delete the information obtained by performing the security processing based on the identifier of the terminal and the identifier of the session, and the corresponding security credential.
[0291] Optionally, assuming that the terminal information includes the GUTI of the terminal, in order to ensure the uniqueness of the terminal identity and protect the user privacy, for different sessions of the terminal, the network side (for example, AMF) can update the GUTI of the terminal in real time, so that the terminal can use different GUTIs for 3GPP access and / or non-3GPP access, and the user plane network element updates the corresponding relationship in real time, that is, stores the corresponding relationship between the updated GUTI of the terminal and the security credential.
[0292] S602, in a case that the security authentication of the terminal by the user plane network element is passed, the user plane network element sends an authentication response message to the terminal, and correspondingly, the terminal receives the authentication response message from the user plane network element, and the authentication response message includes the terminal information.
[0293] Exemplarily, the authentication response message can be an IKE_AUTH_Response message of an IKEv2 protocol, or a Server Hello message of a TLS protocol. The IDr information element can be included in the IKE_AUTH_Response message, and the Pre_shared_key information element can be included in the Server Hello message, and the terminal information can be included in the IDr information element or the Pre_shared_key information element.
[0294] Further, the terminal determines the corresponding session, such as the MAPDU session, according to the IDr information element carried in the authentication response message or the terminal information carried in the Pre_shared_key information element, and further determines the corresponding key, so as to verify the MAC value sent by the user plane network element using the key, and complete the security authentication of the user plane network element. The MAC value can be carried in the authentication response message.
[0295] Optionally, if the security authentication of the terminal fails, the user plane network element can not feed back the authentication result to the terminal, or the user plane network element can feed back a reason value to the terminal, which is used to indicate the reason for failing the security authentication, such as the terminal information not matching or the security credential being invalid, without limitation.
[0296] Based on the above scheme, in the process of establishing a session for a terminal accessing through a 3GPP in an ATSSS-lite scenario, the user plane network element can determine and store the correspondence between the terminal information and the security credential. Further, in the process of the terminal accessing through a non-3GPP network, the terminal can send an authentication request message carrying the terminal information to the user plane network element, so that the user plane network element can determine the security credential based on the terminal information and the locally stored correspondence, and further complete the security authentication of the terminal. This implementation mode not only protects the identity information of the terminal to prevent privacy leakage in the ATSSS-lite scenario, but also enables the user plane network element to retrieve the corresponding security credential of the terminal for authentication, thereby guaranteeing the secure communication of the terminal through the non-3GPP network.
[0297] For ease of understanding, the specific process applicable to the embodiments of the present application is introduced below in different scenarios. In the examples below, the mobility management network element is AMF, the terminal is UE, the session management network element is SMF, and the user plane network element is UPF. It can be understood that the process described below is only an example description, and the embodiments of the present application are not limited thereto. The content not described in detail below can be referred to the description in method 600, which is not described here.
[0298] FIG. 8 is a flowchart of a communication method 800 provided by the embodiments of the present application. As shown in FIG. 8, the following steps are included, and the parts not described in detail can be referred to the above-mentioned existing protocol.
[0299] S801, the UE performs a 3GPP registration process with the network side.
[0300] In other words, the UE completes the registration of 3GPP access, and the specific implementation mode can refer to the existing 3GPP registration process, which is not described here.
[0301] S802, the UE sends a PDU session establishment request message to the AMF, and the AMF receives the PDU session establishment request message from the UE accordingly.
[0302] In an example, the UE sends a non-access stratum (NAS) message to the AMF, and the NAS message includes the PDU session establishment request message. For example, the UE can send the NAS message to the AMF through the RAN, and the NAS message carries the PDU session establishment request message.
[0303] Optionally, the UE also sends an ATSSS-lite indicator to the AMF, where the ATSSS-lite indicator can indicate that the UE supports ATSSS-lite. The ATSSS-lite indicator can be carried in the NAS message, or the ATSSS-lite indicator can be carried in the PDU session establishment request message, or the ATSSS-lite indicator can also be sent to the AMF through separate signaling, which is not limited.
[0304] S803, the AMF sends a PDU session context creation request message (Creat SMContext request) to the SMF, and the SMF receives the PDU session context creation request message from the AMF accordingly.
[0305] Optionally, before step S803 is performed, the method 800 further includes: the AMF selects the SMF, and the specific implementation can refer to the existing process of selecting the SMF by the AMF, which is not described here.
[0306] Optionally, the AMF also sends an ATSSS-lite indicator to the SMF. In one possible case, in step S802, the UE sends the ATSSS-lite indicator to the AMF, so in step S803, the AMF also sends the ATSSS-lite indicator to the SMF.
[0307] The ATSSS-lite indicator can be carried in the PDU session context creation request message, or the ATSSS-lite indicator can also be sent to the SMF through separate signaling, which is not limited.
[0308] S804, the SMF queries subscription data from the UDM, selects the PCF, and obtains policy information.
[0309] For example, the SMF can interact with the UDM to obtain session management related subscription data from the UDM, and the SMF can register UE current session related information to the UDM.
[0310] S805, the SMF sends an N4 session establishment request message to the UPF, and correspondingly, the UPF receives the N4 session establishment request message from the SMF, where the N4 session establishment request message is used to request to establish an N4 session.
[0311] Optionally, in the N4 session establishment process, the N4 session establishment request message can include at least one of the following: an ATSSS-lite indication, an identifier of the UE, and an identifier of the session (such as a PDU session ID). For example, the identifier of the UE can be at least one of the following: a GPSI, a GUTI, a SUCI, or an NAI.
[0312] Optionally, the N4 session establishment request message can be replaced by an N4 session modification request message, and correspondingly, the N4 session establishment response message in the following step S807 can be replaced by an N4 session modification response message, which is not limited.
[0313] S806, the UPF stores the correspondence between the information of the UE and the security credential.
[0314] Optionally, before step S806 is performed, the method 800 further includes: the UPF determines the information of the UE, and the UPF determines the security credential. For details, refer to the related description of the method 600 above, which will not be repeated here for brevity.
[0315] Optionally, the UPF determines the information of the UE, including: in the case that the UE supports ATSSS-lite, the UPF determines the information of the UE. For example, if the N4 session establishment request message in step S805 includes the ATSSS-lite indication, the UPF determines the information of the UE.
[0316] Optionally, the UPF determines the security credential, including: in the case that the UE supports ATSSS-lite, the UPF determines the security credential. For example, if the N4 session establishment request message in step S805 includes the ATSSS-lite indication, the UPF determines the security credential.
[0317] As an example, the UE information includes at least one of the following: an identity of the UE (e.g., GPSI, GUTI, SUCI, or NAI), an identity of the session (e.g., PDU session ID), an IP address of the UE associated with the non-3GPP access, an IP address of the UE associated with the 3GPP access, a public IP address of the UPF, or information (e.g., KID or connection ID or subject name) derived based on the identity of the terminal and the identity of the session. For a specific interpretation, reference can be made to the related description of step S601 in method 600, which will not be repeated here. Alternatively, the IP address of the UE or the public IP address of the UPF can be replaced by an IP address prefix of the UE or an IP address prefix of the UPF, respectively. For ease of illustration, the IP address of the UE or the public IP address of the UPF is taken as an example for illustration.
[0318] S807, the UPF sends an N4 session establishment response to the SMF, and correspondingly, the SMF receives the N4 session establishment response from the UPF.
[0319] The N4 session establishment response can include the public IP address of the UPF. Alternatively, the N4 session establishment response can also include at least one of the following: an identity of the UE, an identity of the session, an IP address of the UE associated with the non-3GPP access, an IP address of the UE associated with the 3GPP access, or information derived based on the identity of the terminal and the identity of the session.
[0320] Alternatively, the UE information can also be carried in other signaling, which is not limited. For example, the UE information can also be carried in an N4 session modification with PFCP or an Nupf_event exposure subscribe request, etc.
[0321] S808, the SMF sends a PDU session accept to the UE, and correspondingly, the UE receives the PDU session accept from the SMF.
[0322] The PDU session accept message can comprise the public IP address of the UPF. Optionally, the PDU session accept message can further comprise at least one of the following: an identity of the UE, an identity of the session, an IP address of the UE associated with the non-3GPP access, an IP address of the UE associated with the 3GPP access, or information derived from a security procedure based on the identity of the terminal and the identity of the session.
[0323] As an example, the SMF can send the PDU session accept message to the UE via the AMF and the RAN in sequence.
[0324] The above steps S801-S808 are described for a session establishment procedure for a UE via a 3GPP access, in which the UE is securely authenticated and the UPF obtains the information of the UE and the security credential associated with the UE. Further, the following steps S809-S815 are described for an authentication procedure for a UE via a non-3GPP access, in which steps S810-S812 are described for an IPsec connection and steps S813-S815 are described for a TLS connection, which are two parallel manners for the UE to be securely authenticated.
[0325] S809, the UE accesses the non-3GPP network.
[0326] Specifically, the UE establishes a connection with the non-3GPP access network, such as an L2 connection. In this way, the UE can send a message to the network via the non-3GPP access manner.
[0327] As an example, the non-3GPP access network can allocate an IP address or an IP address prefix of the UE associated with the non-3GPP access to the UE.
[0328] S810, in the process of accessing the non-3GPP network, the UE sends an authentication request message to the UPF, and the UPF receives the authentication request message from the UE, which comprises the information of the UE.
[0329] As an example, the information of the terminal can comprise at least one of the following: an identity of the UE (such as GPSI, GUTI, SUCI, or NAI), an identity of the session (such as PDU session ID), an IP address of the UE associated with the non-3GPP access, an IP address of the UE associated with the 3GPP access, a public IP address of the UPF, or information derived from a security procedure based on the identity of the terminal and the identity of the session (such as KID or connection ID). For specific interpretation, reference can be made to the description of the information of the UE above, which is not described here.
[0330] The source address of the authentication request message can be an IP address of the UE associated with the non-3GPP access or an IP address of the UE associated with the 3GPP access. The destination address of the authentication request message can be a public IP address of the UPF or an IP address constructed based on a public IP address prefix of the UPF.
[0331] Optionally, the authentication request message can further include a data packet and / or a first information element. The source address and / or the destination address of the data packet are information of the UE. For example, the source address of the data packet can be an IP address of the UE associated with the non-3GPP access or an IP address of the UE associated with the 3GPP access. The destination address of the data packet can be a public IP address of the UPF or an IP address constructed based on a public IP address prefix of the UPF. The first information element includes information of the UE.
[0332] As an example, the authentication request message can be an IPSec request message or an IKE_AUTH_request message. For example, the IKE_AUTH_request message can carry IDi (i.e., the first information element), and the IDi information element carries information of the UE.
[0333] Optionally, before step S810 is performed, the method 800 further includes: the UE constructs information of the UE. For example, the UE can construct the information of the UE according to the information of the UE carried in step S808, such as performing XOR processing on the obtained GPSI of the UE and the PDU session ID to obtain KID, and the like.
[0334] S811, the UPF determines a security credential according to the information of the UE and the corresponding relationship, and performs security authentication on the UE according to the security credential.
[0335] As an example, the UPF retrieves the security credential from the locally stored corresponding relationship according to the information of the terminal. For details, reference can be made to the related description of step S640 of the above method 600. For brevity, no longer be described here.
[0336] Optionally, if the authentication request message in step S810 carries both the data packet and the first information element, before step S811 is performed, the method further includes: the UPF judges whether the destination address and / or the source address of the data packet match the information of the UE carried in the first information element (for example, at least one of the public IP address of the UPF, the IP address of the UE associated with the non-3GPP access, or the IP address of the UE associated with the 3GPP access). For details, reference can be made to the related description of step S640 of the above method 600. For brevity, no longer be described here.
[0337] S812, the UPF sends an authentication response message to the UE, and correspondingly, the UE receives the authentication response message from the UPF.
[0338] The authentication response message can be any of an IPSec response message or an IKE_AUTH_response message. For example, the IKE_AUTH_response message can carry an IDr information element, and the IDr information element carries information of the UE.
[0339] Further, the UE determines a corresponding session, such as a MAPDU session, according to information of the terminal carried in the IDr information element in the authentication response message, and further determines a corresponding key, so as to verify a MAC value sent by the user plane network element using the key, and complete the security authentication of the user plane network element. The MAC value can be carried in the authentication response message.
[0340] Optionally, if the security authentication of the UE fails, the UPF can not feed back an authentication result to the terminal, or the UPF can feed back a reason value to the UE, which is used to indicate a reason for the failure of the security authentication, such as that the information of the UE does not match, or that the security credential is invalid, without limitation.
[0341] S813, in the process of accessing through the non-3GPP access network, the UE sends an authentication request message to the UPF, and correspondingly, the UPF receives the authentication request message from the UE, and the authentication request message includes information of the UE.
[0342] As an example, the fields contained in the information of the UE and the interpretation thereof can refer to the related description of step S810 above, which will not be described here.
[0343] The source address of the authentication request message can be an IP address of the UE associated with the non-3GPP access, or an IP address of the UE associated with the 3GPP access. The destination address of the authentication request message can be a public IP address of the UPF or an IP address constructed based on a public IP address prefix of the UPF.
[0344] Optionally, the authentication request message can further include a data packet and / or a first information element. The source address and / or the destination address of the data packet are information of the UE, for example, the source address of the data packet can be an IP address of the UE associated with the non-3GPP access, or an IP address of the UE associated with the 3GPP access. The destination address of the data packet can be a public IP address of the UPF or an IP address constructed based on a public IP address prefix of the UPF. The first information element includes information of the UE.
[0345] As an example, the authentication request message can be a Client Hello message, a TLS request message, a QUIC request message, or an MPQUIC request message. For example, the pre_shared_key (i.e., the first information element) can be carried in the Client Hello message, and the UE information can be carried in the pre_shared_key information element.
[0346] Optionally, before performing step S810, the method 800 further includes: the UE constructing the UE information, for example, the UE can construct the UE information according to the UE information carried in step S808, such as taking the obtained UE IP address (e.g., the UE IP address associated with the non-3GPP access or the UE IP address associated with the 3GPP access) or the UPF IP address as the UE information.
[0347] S814, the UPF determines the security credential according to the UE information and the correspondence relationship, and performs security authentication on the UE according to the security credential.
[0348] The specific implementation can refer to the related description of step S811 of the above method 800, and will not be described here for brevity.
[0349] S815, the UPF sends an authentication response message to the UE, and correspondingly, the UPF receives the authentication response message from the UPF.
[0350] The authentication response message can be any of the following: a Server Hello message, a TLS response message, a QUIC response message, or an MPQUIC response message. For example, the pre_shared_key information element can be carried in the Server Hello message, and the UE information can be carried in the pre_shared_key information element.
[0351] Further, the UE determines the corresponding session (e.g., the MAPI PDU session) according to the UE information carried in the pre_shared_key information element in the authentication response message, and further determines the corresponding key, so as to use the key to verify the MAC value sent by the user plane network element, and complete the security authentication of the user plane network element. The MAC value can be carried in the authentication response message.
[0352] Optionally, if the security authentication of the UE fails, the UPF can not feed back the authentication result to the terminal, or the UPF can feed back a reason value to the UE, which is used to indicate the reason for the failure of the security authentication, such as the UE information mismatching, or the security credential being invalid, without limitation.
[0353] Based on the above technical solution, in the session establishment process through the 3GPP access, the UPF can determine and store the correspondence between the information of the UE and the security credential. Further, in the process through the non-3GPP access network, the UE can send an authentication request message carrying the information of the UE to the UPF, so that the UPF can determine the security credential based on the information of the UE and the correspondence, and then complete the security authentication of the UE. This implementation manner can not only prevent the leakage of the privacy of the UE, but also enable the UPF to retrieve the corresponding security credential of the UE for authentication, thereby guaranteeing the secure communication of the UE through the non-3GPP access network in the ATSSS-lite scenario.
[0354] The above mainly describes the related scheme of the security authentication of the user plane network element to the terminal in combination with FIGS. 6 to 8, which is mainly applicable to the IPsec or TLS authentication process. Alternatively, the execution subject of the security authentication of the terminal is not limited in the present application. The following describes the related scheme of the security authentication of the terminal through the session management network element and the authentication server function in combination with FIGS. 9 and 10, which is mainly applicable to the EAP-5G authentication process. The scheme can be applicable to the following scenario: the ATSSS-lite scenario, that is, one terminal can simultaneously use one 3GPP access network and one non-3GPP access network; no longer using a border node (such as a TNGF or a N3IWF) on the non-3GPP access. For example, the user plane network element sends the public IP address of the UPF or the IP address of the UE to the terminal, and after receiving the authentication request message from the terminal, the user plane network element requests the session management network element and the authentication server function to perform the security authentication of the terminal through the N4 session.
[0355] FIG. 9 is a schematic diagram of a communication method 900 provided by an embodiment of the present application. As shown in FIG. 9, the terminal, the user plane network element, the session management network element, and the authentication server function are taken as the execution subject to interact, and the method includes the following steps, and the parts not described in detail can be referred to the related description of the above method 600 and the existing protocol.
[0356] S910, the terminal requests to establish a session for the terminal through the 3GPP access.
[0357] In the present application, the session is used for the 3GPP access and the non-3GPP access, for example, the MAPDU session described above, and the specific implementation manner can be referred to the related description of the existing session establishment process for the terminal, which is not described here.
[0358] Alternatively, in the process of establishing the session for the terminal through the 3GPP access, or in the process before the terminal accesses the non-3GPP access network, the user plane network element can send the information of the terminal to the terminal, so as to facilitate the terminal to subsequently access the non-3GPP access network based on the information of the terminal, that is, the method 900 further includes the following step S901.
[0359] S901, the terminal acquires the information of the terminal.
[0360] Exemplarily, the information of the terminal comprises at least one of the following: the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, the IP address of the terminal associated with the session, the public network IP address of the user plane network element, the information obtained by performing security processing based on the identifier of the terminal and the identifier of the session, or the GUTI of the terminal. For specific interpretation, reference can be made to the related description of step S601 of method 600 described above. For the sake of brevity, no longer description is given here.
[0361] For the above-mentioned acquiring of the information of the terminal, the following implementation manners are included but not limited to.
[0362] In an implementation manner, the terminal acquires the information of the terminal, comprising: the user plane network element sends the information of the terminal to the terminal, and correspondingly, the terminal receives the information of the terminal from the user plane network element, at this time, the information of the terminal comprises at least one of the following: the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the session, the IP address of the terminal associated with the 3GPP access, or the public network IP address of the user plane network element.
[0363] In another implementation manner, the terminal acquires the information of the terminal, comprising: the terminal itself determines the information of the terminal, at this time, the information of the terminal comprises at least one of the following: the information obtained by performing security processing based on the identifier of the terminal and the identifier of the session, or the GUTI of the terminal.
[0364] For the above-mentioned sending of the information of the terminal by the user plane network element to the terminal, the following implementation manners are included but not limited to.
[0365] The first implementation manner is that the user plane network element sends the information of the terminal to the terminal according to indication information.
[0366] The indication information indicates the ATSSS-lite scenario; or the indication information indicates that the terminal supports the ATSSS-lite; or the indication information indicates that the session of the terminal is a session under the ATSSS-lite scenario, such as the MAPDU session described above; or the indication information indicates that the terminal does not use a border node (such as a TNGF or a N3IWF) to establish a connection with a core network (such as a UPF) on a non-3GPP access; or the indication information indicates that the terminal accesses the network in the NIN3A manner. The indication information can also be referred to as an ATSSS-lite indicator.
[0367] Optionally, before the user plane network element sends the information of the terminal to the terminal, the method 900 further includes: the user plane network element receiving indication information. For example, the terminal sends the indication information to the user plane network element; for another example, the session management network element sends the indication information to the user plane network element; for yet another example, the terminal sends information #1 to the session management network element, and the session management network element sends the indication information to the user plane network element based on the information #1, which can indicate that the terminal supports ATSSS-lite; for yet another example, the user plane network element receives the indication information from the terminal, for example, in a process of establishing a session for a terminal through a 3GPP access, the terminal sends a PDU session establishment request carrying an ATSSS-lite indication to a mobile management network element through an access network device, the mobile management network element sends a session management SM context creation request carrying the ATSSS-lite indication to the session management network element, and the session management network element sends an ATSSS-lite indication to the user plane network element through an N4 session.
[0368] In a second implementation, based on the session using MPTCP function and / or MPQUIC function, the user plane network element sends the information of the terminal to the terminal, for example, the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the session, and the IP address of the terminal associated with the 3GPP access.
[0369] Optionally, the steering function, for example, MPTCP function and / or MPQUIC function, used by the session can be protocol predefined or preconfigured, or can be indicated or configured by the session management network element through signaling, which is not limited in the present application.
[0370] In the present application, the user plane network element sending the information of the terminal to the terminal can be the user plane network element directly sending the information of the terminal to the terminal, or can be the user plane network element indirectly sending the information of the terminal to the terminal, for example, the user plane network element sending the information of the terminal to the terminal through other network elements, which is not limited.
[0371] S920, in a process of establishing a session for a terminal through a 3GPP access, the user plane network element stores a correspondence between the information of the terminal and an N4 session identifier.
[0372] The N4 session identifier is associated with the session, the N4 session identifier is used to identify an N4 session, and the N4 session is established between the user plane network element and the session management network element and is used to transmit information associated with the session of the terminal. Generally, one session of one terminal corresponds to one N4 session.
[0373] Optionally, there is no sequence between step S920 and step S901, for example, step S920 can be performed first, and then step S901 is performed; or, step S901 can be performed first, and then step S920 is performed; or, step S920 and step S901 can be performed at the same time, which is not limited.
[0374] The correspondence between the information of the terminal and the N4 session identifier stored by the user plane network element includes, but is not limited to, the following implementation manners.
[0375] As an implementation manner, the user plane network element can store the correspondence between the information of the terminal and the N4 session identifier according to the indication information. In other words, the indication information can be used to directly or indirectly indicate (or trigger) the user plane network element to store the correspondence between the information of the terminal and the N4 session identifier. The specific meaning and form of the indication information can refer to the related description of step S601 of method 600 described above, which will not be described here.
[0376] Optionally, before the user plane network element stores the correspondence between the information of the terminal and the N4 session identifier, the method 900 further includes that the user plane network element receives indication information, and the specific implementation manner can refer to the related description of step S901 described above.
[0377] Optionally, before step S920 is performed, the method 900 further includes that the user plane network element obtains the information of the terminal, and the specific implementation manner can refer to the related description of step S620 of method 600 described above, which will not be described here.
[0378] Optionally, before step S920 is performed, the method 900 further includes that the user plane network element obtains the N4 session identifier, including but not limited to the following implementation manners.
[0379] The first implementation manner is that the user plane network element receives the N4 session identifier, for example, the user plane network element receives the N4 session identifier from the session management network element.
[0380] For example, in the process of establishing a session for a terminal, the SMF sends an N4 session establishment request message to the UPF, and correspondingly, the UPF receives the N4 session establishment request message from the SMF, the N4 session establishment request message is used to request to establish an N4 session, and the N4 session establishment request message can include: ATSSS-lite indication, identifier of the UE, identifier of the session (such as PDU session ID) and N4 session identifier (such as N4 session ID).
[0381] The second implementation manner is that the user plane network element generates the N4 session identifier, for example, by generating a 3GPP security context, or randomly generating.
[0382] S930, during the process that the terminal accesses the non-3GPP access network, the terminal sends an authentication request message #1 to the user plane network element, and correspondingly, the user plane network element receives the authentication request message #1 from the terminal.
[0383] The source address of the authentication request message #1 can be an IP address of the UE associated with the non-3GPP access, or an IP address of the UE associated with the 3GPP access. The destination address of the authentication request message #1 can be a public IP address of the UPF or an IP address constructed based on a public IP address prefix of the UPF.
[0384] The terminal sending the authentication request message #1 to the user plane network element includes but is not limited to the following manners.
[0385] In an implementation manner, the terminal sends the authentication request message #1 to the user plane network element based on the ATSSS-lite indication. Optionally, the ATSSS-lite indication can be predefined or preconfigured by a protocol, or determined by the terminal according to its own support of ATSSS-lite.
[0386] In another implementation manner, the terminal sends the authentication request message #1 carrying the authentication request message #1 to the user plane network element based on at least one of the public IP address of the user plane received in step S901, the IP address of the terminal associated with the non-3GPP access, and the IP address of the terminal associated with the session.
[0387] Optionally, the authentication request message #1 can include the information of the terminal.
[0388] The information of the terminal, or the information of the terminal corresponding to the terminal, represents information related to the terminal or for the terminal (or the session).
[0389] Exemplarily, the information of the terminal includes at least one of the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the 3GPP access, the IP address of the terminal associated with the session, the public IP address of the user plane network element, information obtained by performing security processing based on the identifier of the terminal and the identifier of the session, or the GUTI of the terminal. For specific interpretation, reference can be made to the related description of the information of the terminal above, which will not be described here.
[0390] It can be understood that the terminal information is similar to the terminal information, and the difference is that the terminal information is the terminal information stored at the user plane network element, or the information used by the user plane network element to determine the N4 session identifier, and the terminal information is the terminal information carried by the terminal when sending the authentication request message #1. Taking the IP of the terminal associated with the non-3GPP access as an example, the IP of the terminal associated with the non-3GPP access included in the terminal information is IP address #1, and the IP of the terminal associated with the non-3GPP access included in the terminal information is IP address #2. The IP address #1 and the IP address #2 can be the same or different, and the specific judgment process will be introduced below. Here, it is not described.
[0391] The following illustrates the authentication request message #1 including the terminal information.
[0392] As an example, the authentication request message #1 includes a data packet and / or a first information element.
[0393] The first information element includes the terminal information. Optionally, the authentication request message can be an IKE_AUTH_Request message of the IKEv2 protocol, and the first information element can be an IDi information element in the IKE_AUTH_Request message #1 of the IKEv2 protocol.
[0394] The destination address and / or the source address of the data packet are the terminal information. For example, the destination address of the data packet is the terminal information, which can mean that the destination address of the data packet is the public IP address of the user plane network element. The source address of the data packet is the terminal information, which can mean that the source address of the data packet is the IP address of the terminal associated with the 3GPP access; or the source address of the data packet is the terminal information, which can mean that the source address of the data packet is the IP address of the terminal associated with the non-3GPP access; or the source address of the data packet is the terminal information, which can mean that the source address of the data packet is the IP address of the terminal associated with the session.
[0395] That is, the terminal information can be carried in the data packet, or it can be outside the data packet, which is not limited.
[0396] S940, the user plane network element determines the N4 session identifier according to the terminal information.
[0397] As an implementation manner, for the case that the terminal information is not carried in the authentication request message #1, the user plane network element can default that the terminal is legal, and then the user plane network element can determine the N4 session identifier according to the source address and / or the destination address of the authentication request message #1 and the stored corresponding relationship.
[0398] As another implementation manner, for the case that the terminal's information is carried in the authentication request message #1, the user plane network element retrieves the corresponding N4 session identifier based on the terminal's information according to the locally stored correspondence relationship. Optionally, if the user plane network element does not find the corresponding N4 session identifier after retrieving the locally stored correspondence relationship based on the terminal's information, the user plane network element can reject the terminal to access the non-3GPP access network.
[0399] Optionally, if the data packet and the first information element are carried in the authentication request message #1 in the above step S930, before the step S940 is performed, the user plane network element judges or verifies whether the destination address and / or the source address of the data packet are the same as the terminal's information carried in the first information element. For brevity, the specific implementation manner can refer to the related description of the step S640 of the method 600, which will not be described here.
[0400] S950, the user plane network element sends the authentication indication and the N4 identifier to the session management network element, and correspondingly, the session management network element receives the authentication indication and the N4 identifier from the user plane network element. The authentication indication is used to indicate that the terminal is authenticated.
[0401] For example, the user plane network element sends the N4 session to the session management network element, and the N4 session carries the authentication indication (such as EAP auth indicator) and the N4 identifier (such as N4 session ID). Optionally, the authentication indication and the N4 identifier can also be sent to the session management network element through separate signaling, which is not limited.
[0402] S960, the session management network element determines the NAI of the terminal according to the N4 session identifier.
[0403] In an implementation manner, the session management network element determines the identifier of the terminal according to the N4 session identifier, and constructs the NAI of the terminal according to the identifier of the terminal. For example, the session management network element determines the SUPI of the terminal corresponding to the session according to the N4 session identifier, and then constructs the NAI of the terminal using the SUPI of the terminal and the PLMN, wherein the PLMN represents the identifier of the home PLMN of the terminal (i.e. NAI = SUPI@PLMN); for another example, the session management network element determines the information obtained by performing security processing on the identifier of the terminal and the identifier of the session based on the N4 session identifier, such as KID, and then uses the KID as the NAI of the terminal (i.e. NAI = KID); for another example, the session management network element determines the GUTI of the terminal according to the N4 session identifier, and then uses the GUTI of the terminal as the NAI of the terminal (i.e. NAI = GUTI); for another example, the session management network element determines the GUTI of the terminal according to the N4 session identifier, and then constructs the NAI of the terminal using the GUTI of the terminal and the PLMN (i.e. NAI = GUTI@PLMN).
[0404] S970, the session management network element sends an authentication request message #2 to the authentication server function according to the authentication indication, and correspondingly, the authentication server function receives the authentication request message #2 from the session management network element. Wherein, the authentication request message #2 carries the NAI.
[0405] S980, the authentication server function performs security authentication on the terminal according to the NAI.
[0406] The specific implementation of the above steps S970 and S980 can refer to the related description of the security authentication process of the terminal in the existing EAP-5G. For example, the authentication server function finds the corresponding SUPI according to the NAI, requests the authentication material of the SUPI from the UDM side, and then performs the EAP-5G authentication process.
[0407] Optionally, after the authentication is completed, the authentication server function generates a key k (such as EAP success key) for the user plane network element and sends it to the user plane network element, which is used to protect the secure communication between the terminal and the user plane network element.
[0408] Optionally, in the case that the security authentication of the terminal by the authentication server function is passed, the authentication server function can feed back the authentication result to the terminal through the session management network element and the user plane network element, so as to facilitate the terminal to perform security authentication on the user plane network element in the future, and realize bidirectional authentication. That is, the method 900 can further include the following step S902.
[0409] S902, in the case that the security authentication of the terminal on the non-3GPP access is passed, the authentication server function sends an authentication response message to the terminal, and correspondingly, the terminal receives the authentication response message from the authentication server function, the authentication response message being used to indicate the authentication result of the terminal, such as authentication success.
[0410] As an example, the authentication server function sends an authentication response message #1 to the session management network element, the session management network element sends an authentication response message #2 to the user plane network element, the authentication response message #2 can include the identifier of the terminal, the user plane network element sends an authentication response message #3 to the terminal, and the authentication response message #3 can include the information of the terminal. Wherein, the authentication response message can be an IKE_AUTH_Response message of the IKEv2 protocol. Optionally, the IKE_AUTH_Response message can include an IDr information element, and the IDr information element can include the information of the terminal.
[0411] Further, the terminal determines a corresponding session, for example, a MAPDU session, according to the IDr information element carried in the authentication response message, and further determines a corresponding key, so as to verify the MAC value sent by the authentication server function through the user plane network element using the key, and complete the security authentication of the authentication server. The MAC value can be carried in the authentication response message.
[0412] Optionally, if the security authentication of the terminal fails, at least one of the above authentication response message #1, authentication response message #2 or authentication response message #3 can not be sent. For example, if the security authentication of the terminal fails, the user plane network element can not feed back the authentication result to the terminal, that is, the user plane network element can not send the authentication response message #3, or the user plane network element can feed back a reason value to the terminal, indicating the reason for the failure of the security authentication, for example, the information of the terminal does not match, etc., without limitation.
[0413] Based on the above scheme, in the process of establishing a session for a terminal through a 3GPP access in an ATSSS-lite scenario, the user plane network element can determine and store the correspondence between the information of the terminal and the N4 session identifier. Further, in the process of the terminal accessing through a non-3GPP network, the terminal can send an authentication request message to the user plane network element, so that the user plane network element can determine the N4 session identifier based on the information of the terminal and the locally stored correspondence, and further feed back the N4 session identifier and an authentication indication to the session management network element, requesting the session management network element to perform security authentication for the terminal. This implementation mode not only protects the identity information of the terminal and prevents privacy leakage, but also guarantees the secure communication of the terminal through the non-3GPP access network in the ATSSS-lite scenario.
[0414] For ease of understanding, the following takes the mobility management network element as AMF, the terminal as UE, the session management network element as SMF, the user plane network element as UPF, and the authentication server function as AUSF as an example for description. It can be understood that the process described below is only an example for description, and the embodiments of the present application are not limited thereto. The content not described in detail below can refer to the description in method 900, which will not be described hereinafter.
[0415] FIG. 10 is a flowchart of a communication method 1000 provided by an embodiment of the present application. As shown in FIG. 10, the following steps are included, and the parts not described in detail can refer to the above-mentioned existing protocol.
[0416] S1001, the UE performs a 3GPP registration process with the network side.
[0417] S1002, the UE sends a PDU session establishment request message to the AMF, and correspondingly, the AMF receives the PDU session establishment request message from the UE.
[0418] S1003, the AMF sends a PDU session context creation request message to the SMF, and correspondingly, the SMF receives the PDU session context creation request message from the AMF.
[0419] S1004, the SMF queries subscription data from the UDM, performs PCF selection, and obtains policy information.
[0420] S1005, the SMF sends an N4 session establishment request message to the UPF, and correspondingly, the UPF receives the N4 session establishment request message from the SMF, where the N4 session establishment request message is used to request to establish an N4 session.
[0421] The specific implementation of the steps S1001 to S1005 can refer to the related description of the steps S801 to S805 of the method 800, and for brevity, will not be described here.
[0422] S1006, the UPF stores the correspondence between the information of the UE and the N4 session identifier.
[0423] Optionally, before performing the step S1006, the method 1000 further includes: the UPF obtains the information of the UE, and the UPF obtains the N4 session identifier, and the specific implementation can refer to the related description of the method 900.
[0424] Optionally, the UPF obtaining the information of the UE includes: in the case that the UE supports ATSSS-lite, the UPF / SMF determines the information of the UE. For example, if the N4 session establishment request message in the step S1005 includes an ATSSS-lite indication, the UPF determines the information of the UE.
[0425] Optionally, the UPF obtaining the N4 session identifier includes: in the case that the UE supports ATSSS-lite, the SMF determines the N4 session identifier and sends it to the UPF. For example, if the N4 session establishment request message in the step S1005 includes an ATSSS-lite indication, the SMF determines the N4 session identifier according to the ATSSS-lite indication. The determination manner of the N4 session identifier can refer to the related description of the step S920 of the method 900.
[0426] The interpretation of the information of the UE and the N4 session identifier can refer to the related description of the method 900.
[0427] S1007, the UPF sends an N4 session establishment response message to the SMF, and correspondingly, the SMF receives the N4 session establishment response message from the UPF, where the N4 session establishment response message includes the information of the UE.
[0428] S1008, the SMF sends a PDU session accept message to the UE, and the UE receives the PDU session accept message from the SMF accordingly.
[0429] The specific implementation of steps S1007 and S1008 can refer to the related description of steps S807 and S808 of method 800, and details are not described here.
[0430] The above steps S1001 to S1008 are described for the session establishment process of the UE through 3GPP access, in which the UE is securely authenticated, and the UPF obtains the information of the UE and the N4 session identifier, and further, the following steps S1009-S1016 are for the security authentication process of the UE through non-3GPP access.
[0431] S1009, the UE accesses the non-3GPP network.
[0432] Specifically, the UE establishes a connection with the non-3GPP access network, such as establishing an L2 connection with the non-3GPP access network. In this way, the UE can send a message to the network through the non-3GPP access mode.
[0433] S1010, in the process of accessing the non-3GPP network, the UE sends an authentication request message #1 to the UPF, and the UPF receives the authentication request message #1 from the UE accordingly.
[0434] Optionally, the authentication request message #1 includes the information of the UE, and the meaning and interpretation of the information of the terminal can refer to the related description of step S930 of method 900.
[0435] As an example, the authentication request message can be an IPSec request message or an IKE_AUTH_request message. For example, the IKE_AUTH_request message can carry IDi (i.e., the first information element), and the IDi information element carries the information of the UE.
[0436] Optionally, before step S1010 is performed, the method 1000 further includes: the UE constructs the information of the UE, for example, the UE can construct the information of the UE according to the information of the UE carried in step S1008, such as XOR processing the obtained GPSI of the UE and the PDU session ID to obtain KID, etc.
[0437] S1011, the UPF determines the N4 session identifier according to the information of the UE and the corresponding relationship.
[0438] S1012, the UPF sends an N4 message to the SMF, and correspondingly, the SMF receives the N4 message from the UPF.
[0439] The N4 message includes an authentication indication and an N4 session identifier.
[0440] S1013, the SMF determines the NAI of the terminal according to the N4 session identifier.
[0441] S1014, the SMF sends an authentication request message #2 to the AUSF according to the authentication indication, and correspondingly, the AUSF receives the authentication request message #2 from the SMF.
[0442] The authentication request message #2 includes the NAI of the terminal.
[0443] S1015, the AUSF performs security authentication on the terminal according to the NAI of the terminal.
[0444] The specific implementation of steps S1011 to S1015 can refer to the related description of steps S940 to S980 of the above method 900, and will not be repeated here for brevity.
[0445] S1016, the AUSF sends an authentication response message to the UE, and correspondingly, the UE receives the authentication response message from the AUSF.
[0446] The authentication response message is used to indicate the authentication result of the UE, such as authentication success. The authentication response message can be any of the following: IPSec response message or IKE_AUTH_response message. For example, when the authentication response message is an IPSec response message or an IKE_AUTH_response message, the authentication response message can carry an IDr information element, and the IDr information element carries the information of the UE.
[0447] Further, the UE determines the corresponding session, such as the MA PDU session, according to the information of the terminal carried in the IDr information element carried in the authentication response message, and further determines the corresponding key, so as to use the key to verify the MAC value sent by the AUSF through the UPF, and complete the security authentication on the UPF. The MAC value can be carried in the authentication response message.
[0448] Optionally, if the security authentication of the UE fails, the AUSF can not feed back the authentication result to the UE, or the AUSF can feed back a reason value to the UE, which is used to indicate the reason for the failure of the security authentication, such as the information of the UE does not match, etc., which is not limited.
[0449] Based on the above technical solution, in the session establishment process through 3GPP access, the UPF can determine and store the correspondence between the information of the UE and the N4 session identifier. Further, in the process through the non-3GPP access network, the UE can send an authentication request message carrying the information of the UE to the UPF, so that the UPF can determine the N4 session identifier based on the information of the terminal and the correspondence, and then feed back the N4 session identifier and the authentication indication to the SMF, requesting to perform security authentication for the UE. The implementation manner not only protects the identity information of the UE from being leaked, but also guarantees the secure communication of the UE through the non-3GPP access network in the ATSSS-lite scenario.
[0450] It should be understood that the size of the serial number of each process described above does not mean the order of execution, and the execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0451] It should also be understood that the present application will present various aspects, embodiments or features around a system that can include multiple devices, components, modules, etc. It should be understood and appreciated that each system can include additional devices, components, modules, etc., and / or can not include all the devices, components, modules, etc. discussed in conjunction with the drawings. In addition, combinations of these solutions can also be used.
[0452] It should also be understood that in some embodiments described above, devices in existing network architecture are mainly exemplarily illustrated, and it should be understood that the specific form of the device is not limited by the embodiments of the present application. For example, devices that can achieve the same function in the future are also applicable to the embodiments of the present application.
[0453] It can be understood that the methods and operations implemented by the devices in each of the above method embodiments can also be implemented by components (such as chips or circuits) of the devices.
[0454] The above, in combination with FIG. 1 to FIG. 10, details the communication method provided by the embodiments of the present application. The above communication method is mainly introduced from the perspective of the interaction between the terminal (such as UE) and the user plane network element (such as UPF). It can be understood that the terminal and the user plane network element contain the corresponding hardware structure and / or software module for executing each function in order to achieve the above functions.
[0455] Those skilled in the art should be aware that units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by hardware or a combination of hardware and computer software. Whether a certain function is performed in hardware or computer software driven hardware depends on specific application and design constraints. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0456] The communication apparatus provided by the embodiments of the present application will be described in detail below in combination with FIG. 11 to FIG. 14. The description of the apparatus embodiments corresponds to the description of the method embodiments, and thus, the content not described in detail can be referred to the method embodiments above, and part of the content will not be described again for the sake of brevity.
[0457] The embodiments of the present application can divide the functional modules of the communication apparatus according to the method examples described above, for example, each functional module can be divided according to each function, or two or more functions can be integrated in one processing module. The integrated module can be realized in the form of hardware, or in the form of software functional module, or in the combination of software and hardware. The division of the modules in the embodiments of the present application is illustrative, and is only a logical functional division, and another division manner can be used in actual implementation. The following will be described taking the example of dividing each functional module according to each function.
[0458] FIG. 11 is an exemplary block diagram of the communication apparatus provided by the embodiments of the present application. As shown in FIG. 11, the communication apparatus can include a chip system 1100, a memory 1200, a bus 1300, a power management module 1400, or a transceiver 1500, etc.
[0459] The chip system 1100 can be an integrated circuit chip, which has the processing capability of signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware or the instruction in the form of software in the chip system 1100.
[0460] As an example but not limitation, the chip system 1100 can include a circuit or chip responsible for signal processing (such as a modem chip, also known as a baseband chip, or a system on chip SoC chip or SIP chip containing a modem core).
[0461] Optionally, a memory (e.g., a cache) can also be provided in the chip system 1100 for storing instructions and data. In some embodiments, the memory in the chip system 1100 is a cache memory. The memory can hold instructions or data that the chip system 1100 has just used or is recycling. If the chip system 1100 needs to use the instructions or data again, it can be called directly from the memory. This avoids repeated access and reduces the waiting time of the chip system 1100, thus improving the efficiency of the system.
[0462] In some embodiments, the chip system 1100 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity moudle (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0463] The memory 1200 can include random access memory (RAM) and read-only memory (ROM). The memory 1200 can store computer-readable computer-executable code including instructions that, when executed, cause the processor to perform a variety of functions described herein.
[0464] Optionally, the code can include instructions for implementing aspects of the present application. The code can be stored in a non-transitory computer-readable medium such as system memory or other type of memory. In some cases, the code can not be directly executable by the chip system 1100 but can cause a computer (for example, when compiled and executed) to perform functions described herein. In some cases, the memory 1200 can include, among other things, a basic input / output (I / O) system, which can control basic hardware or software operations, such as interaction with peripheral components or devices.
[0465] Exemplarily, the chip system 1100 performs various functional applications and data processing of the communication device 10 by running instructions stored in the memory 1200. For example, when the communication device 10 performs file transmission with other devices, the chip system 1100 of the communication device 10 can invoke computer executable program codes stored in the memory 1200 to implement the data and / or signaling transmission method provided in the embodiments of the present application.
[0466] In addition, the memory 1200 can be integrated in the above chip system 1100, or independent of the chip system 1100.
[0467] The bus 1300 can be a USB, used to support mutual communication between various parts in the communication device 10.
[0468] The power management module 1400 is used to receive charging input from a charger. Optionally, the power management module 1400 can supply power to the communication device 10 (e.g., a battery module of the communication device 10) while charging the communication device 10. As an example but not limitation, the power management module 1400 can also supply power to devices other than the communication device 10.
[0469] The transceiver 1500 can communicate bi-directionally with one or more antennas, wired or wireless links, for example. The transceiver 1500 can represent a wireless transceiver and can communicate bi-directionally with another wireless transceiver, for example. The transceiver 1500 can also include a modem to modulate the packets and to provide the modulated packets to the antennas for transmission, and to demodulate packets received from the antennas. The transceiver 1500 can include a transmitter and a receiver, for example.
[0470] In some cases, a wireless device can include a single antenna. However, in some cases the device can have more than one antenna, like the antennas 1 and 2 shown in FIG. 11, which can be capable of concurrently transmitting or receiving multiple wireless transmissions. Exemplarily, the antennas 1 and 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the communication device 10 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization of the antennas. For example: the antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in combination with a tuning switch. The communication device 10 can transmit files to other devices through a wireless communication function.
[0471] In one design, the communication device 10 can correspond to a terminal in the above method embodiments.
[0472] The apparatus 10 can implement steps or procedures corresponding to those performed by the terminal in the above method embodiments, wherein the transceiver 1500 can be configured to perform the transceiving-related operations of the terminal in the above method embodiments; and the chip system 1100 can be configured to perform the processing-related operations of the terminal in the above method embodiments.
[0473] In another design, the communication apparatus 10 can correspond to the user plane network element in the above method embodiments.
[0474] The apparatus 10 can implement steps or procedures corresponding to those performed by the user plane network element in the above method embodiments, wherein the transceiver 1500 can be configured to perform the transceiving-related operations of the user plane network element in the above method embodiments; and the chip system 1100 can be configured to perform the processing-related operations of the user plane network element in the above method embodiments.
[0475] In this design, the communication apparatus 10 can include modules such as the short-range communication module 1640, the sensor 1610, the display 1620, or the camera 1630, as shown in FIG. 11.
[0476] The short-range communication module 1640 can include a wireless network (WI-FI, or WIFI), or a module supporting short-range communication such as Bluetooth.
[0477] The sensor 1610 can include a pressure sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a distance sensor, a proximity light sensor, a fingerprint sensor, a temperature sensor, a touch sensor, an ambient light sensor, a bone conduction sensor, etc.
[0478] The display 1620 is configured to display images, videos, etc. The display includes a display panel. The display panel can adopt a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light emitting diodes (QLED), etc. For example, in embodiments of the present application, the display can be configured to display interfaces required to be displayed by the communication device 10. For example, the communication device 10 can realize the display function through a graphic processing unit (GPU), a display, an application processor, etc. The GPU is a microprocessor for image processing, connected to the display and the application processor. The GPU is configured to perform mathematical and geometric calculations for graphics rendering. The chip system 1100 can include one or more GPUs, which execute program instructions to generate or change display information.
[0479] The camera 1630 is configured to acquire images, videos, etc.
[0480] It can be understood that the structure shown in FIG. 11 does not constitute a specific limitation on the communication device 10, and the specific structure of the terminal and / or user plane network element can refer to that shown in FIG. 11. In some embodiments, the communication device 10 can also include more or fewer components than those shown in FIG. 11, or combine certain components, or split certain components, or different component arrangements, etc. Alternatively, some components shown in FIG. 11 can be implemented in hardware, software, or a combination of software and hardware, and the terminal and / or user plane network element can add or reduce components on the basis of the structure given in FIG. 11.
[0481] FIG. 12 is a schematic block diagram of a communication device according to an embodiment of the present application. As shown in FIG. 12, the communication device 20 can include a baseband unit 2100, which can communicate with external devices through a cellular RF transceiver 2200 (for example, when the communication device 20 is a terminal, the baseband unit 2100 can communicate with network devices through the cellular RF transceiver 2200; also for example, when the communication device 20 is a user plane network element, the baseband unit 2100 can communicate with terminals and / or user plane network elements through the cellular RF transceiver 2200).
[0482] The baseband unit 2100 can include a computer-readable medium / memory. The baseband unit 2100 is responsible for general processing, including the execution of software stored on the computer-readable medium / memory. The software, when executed by the baseband unit 2100, causes the baseband unit 2100 to perform the various functions described supra. The computer-readable medium / memory can also be used for storing data that is manipulated by the baseband unit 2100 when executing software.
[0483] The baseband unit 2100 further includes a reception unit 2010, a management unit 2020 and a transmission unit 2030. The management unit 2020 includes the one or more sub-units shown in FIG. 12 (e.g., a signal generating unit and / or a signal resolving unit). The units within the management unit 2020 can be stored in the computer-readable medium / memory and / or be configured as hardware within the baseband unit 2100. Among them, the reception unit 2010 and the transmission unit 2030 can be referred to as a transceiver unit.
[0484] When the communication apparatus 20 is configured to implement the functions of the terminal in each of the above method embodiments, the reception unit 2010 is configured to perform the receiving steps of the terminal, the transmission unit 2030 is configured to perform the transmitting steps of the terminal, and the management unit 2020 is configured to perform the processing steps of the terminal.
[0485] For example, when the apparatus 20 is configured to perform the method in FIG. 2, the reception unit 2010 can be configured to perform the steps of receiving information in the method; the management unit 2020 can be configured to perform the processing steps in the method; and the transmission unit 2030 can be configured to perform the steps of transmitting information in the method.
[0486] When the communication apparatus 20 is configured to implement the functions of the user plane network element in each of the above method embodiments, the reception unit 2010 is configured to perform the receiving steps of the user plane network element, the transmission unit 2030 is configured to perform the transmitting steps of the user plane network element, and the management unit 2020 is configured to perform the processing steps of the user plane network element.
[0487] For example, when the apparatus 20 is configured to perform the method in FIG. 2, the reception unit 2010 can be configured to perform the steps of receiving information in the method; the management unit 2020 can be configured to perform the processing steps in the method; and the transmission unit 2030 can be configured to perform the steps of transmitting information in the method.
[0488] For more details about the above reception unit 2010, management unit 2020 and transmission unit 2030, please refer to the relevant description in the above method embodiments, which will not be repeated here.
[0489] FIG. 13 is a schematic block diagram of a chip system 30 according to an embodiment of the present application. The chip system may, for example, comprise a modem chip, also referred to as a baseband chip, or a system on chip (SoC) chip or a system in package (SIP) chip comprising a modem core.
[0490] As shown in FIG. 13, the chip system (or also referred to as a processing system) comprises a processor 3100, a memory 3200, and an input / output interface 3300.
[0491] The processor 3100 may, for example, be a processing circuitry in the chip system comprising at least one processor, such as the processor 1 and the processor 2 shown in FIG. 13. The processor 3100 may be coupled to the memory 3200 to invoke instructions in the memory 3200 so that the chip system can implement the methods and functions of the embodiments of the present application. The input / output interface 3300 may, for example, be an input / output circuit in the chip system to output information processed by the chip system or input data or signaling information to be processed by the chip system.
[0492] As an example, the chip system is configured to implement operations performed by a terminal or a user plane network element in the methods described above.
[0493] For example, the processor 3100 is configured to implement processing-related operations performed by a terminal or a user plane network element in the methods described above, which can be implemented as described above. The input / output interface 3300 is configured to implement sending and / or receiving-related operations performed by a terminal or a user plane network element in the methods described above, which can be implemented as described above.
[0494] FIG. 14 is a schematic block diagram of another chip system 40 according to an embodiment of the present application. As shown in FIG. 14, the chip system (or also referred to as a processing system) comprises an input / output interface 4100 and a logic circuit 4200. The input / output interface 4100 may, for example, be an input / output circuit in the chip system to output information processed by the chip system or input data or signaling information to be processed by the chip system, which can be implemented as described above. The logic circuit 4200 is configured to implement the communication methods described above, which can be implemented as described above.
[0495] As an example, the chip system is configured to implement operations performed by a terminal or a user plane network element in the methods described above.
[0496] For example, the logic circuit 4200 is configured to implement the processing-related operations performed by the terminal or the user plane network element in the above method embodiments; and the input / output interface 4100 is configured to implement the sending and / or receiving-related operations performed by the terminal or the user plane network element in the above method embodiments.
[0497] The embodiments of the present application further provide a computer readable storage medium, which has stored thereon a computer program or instructions for implementing the method performed by the apparatus in the above method embodiments. For example, the computer program, when executed by a computer, causes the computer to implement the method performed by the terminal and / or the user plane network element in the above method embodiments.
[0498] The embodiments of the present application further provide a computer program product, which contains instructions, the instructions being executed by a computer to implement the method performed by the terminal and / or the user plane network element in the above method embodiments.
[0499] The embodiments of the present application further provide a communication system, which includes the user plane network element.
[0500] Optionally, the communication system can further include at least one of the terminal, the mobility management network element, or the session management network element.
[0501] The embodiments of the present application further provide a communication system, which includes the user plane network element and the session management network element.
[0502] Optionally, the communication system can further include at least one of the terminal, the mobility management network element, or the authentication server function.
[0503] The above-provided any kind of apparatus-related content can refer to the corresponding method embodiments provided above for explanation and beneficial effects, which will not be repeated here.
[0504] Those skilled in the art can understand that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solutions. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0505] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described system, apparatus and unit can refer to the corresponding processes in the above method embodiments, which will not be described here.
[0506] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the described device embodiments are merely schematic. The division of the units is merely logical function division. There can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0507] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0508] In addition, each functional unit in the various embodiments of the present application can be integrated into a processing unit, or each unit can be a physically independent unit, or two or more units can be integrated into one unit.
[0509] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the technical solutions or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk, etc.
[0510] The above description is merely a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A communication method characterized by comprising: The method comprises: In a process of establishing a session for a terminal accessing through a third generation partnership project (3GPP) access, storing a correspondence between information of the terminal and a security credential, the security credential being used for security authentication of the terminal in a process of accessing through a non-3GPP access network, the session being used for the 3GPP access and the non-3GPP access; In the process of accessing through the non-3GPP access network by the terminal, receiving an authentication request message from the terminal, the authentication request message comprising the information of the terminal; Determining the security credential according to the information of the terminal and the correspondence; Security authenticating the terminal according to the security credential.
2. The method of claim 1, wherein, The information of the terminal comprises at least one of: An IP address of the terminal associated with the non-3GPP access; An IP address of the terminal associated with the 3GPP access; A public network IP address of a user plane network element; An IP address of the terminal associated with the session; Information obtained based on security processing of an identifier of the terminal and an identifier of the session; or A globally unique temporary UE identifier (GUTI) of the terminal.
3. The method according to claim 1 or 2, characterized in that, The security credential is generated according to a security context of the 3GPP access.
4. The method according to any one of claims 1 to 3, characterized in that, Storing the correspondence between the information of the terminal and the security credential comprises: According to indication information, storing the correspondence between the information of the terminal and the security credential; The indication information indicates that the session is a session in an ATSSS-lite scenario.
5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: Before the terminal accesses through the non-3GPP access network, sending the information of the terminal to the terminal.
6. The method of claim 5, wherein, Sending the information of the terminal to the terminal comprises: According to indication information, sending the information of the terminal to the terminal; The indication information indicates that the session is a session in an ATSSS-lite scenario.
7. The method according to claim 5 or 6, characterized in that, Sending the information of the terminal to the terminal comprises: According to the session using a multi-path transmission control protocol (MPTCP) function and / or a multi-path quick user datagram protocol internet connection protocol (MPQUIC) function, sending, to the terminal, the IP address of the terminal associated with the non-3GPP access, the IP address of the terminal associated with the session, and the IP address of the terminal associated with the 3GPP access.
8. The method according to any one of claims 1 to 7, characterized in that, The authentication request message comprising the information of the terminal comprises: The authentication request message comprises a data packet and / or a first information element, a destination address and / or a source address of the data packet being the information of the terminal, and the first information element comprising the information of the terminal.
9. The method of claim 8, wherein, Determining the security credential according to the information of the terminal and the correspondence comprises: In a case where the source address and / or the destination address of the data packet is the same as the information of the terminal carried in the first information element, determining the security credential according to the information of the terminal and the correspondence.
10. The method according to any one of claims 1 to 9, characterized in that, The method further comprises: In a case where the security authentication of the terminal is passed, sending an authentication response message, the authentication response message comprising the information of the terminal.
11. The method according to any one of claims 1 to 10, characterized in that, The information of the terminal comprises information obtained by performing security processing on the identifier of the terminal and the identifier of the session, and before storing the correspondence between the information of the terminal and the security credential, the method further comprises: obtaining information obtained by performing security processing on the identifier of the terminal and the identifier of the session.
12. The method of claim 11, wherein, The obtaining information obtained by performing security processing on the identifier of the terminal and the identifier of the session comprises: receiving the information obtained by performing security processing on the identifier of the terminal and the identifier of the session from a session management network element; or, receiving the identifier of the terminal and the identifier of the session from a session management network element, and determining the information obtained by performing security processing on the identifier of the terminal and the identifier of the session according to the identifier of the terminal and the identifier of the session.
13. The method according to claim 11 or 12, characterized in that, The method further comprises: deleting the information obtained by performing security processing on the identifier of the terminal and the identifier of the session, and the security credential after performing security authentication on the terminal.
14. The method according to any one of claims 1 to 13, characterized in that, The information of the terminal comprises GUTI of the terminal, and before storing the correspondence between the information of the terminal and the security credential, the method further comprises: receiving the GUTI of the terminal and the security credential from a session management network element.
15. A method of communication, comprising: The method comprises: establishing a session for the terminal through a third generation partnership project (3GPP) access, the session being used for the 3GPP access and a non-3GPP access of the terminal; in the process of accessing the non-3GPP access network, sending an authentication request message to the user plane network element, the authentication request message comprising information of the terminal, the information of the terminal being used for determining a security credential for performing security authentication on the non-3GPP access of the terminal; receiving an authentication response message in the case that the security authentication on the non-3GPP access of the terminal is passed.
16. The method of claim 15, wherein, The information of the terminal comprises at least one of: an IP address of the terminal associated with the non-3GPP access; an IP address of the terminal associated with the 3GPP access; a public IP address of the user plane network element; an IP address of the terminal associated with the session; information obtained by performing security processing on the identifier of the terminal and the identifier of the session; or a global unique temporary UE identifier (GUTI) of the terminal.
17. The method according to claim 15 or 16, characterized in that, The authentication request message comprises the information of the terminal, comprising: the authentication request message comprises a data packet and / or a first information element, a destination address and / or a source address of the data packet being the information of the terminal, and the first information element comprising the information of the terminal.
18. The method of claim 17, wherein, The first information element is: an IDi information element in an IKE_AUTH_Requst message of an Internet Key Exchange (IKE) version 2 (IKEv2) protocol; or a Pre_shared_key information element in a Client Hello message of a Transport Layer Security (TLS) protocol.
19. The method according to any one of claims 15 to 18, characterized in that, In the process of establishing the session for the terminal through the 3GPP access, the method further comprises: sending indication information, the indication information indicating that the session is a session in an ATSSS-lite scenario.
20. The method of any one of claims 15-19, wherein, In a process of establishing a session for the terminal through the 3GPP access, the method further comprises: According to the session using a multi-path transmission control protocol MPTCP function and / or a multi-path quick user datagram protocol internet connection protocol MPQUIC function, receiving an IP address of the terminal associated with the non-3GPP access, an IP address of the terminal associated with the session, and an IP address of the terminal associated with the 3GPP access from the user plane network element.
21. A method of communication, comprising: The method comprises: In a process of establishing a session for a terminal through a third generation partnership project 3GPP access, storing a correspondence between first information of the terminal and an N4 session identifier, the session being for the 3GPP access and a non-3GPP access, the N4 session identifier being associated with the session; In a process of the terminal through the non-3GPP access network, receiving an authentication request message from the terminal; Determining the N4 session identifier according to the first information of the terminal; Sending an authentication indication and the N4 session identifier to a session management network element, the authentication indication being used to indicate a security authentication for the terminal.
22. The method of claim 21, wherein, Before storing the correspondence between the first information of the terminal and the N4 session identifier, the method further comprises: Establishing an N4 session with a session management network element, and receiving the N4 session identifier from the session management network element.
23. The method of claim 21 or 22, wherein, The storing of the correspondence between the first information of the terminal and the N4 session identifier comprises: According to indication information, storing the correspondence between the first information of the terminal and the N4 session identifier; The indication information indicates that the session is a session in an access traffic steering, switching, and splitting ATSSS-lite scenario.
24. The method of claim 22 or 23, wherein, The authentication request message comprises second information of the terminal, the second information of the terminal being used to determine a security credential for a security authentication for the non-3GPP access of the terminal; The determining of the N4 session identifier according to the first information of the terminal comprises: In a case where the first information of the terminal is same as the second information of the terminal, determining the N4 session identifier according to the first information of the terminal and the correspondence.
25. The method of any one of claims 21-24, wherein, The first information of the terminal comprises at least one of: An IP address of the terminal associated with the non-3GPP access; An IP address of the terminal associated with the 3GPP access; A public network IP address of a user plane network element; Information obtained based on a security processing of an identifier of the terminal and an identifier of the session; or A global unique temporary UE identifier GUTI of the terminal.
26. The method of any one of claims 21-25, wherein, The method further comprises: In a case where the security authentication for the non-3GPP access of the terminal is passed, receiving a first key from the authentication server function or the session management network element, the first key being used to protect a secure communication between the terminal and the user plane network element.
27. The method of any one of claims 21 to 26, wherein: The authentication indication and the N4 session identifier are carried in an N4 session message; and / or, The first key is carried in an N4 session message.
28. The method of any one of claims 21-27, wherein, The method further includes: Before the terminal accesses the non-3GPP access network, sending first information of the terminal to the terminal.
29. A method of communication, comprising: The method includes: In a process of establishing a session for a terminal accessing a third generation partnership project (3GPP) access, storing a correspondence between first information of the terminal and an N4 session identifier, the session being for the 3GPP access and a non-3GPP access, the N4 session identifier being associated with the session; In the process of the terminal accessing the non-3GPP access network, receiving an authentication indication and the N4 session identifier from a user plane network element, the authentication indication being used to indicate that the terminal is authenticated securely; According to the N4 session identifier and the correspondence, determining a network access identifier (NAI) of the terminal; According to the authentication indication, sending an authentication request message to an authentication server function, the authentication request message including the NAI.
30. The method of claim 29, wherein, Before storing the correspondence between the first information of the terminal and the N4 session identifier, the method further includes: establishing an N4 session with the user plane network element, and sending the N4 session identifier to the user plane network element; The determining, according to the N4 session identifier and the correspondence, of the NAI of the terminal includes: According to the N4 session identifier and the correspondence, determining first information of the terminal; According to the first information of the terminal, determining the NAI.
31. The method of claim 29 or 30, wherein, The first information of the terminal includes any of the following: a subscriber permanent identifier (SUPI) of the terminal; information obtained by performing security processing based on an identifier of the terminal and an identifier of the session; or a global unique temporary UE identifier (GUTI) of the terminal.
32. The method of claim 30 or 31, wherein, The storing of the correspondence between the first information of the terminal and the N4 session identifier includes: According to indication information, storing the correspondence between the first information of the terminal and the N4 session identifier; The authentication indication and the N4 session identifier are carried in an N4 session message.
33. The method of any one of claims 29-32, wherein, The apparatus includes a module or unit for performing the method of any of claims 1-14; or a module or unit for performing the method of any of claims 15-20; or a module or unit for performing the method of any of claims 21-28; or a module or unit for performing the method of any of claims 29-33.
34. A communications device, characterized by The apparatus includes a processor configured to cause the communication device to perform the method of any of claims 1-14; or a processor configured to cause the communication device to perform the method of any of claims 15-20; or a processor configured to cause the communication device to perform the method of any of claims 21-28; or a processor configured to cause the communication device to perform the method of any of claims 29-33.
35. A communications device, characterized by 36. A communication system, characterized by The communication system further comprises a session management network element and / or a terminal for performing the method according to any one of claims 15 to 20.
37. The communication system of claim 36, wherein, The communication system further comprises a session management network element and / or a terminal for performing the method according to any one of claims 15 to 20.
38. A communication system, characterized by The communication system further comprises a session management network element and / or a terminal for performing the method according to any one of claims 15 to 20.
39. The communication system of claim 38, wherein, The communication system further comprises a session management network element and / or a terminal for performing the method according to any one of claims 15 to 20, the session management network element for performing the method according to any one of claims 29 to 33.
40. A computer-readable storage medium, characterized in that, The computer readable storage medium has stored thereon a computer program or instructions, which, when executed on a communication device, cause the communication device to perform the method according to any one of claims 1 to 20, or cause the communication device to perform the method according to any one of claims 21 to 33.
41. A computer program product, characterised in that, The computer program product comprises a computer program or instructions, which, when executed on a communication device, cause the communication device to perform the method according to any one of claims 1 to 20, or cause the communication device to perform the method according to any one of claims 21 to 33.
Citation Information
Patent Citations
Method and system for authenticating access in mobile wireless network system
CN109417709A
Card binding authentication method and device
CN117098100A