Communication method and related apparatus
By working together with access management devices, session management devices, and forwarding devices, authentication information is actively obtained and session establishment is allowed, which solves the uplink data transmission delay problem caused by link instability in non-terrestrial communication systems and achieves efficient data transmission in store-and-forward mode.
Patent Information
- Application Number
- PCT/CN2025/104382
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-19
- Filing Date
- 2025-06-27
- Publication Date
- 2026-01-22
AI Technical Summary
In non-terrestrial communication systems, the movement of satellites causes service links and feeder links to be unavailable at all times, resulting in increased uplink data transmission latency. This is especially true in store-and-forward mode, where network slicing and data network authentication introduce additional latency issues.
The access management device actively obtains the authentication information of the network slice and allows the terminal device to use the network slice before receiving the authentication result. The session management device actively obtains the authentication information of the data network and indicates that the session is successfully established before receiving the authentication result. The forwarding device processes the uplink data according to the mapping relationship. The terminal device actively obtains the authentication mechanism of the slice and the data network to reduce the time waiting for the authentication result.
It effectively reduces uplink data transmission latency. Especially in store-and-forward mode, terminal devices can complete session establishment and data transmission in a single link connection, avoiding delays caused by waiting for network slicing and data network authentication results.
Smart Images

Figure CN2025104382_22012026_PF_FP_ABST
Abstract
Description
Communication methods and related devices
[0001] This application claims priority to Chinese Patent Application No. 202410980636.0, filed on July 19, 2024, entitled "Communication Method and Related Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communication technology, and in particular to a communication method and related apparatus. Background Technology
[0003] In non-terrestrial network (NTN) systems, satellites in a defined regenerative forwarding architecture can process received signals, including demodulation / decoding, encoding / modulation, and information processing; that is, the satellite possesses all the functions of a radio access network (RAN) node. In this architecture, due to satellite movement, the service link between the satellite and terminal equipment, and the feed link between the gateway station and the satellite, may not be available at all times. Therefore, in this architecture, for uplink, the satellite needs to store uplink (UL) information from the terminal equipment when the service link is available, and then forward the stored UL information to the core network when the feed link becomes available. This satellite operating mode in this scenario can be called store-and-forward (S&F) satellite operation mode.
[0004] For example, before sending UL information, the terminal device may also need to perform network slice authentication and / or data network (DN) authentication, which will introduce additional uplink transmission latency. Summary of the Invention
[0005] This application provides a communication method and related apparatus to reduce the transmission latency of uplink data.
[0006] Firstly, this application provides a communication method that can be applied to an access management device, or implemented by components (such as chips, chip systems, etc.) configured in the access management device, or by logic modules or software capable of implementing all or part of the functions of the access management device; this application does not limit the scope of the method. For ease of understanding and explanation, the method is described below using an access management device as an example. It should be understood that the access management device is located in a non-terrestrial network.
[0007] For example, the method includes: receiving a first request from a terminal device, the first request being for requesting access to the non-terrestrial network, the first request including identifiers of one or more network slices requested by the terminal device; if, among the one or more network slices, at least one network slice with a slice authentication status of pending authentication is included, sending a second request to the terminal device, the second request being for requesting first authentication information, the first authentication information being for authenticating the terminal device's permission to use the at least one network slice; receiving the first authentication information from the terminal device, the first authentication information being for authenticating the terminal device's permission to use the at least one network slice; if no first authentication result is received, sending a first response to the terminal device, the first response being for indicating that the terminal device is allowed to use the at least one network slice, the first authentication result being for indicating that the at least one network slice authentication was successful or that the at least one network slice authentication was unsuccessful.
[0008] Optionally, the first response may send at least one network slice in the form of a list of allowed slices. Optionally, the list of allowed slices may also include network slices whose slice authentication status is authenticated.
[0009] Based on this technical solution, when the access management device receives a first request carrying the identifier of one or more network slices, it can proactively trigger the acquisition of authentication information for at least one network slice whose authentication status is pending. However, after obtaining the authentication information of the network slice, the access management device does not wait for the first authentication result of the first network slice, but instead indicates to the terminal device that at least one network slice is allowed for use by the terminal device. Then, the terminal device can initiate a session establishment process carrying the identifier of the first network slice in at least one network slice. Compared with the scheme where the terminal device needs to receive the authentication result of the first network slice before initiating the session establishment process, the method provided in this application can effectively reduce the additional latency caused by waiting for the authentication result of the network slice. Especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), the terminal device does not need to wait for the authentication result of the network slice from the terrestrial authentication server. Therefore, the session establishment can be completed during a single link connection, and then uplink data can be sent, effectively reducing the transmission latency of uplink data.
[0010] In conjunction with the first aspect, in some implementations of the first aspect, the second request includes at least one freshness parameter, which is used by the terminal device to determine the first authentication information.
[0011] Optionally, the freshness parameter can be a random number.
[0012] In conjunction with the first aspect, in some implementations of the first aspect, the first authentication information includes at least one authentication information; before sending the first response to the terminal device, the method further includes: obtaining from the terminal device the correspondence between the at least one network slice and the at least one authentication information.
[0013] It is understandable that after the access management device obtains multiple authentication information, it can determine the authentication information corresponding to each network slice based on the obtained correspondence.
[0014] Optionally, the correspondence between at least one network slice and at least one authentication information can be sent simultaneously with the first authentication information, or sent separately.
[0015] In conjunction with the first aspect, in some implementations of the first aspect, after sending the first response to the terminal device, the method further includes: receiving a session request from the terminal device, the session request being used to request the establishment of a session for the terminal device to send data through the non-terrestrial network, the session request including an identifier of a first network slice, the at least one network slice including the first network slice; if no authentication result of the first network slice is received, sending a third request to a session management device, the third request being used to request the establishment of the session, the third request including an identifier of the first network slice; the session management device being located in the non-terrestrial network.
[0016] The third request here can be understood as the terminal device sending information to the session management device through the access management device to request the establishment of a session. Specifically, the information used to request the establishment of a session can be the N1 session management container (N1 SM container).
[0017] Based on this, the access management device does not wait for the authentication result of the first network slice, but directly sends a request to the session management device to establish a session, which can effectively reduce the uplink transmission latency caused by waiting for the authentication result.
[0018] In conjunction with the first aspect, in some implementations of the first aspect, the third request includes information indicating that the authentication status of the first network slice is pending authentication, and / or, the third request includes an external identifier of the terminal device.
[0019] Alternatively, the third request may include information indicating that the authentication status of the first network slice is pending authentication, and / or the third request may include the internal identifier of the terminal device.
[0020] Among them, the external or internal identifier of the terminal device is the information used to identify the terminal device.
[0021] In conjunction with the first aspect, in some implementations of the first aspect, after receiving the first authentication information from the terminal device, the method further includes: sending the authentication information of the first network slice to the authentication server of the first network slice; receiving the authentication result of the first network slice from the authentication server of the first network slice; and sending the authentication result of the first network slice to the session management device.
[0022] Optionally, the method further includes: sending authentication information of a second network slice to the authentication server of the first network slice, wherein the at least one network slice includes the second network slice; receiving the authentication result of the second network slice from the authentication server of the second network slice; and sending the authentication result of the second network slice to the session management device.
[0023] In other words, after obtaining the first authentication information, which includes multiple authentication information, the access management device can send the corresponding authentication information to the authentication servers of different network slices to obtain the authentication results of different network slices.
[0024] It is understandable that after the access management device obtains the authentication results of multiple network slices, it can determine the authentication result of each network slice based on the correspondence between the multiple network slices and the authentication results.
[0025] In conjunction with the first aspect, in some implementations of the first aspect, before sending the authentication result of the first network slice to the session management device, the method further includes: determining that the session management device is the session management device corresponding to the session.
[0026] Since different network slices may correspond to different session management devices, after the access management device obtains the authentication result, it can determine the session management device based on the session corresponding to the network slice, so as to avoid sending the authentication result of the network slice to an unmatched session management device, which would cause uplink data transmission failure.
[0027] In conjunction with the first aspect, in some implementations of the first aspect, after receiving the first authentication information from the terminal device, the method further includes: sending to a first forwarding device the correspondence between at least one authentication information in the first authentication information and the identifier of the at least one network slice, as well as the external identifier of the terminal device.
[0028] The first forwarding device is located in a non-terrestrial network.
[0029] Optionally, the first authentication information includes the authentication information of the first network slice, and the correspondence includes the correspondence between the authentication information of the first network slice and the first network slice.
[0030] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: determining that the terminal device accesses the non-terrestrial network, wherein network elements for implementing access procedures and session establishment procedures are deployed in the non-terrestrial network; and / or determining that the uplink or downlink communication of the terminal device is performed in store-and-forward mode.
[0031] Based on this, when the access management device determines that the terminal device is accessing a non-terrestrial network and / or determines that the terminal device is conducting uplink or downlink communication in store-and-forward mode, it can continue the session establishment process without waiting for the authentication result of the network slice carried by the terminal device in the session request, thereby reducing transmission latency.
[0032] Secondly, this application provides a communication method that can be applied to a first forwarding device, or implemented by components (such as chips, chip systems, etc.) configured in the first forwarding device, or by logic modules or software capable of implementing all or part of the functions of the first forwarding device; this application does not limit this. For ease of understanding and explanation, the method is described below using a first forwarding device as an example. It should be understood that the first forwarding device is located in a non-terrestrial network.
[0033] For example, the method includes: receiving a correspondence between at least one authentication information and at least one network slice from an access management device, and an external identifier of the terminal device, wherein the at least one authentication information includes authentication information of a first network slice; and determining a first mapping relationship, wherein the first mapping relationship includes a correspondence between the at least one authentication information, the identifier of the at least one network slice, and the external identifier of the terminal device.
[0034] Optionally, the first mapping relationship may also include the address information of the authentication server for each network slice in at least one network slice.
[0035] The authentication information of the first network slice is used to authenticate the terminal device's permission to use the first network slice.
[0036] Based on this technical solution, the first forwarding device determines the correspondence between the identifier of at least one network slice, the authentication information of at least one network slice, and the external identifier of the terminal device. This enables the first forwarding device to distinguish the authentication results corresponding to different network slices when it obtains the authentication result of the network slice identified by the identifier of at least one network slice, thereby avoiding the problem that the first forwarding device cannot continue to send uplink data due to the mismatch between the authentication result and the network slice.
[0037] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: receiving the identifier of a first network slice from the session management device, the external identifier of the terminal device, and the address information of the uplink data of the terminal device; determining a second mapping relationship based on the identifier of the first network slice from the session management device, the external identifier of the terminal device, and the first mapping relationship, wherein the second mapping relationship includes the correspondence between the identifier of the first network slice, the authentication information of the first network slice, the external identifier of the terminal device, and the address information of the uplink data of the terminal device.
[0038] The address information of the uplink data of the terminal device may include at least one of the following: source Internet Protocol (IP) address, source IP port number, destination IP address, or destination port number.
[0039] Optionally, when the first mapping relationship includes the address information of the authentication server of each network slice in at least one network slice, the second mapping relationship may include the correspondence between the identifier of the first network slice, the authentication information of the first network slice, the address information of the authentication server of the first network slice, the external identifier of the terminal device, and the address information of the uplink data of the terminal device.
[0040] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: receiving first uplink data from the terminal device; caching the first uplink data; determining, based on the second mapping relationship, authentication information of a first network slice corresponding to the address information of the first uplink data; sending the authentication information of the first network slice to the authentication server of the first network slice; receiving the authentication result of the first network slice from the authentication server of the first network slice; and sending the first uplink data when the authentication result of the first network slice indicates that the first network slice has been successfully authenticated.
[0041] Optionally, the method further includes: determining the authentication server of the first network slice corresponding to the authentication information of the first network slice based on the second mapping relationship.
[0042] Optionally, sending the authentication information of the first network slice to the authentication server of the first network slice includes: sending the authentication information of the first network slice to the authentication server of the first network slice through the second forwarding device.
[0043] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: receiving an identifier of a first network slice from a session management device, an external identifier of the terminal device, second authentication information, and address information of the uplink data of the terminal device, wherein the second authentication information is used to authenticate the terminal device's access permission to the DN; determining a fourth mapping relationship based on the identifier of the first network slice from the session management device, the external identifier of the terminal device, and the first mapping relationship, wherein the fourth mapping relationship includes the correspondence between the identifier of the first network slice, the authentication information of the first network slice, the second authentication information, the external identifier of the terminal device, and the address information of the uplink data of the terminal device.
[0044] Optionally, the fourth mapping relationship also includes the authentication server of the DN corresponding to the second authentication information.
[0045] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: receiving first uplink data from the terminal device; caching the first uplink data; determining, based on the fourth mapping relationship, the authentication information of the first network slice corresponding to the address information of the first uplink data and the second authentication information; sending the second authentication information to the authentication server of the DN; receiving a second authentication result from the authentication server of the DN; sending the authentication information of the first network slice to the authentication server of the first network slice; receiving the authentication result of the first network slice from the authentication server of the first network slice; and sending the first uplink data when the authentication result of the first network slice indicates that the first network slice authentication is successful and the second authentication result indicates that the terminal device's access permission authentication to the DN is successful.
[0046] Optionally, the method further includes: determining the authentication server of the DN corresponding to the second authentication information based on the fourth information.
[0047] Optionally, sending the second authentication information to the DN's authentication server includes: sending the second authentication information to the DN's authentication server via a second forwarding device.
[0048] Thirdly, this application provides a communication method that can be applied to a first forwarding device, or implemented by components (such as chips, chip systems, etc.) configured in the first forwarding device, or by logic modules or software capable of implementing all or part of the functions of the first forwarding device. This application does not limit the scope of the method. For ease of understanding and explanation, the method will be described below using a first forwarding device as an example.
[0049] For example, the method includes: receiving second authentication information from the session management device and address information of uplink data from the terminal device; determining a third mapping relationship, the third mapping relationship including the correspondence between the second authentication information and the address information of uplink data from the terminal device.
[0050] The second authentication information is used to authenticate the terminal device's permission to access the DN.
[0051] For address information regarding uplink data, please refer to the description in the second section; it will not be repeated here.
[0052] Optionally, the third mapping relationship may also include the authentication server of the DN corresponding to the second authentication information.
[0053] Based on this technical solution, the first forwarding device determines the correspondence between the second authentication information and the address information of the uplink data of the terminal device. This allows the first forwarding device to distinguish the authentication results corresponding to different address information of the uplink data when it obtains the authentication result of the DN, thereby avoiding the problem that the first forwarding device cannot continue to send uplink data due to the mismatch between the authentication result and the address information of the uplink data.
[0054] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: receiving first uplink data from the terminal device; caching the first uplink data; determining the second authentication information corresponding to the address information of the first uplink data based on the third mapping relationship; sending the second authentication information to the authentication server of the DN; receiving a second authentication result from the authentication server of the DN; and sending the first uplink data when the second authentication result indicates that the terminal device has successfully authenticated its access to the DN.
[0055] Optionally, the method further includes: determining the authentication server of the DN corresponding to the second authentication information based on the third mapping relationship.
[0056] Fourthly, this application provides a communication method that can be applied to a session management device, or implemented by a component (such as a chip, chip system, etc.) configured in the session management device, or by a logic module or software capable of implementing all or part of the functions of the session management device. This application does not limit the scope of the method. For ease of understanding and explanation, the method will be described below using a session management device as an example.
[0057] For example, the method includes: receiving a third request from an access management device, the third request being used to request the establishment of a session for a terminal device to send data through the non-terrestrial network, the third request including a data network name (DN name, DNN), the DNN being the name of the DN requested by the terminal device, and the access management device being located in the non-terrestrial network; if it is determined that the terminal device's permission to access the DN needs to be authenticated, sending a fourth request to the terminal device, the fourth request being used to request the acquisition of second authentication information, the second authentication information being used to authenticate the terminal device's permission to access the DN; receiving the second authentication information from the terminal device, the second authentication information being used to authenticate the terminal device's permission to access the DN; if no second authentication result is received, sending a second response to the terminal device, the second response being used to indicate that the session was successfully established; the second authentication result being used to indicate that the terminal device's permission to access the DN was successfully authenticated, or to indicate that the terminal device's permission to access the DN was unsuccessfully authenticated.
[0058] Based on this technical solution, when the session management device receives a third request carrying a DNN, it can proactively trigger the acquisition of DN authentication information. However, after obtaining the DN authentication information, the session management device does not wait for the DN authentication result but sends a session establishment success response to the terminal device. The terminal device can then send the session data. Compared to schemes where the session management device needs to receive the DN authentication result before continuing the session establishment process, the method provided in this application can effectively reduce the additional latency caused by waiting for the DN authentication result. Especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), the session management device does not need to wait for the DN authentication result, thus completing the session establishment process with a single link connection and sending uplink data, effectively reducing the transmission latency caused by waiting for the DN authentication result.
[0059] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: sending the second authentication information to the authentication server of the DN; receiving the second authentication result from the authentication server of the DN; and, if the second authentication result indicates that the terminal device has successfully authenticated its access to the DN, sending first indication information to a first user plane device, the first indication information being used to indicate sending the session data to the DN, the first user plane device being located in the non-terrestrial network.
[0060] Optionally, sending the second authentication information to the authentication server of the DN includes: sending the second authentication information to the authentication server of the DN through a second user plane device; or, sending the second authentication information to the authentication server of the DN through a second user plane device, a first forwarding device, and a second forwarding device.
[0061] Similarly, receiving a second authentication result from the authentication server of the DN includes: receiving the second authentication result from the authentication server of the DN through a second user plane device; or, receiving the second authentication result from the authentication server of the DN through a second user plane device, a first forwarding device, and a second forwarding device.
[0062] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the third request includes an identifier of the first network slice and information indicating that the authentication status of the first network slice is pending authentication; the method further includes: receiving the authentication result of the first network slice from the access management device; sending the second authentication information to the authentication server of the DN; receiving the second authentication result from the authentication server of the DN; and, if the authentication result of the first network slice indicates that the first network slice has been successfully authenticated, and the second authentication result indicates that the terminal device has successfully authenticated its access to the DN, sending first indication information to the first user plane device, the first indication information being used to indicate sending the session data to the DN, the first user plane device being located in the non-terrestrial network.
[0063] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: sending a second indication message to the first user plane device, the second indication message indicating that the session data be cached. This allows the first user plane device to cache data before successful network slice authentication, and then transmit the data after successful authentication when the power supply link is connected.
[0064] Optionally, the second instruction information can be carried in the N4 message.
[0065] Optionally, the second instruction information may be sent before the second response.
[0066] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the third request includes the identifier of the first network slice and the external identifier of the terminal device; the method further includes: sending the identifier of the first network slice, the second authentication information, the external identifier of the terminal device, and the address information of the uplink data of the terminal device to the first forwarding device, wherein the first forwarding unit is located in the non-terrestrial network.
[0067] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: determining that the terminal device accesses the non-terrestrial network, wherein network elements for implementing access procedures and session establishment procedures are deployed in the non-terrestrial network; and / or determining that the uplink or downlink communication of the terminal device is performed in store-and-forward mode.
[0068] Based on this, when the session management device determines that the terminal device is accessing a non-terrestrial network and / or determines that the terminal device is conducting uplink or downlink communication in store-and-forward mode, it can enable the terminal device to continue the subsequent session process without waiting for the authentication result of the DN when the DN requested for access needs to be authenticated, thus effectively reducing the transmission delay caused by waiting for the authentication result of the DN.
[0069] Fifthly, this application provides a communication method that can be applied to a terminal device, or implemented by a component (such as a chip, chip system, etc.) configured in the terminal device, or by a logic module or software capable of implementing all or part of the functions of the terminal device; this application does not limit this. For ease of understanding and explanation, the method is described below using a terminal device as an example.
[0070] For example, the method includes: sending a first request to an access management device, the first request being for requesting access to a non-terrestrial network, the first request including identifiers of one or more network slices requested by a terminal device, the access management device being located in the non-terrestrial network; receiving a second request from the access management device if, among the one or more network slices, there is at least one network slice with a slice authentication status of pending authentication, the second request being for requesting first authentication information, the first authentication information being used to authenticate the terminal device's permission to use the at least one network slice; determining a slice authentication mechanism for authenticating the at least one network slice, the slice authentication mechanism being a slice authentication mechanism in which a slice authentication server prioritizes authenticating the terminal device; determining the first authentication information based on the slice authentication mechanism of the at least one network slice; and sending the first authentication information to the access management device.
[0071] Based on this technical solution, the terminal device sends a first request carrying the identifiers of one or more network slices to the access management device. If, among the one or more network slices, at least one network slice is in a pending authentication state, the terminal device receives a second request from the access management device to obtain the first authentication information. Then, based on the second request, the terminal device determines the slice authentication mechanism of at least one network slice without needing to obtain the slice authentication mechanism through a terrestrial network slice authentication server. Therefore, the method provided in this application can effectively reduce the additional latency caused by waiting to obtain the slice authentication mechanism, especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), where the terminal device does not need to wait for the slice authentication mechanism from a terrestrial network slice authentication server, effectively reducing the uplink data transmission latency.
[0072] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the slice authentication mechanism may be one of the following: an extensible authentication protocol based on transport layer security (EAP-TLS), an extensible authentication protocol based on password (EAP-PWD), or an extensible authentication protocol based on pre-shared key (EAP-PSK).
[0073] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the second request includes at least one freshness parameter, which is used by the terminal device to determine the first authentication information.
[0074] It can be understood that when there are multiple network slices, the at least one freshness parameter corresponds one-to-one with the at least one network slice.
[0075] For example, at least one freshness parameter can be at least one random number.
[0076] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the method further includes: receiving a first response from the access management device, the first response indicating permission for the terminal device to use the at least one network slice; sending a session request to the access management device, the session request requesting the establishment of a session for the terminal device to send data through the non-terrestrial network, the session request including an identifier of a first network slice, the at least one network slice including the first network slice.
[0077] Based on this, after obtaining the authentication information of at least one network slice whose authentication status is pending, the access management device does not wait for the authentication result of the network slice obtained through the authentication information, but directly instructs the terminal device to allow the use of the at least one network slice. In this way, the terminal device can initiate a session request carrying the first network slice of the at least one network slice. Since it does not need to wait for the authentication result of the network slice, in store-and-forward mode, the terminal device can complete the session establishment process and send uplink data with a single link connection, effectively reducing the transmission latency caused by waiting for the authentication result of the network slice.
[0078] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the method further includes: receiving a session response from the access management device in the absence of receiving the authentication result of the first network slice, the session response being used to indicate that the session was successfully established; and using the session to send uplink data.
[0079] Optionally, the third request includes a DNN, where the DNN is the name of the DN requested by the terminal device.
[0080] In conjunction with the fifth aspect, in some implementations of the fifth aspect, after sending a session request to the access management device, the method further includes: if the authentication result of the first network slice is not received, receiving a fourth request from the session management device, the fourth request being used to request second authentication information, the second authentication information being used to authenticate the terminal device's access permission to the DN; determining a DN authentication mechanism for authenticating the DN, the DN authentication mechanism being a DN authentication server-priority authentication mechanism for the terminal device; determining the second authentication information according to the DN authentication mechanism; sending the second authentication information to the session management device; if the authentication result of the DN is not received, receiving a session response from the access management device, the session response being used to indicate that the session was successfully established; and using the session to send uplink data.
[0081] Based on this, after obtaining the authentication information of the DN, the session management device does not wait for the authentication result of the DN obtained through the authentication information, but directly instructs the terminal device that the session request has been successfully established. Thus, the terminal device can send the session data without waiting for the authentication result of the DN. Therefore, in store-and-forward mode, the terminal device can complete the session establishment process and send uplink data with only one link connection, effectively reducing the transmission latency caused by waiting for the authentication result of the network slice.
[0082] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the DN authentication mechanism is one of the following: EAP-TLS, EAP-PWD, or EAP-PSK.
[0083] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the method further includes: determining access to a non-terrestrial network, wherein network elements are deployed in the non-terrestrial network for implementing access procedures and session establishment procedures; and / or determining uplink or downlink communication in store-and-forward mode.
[0084] Sixthly, this application provides a communication method that can be applied to a terminal device, or implemented by a component (such as a chip, chip system, etc.) configured in the terminal device, or by a logic module or software capable of implementing all or part of the functions of the terminal device; this application does not limit this. For ease of understanding and explanation, the method is described below using a terminal device as an example.
[0085] For example, the method includes: sending a session request to an access management device, the session request being used to request a terminal device to establish a session for sending data via a non-terrestrial network, the session request including a Data Name Node (DN), the DNN being the name of a DN requested by the terminal device, the access management device being located in the non-terrestrial network; receiving a fourth request from the session management device, the fourth request being used to request second authentication information, the second authentication information being used to authenticate the terminal device's permission to access the DN (also referred to as the DN selected for the terminal device); determining a mechanism for authenticating the DN, the DN authentication mechanism being an authentication mechanism whereby a DN authentication server prioritizes authenticating the terminal device; determining the second authentication information based on the DN mechanism; sending the second authentication information to the session management device; and, if no authentication result of the DN is received, receiving a session response from the access management device, the session response being used to indicate that the session was successfully established.
[0086] Based on this technical solution, the terminal device sends a session request carrying the DNN to the access management device. If the DN access requested by the terminal device requires authentication, the terminal device receives a fourth request from the session management device to obtain second authentication information. Then, based on this fourth request, the terminal device determines the DN authentication mechanism without needing to obtain the DN authentication mechanism through a ground-based DN authentication server. Therefore, the method provided in this application can effectively reduce the additional latency caused by waiting for the DN authentication mechanism, especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), where the terminal device does not need to wait for the DN authentication mechanism from a ground-based DN authentication server, effectively reducing the uplink data transmission latency.
[0087] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the DN authentication mechanism is one of the following: EAP-TLS, EAP-PWD, or EAP-PSK.
[0088] Optionally, the method further includes: sending uplink data using the session.
[0089] In conjunction with the sixth aspect, in some implementations of the sixth aspect, before sending a session request to the access management device, the method further includes: determining access to the non-terrestrial network, wherein network elements are deployed in the non-terrestrial network to implement the access procedure and the session establishment procedure; and / or determining uplink or downlink communication in store-and-forward mode.
[0090] In a seventh aspect, this application provides a communication device, including modules or units for implementing the methods of any of the above aspects and any possible implementations of any of the above aspects. It should be understood that each module or unit can implement its corresponding function by executing a computer program.
[0091] Eighthly, this application provides a communication device including a processor, the processor being configured to perform the methods described in any of the foregoing aspects and any possible implementations of any of the foregoing aspects.
[0092] The apparatus may further include a memory for storing instructions and data. The memory is coupled to the processor, which, when executing the instructions stored in the memory, can implement the methods described in the foregoing aspects.
[0093] The device may also include a communication interface for communicating with other devices. For example, the communication interface may be a transceiver, circuit, bus, module or other type of communication interface.
[0094] Ninthly, this application provides a chip system including at least one processor for supporting the implementation of the functions involved in any of the above aspects and any possible implementations of any of the above aspects, such as receiving or processing data and / or information involved in the above methods.
[0095] In one possible design, the chip system also includes a memory for storing program instructions and data, which may be located within or outside the processor.
[0096] The chip system can consist of chips or include chips and other discrete components.
[0097] In a tenth aspect, this application provides a computer-readable storage medium including a computer program that, when run on a computer, causes the computer to implement the methods in any of the foregoing aspects and any possible implementations of any of the foregoing aspects.
[0098] In one aspect, this application provides a computer program product comprising: a computer program (also referred to as code or instructions) that, when run, causes a computer to perform the methods described in any of the above aspects and any possible implementations of any of the above aspects.
[0099] In a twelfth aspect, this application provides a communication system including the aforementioned access management device and terminal device. The access management device is used to implement the method of the first aspect and any possible implementation thereof; the terminal device is used to send a first request to the access management device and receive a first response from the access management device.
[0100] Optionally, the communication system may also include the aforementioned terminal device, which is used to perform the methods in the fifth aspect and any possible implementation thereof.
[0101] Optionally, the communication system may further include the aforementioned first forwarding device, which is used to implement the methods in the second aspect and any possible implementation of the second aspect.
[0102] Optionally, the communication system may further include the aforementioned session management device, which is used to implement the methods in the fourth aspect and any possible implementation of the fourth aspect.
[0103] Optionally, the communication system may also include the aforementioned first user plane equipment.
[0104] In a thirteenth aspect, this application provides a communication system including the aforementioned first forwarding device and access management device. The first forwarding device is used to implement the methods in the second aspect and any possible implementation thereof; the access management device is used to send to the first forwarding device at least one authentication information corresponding to at least one network slice, and an external identifier of the terminal device.
[0105] Optionally, the access management device is also used to implement the methods in the first aspect and any possible implementation of the first aspect.
[0106] Optionally, the communication system may also include the aforementioned terminal device, which is used to perform the methods in the fifth aspect and any possible implementation thereof.
[0107] Optionally, the communication system may also include the aforementioned first user plane equipment.
[0108] In a fourteenth aspect, this application provides a communication system including the aforementioned first forwarding device and session management device. The first forwarding device is used to implement the methods in the third aspect and any possible implementation thereof; the session management device is used to send second authentication information and address information of the uplink data of the terminal device to the first forwarding device.
[0109] Optionally, the session management device is also used to implement the methods in the fourth aspect and any possible implementation of the fourth aspect.
[0110] Optionally, the communication system may also include the aforementioned terminal device, which is used to perform the methods in the sixth aspect and any possible implementation thereof.
[0111] Optionally, the communication system may also include the aforementioned first user plane equipment.
[0112] It should be understood that aspects seven to fourteen of this application correspond to the technical solutions of aspects one to six of this application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be repeated here. Attached Figure Description
[0113] Figure 1 is a schematic diagram of the network architecture of the service-based architecture (SBA) in the fifth-generation (5G) network provided in the embodiments of this application;
[0114] Figure 2 is a schematic diagram of the regeneration network architecture applicable to the method provided in the embodiments of this application;
[0115] Figure 3 is a schematic diagram of a communication scenario where the power supply link is discontinuous, as provided in an embodiment of this application.
[0116] Figure 4 is a schematic flowchart of a communication method in a discontinuous power supply link scenario provided in an embodiment of this application;
[0117] Figures 5 to 9 are schematic flowcharts of the communication method provided in the embodiments of this application;
[0118] Figure 10 is a schematic block diagram of the device provided in an embodiment of this application;
[0119] Figure 11 is another schematic block diagram of the device provided in the embodiments of this application. Detailed Implementation
[0120] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0121] To facilitate understanding of the embodiments of this application, the following points are explained first:
[0122] First, in the embodiments of this application, the use of prefixes such as "first" and "second" is merely for the purpose of distinguishing and describing different things belonging to the same name category, and does not constrain the order, size, or quantity of things. For example, "first forwarding device" and "second forwarding device" are simply different forwarding devices, and do not limit the number of devices or their priority relationship; as another example, "second request" and "third request" are simply different requests, and there is no temporal sequence, size relationship, or priority relationship between them.
[0123] Second, in the embodiments of this application, "send" and "receive" indicate the direction of signal transmission. For example, "send the second authentication information to the authentication server of the DN" can be understood as the destination of the information being the authentication server of the DN, and "receive the first authentication information of the first network slice from the authentication server of the first network slice" can be understood as the source of the information being the authentication server of the first network slice. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface.
[0124] In other words, sending and receiving can occur between devices, such as between a terminal device and an access management device; or they can occur within a device, such as between components, modules, chips, software modules, or hardware modules within a device via a bus, wiring, or interface.
[0125] It is understandable that information may undergo necessary processing, such as encoding and modulation, before being sent from the source to the destination. Similarly, the destination, upon receiving information from the source, can also perform corresponding processing, such as decoding and demodulation, to interpret the valid information from the source. Similar expressions in this application can be understood in a similar way and will not be elaborated further.
[0126] Third, in the embodiments of this application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates an "or" relationship between the preceding and following related objects, but it does not exclude the possibility of indicating an "and" relationship. The specific meaning can be understood in conjunction with the context. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c; a and b; a and c; b and c; or a and b and c. Here, a, b, and c can be single or multiple.
[0127] Fourth, in the embodiments of this application, "instruction" can include direct instruction and indirect instruction, as well as explicit instruction and implicit instruction. The information indicated by a certain piece of information (such as the first instruction information and the second instruction information described below) is called the information to be instructed. In the specific implementation process, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. It can also indirectly indicate the information to be instructed by indicating other information, where there is a correlation between the other information and the information to be instructed; or it can only indicate a part of the information to be instructed, while the other parts of the information to be indicated are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol predefined) arrangement order of various pieces of information, thereby reducing the instruction overhead to a certain extent. This application does not limit the specific method of instruction.
[0128] It is understandable that, for the sender of the instruction information, the instruction information can be used to indicate the information to be indicated, and for the receiver of the instruction information, the instruction information can be used to determine the information to be indicated.
[0129] Fifth, in the embodiments of this application, descriptions such as "when," "under the circumstances," "if," and "if" all refer to the fact that the device (e.g., network device or terminal device) will make corresponding processing under certain objective circumstances. They are not time limits, nor do they require the device (e.g., network device or terminal device) to make a judgment action when implementing it, nor do they mean that there are other limitations.
[0130] Sixth, the tables in the embodiments of this application are merely examples. The values of the information in each table are only examples and can be configured to other values; this application is not limited thereto. The tables do not limit the scope of protection of this application. For example, appropriate modifications and adjustments can be made based on the tables described above, such as splitting, merging, etc. Furthermore, the parameter names shown in the headings of each table can also use other names understandable to the communication device, and the values or representations of the parameters can also be other values or representations understandable to the communication device. Moreover, in the implementation of the above tables, other data structures can also be used, such as arrays, queues, containers, stacks, linear lists, pointers, linked lists, trees, graphs, structures, classes, heaps, hash tables, or hash tables, etc.
[0131] Seventh, the cache and storage involved in this application can refer to storage in one or more memory devices. These one or more memory devices can be separately configured or integrated into an encoder or decoder, processor, or communication device. Alternatively, some of the memory devices can be separately configured, while others can be integrated into the decoder, processor, or communication device. The type of memory can be any form of storage medium, and this application is not limited to this.
[0132] The technical solutions provided in this application can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Worldwide Interoperability for Microwave Access (WiMAX) communication systems, 5th Generation (5G) mobile communication systems or new radio access technology (NR), satellite communication systems, etc. Among them, 5G mobile communication systems can include non-standalone (NSA) and / or standalone (SA) networking.
[0133] The technical solution provided in this application can also be applied to future communication networks.
[0134] For ease of understanding, the network architecture applicable to the methods provided in the embodiments of this application will first be described with reference to the accompanying drawings.
[0135] Figure 1 is a schematic diagram of the SBA network architecture in a 5G network provided in an embodiment of this application. As shown in Figure 1, the 5G network architecture can include three parts: the terminal, the data network (DN), and the operator network.
[0136] The following is a brief explanation of the network elements involved in Figure 1.
[0137] 1. Terminal equipment, also known as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent, or user device.
[0138] A terminal device is a device with wireless transceiver capabilities. A terminal device can communicate with one or more core network (CN) devices (or core equipment) via access network equipment (or access devices) in a wireless access network. Terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water (such as on ships); and they can also be deployed in the air (e.g., on airplanes, balloons, and satellites).
[0139] Terminal devices can also be terminals in an Internet of Things (IoT) system, also known as IoT nodes. IoT is an important component of future information technology development. Its main technical characteristic is connecting objects to networks via communication technologies, thereby realizing an intelligent network that enables human-machine interaction and machine-to-machine interaction. Connections can be made through broadband or narrowband (NB) technologies. IoT technology, for example, can achieve massive connectivity, deep coverage, and low power consumption at the terminal level through narrowband technology.
[0140] The terminal device in this application can be a hardware device, a software function running on dedicated hardware, or a software function running on general-purpose hardware. It can also be a virtualized device, for example, implemented through general-purpose hardware and instantiated virtualization functions, or dedicated hardware and instantiated virtualization functions. Among them, the general-purpose hardware can be a server, such as a cloud server.
[0141] 2. An operator's network may include one or more of the following network elements: network slice selection function (NSSF) network elements, network exposure function (NEF) network elements, network repository function (NRF) network elements, policy control function (PCF) network elements, unified data management (UDM) network elements, application function (AF) network elements, authentication server function (AUSF) network elements, access and mobility management function (AMF) network elements, network slice-specific authentication and authorization function (NSSAAF) network elements, session management function (SMF) network elements, user plane function (UPF) network elements, and access network (AN) (such as RAN network elements), etc. The portion of the above operator's network excluding AN network elements can be referred to as the core network portion. For ease of explanation, the term "network element" will be omitted in the following text. For example, AMF network element is abbreviated as AMF, SMF network element as SMF, UPF network element as UPF, and so on.
[0142] The RAN (Radio Access Registry) is a network composed of one or more RAN nodes, used to implement radio physical layer functions, resource scheduling and radio resource management, radio access control, and mobility management functions. 5G-RAN connects to the user plane function (UPF) via the user plane interface N3 to transmit terminal data; it also establishes a control plane signaling connection with the access and mobility management function (AMF) via the control plane interface N2 to implement functions such as radio access bearer control.
[0143] RAN nodes provide wireless communication services, enabling terminal devices to connect to the wireless network. RAN nodes can also be called RAN devices or access network devices, etc.
[0144] In one possible scenario, a RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation NodeB (gNB), or a base station in a future mobile communication system. A RAN node can be a macro base station, a micro base station, an indoor station, a relay node, a donor node, or a radio controller in a cloud radio access network (CRAN) scenario, or a node in an open radio access network (O-RAN or ORAN) scenario. A RAN node can also be a RAN node in a non-terrestrial network (NTN), meaning the RAN node can be deployed on a high-altitude platform or a satellite. Optionally, a RAN node can also be a server.
[0145] In another possible scenario, multiple RAN nodes collaborate to assist the terminal in achieving wireless access, with each RAN node performing a portion of the base station's functions. For example, RAN nodes can be central units (CUs), distributed units (DUs), CU-control plane (CPs), CU-user plane (UPs), or radio units (RUs), etc. CUs and DUs can be separate entities or included in the same network element, such as a baseband unit (BBU). RUs can be included in radio frequency equipment or radio frequency units, such as remote radio units (RRUs), active antenna units (AAUs), or remote radio heads (RRHs).
[0146] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an open access network (open RAN, O-RAN, or ORAN) system, CU can also be called an open CU (O-CU), DU can also be called an O-DU, CU-CP can also be called an O-CU-CP, CU-UP can also be called an O-CU-UP, and RU can also be called an O-RU. Any of the units among CU (or CU-CP, CU-UP), DU, and RU can be implemented through software modules, hardware modules, or a combination of software and hardware modules.
[0147] The AMF is primarily responsible for terminal authentication, terminal mobility management (MM), network slice selection, and SMF selection; it serves as the anchor point for N1 and N2 signaling connections and provides routing for N1 / N2 session management (SM) messages to the SMF; and it maintains and manages the terminal's state information.
[0148] SMF is primarily responsible for all control plane functions of terminal session management, including UPF selection, Internet Protocol (IP) address allocation, session quality of service (QoS) management, and obtaining PCC (policy and charging control) policies (from PCF).
[0149] UPF serves as the anchor point for protocol data unit (PDU) session connections, and is responsible for filtering terminal data packets, data transmission / forwarding, rate control, and generating billing information.
[0150] UDR is primarily used to store user data, including subscription data invoked by UDM, policy information invoked by PCF, structured data used for capability exposure, and application data invoked by NEF.
[0151] UDM is mainly used to manage user data, such as the management of subscription information, including obtaining subscription information from UDR and providing it to other network elements (such as AMF); generating 3GPP authentication credentials for terminals; and registering and maintaining the network elements currently serving the terminal (for example, the AMF represented by AMF ID1 is the current serving AMF of the terminal).
[0152] NEF is used to connect other internal network elements of the core network with the application function (AF) network elements corresponding to the external application server (AS) of the core network, so as to provide network open capabilities to the AF, or provide information provided by the AF to the core network elements.
[0153] The AUSF authentication server function is used to perform security authentication on terminals when they access the network.
[0154] PCF primarily controls Quality of Service (QoS) policies and charging policies. It provides configuration policy information to terminals and management policy information to network control plane elements (such as AMF and SMF) for managing terminals.
[0155] The Application Provider (AF) primarily conveys the application's requests to the network and can be considered an application server or its proxy. The AF can interact with core network elements to provide services; for example, it can interact with the Process Control Function (PCF) for service policy control, interact with the Network Provider Function (NEF) to obtain network capability information or provide application information to the network, and provide data network access point information to the PCF to generate routing information for corresponding data services.
[0156] NSSAAF interacts with AMF or slice authentication servers to handle authentication and authorization for network slices.
[0157] Secondary authentication UPF is a network element used to perform the secondary authentication process.
[0158] DN primarily provides business services to users.
[0159] Network elements communicate with each other through interfaces. For example, the interface between the terminal and the AMF is interface N1, the interface between the AN and the AMF is interface N2, the interface between the AN and the UPF is interface N3, the interface between the SMF and the UPF is interface N4, and the interface between the UPF and the DN is interface N6. Some network elements can communicate based on service-oriented interfaces. Among them, Nnssf, Nnef, Nnrf, Npcf, Nudm, Naf, Nausf, Namf, and Nsmf in Figure 1 are service-oriented interfaces based on services.
[0160] The above description of the various network elements in the core network and the interfaces between them is merely illustrative and should not constitute any limitation on this application. Furthermore, the various network elements shown in Figure 1 can be understood as network elements in the core network used to implement different functions. These core network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the aforementioned network elements.
[0161] It is understood that the network elements used in future communication systems may be any of the aforementioned network elements, or network elements with the same or similar functions under other names; this application does not limit this.
[0162] The following section uses a 5G network as an example, and with reference to Figure 2, introduces the regenerative network architecture defined in a non-terrestrial network (NTN) system. It can be understood that this regenerative network architecture can be applied to different networks.
[0163] Figure 2 is a schematic diagram of the regeneration network architecture applicable to the method provided in the embodiments of this application. In the regeneration relay architecture, the satellite can process the received signals, including demodulation, decoding, encoding, modulation, and information processing; that is, the satellite has all the functions of the RAN nodes (or, in other words, the RAN nodes in Figure 1 are deployed on the satellite). As shown in Figure 2, the terminal device communicates with the satellite base station, and the satellite base station communicates with the core network through the gateway station. The link between the terminal and the satellite is a service link, and the link between the gateway station and the satellite is a feeder link.
[0164] In the communication scenario shown in Figure 2, satellite movement may result in either a service link being connected but a feeder link being disconnected, or a feeder link being connected but a service link being disconnected. As shown in Figure 3, when the satellite moves to position 1, the service link is connected but the feeder link is disconnected; when the satellite moves to position 2, both the service link and the feeder link are disconnected; when the satellite moves to position 3, the feeder link is connected but the service link is disconnected. In other words, in a regenerable repeater satellite architecture, the service link and / or the feeder link may not be available at all times.
[0165] In this discontinuous power supply scenario, for uplink (UL), when a terminal device connects to a regenerator-forward satellite (i.e., the service link is connected), if the power supply link is unavailable, the satellite needs to store the UL information from the terminal device. When the power supply link becomes available, the satellite forwards the stored UL information to the core network. For downlink (DL), the terrestrial network sends DL information to the regenerator-forward satellite (i.e., the power supply link is connected). If the service link is unavailable at this time, the regenerator-forward satellite needs to store the DL information from the terrestrial network. When the service link between the terminal device and the regenerator-forward satellite becomes available, the satellite forwards the stored DL information to the terminal device. In this discontinuous power supply scenario, the satellite's operating mode can be called store-and-forward (S&F) satellite operation mode.
[0166] In summary, in scenarios with discontinuous power supply, only one link between the service link and the power supply link is connected, requiring the use of a store-and-forward operating mode to achieve information transmission between the terminal and the terrestrial network. The S&F satellite operating mode can be used for services with high latency tolerance or non-real-time transmission, such as cellular internet of things (CIoT) / machine type communication (MTC), and short message service (SMS).
[0167] Based on the architecture shown in Figures 1 and 2 above, for uplink, the terminal device needs to complete an access process (e.g., registration) and a session establishment process (e.g., protocol data unit (PDU) session establishment) before sending UL information to the network. Therefore, the time required for the registration and session establishment processes will affect the transmission latency of uplink information.
[0168] In the 5G process, the registration process of a terminal device requires the participation of AMF, AUSF, and UDM in the core network. The establishment of a PDU session also requires the participation of AMF, SMF, and UDM in the core network. Furthermore, the subsequent transmission of UL information and reception of DL information by the terminal device require the participation of UPF network elements in the core network. For the architecture shown in Figure 1, when the RAN node acts as the RAN node in the terrestrial network, the store-and-forward working mode described above does not exist. Therefore, the terminal device can complete access and session establishment relatively quickly without waiting for the service link and / or feeder link to connect, and then send uplink data. However, for the architecture shown in Figure 2, the access process and session establishment process require multiple connections of the service link and the feeder link to complete, which leads to increased transmission latency of UL information.
[0169] To improve the efficiency of the store-and-forward operating mode, it is considered to deploy the entire core network to the satellite, enabling terminal devices and satellites to complete the registration and PDU session establishment process during a single service link connection, allowing the terminal devices to send UL information. The deployed core network elements can include those participating in the registration and PDU session processes, such as AMF, AUSF, UDM, and SMF elements.
[0170] The overall solution for core network uplink can be either a process of terminal equipment accessing the core network and establishing a session between the terminal equipment and the core network, or it can involve introducing an on-board store-and-forward proxy (SSFP) and a ground-based store-and-forward client (SSFC), with the SSFC responsible for routing the data sent from the satellite to the ground.
[0171] The following is a brief introduction to the SSFP and SSFC scheme with reference to Figure 4. As shown in Figure 4, the service link is connected at time T1. The terminal device can access the satellite and send uplink data at time T1. The SSFP on the satellite caches the uplink data and network access information, where the network access information is used by the ground SSFC to determine how to send the uplink data. At time T2, the feeder link is connected. The SSFP on the satellite interfaces with the ground SSFC and sends the previously stored uplink data and network access information to the SSFC. After obtaining the network access information and uplink data, the SSFC, based on the network access information, performs a session establishment procedure with the ground network as the terminal device and uses the established session to send the uplink data to the DN.
[0172] The purpose of using SSFC as a terminal device to establish a session with the terrestrial network based on network access information to send uplink data is as follows: Under the assumptions of the 3rd Generation Partnership Project (3GPP), data packet routing information alone does not guarantee data delivery to the DN (e.g., in some private networks). The role of the 3GPP network is to select a specific user plane device by establishing a session. This user plane device can then establish a link with the DN requested in the session to send data. Therefore, the above scheme can establish a connection to the DN and send data while reusing the registration and session establishment procedures defined by 3GPP as much as possible.
[0173] It should be noted that the aforementioned terminal device access to satellite and SSFC access to terrestrial network may include the attachment and session establishment process in LTE network or the registration and session establishment process in 5G network. The standard corresponding to the terminal device access to satellite and the SSFC access to terrestrial network must be consistent. For example, both are 5G processes or both are LTE processes.
[0174] The user access control in standard technical specification (TS) 33.501 is divided into primary authentication based on the Universal Subscriber Identity Module (USIM) and authentication based on user identity (ID). The user ID-based authentication process can be either network slice-specific authentication and authorization (NSSAA) or secondary authentication. USIM-based primary authentication and user ID-based authentication respectively use cryptographic methods to authenticate the authenticity of the subscription permanent identifier (SUPI) and the user ID. Slice authentication refers to the authentication of the terminal device's permission to use network slices, as described below; secondary authentication refers to the authentication of the terminal device's permission to access the DN, as described below.
[0175] Slice authentication is used to authenticate terminal devices requesting access to a specific network slice, ensuring access control for that slice. For example, the terminal device includes single network slice selection assistance information (S-NSSAI) in its registration request. The AMF determines whether the requested network slice requires slice authentication. If so, the AMF indicates the slice as pending S-NSSAI in the registration success message. After the network side performs the authentication process with the terminal device, a PDU session is established only if slice authentication is successful. During slice authentication, a network slice authentication, authorization, and accounting (NS-AAA) server deployed outside the core network is responsible for cryptographically verifying the User ID provided by the terminal device for slice authentication.
[0176] Specifically, the pending S-NSSAI sent by the AMF includes the network slices requiring slice authentication in the pending S-NSSAI list. After receiving the pending S-NSSAI, if the terminal device wants to use a network slice in this list to initiate a session, it must first pass slice authentication for that network slice. Then, the AMF will send the allowed S-NSSAI list to the terminal device, after which the terminal device can use the slice in the list to initiate a session.
[0177] Two-factor authentication is used to authenticate terminal devices requesting access to a specific DN, ensuring access control for that DN. Specifically, the terminal device carries the requested DN during the PDU session establishment process. The SMF, based on information in the UDM indicating that two-factor authentication is required for that DN in the terminal device's subscription, triggers two-factor authentication and executes the two-factor authentication process with the terminal device during the PDU session establishment. A data network authentication, authorization, and accounting (DN-AAA) server, deployed outside the core network, is responsible for cryptographically verifying the User ID provided by the terminal device for two-factor authentication. Upon successful two-factor authentication, a session establishment success response is sent to the terminal device, which then uses this session to send data.
[0178] It should be noted that slice authentication for terminal devices using specific slices and secondary authentication for terminal devices accessing specific DNs are not necessarily executed. For example, whether slice authentication is executed depends on the AMF local policy configuration of the serving terminal device in the serving network, while whether secondary authentication is executed depends on the terminal device's subscription for that DN.
[0179] Since the slice authentication process occurs before the session establishment process, it adds extra uplink data transmission latency. Similarly, the secondary authentication process requires interrupting the session establishment process, thus also increasing uplink data transmission latency. As described above, slice authentication and secondary authentication require different AAA servers for verification, and these AAA servers are located in the terrestrial network. Therefore, compared to the traditional terrestrial network architecture, in the non-terrestrial network shown in Figure 2, the slice authentication process and / or secondary authentication process require multiple service link connections and multiple power supply link connections to complete, which significantly increases uplink data transmission latency.
[0180] The following illustrates the potential number of connections required between the service link and the feeder link in a store-and-forward mode scenario where slice authentication and secondary authentication are needed: First, the service link connects for the first time, the terminal device completes the registration process, and the AMF initiates the slice authentication process; the feeder link connects for the first time, and the AMF obtains the slice authentication result from the NS-AAA server; the service link connects for the second time, and after the terminal device obtains the network slice authentication result from the AMF, it initiates a session establishment process. Then, the SMF triggers the secondary authentication process; the feeder link connects for the second time, and the SMF obtains the secondary authentication result from the DN-AAA server; the service link connects for the third time, the terminal device obtains the secondary authentication result from the SMF, completes the session establishment, and sends uplink data to the UPF; the feeder link connects for the third time, and the UPF sends the received uplink data to the DN.
[0181] Therefore, it can be concluded that because slice authentication and / or secondary authentication require the participation of AAA servers (including NS-AAA and DN-AAA) located outside the core network, and neither NS-AAA nor DN-AAA belongs to the operator (NS-AAA is deployed by the slice owner, and DN-AAA is deployed by the DN), it is difficult to deploy AAA servers on satellite. In other words, under S&F operating mode, even if the entire core network is on-board, ensuring that the terminal device and satellite can complete the registration and PDU session establishment process solely through a service link connection, the need for slice authentication and / or secondary authentication may prevent the terminal device from completing the registration and PDU session establishment process and sending uplink data during a single service link connection, increasing uplink data transmission latency.
[0182] In view of this, embodiments of this application provide a communication method and related apparatus. In this method, when a single service link is established, the terminal device executes a process to access a non-terrestrial network. If a slice authentication process is required during this process, the access management device first obtains the authentication information of the network slice without waiting for the authentication result of the network slice. It directly indicates the network slices with a slice authentication status of pending authentication to the terminal device through the list of allowed slices, enabling the terminal device to initiate a session establishment process. And / or, if a secondary authentication process is required during session establishment, the session management network element first obtains the authentication information of the DN without waiting for the secondary authentication result and continues to execute the session establishment process. After successful session establishment, the terminal device sends uplink data to the user plane device, reducing latency. Furthermore, while waiting for the power supply link to connect, the session management network element or the first forwarding device obtains the slice authentication result and / or the secondary authentication result based on the authentication information of the network slice and / or the authentication information of the DN, and instructs the user plane device to send the cached uplink data based on the slice authentication result and / or the secondary authentication result. This method can complete the access process, session establishment process, and uplink data transmission during a single service link connection in scenarios that require slice authentication and / or secondary authentication, effectively reducing the uplink data transmission latency caused by the terminal device waiting for authentication results.
[0183] The communication method provided by the embodiments of this application is described in detail below with reference to Figures 5 to 9. The method provided by this application can be applied to the communication system shown in Figures 1 and 2, but the embodiments of this application are not limited thereto.
[0184] The flowcharts shown in Figures 5 to 9 illustrate the method from the perspective of device interaction, but this application does not limit the subject implementing the method. For example, the access management device in Figures 5 to 9 can be replaced by a chip, chip system, or processor that supports the implementation of the method by the access management device, or it can be a logic module or software that can implement all or part of the functions of the access management device; the session management device in Figures 5 to 9 can be replaced by a chip, chip system, or processor that supports the implementation of the method by the session management device, or it can be a logic module or software that can implement all or part of the functions of the session management device; the terminal device in Figures 5 to 9 can be replaced by a chip, chip system, or processor that supports the implementation of the method by the terminal device, or it can be a logic module or software that can implement all or part of the functions of the terminal device; the first user plane device in Figures 5 to 9 can be replaced by a chip, chip system, or processor that supports the implementation of the method by the first user plane device, or it can be a logic module or software that can implement all or part of the functions of the first user plane device.
[0185] For example, the access management device in Figures 5 to 9 can be an AMF, the session management device can be an SMF, and the first user plane device can be a UPF.
[0186] Figure 5 is a schematic flowchart of a communication method 500 provided in an embodiment of this application. As shown in Figure 5, the method 500 may include steps S501 to S515. The steps in method 500 are described in detail below.
[0187] S501, the terminal device sends a first request to the access management device. The first request is for requesting access to a non-terrestrial network, and the first request includes identifiers of one or more network slices requested by the terminal device. Correspondingly, the access management device receives the first request from the terminal device.
[0188] The access management device in this application is located in a non-terrestrial network. This non-terrestrial network can be any network other than the terrestrial network deployed by the mobile operator, such as a satellite network or a network deployed on a non-fixed platform. Examples of non-fixed platform networks include isolated operation for public safety (IOPS) networks, networks deployed in vehicles, networks deployed on low-altitude platforms, or networks deployed on ships. For instance, when the non-terrestrial network is a satellite, the access management device is deployed on a satellite; similarly, when the non-terrestrial network is an IOPS network, the access management device is deployed within that IOPS network.
[0189] For example, the first request may be a registration request or an attachment request, or other requests for requesting network access as defined in a future communication system. This application does not limit the name of the first request.
[0190] The network slices in this application are logical networks that provide specific network functions and characteristics. Network slices can be identified by S-NSSAI. Alternatively, the identifier for network slices in this application can be S-NSSAI.
[0191] Optionally, the aforementioned one or more network slices may include network slices that are allowed to be used by terminal devices (hereinafter referred to as the first type of network slice for ease of description), and / or may include network slices that are not allowed to be used by terminal devices (hereinafter referred to as the second type of network slice for ease of description). Specifically, network slices that are not allowed to be used by terminal devices refer to network slices that require authentication, while network slices that are allowed to be used by terminal devices refer to network slices that do not require authentication. Specifically, network slices that require authentication are defined as those that require authentication and / or authorization before a terminal device can access or use the network slice. Before the terminal device passes the authentication and / or authorization of the network slice, the terminal device's access status is a pending authentication state, or simply network slice pending authentication. Network slices that do not require authentication are defined as those that do not require authentication and / or authorization before a terminal device can access or use the network slice. The terminal device's access status can be referred to as an authenticated state or a state that does not require authentication, or simply network slice authenticated or not authenticated.
[0192] S502, in one or more network slices, including at least one network slice with a slice authentication status of pending authentication, the access management device sends a second request to the terminal device, the second request being used to request the acquisition of the first authentication information. Correspondingly, the terminal device receives the second request from the access management device.
[0193] For example, the first authentication information can be carried in a non-access stratum (NAS) message.
[0194] The first authentication information in this application is used to authenticate the terminal device's permission to use / access at least one network slice. This first authentication information includes authentication information for each of the at least one network slice; that is, the first authentication information includes at least one authentication information, and each at least one authentication information corresponds one-to-one with at least one network slice.
[0195] Optionally, when the access management device receives one or more network slices, it can classify the network slices according to their authentication status to obtain a first type of network slice and a second type of network slice. The identifier of the first type of network slice can be located in the list of slices to be authenticated on the access management device side, and the identifier of the second type of network slice can be located in the list of allowed slices on the access management device side.
[0196] S503, The terminal device determines a slice authentication mechanism for authenticating at least one network slice.
[0197] This slice authentication mechanism prioritizes the authentication of terminal devices by the slice authentication server.
[0198] For example, the slice authentication mechanism can be one of the following: Extensible Authentication Protocol – Transport Layer Security (EAP-TLS), Extensible Authentication Protocol – Password (EAP-PWD), or Extensible Authentication Protocol – Pre-Shared Key (EAP-PSK).
[0199] S504, The terminal device determines the first authentication information based on the slice authentication mechanism of at least one network slice.
[0200] S505, the terminal device sends the first authentication information to the access management device. Correspondingly, the access management device receives the first authentication information from the terminal device.
[0201] For example, the first authentication information can be carried in the NAS message.
[0202] Optionally, the method 500 further includes: the terminal device sending a mapping relationship between at least one network slice and at least one authentication information to the access management device. Correspondingly, the access management device receives the mapping relationship from the terminal device.
[0203] Since there may be multiple network slices, multiple authentication information can be obtained. Based on this correspondence, the access management device can determine the authentication information of each network slice in at least one network slice. This can effectively avoid the problem of the obtained authentication result not matching the network slice due to the authentication information not matching the network slice.
[0204] It is understandable that when the number of at least one network slice is 1, the terminal device does not need to send the mapping relationship.
[0205] This mapping relationship can be sent simultaneously with the first authentication information or sent separately. For example, the first authentication information may include this mapping relationship.
[0206] S506, if the access management device does not receive the first authentication result, it sends a first response to the terminal device, which indicates that the terminal device is allowed to use at least one network slice. Correspondingly, the terminal device receives the first response from the access management device.
[0207] For example, the first response may be sent in the form of a list of allowed slices, including at least one network slice. Optionally, when one or more network slices include network slices with an authentication status of authenticated or unauthenticated, the list of allowed slices may also include network slices with an authentication status of authenticated or unauthenticated.
[0208] After receiving a first response that sends at least one network slice in the form of a list of allowed slices, the terminal device can select the slice identifier of the first slice from the list of allowed slices and carry it in the session request. The specific implementation method can be found in the description in 3GPP technical specification (TS) 23.502, which will not be repeated here.
[0209] The first authentication result in this application is used to indicate that at least one network slice authentication was successful, or to indicate that at least one network slice authentication was unsuccessful (or, to indicate that at least one network slice authentication failed).
[0210] The first response here can be the response from the access management device to the first request. For example, if the first request is a registration accept request, the first response can be a registration accept message. However, this application is not limited to this. For example, there may be other messages between the first request and the first response, and these other messages can be responses to the first request.
[0211] Similar to the first authentication information, the first authentication result includes the authentication result of each network slice in at least one network slice. That is, the first authentication result includes at least one authentication result, which corresponds one-to-one with at least one network slice. Each authentication result in the first authentication result is used to indicate whether the authentication of its corresponding network slice was successful or unsuccessful.
[0212] In this embodiment, when the access management device receives a first request carrying the identifier of one or more network slices, it can proactively trigger the acquisition of authentication information for at least one network slice whose authentication status is pending. However, after obtaining the authentication information of the network slice, the access management device does not wait for the first authentication result of the first network slice, but instead indicates to the terminal device that at least one network slice is allowed for use by the terminal device. Then, the terminal device can initiate a session establishment process carrying the identifier of the first network slice in at least one network slice. Compared with the scheme where the terminal device needs to receive the authentication result of the first network slice before initiating the session establishment process, the method provided in this application can effectively reduce the additional latency caused by waiting for the authentication result of the network slice. Especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), the terminal device does not need to wait for the authentication result of the network slice from the terrestrial authentication server. Therefore, the session establishment can be completed during a single link connection, and then uplink data can be sent, effectively reducing the transmission latency of uplink data.
[0213] Optionally, the second request includes at least one freshness parameter used to determine the first authentication information. Further, when there are multiple network slices, the at least one freshness parameter corresponds one-to-one with each of the at least one network slice.
[0214] For example, at least one freshness parameter can be at least one random number.
[0215] Optionally, after S506, method 500 further includes: S507, whereby the terminal device sends a session request to the access management device, the session request being used to request the establishment of a session for the terminal device to transmit data over a non-terrestrial network. The session request includes an identifier of a first network slice. Correspondingly, the access management device receives the session request from the terminal device.
[0216] It is understandable that the session requested by this session request can also be used by the terminal device to receive data through a non-terrestrial network.
[0217] Since the first network slice can be any network slice in the list of allowed slices in the first response, and the list of allowed slices in the first response may include not only at least one network slice with a slice authentication status of pending authentication, but also network slices with a slice authentication status of allowed use, the slice authentication status of the first network slice may be pending authentication, authenticated, or not requiring authentication.
[0218] For example, if the authentication status of the first network slice is authenticated or does not require authentication, the access management device determines that it does not need to authenticate the terminal device's permission to use the first network slice. That is, when the authentication status of the first network slice is authenticated or does not require authentication, the access management device directly sends a third request to the session management device, which is used to request the establishment of the aforementioned session. Correspondingly, the session management device receives the third request from the access management device.
[0219] For example, if the slice authentication status of the first network slice is pending authentication, the access management device determines to authenticate the terminal device's permission to use the first network slice. However, in this application, method 500 further includes: S508, whereby the access management device may send a third request to the session management device if it has not received the authentication result of the first network slice. This third request is used to request the establishment of a session. This session is for the terminal device to send data through a non-terrestrial network. Correspondingly, the session management device receives the third request from the access management device.
[0220] The session management device is located in a non-terrestrial network, and the third request includes the identifier of the first network slice.
[0221] This method of executing subsequent session establishment procedures directly without waiting for the authentication result of the first network slice can effectively reduce the transmission latency caused by waiting for the authentication result of the network slice.
[0222] Optionally, if the authentication status of the first network slice is pending authentication, the third request may further include information indicating that the authentication status of the first network slice is pending authentication, and / or, the third request may include an external identifier of the terminal device. Optionally, the access management device may also indicate the information that the authentication status of the first network slice is pending authentication to the session management device through other information.
[0223] The external identifier of the terminal device is used to identify the terminal device outside the network, such as GPSI; or other information that can be used to identify the terminal device to distinguish different terminal devices. This application does not limit this. Furthermore, the external identifier of the terminal can also be used to identify the terminal device inside the network.
[0224] It is understandable that if the third request includes information indicating that the authentication status of the first network slice is pending authentication, then when the session management device receives the third request, it can determine that the terminal device's permission to use / access the first network slice needs to be authenticated, that is, the slice authentication status of the first network slice is pending authentication.
[0225] Optionally, the session request may also include a DNN, which is the name of the DN requested by the terminal device, or in other words, the DNN is the DN that the terminal device requests to access. Similarly, the second request may also include the DNN. Optionally, the above session request may also include an N1 session management container, and the second request may also include the N1 session management container.
[0226] Optionally, the method 500 further includes: S509, the session management device determines whether it is necessary to authenticate the terminal device's access permission to the DN based on the terminal device's subscription information.
[0227] The subscription information of the terminal device can be obtained by the session management device from the UDM.
[0228] Optionally, the method 500 further includes: when the session management device determines that the terminal device needs authentication to use the first network slice, and / or determines that the terminal device needs authentication to access the DN, the session management device sends a second indication message to the first user plane device, the second indication message indicating that the session data be cached. Here, the first user plane device is located in a non-terrestrial network; caching the session data means temporarily not sending the session data.
[0229] The data in the aforementioned session refers to the uplink data sent by the terminal device through the session request.
[0230] For example, the second instruction information can be carried in the N4 message.
[0231] Optionally, when it is determined that the terminal device's access permission to the DN needs to be authenticated, the method 500 may further include: S510, the session management device sends a fourth request to the terminal device, the fourth request being used to request the acquisition of second authentication information. Correspondingly, the terminal device receives the fourth request from the session management device.
[0232] The second authentication information in this application is used to authenticate the terminal device's access rights to the DN.
[0233] For example, the fourth request can be carried in a NAS message.
[0234] Optionally, the method 500 further includes: S511 and S512: S511, the terminal device determines the DN authentication mechanism used for DN authentication; S512, the terminal device determines second authentication information based on the DN authentication mechanism. The DN authentication mechanism can be one of the following: EAP-TLS, EAP-PWD, or EAP-PSK.
[0235] Optionally, the method 500 further includes: S513, the terminal device sends second authentication information to the session management device. Correspondingly, the session management device receives the second authentication information from the terminal device.
[0236] For example, the second authentication information can be carried in the NAS message.
[0237] Optionally, the method 500 further includes: S514, whereby the session management device sends a second response to the terminal device if it does not receive a second authentication result, the second response indicating that the session has been successfully established. Correspondingly, the terminal device receives the second response from the session management device.
[0238] The second authentication result is used to indicate that the terminal device's access to the DN is successfully authenticated, or to indicate that the terminal device's access to the DN is unsuccessful (or, to indicate that the terminal device's access to the DN has failed).
[0239] The second response here can be a response from the session management device to the third request. That is, the session successfully established as indicated in the third response is the session requested to be established in the third request.
[0240] Optionally, the method 500 further includes: S515, the access management device sends a session response to the terminal device, the session response indicating that the session has been successfully established. Correspondingly, the terminal device receives the session response from the access management device.
[0241] Optionally, after S515, the method 500 further includes: the access management device recording the session management device corresponding to the session. Specifically, the access management device maintains the correspondence between the identifier of the terminal device, the identifier of the first network slice, and the identifier of the session management device.
[0242] The session response can be the response made by the access management device to the session request. The second response mentioned above can be understood as the session response sent by the session management device to the terminal device through the access management device.
[0243] In this application, after obtaining the second authentication information, the session management device does not wait for the second authentication result obtained through the second authentication information, but directly sends a session establishment success response to the terminal device, so that the terminal device can send uplink data after receiving the session response, effectively reducing the transmission delay caused by waiting for the DN authentication result.
[0244] Optionally, the method 500 further includes: the terminal device sending first uplink data to the first user plane device. Correspondingly, the first user plane device receives the first uplink data from the terminal device.
[0245] The first uplink data can be uplink data sent by the terminal device through an established session.
[0246] Optionally, the method 500 further includes: the first user plane device caching the first uplink data according to the received second indication information.
[0247] Optionally, prior to S506, the method 500 further includes: the terminal device determining access to a non-terrestrial network; and / or determining whether to perform uplink or downlink communication in store-and-forward mode.
[0248] This non-terrestrial network deploys network elements used to implement access and session establishment procedures. Examples include AMF, SMF, or UDM networks.
[0249] The network elements that are currently in the access process and session establishment process; and / or, the terminal equipment determines whether to perform uplink or downlink communication in store-and-forward mode.
[0250] For example, the terminal device determines access to a non-terrestrial network by: the terminal device receiving broadcast information from a RAN node on a satellite, the broadcast information indicating that the access method is satellite access; and the terminal device determining access to the non-terrestrial network based on the broadcast information.
[0251] Among them, satellite access can be used by terminal equipment to perceive that the RAN node and its corresponding core network are on a satellite rather than a terrestrial network.
[0252] Optionally, the broadcast information can also be used to indicate that the satellite is operating in store-and-forward mode. In this way, the terminal device can determine whether to perform uplink or downlink communication in store-and-forward mode based on the broadcast information.
[0253] For example, the broadcast information mentioned above can carry a specific identifier to indicate the access method and uplink / downlink communication method of the terminal device. This identifier can be a specific network identifier, such as a satellite ID.
[0254] Optionally, prior to S506, the method 500 further includes: the access management device determining that the terminal device accesses a non-terrestrial network; and / or determining whether to forward the uplink or downlink communication of the terminal device in store-and-forward mode.
[0255] In one implementation, the access management device can determine whether it is deployed in a non-terrestrial network based on its local configuration. Therefore, when it receives an access request from a terminal device, it can determine whether the terminal device is accessing the non-terrestrial network or whether the terminal device is performing uplink or downlink communication in store-and-forward mode. This local configuration can be indication information indicating that the access management device is deployed in a non-terrestrial network.
[0256] In another implementation, the access management device determines whether the terminal device performs uplink or downlink communication in store-and-forward mode based on local configuration, which may be indication information indicating the use of store-and-forward mode.
[0257] Optionally, prior to S514, the method 500 further includes: the session management device determining that the terminal device accesses a non-terrestrial network; and / or determining whether to forward the uplink or downlink communication of the terminal device in store-and-forward mode.
[0258] In one implementation, the session management device can determine, based on its local configuration, that it is deployed in a non-terrestrial network. Upon receiving information from a terminal device requesting to establish a session, it can then determine whether the terminal device is accessing the non-terrestrial network or whether it is performing uplink or downlink communication in store-and-forward mode. This local configuration can be indicative information indicating that the session management device is deployed in a non-terrestrial network.
[0259] In another implementation, the session management device determines whether the terminal device uses store-and-forward mode for uplink or downlink communication based on local configuration, which may be indication information indicating the use of store-and-forward mode.
[0260] As an optional embodiment, after the access management device obtains the first authentication information, it can use the communication method shown in Figure 6 or Figure 7 to authenticate the terminal device's permission to use the first network slice.
[0261] Figure 6 is another schematic flowchart of the communication method 600 provided in an embodiment of this application. As shown in Figure 6, the method 600 may include steps S601 to S604. The steps in method 600 are described in detail below.
[0262] S601, the access management device sends the authentication information of the first network slice (hereinafter referred to as authentication information #1) to the authentication server of the first network slice. Correspondingly, the authentication server of the first network slice receives the authentication information of the first network slice.
[0263] The authentication server for the first network slice in this application is located in the terrestrial network.
[0264] Optionally, the access management device sends the authentication information of the first network slice to the authentication server of the first network slice via NSSAAF, which is located in a non-terrestrial network.
[0265] For example, the access management device sends authentication information #1 to the authentication server of the first network slice, including: the access management device sending authentication information #1 to the NSSAAF; the NSSAAF receiving authentication information #1 from the access management device; the NSSAAF caching authentication information #1; and when the terrestrial network is connected to the non-terrestrial network, the NSSAAF sending authentication information #1 to the authentication server of the first network slice.
[0266] Optionally, the access management device can also send the identifier of the first network slice and the external identifier of the terminal device to the NSSAAF. Correspondingly, the NSSAAF receives and caches the correspondence between the identifier of the first network slice and the external identifier of the terminal device. Specifically, the NSSAAF determines the address information of the authentication server of the first network slice based on the identifier of the first network slice, and the terminal device identified by the external identifier of the terminal device is the terminal device that sent the session request carrying the identifier of the first network slice.
[0267] Optionally, NSSAAF may also send the identifier of the first network slice and the external identifier of the terminal device to the authentication server of the first network slice.
[0268] S602, the authentication server of the first network slice sends the authentication result of the first network slice (hereinafter referred to as authentication result #1) to the access management device. Correspondingly, the access management device receives the authentication result of the first network slice.
[0269] Optionally, the authentication server of the first network slice sends the authentication result of the first network slice to the access management device via NSSAAF.
[0270] For example, the authentication server of the first network slice sends authentication result #1 to the access management device, including: when the terrestrial network is connected to the non-terrestrial network, the authentication server of the first network slice sends authentication result #1 to the NSSAAF; the NSSAAF receives authentication result #1 from the authentication server of the first network slice; and sends authentication result #1 to the access management device.
[0271] Optionally, when NSSAAF sends the identifier of the first network slice and the external identifier of the terminal device to the authentication server of the first network slice, the authentication server of the first network slice may also send the identifier of the first network slice and the external identifier of the terminal device to NSSAAF.
[0272] S603, the access management device sends the authentication result of the first network slice to the session management device. Correspondingly, the session management device receives the authentication result of the first network slice from the access management device.
[0273] As mentioned earlier, the first authentication information includes at least one authentication information, which includes authentication information #1. When there are multiple authentication information items, the at least one authentication information may also include the authentication information of the second network slice (hereinafter referred to as authentication information #2 for ease of description).
[0274] Optionally, when at least one authentication information also includes authentication information #2, the method 600 further includes: the access management device sending the authentication information of the second network slice to the authentication service of the second network slice. Correspondingly, the access management device receives the authentication result of the second network slice from the authentication server of the second network slice.
[0275] For a description of the access management device sending authentication information #2, please refer to the description of the access management device sending authentication information #1 in S601. It will not be repeated here.
[0276] In other words, when the first authentication information includes multiple authentication information, the access management device can obtain multiple authentication results through these multiple authentication information. Therefore, when the access management device determines that it needs to authenticate the network slice identified by the identifier of the first network slice carried in the session request, it needs to further determine the session management device corresponding to the session request carrying the first network slice identifier. Therefore, before S603, the method 600 may further include: the access management device determining that the session management device is the session management device corresponding to the session. Specifically, the access management device can determine the session management device corresponding to the session based on the correspondence between the identifier of the terminal device, the first network slice identifier, and the identifier of the session management device maintained in S515.
[0277] The session management device corresponding to the session refers to the session management device that receives the request to establish the session.
[0278] For example, if the access management device sends a session request #1 carrying a first network slice identifier to the session management device #1, then the session management device corresponding to the session requested by the session request #1 is the session management device #1; if the access management device sends a session request #2 carrying a second network slice identifier to the session management device #2, then the session management device corresponding to the session requested by the session request #2 is the session management device #2.
[0279] Optionally, the method 600 further includes: S604, if the first authentication result indicates that the first network slice authentication is successful, the session management device sends first indication information to the first user plane device, the first indication information being used to indicate the transmission of session data. Correspondingly, the user plane device receives the first indication information from the session management device.
[0280] Optionally, the method 600 further includes: the first user plane device sending cached first uplink data according to the received first indication information.
[0281] In this embodiment, during the session establishment process, the network side does not wait for the authentication result of the network slice accessed by the terminal device, but instead sends a session establishment success response to the terminal device, thereby enabling the terminal device to send uplink data efficiently. After receiving the authentication result of the first network slice from the access management device, the session management device can instruct the first user plane device to send the cached uplink data based on the authentication result of the first network slice. This effectively reduces the latency caused by waiting for the authentication result of the network slice, especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), where the terminal device does not need to wait for the authentication result of the network slice from the terrestrial authentication server, thus completing the session establishment and sending uplink data during a single link connection; and it can also instruct the user plane device to send the uplink data after receiving the authentication result, thus realizing data transmission only after successful network slice authentication.
[0282] Figure 7 is another schematic flowchart of the communication method 700 provided in an embodiment of this application. It should be understood that the first forwarding device in Figure 7 can be replaced by a chip, chip system, or processor that supports the implementation of the method by the first forwarding device, or it can also be a logic module or software capable of implementing all or part of the functions of the first forwarding device; the second forwarding device in Figure 7 can be replaced by a chip, chip system, or processor that supports the implementation of the method by the second forwarding device, or it can also be a logic module or software capable of implementing all or part of the functions of the second forwarding device; the second user plane device in Figure 7 can be replaced by a chip, chip system, or processor that supports the implementation of the method by the second user plane device, or it can also be a logic module or software capable of implementing all or part of the functions of the second user plane device.
[0283] For example, the first forwarding device may be an SSFP, and the second forwarding device may be an SSFC.
[0284] As shown in Figure 7, method 700 may include steps S701 to S709. The steps in method 700 are described in detail below.
[0285] S701, the access management device sends the correspondence between at least one authentication information and at least one network slice in the first authentication information to the first forwarding device. Correspondingly, the first forwarding device receives the correspondence between at least one authentication information and at least one network slice from the access management device.
[0286] The first forwarding device in this application is located in a non-terrestrial network.
[0287] Optionally, the access management device may also send an external identifier of the terminal device to the first forwarding device, wherein the terminal device identified by the external identifier requests to use at least one of the aforementioned network slices.
[0288] Based on the foregoing description, the first authentication information includes the authentication information of the first network slice. For a description of the first authentication information and at least one network slice, please refer to the description in method 500; it will not be repeated here.
[0289] Optionally, the first forwarding device may also obtain the address information of the authentication server for each network slice in at least one network slice, including the address information of the authentication server for the first network slice. The address information of the authentication server for each network slice may include the Internet Protocol (IP) address and / or IP port number information of the authentication server.
[0290] For example, the information sent by the access management device to the first forwarding device can be forwarded by NSSAAF. At the same time, the access management device sends the identifier of the first network slice. The address information of the authentication server of the first network slice is determined by NSSAAF based on the identifier of the first network slice.
[0291] S702, the first forwarding device determines a first mapping relationship, which includes a correspondence between at least one authentication information and at least one network slice identifier.
[0292] Optionally, the first mapping relationship also includes a correspondence between the identifier of at least one network slice and the external identifier of the terminal device, that is, the first mapping relationship includes a correspondence between at least one authentication information, the identifier of at least one network slice and the external identifier of the terminal device.
[0293] Optionally, the first mapping relationship also includes the address information of the authentication server for each network slice in at least one network slice.
[0294] Since the first authentication information includes the authentication information of the first network slice, the first mapping relationship includes the correspondence between the identifier of the first network slice, the authentication information of the first network slice, and the external identifier of the terminal device.
[0295] Table 1
[0296] Table 1 illustrates a first mapping relationship. The mapping relationship shown in Table 1 is used to represent the three authentication information corresponding to the three network slices requested by the terminal device identified by external identifier 1, where identifier 1, identifier 2, and identifier 3 represent three different network slices. For example, the network slice identified by identifier 1 can be the first network slice.
[0297] Optionally, the method 700 further includes: S703, the session management device sends the identifier of the first network slice, the external identifier of the terminal device, and the address information of the uplink data to the first forwarding device, wherein the uplink data is data sent by the terminal device. The address information of the uplink data may include at least one of the following: source IP address, source IP port number, destination IP address, or destination port number.
[0298] For example, information sent by the session management device to the first forwarding device can be forwarded by the second user plane device.
[0299] Optionally, the method 700 further includes: S704, the first forwarding device determines a second mapping relationship based on the identifier of the first network slice from the session management device, the external identifier of the terminal device, and the first mapping relationship, the second mapping relationship including the correspondence between the identifier of the first network slice, the authentication information of the first network slice, the external identifier of the terminal device, and at least one address information of the uplink data.
[0300] It is understood that both the session management device and the access management device send the identifier of the first network slice and the external identifier of the terminal device to the first forwarding device. Therefore, the first forwarding device can establish a correspondence between the identifier of the first network slice, the authentication information of the first network slice, the external identifier of the terminal device, the address information of the authentication server of the first network slice, and at least one address information of the uplink data.
[0301] Table 2
[0302] Table 2 illustrates a second mapping relationship. The mapping relationship shown in Table 2 represents the three authentication information corresponding to the three network slices requested by the terminal device identified by external identifier 1, as well as the address information of the corresponding uplink data. Identifiers 1, 2, and 3 represent three different network slices. For example, when the network slice identified by identifier 1 is the first network slice, the addresses 1, 2, and 3 corresponding to this first network slice represent three different addresses of the uplink data.
[0303] Optionally, the method 700 further includes: S705, the first user plane device sends first uplink data to the first forwarding device. Correspondingly, the first forwarding device receives the first uplink data.
[0304] The first uplink data is the data sent by the terminal device to the first forwarding device through the first user plane device.
[0305] It is understandable that parsing the first uplink data can yield the address of the first uplink data.
[0306] Optionally, the method 700 further includes: S706, the first forwarding device buffers the first uplink data.
[0307] Optionally, the method 700 further includes: S707, the first forwarding device determines the authentication information of the first network slice corresponding to the address information of the first uplink data based on the second mapping relationship.
[0308] Since the second mapping relationship includes the correspondence between at least one address information of the uplink data and the authentication information of the network slice, the authentication information of the first network slice corresponding to the address information of the first uplink data can be obtained based on the second mapping relationship.
[0309] Optionally, the method 700 further includes: S708, the first forwarding device sends authentication information of the first network slice to the authentication server of the first network slice. Correspondingly, the authentication server of the first network slice receives the authentication information of the first network slice from the first forwarding device.
[0310] For example, the first forwarding device can send the authentication information of the first network slice to the authentication server of the first network slice through the second forwarding device. Optionally, the second forwarding device can determine to send the authentication information of the first network slice to the authentication server of the first network slice based on the address information of the authentication service of the first network slice sent by the first forwarding device.
[0311] The second forwarding device and the authentication server of the first network slice are located in the terrestrial network.
[0312] Optionally, the method 700 further includes: S709, the authentication server of the first network slice sends the authentication result of the first network slice to the first forwarding device.
[0313] For example, the authentication server of the first network slice sends the authentication result of the first network slice to the first forwarding device through the second forwarding device.
[0314] It is understandable that if multiple terminal devices send uplink data, when the first forwarding device sends different authentication information to the authentication server of the same network slice (e.g., the authentication server of the first network slice), it can simultaneously send the external identifiers of the terminal devices corresponding to the different authentication information; correspondingly, the authentication service of the first network slice can also send the external identifiers of the multiple terminal devices corresponding to the multiple authentication results while sending multiple authentication results.
[0315] Optionally, the method 700 further includes: if the authentication result of the first network slice indicates that the first network slice authentication is successful, the first forwarding device sends the cached first uplink data.
[0316] For example, the first forwarding device can send the first uplink data to the DN through the second forwarding device.
[0317] Based on the example above where the authentication server of the first network slice returns multiple authentication results corresponding to the external identifiers of multiple terminal devices, after receiving multiple authentication results from the first network slice, the first forwarding device can further determine which terminal devices' uplink data can continue to be sent and which terminal devices' uplink data cannot continue to be sent based on the external identifiers of the terminal devices corresponding to the multiple authentication results of the first network slice.
[0318] In this embodiment, during the session establishment process, the network side does not wait for the authentication result of the network slice accessed by the terminal device, but instead sends a session establishment success response to the terminal device, thereby enabling the terminal device to send uplink data efficiently. After receiving the authentication result of the first network slice from the access management device, the first forwarding device can send the cached uplink data based on the authentication result of the first network slice. This effectively reduces the latency caused by waiting for the authentication result of the network slice, especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), where the terminal device does not need to wait for the authentication result of the network slice from the terrestrial authentication server, thus completing the session establishment and sending uplink data during a single link connection; furthermore, it can instruct the client device to send the uplink data after receiving the authentication result, thus realizing data transmission only after successful network slice authentication.
[0319] As an optional embodiment, after obtaining the second information authentication information, the session management device can authenticate the terminal device's access permission to the DN through the method shown in Figure 8 or Figure 9.
[0320] Figure 8 is another schematic flowchart of a communication method 800 provided in an embodiment of this application. As shown in Figure 8, the method 800 may include steps S801 to S803. The steps in method 800 are described in detail below.
[0321] S801, the session management device sends the second authentication information to the DN's authentication server. Correspondingly, the DN's authentication server receives the second authentication information from the session management device.
[0322] The DN's authentication server in this application is located in a terrestrial network.
[0323] Optionally, the session management device sends second authentication information to the authentication server of the DN through a second user plane device located in a non-terrestrial network.
[0324] For example, the session management device sends the second authentication information to the authentication server of the DN, including: the session management device sending authentication information #1 to the second user plane device; the second user plane device receiving the second authentication information from the session management device; the second user plane device caching the second authentication information; and when the terrestrial network is connected to the non-terrestrial network, the second user plane device sending the second authentication information to the authentication server of the DN.
[0325] Optionally, the session management device can also send the identifier of the first network slice and the external identifier of the terminal device to the second user plane device. Correspondingly, the second user plane device receives and caches the correspondence between the identifier of the first network slice and the external identifier of the terminal device.
[0326] S802, the DN's authentication server sends a second authentication result to the session management device. Correspondingly, the session management device receives the second authentication result from the DN's authentication server.
[0327] Optionally, the DN's authentication server sends the authentication result of the first network slice to the access management device through the second user plane device.
[0328] For example, the authentication server of the DN sends a second authentication result to the session management device, including: when the terrestrial network is connected to a non-terrestrial network, the authentication server of the DN sends the second authentication result to the second user plane device; the second user plane device receives the second authentication result from the authentication server of the DN; and sends the second authentication result to the session management device.
[0329] Optionally, the method 800 further includes: S803, if the second authentication result indicates that the terminal device has successfully authenticated its access to the DN, sending first indication information to the first user plane device, the first indication information being used to indicate sending session data to the DN.
[0330] Optionally, the method 800 further includes: the first user plane device sending cached first uplink data to the DN according to the received first indication information.
[0331] In this embodiment, during the session establishment process, the network side does not wait for the authentication result of the DN for the terminal device's access, but instead sends a session establishment success response to the terminal device, thereby enabling the terminal device to efficiently send uplink data. After receiving the second authentication result from the access management device, the session management device can instruct the first user plane device to send the cached uplink data based on the second authentication result. This effectively reduces the latency caused by waiting for the DN authentication result, especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), where the terminal device does not need to wait for the DN authentication result from the terrestrial authentication server, thus completing session establishment and sending uplink data during a single link connection; furthermore, it can instruct the user plane device to send the uplink data only after receiving the subsequent authentication result, also realizing data transmission only after successful network slice authentication.
[0332] It is understood that the embodiments shown in Figures 6 and 8 above can be combined with each other or implemented independently. When Figures 6 and 8 are implemented individually, more or fewer steps may be performed than those shown in Figures 6 and 8; when the embodiments shown in Figures 6 and 8 are combined, the method provided by this application may include: the session management device receiving a first authentication result from the access management device; receiving a second authentication result from the authentication server of the DN; and, if the first authentication result indicates that the first network slice authentication is successful and the second authentication result indicates that the terminal device's access permission authentication to the DN is successful, sending first indication information to the user plane device. Other more detailed processes can be found in the description of the embodiments shown in Figures 7 and 8 above.
[0333] Figure 9 is another schematic flowchart of a communication method 900 provided in an embodiment of this application. As shown in Figure 9, the method 900 may include steps S901 to S907. The steps in method 900 are described in detail below.
[0334] S901, the session management device sends the second authentication information and the address information of the uplink data to the first forwarding device. Correspondingly, the first forwarding device receives the second authentication information and the address information of the uplink data from the session management device.
[0335] Uplink data refers to data sent by the terminal device.
[0336] Optionally, the session management device can also send the address information of the DN's authentication server to the first forwarding device. This DN authentication server address information can be obtained by the session management device parsing the second authentication information, or it can be obtained based on the session management device's local configuration. The DN authentication server address information may include the DN authentication server's IP address and / or IP port number.
[0337] For a description of the external identifier of the terminal device, please refer to the relevant description in Method 700, which will not be repeated here.
[0338] S902, the first forwarding device determines the third mapping relationship, which includes the correspondence between the second authentication information and the address information of the uplink data.
[0339] Optionally, the third mapping relationship also includes the correspondence between the second authentication information and the address information of the DN's authentication server. That is, the third mapping relationship includes the correspondence between the second authentication information, the address information of the uplink data, and the address information of the DN's authentication server.
[0340] Optionally, the method 900 further includes: S903, the first user plane device sends first uplink data to the first forwarding device. Correspondingly, the first forwarding device receives the first uplink data from the first user plane device.
[0341] Optionally, the method 900 further includes: S904, the first forwarding device caches the first uplink data.
[0342] For a description of the first uplink data, please refer to the relevant description above, which will not be repeated here.
[0343] Optionally, the method 900 further includes: S905, the first forwarding device determines the second authentication information corresponding to the address information of the first uplink data based on the third mapping relationship.
[0344] Since the third mapping relationship includes the correspondence between at least one address information of the uplink data and the second authentication information, the address information of the first uplink data and the corresponding second authentication information can be obtained based on the first mapping relationship.
[0345] Optionally, the method 900 further includes: S906, the first forwarding device sends second authentication information to the authentication server of the DN. Correspondingly, the authentication server of the DN receives the second authentication information from the first forwarding device.
[0346] For example, the first forwarding device can send the second authentication information to the DN's authentication server through the second forwarding device. Optionally, the second forwarding device can send the second authentication information to the DN's authentication server using the address information of the DN's authentication server from the first forwarding device.
[0347] The second forwarding device and the DN's authentication server are located in the terrestrial network.
[0348] Optionally, the method 900 further includes: S907, the authentication server of the DN sends a second authentication result to the first forwarding device. Correspondingly, the first forwarding device receives the second authentication result from the authentication server of the DN.
[0349] For example, the DN's authentication server sends the second authentication result to the first forwarding device through the second forwarding device.
[0350] It is understandable that if multiple terminal devices send uplink data, when the first forwarding device sends different second authentication information to the authentication server of the same DN (e.g., the authentication server of the first network slice), it can simultaneously send the external identifiers of the terminal devices corresponding to the different second authentication information; correspondingly, the authentication service of the DN can also send the external identifiers of the multiple terminal devices corresponding to the multiple second authentication results while sending multiple second authentication results.
[0351] Optionally, the method 900 further includes: if the second authentication result indicates that the terminal device has successfully authenticated its access to the DN, the first forwarding device sends the cached first uplink data.
[0352] For example, the first forwarding device can send the first uplink data to the DN through the second forwarding device.
[0353] Based on the example above where the DN's authentication server returns multiple external identifiers of multiple terminal devices corresponding to multiple second authentication results, after receiving multiple second authentication results from the DN, the first forwarding device can further determine which terminal devices' uplink data can continue to be sent and which terminal devices' uplink data cannot continue to be sent based on the external identifiers of the terminal devices corresponding to the multiple second authentication results from the DN.
[0354] In this embodiment, during the session establishment process, the network side does not wait for the authentication result of the DN for the terminal device's access, but instead sends a successful session establishment response to the terminal device, thereby enabling the terminal device to efficiently send uplink data. After receiving the second authentication result from the access management device, the first forwarding device can send the cached uplink data based on the second authentication result. This effectively reduces the latency caused by waiting for the DN authentication result, especially in non-terrestrial communication scenarios (i.e., store-and-forward working mode), where the terminal device does not need to wait for the DN authentication result from the terrestrial authentication server, thus completing session establishment and sending uplink data during a single link connection; furthermore, it can instruct the client-side device to send the uplink data only after receiving the subsequent authentication result, thus realizing data transmission only after successful network slice authentication.
[0355] It is understood that the embodiments shown in Figures 7 and 9 can be combined or implemented independently. When Figures 7 and 9 are implemented individually, more or fewer steps than those shown in Figures 7 and 9 can be performed. When the embodiments shown in Figures 7 and 9 are combined, the method provided by this application may include: a session management device sending a first authentication information, a correspondence between at least one authentication information in the first authentication information and at least one network slice, a second authentication information, at least one address information of uplink data, and an external identifier of the terminal device to a first forwarding device; correspondingly, the first forwarding device, based on the above information received from the session management device and the first mapping relationship, determines a fourth mapping relationship, which includes the correspondence between the first authentication information, the correspondence between at least one authentication information in the first authentication information and at least one network slice, the second authentication information, at least one address information of uplink data, and the external identifier of the terminal device; the first forwarding device, according to the fourth mapping relationship, determines the authentication information and the second authentication information of the first network slice corresponding to the address information of the first uplink data; and sends the authentication information of the first network slice to the authentication server of the first network slice and the second authentication information to the authentication server of the DN. Correspondingly, the first forwarding device receives the authentication result of the first network slice and the second authentication result; and when the first authentication result indicates that the first network slice authentication is successful, and the second authentication result indicates that the terminal device's access permission authentication to the DN is successful, it sends first indication information to the user plane device. For other more detailed procedures, please refer to the description of the embodiments shown in Figures 7 and 9 above.
[0356] The method provided by the embodiments of this application has been described in detail above with reference to Figures 1 to 9. The apparatus provided by the implementation of this application will be described in detail below with reference to Figures 10 and 11.
[0357] Figures 10 and 11 are schematic diagrams of possible apparatuses provided in embodiments of this application. These apparatuses can be used to implement the functions of terminal devices or network devices in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments.
[0358] Figure 10 is a schematic block diagram of the apparatus provided in an embodiment of this application. As shown in Figure 10, the apparatus 1000 includes a receiving module 1010 and a transmitting module 1020. Optionally, the apparatus 1000 further includes a processing module.
[0359] One possible design is that the device 1000 is used to implement the function of the access management device in the method embodiments shown in Figures 5 to 9 above.
[0360] For example, the receiving module 1010 is configured to: receive a first request from a terminal device, the first request being for requesting access to the non-terrestrial network, the first request including identifiers of one or more network slices requested by the terminal device; the sending module 1020 is configured to: send a second request to the terminal device if, among the one or more network slices, there is at least one network slice with a slice authentication status of pending authentication, the second request being for requesting to obtain first authentication information, the first authentication information being for authenticating the terminal device's permission to use the at least one network slice; the receiving module 1010 is further configured to: receive the first authentication information from the terminal device; the sending module 1020 is further configured to: send a first response to the terminal device if no first authentication result is received, the first response being for indicating that the terminal device is allowed to use the at least one network slice.
[0361] Optionally, the receiving module 1010 is further configured to: obtain from the terminal device the correspondence between the at least one network slice and the at least one authentication information.
[0362] Optionally, the receiving module 1010 is further configured to: receive a session request from the terminal device, the session request being used to request the establishment of a session for the terminal device to send data through the non-terrestrial network, the session request including an identifier of a first network slice, the at least one network slice including the first network slice; the sending module 1020 is further configured to: if no authentication result of the first network slice is received, send a third request to the session management device, the third request being used to request the establishment of the session, the third request including an identifier of the first network slice; the session management device is located in the non-terrestrial network.
[0363] Optionally, the sending module 1020 is further configured to: send the authentication information of the first network slice to the authentication server of the first network slice; the receiving module 1010 is further configured to: receive the authentication result of the first network slice from the authentication server of the first network slice; and the sending module 1020 is further configured to: send the authentication result of the first network slice to the session management device.
[0364] Optionally, the processing module is configured to: determine that the session management device is the session management device corresponding to the session.
[0365] Optionally, the sending module 1020 is further configured to: send to the first forwarding device the correspondence between at least one authentication information in the first authentication information and the identifier of the at least one network slice, as well as the external identifier of the terminal device.
[0366] Optionally, the processing module is further configured to: determine that the terminal device accesses the non-terrestrial network, wherein network elements are deployed in the non-terrestrial network to implement the access process and session establishment process; and / or, determine to forward the uplink or downlink communication of the terminal device in store-and-forward mode.
[0367] A more detailed description of the receiving module 1010 and the transmitting module 1020 can be obtained directly from the relevant descriptions in the embodiments shown in Figures 5 to 9, and will not be repeated here.
[0368] Another possible design is that the device 1000 is used to implement the functions of the session management device in the method embodiments shown in Figures 5, 6 and 8 above.
[0369] For example, the receiving module 1010 is configured to: receive a third request from an access management device, the third request being used to request the establishment of a session for a terminal device to send data through the non-terrestrial network, the third request including a DNN, the DNN being the name of the DN requested by the terminal device, and the access management device being located in the non-terrestrial network; the sending module 1020 is further configured to: if it is determined that the terminal device's permission to access the DN needs to be authenticated, send a fourth request to the terminal device, the fourth request being used to request the acquisition of second authentication information, the second authentication information being used to authenticate the terminal device's permission to access the DN; the receiving module 1010 is further configured to: receive the second authentication information from the terminal device, the second authentication information being used to authenticate the terminal device's permission to access the DN; the sending module 1020 is further configured to: if the second authentication result is not received, send a second response to the terminal device, the second response being used to indicate that the session was successfully established.
[0370] Optionally, the sending module 1020 is further configured to: send the second authentication information to the authentication server of the DN; the receiving module 1010 is further configured to: receive the second authentication result from the authentication server of the DN; the sending module 1020 is further configured to: send first indication information to the user plane device when the second authentication result indicates that the terminal device has successfully authenticated its access to the DN, the first indication information being used to indicate that the session data is sent to the DN, the user plane device being located in the non-terrestrial network.
[0371] Optionally, the receiving module 1010 is further configured to: receive the authentication result of the first network slice from the access management device; the sending module 1020 is further configured to: send the second authentication information to the authentication server of the DN; the receiving module 1010 is further configured to: receive the second authentication result from the authentication server of the DN; the sending module 1020 is further configured to: when the authentication result of the first network slice indicates that the first network slice authentication is successful, and the second authentication result indicates that the terminal device's access permission authentication to the DN is successful, send first indication information to the user plane device, the first indication information being used to indicate sending the session data to the DN, the user plane device being located in the non-terrestrial network.
[0372] Optionally, the sending module 1020 is further configured to: send a second indication message to the first user plane device, the second indication message indicating that the data of the session is cached.
[0373] Optionally, the sending module 1020 is further configured to: send the identifier of the first network slice, the second authentication information, the external identifier of the terminal device, and the address information of the uplink data of the terminal device to the first forwarding device, wherein the first forwarding unit is located in the non-terrestrial network.
[0374] Optionally, the processing module is further configured to: determine that the terminal device accesses the non-terrestrial network, wherein network elements are deployed in the non-terrestrial network to implement the access process and session establishment process; and / or, determine to forward the uplink or downlink communication of the terminal device in store-and-forward mode.
[0375] A more detailed description of the receiving module 1010 and the transmitting module 1020 can be obtained directly from the relevant descriptions in the embodiments shown in Figures 5, 6 and 8, and will not be repeated here.
[0376] Another possible design is that the device 1000 is used to implement the function of the first forwarding device in the method embodiments shown in Figures 7 and 9 above.
[0377] For example, the receiving module 1010 is configured to: receive at least one authentication information and at least one network slice correspondence from the access management device, and the external identifier of the terminal device; the processing module is configured to: determine a first mapping relationship, the first mapping relationship including the correspondence between the identifier of the at least one network slice and the at least one authentication information and the external identifier of the terminal device.
[0378] Optionally, the receiving module 1010 is further configured to: receive the identifier of a first network slice from the session management device, the external identifier of the terminal device, and the address information of the uplink data of the terminal device; the processing module is further configured to: determine a second mapping relationship based on the identifier of the first network slice from the session management device, the external identifier of the terminal device, and the first mapping relationship, wherein the second mapping relationship includes the correspondence between the identifier of the first network slice, the authentication information of the first network slice, the external identifier of the terminal device, and the address information of the uplink data of the terminal device.
[0379] Optionally, the receiving module 1010 is further configured to: receive first uplink data from the terminal device; the processing module is further configured to: cache the first uplink data; and, based on the second mapping relationship, determine the authentication information of the first network slice corresponding to the address information of the first uplink data; the sending module 1020 is further configured to: send the authentication information of the first network slice to the authentication server of the first network slice; the receiving module 1010 is further configured to: receive the authentication result of the first network slice from the authentication server of the first network slice; the sending module 1020 is further configured to: send the first uplink data when the authentication result of the first network slice indicates that the first network slice has been successfully authenticated.
[0380] Optionally, the receiving module 1010 is further configured to: receive the identifier of a first network slice from the session management device, the external identifier of the terminal device, second authentication information, and the address information of the uplink data of the terminal device, wherein the second authentication information is used to authenticate the terminal device's access permission to the DN; the processing module is further configured to: determine a fourth mapping relationship based on the identifier of the first network slice from the session management device, the external identifier of the terminal device, and the first mapping relationship, wherein the fourth mapping relationship includes the correspondence between the identifier of the first network slice, the authentication information of the first network slice, the second authentication information, the external identifier of the terminal device, and the address information of the uplink data of the terminal device.
[0381] Optionally, the receiving module 1010 is further configured to: receive first uplink data from the terminal device; the processing module is further configured to: cache the first uplink data; and determine the authentication information of the first network slice and the second authentication information corresponding to the address information of the first uplink data based on the second mapping relationship; the sending module 1020 is further configured to: send the second authentication information to the authentication server of the DN; and send the authentication information of the first network slice to the authentication server of the first network slice; the receiving module 1010 is further configured to: receive a second authentication result from the authentication server of the DN; and receive the authentication result of the first network slice from the authentication server of the first network slice; the sending module 1020 is further configured to: send the first uplink data when the authentication result of the first network slice indicates that the first network slice authentication is successful, and the second authentication result indicates that the terminal device's access permission authentication of the DN is successful.
[0382] A more detailed description of the receiving module 1010 and the transmitting module 1020 can be obtained directly from the relevant descriptions in the embodiments shown in Figures 7 and 9, and will not be repeated here.
[0383] Another possible design is that the device 1000 is used to implement the function of the first forwarding device in the method embodiment shown in FIG9 above.
[0384] For example, the receiving module 1010 is configured to: receive second authentication information from the session management device and address information of the uplink data of the terminal device; the second authentication information is used to authenticate the terminal device's access permission to the DN; the processing module is configured to: determine a third mapping relationship, the third mapping relationship including the correspondence between the second authentication information and the address information of the uplink data of the terminal device.
[0385] Optionally, the receiving module 1010 is further configured to: receive first uplink data from the terminal device; the processing module is further configured to: cache the first uplink data; and determine the second authentication information corresponding to the address information of the first uplink data based on the third mapping relationship; the sending module 1020 is further configured to: send the second authentication information to the authentication server of the DN; the receiving module 1010 is further configured to: receive a second authentication result from the authentication server of the DN; the sending module 1020 is further configured to: send the first uplink data when the second authentication result indicates that the terminal device has successfully authenticated its access to the DN.
[0386] A more detailed description of the receiving module 1010 and the transmitting module 1020 can be obtained directly from the relevant description in the embodiment shown in Figure 9, and will not be repeated here.
[0387] It is understandable that since device 1000 has communication capabilities, it can also be called a communication device.
[0388] Figure 11 is another schematic block diagram of the device provided in an embodiment of this application. As shown in Figure 11, the device 1100 includes one or more processors 1110. The processor 1110 may be a general-purpose processor or a special-purpose processor, etc. For example, it may be a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the device (e.g., terminal device, access management device, session management device, first forwarding device, second forwarding device, first user plane device, second user plane device, or chip, etc.), execute software programs, and process data from the software programs.
[0389] Optionally, in one design, processor 1110 may include a program (also referred to as code or instructions) that can be executed on processor 1110, causing device 1100 to perform the methods executed by the terminal device, access management device, session management device, first forwarding device, second forwarding device, first user plane device, or second user plane device in the above method embodiments. In yet another possible design, device 1100 includes circuitry (not shown in FIG11) for implementing the functions of the terminal device, access management device, or session management device in the above method embodiments.
[0390] For example, the processor 1110 can be used to execute computer programs or instructions in memory to implement the steps performed by the terminal device, access management device, session management device, first forwarding device, second forwarding device, first user plane device or second user plane device in any of the embodiments shown in FIG5 to FIG9.
[0391] Optionally, the device 1100 may include one or more memories 1120 storing programs (sometimes referred to as code or instructions) that can be run on the processor 1110, causing the device 1100 to perform the methods executed by the terminal device, access management device, session management device, first forwarding device, second forwarding device, first user plane device, or second user plane device in the above embodiments.
[0392] Optionally, the processor 1110 and / or memory 1120 may also store data. The processor and memory may be configured separately or integrated together.
[0393] Optionally, the device 1100 may further include a communication interface 1130. The processor 1110, sometimes referred to as a processing unit, controls the device (e.g., a terminal device, access management device, session management device, first forwarding device, second forwarding device, first user plane device, or second user plane device). The communication interface 1130, sometimes referred to as a transceiver unit, transceiver, transceiver circuit, or transceiver, is used to implement the transceiver functions of the device.
[0394] Optionally, the device 1100 also includes a communication interface 1130. The processor 1110 and the communication interface 1130 are coupled to each other. It is understood that the communication interface 1130 can be a transceiver or an input / output interface.
[0395] It is understandable that since device 1100 has communication capabilities, it can also be called a communication device.
[0396] When device 1100 is used to implement the methods of Figures 5 to 9, processor 1110 is used to execute the functions of the aforementioned processing module, and communication interface 1130 is used to execute the functions of the aforementioned sending module or receiving module. Whether communication interface 1130 is used for sending or receiving depends on whether the scheme executed by device 1100 is used to perform a sending action or a receiving action.
[0397] It is understood that when the device 1100 is a terminal device, access management device, session management device, first forwarding device, second forwarding device, first user plane device, or second user plane device, the communication interface 1130 can be a transceiver, specifically including a transmitter and a receiver, with the transmitter used to send signals and the receiver used to receive signals. When the device 1100 is a chip applied to a terminal device or network device, the communication interface 1130 can be an input / output circuit, wherein the input circuit can be used for receiving and the output interface can be used for sending.
[0398] It should be noted that the above method embodiments can be applied to a processor, or implemented by a processor. A processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by software instructions.
[0399] The aforementioned processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor.
[0400] The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in mature storage media in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.
[0401] The memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0402] The methods provided in the above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any combination thereof. When implemented in software, they can be implemented, in whole or in part, in the form of a computer program product. The computer program product may include one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic disk), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0403] This application also provides a communication system, which may include one or more of the aforementioned terminal device, access management device, session management device, first forwarding device, second forwarding device, first user plane device, or second user plane device.
[0404] This application also provides a computer program product, which includes a computer program (also referred to as code or instructions) that, when run, can implement the methods shown in the above method embodiments.
[0405] This application also provides a computer-readable storage medium storing a computer program (also referred to as code or instructions). When the computer program is run, it can implement the methods shown in the above-described method embodiments.
[0406] This application also provides a chip system, which includes at least one processor for implementing the methods shown in the above method embodiments.
[0407] Optionally, the chip system also includes a memory for storing program instructions and data, which may be located inside or outside the processor.
[0408] Optionally, the chip system may further include an interface circuit and / or a power supply circuit, wherein the interface circuit is used to transmit data and the power supply circuit is used to supply power to the chip system.
[0409] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0410] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0411] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0412] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0413] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0414] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.
[0415] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method characterized by comprising: The method is applied to an access management device in a non-ground network, and comprises the following steps: receiving a first request from a terminal device, the first request being used to request access to the non-ground network, and the first request comprising an identity of one or more network slices requested by the terminal device; in a case where the one or more network slices comprise at least one network slice with a slice authentication state of to-be-authenticated, sending a second request to the terminal device, the second request being used to request first authentication information used to authenticate an authority of the terminal device to use the at least one network slice; receiving first authentication information from the terminal device; in a case where a first authentication result is not received, sending a first response to the terminal device, the first response being used to indicate that the terminal device is allowed to use the at least one network slice, and the first authentication result being used to indicate that the authentication of the at least one network slice is successful or unsuccessful.
2. The method of claim 1, wherein, The second request comprises at least one freshness parameter used by the terminal device to determine the first authentication information.
3. The method according to claim 1 or 2, characterized in that, The first authentication information comprises at least one authentication information. Before the step of sending the first response to the terminal device, the method further comprises the following steps: obtaining, from the terminal device, a correspondence between the at least one network slice and the at least one authentication information.
4. The method according to any one of claims 1 to 3, characterized in that, After the step of sending the first response to the terminal device, the method further comprises the following steps: receiving a session request from the terminal device, the session request being used to request establishment of a session in which the terminal device transmits data through the non-ground network, and the session request comprising an identity of a first network slice included in the at least one network slice; in a case where an authentication result of the first network slice is not received, sending a third request to a session management device, the third request being used to request establishment of the session, and the third request comprising the identity of the first network slice; the session management device is located in the non-ground network.
5. The method of claim 4, wherein, The third request comprises information used to indicate that the authentication state of the first network slice is to-be-authenticated, and / or the third request comprises an external identity of the terminal device.
6. The method according to claim 4 or 5, characterized in that, After the step of receiving the first authentication information from the terminal device, the method further comprises the following steps: sending authentication information of the first network slice to an authentication server of the first network slice; receiving an authentication result of the first network slice from the authentication server of the first network slice; sending the authentication result of the first network slice to the session management device.
7. The method of claim 6, wherein, Before the step of sending the authentication result of the first network slice to the session management device, the method further comprises the following steps: determining that the session management device is a session management device corresponding to the session.
8. The method of any one of claims 4 or 5, wherein, After the step of receiving the first authentication information from the terminal device, the method further comprises the following steps: sending, to a first forwarding device, a correspondence relationship between at least one authentication information in the first authentication information and an identifier of the at least one network slice and an external identifier of the terminal device.
9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: determining that the terminal device accesses the non-ground network, and that a network element for implementing an access procedure and a session establishment procedure is deployed in the non-ground network; and / or, determining that uplink communication or downlink communication of the terminal device is performed in a store-and-forward mode.
10. A communication method characterized by comprising: The method is applied to a first forwarding device located in a non-ground network, and includes: receiving second authentication information and address information of uplink data of a terminal device from a session management device, the second authentication information being used for authenticating a right of the terminal device to access a DN; determining a third mapping relationship including a correspondence relationship between the second authentication information and the address information of the uplink data of the terminal device.
11. The method of claim 10, wherein, The method further includes: receiving first uplink data from the terminal device; buffering the first uplink data; based on the third mapping relationship, determining the second authentication information corresponding to the address information of the first uplink data; sending the second authentication information to an authentication server of the DN; receiving a second authentication result from the authentication server of the DN; in a case where the second authentication result indicates that the right of the terminal device to access the DN is successfully authenticated, sending the first uplink data.
12. A communication method, comprising: The method is applied to a first forwarding device located in a non-ground network, and includes: receiving, from an access management device, a correspondence relationship between at least one authentication information and at least one network slice and an external identifier of a terminal device, the at least one authentication information including authentication information of a first network slice, the authentication information of the first network slice being used for authenticating a right of the terminal device to use the first network slice; determining a first mapping relationship including a correspondence relationship between an identifier of the at least one network slice and the at least one authentication information and the external identifier of the terminal device.
13. The method of claim 12, wherein, The method further includes: receiving, from a session management device, an identifier of the first network slice, the external identifier of the terminal device, and address information of uplink data of the terminal device; based on the identifier of the first network slice, the external identifier of the terminal device, and the first mapping relationship from the session management device, determining a second mapping relationship including a correspondence relationship between the identifier of the first network slice, the authentication information of the first network slice, the external identifier of the terminal device, and the address information of the uplink data of the terminal device.
14. The method of claim 13, wherein, The method further includes: receiving first uplink data from the terminal device; buffering the first uplink data; based on the second mapping relationship, determining the authentication information of the first network slice corresponding to the address information of the first uplink data; sending the authentication information of the first network slice to an authentication server of the first network slice; receiving an authentication result of the first network slice from the authentication server of the first network slice; In a case where the authentication result of the first network slice indicates that the first network slice is successfully authenticated, the first uplink data is sent.
15. The method of claim 12, wherein, The method further includes: receiving, from a session management device, an identifier of a first network slice, an external identifier of the terminal device, second authentication information, and address information of uplink data of the terminal device, the second authentication information being used for authenticating a right of the terminal device to access a DN; determining, according to the identifier of the first network slice, the external identifier of the terminal device, and the first mapping relationship, a fourth mapping relationship, the fourth mapping relationship including a corresponding relationship between the identifier of the first network slice, authentication information of the first network slice, the second authentication information, the external identifier of the terminal device, and the address information of the uplink data of the terminal device.
16. The method of claim 15, wherein, The method further includes: receiving first uplink data from the terminal device; buffering the first uplink data; determining, based on the fourth mapping relationship, authentication information of the first network slice corresponding to the address information of the first uplink data and the second authentication information; sending, to an authentication server of a DN, the second authentication information; receiving a second authentication result from the authentication server of the DN; sending, to an authentication server of a first network slice, authentication information of the first network slice; receiving an authentication result of the first network slice from the authentication server of the first network slice; in a case where the authentication result of the first network slice indicates that the first network slice is successfully authenticated, and the second authentication result indicates that the right of the terminal device to access the DN is successfully authenticated, the first uplink data is sent.
17. A communications device, characterized by one or more functional units for implementing the method of any of claims 1-16.
18. A communications device, characterized by a processor configured to execute program code to cause the communication apparatus to implement the method of any of claims 1-16.
19. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, causes the method of any of claims 1-16 to be performed.
20. A computer program product, characterised in that, The computer program, when executed by the processor, causes the method of any of claims 1-16 to be performed. The computer program, when executed by the processor, causes the method of any of claims 1-16 to be performed.
Citation Information
Patent Citations
Methods and apparatus for store and forward in ntn deployments
GB202300747D0