Communication method and related apparatus

By enabling terminal devices in non-terrestrial communication systems to directly initiate session establishment processes without waiting for network slicing and data network authentication results, the transmission latency problem caused by link instability is solved, achieving efficient uplink data transmission.

WO2026016797A1PCT designated stage Publication Date: 2026-01-22HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/104416
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-19
Filing Date
2025-06-27
Publication Date
2026-01-22

AI Technical Summary

Technical Problem

In non-terrestrial communication systems, the intermittent availability of service links and feeder links due to satellite movement leads to increased uplink data transmission latency, especially in store-and-forward mode, where network slicing and data network authentication introduce additional delays.

Method used

When a terminal device accesses a non-terrestrial network, it does not wait for the authentication results of network slicing and data network, but directly initiates a session establishment process. Through the coordinated operation of access management device and session management device, transmission latency is reduced.

Benefits of technology

It effectively reduces transmission latency caused by waiting for network slicing and data network authentication results. Especially in store-and-forward mode, terminal devices can complete session establishment and uplink data transmission in a single link connection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025104416_22012026_PF_FP_ABST
    Figure CN2025104416_22012026_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a communication method and a related apparatus, which can effectively shorten the transmission delay of uplink data. The method comprises: a terminal device sends a first request to an access management device, wherein the first request is used for requesting access to a non-terrestrial network, the first request comprises identifiers of one or more network slices requested by the terminal device, and the access management device is located in the non-terrestrial network; the terminal device receives a first response from the access management device, wherein the first response carries an identifier of a first network slice, and the one or more network slices include the first network slice; and when a slice authentication state of the first network slice is pending authentication, the terminal device sends a session request to the access management device, wherein the session request is used for requesting establishment of a session for the terminal device to send data by means of the non-terrestrial network, and the session request comprises the identifier of the first network slice.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and related apparatus

[0001] This application claims priority from the Chinese patent application No. 202410980936.9 filed on July 19, 2024, and entitled "Communication method and related apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication technology, and in particular to a communication method and related apparatus. BACKGROUND

[0003] In a regenerative repeater architecture defined in a non-terrestrial network (NTN) system, a satellite can process the received signal, including demodulation / decoding, encoding / modulation, and information processing, i.e., the satellite has the function of all radio access network (RAN) nodes on the satellite. In the regenerative repeater architecture, due to the movement of the satellite, the service link between the satellite and the terminal device, and the feeder link between the gateway station and the satellite, can not be available at all times. Therefore, under this architecture, for uplink (UL), the satellite needs to store the UL information from the terminal device when the service link is available, and when the feeder link is available, the satellite transmits the stored UL information to the ground network through the feeder link. This working mode of the satellite can be referred to as a store and forward (S&F) satellite operation mode.

[0004] Exemplarily, before transmitting the UL information, the terminal device can also need to perform network slice authentication and / or data network (DN) authentication, and the network slice authentication and / or DN authentication can bring additional uplink transmission delay. SUMMARY

[0005] The present application provides a communication method and related apparatus to reduce the transmission delay of uplink data.

[0006] In a first aspect, the present application provides a communication method, which can be applied to a terminal device, or implemented by a component (such as a chip, a chip system, etc.) configured in the terminal device, or implemented by a logic module or software capable of implementing all or part of the functions of the terminal device, and the present application does not make any limitation in this regard. Hereinafter, for the convenience of understanding and description, the method is described by taking the terminal device as an example.

[0007] Exemplarily, the method comprises: sending a first request to an access management device, the first request being used for requesting access to a non-ground network, and the first request comprising an identity of one or more network slices requested by the terminal device, the access management device being located in the non-ground network; receiving a first response from the access management device, the first response carrying an identity of a first network slice, the one or more network slices comprising the first network slice; in a case where a slice authentication state of the first network slice is to be authenticated, sending a session request to the access management device, the session request being used for requesting establishment of a session in which the terminal device sends data through the non-ground network, and the session request comprising the identity of the first network slice.

[0008] Optionally, the one or more network slices comprise a network slice allowed to be used by the terminal device (i.e. a slice that does not need to be authenticated, or referred to as an allowed-to-use network slice), and / or comprise a network slice not allowed to be used by the terminal device (i.e. a network slice that needs to be authenticated, or referred to as a to-be-authenticated network slice, or a network slice not currently allowed to be used). Therefore, the first network slice can belong to the allowed-to-use network slice, or can belong to the to-be-authenticated network slice.

[0009] Optionally, the first network slice can be located in a to-be-authenticated slice list in the first response, i.e. the first network slice belongs to the network slice to be authenticated by the terminal device.

[0010] Optionally, in a case where the slice authentication state of the first network slice is to be authenticated, it can be replaced by: regardless of the authentication state of the first network slice.

[0011] Optionally, the first network slice can also be located in an allowed-to-use slice list in the first response, i.e. the first network slice, although objectively belonging to the network slice to be authenticated by the terminal device, is taken as an allowed-to-use slice in the first response sent by the access management device to the terminal device, so that the terminal device can perform the action of session establishment without waiting for the slice authentication result of the first network slice.

[0012] Based on the technical solution, the terminal device can directly send a session request carrying the first network slice to the access management device when receiving the first response carrying the first network slice, regardless of the slice authentication state of the first network slice. That is, when the first network slice belongs to a network slice to be authenticated, the terminal device can directly initiate a session request carrying the first network slice without waiting for the authentication result of the first network slice. Compared with the solution in which the terminal device needs to receive the authentication result of the first network slice and then initiates a session establishment process, the method provided in the application can effectively reduce the additional delay caused by waiting for the authentication result of the network slice. In particular, in a non-terrestrial communication scenario (i.e., a store-and-forward working mode), the terminal device does not need to wait for the authentication result of the network slice from the ground authentication server, and thus can complete session establishment and then send uplink data in a single link connection, effectively reducing the transmission delay of uplink data.

[0013] With reference to the first aspect, in some implementations of the first aspect, the slice authentication state of the first network slice is to be authenticated, including: no authentication result of the first network slice is received, and / or an identifier of the first network slice is located in a to-be-authenticated slice list in the first response.

[0014] The authentication result of the first network slice is used to indicate that the first network slice is authenticated successfully, or is used to indicate that the first network slice is not authenticated successfully.

[0015] Optionally, no authentication result of the first network slice is received, including: the access management device has not triggered an authentication process of the network slice, or the access network device has triggered the authentication process of the network slice but the terminal device has not received the authentication result.

[0016] With reference to the first aspect, in some implementations of the first aspect, the method further includes: receiving a session response from the access management device, the session response being used to indicate that the session establishment is successful; and sending uplink data using the session.

[0017] Based on the technical solution, the terminal device can receive a session response from the access management device when the slice authentication state of the first network slice is to be authenticated, and then send uplink data using the established session, effectively reducing the transmission delay caused by waiting for the authentication result of the network slice.

[0018] In some implementations of the first aspect, the session request further includes a DNN, the DNN being a name of the DN requested by the terminal device; the method further includes: receiving a fourth request from the session management device, the fourth request being used to request second authentication information, the second authentication information being used to authenticate the permission of the terminal device to access the DN; and the using the session to send uplink data includes: in a case where the authentication of the permission of the terminal device to access the DN is not completed, using the session to send uplink data.

[0019] Based on the technical solution, even if the permission of the terminal device to access the DN needs to be authenticated, the terminal device can use the established session to send uplink data in a case where the authentication of the permission of the terminal device to access the DN is not completed, thereby effectively reducing the transmission delay caused by waiting for the authentication result of the DN.

[0020] In some implementations of the first aspect, before the session request is sent to the access management device, the method further includes: determining to access a non-terrestrial network, the non-terrestrial network deploying a network element used to implement an access procedure and a session establishment procedure; and / or determining to perform uplink communication or downlink communication in a store-and-forward mode.

[0021] Based on this, when the terminal device determines to access a non-terrestrial network and / or determines to perform uplink communication or downlink communication in a store-and-forward mode, the terminal device can initiate a session establishment procedure when selecting a network slice to access, regardless of the authentication status of the network slice, thereby effectively reducing the transmission delay caused by waiting for the authentication result of the slice; and / or the terminal device can continue a subsequent session procedure without waiting for the authentication result of the DN in a case where the DN requested to be accessed needs to be authenticated, thereby effectively reducing the transmission delay caused by waiting for the authentication result of the DN.

[0022] In a second aspect, the present application provides a communication method, which can be applied to a terminal device, or implemented by a component (such as a chip, a chip system, etc.) configured in the terminal device, or a logic module or software capable of implementing all or part of the functions of the terminal device, and the present application does not limit this. Hereinafter, for the convenience of understanding and description, the method is described by taking the terminal device as an example.

[0023] Exemplarily, the method includes: sending a session request, the session request being used to request the terminal device to establish a session for sending data through a non-terrestrial network, the session request including a DNN, the DNN being a name of a DN requested by the terminal device; and in a case where the authentication of the permission of the terminal device to access the DN is not completed, receiving a session response, the session response being used to indicate that the session establishment is successful.

[0024] Optionally, the authentication of the permission of the terminal device to access the DN is not completed, including: a second authentication result is not received, or the authentication of the permission of the terminal device to access the DN has not been triggered.

[0025] The second authentication result is used to indicate that the authentication of the permission of the terminal device to access the DN is successful, or is used to indicate that the authentication of the permission of the terminal device to access the DN is unsuccessful.

[0026] Based on the technical solution, after the terminal device sends the session request carrying the DNN, the session response can be received in the case that the authentication of the permission of the terminal device to access the DN is not completed. That is, in the case that the permission of the terminal device to access the DN needs to be authenticated, the session management device can directly send the response of successful session establishment to the terminal device without waiting for the authentication result of the DN. Compared with the solution that the terminal device needs to receive the authentication result of the DN and then sends the response of successful session establishment, the method provided in the application can effectively reduce the transmission delay caused by waiting for the authentication result of the DN. Especially in the non-terrestrial communication scenario (that is, the store-and-forward mode), the session device can not wait for the authentication result of the authentication server of the DN from the ground, so that the terminal device can complete the session establishment in a single link connection, and then send the uplink data, thereby effectively reducing the transmission delay of the uplink data.

[0027] In combination with the second aspect, in some implementations of the second aspect, the method further includes: receiving a fourth request from the session management device, the fourth request being used to obtain second authentication information, the second authentication information being used to authenticate the permission of the terminal device to access the DN.

[0028] Optionally, the method further includes: sending uplink data using the session.

[0029] It can be understood that the receiving of the session response can be performed before, after or simultaneously with the receiving of the fourth request, and the application does not limit this.

[0030] In combination with the second aspect, in some implementations of the second aspect, before the sending of the session request, the method further includes: determining to access the non-terrestrial network, the non-terrestrial network deploying a network element used to implement an access process and a session establishment process; and / or determining to perform uplink communication or downlink communication in a store-and-forward mode.

[0031] In a third aspect, the present application provides a communication method, which can be applied to an access management device, or implemented by a component (such as a chip, a chip system, etc.) configured in the access management device, or a logic module or software capable of implementing all or part of the functions of the access management device, and the present application does not make any limitation in this regard. Hereinafter, for the convenience of understanding and description, the method is described by taking the access management device as an example.

[0032] Exemplarily, the method comprises: receiving a session request from a terminal device, the session request being used to request to establish a session in which the terminal device transmits data through the non-ground network, the session request comprising an identification of a first network slice; in a case where a slice authentication state of the first network slice is to be authenticated, sending a second request to a session management device, the second request being used to request to establish the session, the session management device being located in the non-ground network.

[0033] Optionally, the first network slice can belong to a network slice that the terminal device cannot use, or can belong to a network slice that the terminal device can use. It can be understood that after the access management device receives the identification of the first network slice, it can determine whether the first network slice is in a to-be-authenticated slice list located at the access management device side or in an allowed-to-use slice list.

[0034] Among them, the network slice in the to-be-authenticated slice list is a network slice that the terminal device cannot use, and the slice in the allowed-to-use slice list is a network slice that the terminal device can use.

[0035] Based on this technical solution, when the access management device receives the session request carrying the first network slice, it can send the second request carrying the first network slice to the session management device regardless of the slice authentication state of the first network slice, to continue to request to establish the session; that is, the access management device can also directly execute the subsequent session establishment process without waiting for the authentication result of the first network slice. Compared with the solution in which the access management device needs to receive the authentication result of the first network slice and then continues to execute the session establishment process, the method provided by the present application can effectively reduce the additional time delay caused by waiting for the authentication result of the network slice. Especially in the non-ground communication scenario (i.e. the store-and-forward working mode), the access management can continue to execute the session establishment process without waiting for the authentication result of the network slice, so that the terminal device can complete the session establishment in a single link connection, and then transmit uplink data, effectively reducing the transmission time delay of the uplink data.

[0036] Optionally, the second request further comprises a DNN, the DNN being a name of the DN requested by the terminal device; the method further comprises: receiving a second response from the session management device, the second response being used to indicate that the session establishment is successful, in a case where the authentication of the authority of the terminal device to access the DN is not completed; and sending a session response to the terminal device, the session response being used to indicate that the session establishment is successful.

[0037] It can be understood that the second response can be a response of the session management device to the second request, and the session response can be a response of the access management device to the session request. Here, the second request can be a session request sent by the terminal device to the session management device through the access management device, and the second response can be a session response sent by the session management device to the terminal device through the access management device.

[0038] With reference to the third aspect, in some implementations of the third aspect, the method further comprises: in a case where the identifier of the first network slice is located in the to-be-authenticated slice list, sending a third request to the terminal device, the third request being used to request to obtain first authentication information, the first authentication information being used to authenticate the authority of the terminal device to use the first network slice; and receiving the first authentication information from the terminal device.

[0039] Optionally, the sending of the third request can be performed before, after or simultaneously with the sending of the session response, and the application does not limit this.

[0040] With reference to the third aspect, in some implementations of the third aspect, the method further comprises: sending the first authentication information to an authentication server of the first network slice; receiving a first authentication result from the authentication server of the first network slice, the first authentication result being used to indicate that the authentication of the first network slice is successful or being used to indicate that the authentication of the first network slice is unsuccessful; and sending the first authentication result to the session management device.

[0041] The authentication server of the first network slice is located in a ground network.

[0042] Based on this, the access management device can obtain the first authentication result of the first network slice according to the first authentication information after obtaining the first authentication information, thereby guaranteeing that the uplink communication meets the security or network requirements.

[0043] Optionally, the access management device can send the first authentication information to an authentication server of the first network slice through the NSSAAF. Illustratively, the access management device sends the first authentication information to the NSSAAF; the NSSAAF stores the first authentication information; and after the feeder link is connected, the NSSAAF sends the first authentication information to the authentication server of the first network slice. The NSSAAF is located in the non-terrestrial network.

[0044] With reference to the third aspect, in some implementations of the third aspect, the method further includes: receiving a first request from the terminal device, the first request being used to request access to the non-terrestrial network, and the first request including an identity of one or more network slices requested by the terminal device; and in a case where the slice authentication state of the first network slice is to be authenticated, sending a first response to the terminal device, the first response being used to indicate at least one network slice allowed to be used by the terminal device, the at least one network slice including the first network slice.

[0045] For the description of the one or more network slices and the first network slice, reference can be made to the related description in the first aspect, which will not be repeated here.

[0046] With reference to the third aspect, in some implementations of the third aspect, the slice authentication state of the first network slice being to be authenticated includes: no authentication result of the first network slice is received, and / or the identity of the first network slice is located in a to-be-authenticated slice list.

[0047] With reference to the third aspect, in some implementations of the third aspect, before sending the second request to the session management device, the method further includes: determining that the terminal device accesses the non-terrestrial network, and that a network element for implementing an access procedure and a session establishment procedure is deployed in the non-terrestrial network; and / or determining to forward the uplink communication or the downlink communication of the terminal device in a store-and-forward mode.

[0048] Based on this, when the access management device determines that the terminal device accesses the non-terrestrial network and / or that the terminal device performs uplink communication or downlink communication in a store-and-forward mode, if the network slice carried in the session request by the terminal device needs to be authenticated, the access management device can continue the session establishment procedure without waiting for the authentication result of the network slice, which can reduce the transmission delay.

[0049] In a fourth aspect, the present application provides a communication method, which can be applied to a session management device, or implemented by a component (such as a chip, a chip system, etc.) configured in the session management device, or a logic module or software capable of implementing all or part of the functions of the session management device, and the present application does not make any limitation in this regard. Hereinafter, for the convenience of understanding and description, the method is described by taking the session management device as an example.

[0050] Exemplarily, the method comprises: receiving a second request from the access management device, the second request being used for requesting to establish a session, the second request comprising a DNN, the DNN being the name of a DN requested by the terminal device (may also be referred to as the DN selected by the terminal device), the session being used for the terminal device to send data through the non-terrestrial network; in a case where authentication of the authority of the terminal device to access the DN is not completed, sending a second response to the access management device, the second response being used for indicating that the session is successfully established.

[0051] Based on the technical solution, when the session management device receives the second request carrying the DNN, the session management device can directly send a response indicating that the session is successfully established to the access management device in a case where authentication of the authority of the terminal device to access the DN is not completed. That is, regardless of whether the authentication of the authority of the terminal device to access the DN is needed, the session management device can continue to perform a subsequent session establishment process without waiting for the authentication result of the DN. Compared with a solution in which the session management device needs to receive the authentication result of the DN and then send a response indicating that the session is successfully established, the method provided in the application can effectively reduce the transmission delay caused by waiting for the authentication result of the DN. In particular, in a non-terrestrial communication scenario (i.e., a store-and-forward mode), the session device does not need to wait for the authentication result from the authentication server of the DN on the ground, so that the terminal device can complete the session establishment in a single link connection, thereby effectively reducing the transmission delay of the uplink data.

[0052] In combination with the fourth aspect, in some implementations of the fourth aspect, the method further comprises: sending a fourth request to the terminal device, the fourth request being used for requesting to obtain second authentication information, the second authentication information being used for authenticating the authority of the terminal device to access the DN; and receiving the second authentication information from the terminal device.

[0053] Optionally, the sending of the fourth request can be performed before or after the sending of the second response, or simultaneously, which is not limited in the application.

[0054] In combination with the fourth aspect, in some implementations of the fourth aspect, the method further comprises: sending the second authentication information to an authentication server of the DN; receiving a second authentication result from the authentication server of the DN; and in a case where the second authentication result indicates that the authentication of the authority of the terminal device to access the DN is successful, sending first indication information to a user plane device, the first indication information being used for indicating that the data of the session is sent to the DN, the user plane device being located in the non-terrestrial network.

[0055] The data of the session is uplink data sent by the terminal device through the session.

[0056] Based on this, the session management device located in the non-ground network can obtain the second authentication result in single communication with the authentication server of the DN, and complete the user plane device to send the uplink data of the terminal device to the DN in the case of successful authentication of the DN, effectively reducing the transmission delay of the uplink data.

[0057] In combination with the fourth aspect, in some implementations of the fourth aspect, the method further includes: sending the second authentication information to the authentication server of the DN; receiving a second authentication result from the authentication server of the DN; receiving a first authentication result from the access management device; in the case that the first authentication result indicates that the first network slice authentication is successful, and the second authentication result indicates that the terminal device access permission authentication to the DN is successful, sending first indication information to a user plane device, the first indication information being used to indicate sending data of the session to the DN, the user plane device being located in the non-ground network.

[0058] Based on this, the session management device located in the non-ground network can obtain the second authentication result and the first authentication result in single communication with the authentication server of the DN, and complete the user plane device to send the uplink data of the terminal device to the DN in the case of successful slice authentication and successful authentication of the DN, effectively reducing the transmission delay of the uplink data.

[0059] In combination with the fourth aspect, in some implementations of the fourth aspect, before the second response is sent to the terminal device, the method further includes: sending second indication information to the user plane device, the second indication information being used to instruct the user plane device to cache data of the session.

[0060] In combination with the fourth aspect, in some implementations of the fourth aspect, before the second response is sent to the access management device, the method further includes: determining that the terminal device accesses the non-ground network, and that a network element for implementing an access process and a session establishment process is deployed in the non-ground network; and / or, determining to forward the uplink communication or the downlink communication of the terminal device in a store-and-forward mode.

[0061] Based on this, when the session management device determines that the terminal device accesses the non-ground network and / or determines that the terminal device performs uplink communication or downlink communication in a store-and-forward mode, the terminal device can continue the subsequent session process without waiting for the authentication result of the DN in the case that the DN requested to be accessed needs to be authenticated, effectively reducing the transmission delay caused by waiting for the authentication result of the DN.

[0062] In a fifth aspect, the present application provides a communication method, which can be applied to a session management device, or implemented by a component (such as a chip, a chip system, etc.) configured in the session management device, or a logic module or software capable of implementing all or part of the functions of the session management device, and the present application does not make any limitation in this regard. Hereinafter, for the convenience of understanding and description, the method is described by taking the session management device as an example.

[0063] Exemplarily, the method comprises: receiving a second request from an access management device, the second request being used to request to establish a session, the second request carrying an identifier of a first network slice, the session being used for the terminal device to send data through the non-terrestrial network; sending a second response to the terminal device, the second response being used to indicate that the session establishment is successful; receiving a first authentication result from the access management device; in the case that the first authentication result indicates that the first network slice authentication is successful, sending first indication information to a user plane device, the first indication information being used to indicate to send the data of the session, the user plane device being located in the non-terrestrial network.

[0064] Based on this technical solution, in the session establishment process, the network side does not wait for the authentication result of the terminal device accessing the network slice, but sends a response to the terminal device that the session establishment is successful, so that the terminal device can efficiently send uplink data. After receiving the first authentication result from the access management device, the session management device can instruct the user plane device to send the buffered uplink data based on the first authentication result. Thus, the time delay caused by waiting for the authentication result of the network slice can be effectively reduced, especially in the non-terrestrial communication scenario (i.e. the store-and-forward working mode), the terminal device can not wait for the authentication result of the network slice from the ground authentication server, so that the session establishment can be completed in a single link connection, and then the uplink data can be sent; and the user plane device can be instructed to send the uplink data after receiving the authentication result, which also realizes the transmission of data after the network slice authentication is successful.

[0065] In combination with the fifth aspect, in some implementation forms of the fifth aspect, after the receiving the second request from the access management device, and before the receiving the first authentication result from the access management device, the method further comprises: sending second indication information to the user plane device, the second indication information being used to instruct to buffer the data of the session. Thus, in the case that the network slice has not been authenticated successfully, the user plane device can buffer the data first, and then transmit the data when the feeder link is connected.

[0066] Optionally, the second indication information can be carried in an N4 message.

[0067] In a sixth aspect, the present application provides a communication method, which can be applied to a session management device, or implemented by a component (such as a chip, a chip system, etc.) configured in the session management device, or a logic module or software capable of implementing all or part of the functions of the session management device, and the present application does not make any limitation in this regard. Hereinafter, for the convenience of understanding and description, the method is described by taking the session management device as an example.

[0068] Exemplarily, the method comprises: receiving a second request from an access management device, the second request being used to request to establish a session in which a terminal device transmits data through the non-terrestrial network, the second request carrying a DNN; sending a second response to the access management device, the second response being used to indicate that the session establishment is successful; sending the second authentication information to an authentication server of the DN, the second information being used to authenticate the access right of the terminal device to the DN; receiving a second authentication result from the authentication server of the DN; in the case where the second authentication result indicates that the access right of the terminal device to the DN is authenticated successfully, sending first indication information to a user plane device, the first indication information being used to instruct the user plane device to transmit the data of the session, the user plane device being located in the non-terrestrial network.

[0069] Based on the technical solution, in the session establishment process, the session management device does not wait for the authentication result of the slice of the DN, but only obtains the second authentication information used to authenticate the access right of the terminal device to the DN, and after the session establishment is successful, the session management device obtains the authentication result of the DN through the second authentication information, and instructs the user plane device to transmit the buffered uplink data based on the second authentication result. In the store-and-forward mode, the method provided by the present application can establish a session, obtain uplink data, and obtain second authentication information in the case where one link is connected, complete the authentication of the DN and the transmission of the uplink data in the case where another link is connected, and effectively reduce the transmission delay of the uplink data.

[0070] Optionally, after the second request from the access management device is received, the method further comprises: sending a fourth request to the terminal device, the fourth request being used to request to obtain the second authentication information; and receiving the second authentication information from the terminal device.

[0071] Optionally, the method further comprises: before the first authentication result from the access management device is received, after the second request from the access management device is received, the method further comprises: sending second indication information to the user plane device, the second indication information being used to instruct to buffer the data of the session.

[0072] In a seventh aspect, the present application provides a communication method, which can be applied to a session management device, or implemented by a component (such as a chip, a chip system, etc.) configured in the session management device, or a logic module or software capable of implementing all or part of the functions of the session management device, and the present application does not make any limitation in this regard. Hereinafter, for the convenience of understanding and description, the method is described by taking the session management device as an example.

[0073] Exemplarily, the method comprises: receiving a second request from an access management device, the second request being used to request to establish a session in which a terminal device transmits data through the non-terrestrial network, the second request carrying an identifier of a first network slice and a DNN; sending a second response to the terminal device, the second response being used to indicate that the session establishment is successful; sending the second authentication information to an authentication server of the DN, the second information being used to authenticate the access right of the terminal device to the DN; receiving a second authentication result from the authentication server of the DN; receiving a first authentication result from the access management device; in the case that the first authentication result indicates that the first network slice authentication is successful, and the second authentication result indicates that the access right of the terminal device to the DN is authenticated successfully, sending first indication information to a user plane device, the first indication information being used to instruct the user plane device to send the data of the session, the user plane device being located in the non-terrestrial network.

[0074] Based on the technical solution, in the session establishment process, the access management device and the session management device do not wait for the authentication results of the network slice and the slice of the DN, but only obtain the first authentication information and the second authentication information; and after the session establishment is successful, the access management device obtains the authentication result of the first network slice through the first authentication information and sends the first authentication result to the session management device, and the session management device obtains the authentication result of the DN through the second authentication information and instructs the user plane device to send the buffered uplink data based on the first authentication result and the second authentication result. In the store-and-forward mode, the method provided by the present application can establish a session, obtain uplink data, first authentication information and second authentication information in the case of one link being connected, complete the authentication of the first network slice and the DN, and send the uplink data when the other link is connected, thereby effectively reducing the transmission delay of the uplink data.

[0075] Optionally, after the second request from the access management device is received, the method further comprises: sending a fourth request to the terminal device, the fourth request being used to request to obtain the second authentication information; and receiving the second authentication information from the terminal device.

[0076] Optionally, the method further includes: after receiving the second request from the access management device, before receiving the first authentication result from the access management device, the method further includes: sending second indication information to the user plane device, the second indication information being used to indicate to cache data of the session.

[0077] In an eighth aspect, a communication apparatus is provided, which includes modules or units for implementing the method in any of the preceding aspects and their possible implementation manners.

[0078] In a ninth aspect, a communication apparatus is provided, which includes a processor configured to implement the method in any of the preceding aspects and their possible implementation manners.

[0079] The apparatus can further include a memory for storing instructions and data. The memory is coupled to the processor, and the processor executes the instructions stored in the memory to implement the method described in the preceding aspects.

[0080] The apparatus can further include a communication interface for the apparatus to communicate with other devices. The communication interface can be, for example, a transceiver, a circuit, a bus, a module, or other types of communication interfaces.

[0081] In a tenth aspect, a chip system is provided, which includes at least one processor configured to support the functions involved in any of the preceding aspects and their possible implementation manners, such as receiving or processing data and / or information involved in the methods.

[0082] In a possible design, the chip system further includes a memory configured to store program instructions and data, the memory being located in or out of the processor.

[0083] The chip system can be composed of a chip, or include a chip and other discrete devices.

[0084] In an eleventh aspect, a computer readable storage medium is provided, which includes a computer program, and when the computer program is run on a computer, the computer program makes the computer implement the method in any of the preceding aspects and their possible implementation manners.

[0085] In a twelfth aspect, a computer program product is provided, which includes a computer program (also referred to as code or instructions), and when the computer program is run, the computer program makes a computer execute the method in any of the preceding aspects and their possible implementation manners.

[0086] In a thirteenth aspect, the present application provides a communication system, comprising the session management device and the access management device. The access management device is configured to implement the method in the third aspect and any possible implementation of the third aspect; and the session management device is configured to receive the second request.

[0087] Optionally, the session management device is further configured to implement the method in the fourth to seventh aspects and any possible implementation of the fourth to seventh aspects.

[0088] Optionally, the communication system can further comprise the terminal device, which is configured to implement the method in the first aspect and any possible implementation of the first aspect.

[0089] Optionally, the communication system can further comprise the user plane device.

[0090] In a fourteenth aspect, the present application provides a communication system, comprising the session management device and the access management device. The session management device is configured to implement the method in the fourth aspect and any possible implementation of the fourth aspect; and the access management device is configured to send the second request to the session management device.

[0091] Optionally, the access management device is further configured to implement the method in the third aspect and any possible implementation of the third aspect.

[0092] Optionally, the communication system can further comprise the terminal device, which is configured to implement the method in the second aspect and any possible implementation of the second aspect.

[0093] Optionally, the communication system can further comprise the user plane device.

[0094] In a fifteenth aspect, the present application provides a communication system, comprising the session management device and the access management device. The session management device is further configured to implement the method in the fifth and seventh aspects and any possible implementation of the fifth and seventh aspects; and the access management device is configured to send the first authentication result and the second request to the session management device.

[0095] In a sixteenth aspect, the present application provides a communication system, comprising the session management device and the access management device. The session management device is further configured to implement the method in the sixth aspect and any possible implementation of the sixth aspect; and the access management device is further configured to send the second request to the session management device.

[0096] It should be understood that the eighth aspect to the sixteenth aspect of the present application correspond to the technical solutions of the first aspect to the seventh aspect of the present application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation manners are similar, which will not be described again. BRIEF DESCRIPTION OF DRAWINGS

[0097] FIG. 1 is a schematic diagram of a network architecture suitable for a service-based architecture (SBA) in a fifth generation (5G) network according to an embodiment of the present application;

[0098] FIG. 2 is a schematic diagram of a regenerated network architecture suitable for a method according to an embodiment of the present application;

[0099] FIG. 3 is a schematic diagram of a communication scenario of a discontinuous feeder link according to an embodiment of the present application;

[0100] FIG. 4 is a schematic flowchart of a communication method in a discontinuous feeder link scenario according to an embodiment of the present application;

[0101] FIG. 5 is a schematic flowchart of a communication method according to an embodiment of the present application;

[0102] FIG. 6 is another schematic flowchart of a communication method according to an embodiment of the present application;

[0103] FIG. 7 is still another schematic flowchart of a communication method according to an embodiment of the present application;

[0104] FIG. 8 is a schematic block diagram of an apparatus according to an embodiment of the present application;

[0105] FIG. 9 is another schematic block diagram of an apparatus according to an embodiment of the present application. DETAILED DESCRIPTION

[0106] The technical solutions in the present application will be described below with reference to the accompanying drawings.

[0107] To facilitate understanding of the embodiments of the present application, the following points are first explained:

[0108] First, in the embodiments of the present application, the use of prefixes such as "first", "second", etc. is only for the convenience of distinguishing and describing different things belonging to the same name category, and does not constrain the order, size or quantity of the things. For example, "first request" and "second request" are only different requests, and there is no time sequence, size relationship or priority relationship between them.

[0109] Secondly, in the embodiments of the present application, "sending" and "receiving" represent the direction of signal transmission. For example, "sending a first request to the access management" can be understood as that the destination of the information is the access management device, which can include direct transmission through the air interface, and also include indirect transmission through the air interface by other units or modules. "Receiving a session request of a terminal device" can be understood as that the source of the session request is the terminal device, which can include direct reception from the terminal device through the air interface, and also include indirect reception from the terminal device through the air interface by other units or modules. "Sending" can also be understood as "output" of a chip interface, and "receiving" can also be understood as "input" of a chip interface.

[0110] In other words, sending and receiving can be performed between devices, for example, between the access management device and the terminal device, or can be performed within a device, for example, between components, modules, chips, software modules or hardware modules within the device through a bus, wire or interface.

[0111] It can be understood that the information can be processed as necessary, such as encoding and modulation, before being sent from the source to the destination. The destination can also perform corresponding processing, such as decoding and demodulation, after receiving the information from the source, so as to interpret the valid information from the source. Similar expressions in the present application can be similarly understood, and will not be repeated here.

[0112] Thirdly, in the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. "And / or" describes the association relationship between the associated objects, which means that there can be three kinds of relationships, for example, A and / or B, which can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it, but does not rule out the case that the associated objects before and after it represent an "and" relationship. The specific meaning can be understood in combination with the context. "At least one of the following" or similar expressions means any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b or c can represent: a, b, c; a and b; a and c; b and c; or a and b and c. Where a, b, c can be single or multiple.

[0113] Fourthly, in the embodiments of the present application, the indication can include direct indication and indirect indication, and can also include explicit indication and implicit indication. The information indicated by certain information (the first indication information and the second indication information described below) is referred to as to-be-indicated information. In the implementation process, there are many ways to indicate the to-be-indicated information, for example, but not limited to, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or an index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, where the other information and the to-be-indicated information have an association relationship. The to-be-indicated information can also be indicated only by a part of the to-be-indicated information, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of a specific information can be achieved by means of the arrangement order of each information agreed in advance (for example, predefined by a protocol), thereby reducing the indication overhead to a certain extent. The specific manner of indication is not limited in the present application.

[0114] It can be understood that, for the sender of the indication information, the indication information can be used to indicate the to-be-indicated information, and for the receiver of the indication information, the indication information can be used to determine the to-be-indicated information.

[0115] Fifthly, in the embodiments of the present application, the descriptions such as "when", "in the case of", "if", and "whether" all refer to that the device (such as a terminal device, an access management device, or a session management device) will make corresponding processing under certain objective circumstances, and are not limited in time, and do not require the device (such as a terminal device, an access management device, or a session management device) to have a judgment action when implemented, nor does it mean that there are other limitations.

[0116] Sixthly, the storage or buffering involved in the present application can refer to storage or buffering in one or more memories. The one or more memories can be separately arranged or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially separately arranged and partially integrated in a decoder, a processor, or a communication device. The type of the memory can be any form of storage medium, and the present application does not limit this.

[0117] The technical solutions provided in the present application can be applied to various communication systems, for example: a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), a worldwide interoperability for microwave access (WiMAX) communication system, a 5th generation (5G) mobile communication system or a new radio access technology (NR), a satellite communication system, and the like. The 5G mobile communication system can include non-standalone (NSA) and / or standalone (SA).

[0118] The technical solutions provided in the present application can also be applied to future communication networks.

[0119] For the convenience of understanding, first, the network architecture applicable to the method provided in the embodiments of the present application is described in combination with the drawings.

[0120] FIG. 1 is a network architecture diagram of SBA in a 5G network provided in the embodiments of the present application. As shown in FIG. 1, the 5G network architecture can include three parts, which are terminal, data network (DN) and operator network.

[0121] The network elements involved in FIG. 1 are briefly described below.

[0122] 1. The terminal device can also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user equipment.

[0123] The terminal device is a device with wireless transceiver function. The terminal device can communicate with one or more core network (CN) devices (or core devices) through an access network device (or access device) in the wireless access network. The terminal device can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; can also be deployed on water (such as ships, etc.); can also be deployed in the air (such as airplanes, balloons and satellites, etc.).

[0124] The terminal device can also be a terminal in an internet of things (IoT) system, which can also be referred to as an IoT node. The IoT is an important component of future information technology development, and its main technical feature is to connect objects through communication technology and a network, thereby realizing an intelligent network of human-machine interconnection and object-object interconnection. The connection can be through broadband technology or narrow band (NB) technology. IoT technology can achieve mass connection, deep coverage, and terminal power saving through, for example, narrow band technology.

[0125] The terminal device in this application can be a hardware device, a software function running on special hardware, or a software function running on general hardware, and can also be a virtualized device, such as being implemented through general hardware and instantiated virtualization functions, or special hardware and instantiated virtualization functions. The general hardware can be a server, such as a cloud server.

[0126] 2. The operator network can include one or more of the following network elements: a network slice selection function (NSSF) network element, a network exposure function (NEF) network element, a network repository function (NRF), a policy control function (PCF), a unified data management (UDM) network element, an application function (AF) network element, an authentication server function (AUSF) network element, an access and mobility management function (AMF) network element, a network slice-specific authentication and authorization function (NSSAAF), a session management function (SMF) network element, a user plane function (UPF) network element, and an access network (AN) (such as a RAN network element), etc. Among the above operator network, except for the AN network element, the part can be referred to as a core network part. In the following, for the convenience of description, the word "network element" is omitted, such as the AMF network element is referred to as AMF, the SMF network element is referred to as SMF, the UPF network element is referred to as UPF, etc.

[0127] Among them, the RAN is a network composed of one or more RAN nodes, which is used to realize the functions of wireless physical layer, resource scheduling and radio resource management, radio access control and mobility management. The 5G-RAN can be connected through the user plane interface N3 and the user plane function (UPF) to transmit the data of the terminal; the 5G-RAN establishes a control plane signaling connection through the control plane interface N2 and the access and mobility management function (AMF), which is used to realize the functions of radio access bearer control, etc.

[0128] The RAN node can provide wireless communication function services and access the terminal device to the wireless network. The RAN node can also be referred to as a RAN device, or an access network device, etc.

[0129] In one possible scenario, the RAN node can be a base station, an evolved Node B (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), or a base station in a future mobile communication system. The RAN node can be a macro base station, a micro base station, or an indoor station, a relay node or a donor node, or a radio controller in a cloud radio access network (CRAN) scenario, a node in an open radio access network (O-RAN or ORAN) scenario, etc. The RAN node can also be a RAN node in a non terrestrial network (NTN), i.e., the RAN node can be deployed in a high-altitude platform or a satellite. Optionally, the RAN node can also be a server.

[0130] In another possible scenario, a terminal is assisted by multiple RAN nodes to implement wireless access, and different RAN nodes respectively implement part of the functions of a base station. For example, the RAN node can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0131] In different systems, the CU (or CU-CP and CU-UP), DU or RU can also have different names, but those skilled in the art can understand their meanings. For example, in an open RAN (O-RAN or ORAN) system, the CU can also be referred to as an open CU (O-CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. Among them, any one of the CU (or CU-CP, CU-UP), DU and RU can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0132] The AMF is mainly responsible for terminal authentication, terminal mobility management (MM), network slice selection, SMF selection and the like; as an anchor point of N1 and N2 signaling connection and provides routing of N1 / N2 session management (SM) messages for the SMF; maintains and manages the state information of the terminal.

[0133] The SMF is mainly responsible for all control plane functions of terminal session management, including UPF selection, internet protocol (IP) address allocation, session quality of service (QoS) management, (from PCF) obtaining PCC (policy and charging control) policy and the like.

[0134] The UPF is an anchor point of a protocol data unit (PDU) session connection, and is responsible for data packet filtering, data transmission / forwarding, rate control, generating charging information and the like of the terminal.

[0135] The UDR is mainly used to store user data, including subscription data called by the UDM, policy information called by the PCF, structured data for capability exposure, application data called by the NEF and the like.

[0136] The UDM is mainly used to manage and control user data, such as management of subscription information, including obtaining subscription information from the UDR and providing it to other network elements (such as the AMF); generating 3rd generation partnership project (3GPP) authentication credentials for the terminal; registering and maintaining network elements currently serving the terminal (for example, the AMF represented by AMF ID1 is the current serving AMF, serving AMF, for the terminal).

[0137] The NEF is used for interaction between other internal network elements of the core network and application function (AF) network elements corresponding to application servers (AS) outside the core network, to provide network opening capabilities to the AF, or to provide information provided by the AF to the core network element.

[0138] The AUSF is an authentication server function, used for security authentication of a terminal when the terminal accesses the network.

[0139] The PCF mainly performs policy control such as quality of service (QoS) policy and charging policy. It provides configuration policy information for the terminal and provides policy information for controlling the terminal to the control plane network element (for example, AMF, SMF) of the network.

[0140] The AF mainly transmits the demand of the application side to the network side, and can be regarded as an application server or a proxy of the application server. The AF can interact with the core network element to provide some services, for example, interacting with the PCF to perform service policy control, interacting with the NEF to obtain some network capability information or providing some application information to the network, and providing some data network access point information to the PCF to generate corresponding data service routing information.

[0141] The NSSAAF interacts with the AMF or the slice authentication server to process the authentication and authorization of the network slice.

[0142] The DN mainly provides service services for users.

[0143] The network elements communicate with each other through interfaces. For example, the interface between the terminal and the AMF is the N1 interface, the interface between the AN and the AMF is the N2 interface, the interface between the AN and the UPF is the N3 interface, the interface between the SMF and the UPF is the N4 interface, and the interface between the UPF and the DN is the N6 interface. Some network elements can communicate based on a service-based interface. In FIG. 1, Nnssf, Nnef, Nnrf, Npcf, Nudm, Naf, Nausf, Namf, and Nsmf are service-based interfaces.

[0144] The above description of the network elements in the core network and the interfaces between the network elements is only exemplary and should not be construed as limiting the present application. In addition, each network element shown in FIG. 1 can be understood as a network element in the core network for implementing different functions. These core network elements can be independent devices or can be integrated into the same device to implement different functions. The specific form of the network elements is not limited in the present application.

[0145] It can be understood that the network element applied in the future communication system can be the network element described above, or can also be a network element with the same or similar function and other names, which is not limited in the present application.

[0146] In the following, taking a 5G network as an example, the defined regenerative network architecture in a non-terrestrial network (NTN) system is introduced in combination with FIG. 2. It can be understood that the regenerative network architecture can be applied in different networks.

[0147] FIG. 2 is a schematic diagram of a regenerative network architecture suitable for the method provided in the embodiments of the present application. In the regenerative forwarding architecture, the satellite can process the received signal, including demodulation, decoding, encoding, modulation and information processing, that is, the satellite has the function of all RAN nodes (or in other words, the RAN nodes in FIG. 1 are deployed on the satellite). As shown in FIG. 2, the terminal device communicates with the satellite base station, and the satellite base station communicates with the core network through the gateway station. Among them, the link between the terminal and the satellite is the service link, and the link between the gateway station and the satellite is the feeder link.

[0148] In the communication scenario shown in FIG. 2, the movement of the satellite can cause the service link to be connected and the feeder link to be disconnected; or the feeder link to be connected and the service link to be disconnected. As shown in FIG. 3, when the satellite moves to position 1, the service link is connected and the feeder link is disconnected; when the satellite moves to position 2, neither the service link nor the feeder link is connected; when the satellite moves to position 3, the feeder link is connected and the service link is disconnected. That is, in the regenerative forwarding satellite architecture, the service link and / or the feeder link can not be available at all times.

[0149] In this feeder discontinuous scenario, for uplink (UL), when the terminal device accesses the regenerative forwarding satellite (i.e., the service link is connected), if the feeder link is not available, the satellite needs to store the UL information from the terminal device, and when the feeder link is available, the satellite forwards the stored UL information to the core network. For downlink (DL), the ground network sends DL information to the regenerative forwarding satellite (i.e., the feeder link is connected), and if the service link is not available at this time, the regenerative forwarding satellite needs to store the DL information from the ground network, and when the service link between the terminal device and the regenerative forwarding satellite is available, the stored DL information is forwarded to the terminal device. In the above feeder discontinuous scenario, the working mode of the satellite can be referred to as a store and forward (S&F) satellite operation mode.

[0150] In summary, in the feeder discontinuous scenario, only one of the service link and the feeder link is in a connected state, and the store-and-forward mode needs to be used to implement information transmission between the terminal and the ground network. The S&F satellite operating mode can be used to transmit services with high delay tolerance or non-real-time, such as cellular internet of things (CIoT) / machine type communication (MTC), short message service (SMS), and the like.

[0151] In combination with the architecture shown in FIGS. 1 and 2, for uplink, the terminal device needs to complete an access procedure (for example, a registration procedure) and a session establishment procedure (for example, a protocol data unit (PDU) session establishment procedure) before sending UL information to the network. Therefore, the required time length of the registration procedure and the session establishment procedure affects the transmission delay of the uplink information.

[0152] In the 5G procedure, the terminal device needs the participation of the AMF, the AUSF, and the UDM in the core network to complete the registration procedure, and the participation of the AMF, the SMF, and the UDM in the core network to complete the PDU session establishment procedure. Further, the participation of the UPF network element in the core network is needed to complete the subsequent sending of UL information of the terminal device and the reception of DL information of the terminal device. For the architecture shown in FIG. 1, when the RAN node is the RAN node in the ground network, the store-and-forward operating mode described above does not exist, and therefore the terminal device can not need to wait for the connection of the service link and / or the feeder link, and can complete the access and session establishment in a timely manner, and then send uplink data. For the architecture shown in FIG. 2, the access procedure and the session establishment procedure need multiple connections of the service link and multiple connections of the feeder link, and therefore the transmission delay of the UL information is increased.

[0153] In order to improve the efficiency of the store-and-forward operating mode, the core network as a whole is considered to be launched into space, so that the terminal device and the satellite can complete the registration and PDU session establishment procedures in a single connection of the service link, so as to send UL information of the terminal device. The core network network element launched into space can include network elements participating in the registration procedure and the PDU session procedure, such as the AMF, the AUSF, the UDM, and the SMF network element.

[0154] The overall satellite core network solution can be a process of terminal device accessing the core network and terminal device and core network establishing a session. The process is only for passing through the UPF or introducing a satellite store and forward proxy (SSFP) and a satellite store and forward client (SSFC) on the ground, and the SSFC is responsible for routing data sent by the satellite to the ground. Therefore, the user plane device in the present application can be a UPF or a SSFP.

[0155] The scheme of introducing SSFP and SSFC will be briefly introduced below in combination with FIG. 4. As shown in FIG. 4, the service link is connected at T1, and the terminal device can access the satellite and send uplink data at T1, and the uplink data and network access information are cached by the SSFP on the satellite, wherein the network access information is used for the subsequent SSFC on the ground to determine how to send the uplink data. At T2, the feeder link is connected, the SSFP on the satellite is connected with the SSFC on the ground, and the previously stored uplink data and network access information are sent to the SSFC; after obtaining the network access information and the uplink data, the SSFC performs a session establishment process with the ground network in the identity of the terminal device according to the network access information, and sends the uplink data to the DN using the established session.

[0156] The use of SSFC in the form of terminal device to establish a session with the ground network according to the network access information to send uplink data is for the purpose that in the assumption of the 3rd generation partnership project (3GPP), the routing information of the data packet cannot guarantee that the data is sent to the DN (for example, some private DN), and the role of the 3GPP network can be selected by establishing a session. A specific user plane device can establish a link with the DN required by the session to send data. Therefore, the above scheme can reuse the registration and session establishment process defined by the 3GPP as much as possible to connect to the DN to send data.

[0157] It should be noted that the above terminal device accessing the satellite and the SSFC accessing the ground network can include attachment and session establishment in the LTE network, or registration and session establishment process in the 5G network, wherein the corresponding system of the terminal device accessing the satellite process and the SSFC accessing the ground network process needs to be consistent, for example, both are 5G processes or both are LTE processes.

[0158] The user access control in the standard technical specification (TS) 33.501 is divided into a primary authentication based on a global universal subscriber identity module (USIM) and an authentication procedure based on a user (user) identity (ID). Among them, the authentication procedure based on the user ID can be a network slice-specific authentication and authorization (NSSAA) or a secondary authentication. The primary authentication based on the USIM and the authentication based on the user ID respectively authenticate the authenticity of a subscription permanent identifier (SUPI) and the user ID based on a cryptographic means. Among them, the slice authentication refers to the authentication of the right of the terminal device to use a network slice described below; the secondary authentication refers to the authentication of the right of the terminal device to access a DN described below.

[0159] The slice authentication is used to authenticate the terminal device applying to use a certain network slice, so as to ensure the access control to a specific network slice. Exemplarily, the terminal device carries single network slice selection assistance information (S-NSSAI) of the network slice applying to access in a registration request, the AMF determines whether the network slice applied by the terminal device needs to perform the slice authentication, and if so, indicates the slice to the terminal device in the form of a pending S-NSSAI in a registration success message. And after the slice authentication procedure is performed between the network side and the terminal device, the establishment of the PDU session of the terminal device is performed again in the case of successful slice authentication. In the slice authentication process, the network slice authentication, authorization and accounting server (NS-AAA) server deployed outside the core network and responsible for the slice authentication is responsible for verifying the user ID provided by the terminal device for the slice authentication based on a cryptographic means.

[0160] The form of the pending S-NSSAI sent by the AMF is specifically that the network slice requiring slice authentication is included in the pending S-NSSAI list. After receiving the pending S-NSSAI, if the terminal device wants to initiate session establishment using the network slice in the list, the terminal device needs to first pass the slice authentication for the network slice, and then the AMF includes the slice in the allowed S-NSSAI list and sends it to the terminal device, and then the terminal device can initiate session establishment using the slice in the list.

[0161] The secondary authentication is used to authenticate the terminal device applying to access a certain DN, to ensure access control to a specific DN. Specifically, the terminal device carries the DNN applying for access in the PDU session establishment process, and the SMF triggers secondary authentication according to the information in the terminal device subscription in the UDM that needs secondary authentication for the DNN, and performs the secondary authentication process with the terminal device in the PDU session establishment process, wherein the data network authentication, authorization and accounting server (DN-AAA) server deployed outside the core network is responsible for verifying the User ID provided by the terminal device for secondary authentication based on cryptographic means. After the secondary authentication is successful, a response of successful session establishment is sent to the terminal device, and then the terminal device sends data using the session.

[0162] It should be noted that the slice authentication for the terminal device to use a specific slice and the secondary authentication for the terminal device to access a specific DN are not necessarily performed. For example, whether the slice authentication is performed depends on the local policy configuration of the AMF serving the terminal device in the serving network of the terminal device, and whether the secondary authentication is performed depends on the subscription of the terminal device for the DN.

[0163] Since the slice authentication process is performed before the session establishment process, the transmission delay of uplink data is additionally increased when the slice authentication is performed. When the secondary authentication process is performed, the session establishment process needs to be interrupted, so the secondary authentication also increases the transmission delay of uplink data. As described above, slice authentication and secondary authentication require different AAA servers for verification, and the AAA server is located in the ground network. Therefore, compared with the traditional ground network architecture, in the regenerative network architecture shown in FIG. 2, the slice authentication process and / or the secondary authentication process need to be connected multiple times through the service link and the power feeding link to be completed, which greatly increases the transmission delay of uplink data.

[0164] The following shows the number of possible connections of the service link and the feeder link in the store-and-forward mode in the scenario where slice authentication and secondary authentication need to be performed: first, the service link is connected for the first time, the terminal device completes the registration process, and the AMF initiates the slice authentication process; the feeder link is connected for the first time, and the AMF obtains the slice authentication result from the NS-AAA server; the service link is connected for the second time, and after the terminal device obtains the authentication result of the network slice from the AMF, the terminal device initiates the session establishment process. Then, the SMF triggers the secondary authentication process; the feeder link is connected for the second time, and the SMF obtains the secondary authentication result from the DN-AAA server; the service link is connected for the third time, the terminal device obtains the secondary authentication result from the SMF, and completes the session establishment, and sends the uplink data to the UPF; the feeder link is connected for the third time, and the UPF sends the received uplink data to the DN.

[0165] Therefore, since the slice authentication and / or the secondary authentication need to involve the AAA server (including the NS-AAA and / or the DN-AAA) located outside the core network, and the NS-AAA and the DN-AAA do not belong to the operator, the NS-AAA is deployed by the slice owner, and the DN-AAA is deployed by the DN, it is difficult to implement on-board deployment of the AAA server. That is, in the S&F working mode, the terminal device may not be able to complete the registration and PDU session establishment process and send the uplink data during a single service link connection due to the need to perform slice authentication and / or secondary authentication, which increases the transmission delay of the uplink data.

[0166] Therefore, the embodiments of the present application provide a communication method and related apparatus, in which, during a single service link connection, the terminal device performs the process of accessing the non-terrestrial network, and regardless of whether the slice authentication process is performed or the slice authentication result, the terminal device directly initiates the session establishment process; and / or, during the session establishment, regardless of whether the secondary authentication process is performed or the secondary authentication result, the session establishment process continues to be performed. Then, after the session establishment is successful, the terminal device sends the uplink data to the user plane device, which can reduce the time delay. Further, when waiting for the feeder link to be connected, the session management network element obtains the slice authentication result and / or the secondary authentication result, and according to the slice authentication result and / or the secondary authentication result, instructs the user plane device to send the buffered uplink data to the data network. The method can complete the access process, the session establishment process, and the sending of the uplink data during a single service link connection in the scenario where slice authentication and / or secondary authentication need to be performed, effectively reducing the transmission delay of the uplink data caused by waiting for the authentication result.

[0167] The communication method provided by the embodiments of the present application is described in detail below in combination with FIGS. 5 to 7. The method provided by the present application can be applied to the network architecture shown in FIGS. 1 and 2, but the embodiments of the present application are not limited thereto.

[0168] In the flowcharts shown in FIGs. 5-7, the method is shown from the perspective of device interaction, but the application does not limit the subject of the method execution. For example, the terminal device in FIGs. 5-7 can be replaced by a chip, a chip system, or a processor supporting the terminal device to implement the method, and can also be a logical module or software capable of implementing all or part of the terminal device functions; the access management device in FIGs. 5-7 can be replaced by a chip, a chip system, or a processor supporting the access management device to implement the method, and can also be a logical module or software capable of implementing all or part of the access management device functions; the session management device in FIGs. 5-7 can be replaced by a chip, a chip system, or a processor supporting the access management device to implement the method, and can also be a logical module or software capable of implementing all or part of the session management device functions; the user plane device in FIGs. 5-7 can be replaced by a chip, a chip system, or a processor supporting the user plane device to implement the method, and can also be a logical module or software capable of implementing all or part of the user plane device functions.

[0169] Exemplarily, the access management device shown in FIGs. 5-7 can be an AMF, the session management device can be an SMF, the user plane device can be a UPF, the authentication server of the first network slice can be an NS-AAA, and the authentication server of the DN can be a DN-AAA server.

[0170] FIG. 5 is a schematic flowchart of a communication method 500 provided by an embodiment of the application. As shown in FIG. 5, the method 500 can include S501-S510. The steps in the method 500 are described in detail below.

[0171] S501, the terminal device sends a first request to the access management device, the first request being used to request access to a non-terrestrial network, and the first request including an identity of one or more network slices requested by the terminal device. Correspondingly, the access management device receives the first request from the terminal device.

[0172] The access management device in the application is located in a non-terrestrial network. The non-terrestrial network can be any network other than a terrestrial network deployed by a mobile operator, such as a satellite network or a network deployed on a non-fixed platform. The network deployed on a non-fixed platform can be, for example, an isolated operation for public safety (IOPS) network, a network deployed on a vehicle, a network deployed on a low-altitude platform, or a network deployed on a ship. For example, when the non-terrestrial network is a satellite, the access management device is deployed on the satellite, and for another example, when the non-terrestrial network is an IOPS network, the access management device is deployed in the IOPS network.

[0173] Exemplarily, the first request can be a registration request or an attach request, or other request defined in future communication system for requesting to access a network. The present application does not limit the name of the first request.

[0174] The network slice in the present application is used to provide a logical network with specific network functions and characteristics. Exemplarily, the network slice can be identified by S-NSSAI. Alternatively, the identification of the network slice in the present application can be S-NSSAI.

[0175] It can be understood that the one or more network slices requested by the terminal device can include a network slice (referred to as a first type of network slice for convenience of description) that allows the terminal device to use, and / or a network slice (referred to as a second type of network slice for convenience of description) that does not allow the terminal device to use. Specifically, the network slice that allows the terminal device to use refers to a network slice that does not need to be authenticated, and the network slice that does not allow the terminal device to use refers to a network slice that needs to be authenticated. Specifically, the network slice that needs to be authenticated needs to be authenticated and / or authorized before the terminal device accesses the network slice, and the state of the terminal device accessing the network slice before the terminal device is authenticated and / or authorized by the network slice is referred to as a to-be-authenticated state, or simply a network slice to-be-authenticated. The network slice that does not need to be authenticated does not need to be authenticated and / or authorized, and the state of the terminal device accessing the network slice can be referred to as an authenticated state or a non-authentication state, which can be simply referred to as a network slice authenticated or non-authentication.

[0176] S502, the access management device sends a first response to the terminal device, and the first response carries the identification of the first network slice, and the first network slice is included in the one or more network slices. Correspondingly, the terminal device receives the first response from the access network device.

[0177] The first response in the present application can be a response made by the access management device to the first request. For example, when the first request is a registration request (registration accept), the first response can be a registration accept (registration accept) message. However, the present application does not limit this. For example, there are other messages between the first request and the first response, and the other messages can be a response made to the first request.

[0178] Optionally, the first response can also carry the identification of the remaining network slices in the one or more network slices requested by the terminal device, in addition to the first network slice. When the first response carries the identification of the one or more network slices requested by the terminal device, the identification of the one or more network slices can be sent to the terminal device in different forms.

[0179] In a first possible implementation, in a case where the one or more network slices requested by the terminal device include the first type of network slice and the second type of network slice, the access management device can send the first type of network slice to the terminal device in the form of a list of allowed-to-use slices, and send the second type of network slice to the terminal device in the form of a list of slices-to-be-authenticated.

[0180] That is, in a case where the one or more network slices requested by the terminal device include the first type of network slice and the second type of network slice, the access management device includes the list of allowed-to-use slices and the list of slices-to-be-authenticated in the first response sent by the access management device. The list of allowed-to-use slices includes the identifier of the first type of network slice, and the list of slices-to-be-authenticated includes the identifier of the second type of network slice.

[0181] Optionally, the access management device stores the list of slices-to-be-authenticated sent to the terminal device.

[0182] In a second possible implementation, in a case where the one or more network slices requested by the terminal device include the first type of network slice and the second type of network slice, the access management device can send the first type of network slice and the second type of network slice to the terminal device in the form of a list of allowed-to-use slices.

[0183] That is, in a case where the one or more network slices requested by the terminal device include the first type of network slice and the second type of network slice, the first response sent by the access management device includes a list of allowed-to-use slices, but does not include a list of slices-to-be-authenticated. The list of allowed-to-use slices includes the identifier of the first type of network slice and the identifier of the second type of network slice. That is, in the present application, when receiving the one or more network slices requested by the terminal device, the access management device can place the identifiers of the network slices allowed to use and the identifiers of the network slices not allowed to use in the list of allowed-to-use slices regardless of the authentication status of the network slices, and send the list to the terminal device.

[0184] Alternatively, the S502 can be replaced by: the access management device sends a first response to the terminal device, the first response being used to indicate at least one network slice authenticated by the terminal device, the at least one network slice including the first network slice. The at least one network slice can include the second type of network slice in the one or more network slices requested by the terminal device.

[0185] S503, in a case where the slice authentication state of the first network slice is to be authenticated, the terminal device sends a session request to the access management device, the session request being used to request establishment of a session in which the terminal device transmits data through the non-terrestrial network, and the session request comprising the identity of the first network slice. Correspondingly, the access network management device receives the session request from the terminal device.

[0186] It can be understood that the session requested to be established by the session request described above can also be used for the terminal device to receive data through the non-terrestrial network.

[0187] Exemplarily, the session requested to be established by the session request can be a PDU session.

[0188] Optionally, the slice authentication state of the first network slice being to be authenticated comprises that no authentication result of the first network slice is received, and / or the identity of the first network slice is located in the to-be-authenticated slice list.

[0189] The no authentication result of the first network slice being received comprises that the access management device has not triggered the authentication process of the network slice, or the access network device has triggered the authentication process of the network slice but the terminal device has not received the authentication result, or the first network slice belongs to the first type of network slice. The timing at which the access management device triggers the authentication process of the network slice is not limited by the present application, for example, it can be before, at or after sending the first response (such as after receiving the session request).

[0190] Alternatively, S503 can be replaced by: regardless of the slice authentication state of the first network slice (that is, regardless of whether the identity of the first network slice is located in the to-be-authenticated slice list or in the allowed-to-use slice list), the terminal device sends the session request carrying the identity of the first network slice to the access management device.

[0191] Optionally, if the identity of the network slice received by the terminal device is sent in the form described in the first possible implementation manner described above, when the terminal device needs to access the network slice identified by the identity in the to-be-authenticated slice list, the terminal device can regard the network slice identified by the identity in the to-be-authenticated slice list as an allowed-to-use network slice to initiate the session request. That is, the identity of the first network slice can be located in the to-be-authenticated slice list.

[0192] Optionally, if the identity of the network slice received by the terminal device is sent in the form described in the second possible implementation manner described above, the terminal device selects the slice identity of the first slice from the allowed-to-use slice list and carries it in the session request. The specific implementation manner can be referred to the description in the 3GPP technical specification (TS) 23.502, which will not be described here again.

[0193] In the embodiments of the present application, the terminal device can directly send a session request carrying the first network slice to the access management device when receiving the first response carrying the first network slice, regardless of the slice authentication state of the first network slice. That is, when the first network slice belongs to the network slice to be authenticated, the terminal device can directly initiate a session request carrying the first network slice without waiting for the authentication result of the first network slice. Compared with the solution in which the terminal device needs to receive the authentication result of the first network slice and then initiates the session establishment process, the method provided in the present application can effectively reduce the time delay caused by waiting for the authentication result of the network slice. In particular, in the non-terrestrial communication scenario (i.e., the store-and-forward working mode), the terminal device can not need to wait for the authentication result of the network slice. Therefore, the terminal device can complete the session establishment in a single link connection, and then send uplink data, thereby effectively reducing the transmission time delay of the uplink data.

[0194] Optionally, after S503, the method 500 further includes: S504, in a case where the slice authentication state of the first network slice is to be authenticated, the access management device sends a second request to the session management device, the second request being used to request to establish a session, the session being the session requested by the terminal device to send data through the non-terrestrial network. Correspondingly, the session management device receives the second request from the access management device.

[0195] The session management device in the present application is located in the non-terrestrial network.

[0196] The second request herein can be understood as that the terminal device sends information used to request to establish a session to the session management device through the access management device. Specifically, the information used to request to establish a session can be an N1 session management container (N1 SM container).

[0197] Optionally, the second request can carry the identifier of the first network slice.

[0198] In the present application, the access management device can continue to perform the subsequent session establishment process after receiving the session request carrying the first network slice, regardless of the authentication state of the first network slice, thereby effectively reducing the time delay caused by waiting for the authentication result of the first network slice.

[0199] Optionally, the method 500 further includes: the access management device determines that the state of the first network slice is to be authenticated.

[0200] Exemplarily, if the identity of the first network slice is located in the to-be-authenticated slice list at the side of the access management device, the access management device can determine that the authentication state of the first network slice is to-be-authenticated. Optionally, the access management device can determine whether the identity of the first network slice is located in the to-be-authenticated slice list at the side of the access management device according to the to-be-authenticated slice list of the terminal device stored in S502.

[0201] It should be noted that, in the case that the first network slice belongs to the second type of network slice, in S502, the identity of the first network slice in the first response sent by the access management device is located in the to-be-authenticated slice list (i.e., the first implementation manner in S502) or the allowed-to-use slice list (i.e., the second implementation manner in S502), and at the side of the access management device, the identity of the first network slice is located in the to-be-authenticated slice list.

[0202] The step (referred to as step 1) of determining, by the access management device, that the state of the first network slice is to-be-authenticated can be performed before or after S504, and the application does not limit the execution order of step 1 and S504. However, it should be noted that if step 1 is performed before S504, even if the access management device determines that the identity of the first network slice is located in the to-be-authenticated slice list at the side of the access management device, the access management device can continue to perform S504 in the case that the slice authentication state of the first network slice is to-be-authenticated.

[0203] Optionally, in the case that the authentication state of the first network slice is to-be-authenticated, the method 500 can further include: triggering, by the access management device, an authentication process of the first network slice.

[0204] Exemplarily, the authentication process of the first network slice can include: obtaining first authentication information of the first network slice; and obtaining a first authentication result of the first network slice based on the first authentication information. The first authentication information is used to authenticate the permission of the terminal device to use the first network slice, and the first authentication result is used to indicate that the authentication of the first network slice is successful, or is used to indicate that the authentication of the first network slice is unsuccessful (or in other words, is used to indicate that the authentication of the first network slice fails).

[0205] For detailed description of obtaining the first authentication information, refer to the description in S507 and S508 below, which will not be described here in detail. For detailed description of obtaining the first authentication result, refer to the related description in method 600 below, which will not be described here in detail.

[0206] Optionally, the session request sent by the terminal device can further include a DNN, the DNN being a name of the DN requested by the terminal device, or in other words, the DNN being a DN accessed by the terminal device. Similarly, the second request can further include the DNN. Optionally, the session request can further include an N1 session management container, and the second request can also include the N1 session management container.

[0207] Optionally, after S504, the method 500 further includes: S505, in a case where the authentication of the permission of the terminal device to access the DN is not completed, the session management device sends a second response to the access management device, the second response being used to indicate that the session establishment is successful. Correspondingly, the access management device receives the second response from the session management device.

[0208] The second response can be a response made by the session management device to the second request.

[0209] The authentication of the permission of the terminal device to access the DN not being completed includes that the session management device does not receive an authentication result of the permission of the terminal device to access the DN, or that the authentication of the permission of the terminal device to access the DN has not been triggered.

[0210] Optionally, the method 500 further includes: the session management device determines that the permission of the terminal device to access the DN needs to be authenticated based on subscription information of the terminal device. The subscription information of the terminal device can be obtained by the session management device from a UDM.

[0211] The step of determining that the permission of the terminal device to access the DN needs to be authenticated (referred to as step 2) can be executed before or after S505, and the application does not limit the execution order of step 2 and S505. However, it should be noted that if step 2 is executed before S505, even if the session management device determines that the permission of the terminal device to access the DN needs to be authenticated, the session management device can still continue to execute S505 in a case where the authentication of the permission of the terminal device to access the DN is not completed.

[0212] Optionally, in a case where it is determined that the permission of the terminal device to access the DN needs to be authenticated, the method 500 further includes: the session management device triggers an authentication procedure of the DN.

[0213] Exemplarily, the authentication procedure of the DN can include: obtaining second authentication information of the DN; and obtaining a second authentication result of the DN based on the second authentication information. The second authentication information is used to authenticate the permission of the terminal device to access the DN, and the second authentication result is used to indicate that the authentication of the permission of the terminal device to access the DN is successful, or to indicate that the authentication of the permission of the terminal device to access the DN is not successful (or in other words, only the authentication of the permission of the terminal device to access the DN fails).

[0214] For details of obtaining the second authentication information, refer to the description in S509 and S510 below, which are not described here in detail. For details of obtaining the second authentication result, refer to the related description in method 700 below, which is not described here in detail.

[0215] Optionally, the method 500 further includes: S506, the access management device sends a session response to the terminal device, the session response being used to indicate that the session establishment is successful. Correspondingly, the terminal device receives the session response from the access management device.

[0216] The session response can be a response made by the session management device to the session request. The second response described above can be understood as a session response sent by the session management device to the terminal device through the access management device.

[0217] In this application, after receiving the second request carrying the DNN, the session management device can further determine whether the DN identified by the DNN needs to be authenticated, but the session management device can ignore the authentication result of the DN and directly reply to the terminal device with a response indicating that the session establishment is successful, effectively reducing the time delay caused by waiting for the authentication result of the DN.

[0218] Optionally, after S504, the method 500 further includes: the session management device sends second indication information to the user plane device, the second indication information being used to indicate to cache data of the session, the data of the session being uplink data sent by the terminal device through the session after the session establishment is successful. Correspondingly, the user plane device receives the second indication information from the session management device.

[0219] The second indication information can be carried in an N4 message.

[0220] Optionally, after S506, the method 500 further includes: the terminal device sends uplink data to the user plane device using the session. Correspondingly, the user plane device receives the uplink data from the terminal device. Optionally, after receiving the uplink data, the user plane device caches the uplink data according to the received second indication information. The caching of the uplink data means that the uplink data is not sent temporarily.

[0221] In the present application, in the case that the terminal device needs to be authenticated for the first network slice to which the terminal device requests to access, the terminal device initiates a session procedure without waiting for the authentication result of the network slice, and / or in the case that the DN to which the terminal device requests to access needs to be authenticated, the session management device sends a message of session success to the terminal device without waiting for the authentication result of the DN. That is, the terminal device sends uplink data in the case that the network slice is not authenticated successfully and / or the DN is not authenticated successfully. However, for network security, the session management device sends information for indicating to cache the uplink data in advance, so that the user plane device caches the uplink data when receiving the uplink data. Thus, the user plane device transmits the data when the feeder link is connected after the authentication is successful.

[0222] Optionally, before S503, the method 500 further includes: determining, by the terminal device, to access a non-terrestrial network in which a network element for implementing the access procedure and the session establishment procedure is deployed; and / or determining, by the terminal device, to perform uplink communication or downlink communication in a store-and-forward mode.

[0223] Illustratively, the determining, by the terminal device, to access the non-terrestrial network includes: receiving, by the terminal device, broadcast information from a RAN node on a satellite, the broadcast information being used to indicate that the access mode is a satellite access mode; and determining, by the terminal device, to access the non-terrestrial network based on the broadcast information.

[0224] The satellite access mode can be used for the terminal device to perceive that the RAN node and the corresponding core network thereof are on the satellite rather than the non-terrestrial network.

[0225] Optionally, the broadcast information can also be used to indicate that the working mode of the satellite is a store-and-forward mode. In this way, the terminal device can determine to perform uplink communication or downlink communication in a store-and-forward mode based on the broadcast information.

[0226] Illustratively, the above broadcast information can indicate the access mode of the terminal device and the mode of uplink communication or downlink communication by carrying a specific identifier, which can be a specific network identifier, such as a satellite ID, etc.

[0227] Optionally, before S504, the method 500 further includes: determining, by the access management device, that the terminal device accesses a non-terrestrial network in which a network element for implementing the access procedure and the session establishment procedure is deployed; and / or determining, by the access management device, that the terminal device performs uplink communication or downlink communication in a store-and-forward mode.

[0228] In an implementation, the access management device can determine, according to a local configuration, that it is deployed in a non-terrestrial network, and then determine, when the access request of the terminal device is obtained, that the terminal device accesses the non-terrestrial network, or that the terminal device performs uplink communication or downlink communication in the store-and-forward mode. The local configuration can be indication information indicating that the access management device is deployed in a non-terrestrial network, or can be indication information indicating that the store-and-forward mode is used.

[0229] Optionally, before S505, the method 500 further includes: the session management device determining that the terminal device accesses a non-terrestrial network in which a network element for implementing an access procedure and a session establishment procedure is deployed; and / or, the session management device determining that the terminal device performs uplink communication or downlink communication in the store-and-forward mode.

[0230] In an implementation, the session management device can determine, according to a local configuration, that it is deployed in a non-terrestrial network, and then determine, when the information for requesting to establish a session of the terminal device is obtained, that the terminal device accesses the non-terrestrial network, or that the terminal device performs uplink communication or downlink communication in the store-and-forward mode. The local configuration can be indication information indicating that the session management device is deployed in a non-terrestrial network, or can be indication information indicating that the store-and-forward mode is used.

[0231] Optionally, the method 500 further includes: S508, the access management device sending a third request to the terminal device, the third request being used for requesting to obtain first authentication information. Correspondingly, the terminal device receives the third request from the access management device.

[0232] The S508 can be executed before S504, or after S504, or simultaneously with S504, and the application does not limit the order of sending the second request and the third request.

[0233] Optionally, the method 500 further includes: S509, the terminal device sending the first authentication information to the access management device. Correspondingly, the access management device receives the first authentication information from the terminal device.

[0234] Optionally, the method 500 further includes: S511, the session management device sending a fourth request to the terminal device, the fourth request being used for obtaining second authentication information. Correspondingly, the terminal device receives the fourth request from the session management device.

[0235] The fourth request and the second response can be sent simultaneously or separately. For example, the fourth request is sent before the second response, or the fourth request is sent after the second response, or the fourth request is carried in the second response simultaneously. The application does not limit the order of sending the fourth request and the second response.

[0236] Optionally, the method 500 further includes: S512, the terminal device sends the second authentication information to the session management device. Correspondingly, the session management device receives the second authentication information from the terminal device.

[0237] Optionally, in the store-and-forward working mode, after receiving the second authentication information, the session management device can store the second authentication information, so as to send the second authentication information through the authentication server of the DN to obtain the second authentication result when the non-terrestrial network is connected with the terrestrial network.

[0238] FIG. 6 is a schematic flowchart of another communication method 600 provided by an embodiment of the present application. As shown in FIG. 6, the method 600 can include S601 to S604. The steps in the method 600 are described in detail as follows.

[0239] S601, the access management device sends a second request to the session management device, the second request being used to request to establish a session in which the terminal device sends data through the non-terrestrial network, and the second request carrying an identifier of the first network slice. Correspondingly, the session management device receives the second request from the access management device.

[0240] The description of the second request can refer to the related description in S504 in the foregoing, which is not described here again.

[0241] S602, the session management device sends a second response to the access management device, the second response being used to indicate that the session establishment is successful. Correspondingly, the access management device receives the second response from the session management device.

[0242] The description of the second response can refer to the related description in S505 in the foregoing, which is not described here again.

[0243] S603, the access management device sends the first authentication result to the session management device. Correspondingly, the session management device receives the first authentication result from the access management device.

[0244] Optionally, before S603, the method 600 further includes: the access management device sends the first authentication information to the authentication server of the first network slice. Correspondingly, the authentication server of the first network slice receives the first authentication information from the access management device.

[0245] The description of the first authentication information can refer to the description in S508 and S509 in the foregoing, which is not described here again.

[0246] Optionally, the method 600 further includes: the authentication server of the first network slice sending the first authentication result to the access management device. Correspondingly, the access management device receives the first authentication result from the authentication server of the first network slice.

[0247] Optionally, the method 600 further includes: the authentication server of the first network slice sending the first authentication result to the access management device. Correspondingly, the access management device receives the first authentication result from the authentication server of the first network slice.

[0248] Optionally, the authentication server of the first network slice is located in the ground network. For example, in the store-and-forward mode, the process of obtaining the first authentication result needs to be performed when the feeder link is connected.

[0249] Optionally, the authentication server of the first network slice sends the first authentication information to the access management device through the NSSAAF.

[0250] S604, in the case where the first authentication result indicates that the first network slice is successfully authenticated, the session management device sends first indication information to the user plane device, the first indication information being used to indicate the data of the session. Correspondingly, the user plane device receives the first indication information from the session management device. Further, the user plane device can send the buffered data according to the first indication information.

[0251] Optionally, the data of the session sent by the user plane device is uplink data sent by the terminal device through the session, and the session refers to the session established in S602.

[0252] Optionally, the user plane device is located in the non-ground network.

[0253] Optionally, in the case where the first authentication result indicates that the first network slice is not successfully authenticated, the session management device does not send the first indication information, or sends information used to indicate that the data of the session is discarded to the user plane device.

[0254] In the session establishment process, the network side does not wait for the authentication result of the terminal device accessing the network slice, but sends a response of successful session establishment to the terminal device, so that the terminal device can efficiently send uplink data. After receiving the first authentication result from the access management device, the session management device can instruct the user plane device to send the buffered uplink data based on the first authentication result. Thus, the latency caused by waiting for the authentication result of the network slice can be effectively reduced. In particular, in a non-ground communication scenario (i.e., a store-and-forward working mode), the terminal device can not need to wait for the authentication result of the network slice from the ground authentication server, so that the session establishment and uplink data transmission can be completed in a single link connection. In addition, the uplink data can be transmitted after the authentication result is received, which also realizes data transmission after successful network slice authentication.

[0255] Only the first authentication information used for authenticating the right of the terminal device to use the first network slice is obtained, and after the session establishment is successful, the access management device obtains the authentication result of the first network slice through the first authentication information and sends the first authentication result to the session management device, so that the session management device can instruct the user plane device to send the buffered uplink data based on the first authentication result. In a store-and-forward mode, the method provided in the present application can establish a session, obtain uplink data, and obtain first authentication information in a single link connection, complete network slice authentication and uplink data transmission in another link connection, and effectively reduce the transmission latency of uplink data.

[0256] Optionally, before S601, the method 600 further includes: the access management device and / or the session management device determine that the terminal device accesses a non-ground network in which a network element for implementing the access process and the session establishment process is deployed; and / or the access management device and the session management device determine that the terminal device performs uplink communication or downlink communication in a store-and-forward mode.

[0257] The process can refer to the related description in the method 500, which will not be repeated here.

[0258] Optionally, before S601, the method 600 further includes: S501 to S503 in the method 500. For brevity, the details will not be repeated here.

[0259] Optionally, after the access management device receives the session request from the terminal device, the method 600 further includes: the access management device determines that the authentication state of the first network slice is to be authenticated.

[0260] The process can refer to the description of step 1 in the method 500, which will not be repeated here.

[0261] Optionally, in the case that the authentication state of the first network slice is to be authenticated, the method 600 further comprises S507 and S508 in the method 500. For brevity, the details are not repeated here.

[0262] Optionally, before S603, the method 600 further comprises: the access management device sends first authentication waiting indication information to the session management device, the first authentication waiting indication information being used to indicate that the first network slice needs to be authenticated. Correspondingly, the session management device receives the first authentication waiting indication information.

[0263] Further, the session management device acquires the first authentication waiting indication information, and determines that S604 can be continued after the first authentication result is acquired; if the session management device does not acquire the first authentication waiting indication information, the first authentication result does not need to be waited for, and the first indication information can be directly sent to the user plane device.

[0264] The description of the third information and the first authentication information can refer to the description in S507 and S508 above, and is not repeated here.

[0265] It can be understood that the embodiments shown in FIGS. 5 and 6 can be combined with each other or independently implemented. When FIGS. 5 and 6 are independently implemented, more or fewer steps than those shown in FIGS. 5 and 6 can be performed; when the embodiments shown in FIGS. 5 and 6 are combined, the method provided by the present application can comprise S501 to S506, and in the case that the authentication state of the first network slice is to be authenticated, S507, S508, and the following steps in the method 600 are continued: the access management device sends the first authentication information to the authentication server of the first network slice, the authentication server of the first network slice sends the first authentication result to the access management device, S603, and S604. Other more detailed processes can refer to the description of the embodiments shown in FIGS. 5 and 6 above.

[0266] FIG. 7 is a schematic flowchart of another communication method 700 provided by an embodiment of the present application. As shown in FIG. 7, the method 700 can comprise S701 to S705. The steps in the method 700 are described in detail as follows.

[0267] S701, the access management device sends a second request to the session management device, the second request being used to request to establish a session in which the terminal device sends data through the non-terrestrial network, and the second request carries a DNN. Correspondingly, the session management device receives the second request from the access management device.

[0268] The description of the second request can refer to the related description in S504 above, and is not repeated here.

[0269] S702, the session management device sends a second response to the access management device, the second response being used to indicate that the session establishment is successful. Correspondingly, the access management device receives the second response from the session management device.

[0270] The description of the second response can refer to the description in S505.

[0271] S703, the session management device sends second authentication information to an authentication server of the DN, the second authentication information being used to authenticate the access right of the terminal device to the DN. Correspondingly, the authentication server of the DN receives the second authentication information from the session management device.

[0272] The authentication server of the DN in the present application is located in the ground network. For example, in the store-and-forward mode, the second authentication information needs to be sent to the authentication server of the DN in the power link connection.

[0273] Optionally, before S703, the method 700 further includes S509 and S510 in the method 500, which will not be described herein for brevity.

[0274] Optionally, the method 700 further includes that the session management device stores the second authentication information, so as to obtain a second authentication result from the authentication server of the DN using the second authentication information after the non-terrestrial network and the ground network are connected.

[0275] S704, the session management device receives the second authentication result from the authentication server of the DN. Correspondingly, the authentication server of the DN receives the second authentication result from the session management device.

[0276] Similarly to the sending of the second authentication information, in the store-and-forward mode, the second authentication result needs to be obtained in the power link connection.

[0277] S705, in the case that the second authentication result indicates that the access right of the terminal device to the DN is authenticated successfully, the session management device sends first indication information to the user plane device, the first indication information being used to indicate the data of the sent session. Correspondingly, the user plane device receives the first indication information from the session management device. Further, the user plane device can send the buffered data according to the first indication information.

[0278] The description of the first indication information and the user plane device can refer to the description in S604, which will not be described herein for brevity.

[0279] In the session establishment process, the session management device does not wait for the authentication result of the slice of the DN, but sends a response of successful session establishment to the terminal device, so that the terminal device can efficiently send uplink data. After receiving the authentication result of the DN, the session management device can instruct the user plane device to send the buffered uplink data based on the second authentication result. Thus, the latency caused by waiting for the authentication result of the DN can be effectively reduced, especially in a non-ground communication scenario (i.e., a store-and-forward working mode). In this case, the terminal device does not need to wait for the authentication result of the DN from the authentication server on the ground, so that the session establishment can be completed in a single link connection, and then the uplink data can be sent. After receiving the authentication result, the user plane device is instructed to send the uplink data, so that the data transmission is realized after the successful authentication of the DN.

[0280] Optionally, before S701, the method 700 further includes: the access management device and / or the session management device determining that the terminal device accesses a non-ground network in which a network element for implementing the access process and the session establishment process is deployed; and / or the access management device and the session management device determining that the terminal device performs uplink communication or downlink communication in a store-and-forward mode.

[0281] The process can refer to the related description in the method 500, which will not be repeated here.

[0282] Optionally, before S701, the method 700 further includes: S501-S503 in the method 500. For brevity, the details will not be repeated here.

[0283] Optionally, after the access management device receives the session request from the terminal device, the method 700 further includes: the access management device determining that the authentication state of the first network slice is authenticated.

[0284] Optionally, in the case that the authentication state of the first network slice is authenticated, the access management device can send second authentication waiting indication information to the session management device, where the second authentication waiting indication information is used to indicate that the first network slice does not need to be authenticated. In this way, the session management device can continue to perform S705 after obtaining the second authentication waiting indication information and the second authentication result.

[0285] Alternatively, in the case that the authentication state of the first network slice is to be authenticated, the access management device does not send the first authentication waiting indication information to the session management device. In this way, the session management device can directly perform S705 after obtaining the second authentication result.

[0286] The description of the first authentication waiting indication information can refer to the description in the method 600, which will not be repeated here.

[0287] Optionally, before S703, the method 700 further includes: determining, by the session management device, that the access permission of the terminal device to the DN needs to be authenticated based on subscription information of the terminal device.

[0288] The process can refer to the description in S510, which will not be repeated here.

[0289] It can be understood that the embodiments shown in FIGS. 6 and 7 can be combined with each other or independently implemented. When FIGS. 6 and 7 are independently implemented, more or fewer steps than those shown in FIGS. 6 and 7 can be performed; when the embodiments shown in FIGS. 6 and 7 are combined, the method provided by the present application can include: the session management device receives the first authentication result from the access management device; receives the second authentication result from the authentication server of the DN; in the case that the first authentication result indicates that the first network slice authentication is successful, and the second authentication result indicates that the access permission of the terminal device to the DN is successfully authenticated, the first indication information is sent to the user plane device. Other more detailed processes can refer to the description of the embodiments shown in FIGS. 7 and 8.

[0290] It can be understood that the embodiments shown in FIGS. 5 and 7 can be combined with each other or independently implemented. When FIGS. 5 and 7 are independently implemented, more or fewer steps than those shown in FIGS. 5 and 7 can be performed; when the embodiments shown in FIGS. 5 and 7 are combined, the method provided by the present application can include: S501 to S506, and in the case that the access permission of the terminal device to the DN needs to be authenticated, continue to perform S509 and S510, and the following steps in the method 700: S703, S704 and S705. Other more detailed processes can refer to the description of the embodiments shown in FIGS. 5 and 7.

[0291] It should also be understood that the embodiments shown in FIG. 5, FIG. 6 and FIG. 7 can be combined with each other or implemented independently. When FIG. 5, FIG. 6 and FIG. 7 are implemented independently, more or fewer steps than those shown in FIG. 5, FIG. 6 and FIG. 7 can be performed; when the embodiments shown in FIG. 5, FIG. 6 and FIG. 7 are combined, the method provided in the present application can include: S501 to S506, and in the case that the authentication state of the first network slice is to be authenticated, continue to perform S507 and S508, and in the case that the authentication of the permission of the terminal device to access the DN is required, continue to perform S509 and S510, and the following steps in method 600 and method 700: the access management device sends the first authentication information to the authentication server of the first network slice, the authentication server of the first network slice sends the first authentication result to the access management device, S603, S703, S704, and in the case that the first authentication result indicates that the authentication of the first network slice is successful, and the second authentication result indicates that the authentication of the permission of the terminal device to access the DN is successful, the first indication information is sent to the user plane device. Other more detailed processes can refer to the descriptions of the embodiments shown in FIG. 5, FIG. 6 and FIG. 7 above.

[0292] The method provided by the embodiments of the present application is described in detail above in combination with FIG. 1 to FIG. 7, and the apparatus provided by the embodiments of the present application is described in detail below in combination with FIG. 8 and FIG. 9.

[0293] FIG. 8 and FIG. 9 are schematic diagrams of possible apparatuses provided by the embodiments of the present application. These apparatuses can be used to implement the functions of the terminal device, the access management device or the session management device in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.

[0294] FIG. 8 is a schematic block diagram of an apparatus provided by the embodiments of the present application. As shown in FIG. 8, the apparatus 800 includes a sending module 810 and a receiving module 820. Optionally, the apparatus 800 can further include a processing module.

[0295] A possible design is that the apparatus 800 is used to implement the functions of the terminal device in the method embodiments shown in FIG. 5.

[0296] Exemplarily, the sending module 810 is configured to: send a first request to an access management device, the first request being used to request access to a non-terrestrial network, and the first request comprising an identifier of one or more network slices requested by the terminal device; and the receiving module 820 is configured to: receive a first response from the access management device, the first response carrying an identifier of a first network slice, and the one or more network slices comprising the first network slice; and the sending module 810 is further configured to: in a case where a slice authentication state of the first network slice is to be authenticated, send a session request to the access management device, the session request being used to request establishment of a session in which the terminal device transmits data through the non-terrestrial network, and the session request comprising the identifier of the first network slice.

[0297] Optionally, the receiving module 820 is further configured to: receive a session response from the access management device, the session response being used to indicate that the session is successfully established; and the sending module 810 is further configured to: transmit uplink data by using the session.

[0298] Optionally, the receiving module 820 is further configured to: receive a fourth request from the session management device, the fourth request being used to request acquisition of second authentication information, and the second authentication information being used to authenticate a right of the terminal device to access the DN; and the sending module 810 is specifically configured to: in a case where the authentication of the right of the terminal device to access the DN is not completed, transmit uplink data by using the session.

[0299] Optionally, the processing module is configured to: determine to access a non-terrestrial network, and the non-terrestrial network comprises a network element used to implement an access procedure and a session establishment procedure; and / or, determine to perform uplink communication or downlink communication in a store-and-forward mode.

[0300] Exemplarily, the sending module 810 is configured to: send a session request, the session request being used to request the terminal device to establish a session in which data is transmitted through a non-terrestrial network, and the session request comprising a DNN, the DNN being a name of a DN requested by the terminal device, and the access management device being located in the non-terrestrial network; and in a case where the authentication of the right of the terminal device to access the DN is not completed, receive a session response, the session response being used to indicate that the session is successfully established.

[0301] Optionally, the receiving module 820 is configured to: receive a fourth request from the session management device, the fourth request being used to acquire second authentication information, and the second authentication information being used to authenticate a right of the terminal device to access the DN.

[0302] Optionally, the sending module 810 is further configured to: transmit uplink data by using the session.

[0303] Optionally, the processing module is configured to determine to access the non-terrestrial network, and determine that a network element for implementing an access procedure and a session establishment procedure is deployed in the non-terrestrial network; and / or, determine to perform uplink communication or downlink communication in a store-and-forward mode.

[0304] More detailed descriptions about the sending module 810 and the receiving module 820 can be directly obtained by referring to the related descriptions in the embodiments of the method 500, and thus are not described herein.

[0305] Another possible design is that the apparatus 800 is configured to implement the functions of the access management device in the method embodiments shown in FIGS. 5 to 7.

[0306] Exemplarily, the receiving module 820 is configured to receive a session request from a terminal device, the session request being used to request establishment of a session in which the terminal device transmits data through the non-terrestrial network, and the session request including an identifier of a first network slice; and the sending module 810 is configured to, in a case where a slice authentication state of the first network slice is to be authenticated, send a second request to a session management device, the second request being used to request establishment of the session, and the session management device being located in the non-terrestrial network.

[0307] Optionally, the sending module 810 is further configured to, in a case where the identifier of the first network slice is located in a to-be-authenticated slice list, send a third request to the terminal device, the third request being used to request acquisition of first authentication information, the first authentication information being used to authenticate a right of the terminal device to use the first network slice; and the receiving module 820 is further configured to receive the first authentication information from the terminal device.

[0308] Optionally, the sending module 810 is further configured to send the first authentication information to an authentication server of the first network slice; the receiving module 820 is further configured to receive a first authentication result from the authentication server of the first network slice, the first authentication result being used to indicate that the first network slice is authenticated successfully or used to indicate that the first network slice is not authenticated successfully; and the sending module 810 is further configured to send the first authentication result to the session management device.

[0309] Optionally, the receiving module 820 is further configured to receive a first request from the terminal device, the first request being used to request access to the non-terrestrial network, and the first request including identifiers of one or more network slices requested by the terminal device; and the sending module 810 is further configured to, in a case where a slice authentication state of the first network slice is to be authenticated, send a first response to the terminal device, the first response being used to indicate at least one network slice allowed to be used by the terminal device, the at least one network slice including the first network slice.

[0310] Optionally, the processing module is configured to determine that the terminal device accesses the non-terrestrial network, and that a network element for implementing an access procedure and a session establishment procedure is deployed in the non-terrestrial network; and / or determine to forward uplink communication or downlink communication of the terminal device in a store-and-forward mode.

[0311] More detailed descriptions of the sending module 810 and the receiving module 820 can be directly obtained by referring to the descriptions of the method 500, the method 600, or the method 700, which will not be repeated here.

[0312] Another possible design is that the apparatus 800 is configured to implement the functions of the session management device in the method embodiments shown in FIGS. 5 to 7.

[0313] For example, the receiving module 820 is configured to receive a second request from an access management device, the second request being used to request establishment of a session, the second request carrying an identifier of a first network slice, the session being used for the terminal device to send data through the non-terrestrial network; the sending module 810 is configured to send a second response to the terminal device, the second response being used to indicate that the session is successfully established; the receiving module 820 is further configured to receive a first authentication result from the access management device; and the sending module 810 is further configured to send first indication information to a user plane device in a case where the first authentication result indicates that the first network slice is successfully authenticated, the first indication information being used to indicate that data of the session is sent, the user plane device being located in the non-terrestrial network.

[0314] Optionally, the sending module 810 is further configured to send second indication information to the user plane device, the second indication information being used to indicate that data of the session is buffered.

[0315] For example, the receiving module 820 is configured to receive a second request, the second request being used to request establishment of a session, the second request including a DNN, the DNN being a name of a DN requested by a terminal device, the session being used for the terminal device to send data through the non-terrestrial network; and the sending module 810 is configured to send a second response to the terminal device in a case where authentication of an access right of the terminal device to the DN is not completed, the second response being used to indicate that the session is successfully established.

[0316] Optionally, the sending module 810 is further configured to send a fourth request to the terminal device, the fourth request being used to request acquisition of second authentication information, the second authentication information being used to authenticate the access right of the terminal device to the DN; and the receiving module 820 is further configured to receive the second authentication information from the terminal device.

[0317] Optionally, the sending module 810 is further configured to send the second authentication information to an authentication server of the DN; the receiving module 820 is further configured to receive a second authentication result from the authentication server of the DN; and the sending module 810 is further configured to send first indication information to a user plane device in the non-terrestrial network, the first indication information being used to instruct the DN to send data of the session, in a case where the first authentication result indicates that the first network slice authentication is successful and the second authentication result indicates that the permission authentication of the terminal device accessing the DN is successful.

[0318] Optionally, the sending module 810 is further configured to send the second authentication information to an authentication server of the DN; the receiving module 820 is further configured to receive a second authentication result from the authentication server of the DN; and the sending module 810 is further configured to send first indication information to a user plane device in the non-terrestrial network, the first indication information being used to instruct the DN to send data of the session, in a case where the first authentication result indicates that the first network slice authentication is successful and the second authentication result indicates that the permission authentication of the terminal device accessing the DN is successful.

[0319] Optionally, the sending module 810 is further configured to send second indication information to the user plane device, the second indication information being used to instruct the user plane device to cache data of the session.

[0320] Optionally, the processing module is configured to determine that the terminal device accesses the non-terrestrial network, and that a network element for implementing an access procedure and a session establishment procedure is deployed in the non-terrestrial network; and / or, determine to forward uplink communication or downlink communication of the terminal device in a store-and-forward mode.

[0321] More detailed description of the sending module 810 and the receiving module 820 can be directly obtained by referring to the description of the method 500, the method 600 or the method 700, which will not be repeated here.

[0322] It can be understood that, since the apparatus 800 has a communication function, it can also be referred to as a communication apparatus.

[0323] FIG. 9 is another schematic block diagram of an apparatus provided by an embodiment of the present application. As shown in FIG. 9, the apparatus 900 includes one or more processors 910. The processor 910 can be a general-purpose processor or a special-purpose processor, etc. For example, it can be a baseband processor or a central processing unit. The baseband processor can be used to process a communication protocol and communication data, and the central processing unit can be used to control the apparatus (e.g., a terminal device, an access management device, a session management device, a user plane device or a chip, etc.), execute a software program, and process data of the software program.

[0324] Optionally, in one design, the processor 910 can include a program (also can be referred to as code or instruction) that can be run on the processor 910, so that the apparatus 900 performs the method performed by the terminal device, the access management device, the session management device or the user plane device in the above method embodiments. In yet another possible design, the apparatus 900 includes circuitry (not shown in FIG. 9) for implementing the functions of the terminal device, the access management device, the session management device or the user plane device in the above method embodiments.

[0325] Exemplarily, the processor 910 can be configured to execute the computer program or instruction in the memory to implement the steps performed by the terminal device, the access management device, the session management device or the user plane device in the method embodiments shown in any one of the embodiments shown in FIGS. 5 to 7.

[0326] Optionally, one or more memories 920 can be included in the apparatus 900, and a program (also can be referred to as code or instruction) can be stored on the memory 920, and the program can be run on the processor 910, so that the apparatus 900 performs the method performed by the terminal device, the access management device, the session management device or the user plane device in the above embodiments.

[0327] Optionally, the processor 910 and / or the memory 920 can also store data. The processor and the memory can be separately arranged or integrated together.

[0328] Optionally, the apparatus 900 can further include a communication interface 930. The processor 910 can also be referred to as a processing unit, and controls the apparatus (such as the terminal device, the access management device, the session management device or the user plane device). The communication interface 930 can also be referred to as a transceiving unit, a transceiver, a transceiving circuit or a transceiver, and is configured to implement the transceiving function of the apparatus.

[0329] Optionally, the apparatus 900 further includes a communication interface 930. The processor 910 and the communication interface 930 are coupled to each other. It can be understood that the communication interface 930 can be a transceiver or an input / output interface.

[0330] It can be understood that the apparatus 900 can also be referred to as a communication apparatus due to its communication function.

[0331] When the apparatus 900 is used to implement the methods shown in FIGS. 5 to 7, the processor 910 is configured to perform the functions of the above processing modules, and the communication interface 930 is configured to perform the functions of the above sending modules or receiving modules. Whether the communication interface 930 is configured to send or receive can be determined according to whether the apparatus 900 performs a sending action or a receiving action in the scheme.

[0332] It can be understood that when the apparatus 900 is a terminal device, an access management device, a session management device, or a user plane device, the communication interface 930 can be a transceiver, and specifically can include a transmitter and a receiver. The transmitter is configured to transmit signals, and the receiver is configured to receive signals. When the apparatus 900 is a chip applied to a terminal device, an access management device, a session management device, or a user plane device, the communication interface 930 can be an input / output circuit. The input circuit can be configured to receive, and the output interface can be configured to transmit.

[0333] It should be noted that the method embodiments described above can be applied to a processor or implemented by a processor. The processor can be an integrated circuit chip having a signal processing capability. In the implementation process, each step of the above method embodiments can be completed by integrated logic circuits or instructions in the form of software in the processor.

[0334] The processor described above can be a general processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, or any combination thereof. The general processor can be a microprocessor, or any conventional processor, etc.

[0335] The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as hardware code processing executed by a processor, or executed by a combination of hardware and software modules in the processor. The software module can be located in a storage medium in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, or the like. The storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the above method.

[0336] The memory in the embodiments of the present application can be a volatile memory or a nonvolatile memory, or can include both volatile and nonvolatile memory. Among them, the nonvolatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example, and not limitation, many forms of RAM can be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It is noted that the memory of the systems and methods described herein is intended to include, without being limited to, these and any other suitable types of memory.

[0337] The method provided by the above embodiments can be implemented by software, hardware, firmware, or any combination thereof, in whole or in part. When implemented by software, the method can be implemented in whole or in part in the form of a computer program product. The computer program product can include one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through a wired (such as coaxial cable, optical fiber, digital subscriber (DSL)) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic disk), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0338] The embodiments of the present application also provide a communication system, which includes one or more of the foregoing devices (terminal device, access management device, session management device, user plane function device, etc.).

[0339] The embodiments of the present application also provide a computer program product, which includes a computer program (also referred to as code or instructions). When the computer program is executed, the method shown in the above method embodiments can be implemented.

[0340] The embodiments of the present application also provide a computer-readable storage medium, which stores a computer program (also referred to as code or instructions). When the computer program is executed, the method shown in the above method embodiments can be implemented.

[0341] The embodiments of the present application also provide a chip system, which includes at least one processor for implementing the method shown in the above method embodiments.

[0342] Optionally, the chip system further includes a memory for saving program instructions and data, and the memory is located in the processor or outside the processor.

[0343] Optionally, the chip system further comprises an interface circuit for transmitting data and / or a power supply circuit for supplying power to the chip system.

[0344] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0345] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0346] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0347] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiment.

[0348] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0349] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the present application that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk or an optical disk.

[0350] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method characterized by comprising: Comprising: sending a first request to an access management device, the first request being used to request access to a non-terrestrial network, the first request comprising an identity of one or more network slices requested by a terminal device, the access management device being located in the non-terrestrial network; receiving a first response from the access management device, the first response carrying an identity of a first network slice, the one or more network slices comprising the first network slice; in a case where a slice authentication status of the first network slice is to be authenticated, sending a session request to the access management device, the session request being used to request establishment of a session in which the terminal device transmits data through the non-terrestrial network, the session request comprising the identity of the first network slice.

2. The method of claim 1, wherein, The slice authentication status of the first network slice is to be authenticated, comprising: not receiving an authentication result of the first network slice, and / or the identity of the first network slice being located in a to-be-authenticated slice list in the first response.

3. The method according to claim 1 or 2, characterized in that, The method further comprises: receiving a session response from the access management device, the session response being used to indicate that the session is successfully established; transmitting uplink data using the session.

4. The method of claim 3, wherein, The session request further comprises a data network name (DNN), the DNN being a name of a data network (DN) requested by the terminal device; The method further comprises: receiving a fourth request from the session management device, the fourth request being used to request acquisition of second authentication information, the second authentication information being used to authenticate a right of the terminal device to access the DN; The transmitting uplink data using the session, comprising: transmitting uplink data using the session in a case where the authentication of the right of the terminal device to access the DN is not completed.

5. The method according to any one of claims 1 to 4, characterized in that, Before the sending the session request to the access management device, the method further comprises: determining to access a non-terrestrial network, the non-terrestrial network deploying network elements used to implement an access procedure and a session establishment procedure; and / or determining to perform uplink communication or downlink communication in a store-and-forward mode.

6. A communication method characterized by comprising: Comprising: sending a session request, the session request being used to request a terminal device to establish a session in which the terminal device transmits data through a non-terrestrial network, the session request comprising a data network name (DNN), the DNN being a name of a DN requested by the terminal device; receiving a session response in a case where an authentication of a right of the terminal device to access the DN is not completed, the session response being used to indicate that the session is successfully established.

7. The method of claim 6, wherein, The method further comprises: receiving a fourth request from a session management device, the fourth request being used to acquire second authentication information, the second authentication information being used to authenticate the right of the terminal device to access the DN.

8. The method according to claim 6 or 7, characterized in that, The method further comprises: transmitting uplink data using the session.

9. The method according to any one of claims 6 to 8, characterized in that, Before the sending the session request, the method further comprises: determining to access the non-terrestrial network, the non-terrestrial network deploying network elements used to implement an access procedure and a session establishment procedure; and / or determining to perform uplink communication or downlink communication in a store-and-forward mode.

10. A communication method characterized by comprising: Applied to an access management device, the access management device being located in a non-terrestrial network, the method comprising: receiving a session request from a terminal device, the session request being used to request to establish a session in which the terminal device transmits data through the non-terrestrial network, the session request comprising an identity of a first network slice; in a case where a slice authentication status of the first network slice is to be authenticated, sending a second request to a session management device, the second request being used to request to establish the session, the session management device being located in the non-terrestrial network.

11. The method of claim 10, wherein, The method further comprises: in a case where the identity of the first network slice is located in a to-be-authenticated slice list, sending a third request to the terminal device, the third request being used to request to obtain first authentication information, the first authentication information being used to authenticate a right of the terminal device to use the first network slice; receiving the first authentication information from the terminal device.

12. The method of claim 11, wherein, The method further comprises: sending the first authentication information to an authentication server of the first network slice; receiving a first authentication result from the authentication server of the first network slice, the first authentication result being used to indicate that the first network slice is authenticated successfully or used to indicate that the first network slice is not authenticated successfully; sending the first authentication result to the session management device.

13. The method according to any one of claims 10 to 12, characterized in that, The method further comprises: receiving a first request from the terminal device, the first request being used to request to access to the non-terrestrial network, the first request comprising an identity of one or more network slices requested by the terminal device; in a case where the slice authentication status of the first network slice is to be authenticated, sending a first response to the terminal device, the first response being used to indicate at least one network slice allowed to be used by the terminal device, the at least one network slice comprising the first network slice.

14. The method according to any one of claims 10 to 13, characterized in that, The slice authentication status of the first network slice is to be authenticated, comprising: no authentication result of the first network slice is received, and / or the identity of the first network slice is located in a to-be-authenticated slice list.

15. The method according to any one of claims 10 to 14, characterized in that, Before sending the second request to the session management device, the method further comprises: determining that the terminal device accesses the non-terrestrial network, the non-terrestrial network deploying a network element used to implement an access procedure and a session establishment procedure; and / or determining to perform uplink communication or downlink communication of the terminal device in a store-and-forward mode.

16. A method of communication, comprising: Applied to a session management device located in a non-terrestrial network, the method comprises: receiving a second request from an access management device, the second request being used to request to establish a session, the second request carrying an identity of a first network slice, the session being used for a terminal device to transmit data through the non-terrestrial network; sending a second response to the terminal device, the second response being used to indicate that the session is established successfully; receiving a first authentication result from the access management device; in a case where the first authentication result indicates that the first network slice is authenticated successfully, sending first indication information to a user plane device, the first indication information being used to indicate to send data of the session, the user plane device being located in the non-terrestrial network.

17. The method of claim 16, wherein, After the receiving the second request from the access management device, before the receiving the first authentication result from the access management device, the method further comprises: sending second indication information to the user plane device, the second indication information being used for indicating to cache data of the session.

18. A method of communication, comprising: Applied to a session management device, the session management device being located in a non-terrestrial network, the method comprises: receiving a second request, the second request being used for requesting to establish a session, a data network name (DNN) being included in the second request, the DNN being a name of a data network (DN) requested by a terminal device, the session being used for the terminal device to send data through the non-terrestrial network; in a case where authentication of a right of the terminal device to access the DN is not completed, sending a second response to the terminal device, the second response being used for indicating that the session establishment is successful.

19. The method of claim 18, wherein, The method further comprises: sending a fourth request to the terminal device, the fourth request being used for requesting to obtain second authentication information, the second authentication information being used for authenticating the right of the terminal device to access the DN; receiving the second authentication information from the terminal device.

20. The method of claim 19, wherein, The method further comprises: sending the second authentication information to an authentication server of the DN; receiving a second authentication result from the authentication server of the DN; in a case where the second authentication result indicates that the authentication of the right of the terminal device to access the DN is successful, sending first indication information to a user plane device, the first indication information being used for indicating to send data of the session to the DN, the user plane device being located in the non-terrestrial network.

21. The method of claim 18, wherein, The method further comprises: sending the second authentication information to an authentication server of the DN; receiving a second authentication result from the authentication server of the DN; receiving a first authentication result from the access management device; in a case where the first authentication result indicates that a first network slice authentication is successful, and the second authentication result indicates that the authentication of the right of the terminal device to access the DN is successful, sending first indication information to a user plane device, the first indication information being used for indicating to send data of the session to the DN, the user plane device being located in the non-terrestrial network.

22. The method of claim 20 or 21, wherein, Before the sending the second response to the terminal device, the method further comprises: sending second indication information to the user plane device, the second indication information being used for indicating to cache data of the session by the user plane device.

23. The method of any one of claims 18-22, wherein, Before the sending the second response to the access management device, the method further comprises: determining that the terminal device accesses the non-terrestrial network, the non-terrestrial network deploying a network element used for implementing an access procedure and a session establishment procedure; and / or, determining to perform uplink communication or downlink communication of the terminal device in a store-and-forward mode.

24. A communications device, characterized by comprise one or more functional units for implementing the method according to any one of claims 1 to 23.

25. A communications device, characterized by comprise a processor configured to execute program code to cause the communication apparatus to implement the method according to any one of claims 1 to 23.

26. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by the processor, causes the method of any one of claims 1 to 23 to be performed.

27. A computer program product, characterised in that, The computer program, when executed by the processor, causes the method of any one of claims 1 to 22 to be performed.

28. A communication system, characterized by The computer program comprises: The access management device is configured to perform the method of any one of claims 10 to 15. The access management device is configured to perform the method of any one of claims 10 to 15. The session management device is configured to receive the second request.

29. The system of claim 28, wherein, The system further comprises: The session management device is further configured to perform the method of claim 16 or 17.

30. The system of claim 28 or 29, wherein, The system further comprises: The terminal device is configured to perform the method of any one of claims 1 to 5.

31. The system of any one of claims 28-30, wherein, The system further comprises: The user plane device is configured to receive first indication information from the session management device, wherein the first indication information is used to indicate data of a session to be transmitted, and the user plane device is located in a non-terrestrial network. The data of the session is transmitted according to the first indication information.

32. The system of claim 31, wherein, The user plane device is further configured to: receive second indication information from the session management device, wherein the second indication information is used to indicate data of the session to be cached, and the data of the session is cached according to the second indication information.

33. A communication system, characterized by The computer program comprises: The session management device is configured to perform the method of any one of claims 18 to 23. The access management device is configured to send a second request to the session management device.

34. The system of claim 33, wherein, The access management device is further configured to: perform the method of any one of claims 10 to 15.

35. The system of claim 33 or 34, wherein, The system further comprises: The terminal device is configured to perform the method of any one of claims 6 to 9.

36. The system of any one of claims 33 to 35, wherein, The system further comprises: The user plane device is configured to receive first indication information from the session management device, wherein the first indication information is used to indicate data of a session to be transmitted, and the user plane device is located in a non-terrestrial network. The data of the session is transmitted according to the first indication information.

37. The system of claim 36, wherein, The user plane device is further configured to: receive second indication information from the session management device, wherein the second indication information is used to indicate data of the session to be cached, and the data of the session is cached according to the second indication information.

Citation Information

Patent Citations

  • Terminal equipment registration method and device

    CN111654862A

  • Method and apparatus for controlling network slice in wireless communication system

    US20210136715A1

  • Handling of slices subject to network slice specific authentication and authorization procedure

    US20220141656A1

  • Network slice authentication and authorization method and apparatus

    WO2022041152A1