Communication method and apparatus

By generating NAS security contexts that associate terminal devices with different networks, the problem of terminal devices failing to register in distributed subnets is solved, and secure communication between terminal devices and different networks is achieved.

WO2026067106A1PCT designated stage Publication Date: 2026-04-02HUAWEI TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-15
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

In a distributed subnet architecture, it is difficult for terminal devices to successfully register with both the central network and the subnet simultaneously, and existing technologies cannot guarantee the communication security between terminal devices and different networks.

Method used

By generating NAS security contexts that associate terminal devices with different networks, the terminal devices can save NAS security contexts at the network level, ensuring that the terminal devices can successfully register to different networks and communicate through network-level security protection.

Benefits of technology

It enables terminal devices to successfully register with the central network and subnets in a distributed subnet scenario, and ensures secure communication with different networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025121339_02042026_PF_FP_ABST
    Figure CN2025121339_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the field of communications. Provided are a communication method and apparatus, which aim to enable a terminal apparatus to successfully register with different networks, and to ensure the security of communication between the terminal apparatus and each of the different networks. The method comprises: during the process of a terminal apparatus registering with a first network, generating first NAS security context associated with the first network for the terminal apparatus, wherein the first NAS security context is used for performing security protection on NAS messages exchanged between the terminal apparatus and the first network; and when the terminal apparatus has registered with the first network, if the terminal apparatus needs to register with a second network, determining whether the terminal apparatus has NAS security context associated with the second network, and in response to the terminal apparatus having no NAS security context associated with the second network, generating second NAS security context associated with the second network for the terminal apparatus, wherein the second NAS security context is used for performing security protection on NAS messages exchanged between the terminal apparatus and the second network, and the first network and the second network share network functions.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and apparatus

[0001] The present application claims priority from the Chinese patent application No. 202411393314.2 filed on September 30, 2024, and entitled "Communication method and apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication, in particular to a communication method and apparatus. BACKGROUND

[0003] There are generally two types of non-public networks (NPNs), such as stand-alone non-public networks (SNPNs) and public network integrated non-public networks (PNI-NPNs). Currently, distributed subnetworks are further proposed. In the architecture of the distributed subnetwork, the core network (CN) can be divided into two parts: a large network and a subnetwork. The large network is a central network deployed by an operator, which can also be referred to as a central network, and has complete core network functions to provide all management services for terminals. There can be multiple subnetworks, and a terminal can simultaneously obtain services of multiple subnetworks. The network elements in the subnetwork are deployed on demand, and the missing network elements can obtain services using the corresponding network of the large network, that is, part of the network functions in the central network can be shared and used by the subnetwork.

[0004] A terminal can expect to register to the large network and the subnetwork respectively to obtain services from the large network and the subnetwork respectively. However, it is found in actual research that if the terminal registers to the central network first, the terminal will fail to initiate registration to the subnetwork, and vice versa. Therefore, how to ensure that the terminal can successfully register to different networks is a problem to be studied at present. SUMMARY

[0005] Embodiments of the present application provide a communication method and apparatus to enable a terminal device to successfully register to different networks and ensure the communication security of the terminal device with different networks respectively.

[0006] To achieve the above-mentioned purpose, the present application adopts the following technical solutions:

[0007] In a first aspect, a communication method is provided. The method can be performed by a terminal device, a component (e.g., a chip or a chip system) of the terminal device, a logic node, a logic module, or software that can implement all or part of the functions of the terminal device. The method includes: in a process in which the terminal device registers to a first network, generating a first non-access stratum (NAS) security context associated with the terminal device and the first network, the first NAS security context being used for security protection of NAS messages exchanged between the terminal device and the first network. In a case where the terminal device has registered to the first network, if the terminal device needs to register to a second network, determining whether the terminal device has a NAS security context associated with the second network, and in response to the terminal device not having a NAS security context associated with the second network, generating a second NAS security context associated with the terminal device and the second network. The second NAS security context is used for security protection of NAS messages exchanged between the terminal device and the second network, and the first network and the second network share network functions.

[0008] Therefore, when the terminal device registers to the first network first, the terminal device can generate the first NAS security context associated with the first network. When the terminal device needs to register to the second network again, since the first NAS security context is associated with the first network and the terminal device does not have a NAS security context associated with the second network, the terminal device initiates a plaintext registration to the second network, so that the terminal device can register to the second network and generate the second NAS security context associated with the second network. In this way, the terminal device can successfully register to different networks, and the NAS security contexts of different networks can be associated and stored in network granularity, so as to ensure the communication security of the terminal device with different networks.

[0009] In a possible design, the first network is a center network, and the second network is a subnet. Some network functions in the center network are shared with the subnet, that is, the terminal device can successfully register to the center network and the subnet and ensure the communication security in a distributed subnet scenario.

[0010] In a possible design, the generating of the second NAS security context associated with the terminal device and the second network includes: sending a registration request message in plaintext to the second network, the registration request message being used for the terminal device to request registration to the second network; performing authentication in a process in which the terminal device registers to the second network; and generating the second NAS security context associated with the terminal device and the second network through a non-access stratum security mode control (NAS SMC) procedure in a case where the authentication is passed.

[0011] Optionally, the registration type contained in the registration request message is subnet registration.

[0012] It can be seen that, since the terminal device saves the NAS security context in the granularity of the network, the terminal device can also determine whether the network has an associated NAS security context in the granularity of the network, instead of whether the local NAS security context exists. In this case, since the terminal device associates the first NAS security context with the first network, and the second network does not have an associated NAS security context, even if the terminal device has the first NAS security context, it cannot be used to protect the second registration request message. Therefore, the terminal device can send the registration request message in plaintext to the second network, so that the second network can interpret the registration request message and trigger the subsequent process of registration, such as authentication and generation of the NAS security context.

[0013] Optionally, the authentication is performed, including: receiving an authentication request message from the second network, the authentication request message indicating that the terminal device authenticates the second network, and authenticating the second network according to the authentication request message; and the authentication request message carries the identifier of the second network. The second NAS security context associated with the second network is generated, including: generating the second NAS security context associated with the second network according to the identifier of the second network carried in the authentication request message. That is, the terminal device can determine, according to the identifier of the network carried in the authentication request message, that the authentication is performed for registration to which network, so as to associate the subsequently generated NAS security context with the identifier of the network, and avoid the situation that the NAS security context is stored incorrectly due to simultaneous execution of multiple authentication processes.

[0014] Optionally, before sending the registration request message in plaintext to the second network, the method further includes: receiving a first registration accept message from the first network, the first registration accept message indicating that the terminal device is successfully registered to the first network; in response to the terminal device being successfully registered to the first network, associating the state that the terminal device has registered to the network with the first network; and if the first service of the terminal device is authorized to be initiated in the second network, and the state that the terminal device has registered to the network is associated with the first network but not associated with the second network, determining that the terminal device needs to be registered to the second network. That is, when the terminal device is successfully registered to the first network, the terminal device associates the state that the terminal device has registered to the network with the first network, so as to trigger the terminal device to determine whether the state that the terminal device has registered to the network is also associated with the subnet (such as the second network) when the terminal device subsequently wants to register to the subnet, and if not, initiates registration to the subnet, so as to ensure that the terminal device can be registered to multiple networks at the same time.

[0015] Optionally, the method further comprises: determining that the first service is authorized to be initiated at the second network according to a subnet authorized service of the terminal device, the subnet authorized service indicating at least one subnet to which the terminal device is authorized to register and a service corresponding to each of the at least one subnet, the second network belonging to the at least one subnet, and the first service belonging to the service corresponding to the second network; and wherein the first registration acceptance message comprises the subnet authorized service. That is, the terminal device can obtain the subnet authorized service when the terminal device registers to the first network, so that the terminal device knows which networks can be registered to subsequently, and registration failure is avoided.

[0016] Optionally, the method further comprises: receiving a second registration acceptance message from the second network, the second registration acceptance message indicating that the terminal device successfully registers to the second network; and in response to the terminal device successfully registering to the second network, associating a state in which the terminal device has registered to a network with the second network, so as to avoid repeatedly initiating registration to the second network.

[0017] In a possible design, generating the first NAS security context associated with the first network by the terminal device comprises: performing authentication in a process in which the terminal device registers to the first network; and generating the first NAS security context associated with the first network by the terminal device through a NAS SMC procedure in a case where the authentication is passed, so as to use the first NAS security context when initiating registration to other networks by associating the first network, and ensure that the terminal device can register to different networks.

[0018] Optionally, performing authentication comprises: receiving an authentication request message from the first network, the authentication request message indicating that the terminal device authenticates the first network, and the authentication request message carrying an identity of the first network; authenticating the first network according to the authentication request message; and generating the first NAS security context associated with the first network by the terminal device comprises: generating the first NAS security context associated with the first network by the terminal device according to the identity of the first network carried in the authentication request message. That is, the terminal device can associate and save the generated NAS security context with the identity of the network according to the identity of the network carried in the authentication request message, so as to avoid a situation in which NAS security contexts are stored incorrectly due to simultaneous execution of multiple authentication procedures.

[0019] In a possible design, the terminal device accesses the first network and the second network through access types of the Third Generation Partnership Project (3GPP) respectively, such as an access network device shared by the first network and the second network, so as to subsequently initiate registration to the first network and the second network respectively.

[0020] In a second aspect, a communication method is provided. The method comprises: in a case where a terminal device requests to register to a first network, triggering, by a first authentication function network element, first authentication of the terminal device; determining, by the first authentication function network element, a result of the first authentication of the terminal device in association with the first network; in a case where the terminal device requests to register to a second network, triggering, by the first authentication function network element, second authentication of the terminal device, the first network and the second network sharing network functions; and determining, by the first authentication function network element, a result of the second authentication of the terminal device in association with the second network.

[0021] Therefore, the first authentication function network element can store the authentication results of the terminal device in network granularity, or the authentication results of the same terminal device in multiple networks, so that the authentication results corresponding to the registration of the terminal device in different networks can be saved by the first authentication function network element.

[0022] In a possible design, the first network is a central network, and the second network is a subnet, and part of network functions in the central network are shared by the subnet.

[0023] In a possible design, the method further comprises: receiving, by the first authentication function network element, a first authentication request message from a first access management network element, the first access management network element being a network element in the first network, and the first authentication request message being used to request to authenticate the terminal device in a case where the terminal device requests to register to the first network; and triggering, by the first authentication function network element, the first authentication of the terminal device, including: triggering, by the first authentication function network element, the first authentication according to the first authentication request message. That is, the network side can be aware that the terminal device initiates registration to the first network, and can determine whether to initiate authentication for the terminal device requesting to register to the first network according to the network to which the terminal device subscribes, so that invalid authentication can be avoided, for example, the terminal device is not authorized to register to the first network, but authentication is initiated for the terminal device requesting to register to the first network.

[0024] Optionally, the first authentication request message carries an identifier of the first network, and triggering, by the first authentication function network element, the first authentication includes: sending, by the first authentication function network element, the identifier of the first network to a data management network element serving the terminal device; receiving, by the first authentication function network element, first result information returned by the data management network element, the first result information indicating whether the terminal device is allowed to be authenticated in the first network; and triggering, by the first authentication function network element, the first authentication in a case where the first result information indicates that the terminal device is allowed to be authenticated in the first network. Alternatively, the first authentication function network element obtains a network list from the data management network element, the networks in the network list being networks to which the terminal device subscribes; determines, by the first authentication function network element, whether the network list contains the first network according to the identifier of the first network; and triggers, by the first authentication function network element, the first authentication in a case where the network list contains the first network.

[0025] It can be seen that the first authentication function network element can provide the identity of the first network to the data management network element to trigger the data management network element to determine whether to allow the terminal device to be authenticated in the first network. For example, the data management network element can determine whether the network to which the terminal device is subscribed includes the first network according to the identity of the first network. If the network to which the terminal device is subscribed includes the first network, the data management network element determines to allow the terminal device to be authenticated in the first network, otherwise, the terminal device is not allowed to be authenticated. In other words, the terminal device initiates registration to the subscribed network, and the network authenticates the terminal device, so that the terminal device can successfully register to the network subsequently, otherwise, the network rejects the authentication, so that the terminal device cannot register to the unsubscribed network. In the case of allowing the terminal device to be authenticated, the data management network element can generate a first authentication vector of the terminal device according to the subscription data of the terminal device, for first authentication of the terminal device, otherwise, the authentication vector of the terminal device is not generated.

[0026] Of course, the first authentication function network element can also determine whether to trigger the first authentication of the terminal device according to the network to which the terminal device is subscribed, without the data management network element to determine, thereby reducing the processing overhead of the data management network element.

[0027] A possible design scheme, the method further comprises: the first authentication function network element receives a second authentication request message from the second access management network element, the second access management network element is a network element in the second network, and the second authentication request message is used to request to authenticate the terminal device in the case that the terminal device requests to register to the second network; the first authentication function network element triggers the second authentication of the terminal device, comprising: the first authentication function network element triggers the second authentication according to the second authentication request message. Similarly, the network side can determine whether to request authentication of the terminal device to the second network by sensing that the terminal device initiates registration to the second network, so that the invalid authentication can be avoided, for example, the terminal device is not authorized to register to the second network, but authentication is initiated for the terminal device to request to register to the second network.

[0028] Optionally, the second authentication request message carries an identity of the second network, and the first authentication function network element triggers the second authentication according to the second authentication request message, including: the first authentication function network element sends the identity of the second network to a data management network element serving the terminal device; the first authentication function network element receives second result information returned by the data management network element, the second result information indicating whether the terminal device is allowed to be authenticated in the second network; in a case where the second result information indicates that the terminal device is allowed to be authenticated in the second network, the first authentication function network element triggers the second authentication; or the first authentication function network element acquires a network list from the data management network element, the networks in the network list being networks to which the terminal device subscribes; the first authentication function network element determines whether the network list contains the second network according to the identity of the second network; and in a case where the network list contains the second network, the first authentication function network element triggers the second authentication.

[0029] In a third aspect, a communication method is provided, including: in a case where a terminal device requests to register to a target network, an access management network element determines a first authentication function network element, the access management network element being a network element in the target network; and the access management network element sends an authentication request message to the first authentication function network element, the authentication request message being used to request to authenticate the terminal device in the case where the terminal device requests to register to the target network.

[0030] In a possible design, the authentication request message includes an identity of the target network.

[0031] Optionally, in a case where the first authentication function network element triggers authentication of the terminal device, the method further includes: the access management network element sends an authentication request message to the terminal device, the authentication request message being used to request the terminal device to authenticate the target network, the authentication request message including the identity of the target network.

[0032] In a possible design, the method further includes: receiving, by the access management network element, a registration request message from the terminal device, the registration request message being used for the terminal device to request registration to a target network, and in a case where the target network is a subnet, a registration type in the registration request message being subnet registration; and in response to the registration type being subnet registration, directly sending, by the access management network element, a registration accept message to the terminal device in a case where authentication of the terminal device is passed, the registration accept message indicating that the terminal device is successfully registered to the target network. That is, since subnet registration is usually after central network registration, in this case, since the terminal device has obtained the terminal device's subnet authorized service and some other information, such as the terminal device's mobility subscription data, in the process of registering to the central network, for the access management network element in the second network (i.e., the subnet), in a case where authentication is passed, the access management network element can directly indicate that the terminal device is successfully registered to the second network, so as to shorten the registration procedure, reduce latency, and save signaling overhead.

[0033] It can be understood that the technical effects of the method in the third aspect can also be referred to the related descriptions of the method in the first aspect or the second aspect, and will not be repeated here.

[0034] In a fourth aspect, a communication apparatus is provided. The communication apparatus is configured to perform the communication method in any of the implementation manners of the first aspect or the third aspect.

[0035] In this application, the communication apparatus in the fourth aspect can be a terminal device, or a component (e.g., a processor, a chip, or a chip system) of the terminal device, or a logic node, a logic module, or software capable of realizing all or part of the functions of the terminal device. Alternatively, the communication apparatus in the fourth aspect can be a network device, or a component (e.g., a processor, a chip, or a chip system) of the network device, or a logic node, a logic module, or software capable of realizing all or part of the functions of the network device.

[0036] It should be understood that the communication apparatus in the fourth aspect includes modules, units, or means corresponding to the communication method in any of the first aspect or the third aspect, which can be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units for performing the functions involved in the communication method.

[0037] In a fifth aspect, a communication apparatus is provided. The communication apparatus includes a processor configured to perform the communication method in any of the implementation manners of the first aspect or the third aspect.

[0038] In one possible design, the communication device described in the fifth aspect may further include a transceiver. This transceiver may be a transceiver circuit or an interface circuit. The transceiver can be used for communication between the communication device described in the fifth aspect and other communication devices.

[0039] In one possible design, the communication device described in the fifth aspect may further include a memory. This memory may be integrated with the processor or disposed separately. The memory may be used to store computer programs and / or data relating to the communication method described in either the first or third aspect.

[0040] In this application, the communication device described in the fifth aspect can be a terminal device, a component of a terminal device (e.g., a processor, chip, or chip system), or a logical node, logical module, or software capable of implementing all or part of the functions of a terminal device. Alternatively, the communication device described in the fifth aspect can be a network device, a component of a network device (e.g., a processor, chip, or chip system), or a logical node, logical module, or software capable of implementing all or part of the functions of a network device.

[0041] A sixth aspect provides a communication device. The communication device includes a processor coupled to a memory, the processor executing a computer program stored in the memory, such that the communication device performs the communication method described in any possible implementation of the first or third aspect.

[0042] In one possible design, the communication device described in the sixth aspect may further include a transceiver. This transceiver may be a transceiver circuit or an interface circuit. The transceiver can be used for communication between the communication device described in the sixth aspect and other communication devices.

[0043] In this application, the communication device described in the sixth aspect can be a terminal device, a component of a terminal device (e.g., a processor, chip, or chip system), or a logical node, logical module, or software capable of implementing all or part of the functions of a terminal device. Alternatively, the communication device described in the sixth aspect can be a network device, a component of a network device (e.g., a processor, chip, or chip system), or a logical node, logical module, or software capable of implementing all or part of the functions of a network device.

[0044] A seventh aspect provides a communication device, comprising: a processor and a memory; the memory being used to store a computer program, which, when executed by the processor, causes the communication device to perform the communication method described in any one of the first or third aspects.

[0045] In a possible design, the communication apparatus in the seventh aspect further includes a transceiver. The transceiver can be a transceiver circuit or an interface circuit. The transceiver can be used for the communication apparatus in the seventh aspect to communicate with another communication apparatus.

[0046] In this application, the communication apparatus in the seventh aspect can be a terminal apparatus, or a component (for example, a processor, a chip, or a chip system) of the terminal apparatus, or a logic node, a logic module, or software that can implement all or part of the functions of the terminal apparatus. Alternatively, the communication apparatus in the seventh aspect can be a network device, or a component (for example, a processor, a chip, or a chip system) of the network device, or a logic node, a logic module, or software that can implement all or part of the functions of the network device.

[0047] In the eighth aspect, a communication apparatus is provided, including: a processor; and the processor is configured to read a computer program in a memory, and execute the communication method in any one of the implementation manners of the first aspect or the third aspect according to the computer program.

[0048] In a possible design, the communication apparatus in the eighth aspect further includes a transceiver. The transceiver can be a transceiver circuit or an interface circuit. The transceiver can be used for the communication apparatus in the eighth aspect to communicate with another communication apparatus.

[0049] In this application, the communication apparatus in the eighth aspect can be a terminal apparatus, or a component (for example, a processor, a chip, or a chip system) of the terminal apparatus, or a logic node, a logic module, or software that can implement all or part of the functions of the terminal apparatus. Alternatively, the communication apparatus in the eighth aspect can be a network device, or a component (for example, a processor, a chip, or a chip system) of the network device, or a logic node, a logic module, or software that can implement all or part of the functions of the network device.

[0050] In the ninth aspect, a processor is provided. The processor is configured to execute the communication method in any one of the implementation manners of the first aspect or the third aspect.

[0051] In the tenth aspect, a communication system is provided. The communication system includes a terminal apparatus configured to execute the method in the first aspect, and a network device configured to execute the method in the second aspect or the third aspect, for example, a first authentication function network element or an access management network element.

[0052] In the eleventh aspect, a computer readable storage medium is provided, including: a computer program or instructions; when the computer program or instructions run on a computer, the computer program or instructions make the computer execute the communication method in any one of the implementation manners of the first aspect or the third aspect.

[0053] In a twelfth aspect, a computer program product is provided, including a computer program or instructions, which, when executed on a computer, cause the computer to perform the communication method according to any possible implementation of the first aspect or the third aspect. BRIEF DESCRIPTION OF DRAWINGS

[0054] FIG. 1 is a schematic diagram of an architecture of a distributed subnetwork;

[0055] FIG. 2 is a schematic diagram of a registration procedure;

[0056] FIG. 3 is a schematic diagram of a judging logic of a registration state;

[0057] FIG. 4 is a schematic diagram of an architecture of a communication system according to an embodiment of the present application;

[0058] FIG. 5 is a schematic diagram of a communication method according to an embodiment of the present application;

[0059] FIG. 6 is a schematic diagram of a communication method according to an embodiment of the present application;

[0060] FIG. 7 is a schematic diagram of a communication method according to an embodiment of the present application;

[0061] FIG. 8 is a schematic diagram of a communication method according to an embodiment of the present application;

[0062] FIG. 9 is a schematic diagram of a communication apparatus according to an embodiment of the present application;

[0063] FIG. 10 is a schematic diagram of a communication apparatus according to an embodiment of the present application. DETAILED DESCRIPTION

[0064] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as a wireless network (Wi-Fi) system, a vehicle to everything (V2X) communication system, a device to device (D2D) communication system, a vehicle networking communication system, a 4th generation (4G) mobile communication system such as a long term evolution (LTE) system, a worldwide interoperability for microwave access (WiMAX) communication system, a 5th generation (5G) mobile communication system such as a new radio (NR) system, and a future communication system.

[0065] The technical terms and related technical solutions in the present application will be described below with reference to the accompanying drawings.

[0066] 1. NPN:

[0067] NPN is defined in the existing standard, and a third-party service provider can deploy NPN to provide services for terminals. For example, NPN can be deployed in an industrial park to provide high-reliability and low-latency communication services for devices within the park. However, the NPN in the prior art has some problems and cannot meet the future network requirements.

[0068] For example, there are two deployment modes of NPN, SNPN and PNI-NPN.

[0069] SNPN requires the deployment of independent core network equipment, so the operation and maintenance cost requirement is relatively high when deploying SNPN, and small and medium-sized enterprises cannot afford the deployment / maintenance cost. PNI-NPN does not require additional deployment of core network, and through the core network of the operator's public network, specific resources are isolated by using slicing / data network name (DNN) and the like, and are configured for PNI-NPN to use. This deployment mode relies on the core network of the operator, so it is difficult for enterprises to achieve autonomous management of PNI-NPN, and they can only rely on the corresponding functions provided by the large network core network. For the needs of enterprises, PNI-NPN cannot achieve agile deployment. Therefore, in the future network evolution, a distributed subnetwork deployment mode needs to be proposed.

[0070] 2. Distributed subnetwork:

[0071] FIG. 1 is a schematic diagram of the architecture of a distributed subnetwork. As shown in FIG. 1, in the architecture of the distributed subnetwork, the core network can be divided into two parts: a large network and a subnetwork. The large network is a central network deployed by an operator, which can also be referred to as a central network, and has complete core network functions and can provide all management services for terminals. There can be multiple subnetworks, and a terminal can simultaneously obtain services of multiple subnetworks. The network elements in the subnetwork are deployed on demand, and the missing network elements can use the corresponding network of the large network to obtain services, that is, part of the network functions in the central network can be shared and used by the subnetwork.

[0072] For example, the access and mobility management function (AMF) function of the existing network is split, and part of the access control function is split into a non-access-stratum (NAS) management function (NMF), referred to as NM for short, which can also be referred to as an access management network element / function / entity, without limitation. Since the subnet also needs to process the NAS message of the terminal, the NM will be deployed in each subnet as an entry network element of the terminal accessing the subnet. Part of the original mobility management function is a mobility management function (MMF), referred to as MM for short, and the mobility management of the terminal can be processed by the large network, and the MM can be deployed in the large network, and the subnet can optionally deploy the MM.

[0073] As can be seen, when the distributed subnet is deployed, only part of the function network element is deployed on demand, so it is not necessary to deploy a complete core network element like the SNPN, thereby saving the operation and maintenance cost of the core network. Since the subnet only deploys part of the function network element on demand, other network elements that are not deployed still need to be provided by the large network core network, thereby providing the terminal with complete services. Since the core network of the distributed subnet is locally deployed, it can be autonomously managed by the enterprise, and agile deployment of the network function (NF) of the subnet can be realized.

[0074] 3. Registration process:

[0075] FIG. 2 is a current registration process, as shown in FIG. 2, the process is as follows:

[0076] S201, a user equipment (UE) sends a registration request message to a radio access network (RAN).

[0077] The registration request message carries a registration type and identification information of the UE, such as a subscription concealed identifier (SUCI) or a 5G-globally unique temporary identifier (5G-GUTI) or a permanent equipment identifier (PEI). The 5G-GUTI is a temporary identifier allocated by the AMF for the UE. If the UE has never been registered in the network before, there is no 5G-GUTI, and the UE carries a SUCI for registration. The SUCI is encrypted to be a subscription permanent identifier (SUPI). The SUCI is used as much as possible to minimize the exposure of the SUPI of the UE and avoid security problems.

[0078] The registration type includes the following types:

[0079] 1) Initial registration: a registration procedure initiated when the UE is in a deregistered state.

[0080] 2) Mobility registration update: a registration procedure initiated when the UE needs to move.

[0081] 3) Periodic registration update: a registration procedure initiated when the UE is in a registered state and the periodic registration update timer expires.

[0082] 4) Emergency registration: a registration procedure initiated when the UE is in a service-restricted state.

[0083] For the identification information of the UE, when the UE has a valid 5G-GUTI, the 5G-GUTI is carried in the registration request; if the UE has no valid 5G-GUTI, the SUCI is carried; in the emergency registration, if the UE has no valid 5G-GUTI and no SUPI, the PEI is carried.

[0084] S202, the RAN selects a suitable AMF.

[0085] S203, the RAN sends a registration request message to the AMF.

[0086] S204, the new AMF interacts with the old AMF to obtain the context of the UE.

[0087] S204 is optional. When the UE initiates registration due to changing AMF (e.g. after moving out of the service area of the AMF, the UE initiates mobility registration update), the AMF (i.e. the new AMF) currently applying for registration can find the above-mentioned AMF providing the service area (i.e. the old AMF) according to the 5G-GUTI information provided by the UE, and request the context of the UE from the old AMF. In the following description, if no AMF is specified, the AMF refers to the new AMF.

[0088] S205, the AMF selects a suitable AUSF to perform authentication and other security processes.

[0089] S206, the UE, AMF, AUSF and UDM interact, and the mutual authentication between the UE and the network side is completed.

[0090] The AUSF saves the authentication result of the UE, and the UE and the AMF save the NAS security context of the UE generated in the authentication process.

[0091] The NAS security context of the UE can be used to ensure the security of NAS communication, such as encrypting and integrity protecting the NAS messages exchanged between the UE and the network. The NAS security context of the UE can include: a key K SAME / a key K AMF , a NAS algorithm, a NAS encryption key and a NAS integrity protection key. The NAS algorithm can be a NAS encryption and integrity protection algorithm. The NAS encryption key and the NAS integrity protection key can be derived by taking the key K SAME / the key K AMF as the input parameter of the NAS algorithm.

[0092] S207, after the mutual authentication between the UE and the network side is successful, the AMF interacts with the UDM to obtain the subscription data of the UE.

[0093] S208, the UDM notifies the old AMF to deregister.

[0094] S209, the old AMF initiates a deregistration process to the UDM.

[0095] S208-S209 are optional. When the UE changes the AMF (as described in S204 above), after the UDM receives the registration request sent by the new AMF, the UDM sends a deregistration notification to the old AMF. After receiving the deregistration notification, the old AMF initiates a deregistration process to the UDM.

[0096] S210, the AMF sends an N2 message to the RAN.

[0097] The N2 message includes a NAS message that needs to be forwarded by the RAN to the UE. The NAS message includes a registration accept message sent by the AMF to the UE.

[0098] S211, the RAN sends a registration accept message to the UE.

[0099] In addition, the flowchart shown in FIG. 2 can also refer to the relevant introduction in TS23.502-4.2.2.2 section, which will not be repeated here.

[0100] 4. Service judgment logic of the UE:

[0101] When the UE needs to initiate a service request, the specific judgment logic is as follows:

[0102] As shown in FIG. 3, the UE obtains a new service request. The UE first judges the current registration state. If the current state is the RM-DEREGISTERED state, the UE needs to re-perform network selection registration. When the UE completes network selection registration according to the network selection list, the UE enters the RM-REGISTERED state. When the UE is in the RM-REGISTERED state, the UE can determine the corresponding request message according to the URSP rule and send the request message.

[0103] As can be seen, in the existing UE logic, the UE only saves one registration state. If the UE completes registration in the large network, the UE is in the RM-REGISTERED state. In the RM-REGISTERED state, the UE can directly initiate a service request to the subnet without initiating registration to the subnet, that is, the UE can not be registered to the large network and the subnet at the same time. At this time, the UE can use the security context of the large network to encrypt the service request, and the NMF of the subnet cannot process the service request, resulting in failure of the UE to obtain service.

[0104] In the above registration procedure, the AUSF stores the authentication result of the UE, and the UE and the AMF store the NAS security context of the UE. After that, if the UE has a new authentication result, the AUSF replaces the previously stored authentication result, and the UE and the AMF also update the previously stored security context. However, in the distributed subnetwork scenario, even if the UE can initiate registration to the large network and the subnetwork in sequence, if the UE registers to the subnetwork first, the UE will initiate registration to the large network again, and the registration request message sent to the large network will be protected by security because the UE already has the NAS security context. Since the NAS security context is the NAS security context generated when the UE registers to the subnetwork, and the large network does not have the corresponding NAS security context, the large network cannot interpret the registration request message protected by security, resulting in failure of the UE to register to the large network. Similarly, if the UE registers to the large network first and then initiates registration to the subnetwork, the same problem will exist, that is, the subnetwork cannot interpret the registration request message protected by security, resulting in failure of the UE to register to the subnetwork.

[0105] To solve the above technical problems, the embodiments of the present application provide the following technical solutions. The technical solutions in the present application will be described below with reference to the drawings.

[0106] The present application will present various aspects, embodiments or features around a system that can include multiple devices, components, modules, etc. It should be understood and appreciated that each system can include additional devices, components, modules, etc., and / or can not include all of the devices, components, modules, etc. discussed in connection with the drawings. Furthermore, combinations of these aspects can also be used.

[0107] In addition, in the embodiments of the present application, the words such as "exemplary", "for example", etc. are used to mean example, illustration or description. Any embodiment or design scheme described as "exemplary" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "exemplary" is intended to present the concept in a specific manner.

[0108] First, in the present application, "for indicating" can include for directly indicating and for indirectly indicating. When describing that "information" is used to indicate A, it can include that the information directly indicates A or indirectly indicates A, and does not mean that A must be carried in the information.

[0109] The information indicated by one information is referred to as to-be-indicated information. In the implementation process, the to-be-indicated information can be indicated in various ways, for example, but not limited to, directly indicating the to-be-indicated information, such as the to-be-indicated information itself or an index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, where the other information is associated with the to-be-indicated information. The to-be-indicated information can also be indicated only in part, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of a specific information can also be achieved by means of the arrangement order of various information agreed in advance (for example, specified by a protocol), thereby reducing the indication overhead to a certain extent. Meanwhile, the common part of various information can be identified and uniformly indicated, so as to reduce the indication overhead caused by separately indicating the same information.

[0110] In addition, the specific indication manner can also be various existing indication manners, for example, but not limited to, the above-mentioned indication manners and various combinations thereof. The specific details of various indication manners can be referred to the prior art, which will not be described herein. As can be seen from the above, for example, when multiple information of the same type needs to be indicated, the indication manners of different information can be different. In the implementation process, the required indication manner can be selected according to the specific needs, and the selected indication manner is not limited by the embodiments of the present application. In this way, the indication manner involved in the embodiments of the present application should be understood as covering various methods that can enable the to-be-indicated party to know the to-be-indicated information.

[0111] The to-be-indicated information can be sent as a whole, or can be divided into multiple sub-information and sent separately, and the sending period and / or sending occasion of the sub-information can be the same or different. The specific sending method is not limited by the present application. The sending period and / or sending occasion of the sub-information can be predefined, for example, predefined according to a protocol, or configured by the transmitting end device by sending configuration information to the receiving end device. The configuration information can include, for example, but not limited to, one of radio resource control (RRC) signaling, medium access control (MAC) layer signaling and physical layer signaling, or a combination of at least two of them. The MAC layer signaling includes, for example, MAC control element (CE), and the physical (PHY) layer signaling includes, for example, downlink control information (DCI).

[0112] Second, in the embodiments shown below, the first, second and various numbers are only used for differentiation for the convenience of description, and do not limit the scope of the embodiments of the present application. For example, different indication information is differentiated.

[0113] Thirdly, the "preset" or "predefined" or "preconfigured" can be realized by pre-storing corresponding codes, tables or other means for indicating relevant information in devices (for example, including terminal devices and network devices), and can also be pre-specified in a protocol. The specific implementation manner is not limited in the present application. Wherein, the "storing" can mean storing in one or more memories. The one or more memories can be separately arranged or integrated in the encoder or decoder, processor, or communication device. The one or more memories can also be partially separately arranged and partially integrated in the decoder, processor, or communication device. The type of memory can be any form of storage medium, which is not limited in the present application.

[0114] Fourthly, the "protocol" involved in the embodiments of the present application can refer to a standard protocol in the communication field, which can include, for example, the LTE protocol (such as the technical specification (TS) 36, that is, the technical specification of the TS36 series) of the 3GPP, the NR protocol (such as the technical specification of the TS38 series) and the related protocol applied to the future communication system, which is not limited in the present application.

[0115] The network architecture and service scenario described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. It can be known by those skilled in the art that, with the evolution of network architecture and the appearance of new service scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0116] The network architecture and service scenario described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. It can be known by those skilled in the art that, with the evolution of network architecture and the appearance of new service scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0117] In order to facilitate understanding of the embodiments of the present application, first, the communication system suitable for the embodiments of the present application is described in detail taking the communication system shown in FIG. 4 as an example. Exemplarily, FIG. 4 is a schematic architecture diagram of a communication system suitable for the method provided by the embodiments of the present application.

[0118] FIG. 4 is a schematic architecture diagram of a communication system, which mainly includes a terminal device and a network device.

[0119] The terminal device can be a terminal with transceiver function, or can also be a chip or chip system arranged in the terminal device. The terminal device can also be referred to as a user equipment (UE), an access terminal, a subscriber unit, a user station, a mobile station (MS), a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The terminal device in the embodiments of the present application can be a mobile phone, a cellular phone, a smart phone, a Pad, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handset, a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart home device (for example, a refrigerator, a television, an air conditioner, an electricity meter, etc.), a smart robot, a mechanical arm, a plant device, a wireless terminal in self-driving, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in telemedicine, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle-mounted terminal, a road side unit (RSU) with terminal function, etc., a flight device (for example, a smart robot, a hot air balloon, a drone, an airplane), etc. The terminal device in the present application can also be a vehicle-mounted module, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip, or a vehicle-mounted unit built into a vehicle as one or more components or units. The terminal device can also be other devices with terminal functions, for example, the terminal device can also be a device with terminal function in D2D communication. The embodiments of the present application do not limit the device form of the terminal device, and the device for realizing the function of the terminal can be a terminal device; it can also be a device capable of supporting the terminal to realize the function, such as a chip system. The device can be installed in the terminal or used with the terminal. In the embodiments of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices.

[0120] The network device can be a network on the network side, such as an access management network element and / or an authentication function network element.

[0121] The access management network element can be the above-mentioned NM, or can also be a traditional AMF, or can also be a network element / function / entity for implementing an access management function in a future communication system, and the specific naming is not limited. The access management network element can be a network element in the target network, such as the access management network element can be multiple, such as a first access management network element and a second access management network element, and the target network can also be multiple, such as a first network and a second network. The first access management network element can be a network element in the first network, and the second access management network element can be a network element in the second network. The first network and the second network can share network functions. For example, the first network can be a large network, or a central network, and the second network can be a subnet; or the first network is a subnet, and the second network is a central network. Part of the network functions in the central network can be shared by the subnet, such as the subnet can use the ASUF, PCF, SMF, etc. network element in the central network. The service range of the central network can also cover the subnet, such as the service range of the subnet is the area where the park, factory, etc. is located, and the service range of the central network is the service range of the operator network, which can cover the park, factory, etc. For ease of understanding, the present application is introduced by taking the first network as the central network and the second network as the subnet as an example.

[0122] The authentication function network element can be the above-mentioned ASUF, or can also be a network element / function / entity for implementing an authentication function in a future communication system, and the specific naming is not limited. The authentication function network element can also be multiple, such as a first authentication function network element and a second authentication function network element, the first authentication function network element can be a network element in the first network, and the second authentication function network element can be a network element in the second network. Alternatively, these authentication function network elements can also be located in the central network, but can serve different networks, such as the first authentication function network element and the second authentication function network element are located in the central network, the first authentication function network element serves the central network, such as authenticating the terminal device registered to the central network, and the second authentication function network element serves the subnet, such as authenticating the terminal device registered to the subnet.

[0123] In the communication system, the terminal device can access the first network and the second network through a 3GPP access type, such as accessing the shared access network device of the first network and the second network, for subsequent registration to the first network and the second network.

[0124] When the terminal device registers to the first network for the first time, the terminal device can generate a first NAS security context associated with the first network. When the terminal device needs to register to the second network again, since the first NAS security context is associated with the first network and the terminal device does not have a NAS security context associated with the second network, the terminal device initiates a plaintext registration to the second network, so that the terminal device can register to the second network and generate a second NAS security context associated with the second network. In other words, even if the terminal device has the first NAS security context, the first NAS security context is not used to secure the registration initiated to the second network. In this way, not only can the terminal device successfully register to different networks, but also the NAS security context of different networks can be saved in network granularity, and the communication security of the terminal device with different networks is ensured.

[0125] It should be understood that the communication method provided by the embodiments of the present application can be applied between the terminal device and the network device as shown in FIG. 4, and the specific implementation can be referred to the method embodiments described below, which will not be described here. The scheme in the embodiments of the present application can also be applied to other communication systems, and the corresponding name can also be replaced by the name of the corresponding function in other communication systems.

[0126] It should also be understood that FIG. 4 is only a simplified schematic diagram for understanding, and other network devices and / or other terminal devices can also be included in the communication system, which are not shown in FIG. 4.

[0127] The interaction process between the devices in the communication system will be specifically introduced below by combining FIG. 5-FIG. 8 and the method embodiments. The communication method provided by the embodiments of the present application can be applied to the interaction between the devices in the communication system, which will be specifically introduced below.

[0128] As shown in FIG. 5, the flow of the communication method is as follows:

[0129] S501, in the process of registering the terminal device to the first network, the terminal device generates a first NAS security context associated with the terminal device and the first network.

[0130] The first NAS security context can be used for security protection of NAS messages exchanged between the terminal device and the first network. Details can be referred to the related description of the NAS security context, which will not be repeated here. The association of the first NAS security context with the first network can mean that the terminal device stores the first NAS security context in association with an identifier of the first network, indicating the applicable scope of the first NAS security context, such as applicable to security protection of NAS messages exchanged between the terminal device and the first network. If the terminal device exchanges NAS messages with other networks, the first NAS security context cannot be used for security protection of the NAS messages. The identifier of the first network can be an identifier (PLMN ID) of a public land mobile network (PLMN), or any other possible identifier, which is not limited in particular.

[0131] Specifically, the terminal device can initiate registration (initial registration) to the first network, such as sending a registration request message, denoted as a first registration request message, to the first network.

[0132] For example, the terminal device can send an access layer (AN) message, denoted as a first AN message, to the access network device. The first AN message can include AN parameters and the first registration request message. The first registration request message can be used for the terminal device to request registration to the first network, such as including an identifier of the terminal device, which can be SUCI or any other possible identifier, which is not limited. The AN parameters can indicate an identifier of a PLMN currently selected by the terminal device (selected PLMN ID), i.e., indicating the network to which the terminal device wants to register, which can be an identifier of the first network.

[0133] Upon receiving the first AN message, the access network device can send the first registration request message to the first access management network element. The first access management network element can be a network element in the first network. For example, the access network device can select the first access management network element in the first network to send the first registration request message according to the identifier of the first network. For the first access management network element, in the case that the terminal device requests registration to the first network, the first access management network element can determine the first authentication function network element. For example, the first access management network element can determine that the terminal device requests registration to the first network according to the received first registration request message, and thus select the first authentication function network element in the first network.

[0134] The first access management network element can send an authentication request message, denoted as a first authentication request message, to the first authentication function network element. The first authentication request message can be used to indicate that the terminal device is authenticated in the case that the terminal device requests to register to the first network. For example, the first authentication request message can contain the identity of the terminal device and the identity of the first network, indicating that the authentication for the terminal device is performed in the case that the terminal device requests to register to the first network, so that the first authentication function network element can subsequently associate the authentication result of the terminal with the first network. Alternatively, the identity of the first network can be replaced by the identity of the first access management network element, such as the identity of the first access management network element containing the identity of the first network in the construction of the identity of the first access management network element, or the identity of the first access management network element and the identity of the first network are stored in the first network to determine the identity of the first network, and the specific implementation mode is not limited.

[0135] In the case that the terminal device requests to register to the first network, the first authentication function network element can trigger the authentication of the terminal device, denoted as a first authentication. For example, the first authentication function network element receives the first authentication request message from the first access management network element. The first authentication function network element can determine to trigger the first authentication of the terminal device according to the first authentication request message, which is introduced below in two cases.

[0136] Case 1:

[0137] The first authentication function network element can obtain the identity of the first network in the first authentication request message and send the identity of the first network to the data management network element serving the terminal device. The data management network element serving the terminal device can be a data management network element that saves the subscription data of the terminal, and the data management network element is a network element in the first network, such as a UDM or other network element with data management / storage function. Specifically, the first authentication function network element can send a first subscription data request message to the data management network element. The first subscription data request message can contain the identity of the terminal device and the identity of the first network. The first subscription data request message can be implemented by reusing an existing message, such as a UE authentication obtain request (Nudm_UEAuthentication_Get Request) message, or can be a newly defined message, and the specific implementation is not limited. Alternatively, the identity of the first network in the first subscription data request message can be replaced by the identity of the first access management network element.

[0138] After receiving the first subscription data request message, the data management network element can obtain the subscription data of the terminal device according to the identifier of the terminal device. The data management network element can determine the network list in the subscription data of the terminal device according to the identifier of the first network. The networks in the network list are the networks to which the terminal device is subscribed, or in other words, the networks that allow the terminal device to authenticate. Thus, the data management network element can determine whether the network to which the terminal device is subscribed contains the first network. Alternatively, the data management network element can also determine the identifier of the first network corresponding to the identifier of the first access management network element according to the identifier of the first access management network element, and further determine whether the network to which the terminal device is subscribed contains the first network. If the network to which the terminal device is subscribed contains the first network, the data management network element determines to allow the terminal device to be authenticated in the first network, or in other words, to allow the terminal device to be authenticated in the case where the terminal device requests to register to the first network, otherwise, the terminal device is not allowed to be authenticated. In other words, the network will authenticate the terminal device only in the case where the terminal device initiates registration to the network to which it has subscribed, so that the terminal device can successfully register to the network subsequently, otherwise, the network will refuse authentication, so that the terminal device cannot register to the network to which it has not subscribed.

[0139] In the case where the terminal device is allowed to be authenticated, the data management network element can generate a first authentication vector of the terminal device according to the subscription data of the terminal device. The first authentication vector can be used for authentication of the terminal device, which can be a 5G home environment authentication vector (5G HE AV), or a transformed authentication vector AV', or other similar data in future communication systems. Of course, if the data management network element determines not to allow the terminal device to be authenticated in the first network, the data management network element can also not generate the first authentication vector to avoid redundancy.

[0140] The data management network element can send the first result information to the first authentication function network element, and the first authentication function network element can receive the first result information returned by the data management network element. The first result information can indicate whether the terminal device is allowed to be authenticated in the first network. For example, the first result information can be displayed information, such as a 1-bit information element, and the two values 1 / 0 are used to indicate whether the terminal device is allowed to be authenticated in the first network. The first result information can be carried in the first subscription data response message. The first subscription data response message can be implemented by reusing an existing message, such as a UE authentication obtaining response (Nudm_UEAuthentication_Get Response) message, or can be a newly defined message, without limitation. In the case where the terminal device is allowed to be authenticated in the first network, the first subscription data response message can further include a first authentication vector, otherwise, the first subscription data response message does not include the first authentication vector. It can be understood that the data management network element can also implicitly indicate whether the terminal device is allowed to be authenticated in the first network by whether the first subscription data response message carries the first authentication vector, that is, the first result information is implicit information.

[0141] In the case where the first result information indicates that the terminal device is allowed to be authenticated in the first network, the first authentication function network element triggers the first authentication of the terminal device, otherwise, the first authentication of the terminal device is not triggered, and the terminal device fails to register to the first network.

[0142] Case 2:

[0143] The first authentication function network element obtains a network list from the data management network element, and the networks in the network list are the networks to which the terminal device is subscribed. For example, the first authentication function network element can also send a first subscription data request message to the data management network element, which is different from the above case 1. The first subscription data request message can include the identifier of the terminal device, and can not include the identifier of the first network. Other aspects can be referred to the above description of case 1, and will not be repeated here.

[0144] The data management network element receives the first subscription data request message, and can obtain the subscription data of the terminal device according to the identifier of the terminal device. The data management network element can generate the first authentication vector according to the subscription data of the terminal device, and details can be referred to the related description of case 1, which will not be repeated here. The data management network element can also obtain the network list, i.e., the network to which the terminal device subscribes, from the subscription data of the terminal device. The data management network element sends the network list to the first authentication function network element, and the first authentication function network element can receive the network list returned by the data management network element. For example, the network list can be carried in the first subscription data response message, and the first subscription data response message can also include the first authentication vector. Details can be referred to the related description of case 1, which will not be repeated here.

[0145] It can be understood that the processes of case 1 and case 2 are optional. For example, the data management network element or the first authentication function network element can not make a judgment, and the first authentication function network element can trigger the first authentication of the terminal device by default.

[0146] After receiving the network list, the first authentication function network element can determine whether the network list includes the first network according to the identifier of the first network. In the case where the network list includes the first network, the first authentication function network element triggers the first authentication of the terminal device, otherwise, the first authentication of the terminal device is not triggered, and the terminal device fails to register to the first network.

[0147] In the case where the first authentication function network element triggers the first authentication of the terminal device, the first authentication function network element can execute the process of the first authentication of the terminal device. For example, the first authentication function network element can send an authentication response message, denoted as a first authentication response message, to the first access management network element. The first authentication response message can be used to respond to the first authentication request message. The first authentication response message can include the first authentication vector. Correspondingly, the first access management network element can receive the first authentication response message and continue to execute the subsequent process of the first authentication. For example, the first access management network element can send an authentication request message, denoted as a first authentication request message, to the terminal device according to the first authentication response message. The first authentication request message can instruct the terminal device to authenticate the first network, such as carrying the first authentication token (AUTN) in the first authentication vector of the terminal device, so that the terminal device authenticates the first network. Optionally, the first authentication request message can also carry the identifier of the first network, so as to indicate that the authentication (or the first authentication) is the authentication executed for the terminal device requesting to register to the first network.

[0148] In the process of the terminal device registering to the first network, the terminal device can perform authentication. For example, the terminal device receives a first authentication request message from the first network, and according to the first authentication request message, authenticates the first network, such as verifying the first authentication token. If the verification is passed, it means that the terminal device authenticates the first network successfully, otherwise, the terminal device fails to authenticate the first network, and the process terminates. In the case that the terminal device authenticates the first network successfully, the terminal device can continue to trigger the subsequent process of the first authentication for authenticating the terminal device by the network. Correspondingly, the first authentication function network element can determine the result of the first authentication of the terminal device and the first network, such as the result can be that the first authentication of the terminal device is passed. For example, the first authentication function network element can determine the result of the first authentication according to whether the authentication of the terminal device by the first authentication function network element is passed. If the authentication of the terminal device by the first authentication function network element is passed, the first authentication function network element determines that the first authentication of the terminal device is passed, that is, the result of the first authentication, and continues the subsequent registration process, otherwise, the first authentication function network element determines that the first authentication of the terminal device fails, and the process terminates. The first authentication function network element can also associate the result of the first authentication with the first network, such as associating and saving the identity of the terminal device, the result of the first authentication and the identity of the first network according to the identity of the first network and the identity of the terminal device obtained in advance, to indicate that the result of the first authentication is the authentication result determined by the terminal device when requesting to register to the first network. In other words, the first authentication function network element can store the authentication result of the terminal device in the granularity of a network, or the authentication result of the same terminal device in multiple networks. In this way, the authentication result corresponding to the registration of the terminal device in different networks can be saved by the first authentication function network element. Additionally, the first authentication function network element can also indicate to the terminal device whether the first authentication of the terminal device is passed or failed.

[0149] It can be understood that the process of the first authentication of the terminal device can also refer to TS 33.501-6.1.3 section, which will not be repeated here.

[0150] In the case that the first authentication of the terminal device is passed, the terminal device generates a first NAS security context associated with the first network via a non-access stratum security mode-control (NAS SMC) procedure. For example, the terminal device can generate the first NAS security context associated with the first network according to the first authentication request message carrying the identifier of the first network, and specifically, the first NAS security context can be associated with and stored with the identifier of the first network. That is, the terminal device can determine, according to the identifier of the network carried by the authentication request message, that the authentication is performed for registration to which network, so as to associate and store the subsequently generated NAS security context with the identifier of the network, thereby avoiding the NAS security context storage error caused by simultaneous execution of multiple authentication procedures. Of course, if the first authentication request message does not carry the identifier of the network, the terminal device can store the first NAS security context with the identifier of the first network by default. That is, the terminal device can store the NAS security context of the terminal device in the granularity of the network, so that the NAS security context generated by the terminal device in different networks can be stored by the terminal device.

[0151] It can be understood that the NAS SMC procedure can refer to the related description in TS 33.501-6.7.2, which will not be repeated here.

[0152] In the case that the first authentication of the terminal device is passed, the first access management network element can send a first registration accept message to the terminal device, and correspondingly, the terminal device can receive the first registration accept message from the first network. The first registration accept message can indicate that the terminal device is successfully registered to the first network. In addition, the first registration accept message can also include the subnet authorization service of the terminal device. For example, the subnet authorization service can indicate at least one subnet to which the terminal device is authorized to register, and the service corresponding to each of the at least one subnet, such as information including the service corresponding to the identifier of each of the at least one subnet, to indicate that the terminal device can initiate which service in which subnet. The service information can be DNN and / or slice information, or any other information that can be used to indicate the service, which is not limited in particular. The identifier of the subnet can be a PLMN ID, or any information that can be used to identify the subnet, which is not limited in particular. In the case that the first authentication of the terminal device is passed, the first access management network element can obtain the subnet authorization service of the terminal device from the data management network element and carry it to the first registration accept message to deliver to the terminal device.

[0153] After receiving the first registration accept message, the terminal device associates the state that the terminal device has registered to a network with the first network to indicate that the terminal device has registered to the first network, in response to the fact that the terminal device has successfully registered to the first network, since the first registration accept message indicates that the terminal device has successfully registered to the first network. The state that the terminal device has registered to a network can be an RM registration state, or can also be a registration state defined in the future, which is not limited in particular. The terminal device can specifically associate and save the RM registration state with the identity of the first network. That is, the terminal device can also store the state that the terminal device has registered to a network in network granularity, so that when the terminal device initiates registration to other networks, it can determine which networks are not registered and need to initiate registration accordingly.

[0154] It can be understood that the terminal device can initiate registration to the first network by reusing existing technologies, such as initiating registration by default, without the need to determine whether the state that the terminal device has registered to a network is associated with the first network. When the terminal device successfully registers to the first network, the terminal device associates the state that the terminal device has registered to a network with the first network, so as to trigger the terminal device to determine whether the state that the terminal device has registered to a network is also associated with a subnet (such as a second network) when the terminal device subsequently wants to register to the subnet. If not, the terminal device initiates registration to the subnet, and the specific implementation can also be referred to the related description of S502-S503 below, which will not be described in detail. Of course, the terminal device can also perform the judgment logic of the embodiments of the present application when initiating registration to the first network, such as the state that the terminal device has registered to a network is not associated with the first network, or the second network is associated with the state that the terminal device has registered to a network. The terminal device initiates registration to the first network.

[0155] S502, if the terminal device needs to register to a second network in the case that the terminal device has registered to a first network, the terminal device determines whether the terminal device has a NAS security context associated with the second network.

[0156] S503, in response to the fact that the terminal device does not have a NAS security context associated with the second network, the terminal device generates a second NAS security context associated with the second network.

[0157] For example, if the first service of the terminal device is authorized to be initiated in the second network, and the state that the terminal device has registered to a network is associated with the first network but not associated with the second network, the terminal device can determine that the terminal device needs to register to the second network. The first service can be provided at the application layer of the terminal device, such as providing service information of the first service, such as including DNN and / or slice information, etc.

[0158] The terminal device can determine that the first service is authorized to be initiated in the second network according to the sub-network authorized service of the terminal device, for example, the second network belongs to at least one sub-network indicated by the sub-network authorized service, and the first service belongs to the service corresponding to the second network in the sub-network authorized service, then the terminal device can determine that the first service is authorized to be initiated in the second network. In this case, the terminal device has associated the state that the terminal device has registered to the network to the first network, and the second network has not associated the state that the terminal device has registered to the network, or the second network has associated the state that the terminal device has logged out of the network, such as the RM logout state, and the terminal device can determine that the terminal device has not registered to the second network according to this, and therefore decides to need to initiate registration to the second network, such as sending a registration request message to the second network, such as a second registration request message.

[0159] When the terminal device determines that it needs to initiate registration to the second network, such as sending a NAS message (such as a second registration request message), according to the existing judgment logic of the terminal device, the terminal device can judge whether there is a NAS security context locally, if there is a NAS security context, the terminal device uses the NAS security context to protect the NAS message, otherwise, no security protection is performed, and the NAS message in plaintext is sent. In the embodiment of the present application, since the terminal device saves the NAS security context in network granularity, the terminal device can also judge whether the network has an associated NAS security context in network granularity, rather than whether there is a NAS security context locally. In this case, since the terminal device associates the first NAS security context with the first network, and the second network has no associated NAS security context, even if the terminal device has the first NAS security context, it cannot be used to protect the second registration request message. Therefore, the terminal device can send the second registration request message in plaintext to the second network, so that the second network can interpret the second registration request message and trigger subsequent processes, such as authentication and generation of a NAS security context.

[0160] For example, the terminal device can send a second AN message to the access network device, which can contain an identity of the second network and a second registration request message. The identity of the second network can be a PLMN ID, or can also be an identity defined for a subnet, which can be distinguished from the identity (such as a PLMN ID) of the central network. The second registration request message can be used for the terminal device to request registration to the second network, such as containing an identity of the terminal device, such as a SUCI. Optionally, the registration type in the second registration request message can be a newly defined registration type, such as a subnet registration. Optionally, the second AN message can contain information for indicating the subnet registration, such as denoted as a subnet registration indication. The subnet registration indication can indicate that the current registration is a subnet registration, and the subnet registration indication in combination with the identity of the second network can indicate that the current registration is required to the subnet. Of course, if the identity of the second network is an identity defined for a subnet, which can indicate that the second network is a subnet, or the registration type in the second registration request message is a subnet registration, the second AN message can also not carry the subnet registration indication.

[0161] In the case of receiving the second AN message, the access network device can send the second registration request message to a second access management network element. The second access management network element can be a network element in the second network. For example, the access network device can determine that the terminal device wants to register to the second network which is a subnet according to the identity of the second network, and optionally according to the subnet registration indication or the registration type being a subnet registration, so as to select to send the second registration request message to the second access management network element deployed in the second network.

[0162] The second access management network element can send an authentication request message to the first authentication function network element, that is, continue to send an authentication request message to the first authentication function network element in the central network by default, such as denoted as a second authentication request message, which can be used to indicate that the terminal device is authenticated in the case that the terminal device requests registration to the second network. For example, the second authentication request message can contain an identity of the terminal device and an identity of the second network, indicating that the authentication for the terminal device is performed in the case that the terminal device requests registration to the first network, so that the first authentication function network element can subsequently associate the authentication result of the terminal with the second network. Optionally, the identity of the second network can also be replaced by an identity of the second access management network element, such as the identity of the second access management network element containing the identity of the second network in the construction of the identity of the second access management network element, or the first network storing a correspondence between the identity of the second access management network element and the identity of the second network, for determining the identity of the second network, without limitation to the specific implementation manner.

[0163] In case that the terminal device requests to register to the second network, the first authentication function network element can continue to trigger the authentication of the terminal device, denoted as second authentication. For example, the first authentication function network element can receive a second authentication request message from the second access management network element, and determine to trigger the second authentication of the terminal device according to the second authentication request message, which is introduced below in two cases.

[0164] Case 3:

[0165] The first authentication function network element can obtain the identity of the second network in the second authentication request message, and send the identity of the first network to the data management network element. For example, the first authentication function network element can send a second subscription data request message to the data management network element. The second subscription data request message can contain the identity of the terminal device and the identity of the second network. The second subscription data request message can also be implemented by reusing an existing message, such as a UE authentication obtaining request message, or can be a newly defined message, which is not limited in particular. Alternatively, the identity of the second network in the second subscription data request message can be replaced by the identity of the second access management network element.

[0166] After receiving the second subscription data request message, the data management network element can obtain the subscription data of the terminal device according to the identity of the terminal device. The data management network element can determine whether the network to which the terminal device subscribes contains the second network according to the identity of the second network. Alternatively, the data management network element can determine the identity of the second network corresponding to the identity of the second access management network element according to the identity of the second access management network element, and further determine whether the network to which the terminal device subscribes contains the second network. If the network to which the terminal device subscribes contains the second network, the data management network element determines to allow the authentication of the terminal device in the second network, or in other words, to allow the authentication of the terminal device in case that the terminal device requests to register to the second network, otherwise, the authentication of the terminal device is not allowed.

[0167] The data management network element can obtain the subscription data of the terminal device according to the identity of the terminal device. The data management network element can generate a second authentication vector of the terminal device according to the subscription data of the terminal device. The second authentication vector is different from the first authentication vector, and the second authentication vector can also be used for the authentication of the terminal device, and the specific implementation can refer to the above introduction of the first authentication vector, which is not described herein again. Of course, if the data management network element determines not to allow the authentication of the terminal device in the second network, the data management network element can also not generate the second authentication vector to avoid redundancy. The data management network element can send second result information to the first authentication function network element, and the first authentication function network element can receive the second result information returned by the data management network element. The second result information can indicate whether to allow the authentication of the terminal device in the second network, and the specific implementation is similar to the above first result information, which can be understood by referring to the above, and is not described herein again.

[0168] In case that the second result information indicates that the terminal device is allowed to be authenticated in the second network, the first authentication function network element triggers the second authentication of the terminal device, otherwise, the first authentication function network element does not trigger the second authentication of the terminal device, and the terminal device fails to register to the second network.

[0169] Case 4:

[0170] The first authentication function network element obtains a network list from the data management network element, and the networks in the network list are the networks to which the terminal device subscribes. For example, the first authentication function network element can also send a second subscription data request message to the data management network element. Different from the above-mentioned case 3, the second subscription data request message can contain the identity of the terminal device, and can not contain the identity of the second network. Other details can be referred to the above-mentioned case 3, and will not be described here.

[0171] After receiving the second subscription data request message, the data management network element can obtain the subscription data of the terminal device according to the identity of the terminal device. The data management network element can generate the second authentication vector of the terminal device according to the subscription data of the terminal device. Details can be referred to the above-mentioned case 3, and will not be described here. The data management network element can also obtain the network list from the subscription data of the terminal device, and return the network list to the first authentication function network element. Correspondingly, the first authentication function network element can receive the network list returned by the data management network element. For example, the network list can be carried in a second subscription data response message, and the second subscription data response message can also contain the second authentication vector. Details can be referred to the above-mentioned case 3, and will not be described here.

[0172] After receiving the network list, the first authentication function network element can determine whether the network list contains the second network according to the identity of the second network. In case that the network list contains the second network, the first authentication function network element triggers the second authentication of the terminal device, otherwise, the first authentication function network element does not trigger the second authentication of the terminal device, and the terminal device fails to register to the second network.

[0173] It can be understood that the above-mentioned case 3 and case 4 are only examples. For example, after obtaining the network list by executing the process of case 2, the first authentication function network element can save the network list. In case that the first authentication function network element receives the second authentication request message, the first authentication function network element can also determine whether the locally saved network list contains the second network, and does not need to obtain the network list from the data management network element again, so as to reduce the communication overhead.

[0174] In a case that the first authentication function network element triggers the second authentication of the terminal device, the first authentication function network element can perform a procedure of the second authentication of the terminal device. For example, the first authentication function network element can send an authentication response message, denoted as a second authentication response message, to the second access management network element. The second authentication response message can be used to respond to the second authentication request message. The second authentication response message can comprise a second authentication vector. Correspondingly, the second access management network element can receive the second authentication response message and continue to perform a subsequent procedure of the second authentication. For example, the second access management network element can send an authentication request message, denoted as a second authentication request message, to the terminal device according to the second authentication response message. The second authentication request message can instruct the terminal device to authenticate the second network, such as carrying a second authentication token in the second authentication vector of the terminal device, for the terminal device to authenticate the second network. Optionally, the second authentication request message can further carry an identity of the second network, for indicating that the authentication (or the second authentication) is performed for the terminal device to request to register to the second network.

[0175] In a process that the terminal device registers to the second network, the terminal device can perform authentication. For example, the terminal device receives the second authentication request message from the second network and authenticates the second network according to the second authentication request message, such as verifying the second authentication token. If the verification is passed, it indicates that the terminal device passes the authentication of the second network. Otherwise, the terminal device fails the authentication of the second network and the procedure is terminated. In a case that the terminal device passes the authentication of the second network, the terminal device can continue to trigger a subsequent procedure of the second authentication, for the network (such as the first authentication function network element) to authenticate the terminal device.

[0176] The first authentication function network element can determine a result of the second authentication of the terminal device associated with the second network. For example, the first authentication function network element can determine the result of the second authentication according to whether the first authentication function network element passes the authentication of the terminal device. If the first authentication function network element passes the authentication of the terminal device, the first authentication function network element determines that the second authentication of the terminal device passes, i.e., the result of the second authentication, and continues a subsequent registration procedure. Otherwise, the first authentication function network element determines that the second authentication of the terminal device fails and the procedure is terminated. The first authentication function network element can further associate the result of the second authentication with the second network, such as associating and saving an identity of the terminal device, the result of the second authentication and an identity of the second network according to the identity of the second network and the identity of the terminal device obtained in advance, to indicate that the result of the second authentication is determined for the terminal device to request to register to the second network. Additionally, the first authentication function network element can further indicate whether the second authentication of the terminal device passes or fails.

[0177] It can be understood that the procedure of the second authentication of the terminal device can also refer to TS 33.501-6.1.3 section, which is not described herein again.

[0178] In case that the second authentication of the terminal device is passed, the terminal device can also generate a second NAS security context associated with the second network via the NAS SMC procedure. For example, the terminal device can generate the second NAS security context associated with the second network according to that the second authentication request message carries the identity of the second network, and specifically, the second NAS security context can be saved in association with the identity of the second network. Of course, if the second authentication request message does not carry the identity of the network, the terminal device can save the second NAS security context in association with the identity of the second network by default.

[0179] In case that the second authentication of the terminal device is passed, the second access management network element can directly send a second registration accept message to the terminal device. The second registration accept message can indicate that the terminal device is successfully registered to the second network. That is, since the terminal device has obtained the subnet authorization service of the terminal device and some other information such as the mobility subscription data of the terminal device in the process of registering to the first network, the second access management network element in the second network (i.e., the subnet) can not need to obtain these information again in case that the authentication is passed, and directly indicates that the terminal device is successfully registered to the second network, so as to shorten the registration procedure, reduce the time delay, and save the signaling overhead.

[0180] After receiving the second registration accept message, the terminal device can associate the state of the network to which the terminal device has registered with the second network according to the second registration accept message, and specifically, the RM registration state can be saved in association with the identity of the second network to indicate that the terminal device has registered to the second network.

[0181] It can be understood that in case of registering to the second network, the terminal device can also register to more subnets such as a third network, a fourth network, and the like, and the principle is similar to that of registering to the second network, which can be understood with reference, and will not be described herein again.

[0182] It should also be understood that in S501-S503, the authentication is triggered by the authentication function network element in the center network, such as the first authentication function network element, and the multiple authentication results corresponding to the registration of the terminal device in multiple networks are only saved by the authentication function network element, for example, when the terminal device initiates registration to different networks, the access management network element in different networks can also select the authentication function network element in the network where the access management network element is located, such as the first access management network element selects the first authentication function network element, and the second access management network element selects the second authentication function network element, and the second authentication function network element is a network element in the second network. Alternatively, these authentication function network elements can also be located in the center network, but can serve different networks, such as the first authentication function network element and the second authentication function network element are located in the center network, the first authentication function network element serves the center network, such as authenticating the terminal device registered to the center network, and the second authentication function network element serves the subnet, such as authenticating the terminal device registered to the subnet. On this basis, if the authentication of the terminal device is triggered by each of the authentication function network elements, each authentication function network element can only save one authentication result corresponding to the registration initiated by the terminal device to the network where the authentication function network element is located.

[0183] In summary, when the terminal device is registered to the first network first, the terminal device can generate the first NAS security context associated with the first network. When the terminal device needs to be registered to the second network again, since the first NAS security context is associated with the first network, and the terminal device does not have a NAS security context associated with the second network, the terminal device initiates registration in plaintext to the second network, so that the terminal device can be registered to the second network and generate the second NAS security context associated with the second network. In this way, not only can the terminal device successfully register to different networks, but also the NAS security context of different networks can be saved in network granularity to ensure the communication security of the terminal device with different networks respectively.

[0184] It can be understood that the above is an example that the first network is the center network and the second network is the subnet. For the case that the first network is the subnet and the second network is the center network, i.e., first registered to the subnet and then registered to the big network, the method shown in the above FIG. 5 is also applicable, which can be understood with reference, and will not be described here.

[0185] The above describes the communication method provided by the embodiment of the application in combination with FIG. 5. The specific process of the communication method provided by the embodiment of the application will be described in detail in combination with FIG. 6-FIG. 8.

[0186] FIG. 6 is a flow diagram of a communication method according to an embodiment of the present application. The flow shown in FIG. 6 mainly involves the interaction between the UE, the RAN, the central network and the subnet.

[0187] The network elements of the central network (e.g., the first network) mainly include the NM1 (e.g., the first access management network element), the MM, the AUSF (e.g., the first authentication function network element) and the UDM (e.g., the data management network element). The network elements of the subnet (e.g., the second network) mainly include the NM2 (e.g., the second access management network element). In this flow, the UE can first complete registration in the central network, in which process, the UE can generate the NAS security context associated to the central network and determine the RM registration state associated to the central network. Then, the UE can initiate registration to the subnet according to the RM registration state associated to the central network, and the subnet is in the RM registration state or the RM deregistration state, in which process, the UE can generate the NAS security context associated to the subnet and determine the RM registration state associated to the subnet. In this way, not only the UE is registered to the central network and the subnet simultaneously, but also the UE can use the NAS security context associated to the central network to communicate with the central network securely and use the NAS security context associated to the subnet to communicate with the subnet securely.

[0188] Specifically, as shown in FIG. 6, the flow of the communication method is as follows:

[0189] S601, the UE sends an AN message #1 to the RAN.

[0190] The AN message #1 can contain the AN parameter and the registration request message #1 (e.g., the first registration request message), and the AN parameter #1 indicates the identity of the PLMN currently selected by the UE (selected PLMN ID), i.e., indicates the network to which the UE wants to register, which can be the central network. The registration request message #1 includes the identity of the UE, such as SUCI.

[0191] In addition, the AN message #1 can also refer to the related introduction of the first AN message described above, which will not be described here.

[0192] S602, the RAN sends an N2 message #1 to the NM1.

[0193] The N2 message #1 can contain the registration request message #1 in the AN message #1. The RAN can determine that the PLMN is the central network according to the identity of the PLMN currently selected by the UE, and then send the N2 message #1 to the NM1 in the central network. In S602, the identity of the PLMN currently selected by the UE is the identity of the central network.

[0194] S603, the NM1 sends an authentication request message #1 to the AUSF.

[0195] The AUSF is an AUSF in the deployment center network.

[0196] The authentication request message #1 can be used to indicate to authenticate the UE in the case that the UE requests to register to the center network, which can be referred to the related description of the first authentication request message, and details are not described herein.

[0197] The AUSF can determine whether to authenticate the UE in the case that the UE requests to register to the center network, that is, to perform S604a-S605a or S604b-S605b described below.

[0198] S604a, the AUSF sends a subscription data request message #1 to the UDM.

[0199] The UDM is a UDM in the deployment center network.

[0200] The subscription data request message #1 is used to request the authentication vector of the UE. The subscription data request message #1 can contain the identity of the UE, and can also contain the identity of the center network or the identity of the NM1.

[0201] S605a, the UDM sends a subscription data response message #1 to the AUSF.

[0202] The subscription data response message #1 can be used to respond to the subscription data request message #1, such as containing the authentication vector #1 of the UE (such as the first authentication vector described above) and the first result information.

[0203] It can be understood that S604a-S605a can also be referred to the related description of case 1 described above, and details are not described herein.

[0204] S604b, the AUSF sends a subscription data request message #2 to the UDM.

[0205] Unlike the subscription data request message #1 described above, the subscription data request message #2 contains the identity of the UE, but can not carry the identity of the center network.

[0206] S605b, the UDM sends a subscription data response message #2 to the AUSF.

[0207] The subscription data response message #2 can be used to respond to the subscription data request message #2, such as containing the authentication vector #1 of the UE (such as the first authentication vector described above), and can also contain the network to which the UE subscribes, such as a network list.

[0208] It can be understood that S604b-S605b can also be referred to the related description of case 2 described above, and details are not described herein.

[0209] It can be understood that S604a-S605a and S604b-S605b are in an "or" execution relationship.

[0210] S606, if the AUSF determines to authenticate the UE in the case that the UE requests to register to the central network, triggering authentication of the UE.

[0211] The authentication of the UE can be performed by the UE, NM1, SEAF, AUSF, and UDM, so as to authenticate the UE in the central network. For details, refer to the related description in TS33.501-6.1.3 chapter, which will not be repeated here.

[0212] The AUSF can save the authentication result of the UE in the central network, such as whether the authentication is passed or failed.

[0213] In the case that the authentication is passed, the UE can generate a NAS security context of the UE associated to the central network, or a NAS security context of the central network, denoted as NAS security context #1. The UE can save the NAS security context #1 of the UE in association with the network to which the UE is currently registered, such as saving the NAS security context #1 of the UE in association with the identifier of the central network, so as to indicate that the NAS security context #1 of the UE is applicable to the central network.

[0214] In addition, the NAS security context #1 can also refer to the related description of the first NAS security context described above, which will not be repeated here.

[0215] S607, the NM1 sends a subscription data request message #3 to the UDM.

[0216] The subscription data request message #3 can be used to request service subscription data of the UE, such as containing the identifier of the UE.

[0217] S608, the UDM sends a subscription data response message #3 to the NM1.

[0218] The subscription data response message #3 can be used to respond to the subscription data request message #3, such as containing the service subscription data of the UE. The service subscription data of the UE can contain authorized subnet services (or authorized subnet services) of the UE, for example, the authorized subnet services of the UE can contain the identifier of the associated subnet and the information of the service, so as to indicate that the UE can obtain the service in the subnet. The information of the service can be DNN and / or slice information, or any other information that can be used to indicate the service, which is not limited in detail.

[0219] The UDM can obtain the subscription data of the UE according to the identity of the UE in the subscription data request message #3, and obtain the part related to the service from the subscription data of the UE, i.e. the service subscription data of the UE. The UDM can carry the service subscription data of the UE to the subscription data response message #3, and then return to the NM1.

[0220] S609, the NM1 sends a mobility update request message to the MM.

[0221] The mobility update request message can request the MM to register the mobility management context of the UE, such as containing the identity of the UE.

[0222] S610, the MM sends a subscription data request message #4 to the UDM.

[0223] The MM can request the UDM to provide the mobility subscription data of the UE according to the mobility update request message, i.e. send the subscription data request message #4 to the UDM. The subscription data request message #4 can be used to request the mobility subscription data of the UE, such as containing the identity of the UE.

[0224] S611, the UDM sends a subscription data response message #4 to the MM.

[0225] The subscription data response message #4 can be used to respond to the subscription data request message #4, such as containing the mobility subscription data of the UE, such as the mobility restriction list, the registration area, etc. The UDM can obtain the subscription data of the UE according to the identity of the UE in the subscription data request message #4, and obtain the part related to the mobility from the subscription data of the UE, i.e. the mobility subscription data of the UE. The UDM can carry the mobility subscription data of the UE to the subscription data response message #4, and then return to the AUSF.

[0226] S612, the MM sends a mobility update response message to the NM1.

[0227] The mobility update response message can respond to the mobility update request message, such as containing the mobility management context of the UE. The MM can determine the mobility data of the UE according to the mobility management context of the UE, such as also containing the mobility restriction list, the registration area, etc. The MM can carry the mobility subscription data of the UE to the mobility update response message, and then return to the NM1.

[0228] S613, the NM1 sends an initial connection setup request message to the RAN.

[0229] The initial connection establishment request message can include a registration accept message #1, which can be used to respond to the registration request message #1. The registration accept message #1 can contain information in the mobility management context of the UE, such as a mobility restriction list, a registration area, and the like, and can also contain information in the service subscription data of the UE, such as authorized subnet services of the UE.

[0230] S614, the RAN sends a registration accept message #1 to the UE.

[0231] S615, the UE saves the registration state information of the central network.

[0232] In S615, the registration state information of the central network can include the identity of the central network and the RM registration state, indicating that the registration state of the UE in the central network is the RM registration state.

[0233] It can be understood that the above S601-S615 can also refer to the related description of S501, which will not be repeated here.

[0234] S616, the UE determines that it needs to register to subnet #1 (such as the second network).

[0235] The UE can determine that a new service needs to be initiated in subnet #1 according to service information. The service information can be provided by the application layer of the UE, such as including DNN and / or slice information, to trigger the UE to initiate a new service. The UE can determine whether the service information corresponds to a subnet in the authorized subnet services of the UE, and if the service information corresponds to subnet #1 in the authorized subnet services of the UE, it is determined that the new service needs to be initiated in subnet #1, otherwise, the UE can initiate the new service in the central network.

[0236] In the case that the new service needs to be initiated in subnet #1, the UE can determine the registration state of the UE in subnet #1, such as whether the registration state information of subnet #1 is saved. The registration state information of subnet #1 can include the identity of subnet #1, and the RM registration state or the RM deregistration state, indicating that the UE is registered or deregistered in subnet #1. If the registration state information of subnet #1 is not saved, or the registration state information of subnet #1 is saved but is in the RM deregistration state, the UE determines that it needs to register (or re-register) to subnet #1, i.e., S617 is executed, otherwise, the UE can initiate the service to subnet #1 according to the URSP.

[0237] It can be understood that S616 can also refer to the related description of S502, which will not be repeated here.

[0238] S617, the UE sends an AN message #2 to the RAN.

[0239] The AN message #2 can comprise the identification of the subnet #1 and the registration request message #2. In addition, the AN message #2 can refer to the related description of the second AN message, which will not be repeated here.

[0240] S618, the RAN sends an N2 message #2 to the NM2.

[0241] The N2 message #2 can comprise the registration request message #2 in the AN message #2. The RAN can determine that the UE wants to register to the subnet #1 according to the registration request message #2, and thus select to send the N2 message #2 to the NM2 deployed in the subnet #1.

[0242] S619, the NM2 sends an authentication request message #2 to the AUSF.

[0243] The authentication request message #2 can be used to indicate to authenticate the UE in the case that the UE requests to register to the subnet #1. For details, refer to the related description of the second authentication request message, which will not be repeated here.

[0244] S620, the AUSF sends a subscription data request message #5 to the UDM.

[0245] The subscription data request message #5 can be used to request the authentication vector of the UE. For example, the subscription data request message #5 can comprise the identification of the UE, and optionally, the subscription data request message #5 can further comprise the identification of the subnet or the identification of the NM2.

[0246] S621, the UDM sends a subscription data response message #5 to the AUSF.

[0247] The subscription data response message #5 can be used to respond to the subscription data request message #5, such as comprising the authentication vector #2 (such as the second authentication vector) of the UE. Optionally, in the case that the subscription data request message #5 comprises the identification of the subnet or the identification of the NM2, the subscription data response message #5 can further comprise the second result information.

[0248] It can be understood that if the AUSF obtains the network subscribed by the UE in advance through S605b, the UDM can not provide the network subscribed by the UE in S620-S621.

[0249] S622, if the AUSF determines to authenticate the UE in the case that the UE requests to register to the subnet #1, the authentication of the UE is triggered.

[0250] The authentication of the UE can be performed by the UE, the NM2, the SEAF, the AUSF, and the UDM, so as to authenticate the UE in the central network. For details, refer to the related description of TS33.501-6.1.3 chapter, which will not be repeated here.

[0251] It can be understood that S620-S622 can also refer to the above-mentioned case 2 and case 4, and will not be repeated here.

[0252] The AUSF can save the authentication result of the UE in the central network, such as whether the authentication is passed or failed.

[0253] In the case of passing the authentication, the UE can generate the NAS security context of the UE associated with the subnet #1, or the NAS security context of the subnet #1, such as NAS security context #2. The UE can save the NAS security context #2 of the UE in association with the network currently registered by the UE, such as saving the NAS security context #2 of the UE in association with the identifier of the subnet #1, to indicate that the NAS security context #2 of the UE is applicable to the subnet #1.

[0254] In addition, the NAS security context #2 can also refer to the above-mentioned second NAS security context, and will not be repeated here.

[0255] S623, the NM2 sends a registration accept message #2 to the UE.

[0256] The registration accept message #2 can respond to the registration request message #2, and the difference from the above-mentioned registration accept message #1 is that since the network side has sent the registration related information (such as the mobility restriction list, the registration area, the authorized subnet service of the UE, etc.) to the UE through the mobility update response message, the registration accept message #2 can no longer carry these information. In other words, the NM2 can immediately or directly perform S623 in the case of determining that the authentication is passed, without performing the process similar to S607-S611.

[0257] S624, the UE saves the registration state information of the subnet #1.

[0258] In S624, the registration state information of the subnet #1 can include the identifier of the subnet #1 and the RM registration state, to indicate that the registration state of the UE in the subnet #1 is the RM registration state.

[0259] It can be understood that the above-mentioned process is taken as an example of the subnet #1, but not as a limitation, for example, the UE can also initiate registration to more subnets, such as to the subnet #2, and the process is similar to the above-mentioned UE registration to the subnet #1, please refer to the understanding, and will not be repeated here.

[0260] Fig. 7 is a flow diagram of a communication method provided by an embodiment of the application. The flow shown in Fig. 7 mainly involves the interaction between the UE, the RAN, the central network and the subnet.

[0261] The network elements of the center network (e.g., the first network) mainly include NM1 (e.g., the first access management network element), MM, AUSF (e.g., the first authentication function network element), and UDM (e.g., the data management network element). The network elements of the sub-network (e.g., the second network) mainly include NM2 (e.g., the second access management network element). Different from FIG. 6, in the case that the UE registers to the center network, NM1 can send the identity of the center network to the UE in the authentication process of the UE, so that the UE associates the generated NAS security context #1 to the center network. Similarly, in the case that the UE registers to the sub-network #1, NM2 can also send the identity of the sub-network #1 to the UE in the authentication process of the UE, so that the UE associates the generated NAS security context #2 to the sub-network #1.

[0262] Specifically, as shown in FIG. 7, the flow of the communication method is as follows:

[0263] S701, the UE sends an AN message #1 to the RAN.

[0264] S702, the RAN sends an N2 message #1 to NM1.

[0265] S703, NM1 sends an authentication request message #1 to AUSF.

[0266] The AUSF is deployed in the center network.

[0267] S704a, the AUSF sends a subscription data request message #1 to UDM.

[0268] S705a, the UDM sends a subscription data response message #1 to the AUSF.

[0269] S704b, the AUSF sends a subscription data request message #2 to UDM.

[0270] S705b, the UDM sends a subscription data response message #2 to the AUSF.

[0271] Wherein, S701-S705b can refer to the related description of S601-S605b above, which will not be repeated here.

[0272] S706, the AUSF sends an authentication response message #1 to NM1.

[0273] If the AUSF determines to authenticate the UE in the case that the UE requests to register to the center network, the authentication of the UE is triggered, that is, S706 is executed. The authentication response message #1 can be used to respond to the authentication request message #1, such as containing the authentication vector #1 of the UE, which can refer to the related description of the first authentication response message above, which will not be repeated here.

[0274] S707, NM1 sends an authentication request message #1 to the UE.

[0275] The authentication request message #1 can indicate that the UE is authenticated to the central network, such as carrying the AUTN #1 in the authentication vector #1, in addition, the authentication request message #1 can also carry the identity of the central network, which can be referred to the above description of the first authentication request message, and details are not described herein. Then, the UE can continue to complete the subsequent authentication process with the network, and the AUSF can save the authentication result of the UE in the central network, such as whether the authentication is passed or failed. The authentication process can also be referred to the related description in TS33.501-6.1.3 chapter, and details are not described herein.

[0276] In the case of passing the authentication, the UE can generate the NAS security context #1 associated to the central network, such as saving the NAS security context #1 of the UE and the identity of the central network, to indicate that the NAS security context #1 of the UE is applicable to the central network. In addition, the NAS security context #1 can also be referred to the above description of the first NAS security context, and details are not described herein.

[0277] S708, the NM1 sends a subscription data request message #3 to the UDM.

[0278] S709, the UDM sends a subscription data response message #3 to the NM1.

[0279] S710, the NM1 sends a mobility update request message to the MM.

[0280] S711, the MM sends a subscription data request message #4 to the UDM.

[0281] S712, the UDM sends a subscription data response message #4 to the MM.

[0282] S713, the MM sends a mobility update response message to the NM1.

[0283] S714, the NM1 sends an initial connection establishment request message to the RAN.

[0284] S715, the RAN sends a registration accept message #1 to the UE.

[0285] S716, the UE saves the registration state information of the central network.

[0286] S717, the UE determines that it needs to be registered to the subnetwork #1 (such as the second network).

[0287] S718, the UE sends an AN message #2 to the RAN.

[0288] S719, the RAN sends an N2 message #2 to the NM2.

[0289] S720, the NM2 sends an authentication request message #2 to the AUSF.

[0290] S721, the AUSF sends a subscription data request message #5 to the UDM.

[0291] S722, the UDM sends a subscription data response message #5 to the AUSF.

[0292] Wherein, S708-S722 can also refer to the related introduction of S607-S621, which will not be repeated here.

[0293] S723, the AUSF sends an authentication response message #2 to the NM2.

[0294] If the AUSF determines to authenticate the UE in the case that the UE requests to register to the subnet #1, the authentication of the UE is triggered, that is, S723 is executed. The authentication response message #2 can be used to respond to the authentication request message #2, such as containing the authentication vector #2 of the UE, which can refer to the related introduction of the second authentication response message above, and will not be repeated here.

[0295] S724, the NM1 sends an authentication request message #2 to the UE.

[0296] The authentication request message #2 can indicate that the UE authenticates the subnet #1, such as carrying the AUTN #2 in the authentication vector #2. In addition, the authentication request message 2 can also carry the identifier of the subnet #1, which can refer to the related introduction of the second authentication request message above, and will not be repeated here. Then, the UE can continue to cooperate with the network to complete the subsequent authentication process, and the AUSF can save the authentication result of the UE in the subnet #1, such as whether the authentication is passed or failed. The process of authentication can also refer to the related introduction of TS33.501-6.1.3 chapter, which will not be repeated here.

[0297] In the case that the authentication is passed, the UE can generate the NAS security context #2 associated with the subnet #1, such as saving the NAS security context 21 of the UE and the identifier of the subnet #1 to represent that the NAS security context #2 of the UE is applicable to the central network. In addition, the NAS security context #2 can refer to the related introduction of the second NAS security context above, which will not be repeated here.

[0298] S725, the NM2 sends a registration accept message #2 to the UE.

[0299] S726, the UE saves the registration state information of the subnet #1.

[0300] Wherein, S725-S726 can also refer to the related introduction of S723-S724 above, which will not be repeated here.

[0301] It can be understood that the above procedure is taken as an example of Subnet #1, but not as a limitation. For example, the UE can also initiate registration to more subnets, such as Subnet #2, and the procedure is similar to the above registration of the UE to Subnet #1. Please refer to the understanding, which will not be repeated here.

[0302] FIG. 8 is a flow diagram of a communication method provided by an embodiment of the application. The flow shown in FIG. 8 mainly involves the interaction between the UE, the RAN, the center network, and the subnet.

[0303] The network elements of the center network (such as the first network) mainly include NM1 (such as the first access management network element), MM, AUSF (such as the first authentication function network element), and UDM (such as the data management network element). The network elements of the subnet (such as the second network) mainly include NM2 (such as the second access management network element). The difference from FIG. 6 is that, in the case of registration to the center network, NM1 can select AUSF1 of the center network for AUSF1 to trigger the authentication of the UE. Similarly, in the case of registration to Subnet #1, NM2 can select AUSF2 of Subnet #1 for AUSF2 to trigger the authentication of the UE.

[0304] Specifically, as shown in FIG. 8, the procedure of the communication method is as follows:

[0305] S801, the UE sends an AN message #1 to the RAN.

[0306] S802, the RAN sends an N2 message #1 to NM1.

[0307] S801-S802 can also refer to the related introduction of S801-S802, which will not be repeated here.

[0308] S803, NM1 sends an authentication request message #1 to AUSF1.

[0309] AUSF1 is an AUSF deployed in the center network. Unlike S603 above, the authentication request message #1 can not carry the identifier of the center network, and other aspects can be understood by referring to S603, which will not be repeated here.

[0310] S804, AUSF1 sends a subscription data request message #1 to UDM.

[0311] S805, UDM sends a subscription data response message #1 to AUSF1.

[0312] It can be understood that S804-S805 is an existing procedure, the subscription data request message #1 can not carry the identifier of the center network, and AUSF1 does not need to determine whether to authenticate the UE in the case of UE requesting to register to the center network, which can be authenticated by default.

[0313] S806, the AUSF sends an authentication response message #1 to the NM1.

[0314] S807, the NM1 sends an authentication request message #1 to the UE.

[0315] Wherein, S806-S807 are similar to S706-S707, i.e. the identity of the central network can be delivered to the UE, or not, i.e. the flow of FIG. 6 can be referred to for understanding, and will not be repeated here.

[0316] S808, the NM1 sends a subscription data request message #2 to the UDM.

[0317] S809, the UDM sends a subscription data response message #2 to the NM1.

[0318] S810, the NM1 sends a mobility update request message to the MM.

[0319] S811, the MM sends a subscription data request message #3 to the UDM.

[0320] S812, the UDM sends a subscription data response message #3 to the MM.

[0321] S813, the MM sends a mobility update response message to the NM1.

[0322] S814, the NM1 sends an initial connection establishment request message to the RAN.

[0323] S815, the RAN sends a registration accept message #1 to the UE.

[0324] S816, the UE saves the registration state information of the central network.

[0325] S817, the UE determines that it needs to register to the subnetwork #1 (such as the second network).

[0326] S818, the UE sends an AN message #2 to the RAN.

[0327] S819, the RAN sends an N2 message #2 to the NM2.

[0328] Wherein, S808-S819 can also be referred to the related introduction of S607-S618, which will not be repeated here.

[0329] S820, the NM2 sends an authentication request message #2 to the AUSF #2.

[0330] The AUSF2 is the AUSF deployed in the subnetwork #1. Unlike S619, the authentication request message #2 can not carry the identity of the subnetwork #1, and the others can be understood by referring to S619, which will not be repeated here.

[0331] S821, the AUSF 2 sends a subscription data request message #4 to the UDM.

[0332] S822, the UDM sends a subscription data response message #4 to the AUSF 2.

[0333] It can be understood that S821-S822 are existing processes, the subscription data request message #4 can not carry the identifier of the subnet #1, and the AUSF 2 does not need to determine whether to authenticate the UE in the case that the UE requests to register to the subnet #1, and can authenticate the UE by default.

[0334] S823, the AUSF sends an authentication response message #2 to the NM 2.

[0335] S824, the NM 1 sends an authentication request message #2 to the UE.

[0336] S823-S824 are similar to S723-S724 described above, that is, the identifier of the central network can be transmitted to the UE, or can not be transmitted, that is, the flow in FIG. 6 can be understood, and details are not described herein.

[0337] S825, the NM 2 sends a registration accept message #2 to the UE.

[0338] S826, the UE saves the registration state information of the subnet #1.

[0339] S825-S826 can also refer to the related description of S623-S624 described above, and details are not described herein.

[0340] It can be understood that the above process is taken as an example of the subnet #1, but is not as a limitation, for example, the UE can also initiate registration to more subnets, such as the subnet #2, and the process is similar to the registration of the UE to the subnet #1, and details are not described herein.

[0341] The communication method provided by the embodiments of the present application is described in detail above in combination with FIGS. 5-8. The communication device for executing the communication method provided by the embodiments of the present application is described in detail below in combination with FIGS. 9 and 10.

[0342] Exemplarily, FIG. 9 is a structural schematic diagram one of a communication device provided by the embodiments of the present application. As shown in FIG. 9, the communication device 900 includes a processing module 901 and a transceiver module 902. For the convenience of description, FIG. 9 only shows the main components of the communication device.

[0343] In some embodiments, the communication device 900 can be used to realize the functions of the terminal device in the above-described method shown in FIGS. 5-8. For example, the processing module 902 is used to realize the transceiving function of the terminal device, and the processing module 901 is used to realize the processing function of the terminal device except the transceiving function.

[0344] In some other embodiments, the communication apparatus 900 can be configured to implement the function of an authentication function network element (e.g., the first authentication function network element) in the methods shown in FIGS. 5-8. For example, the processing module 901 is configured to implement the processing function of the authentication function network element, and the transceiver module 902 is configured to implement the transceiving function of the authentication function network element.

[0345] In some other embodiments, the communication apparatus 900 can be configured to implement the function of an access management network element (e.g., the first access management network element or the second access management network element) in the methods shown in FIGS. 5-8. For example, the processing module 901 is configured to implement the processing function of the access management network element, and the transceiver module 902 is configured to implement the transceiving function of the access management network element.

[0346] Optionally, the communication apparatus 900 can further include a storage module (not shown in FIG. 9) storing programs or instructions. When the processing module 901 executes the programs or instructions, the communication apparatus 900 can perform the communication methods shown in FIGS. 5-8.

[0347] It should be understood that the processing module 901 involved in the communication apparatus 900 can be implemented by a processor or processor-related circuit component, and can be a processor or processing unit; and the transceiver module 902 can be implemented by a transceiver or transceiver-related circuit component, and can be a transceiver or transceiving unit.

[0348] It should be understood that the communication apparatus 900 can be a terminal apparatus or a network device, or can be a component (e.g., a processor, a chip, or a chip system, etc.) of a terminal apparatus or a network device, or can be a logic node, a logic module, or software capable of implementing all or part of the functions of a terminal apparatus or a network device, and the present application does not limit the same.

[0349] By way of example, FIG. 10 is a structural schematic diagram of a communication apparatus according to an embodiment of the present application. The communication apparatus can be a terminal device or a network device, or can be a chip (system) or other component or assembly that can be arranged in a terminal device or a network device. As shown in FIG. 10, the communication apparatus 1000 can include a processor 1001. Optionally, the communication apparatus 1000 can further include a memory 1002 and / or a transceiver 1003. The processor 1001 is coupled with the memory 1002 and the transceiver 1003, for example, through a communication bus.

[0350] The components of the communication apparatus 1000 will be described in detail below in conjunction with FIG. 10:

[0351] The processor 1001 is a control center of the communication device 1000, which can be one processor or a combination of multiple processing elements. For example, the processor 1001 is one or more central processing units (CPUs), application specific integrated circuits (ASICs), or one or more integrated circuits configured to implement one or more embodiments of the application, such as one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0352] Optionally, the processor 1001 can perform various functions of the communication device 1000 by running or executing software programs stored in the memory 1002 and calling data stored in the memory 1002.

[0353] In a specific implementation, as an embodiment, the processor 1001 can include one or more CPUs, such as CPU0 and CPU1 shown in FIG. 10, for executing the communication method shown in FIGS. 5-8.

[0354] In a specific implementation, as an embodiment, the communication device 1000 can also include multiple processors, such as the processor 1001 and the processor 1004 shown in FIG. 10. Each of these processors can be a single-CPU or a multi-CPU. The processor here can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0355] The memory 1002 is configured to store software programs for implementing the schemes of the application and to be controlled by the processor 1001 to perform the schemes. The specific implementation can refer to the above method embodiments, which will not be repeated here.

[0356] Optionally, the memory 1002 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage or other magnetic storage devices, or any other medium capable of storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this. The memory 1002 can be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 through the interface circuit (not shown in FIG. 10) of the communication apparatus 1000, and the embodiments of the present application do not make a specific limitation in this regard.

[0357] The transceiver 1003 is configured to communicate with other communication apparatuses. For example, the communication apparatus 1000 is a terminal device, and the transceiver 1003 can be configured to communicate with a network device or another terminal device. For another example, the communication apparatus 1000 is a network device, and the transceiver 1003 can be configured to communicate with a terminal device or another network device.

[0358] Optionally, the transceiver 1003 can include a receiver and a transmitter (not shown separately in FIG. 10). The receiver is configured to implement the receiving function, and the transmitter is configured to implement the transmitting function.

[0359] Optionally, the transceiver 1003 can be integrated with the processor 1001 or exist independently and be coupled to the processor 1001 through the interface circuit (not shown in FIG. 10) of the communication apparatus 1000, and the embodiments of the present application do not make a specific limitation in this regard.

[0360] It should be noted that the structure of the communication apparatus 1000 shown in FIG. 10 does not constitute a limitation on the communication apparatus, and the actual communication apparatus can include more or fewer components than those shown, or combine certain components, or have a different arrangement of components.

[0361] In addition, the technical effects of the communication apparatus 1000 can refer to the technical effects of the communication method described in the above method embodiments, which will not be described here again.

[0362] It is to be understood that the processor in the present application can be a CPU, and can also be other general-purpose processors, DSPs, ASICs, FPGAs or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0363] It is also to be understood that the memory in the present application can be a volatile memory or a nonvolatile memory, or can include both volatile and nonvolatile memory. Among them, the nonvolatile memory can be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an EEPROM or a flash memory. The volatile memory can be a RAM used as an external cache. By way of example, but not limitation, many forms of RAM can be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DR RAM).

[0364] The above-described embodiments can be implemented in part or in whole through software, hardware (e.g., circuitry), firmware, or any combination thereof. When implemented in software, the above-described embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When loaded and executed by a computer, the computer instructions or computer programs can produce the processes or functions described above in accordance with the embodiments of the present application. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, such as from a website site, a computer, a server, or a data center to another website site, a computer, a server, or a data center through a wired (e.g., infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium or a collection of medium accessible by a computer or a data storage device such as a server, a data center, etc. containing one or more available medium. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.

[0365] It should be understood that the term "and / or" in this document is merely used to describe an associated relationship between associated objects, and can represent three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone, where A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the front and rear associated objects, but can also represent an "and / or" relationship. The specific meaning can be understood according to the context before and after.

[0366] In this application, "at least one" means one or more, and "multiple" means two or more. "At least one of the following" or similar expressions means any combination of the items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.

[0367] It should be understood that in various embodiments of the present application, the size of the sequence number of the above-described processes does not mean the order of execution, and the execution order of the processes should be determined according to their functions and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0368] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0369] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0370] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0371] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0372] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.

[0373] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk, etc.

[0374] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method characterized by comprising: The method is applied to a terminal device, and comprises: In a process in which the terminal device registers to a first network, a first non-access stratum (NAS) security context associated with the terminal device and the first network is generated, the first NAS security context being used for security protection of NAS messages exchanged between the terminal device and the first network; In a case where the terminal device has registered to the first network, if the terminal device needs to register to a second network, it is determined whether the terminal device has a NAS security context associated with the second network; In response to the terminal device not having a NAS security context associated with the second network, a second NAS security context associated with the terminal device and the second network is generated, the second NAS security context being used for security protection of NAS messages exchanged between the terminal device and the second network, and the first network and the second network share network functions.

2. The method of claim 1, wherein, The first network is a center network, and the second network is a subnet, and part of network functions in the center network are shared with the subnet.

3. The method according to claim 1 or 2, characterized in that, The generation of the second NAS security context associated with the terminal device and the second network comprises: sending, to the second network, a registration request message in plaintext, the registration request message being used for the terminal device to request registration to the second network; performing authentication in a process in which the terminal device registers to the second network; in a case where the authentication is passed, generating, through a non-access stratum security mode control (NAS SMC) procedure, the second NAS security context associated with the terminal device and the second network.

4. The method of claim 3, wherein, The registration type contained in the registration request message is subnet registration.

5. The method according to claim 3 or 4, characterized in that, The performance of authentication comprises: receiving an authentication request message from the second network, the authentication request message indicating that the terminal device authenticates the second network, and the authentication request message carrying an identity of the second network; authenticating the second network according to the authentication request message; The generation of the second NAS security context associated with the terminal device and the second network comprises: generating the second NAS security context associated with the terminal device and the second network according to the authentication request message carrying the identity of the second network.

6. The method according to any one of claims 3-5, characterized in that, Before the sending, to the second network, of the registration request message in plaintext, the method further comprises: receiving a first registration accept message from the first network, the first registration accept message indicating that the terminal device successfully registers to the first network; in response to the terminal device successfully registering to the first network, associating a state in which the terminal device has registered to a network with the first network; if first service of the terminal device is authorized to be initiated in the second network, and the state in which the terminal device has registered to a network is associated with the first network but not associated with the second network, determining that the terminal device needs to register to the second network.

7. The method of claim 6, wherein, The method further comprises: According to a subnet authorized service of the terminal device, it is determined that the first service is authorized to be initiated at the second network, the subnet authorized service indicates at least one subnet to which the terminal device is authorized to register and a service corresponding to each of the at least one subnet, and the second network belongs to the at least one subnet, and the first service belongs to the service corresponding to the second network.

8. The method of claim 7, wherein, The first registration acceptance message includes the subnet authorized service.

9. The method according to claim 6 or 7, characterized in that, The method further includes: receiving a second registration acceptance message from the second network, the second registration acceptance message indicating that the terminal device is successfully registered to the second network; in response to the terminal device being successfully registered to the second network, associating a state in which the terminal device is registered to a network with the second network.

10. The method of claim 2, wherein, The first NAS security context associated with the terminal device and the first network includes: performing authentication in a process in which the terminal device is registered to the first network; in a case where the authentication is passed, generating the first NAS security context associated with the terminal device and the first network through a NAS SMC process.

11. The method of claim 10, wherein, The authentication includes: receiving an authentication request message from the first network, the authentication request message indicating that the terminal device is authenticated to the first network, and the authentication request message carrying an identity of the first network; authenticating the first network according to the authentication request message; The first NAS security context associated with the terminal device and the first network includes: generating the first NAS security context associated with the terminal device and the first network according to the authentication request message carrying the identity of the first network.

12. The method according to any one of claims 1-11, characterized in that, The terminal device accesses the first network and the second network through an access type of the third generation partnership project (3GPP).

13. A method of communication, comprising: The method includes: in a case where a terminal device requests to register to a first network, a first authentication function network element triggers first authentication of the terminal device; the first authentication function network element determines a result of the first authentication associated with the terminal device and the first network; in a case where the terminal device requests to register to a second network, the first authentication function network element triggers second authentication of the terminal device, and the first network and the second network share network functions; the first authentication function network element determines a result of the second authentication associated with the terminal device and the second network.

14. The method of claim 13, wherein, The first network is a central network, and the second network is a subnet, and part of network functions in the central network are shared by the subnet.

15. The method according to claim 13 or 14, characterized in that, The method further includes: the first authentication function network element receives a first authentication request message from a first access management network element, the first access management network element being a network element in the first network, and the first authentication request message being used to request to authenticate the terminal device in a case where the terminal device requests to register to the first network; the first authentication function network element triggering the first authentication of the terminal device includes: the first authentication function network element triggers the first authentication according to the first authentication request message.

16. The method of claim 15, wherein, The first authentication request message carries an identity of the first network, and the first authentication function network element triggers the first authentication according to the first authentication request message, including: The first authentication function network element sends the identity of the first network to a data management network element serving the terminal device; The first authentication function network element receives first result information returned by the data management network element, and the first result information indicates whether the terminal device is allowed to be authenticated in the first network; In a case where the first result information indicates that the terminal device is allowed to be authenticated in the first network, the first authentication function network element triggers the first authentication; Or; The first authentication function network element obtains a network list from the data management network element, and the networks in the network list are networks to which the terminal device subscribes; The first authentication function network element determines whether the network list contains the first network according to the identity of the first network; In a case where the network list contains the first network, the first authentication function network element triggers the first authentication.

17. The method of claim 13 or 14, wherein, The method further includes: The first authentication function network element receives a second authentication request message from a second access management network element, the second access management network element is a network element in the second network, and the second authentication request message is used to request to authenticate the terminal device in a case where the terminal device requests to register to the second network; The first authentication function network element triggers second authentication of the terminal device, including: The first authentication function network element triggers the second authentication according to the second authentication request message.

18. The method of claim 17, wherein, The second authentication request message carries an identity of the second network, and the first authentication function network element triggers the second authentication according to the second authentication request message, including: The first authentication function network element sends the identity of the second network to a data management network element serving the terminal device; The first authentication function network element receives second result information returned by the data management network element, and the second result information indicates whether the terminal device is allowed to be authenticated in the second network; In a case where the second result information indicates that the terminal device is allowed to be authenticated in the second network, the first authentication function network element triggers the second authentication; Or; The first authentication function network element obtains a network list from the data management network element, and the networks in the network list are networks to which the terminal device subscribes; The first authentication function network element determines whether the network list contains the second network according to the identity of the second network; In a case where the network list contains the second network, the first authentication function network element triggers the second authentication.

19. A communications device, characterized by The communication device is configured to perform the method of any one of claims 1-18.

20. A communications device, characterized by Including: a processor and a memory; The memory is configured to store computer instructions, and when the processor executes the instructions, the communication device is configured to perform the method of any one of claims 1-18.

21. A communications device, characterized by Including: a processor and an interface circuit; wherein, The interface circuit is configured to receive code instructions and transmit the code instructions to the processor. The processor is configured to execute the code instructions to perform the method of any one of claims 1-18.

22. A communications device, characterized by The communication device includes a processor and a transceiver, the transceiver is configured to exchange information between the communication device and other communication devices, and the processor executes program instructions to perform the method of any one of claims 1-18.

23. The communication apparatus according to any one of claims 19-22, wherein, The communication device is a chip.

24. A communication system, characterized by The system includes the terminal device of any one of claims 1-12, and the first authentication function network element of any one of claims 13-18.

25. A computer readable storage medium, characterized in that, The computer readable storage medium includes a computer program or instructions, when the computer program or instructions are executed on a computer, the computer is caused to perform the method of any one of claims 1-18.

26. A computer program product, characterised in that, The computer program product includes: a computer program or instructions, when the computer program or instructions are executed on a computer, the computer is caused to perform the method of any one of claims 1-18.

Citation Information

Patent Citations

  • A secure communication method and apparatus

    CN109803350A

  • Communication method and related equipment

    CN113810989A

  • Information transmission method and device

    CN116033464A

  • Handling registration of user equipment in different communication networks

    CN116472730A

  • Communication method and communication device

    CN117812574A