Communication method, communication system, storage medium and program product

By introducing network function interaction between the core network and application functions, terminal authentication results can be obtained directly from the core network, solving the problem of low authentication efficiency in existing technologies and realizing a more efficient and secure authentication process.

WO2026156804A1PCT designated stage Publication Date: 2026-07-30BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2025-01-26
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

In existing technologies, application functions need to run the AKMA/GBA process during terminal authentication, resulting in low authentication efficiency and a lack of a mechanism for the core network to provide the authentication results of the subscribed user to the application functions.

Method used

The first network function receives a request message sent by the second network function, which contains the terminal identifier and information. This message is used by the application function to authenticate the terminal or obtain second information, omitting part of the authentication process between the AF and the terminal, and directly obtaining the authentication result from the core network.

Benefits of technology

It improves the communication efficiency of the authentication process, reduces redundant authentication steps between application functions and terminals, and enhances the security and efficiency of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025075175_30072026_PF_FP_ABST
    Figure CN2025075175_30072026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a communication method, a communication system, a storage medium and a program product. The communication method comprises: receiving a first request message sent by a second network function, wherein the first request message comprises first information and / or a first terminal identifier, and the first information is used by an application function (AF) to authenticate a terminal or is used by the AF to acquire second information. By means of the embodiments of the present disclosure, the communication efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods, communication systems, storage media and software products Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to communication methods, communication systems, storage media, and program products. Background Technology

[0002] In the mobile internet, application functions (e.g., application servers, application clients running on the UE) need to authenticate users or subscribed users before providing services. This authentication involves identifying the user or subscribed user using their Generic Public Subscription Identifier (GPSI) or Mobile Station International Subscriber Directory Number (MSISDN). The authentication process determines whether the identifier truly belongs to the user or is associated with the terminal device used by the user (e.g., the identifier is associated with the authenticated identifier of the terminal device). In communication systems, these application functions authenticate users or subscribed users via protocol-defined Authentication and Key Management for Applications (AKMA) or protocol-defined Generic Bootstrapping Architecture (GBA). To obtain an authentication result, each application client in the terminal needs to run an AKMA / GBA process, which must obtain a shared key and run a separate authentication process. Summary of the Invention

[0003] Improving the communication efficiency of the authentication process is a problem that needs to be solved.

[0004] This disclosure presents communication methods, communication systems, storage media, and program products.

[0005] According to a first aspect of the present disclosure, a communication method is proposed, executed by a first network function, the method comprising: receiving a first request message sent by a second network function, the first request message including first information and / or a first terminal identifier.

[0006] According to a second aspect of the present disclosure, a communication method is proposed, executed by a second network function, the method comprising: sending a first request message to a first network function, the first request message including first information and / or a first terminal identifier, the first information being used by an application function (AF) to authenticate a terminal or by the AF to obtain second information.

[0007] According to a third aspect of the present disclosure, a communication method is proposed, executed by an application function (AF), the method comprising: sending a third request message to a second network function, the third request message including first information and / or a first terminal identifier, wherein the first information is used by the application function (AF) to authenticate the terminal or by the AF to obtain the second information.

[0008] According to a fourth aspect of the present disclosure, a communication method is provided, executed by a third network function, the method comprising: sending a second request message to a first network function, the second request message including third information and / or a third terminal identifier, the third information and the third terminal identifier being used to establish an association relationship, the association relationship being used to determine the second information.

[0009] According to a fifth aspect of the present disclosure, a communication method is proposed, executed by a fourth network function, the method comprising: receiving third information and / or a third terminal identifier sent by a third network function, wherein the third information and the third terminal identifier are used to establish an association relationship, and the association relationship is used to determine second information.

[0010] According to a sixth aspect of the present disclosure, a communication method is proposed, executed by a terminal, the method comprising: sending first information and / or a first terminal identifier to an application function AF; wherein the first information is used by the application function AF to authenticate the terminal or by the AF to obtain second information.

[0011] According to a seventh aspect of the present disclosure, a communication device is provided for performing the communication method of any of the above aspects.

[0012] According to an eighth aspect of the present disclosure, a communication system is proposed, including a first network function, a second network function, an application function, a third network function, a fourth network function, and a terminal, wherein the first network element is configured to implement the communication method of the first aspect, the second network function is configured to implement the communication method of the second aspect, the application function is configured to implement the communication method of the third aspect, the third network function is configured to implement the communication method of the fourth aspect, the fourth network function is configured to implement the communication method of the fifth aspect, and the terminal is configured to implement the terminal's communication method.

[0013] According to a ninth aspect of the present disclosure, a storage medium is provided that stores instructions which, when executed on a communication device, cause the communication device to perform the communication method of any of the above aspects.

[0014] According to a tenth aspect of the present disclosure, a program product is provided, including at least one of a program and instructions, wherein when the program or instructions are executed by a communication device, the communication method of any of the above aspects is implemented.

[0015] In this embodiment of the disclosure, a first network function receives a first request message sent by a second network function. The first request message includes first information and / or a first terminal identifier. The first information is used by the application function to authenticate the terminal or by the AF to obtain the second information. This method enables the AF to obtain the first information from the network function, thereby providing services to the terminal based on the first information, omitting the authentication process between the AF and the terminal, thus improving communication efficiency while ensuring security. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.

[0017] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0018] Figure 2 is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure.

[0019] Figure 3 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.

[0020] Figure 4 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.

[0021] Figure 5 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.

[0022] Figure 6 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.

[0023] Figure 7 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.

[0024] Figure 8 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.

[0025] Figure 9A is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure.

[0026] Figure 9B is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure.

[0027] Figure 10A is a schematic diagram of the structure of the first network function proposed in an embodiment of this disclosure.

[0028] Figure 10B is a schematic diagram of the structure of the second network function proposed in an embodiment of this disclosure.

[0029] Figure 10C is a schematic diagram of the application function proposed in the embodiments of this disclosure.

[0030] Figure 10D is a schematic diagram of the structure of the third network function proposed in an embodiment of this disclosure.

[0031] Figure 10E is a schematic diagram of the structure of the fourth network function proposed in an embodiment of this disclosure.

[0032] Figure 10F is a schematic diagram of the structure of the terminal proposed in the embodiments of this disclosure.

[0033] Figure 11A is a schematic diagram of the structure of the communication device proposed in an embodiment of this disclosure.

[0034] Figure 11B is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. Detailed Implementation

[0035] This disclosure presents communication methods, communication systems, storage media, and program products.

[0036] In a first aspect, embodiments of this disclosure propose a communication method executed by a first network function. The method includes: receiving a first request message sent by a second network function, wherein the first request message includes first information and / or a first terminal identifier, wherein the first information is used by an application function (AF) to authenticate the terminal or by the AF to obtain the second information.

[0037] In this embodiment of the disclosure, a first network function receives a first request message sent by a second network function. The first request message includes first information and / or a first terminal identifier. The first information is used by the application function to authenticate the terminal or by the AF to obtain the second information. This method enables the AF to obtain the first information from the network function, thereby providing services to the terminal based on the first information, omitting the authentication process between the AF and the terminal, thus improving communication efficiency while ensuring security.

[0038] In conjunction with some embodiments of the first aspect, in some embodiments, the second information is used to indicate at least one of the following: the first terminal identifier is an identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with a terminal identifier that has been authenticated by the network; the first terminal identifier is not an identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; the first terminal identifier has no mapping relationship with a terminal identifier that has been authenticated by the network.

[0039] In conjunction with some embodiments of the first aspect, in some embodiments, the first request message includes the first information and the first terminal identifier; the method further includes: determining second information based on the first information and the first terminal identifier; and sending a first response message to the second network function, the first response message including the second information.

[0040] In some embodiments of the first aspect, determining the second information based on the first information and the first terminal identifier includes: retrieving associated information based on the first information or the first terminal identifier, the associated information including third information and the second terminal identifier; determining the second information when a first condition is met; the second information indicating at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with a network-authenticated terminal identifier; determining the second information when a second condition is met; the second information indicating at least one of the following: the first terminal identifier is not the identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; the first terminal identifier has no mapping relationship with a network-authenticated terminal identifier; wherein the first condition includes: the first terminal identifier and the second terminal identifier are consistent, and the first information and the third information are consistent; wherein the second condition includes at least one of the following: the third information is inconsistent with the first information; the second terminal identifier is inconsistent with the first terminal identifier; no associated information was retrieved.

[0041] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: deleting the third information or the associated information when the first condition is met.

[0042] In conjunction with some embodiments of the first aspect, in some embodiments, the first request message includes the first information; the method further includes: retrieving a second terminal identifier associated with the first information based on the first information; and sending the second terminal identifier to the second network function, the second terminal identifier being used to determine the second information.

[0043] In conjunction with some embodiments of the first aspect, in some embodiments, the first request message includes the first terminal identifier; the method further includes: retrieving third information associated with the first terminal identifier based on the first terminal identifier; and sending the third information to the second network function, wherein the third information is used to determine the second information.

[0044] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes: receiving a second request message sent by a third network function, the second request message including third information and a third terminal identifier; establishing an association relationship between at least two of the third information, the third terminal identifier, and the second terminal identifier, wherein the second terminal identifier and the third terminal identifier are different types of the same terminal identifier; and sending a second response message to the third network function, the second response message corresponding to the second request message.

[0045] Secondly, this disclosure provides a communication method executed by a second network function. The method includes sending a first request message to a first network function, the first request message including first information and / or a first terminal identifier, the first information being used by the application function (AF) to authenticate the terminal or by the AF to obtain second information.

[0046] In conjunction with some embodiments of the second aspect, in some embodiments, the second information is used to indicate at least one of the following: the first terminal identifier is an identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with a terminal identifier that has been authenticated by the network; the first terminal identifier is not an identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; the first terminal identifier has no mapping relationship with a terminal identifier that has been authenticated by the network.

[0047] In conjunction with some embodiments of the second aspect, in some embodiments, the first request message includes the first information and the first terminal identifier; the method further includes: receiving a first response message sent by the first network function, the first response message including the second information, the second information being determined based on the first information and the first terminal identifier.

[0048] In conjunction with some embodiments of the second aspect, in some embodiments, when the first condition is met, the second information is used to indicate at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; there is a mapping relationship between the first terminal identifier and the network-authenticated terminal identifier; when the second condition is met, the second information is used to indicate at least one of the following: the first terminal identifier is not the identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; there is no mapping relationship between the first terminal identifier and the network-authenticated terminal identifier; wherein, the first condition includes: the first terminal identifier and the second terminal identifier are consistent, and / or, the first information and the third information are consistent; wherein, the second condition includes at least one of the following: the third information is inconsistent with the first information; the second terminal identifier is inconsistent with the first terminal identifier; no associated information was retrieved; wherein, the second terminal identifier and the third information are retrieved based on the first information or the first terminal identifier.

[0049] In conjunction with some embodiments of the second aspect, in some embodiments, the first request message includes the first information; the method further includes: receiving a second terminal identifier sent by the first network function, the second terminal identifier being associated with the first information; and determining the second information based on the second terminal identifier.

[0050] In conjunction with some embodiments of the second aspect, in some embodiments, the first request message includes the first terminal identifier; the method further includes: receiving third information sent by the first network function, the third information being associated with the first terminal identifier; and determining the second information based on the third information.

[0051] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: receiving a third request message sent by the AF, the third request message including first information and / or a first terminal identifier, the third request message being used to obtain the second information.

[0052] In some embodiments, in conjunction with the second aspect, the method further includes sending a third response message to the AF, the third response message including the second information.

[0053] Thirdly, this disclosure provides a communication method executed by an application function (AF). The method includes sending a third request message to a second network function, the third request message including first information and / or a first terminal identifier, wherein the first information is used by the application function AF to authenticate the terminal or by the AF to obtain the second information.

[0054] In conjunction with some embodiments of the third aspect, in some embodiments, the second information is used to indicate at least one of the following: the first terminal identifier is an identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with a terminal identifier that has been authenticated by the network; the first terminal identifier is not an identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; the first terminal identifier has no mapping relationship with a terminal identifier that has been authenticated by the network.

[0055] In some embodiments, in conjunction with the third aspect, the method further includes: receiving a third response message sent by the second network function, the third response message including the second information.

[0056] In some embodiments, in conjunction with the third aspect, the method further includes: receiving the first information and / or the first terminal identifier sent by the terminal; and determining the second network function based on the first terminal identifier.

[0057] In some embodiments, in conjunction with the third aspect, the method further includes: determining whether to provide services to the terminal based on the second information.

[0058] Fourthly, embodiments of this disclosure propose a communication method executed by a third network function, the method comprising: sending a second request message to a first network function, the second request message including third information and / or a third terminal identifier, the third information and the third terminal identifier being used to establish an association relationship, the association relationship being used to determine the second information.

[0059] In conjunction with some embodiments of the fourth aspect, in some embodiments, the second information is used to indicate at least one of the following: the first terminal identifier is an identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with a terminal identifier that has been authenticated by the network; the first terminal identifier is not an identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; the first terminal identifier has no mapping relationship with a terminal identifier that has been authenticated by the network.

[0060] In some embodiments, in conjunction with the fourth aspect, the method further includes: receiving a second response message sent by the first network function, the second response message corresponding to the second request message, the second response message including the third information and the third terminal identifier.

[0061] In some embodiments, in conjunction with the fourth aspect, the method further includes: sending the third information and / or the third terminal identifier to the fourth network function.

[0062] Fifthly, embodiments of this disclosure propose a communication method executed by a fourth network function, the method comprising: receiving third information and / or a third terminal identifier sent by a third network function, wherein the third information and the third terminal identifier are used to establish an association relationship, and the association relationship is used to determine second information.

[0063] In conjunction with some embodiments of the fifth aspect, in some embodiments, the second information is used to indicate at least one of the following: the first terminal identifier is an identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with a terminal identifier that has been authenticated by the network; the first terminal identifier is not an identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; the first terminal identifier has no mapping relationship with a terminal identifier that has been authenticated by the network.

[0064] In some embodiments, in conjunction with the fifth aspect, the method further includes sending the third information and the third terminal identifier to the terminal.

[0065] In a sixth aspect, embodiments of this disclosure propose a communication method executed by a terminal, the method comprising: sending first information and / or a first terminal identifier to an application function AF; the first information being used by the application function AF to authenticate the terminal or by the AF to obtain second information.

[0066] In conjunction with some embodiments of the sixth aspect, in some embodiments, the second information is used to indicate at least one of the following: the first terminal identifier is an identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with a terminal identifier that has been authenticated by the network; the first terminal identifier is not an identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network.

[0067] In some embodiments of the sixth aspect, the method further includes: receiving third information and the third terminal identifier sent by the fourth network function, wherein the third information and the third terminal identifier are used to establish an association relationship, and the association relationship is used to determine the second information.

[0068] In a seventh aspect, embodiments of this disclosure provide a communication device for performing the communication method of any of the above aspects.

[0069] Eighthly, embodiments of this disclosure propose a communication system including a first network function, a second network function, an application function, a third network function, a fourth network function, and a terminal, wherein the first network element is configured to implement the communication method of the first aspect, the second network function is configured to implement the communication method of the second aspect, the application function is configured to implement the communication method of the third aspect, the third network function is configured to implement the communication method of the fourth aspect, the fourth network function is configured to implement the communication method of the fifth aspect, and the terminal is configured to implement the terminal's communication method.

[0070] Ninthly, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform any of the communication methods described above.

[0071] In a tenth aspect, embodiments of this disclosure provide a program product, including at least one of a program and instructions, wherein when the program or instructions are executed by a communication device, the communication method of any of the above aspects is implemented.

[0072] In one aspect, embodiments of this disclosure provide a computer program that, when executed by a communication device, causes the communication device to perform any of the communication methods described above.

[0073] In a twelfth aspect, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described in the alternative implementations of any of the foregoing aspects.

[0074] It is understood that the aforementioned network functions, application functions, terminals, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0075] This disclosure provides communication methods, terminals, network devices, communication systems, and storage media. In some embodiments, the terms "communication method" and "information sending method," "information receiving method," etc., can be used interchangeably.

[0076] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0077] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0078] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0079] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.

[0080] In the embodiments disclosed herein, "multiple" refers to two or more.

[0081] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0082] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.

[0083] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.

[0084] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0085] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0086] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.

[0087] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0088] In some embodiments, devices, etc., can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as “device”, “equipment”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, and “subject” can be used interchangeably.

[0089] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).

[0090] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.

[0091] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.

[0092] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.

[0093] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.

[0094] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0095] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0096] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0097] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0098] As shown in Figure 1, the communication system 100 includes a first network function 101, a second network function 102, a third network function 103, a fourth network function 104, an application function 105, and a terminal 106.

[0099] In some embodiments, terminal 106 may be user equipment (UE), and terminals include, but are not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.

[0100] In some embodiments, the core network device may be a single device including a first network function 101, a second network function 102, a third network function 103, a fourth network function 104, etc., or it may be multiple devices or a group of devices, each including all or part of the first network function 101, the second network function 102, the third network function 103, the fourth network function 104, etc. Network functions (also referred to as network elements) may be virtual or physical. The core network may include, for example, at least one of the Evolved Packet Core (EPC), 5G Core Network (5GCN), and Next Generation Core (NGC).

[0101] In some embodiments, the first network function 101 is, for example, a unified data management network function (UDM).

[0102] In some embodiments, the first network function 101 is, for example, a network function for managing user subscription data.

[0103] In some embodiments, the second network function 102 is, for example, the network exposure function (NEF).

[0104] In some embodiments, the third network function 103 is, for example, an authentication server function (AUSF).

[0105] In some embodiments, the third network function 103 is, for example, a network function for authenticating the UE.

[0106] In some embodiments, the fourth network function 104 is, for example, an Access and Mobility Management Function (AMF) or a Security Anchor Function (SEAF).

[0107] In some embodiments, the fourth network function 104 is, for example, a network function for access and mobility management.

[0108] In some embodiments, application function 105 may be, for example, an application server or an application client running on a terminal.

[0109] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.

[0110] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. ​​The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.

[0111] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).

[0112] In the mobile internet, application functions (e.g., application servers, application clients running on the UE) need to authenticate users or subscribed users before providing services. This authentication involves identifying the user or subscribed user using their Generic Public Subscription Identifier (GPSI) or Mobile Station International Subscriber Directory Number (MSISDN). The authentication process determines whether the identifier truly belongs to the user or is associated with the terminal device used by the user (e.g., the identifier is associated with the authenticated identifier of the terminal device). In communication systems, these application functions authenticate users or subscribed users via protocol-defined Authentication and Key Management for Applications (AKMA) or protocol-defined Generic Bootstrapping Architecture (GBA). To obtain an authentication result, each application client in the terminal needs to run an AKMA / GBA process, which must obtain a shared key and run a separate authentication process.

[0113] In communication systems, in order to obtain services from a 3GPP network, a subscribed user needs to be authenticated by the core network through the UE. If the application function (AF) can directly obtain the subscribed user's authentication result from the core network, there is no need to run an authentication process like AKMA or GBA at the application layer, thus improving authentication efficiency.

[0114] However, there is currently no existing mechanism that enables the core network to provide signed user authentication results to application functions.

[0115] Figure 2 is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 2, the embodiments of the present disclosure relate to a communication method, which includes:

[0116] Step S2101: The terminal is successfully authenticated.

[0117] In some embodiments, the terminal is successfully authenticated by the core network.

[0118] In some embodiments, the fourth network function and / or the third network function authenticate the terminal.

[0119] In some embodiments, network function (NF) may also be replaced by network element or entity; this disclosure does not limit the name.

[0120] In some embodiments, the first network function is, for example, a unified data management network element (UDM).

[0121] In some embodiments, the second network function is, for example, the network exposure function (NEF).

[0122] In some embodiments, the third network function is, for example, the Authentication Server Function (AUSF).

[0123] In some embodiments, the fourth network function is, for example, the Access and Mobility Management Function (AMF) or the Security Anchor Function (SEAF).

[0124] In step S2102, the third network function sends a second request message to the first network function.

[0125] In some embodiments, the first network function receives a second request message sent by the third network function.

[0126] In some embodiments, the second request message may be, for example, an authentication result confirmation request.

[0127] In some embodiments, the second request message is sent after the third network function has successfully authenticated the terminal, and the second request message is used to notify the first network function of the authentication result and authentication time of the terminal.

[0128] In some embodiments, the second request message includes third information and / or a third terminal identifier.

[0129] In some embodiments, after the third network function authenticates the terminal, the third network function may generate one or more third pieces of information, which may be a random number, cookie, token, code, etc. In the following description, a random number is used as an example of the third information, but this disclosure does not limit the form of the third information.

[0130] In some embodiments, third information is also referred to as retrieving information.

[0131] In some embodiments, the third information is used to determine the second information, and the description of the second information is given in the following steps.

[0132] In some embodiments, the third information and the third terminal identifier are used to establish an association relationship, and the description of the association relationship is given in the following steps.

[0133] In some embodiments, the third terminal identifier is the identifier of an authenticated terminal. The third terminal identifier may, for example, be the terminal's Subscription Permanent Identifier (SUPI).

[0134] In some embodiments, the second request message may also include an authentication timestamp, authentication type, and service network name, etc.

[0135] Step S2103: The first network function establishes a connection.

[0136] In some embodiments, the first network function establishes an association between at least two of the third information, the third terminal identifier, and the second terminal identifier. For example, the first network function establishes an association between the third information and the third terminal identifier. Another example is that the first network function establishes an association between the third terminal identifier and the second terminal identifier. Yet another example is that the first network function establishes an association between the second terminal identifier and the third terminal identifier.

[0137] In some embodiments, the second terminal identifier and the third terminal identifier are different types of identifiers for the same terminal.

[0138] In some embodiments, the second terminal identifier and the third terminal identifier are identifiers of the same terminal. The second terminal identifier may be, for example, a Generic Public Subscription Identifier (GPSI), that is, the second terminal identifier may be the GPSI of the terminal and the third terminal identifier may be the SUPI of the terminal.

[0139] In some embodiments, the association relationship may also be referred to as a mapping relationship.

[0140] In some embodiments, the first network function stores the association after establishing the association.

[0141] In step S2104, the first network function sends a second response message to the third network function.

[0142] In some embodiments, the third network function receives a second response message sent by the first network function.

[0143] In some embodiments, the second response message corresponds to the second request message.

[0144] In some embodiments, the second response message may be, for example, an authentication result confirmation response.

[0145] In some embodiments, the first network function sends third information and / or a third terminal identifier to the third network function.

[0146] In step S2105, the third network function sends third information and / or the third terminal identifier to the fourth network function.

[0147] In some embodiments, the fourth network function receives third information and / or a third terminal identifier sent by the third network function.

[0148] In some embodiments, the third information and / or third terminal identifier sent by the third network function to the fourth network function may be carried in a delivery request. This delivery request is used to deliver the third information and may also be referred to as a retrieval information delivery request or a fourth request.

[0149] In some embodiments, the third network function sends a third terminal identifier and one or more third pieces of information corresponding to the third terminal identifier to the fourth network function.

[0150] Step S2106: The fourth network function sends third information and / or third terminal identifier to the terminal.

[0151] In some embodiments, the terminal receives third information and / or a third terminal identifier sent by a fourth network function.

[0152] In some embodiments, the third information and / or third terminal identifier sent by the fourth network function to the terminal may be carried in a transmission request. This transmission request is used to transmit the third information and may also be referred to as a retrieval information transmission request or a fifth request.

[0153] In some embodiments, the fourth network function sends a third terminal identifier and one or more third pieces of information corresponding to the third terminal identifier to the terminal.

[0154] In some embodiments, after receiving third information and / or a third terminal identifier, the terminal stores the third information and / or the third terminal identifier in the terminal for subsequent use.

[0155] In some embodiments, if the terminal stores third information, after receiving the third information, the terminal will replace the originally stored third information with the received third information.

[0156] In some embodiments, the terminal sends a confirmation message to the fourth network function.

[0157] In some embodiments, the fourth network function sends a delivery confirmation to the third network function.

[0158] Step S2107: The application function sends an authentication request to the terminal.

[0159] In some embodiments, the terminal receives an authentication request sent by an application function.

[0160] In some embodiments, an authentication request may also be referred to as an authentication request message.

[0161] In some embodiments, an application function (AF) may be an application server or an application client running on a terminal.

[0162] In some embodiments, before the application function sends an authentication request to the terminal, a Transport Layer Security (TLS) tunnel is established between the terminal and the application function. The terminal authenticates the application function using the application function's public key certificate. The terminal verifies whether the certificate corresponds to the fully qualified domain name (FQDN) of the application function with which it established the tunnel. During this process, the terminal is not authenticated.

[0163] In some embodiments, the authentication request is used by the application function to authenticate the terminal, and the authentication request may also be referred to as the fifth request.

[0164] In some embodiments, step S2107 can be omitted, meaning the application function does not need to send an authentication request to the terminal.

[0165] Step S2108: The terminal sends first information and / or first terminal identifier to the application function.

[0166] In some embodiments, the application function receives first information and / or a first terminal identifier sent by the terminal.

[0167] In some embodiments, the terminal may proactively send first information and / or a first terminal identifier to the application function.

[0168] In some embodiments, the terminal may send an authentication response to the application function in response to an authentication request sent by the application function, the authentication response including first information and / or a first terminal identifier.

[0169] In some embodiments, the first information may be referred to as retrieval information, and the first information may be one of the third information.

[0170] Taking the first and third information as random numbers as an example, the fourth network function sends one or more random numbers to the terminal, and the terminal sends one of the random numbers to the application function for authentication between the terminal and the application function.

[0171] In some embodiments, if the first information is used for authentication between the terminal and the application function, the terminal will delete the first information.

[0172] In some embodiments, if the first information has already been sent to the application function by the terminal, the terminal will delete the first information.

[0173] In some embodiments, the first terminal identifier may be, for example, the terminal's GPSI.

[0174] In some embodiments, the terminal sends home network information to the application function, for example, the terminal indicates its home network identifier to the application function.

[0175] Step S2109: The application function determines the second network function based on the first terminal identifier or the home network information.

[0176] In some embodiments, the application function determines the home network information of the terminal based on a first terminal identifier (e.g., GPSI), and determines a second network function based on the home network information.

[0177] In some embodiments, the application function determines a second network function based on home network information.

[0178] In step S2110, the application function sends a third request message to the second network function.

[0179] In some embodiments, the second network function receives a third request message sent by the application function.

[0180] In some embodiments, the third request message is used to obtain second information.

[0181] In some embodiments, the third request message may also be referred to as a retrieval request.

[0182] In some embodiments, the third request message includes first information and / or a first terminal identifier.

[0183] Step S2111: The second network function sends a first request message to the first network function.

[0184] In some embodiments, the first network function receives a first request message sent by the second network function.

[0185] In some embodiments, the first request message includes first information and / or a first terminal identifier. That is, the first request message may include first information, or the first request message may include a first terminal identifier, or the first request message may include both first information and a first terminal identifier.

[0186] In some embodiments, the first information is used by the AF to authenticate the terminal, or the first information is used by the AF to obtain the second information.

[0187] In some embodiments, the second information indicating the result of the first information feedback may include a pass or a fail, or similar expressions, all of which are applicable to this application.

[0188] In some embodiments, the second information is used to indicate at least one of the following:

[0189] The first terminal identifier is the identifier of the terminal;

[0190] The first terminal identifier is one that has already been authenticated by the network;

[0191] There is a mapping relationship between the first terminal identifier and the terminal identifiers that have been authenticated by the network;

[0192] The first terminal identifier is not the terminal's identifier;

[0193] The first terminal identifier is not an identifier that has been authenticated by the network;

[0194] There is no mapping relationship between the first terminal identifier and the terminal identifiers that have been authenticated by the network.

[0195] The following explanation addresses the case where the first request message includes first information and a first terminal identifier, whereby the second network function sends the first information and the first terminal identifier to the first network function, and the first network function determines the second information based on the first information and the first terminal identifier.

[0196] In some embodiments, the first network function determines the second information based on the first information and the first terminal identifier.

[0197] In some embodiments, determining the second information based on the first information and the first terminal identifier includes: retrieving associated information based on the first information or the first terminal identifier, wherein the associated information includes the third information and the second terminal identifier.

[0198] In some embodiments, if a first condition is met, second information is determined, the second information indicating at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with the terminal identifier that has been authenticated by the network; wherein the first condition includes: the first terminal identifier and the second terminal identifier are the same, and / or, the first information and the third information are the same.

[0199] In some embodiments, the first network function stores the association between third information and a second terminal identifier, wherein the second terminal identifier is authenticated.

[0200] In some embodiments, the first network function stores the association between third information and the second terminal identifier, wherein the second terminal identifier is a terminal identifier that has been authenticated by the core network.

[0201] In one example, a first network function receives a first message and a first terminal identifier. Based on the first message, it can retrieve an associated message that includes a third message and a second terminal identifier. At this time, the third message included in the associated message is consistent with the first message included in the first request message. The first network function determines whether the second terminal identifier included in the associated message is consistent with the first terminal identifier included in the first request message. If the second terminal identifier is consistent with the first terminal identifier, the authentication result is determined to be positive, that is, the second message indicates at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; or there is a mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

[0202] For example, the first request message includes a random number 1 and GPSI1. The first network function performs a search based on the random number 1 and retrieves a piece of associated information that includes the random number 1 and GPSI1. If the GPSI1 included in the associated information is consistent with the GPSI1 in the first request message, then the authentication result is determined to be positive.

[0203] In another example, the first network function receives the first information and the first terminal identifier. Based on the first terminal identifier, it can retrieve an associated information that includes the third information and the second terminal identifier. At this time, the second terminal identifier included in the associated information is consistent with the first terminal identifier included in the first request message. The first network function determines whether the third information included in the associated information is consistent with the first information included in the first request message. If the third information is consistent with the first information, the authentication result is determined to be positive, that is, the second information indicates at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; or there is a mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

[0204] For example, the first request message includes random number 1 and GPSI1. The first network function performs a search based on GPSI1 and retrieves a piece of related information that includes random number 1 and GPSI1. If the random number 1 included in the related information is consistent with the random number 1 in the first request message, then the authentication result is determined to be positive.

[0205] In some embodiments, when a second condition is met, second information is determined, which indicates at least one of the following: the first terminal identifier is not an identifier of a terminal; the first terminal identifier is not an identifier that has been authenticated by the network; there is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network; wherein the second condition includes at least one of the following: the third information is inconsistent with the first information; the second terminal identifier is inconsistent with the first terminal identifier; no associated information was found.

[0206] In one example, the first network function receives first information and a first terminal identifier. Based on the first information, it can retrieve associated information including third information and a second terminal identifier. At this time, the third information included in the associated information is consistent with the first information included in the first request message. The first network function determines whether the second terminal identifier included in the associated information is consistent with the first terminal identifier included in the first request message. If the second terminal identifier and the first terminal identifier are inconsistent, the authentication result is determined to be negative, that is, the second information indicates at least one of the following: the first terminal identifier is not the identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; or there is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

[0207] For example, the first request message includes random number 1 and GPSI1. The first network function performs a search based on random number 1 and retrieves a piece of associated information including random number 1 and GPSI2. If the GPSI2 included in the associated information is inconsistent with the GPSI1 in the first request message, then the authentication result is determined to be negative.

[0208] In another example, the first network function receives the first information and the first terminal identifier. Based on the first terminal identifier, it can retrieve an associated information that includes the third information and the second terminal identifier. At this time, the second terminal identifier included in the associated information is consistent with the first terminal identifier included in the first request message. The first network function determines whether the third information included in the associated information is consistent with the first information included in the first request message. If the third information and the first information are inconsistent, the authentication result is determined to be negative, that is, the second information indicates at least one of the following: the first terminal identifier is not the identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; or there is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

[0209] For example, the first request message includes random number 1 and GPSI1. The first network function performs a search based on GPSI1 and retrieves a piece of associated information including random number 2 and GPSI1. If the random number 2 included in the associated information is inconsistent with the random number 1 in the first request message, then the authentication result is determined to be negative.

[0210] In another example, the first network function receives the first information and the first terminal identifier. If no associated information is found based on the first information, or if no associated information is found based on the first terminal identifier, the authentication result is determined to be negative. That is, the second information indicates at least one of the following: the first terminal identifier is not the identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; or there is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

[0211] For example, if the first request message includes a random number 1 and GPSI1, and the first network function performs a search based on the random number 1 and does not find any related information containing the random number 1, or if the first network function performs a search based on the GPSI1 and does not find any related information containing the GPSI1, then the authentication result is determined to be negative.

[0212] In some embodiments, if a first condition is met, the first network function deletes the third information or associated information.

[0213] In some embodiments, if the first condition is met and it is determined that the third information is being used, then the third information is deleted, or the associated information containing the third information is deleted. Deleting the associated information containing the third information means deleting this associated information, and the third information and the second terminal identifier included in this associated information are also deleted.

[0214] The following description addresses the case where the first request message includes first information, namely, the second network function sends the first information to the first network function, the first network function retrieves the second terminal identifier based on the first information, the first network function sends the second terminal identifier to the second network function, and the second network function determines the second information based on the second terminal identifier.

[0215] In some embodiments, the first request message includes first information; the first network function retrieves a second terminal identifier associated with the first information based on the first information; the first network function sends the second terminal identifier to the second network function, the second terminal identifier being used to determine the second information.

[0216] In one example, a first network function receives a first message and retrieves associated information including the first message and a second terminal identifier based on the first message. The first network function sends the second terminal identifier to a second network function, which then determines whether the second terminal identifier and the first terminal identifier are consistent. If the second terminal identifier and the first terminal identifier are consistent, the authentication result is determined to be positive, meaning the second message indicates at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier has been authenticated by the network; or there is a mapping relationship between the first terminal identifier and a terminal identifier that has been authenticated by the network. If the second terminal identifier and the first terminal identifier are inconsistent, the authentication result is determined to be negative, meaning the second message indicates at least one of the following: the first terminal identifier is not the identifier of the terminal; the first terminal identifier has not been authenticated by the network; or there is no mapping relationship between the first terminal identifier and a terminal identifier that has been authenticated by the network.

[0217] For example, the first request message includes a random number 1. The first network function performs a search based on the random number 1 and obtains a piece of associated information including the random number 1 and GPSI1. The first network function sends the GPSI1 to the second network function. The second network function determines that the GPSI1 sent by the first network function is consistent with the GPSI1 sent by the application function, and then determines that the authentication result is positive.

[0218] For example, the first request message includes a random number 1. The first network function performs a search based on the random number 1 and obtains a piece of associated information including the random number 1 and GPSI2. The first network function sends GPSI2 to the second network function. The second network function determines that the GPSI2 sent by the first network function is inconsistent with the GPSI1 sent by the application function, and thus determines that the authentication result is negative.

[0219] The following explanation addresses the case where the first request message includes first information and a first terminal identifier, whereby the second network function sends the first information and the first terminal identifier to the first network function, and the first network function determines the second information based on the first information and the first terminal identifier.

[0220] In some embodiments, the first request message includes a first terminal identifier; the first network function retrieves third information associated with the first terminal identifier based on the first terminal identifier; the first network function sends the third information to a second network function, the third information being used to determine the second information.

[0221] In one example, a first network function receives a first terminal identifier and retrieves associated information including the first terminal identifier and third information based on the first terminal identifier. The first network function sends the third information to a second network function, which determines whether the third information and the first information are consistent. If the third information and the first information are consistent, the authentication result is determined to be positive, that is, the second information indicates at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier has been authenticated by the network; or there is a mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network. If the third information and the first information are inconsistent, the authentication result is determined to be negative, that is, the second information indicates at least one of the following: the first terminal identifier is not the identifier of the terminal; the first terminal identifier has not been authenticated by the network; or there is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

[0222] For example, the first request message includes GPSI1. The first network function performs a search based on GPSI1 and obtains a piece of associated information including random number 1 and GPSI1. The first network function sends random number 1 to the second network function. The second network function determines that the random number 1 sent by the first network function is consistent with the random number 1 sent by the application function, and then determines that the authentication result is positive.

[0223] For example, the first request message includes GPSI1. The first network function performs a search based on GPSI1 and obtains a piece of associated information including random number 2 and GPSI1. The first network function sends random number 2 to the second network function. The second network function determines that the random number 2 sent by the first network function is inconsistent with the random number 1 sent by the application function, and thus determines that the authentication result is negative.

[0224] In step S2112, the first network function sends a first response message to the second network function.

[0225] In some embodiments, the second network function receives a first response message sent by the first network function.

[0226] In some embodiments, the first response message corresponds to the first request message.

[0227] In some embodiments, the first response message may also be referred to as a retrieval response.

[0228] In some embodiments, the first request message includes first information and a first terminal identifier, and the first response message includes second information.

[0229] In some embodiments, the first request message includes first information, and the first response message includes a second terminal identifier.

[0230] In some embodiments, the first request message includes a first terminal identifier, and the first response message includes third information.

[0231] In step S2113, the second network function sends a third response message to the application function.

[0232] In some embodiments, the application function receives a third response message sent by the second network function.

[0233] In some embodiments, the third response message includes second information.

[0234] In some embodiments, the third response message corresponds to the third request message.

[0235] In some embodiments, the third response message may also be referred to as a retrieval response.

[0236] In step S2114, the application function determines whether to provide services to the terminal based on the second information.

[0237] In some embodiments, the second information indicates at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; there is a mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network; and the application function is determined to provide services to the terminal.

[0238] In some embodiments, the second information indicates at least one of the following: the first terminal identifier is not an identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; there is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network; the application function determines that it will not provide services to the terminal.

[0239] In this embodiment of the disclosure, a first network function receives a first request message sent by a second network function. The first request message includes first information and / or a first terminal identifier. The first information is used by the application function to authenticate the terminal or by the application function to obtain second information. This method enables the application function to obtain the first information from the network function, thereby providing services to the terminal based on the first information. This omits the authentication process between the application function and the terminal (e.g., omitting the process of the application function triggering the network to send a verification code to the terminal, and the terminal logging in based on the verification code), thereby improving communication efficiency while ensuring security.

[0240] The communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2114. For example, step S2111 may be implemented as a standalone embodiment, step S2110 may be implemented as a standalone embodiment, step S2102 may be implemented as a standalone embodiment, step S2105 may be implemented as a standalone embodiment, and step S2108 may be implemented as a standalone embodiment, but is not limited thereto.

[0241] In some embodiments, step S2101 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0242] In some embodiments, step S2102 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0243] In some embodiments, step S2104 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0244] In some embodiments, step S2105 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0245] In some embodiments, step S2106 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0246] In some embodiments, step S2107 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0247] In some embodiments, step S2109 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0248] In some embodiments, step S2112 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0249] In some embodiments, step S2113 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0250] In some embodiments, other optional implementations described before or after the specification corresponding to FIG2 may be referred to.

[0251] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0252] In some embodiments, terms such as “moment,” “point in time,” “time,” and “time location” can be used interchangeably, as can terms such as “duration,” “segment,” “time window,” “window,” and “time.”

[0253] In some embodiments, “get,” “obtain,” “receive,” “transmit,” “bidirectional transmission,” and “send and / or receive” can be used interchangeably and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining through self-processing, or autonomous implementation, among other meanings.

[0254] In some embodiments, terms such as “send,” “transmit,” “report,” “distribute,” “transfer,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.

[0255] In some embodiments, terms such as "certain," "preset," "default," "set," "indicated," "a certain," "any," and "first" can be used interchangeably. "Certain A," "preset A," "default A," "set A," "indicated A," "a certain A," "any A," and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.

[0256] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value (bool)) represented by true or false, or by a numerical comparison (e.g., a comparison with a predetermined value), but is not limited thereto.

[0257] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the receiver to respond to the sent content.

[0258] Figure 3 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3, the embodiment of the present disclosure relates to a communication method executed by a first network function, the method comprising:

[0259] Step S3101: Receive the first request message sent by the second network function.

[0260] The optional implementation of step S3101 can be found in the optional implementation of step S2111 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0261] Step S3102: Send a first response message to the second network function.

[0262] The optional implementation of step S3102 can be found in the optional implementation of step S2112 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0263] The communication method involved in the embodiments of this disclosure may include at least one of steps S3101 to S3102. For example, step S3101 may be implemented as a standalone embodiment, but is not limited thereto.

[0264] In some embodiments, step S3102 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0265] Figure 4 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4, the present disclosure relates to a communication method executed by a second network function, the method comprising:

[0266] Step S4101: Send a first request message to the first network function.

[0267] The optional implementation of step S4101 can be found in the optional implementation of step S2111 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0268] Step S4102: Receive the first response message sent by the first network function.

[0269] The optional implementation of step S4102 can be found in the optional implementation of step S2112 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0270] The communication method involved in the embodiments of this disclosure may include at least one of steps S4101 to S4102. For example, step S4101 may be implemented as a standalone embodiment, but is not limited thereto.

[0271] In some embodiments, step S4102 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0272] Figure 5 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 5, the embodiments of the present disclosure relate to a communication method executed by an application function, the method including:

[0273] Step S5101: Send a third request message to the second network function.

[0274] The optional implementation of step S5101 can be found in the optional implementation of step S2110 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0275] Step S5102: Receive the third response message sent by the second network function.

[0276] The optional implementation of step S5102 can be found in the optional implementation of step S2113 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0277] The communication method involved in the embodiments of this disclosure may include at least one of steps S5101 to S5102. For example, step S5101 may be implemented as a standalone embodiment, but is not limited thereto.

[0278] In some embodiments, step S5102 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0279] Figure 6 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 6, the embodiment of the present disclosure relates to a communication method executed by a third network function, the method comprising:

[0280] Step S6101: Send a second request message to the first network function.

[0281] The optional implementation of step S6101 can be found in the optional implementation of step S2102 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0282] Step S6102: Receive the second response message sent by the first network function.

[0283] The optional implementation of step S6102 can be found in the optional implementation of step S2104 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0284] The communication method involved in the embodiments of this disclosure may include at least one of steps S6101 to S6102. For example, step S6101 may be implemented as a standalone embodiment, but is not limited thereto.

[0285] In some embodiments, step S6102 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0286] Figure 7 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 7, the present disclosure relates to a communication method executed by a fourth network function, the method comprising:

[0287] Step S7101: Receive third information and / or third terminal identifier sent by the third network function.

[0288] The optional implementation of step S7101 can be found in the optional implementation of step S2105 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0289] Step S7102: Send third information and / or third terminal identifier to the terminal.

[0290] The optional implementation of step S7102 can be found in the optional implementation of step S2106 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0291] The communication method involved in the embodiments of this disclosure may include at least one of steps S7101 to S7102. For example, step S7101 may be implemented as a separate embodiment, and step S7102 may be implemented as a separate embodiment, but are not limited thereto.

[0292] In some embodiments, step S7101 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0293] In some embodiments, step S7102 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0294] Figure 8 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 8, the embodiments of the present disclosure relate to a communication method executed by a terminal, the method including:

[0295] Step S8101: Receive third information and / or third terminal identifier sent by the fourth network function.

[0296] The optional implementation of step S8101 can be found in the optional implementation of step S2106 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0297] In some embodiments, the first network function directly sends third information and / or a third terminal identifier to the terminal through the fourth network function, without needing to communicate with the fourth network function through the third network function.

[0298] Step S8102: Send the first information and / or the first terminal identifier to the application function.

[0299] The optional implementation of step S8102 can be found in the optional implementation of step S2108 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0300] The communication method involved in the embodiments of this disclosure may include at least one of steps S8101 to S8102. For example, step S8101 may be implemented as a separate embodiment, and step S8102 may be implemented as a separate embodiment, but are not limited thereto.

[0301] In some embodiments, step S8101 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0302] In some embodiments, step S8102 is optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0303] In some embodiments, the above methods may include the methods of the embodiments of the communication system side, network function side, application function side, terminal side, etc., which will not be described in detail here.

[0304] This disclosure proposes a communication method and designs a security mechanism for a communication system, enabling the core network to provide authentication results to application functions.

[0305] Figure 9A is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. Figure 9A illustrates the process of generating authenticated UE ID retrieving information. As shown in Figure 9A, the embodiments of the present disclosure relate to a communication method, which includes:

[0306] In step S9101, the UE was successfully authenticated.

[0307] In step S9102, NF3 (e.g., AUSF) sends a UE authentication result confirmation request to NF1 (e.g., UDM).

[0308] In some embodiments, the UE authentication result confirmation request includes authenticated UE ID retrieving information.

[0309] In some embodiments, the authenticated UE ID retrieval information may also be referred to as retrieval information or first information.

[0310] In some embodiments, the UE authentication result confirmation request may be, for example, N. NF1(UDM) _UEAuthentication_Result Confirmation request.

[0311] In some embodiments, NF3 (e.g., the Authentication Server Function (AUSF)) uses N UDMThe `_UEAuthentication_ResultConfirmation` request notifies NF1 (e.g., Unified Data Manager, UDM) of the result and timing of the authentication process with the UE. This request includes the Subscription Permanent Identifier (SUPI), the authentication timestamp, the authentication type (e.g., EAP method or 5G-AKA), and the serving network name. If the UE is successfully authenticated, NF3 (e.g., AUSF) generates one or more authentication UE ID retrieval messages (e.g., random numbers) and sends the generated authentication UE ID retrieval messages to NF1. The authentication UE ID retrieval messages enable the Application Function (AF) to verify whether the UE ID provided by the UE has been authenticated by the core network.

[0312] In some embodiments, the UE ID retrieval information for authentication may be a cookie, a random number, a token, a code, etc.

[0313] Step S9103: NF1 stores the UE's authentication status.

[0314] In some embodiments, NF1 (e.g., UDM) stores the UE's authentication status (SUPI, authentication result, timestamp, and service network name, and one or more authenticated UE ID retrieval information). NF1 then establishes a mapping between the UE ID retrieval information and the authenticated UE ID (i.e., SUPI).

[0315] In step S9104, NF1 sends a UE authentication result confirmation response to NF3.

[0316] In some embodiments, the UE authentication result confirmation response may be, for example, N. NF1(UDM) _UEAuthentication_Result Confirmation response.

[0317] In some embodiments, NF1 (e.g., UDM) uses N UDM The _UEAuthentication_ResultConfirmation response is sent to NF3 (e.g., AUSF).

[0318] In step S9105, NF3 sends a retrieval information transmission request to NF4 (e.g., AMF / SEAF).

[0319] In some embodiments, the information delivery request may be referred to as an authenticated UE ID retrieving information delivery request.

[0320] In some embodiments, the retrieval information delivery request includes retrieval information for the authenticated UE ID.

[0321] In some embodiments, NF3 (e.g., AUSF) sends an authenticated UE ID retrieval information delivery request to the UE via NF4 (e.g., Access and Mobility Management Function (AMF) or Security Anchor Function (SEAF)). This request includes SUPI and one or more authenticated UE ID retrieval messages.

[0322] In step S9106, NF4 sends a retrieval information transmission request to UE.

[0323] In some embodiments, the retrieval information delivery request includes retrieval information for the authenticated UE ID.

[0324] In some embodiments, the NF4 (e.g., AMF) sends an authentication UE ID retrieval information delivery request to the UE. This request includes the authentication UE ID retrieval information.

[0325] Step S9107: The UE stores the retrieved information.

[0326] In some embodiments, when an authenticated UE ID retrieval message is received, the UE stores the authenticated UE ID retrieval message to replace the old authenticated UE ID retrieval message (if any).

[0327] In step S9108, the UE sends a retrieval information transmission confirmation to NF4.

[0328] In some embodiments, the retrieval information delivery confirmation may be referred to as the authentication UE ID retrieval information delivery confirmation.

[0329] In some embodiments, the UE sends an authentication UE ID retrieval information transmission confirmation to the NF3 via the NF4.

[0330] In step S9109, NF4 sends a retrieval information transmission confirmation to NF3.

[0331] In some embodiments, NF4 sends an authentication UE ID retrieval information transmission confirmation to NF3.

[0332] Figure 9B is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. Figure 9B illustrates the process by which an application function retrieves an authenticated UE ID by accessing information using the authenticated UE ID. As shown in Figure 9B, this disclosure relates to a communication method, which includes:

[0333] Step S9201: Establish a TLS tunnel based on the AF certificate.

[0334] In some embodiments, to obtain services from an AF, the UE establishes a Transport Layer Security (TLS) tunnel with the AF. The TLS tunnel is established using the AF's certificate. The UE authenticates the AF using its public key certificate. During this process, the UE verifies whether the server certificate corresponds to the fully qualified domain name (FQDN) of the AF with which it is establishing the tunnel. The UE is not authenticated by the AF during this process.

[0335] In step S9202, the AF sends an authentication request to the UE.

[0336] In step S9203, the UE sends an authentication response to the AF.

[0337] In some embodiments, the UE authentication response includes home network information and retrieval information.

[0338] In some embodiments, the response includes a Generic Public Subscription Identifier (GPSI) containing home network information (e.g., home network identifier) ​​and an authenticated UE ID retrieval information (e.g., a random number) obtained in Figure 9A. Once the authenticated UE ID retrieval information is used by the UE for authentication with the AF, the UE removes the used information from the stored authenticated UE ID retrieval information.

[0339] In some embodiments, the UE sends home network information to the AF.

[0340] Step S9204: AF selects NF2 based on the home network information.

[0341] In some embodiments, AF selects NF2 (e.g., Network Exposure Function (NEF)) based on the home network information in the received GPSI.

[0342] In step S9205, AF sends a retrieval request to NF2 (e.g., NEF).

[0343] In some embodiments, a retrieval request may be referred to as an authenticated UE ID retrieval request.

[0344] In some embodiments, the AF sends GPSI and certified UE ID retrieval information to the NF2 based on the certified UE ID retrieval request.

[0345] In step S9206, NF2 sends a retrieval request to NF1 (e.g., UDM).

[0346] In some embodiments, NF1 discovers the UE ID based on the received GPSI.

[0347] In some embodiments, NF2 sends GPSI and certified UE ID retrieval information to NF1 based on the certified UE ID retrieval request.

[0348] In some embodiments, NF1 retrieves information based on the authenticated UE ID to identify the authenticated UE ID (i.e., the GPSI associated with the information).

[0349] In some embodiments, NF1 identifies the SUPI based on the authenticated UE ID retrieval information, and then finds the GPSI associated with the SUPI based on the identified SUPI.

[0350] In some embodiments, NF1 sends the authenticated UE ID identification result to NF2. Specifically, if NF1 cannot retrieve the authenticated UE ID or the retrieved authenticated UE ID is not the same as the ID associated with the GPSI provided by NF2, NF1 sends a failure message to NF2. The failure message indicates that the provided GPSI is not an authenticated UE ID. Otherwise, NF1 sends a positive message to NF2, indicating that the GPSI is an authenticated UE ID.

[0351] In step S9207, NF1 sends a retrieval response to NF2.

[0352] In some embodiments, once a matching authenticated UE ID is received from NF2 or NF1 sends a positive message to NF2, NF1 removes the used entry from its locally stored authenticated UE ID retrieval information. Then, NF1 sends the authenticated UE ID identification result to NF2 based on the authenticated UE ID retrieval response.

[0353] In step S9208, NF2 sends a retrieval response to AF.

[0354] In some embodiments, the retrieval response may include identification results.

[0355] In some embodiments, NF2 sends the authenticated UE ID identification result to AF.

[0356] In some embodiments, the authenticated UE ID identification result can be received from NF1.

[0357] In some embodiments, if the authentication result of the UE ID is positive, the AF will treat the received GPSI as an authenticated UE ID and provide services based on the received UE ID.

[0358] This disclosure provides an embodiment of a security mechanism for a communication system, enabling the core network to provide authentication results to application functions.

[0359] In some embodiments, the following alternatives exist.

[0360] Alternative Solution #1:

[0361] In the embodiment shown in Figure 9B, step S9206 can be replaced by: NF2 sending the authenticated UE ID retrieval information to NF1.

[0362] Step S9207 can be replaced by: NF1 sending the retrieved GPSI to NF2. If the GPSI cannot be retrieved, NF1 sends a failure message to NF2.

[0363] Step S9208 can be replaced by: NF2 generating an authenticated UE ID identification result based on the GPSI sent by AF and the GPSI sent by NF1. Specifically, if the GPSI provided by AF is the same as that provided by NF1, the authenticated UE ID identification result is positive. If NF1 sends a failure message or the GPSI provided by AF is inconsistent with that provided by NF1, the result is negative.

[0364] Alternative Solution #2:

[0365] In the embodiment shown in Figure 9B, step S9206 can be replaced by: NF2 sending the received GPSI to NF1.

[0366] Step S9207 can be replaced by: NF1 identifying the authenticated UE ID retrieval information based on the received GPSI, and sending the retrieved information to NF1.

[0367] Step S9208 can be replaced by: NF1 generating an authenticated UE ID identification result based on the authenticated UE ID retrieval information sent by AF and NF1. Specifically, if the information provided by AF is the same as the information provided by NF1, the authenticated UE ID identification result is positive. Otherwise, the result is negative.

[0368] Note: The security drawback of this alternative is that the UE ID retrieval information of the unrelated UE's authentication (assuming that the GPSI does not match the authenticated UE ID retrieval information sent by the UE) is security sensitive and known only to the UE and AUSF / UDM, and must be unnecessarily exposed to another entity.

[0369] In some embodiments, NF1 (e.g., UDM) has the following functions:

[0370] If the UE is successfully authenticated and the UE's subscription information indicates that the UE supports single sign-on based on the core network, then the UDM generates authenticated UE ID retrieval information and establishes a mapping relationship between the UE ID retrieval information and the authenticated UE ID (i.e., SUPI and GPSI belong to the authenticated UE).

[0371] NF1 (e.g., UDM) can send an authentication UE ID retrieval information transmission request to the UE via NF4 (e.g., AMF).

[0372] NF1 (e.g., UDM) can send an authentication UE ID retrieval information transmission request to the UE via NF4 (e.g., AMF).

[0373] NF1 (e.g., UDM) can receive the authentication UE ID retrieval information transmission confirmation from the UE via NF4 (e.g., AMF).

[0374] NF1 (e.g., UDM) can retrieve information from the AF by receiving the authenticated UE ID via NF2 (e.g., NEF).

[0375] NF1 (e.g., UDM) can send the UE ID to AF via NF2.

[0376] NF1 can generate a certified UE ID verification result based on the information provided by AF and NF2.

[0377] In some embodiments, the UE has the following functions:

[0378] The UE can receive the authenticated UE ID retrieval information from NF1 via NF4 (e.g., AMF).

[0379] The UE can send the authenticated UE ID retrieval information confirmation to NF1 via NF4 (e.g., AMF).

[0380] The UE can send an authentication response to the AF. This response includes home network information (e.g., home network identifier) ​​and authentication UE ID retrieval information.

[0381] In some embodiments, AF has the following functions:

[0382] The AF can send authentication requests to the UE.

[0383] The AF can select NF2 (e.g., NEF) based on the home network information sent by the UE.

[0384] AF can send authenticated UE ID retrieval information to NF2 via an authenticated UE ID retrieval request.

[0385] AF can receive the authenticated UE ID from NF2.

[0386] In some embodiments, NF4 has the following functions:

[0387] NF4 can receive authenticated UE ID retrieval information from NF1.

[0388] NF4 can receive authenticated UE ID retrieval information confirmation from the UE.

[0389] NF4 can send authenticated UE ID retrieval information to the UE.

[0390] NF4 can send authenticated UE ID retrieval information confirmation to NF1.

[0391] In some embodiments, NF2 has the following functions:

[0392] NF2 can receive authenticated UE ID retrieval information from AF via authenticated UE ID retrieval request.

[0393] NF2 discovers NF1 by retrieving information based on the authenticated UE ID.

[0394] NF2 can send authenticated UE ID retrieval information to NF1 via an authenticated UE ID retrieval request.

[0395] NF2 can receive the authenticated UE ID from NF1 via the authenticated UE ID retrieval response.

[0396] NF2 can send the authenticated UE ID to AF via the authenticated UE ID retrieval response.

[0397] NF2 can generate an authenticated UE ID verification result based on the information provided by AF and NF1.

[0398] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.

[0399] This disclosure also provides an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.

[0400] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through a configuration file, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0401] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0402] Figure 10A is a schematic diagram of the structure of a first network function proposed in an embodiment of this disclosure. As shown in Figure 10A, the first network function 10100 may include a transceiver module 10101. In some embodiments, the transceiver module 10101 is used to receive a first request message.

[0403] In some embodiments, the first network function further includes a processing module.

[0404] In some embodiments, the first request message includes the first information and the first terminal identifier; the processing module is configured to determine second information based on the first information and the first terminal identifier; the transceiver module is configured to send a first response message to the second network function, the first response message including the second information.

[0405] In some embodiments, the processing module is configured to: retrieve associated information based on the first information or the first terminal identifier, the associated information including third information and the second terminal identifier; determine second information if a first condition is met, the second information indicating at least one of the following: the first terminal identifier is the identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; the first terminal identifier has a mapping relationship with a terminal identifier that has been authenticated by the network; determine second information if a second condition is met, the second information indicating at least one of the following: the first terminal identifier is not the identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; the first terminal identifier has no mapping relationship with a terminal identifier that has been authenticated by the network; wherein the first condition includes: the first terminal identifier and the second terminal identifier are consistent, and the first information and the third information are consistent; wherein the second condition includes at least one of the following: the third information is inconsistent with the first information; the second terminal identifier is inconsistent with the first terminal identifier; no associated information is retrieved.

[0406] In some embodiments, the processing module is configured to delete the third information or the associated information if a first condition is met.

[0407] In some embodiments, the first request message includes the first information; the processing module is configured to retrieve a second terminal identifier associated with the first information based on the first information; and send the second terminal identifier to the second network function, wherein the second terminal identifier is used to determine the second information.

[0408] In some embodiments, the first request message includes the first terminal identifier; the processing module is configured to retrieve third information associated with the first terminal identifier based on the first terminal identifier; and send the third information to the second network function, wherein the third information is used to determine the second information.

[0409] In some embodiments, the transceiver module is configured to receive a second request message sent by a third network function, the second request message including third information and a third terminal identifier; the processing module is configured to establish an association relationship between at least two of the third information, the third terminal identifier and the second terminal identifier, wherein the second terminal identifier and the third terminal identifier are different types of the same terminal; and send a second response message to the third network function, the second response message corresponding to the second request message.

[0410] Figure 10B is a schematic diagram of the structure of the second network function proposed in an embodiment of this disclosure. As shown in Figure 10B, the second network function 10200 may include a transceiver module 10201. In some embodiments, the transceiver module 10201 is used to send a first request message.

[0411] In some embodiments, the second network function may further include a processing module.

[0412] In some embodiments, the first request message includes the first information and the first terminal identifier; the transceiver module is configured to receive a first response message sent by the first network function, the first response message including the second information, the second information being determined based on the first information and the first terminal identifier.

[0413] In some embodiments, when a first condition is met, the second information is used to indicate at least one of the following: the first terminal identifier is an identifier of the terminal; the first terminal identifier is an identifier that has been authenticated by the network; there is a mapping relationship between the first terminal identifier and a terminal identifier that has been authenticated by the network; when a second condition is met, the second information is used to indicate at least one of the following: the first terminal identifier is not an identifier of the terminal; the first terminal identifier is not an identifier that has been authenticated by the network; there is no mapping relationship between the first terminal identifier and a terminal identifier that has been authenticated by the network; wherein the first condition includes: the first terminal identifier and the second terminal identifier are consistent, and / or, the first information and the third information are consistent; wherein the second condition includes at least one of the following: the third information is inconsistent with the first information; the second terminal identifier is inconsistent with the first terminal identifier; no associated information was retrieved; wherein the second terminal identifier and the third information are retrieved based on the first information or the first terminal identifier.

[0414] In some embodiments, the first request message includes the first information; the transceiver module is configured to receive a second terminal identifier sent by the first network function, the second terminal identifier being associated with the first information; and to determine the second information based on the second terminal identifier.

[0415] In some embodiments, the first request message includes the first terminal identifier; the transceiver module is configured to receive third information sent by the first network function, the third information being associated with the first terminal identifier; and determine the second information based on the third information.

[0416] In some embodiments, the transceiver module is used to receive a third request message sent by the AF, the third request message including first information and / or a first terminal identifier, and the third request message is used to obtain the second information.

[0417] In some embodiments, the transceiver module is configured to send a third response message to the AF, the third response message including the second information.

[0418] Figure 10C is a schematic diagram of the application function proposed in an embodiment of this disclosure. As shown in Figure 10C, the application function 10300 may include a transceiver module 10301. In some embodiments, the transceiver module 10301 is used to send a third request message.

[0419] In some embodiments, the application functionality may further include a processing module.

[0420] In some embodiments, the transceiver module is configured to receive a third response message sent by the second network function, the third response message including the second information.

[0421] In some embodiments, the transceiver module is configured to receive the first information and / or the first terminal identifier sent by the terminal; and determine the second network function based on the first terminal identifier.

[0422] In some embodiments, the transceiver module is used to determine whether to provide services to the terminal based on the second information.

[0423] Figure 10D is a schematic diagram of the structure of the third network function proposed in an embodiment of this disclosure. As shown in Figure 10D, the third network function 10400 may include a transceiver module 10401. In some embodiments, the transceiver module 10401 is used to send a second request message.

[0424] In some embodiments, the third network function may further include a processing module.

[0425] In some embodiments, the transceiver module is configured to receive a second response message sent by the first network function, the second response message corresponding to the second request message, and the second response message including the third information and the third terminal identifier.

[0426] In some embodiments, the transceiver module is used to send the third information and / or the third terminal identifier to the fourth network function.

[0427] Figure 10E is a schematic diagram of the structure of the fourth network function proposed in an embodiment of this disclosure. As shown in Figure 10E, the fourth network function 10500 may include a transceiver module 10501. In some embodiments, the transceiver module 10501 is used to receive third information and / or a third terminal identifier.

[0428] In some embodiments, the fourth network function may further include a processing module.

[0429] In some embodiments, the transceiver module is used to send the third information and the third terminal identifier to the terminal.

[0430] Figure 10F is a schematic diagram of the structure of a terminal according to an embodiment of this disclosure. As shown in Figure 10F, the terminal 10600 may include a transceiver module 10601. In some embodiments, the transceiver module 10601 is used to transmit first information and / or a first terminal identifier.

[0431] In some embodiments, the terminal may further include a processing module.

[0432] In some embodiments, the transceiver module is used to receive third information sent by the fourth network function and the third terminal identifier, the third information and the third terminal identifier are used to establish an association relationship, and the association relationship is used to determine the second information.

[0433] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module. Optionally, the processing module may be interchangeable with a processor.

[0434] Figure 11A is a schematic diagram of the structure of the communication device 11100 proposed in an embodiment of this disclosure. The communication device 11100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 11100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0435] As shown in Figure 11A, the communication device 11100 includes one or more processors 11101. The processor 11101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 11100 can be used to execute any of the above methods. Optionally, one or more processors 11101 can be used to invoke instructions to cause the communication device 11100 to execute any of the above methods.

[0436] In some embodiments, the communication device 11100 further includes one or more transceivers 11102. When the communication device 11100 includes one or more transceivers 11102, the transceivers 11102 perform at least one of the communication steps (e.g., step S2102, but not limited thereto) in the above method, such as sending and / or receiving, while the processor 11101 performs at least one of other steps (e.g., step S2103, but not limited thereto). In optional embodiments, the transceivers may include receivers and / or transmitters, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, interface, etc., can be used interchangeably; the terms transmitter, sending unit, transmitter, sending circuit, etc., can be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., can be used interchangeably.

[0437] In some embodiments, the communication device 11100 further includes one or more memories 11103 for storing data. Optionally, all or part of the memories 11103 may be located outside the communication device 11100. In optional embodiments, the communication device 11100 may include one or more interface circuits 11104. Optionally, the interface circuits 11104 are connected to the memories 11103 and can be used to receive data from the memories 11103 or other devices, and can be used to send data to the memories 11103 or other devices. For example, the interface circuits 11104 can read data stored in the memories 11103 and send the data to the processor 11101.

[0438] The communication device 11100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 11100 described in this disclosure is not limited thereto, and the structure of the communication device 11100 may not be limited by FIG11A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0439] Figure 11B is a schematic diagram of the structure of chip 11200 according to an embodiment of this disclosure. For cases where the communication device 11100 can be a chip or a chip system, please refer to the schematic diagram of chip 11200 shown in Figure 11B, but it is not limited thereto.

[0440] Chip 11200 includes one or more processors 11201. Chip 11200 is used to perform any of the methods described above.

[0441] In some embodiments, chip 11200 further includes one or more interface circuits 11202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 11200 further includes one or more memories 11203 for storing data. Optionally, all or part of the memories 11203 may be located outside of chip 11200. Optionally, interface circuit 11202 is connected to memory 11203, and interface circuit 11202 can be used to receive data from memory 11203 or other devices, and interface circuit 11202 can be used to send data to memory 11203 or other devices. For example, interface circuit 11202 can read data stored in memory 11203 and send the data to processor 11201.

[0442] In some embodiments, the interface circuit 11202 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., step S2102, but not limited thereto). For example, the interface circuit 11202 performing the communication steps such as sending and / or receiving in the above method means that the interface circuit 11202 performs data interaction between the processor 11201, the chip 11200, the memory 11203, or the transceiver device. In some embodiments, the processor 11201 performs at least one of other steps (e.g., step S2103, but not limited thereto).

[0443] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0444] This disclosure also proposes a storage medium storing instructions that, when executed on the communication device 11100, cause the communication device 11100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0445] This disclosure also provides a program product that, when executed by the communication device 11100, causes the communication device 11100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0446] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

Claims

1. A communication method, characterized in that, Performed by a first network function, the method includes: The system receives a first request message sent by a second network function. The first request message includes first information and / or a first terminal identifier. The first information is used by the application function (AF) to authenticate the terminal or by the AF to obtain the second information.

2. The method according to claim 1, characterized in that, The second information is used to indicate at least one of the following: The first terminal identifier is the identifier of the terminal; The first terminal identifier is an identifier that has been authenticated by the network; The first terminal identifier has a mapping relationship with the terminal identifier that has been authenticated by the network; The first terminal identifier is not the identifier of the terminal; The first terminal identifier is not an identifier that has been authenticated by the network; There is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

3. The method according to claim 1 or 2, characterized in that, The first request message includes the first information and the first terminal identifier; The method further includes: Based on the first information and the first terminal identifier, the second information is determined; Send a first response message to the second network function, the first response message including the second information.

4. The method according to claim 3, characterized in that, The step of determining the second information based on the first information and the first terminal identifier includes: Retrieve associated information based on the first information or the first terminal identifier, wherein the associated information includes third information and the second terminal identifier; If the first condition is met, second information is determined, which indicates at least one of the following: The first terminal identifier is the identifier of the terminal; The first terminal identifier is an identifier that has been authenticated by the network; The first terminal identifier has a mapping relationship with the terminal identifier that has been authenticated by the network; If the second condition is met, second information is determined, which indicates at least one of the following: The first terminal identifier is not the identifier of the terminal; The first terminal identifier is not an identifier that has been authenticated by the network; The first terminal identifier has no mapping relationship with the terminal identifier that has been authenticated by the network; The first condition includes: the first terminal identifier and the second terminal identifier are the same, and / or the first information and the third information are the same; The second condition includes at least one of the following: The third piece of information is inconsistent with the first piece of information; The second terminal identifier is inconsistent with the first terminal identifier; No related information was found.

5. The method according to claim 4, characterized in that, The method further includes: If the first condition is met, delete the third information or the associated information.

6. The method according to claim 1 or 2, characterized in that, The first request message includes the first information; The method further includes: Based on the first information, a second terminal identifier associated with the first information is retrieved; The second terminal identifier is sent to the second network function, and the second terminal identifier is used to determine the second information.

7. The method according to claim 1 or 2, characterized in that, The first request message includes the first terminal identifier; The method further includes: Retrieve third information associated with the first terminal identifier based on the first terminal identifier; The third information is sent to the second network function, and the third information is used to determine the second information.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: Receive a second request message sent by a third network function, the second request message including third information and a third terminal identifier; Establish an association relationship between at least two of the third information, the third terminal identifier, and the second terminal identifier, wherein the second terminal identifier and the third terminal identifier are different types of identifiers of the same terminal; A second response message is sent to the third network function, the second response message corresponding to the second request message.

9. A communication method, characterized in that, Performed by a second network function, the method includes: Send a first request message to a first network function, the first request message including first information and / or a first terminal identifier, the first information being used by the application function (AF) to authenticate the terminal or by the AF to obtain second information.

10. The method according to claim 9, characterized in that, The second information is used to indicate at least one of the following: The first terminal identifier is the identifier of the terminal; The first terminal identifier is an identifier that has been authenticated by the network; The first terminal identifier has a mapping relationship with the terminal identifier that has been authenticated by the network; The first terminal identifier is not the identifier of the terminal; The first terminal identifier is not an identifier that has been authenticated by the network; There is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

11. The method according to claim 9 or 10, characterized in that, The first request message includes the first information and the first terminal identifier; The method further includes: The system receives a first response message sent by the first network function, the first response message including the second information, the second information being determined based on the first information and the first terminal identifier.

12. The method according to claim 11, characterized in that, If the first condition is met, the second information is used to indicate at least one of the following: The first terminal identifier is the identifier of the terminal; The first terminal identifier is an identifier that has been authenticated by the network; The first terminal identifier has a mapping relationship with the terminal identifier that has been authenticated by the network; If the second condition is met, the second information is used to indicate at least one of the following: The first terminal identifier is not the identifier of the terminal; The first terminal identifier is not an identifier that has been authenticated by the network; The first terminal identifier has no mapping relationship with the terminal identifier that has been authenticated by the network; The first condition includes: the first terminal identifier and the second terminal identifier are the same, and / or the first information and the third information are the same; The second condition includes at least one of the following: The third piece of information is inconsistent with the first piece of information; The second terminal identifier is inconsistent with the first terminal identifier; No related information was found; The second terminal identifier and the third information are obtained based on the first information or the first terminal identifier.

13. The method according to claim 9 or 10, characterized in that, The first request message includes the first information; The method further includes: Receive a second terminal identifier sent by the first network function, wherein the second terminal identifier is associated with the first information; The second information is determined based on the second terminal identifier.

14. The method according to claim 9 or 10, characterized in that, The first request message includes the first terminal identifier; The method further includes: Receive third information sent by the first network function, wherein the third information is associated with the first terminal identifier; The second information is determined based on the third information.

15. The method according to any one of claims 9 to 14, characterized in that, The method further includes: The third request message sent by the AF is received. The third request message includes first information and / or a first terminal identifier. The third request message is used to obtain the second information.

16. The method according to claim 15, characterized in that, The method further includes: A third response message is sent to the AF, the third response message including the second information.

17. A communication method, characterized in that, Performed by application function AF, the method includes: Send a third request message to the second network function. The third request message includes first information and / or a first terminal identifier. The first information is used by the application function (AF) to authenticate the terminal or by the AF to obtain the second information.

18. The method according to claim 17, characterized in that, The second information is used to indicate at least one of the following: The first terminal identifier is the identifier of the terminal; The first terminal identifier is an identifier that has been authenticated by the network; The first terminal identifier has a mapping relationship with the terminal identifier that has been authenticated by the network; The first terminal identifier is not the identifier of the terminal; The first terminal identifier is not an identifier that has been authenticated by the network; There is no mapping relationship between the first terminal identifier and the terminal identifier that has been authenticated by the network.

19. The method according to claim 17 or 18, characterized in that, The method further includes: Receive a third response message sent by the second network function, the third response message including the second information.

20. The method according to any one of claims 17 to 19, characterized in that, The method further includes: Receive the first information and / or the first terminal identifier sent by the terminal; The second network function is determined based on the first terminal identifier.

21. The method according to any one of claims 17 to 20, characterized in that, The method further includes: Based on the second information, determine whether to provide services to the terminal.

22. A communication method, characterized in that, Performed by a third network function, the method includes: Send a second request message to the first network function. The second request message includes third information and / or a third terminal identifier. The third information and the third terminal identifier are used to establish an association relationship, and the association relationship is used to determine the second information.

23. The method according to claim 22, characterized in that, The second information is used to indicate at least one of the following: The first terminal identifier is the identifier of the terminal; The first terminal identifier is one that has already been authenticated by the network; There is a mapping relationship between the first terminal identifier and the terminal identifiers that have been authenticated by the network; The first terminal identifier is not the identifier of the terminal; The first terminal identifier is not an identifier that has been authenticated by the network; There is no mapping relationship between the first terminal identifier and the terminal identifiers that have been authenticated by the network.

24. The method according to claim 22 or 23, characterized in that, The method further includes: The system receives a second response message sent by the first network function. The second response message corresponds to the second request message and includes the third information and the third terminal identifier.

25. The method according to any one of claims 22 to 24, characterized in that, The method further includes: Send the third information and / or the third terminal identifier to the fourth network function.

26. A communication method, characterized in that, Performed by a fourth network function, the method includes: The system receives third information and / or a third terminal identifier sent by a third network function. The third information and the third terminal identifier are used to establish an association relationship, and the association relationship is used to determine the second information.

27. The method according to claim 26, characterized in that, The second information is used to indicate at least one of the following: The first terminal identifier is the identifier of the terminal; The first terminal identifier is one that has already been authenticated by the network; There is a mapping relationship between the first terminal identifier and the terminal identifiers that have been authenticated by the network; The first terminal identifier is not the identifier of the terminal; The first terminal identifier is not an identifier that has been authenticated by the network; There is no mapping relationship between the first terminal identifier and the terminal identifiers that have been authenticated by the network.

28. The method according to claim 26 or 27, characterized in that, The method further includes: Send the third information and the third terminal identifier to the terminal.

29. A communication method, characterized in that, The method, executed by a terminal, includes: Send first information and / or first terminal identifier to the application function AF; the first information is used by the application function AF to authenticate the terminal or by the AF to obtain second information.

30. The method according to claim 29, characterized in that, The second information is used to indicate at least one of the following: The first terminal identifier is the identifier of the terminal; The first terminal identifier is an identifier that has been authenticated by the network; The first terminal identifier has a mapping relationship with the terminal identifier that has been authenticated by the network; The first terminal identifier is not the identifier of the terminal; The first terminal identifier is not an identifier that has been authenticated by the network.

31. The method according to claim 29 or 30, characterized in that, The method further includes: The system receives third information and a third terminal identifier sent by a fourth network function. The third information and the third terminal identifier are used to establish an association relationship, and the association relationship is used to determine the second information.

32. A communication device, characterized in that, The communication device is used to perform the communication method according to any one of claims 1 to 8, or the communication method according to any one of claims 9 to 16, or the communication method according to any one of claims 17 to 21, or the communication method according to any one of claims 22 to 25, or the communication method according to any one of claims 26 to 28, or the communication method according to any one of claims 29 to 31.

33. A communication system, characterized in that, The device includes a first network function, a second network function, an application function, a third network function, a fourth network function, and a terminal. The first network function is configured to implement the communication method according to any one of claims 1 to 8; the second network function is configured to implement the communication method according to any one of claims 9 to 16; the application function is configured to implement the communication method according to any one of claims 17 to 21; the third network function is configured to implement the communication method according to any one of claims 22 to 25; the fourth network function is configured to implement the communication method according to any one of claims 26 to 28; and the terminal is configured to implement the communication method according to any one of claims 29 to 31.

34. A storage medium, characterized in that, The storage medium stores instructions that, when executed on the communication device, cause the communication device to perform the communication method as described in any one of claims 1 to 8, or any one of claims 9 to 16, or the communication method as described in any one of claims 17 to 21, or the communication method as described in any one of claims 22 to 25, or the communication method as described in any one of claims 26 to 28, or the communication method as described in any one of claims 29 to 31.

35. A program product, characterized in that, It includes at least one of a program or instructions, wherein when the program or instructions are executed by a communication device, they implement the communication method according to any one of claims 1 to 8, or the communication method according to any one of claims 9 to 16, or the communication method according to any one of claims 17 to 21, or the communication method according to any one of claims 22 to 25, or the communication method according to any one of claims 26 to 28, or the communication method according to any one of claims 29 to 31.