Communication method and apparatus
Patent Information
- Application Number
- PCT/CN2025/080103
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2026-09-03
Smart Images

Figure CN2025080103_03092026_PF_FP_ABST
Abstract
Description
Communication methods and devices Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology
[0002] In related technologies, when the first network element receives a message from the second network element requesting to provide services to the terminal, it does not verify whether the second network element is a service network element for the terminal, but directly allows the second network element to provide services to the terminal as a service network element. In this case, the second network element can obtain the terminal's private data. Attackers can easily use the second network element, which is not actually serving the terminal, to carry out fraudulent attacks. Summary of the Invention
[0003] This disclosure provides a communication method and apparatus, which, when a first network element receives a first message from a second network element requesting to provide services to a terminal, verifies whether the second network element is a serving network element for the terminal. Based on the verification result of whether the second network element is a serving network element for the terminal, it determines whether to allow the second network element to provide services to the terminal. This can prevent the leakage of the terminal's privacy data, avoid fraud attacks, and improve the information security of communication.
[0004] This disclosure presents a communication method and apparatus.
[0005] According to a first aspect of the present disclosure, a communication method is proposed, executed by a first network element, comprising: receiving a first message, wherein the first message is used to instruct a second network element to request to provide services to a terminal; and determining, based on the first message, whether the second network element is a serving network element of the terminal.
[0006] In the above embodiments, the first network element can verify whether the second network element is a serving network element of the terminal, so as to determine whether the second network element is allowed to provide services to the terminal based on the verification result of whether the second network element is a serving network element of the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication.
[0007] According to a second aspect of the present disclosure, a communication method is proposed, executed by a second network element, comprising: sending a first message, wherein the first message is used to instruct the second network element to request to provide services to a terminal, and the first message is used by the first network element to determine whether the second network element is a service network element for the terminal.
[0008] In the above embodiments, when the second network element sends a message to the first network element requesting to be the service network element of the terminal, the first network element can verify whether the second network element is the service network element of the terminal. Based on the verification result of whether the second network element is the service network element of the terminal, it can determine whether the second network element is allowed to provide services to the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication.
[0009] According to a third aspect of the present disclosure, a communication method is proposed, executed by a third network element, comprising: receiving a second message or a fourth message, wherein the second message is used to request the third network element to verify whether the second network element is a serving network element of the terminal, and the fourth message is used to request to obtain the authentication status information of the terminal, wherein the second message or the fourth message is sent by a first network element upon receiving a first message sent by the second network element, and the first message is used to instruct the second network element to request to provide services to the terminal.
[0010] In the above embodiments, the third network element can provide the first network element with the terminal's authentication status information, so that the first network element can determine the terminal's access network information and home network information. Therefore, upon receiving a first message from the second network element requesting to provide services to the terminal, the first network element can determine whether the second network element is the terminal's serving network element, thus preventing the leakage of the terminal's privacy data, avoiding fraud attacks, and improving communication information security. Alternatively, the third network element can provide the first network element with the verification result of whether the second network element is the terminal's serving network element, so that upon receiving a first message from the second network element requesting to provide services to the terminal, the first network element can determine whether the second network element is the terminal's serving network element, thus preventing the leakage of the terminal's privacy data, avoiding fraud attacks, and improving communication information security.
[0011] According to a fourth aspect of the present disclosure, a first network element is provided, comprising: a transceiver module for receiving a first message, wherein the first message is used to instruct a second network element to request to provide services to a terminal; and a processing module for determining, based on the first message, whether the second network element is a serving network element of the terminal.
[0012] According to a fifth aspect of the present disclosure, a second network element is provided, comprising: a transceiver module, configured to send a first message, wherein the first message is configured to instruct the second network element to request to provide services to a terminal, and the first message is configured by the first network element to determine whether the second network element is a service network element for the terminal.
[0013] According to a sixth aspect of the present disclosure, a third network element is proposed, comprising: a transceiver module, configured to receive a second message or a fourth message, wherein the second message is configured to request the third network element to verify whether the second network element is a serving network element of the terminal, and the fourth message is configured to request to obtain authentication status information of the terminal, wherein the second message or the fourth message is sent by the first network element upon receiving a first message sent by the second network element, and the first message is configured to instruct the second network element to request to provide services to the terminal.
[0014] According to a seventh aspect of the present disclosure, a first network element is provided, comprising: one or more processors, wherein the first network element is configured to perform the method described in the first aspect.
[0015] According to an eighth aspect of the present disclosure, a second network element is provided, comprising: one or more processors, wherein the second network element is configured to perform the method described in the second aspect.
[0016] According to a ninth aspect of the present disclosure, a third network element is provided, comprising: one or more processors, wherein the third network element is configured to perform the method described in the third aspect.
[0017] According to a tenth aspect of the present disclosure, a communication device is provided, comprising: one or more processors; and a memory coupled to the processors, the memory storing instructions which, when executed by the processors, cause the communication device to perform the method as described in at least one of the first, second, and third aspects.
[0018] According to an eleventh aspect of the present disclosure, a communication system is provided, comprising: a first network element, a second network element, and a third network element; the first network element performs the method as described in the first aspect, the second network element performs the method as described in the second aspect embodiment, and the third network element performs the method as described in the third aspect embodiment.
[0019] According to a twelfth aspect of the present disclosure, a computer storage medium is provided, wherein the computer storage medium stores computer-executable instructions; after being executed by a processor, the computer-executable instructions are capable of implementing the method described in at least one of the first, second, and third aspects.
[0020] According to a thirteenth aspect of the present disclosure, a computer program product is provided, wherein the computer program product stores a computer program; after being executed by a processor, the computer program is capable of implementing the method described in at least one of the first, second, and third aspects.
[0021] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this disclosure. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.
[0023] Figure 1 is an architecture diagram of a communication system provided in an embodiment of this disclosure;
[0024] Figure 2A is a flowchart of a communication method provided in an embodiment of this disclosure;
[0025] Figure 2B is a flowchart of another communication method provided in an embodiment of this disclosure;
[0026] Figure 2C is a flowchart of another communication method provided in an embodiment of this disclosure;
[0027] Figure 2D is a flowchart of another communication method provided in an embodiment of this disclosure;
[0028] Figure 3A is a flowchart of another communication method provided in an embodiment of this disclosure;
[0029] Figure 3B is a flowchart of another communication method provided in an embodiment of this disclosure;
[0030] Figure 3C is a flowchart of another communication method provided in an embodiment of this disclosure;
[0031] Figure 4A is a flowchart of authorized service access in a roaming scenario provided by an embodiment of this disclosure;
[0032] Figure 4B is a flowchart of a service request provided in an embodiment of this disclosure;
[0033] Figure 4C is a flowchart of another service request provided in an embodiment of this disclosure;
[0034] Figure 5A is a structural diagram of a first network element provided in an embodiment of this disclosure;
[0035] Figure 5B is a structural diagram of a second network element provided in an embodiment of this disclosure;
[0036] Figure 5C is a structural diagram of a third network element provided in an embodiment of this disclosure;
[0037] Figure 6A is a structural diagram of a communication device provided in an embodiment of this disclosure;
[0038] Figure 6B is a structural diagram of a chip provided in an embodiment of this disclosure. Detailed Implementation
[0039] This disclosure presents a communication method and apparatus.
[0040] In a first aspect, embodiments of this disclosure propose a communication method executed by a first network element, comprising: receiving a first message, wherein the first message is used to instruct a second network element to request to provide services to a terminal; and determining, based on the first message, whether the second network element is a serving network element for the terminal.
[0041] In the above embodiments, the first network element can verify whether the second network element is a serving network element of the terminal, so as to determine whether the second network element is allowed to provide services to the terminal based on the verification result of whether the second network element is a serving network element of the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication.
[0042] In conjunction with some embodiments of the first aspect, in some embodiments, the first network element determines whether the second network element is a serving network element of the terminal based on the first message, including: sending a second message to a third network element based on the first message, wherein the second message is used to request the third network element to verify whether the second network element is a serving network element of the terminal; receiving a third message sent by the third network element, wherein the third message is used to indicate the verification result of whether the second network element is a serving network element of the terminal; and determining whether the second network element is a serving network element of the terminal based on the third message.
[0043] In the above embodiments, the first network element can request the third network element to verify whether the second network element is a serving network element of the terminal, and obtain the verification result of whether the second network element is a serving network element of the terminal from the third network element. This can determine whether the second network element is a serving network element of the terminal, and determine whether the second network element is allowed to provide services to the terminal based on the verification result of whether the second network element is a serving network element of the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication.
[0044] In conjunction with some embodiments of the first aspect, in some embodiments, the first network element determines whether the second network element is a serving network element of the terminal based on the first message, including: determining the terminal's first network information based on the first message and the terminal's authentication status information, wherein the first network information is at least one of access network information and home network information; determining the second network information to which the second network element belongs; and determining whether the second network element is a serving network element of the terminal based on the first network information and the second network information.
[0045] In the above embodiments, the first network element can determine whether the second network element is a serving network element of the terminal based on the terminal's authentication status information. Based on the verification result of whether the second network element is a serving network element of the terminal, it can determine whether the second network element is allowed to provide services to the terminal. This can prevent the leakage of the terminal's privacy data, avoid fraud attacks, and improve the information security of communication.
[0046] In conjunction with some embodiments of the first aspect, in some embodiments, the above method further includes: a first network element sending a fourth message to a third network element, wherein the fourth message is used to request the acquisition of the terminal's authentication status information; receiving a fifth message sent by the third network element, wherein the fifth message is used to indicate the terminal's authentication status information; and determining the terminal's authentication status information based on the fifth message.
[0047] In the above embodiments, the first network element can obtain the terminal's authentication status information from the third network element to determine whether the second network element is the terminal's serving network element. Based on the verification result of whether the second network element is the terminal's serving network element, it can determine whether to allow the second network element to provide services to the terminal. This can prevent the leakage of the terminal's privacy data, avoid fraud attacks, and improve the information security of communication.
[0048] In conjunction with some embodiments of the first aspect, in some embodiments, the first message is further used to request an access token, wherein the above method further includes: the first network element determining the second network element as the serving network element of the terminal, generating an access token; and sending a sixth message, wherein the sixth message includes the access token.
[0049] In the above embodiments, when the first network element determines that the second network element is the serving network element of the terminal, it can generate an access token and send it to the second network element so that the second network element can use the access token to provide services to the terminal. This can prevent the leakage of the terminal's privacy data, avoid fraud attacks, and improve the information security of communication.
[0050] In conjunction with some embodiments of the first aspect, in some embodiments, the above method further includes: the first network element determining that the second network element has changed from a serving network element of the terminal to a non-serving network element, and revoking the access token.
[0051] In the above embodiments, when the first network element determines that the second network element is the serving network element of the terminal, it can generate an access token and send it to the second network element, so that the second network element can use the access token to provide services to the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication. Furthermore, when it is determined that the second network element is not the serving network element of the terminal, it can proactively and promptly revoke the access token and stop allowing the second network element to provide services to the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication.
[0052] In conjunction with some embodiments of the first aspect, in some embodiments, the first network element determines that the second network element has changed from a serving network element of the terminal to a non-serving network element, including: sending a seventh message to a third network element, wherein the seventh message is used to subscribe to the terminal's authentication status information; receiving an eighth message sent by the third network element, wherein the eighth message is used to indicate the terminal's updated authentication status information, wherein the terminal's updated authentication status information is used to indicate that the second network element is not a serving network element of the terminal; and determining that the second network element has changed from a serving network element of the terminal to a non-serving network element based on the terminal's updated authentication status information.
[0053] In the above embodiments, the first network element can subscribe to the terminal's authentication status information from the third network element. When the terminal's authentication status information is updated, it can receive the eighth message sent by the third network element. If the updated authentication status information of the terminal indicates that the second network element is not the terminal's serving network element, the first network element can determine that the second network element is not the terminal's serving network element based on the updated authentication status information of the terminal, and thus stop allowing the second network element to provide services to the terminal, thereby preventing the leakage of the terminal's privacy data, preventing fraud attacks, and improving the information security of communication.
[0054] In conjunction with some embodiments of the first aspect, in some embodiments, the access token includes identification information of the terminal.
[0055] In the above embodiments, the access token includes the terminal's identification information, which can indicate that the access token is only valid for the terminal indicated by the terminal's identification information. That is, the access token can only provide services to the terminal indicated by the terminal's identification information included in the access token, which can protect the terminal's privacy data security and improve the information security of communication.
[0056] In conjunction with some embodiments of the first aspect, in some embodiments, the first message includes at least one of the following: identification information of the terminal; and second network information to which the second network element belongs.
[0057] In the above embodiments, the first network element receives a first message sent by the second network element, which includes the terminal's identification information, to instruct the second network element to request to provide services to the terminal, and / or the first message includes the second network information to which the second network element belongs. If the first network information of the terminal is determined, the second network element is determined to be the terminal's serving network element based on the first network information and the second network information.
[0058] Secondly, this disclosure provides a communication method executed by a second network element, comprising: sending a first message, wherein the first message is used to instruct the second network element to request to provide services to the terminal, and the first message is used by the first network element to determine whether the second network element is a service network element for the terminal.
[0059] In the above embodiments, when the second network element sends a message to the first network element requesting to be the service network element of the terminal, the first network element can verify whether the second network element is the service network element of the terminal. Based on the verification result of whether the second network element is the service network element of the terminal, it can determine whether the second network element is allowed to provide services to the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication.
[0060] In conjunction with some embodiments of the second aspect, in some embodiments, the first message is further used to request an access token, wherein the above method further includes: the second network element receiving a sixth message sent by the first network element, wherein the sixth message includes an access token, the access token being generated by the first network element when it determines that the second network element is the serving network element of the terminal.
[0061] In conjunction with some embodiments of the second aspect, in some embodiments, the access token includes the terminal's identification information.
[0062] In conjunction with some embodiments of the second aspect, in some embodiments, the first message includes at least one of the following: the terminal's identification information; and the second network information to which the second network element belongs.
[0063] Thirdly, this disclosure provides a communication method executed by a third network element, comprising: receiving a second message or a fourth message, wherein the second message is used to request the third network element to verify whether the second network element is a serving network element of the terminal, and the fourth message is used to request to obtain the authentication status information of the terminal, wherein the second message or the fourth message is sent by the first network element upon receiving a first message sent by the second network element, and the first message is used to instruct the second network element to request to provide services to the terminal.
[0064] In the above embodiments, the third network element can provide the first network element with the terminal's authentication status information, so that the first network element can determine the terminal's access network information and / or home network information. Therefore, upon receiving a first message from the second network element requesting to provide services to the terminal, the first network element can determine whether the second network element is the terminal's serving network element, thus preventing the leakage of the terminal's privacy data, avoiding fraud attacks, and improving communication information security. Alternatively, the third network element can provide the first network element with the verification result of whether the second network element is the terminal's serving network element, so that upon receiving a first message from the second network element requesting to provide services to the terminal, the first network element can determine whether the second network element is the terminal's serving network element, thus preventing the leakage of the terminal's privacy data, avoiding fraud attacks, and improving communication information security.
[0065] In conjunction with some embodiments of the third aspect, in some embodiments, the above method further includes: a third network element determining first network information of the terminal based on the terminal's authentication status information, wherein the first network information is at least one of access network information and home network information; determining second network information to which the second network element belongs; determining an authentication result based on the first network information and the second network information; and sending a third message to the first network element, wherein the third message is used to indicate whether the second network element is the verification result of the terminal's serving network element.
[0066] In conjunction with some embodiments of the third aspect, in some embodiments, the above method further includes: the third network element sending a fifth message to the first network element, wherein the fifth message is used to indicate the authentication status information of the terminal.
[0067] In conjunction with some embodiments of the third aspect, in some embodiments, the first message is further used to request an access token, and the above method further includes: the third network element receiving a seventh message sent by the first network element, wherein the seventh message is used to subscribe to the authentication status information of the terminal; and sending an eighth message to the first network element, wherein the eighth message is used to indicate the updated authentication status information of the terminal, wherein the updated authentication status information of the terminal is used by the first device to determine that the second network element is not the serving network element of the terminal.
[0068] In conjunction with some embodiments of the third aspect, in some embodiments, the access token includes the terminal's identification information.
[0069] In conjunction with some embodiments of the third aspect, in some embodiments, the first message includes at least one of the following: the terminal's identification information; and the second network information to which the second network element belongs.
[0070] Fourthly, this disclosure provides a first network element, including: a transceiver module for receiving a first message, wherein the first message is used to instruct a second network element to request to provide services to a terminal; and a processing module for determining, based on the first message, whether the second network element is a serving network element for the terminal.
[0071] Fifthly, this disclosure provides a second network element, including: a transceiver module, used to send a first message, wherein the first message is used to instruct the second network element to request to provide services to the terminal, and the first message is used by the first network element to determine whether the second network element is a service network element of the terminal.
[0072] In a sixth aspect, embodiments of this disclosure propose a third network element, including: a transceiver module, configured to receive a second message or a fourth message, wherein the second message is configured to request the third network element to verify whether the second network element is a serving network element of the terminal, and the fourth message is configured to request to obtain the authentication status information of the terminal, wherein the second message or the fourth message is sent by the first network element upon receiving a first message sent by the second network element, and the first message is configured to instruct the second network element to request to provide services to the terminal.
[0073] In a seventh aspect, a first network element is proposed, comprising: one or more processors, wherein the first network element is used to execute the method described in the first aspect.
[0074] Eighthly, a second network element is proposed, comprising: one or more processors, wherein the second network element is used to execute the method described in the second aspect.
[0075] In a ninth aspect, a third network element is proposed, comprising: one or more processors, wherein the third network element is used to execute the method described in the third aspect.
[0076] In a tenth aspect, embodiments of this disclosure provide a communication device, the communication device comprising: one or more processors; and a memory coupled to the processors, the memory storing instructions which, when executed by the processors, cause the communication device to perform the method described in at least one of the first, second, and third aspects.
[0077] In one aspect, embodiments of this disclosure provide a communication system comprising: a first network element, a second network element, and a third network element; wherein the first network element is configured to perform the method described in the first aspect, the second network element is configured to perform the method described in the second aspect, and the third network element is configured to perform the method described in the third aspect.
[0078] In a twelfth aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in at least one of the first, second, and third aspects.
[0079] In a thirteenth aspect, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in at least one of the first, second, and third aspects.
[0080] In a fourteenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in at least one of the first, second, and third aspects.
[0081] In a fifteenth aspect, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described in at least one of the first, second, and third aspects described above.
[0082] It is understood that the aforementioned communication equipment, communication system, storage medium, program product, etc., are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0083] This disclosure provides a communication method and apparatus. In some embodiments, the terms "communication method" and "information processing method" or "information transmission method" can be used interchangeably.
[0084] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments. In all embodiments of this disclosure, unless otherwise specified or logically conflicting, the terminology and / or descriptions between the embodiments are consistent and can be mutually referenced. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0085] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0086] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0087] In the embodiments disclosed herein, "multiple" refers to two or more.
[0088] In some embodiments, the terms “at least one of A or B, at least one of A and B”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0089] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, both A and B are executed. The same applies when there are more branches such as A, B, C, etc.
[0090] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.
[0091] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0092] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0093] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.
[0094] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.
[0095] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0096] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “network function,” “network device,” “function,” “node,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.
[0097] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).
[0098] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.
[0099] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.
[0100] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.
[0101] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
[0102] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0103] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0104] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0105] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
[0106] Figure 1 is an architecture diagram of a communication system provided in an embodiment of this disclosure.
[0107] As shown in Figure 1, the communication system 100 includes multiple terminals 101 and network devices 102.
[0108] In some embodiments, terminal 101 includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal, augmented reality (AR) terminal, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical surgery, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, and wireless terminal in smart home.
[0109] In some embodiments, network device 102 may include at least one of access network device and core network device.
[0110] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.
[0111] In some embodiments, the access network device may be a satellite.
[0112] In some embodiments, the core network equipment may be a single device, multiple devices, or a group of devices, including all or part of a first network element, a second network element, a third network element, etc. Network elements may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), a 6G Core Network (6GCN), and a Next Generation Core (NGC).
[0113] In some embodiments, the first network element provides network service storage and service discovery functions. It is primarily responsible for the automated management, selection, and expansion of network functions, including service registration, discovery, status monitoring, and authorization, enabling on-demand configuration of network functions and services, and interconnection between network functions. The first network element can also act as an authorization server, responsible for verifying the identity of service consumers (NF consumers) and issuing access tokens.
[0114] In some embodiments, the first network element is a network function element. For example, it may be a function element responsible for access control and mobility management of terminal access to the operator's network, or a function element responsible for managing the terminal's data packets and sessions, or a function element used for authentication of network subscribers by the operator's network, or a function element used for storing service security requirements and providing policy determination information, or a function element used for policy control decisions, providing service data flow and application detection, gating, quality of service (QoS), and flow-based charging control, or a function element used for selecting network slice instances for service user equipment, etc. The first network element acts as a service producer (NF producer), verifying the access token provided by the service consumer, responding to the service consumer's requests, and providing the requested resources, etc.
[0115] In some embodiments, the second network element is a network function network element. For example, it may be a function network element responsible for access control and mobility management of terminal access to the operator's network, or a function network element responsible for managing terminal data packets and sessions, or a function network element used for operator network authentication of subscribed users, or a function network element used for storing service security requirements and providing policy determination information, or a function network element used for policy control decisions, providing service data flow and application detection, gating, quality of service (QoS), and flow-based charging control, or a function network element used for selecting network slice instances for service user equipment, etc. The second network element acts as a service consumer, used to initiate authentication requests to the authentication server to obtain access tokens, and to initiate requests to service producers to obtain resources, etc.
[0116] In some embodiments, the third network element is used to manage terminal identifiers, subscription data, authentication data, etc., and is also responsible for the service network element registration management of the terminal, and stores the terminal's subscription information. In this embodiment, the terminal's context is also stored.
[0117] In some embodiments, the first network element is a network repository function (NRF) element or a network exposure function (NEF). For example, the NRF receives an NF discovery request from a certain NF network element and provides the discovered NF network element (discovered) information to the requesting NF network element.
[0118] In some embodiments, the first network element is a network function (NF) network element with service producer identity. The NF can be an access and mobility management function (AMF) network element, a session management function (SMF) network element, an authentication server function (AUSF) network element, an application function (AF) network element, a policy control function (PCF) network element, a network slice selection function (NSSF) network element, etc. For example, the first network element can provide Nudm_UECM service, or a network element can provide Nausf_UEAuthentication service, etc.
[0119] In some embodiments, the second network element is a network function (NF) network element with a service consumer identity. For example, the NF can be an AMF network element, SMF network element, AUSF network element, AF network element, PCF network element, NSSF network element, etc. For example, the second network element can be a network element capable of requesting the Nudm_UECM service, a network element capable of requesting the Nausf_UEAuthentication service, etc.
[0120] It is understandable that both the first and second network elements are NF (Network Function) elements. When multiple NF elements exist, they interact through service-based interfaces (SBIs). One NF element can provide one or more NF services. NF services can use either a request-response or subscription-notification approach. Each NF element can act as a service producer, providing an application programming interface (API) for other NF elements to call, or as a service consumer, calling the APIs of other NF elements. NF elements allow other authorized NF elements to access their services.
[0121] In some embodiments, the third network element is, for example, a unified data management (UDM) network element, or a network element in 6G that manages or stores terminal status information.
[0122] In some embodiments, the first network element and the second network element are in different networks.
[0123] In some embodiments, at least one of the first network element, the second network element, and the third network element can be independent of the core network equipment.
[0124] In some embodiments, at least one of the first network element, the second network element, and the third network element may be part of the core network equipment.
[0125] In some embodiments, the first network element may also be referred to as the first device, the second network element may also be referred to as the second device, and the third network element may also be referred to as the third device.
[0126] In some embodiments, the service producer, NF producer, NF producer, service producer, NF serviceproducer and producer can be interchanged with each other, and the service consumer, NF consumer, NF consumer, service consumer and NF service consumer can be interchanged with each other.
[0127] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.
[0128] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0129] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), Super 3G, IMT-Advanced, 4th Generation Mobile Communication System (4G), 5th Generation Mobile Communication System (5G), 5G New Radio (NR), 6th Generation Mobile Communication System (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future Generation Radio Access (FX), Global System for Mobile Communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, ultra-wideband (UWB), Bluetooth (a registered trademark), public land mobile network (PLMN) networks, device-to-device (D2D) systems, machine-to-machine (M2M) systems, internet of things (IoT) systems, vehicle-to-everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0130] In related technologies, when a first network element receives a message from a second network element requesting to provide services to a terminal, it does not verify whether the second network element is a service network element for the terminal. Instead, it directly allows the second network element to act as a service network element for the terminal and provide services to the terminal. In this case, the second network element can obtain the terminal's private data. Attackers can easily use the second network element, which is not actually serving the terminal, to carry out fraudulent attacks. This is a problem that urgently needs to be solved.
[0131] Based on this, embodiments of this disclosure provide a communication method and apparatus, wherein the method executed by a first network element includes: receiving a first message, wherein the first message is used to instruct a second network element to request to provide services to a terminal; and determining, based on the first message, whether the second network element is a serving network element of the terminal. Thus, the first network element can verify whether the second network element is a serving network element of the terminal, and based on the verification result, determine whether to allow the second network element to provide services to the terminal, thereby preventing the leakage of the terminal's privacy data, preventing fraud attacks, and improving the information security of communication.
[0132] Figure 2A is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 2A, the embodiments of the present disclosure relate to a communication method, which includes:
[0133] S201A, the second network element sends the first message to the first network element.
[0134] In some embodiments, the first network element receives a first message sent by the second network element, but is not limited thereto. The first network element may also receive a first message sent by other entities other than the second network element, in which case S201A can be omitted.
[0135] In some embodiments, the first network element obtains the first message specified by the protocol, in which case S201A can be omitted.
[0136] In some embodiments, the first network element obtains the first message from the upper layer(s), in which case S201A can be omitted.
[0137] In some embodiments, the first network element processes the data to obtain the first message, in which case S201A can be omitted.
[0138] In some embodiments, the first network element autonomously implements the function indicated by the first message, or the above function is a default or default value, in which case S201A can be omitted.
[0139] In some embodiments, the first message is used to request services to the terminal.
[0140] In some embodiments, the first message is used to request to become a service network element of the terminal.
[0141] In some embodiments, the first message is used to request the service network element of the terminal to be updated to be the second network element.
[0142] In some embodiments, the first message is used to instruct the second network element to request services to the terminal.
[0143] In some embodiments, the first message is used to request an access token.
[0144] In some embodiments, the first message is used to request an access token to obtain data related to the terminal, thereby providing services to the terminal.
[0145] In some embodiments, the first network element acts as an authentication server, responsible for verifying the identity of the service consumer and issuing access tokens to the authorized service consumer. The first network element is a network repository function (NRF) element or a network exposure function (NEF) element, etc.
[0146] In some embodiments, the second network element acts as a service consumer, used to initiate authentication requests to the authentication server to obtain access tokens, and to initiate requests to the service producer to obtain resources, etc.
[0147] In some embodiments, the first network element is an authentication server, and the second network element is a service consumer. Optionally, if the first network element and the second network element belong to different networks, the second network element can send a first message to the first network element through an authentication server belonging to the same network. For example, the first network element is NRF2, and the second network element is NF1, where NF1 belongs to network PLMN1, NRF2 belongs to network PLMN2, and NRF1 and NF1 belong to the same network PLMN1. NF1 sends the first message to NRF1 through NRF2.
[0148] In some embodiments, the first message includes at least one of the following: identification information of the terminal; and second network information to which the second network element belongs.
[0149] In this embodiment, the first message includes the terminal's identification information, which can be an identifier, such as at least one of a generic public subscription identifier (GPSI), a subscription concealed identifier (SUCI), and a subscriber permanent ID (SUPI). In this case, the first message is used to request services for the terminal indicated by the terminal's identification information. It can be explained that the second network element sends the first message to obtain an access token, and based on this access token, obtains data related to the terminal, thereby enabling the provision of services to the terminal.
[0150] In this embodiment of the disclosure, the first message includes second network information to which the second network element belongs. The second network information may be an identifier of the public land mobile network (PLMN) to which the second network element belongs, or an identifier of the second network element itself, etc.
[0151] In some embodiments, the first network element is an authentication server, the second network element is a service consumer, and the first message further includes at least one of the following: the identifier (ID) of the second network element; the resource range information requested from the service producer; the NF type of the second network element; the PLMN ID of the second network element; and the NF type of the requested service producer.
[0152] In some embodiments, the second network element determines to send the first message to the first network element on its own, or determines to send the first message to the first network element based on the instruction information sent by the first network element, or the second network element determines to send the first message to the first network element based on the agreement.
[0153] For example, if the second network element determines on its own or based on the agreement that it needs to provide services to the terminal, it determines to send the first message to the first network element.
[0154] For example, when the second network element receives an instruction from the first network element indicating that the second network element will provide services to the terminal, the second network element may send a first message to the first network element.
[0155] In some embodiments, the second network element may reuse existing signaling or messages to send a first message to the first network element, or send a first message to the first network element using new signaling or messages.
[0156] S202A, the first network element sends a second message to the third network element.
[0157] In some embodiments, the third network element receives the second message sent by the first network element, but is not limited thereto. The third network element may also receive the second message sent by other entities other than the first network element, in which case S202A can be omitted.
[0158] In some embodiments, the third network element obtains the second message specified by the protocol, in which case S202A can be omitted.
[0159] In some embodiments, the third network element obtains the second message from the upper layer(s), in which case S202A can be omitted.
[0160] In some embodiments, the third network element processes the data to obtain the second message, in which case S202A can be omitted.
[0161] In some embodiments, the third network element autonomously implements the function indicated by the second message, or the above function is a default or default value, in which case S202A can be omitted.
[0162] In some embodiments, the second message is used to request the third network element to verify whether the second network element is the serving network element of the terminal.
[0163] In some embodiments, the second message is used to request the third network element to provide a verification result as to whether the second network element is the serving network element of the terminal.
[0164] In some embodiments, the second message is used to request the third network element to confirm whether the second network element is the serving network element of the terminal.
[0165] In some embodiments, the third network element is used to manage terminal identifiers, subscription data, authentication data, etc., and is also responsible for the service network element registration management of the terminal, and stores the terminal's subscription information. In this embodiment, the terminal's context is also stored.
[0166] In some embodiments, the third network element is a UDM, or a network element in 6G that manages or stores terminal status information.
[0167] In some embodiments, the second message includes at least one of the following: terminal identification information, second network information to which the second network element belongs, resource range information requested from the service provider, and the NF type of the requested service provider.
[0168] In this embodiment of the disclosure, the second message includes the terminal's identification information, wherein the identification information can be an identifier, such as at least one of GPSI, SUCI, and SUPI.
[0169] In this embodiment of the disclosure, the second message includes second network information to which the second network element belongs. The second network information can be the identifier of a PLMN or the identifier of the second network element. Optionally, when a third network element receives a second message sent by a first network element, and the second message includes the identifier of the second network element, the third network element can determine the network to which the second network element belongs based on the identifier, for example, determining the information of the PLMN to which the second network element belongs.
[0170] In some embodiments, a first network element receives a first message sent by a second network element. If the first message requests to provide services to a terminal and the first network element and the second network element are not on the same network, the first network element sends a second message to a third network element.
[0171] In some embodiments, the first network element may reuse existing signaling or messages to send a second message to the third network element, or send a second message to the third network element using new signaling or messages.
[0172] S203A, the third network element determines the terminal's first network information and the second network information to which the second network element belongs based on the terminal's authentication status information. Based on the first and second network information, it determines whether the second network element is the verification result of the terminal's serving network element.
[0173] In this embodiment of the disclosure, the third network element stores the authentication status information of the terminal. The authentication status information of the terminal includes the terminal's first network information, which includes at least one of the terminal's access network information (information of the access network that the terminal has successfully authenticated) and the terminal's home network information (information of the terminal's home network).
[0174] In some embodiments, the terminal's authentication status information includes at least one of the following: the terminal's identification information, the authentication result, the time corresponding to the authentication result, and the network information used for authentication. The terminal's authentication status information can be used to determine the information of the network to which the terminal has most recently successfully authenticated.
[0175] In some embodiments, the third network element receives a second message sent by the second network element. If the second message is used to request the third network element to verify whether the second network element is a serving network element of the terminal, the third network element can determine the first network information of the terminal based on the terminal's authentication status information, and determine the second network information to which the second network element belongs. Furthermore, based on the first network information and the second network information, the third network element can determine the verification result of whether the second network element is a serving network element of the terminal.
[0176] It is understandable that the terminal may be in a roaming state, that is, outside the coverage area of the home network. In order to achieve communication, the terminal will access other networks outside the home network.
[0177] In some embodiments, the first network information is at least one of access network information and home network information.
[0178] In this embodiment, the terminal's first network information is the terminal's access network information, which is the information corresponding to the network to which the terminal recently successfully completed the authentication process. Optionally, the terminal's access network information is the identifier of the PLMN that the terminal is currently accessing and that has successfully completed the authentication process. For example, if the terminal accesses PLMN1 and successfully completes the two-way authentication process at time T1, and then moves to PLMN2 and successfully completes the two-way authentication process, the third network element stores the information of PLMN2 and determines the information of PLMN2 as the terminal's first network information. Alternatively, if the terminal accesses PLMN1 and successfully completes the two-way authentication process at time T1, and then moves to PLMN2 but fails to complete the two-way authentication process, the third network element stores the information of PLMN1 and determines the information of PLMN1 as the terminal's first network information.
[0179] In this embodiment of the disclosure, the first network information of the terminal is the terminal's home network information, wherein the home network information can be information about the terminal's home network. Optionally, the terminal's home network information is the identifier of the PLMN to which the terminal belongs.
[0180] In some embodiments, the first message includes second network information to which the second network element belongs, and the first network element can determine the second network information to which the second network element belongs based on the first message.
[0181] In some embodiments, the third network element determines the first network information of the terminal and the second network information to which the second network element belongs. If the first network information and the second network information indicate the same network, the second network element is determined to be the serving network element of the terminal; conversely, if the first network information and the second network information indicate different networks, the second network element is determined not to be the serving network element of the terminal.
[0182] For example, the third network element determines that the first network information of the terminal is PLMN identifier (ID) #1, and the second network information of the second network element is PLMN ID #1. Since PLMN ID #1 is the same network, the second network element can be determined to be the serving network element of the terminal.
[0183] For example, if the third network element determines that the first network information of the terminal is PLMN identifier (ID) #1 and the second network information of the second network element is PLMN ID #2, and PLMN ID #1 and PLMN ID #2 are different networks, then it can be determined that the second network element is not the serving network element of the terminal.
[0184] S204A, the third network element sends a third message to the first network element.
[0185] In some embodiments, the first network element receives a third message sent by the third network element, but is not limited thereto. The first network element may also receive a third message sent by other entities other than the third network element, in which case S204A can be omitted.
[0186] In some embodiments, the first network element obtains a third message as specified by the protocol, in which case S204A can be omitted.
[0187] In some embodiments, the first network element obtains the third message from the upper layer(s), in which case S204A can be omitted.
[0188] In some embodiments, the first network element processes the data to obtain the third message, in which case S204A can be omitted.
[0189] In some embodiments, the first network element autonomously implements the function indicated by the third message, or the above function is a default or default value, in which case S204A can be omitted.
[0190] In some embodiments, the third message is used to indicate whether the second network element is the verification result of the terminal's serving network element.
[0191] In some embodiments, the third message is used to indicate that the second network element is the serving network element of the terminal.
[0192] In some embodiments, the third message is used to indicate that the second network element is not a serving network element of the terminal.
[0193] In some embodiments, the third message includes at least one bit, indicating that the second network element is a serving network element of the terminal when at least one bit is a first value, and indicating that the second network element is not a serving network element of the terminal when at least one bit is a second value.
[0194] In some embodiments, if the third message includes the first identifier, it indicates that the second network element is a serving network element of the terminal; if the third message does not include the first identifier, it indicates that the second network element is not a serving network element of the terminal.
[0195] In some embodiments, if the third network element determines in S203A whether the second network element is the service network element of the terminal, it sends a third message to the first network element.
[0196] In some embodiments, the third network element may reuse existing signaling or messages to send a third message to the first network element, or send a third message to the first network element using new signaling or messages.
[0197] In S205A, the first network element determines whether the second network element is the serving network element of the terminal based on the third message.
[0198] In this embodiment of the disclosure, the first network element receives a third message sent by the third network element, which can determine whether the second network element is the serving network element of the terminal.
[0199] In one possible implementation, when the third message is used to indicate that the second network element is the serving network element of the terminal, the first network element can determine that the second network element is the serving network element of the terminal.
[0200] In another possible implementation, if the third message is used to indicate that the second network element is not the serving network element of the terminal, the first network element can determine that the second network element is not the serving network element of the terminal.
[0201] In some embodiments, when the first network element determines that the second network element is the serving network element of the terminal, it sends a response message to the second network element. The response message is used to indicate that the second network element is allowed to provide services to the terminal, or to send the data or resources of the requested service to the second network element, or to generate an access token for the second network element that enables it to provide services to the terminal.
[0202] In some embodiments, if the first network element determines that the second network element is not a serving network element for the terminal, it sends a response message to the second network element. The response message indicates that the second network element is refused service to the terminal, or it indicates an error. Optionally, in this case, subsequent steps S206A to S210A can be omitted.
[0203] S206A, the first network element determines the second network element as the service network element of the terminal and generates an access token.
[0204] In some embodiments, the first network element is an authentication server and the second network element is a service consumer. When the first network element determines that the second network element is the service network element of the terminal, the first network element can generate an access token. The access token is used by the second network element to obtain relevant data of the terminal from the service producer to support the second network element in providing services to the terminal.
[0205] In some embodiments, the access token includes the terminal's identification information.
[0206] In this embodiment of the disclosure, the access token includes the terminal's identification information, such as the terminal's identifier (ID). That is, the access token can be used by a second network element to obtain relevant data of the terminal indicated by the terminal's identification information from the service provider, thereby supporting the second network element in providing services to the terminal indicated by the terminal's identification information. The access token is only valid for the specified terminal.
[0207] In some embodiments, the access token may contain the identifiers of one or more terminals. When the access token contains the identifiers of multiple terminals, the second network element can use the access token to obtain relevant data of the terminals indicated by the identifier information of the multiple terminals from the service provider.
[0208] S207A, the first network element sends the sixth message to the second network element.
[0209] In some embodiments, the second network element receives a sixth message sent by the first network element, but is not limited thereto. The second network element may also receive a sixth message sent by other entities other than the first network element, in which case S207A can be omitted.
[0210] In some embodiments, the second network element obtains the sixth message specified by the protocol, in which case S207A can be omitted.
[0211] In some embodiments, the second network element obtains the sixth message from the upper layer(s), in which case S207A can be omitted.
[0212] In some embodiments, the second network element processes the data to obtain the sixth message, in which case S207A can be omitted.
[0213] In some embodiments, the second network element autonomously implements the function indicated by the sixth message, or the above function is a default or default value, in which case S207A can be omitted.
[0214] In some embodiments, the sixth message includes an access token.
[0215] In some embodiments, the sixth message includes the terminal's identification information.
[0216] In some embodiments, when the first network element generates an access token, it sends a sixth message to the second network element, the sixth message including the access token.
[0217] In some embodiments, the access token includes the terminal's identification information.
[0218] In some embodiments, the access token includes identification information for multiple terminals.
[0219] In some embodiments, the first network element may reuse existing signaling or messages to send a sixth message to the second network element, or send a sixth message to the second network element using new signaling or messages.
[0220] In some embodiments, the first network element is an authentication server, and the second network element is a service consumer. Optionally, if the first network element and the second network element belong to different networks, the first network element can send a sixth message to the second network element through an authentication server belonging to the same access network as the second network element.
[0221] In some embodiments, the first network element sends an access token acquisition (Nnrf_AccessToken_Get) response message to the second network element, wherein the Nnrf_AccessToken_Get response message includes a sixth message.
[0222] S208A, the first network element sends the seventh message to the third network element.
[0223] In some embodiments, the third network element receives the seventh message sent by the first network element, but is not limited thereto. The third network element may also receive the seventh message sent by other entities other than the first network element, in which case S208A can be omitted.
[0224] In some embodiments, the third network element obtains the seventh message specified by the protocol, in which case S208A can be omitted.
[0225] In some embodiments, the third network element obtains the seventh message from the upper layer(s), in which case S208A can be omitted.
[0226] In some embodiments, the third network element processes the data to obtain the seventh message, in which case S208A can be omitted.
[0227] In some embodiments, the third network element autonomously implements the function indicated by the seventh message, or the above function is a default or default value, in which case S208A can be omitted.
[0228] In some embodiments, S208A can be executed simultaneously with S201A or executed in a different order; S208A can be executed simultaneously with S202A or executed in a different order; S208A can be executed simultaneously with S203A or executed in a different order; S208A can be executed simultaneously with S204A or executed in a different order; S208A can be executed simultaneously with S205A or executed in a different order; and S206A can be executed simultaneously with S207A or executed in a different order.
[0229] In some embodiments, when the first network element is based on a database shared with the third network element, the first network element can determine the authentication status information of the terminal based on the data in the database. In this case, the first network element does not need to send the seventh message to the third network element, and S208A can be omitted.
[0230] In some embodiments, the seventh message is used to subscribe to the authentication status information of the terminal.
[0231] In some embodiments, the seventh message is used to instruct the third network element to send the updated authentication status information of the terminal to the first network element when the authentication status information of the terminal is updated.
[0232] In some embodiments, the seventh message is used to subscribe to the terminal's authentication status information to the third network element. Optionally, upon receiving the seventh message from the first network element, the third network element, if it determines that the terminal's authentication status information has been updated, may indicate the updated authentication status information of the terminal to the first network element.
[0233] In some embodiments, the terminal's authentication status information includes the terminal's access network information and home network information.
[0234] In some embodiments, the seventh message is used to verify whether the subscribed second network element is the serving network element of the terminal.
[0235] In some embodiments, the seventh message is used to instruct the third network element to send the updated verification result of whether the second network element is the serving network element of the terminal when the terminal's authentication status information is updated to the first network element.
[0236] In some embodiments, the seventh message is used to subscribe to the verification result of the second network element obtained from the terminal's authentication status information from the third network element. Optionally, when the third network element receives the seventh message sent by the first network element and determines that the terminal's authentication status information has been updated, resulting in a change in the verification result of the second network element as a terminal serving network element, it may indicate the updated verification result of the second network element to the first network element.
[0237] In some embodiments, the first network element determines to send the seventh message to the third network element on its own, or determines to send the seventh message to the third network element when sending an access token to the second network element, or the first network element determines to send the seventh message to the third network element based on the agreement.
[0238] In some embodiments, the first network element may reuse existing signaling or messages to send a seventh message to the third network element, or send a seventh message to the third network element using new signaling or messages.
[0239] S209A, the third network element sends the eighth message to the first network element.
[0240] In some embodiments, the first network element receives the eighth message sent by the third network element, but is not limited thereto. The first network element may also receive the eighth message sent by other entities other than the third network element, in which case S209A can be omitted.
[0241] In some embodiments, the first network element obtains the eighth message specified by the protocol, in which case S209A can be omitted.
[0242] In some embodiments, the first network element obtains the eighth message from the upper layer(s), in which case S209A can be omitted.
[0243] In some embodiments, the first network element processes the data to obtain the eighth message, in which case S209A can be omitted.
[0244] In some embodiments, the first network element autonomously implements the function indicated by the eighth message, or the above function is a default or default value, in which case S209A can be omitted.
[0245] In some embodiments, when the first network element is based on a database shared with the third network element, the first network element can determine the authentication status information of the terminal based on the data in the database. In this case, the third network element does not need to send the eighth message to the first network element, and S209A can be omitted.
[0246] In some embodiments, the eighth message is used to indicate the updated authentication status information of the terminal.
[0247] In some embodiments, the eighth message is used to indicate that the terminal's access network information has changed.
[0248] In some embodiments, the eighth message is used to indicate that the terminal's home network information has changed.
[0249] In some embodiments, the eighth message is used to indicate the terminal's access network information, wherein the eighth message indicates that the terminal's access network information is different from the terminal's access network information previously sent to the first network element.
[0250] In some embodiments, the eighth message is used to indicate the authentication status information of the terminal, wherein the authentication status information of the terminal has changed relative to the information previously sent by the third network element to the first network element.
[0251] In some embodiments, the eighth message is used to indicate a change in the terminal's authentication status information, such as the terminal's access network information being switched from first network information to third network information, wherein the first network information (PLMN#1) and the third network information (PLMN#3) are different.
[0252] In some embodiments, the updated authentication status information of the terminal is used to indicate that the second network element is not the serving network element of the terminal.
[0253] In some embodiments, the eighth message is used to indicate the updated authentication status information of the terminal, which in turn indicates the terminal's access network information. The eighth message indicates that the terminal's access network information is different from the terminal's access network information previously sent to the first network element.
[0254] In some embodiments, the eighth message is used to indicate that the verification result of the second network element has changed.
[0255] In some embodiments, the eighth message is used to indicate that the second network element is no longer the serving network element of the terminal.
[0256] S210A, the first network element determines, according to the eighth message, that the second network element has been changed from the terminal's serving network element to a non-serving network element, and revokes the access token.
[0257] In this embodiment of the disclosure, if the first network element receives the eighth message sent by the third network element and determines that the second network element has changed from a serving network element of the terminal to a non-serving network element, it revokes the access token. Optionally, the access token is generated by the first network element in S206A.
[0258] In some embodiments, if the first network element receives the eighth message sent by the third network element and determines that the second network element is not the serving network element of the terminal, it revokes the access token. Optionally, the access token is generated by the first network element in S206A.
[0259] In some embodiments, if the first network element revokes the access token, the second network element will no longer be able to provide services to the terminal.
[0260] In some embodiments, if the first network element revokes the access token, the second network element will be unable to authenticate the access token when it continues to use the access token to provide services to the terminal, and thus the second network element will be unable to provide services to the terminal.
[0261] In some embodiments, when the first network element receives the eighth message from the third network element and determines that the second network element has changed from a serving network element to a non-serving network element of the terminal, it modifies the terminal identifier contained in the access token. For example, the original access token contained terminal identifier 1 and terminal identifier 2, and the second network element could use this access token to provide services to terminals 1 and 2. After the first network element receives the eighth message indicating an update to the authentication status information of terminal 1, it deletes terminal identifier 1 from the access token, retains only terminal identifier 2, and revokes the authorization to provide services to terminal 1 in the access token. The first network element can then send the updated access token to the second network element.
[0262] In some embodiments, when it is determined that the second network element has been changed from a serving network element of the terminal to a non-serving network element, the first network element sends a message to the second network element to notify of the revocation or update of the access token.
[0263] In some embodiments, when it is determined that the second network element has been changed from a serving network element of the terminal to a non-serving network element, the first network element sends a message to the service producer to notify of the revocation or update of the access token.
[0264] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.
[0265] In some embodiments, "acquire," "get," "obtain," "receive," "transmit," "bidirectional transmission," and "send and / or receive" can be used interchangeably and can be interpreted as receiving from other entities, acquiring from protocols, acquiring from higher layers, obtaining through self-processing, or autonomous implementation. Protocols include, for example, at least one of the 3GPP protocol, Wi-Fi protocol, and audio and / or video protocols.
[0266] In some embodiments, terms such as “send,” “transmit,” “report,” “distribute,” “transmit,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.
[0267] In some embodiments, terms such as "certain," "preset," "default," "set," "indicated," "a certain," "any," and "first" can be used interchangeably. "Certain A," "preset A," "default A," "set A," "indicated A," "a certain A," "any A," and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.
[0268] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (boolean), or by a comparison of numerical values (e.g., a comparison with a predetermined value), but is not limited thereto.
[0269] By implementing the embodiments of this disclosure, the first network element can verify whether the second network element is a serving network element of the terminal, and determine whether to allow the second network element to provide services to the terminal based on the verification result of whether the second network element is a serving network element of the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication.
[0270] The communication methods involved in the embodiments of this disclosure may include at least one of S201A to S210A. For example, S201A can be implemented as an independent embodiment, S202A can be implemented as an independent embodiment, S203A can be implemented as an independent embodiment, S204A can be implemented as an independent embodiment, S205A can be implemented as an independent embodiment, S206A can be implemented as an independent embodiment, S207A can be implemented as an independent embodiment, S208A can be implemented as an independent embodiment, S209A can be implemented as an independent embodiment, S210A can be implemented as an independent embodiment, S201A+S202A+S203A+S204A+S205A can be implemented as an independent embodiment, S201A+S202A+S203A+S204A+S205A+S206A+S207A can be implemented as an independent embodiment, and S208A+S209A+S210A can be implemented as an independent embodiment, but are not limited thereto.
[0271] In some embodiments, S208A can be executed simultaneously with S201A or executed in a different order; S208A can be executed simultaneously with S202A or executed in a different order; S208A can be executed simultaneously with S203A or executed in a different order; S208A can be executed simultaneously with S204A or executed in a different order; S208A can be executed simultaneously with S205A or executed in a different order; and S206A can be executed simultaneously with S207A or executed in a different order.
[0272] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0273] Figure 2B is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 2B, the present disclosure relates to a communication method, which includes:
[0274] S201B, the second network element sends the first message to the first network element.
[0275] The optional implementations of S201B can be found in the optional implementations of S201A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0276] S202B, the first network element sends the fourth message to the third network element.
[0277] In some embodiments, the third network element receives a fourth message sent by the first network element, but is not limited thereto. The third network element may also receive a fourth message sent by other entities other than the first network element, in which case S202B can be omitted.
[0278] In some embodiments, the third network element obtains the fourth message specified by the protocol, in which case S202B can be omitted.
[0279] In some embodiments, the third network element obtains the fourth message from the upper layer(s), in which case S202B can be omitted.
[0280] In some embodiments, the third network element processes the data to obtain the fourth message, in which case S202B can be omitted.
[0281] In some embodiments, the third network element autonomously implements the function indicated by the fourth message, or the above function is a default or default value, in which case S202B can be omitted.
[0282] In some embodiments, the fourth message is used to request the authentication status information of the terminal.
[0283] In some embodiments, the fourth message is used to request at least one of the terminal's access network information and home network information.
[0284] In some embodiments, the fourth message is used to request network information of the terminal, including at least one of the terminal's access network information and home network information.
[0285] In some embodiments, the third network element is used to manage terminal identifiers, subscription data, authentication data, etc., and is also responsible for the service network element registration management of the terminal, and stores the terminal's subscription information. In this embodiment, the terminal's context is also stored.
[0286] In some embodiments, the third network element is a UDM, or a network element in 6G that manages or stores terminal status information.
[0287] In some embodiments, the fourth message includes: the terminal's identification information.
[0288] In this embodiment of the disclosure, the fourth message includes the terminal's identification information, wherein the identification information can be an identifier, such as at least one of GPSI, SUCI, and SUPI.
[0289] In some embodiments, the first network element receives a first message sent by the second network element. If the first message requests to provide services to the terminal, the first network element sends a fourth message to the third network element.
[0290] In some embodiments, the first network element may reuse existing signaling or messages to send a fourth message to the third network element, or send a fourth message to the third network element using new signaling or messages.
[0291] S203B, the third network element sends the fifth message to the first network element.
[0292] In some embodiments, the first network element receives a fifth message sent by the third network element, but is not limited thereto. The first network element may also receive a fifth message sent by other entities other than the third network element, in which case S203B can be omitted.
[0293] In some embodiments, the first network element obtains the fifth message specified by the protocol, in which case S203B can be omitted.
[0294] In some embodiments, the first network element obtains the fifth message from the upper layer(s), in which case S203B can be omitted.
[0295] In some embodiments, the first network element processes the data to obtain the fifth message, in which case S203B can be omitted.
[0296] In some embodiments, the first network element autonomously implements the function indicated by the fifth message, or the above function is a default or default value, in which case S203B can be omitted.
[0297] In some embodiments, the fifth message is used to indicate the authentication status information of the terminal.
[0298] In some embodiments, the terminal's authentication status information includes at least one of the following: the terminal's identification information, the authentication result, the time corresponding to the authentication result, and the network information used for authentication. The terminal's authentication status information can be used to determine the information of the network to which the terminal has most recently successfully authenticated.
[0299] In some embodiments, the fifth message is used to indicate at least one of the terminal's access network information and home network information.
[0300] In some embodiments, the fifth message is used to indicate network information of the terminal, including at least one of the terminal's access network information and home network information.
[0301] In some embodiments, when a third network element receives a fourth message from a first network element, it sends a fifth message to the first network element.
[0302] In some embodiments, if the third network element determines that the authentication status information of the terminal has changed, it sends a fifth message to the first network element.
[0303] In some embodiments, the third network element periodically sends a fifth message to the first network element.
[0304] In some embodiments, the third network element may reuse existing signaling or messages to send a fifth message to the first network element, or send a fifth message to the first network element using new signaling or messages.
[0305] S204B, the first network element determines the terminal's authentication status information based on the fifth message.
[0306] In this embodiment of the disclosure, the first network element receives a fifth message sent by the third network element and can determine the authentication status information of the terminal. For example, determining the terminal's network information includes at least one of the terminal's access network information and home network information.
[0307] S205B: The first network element determines the first network information of the terminal based on the first message and the terminal's authentication status information, determines the second network information to which the second network element belongs, and determines whether the second network element is the terminal's serving network element based on the first network information and the second network information.
[0308] In some embodiments, if the first network element stores the authentication status information of the terminal, the above S202B to S204B can be omitted.
[0309] In this embodiment of the disclosure, the authentication status information of the terminal includes the terminal's first network information, which includes at least one of the terminal's access network information (information of the access network to which the terminal has successfully authenticated) and the terminal's home network information (information of the terminal's home network).
[0310] In some embodiments, the first message includes second network information to which the second network element belongs, and the first network element can determine the second network information to which the second network element belongs based on the first message.
[0311] In some embodiments, the first network element determines the first network information of the terminal and the second network information to which the second network element belongs. If the first network information and the second network information indicate the same network, the second network element is determined to be the serving network element of the terminal; conversely, if the first network information and the second network information indicate different networks, the second network element is determined not to be the serving network element of the terminal.
[0312] For example, the first network element determines that the first network information of the terminal is PLMN ID#1, and the second network information of the second network element is PLMN ID#1. Since PLMN ID#1 is the same network, the second network element can be determined to be the serving network element of the terminal.
[0313] For example, if the first network element determines that the first network information of the terminal is PLMN ID#1 and the second network information of the second network element is PLMN ID#2, and PLMN ID#1 and PLMN ID#2 are different networks, then it can be determined that the second network element is not the serving network element of the terminal.
[0314] S206B, the first network element determines the second network element as the service network element of the terminal and generates an access token.
[0315] The optional implementations of S206B can be found in the optional implementations of S206A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0316] S207B, the first network element sends the sixth message to the second network element.
[0317] The optional implementations of S207B can be found in the optional implementations of S207A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0318] S208B, the first network element sends the seventh message to the third network element.
[0319] The optional implementations of S208B can be found in the optional implementations of S208A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0320] S209B, the third network element sends the eighth message to the first network element.
[0321] The optional implementations of S209B can be found in the optional implementations of S209A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0322] S210B, the first network element determines, based on the eighth message, that the second network element has been changed from the terminal's serving network element to a non-serving network element, and revokes the access token.
[0323] The optional implementations of S210B can be found in the optional implementations of S210A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0324] By implementing the embodiments of this disclosure, the first network element can verify whether the second network element is a serving network element of the terminal, and determine whether to allow the second network element to provide services to the terminal based on the verification result of whether the second network element is a serving network element of the terminal. This can prevent the leakage of the terminal's privacy data, prevent fraud attacks, and improve the information security of communication.
[0325] The communication methods involved in the embodiments of this disclosure may include at least one of S201B to S210B. For example, S201B can be implemented as an independent embodiment, S202B can be implemented as an independent embodiment, S203B can be implemented as an independent embodiment, S204B can be implemented as an independent embodiment, S205B can be implemented as an independent embodiment, S206B can be implemented as an independent embodiment, S207B can be implemented as an independent embodiment, S208B can be implemented as an independent embodiment, S209B can be implemented as an independent embodiment, S210B can be implemented as an independent embodiment, S201B+S202B+S203B+S204B+S205B can be implemented as an independent embodiment, S201B+S202B+S203B+S204B+S205B+S206B+S207B can be implemented as an independent embodiment, and S208B+S209B+S210B can be implemented as an independent embodiment, but are not limited thereto.
[0326] In some embodiments, S208B can be executed simultaneously with S201B or executed in a different order; S208B can be executed simultaneously with S202B or executed in a different order; S208B can be executed simultaneously with S203B or executed in a different order; S208B can be executed simultaneously with S204B or executed in a different order; S208B can be executed simultaneously with S205B or executed in a different order; and S206B can be executed simultaneously with S207B or executed in a different order.
[0327] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0328] Figure 2C is an interactive schematic diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 2C, the embodiments of the present disclosure relate to a communication method, which includes:
[0329] S201C, the second network element sends the first message to the first network element.
[0330] In some embodiments, the first network element receives a first message sent by the second network element, but is not limited thereto. The first network element may also receive a first message sent by other entities other than the second network element, in which case S201C can be omitted.
[0331] In some embodiments, the first network element obtains the first message specified by the protocol, in which case S201C can be omitted.
[0332] In some embodiments, the first network element obtains the first message from the upper layer(s), in which case S201C can be omitted.
[0333] In some embodiments, the first network element processes the data to obtain the first message, in which case S201C can be omitted.
[0334] In some embodiments, the first network element autonomously implements the function indicated by the first message, or the above function is a default or default value, in which case S201C can be omitted.
[0335] In some embodiments, the first message is used to request services to the terminal.
[0336] In some embodiments, the first message is used to instruct the second network element to request services to the terminal.
[0337] In some embodiments, the first message is used to request to become a service network element of the terminal.
[0338] In some embodiments, the first message is used to request the service network element of the terminal to be updated to be the second network element.
[0339] In some embodiments, the first message is used to request a service, and the first message includes an access token.
[0340] In some embodiments, the first message is used to request service resources, and the first message includes an access token.
[0341] In some embodiments, the first network element acts as a service producer (NF producer) to verify the access token provided by the service consumer, respond to the service consumer's requests, and provide the requested resources, etc.
[0342] In some embodiments, the second network element acts as a service consumer (NF Consumer), which initiates authentication requests to the authentication server to obtain an access token, and initiates requests carrying the access token to the service producer to obtain resources, etc.
[0343] In some embodiments, the first network element is a service producer, and the second network element is a service consumer. The first network element sends a first message to the second network element to request the resources required for the service. The first message carries an access token. Optionally, the first network element and the second network element belong to different networks. Optionally, the access token is obtained by the second network element from an authentication server belonging to the same network as the first network element through an authentication server belonging to the same network.
[0344] For example, the first network element is NF1 and the second network element is NF2. The first network element is an NF with the identity of a service producer, and the second network element is an NF with the identity of a service consumer. NF1 and NF2 are NFs in different networks. For example, the network to which NF1 belongs is PLMN1, and the network to which NF2 belongs is PLMN2. NRF1 and NF1 belong to the same network, and NRF2 and NF2 belong to the same network. NF2 obtains an access token from NRF1 through NRF2.
[0345] In some embodiments, the first message includes at least one of the following: terminal identification information; second network information to which the second network element belongs; and access token.
[0346] In this embodiment of the disclosure, the first message includes the terminal's identification information, wherein the identification information can be an identifier, such as at least one of GPSI, SUCI, and SUPI. In this case, the first message is used to request services for the terminal indicated by the terminal's identification information.
[0347] In this embodiment of the disclosure, the first message includes second network information to which the second network element belongs. The second network information may be an identifier of the public land mobile network (PLMN) to which the second network element belongs, or an identifier of the second network element itself, etc.
[0348] In some embodiments, the second network element determines to send the first message to the first network element on its own, or determines to send the first message to the first network element based on the instruction information sent by the first network element, or the second network element determines to send the first message to the first network element based on the agreement.
[0349] For example, if the second network element determines on its own or based on the agreement that it needs to provide services to the terminal, it determines to send the first message to the first network element.
[0350] For example, when the second network element receives an instruction from the first network element indicating that the second network element will provide services to the terminal, the second network element may send a first message to the first network element.
[0351] In some embodiments, the second network element may reuse existing signaling or messages to send a first message to the first network element, or send a first message to the first network element using new signaling or messages.
[0352] S202C, the first network element sends a second message to the third network element.
[0353] In some embodiments, the third network element receives the second message sent by the first network element, but is not limited thereto. The third network element may also receive the second message sent by other entities other than the first network element, in which case S202C can be omitted.
[0354] In some embodiments, the third network element obtains the second message specified by the protocol, in which case S202C can be omitted.
[0355] In some embodiments, the third network element obtains the second message from the upper layer(s), in which case S202C can be omitted.
[0356] In some embodiments, the third network element processes the data to obtain the second message, in which case S202C can be omitted.
[0357] In some embodiments, the third network element autonomously implements the function indicated by the second message, or the above function is a default or default value, in which case S202C can be omitted.
[0358] In some embodiments, the second message is used to request the third network element to verify whether the second network element is the serving network element of the terminal.
[0359] In some embodiments, the second message is used to request the third network element to provide a verification result as to whether the second network element is the serving network element of the terminal.
[0360] In some embodiments, the second message is used to request the third network element to confirm whether the second network element is the serving network element of the terminal.
[0361] In some embodiments, the third network element is used to manage terminal identifiers, subscription data, authentication data, etc., and is also responsible for the service network element registration management of the terminal, and stores the terminal's subscription information. In this embodiment, the terminal's context is also stored.
[0362] In some embodiments, the third network element is a UDM, or a network element in 6G that manages or stores terminal status information.
[0363] In some embodiments, the second message includes at least one of the following: terminal identification information, second network information to which the second network element belongs, resource range information requested from the service provider, and the NF type of the requested service provider.
[0364] In this embodiment of the disclosure, the second message includes the terminal's identification information, wherein the identification information can be an identifier, such as at least one of the following: a generic public subscription identifier (GPSI), a subscription concealed identifier (SUCI), and a subscriber permanent ID (SUPI).
[0365] In this embodiment of the disclosure, the second message includes second network information to which the second network element belongs. The second network information may be the identifier of the PLMN or the identifier of the second network element.
[0366] In some embodiments, a first network element receives a first message sent by a second network element. If the first message requests to provide services to a terminal and the first network element and the second network element belong to different networks, the first network element sends a second message to a third network element.
[0367] In some embodiments, a first network element receives a first message sent by a second network element. If the first message requests to provide services to the terminal and the access token carried by the second network element is verified by the first network element, the first network element sends a second message to a third network element.
[0368] In some embodiments, a first network element receives a first message sent by a second network element, the first message requesting to provide services to the terminal. If the access token carried by the second network element is verified by the first network element and the first and second network elements belong to different networks, the first network element sends a second message to a third network element.
[0369] In some embodiments, the first network element may reuse existing signaling or messages to send a second message to the third network element, or send a second message to the third network element using new signaling or messages.
[0370] S203C, the third network element determines the terminal's first network information and the second network information to which the second network element belongs based on the terminal's authentication status information. Based on the first and second network information, it determines whether the second network element is the verification result of the terminal's serving network element.
[0371] In this embodiment of the disclosure, the third network element stores the authentication status information of the terminal. The authentication status information of the terminal includes the terminal's first network information, which includes at least one of the terminal's access network information (information of the access network that the terminal has successfully authenticated) and the terminal's home network information (information of the terminal's home network).
[0372] In some embodiments, the terminal's authentication status information includes at least one of the following: the terminal's identification information, the authentication result, the time corresponding to the authentication result, and the network information used for authentication. The terminal's authentication status information can be used to determine the information of the network to which the terminal has most recently successfully authenticated.
[0373] In some embodiments, the third network element receives a second message sent by the second network element. If the second message is used to request the third network element to verify whether the second network element is a serving network element of the terminal, the third network element can determine the first network information of the terminal based on the terminal's authentication status information, and determine the second network information to which the second network element belongs. Furthermore, based on the first network information and the second network information, the third network element can determine the verification result of whether the second network element is a serving network element of the terminal.
[0374] It is understandable that the terminal may be in a roaming state, that is, outside the coverage area of the home network. In order to achieve communication, the terminal will access other networks outside the home network.
[0375] In some embodiments, the first network information is at least one of access network information and home network information.
[0376] In this embodiment, the terminal's first network information is the terminal's access network information, which is the information corresponding to the network to which the terminal recently successfully completed the authentication process. Optionally, the terminal's access network information is the identifier of the PLMN that the terminal is currently accessing and that has successfully completed the authentication process. For example, if the terminal accesses PLMN1 and successfully completes the two-way authentication process at time T1, and then moves to PLMN2 and successfully completes the two-way authentication process, the third network element stores the information of PLMN2 and determines the information of PLMN2 as the terminal's first network information. Alternatively, if the terminal accesses PLMN1 and successfully completes the two-way authentication process at time T1, and then moves to PLMN2 but fails to complete the two-way authentication process, the third network element stores the information of PLMN1 and determines the information of PLMN1 as the terminal's first network information.
[0377] In this embodiment of the disclosure, the first network information of the terminal is the terminal's home network information, wherein the home network information can be information about the terminal's home network. Optionally, the terminal's home network information is the identifier of the PLMN to which the terminal belongs.
[0378] In some embodiments, the first message includes second network information to which the second network element belongs, and the first network element can determine the second network information to which the second network element belongs based on the first message.
[0379] In some embodiments, the third network element determines the first network information of the terminal and the second network information to which the second network element belongs. If the first network information and the second network information indicate the same network, the second network element is determined to be the serving network element of the terminal; conversely, if the first network information and the second network information indicate different networks, the second network element is determined not to be the serving network element of the terminal.
[0380] For example, the third network element determines that the first network information of the terminal is PLMN identifier (ID) #1, and the second network information of the second network element is PLMN ID #1. Since PLMN ID #1 is the same network, the second network element can be determined to be the serving network element of the terminal.
[0381] For example, if the third network element determines that the first network information of the terminal is PLMN identifier (ID) #1 and the second network information of the second network element is PLMN ID #2, and PLMN ID #1 and PLMN ID #2 are different networks, then it can be determined that the second network element is not the serving network element of the terminal.
[0382] S204C, the third network element sends a third message to the first network element.
[0383] In some embodiments, the first network element receives a third message sent by the third network element, but is not limited thereto. The first network element may also receive a third message sent by other entities other than the third network element, in which case S204C can be omitted.
[0384] In some embodiments, the first network element obtains a third message as specified by the protocol, in which case S204C can be omitted.
[0385] In some embodiments, the first network element obtains the third message from the upper layer(s), in which case S204C can be omitted.
[0386] In some embodiments, the first network element processes the data to obtain the third message, in which case S204C can be omitted.
[0387] In some embodiments, the first network element autonomously implements the function indicated by the third message, or the above function is a default or default value, in which case S204C can be omitted.
[0388] In some embodiments, the third message is used to indicate whether the second network element is the verification result of the terminal's serving network element.
[0389] In some embodiments, the third message is used to indicate that the second network element is the serving network element of the terminal.
[0390] In some embodiments, the third message is used to indicate that the second network element is not a serving network element of the terminal.
[0391] In some embodiments, the third message includes at least one bit, indicating that the second network element is a serving network element of the terminal when at least one bit is a first value, and indicating that the second network element is not a serving network element of the terminal when at least one bit is a second value.
[0392] In some embodiments, if the third message includes the first identifier, it indicates that the second network element is a serving network element of the terminal; if the third message does not include the first identifier, it indicates that the second network element is not a serving network element of the terminal.
[0393] In some embodiments, if the third network element determines in S203C whether the second network element is the service network element of the terminal, it sends a third message to the first network element.
[0394] In some embodiments, the third network element may reuse existing signaling or messages to send a third message to the first network element, or send a third message to the first network element using new signaling or messages.
[0395] In S205C, the first network element determines whether the second network element is the serving network element of the terminal based on the third message.
[0396] In this embodiment of the disclosure, the first network element receives a third message sent by the third network element, which can determine whether the second network element is the serving network element of the terminal.
[0397] In one possible implementation, when the third message is used to indicate that the second network element is the serving network element of the terminal, the first network element can determine that the second network element is the serving network element of the terminal.
[0398] In another possible implementation, if the third message is used to indicate that the second network element is not the serving network element of the terminal, the first network element can determine that the second network element is not the serving network element of the terminal.
[0399] In some embodiments, when the first network element determines that the second network element is the serving network element of the terminal, it sends the relevant data or resources of the service requested by the first network element to the second network element.
[0400] In some embodiments, if the first network element determines that the second network element is not a serving network element for the terminal, it sends a response message to the second network element. The response message is used to indicate that the second network element is refused to provide services to the terminal, or the response message is used to indicate an error.
[0401] The communication method involved in the embodiments of this disclosure may include at least one of S201C to S210C. For example, S201C may be implemented as a standalone embodiment, S202C may be implemented as a standalone embodiment, S203C may be implemented as a standalone embodiment, S204C may be implemented as a standalone embodiment, and S205C may be implemented as a standalone embodiment, but is not limited thereto.
[0402] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0403] Figure 2D is an interactive schematic diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 2D, the embodiments of the present disclosure relate to a communication method, which includes:
[0404] S201D, the second network element sends the first message to the first network element.
[0405] The optional implementations of S201D can be found in the optional implementations of S201C in Figure 2C, as well as other related parts in the embodiments involved in Figure 2C, which will not be repeated here.
[0406] S202D: The first network element sends the fourth message to the third network element.
[0407] In some embodiments, the third network element receives a fourth message sent by the first network element, but is not limited thereto. The third network element may also receive a fourth message sent by other entities other than the first network element, in which case S202D can be omitted.
[0408] In some embodiments, the third network element obtains the fourth message specified by the protocol, in which case S202D can be omitted.
[0409] In some embodiments, the third network element obtains the fourth message from the upper layer(s), in which case S202D can be omitted.
[0410] In some embodiments, the third network element processes the data to obtain the fourth message, in which case S202D can be omitted.
[0411] In some embodiments, the third network element autonomously implements the function indicated by the fourth message, or the above function is a default or default setting, in which case S202D can be omitted.
[0412] In some embodiments, the fourth message is used to request the authentication status information of the terminal.
[0413] In some embodiments, the fourth message is used to request at least one of the terminal's access network information and home network information.
[0414] In some embodiments, the fourth message is used to request network information of the terminal, including at least one of the terminal's access network information and home network information.
[0415] In some embodiments, the third network element is used to manage terminal identifiers, subscription data, authentication data, etc., and is also responsible for the service network element registration management of the terminal, and stores the terminal's subscription information. In this embodiment, the terminal's context is also stored.
[0416] In some embodiments, the third network element is a UDM, or a network element in 6G that manages or stores terminal status information.
[0417] In some embodiments, the fourth message includes: the terminal's identification information.
[0418] In this embodiment of the disclosure, the fourth message includes the terminal's identification information, wherein the identification information can be an identifier, such as at least one of the following: a generic public subscription identifier (GPSI), a subscription concealed identifier (SUCI), and a subscriber permanent ID (SUPI).
[0419] In some embodiments, if a first network element receives a first message sent by a second network element, and the first message requests to provide services to a terminal and the first network element and the second network element belong to different networks, the first network element sends a fourth message to a third network element.
[0420] In some embodiments, a first network element receives a first message sent by a second network element. If the first message requests to provide services to the terminal and the access token carried by the second network element is verified by the first network element, the first network element sends a fourth message to a third network element.
[0421] In some embodiments, the first network element receives a first message sent by the second network element, the first message requesting to provide services to the terminal. If the access token carried by the second network element is verified by the first network element and the first network element and the second network element belong to different networks, the first network element sends a fourth message to the third network element.
[0422] In some embodiments, the first network element may reuse existing signaling or messages to send a fourth message to the third network element, or send a fourth message to the third network element using new signaling or messages.
[0423] S203D, the third network element sends the fifth message to the first network element.
[0424] In some embodiments, the first network element receives a fifth message sent by the third network element, but is not limited thereto. The first network element may also receive a fifth message sent by other entities other than the third network element, in which case S203D can be omitted.
[0425] In some embodiments, the first network element obtains the fifth message specified by the protocol, in which case S203D can be omitted.
[0426] In some embodiments, the first network element obtains the fifth message from the upper layer(s), in which case S203D can be omitted.
[0427] In some embodiments, the first network element processes the data to obtain the fifth message, in which case S203D can be omitted.
[0428] In some embodiments, the first network element autonomously implements the function indicated by the fifth message, or the above function is a default or default value, in which case S203D can be omitted.
[0429] In some embodiments, the fifth message is used to indicate the authentication status information of the terminal.
[0430] In some embodiments, the terminal's authentication status information includes at least one of the following: the terminal's identification information, the authentication result, the time corresponding to the authentication result, and the network information used for authentication. The terminal's authentication status information can be used to determine the information of the network to which the terminal has most recently successfully authenticated.
[0431] In some embodiments, the fifth message is used to indicate at least one of the terminal's access network information and home network information.
[0432] In some embodiments, the fifth message is used to indicate network information of the terminal, including at least one of the terminal's access network information and home network information.
[0433] In some embodiments, when a third network element receives a fourth message from a first network element, it sends a fifth message to the first network element.
[0434] In some embodiments, if the third network element determines that the authentication status information of the terminal has changed, it sends a fifth message to the first network element.
[0435] In some embodiments, the third network element periodically sends a fifth message to the first network element.
[0436] In some embodiments, the third network element may reuse existing signaling or messages to send a fifth message to the first network element, or send a fifth message to the first network element using new signaling or messages.
[0437] S204D, the first network element determines the terminal's authentication status information based on the fifth message.
[0438] In this embodiment of the disclosure, the first network element receives a fifth message sent by the third network element and can determine the authentication status information of the terminal. For example, determining the terminal's network information includes at least one of the terminal's access network information and home network information.
[0439] S205D: The first network element determines the first network information of the terminal based on the first message and the terminal's authentication status information, determines the second network information to which the second network element belongs, and determines whether the second network element is the terminal's serving network element based on the first network information and the second network information.
[0440] In some embodiments, if the first network element stores the authentication status information of the terminal, the above S202D to S204D can be omitted.
[0441] In this embodiment of the disclosure, the authentication status information of the terminal includes the terminal's first network information, which includes at least one of the terminal's access network information (information of the access network to which the terminal has successfully authenticated) and the terminal's home network information (information of the terminal's home network).
[0442] In some embodiments, the first message includes second network information to which the second network element belongs, and the first network element can determine the second network information to which the second network element belongs based on the first message.
[0443] In some embodiments, the first network element determines the first network information of the terminal and the second network information to which the second network element belongs. If the first network information and the second network information indicate the same network, the second network element is determined to be the serving network element of the terminal; conversely, if the first network information and the second network information indicate different networks, the second network element is determined not to be the serving network element of the terminal.
[0444] For example, the first network element determines that the first network information of the terminal is PLMN ID#1, and the second network information of the second network element is PLMN ID#1. Since PLMN ID#1 is the same network, the second network element can be determined to be the serving network element of the terminal.
[0445] For example, if the first network element determines that the first network information of the terminal is PLMN ID#1 and the second network information of the second network element is PLMN ID#2, and PLMN ID#1 and PLMN ID#2 are different networks, then it can be determined that the second network element is not the serving network element of the terminal.
[0446] The communication method involved in the embodiments of this disclosure may include at least one of S201D to S205D. For example, S201D may be implemented as a standalone embodiment, S202D may be implemented as a standalone embodiment, S203D may be implemented as a standalone embodiment, S204D may be implemented as a standalone embodiment, and S205D may be implemented as a standalone embodiment, but is not limited thereto.
[0447] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0448] Figure 3A is a schematic diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3A, the present disclosure relates to a communication method, which includes:
[0449] S301A, the second network element sends the first message to the first network element.
[0450] In some embodiments, the first message is used to instruct the second network element to request services to the terminal.
[0451] The optional implementations of S301A can be found in the optional implementations of S201A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0452] The optional implementation of S301A can be found in the optional implementation of S201B in Figure 2B and other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0453] S302A: The first network element determines whether the second network element is the serving network element of the terminal based on the first message.
[0454] The optional implementations of S302A can be found in the optional implementations of S202A to S205A in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0455] The optional implementations of S302A can be found in the optional implementations of S202B to S205B in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0456] In some embodiments, the first network element determines whether the second network element is a serving network element of the terminal based on the first message, including: sending a second message to a third network element based on the first message, wherein the second message is used to request the third network element to verify whether the second network element is a serving network element of the terminal; receiving a third message sent by the third network element, wherein the third message is used to indicate the verification result of whether the second network element is a serving network element of the terminal; and determining whether the second network element is a serving network element of the terminal based on the third message.
[0457] In some embodiments, the first network element determines whether the second network element is a serving network element of the terminal based on the first message, including: determining the terminal's first network information based on the first message and the terminal's authentication status information, wherein the first network information is at least one of access network information and home network information; determining the second network information to which the second network element belongs; and determining whether the second network element is a serving network element of the terminal based on the first network information and the second network information.
[0458] In some embodiments, the method further includes: a first network element sending a fourth message to a third network element, wherein the fourth message is used to request the acquisition of the terminal's authentication status information; receiving a fifth message sent by the third network element, wherein the fifth message is used to indicate the terminal's authentication status information; and determining the terminal's authentication status information based on the fifth message.
[0459] In some embodiments, the first message is further used to request an access token, wherein the above method further includes: the first network element determining the second network element as the serving network element of the terminal, generating an access token; and sending a sixth message to the second network element, wherein the sixth message includes the access token.
[0460] In some embodiments, the above method further includes: the first network element determining that the second network element has changed from a serving network element of the terminal to a non-serving network element, and revoking the access token.
[0461] In some embodiments, the first network element determines that the second network element has changed from a serving network element of the terminal to a non-serving network element, including: sending a seventh message to a third network element, wherein the seventh message is used to subscribe to the terminal's authentication status information; receiving an eighth message sent by the third network element, wherein the eighth message is used to indicate the terminal's updated authentication status information, wherein the terminal's updated authentication status information is used to indicate that the second network element is not a serving network element of the terminal; and determining that the second network element has changed from a serving network element of the terminal to a non-serving network element based on the terminal's updated authentication status information.
[0462] In some embodiments, the access token includes the terminal's identification information.
[0463] In some embodiments, the first message includes at least one of the following: identification information of the terminal; and second network information to which the second network element belongs.
[0464] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.
[0465] Figure 3B is a schematic diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3B, the present disclosure relates to a communication method, which includes:
[0466] S301B: The first network element sends a second or fourth message to the third network element.
[0467] In some embodiments, the second message is used to request the third network element to verify whether the second network element is a serving network element of the terminal, and the fourth message is used to request to obtain the authentication status information of the terminal. The second message or the fourth message is sent by the first network element after receiving the first message sent by the second network element. The first message is used to instruct the second network element to request to provide services to the terminal.
[0468] The optional implementation of S301B can be found in the optional implementation of S202A in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0469] The optional implementation of S301B can be found in the optional implementation of S202B in Figure 2B and other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0470] In some embodiments, the method further includes: a third network element determining first network information of the terminal based on the terminal's authentication status information, wherein the first network information is at least one of access network information and home network information; determining second network information to which the second network element belongs; determining an authentication result based on the first network information and the second network information; and sending a third message to the first network element, wherein the third message is used to indicate whether the second network element is the verification result of the terminal's serving network element.
[0471] In some embodiments, the method further includes: a third network element sending a fifth message to a first network element, wherein the fifth message is used to indicate the authentication status information of the terminal.
[0472] In some embodiments, the first message is further used to request an access token, and the method further includes: a third network element receiving a seventh message sent by a first network element, wherein the seventh message is used to subscribe to the authentication status information of the terminal; and sending an eighth message to the first network element, wherein the eighth message is used to indicate the updated authentication status information of the terminal, wherein the updated authentication status information of the terminal is used by the first device to determine that the second network element is not the serving network element of the terminal.
[0473] In some embodiments, the access token includes the terminal's identification information.
[0474] In some embodiments, the first message includes at least one of the following: identification information of the terminal; and second network information to which the second network element belongs.
[0475] Figure 3C is a schematic diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3C, the present disclosure relates to a communication method, which includes:
[0476] S301C, the first network element sends the sixth message to the second network element.
[0477] The optional implementation of S301C can be found in the optional implementation of S207A in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0478] S302C, the first network element sends the seventh message to the third network element.
[0479] S302C can be executed simultaneously with S301C or executed in an alternate order.
[0480] The optional implementation of S302C can be found in the optional implementation of S208A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0481] S303C, the third network element sends the eighth message to the first network element.
[0482] The optional implementation of S303C can be found in the optional implementation of S209A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0483] S304C, the first network element determines, based on the eighth message, that the second network element has been changed from the terminal's serving network element to a non-serving network element, and revokes the access token.
[0484] The optional implementation of S304C can be found in the optional implementation of S210A in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0485] To facilitate understanding of the embodiments of this disclosure, an exemplary embodiment is provided.
[0486] In an exemplary embodiment, 5G offers better security compared to 4G by strengthening home control to prevent certain types of fraud. When the home network receives a request from the visited network-as-a-service (SN), the home network is able to verify whether the device is indeed being served by the visited network.
[0487] This increased attribution control appears in 5GS in the following form:
[0488] - For EAP-AKA', when the EAP-Response / AKA'-Challenge received by the AUSF is successfully verified, the AUSF in the home network will be confirmed, that is, the UE has successfully authenticated its identity through the specific serving network.
[0489] - For 5G AKA, when the AUSF receives the authentication confirmation in the Nausf_UEAuthentication_Authenticate request message and it is successfully verified, the AUSF in the home network obtains confirmation that the UE has successfully completed authentication through a certain serving network.
[0490] By storing the UE's authentication state (subscription permanent identifier (SUPI), authentication result, timestamp, and service network name), the UDM can detect fraudulent attacks from NFs in the guest network. For example, the UDM can identify a fraudulent Nudm_UECM_Registration Request message that attempts to register a guest network NF in the home network's UDM, claiming that the network is serving a user who is not actually in the claimed NF network. In this case, linking the UE's authentication state to subsequent processes provides the necessary protection against fraudulent NF registration.
[0491] However, the added home control is only considered during the UE registration process. The NF creator in the Home PLMN (HPLMN) does not mandate a check of the UE's authentication status for each request received from an NF consumer in another PLMN. Therefore, such fraudulent attacks can still be launched in 5G. For example, a fraudulent NF consumer claims to be the UE's serving NF and sends a Nudm_SDM_Get request to the NF producer (e.g., UDM). If the NF consumer's serving PLMN is not associated with the UE's authentication status, the NF producer cannot determine whether the request originates from an NF in the network the UE is accessing, allowing the fraudulent NF consumer to obtain the UE's subscription data. This fraudulent attack could potentially infringe on subscriber privacy.
[0492] In some embodiments, as shown in Figure 4A, how to authorize service access in roaming scenarios is specified.
[0493] 2. The NRF in the accessing PLMN should verify the input parameters in the access token request. If the parameter verification in the access token request fails, the access token request will not be processed further. After successful verification of the input parameters, the vNRF should identify the NRF in the home PLMN (hNRF) based on the home PLMN ID and request an access token from the hNRF. The vNRF should forward the parameters it obtains from the NF service consumer (including the NF service consumer type) to the hNRF.
[0494] 3. hNRF checks whether the NF service consumer is authorized to access the requested service. If the NF service consumer is authorized, hNRF should generate an access token containing the appropriate claim. hNRF should digitally sign the generated access token using a shared key or private key. If the NF service consumer is not authorized, hNRF will not issue an access token to the NF service consumer.
[0495] As described in steps 2 and 3, service access authorization is independent of the UE authentication status. If the hNRF determines that an NF consumer in PLMN A is allowed to access the service, the hNRF will generate an access token for the NF consumer in PLMN A. In this case, a fraudulent NF consumer claiming to be the UE's NF can still obtain the UE's privacy-sensitive information from the NF producer in the HPLMN.
[0496] The main objectives of this disclosure are as follows:
[0497] - Enable NF producers in the UE HPLMN to verify that requests from NF consumers do indeed originate from the network accessed by the UE.
[0498] - Link the UE authentication status with service access authorization.
[0499] For example, as shown in Figure 4B, a service request process is provided.
[0500] 1. The NF service consumer should request an access token from the NRF within the same PLMN. The request includes the NF instance ID of the NF service consumer, the requested "scope" (including the expected NF service name and optional "other scope" information) (i.e., the requested resource and the requested operation (service operation) on the resource), the NF type of the expected NF service producer instance, the NF type of the NF service consumer, the home PLMN ID and the service PLMN ID, the PLMN ID of the NF consumer, the UE identifier, the S-NSSAI list or NSI ID list (optional) of the expected NF service producer instance, and the NF set ID and / or NF service set ID of the expected NF service producer instance.
[0501] 2. The NRF in the accessing PLMN should verify the input parameters in the access token request. If the parameter verification fails, the access token request will not be processed further. After successful verification of the input parameters, the NRF in PLMN A should identify the NRF in the home PLMN (hNRF) based on the home PLMN ID and request an access token from the hNRF. The NRF in PLMN A should forward the parameters (including the NF service consumer type) it obtained from the NF service consumer to the hNRF.
[0502] 3.hNRF checks whether the NF service consumer has the right to access the requested service.
[0503] hNRF can determine whether the PLMN ID provided by the NF consumer is the same as the PLMN ID accessed by the UE based on the latest UE authentication status. If the NF consumer's PLMN ID is the same as the PLMN ID accessed by the UE, hNRF determines that the NF service consumer is authorized. Otherwise, authorization fails.
[0504] hNRF can obtain the UE authentication status using one of the following methods:
[0505] After receiving the access token request, -hNRF will send the request to UDM to obtain the latest UE authentication status.
[0506] -hNRF can store UE authentication status locally and use the stored UE authentication status to determine [the authentication status].
[0507] Alternatively, hNRF can send a request to UDM, including the PLMN ID of the NF consumer, and have UDM determine whether the NF consumer's PLMN ID is the same as the UE's vPLMN ID.
[0508] 4. If the NF service consumer is authorized, hNRF shall generate an access token containing an appropriate claim. hNRF shall digitally sign the generated access token using a shared key or private key. If the NF service consumer is not authorized, hNRF shall not issue an access token to the NF service consumer.
[0509] The token's claim should include the NRF (issuer's) NF instance ID, the NF service consumer's NF instance ID plus its PLMN ID (consumer), the NF service producer's NF type plus its PLMN ID (audience), the intended service name (scope), and expiration time (expiration), as well as optional "other scope" information (allowed resources and allowed actions on those resources (service actions)). The claim may include single network slice selection assistance information (S-NSSAI) or a list of network slice instance (NSI) IDs for the intended NF service creator instance. The claim may include the NF set ID and / or NF service set ID for the intended NF service producer instance. The claim may include the UE identifier.
[0510] 5. If authorization is successful, the access token should be included in the vNRF Nnrf_AccessToken_Get response message. Otherwise, it will respond according to the OAuth 2.0 error response.
[0511] 6. vNRF should forward the Access Token Get (Nnrf_AccessToken_Get) response or error message to the NF service consumer. The NF service consumer can store the received token. The stored token can be reused for services of the NF service provider type listed in the access claims (scope, audience).
[0512] 7. An NF service consumer requests a service from an NF service producer. The NF service consumer should include an access token.
[0513] NF service consumers and NF service producers should authenticate each other.
[0514] 8. NF service providers shall verify tokens in accordance with the method specified in TS 33.501.
[0515] 9. If authentication is successful, the NF service producer should execute the requested service and respond to the NF service consumer. Otherwise, it will respond according to the OAuth 2.0 error response.
[0516] For example, an access token revocation method is provided. Assume: hNRF subscribes to the UE authentication state from UDM. If the UE authentication state changes, UDM sends a notification message to hNRF. The notification message may contain the latest UE authentication state. Upon receiving the notification message from UDM (e.g., moving the UE to another vPLMN), hNRF updates the stored UE authentication state and revoks the access token previously generated for the NF in the UE's previous vPLMN.
[0517] As exemplarily shown in Figure 4C, another service request flow is provided.
[0518] 1. NF service consumers should request access tokens from the NRF within the same PLMN. The request includes the NF instance ID of the NF service consumer, the requested "scope" (including the expected NF service name and optional "other scope" information) (i.e., the requested resource and the requested operation on the resource (service operation)), the NF type of the expected NF service producer instance, the NF type of the NF service consumer, the home PLMN ID and the service PLMN ID, the PLMN ID of the NF consumer, the S-NSSAI list or NSI ID list (optional) of the expected NF service producer instance, and the NF set ID and / or NF service set ID of the expected NF service producer instance.
[0519] 2. The NRF in the accessing PLMN should verify the input parameters in the access token request. If the parameter verification fails, the access token request will not be processed further. After successful verification of the input parameters, the NRF in PLMN A should identify the NRF in the home PLMN (hNRF) based on the home PLMN ID and request an access token from the hNRF. The NRF in PLMN A should forward the parameters (including the NF service consumer type) it obtained from the NF service consumer to the hNRF.
[0520] 3. The hNRF checks whether the NF service consumer is authorized to access the requested service. If the NF service consumer is authorized, the hNRF should generate an access token containing appropriate claims. The hNRF should digitally sign the generated access token using a shared key or private key. If the NF service consumer is not authorized, the hNRF will not issue an access token to the NF service consumer. The claims contained in the token should follow the method specified in TS 33.501.
[0521] 4. If authorization is successful, the access token should be included in the vNRF Nnrf_AccessToken_Get response message. Otherwise, it will respond according to the OAuth 2.0 error response.
[0522] 5. vNRF should forward the Access Token Get (Nnrf_AccessToken_Get) response or error message to the NF service consumer. The NF service consumer can store the received token. The stored token can be reused for services of the NF service provider type listed in the access claims (scope, audience).
[0523] 6. An NF service consumer requests a service from an NF service producer. The NF service consumer should include an access token.
[0524] NF service consumers and NF service producers should authenticate each other.
[0525] 7.NF service providers shall verify tokens in accordance with the method specified in TS 33.501.
[0526] 8. After successful access token verification, the NF producer in the HPLMN performs UE authentication status verification. The NF producer can interact with the UDM to obtain the UE authentication status or verification result. The NF producer can obtain the UE authentication status through one of the following methods:
[0527] -NF producers will send requests to UDM to obtain the latest UE certification status.
[0528] -NF producers can store UE authentication status locally and use the stored UE authentication status to determine [the status].
[0529] Alternatively, the NF producer can send a request to the UDM, including the NF consumer's PLMN ID, and have the UDM determine whether the NF consumer's PLMN ID is the same as the UE's vPLMN ID.
[0530] 9. If authentication is successful, the NF service producer should execute the requested service and respond to the NF service consumer. Otherwise, it will respond according to the OAuth 2.0 error response.
[0531] In some embodiments, the hNRF should be able to determine whether the NF consumer is from the UE’s most recently authenticated access PLMN before generating an access token for the NF consumer.
[0532] In some embodiments, hNRF should be able to revoke the generated access token after the UE authentication status changes.
[0533] In some embodiments, hNRF should be able to subscribe to the UE authentication status to UDM.
[0534] In some embodiments, if the NF consumer and the NF producer belong to different PLMNs, the NF producer should be able to determine whether the NF consumer is from the UE’s most recently authenticated access PLMN before providing the requested data to the NF consumer.
[0535] In some embodiments, the UDM should be able to provide the hNRF with the latest UE authentication status.
[0536] In some embodiments, if the UE authentication status changes, the UDM should be able to notify the subscribed hNRF.
[0537] This disclosure also proposes an apparatus (also referred to as a communication device, etc.) for implementing any of the above methods. For example, an apparatus is proposed, which includes units or modules for implementing the steps performed by the first network element in any of the above methods. Furthermore, another apparatus is proposed, which includes units or modules for implementing the steps performed by the second network element in any of the above methods.
[0538] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0539] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).
[0540] Figure 5A is a schematic diagram of the structure of the first network element proposed in an embodiment of this disclosure. As shown in Figure 5A, the first network element 10 may include at least one of a transceiver module 11, a processing module 12, etc.
[0541] In some embodiments, the transceiver module 11 is configured to receive a first message, wherein the first message is configured to instruct a second network element to request to provide services to the terminal; and the processing module 12 is configured to determine, based on the first message, whether the second network element is a service network element of the terminal.
[0542] Optionally, the transceiver module 11 is used to perform at least one of the communication steps such as sending and / or receiving performed by the first network element 10 in any of the above methods (e.g., the communication steps such as sending and / or receiving performed by the first network element in S201A~S210A, S201B~S210B, S201C~S205C, S201D~S205D, S301A~S302A, S301B, S301C~S304C, but not limited thereto), which will not be elaborated here. Optionally, the processing module 12 is used to execute at least one of the other steps executed by the first network element 10 in any of the above methods (e.g., other steps besides the communication steps such as sending and / or receiving executed by the first network element in S201A~S210A, S201B~S210B, S201C~S205C, S201D~S205D, S301A~S302A, S301B, S301C~S304C, but not limited thereto), which will not be elaborated here.
[0543] In some embodiments, the transceiver module may include a sending module and / or a receiving module, which may be separate or integrated together.
[0544] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module.
[0545] In some embodiments, the processing module can be replaced by the processor, and the transceiver module can be replaced by the transceiver.
[0546] Figure 5B is a schematic diagram of the structure of the second network element proposed in an embodiment of this disclosure. As shown in Figure 5B, the second network element 20 may include at least one of a transceiver module 21, a processing module 22, etc.
[0547] In some embodiments, the transceiver module 21 is configured to send a first message, wherein the first message is configured to instruct the second network element to request to provide services to the terminal, and the first message is configured by the first network element to determine whether the second network element is a service network element of the terminal.
[0548] Optionally, the transceiver module 21 is used to perform at least one of the communication steps such as sending and / or receiving performed by the second network element 20 in any of the above methods (e.g., the communication steps such as sending and / or receiving performed by the second network element in S201A~S210A, S201B~S210B, S201C~S205C, S201D~S205D, S301A~S302A, S301B, S301C~S304C, but not limited thereto), which will not be elaborated here. Optionally, the processing module 22 is used to perform at least one of the other steps performed by the second network element 20 in any of the above methods (e.g., other steps besides the communication steps such as sending and / or receiving performed by the second network element in S201A~S210A, S201B~S210B, S201C~S205C, S201D~S205D, S301A~S302A, S301B, S301C~S304C, but not limited thereto), which will not be elaborated here.
[0549] In some embodiments, the transceiver module may include a sending module and / or a receiving module, which may be separate or integrated together.
[0550] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module.
[0551] In some embodiments, the processing module can be replaced by the processor, and the transceiver module can be replaced by the transceiver.
[0552] Figure 5C is a schematic diagram of the structure of the third network element proposed in an embodiment of this disclosure. As shown in Figure 5C, the third network element 30 may include at least one of a transceiver module 31, a processing module 32, etc.
[0553] In some embodiments, the transceiver module 31 is configured to receive a second message or a fourth message, wherein the second message is configured to request a third network element to verify whether the second network element is a serving network element of the terminal, and the fourth message is configured to request to obtain the authentication status information of the terminal. The second message or the fourth message is sent by the first network element after receiving a first message sent by the second network element, and the first message is configured to instruct the second network element to request to provide services to the terminal.
[0554] Optionally, the transceiver module 31 is used to perform at least one of the communication steps such as sending and / or receiving performed by the third network element 30 in any of the above methods (e.g., the communication steps such as sending and / or receiving performed by the third network element in S201A~S210A, S201B~S210B, S201C~S205C, S201D~S205D, S301A~S302A, S301B, S301C~S304C, but not limited to these), which will not be elaborated here. Optionally, the processing module 32 is used to perform at least one of the other steps performed by the third network element 30 in any of the above methods (e.g., other steps besides the communication steps such as sending and / or receiving performed by the third network element in S201A~S210A, S201B~S210B, S201C~S205C, S201D~S205D, S301A~S302A, S301B, S301C~S304C, but not limited thereto), which will not be elaborated here.
[0555] In some embodiments, the transceiver module may include a sending module and / or a receiving module, which may be separate or integrated together.
[0556] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module.
[0557] In some embodiments, the processing module can be replaced by the processor, and the transceiver module can be replaced by the transceiver.
[0558] Figure 6A is a schematic diagram of the structure of the communication device 5100 proposed in an embodiment of this disclosure. The communication device 5100 can be a first network element, a second network element, a chip, chip system, or processor that supports the first network element in implementing any of the above methods, or a chip, chip system, or processor that supports the second network element in implementing any of the above methods. The communication device 5100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0559] As shown in Figure 6A, the communication device 5100 is used to execute any of the above methods. In some embodiments, the communication device 5100 includes one or more processors 5101. The processor 5101 may be a general-purpose processor or a special-purpose processor, such as a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, and the central processing unit may be used to control communication devices (e.g., base stations, baseband chips, terminals, terminal chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 5100 is used to execute any of the above methods. Optionally, one or more processors 5101 are used to invoke instructions to cause the communication device 5100 to execute any of the above methods.
[0560] In some embodiments, the communication device 5100 further includes one or more transceivers 5102. When the communication device 5100 includes one or more transceivers 5102, the transceiver 5102 performs at least one of the communication steps such as sending and / or receiving in the above-described method (e.g., the sending and / or receiving steps in S201A-S210A, S201B-S210B, S201C-S205C, S201D-S205D, S301A-S302A, S301B, S301C-S304C, but not limited thereto), and the processor 5101 performs at least one of the other steps (e.g., other steps besides sending and / or receiving in S201A-S210A, S201B-S210B, S201C-S205C, S201D-S205D, S301A-S302A, S301B, S301C-S304C, but not limited thereto). In optional embodiments, the transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, interface, etc., can be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., can be used interchangeably; the terms receiver, receiving unit, receiver, receiving circuit, etc., can be used interchangeably.
[0561] In some embodiments, the communication device 5100 further includes one or more memories 5103 for storing data and / or instructions. Optionally, one or more processors 5101 are used to invoke instructions stored in the memory 5103 to cause the communication device 5100 to perform any of the above methods. Optionally, all or part of the memory 5103 may also be located outside the communication device 5100. In an optional embodiment, the communication device 5100 may include one or more interface circuits 5104. Optionally, the interface circuit 5104 is connected to the memory 5103 and can be used to receive data and / or instructions from the memory 5103 or other devices, and can be used to send data and / or instructions to the memory 5103 or other devices. For example, the interface circuit 5104 can read data and / or instructions stored in the memory 5103 and send the data and / or instructions to the processor 5101.
[0562] The communication device 5100 described in the above embodiments may be a first network element or a second network element, but the scope of the communication device 5100 described in this disclosure is not limited thereto, and the structure of the communication device 5100 may not be limited by FIG. 6A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: (1) an independent integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data, programs and / or instructions; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal, smart terminal, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0563] Figure 6B is a schematic diagram of the structure of the chip 5200 proposed in an embodiment of this disclosure. For cases where the communication device 5100 can be a chip or a chip system, please refer to the schematic diagram of the chip 5200 shown in Figure 6B, but it is not limited thereto.
[0564] Chip 5200 includes one or more processors 5201. Chip 5200 is used to perform any of the methods described above.
[0565] In some embodiments, chip 5200 further includes one or more interface circuits 5202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 5200 further includes one or more memories 5203 for storing data and / or instructions. Optionally, all or part of the memories 5203 may be located outside of chip 5200. Optionally, the interface circuit 5202 is connected to the memories 5203, and the interface circuit 5202 can be used to receive data and / or instructions from the memories 5203 or other devices, and the interface circuit 5202 can be used to send data and / or instructions to the memories 5203 or other devices. For example, the interface circuit 5202 can read data and / or instructions stored in the memories 5203 and send the data and / or instructions to the processor 5201.
[0566] In some embodiments, the interface circuit 5202 performs at least one of the communication steps such as sending and / or receiving in the above-described method (e.g., the sending and / or receiving steps in S201A-S210A, S201B-S210B, S201C-S205C, S201D-S205D, S301A-S302A, S301B, S301C-S304C, but not limited thereto). The interface circuit 5202 performing the communication steps such as sending and / or receiving in the above-described method refers, for example, to the interface circuit 5202 performing data and / or instruction interaction between the processor 5201, chip 5200, memory 5203, or transceiver device. In some embodiments, the processor 5201 performs at least one of other steps (e.g., steps other than sending and / or receiving in S201A-S210A, S201B-S210B, S201C-S205C, S201D-S205D, S301A-S302A, S301B, S301C-S304C, but not limited thereto).
[0567] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.
[0568] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0569] This disclosure also proposes a program product, including a program and / or instructions, which, when executed by a communication device, cause the communication device to perform any of the above methods. Optionally, the program product is a computer program product. Optionally, the program product is stored on the storage medium.
[0570] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
[0571] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0572] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0573] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. A communication method, characterized in that, The method is executed by the first network element and includes: Receive a first message, wherein the first message is used to instruct the second network element to request to provide services to the terminal; Based on the first message, determine whether the second network element is the serving network element of the terminal.
2. The method as described in claim 1, characterized in that, The step of determining whether the second network element is the serving network element of the terminal based on the first message includes: According to the first message, a second message is sent to the third network element, wherein the second message is used to request the third network element to verify whether the second network element is the serving network element of the terminal; Receive a third message sent by the third network element, wherein the third message is used to indicate the verification result of whether the second network element is the serving network element of the terminal; Based on the third message, it is determined whether the second network element is the serving network element of the terminal.
3. The method as described in claim 1, characterized in that, The step of determining whether the second network element is the serving network element of the terminal based on the first message includes: Based on the first message and the authentication status information of the terminal, the first network information of the terminal is determined, wherein the first network information is at least one of access network information and home network information; Determine the second network information to which the second network element belongs; Based on the first network information and the second network information, determine whether the second network element is a serving network element of the terminal.
4. The method as described in claim 3, characterized in that, The method further includes: Send a fourth message to a third network element, wherein the fourth message is used to request the authentication status information of the terminal; The terminal receives a fifth message sent by the third network element, wherein the fifth message is used to indicate the authentication status information of the terminal. The authentication status information of the terminal is determined based on the fifth message.
5. The method according to any one of claims 1 to 4, characterized in that, The first message is also used to request an access token.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: The second network element is identified as the serving network element of the terminal, and an access token is generated; Send a sixth message, wherein the sixth message includes the access token.
7. The method as described in claim 6, characterized in that, The method further includes: If the second network element is determined to have changed from a serving network element of the terminal to a non-serving network element, the access token is revoked.
8. The method as described in claim 7, characterized in that, The step of determining that the second network element has been changed from a serving network element of the terminal to a non-serving network element includes: Send a seventh message to a third network element, wherein the seventh message is used to subscribe to the authentication status information of the terminal; The system receives an eighth message sent by the third network element, wherein the eighth message is used to indicate the updated authentication status information of the terminal, and the updated authentication status information of the terminal is used to indicate that the second network element is not the serving network element of the terminal. Based on the updated authentication status information of the terminal, it is determined that the second network element has been changed from a serving network element of the terminal to a non-serving network element.
9. The method according to any one of claims 6 to 8, characterized in that, The access token includes the terminal's identification information.
10. The method according to any one of claims 1 to 9, characterized in that, The first message includes at least one of the following: The terminal's identification information; The second network information to which the second network element belongs.
11. A communication method, characterized in that, The method is executed by the second network element and includes: Send a first message, wherein the first message is used to instruct the second network element to request to provide services to the terminal, and the first message is used to determine whether the second network element is a service network element of the terminal.
12. The method as described in claim 11, characterized in that, The first message is also used to request an access token, wherein the method further includes: A sixth message is received, wherein the sixth message includes the access token, which is generated by the first network element when it determines that the second network element is the serving network element of the terminal.
13. The method as described in claim 12, characterized in that, The access token includes the terminal's identification information.
14. The method according to any one of claims 11 to 13, characterized in that, The first message includes at least one of the following: The terminal's identification information; The second network information to which the second network element belongs.
15. A communication method, characterized in that, The method is executed by a third network element and includes: Receive a second message or a fourth message, wherein the second message is used to request the third network element to verify whether the second network element is a serving network element of the terminal, and the fourth message is used to request to obtain the authentication status information of the terminal. The second message or the fourth message is sent by the first network element after receiving the first message sent by the second network element, and the first message is used to instruct the second network element to request to provide services to the terminal.
16. The method as described in claim 15, characterized in that, The method further includes: Based on the authentication status information of the terminal, the first network information of the terminal is determined, wherein the first network information is at least one of access network information and home network information; Determine the second network information to which the second network element belongs; Based on the first network information and the second network information, determine whether the second network element is the verification result of the serving network element of the terminal; A third message is sent to the first network element, wherein the third message is used to indicate whether the second network element is the verification result of the serving network element of the terminal.
17. The method as described in claim 15, characterized in that, The method further includes: A fifth message is sent to the first network element, wherein the fifth message is used to indicate the authentication status information of the terminal.
18. The method according to any one of claims 15 to 17, characterized in that, The first message is also used to request an access token.
19. The method according to any one of claims 15 to 18, characterized in that, The method further includes: Receive a seventh message sent by a first network element, wherein the seventh message is used to subscribe to the authentication status information of the terminal; An eighth message is sent to the first network element, wherein the eighth message is used to indicate the updated authentication status information of the terminal, and the updated authentication status information of the terminal is used by the first device to determine that the second network element is not the serving network element of the terminal.
20. The method as described in claim 19, characterized in that, The access token includes the terminal's identification information.
21. The method according to any one of claims 15 to 20, characterized in that, The first message includes at least one of the following: The terminal's identification information; The second network information to which the second network element belongs.
22. A communication device, characterized in that, The communication device is used to perform the method according to any one of claims 1 to 10, 11 to 14, and 15 to 21.
23. A communication system, characterized in that, The system includes a first network element, a second network element, and a third network element, wherein the first network element is configured to implement the method of any one of claims 1 to 10, the second network element is configured to implement the method of any one of claims 11 to 14, and the third network element is configured to implement the method of any one of claims 15 to 21.
24. A storage medium storing instructions, characterized in that, When the instructions are executed on a communication device, the communication device performs the method as described in any one of claims 1 to 10, 11 to 14, and 15 to 21.
25. A program product comprising at least one of a program and instructions, characterized in that, When at least one of the programs or instructions is executed by a communication device, it implements the method described in any one of claims 1 to 10, 11 to 14, and 15 to 21.