Communication method and apparatus

WO2026200272A1PCT designated stage Publication Date: 2026-10-01HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/076149
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-27
Filing Date
2026-01-30
Publication Date
2026-10-01

Smart Images

  • Figure CN2026076149_01102026_PF_FP_ABST
    Figure CN2026076149_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and provides a communication method and apparatus. When an IMS network element determines that a first condition is satisfied (a terminal device accesses an access network by means of a satellite, and / or the terminal device sends a first message to request authentication on the terminal device via a first authentication mode), the terminal device is authenticated via the first authentication mode. As the first authentication mode is binding authentication between the access network and an IMS network, the authentication mode reuses an authentication result between the access network and the terminal device, thereby reducing signaling interaction procedures compared with performing mutual authentication between the IMS network and a UE. In a satellite scenario, the use of the first authentication mode can reduce the delay required for a narrowband Internet of things device to register with the IMS network.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and apparatus

[0001] Cross-references to related applications

[0002] This application claims priority to Chinese Patent Application No. 202510382321.0, filed on March 27, 2025, entitled "A Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology

[0004] With the rapid development of mobile communication technology, in order to meet people's needs for voice communication anytime and anywhere, researching how to use narrowband IoT devices for voice communication in satellite scenarios has become an industry consensus.

[0005] Before engaging in voice communication, terminal devices typically undergo an Internet Protocol (IP) Multimedia Subsystem (IMS) registration process. Only after successful authentication and authorization by the IMS system can they enjoy voice communication services. However, due to limitations such as bandwidth constraints and transmission delays, the latency required for narrowband IoT devices to register with the IMS network in satellite scenarios is excessive, severely impacting user experience. Summary of the Invention

[0006] This application provides a communication method and apparatus to reduce the latency required for narrowband IoT devices to register to the IMS network in satellite scenarios.

[0007] Firstly, this application provides a communication method that can be applied to an IMS network element. For example, the IMS network element may be the IMS network element itself, a component within the IMS network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logical module or software capable of implementing all or part of the IMS network element's functions. For instance, the IMS network element may include a proxy-call session control function (P-CSCF) network element, an interrogating-call session control function (I-CSCF) network element, a serving-call session control function (S-CSCF) network element, etc. This application does not limit the specific form of the IMS network element. The execution is as follows:

[0008] The system receives a first message requesting registration of the terminal device in the IMS network. Upon determining that a first condition is met, the system authenticates the terminal device using a first authentication method, obtaining an authentication result. If the authentication result is successful, a second message is sent to the terminal device, indicating that the terminal device has successfully registered in the IMS network. The first condition includes: the terminal device accessing the access network via satellite, and / or, the first message requesting authentication of the terminal device using the first authentication method. The first authentication method is a binding authentication between the access network and the IMS network.

[0009] In this context, the IMS network is the service network, while the networks that provide communication connections between terminal devices and the IMS network are called access networks, such as the evolved packet system (EPS) and the 5th generation (5G) system (5GS). The binding authentication between the access network and the IMS network can be understood as the IMS network operator binding the authentication of the IMS network with that of the access network. That is, when a terminal device is authenticated through the access network, the IMS network considers the user secure. For example, IMS network elements determine whether to authorize the terminal device to register on the IMS network by comparing the IP address from the terminal device with the IP address of the terminal device from the home subscriber server (HSS) in the 4th generation (4G) core network (evolved packet core, EPC).

[0010] In this application, when the IMS network element determines, based on the first message, that the first condition is met (the terminal device accesses the access network via satellite, and / or the terminal device requests authentication using the first authentication method via the first message), it uses the first authentication method to authenticate the terminal device. Since the first authentication method binds the access network and the IMS network, it reuses the authentication results of the access network and the terminal device, reducing signaling interaction procedures compared to two-way authentication between the IMS network and the UE. In satellite scenarios, using the first authentication method can reduce the latency required for narrowband IoT devices to register to the IMS network.

[0011] In one possible implementation, the first message includes: the access method of the terminal device accessing the access network via satellite; and / or, a first instruction information for authenticating the terminal device using a first authentication method.

[0012] When the first message includes the above information, the IMS network element determines that the first condition is met, and uses the first authentication method to authenticate the terminal device to reduce IMS registration latency.

[0013] In one possible implementation, the first message also includes the first address of the terminal device.

[0014] The first address of the terminal device can be its IP address, media access control (MAC) address, etc., and is not specifically limited here. When the first message also includes the first address of the terminal device, the IMS network element can request the second address of the terminal device that has been authenticated by the access network from the access network. If the first address and the second address are the same, it is determined that the terminal device has been successfully registered in the IMS network.

[0015] In one possible implementation, the IMS network element determines that the terminal device has been successfully authenticated when the first address of the terminal device is the same as the second address of the terminal device, wherein the second address comes from the access network.

[0016] IMS network elements determine whether terminal authentication is successful by comparing whether the first address and the second address are the same. Based on this, IMS registration latency can be reduced and data processing efficiency can be improved.

[0017] In one possible implementation, the IMS network element also sends a first request message to the access network, the first request message being used to request a second address from the terminal device; and receives the second address from the access network.

[0018] After successful authentication between the access network and the terminal device, the IMS network element requests a second address of the authenticated terminal device from the access network. This second address is used by the IMS network element to determine whether to authorize the terminal device to register on the IMS network. This reduces the signaling interaction process between the IMS network element and the terminal device, thus reducing transmission latency.

[0019] In one possible implementation, if the authentication result is successful, the IMS network element sends encrypted and integrity-protected IMS signaling to the terminal device.

[0020] Based on this, the security and integrity of information exchange between IMS network elements and terminal devices can be guaranteed.

[0021] In one possible implementation, the first message also includes second instruction information, which is used to instruct the IMS network element to encrypt and protect the integrity of the IMS signaling transmitted from the IMS network element to the terminal device after successfully authenticating the terminal device through the first authentication method.

[0022] When the first message includes the second instruction information, encrypting and protecting the integrity of the IMS signaling transmitted from the IMS network element to the terminal device can ensure the security and integrity of information exchange between the IMS network element and the terminal device.

[0023] In one possible implementation, the IMS network element also sends a second request message to the access network, the second request message being used to request security parameters used between the access network and the terminal equipment; receives security parameters from the access network; and encrypts and protects the integrity of the IMS signaling according to the security parameters.

[0024] Security parameters can be understood as the keys of terminal devices. By using security parameters to encrypt and protect the integrity of IMS signaling transmitted from IMS network elements to terminal devices, the security and integrity of information exchange between IMS network elements and terminal devices can be guaranteed.

[0025] In one possible implementation, when the first condition is not met, the IMS network element authenticates the terminal device through a second authentication method, which is a two-way authentication performed between the IMS network element and the terminal device; and sends a third message to the terminal device, which is used to indicate the authentication parameters related to the second authentication method.

[0026] Secondly, this application provides a communication method that can be applied to a terminal device. For example, the terminal device may be the terminal device itself, components within the terminal device (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the terminal device's functions. For example, the terminal device may be a narrowband IoT device, etc. This application does not limit the specific form of the terminal device. The execution is as follows:

[0027] Send a first message, which requests the registration of a terminal device in the Internet Protocol Multimedia Subsystem (IMS) network. The first message includes: the access method of the terminal device accessing the access network via satellite; and / or, a first indication information for authenticating the terminal device using a first authentication method; the first message is used to trigger the IMS network to authenticate the terminal device using the first authentication method; the first authentication method is a binding authentication between the access network and the IMS network; receive a second message, which indicates that the terminal device has successfully registered in the IMS network.

[0028] In one possible implementation, the first message also includes the first address of the terminal device.

[0029] In one possible implementation, the terminal device accesses the access network via satellite before sending the first message.

[0030] When a terminal device accesses the network via satellite, the first authentication method is explicitly used, which can reduce registration latency in the IMS network.

[0031] In one possible implementation, the first message also includes second instruction information, which is used to instruct the IMS network element to encrypt and protect the integrity of the IMS signaling transmitted from the IMS network element to the terminal device after successfully authenticating the terminal device through the first authentication method.

[0032] In one possible implementation, the terminal device determines the security parameters used between the access network and the terminal device; and encrypts and protects the integrity of the IMS signaling transmitted by the terminal device to the IMS network element according to the security parameters.

[0033] By using security parameters to encrypt and protect the integrity of IMS signaling transmitted from terminal devices to IMS network elements, the security and integrity of information exchange between IMS network elements and terminal devices can be guaranteed.

[0034] In one possible implementation, the security parameter is the IMS key negotiated between the terminal device and the access network.

[0035] When a terminal device registers with the access network, it negotiates a key with the access network. This negotiated key ensures the security and integrity of signaling exchanged between the UE and IMS network elements.

[0036] In one possible implementation, the access network supports narrowband IoT.

[0037] Thirdly, embodiments of this application provide a communication device, which can be an IMS network element or a terminal device. The communication device has the functions to implement the first to second aspects described above. For example, the communication device includes modules, units, or means that perform the steps involved in the first to second aspects. These functions, units, or means can be implemented by software, hardware, or hardware executing corresponding software.

[0038] In one possible design, the communication device includes a processing unit and a transceiver unit. The transceiver unit can be used to send and receive signals to enable communication between the communication device and other devices. The processing unit can be used to perform some internal operations of the communication device. The transceiver unit can be called an input / output unit, a communication unit, etc., and can be a transceiver; the processing unit can be a processor. When the communication device is a module (e.g., a chip) in a communication device, the transceiver unit can be an input / output interface, input / output circuit, or input / output pins, etc., and can also be called an interface, communication interface, or interface circuit, etc.; the processing unit can be a processor, processing circuit, or logic circuit, etc.

[0039] In another possible design, the communication device includes a processor and may further include a transceiver for transmitting and receiving signals. The processor executes program instructions to perform the methods in any of the possible designs or implementations of the first to second aspects described above. The communication device may also include one or more memories coupled to the processor, which may store necessary computer programs or instructions for implementing the functions involved in the first to second aspects described above. The processor can execute the computer programs or instructions stored in the memory, and when the computer programs or instructions are executed, the communication device implements the methods in any of the possible designs or implementations of the first to second aspects described above.

[0040] In another possible design, the communication device includes a processor that can be coupled to a memory. The memory can store necessary computer programs or instructions for implementing the functions described in the first to second aspects above. The processor can execute the computer programs or instructions stored in the memory, causing the communication device to implement the methods in any possible design or implementation of the first to second aspects above, when the computer programs or instructions are executed.

[0041] In another possible design, the communication device includes a processor and an interface circuit, wherein the processor is used to communicate with other devices through the interface circuit and to perform the methods in any possible design or implementation of the first to second aspects described above.

[0042] Understandably, in the third aspect described above, the processor can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, integrated circuit, etc.; when implemented in software, the processor can be a general-purpose processor that reads software code stored in memory. Furthermore, there can be one or more processors, and one or more memories. The memory can be integrated with the processor or separated from it. In specific implementations, the memory can be integrated with the processor on the same chip or disposed on different chips. This application does not limit the type of memory or the arrangement of the memory and processor.

[0043] Fourthly, embodiments of this application provide a communication system including the aforementioned IMS network element and terminal device. The IMS network element can be used to execute the method in the first aspect, and the terminal device can be used to execute the method in the second aspect. Furthermore, it should be noted that in each aspect, there may be processes executed interactively by multiple devices or network elements; the corresponding processes cannot be executed by a single device or network element. Instead, the corresponding processes are executed primarily through the interaction of corresponding devices or network elements, which will not be elaborated upon here.

[0044] Fifthly, this application provides a chip system including a processor and potentially a memory, for implementing the methods described in the first to second aspects above. The chip system may be composed of chips or may include chips and other discrete devices.

[0045] Sixthly, this application also provides a computer-readable storage medium storing computer-readable instructions that, when executed on a computer, cause the computer to perform the methods described in the first to second aspects.

[0046] In a seventh aspect, this application provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the methods of the embodiments of the first to second aspects described above.

[0047] The technical effects that can be achieved by the second to seventh aspects mentioned above can be referred to the description of the technical effects that can be achieved by the corresponding possible design schemes in the first aspect mentioned above, and will not be repeated here. Attached Figure Description

[0048] Figure 1 shows a schematic diagram of a communication system;

[0049] Figure 2 shows a schematic diagram of an IMS communication system;

[0050] Figure 3 shows a schematic diagram of a satellite access IMS communication system;

[0051] Figure 4 illustrates a schematic diagram of an IMS authentication and key agreement (AKA) authentication and registration process;

[0052] Figure 5 illustrates a schematic diagram of the authentication and registration process for a General Packet Radio System (GPRS)-IMS bundled authentication (GIBA).

[0053] Figure 6 shows a schematic diagram of an IMS registration process provided in an embodiment of this application;

[0054] Figure 7 shows a schematic diagram of a key negotiation process provided in an embodiment of this application;

[0055] Figure 8 shows a flowchart of a communication method provided in an embodiment of this application;

[0056] Figure 9 shows a flowchart of another communication method provided in an embodiment of this application;

[0057] Figure 10 is a schematic diagram of a communication device structure provided in an embodiment of this application;

[0058] Figure 11 is a schematic diagram of a communication device structure provided in an embodiment of this application;

[0059] Figure 12 is a schematic diagram of a communication device structure provided in an embodiment of this application;

[0060] Figure 13 is a schematic diagram of a communication device structure provided in an embodiment of this application;

[0061] Figure 14 is a schematic diagram of a communication device structure provided in an embodiment of this application. Detailed Implementation

[0062] The technical solutions of the embodiments of this application will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them.

[0063] In this application embodiment, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these dozen or more items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0064] In the embodiments of this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, which may include direct transmission via the air interface or indirect transmission by other units or modules via the air interface. "Receive information from YY" can be understood as the source of the information being YY, which may include direct reception from YY via the air interface or indirect reception from YY by other units or modules via the air interface. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface. In other words, sending and receiving can occur between devices, such as between network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface. It is understood that information may undergo necessary processing, such as encoding and modulation, between the source and destination of information transmission, but the destination can understand the valid information from the source. Similar expressions in this application can be understood in a similar way and will not be repeated here.

[0065] In the embodiments of this application, "when," "if," and "if" all refer to the device taking corresponding actions under certain objective circumstances, not a time limit, nor do they require the device to perform a judgment action, nor do they imply any other limitations. Unless otherwise specified, "if" and "if" are interchangeable, and "when" and "in the case of" are interchangeable. "When" and "if" / "if" are interchangeable. In the embodiments of this application, "*" can be used to represent "multiplication."

[0066] The ordinal numbers such as "first" and "second" mentioned in the embodiments of this application are used to distinguish multiple objects and are not used to limit the size, content, order, timing, priority, or importance of the multiple objects. For example, the first sequence and the second sequence refer to two different sequences, and do not indicate that the content, priority, or importance of these two sequences are different. Words such as "exemplary" or "for example" are used to indicate that they are examples, illustrations, or explanations. Any embodiment or design that is described as "exemplary" or "for example" in this application should not be construed as being better or more advantageous than other embodiments or design solutions. Specifically, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0067] Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a list of units is not necessarily limited to those units, but may include other units not expressly listed or inherent to those processes, methods, products, or apparatuses. The methods and apparatuses provided in the embodiments of this application are based on the same or similar technical concepts. Since the principles by which the methods and apparatuses solve the problems are similar, implementations of the apparatus and methods can be referred to mutually, and repeated details will not be elaborated further.

[0068] The technical solution provided in this application can be applied to the 5th generation (the 5 th This technology can be applied to 5G (5G) systems, or to future communication systems or other similar communication systems. Furthermore, the technical solutions provided in this application can be applied to cellular links, public land mobile networks (PLMNs), machine-to-machine (M2M) networks, Internet of Things (IoT) networks, or other networks. It can also be applied to links between devices, such as device-to-device (D2D) links. D2D links can also be called sidelinks, which are also referred to as edge links or secondary links. In this application, the above terms all refer to links established between devices of the same type, and their meanings are the same. The so-called "same type of device" can be a link between terminal devices, a link between base stations, or a link between relay nodes, etc., and this application does not limit this.

[0069] Figure 1 is a schematic diagram of the architecture of the communication system 1000 used in an embodiment of this application. As shown in Figure 1, the communication system includes a wireless access network 100 and a core network 200. Optionally, the communication system 1000 may also include an Internet 300. The wireless access network 100 may include at least one wireless access network device (110a and 110b in Figure 1) and at least one terminal (120a-120j in Figure 1). The terminal is connected to the wireless access network device wirelessly, and the wireless access network device is connected to the core network wirelessly or via a wired connection. The core network device and the wireless access network device may be independent physical devices, or the functions of the core network device and the logical functions of the wireless access network device may be integrated on the same physical device, or a single physical device may integrate some of the functions of the core network device and some of the functions of the wireless access network device. Terminals and wireless access network devices can be interconnected via wired or wireless connections. Figure 1 is only a schematic diagram; the communication system may also include other network devices, such as wireless relay devices and wireless backhaul devices, which are not shown in Figure 1.

[0070] Wireless access network equipment can be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next-generation NodeB (gNB) in a 5G mobile communication system, a next-generation base station in a future communication system, a base station in a future mobile communication system, or an access node in a wireless-fidelity (WiFi) system; it can also be a module or unit that performs some of the functions of a base station. In some deployments, a gNB can include a centralized unit (CU) and a distributed unit (DU). The CU implements some of the functions of the gNB, and the DU implements some of the functions of the gNB. For example, the CU is responsible for handling non-real-time protocols and services. For example, it implements radio resource control (RRC), service data adaptation protocol (SDAP) functions, and packet data convergence protocol (PDCP) layer functions. The DU is responsible for handling physical layer protocols and real-time services. For example, it can implement the functions of the radio link control (RLC) layer, medium access control (MAC) layer, and physical (PHY) layer. The gNB can also include an active antenna unit (AAU). The AAU implements some physical layer processing functions, radio frequency processing, and related functions of the active antenna. Since the information in the RRC layer ultimately becomes the information in the PHY layer, or is derived from the information in the PHY layer, in this architecture, higher-layer signaling (e.g., RRC layer signaling) can also be considered to be sent by the DU, or by the DU and AAU. It is understood that the network device can be one or more of the following: CU node, DU node, and AAU node. Furthermore, the CU can be a network device in the radio access network (RAN), or a network device in the core network (CN); this application does not limit this. Additionally, in the embodiments of this application, the network device provides services to the cell, and the terminal device communicates with the network device through the transmission resources (e.g., frequency domain resources, or spectrum resources) used by the cell. The cell can be the cell corresponding to network equipment (such as a base station). The cell can belong to a macro base station or to a base station corresponding to a small cell.For example, small cells may include: metro cells, micro cells, pico cells, femto cells, etc. Because small cells have the characteristics of small coverage area and low transmission power, they can provide high-speed data transmission services. Furthermore, in other possible cases, the network device can be other devices that provide wireless communication functions for terminal devices. The embodiments of this application do not limit the specific technology or device form used in the network device.

[0071] In a CU-DU architecture, or in an open RAN (ORAN) system, access network equipment may include one or more logical network elements such as CU, DU, CU-control plane (CP), CU-user plane (UP), or radio unit (RU). CU and DU can be separate entities or included in the same network element, such as a baseband unit (BBU). RU may be included in radio equipment or radio units, such as remote radio units (RRU), active antenna units (AAU), or remote radio heads (RRH).

[0072] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an ORAN system, CU can also be called an open CU (open CU, O-CU), DU can also be called an open DU (open DU, O-DU), CU-CP can also be called an open CU-CP (open CU-CP, O-CU-CP), CU-UP can also be called an open CU-UP (open CU-CP, O-CU-UP), and RU can also be called an open RU (open RU, O-RU). For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples in its embodiments. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in the embodiments of this application can be implemented through software modules, hardware modules, or a combination of software modules and hardware modules. CU and DU can be configured according to the protocol layer functions of the wireless network they implement.

[0073] The above CU and DU configurations are merely examples; the functions of the CU and DU can be configured as needed. For instance, the CU or DU can be configured to have more protocol layer functions, or only some protocol layer processing functions. For example, some RLC layer functions and protocol layer functions above the RLC layer can be placed in the CU, while the remaining RLC layer functions and protocol layer functions below the RLC layer can be placed in the DU. Furthermore, the functions of the CU or DU can be divided according to service type or other system requirements, such as by latency. Functions that require low latency can be placed in the DU, while functions that do not require low latency can be placed in the CU.

[0074] DU and RU can cooperate to implement the functions of the PHY layer. A DU can be connected to one or more RUs. The functions of DU and RU can be configured in various ways depending on the design. For example, a DU can be configured to implement baseband functions, and an RU can be configured to implement mid-RF functions. Another example is that a DU can be configured to implement higher-level functions in the PHY layer, and an RU can be configured to implement lower-level functions in the PHY layer, or to implement both lower-level and RF functions. Higher-level functions in the physical layer can include a portion of the physical layer's functions that are closer to the MAC layer, while lower-level functions in the physical layer can include another portion of the physical layer's functions that are closer to the mid-RF side.

[0075] A terminal can also be referred to as a terminal device, user interface (UE), mobile station, or mobile terminal (MT). Terminals can be widely used in various scenarios, such as D2D, vehicle-to-everything (V2X) communication, machine-type communication (MTC), IoT, virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Terminals can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc. The embodiments of this application do not limit the specific technologies or device forms used in the terminal.

[0076] Network devices and terminals can be fixed in location or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can be deployed on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of the network devices and terminals.

[0077] The roles of network devices and terminals can be relative. For example, the helicopter or drone 120i in Figure 1 can be configured as a mobile network device. For terminals 120j that access the wireless access network 100 via 120i, drone 120i is a network device; however, for network device 110a, 120i is a terminal, meaning that 110a and 120i communicate via a wireless air interface protocol. Of course, 110a and 120i can also communicate via a network device-to-network device interface protocol. In this case, relative to 110a, 120i is also a network device. Therefore, both network devices and terminals can be collectively referred to as communication devices. 110a and 110b in Figure 1 can be called communication devices with network device functions, and 120a-120j in Figure 1 can be called communication devices with terminal functions.

[0078] In the embodiments of this application, the functions of the network device can be executed by modules (such as chips) within the network device, or by a control subsystem that includes network device functions. This control subsystem, including network device functions, can be a control center in the aforementioned application scenarios such as smart grids, industrial control, intelligent transportation, and smart cities. Similarly, the functions of the terminal can be executed by modules (such as chips or modems) within the terminal, or by a device that includes terminal functions.

[0079] The communication systems and architectures described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0080] In this application, the term "xx network element" can also be abbreviated as "xx". For example, the S-CSCF network element is abbreviated as S-CSCF, the UDM network element is abbreviated as UDM, etc. For ease of explanation, the term "network element" will be omitted in the following description.

[0081] With the rapid development of mobile communication technology, in order to meet people's needs for voice communication anytime and anywhere, researching how to use narrowband IoT devices for voice communication in satellite scenarios has become an industry consensus. Before conducting voice communication, user equipment must first complete the IMS registration process. Only after successful authentication and authorization by the IMS network can it enjoy voice communication services.

[0082] Figure 2 shows a possible system architecture diagram of the IMS network. Terminals can access the IMS network, which can communicate with the 5G core network (5GC) or EPC. Figure 2 mainly involves, but is not limited to, the following network elements: Home Subscriber Server (HSS), Unified Data Management (UDM), I-CSCF, S-CSCF, P-CSCF, Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), and IMS Application Server (AS). Table 1 provides a brief description of the functions of each network element involved in Figure 2.

[0083] Table 1

[0084] In Table 1, IMS users can be understood as terminal devices.

[0085] Figure 3 shows the system architecture for voice communication using narrowband IoT devices in a satellite scenario. In this architecture, the UE accesses the EPC / 5GC via satellite and gateway station, and then accesses the IMS network through the EPC / 5GC to obtain voice services. Based on satellite altitude, i.e., satellite orbital altitude, satellite systems can be divided into highly elliptical orbit (HEO) satellites, geostationary earth orbit (GEO) satellites, medium earth orbit (MEO) satellites, and low earth orbit (LEO) satellites. The gateway station (also called a ground station, earth station, or gateway) can be used to connect satellites and base stations.

[0086] To better illustrate the solution of this application, the technical terms involved in this application are explained below:

[0087] 1) IMS authentication mechanism

[0088] IMS authentication mechanisms include "Sip Digest authentication," "AKA authentication," and "Cellular authentication and voice encryption (CAVE)-based AKA authentication." Sip Digest authentication is applicable to mobile and fixed terminals without a Universal Subscriber Identity Module (USIM) card; AKA authentication is applicable to mobile and fixed terminals with an ISIM card; and CAVE-based AKA authentication is applicable to mobile terminals with a removable-USIM (R-UIM) card. The authentication registration process for these three mechanisms is similar; the following explanation can be found by referring to the IMS AKA authentication registration process in section 2).

[0089] In addition, it may include GIBA authentication. GIBA authentication involves verifying and authorizing user identity between GPRS and IMS networks to ensure that users can seamlessly communicate and access services between the two networks.

[0090] 2) IMS AKA Authentication and Registration Process

[0091] Figure 4 illustrates the IMS AKA authentication and registration process. Taking the core network as the EPC as an example, this process can be implemented based on the interaction between the terminal device, the radio access network device, and the core network elements and IMS network elements in the EPC. The terminal device is exemplified by the UE, the radio access network device by the RAN device, the core network elements by the Mobility Management Entity (MME) and HSS, and the IMS network elements by the P-CSCF, I-CSCF, and S-CSCF. The execution is as follows:

[0092] Step 401: The UE accesses the 3GPP network to create a data transmission channel.

[0093] The 3GPP network can be GPRS, EPC, 5GC, etc., which are only examples and not specific limitations.

[0094] Step 402: The UE sends a SIP message to the P-CSCF through the 3GPP network.

[0095] Figure 4 uses a SIP message as a registration request message as an example. This SIP message is the first SIP message sent by the UE and has not undergone integrity protection (where integrity protection is used to ensure that the content in the message is not tampered with).

[0096] The REGISTER request message is used to request the UE to register with the IMS system. For example, the REGISTER request message includes: UE identifier (e.g., IP multimedia public identity (IMPU)), UE address information (e.g., UE IP address), UE access network information (e.g., 3GPP Universal Terrestrial Radio Access Network (UTRAN) - Time Division Duplex (TDD)), UE supported authentication methods, call identifier (initiated by the UE), and maximum message forwarding count.

[0097] Step 403: The P-CSCF sends the REGISTER request message to the I-CSCF.

[0098] Step 404: The I-CSCF determines a suitable S-CSCF and sends a REGISTER request message to the S-CSCF.

[0099] Step 405: S-CSCF obtains one or more authentication vectors (AVs) from HSS.

[0100] AV includes random numbers, keys, authentication tokens, etc., which are only illustrated here and are not specifically limited.

[0101] Step 406: The S-CSCF determines the AV to be used and includes it in a 401 Unauthorized Response message, which is then sent to the I-CSCF.

[0102] In step 407, the I-CSCF sends a 401 Unauthorized Response message to the P-CSCF.

[0103] Step 408: The P-CSCF deletes the key contained in the 401 Unauthorized Response Message and sends a 401 Unauthorized Response Message to the UE.

[0104] Step 409: The UE authenticates the network's identity based on the authentication token in the 401 Unauthorized Response message and calculates the response based on a random number.

[0105] Step 410: The UE sends the response to the P-CSCF in a REGISTER request message.

[0106] In addition, for example, the REGISTER request message also includes: UE identifier, UE address information, UE access network information, authentication methods supported by the UE, call identifier (initiated by the UE), maximum number of message forwardings, etc.

[0107] Step 411: The P-CSCF sends the REGISTER request message to the S-CSCF via the I-CSCF.

[0108] Step 412, S-CSCF verifies the UE identity based on the AV and the response in the REGISTER request message from the UE.

[0109] Step 413: After successful UE authentication, the S-CSCF sends a 200 OK message to the UE, indicating that the UE registration was successful.

[0110] It is important to note that subsequent SIP messages need to be encrypted and protected for integrity.

[0111] 3) GIBA Authentication and Registration Process

[0112] Under the GIBA authentication method, the IMS network does not perform a separate authentication process for the UE. Instead, it relies on the 3GPP network (such as GPRS) to authenticate the UE. The IMS network element determines whether the UE has been successfully authorized by comparing the IP address of the SIP REGISTER request message sent by the UE with the IP address from the HSS.

[0113] Figure 5 illustrates the GIBA authentication and registration process. This process can be implemented based on the interaction between the terminal device, the radio access network device, and the core network elements and IMS elements in GPRS. The terminal device is illustrated using a UE as an example, the radio access network device using a RAN device as an example, the core network elements using a gateway GPRS support node (GGSN) and HSS as examples, and the IMS elements using P-CSCF, I-CSCF, and S-CSCF as examples. The execution is as follows:

[0114] Step 501: The UE accesses the 3GPP network, activates the packet data protocol (PDP) context, and the HSS stores the UE's IP address.

[0115] Step 502: The UE sends a SIP message to the P-CSCF through the 3GPP network.

[0116] Figure 5 uses the REGISTER request SIP message as an example. This SIP message is the first SIP message sent by the UE and has not undergone integrity protection (where integrity protection is used to ensure that the content in the message is not tampered with).

[0117] The REGISTER request message is used to request the UE to register with the IMS system. This REGISTER request message includes: the UE IP address and the UE identifier (such as the IMS public user identity, IMS public user identity).

[0118] Step 503: The P-CSCF sends the REGISTER request message to the I-CSCF.

[0119] Step 504: The I-CSCF determines a suitable S-CSCF and sends a REGISTER request message to the S-CSCF.

[0120] Step 505: The S-CSCF sends a Cx interface-multimedia authentication request (Cx-MAR) message to the HSS.

[0121] The Cx-MAR message indicates that the UE is authenticated using GIBA, and the Cx-MAR message contains the UE identifier.

[0122] Step 506: HSS sends a Cx interface-multimedia authentication answer (Cx-MAA) message to S-CSCF.

[0123] The Cx-MAA message contains the UE IP address stored in the HSS.

[0124] Step 507: The S-CSCF compares the UE IP address in the REGISTER request message with the UE IP address from the HSS.

[0125] If the S-CSCF determines that the UE IP address in the REGISTER request message is the same as the UE IP address from the HSS, then proceed to step 508.

[0126] Step 508: The S-CSCF sends a SIP 200 OK message to the UE, indicating that the UE has successfully registered.

[0127] It should be noted that the above-mentioned GGSN functions similarly to the P-GW in 4G and the user plane function (UPF) in 5G. If GIBA authentication-related processes are to be executed in 4G or 5G, the above-mentioned GGSN can be replaced with P-GW or UPF.

[0128] 4) Narrowband Internet of Things (NB-IoT)

[0129] NB-IoT occupies a narrow bandwidth, requiring only about 180kHz, and can coexist with existing networks. It can be directly deployed on EPS or 5GS (which can also be understood as EPS or 5GS supporting narrowband IoT), thus reusing existing networks on EPS or 5GS, thereby reducing deployment costs and enabling smooth upgrades. In addition, NB-IoT devices have the characteristics of ultra-strong coverage, ultra-large connectivity (for example, one sector of NB-IoT can support tens of thousands of connections, supporting low latency sensitivity, ultra-low device cost, low device power consumption and optimized network architecture), ultra-low power consumption, and ultra-low cost.

[0130] In the IMS AKA authentication and registration process, mutual authentication between the UE and the IMS network is required. This necessitates the UE sending two REGISTER request messages, introducing additional interaction latency. Furthermore, NB-IoT devices have relatively narrow bandwidth, and in satellite scenarios, the distance between the UE and the satellite is considerable; the extended propagation latency negatively impacts service experience.

[0131] Based on this, this application provides a communication method to reduce the latency required for narrowband IoT devices to register with the IMS network in satellite scenarios. This method can be implemented based on data interaction between terminal devices, network elements in the access network, and IMS network elements in the IMS network. The IMS network is the service network, and any network providing communication connections between the terminal device and the IMS network is called the access network, such as the evolved packet system (EPS) or 5G system (5GS). Descriptions related to the IMS network and access network in this document can be understood by referring to the descriptions here; other locations will not elaborate further. Network elements in the access network include core network elements and radio access network devices. Terminal devices can be understood as NB-IoT devices, such as smart water meters and tag devices. Core network elements can be network elements in the EPC or 5GC, such as the MME, P-GW, and HSS in the EPC, and the access and mobility management function (AMF), UPF, and UDM in the 5GC. IMS network elements may include P-CSCF, I-CSCF, S-CSCF, etc. This is only an example and not a specific limitation. The terminal device (or core network element or IMS network element) can be the terminal device (or core network element or IMS network element) itself, or a component within the terminal device (or core network element or IMS network element) (e.g., processor, chip, or chip system), or a logical module or software implementing all or part of the terminal device (or core network element or IMS network element). The number of terminal devices may also be multiple, which is not specifically limited here; Figure 6 uses one as an example. Referring to Figure 6, the following is executed:

[0132] Step 601: The terminal device sends a first message to the IMS network element through the access network. Correspondingly, the IMS network element receives the first message.

[0133] The first message is used to request the registration of the terminal device on the IMS network.

[0134] For example, the first message can reuse an existing SIP message, such as a REGISTER request message, or it can be a new type of message; no specific limitation is made here. For example, the information included in the first message can be the same as the information included in an existing SIP message, such as the identifier of the terminal device, the address information of the terminal device, the access network information of the terminal device, the authentication methods supported by the terminal device, the call identifier, the maximum number of message forwardings, etc. This is only an example and is not a specific limitation.

[0135] For example, before sending the first message, the terminal device determines the first authentication method (i.e., the terminal device accesses the access network via satellite) based on the terminal device's access to the access network via satellite. For instance, the terminal device can determine its satellite access method through system messages in the cell broadcast message. For example, the terminal device determines that it is currently within the NB-IoT network coverage area through a system information block (SIB) specific to the NB-IoT cell, such as SIB32, and determines that it accesses via satellite based on the satellite information list element (IE) in the system message. The first authentication method is access network and IMS network bound authentication (e.g., GIBA authentication mentioned in 3 above). The authentication described in this application refers to IMS domain authentication or service-level authentication. Access network and IMS network bound authentication can be understood as the IMS network operator binding the IMS network authentication with the access network authentication; that is, when the terminal device authenticates through the access network, the IMS network considers the user secure. For example, the IMS network element determines whether to authorize a terminal device to register in the IMS network by comparing the IP address from the terminal device with the IP address from the HSS in the EPC. This is only an example and not a specific limitation. Because narrowband IoT devices have narrow bandwidth and satellite access communication distances are long, authentication methods with long latency cannot meet business requirements. Therefore, a first authentication method with shorter latency is used for authentication.

[0136] For example, when the terminal device explicitly adopts the first authentication method, the first message may also include first indication information for authenticating the terminal device using the first authentication method, so that the IMS network element explicitly adopts the first authentication method for authenticating the terminal device. For example, the header field of the first message may be filled with a requirement for a second authentication method, and the first message additionally includes first indication information. The second authentication method is a two-way authentication performed between the IMS network element and the terminal device, such as the IMS AKA authentication mentioned in 2) above. The narrowband IoT device supports both the first and second authentication methods. If the header field of the first message is filled with a requirement for the second authentication method, the IMS network element assumes that the terminal device supports encryption and integrity protection of the IMS signaling transmitted from the IMS network element to the terminal device.

[0137] Alternatively, the terminal device may fill the header field of the first message with a request for the first authentication method, so that the IMS network element can parse the header field of the first message and determine whether to use the first authentication method to authenticate the terminal device. When the request for the first authentication method is filled into the header field of the first message, the first message may also include second indication information. This second indication information instructs the IMS network element to encrypt and protect the integrity of the IMS signaling transmitted from the IMS network element to the terminal device after authenticating the terminal device using the first authentication method. Including the second indication information in the first message, encrypting and protecting the integrity of the IMS signaling transmitted from the IMS network element to the terminal device ensures the security and integrity of information exchange between the IMS network element and the terminal device.

[0138] Step 602: The IMS network element determines whether the first condition is met; if the first condition is met, step 603A is executed; if the first condition is not met, steps 603B to 603D are executed.

[0139] The first condition includes the terminal device accessing the access network via satellite, and / or the first message requesting authentication of the terminal device using the first authentication method.

[0140] For example, when the access network information carried in the first message indicates that the terminal device accesses an access network via satellite, wherein the access network supports narrowband IoT, such as NB-IoT non-terrestrial network (NTN), NB-IoT (GEO), 3GPP NB-IoT NTN, 3GPP NB-IoT (GEO), etc., the IMS network element determines that the first condition is met. For example, the IMS network element determines that the first condition is met when it determines, based on its local configuration, that the first message originates from a satellite network (or, NTN).

[0141] For example, when the first message carries first indication information requesting authentication of the terminal device using the first authentication method, the IMS network element determines that the first condition is met. Furthermore, the first indication information can be carried in the access network information.

[0142] Step 603A: The IMS network element authenticates the terminal device through the first authentication method and obtains the authentication result.

[0143] For example, when the IMS network element determines that the first condition is met, the first message may include: the access method of the terminal device accessing the access network via satellite; and / or, a first indication information for authenticating the terminal device using a first authentication method.

[0144] For example, the first message also includes a first address of the terminal device. The first address of the terminal device can be its IP address, MAC address, etc., and is not specifically limited here. When the first message includes the first address of the terminal device, the IMS network element can request a second address of the terminal device that has been authenticated by the access network. If the first address and the second address are the same, it is determined that the terminal device has been successfully registered in the IMS network.

[0145] Specifically, the IMS network element determines that the terminal device's authentication is successful when its first address matches the terminal device's second address (the address stored by the access network after successful authentication). The second address, originating from the access network, can be the terminal device's address sent by the access network (e.g., the HSS in the EPC), such as an IP address or MAC address. The IMS network element determines successful authentication by comparing the first and second addresses, thereby reducing IMS registration latency and improving data processing efficiency. For example, the IMS network element also sends a first request message to the access network requesting the terminal device's second address. After finding the second address, the access network sends it to the IMS network element. After successful authentication between the access network and the terminal device, the IMS network element requests the second address of the authenticated terminal device from the access network, allowing it to determine whether to authorize the terminal device's registration on the IMS network. This reduces signaling interaction between the IMS network element and the terminal device, thus reducing transmission latency.

[0146] Step 603B: The IMS network element authenticates the terminal device through the second authentication method.

[0147] For example, the second authentication method is IMS AKA authentication.

[0148] For example, when the IMS network element determines that the first condition is not met, the access method of the terminal device in the first message can be terrestrial cellular network access, etc., and the first message does not include the first indication information.

[0149] Step 603C: The IMS network element sends a third message to the terminal device.

[0150] The third message indicates the authentication parameters related to the second authentication method. Examples include a random number (RAND) and an authentication token (AUTN). This third message can be the 401 Unauthorized Response message mentioned in step 407 of the IMS AKA authentication and registration process described above.

[0151] Step 603D: The terminal device sends the fourth message to the IMS network element.

[0152] The fourth message includes a user response (RES) generated by the terminal device in response to the RAND in the authentication parameters. For example, the fourth message is of the same type as the first message, such as a REGISTER request message.

[0153] Step 604: When the authentication result is successful, the IMS network element sends a second message to the terminal device.

[0154] The second message indicates that the terminal device has successfully registered in the IMS network. This second message can be the SIP 200 OK message mentioned in step 508 of the GIBA authentication and registration process described above. Optionally, the second message may also include a first authentication method acceptance message.

[0155] For example, after successfully authenticating the terminal device through the first authentication method, the IMS network element sends encrypted and integrity-protected IMS signaling to the terminal device. The second message sent after successful authentication (e.g., a SIP 200 OK message), and / or the IMS information sent after the second message, can all be encrypted and integrity-protected. Based on this, the security and integrity of information exchange between the IMS network element and the terminal device can be guaranteed.

[0156] In one possible implementation, the IMS network element further sends a second request message to the access network (e.g., the HSS in the EPC). This second request message requests security parameters used between the access network and the terminal device. After obtaining the security parameters, the access network sends them back to the IMS network element. Based on the security parameters, the IMS network element encrypts and protects the integrity of the IMS signaling transmitted from the IMS network element to the terminal device. Here, the security parameters can be understood as the terminal device's key (e.g., the key determined after successful authentication between the terminal device and the access network). Using security parameters to encrypt and protect the integrity of the IMS signaling transmitted from the IMS network element to the terminal device ensures the security and integrity of information exchange between the IMS network element and the terminal device. For example, the IMS network element can subscribe to the security parameters from the access network, and when the security parameters are updated, the access network can send the updated security parameters to the IMS network element.

[0157] In one possible implementation, the terminal device determines the security parameters used between the access network and the terminal device; the terminal device then encrypts and protects the integrity of the IMS signaling transmitted from the terminal device to the IMS network element based on these security parameters. Using security parameters to encrypt and protect the integrity of the IMS signaling transmitted from the terminal device to the IMS network element ensures the security and integrity of information exchange between the IMS network element and the terminal device.

[0158] The aforementioned security parameters can be the IMS key negotiated between the terminal device and the access network. For example, the terminal device can send a fifth message to the access network, requesting registration within the network. This fifth message includes IMS key (i.e., IMS key) negotiation information. This fifth message can be an attach request message. The access network can obtain an authentication token and send it to the terminal device. When the terminal device successfully authenticates with the access network using the authentication token, it determines the IMS key corresponding to the token. In addition to receiving the authentication token from the access network, the terminal device also receives a random number. The terminal device can generate a first response (e.g., RES) based on this random number and send it to the access network. When the access network determines that the first response is identical to a second response (e.g., an expected response (XRES)), it obtains the security parameters. During registration with the access network, the terminal device negotiates a key with the network. This negotiated key is used to encrypt and protect the integrity of subsequent IMS signaling transmitted between the terminal device and IMS network elements, thereby reducing registration latency in the IMS network.

[0159] Referring to Figure 7, the IMS key negotiation process is illustrated. Figure 7 uses an NB-IoT device as the terminal device (UE as an example), the core network elements as the MME and HSS in the EPC, and the IMS network element as the S-CSCF. The execution is as follows:

[0160] Step 701: The UE sends an Attach request message to the MME.

[0161] The UE, based on its current access method of narrowband high-orbit satellite and / or the need to register with the IMS network subsequently, carries IMS security parameter negotiation information in the Attach request message. Additionally, the Attach request message also includes the UE's identifier.

[0162] Step 702: The MME requests the authentication vector from the HSS.

[0163] For example, the HSS may send multiple authentication vectors to the MME, and the authentication vectors are ordered according to priority. The MME can determine the authentication vector to use based on the priority order of the authentication vectors.

[0164] The authentication vector is mainly used for IMS key negotiation and includes RAND, integrity key (IK), cipher key (CK), AUTN (authentication token), XRES, etc.

[0165] Step 703: The MME sends a Challenge message to the UE.

[0166] For example, the Challenge message contains RAND and AUTN.

[0167] Step 704: When the UE successfully verifies its identity to access the network based on AUTN, it determines the IMS key (e.g., IK and CK).

[0168] For example, when the UE successfully authenticates its identity to access the network based on AUTN, the UE reads IK and CK through the USIM card.

[0169] Step 705: The UE calculates RES based on RAND.

[0170] The specific calculation method will not be explained in detail here; please refer to existing technologies for understanding.

[0171] Step 706: The UE sends RES to the MME.

[0172] Step 707: When the MME determines that RES is the same as XRES, it stores the IMS key (i.e., IK and CK in the authentication vector).

[0173] Optionally, if the S-CSCF has subscribed to the key update event from the MME, or if the S-CSCF has not subscribed to the key update event from the MME but the HSS requests the key from the MME, steps 708 and 709 are executed.

[0174] Step 708: The MME sends the updated IMS key to the S-CSCF via the HSS.

[0175] Step 709: The MME sends a key update notification message to the UE to indicate that the key was successfully sent to the IMS.

[0176] Subsequently, the UE and S-CSCF can use the IMS key to encrypt and protect the integrity of the IMS signaling transmitted between the UE and S-CSCF.

[0177] In this application, when the IMS network element determines that the first condition is met (the terminal device accesses the access network via satellite, and / or the terminal device requests authentication using the first authentication method via a first message), it uses the first authentication method to authenticate the terminal device. Since the first authentication method binds the access network and the IMS network, it reuses the authentication results of the access network and the terminal device, reducing signaling interaction procedures compared to two-way authentication between the IMS network and the UE. In satellite scenarios, using the first authentication method can reduce the latency required for narrowband IoT devices to register to the IMS network.

[0178] To better illustrate the solution of this application, the following description refers to Figure 8. Figure 8 uses an NB-IoT device as the terminal device (UE is used as an example in Figure 8), the core network elements as MME, P-GW, and HSS, and the IMS network elements as P-CSCF, I-CSCF, and S-CSCF. The S-CSCF uses GIBA authentication. Optionally, a service capability exposure function (SCEF) is also included to send the updated key to the IMS network elements.

[0179] Step 800: The UE successfully registers with the EPC via the GEO satellite and establishes a packet data network (PDN) connection.

[0180] It is important to note that the UE IP address is allocated by the EPC and stored in the HSS. During the EPC registration process, the MME and UE perform a security / authentication process to determine the security key, CN Key.

[0181] Step 801: The UE sends a session initiation REGISTER request message (i.e., the first message mentioned above) to the P-CSCF via the PDN connection.

[0182] The header field of this REGISTER request message is filled according to the AKA authentication mechanism requirements. Optionally, the REGISTER request message includes first indication information for authenticating the terminal device using a first authentication method (such as GIBA). This can be understood with reference to the above description and will not be repeated here. Furthermore, this first message also includes the UE's first address, i.e., the UE IP address.

[0183] Specifically, the UE can send a session initiation REGISTER request message to the P-CSCF via the P-GW.

[0184] Step 802: P-CSCF sends a REGISTER request message to S-CSCF.

[0185] Step 803: S-CSCF determines to use the first authentication method to authenticate the UE.

[0186] S-CSCF determines the first authentication method to authenticate the UE based on the UE's access network information and / or the first indication information in the SIP REGISTER request message.

[0187] For example, the S-CSCF determines to skip IMS AKA authentication and perform the first authentication method, such as GIBA authentication, based on the access network information (P-Acces-Netowork-Info, PANI) in the SIP REGISTER request message, such as PANI = "NB-NTN", "NB-IoT(GEO)", "3GPP NB-NTN", "3GPP NB-IoT(GEO)" etc.

[0188] For example, the S-CSCF indicates the use of a first authentication method to authenticate the UE based on the first indication information of the SIP REGISTER request message, determines to skip IMS AKA authentication, and performs the first authentication method, such as GIBA authentication, for the UE.

[0189] It should be noted that S-CSCF can also decide whether to use the first authentication method based on the operator's policy. For example, if the IMS system and the EPC currently accessed by the UE are from the same operator, or are different operators with a cooperation agreement, the first authentication method can be used. If the IMS system and the EPC currently accessed by the UE are from different operators, or are different operators without a cooperation agreement, the second authentication method can be used.

[0190] Step 804: The S-CSCF requests the UE's second address from the HSS.

[0191] For example, when the S-CSCF requests the UE's second address from the HSS, it may carry indication information of the first authentication method, such as GIBA authentication indication information, and may also carry the UE's identifier. Afterwards, the HSS sends the IP address corresponding to the UE's PDN connection to the S-CSCF.

[0192] Step 805: The S-CSCF compares the UE IP address carried in the REGISTER request message with the UE IP address information returned by the HSS to determine whether the UE authentication was successful.

[0193] For example, if the UE IP address carried in the REGISTER request message and the UE IP address information returned by the HSS are the same, the S-CSCF determines that the UE authentication is successful.

[0194] Step 806: The S-CSCF sends a SIP 200OK message to the UE (i.e., the second message mentioned above).

[0195] The SIP 200 OK message indicates that the UE has successfully registered in the IMS network. Refer to the description of the second message above for clarification; it will not be repeated here.

[0196] The subsequent interaction between the UE and the IMS network element can be understood by referring to steps 807 to 811.

[0197] Step 807: The S-CSCF requests the IMS key from the HSS.

[0198] In this process, the IMS key reuses the MME and UE to perform the security / authentication process and determine the security key CN Key (specifically, it may include IK and CK).

[0199] Step 808: HSS requests the IMS key from MME.

[0200] Step 809: HSS sends the IMS key to S-CSCF.

[0201] Step 810: The S-CSCF sends the IMS key to the P-CSCF.

[0202] Step 811: For subsequent SIP messages, the UE and P-CSCF use the IMS key for encryption and integrity protection.

[0203] Optionally, the S-CSCF also subscribes to IMS key update events. Steps 812 to 814 can also be performed. The execution order of steps 812 to 814 is not limited; they can be performed before or after steps 810 to 811.

[0204] Step 812: The S-CSCF subscribes to the HSS for key update events via the SCEF.

[0205] Step 813: HSS requests the updated IMS key from MME.

[0206] Step 814: HSS sends the updated IMS key to S-CSCF via SCEF.

[0207] In this approach, when narrowband IoT devices access the network via satellite, the IMS network element determines to skip the two-way authentication process between the IMS and the UE, reducing the interaction during IMS registration and thus shortening the IMS registration latency.

[0208] The scheme of this application will be specifically described below with reference to FIG9. FIG9 uses an NB-IoT device as the terminal device (UE as an example in FIG9), the core network elements as MME, P-GW, and HSS, and the IMS network elements as P-CSCF, I-CSCF, and S-CSCF for illustration. The S-CSCF decides to use GIBA authentication. Optionally, SCEF is also included to send the updated key to the IMS network elements.

[0209] Step 900: The UE successfully registers with the EPC via the GEO satellite and establishes a PDN connection.

[0210] It is important to note that the UE IP address is allocated by the EPC and stored in the HSS. During the EPC registration process, the MME and UE perform a security / authentication process to determine the security key, CN Key.

[0211] Step 901: The UE determines the first authentication method (such as GIBA authentication) to be used based on the narrowband IoT satellite access method.

[0212] Step 902: The UE sends a session initiation REGISTER request message (i.e., the first message mentioned above) to the P-CSCF via the PDN connection.

[0213] The header field of the REGISTER request message is filled according to the GIBA authentication mechanism requirements. Optionally, the REGISTER request message includes second indication information, which instructs the IMS network element to encrypt and protect the integrity of the IMS signaling transmitted from the IMS network element to the UE after authenticating the UE through the first authentication method. This can be understood with reference to the above description and will not be repeated here. Furthermore, the first message also includes the UE's first address, i.e., the UE IP address.

[0214] Specifically, the UE can send a session initiation REGISTER request message to the P-CSCF via the P-GW.

[0215] Steps 903 to 915 can be understood by referring to steps 802 to 814, and will not be repeated here.

[0216] In this approach, when a narrowband IoT device accesses the network via satellite, the UE determines to skip the IMS two-way authentication process, reducing the interaction required for IMS registration and thus shortening the IMS registration latency.

[0217] The foregoing primarily describes the solutions provided by the embodiments of this application from the perspective of device interaction. It is understood that, in order to achieve the above functions, each device may include corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0218] The embodiments of this application can divide the device into functional units according to the above method examples. For example, each function can be divided into a separate functional unit, or two or more functions can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0219] Figure 10 illustrates a possible exemplary block diagram of a communication device according to an embodiment of this application, when using integrated units. As shown in Figure 10, the communication device may include a processing unit 1001 and a transceiver unit 1002. The processing unit 1001 is used to control and manage the operation of the communication device. The transceiver unit 1002 is used to support communication between the communication device and other devices. Optionally, the transceiver unit 1002 may include a receiving unit and / or a transmitting unit, respectively used to perform receiving and transmitting operations. Optionally, the communication device may also include a storage unit for storing the program code and / or data of the communication device. The transceiver unit may be referred to as an input / output unit, a communication unit, etc., and the transceiver unit may be a transceiver; the processing unit may be a processor. When the communication device is a module (e.g., a chip) in a communication device, the transceiver unit may be an input / output interface, an input / output circuit, or an input / output pin, etc., and may also be referred to as an interface, a communication interface, or an interface circuit, etc.; the processing unit may be a processor, a processing circuit, or a logic circuit, etc. Exemplarily, the device may be the aforementioned IMS network element or terminal device.

[0220] More detailed descriptions of the processing unit 1001 and the transceiver unit 1002 can be obtained directly from the relevant descriptions in the above method embodiments, and will not be repeated here.

[0221] In one embodiment, the communication device is an IMS network element. The transceiver unit 1002 is used to receive a first message, which requests the registration of a terminal device in the IMS network. The processing unit 1001 is used to authenticate the terminal device through a first authentication method when it is determined that a first condition is met, and obtain an authentication result. The first condition includes: the terminal device accesses the access network via satellite, and / or the first message requests the authentication of the terminal device using the first authentication method, which is a binding authentication between the access network and the IMS network. When the authentication result is successful, the transceiver unit 1002 is also used to send a second message to the terminal device, which indicates that the terminal device has successfully registered in the IMS network.

[0222] In another embodiment, the communication device is a terminal device, and the transceiver unit 1002 is used to send a first message, which is used to request the terminal device to register in the Internet Protocol Multimedia Subsystem (IMS) network. The first message includes: the access method of the terminal device accessing the access network via satellite; and / or, a first indication information for authenticating the terminal device using a first authentication method; the first message is used to trigger the IMS network to authenticate the terminal device using the first authentication method; the first authentication method is the binding authentication of the access network and the IMS network; and to receive a second message, which is used to indicate that the terminal device has successfully registered in the IMS network.

[0223] In one possible design, when the communication device is a terminal device or a communication module within a terminal device, the functionality of the processing unit 1001 can be implemented by one or more processors. Specifically, the processor may include a modem chip, or a system-on-a-chip (SoC) chip or a SIP chip containing a modem core. The functionality of the transceiver unit 1002 can be implemented by transceiver circuitry.

[0224] In one possible design, when the communication device is a circuit or chip responsible for communication functions in a terminal device, such as a modem chip or a system-on-a-chip (SoC) or SIP chip containing a modem core, the function of the processing unit 1001 can be implemented by a circuit system in the aforementioned chip that includes one or more processors or processor cores. The function of the transceiver unit 1002 can be implemented by the interface circuitry or data transceiver circuitry on the aforementioned chip.

[0225] When the aforementioned communication device is a module applied in a base station, the base station module implements the functions of the base station in the above method embodiments. The base station module receives information from other modules (such as radio frequency modules or antennas) in the base station, which is information sent by the UE to the base station; or, the base station module sends information to other modules (such as radio frequency modules or antennas) in the base station, which is information sent by the base station to the UE. Here, the base station module can be the baseband chip of the base station, or it can be a DU or other modules, where the DU can be an O-DU under the O-RAN architecture.

[0226] Figure 11 is an exemplary block diagram of a communication device provided in an embodiment of this application. For example, the communication device 10 may include a chip system 110, a memory 120, a bus 130, a power management module 140, or a transceiver 150, etc.

[0227] The chip system 110 can be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed through integrated logic circuits in the hardware of the chip system 110 or through software instructions.

[0228] As an example and not a limitation, chip system 110 may include circuitry or chips responsible for signal processing (such as a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip or system-in-package (SIP) chip containing a modem core).

[0229] Optionally, the chip system 110 may also include a memory (such as a cache) for storing instructions and data. In some embodiments, the memory in the chip system 110 is a cache memory. This memory can store instructions or data that the chip system 110 has just used or that are used repeatedly. If the chip system 110 needs to use the instruction or data again, it can directly retrieve it from the memory. This avoids repeated accesses, reduces the waiting time of the chip system 110, and thus improves the efficiency of the system.

[0230] In some embodiments, the chip system 110 may include one or more interfaces. Interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a SIM interface, and / or a USB interface, etc.

[0231] Memory 120 may include random access memory (RAM) and read-only memory (ROM). Memory 120 may store computer-readable, computer-executable code, including instructions that, when executed, cause the processor to perform the various functions described in this application.

[0232] Optionally, the code may include instructions for implementing various aspects of the embodiments of this application. The code may be stored in a non-transitory computer-readable medium such as system memory or other types of memory. In some cases, the code may not be directly executable by the chip system 110, but may enable a computer (e.g., at compile and execution time) to perform the functions described in this application. In some cases, memory 120 may in particular contain a basic I / O system that controls basic hardware or software operations, such as interaction with peripheral components or devices.

[0233] For example, the chip system 110 executes various functional applications and data processing of the communication device 10 by running instructions stored in the memory 120. For instance, when the communication device 10 transfers files with other devices (which may also be terminal devices or network devices), the chip system 110 of the communication device 10 can call the computer-executable program code stored in the memory 120 to implement the encoding or decoding methods provided in the embodiments of this application.

[0234] In addition, the memory 120 can be integrated into the chip system 110 or independent of the chip system 110.

[0235] Bus 130 may be a universal serial bus (USB) used to support communication between various parts of the communication device 10.

[0236] The power management module 140 is used to receive charging input from the charger. Optionally, the power management module 140 can also supply power to the communication device 10 while charging it (e.g., the battery module of the communication device 10). By way of example and not limitation, the power management module 140 can also supply power to other devices besides the communication device 10.

[0237] Transceiver 150 can communicate bidirectionally via one or more antennas, wired links, or wireless links. For example, transceiver 150 can represent a wireless transceiver and can communicate bidirectionally with another wireless transceiver. Transceiver 150 may also include a modem for modulating packets and providing the modulated packets to the antenna for transmission, and for demodulating packets received from the antenna. Transceiver 150 may include a receiver and a transmitter, the receiver performing the function of receiving information and the transmitter performing the function of transmitting information.

[0238] In some cases, a wireless device may include a single antenna. However, in other cases, the device may have more than one antenna, such as antenna 1 and antenna 2 shown in FIG. 11, which may be capable of simultaneously transmitting or receiving multiple wireless transmissions. Exemplarily, antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in communication device 10 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch. Communication device 10 can transfer files to other devices via wireless communication functions.

[0239] In one design, the communication device 10 may correspond to the IMS network element in the above method embodiments. The communication device 10 can implement the steps or processes executed by the IMS network element in the above method embodiments, wherein the transceiver 150 can be used to perform the transmission and reception related operations of the IMS network element in the above method embodiments; and the chip system 110 can be used to perform the processing related operations of the IMS network element in the above method embodiments.

[0240] In another design, the communication device 10 may correspond to the terminal device in the above method embodiments. The communication device 10 can implement the steps or processes executed by the terminal device in the above method embodiments, wherein the transceiver 150 can be used to perform the transmission and reception related operations of the terminal device in the above method embodiments; and the chip system 110 can be used to perform the processing related operations of the terminal device in the above method embodiments.

[0241] Under this design, the communication device 10 may include modules such as a short-range communication module 164, a sensor 161, a display 162, or a camera 163, as shown in Figure 6.

[0242] The short-range communication module 164 may include modules that support short-range communication, such as WiFi and Bluetooth.

[0243] Sensor 161 may include pressure sensors, gyroscope sensors, barometric pressure sensors, magnetic sensors, accelerometers, distance sensors, proximity sensors, fingerprint sensors, temperature sensors, touch sensors, ambient light sensors, bone conduction sensors, etc.

[0244] Display 162 is used to display images, videos, etc. The display includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled LED, a MicroLED, a Micro-OLED, a quantum dot light-emitting diode (QLED), etc. For example, in this embodiment, the display can be used to display the interface required by the communication device 10. Exemplarily, the communication device 10 implements display functions through a GPU, a display, and an application processor. The GPU is a microprocessor for image processing, connected to the display and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The chip system 110 may include one or more GPUs that execute program instructions to generate or modify display information.

[0245] Camera 163 is used to acquire images, videos, etc.

[0246] It is understood that the structure shown in Figure 12 does not constitute a specific limitation on the communication device 20. In some embodiments, the communication device 20 may also include more or fewer components than those shown in Figure 12, or combine some components, or split some components, or have different component arrangements, etc. Alternatively, some components shown in Figure 12 may be implemented in hardware, software, or a combination of software and hardware, and the communication device 20 may add or remove components based on the structure given in Figure 12.

[0247] Figure 12 is a schematic block diagram of a communication device provided in an embodiment of this application. The communication device 20 may include a baseband unit 210, which can communicate with external devices via a cellular radio frequency (RF) transceiver 220 (e.g., if the communication device 20 is a terminal device, the baseband unit 210 can communicate with network devices via the cellular RF transceiver 220; or, if the communication device 20 is a network device, the baseband unit 210 can communicate with terminal devices and / or core network devices via the cellular RF transceiver 220).

[0248] Baseband unit 210 may include computer-readable medium / memory. Baseband unit 210 is responsible for general processing, including the execution of software stored on the computer-readable medium / memory. When executed by baseband unit 210, the software causes baseband unit 210 to perform the various functions described above. The computer-readable medium / memory may also be used to store data manipulated by baseband unit 210 during software execution.

[0249] The baseband unit 210 further includes a receiving unit 201, a management unit 202, and a transmitting unit 203. The management unit 202 includes the one or more sub-units shown in FIG. 12. The units within the management unit 202 may be stored in a computer-readable medium / memory and / or configured as hardware within the baseband unit 210. The receiving unit 201 and the transmitting unit 203 may be referred to as transceiver units.

[0250] Figure 13 is a schematic block diagram of a chip system provided in an embodiment of this application. The chip system 30 includes, but is not limited to, a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip or a system-in-package (SIP) chip containing a modem core.

[0251] The chip system (or processing system) includes a processor 310 and an input / output interface 330. Optionally, the chip system also includes a memory 320.

[0252] The processor 310 can be a processing circuit in the chip system (including at least one processor, such as processor 311 and processor 312 as shown in FIG. 13). The processor 310 can be coupled to the memory 320, and call the instructions in the memory 320, so that the chip system can implement the methods and functions of the various embodiments of this application. The input / output interface 330 can be an input / output circuit in the chip system, which outputs the information processed by the chip system, or inputs the data or signaling information to be processed into the chip system for processing.

[0253] As one approach, this chip system is used to implement the operations performed by IMS network elements or terminal devices in the various method embodiments described above.

[0254] For example, processor 310 is used to implement the processing-related operations performed by the IMS network element or terminal device in the above method embodiments, as described in the foregoing embodiments; input / output interface 330 is used to implement the sending and / or receiving-related operations performed by the IMS network element or terminal device in the above method embodiments, as described in the foregoing embodiments.

[0255] Figure 14 is a schematic block diagram of a chip system provided in an embodiment of this application. The chip system 40 (or processing system) includes an input / output interface 410 and logic circuitry 420. The input / output interface 410 can be an input / output circuit within the chip system, outputting processed information or inputting data or signaling information to be processed into the chip system for processing; details can be found in the descriptions of the preceding embodiments. The logic circuitry 420 is used to execute the aforementioned communication method; details can also be found in the descriptions of the preceding embodiments.

[0256] As one approach, this chip system is used to implement the operations performed by IMS network elements or terminal devices in the various method embodiments described above.

[0257] For example, logic circuit 420 is used to implement processing-related operations performed by IMS network element or terminal device in the above method embodiments; input / output interface 410 is used to implement sending and / or receiving-related operations performed by IMS network element or terminal device in the above method embodiments.

[0258] This application also provides a computer-readable storage medium storing computer instructions for implementing the methods executed by an IMS network element or a terminal device in the above-described method embodiments.

[0259] For example, when the computer program is executed by a computer, it enables the computer to implement the methods executed by the IMS network element or terminal device in the various embodiments of the above methods.

[0260] This application also provides a computer program product comprising instructions that, when executed by a computer, implement the methods performed by an IMS network element or terminal device in the above-described method embodiments.

[0261] This application also provides a communication system, including the aforementioned IMS network element and terminal device.

[0262] The explanations and beneficial effects of the relevant contents in any of the devices provided above can be found in the corresponding method embodiments provided above, and will not be repeated here.

[0263] The method steps in the embodiments of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, compact disc read-only memory (CD-ROM), or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Additionally, the ASIC can reside in a first communication device. Alternatively, the processor and storage medium can exist as discrete components in an access network device or terminal.

[0264] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. A computer program is a set of instructions that directs each step of an action of an electronic computer or other device with message processing capabilities. It is typically written in a programming language and runs on a target architecture. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed, in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be volatile or non-volatile, or it can include both types of storage media.

[0265] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0266] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The order of the process numbers described above does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.

Claims

1. A communication method, characterized in that, include: Receive a first message, the first message being used to request the registration of terminal devices in the Internet Protocol Multimedia Subsystem (IMS) network; When the first condition is met, the terminal device is authenticated through the first authentication method to obtain the authentication result. The first condition includes: the terminal device accesses the access network via satellite, and / or the first message request uses the first authentication method to authenticate the terminal device. The first authentication method is access network and IMS network binding authentication. When the authentication result is successful, a second message is sent to the terminal device, which indicates that the terminal device has successfully registered in the IMS network.

2. The method according to claim 1, characterized in that, The first message includes: the access method of the terminal device accessing the access network via satellite; and / or, a first indication information for authenticating the terminal device using a first authentication method.

3. The method according to claim 1 or 2, characterized in that, The first message also includes the first address of the terminal device.

4. The method according to claim 3, characterized in that, The step of authenticating the terminal device through the first authentication method to obtain the authentication result includes: If the first address is the same as the second address of the terminal device, then the terminal device is determined to have been successfully authenticated, and the second address is from the access network.

5. The method according to claim 4, characterized in that, The method further includes: Send a first request message to the access network, the first request message being used to request the second address; Receive the second address from the access network.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: If the authentication result is successful, IMS signaling with encryption and integrity protection is sent to the terminal device.

7. The method according to any one of claims 1-5, characterized in that, The first message also includes a second instruction, which instructs the IMS network element to encrypt and protect the integrity of the IMS signaling transmitted from the IMS network element to the terminal device after successfully authenticating the terminal device through the first authentication method.

8. The method according to claim 6 or 7, characterized in that, The method further includes: Send a second request message to the access network, the second request message being used to request security parameters used between the access network and the terminal device; Receive the security parameters from the access network; The IMS signaling is encrypted and its integrity protected according to the security parameters.

9. The method according to claim 1, characterized in that, The method further includes: If the first condition is not met, the terminal device is authenticated through a second authentication method, wherein the second authentication method is to perform bidirectional authentication between the IMS network element and the terminal device. A third message is sent to the terminal device, the third message being used to indicate authentication parameters related to the second authentication method.

10. A communication method, characterized in that, include: Send a first message, which requests the registration of a terminal device in the Internet Protocol Multimedia Subsystem (IMS) network. The first message includes: the access method of the terminal device accessing the access network via satellite; and / or, a first indication information for authenticating the terminal device using a first authentication method; the first message is used to trigger the IMS network to authenticate the terminal device using the first authentication method; the first authentication method is a binding authentication between the access network and the IMS network. A second message is received, which indicates that the terminal device has successfully registered in the IMS network.

11. The method according to claim 10, characterized in that, Before sending the first message, the method further includes: The terminal device accesses the access network via satellite.

12. The method according to claim 10 or 11, characterized in that, The first message also includes the first address of the terminal device.

13. The method according to any one of claims 10-12, characterized in that, The first message also includes a second instruction, which instructs the IMS network element to encrypt and protect the integrity of the IMS signaling transmitted from the IMS network element to the terminal device after successfully authenticating the terminal device through the first authentication method.

14. The method according to any one of claims 10-13, characterized in that, The method further includes: Determine the security parameters used between the access network and the terminal device; Based on the security parameters, the IMS signaling transmitted from the terminal device to the IMS network element is encrypted and its integrity is protected.

15. The method according to claim 14, characterized in that, The security parameter is the IMS key negotiated between the terminal device and the access network.

16. The method according to any one of claims 1-15, characterized in that, The access network supports narrowband IoT.

17. A communication device, characterized in that, It includes at least one processor; and a communication interface communicatively connected to said at least one processor; said at least one processor executes instructions stored in memory to cause the method of any one of claims 1 to 9 to be executed, or the method of any one of claims 10 to 16 to be executed.

18. A computer-readable storage medium, characterized in that, The computer contains a computer program or instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1 to 16.

19. A computer program product, characterized in that, When the computer reads and executes the computer program product, the method described in any one of claims 1 to 16 is performed.