WO2022028030A1 - Slice authentication method and corresponding apparatus - Google Patents

Slice authentication method and corresponding apparatus Download PDF

Info

Publication number
WO2022028030A1
WO2022028030A1 PCT/CN2021/093587 CN2021093587W WO2022028030A1 WO 2022028030 A1 WO2022028030 A1 WO 2022028030A1 CN 2021093587 W CN2021093587 W CN 2021093587W WO 2022028030 A1 WO2022028030 A1 WO 2022028030A1
Authority
WO
WIPO (PCT)
Prior art keywords
network element
slice
authentication
access management
management network
Prior art date
Application number
PCT/CN2021/093587
Other languages
French (fr)
Chinese (zh)
Inventor
戚彩霞
银宇
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2022028030A1 publication Critical patent/WO2022028030A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/16Discovering, processing access restriction or access information

Definitions

  • the old access management node may not support the network slice authentication function (ie, there is no network slice authentication result).
  • the old access management node is an access management node in the fourth generation (4th-Generation, 4G) mobile communication network, or the old access management node is not supported in the fifth generation (5th-Generation, 5G) The access management node of the network slice authentication function.
  • 4G fourth generation
  • 5G fifth generation
  • the terminal device can obtain the authentication result only by executing the network slice authentication process, which increases the system signaling overhead and increases the service delay of the terminal device.
  • the first network element is a second slice authentication network element.
  • the third access management network element can obtain the authentication result corresponding to the first slice on the data management network element through the second slice authentication network element, and thus does not need to perform the network slice authentication process for the first slice, which can save system information. Reduce the overhead and reduce the service delay of the terminal equipment.
  • the method further includes: the first slice authentication network element or the second slice authentication network element receives an authentication revocation message from the verification, authorization and accounting AAA server, and according to the authentication revocation message , modify the authentication result corresponding to the first slice stored in the data management network element to an authentication failure; or, the first slice authentication network element or the second slice authentication network element receives the data from the AAA server The re-authentication message, according to the re-authentication message, delete the authentication result corresponding to the first slice stored in the data management network element.
  • the third access management network element can obtain the authentication result corresponding to the first slice from the first slice authentication network element, so it is not necessary to perform the network slice authentication process for the first slice, which can save system signaling overhead and reduce terminal The service delay of the device.
  • the method before the terminal device moves from the second access management network element to the third access management network element, the method further includes: corresponding to the first slice After the authentication of the first slice is completed, the first slice authentication network element saves the authentication result corresponding to the first slice, and registers the identity of the first slice authentication network element to the data management network Yuan.
  • This embodiment provides various implementation manners for the third access management network element to determine that the second access management network element does not support the network slice authentication function, which improves the flexibility of the solution.
  • the data management network element receiving the request message from the third access management network element includes: the data management network element receiving the request message sent by the second slice authentication network element, wherein the third access management network element receives the request message sent by the second slice authentication network element.
  • the request message sent by the two-slice authentication network element is sent by the third access management network element to the second slice authentication network element; the data management network element returns a response message to the third access management network element network element, including: the data management network element sends a response message to the second slice authentication network element, and sends the response message to the third access management network element through the second slice authentication network element network element.
  • the method further includes: receiving, by the data management network element, a first message from the first slice authentication network element or the second slice authentication network element, and storing the stored data according to the first message.
  • the authentication result corresponding to the first slice is modified to be an authentication failure; or, the data management network element receives the second message from the first slice authentication network element or the second slice authentication network element, according to the described The second message deletes the stored authentication result corresponding to the first slice.
  • the system further includes a first access management network element and a first slice authentication network element; when the terminal device moves from the second access management network element to the first access management network element Before the third access management network element, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element; the first access management network element or the third access management network element
  • the one slice authentication network element is used for: storing the authentication result corresponding to the first slice to the data management network element.
  • the first slice authentication network element is further configured to: before the terminal device moves from the second access management network element to the third access management network element, After the authentication corresponding to the first slice is completed, the authentication result corresponding to the first slice is saved, and the identifier of the authentication network element of the first slice is registered to the data management network element.
  • the terminal device before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element
  • the service scope of the first slice authentication network element or the second slice authentication network element is further used to: receive an authentication revocation message from the AAA server, and according to the authentication revocation message, convert the first slice authentication
  • the authentication result corresponding to the first slice stored in the authentication network element is modified to be an authentication failure; or, a re-authentication message from the AAA server is received, and according to the re-authentication message, the first The authentication result corresponding to the first slice stored in the slice authentication network element is deleted.
  • a sixth aspect provides a slice authentication device, which can be, for example, a network element of a third access management node or a chip set inside the network element of the third access management node, and the device includes a device for performing the second aspect or the first Modules of the method described in any possible implementation manner of the second aspect.
  • the apparatus may include: a sending unit, configured to: after the terminal device moves from the second access management network element that does not support the network slice authentication function to the apparatus that supports the network slice authentication function, send the message to the first A network element sends a first request message, wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; a receiving unit is configured to receive information from the first slice.
  • the first response message of the network element where the first response message includes the authentication result corresponding to the first slice.
  • a slice authentication device which can be, for example, a data management network element or a chip set inside the data management network element, and the device includes the third aspect or any possible implementation of the third aspect.
  • a slice authentication device which can be, for example, a first slice authentication network element or a chip arranged inside the first slice authentication network element, and the device includes a device for performing the fourth aspect or the first A module of the method described in any possible implementation manner of the four aspects.
  • a communication apparatus comprising: at least one processor; and a communication interface communicatively connected to the at least one processor; The communication interface executes as in the second aspect or any possible implementation manner of the second aspect or the third aspect or any possible implementation manner of the third aspect or the fourth aspect or any possible implementation manner of the fourth aspect the method described.
  • a computer-readable storage medium comprising a program or an instruction, when the program or instruction is executed on a computer, such as the second aspect or any possible implementation manner of the second aspect or the third aspect, the program or instruction is executed. or any of the possible embodiments of the third aspect or the method described in the fourth aspect or any of the possible embodiments of the fourth aspect is performed.
  • a chip is provided, the chip is coupled with a memory, and is used for reading and executing program instructions stored in the memory, so that the second aspect or any possible implementation manner of the second aspect or the first The method described in the third aspect or any possible embodiment of the third aspect or the fourth aspect or any possible embodiment of the fourth aspect is performed.
  • FIG. 5 is a flowchart of a method for withdrawing an authentication result and a method for re-authentication provided by an embodiment of the present application;
  • FIG. 11 is a flowchart of another authentication result withdrawal method and re-authentication method provided by an embodiment of the present application.
  • NSSAA Network Slice-Specific Authentication and Authorization
  • the slice authentication function sends an authentication, authorization, and accounting (Authentication, Authorization, Accounting, AAA) protocol message to the AAA server, where the AAA protocol message includes the user identifier GPSI, slice identifier received by the slice authentication function in step S103 S-NSSAI and EAP messages.
  • AAA authentication, authorization, and accounting
  • the AAA server replies an AAA protocol message to the slice authentication function, where the AAA protocol message includes the user identifier GPSI, the slice identifier S-NSSAI, and the EAP message sent to the terminal device.
  • the access management node sends a request message to the terminal device, where the request message includes the slice identifier S-NSSAI and the EAP message.
  • the terminal device After receiving the network slice authentication request message, the terminal device replies to the access management node with a response message, where the response message includes the slice identifier S-NSSAI and an EAP message sent to the AAA server.
  • the AAA server replies an AAA protocol message to the slice authentication function, where the AAA protocol message includes the user identity GPSI, the slice identity S-NSSAI, the EAP message sent to the terminal device, and the authentication result for the slice (EAP success/failure). ).
  • the slice authentication function replies a response message to the access management node, and the response message includes the user identifier GPSI, slice identifier S-NSSAI, EAP message and authentication result (EAP success/ Fail);
  • the data management network element is used to manage the subscription data of the terminal equipment.
  • the slice authentication network element is used to forward relevant messages between the terminal device and the AAA server for slice authentication/slice re-authentication/revocation of authentication results.
  • these may include mobile telephones (or "cellular" telephones), computers with mobile terminal equipment, portable, pocket-sized, hand-held, computer-embedded mobile devices, and the like.
  • mobile telephones or "cellular" telephones
  • PCS personal communication service
  • SIP session initiation protocol
  • WLL wireless local loop
  • PDA personal digital assistant
  • constrained devices such as devices with lower power consumption, or devices with limited storage capacity, or devices with limited computing power, etc.
  • it includes information sensing devices such as barcodes, radio frequency identification (RFID), sensors, global positioning system (GPS), and laser scanners.
  • RFID radio frequency identification
  • GPS global positioning system
  • the terminal device may also be a wearable device.
  • Wearable devices can also be called wearable smart devices or smart wearable devices, etc. It is a general term for the application of wearable technology to intelligently design daily wear and develop wearable devices, such as glasses, gloves, watches, clothing and shoes. Wait.
  • a wearable device is a portable device that is worn directly on the body or integrated into the user's clothing or accessories. Wearable device is not only a hardware device, but also realizes powerful functions through software support, data interaction, and cloud interaction.
  • Enhanced next-generation base station can also include a centralized unit (centralized unit in a cloud radio access network, Cloud RAN) system unit, CU) and distributed unit (distributed unit, DU), or may also include a relay device, which is not limited in this embodiment of the present application.
  • network element in the embodiments of the present application may also be replaced with other terms, for example, “function” or “node” and the like.
  • access management network element can also be replaced with “access management node”
  • data management network element can also be replaced with “data management function”
  • silice authentication network element can also be replaced with “Slice authentication function”, etc.
  • At least one of the following items refers to any combination of these items, including any combination of single item(s) or plural items(s), such as at least one of a, b or c (a), can mean: a, or b, or c, or a and b, or b and c, or a and c, or a and b and c.
  • the third access management network element After the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function, the third access management network element sends a request to the first network element.
  • a first request message is sent, where the first request message includes identification information of the first slice; the first network element receives the first request message from the third access management network element.
  • Case 3 After the terminal device moves from the second access management network element to the third access management network element, the third access management network element obtains the features supported by the second access management network element from the second access management network element list, and it is determined according to the supported feature list that the second access management network element does not support the network slice authentication function.
  • the feature list includes various features supported by the second access management network element, and the feature list does not include the feature of the network slice authentication function, then the third access management network element determines that the second access management network element Meta does not support the network slice authentication function.
  • the authentication result corresponding to the first slice is stored on the designated network element in the communication system, and the authentication result is authentication success or authentication failure.
  • the authentication result corresponding to the first slice stored by the designated network element is before the terminal device moves from the second access management network element to the third access management network element, and after the authentication corresponding to the first slice is completed. , which is stored in the specified NE.
  • the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element , wherein the first access management network element and the third access management network element are the same or different.
  • the terminal device is located within the service range of the first access management network element, if the communication system performs the network slice authentication process for the first slice, after the authentication corresponding to the first slice is completed, the first slice The corresponding authentication result is saved to the designated network element.
  • the method for the communication system to perform the network slice authentication process for the first slice may refer to FIG. 1 , which will not be described in detail here.
  • the terminal device before the terminal device moves from the second access management network element to the third access management network element, the terminal device first moves from the first access management network element that supports the network slice authentication function to the first access management network element that does not support the network slice authentication function.
  • the fourth access management network element with the authorization function is moved from the fourth access management network element to the second access management network element that does not support the network slice authentication function, wherein the first access management network element is connected to the third access management network element.
  • the incoming management network elements are the same or different.
  • the first network element is specifically the second slice authentication network element
  • the second network element is specifically the data management network element.
  • the terminal equipment moves from the first access management network element supporting the network slice authentication function to the second access management network element, the terminal equipment
  • the terminal equipment When the device is in the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first access management network element or the first slice authentication network element authenticates the authentication corresponding to the first slice. The result is stored in the data management network element.
  • the AAA server can trigger the authentication corresponding to the first slice.
  • the revocation process or re-authentication process of the authorization result Since the second access management network element does not support the slice authentication function, and the slice authentication result is stored in the designated network element, the slice authentication network element can notify the designated network element to perform authentication result withdrawal or re-authentication.
  • the AAA server sends a re-authentication message to the first slice authentication network element or the second slice authentication network element; the first slice authentication network element Or the second slice authentication network element deletes the authentication result corresponding to the first slice stored in the data management network element according to the re-authentication message.
  • the specific manner in which the first slice authentication network element or the second slice authentication network element deletes the authentication result corresponding to the first slice stored in the data management network element may be: the first slice authentication network element.
  • slice authentication network elements can also be used to replace the first slice authentication network element or the second slice authentication network element to perform the above re-authentication process.
  • the AAA server can trigger the The withdrawal process or the re-authentication process of the authentication result corresponding to the slice. Since the second access management network element does not support the slice authentication function, the authentication result of the slice is stored in the first slice authentication network element. Therefore, the slice authentication network element can notify the first slice authentication network element to perform the operation. The authentication result is withdrawn or re-authenticated.
  • the AAA server triggers the withdrawal process for the authentication result corresponding to the first slice:
  • the AAA server triggers the re-authentication process corresponding to the first slice:
  • the AAA server sends a re-authentication message to the first slice authentication network element, and the first slice authentication network element stores itself according to the re-authentication message.
  • the authentication result corresponding to the first slice is deleted; or, the AAA server sends a re-authentication message to the second slice authentication network element, and the second slice authentication network element sends the element sends a fourth message (including the identifier of the first slice, used to notify the first slice authentication network element to delete the authentication result corresponding to the first slice), and the first slice authentication network element according to the fourth message Delete the authentication result corresponding to the first slice stored by itself.
  • the AAA server can trigger the authentication corresponding to the first slice.
  • the AAA server sends an authentication revocation message (including the identifier of the first slice) to the first slice authentication network element or the second slice authentication network element, and the first slice authentication network element
  • the slice authentication network element or the second slice authentication network element After receiving the message, the slice authentication network element or the second slice authentication network element sends an authentication withdrawal message (including the identifier of the first slice) to the first access management network element; the first access management network element obtains the After the authentication revocation message, send a fifth message (including the identifier of the first slice to notify the data management network element to modify the authentication result corresponding to the first slice to an authentication failure) to the data management network element; data management After receiving the fifth message, the network element modifies the authentication result corresponding to the first slice stored by itself to the authentication failure.
  • the AAA server triggers the re-authentication process corresponding to the first slice:
  • the authentication result revocation or re-authentication may also be performed through the slice authentication network element, and the specific method may refer to the above-mentioned case 1, which will not be repeated here.
  • the fifth message and the sixth message may specifically be the subscription data.
  • Data update request message if the authentication result corresponding to the first slice is specifically stored in the subscription data of the terminal device (the subscription data of the terminal device is stored in the data management network element), then the fifth message and the sixth message may specifically be the subscription data.
  • Data update request message if the authentication result corresponding to the first slice is specifically stored in the subscription data of the terminal device (the subscription data of the terminal device is stored in the data management network element), then the fifth message and the sixth message may specifically be the subscription data. Data update request message.
  • the AAA server triggers the re-authentication process corresponding to the first slice:
  • the authentication result revocation or re-authentication may also be performed by using the slice authentication network element, and the specific method may refer to the above-mentioned case 2, which will not be repeated here.
  • the second slice authentication network element learns that the first access management network element supports the network slice authentication function according to the access management network element registration information obtained from the data management network element.
  • the authentication network element notifies the first access management network element, and the first access management network element modifies the authentication result on the data management network element.
  • a specific slice authentication method provided in this embodiment can be applied to the network architecture shown in FIG. 2 , and the method includes:
  • the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element obtains the subscription data of the terminal device according to the slice identifier S included in the subscription data.
  • -NSSAI and its network slice authentication indication information If the network slice identified by S-NSSAI (equivalent to the first slice above) needs to perform network slice authentication, the first access management network element triggers the network slice authentication
  • the specific process is the same as that in Figure 1.
  • the first access management network element corresponds to the access management node in FIG. 1
  • the first slice authentication network element corresponds to the slice authentication function in FIG. 1 .
  • the terminal device sends a registration update request message to the third access management network element.
  • the data management node sends a subscription data response message (a first response message) to the third access management network element, where the subscription data includes the authentication result.
  • the third access management network element After the third access management network element obtains the slice identifier S-NSSAI and the authentication result, it performs the operation of allowing or not allowing the terminal device to establish a session to the network slice according to the authentication result, and does not repeat the network slice authentication. Process.
  • the AAA service may also trigger the process of withdrawing the authentication result or re-authentication.
  • a flowchart of a method for withdrawing an authentication result provided in an embodiment of the present application can be applied to the network architecture shown in FIG. 2 . Or it is executed when the second access management network element is accessed. Methods include:
  • the withdrawal of the authentication result ie, S501a shown in FIG. 5
  • the re-authentication process ie, S501b shown in FIG. 5
  • the authentication result revocation is used for the network slice whose authentication result is EAP success, and the authentication result is changed to EAP failure; EAP authentication.
  • the AAA server sends a corresponding AAA protocol message to the second slice authentication network element, and the second slice authentication network element may be the same as or different from the first slice authentication network element.
  • the second slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:
  • the second slice authentication network element executes S504a and S505a.
  • the subscription data update request message is used to notify the data management network element to modify the authentication result , the subscription data update request message carries the authentication result and the authentication result is EAP failure. If the AAA server triggers the re-authentication process, the subscription data update request message is used to notify the data management network element to delete the authentication result.
  • the subscription data update request message may not contain the authentication result, or contain an empty authentication result, or Contains the authentication result and also contains deletion indication information.
  • the second slice authentication network element modifies the authentication result corresponding to the slice identifier S-NSSAI in the subscription data on the data management network element to EAP failure;
  • the server triggers the re-authentication process, and the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the subscription data on the data management network element.
  • the first access management network element triggers a network slice authentication process for the re-authenticated network slice, and the specific process is the same as the process in FIG. 1 .
  • S508 The data management network element replies a subscription data update response message to the first access management network element, which is used to indicate whether the subscription data update succeeds or fails.
  • S505c The first access management network element replies with an authentication result withdrawal notification response message.
  • S507a The data management network element replies a subscription data update response message to the first access management network element, which is used to indicate success or failure of the subscription data update.
  • S507b and S506a can also be performed by the second slice authentication network element, and the authentication result obtained after re-authentication is stored in the subscription data of the terminal device, or the slice identifier S-NSSAI is stored. The corresponding authentication result is changed to EAP failure.
  • the first access management network element stores the authentication result on the data management network element during the network slice authentication process, so that the terminal device in the mobile scenarios listed in the above-mentioned first and second scenarios, the first The three access management network elements can obtain the authentication results from the data management network elements, so that the network slice authentication process does not need to be performed for network slices, which saves network signaling overhead, and the terminal equipment does not need to wait for the third access A session to a specific network slice can be established only after the management NE completes the network slice authentication process, which speeds up the process of service establishment and improves the service experience of terminal devices.
  • the AAA server can also trigger the re-authentication or authentication result withdrawal process, which improves the flexibility of network slice authentication.
  • the differences from the first embodiment include: in the second embodiment, the authentication result is stored in the data management network element by the slice authentication network element, and is also obtained from the data management network element by the slice authentication network element; The result is stored in the data management network element by the access management network element, and is also obtained from the data management network element by the access management network element.
  • FIG. 6 a flowchart of another specific slice authentication method provided by an embodiment of the present application, the method can be applied to the network architecture shown in FIG. 2 , and the method includes:
  • a first access management network element triggers a network slice authentication process.
  • the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element obtains the subscription data of the terminal device according to the slice identifier S included in the subscription data.
  • -NSSAI and its network slice authentication indication information If the network slice identified by S-NSSAI (equivalent to the first slice above) needs to perform network slice authentication, the first access management network element triggers the network slice authentication
  • the specific process is the same as that in Figure 1.
  • the first access management network element corresponds to the access management network element in FIG. 1
  • the first slice authentication network element corresponds to the slice authentication function in FIG. 1 .
  • the first slice authentication network element learns the authentication result of the network slice (that is, after performing S1011 shown in FIG. 1 ), it continues to perform the following steps:
  • the above S601 to S603 describe the process that the first slice authentication network element stores the authentication result in the data management network element. element) the process of obtaining the authentication result from the data management network element.
  • the terminal device triggers the registration update process:
  • S604 The terminal device sends a registration update request message to the third access management network element.
  • the second slice authentication network element sends a request message for obtaining the authentication result to the data management network element, where the message includes the identifier of the terminal device and also includes one or more slice identifiers S-NSSAI.
  • the data management network element replies the obtaining authentication result response message to the second slice authentication network element, and the message includes the authentication result.
  • the message may also include the slice identifier S-NSSAI.
  • the authentication result response message may specifically include multiple slice identifiers S-NSSAI, and an authentication result corresponding to each slice.
  • the second slice authentication network element replies to the third access management network element with a response message for obtaining the authentication result (the first response message), and the response message for obtaining the authentication result includes the authentication result.
  • the obtaining authentication result response message also includes the slice identifier S-NSSAI.
  • the AAA service may also trigger the process of withdrawing the authentication result or re-authentication.
  • the following describes the method for the AAA service to trigger the authentication result withdrawal or re-authentication process.
  • the data management network element replies a response message to the second slice authentication network element, where the message includes the mobility management network element registration information, and the mobility management network element registration information includes the access management network element identifier.
  • the access management network element is identified as NF Instance ID.
  • the second slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:
  • the second slice authentication network element executes S704a and S705a.
  • the second slice authentication network element sends an authentication result update request message to the data management network element, where the authentication result update request message includes the slice identifier S-NSSAI.
  • the authentication result update request message further includes the authentication result.
  • the second slice authentication network element After the data management network element receives the authentication result update request message, if the AAA server triggers the authentication result withdrawal process, the second slice authentication network element will authenticate the slice identifier S-NSSAI corresponding to the authentication result data.
  • the authorization result is modified to EAP failure; if the AAA server triggers the re-authentication process, the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the subscription data.
  • the authentication result update request message is used to notify the data management network element to modify the authentication As a result, the subscription data update request message carries the authentication result and the authentication result is EAP failure. If the AAA server triggers the re-authentication process, the authentication result update request message is used to notify the data management network element to delete the authentication result.
  • the subscription data update request message may not contain the authentication result, or contain an empty authentication result. Or include the authentication result and also include deletion indication information.
  • the slice identifier S-NSSAI and the authentication result are stored in the authentication result data of the data management network element.
  • Embodiment 1 stores the authentication result.
  • the slice identifier S-NSSAI corresponds to the data, so in this embodiment S704a, the second slice authentication network element sends an authentication result update request message to the data management network element, while in the embodiment In S504a, the second slice authentication network element sends a subscription data update request message to the data management network element.
  • S705a The data management network element replies an authentication result update response message to the second slice authentication network element, which is used to indicate whether the authentication result data update succeeds or fails.
  • the second slice authentication network element sends a re-authentication notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
  • S705b The first access management network element replies with a re-authentication notification response message.
  • the second slice authentication network element sends an authentication result update request message to the data management network element, where the message carries the slice identifier and the authentication result obtained after re-authentication.
  • the data management network element replies an authentication result update response message to the second slice authentication network element, which is used to indicate whether the subscription data update succeeds or fails.
  • the second slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI;
  • the second slice authentication network element sends an authentication result update request message to the data management network element, where the message includes the slice identifier S-NSSAI and the authentication result.
  • the message is used to modify the authentication result corresponding to the slice identifier S-NSSAI to EAP failure.
  • the data management network element stores the slice identifier S-NSSAI and its authentication result.
  • S707a The data management network element replies an authentication result update response message to the second slice authentication network element, which is used to indicate whether the authentication result update succeeds or fails.
  • the first slice authentication network element stores the authentication result on the data management network element during the network slice authentication process, so that the terminal device in the mobile scenarios listed in the above-mentioned first and second scenarios
  • the third access management network element can obtain the authentication result from the data management network element, so that the network slice authentication process does not need to be performed for the network slice, which saves network signaling overhead, and the terminal device does not need to wait for the third access management network element.
  • a session to a specific network slice can be established only after the inbound management NE completes the network slice authentication process, which speeds up the process of service establishment and improves the service experience of terminal devices.
  • the AAA server can also trigger the re-authentication or authentication result withdrawal process, which improves the flexibility of network slice authentication.
  • the authentication result is stored on the first slice authentication network element, the first slice authentication network element stores the authentication result during the network slice authentication process, and the first slice authentication network element also Register the registration information of the first slice authentication network element to the data management network element; the third access management network element requests the authentication result from the second slice authentication network element, and the second slice authentication network element obtains the authentication result from the data management network element.
  • the element obtains the registration information of the first slice authentication network element, and requests the authentication result from the first slice authentication network element according to the registration information of the first slice authentication network element.
  • the second slice authentication network element notifies the first slice authentication network element to update the authentication result.
  • a first access management network element triggers a network slice authentication process.
  • the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element obtains the subscription data of the terminal device according to the slice identifier S included in the subscription data.
  • -NSSAI and its network slice authentication indication information If the network slice identified by S-NSSAI (equivalent to the first slice above) needs to perform network slice authentication, the first access management network element triggers the network slice authentication
  • the specific process is the same as that in Figure 1.
  • the first access management network element corresponds to the access management node in FIG. 1
  • the first slice authentication network element corresponds to the slice authentication function in FIG. 1 .
  • the first slice authentication network element learns the authentication result of the network slice (that is, after performing S1011 shown in FIG. 1 ), it continues to perform the following steps:
  • the first slice authentication network element stores the user identifier, the network slice S-NSSAI and the authentication result.
  • the first slice authentication network element sends a registration request message to the data management network element, which is used to register the information of the first slice authentication network element in the data management network element, where the message includes the user identifier, the network slice S-NSSAI and first slice authentication network element identifier.
  • the first slice authentication network element identifier may be a network function instance identifier.
  • the data management network element replies a registration response message to the first slice authentication network element, which is used to indicate whether the registration of the first slice authentication network element information succeeds or fails.
  • the data management network element stores the registration information of the first slice authentication network element.
  • the third access management network element selects the second slice authentication network element, and sends a request message for obtaining the authentication result (the first request message) to the second slice authentication network element, and the message includes the user ID , Network slice S-NSSAI.
  • the second slice authentication network element does not have an authentication result corresponding to the user identifier and the network slice S-NSSAI locally, and sends a message of obtaining slice authentication registration information to the data management network element, where the message includes the user identifier and the network slice S-NSSAI .
  • the slice authentication network element registration information further includes the network slice S-NSSAI.
  • the data management network element queries the slice authentication network element registration information corresponding to the parameter according to the parameters in the message in step S807, and sends the slice authentication network element registration information to the second slice authentication network element.
  • the second slice authentication network element sends a request message for obtaining the authentication result to the first slice authentication network element according to the identifier of the first slice authentication, where the message includes the user identifier and the network slice S-NSSAI.
  • the first slice authentication network element replies a response message for obtaining the authentication result to the second slice authentication network element, where the authentication result response message includes the authentication result.
  • the authentication result response message further includes the user identifier and the network slice S-NSSAI.
  • the authentication result response message may further include the user identifier, the network slice S-NSSAI.
  • the terminal device can subscribe to multiple slice identifiers S-NSSAI that need to perform network slice authentication, and the second slice authentication network element can perform multiple requests to obtain the authentication results, and each request is used to request one or more S-NSSAI. Multiple slices identify S-NSSAI and their corresponding authentication results.
  • the access management network element may also go to the data management network element to obtain slice authentication registration information, and then obtain the authentication result of the network slice.
  • S807-S8012 are replaced by For the following steps 1) to 4):
  • the third access management network element sends a message of obtaining slice authentication registration information to the data management network element, and the message includes the user identifier and the network slice S-NSSAI.
  • the third access management network element sends a request message for obtaining the authentication result to the first slice authentication network element according to the identifier of the first slice authentication network element, and the message includes the user identifier and the network slice S-NSSAI.
  • the first slice authentication network element replies with a response message for obtaining the authentication result, and the message includes the user identifier, the network slice S-NSSAI and the authentication result.
  • the AAA service may also trigger the process of withdrawing the authentication result or re-authentication.
  • the following describes the method for the AAA service to trigger the authentication result withdrawal or re-authentication process.
  • FIG. 9 it is a flowchart of another method for withdrawing an authentication result provided by an embodiment of the present application.
  • the method can be applied to the network architecture shown in FIG. 2 . Executed when the network element or the second access management network element is accessed. Methods include:
  • the AAA server sends an AAA protocol message to the second slice authentication network element, which is used to trigger an authentication result withdrawal or re-authentication process.
  • the second slice authentication network element performs steps S904, S905, S906a and S907a.
  • steps S908a and S909a may also be performed.
  • the second slice authentication network element does not have the authentication result corresponding to the user identifier and the network slice S-NSSAI locally, and sends a message of obtaining slice authentication registration information to the data management network element, where the message includes the user identifier and the network slice S-NSSAI .
  • S905 The data management network element replies a response message for obtaining slice authentication registration information to the second slice authentication network element, where the message includes the slice authentication network element registration information, and the slice authentication network element registration information includes the network slice S-NSSAI and the first slice authentication network element. Identifier of all slice authentication network elements. Specifically, the data management network element queries the slice authentication network element registration information corresponding to the parameters according to the parameters in the S904 message, and sends the slice authentication network element registration information to the second slice authentication network element.
  • S906a The second slice authentication network element sends an update authentication result request message to the first slice authentication network element, where the message includes the user identifier, the slice identifier S-NSSAI and its authentication result.
  • the first slice authentication network element After receiving the message, the first slice authentication network element updates the authentication result. If the AAA server triggers the authentication result withdrawal process, the second slice authentication network element modifies the authentication result corresponding to the slice identifier S-NSSAI in the first slice authentication network element to EAP failure. If the AAA server triggers the re-authentication process, the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the first slice authentication network element.
  • the first slice authentication network element replies an update authentication result response message to the second slice authentication network element, which is used to indicate whether the authentication result update succeeds or fails.
  • the first slice authentication network element executes S908a and S909a.
  • the first slice authentication network element sends a deregistration request message to the data management network element, where the message includes the slice identifier S-NSSAI, and may also include the identifier of the first slice authentication network element.
  • the registration information of the mobility management network element contains the identity of the access management network element, and the clear indication indicates that the access management network element is not separated, or the registration information of the mobility management network element does not contain the clear indication information, and the supported feature information indicates that the access management network element is not separated
  • the incoming management network element supports the network slice authentication function, that is, the above case 1, and the second slice authentication network element performs steps S904, S905, S906b or S906c and subsequent steps.
  • the second slice authentication network element does not have the authentication result corresponding to the user identifier and the network slice S-NSSAI locally, and sends a message of obtaining slice authentication registration information to the data management network element, where the message includes the user identifier and the network slice S-NSSAI .
  • the data management network element replies a response message for obtaining slice authentication registration information to the second slice authentication network element, where the message includes the slice authentication network element registration information, and the slice authentication network element registration information includes the network slice S-NSSAI and the first slice authentication network element. Identifier of all slice authentication network elements. Specifically, the data management network element queries the slice authentication network element registration information corresponding to the parameters according to the parameters in the S904 message, and sends the slice authentication network element registration information to the second slice authentication network element.
  • AAA server triggers re-authentication:
  • the second slice authentication network element sends a re-authentication notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
  • the first access management network element triggers a network slice authentication process for the re-authenticated network slice, and the specific process is the same as that in FIG. 1 .
  • the second slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
  • S907c The first access management network element replies with an authentication result withdrawal notification response message.
  • the first slice authentication network element stores the authentication result in the network slice authentication process, and registers the registration information of the first slice authentication network element to the data management network element, so that the terminal device is in the above-mentioned
  • the third access management network element can obtain the authentication result through the second slice authentication network element (that is, triggering the second slice authentication network element to obtain the first slice authentication network element from the data management network element.
  • All slice authentication network element registration information after obtaining the authentication result from the first slice authentication network element according to the first slice authentication network element registration information, return the authentication result to the third access management network element), Furthermore, it is not necessary to perform the network slice authentication process for the network slice, which saves network signaling overhead, and the terminal device does not need to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice. The process of establishing a service is accelerated, and the service experience of the terminal device can be improved.
  • the AAA server can also trigger the re-authentication or authentication result withdrawal process, which improves the flexibility of network slice authentication.
  • Embodiment 4 the first slice authentication network element does not need to register the registration information of the first slice authentication network element to the data management network element, and the third access management The network element may directly obtain the authentication result from the first slice authentication network element.
  • this embodiment may be applicable to a scenario in which only one slice authentication network element (ie, the above-mentioned first slice authentication network element) is deployed in the current network.
  • a first access management network element triggers a network slice authentication process.
  • the first slice authentication network element learns the authentication result of the network slice (that is, after performing S1011 shown in FIG. 1 ), it continues to perform the following steps:
  • the first slice authentication network element stores the user identifier, the network slice S-NSSAI and the authentication result.
  • the above S1001 to S1002 describe the process of the first slice authentication network element storing the authentication result.
  • the new access management network element (third access management network element) starts from the first slice of the authentication network element.
  • the process of obtaining the authentication result by the slice authentication network element is described.
  • the third access management network element sends a request message (first request message) for obtaining the authentication result to the first slice authentication network element, where the message includes the user identifier and the network slice S-NSSAI.
  • the message may contain one or more network slice identifiers S-NSSAI.
  • the first slice authentication network element replies with a response message for obtaining the authentication result (a first response message), and the message includes the authentication result.
  • the authentication result response message further includes the user identifier, the network slice S-NSSAI.
  • the following describes the method for the AAA service to trigger the authentication result withdrawal or re-authentication process.
  • the AAA server sends an AAA protocol message to the first slice authentication network element, which is used to trigger an authentication result withdrawal or re-authentication process.
  • the AAA server triggers the withdrawal of the authentication result (ie S1101a shown in FIG. 11 ) or the re-authentication process (ie, S1101b shown in FIG. 11 ) due to the modification of configuration information.
  • the authentication result revocation is used for the network slice whose authentication result is EAP success, and the authentication result is changed to EAP failure; EAP authentication.
  • the AAA server sends a corresponding AAA protocol message to the first slice authentication network element.
  • the first slice authentication network element After receiving the AAA protocol message, the first slice authentication network element sends a request message to the data management network element, where the request message is used to query the mobile management network element registration information of the service terminal device.
  • the data management network element replies a response message to the first slice authentication network element, where the message includes mobility management network element registration information, and the mobility management network element registration information includes an access management network element identifier.
  • the access management network element is identified as NF Instance ID.
  • the first slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:
  • the first slice authentication network element changes the authentication result to EAP failure, and if it is re-authentication, the first slice authentication network element deletes the authentication result.
  • the registration information of the mobility management network element contains the identification of the access management network element, and the clear indication indicates that the access management network element is not separated, or the registration information of the mobility management network element does not contain the clear indication information, and the supported feature information Indicates that the access management network element supports the network slice authentication function, that is, the above case 1, the first slice authentication network element performs step S1104a or S1104b and subsequent steps.
  • AAA server triggers re-authentication:
  • the first slice authentication network element sends a re-authentication notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
  • the first access management network element triggers a network slice authentication process for the re-authenticated network slice, and the specific process is the same as the process in FIG. 1 .
  • the first slice authentication network element After obtaining the authentication result sent by the AAA server in the network slice authentication process, the first slice authentication network element updates the locally stored authentication result of the network slice, and changes the authentication result to EAP failure.
  • S1105b The first access management network element replies with an authentication result withdrawal notification response message.
  • S1106b The first slice authentication network element updates the authentication result, and deletes the locally stored authentication result of the network slice.
  • the first slice authentication network element stores the authentication result in the network slice authentication process, so that the third access management network element in the mobile scenarios listed in the above-mentioned scenarios 1 and 2 for the terminal device
  • the authentication result can be obtained directly from the first slice authentication network element, so that the network slice authentication process does not need to be performed for the network slice, which saves network signaling overhead, and the terminal device does not need to wait for the third access management network element to execute.
  • a session to a specific network slice can be established only after the network slice authentication process is completed, which speeds up the process of service establishment and improves the service experience of terminal devices.
  • the AAA server can also trigger the re-authentication or authentication result withdrawal process, which improves the flexibility of network slice authentication.
  • the new access management network element obtains the authentication result from the specified network element.
  • the new access management network element In addition to obtaining the authentication result from the old access management network element (for example, obtaining the user context from the second access management network element, the user context carries the authentication result), the method can also be provided according to the embodiment of the present application, Obtain the authentication result from the specified network element.
  • an embodiment of the present application provides a slice authentication device 1200, which may be, for example, a third access management node network element or a chip set inside the third access management node network element. It includes a module for executing the method executed by the network element of the third access management node in the method embodiments shown in FIG. 3 to FIG. 11 .
  • the sending unit 1201 is configured to: after the terminal device moves from the second access management network element that does not support the network slice authentication function to the device that supports the network slice authentication function, send a first request message to the first network element , wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
  • the receiving unit 1202 is configured to receive a first response message from the first network element, where the first response message includes an authentication result corresponding to the first slice.
  • the apparatus further includes a processing unit 1203; after the terminal device moves from the second access management network element to the apparatus, the apparatus sends a first request message to the first network element Previously, the processing unit 1203 was used to:
  • the dashed box in FIG. 12 is used to indicate that the processing unit 1203 is optional for the apparatus 1200 .
  • the apparatus 1300 may include:
  • the receiving unit 1301 is configured to, after the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function, to receive the information from the third access management network element.
  • a request message for entering a management network element the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
  • the sending unit 1302 is configured to send a response message to the third access management network element, where the response message includes an authentication result corresponding to the first slice.
  • the receiving unit 1301 is configured to: receive a request message sent by a second slice authentication network element, wherein the request message sent by the second slice authentication network element is the third access sent by the management network element to the second slice authentication network element;
  • the terminal device moves from the first access management network element that supports the network slice authentication function. moving the access management network element to the second access management network element;
  • the receiving unit 1301 is further configured to: receive the authentication result corresponding to the first slice from the first access management network element or the first slice authentication network element;
  • the apparatus further includes a storage unit 1303 for storing the authentication result corresponding to the first slice.
  • the terminal device before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element the scope of services;
  • the receiving unit 1301 is further configured to: receive the first message from the first slice authentication network element or the second slice authentication network element; the apparatus further includes a processing unit 1304, configured to send the message according to the first message.
  • the authentication result corresponding to the first slice stored by the device is modified as authentication failure; or,
  • the receiving unit 1301 is further configured to: receive a second message from the first slice authentication network element or the second slice authentication network element; the apparatus further includes a processing unit 1304, configured to, according to the second message, The authentication result corresponding to the first slice stored by the device is deleted.
  • the dotted box in FIG. 13 is used to indicate that the storage unit 1303 and the processing unit 1304 are optional to the apparatus 1300 .
  • the apparatus 1400 may include:
  • the receiving unit 1401 is configured to: after the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function A request message from a network element for authorization, the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
  • the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function.
  • the access management network element is moved to the second access management network element, and the apparatus further includes:
  • Storage unit 1403 is used to save the authentication result corresponding to the first slice after the authentication corresponding to the first slice is completed;
  • the processing unit 1404 registers the identifier of the device with the data management network element.
  • the terminal device before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element the scope of services;
  • the receiving unit 1401 is further configured to: receive an authentication revocation message from the AAA server; the apparatus further includes a processing unit 1404, configured to store the authentication corresponding to the first slice according to the authentication revocation message The result is modified to authentication failure; or,
  • the receiving unit 1401 is further configured to: receive a re-authentication message from the AAA server; the apparatus further includes a processing unit 1404, configured to, according to the re-authentication message, store the authentication corresponding to the first slice. the right to result deletion; or,
  • the receiving unit 1401 is further configured to: receive a third message from the second slice authentication network element; the apparatus further includes a processing unit 1404, configured to correspond to the stored first slice according to the third message.
  • the authentication result of is modified to authentication failure; or,
  • the dotted box in FIG. 14 is used to indicate that the storage unit 1403 and the processing unit 1404 are optional to the apparatus 1400 .
  • an embodiment of the present application further provides a communication apparatus 1500, including:
  • the memory 1502 is located outside the apparatus 1500 .
  • the apparatus 1500 includes the memory 1502, the memory 1502 is connected to the at least one processor 1501, and the memory 1502 stores instructions executable by the at least one processor 1501.
  • the memory 1502 is located outside the apparatus 1500 .
  • the apparatus 1500 includes the memory 1502, the memory 1502 is connected to the at least one processor 1501, and the memory 1502 stores instructions executable by the at least one processor 1501.
  • Figure 15 shows with dashed lines that memory 1502 is optional to apparatus 1500.
  • the processor mentioned in the embodiments of the present application may be implemented by hardware or software.
  • the processor When implemented in hardware, the processor may be a logic circuit, an integrated circuit, or the like.
  • the processor When implemented in software, the processor may be a general-purpose processor implemented by reading software codes stored in memory.
  • the processor may be a central processing unit (Central Processing Unit, CPU), or other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application specific integrated circuit (Application Specific Integrated Circuit, ASIC) , Off-the-shelf Programmable Gate Array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
  • a general purpose processor may be a microprocessor or the processor may be any conventional processor or the like.
  • RAM Static RAM
  • DRAM Dynamic RAM
  • SDRAM Synchronous DRAM
  • SDRAM double data rate synchronous dynamic random access memory
  • Double Data Eate SDRAM DDR SDRAM
  • enhanced SDRAM ESDRAM
  • synchronous link dynamic random access memory Synchlink DRAM, SLDRAM
  • Direct Rambus RAM Direct Rambus RAM
  • memory described herein is intended to include, but not be limited to, these and any other suitable types of memory.
  • an embodiment of the present application further provides a computer-readable storage medium, including a program or an instruction.
  • a program or an instruction When the program or instruction is run on a computer, the above-mentioned method embodiments shown in FIG. 3 to FIG. 11 are implemented. The method executed by any one network element is executed.
  • an embodiment of the present application further provides a chip, which is coupled to a memory and used to read and execute program instructions stored in the memory, so that the method embodiments shown in FIG. 3 to FIG. 11 above are The method executed by any one of the network elements is executed.
  • an embodiment of the present application further provides a computer program product, which includes instructions, when running on a computer, to make the method executed by any one of the network elements in the method embodiments shown in FIG. 3 to FIG. 11 above. be executed.
  • the above-mentioned embodiments it may be implemented in whole or in part by software, hardware, firmware or any combination thereof.
  • software it can be implemented in whole or in part in the form of a computer program product.
  • the computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated.
  • the computer may be a general purpose computer, special purpose computer, computer network, or other programmable device.
  • the computer instructions may be stored in or transmitted from one computer-readable storage medium to another, for example, from a website site, computer, server, or data center via Transmission to another website site, computer, server, or data center by wired (eg, coaxial cable, optical fiber, digital subscriber line, DSL) or wireless (eg, infrared, wireless, microwave, etc.) means.
  • the computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes an integration of one or more available media.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Provided in the embodiments of the present application are a slice authentication method and a corresponding apparatus. After a terminal device moves from a service range of a second access management network element that does not support a network slice authentication function to a service range of a third access management network element that supports the network slice authentication function, the third access management network element can send a first request message to a first network element to acquire an authentication result of a first slice that needs to be authenticated, such that the third access management network element does not need to execute a network slice authentication process, and the system signaling overheads can thus be effectively saved. In addition, the terminal device no longer needs to wait for the third access management network element to completely execute the network slice authentication process before establishing a session for a specific network slice, thereby accelerating the process of service establishment, and reducing the service delay of the terminal device.

Description

一种切片鉴权方法及对应装置A slice authentication method and corresponding device
相关申请的交叉引用CROSS-REFERENCE TO RELATED APPLICATIONS
本申请要求在2020年08月07日提交中国专利局、申请号为202010791231.4、申请名称为“一种切片鉴权方法及对应装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims the priority of the Chinese patent application with the application number 202010791231.4 and the application title "A Slice Authentication Method and Corresponding Device" filed with the China Patent Office on August 7, 2020, the entire contents of which are incorporated herein by reference Applying.
技术领域technical field
本申请涉及通信技术领域,尤其涉及一种切片鉴权方法及对应装置。The present application relates to the field of communication technologies, and in particular, to a slice authentication method and a corresponding device.
背景技术Background technique
目前,终端设备在从旧的接入管理节点的服务范围进入新的接入管理节点的服务范围后,允许新的接入管理节点从旧的接入管理节点获取网络切片的鉴权结果,进而新的接入管理节点可以省去对终端设备执行网络切片鉴权过程,可以有效减少信令开销。但新的接入管理节点能够从旧的接入管理节点获取网络切片的鉴权结果的前提是,旧的接入管理节点支持网络切片鉴权功能,这是因为只有支持网络切片鉴权功能的接入管理节点才具有网络切片的鉴权结果。At present, after the terminal device enters the service range of the new access management node from the service range of the old access management node, the new access management node is allowed to obtain the authentication result of the network slice from the old access management node, and then The new access management node can eliminate the need to perform the network slice authentication process on the terminal device, which can effectively reduce signaling overhead. However, the premise that the new access management node can obtain the authentication result of the network slice from the old access management node is that the old access management node supports the network slice authentication function. This is because only the network slice authentication function is supported. Only the access management node has the authentication result of the network slice.
然而在实际应用中,旧的接入管理节点很可能不支持网络切片鉴权功能(即没有网络切片的鉴权结果)。例如,旧的接入管理节点是第四代(4th-Generation,4G)移动通信网络中的接入管理节点,或者旧的接入管理节点是第五代(5th-Generation,5G)中不支持网络切片鉴权功能的接入管理节点。这些情况将导致新的接入管理节点无法从旧的接入管理节点获得网络切片的鉴权结果,那么终端设备移动到新的接入管理节点的服务范围时,新的接入管理节点必须对终端设备执行网络切片鉴权流程才能获得鉴权结果,这致使系统信令开销增大,且增大了终端设备的业务时延。However, in practical applications, the old access management node may not support the network slice authentication function (ie, there is no network slice authentication result). For example, the old access management node is an access management node in the fourth generation (4th-Generation, 4G) mobile communication network, or the old access management node is not supported in the fifth generation (5th-Generation, 5G) The access management node of the network slice authentication function. These situations will cause the new access management node to fail to obtain the authentication result of the network slice from the old access management node. When the terminal device moves to the service range of the new access management node, the new access management node must The terminal device can obtain the authentication result only by executing the network slice authentication process, which increases the system signaling overhead and increases the service delay of the terminal device.
发明内容SUMMARY OF THE INVENTION
本申请实施例提供一种切片鉴权方法及对应装置,用于节省系统信令开销,降低终端设备的业务时延。Embodiments of the present application provide a slice authentication method and a corresponding device, which are used to save system signaling overhead and reduce service delay of terminal equipment.
第一方面,提供一种切片鉴权方法,包括:终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,所述第三接入管理网元向第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;所述第三接入管理网元接收来自所述第一网元的第一响应消息,所述第一响应消息包括所述第一切片对应的鉴权结果。In a first aspect, a slice authentication method is provided, including: after a terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, The third access management network element sends a first request message to the first network element, wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; The third access management network element receives a first response message from the first network element, where the first response message includes an authentication result corresponding to the first slice.
本申请实施例中,当终端设备从不支持网络切片鉴权功能的第二接入管理网元的服务范围移动至支持网络切片鉴权功能的第三接入管理网元的服务范围后,第三接入管理网元可以从第一网元获取到需要鉴权的第一切片的鉴权结果,从而无需执行网络切片鉴权流程,可以有效节省系统信令开销;同时终端设备也不再需要等待第三接入管理网元执行完网络切片鉴权流程后才能建立到特定网络切片的会话,加速了业务建立的过程,降低了终端设 备的业务时延。In this embodiment of the present application, after the terminal device moves from the service scope of the second access management network element that does not support the network slice authentication function to the service scope of the third access management network element that supports the network slice authentication function, the first The three access management network elements can obtain the authentication result of the first slice that needs to be authenticated from the first network element, so that the network slice authentication process does not need to be performed, and the system signaling overhead can be effectively saved; It is necessary to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice, which speeds up the process of service establishment and reduces the service delay of the terminal device.
一种可能的实施方式中,所述第一网元为数据管理网元;在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述方法还包括:所述第一接入管理网元或第一切片鉴权网元将所述第一切片对应的鉴权结果储存到所述数据管理网元。In a possible implementation manner, the first network element is a data management network element; before the terminal device moves from the second access management network element to the third access management network element, the The terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element, and the method further includes: the first access management network element or the first slice authentication The authority network element stores the authentication result corresponding to the first slice to the data management network element.
通过该实施方式,第一接入管理网元或第一切片鉴权网元将第一切片对应的鉴权结果储存到数据管理网元,使得终端设备从不支持网络切片鉴权功能的第二接入管理网元的服务范围移动至支持网络切片鉴权功能的第三接入管理网元的服务范围后,第三接入管理网元可以从数据管理网元获取到需要鉴权的第一切片的鉴权结果,保证了方案的可靠性。Through this embodiment, the first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice in the data management network element, so that the terminal device never supports the network slice authentication function. After the service scope of the second access management network element is moved to the service scope of the third access management network element that supports the network slice authentication function, the third access management network element can obtain the data that needs to be authenticated from the data management network element. The authentication result of the first slice ensures the reliability of the solution.
一种可能的实施方式中,所述第一网元为第二切片鉴权网元。In a possible implementation manner, the first network element is a second slice authentication network element.
通过该实施方式,终端设备从不支持网络切片鉴权功能的第二接入管理网元的服务范围移动至支持网络切片鉴权功能的第三接入管理网元的服务范围后,第三接入管理网元可以从第二切片鉴权网元获取到需要鉴权的第一切片的鉴权结果,进而不需要针对第一切片执行网络切片鉴权流程,可以节省系统信令开销,降低终端设备的业务时延。Through this embodiment, after the terminal device moves from the service scope of the second access management network element that does not support the network slice authentication function to the service scope of the third access management network element that supports the network slice authentication function, the third access management network element The incoming management network element can obtain the authentication result of the first slice that needs to be authenticated from the second slice authentication network element, and thus does not need to perform the network slice authentication process for the first slice, which can save system signaling overhead, Reduce the service delay of terminal equipment.
一种可能的实施方式中,在所述第三接入管理网元向第一网元发送第一请求消息之后,所述方法还包括:所述第二切片鉴权网元向数据管理网元发送所述第一切片的标识信息;所述第二切片鉴权网元接收来自所述数据管理网元的所述第一切片对应的鉴权结果;所述第二切片鉴权网元向所述第三接入管理网元发送所述第一切片对应的鉴权结果。In a possible implementation manner, after the third access management network element sends the first request message to the first network element, the method further includes: the second slice authentication network element sends a data management network element to the data management network element. Send the identification information of the first slice; the second slice authentication network element receives the authentication result corresponding to the first slice from the data management network element; the second slice authentication network element Send the authentication result corresponding to the first slice to the third access management network element.
通过该实施方式,终端设备从不支持网络切片鉴权功能的第二接入管理网元的服务范围移动至支持网络切片鉴权功能的第三接入管理网元的服务范围后,第三接入管理网元可以通过第二切片鉴权网元去获取数据管理网元上的第一切片对应的鉴权结果,进而不需要针对第一切片执行网络切片鉴权流程,可以节省系统信令开销,降低终端设备的业务时延。Through this embodiment, after the terminal device moves from the service scope of the second access management network element that does not support the network slice authentication function to the service scope of the third access management network element that supports the network slice authentication function, the third access management network element The incoming management network element can obtain the authentication result corresponding to the first slice on the data management network element through the second slice authentication network element, and thus does not need to perform the network slice authentication process for the first slice, which can save system information. Reduce the overhead and reduce the service delay of the terminal equipment.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述方法还包括:所述第一接入管理网元或第一切片鉴权网元将所述第一切片对应的鉴权结果储存到所述数据管理网元。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function. The access management network element is moved to the second access management network element, and the method further includes: the first access management network element or the first slice authentication network element The authentication result is stored in the data management network element.
通过该实施方式,第一接入管理网元或第一切片鉴权网元将第一切片对应的鉴权结果储存到数据管理网元,使得终端设备从不支持网络切片鉴权功能的第二接入管理网元的服务范围移动至支持网络切片鉴权功能的第三接入管理网元的服务范围后,第三接入管理网元可以从通过第二切片鉴权网元可以从数据管理网元获取到第一切片对应的鉴权结果,保证了方案的可靠性。Through this embodiment, the first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice in the data management network element, so that the terminal device never supports the network slice authentication function. After the service scope of the second access management network element is moved to the service scope of the third access management network element that supports the network slice authentication function, the third access management network element can be authenticated by the second slice from the network element. The data management network element obtains the authentication result corresponding to the first slice, which ensures the reliability of the solution.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备位于所述第二接入管理网元的服务范围时,所述方法还包括:第一切片鉴权网元或第二切片鉴权网元接收来自验证、授权和记账AAA服务器的鉴权撤回消息,根据所述鉴权撤回消息,将所述数据管理网元中储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,第一切片鉴权网元或第二切片鉴权网元接收来自AAA服务器的重鉴权消息,根据所述重鉴权消息,将所述数据管理网元中储存的所述第一切片对应的鉴权结果删除。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element When the scope of service is limited, the method further includes: the first slice authentication network element or the second slice authentication network element receives an authentication revocation message from the verification, authorization and accounting AAA server, and according to the authentication revocation message , modify the authentication result corresponding to the first slice stored in the data management network element to an authentication failure; or, the first slice authentication network element or the second slice authentication network element receives the data from the AAA server The re-authentication message, according to the re-authentication message, delete the authentication result corresponding to the first slice stored in the data management network element.
通过该实施方式,当数据管理网元存储第一切片的鉴权结果后,AAA服务器还可以针对第一切片触发的重鉴权或者鉴权结果撤回流程,提升了网络切片鉴权的灵活性。Through this implementation, after the data management network element stores the authentication result of the first slice, the AAA server can also trigger the re-authentication or the authentication result withdrawal process for the first slice, which improves the flexibility of network slice authentication. sex.
一种可能的实施方式中,在所述第三接入管理网元向第一网元发送第一请求消息之后,所述方法还包括:所述第二切片鉴权网元向第一切片鉴权网元发送所述第一切片的标识信息;所述第二切片鉴权网元接收来自所述第一切片鉴权网元的所述第一切片对应的鉴权结果;所述第二切片鉴权网元向所述第三接入管理网元发送所述第一切片对应的鉴权结果。In a possible implementation manner, after the third access management network element sends the first request message to the first network element, the method further includes: the second slice authentication network element sends the first slice to the first network element. The authentication network element sends the identification information of the first slice; the second slice authentication network element receives the authentication result corresponding to the first slice from the first slice authentication network element; The second slice authentication network element sends the authentication result corresponding to the first slice to the third access management network element.
通过该实施方式,终端设备从不支持网络切片鉴权功能的第二接入管理网元的服务范围移动至支持网络切片鉴权功能的第三接入管理网元的服务范围后,第三接入管理网元可以从第一切片鉴权网元获得的第一切片对应的鉴权结果,进而不需要针对第一切片执行网络切片鉴权流程,可以节省系统信令开销,降低终端设备的业务时延。Through this embodiment, after the terminal device moves from the service scope of the second access management network element that does not support the network slice authentication function to the service scope of the third access management network element that supports the network slice authentication function, the third access management network element The access management network element can obtain the authentication result corresponding to the first slice from the first slice authentication network element, so it is not necessary to perform the network slice authentication process for the first slice, which can save system signaling overhead and reduce terminal The service delay of the device.
一种可能的实施方式中,在所述第二切片鉴权网元向第一切片鉴权网元发送第三请求消息之前,所述方法还包括:所述第二切片鉴权网元向数据管理网元发送请求消息;所述第二切片鉴权网元接收来自所述数据管理网元的所述第一切片鉴权网元的标识;所述第二切片鉴权网元向第一切片鉴权网元发送第三请求消息,包括:所述第二切片鉴权网元根据所述第一切片鉴权网元的标识,向所述第一切片鉴权网元发送所述第一切片的标识信息。In a possible implementation manner, before the second slice authentication network element sends the third request message to the first slice authentication network element, the method further includes: the second slice authentication network element to the first slice authentication network element. The data management network element sends a request message; the second slice authentication network element receives the identifier of the first slice authentication network element from the data management network element; the second slice authentication network element reports to the first slice authentication network element Sending a third request message by all slice authentication network elements includes: the second slice authentication network element sends, according to the identifier of the first slice authentication network element, to the first slice authentication network element Identification information of the first slice.
通过该实施方式,第二切片鉴权网元可以从数据管理网元查询到第一切片对应的鉴权结果的保存位置(即第一切片鉴权网元),进而向第一切片鉴权网元发送第一切片的标识信息以从第一切片鉴权网元获取到第一切片对应的鉴权结果,保证了方案的可靠性。Through this implementation, the second slice authentication network element can query the storage location of the authentication result corresponding to the first slice (that is, the first slice authentication network element) from the data management network element, and then send the first slice authentication network element to the first slice. The authentication network element sends the identification information of the first slice to obtain the authentication result corresponding to the first slice from the first slice authentication network element, which ensures the reliability of the solution.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述方法还包括:在所述第一切片对应的鉴权完成之后,所述第一切片鉴权网元保存所述第一切片对应的鉴权结果,并将所述第一切片鉴权网元的标识注册到所述数据管理网元。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the method further includes: corresponding to the first slice After the authentication of the first slice is completed, the first slice authentication network element saves the authentication result corresponding to the first slice, and registers the identity of the first slice authentication network element to the data management network Yuan.
通过该实施方式,第一切片鉴权网元不仅保存第一切片对应的鉴权结果的,而且将第一切片鉴权网元的标识注册到数据管理网元,以便于后续其它网元查询第一切片对应的鉴权结果的保存位置,进一步提高了方案的可靠性。Through this embodiment, the first slice authentication network element not only stores the authentication result corresponding to the first slice, but also registers the identifier of the first slice authentication network element to the data management network element, so as to facilitate subsequent network elements of other networks. The storage location of the authentication result corresponding to the first slice is meta-queried, which further improves the reliability of the solution.
一种可能的实施方式中,所述第一网元为第一切片鉴权网元;在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述方法还包括:所述第一切片鉴权网元储存所述第一切片对应的鉴权结果。In a possible implementation manner, the first network element is a first slice authentication network element; when the terminal equipment moves from the second access management network element to the third access management network element Before, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element, and the method further includes: storing the first slice authentication network element The authentication result corresponding to the first slice.
通过该实施方式,第一切片管理网元储存第一切片对应的鉴权结果,终端设备从不支持网络切片鉴权功能的第二接入管理网元的服务范围移动至支持网络切片鉴权功能的第三接入管理网元的服务范围后,第三接入管理网元直接从第一切片管理网元获得的第一切片对应的鉴权结果,进而不需要针对第一切片执行网络切片鉴权流程,可以节省系统信令开销,降低终端设备的业务时延。Through this embodiment, the first slice management network element stores the authentication result corresponding to the first slice, and the terminal device moves from the service scope of the second access management network element that does not support the network slice authentication function to the network slice authentication function that supports network slice authentication. After the service scope of the third access management network element with the authorization function, the third access management network element directly obtains the authentication result corresponding to the first slice from the first slice management network element, and does not need to target all the first slices. The slice performs the network slice authentication process, which can save the system signaling overhead and reduce the service delay of the terminal equipment.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备位于所述第二接入管理网元的服务范围时,所述方法还包括:第一切片鉴权网元或第二切片鉴权网元接收来自AAA服务器的鉴权撤回消息,根据所述鉴权撤回消息,将所述第一切片鉴权网元中储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,第一切片鉴权网元或第二切片鉴权网元接收来自AAA服务器的重鉴权消息,根据所述重鉴权消息,将所述第一切片鉴权网元中储存的所述第一切片对应的鉴权结果删除。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element When the service scope is limited, the method further includes: the first slice authentication network element or the second slice authentication network element receives an authentication revocation message from the AAA server, and according to the authentication revocation message, revoking the first slice authentication The authentication result corresponding to the first slice stored in the slice authentication network element is modified to be an authentication failure; The authentication message, according to the re-authentication message, deletes the authentication result corresponding to the first slice stored in the first slice authentication network element.
通过该实施方式,当第一切片鉴权网元存储第一切片的鉴权结果后,AAA服务器还可 以针对第一切片触发重鉴权或者鉴权结果撤回流程,提升了网络切片鉴权的灵活性。Through this implementation, after the first slice authentication network element stores the authentication result of the first slice, the AAA server can also trigger the re-authentication or authentication result withdrawal process for the first slice, which improves the network slice authentication. flexibility of rights.
一种可能的实施方式中,在终端设备从所述第二接入管理网元移动到所述第三接入管理网元之后,所述第三接入管理网元向第一网元发送第一请求消息之前,还包括:所述第二接入管理网元为4G网络的移动管理节点MME,则所述第三接入管理网元确定所述第二接入管理网元不支持网络切片鉴权功能;或者,所述第三接入管理网元从所述第二接入管理网元获取所述终端设备的用户上下文,其中,所述用户上下文中不包含所述第一切片对应的鉴权结果,则所述第三接入管理网元确定所述第二接入管理网元不支持网络切片鉴权功能;或者,所述第三接入管理网元从所述第二接入管理网元获取所述第二接入管理网元支持的特性列表,根据所述支持的特性列表确定所述第二接入管理网元不支持网络切片鉴权功能。In a possible implementation manner, after the terminal device moves from the second access management network element to the third access management network element, the third access management network element sends the first network element to the first network element. Before the request message, it further includes: the second access management network element is a mobility management node MME of a 4G network, and the third access management network element determines that the second access management network element does not support network slicing authentication function; or, the third access management network element obtains the user context of the terminal device from the second access management network element, wherein the user context does not include the corresponding first slice the authentication result, the third access management network element determines that the second access management network element does not support the network slice authentication function; The access management network element obtains a list of features supported by the second access management network element, and determines, according to the supported feature list, that the second access management network element does not support the network slice authentication function.
该实施方式提供了多种第三接入管理网元确定第二接入管理网元不支持网络切片鉴权功能的实现方式,提高了方案的灵活性。This embodiment provides various implementation manners for the third access management network element to determine that the second access management network element does not support the network slice authentication function, which improves the flexibility of the solution.
第二方面,提供一种切片鉴权方法,包括:终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,所述第三接入管理网元向第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;所述第三接入管理网元接收来自所述第一网元的第一响应消息,所述第一响应消息包括所述第一切片对应的鉴权结果。In a second aspect, a slice authentication method is provided, including: after a terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, The third access management network element sends a first request message to the first network element, wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; The third access management network element receives a first response message from the first network element, where the first response message includes an authentication result corresponding to the first slice.
一种可能的实施方式中,所述第一网元为数据管理网元、第一切片鉴权网元、或第二切片鉴权网元。In a possible implementation manner, the first network element is a data management network element, a first slice authentication network element, or a second slice authentication network element.
一种可能的实施方式中,在终端设备从所述第二接入管理网元移动到所述第三接入管理网元之后,所述第三接入管理网元向第一网元发送第一请求消息之前,还包括:所述第二接入管理网元为4G网络的MME,则所述第三接入管理网元确定所述第二接入管理网元不支持网络切片鉴权功能;或者,所述第三接入管理网元从所述第二接入管理网元获取所述终端设备的用户上下文,其中,所述用户上下文中不包含所述第一切片对应的鉴权结果,则所述第三接入管理网元确定所述第二接入管理网元不支持网络切片鉴权功能;或者,所述第三接入管理网元从所述第二接入管理网元获取所述第二接入管理网元支持的特性列表,根据所述支持的特性列表确定所述第二接入管理网元不支持网络切片鉴权功能。In a possible implementation manner, after the terminal device moves from the second access management network element to the third access management network element, the third access management network element sends the first network element to the first network element. Before the request message, it further includes: the second access management network element is an MME of the 4G network, then the third access management network element determines that the second access management network element does not support the network slice authentication function ; or, the third access management network element obtains the user context of the terminal device from the second access management network element, wherein the user context does not include the authentication corresponding to the first slice As a result, the third access management network element determines that the second access management network element does not support the network slice authentication function; or, the third access management network element obtains information from the second access management network element The element obtains a feature list supported by the second access management network element, and determines, according to the supported feature list, that the second access management network element does not support a network slice authentication function.
第三方面,提供一种切片鉴权方法,包括:终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,数据管理网元接收来自所述第三接入管理网元的请求消息,所述请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;所述数据管理网元返回响应消息给所述第三接入管理网元,所述响应消息包括所述第一切片对应的鉴权结果。In a third aspect, a slice authentication method is provided, including: after a terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, The data management network element receives a request message from the third access management network element, where the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; the data management The network element returns a response message to the third access management network element, where the response message includes the authentication result corresponding to the first slice.
一种可能的实施方式中,数据管理网元接收来自所述第三接入管理网元的请求消息,包括:数据管理网元接收第二切片鉴权网元发送的请求消息,其中所述第二切片鉴权网元发送的请求消息是所述第三接入管理网元发送给所述第二切片鉴权网元的;所述数据管理网元返回响应消息给所述第三接入管理网元,包括:所述数据管理网元将响应消息发送给所述第二切片鉴权网元,通过所述第二切片鉴权网元将所述响应消息发送给所述第三接入管理网元。In a possible implementation manner, the data management network element receiving the request message from the third access management network element includes: the data management network element receiving the request message sent by the second slice authentication network element, wherein the third access management network element receives the request message sent by the second slice authentication network element. The request message sent by the two-slice authentication network element is sent by the third access management network element to the second slice authentication network element; the data management network element returns a response message to the third access management network element network element, including: the data management network element sends a response message to the second slice authentication network element, and sends the response message to the third access management network element through the second slice authentication network element network element.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述 第二接入管理网元,所述方法还包括:所述数据管理网元接收来自第一接入管理网元或第一切片鉴权网元的第一切片对应的鉴权结果;所述数据管理网元储存所述第一切片对应的鉴权结果。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function. The access management network element is moved to the second access management network element, and the method further includes: the data management network element receives the first access management network element from the first access management network element or the first slice authentication network element. The authentication result corresponding to the slice; the data management network element stores the authentication result corresponding to the first slice.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备位于所述第二接入管理网元的服务范围时,所述方法还包括:所述数据管理网元接收来自第一切片鉴权网元或第二切片鉴权网元的第一消息,根据所述第一消息将储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,所述数据管理网元接收来自第一切片鉴权网元或第二切片鉴权网元的第二消息,根据所述第二消息,将储存的所述第一切片对应的鉴权结果删除。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element When the service scope is limited, the method further includes: receiving, by the data management network element, a first message from the first slice authentication network element or the second slice authentication network element, and storing the stored data according to the first message. The authentication result corresponding to the first slice is modified to be an authentication failure; or, the data management network element receives the second message from the first slice authentication network element or the second slice authentication network element, according to the described The second message deletes the stored authentication result corresponding to the first slice.
第四方面,提供一种切片鉴权方法,包括:终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,第一切片鉴权网元接收来自第二切片鉴权网元的请求消息,所述请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;所述第一切片鉴权网元返回响应消息给所述第二切片鉴权网元,所述响应消息包括所述第一切片对应的鉴权结果。In a fourth aspect, a slice authentication method is provided, including: after a terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, The first slice authentication network element receives a request message from the second slice authentication network element, where the request message includes identification information of the first slice, and the first slice is a slice that needs to be authenticated; the The first slice authentication network element returns a response message to the second slice authentication network element, where the response message includes an authentication result corresponding to the first slice.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述方法还包括:在所述第一切片对应的鉴权完成之后,所述第一切片鉴权网元保存所述第一切片对应的鉴权结果,并将所述第一切片鉴权网元的标识注册到数据管理网元。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function. The access management network element is moved to the second access management network element, and the method further includes: after the authentication corresponding to the first slice is completed, the first slice authentication network element saves the The authentication result corresponding to the first slice is registered, and the identifier of the authentication network element of the first slice is registered to the data management network element.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备位于所述第二接入管理网元的服务范围时,所述方法还包括:所述第一切片鉴权网元接收来自AAA服务器的鉴权撤回消息,根据所述鉴权撤回消息将储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,所述第一切片鉴权网元接收来自AAA服务器的重鉴权消息,根据所述重鉴权消息,将储存的所述第一切片对应的鉴权结果删除;或者,所述第一切片鉴权网元接收来自第二切片鉴权网元的第三消息,根据所述第三消息将储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,所述第一切片鉴权网元接收来自第二切片鉴权网元的第四消息,根据所述第四消息,将储存的所述第一切片对应的鉴权结果删除。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element When the service scope is limited, the method further includes: the first slice authentication network element receives an authentication revocation message from the AAA server, and stores the authentication revocation message corresponding to the first slice according to the authentication revocation message. The authorization result is modified to authentication failure; or, the first slice authentication network element receives the re-authentication message from the AAA server, and according to the re-authentication message, stores the authentication corresponding to the first slice. or, the first slice authentication network element receives the third message from the second slice authentication network element, and stores the authentication result corresponding to the first slice according to the third message Modified as authentication failure; or, the first slice authentication network element receives the fourth message from the second slice authentication network element, and according to the fourth message, stores the corresponding first slice The authentication result is deleted.
第五方面,提供一种切片鉴权系统,包括:终端设备、不支持网络切片鉴权功能的第二接入管理网元、支持网络切片鉴权功能的第三接入管理网元以及第一网元;其中,所述第三接入管理网元用于:在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元后,向所述第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;所述第一网元用于:接收所述第一请求消息,并发送第一响应消息给所述第三接入管理网元,所述第一响应消息包括所述第一切片对应的鉴权结果;所述第三接入管理网元还用于:接收来自所述第一网元的所述第一响应消息。A fifth aspect provides a slice authentication system, including: a terminal device, a second access management network element that does not support the network slice authentication function, a third access management network element that supports the network slice authentication function, and a first access management network element. network element; wherein, the third access management network element is configured to: after the terminal equipment moves from the second access management network element to the third access management network element, to the first access management network element The network element sends a first request message, wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; the first network element is used for: receiving the the first request message, and send a first response message to the third access management network element, where the first response message includes the authentication result corresponding to the first slice; the third access management network element is further used for: receiving the first response message from the first network element.
一种可能的实施方式中,所述第一网元为数据管理网元,所述系统还包括第一接入管理网元和第一切片鉴权网元;在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元;所述第一接入管理网元或第一切片鉴权网元用于:将所述第一切片对 应的鉴权结果储存到所述数据管理网元。In a possible implementation manner, the first network element is a data management network element, and the system further includes a first access management network element and a first slice authentication network element; Before the second access management network element moves to the third access management network element, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element ; the first access management network element or the first slice authentication network element is used for: storing the authentication result corresponding to the first slice to the data management network element.
一种可能的实施方式中,所述第一网元为第二切片鉴权网元。In a possible implementation manner, the first network element is a second slice authentication network element.
一种可能的实施方式中,所述第二切片鉴权网元用于:在所述第三接入管理网元向第一网元发送第一请求消息之后,向数据管理网元发送所述第一切片的标识信息;接收来自所述数据管理网元的所述第一切片对应的鉴权结果;向所述第三接入管理网元发送所述第一切片对应的鉴权结果。In a possible implementation manner, the second slice authentication network element is configured to: after the third access management network element sends the first request message to the first network element, send the identification information of the first slice; receiving the authentication result corresponding to the first slice from the data management network element; sending the authentication corresponding to the first slice to the third access management network element result.
一种可能的实施方式中,所述系统还包括第一接入管理网元和第一切片鉴权网元;在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元;所述第一接入管理网元或第一切片鉴权网元用于:将所述第一切片对应的鉴权结果储存到所述数据管理网元。In a possible implementation manner, the system further includes a first access management network element and a first slice authentication network element; when the terminal device moves from the second access management network element to the first access management network element Before the third access management network element, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element; the first access management network element or the third access management network element The one slice authentication network element is used for: storing the authentication result corresponding to the first slice to the data management network element.
一种可能的实施方式中,所述系统还包括所述第一切片鉴权网元;所述第二切片鉴权网元用于:在所述第三接入管理网元向第一网元发送第一请求消息之后,向第一切片鉴权网元发送所述第一切片的标识信息;所述第一切片鉴权网元用于:接收来自所述第二切片鉴权网元的所述第一切片的标识信息,向所述第二切片鉴权网元发送所述第一切片对应的鉴权结果;所述第二切片鉴权网元还用于:接收来自所述第一切片鉴权网元的所述第一切片对应的鉴权结果;向所述第三接入管理网元发送所述第一切片对应的鉴权结果。In a possible implementation manner, the system further includes the first slice authentication network element; the second slice authentication network element is used for: sending the third access management network element to the first network element. After sending the first request message, the first slice authentication network element sends the identification information of the first slice to the first slice authentication network element; the first slice authentication network element is used for: receiving the authentication information from the second slice The identification information of the first slice of the network element, and send the authentication result corresponding to the first slice to the second slice authentication network element; the second slice authentication network element is further used for: receiving The authentication result corresponding to the first slice from the first slice authentication network element; and sending the authentication result corresponding to the first slice to the third access management network element.
一种可能的实施方式中,所述第二切片鉴权网元还用于:在所述第二切片鉴权网元向第一切片鉴权网元发送第三请求消息之前,向数据管理网元发送请求消息;接收来自所述数据管理网元的所述第一切片鉴权网元的标识;所述第二切片鉴权网元在向第一切片鉴权网元发送第三请求消息时,具体用于:根据所述第一切片鉴权网元的标识,向所述第一切片鉴权网元发送所述第一切片的标识信息。In a possible implementation manner, the second slice authentication network element is further configured to: before the second slice authentication network element sends the third request message to the first slice authentication network element, send a request message to the data management network element. The network element sends a request message; receives the identifier of the first slice authentication network element from the data management network element; the second slice authentication network element is sending the third slice authentication network element to the first slice authentication network element. When the request message is used, it is specifically used for: sending the identification information of the first slice to the first slice authentication network element according to the identifier of the first slice authentication network element.
一种可能的实施方式中,所述第一切片鉴权网元还用于:在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,在所述第一切片对应的鉴权完成之后,保存所述第一切片对应的鉴权结果,并将所述第一切片鉴权网元的标识注册到所述数据管理网元。In a possible implementation manner, the first slice authentication network element is further configured to: before the terminal device moves from the second access management network element to the third access management network element, After the authentication corresponding to the first slice is completed, the authentication result corresponding to the first slice is saved, and the identifier of the authentication network element of the first slice is registered to the data management network element.
一种可能的实施方式中,所述第一网元为第一切片鉴权网元;在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元;所述第一切片鉴权网元还用于:储存所述第一切片对应的鉴权结果。In a possible implementation manner, the first network element is a first slice authentication network element; when the terminal equipment moves from the second access management network element to the third access management network element Before, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element; the first slice authentication network element is further used for: storing the The authentication result corresponding to the first slice.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备位于所述第二接入管理网元的服务范围时,第一切片鉴权网元或第二切片鉴权网元还用于:接收来自验证、授权和记账AAA服务器的鉴权撤回消息,根据所述鉴权撤回消息,将所述数据管理网元中储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,接收来自AAA服务器的重鉴权消息,根据所述重鉴权消息,将所述数据管理网元中储存的所述第一切片对应的鉴权结果删除。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element When the service scope of the first slice authentication network element or the second slice authentication network element is also used for: receiving the authentication revocation message from the verification, authorization and accounting AAA server, and according to the authentication revocation message, The authentication result corresponding to the first slice stored in the data management network element is modified to be an authentication failure; or, receiving a re-authentication message from the AAA server, and according to the re-authentication message, the data The authentication result corresponding to the first slice stored in the management network element is deleted.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备位于所述第二接入管理网元的服务范围时,第一切片鉴权网元或第二切片鉴权网元还用于:接收来自AAA服务器的鉴权撤回消息,根据所述鉴权撤回消息,将所述第一切片鉴权网元中储存的所述第一切片对应的鉴权结果修改为鉴权失 败;或者,接收来自AAA服务器的重鉴权消息,根据所述重鉴权消息,将所述第一切片鉴权网元中储存的所述第一切片对应的鉴权结果删除。In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element When the service scope of the first slice authentication network element or the second slice authentication network element is further used to: receive an authentication revocation message from the AAA server, and according to the authentication revocation message, convert the first slice authentication The authentication result corresponding to the first slice stored in the authentication network element is modified to be an authentication failure; or, a re-authentication message from the AAA server is received, and according to the re-authentication message, the first The authentication result corresponding to the first slice stored in the slice authentication network element is deleted.
一种可能的实施方式中,在终端设备从所述第二接入管理网元移动到所述第三接入管理网元之后,所述第三接入管理网元向第一网元发送第一请求消息之前,所述第三接入管理网元还用于:所述第二接入管理网元为4G网络的移动管理节点MME,则确定所述第二接入管理网元不支持网络切片鉴权功能;或者,从所述第二接入管理网元获取所述终端设备的用户上下文,其中,所述用户上下文中不包含所述第一切片对应的鉴权结果,则确定所述第二接入管理网元不支持网络切片鉴权功能;或者,从所述第二接入管理网元获取所述第二接入管理网元支持的特性列表,根据所述支持的特性列表确定所述第二接入管理网元不支持网络切片鉴权功能。In a possible implementation manner, after the terminal device moves from the second access management network element to the third access management network element, the third access management network element sends the first network element to the first network element. Before a request message, the third access management network element is further configured to: the second access management network element is a mobility management node MME of the 4G network, and then determine that the second access management network element does not support the network slice authentication function; or, obtain the user context of the terminal device from the second access management network element, where the user context does not contain the authentication result corresponding to the first slice, then determine the user context of the terminal device. the second access management network element does not support the network slice authentication function; or, obtain a feature list supported by the second access management network element from the second access management network element, according to the supported feature list It is determined that the second access management network element does not support the network slice authentication function.
第六方面,提供一种切片鉴权装置,可以例如为第三接入管理节网元或者设置在第三接入管理节网元内部的芯片,该装置包括用于执行上述第二方面或第二方面任一种可能的实现方式所述方法的模块。A sixth aspect provides a slice authentication device, which can be, for example, a network element of a third access management node or a chip set inside the network element of the third access management node, and the device includes a device for performing the second aspect or the first Modules of the method described in any possible implementation manner of the second aspect.
示例性的,该装置可以包括:发送单元,用于:在终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的所述装置后,向第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;接收单元,用于接收来自所述第一网元的第一响应消息,所述第一响应消息包括所述第一切片对应的鉴权结果。Exemplarily, the apparatus may include: a sending unit, configured to: after the terminal device moves from the second access management network element that does not support the network slice authentication function to the apparatus that supports the network slice authentication function, send the message to the first A network element sends a first request message, wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; a receiving unit is configured to receive information from the first slice. The first response message of the network element, where the first response message includes the authentication result corresponding to the first slice.
第七方面,提供一种切片鉴权装置,可以例如为数据管理网元或者设置在数据管理网元内部的芯片,该装置包括用于执行上述第三方面或第三方面任一种可能的实现方式所述方法的模块。In a seventh aspect, a slice authentication device is provided, which can be, for example, a data management network element or a chip set inside the data management network element, and the device includes the third aspect or any possible implementation of the third aspect. A module of the method described in the manner.
示例性的,该装置可以包括:接收单元,用于在终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,接收来自所述第三接入管理网元的请求消息,所述请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;发送单元,用于发送响应消息给所述第三接入管理网元,所述响应消息包括所述第一切片对应的鉴权结果。Exemplarily, the apparatus may include: a receiving unit configured to, after the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function , receiving a request message from the third access management network element, where the request message includes the identification information of the first slice, and the first slice is the slice that needs to be authenticated; the sending unit is used to send a response message to the third access management network element, and the response message includes the authentication result corresponding to the first slice.
第八方面,提供一种切片鉴权装置,可以例如为第一切片鉴权网元或者设置在第一切片鉴权网元内部的芯片,该装置包括用于执行上述第四方面或第四方面任一种可能的实现方式所述方法的模块。In an eighth aspect, a slice authentication device is provided, which can be, for example, a first slice authentication network element or a chip arranged inside the first slice authentication network element, and the device includes a device for performing the fourth aspect or the first A module of the method described in any possible implementation manner of the four aspects.
示例性的,该装置可以包括:接收单元,用于:在终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,接收来自第二切片鉴权网元的请求消息,所述请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;发送单元,用于发送响应消息给所述第二切片鉴权网元,所述响应消息包括所述第一切片对应的鉴权结果。Exemplarily, the apparatus may include: a receiving unit, configured to: when the terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function Then, receive a request message from the second slice authentication network element, where the request message includes the identification information of the first slice, and the first slice is the slice that needs to be authenticated; the sending unit is used to send a response message The network element is authenticated for the second slice, and the response message includes the authentication result corresponding to the first slice.
第九方面,提供一种通信装置,包括:至少一个处理器;以及与所述至少一个处理器通信连接的通信接口;所述至少一个处理器通过执行存储器存储的指令,使得所述装置通过所述通信接口执行如第二方面或第二方面任一种可能的实施方式或第三方面或第三方面任一种可能的实施方式或第四方面或第四方面任一种可能的实施方式中所述的方法。In a ninth aspect, a communication apparatus is provided, comprising: at least one processor; and a communication interface communicatively connected to the at least one processor; The communication interface executes as in the second aspect or any possible implementation manner of the second aspect or the third aspect or any possible implementation manner of the third aspect or the fourth aspect or any possible implementation manner of the fourth aspect the method described.
可选的,所述存储器位于所述装置之外。Optionally, the memory is located outside the device.
可选的,所述装置包括所述存储器,所述存储器与所述至少一个处理器相连,所述存 储器存储有可被所述至少一个处理器执行的指令。Optionally, the apparatus includes the memory connected to the at least one processor, the memory storing instructions executable by the at least one processor.
第十方面,提供一种计算机可读存储介质,包括程序或指令,当所述程序或指令在计算机上运行时,使得如第二方面或第二方面任一种可能的实施方式或第三方面或第三方面任一种可能的实施方式或第四方面或第四方面任一种可能的实施方式中所述的方法被执行。In a tenth aspect, a computer-readable storage medium is provided, comprising a program or an instruction, when the program or instruction is executed on a computer, such as the second aspect or any possible implementation manner of the second aspect or the third aspect, the program or instruction is executed. or any of the possible embodiments of the third aspect or the method described in the fourth aspect or any of the possible embodiments of the fourth aspect is performed.
第十一方面,提供一种芯片,所述芯片与存储器耦合,用于读取并执行所述存储器中存储的程序指令,使得如第二方面或第二方面任一种可能的实施方式或第三方面或第三方面任一种可能的实施方式或第四方面或第四方面任一种可能的实施方式中所述的方法被执行。In an eleventh aspect, a chip is provided, the chip is coupled with a memory, and is used for reading and executing program instructions stored in the memory, so that the second aspect or any possible implementation manner of the second aspect or the first The method described in the third aspect or any possible embodiment of the third aspect or the fourth aspect or any possible embodiment of the fourth aspect is performed.
第十二方面,提供一种计算机程序产品,包括指令,当其在计算机上运行时,使得如第二方面或第二方面任一种可能的实施方式或第三方面或第三方面任一种可能的实施方式或第四方面或第四方面任一种可能的实施方式中所述的方法被执行。A twelfth aspect provides a computer program product comprising instructions which, when run on a computer, cause as in the second aspect or any of the possible embodiments of the second aspect or the third aspect or any of the third aspects The method described in the possible embodiments or the fourth aspect or any of the possible embodiments of the fourth aspect is performed.
附图说明Description of drawings
图1为网络切片鉴权的流程图;Fig. 1 is the flow chart of network slice authentication;
图2本申请实施例适用的一种通信系统的网络架构图;FIG. 2 is a network architecture diagram of a communication system to which an embodiment of the present application is applicable;
图3为本申请实施例提供的一种切片鉴权方法的流程图;3 is a flowchart of a slice authentication method provided by an embodiment of the present application;
图4为本实施例提供的一种具体的切片鉴权方法的流程图;4 is a flowchart of a specific slice authentication method provided in this embodiment;
图5为本申请实施例提供的一种鉴权结果撤回方法和重鉴权方法的流程图;5 is a flowchart of a method for withdrawing an authentication result and a method for re-authentication provided by an embodiment of the present application;
图6为本申请实施例提供的另一种具体的切片鉴权方法的流程图;6 is a flowchart of another specific slice authentication method provided by an embodiment of the present application;
图7为本申请实施例提供的另一种鉴权结果撤回方法和重鉴权方法的流程图;7 is a flowchart of another authentication result withdrawal method and re-authentication method provided by an embodiment of the present application;
图8为本实施例提供的另一种具体的切片鉴权方法的流程图;FIG. 8 is a flowchart of another specific slice authentication method provided in this embodiment;
图9为本申请实施例提供的另一种鉴权结果撤回方法和重鉴权方法的流程图;9 is a flowchart of another authentication result withdrawal method and re-authentication method provided by an embodiment of the present application;
图10为本实施例提供的另一种具体的切片鉴权方法的流程图;10 is a flowchart of another specific slice authentication method provided in this embodiment;
图11为本申请实施例提供的另一种鉴权结果撤回方法和重鉴权方法的流程图;11 is a flowchart of another authentication result withdrawal method and re-authentication method provided by an embodiment of the present application;
图12为本申请实施例提供的一种切片鉴权装置的结构示意图;12 is a schematic structural diagram of a slice authentication apparatus provided by an embodiment of the present application;
图13为本申请实施例提供的另一种切片鉴权装置的结构示意图;13 is a schematic structural diagram of another slice authentication apparatus provided by an embodiment of the present application;
图14为本申请实施例提供的另一种切片鉴权装置的结构示意图;14 is a schematic structural diagram of another slice authentication apparatus provided by an embodiment of the present application;
图15为本申请实施例提供的一种通信装置的结构示意图。FIG. 15 is a schematic structural diagram of a communication apparatus according to an embodiment of the present application.
具体实施方式detailed description
网络切片鉴权和授权(Network Slice-Specific Authentication and Authorization,NSSAA)功能用于对终端设备签约的切片进行鉴权和授权。The Network Slice-Specific Authentication and Authorization (NSSAA) function is used to authenticate and authorize slices subscribed by terminal devices.
图1为网络切片鉴权的流程图,如图1所示,接入管理节点根据终端设备的签约数据中签约的切片信息,针对需要执行网络切片鉴权的切片触发网络切片鉴权流程:Figure 1 is a flowchart of network slice authentication. As shown in Figure 1, the access management node triggers the network slice authentication process for the slice that needs to perform network slice authentication according to the slice information signed in the subscription data of the terminal device:
S101、接入管理节点发送网络切片鉴权请求消息给终端设备,该请求消息中包含切片标识:单个网络切片选择辅助信息(Single Network Slice Selection Assistance Information,S-NSSAI)。S101. The access management node sends a network slice authentication request message to the terminal device, where the request message includes a slice identifier: single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI).
S102、终端设备收到该请求消息后,回复响应消息给终端设备,该响应消息中包含切 片标识S-NSSAI和扩展鉴权协议(Extensible Authentication Protocol,EAP)消息,EAP消息中包含终端设备分配的EAP标识。S102. After receiving the request message, the terminal device replies to the terminal device with a response message, where the response message includes the slice identifier S-NSSAI and the Extensible Authentication Protocol (EAP) message, and the EAP message includes the information allocated by the terminal device. EAP ID.
S103、接入管理节点发送请求消息给切片鉴权功能,该请求消息中包含用户标识:通用公开用户标识(Generic Public Subscription Identifier,GPSI),切片标识S-NSSAI,和步骤S102中接入管理节点收到的EAP消息。S103. The access management node sends a request message to the slice authentication function, where the request message includes a user identifier: a Generic Public Subscription Identifier (GPSI), a slice identifier S-NSSAI, and the access management node in step S102 EAP message received.
S104、切片鉴权功能发送验证、授权和记账(Authentication,Authorization,Accounting,AAA)协议消息给AAA服务器,该AAA协议消息中包含步骤S103中切片鉴权功能收到的用户标识GPSI、切片标识S-NSSAI和EAP消息。S104, the slice authentication function sends an authentication, authorization, and accounting (Authentication, Authorization, Accounting, AAA) protocol message to the AAA server, where the AAA protocol message includes the user identifier GPSI, slice identifier received by the slice authentication function in step S103 S-NSSAI and EAP messages.
S105、AAA服务器回复AAA协议消息给切片鉴权功能,该AAA协议消息中包含用户标识GPSI、切片标识S-NSSAI和发送给终端设备的EAP消息。S105, the AAA server replies an AAA protocol message to the slice authentication function, where the AAA protocol message includes the user identifier GPSI, the slice identifier S-NSSAI, and the EAP message sent to the terminal device.
S106、切片鉴权功能回复响应消息给接入管理节点,该响应消息中包含步骤S105中切片鉴权功能收到的用户标识GPSI、切片标识S-NSSAI和EAP消息。S106 , the slice authentication function replies to the access management node with a response message, where the response message includes the user identifier GPSI, slice identifier S-NSSAI and EAP message received by the slice authentication function in step S105 .
S107、接入管理节点发送请求消息给终端设备,该请求消息中包含切片标识S-NSSAI和EAP消息。S107: The access management node sends a request message to the terminal device, where the request message includes the slice identifier S-NSSAI and the EAP message.
S108、终端设备收到网络切片鉴权请求消息后,回复响应消息给接入管理节点,该响应消息中包含切片标识S-NSSAI和发送给AAA服务器EAP消息。S108. After receiving the network slice authentication request message, the terminal device replies to the access management node with a response message, where the response message includes the slice identifier S-NSSAI and an EAP message sent to the AAA server.
S109、接入管理节点发送请求消息给切片鉴权功能,该请求消息中包含用户标识GPSI、切片标识S-NSSAI和步骤S108中接入管理节点收到的EAP消息。S109, the access management node sends a request message to the slice authentication function, where the request message includes the user identifier GPSI, the slice identifier S-NSSAI, and the EAP message received by the access management node in step S108.
S1010、切片鉴权功能发送AAA协议消息给AAA服务器,该AAA协议消息中包含步骤S109中切片鉴权功能收到的用户标识GPSI、切片标识S-NSSAI和EAP消息。S1010. The slice authentication function sends an AAA protocol message to the AAA server, where the AAA protocol message includes the user identifier GPSI, slice identifier S-NSSAI and EAP message received by the slice authentication function in step S109.
需要说明的是,步骤S105~S1010,是AAA服务器和终端设备之间完成一次EAP消息的交互的过程(EAP认证过程),终端设备和AAA服务器之间通过EAP认证过程完成相互认证,如AAA服务器验证终端设备的合法身份,终端设备验证AAA服务器的合法身份等。接入管理节点和切片鉴权功能在此过程中只用于转发终端设备和AAA服务器之间的EAP消息。如果AAA服务器和终端设备之间需要多次EAP消息交互才能完成鉴权过程,则步骤S105至S1010可以多次执行,这里不再赘述。It should be noted that steps S105 to S1010 are the process of completing an EAP message interaction between the AAA server and the terminal device (EAP authentication process), and the terminal device and the AAA server complete mutual authentication through the EAP authentication process, such as the AAA server. Verify the legal identity of the terminal device, and the terminal device verifies the legal identity of the AAA server, etc. The access management node and slice authentication function are only used to forward EAP messages between the terminal device and the AAA server in this process. If multiple EAP message exchanges are required between the AAA server and the terminal device to complete the authentication process, steps S105 to S1010 may be performed multiple times, which will not be repeated here.
S1011、AAA服务器回复AAA协议消息给切片鉴权功能,该AAA协议消息中包含用户标识GPSI、切片标识S-NSSAI、发送给终端设备的EAP消息和针对此切片的鉴权结果(EAP成功/失败)。S1011, the AAA server replies an AAA protocol message to the slice authentication function, where the AAA protocol message includes the user identity GPSI, the slice identity S-NSSAI, the EAP message sent to the terminal device, and the authentication result for the slice (EAP success/failure). ).
S1012、切片鉴权功能回复响应消息给接入管理节点,该响应消息中包含步骤S1011中切片鉴权功能收到的用户标识GPSI、切片标识S-NSSAI、EAP消息和鉴权结果(EAP成功/失败);S1012, the slice authentication function replies a response message to the access management node, and the response message includes the user identifier GPSI, slice identifier S-NSSAI, EAP message and authentication result (EAP success/ Fail);
S1013、接入管理节点发送网络切片鉴权结果通知消息给终端设备,该通知消息中包含切片标识S-NSSAI和EAP消息,EAP消息中包含EAP鉴权成功或者失败的信息。S1013 , the access management node sends a network slice authentication result notification message to the terminal device, where the notification message includes the slice identifier S-NSSAI and an EAP message, and the EAP message includes information about EAP authentication success or failure.
通过上述网络切片鉴权流程,接入管理节点可以获知所述网络切片的鉴权结果为EAP成功/失败,并根据鉴权结果执行相应的操作。例如,针对EAP成功的网络切片,接入管理节点允许终端设备建立到该网络切片的会话;针对EAP失败的网络切片,接入管理节点不允许终端设备建立到该网络切片的会话。Through the above network slice authentication process, the access management node can learn that the authentication result of the network slice is EAP success/failure, and perform corresponding operations according to the authentication result. For example, for a network slice where EAP succeeds, the access management node allows the terminal device to establish a session to the network slice; for a network slice where EAP fails, the access management node does not allow the terminal device to establish a session to the network slice.
通过上述网络切片鉴权流程可以看出,网络切片鉴权过程涉及终端设备和AAA服务器之间的多次信令交互。而终端设备在移动过程中可能移出旧的接入管理节点的服务范围, 需要选择新的接入管理节点接入。在这种情况下,为了节约信令开销,新的接入管理节点可以从旧的接入管理节点获取网络切片的鉴权结果,进而可以不需要再针对新的接入管理节点再次执行上述网络切片鉴权过程。It can be seen from the above network slice authentication process that the network slice authentication process involves multiple signaling interactions between the terminal device and the AAA server. However, the terminal equipment may move out of the service range of the old access management node during the moving process, and a new access management node needs to be selected for access. In this case, in order to save signaling overhead, the new access management node can obtain the authentication result of the network slice from the old access management node, so that it is not necessary to perform the above network operation again for the new access management node. Slice authentication process.
但是,网络切片鉴权功能是第五代(5th-Generation,5G)移动通信网络才开始具有的功能,当终端设备从5G网络(第一接入管理节点)移动到4G网络(第二接入管理节点),再移动到5G网络(第三接入管理节点,第三接入管理节点和第一接入管理节点相同或不同)时,由于第二接入管理节点不支持网络切片鉴权功能,所以不会从第一接入管理节点获取网络切片的鉴权结果,致使第三接入管理节点无法从第二接入管理节点获得网络切片的鉴权结果,所以终端设备移动到第三接入管理节点时,需要重新执行上述网络切片鉴权流程来获得鉴权结果。However, the network slicing authentication function is a function that the 5th-Generation (5G) mobile communication network has only begun to have. When the terminal device moves from the 5G network (the first access management node) to the 4G network (the second access management node) management node), and then move to the 5G network (the third access management node, the third access management node and the first access management node are the same or different), because the second access management node does not support the network slice authentication function , so the authentication result of the network slice will not be obtained from the first access management node, so that the third access management node cannot obtain the authentication result of the network slice from the second access management node, so the terminal device moves to the third access management node. When entering the management node, the above-mentioned network slice authentication process needs to be re-executed to obtain the authentication result.
不仅如此,在实际部署中5G移动通信网络中也只有部分接入管理节点支持网络切片鉴权功能,另外部分的接入管理节点并不支持网络切片鉴权功能。当终端设备在5G网络中,从支持网络切片鉴权功能的第一接入管理节点移动到不支持网络切片鉴权功能的第二接入管理节点,再移动到支持网络切片鉴权功能的第三接入管理节点时,由于第二接入管理节点不支持网络切片鉴权功能,所以第三接入管理节点也无法从第二接入管理节点获得网络切片的鉴权结果,所以终端设备移动到第三接入管理节点时,仍需要重新执行上述网络切片鉴权流程来获得鉴权结果。Not only that, in the actual deployment of the 5G mobile communication network, only some access management nodes support the network slice authentication function, and other access management nodes do not support the network slice authentication function. When the terminal device is in the 5G network, it moves from the first access management node that supports the network slice authentication function to the second access management node that does not support the network slice authentication function, and then moves to the second access management node that supports the network slice authentication function. When three access management nodes are used, since the second access management node does not support the network slice authentication function, the third access management node cannot obtain the authentication result of the network slice from the second access management node, so the terminal equipment moves When reaching the third access management node, the above-mentioned network slice authentication process still needs to be re-executed to obtain the authentication result.
在上述两种终端设备移动场景中,第三接入管理节点都需要重新执行网络切片鉴权流程来获得网络切片对应的鉴权结果,增大了信令开销。并且,由于第三接入管理节点需要获得鉴权结果才能获知终端设备能否建立到所述网络切片的会话,而网络切片鉴权过程涉及终端设备和AAA服务器之间的多次信令交互,需要一定时间,所以给终端设备的业务也带来了一定的时延。In the above two terminal equipment moving scenarios, the third access management node needs to re-execute the network slice authentication process to obtain the authentication result corresponding to the network slice, which increases signaling overhead. Moreover, since the third access management node needs to obtain the authentication result to know whether the terminal device can establish a session to the network slice, and the network slice authentication process involves multiple signaling interactions between the terminal device and the AAA server, It takes a certain amount of time, so it also brings a certain delay to the service of the terminal device.
鉴于此,本申请实施例提供一种切片鉴权方法及对应装置。当终端设备处于任意接入管理节点的服务范围时,如果系统中针对任意网络切片执行了网络切片鉴权流程,获得了网络切片的鉴权结果,则可以将网络切片的鉴权结果保存到指定网元(该指定网元可以是数据管理功能或切片鉴权功能等,本申请实施例不做限制)。这样,当终端设备移动到新的接入管理节点的服务范围时,如果旧的接入管理节点支持网络切片鉴权功能,则新的接入管理节点不仅可以从旧的接入管理节点获取网络切片的鉴权结果,还可以从指定网元获取网络切片的鉴权结果;如果旧的接入管理节点不支持网络切片鉴权功能,则新的接入管理节点可以从指定网元获取网络切片的鉴权结果。可见,通过本申请实施例,终端设备在从旧的接入管理节点的服务范围进入新的接入管理节点的服务范围后,无论旧的接入管理节点是否支持网络切片鉴权功能,都无需重新执行网络切片鉴权流程就能获得网络切片的鉴权结果,因而可以节省系统信令开销,提升终端设备的业务性能。具体方案将在后文进一步详细介绍。In view of this, embodiments of the present application provide a slice authentication method and a corresponding device. When the terminal device is in the service scope of any access management node, if the network slice authentication process is performed for any network slice in the system, and the authentication result of the network slice is obtained, the authentication result of the network slice can be saved to the specified Network element (the specified network element may be a data management function or a slice authentication function, etc., which is not limited in this embodiment of the present application). In this way, when the terminal device moves to the service range of the new access management node, if the old access management node supports the network slice authentication function, the new access management node can not only obtain network access from the old access management node The authentication result of the slice can also be obtained from the specified network element. If the old access management node does not support the network slice authentication function, the new access management node can obtain the network slice from the specified network element. the authentication result. It can be seen that, through the embodiments of the present application, after the terminal device enters the service range of the new access management node from the service range of the old access management node, no matter whether the old access management node supports the network slice authentication function, it does not need to be The authentication result of the network slicing can be obtained by re-executing the network slicing authentication process, thereby saving the system signaling overhead and improving the service performance of the terminal device. The specific scheme will be introduced in further detail later.
本申请实施例的技术方案可以应用于各种通信系统,例如:第五代(5th generation,5G)通信系统、第六代(6th generation,6G)通信系统或未来的其他演进系统、或其他各种采用无线接入技术的无线通信系统等,只要该通信系统中存在网络切片鉴权需求,则均可以采用本申请实施例的技术方案。The technical solutions of the embodiments of the present application may be applied to various communication systems, for example, a fifth generation (5th generation, 5G) communication system, a sixth generation (6th generation, 6G) communication system, or other future evolution systems, or other various A wireless communication system adopting a wireless access technology, etc., as long as there is a network slice authentication requirement in the communication system, the technical solutions of the embodiments of the present application can be adopted.
图2示出了本申请实施例适用的一种通信系统的网络架构图,该通信系统包括终端设备、接入节点、接入管理网元、数据管理网元、切片鉴权网元以及AAA服务器等,终端 设备通过当前位置的接入节点接入无线网络。需要说明的是,图2中的每个网元都只是示例性地示出了一个,在实际应用中,该通信系统中的任意网元都可能是多个。FIG. 2 shows a network architecture diagram of a communication system to which an embodiment of the present application is applied, where the communication system includes a terminal device, an access node, an access management network element, a data management network element, a slice authentication network element, and an AAA server etc., the terminal device accesses the wireless network through the access node at the current location. It should be noted that each network element in FIG. 2 is only shown as one, and in practical applications, there may be multiple network elements in the communication system.
接入管理网元用于终端设备的设备注册、安全认证、移动性管理和位置管理等。The access management network element is used for device registration, security authentication, mobility management, and location management of terminal devices.
数据管理网元用于管理终端设备的签约数据。The data management network element is used to manage the subscription data of the terminal equipment.
切片鉴权网元用于转发终端设备和AAA服务器之间用于切片鉴权/切片重鉴权/鉴权结果撤回等的相关消息。The slice authentication network element is used to forward relevant messages between the terminal device and the AAA server for slice authentication/slice re-authentication/revocation of authentication results.
AAA服务器用于执行网络切片的EAP鉴权。The AAA server is used to perform EAP authentication for network slicing.
终端设备,又可称为终端,包括向用户提供语音和/或数据连通性的设备,例如可以包括具有无线连接功能的手持式设备、或连接到无线调制解调器的处理设备。该终端设备可以经无线接入网(radio access network,RAN)与核心网进行通信,与RAN交换语音和/或数据。该终端设备可以包括用户设备(user equipment,UE)、无线终端设备、移动终端设备、设备到设备通信(device-to-device,D2D)终端设备、V2X终端设备、机器到机器/机器类通信(machine-to-machine/machine-type communications,M2M/MTC)终端设备、物联网(internet of things,IoT)终端设备、订户单元(subscriber unit)、订户站(subscriber station),移动站(mobile station)、远程站(remote station)、接入点(access point,AP)、远程终端(remote terminal)、接入终端(access terminal)、用户终端(user terminal)、用户代理(user agent)、或用户装备(user device)等。例如,可以包括移动电话(或称为“蜂窝”电话),具有移动终端设备的计算机,便携式、袖珍式、手持式、计算机内置的移动装置等。例如,个人通信业务(personal communication service,PCS)电话、无绳电话、会话发起协议(session initiation protocol,SIP)话机、无线本地环路(wireless local loop,WLL)站、个人数字助理(personal digital assistant,PDA)、等设备。还包括受限设备,例如功耗较低的设备,或存储能力有限的设备,或计算能力有限的设备等。例如包括条码、射频识别(radio frequency identification,RFID)、传感器、全球定位系统(global positioning system,GPS)、激光扫描器等信息传感设备。A terminal device, also referred to as a terminal, includes a device that provides voice and/or data connectivity to a user, and may include, for example, a handheld device with wireless connectivity, or a processing device connected to a wireless modem. The terminal equipment may communicate with the core network via a radio access network (RAN), and exchange voice and/or data with the RAN. The terminal equipment may include user equipment (UE), wireless terminal equipment, mobile terminal equipment, device-to-device (D2D) terminal equipment, V2X terminal equipment, machine-to-machine/machine-type communication ( machine-to-machine/machine-type communications, M2M/MTC) terminal equipment, Internet of things (IoT) terminal equipment, subscriber unit (subscriber unit), subscriber station (subscriber station), mobile station (mobile station) , remote station (remote station), access point (access point, AP), remote terminal (remote terminal), access terminal (access terminal), user terminal (user terminal), user agent (user agent), or user equipment (user device), etc. For example, these may include mobile telephones (or "cellular" telephones), computers with mobile terminal equipment, portable, pocket-sized, hand-held, computer-embedded mobile devices, and the like. For example, personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (personal digital assistants), PDA), etc. Also includes constrained devices, such as devices with lower power consumption, or devices with limited storage capacity, or devices with limited computing power, etc. For example, it includes information sensing devices such as barcodes, radio frequency identification (RFID), sensors, global positioning system (GPS), and laser scanners.
作为示例而非限定,在本申请实施例中,该终端设备还可以是可穿戴设备。可穿戴设备也可以称为穿戴式智能设备或智能穿戴式设备等,是应用穿戴式技术对日常穿戴进行智能化设计、开发出可以穿戴的设备的总称,如眼镜、手套、手表、服饰及鞋等。可穿戴设备即直接穿在身上,或是整合到用户的衣服或配件的一种便携式设备。可穿戴设备不仅仅是一种硬件设备,更是通过软件支持以及数据交互、云端交互来实现强大的功能。广义穿戴式智能设备包括功能全、尺寸大、可不依赖智能手机实现完整或者部分的功能,例如:智能手表或智能眼镜等,以及只专注于某一类应用功能,需要和其它设备如智能手机配合使用,如各类进行体征监测的智能手环、智能头盔、智能首饰等。As an example and not a limitation, in this embodiment of the present application, the terminal device may also be a wearable device. Wearable devices can also be called wearable smart devices or smart wearable devices, etc. It is a general term for the application of wearable technology to intelligently design daily wear and develop wearable devices, such as glasses, gloves, watches, clothing and shoes. Wait. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothing or accessories. Wearable device is not only a hardware device, but also realizes powerful functions through software support, data interaction, and cloud interaction. In a broad sense, wearable smart devices include full-featured, large-scale, complete or partial functions without relying on smart phones, such as smart watches or smart glasses, and only focus on a certain type of application function, which needs to cooperate with other devices such as smart phones. Use, such as all kinds of smart bracelets, smart helmets, smart jewelry, etc. for physical sign monitoring.
而如上介绍的各种终端设备,如果位于车辆上(例如放置在车辆内或安装在车辆内),都可以认为是车载终端设备,车载终端设备例如也称为车载单元(on-board unit,OBU)。The various terminal devices described above, if they are located on the vehicle (for example, placed in the vehicle or installed in the vehicle), can be considered as on-board terminal equipment. For example, the on-board terminal equipment is also called on-board unit (OBU). ).
接入节点,例如包括接入网(access network,AN)设备,无线接入网(radio access network,RAN)设备,接入网设备例如基站(例如,接入点),可以是指接入网中在空口通过一个或多个小区与无线终端设备通信的设备。基站可用于将收到的空中帧与网际协议(IP)分组进行相互转换,作为终端设备与接入网的其余部分之间的路由器,其中接入网的其余部分可包括IP网络。网络设备还可协调对空口的属性管理。例如,网络设备可以包括长期演进(long term evolution,LTE)系统或高级长期演进(long term evolution-advanced,LTE-A) 中的演进型基站(NodeB或eNB或e-NodeB,evolved Node B),或者也可以包括第五代移动通信技术(the 5th generation,5G)新空口(new radio,NR)系统中的下一代节点B(next generation node B,gNB)或者下一代演进型基站(next generation evolved nodeB,ng-eNB)、en-gNB(enhanced next generation node B,gNB):增强的下一代基站;也可以包括云接入网(cloud radio access network,Cloud RAN)系统中的集中式单元(centralized unit,CU)和分布式单元(distributed unit,DU),或者还可以包括中继设备,本申请实施例并不限定。An access node, for example, includes an access network (AN) device, a radio access network (RAN) device, and an access network device such as a base station (eg, an access point), which may refer to an access network A device that communicates with a wireless terminal device over the air interface through one or more cells. The base station may be used to convert received air frames to and from Internet Protocol (IP) packets and act as a router between the terminal device and the rest of the access network, which may include the IP network. The network device can also coordinate the attribute management of the air interface. For example, the network device may include a long term evolution (long term evolution, LTE) system or an evolved base station (NodeB or eNB or e-NodeB, evolved Node B) in long term evolution-advanced (LTE-A), Or it can also include the next generation node B (gNB) or the next generation evolved base station (next generation evolved base station) in the new radio (new radio, NR) system of the fifth generation mobile communication technology (the 5th generation, 5G). nodeB, ng-eNB), en-gNB (enhanced next generation node B, gNB): Enhanced next-generation base station; can also include a centralized unit (centralized unit in a cloud radio access network, Cloud RAN) system unit, CU) and distributed unit (distributed unit, DU), or may also include a relay device, which is not limited in this embodiment of the present application.
应理解,图2所示的网络架构可以应用于实际的移动通信网络。例如,应用于5G移动通信网络时,接入管理节点可以为5G网络中的接入和移动性管理功能(Access&Mobility Function,AMF),数据管理功能可以为5G网络中的统一数据管理功能(Unified Data Management,UDM),切片鉴权功能可以为5G网络中的网络切片鉴权功能(Network Slice-Specific Authentication and Authorization Function,NSSAAF),AAA服务器可以为5G网络中的AAA服务器(AAA Server,AAA-S)。It should be understood that the network architecture shown in FIG. 2 can be applied to an actual mobile communication network. For example, when applied to a 5G mobile communication network, the access management node may be the access and mobility management function (AMF) in the 5G network, and the data management function may be the unified data management function (Unified Data Management) in the 5G network. Management, UDM), the slice authentication function can be the network slice authentication function (Network Slice-Specific Authentication and Authorization Function, NSSAAF) in the 5G network, and the AAA server can be the AAA server in the 5G network (AAA Server, AAA-S ).
为了使本申请实施例的目的、技术方案和优点更加清楚,下面将结合附图对本申请实施例的技术方案作进一步地详细描述。In order to make the objectives, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions of the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
本申请实施例中的术语“网络切片”和“切片”指的是同一内容,在不同的地方使用其中一种描述,二者可以互换。The terms "network slice" and "slice" in the embodiments of this application refer to the same content, and one of the descriptions is used in different places, and the two are interchangeable.
本申请实施例中各个网元可以是物理概念,例如在物理上可以是单个的设备或节点,也可以将至少两个网元集成在同一个物理设备或节点上,或者,本文所示的网元也可以是逻辑概念,例如为软件模块或者为与各个网元提供的服务对应的网络功能,网络功能可以理解为虚拟化实现下的一个虚拟化功能,还可以理解为服务化网络下提供服务的网络功能,例如,专门用于为用户面分配PDU会话资源的网络功能,或者专门用于执行网络切片的EAP鉴权的网络功能等,本申请实施例不作具体限定。Each network element in this embodiment of the present application may be a physical concept, for example, it may be a single device or node physically, or at least two network elements may be integrated on the same physical device or node, or the network shown in this document An element can also be a logical concept, such as a software module or a network function corresponding to the service provided by each network element. A network function can be understood as a virtualized function under virtualization implementation, or as a service provided under a service-oriented network. For example, a network function dedicated to allocating PDU session resources for the user plane, or a network function dedicated to performing EAP authentication of network slices, etc., which are not specifically limited in this embodiment of the present application.
本申请实施例中的术语“网元”还可以被替换为其它术语,比如可以替换为“功能”或“节点”等。例如,“接入管理网元”还可以被替换为“接入管理节点”,“数据管理网元”还可以被替换为“数据管理功能”,“切片鉴权网元”还可以被替换为“切片鉴权功能”等。The term "network element" in the embodiments of the present application may also be replaced with other terms, for example, "function" or "node" and the like. For example, "access management network element" can also be replaced with "access management node", "data management network element" can also be replaced with "data management function", and "slice authentication network element" can also be replaced with "Slice authentication function", etc.
本申请实施例中的术语“系统”和“网络”可被互换使用。“至少一个”是指一个或者多个,“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B的情况,其中A,B可以是单数或者复数。字符“/”一般表示前后关联对象是一种“或”的关系。“以下至少一项(个)”或其类似表达,是指的这些项中的任意组合,包括单项(个)或复数项(个)的任意组合,例如a、b或c中的至少一项(个),可以表示:a,或b,或c,或a和b,或b和c,或a和c,或a和b和c。The terms "system" and "network" in the embodiments of the present application may be used interchangeably. "At least one" means one or more, and "plurality" means two or more. "And/or", which describes the relationship of the associated objects, indicates that there can be three kinds of relationships, for example, A and/or B, it can indicate that A exists alone, A and B exist at the same time, and B exists alone, where A, B can be singular or plural. The character "/" generally indicates that the associated objects are an "or" relationship. "At least one of the following items" or similar expressions, refers to any combination of these items, including any combination of single item(s) or plural items(s), such as at least one of a, b or c (a), can mean: a, or b, or c, or a and b, or b and c, or a and c, or a and b and c.
除非有相反的说明,本申请实施例提及“第一”、“第二”等序数词是用于对多个对象进行区分,不用于限定多个对象的顺序、时序、优先级或者重要程度。例如,第一优先级准则和第二优先级准则,只是为了区分不同的准则,而并不是表示这两种准则的内容、优先级或者重要程度等的不同。Unless stated to the contrary, ordinal numbers such as “first” and “second” mentioned in the embodiments of the present application are used to distinguish multiple objects, and are not used to limit the order, sequence, priority, or importance of multiple objects . For example, the first priority criterion and the second priority criterion are only for distinguishing different criteria, and do not indicate the difference in content, priority, or importance of the two criteria.
本申请实施例和权利要求书及附图中的术语“包括”和“具有”不是排他的。例如,包括了一系列步骤或模块的过程、方法、系统、产品或设备,不限定于已列出的步骤或模块,还可以包括没有列出的步骤或模块。The terms "comprising" and "having" in the embodiments and claims of the present application and the drawings are not exclusive. For example, a process, method, system, product or device that includes a series of steps or modules is not limited to the listed steps or modules, and may also include unlisted steps or modules.
如图3所示,为本申请实施例提供的一种切片鉴权方法的流程图,该方法可以应用于图2所示的通信系统。方法包括:As shown in FIG. 3 , it is a flowchart of a slice authentication method provided by an embodiment of the present application, and the method can be applied to the communication system shown in FIG. 2 . Methods include:
S301、终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,第三接入管理网元向第一网元发送第一请求消息,第一请求消息包括第一切片的标识信息;第一网元接收来自第三接入管理网元的第一请求消息。S301. After the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function, the third access management network element sends a request to the first network element. A first request message is sent, where the first request message includes identification information of the first slice; the first network element receives the first request message from the third access management network element.
第一请求消息用于请求获取第一切片对应的鉴权结果,第一切片为需要进行鉴权的切片。The first request message is used to request to obtain the authentication result corresponding to the first slice, and the first slice is the slice that needs to be authenticated.
第三接入管理网元确定第二接入管理网元不支持网络切片鉴权功能包括以下三种情况:The third access management network element determines that the second access management network element does not support the network slice authentication function, including the following three cases:
情况1、终端设备从第二接入管理网元移动到第三接入管理网元后,获知第二接入管理网元为4G网络的移动管理节点MME,则第三接入管理网元确定第二接入管理网元不支持网络切片鉴权功能。Scenario 1. After the terminal equipment moves from the second access management network element to the third access management network element, it learns that the second access management network element is the mobility management node MME of the 4G network, then the third access management network element determines The second access management network element does not support the network slice authentication function.
情况2、终端设备从第二接入管理网元移动到第三接入管理网元后,第三接入管理网元从第二接入管理网元获取终端设备的用户上下文,用户上下文中不包含第一切片对应的鉴权结果,则第三接入管理网元确定第二接入管理网元不支持网络切片鉴权功能。Scenario 2: After the terminal device moves from the second access management network element to the third access management network element, the third access management network element obtains the user context of the terminal device from the second access management network element, and the user context does not exist in the user context. If the authentication result corresponding to the first slice is included, the third access management network element determines that the second access management network element does not support the network slice authentication function.
情况3、终端设备从第二接入管理网元移动到第三接入管理网元后,第三接入管理网元从第二接入管理网元获取第二接入管理网元支持的特性列表,根据支持的特性列表确定第二接入管理网元不支持网络切片鉴权功能。例如,该特性列表中包含第二接入管理网元支持的各项特性,该特性列表中不包括网络切片鉴权功能这项特性,则第三接入管理网元确定第二接入管理网元不支持网络切片鉴权功能。Case 3: After the terminal device moves from the second access management network element to the third access management network element, the third access management network element obtains the features supported by the second access management network element from the second access management network element list, and it is determined according to the supported feature list that the second access management network element does not support the network slice authentication function. For example, the feature list includes various features supported by the second access management network element, and the feature list does not include the feature of the network slice authentication function, then the third access management network element determines that the second access management network element Meta does not support the network slice authentication function.
S302、第一网元向第三接入管理网元返回第一响应消息,第一响应消息包括第一切片对应的鉴权结果;第三接入管理网元接收第一网元返回的第一响应消息。S302. The first network element returns a first response message to the third access management network element, where the first response message includes the authentication result corresponding to the first slice; the third access management network element receives the first response message returned by the first network element. A response message.
在本申请实施例中,通信系统中的指定网元上保存有第一切片对应的鉴权结果,鉴权结果为鉴权成功或鉴权失败。该指定网元储存的第一切片对应的鉴权结果,是在终端设备从第二接入管理网元移动到第三接入管理网元之前,在第一切片对应的鉴权完成之后,保存在该指定网元的。In the embodiment of the present application, the authentication result corresponding to the first slice is stored on the designated network element in the communication system, and the authentication result is authentication success or authentication failure. The authentication result corresponding to the first slice stored by the designated network element is before the terminal device moves from the second access management network element to the third access management network element, and after the authentication corresponding to the first slice is completed. , which is stored in the specified NE.
例如,在终端设备从第二接入管理网元移动到第三接入管理网元之前,终端设备从支持网络切片鉴权功能的第一接入管理网元移动到第二接入管理网元,其中第一接入管理网元与第三接入管理网元相同或不同。当终端设备位于第一接入管理网元的服务范围内时,如果通信系统针对第一切片执行网络切片鉴权流程,则在第一切片对应的鉴权完成之后,将第一切片对应的鉴权结果保存到该指定网元。其中通信系统针对第一切片执行网络切片鉴权流程的方法可以参考图1,这里不再详细介绍。For example, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element , wherein the first access management network element and the third access management network element are the same or different. When the terminal device is located within the service range of the first access management network element, if the communication system performs the network slice authentication process for the first slice, after the authentication corresponding to the first slice is completed, the first slice The corresponding authentication result is saved to the designated network element. The method for the communication system to perform the network slice authentication process for the first slice may refer to FIG. 1 , which will not be described in detail here.
再如,在终端设备从第二接入管理网元移动到第三接入管理网元之前,终端设备先从支持网络切片鉴权功能的第一接入管理网元移动到不支持网络切片鉴权功能的第四接入管理网元,再从第四接入管理网元移动到不支持网络切片鉴权功能的第二接入管理网元,其中第一接入管理网元与第三接入管理网元相同或不同。当终端设备位于第一接入管理网元的服务范围内时,通信系统针对第一切片执行网络切片鉴权流程,则在第一切片对应的鉴权完成之后,将第一切片对应的鉴权结果保存到该指定网元。For another example, before the terminal device moves from the second access management network element to the third access management network element, the terminal device first moves from the first access management network element that supports the network slice authentication function to the first access management network element that does not support the network slice authentication function. The fourth access management network element with the authorization function is moved from the fourth access management network element to the second access management network element that does not support the network slice authentication function, wherein the first access management network element is connected to the third access management network element. The incoming management network elements are the same or different. When the terminal device is located within the service range of the first access management network element, the communication system performs the network slice authentication process for the first slice, and after the authentication corresponding to the first slice is completed, the first slice corresponds to The authentication result is saved to the specified network element.
当然,终端设备从第二接入管理网元移动到第三接入管理网元之前,还可能经历更多的接入管理网元的切换,这里不做限制。只要终端设备在从第二接入管理网元移动到第三 接入管理网元之前,终端设备处于任意接入管理网元的服务范围时,通信系统针对第一切片执行了网络切片鉴权流程,则通信系统都可以将第一切片对应的鉴权结果保存到该指定网元。为了便于描述,在接下来的实施例中,主要以终端设备先从支持网络切片鉴权功能的第一接入管理网元移动到不支持网络切片鉴权功能的第二接入管理网元,再从不支持网络切片鉴权功能的第二接入管理网移动到支持网络切片鉴权功能的第三接入管理网元的过程为例。Of course, before the terminal device moves from the second access management network element to the third access management network element, it may also experience more switching of the access management network element, which is not limited here. As long as the terminal device is in the service range of any access management network element before moving from the second access management network element to the third access management network element, the communication system performs network slice authentication for the first slice process, the communication system can save the authentication result corresponding to the first slice to the designated network element. For ease of description, in the following embodiments, the terminal equipment is mainly moved from the first access management network element that supports the network slice authentication function to the second access management network element that does not support the network slice authentication function, Another example is the process of moving from the second access management network that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function.
在本申请实施例中,第一接入管理网元和第三接入管理网元连接的切片鉴权网元可以相同,也可以不同,具体取决于网络架构的实际部署。例如,第一接入管理网元连接第一切片鉴权网元,第二接入管理网元连接第二切片鉴权网元,且第一切片鉴权网元和第二切片鉴权网元不同。又如,第一接入管理网元连接第一切片鉴权网元,第二接入管理网元连接第二切片鉴权网元,且第一切片鉴权网元和第二切片鉴权网元相同(第一接入管理网元和第二接入管理网元均连接第一切片鉴权网元)。In this embodiment of the present application, the slice authentication network elements connected to the first access management network element and the third access management network element may be the same or different, depending on the actual deployment of the network architecture. For example, the first access management network element is connected to the first slice authentication network element, the second access management network element is connected to the second slice authentication network element, and the first slice authentication network element and the second slice authentication network element The network elements are different. For another example, the first access management network element is connected to the first slice authentication network element, the second access management network element is connected to the second slice authentication network element, and the first slice authentication network element and the second slice authentication network element are connected. The authority network elements are the same (both the first access management network element and the second access management network element are connected to the first slice authentication network element).
一种可能的设计中,该指定网元是第一网元。换而言之,第一网元保存有第一切片对应的鉴权结果,则第一网元在收到第一请求消息之后,从自身的存储单元中读取第一切片对应的鉴权结果,然后生成第一响应消息并返回给第三接入管理网元。In a possible design, the designated network element is the first network element. In other words, if the first network element stores the authentication result corresponding to the first slice, after receiving the first request message, the first network element reads the authentication result corresponding to the first slice from its own storage unit. Then, the first response message is generated and returned to the third access management network element.
例如,第一网元具体为数据管理网元。终端设备从第二接入管理网元移动到第三接入管理网元之前,终端设备从支持网络切片鉴权功能的第一接入管理网元移动到第二接入管理网元,终端设备处于第一接入管理网元的服务范围时,在第一切片对应的鉴权完成之后,第一接入管理网元或第一接入管理网元连接的第一切片鉴权网元将第一切片对应的鉴权结果储存到数据管理网元。For example, the first network element is specifically a data management network element. Before the terminal equipment moves from the second access management network element to the third access management network element, the terminal equipment moves from the first access management network element supporting the network slice authentication function to the second access management network element, the terminal equipment When in the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first access management network element or the first slice of the first access management network element connected to the authentication network element The authentication result corresponding to the first slice is stored in the data management network element.
或者,例如,第一网元具体为第一切片鉴权网元。终端设备从第二接入管理网元移动到第三接入管理网元之前,终端设备从支持网络切片鉴权功能的第一接入管理网元移动到第二接入管理网元,终端设备处于第一接入管理网元的服务范围时,在第一切片对应的鉴权完成之后,第一接入管理网元连接的第一切片鉴权网元储存第一切片对应的鉴权结果。Or, for example, the first network element is specifically the first slice authentication network element. Before the terminal equipment moves from the second access management network element to the third access management network element, the terminal equipment moves from the first access management network element supporting the network slice authentication function to the second access management network element, the terminal equipment When in the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first slice authentication network element connected to the first access management network element stores the authentication corresponding to the first slice. rights results.
另一种可能的设计中,指定网元是第二网元,第二网元与第一网元不同。换而言之,第一网元未保存有第一切片对应的鉴权结果,但第一网元可以从保存有第一切片对应的鉴权结果的第二网元处获取第一切片对应的鉴权结果。第一网元在收到第一请求消息之后,从第二网元处获取第一切片对应的鉴权结果,然后生成第一响应消息并返回给第三接入管理网元。In another possible design, the designated network element is a second network element, and the second network element is different from the first network element. In other words, the first network element does not store the authentication result corresponding to the first slice, but the first network element can obtain the first information from the second network element that stores the authentication result corresponding to the first slice. The authentication result corresponding to the slice. After receiving the first request message, the first network element obtains the authentication result corresponding to the first slice from the second network element, and then generates a first response message and returns it to the third access management network element.
例如,第一网元具体为第二切片鉴权网元,第二网元具体为数据管理网元。在终端设备从第二接入管理网元移动到第三接入管理网元之前,终端设备从支持网络切片鉴权功能的第一接入管理网元移动到第二接入管理网元,终端设备处于第一接入管理网元的服务范围时,在第一切片对应的鉴权完成之后,第一接入管理网元或第一切片鉴权网元将第一切片对应的鉴权结果储存到数据管理网元。在终端设备从第二接入管理网元移动到第三接入管理网元之后,第三接入管理网元向第二切片鉴权网元发送第一请求消息;第二切片鉴权网元收到第一请求消息后,先从数据管理网元处获取第一切片对应的鉴权结果(例如,第二切片鉴权网元向数据管理网元发送第一切片的标识信息,数据管理网元根据第一切片的标识信息返回第一切片对应的鉴权结果给第二切片鉴权网元);之后,第二切片鉴权网元向第三接入管理网元发送第一切片对应的鉴权结果(第一响应消息)。For example, the first network element is specifically the second slice authentication network element, and the second network element is specifically the data management network element. Before the terminal equipment moves from the second access management network element to the third access management network element, the terminal equipment moves from the first access management network element supporting the network slice authentication function to the second access management network element, the terminal equipment When the device is in the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first access management network element or the first slice authentication network element authenticates the authentication corresponding to the first slice. The result is stored in the data management network element. After the terminal device moves from the second access management network element to the third access management network element, the third access management network element sends the first request message to the second slice authentication network element; the second slice authentication network element After receiving the first request message, first obtain the authentication result corresponding to the first slice from the data management network element (for example, the second slice authentication network element sends the identification information of the first slice to the data management network element, and the data The management network element returns the authentication result corresponding to the first slice to the second slice authentication network element according to the identification information of the first slice); after that, the second slice authentication network element sends the third access management network element to the third access management network element. The authentication result (first response message) corresponding to each slice.
或者,例如,第一网元具体为第二切片鉴权网元,第二网元具体为第一切片鉴权网元。 在终端设备从第二接入管理网元移动到第三接入管理网元之前,终端设备从支持网络切片鉴权功能的第一接入管理网元移动到第二接入管理网元,终端设备处于第一接入管理网元的服务范围时,在第一切片对应的鉴权完成之后,第一接入管理网元连接的第一切片鉴权网元保存第一切片对应的鉴权结果,并将第一切片鉴权网元的标识注册到数据管理网元,以便于后续其它网元查询第一切片对应的鉴权结果的保存位置。在终端设备从第二接入管理网元移动到第三接入管理网元之后,第三接入管理网元向第二切片鉴权网元发送第一请求消息;第二切片鉴权网元收到第一请求消息之后,先向数据管理网元发送请求消息(包含第一切片的标识信息,用于查询第一切片对应的鉴权结果的保存位置),数据管理网元接收该请求消息后返回第一切片鉴权网元的标识(即第一切片对应的鉴权结果的保存位置)给第二切片鉴权网元;第二切片鉴权网元根据收到的第一切片鉴权网元的标识确定第一切片对应的鉴权结果保存在第一切片鉴权网元,向第一切片鉴权网元发送第一切片的标识信息;第一切片鉴权网元返回第一切片对应的鉴权结果给第二切片鉴权网元,第二切片鉴权网元收到第一切片鉴权网元返回的第一切片对应的鉴权结果后,返回第一切片对应的鉴权结果给第三接入管理网元(第一响应消息)。Or, for example, the first network element is specifically the second slice authentication network element, and the second network element is specifically the first slice authentication network element. Before the terminal equipment moves from the second access management network element to the third access management network element, the terminal equipment moves from the first access management network element supporting the network slice authentication function to the second access management network element, the terminal equipment When the device is in the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first slice authentication network element connected to the first access management network element saves the first slice corresponding to the first slice. The authentication result is obtained, and the identifier of the authentication network element of the first slice is registered to the data management network element, so that subsequent network elements can query the storage location of the authentication result corresponding to the first slice. After the terminal device moves from the second access management network element to the third access management network element, the third access management network element sends the first request message to the second slice authentication network element; the second slice authentication network element After receiving the first request message, first send a request message (including the identification information of the first slice to query the storage location of the authentication result corresponding to the first slice) to the data management network element, and the data management network element receives the After the request message, the identifier of the first slice authentication network element (that is, the storage location of the authentication result corresponding to the first slice) is returned to the second slice authentication network element; the second slice authentication network element is based on the received The identification of each slice authentication network element determines that the authentication result corresponding to the first slice is stored in the first slice authentication network element, and sends the identification information of the first slice to the first slice authentication network element; first The slice authentication network element returns the authentication result corresponding to the first slice to the second slice authentication network element, and the second slice authentication network element receives the corresponding first slice returned by the first slice authentication network element. After the authentication result, the authentication result corresponding to the first slice is returned to the third access management network element (the first response message).
当然,以上仅仅是对鉴权结果保存位置以及第一网元的具体实现方式的举例而非限定,在实际应用中不排除鉴权结果保存位置、第一网元还有其他实现方式的可能性。Of course, the above is only an example of the storage location of the authentication result and the specific implementation of the first network element, but not a limitation. In practical applications, the possibility of the storage location of the authentication result, the first network element and other implementations is not excluded. .
可选的,当第一接入管理网元或者第一切片鉴权网元将第一切片对应的鉴权结果存储到指定网元后,AAA服务器可以触发针对第一切片对应的鉴权结果的撤回流程或者重鉴权流程。Optionally, after the first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice in the designated network element, the AAA server may trigger the authentication corresponding to the first slice. The revocation process or re-authentication process of the authorization result.
AAA服务器触发针对第一切片对应的鉴权结果的撤回流程或者重鉴权流程包括但不限于以下四种情况:The AAA server triggers the withdrawal process or re-authentication process for the authentication result corresponding to the first slice, including but not limited to the following four cases:
情况1,当第一切片对应的鉴权结果存储在数据管理网元的情况下,终端设备处于第二接入管理网元的服务范围时,AAA服务器可以触发针对第一切片对应的鉴权结果的撤回流程或者重鉴权流程。由于第二接入管理网元不支持切片鉴权功能,切片的鉴权结果存储在指定网元,所以可以通过切片鉴权网元通知指定网元来执行鉴权结果撤回或重鉴权。In case 1, when the authentication result corresponding to the first slice is stored in the data management network element, and the terminal device is in the service range of the second access management network element, the AAA server can trigger the authentication corresponding to the first slice. The revocation process or re-authentication process of the authorization result. Since the second access management network element does not support the slice authentication function, and the slice authentication result is stored in the designated network element, the slice authentication network element can notify the designated network element to perform authentication result withdrawal or re-authentication.
1)AAA服务器触发针对第一切片对应的鉴权结果的撤回流程:1) The AAA server triggers the withdrawal process for the authentication result corresponding to the first slice:
具体的,当鉴权结果是鉴权成功时,AAA服务器可以向第一切片鉴权网元或第二切片鉴权网元发送鉴权撤回消息;第一切片鉴权网元或第二切片鉴权网元根据鉴权撤回消息将数据管理网元中储存的第一切片对应的鉴权结果修改为鉴权失败。其中第一切片鉴权网元或第二切片鉴权网元将数据管理网元中储存的第一切片对应的鉴权结果修改为鉴权失败的具体方式可以是:第一切片鉴权网元或第二切片鉴权网元向数据管理网元发送第一消息(包含第一切片的标识,用于通知数据管理网元将第一切片对应的鉴权结果修改为鉴权失败),数据管理网元根据第一消息将自身储存的第一切片对应的鉴权结果修改为鉴权失败。Specifically, when the authentication result is that the authentication is successful, the AAA server may send an authentication withdrawal message to the first slice authentication network element or the second slice authentication network element; the first slice authentication network element or the second slice authentication network element The slice authentication network element modifies the authentication result corresponding to the first slice stored in the data management network element to an authentication failure according to the authentication withdrawal message. The specific manner in which the first slice authentication network element or the second slice authentication network element modifies the authentication result corresponding to the first slice stored in the data management network element to an authentication failure may be: the first slice authentication The right network element or the second slice authentication network element sends a first message (including the identifier of the first slice to the data management network element, which is used to notify the data management network element to modify the authentication result corresponding to the first slice to an authentication failure), the data management network element modifies the authentication result corresponding to the first slice stored by itself to the authentication failure according to the first message.
可选的,数据管理网元具体可以是将第一切片对应的鉴权结果修改为EAP失败。Optionally, the data management network element may specifically modify the authentication result corresponding to the first slice to EAP failure.
当然,如果系统中还存在其它切片鉴权网元,也可以通过其它切片鉴权网元来替代第一切片鉴权网元或第二切片鉴权网元执行上述鉴权结果撤回过程。Of course, if there are other slice authentication network elements in the system, other slice authentication network elements can also be used to replace the first slice authentication network element or the second slice authentication network element to perform the above authentication result withdrawal process.
2)AAA服务器触发针对第一切片的重鉴权流程:2) The AAA server triggers the re-authentication process for the first slice:
具体的,当鉴权结果是鉴权成功或鉴权失败时,AAA服务器向第一切片鉴权网元或第二切片鉴权网元发送重鉴权消息;第一切片鉴权网元或第二切片鉴权网元根据重鉴权消息将数据管理网元中储存的第一切片对应的鉴权结果删除。进一步的,第一切片鉴权网元或 第二切片鉴权网元将数据管理网元中储存的第一切片对应的鉴权结果删除的具体方式可以是:第一切片鉴权网元或第二切片鉴权网元向数据管理网元发送第二消息(包含第一切片的标识,用于通知数据管理网元将第一切片对应的鉴权结果删除),数据管理网元根据第二消息删除自身储存的第一切片对应的鉴权结果。Specifically, when the authentication result is that the authentication succeeds or the authentication fails, the AAA server sends a re-authentication message to the first slice authentication network element or the second slice authentication network element; the first slice authentication network element Or the second slice authentication network element deletes the authentication result corresponding to the first slice stored in the data management network element according to the re-authentication message. Further, the specific manner in which the first slice authentication network element or the second slice authentication network element deletes the authentication result corresponding to the first slice stored in the data management network element may be: the first slice authentication network element. or the second slice authentication network element sends a second message (including the identifier of the first slice to the data management network element to notify the data management network element to delete the authentication result corresponding to the first slice), and the data management network The element deletes the authentication result corresponding to the first slice stored by itself according to the second message.
当然,如果系统中还存在其它切片鉴权网元,也可以通过其它切片鉴权网元来替代第一切片鉴权网元或第二切片鉴权网元执行上述重鉴权过程。Of course, if there are other slice authentication network elements in the system, other slice authentication network elements can also be used to replace the first slice authentication network element or the second slice authentication network element to perform the above re-authentication process.
当数据管理网元中储存的第一切片对应的鉴权结果被删除后,第三接入管理网元发现数据管理网元没有第一切片对应的鉴权结果,则将触发第三接入管理网元执行针对第一切片的重鉴权流程。After the authentication result corresponding to the first slice stored in the data management network element is deleted, the third access management network element finds that the data management network element does not have an authentication result corresponding to the first slice, and triggers the third access management network element. The incoming management network element performs the re-authentication process for the first slice.
可选的,如果第一切片对应的鉴权结果具体是储存在终端设备的签约数据中(终端设备的签约数据储存在数据管理网元上),则上述第一消息、第二消息具体可以是签约数据更新请求消息。Optionally, if the authentication result corresponding to the first slice is specifically stored in the subscription data of the terminal device (the subscription data of the terminal device is stored on the data management network element), the above-mentioned first message and the second message may specifically be is a subscription data update request message.
情况2,当第一切片对应的鉴权结果存储在第一切片鉴权网元的情况下,终端设备处于第二接入管理网元的服务范围时,AAA服务器可以触发针对第一切片对应的鉴权结果的撤回流程或者重鉴权流程。由于第二接入管理网元不支持切片鉴权功能,切片的鉴权结果存储在第一切片鉴权网元,所以可以通过切片鉴权网元通知第一切片鉴权网元来执行鉴权结果撤回或重鉴权。In case 2, when the authentication result corresponding to the first slice is stored in the authentication network element of the first slice, and the terminal device is in the service range of the second access management network element, the AAA server can trigger the The withdrawal process or the re-authentication process of the authentication result corresponding to the slice. Since the second access management network element does not support the slice authentication function, the authentication result of the slice is stored in the first slice authentication network element. Therefore, the slice authentication network element can notify the first slice authentication network element to perform the operation. The authentication result is withdrawn or re-authenticated.
1)AAA服务器触发针对第一切片对应的鉴权结果的撤回流程:1) The AAA server triggers the withdrawal process for the authentication result corresponding to the first slice:
具体的,当鉴权结果是鉴权成功时,AAA服务器向第一切片鉴权网元发送鉴权撤回消息,第一切片鉴权网元根据鉴权撤回消息将自身储存的第一切片对应的鉴权结果修改为鉴权失败;或者,AAA服务器向第二切片鉴权网元发送鉴权撤回消息,第二切片鉴权网元根据鉴权撤回消息向第一切片鉴权网元发送第三消息(包含第一切片的标识,用于通知第一切片鉴权网元将第一切片对应的鉴权结果修改为鉴权失败),第一切片鉴权网元根据第三消息将自身储存的第一切片对应的鉴权结果修改为鉴权失败。可选的,第一切片鉴权网元具体可以是将第一切片对应的鉴权结果修改为EAP失败。Specifically, when the authentication result is that the authentication is successful, the AAA server sends an authentication revocation message to the first slice authentication network element, and the first slice authentication network element stores the first The authentication result corresponding to the slice is modified to be an authentication failure; or, the AAA server sends an authentication revocation message to the second slice authentication network element, and the second slice authentication network element sends the first slice authentication network element according to the authentication revocation message to the first slice authentication network element. element sends a third message (including the identifier of the first slice, which is used to notify the first slice authentication network element to modify the authentication result corresponding to the first slice to an authentication failure), and the first slice authentication network element According to the third message, the authentication result corresponding to the first slice stored by itself is modified to be authentication failure. Optionally, the first slice authentication network element may specifically modify the authentication result corresponding to the first slice to EAP failure.
2)AAA服务器触发针对第一切片对应的重鉴权流程:2) The AAA server triggers the re-authentication process corresponding to the first slice:
具体的,当鉴权结果是鉴权成功或鉴权失败时,AAA服务器向第一切片鉴权网元发送重鉴权消息,第一切片鉴权网元根据重鉴权消息将自身储存的第一切片对应的鉴权结果删除;或者,AAA服务器向第二切片鉴权网元发送重鉴权消息,第二切片鉴权网元根据重鉴权消息向第一切片鉴权网元发送第四消息(包含第一切片的标识,用于通知第一切片鉴权网元将第一切片对应的鉴权结果删除),第一切片鉴权网元根据第四消息删除自身储存的第一切片对应的鉴权结果。Specifically, when the authentication result is that the authentication succeeds or the authentication fails, the AAA server sends a re-authentication message to the first slice authentication network element, and the first slice authentication network element stores itself according to the re-authentication message. The authentication result corresponding to the first slice is deleted; or, the AAA server sends a re-authentication message to the second slice authentication network element, and the second slice authentication network element sends the element sends a fourth message (including the identifier of the first slice, used to notify the first slice authentication network element to delete the authentication result corresponding to the first slice), and the first slice authentication network element according to the fourth message Delete the authentication result corresponding to the first slice stored by itself.
情况3,当第一切片对应的鉴权结果存储在数据管理网元的情况下,终端设备处于第一接入管理网元的服务范围时,AAA服务器可以触发针对第一切片对应的鉴权结果的撤回流程或者重鉴权流程。由于第一接入管理网元支持切片鉴权功能,切片的鉴权结果存储在第一接入管理网元和指定网元,所以可以通过切片鉴权网元通知第一接入管理网元来执行鉴权结果撤回或重鉴权。In case 3, when the authentication result corresponding to the first slice is stored in the data management network element, and the terminal device is in the service range of the first access management network element, the AAA server can trigger the authentication corresponding to the first slice. The revocation process or re-authentication process of the authorization result. Since the first access management network element supports the slice authentication function, and the authentication result of the slice is stored in the first access management network element and the designated network element, the slice authentication network element can notify the first access management network element to Perform authentication result revocation or re-authentication.
1)AAA服务器触发针对第一切片对应的鉴权结果的撤回流程:1) The AAA server triggers the withdrawal process for the authentication result corresponding to the first slice:
具体的,当鉴权结果是鉴权成功时,AAA服务器向第一切片鉴权网元或第二切片鉴权网元发送鉴权撤回消息(包含第一切片的标识),第一切片鉴权网元或第二切片鉴权网元 收到该消息后,发送鉴权撤回消息(包含第一切片的标识)给第一接入管理网元;第一接入管理网元获得鉴权撤回消息后,发送第五消息(包含第一切片的标识,用于通知数据管理网元将第一切片对应的鉴权结果修改为鉴权失败)给数据管理网元;数据管理网元收到第五消息后,将自身储存的第一切片对应的鉴权结果修改为鉴权失败。Specifically, when the authentication result is that the authentication is successful, the AAA server sends an authentication revocation message (including the identifier of the first slice) to the first slice authentication network element or the second slice authentication network element, and the first slice authentication network element After receiving the message, the slice authentication network element or the second slice authentication network element sends an authentication withdrawal message (including the identifier of the first slice) to the first access management network element; the first access management network element obtains the After the authentication revocation message, send a fifth message (including the identifier of the first slice to notify the data management network element to modify the authentication result corresponding to the first slice to an authentication failure) to the data management network element; data management After receiving the fifth message, the network element modifies the authentication result corresponding to the first slice stored by itself to the authentication failure.
2)AAA服务器触发针对第一切片对应的重鉴权流程:2) The AAA server triggers the re-authentication process corresponding to the first slice:
具体的,当鉴权结果是鉴权成功或鉴权失败时,AAA服务器向第一切片鉴权网元或第二切片鉴权网元发送重鉴权消息(包含第一切片的标识);第一切片鉴权网元或第二切片鉴权网元收到重鉴权消息后,发送重鉴权消息(包含第一切片的标识)给第一接入管理网元;第一接入管理网元获得重鉴权消息后,发送第六消息(包含第一切片的标识,用于通知数据管理网元删除第一切片对应的鉴权结果)给数据管理网元;数据管理网元收到第六消息后,删除自身储存的第一切片对应的鉴权结果。Specifically, when the authentication result is that the authentication succeeds or the authentication fails, the AAA server sends a re-authentication message (including the identifier of the first slice) to the first slice authentication network element or the second slice authentication network element. ; After the first slice authentication network element or the second slice authentication network element receives the re-authentication message, it sends the re-authentication message (including the identity of the first slice) to the first access management network element; the first After the access management network element obtains the re-authentication message, it sends a sixth message (including the identifier of the first slice to notify the data management network element to delete the authentication result corresponding to the first slice) to the data management network element; the data After receiving the sixth message, the management network element deletes the authentication result corresponding to the first slice stored by itself.
当然,在这种情况下,也可以通过切片鉴权网元来执行鉴权结果撤回或重鉴权,具体方式可参考上述情况1,这里不再赘述。Of course, in this case, the authentication result revocation or re-authentication may also be performed through the slice authentication network element, and the specific method may refer to the above-mentioned case 1, which will not be repeated here.
可选的,如果第一切片对应的鉴权结果具体是储存在终端设备的签约数据中(终端设备的签约数据储存数据管理网元),则上述第五消息、第六消息具体可以是签约数据更新请求消息。Optionally, if the authentication result corresponding to the first slice is specifically stored in the subscription data of the terminal device (the subscription data of the terminal device is stored in the data management network element), then the fifth message and the sixth message may specifically be the subscription data. Data update request message.
情况4,当第一切片对应的鉴权结果存储在第一切片鉴权网元的情况下,终端设备处于第一接入管理网元的服务范围时,AAA服务器可以触发针对第一切片对应的鉴权结果的撤回流程或者重鉴权流程。由于第一接入管理网元支持切片鉴权功能,切片的鉴权结果存储在第一接入管理网元,所以可以通过切片鉴权网元通知第一接入管理网元来执行鉴权结果撤回或重鉴权。In case 4, when the authentication result corresponding to the first slice is stored in the authentication network element of the first slice, and the terminal device is in the service range of the first access management network element, the AAA server can trigger the The withdrawal process or the re-authentication process of the authentication result corresponding to the slice. Since the first access management network element supports the slice authentication function, and the authentication result of the slice is stored in the first access management network element, the slice authentication network element can notify the first access management network element to execute the authentication result. Withdraw or re-authenticate.
1)AAA服务器触发针对第一切片对应的鉴权结果的撤回流程:1) The AAA server triggers the withdrawal process for the authentication result corresponding to the first slice:
具体的,当鉴权结果是鉴权成功时,首先AAA服务器向第一切片鉴权网元或第二切片鉴权网元发送鉴权撤回消息;然后第一切片鉴权网元或第二切片鉴权网元向第一接入管理网元发送鉴权撤回消息;第一接入管理网元获得鉴权撤回消息后,发送第七消息(包含第一切片的标识,用于通知第一切片鉴权网元将第一切片对应的鉴权结果修改为鉴权失败)给第一切片鉴权网元;第一切片鉴权网元收到第七消息后,将自身储存的第一切片对应的鉴权结果修改为鉴权失败。Specifically, when the authentication result is that the authentication is successful, first, the AAA server sends an authentication revocation message to the first slice authentication network element or the second slice authentication network element; then the first slice authentication network element or the third slice authentication network element sends an authentication revocation message; The two-slice authentication network element sends an authentication revocation message to the first access management network element; after the first access management network element obtains the authentication revocation message, it sends a seventh message (including the identifier of the first slice to notify the The first slice authentication network element modifies the authentication result corresponding to the first slice as authentication failure) to the first slice authentication network element; after receiving the seventh message, the first slice authentication network element sends the The authentication result corresponding to the first slice stored by itself is modified as authentication failure.
2)AAA服务器触发针对第一切片对应的重鉴权流程:2) The AAA server triggers the re-authentication process corresponding to the first slice:
具体的,当鉴权结果是鉴权成功或鉴权失败时,首先AAA服务器向第一切片鉴权网元或第二切片鉴权网元发送重鉴权消息;然后第一切片鉴权网元或第二切片鉴权网元向第一接入管理网元发送重鉴权消息;第一接入管理网元获得重鉴权消息后,发送第八消息(包含第一切片的标识,用于通知第一切片鉴权网元将第一切片对应的鉴权结果删除)给第一切片鉴权网元;第一切片鉴权网元收到第八消息后,重鉴权自身储存的第一切片对应的鉴权结果。Specifically, when the authentication result is that the authentication succeeds or the authentication fails, the AAA server first sends a re-authentication message to the first slice authentication network element or the second slice authentication network element; then the first slice authentication The network element or the second slice authentication network element sends a re-authentication message to the first access management network element; after the first access management network element obtains the re-authentication message, it sends an eighth message (containing the identifier of the first slice). is used to notify the first slice authentication network element to delete the authentication result corresponding to the first slice) to the first slice authentication network element; after receiving the eighth message, the first slice authentication network element re- The authentication result corresponding to the first slice stored by the authentication itself.
当然,在这种情况下,也可以通过切片鉴权网元来执行鉴权结果撤回或重鉴权,具体方式可参考上述情况2,这里不再赘述。Of course, in this case, the authentication result revocation or re-authentication may also be performed by using the slice authentication network element, and the specific method may refer to the above-mentioned case 2, which will not be repeated here.
通过上述可知,本申请实施例中,当终端设备从不支持网络切片鉴权功能的第二接入管理网元的服务范围移动至支持网络切片鉴权功能的第三接入管理网元的服务范围后,第三接入管理网元可以从指定网元(如第一切片鉴权网元、数据管理网元等)获取需要鉴权 的网络切片(如第一切片)的鉴权结果,无需重新执行网络切片鉴权流程,可以有效节省系统信令开销。同时终端设备也不再需要等待第三接入管理网元执行完网络切片鉴权流程后才能建立到特定网络切片的会话,加速了业务建立的过程,降低了终端设备的业务时延。It can be seen from the above that in this embodiment of the present application, when the terminal device moves from the service scope of the second access management network element that does not support the network slice authentication function to the service scope of the third access management network element that supports the network slice authentication function After the range, the third access management network element can obtain the authentication result of the network slice (such as the first slice) that needs to be authenticated from the specified network element (such as the first slice authentication network element, data management network element, etc.) , there is no need to re-execute the network slice authentication process, which can effectively save the system signaling overhead. At the same time, the terminal device no longer needs to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice, which speeds up the process of service establishment and reduces the service delay of the terminal device.
应理解,上述各实施方式可以相互结合以实现不同的技术效果。It should be understood that the above embodiments can be combined with each other to achieve different technical effects.
为了便于更清楚地理解本申请实施例所提供的技术方案,下面介绍几个更加具体的实施方案。In order to facilitate a clearer understanding of the technical solutions provided by the embodiments of the present application, several more specific implementations are introduced below.
实施例一Example 1
本实施例主要介绍:网络切片的鉴权结果存储在数据管理网元上,第一接入管理网元在网络切片鉴权过程中去数据管理网元上存储鉴权结果;第三接入管理网元从数据管理网元上获取所述鉴权结果。可选的,在AAA服务器触发的重鉴权或者鉴权结果撤回流程中,当终端设备处于第二接入管理网元的服务范围时,第二切片鉴权网元根据从数据管理网元上获取的接入管理网元注册信息,获知第二接入管理网元不支持网络切片鉴权功能后,直接修改数据管理网元上的鉴权结果;或者,当终端设备处于第一接入管理网元的服务范围时,第二切片鉴权网元根据从数据管理网元上获取的接入管理网元注册信息,获知第一接入管理网元支持网络切片鉴权功能后,第二切片鉴权网元通知第一接入管理网元,由第一接入管理网元去修改数据管理网元上的鉴权结果。This embodiment mainly introduces: the authentication result of the network slice is stored on the data management network element, and the first access management network element stores the authentication result on the data management network element during the network slice authentication process; the third access management network element stores the authentication result on the data management network element; The network element obtains the authentication result from the data management network element. Optionally, in the re-authentication or authentication result withdrawal process triggered by the AAA server, when the terminal device is in the service range of the second access management network element, the second slice authentication network element is based on the data from the data management network element. After obtaining the access management network element registration information, after learning that the second access management network element does not support the network slice authentication function, directly modify the authentication result on the data management network element; or, when the terminal device is in the first access management network In the service scope of the network element, the second slice authentication network element learns that the first access management network element supports the network slice authentication function according to the access management network element registration information obtained from the data management network element. The authentication network element notifies the first access management network element, and the first access management network element modifies the authentication result on the data management network element.
如图4所示,为本实施例提供的一种具体的切片鉴权方法,该方法可以应用于图2所示的网络架构中,方法包括:As shown in FIG. 4 , a specific slice authentication method provided in this embodiment can be applied to the network architecture shown in FIG. 2 , and the method includes:
S401、第一接入管理网元触发网络切片鉴权流程。S401. A first access management network element triggers a network slice authentication process.
具体的,终端设备接入第一接入管理网元,第一接入管理网元从数据管理网元获取终端设备的签约数据,第一接入管理网元根据签约数据中包含的切片标识S-NSSAI,及其网络切片鉴权指示信息获知S-NSSAI所标识的网络切片(相当于上文中的第一切片)需要执行网络切片鉴权,则第一接入管理网元触发网络切片鉴权流程,具体流程和图1流程相同。其中第一接入管理网元对应图1中的接入管理节点,第一切片鉴权网元对应图1中的切片鉴权功能。Specifically, the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element obtains the subscription data of the terminal device according to the slice identifier S included in the subscription data. -NSSAI, and its network slice authentication indication information If the network slice identified by S-NSSAI (equivalent to the first slice above) needs to perform network slice authentication, the first access management network element triggers the network slice authentication The specific process is the same as that in Figure 1. The first access management network element corresponds to the access management node in FIG. 1 , and the first slice authentication network element corresponds to the slice authentication function in FIG. 1 .
当第一接入管理网元获知网络切片的鉴权结果(即执行完图1所示的S1012)后,继续执行如下步骤:When the first access management network element learns the authentication result of the network slicing (that is, after performing S1012 shown in FIG. 1 ), it continues to perform the following steps:
S402、第一接入管理网元发送请求消息给数据管理网元,该请求消息中包含切片标识S-NSSAI及其鉴权结果(即S-NSSAI所标识的网络切片对应的鉴权结果)。数据管理网元收到消息后,更新签约数据,将鉴权结果存储到签约数据中切片标识S-NSSAI对应的数据中。需要说明的是,如果终端设备的签约数据中不存在切片标识S-NSSAI,则数据管理网元可以不更新签约数据。S402. The first access management network element sends a request message to the data management network element, where the request message includes the slice identifier S-NSSAI and its authentication result (ie, the authentication result corresponding to the network slice identified by the S-NSSAI). After receiving the message, the data management network element updates the subscription data, and stores the authentication result in the data corresponding to the slice identifier S-NSSAI in the subscription data. It should be noted that, if the slice identifier S-NSSAI does not exist in the subscription data of the terminal device, the data management network element may not update the subscription data.
S403:数据管理网元回复响应消息给第一接入管理网元,用于指示签约数据更新成功或者失败。S403: The data management network element replies a response message to the first access management network element, which is used to indicate whether the subscription data update succeeds or fails.
需要说明的是,终端设备可以签约多个需要执行网络切片鉴权的切片标识S-NSSAI(即多个不同的第一切片),第一接入管理网元可以执行多次请求,每次请求用以存储一个或者多个切片标识S-NSSAI,及每个S-NSSAI标识的切片对应的鉴权结果。It should be noted that the terminal device can subscribe to multiple slice identifiers S-NSSAI (that is, multiple different first slices) that need to perform network slice authentication, and the first access management network element can perform multiple requests, each time The request is used to store one or more slice identifiers S-NSSAI, and the authentication result corresponding to the slice identified by each S-NSSAI.
上面S401~S403介绍了第一接入管理网元将鉴权结果储存到数据管理网元的过程,接下来介绍终端设备发生移动后,新的接入管理网元(即第三接入管理网元)从数据管理网元获取鉴权结果的过程。The above S401 to S403 describe the process that the first access management network element stores the authentication result in the data management network element. element) the process of obtaining the authentication result from the data management network element.
场景一、终端设备从5G网络移动到4G网络,选择4G网络的第二接入管理网元服务,随后终端设备又移动到5G网络,选择5G网络的第三接入管理网元服务,其中第三接入管理网元和第一接入管理网元可以相同或者不同。针对4G网络,接入管理网元具体可以为移动管理实体(Mobility Management Entity,MME)。Scenario 1. The terminal device moves from the 5G network to the 4G network, selects the second access management network element service of the 4G network, and then moves the terminal device to the 5G network and selects the third access management network element service of the 5G network. The third access management network element and the first access management network element may be the same or different. For the 4G network, the access management network element may specifically be a mobility management entity (Mobility Management Entity, MME).
场景二:终端设备在5G网络内移动,从支持网络切片鉴权功能的第一接入管理网元,移动到不支持网络切片鉴权功能的第二接入管理网元,后来又移动到支持网络切片鉴权功能的第三接入管理网元,其中,第三接入管理网元和第一接入管理网元可以相同或者不同。针对5G网络,接入管理网元具体可以为接入和移动性管理功能(Access&Mobility Function,AMF)。Scenario 2: The terminal device moves in the 5G network, from the first access management network element that supports the network slice authentication function to the second access management network element that does not support the network slice authentication function, and then moves to the second access management network element that supports the network slice authentication function. The third access management network element of the network slice authentication function, wherein the third access management network element and the first access management network element may be the same or different. For the 5G network, the access management network element may specifically be an access and mobility management function (Access & Mobility Function, AMF).
当终端设备的移动发生以上任一种场景时,终端设备从第一接入管理网元移动到第二接入管理网元后,第二接入管理网元获取第一接入管理网元上的终端设备的用户上下文。因为第二接入管理网元为4G网络的节点,或者第二接入管理网元不支持网络切片鉴权功能,第一接入管理网元发送的用户上下文中不包含切片标识S-NSSAI,及其鉴权结果。或者,第一接入管理网元发送的用户上下文中包含切片标识S-NSSAI及其鉴权结果,但是第二接入管理网元因为不认识切片标识S-NSSAI及其鉴权结果,直接丢弃。而第一接入管理网元将用户上下文发送给第二接入管理节后,删除本地存储的用户上下文。When any of the above scenarios occurs when the terminal equipment moves, after the terminal equipment moves from the first access management network element to the second access management network element, the second access management network element obtains the information on the first access management network element. The user context of the end device. Because the second access management network element is a node of the 4G network, or the second access management network element does not support the network slice authentication function, the user context sent by the first access management network element does not contain the slice identifier S-NSSAI, and its authentication results. Or, the user context sent by the first access management network element includes the slice identifier S-NSSAI and its authentication result, but the second access management network element directly discards the slice identifier S-NSSAI and its authentication result because it does not recognize the slice identifier S-NSSAI and its authentication result. . However, after the first access management network element sends the user context to the second access management section, the locally stored user context is deleted.
随后当终端设备从第二接入管理网元移动到第三接入管理网元后,流程类似,第三接入管理网元获取第二接入管理网元上的终端设备的用户上下文。用户上下文中不包含切片标识S-NSSAI,及其鉴权结果。Subsequently, when the terminal device moves from the second access management network element to the third access management network element, the process is similar, and the third access management network element obtains the user context of the terminal device on the second access management network element. The slice identifier S-NSSAI and its authentication result are not included in the user context.
请继续参见图4,在终端设备从第二接入管理网元移动到第三接入管理网元流程中,终端设备触发注册更新流程:Please continue to refer to FIG. 4 , in the process of moving the terminal device from the second access management network element to the third access management network element, the terminal device triggers the registration update process:
S404:在注册流程中,终端设备发送注册更新请求消息给第三接入管理网元。S404: In the registration process, the terminal device sends a registration update request message to the third access management network element.
S405:在注册流程中,第三接入管理网元发送签约数据请求消息(第一请求消息),向数据管理节点获取终端设备的签约数据。S405: In the registration process, the third access management network element sends a subscription data request message (a first request message) to acquire the subscription data of the terminal device from the data management node.
S406:数据管理节点发送签约数据响应消息(第一响应消息)给第三接入管理网元,签约数据中包含鉴权结果。S406: The data management node sends a subscription data response message (a first response message) to the third access management network element, where the subscription data includes the authentication result.
可选的,签约数据中还包含切片标识S-NSSAI。Optionally, the subscription data also includes the slice identifier S-NSSAI.
可选的,签约数据中可以进一步包含多个切片标识S-NSSAI(即多个第一切片),及其鉴权结果。Optionally, the subscription data may further include multiple slice identifiers S-NSSAI (ie, multiple first slices), and authentication results thereof.
第三接入管理网元获得上述切片标识S-NSSAI,及其鉴权结果后,针对鉴权结果执行允许或者不允许终端设备建立到网络切片的会话的操作,不再重复执行网络切片鉴权流程。After the third access management network element obtains the slice identifier S-NSSAI and the authentication result, it performs the operation of allowing or not allowing the terminal device to establish a session to the network slice according to the authentication result, and does not repeat the network slice authentication. Process.
可替换的,上述S401~S403流程中,也可以由切片鉴权网元将网络切片的鉴权结果存储到终端设备的签约数据中,具体区别为,上述S401~S403依次替换为如下步骤1)~3):Alternatively, in the above processes of S401 to S403, the authentication result of the network slice may also be stored in the subscription data of the terminal device by the slice authentication network element. The specific difference is that the above S401 to S403 are sequentially replaced by the following steps 1) ~3):
1)终端设备接入第一接入管理网元,第一接入管理网元从数据管理网元获取终端设备的签约数据,第一接入管理网元根据签约数据中包含的切片标识S-NSSAI,及其网络切片鉴权指示信息获知S-NSSAI所标识的网络切片(相当于上文中的第一切片)需要执行网络切片鉴权,则第一接入管理网元触发网络切片鉴权流程,具体流程和图1流程相同。其中第一接入管理网元对应图1中的接入管理节点,第一切片鉴权网元对应图1中的切片鉴权功能。1) The terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element obtains the subscription data of the terminal device according to the slice identifier S- NSSAI, and its network slice authentication indication information learn that the network slice identified by S-NSSAI (equivalent to the first slice above) needs to perform network slice authentication, then the first access management network element triggers network slice authentication The specific process is the same as that in Figure 1. The first access management network element corresponds to the access management node in FIG. 1 , and the first slice authentication network element corresponds to the slice authentication function in FIG. 1 .
当第一切片鉴权网元获知网络切片的鉴权结果(即执行完图1所示的S1011)后,继 续执行如下步骤:When the first slice authentication network element learns the authentication result of the network slice (that is, after performing S1011 shown in Figure 1), continue to perform the following steps:
2)第一切片鉴权网元发送请求消息给数据管理网元,消息中包含切片标识S-NSSAI及其鉴权结果。数据管理网元收到消息后,更新签约数据,将鉴权结果存储到签约数据中切片标识S-NSSAI对应的数据中。如果终端设备的签约数据中不存在切片标识S-NSSAI,则数据管理网元不更新签约数据;2) The first slice authentication network element sends a request message to the data management network element, and the message includes the slice identifier S-NSSAI and its authentication result. After receiving the message, the data management network element updates the subscription data, and stores the authentication result in the data corresponding to the slice identifier S-NSSAI in the subscription data. If there is no slice identifier S-NSSAI in the subscription data of the terminal device, the data management network element does not update the subscription data;
3)数据管理网元回复响应消息给第一切片鉴权网元,用于指示签约数据更新成功或者失败。3) The data management network element replies with a response message to the first slice authentication network element, which is used to indicate the success or failure of the subscription data update.
同理,终端设备可以签约多个需要执行网络切片鉴权的切片标识S-NSSAI,第一切片鉴权网元可以执行多次请求,每次请求用以存储一个或者多个切片标识S-NSSAI,及其对应的鉴权结果。In the same way, the terminal device can subscribe to multiple slice identifiers S-NSSAI that need to perform network slice authentication, and the first slice authentication network element can perform multiple requests, and each request is used to store one or more slice identifiers S-NSSAI. NSSAI, and its corresponding authentication result.
当第一接入管理网元或者第一切片鉴权网元将鉴权结果存储到签约数据中后,AAA服务还可以触发鉴权结果撤回或者重鉴权的流程。After the first access management network element or the first slice authentication network element stores the authentication result in the subscription data, the AAA service may also trigger the process of withdrawing the authentication result or re-authentication.
以下介绍AAA服务触发鉴权结果撤回或者重鉴权流程的方法。The following describes the method for the AAA service to trigger the authentication result withdrawal or re-authentication process.
如图5所示,为本申请实施例提供的一种鉴权结果撤回方法的流程图,该方法可以应用于图2所示的网络架构,具体可以在终端设备在第一接入管理网元或者第二接入管理网元接入时执行。方法包括:As shown in FIG. 5 , a flowchart of a method for withdrawing an authentication result provided in an embodiment of the present application can be applied to the network architecture shown in FIG. 2 . Or it is executed when the second access management network element is accessed. Methods include:
S501:AAA服务器向第二切片鉴权网元发送AAA协议消息,用于触发鉴权结果撤回或重鉴权流程。S501: The AAA server sends an AAA protocol message to the second slice authentication network element, which is used to trigger an authentication result withdrawal or re-authentication process.
具体的,AAA服务器上由于配置信息修改等,触发鉴权结果撤回(即图5所示的S501a),或者重鉴权流程(即图5所示的S501b)。其中鉴权结果撤回应用于鉴权结果为EAP成功的网络切片,将鉴权结果改为EAP失败;重鉴权流程用于通知接入管理网元触发网络切片鉴权流程,对网络切片重新进行EAP鉴权。AAA服务器发送对应的AAA协议消息给第二切片鉴权网元,第二切片鉴权网元可以和第一切片鉴权网元相同或者不同。Specifically, due to the modification of configuration information on the AAA server, the withdrawal of the authentication result (ie, S501a shown in FIG. 5 ), or the re-authentication process (ie, S501b shown in FIG. 5 ) is triggered. The authentication result revocation is used for the network slice whose authentication result is EAP success, and the authentication result is changed to EAP failure; EAP authentication. The AAA server sends a corresponding AAA protocol message to the second slice authentication network element, and the second slice authentication network element may be the same as or different from the first slice authentication network element.
S502:第二切片鉴权网元收到消息后,发送请求消息给数据管理网元,该请求消息用于查询服务终端设备的移动管理网元的注册信息;S502: After receiving the message, the second slice authentication network element sends a request message to the data management network element, where the request message is used to query the registration information of the mobility management network element serving the terminal device;
S503:数据管理网元回复响应消息给第二切片鉴权网元,该响应消息中包含移动管理网元注册信息,移动管理网元注册信息中包含接入管理网元标识。例如,接入管理网元标识为网络功能实例标识(Network function Instance Identity,NF Instance ID)。S503: The data management network element replies a response message to the second slice authentication network element, where the response message includes the mobility management network element registration information, and the mobility management network element registration information includes the access management network element identifier. For example, the access management network element identifier is a network function instance identifier (Network function Instance Identity, NF Instance ID).
移动管理网元注册信息的内容包括但不限于以下三种情况(Case):The content of the registration information of the mobility management network element includes but is not limited to the following three cases (Case):
Case1,移动管理网元注册信息中包括接入管理网元标识,针对终端设备当前在第一接入管理网元接入时,接入管理网元标识为第一接入管理网元的标识。Case 1, the mobility management network element registration information includes the access management network element identifier, and when the terminal device is currently accessing the first access management network element, the access management network element identifier is the identifier of the first access management network element.
Case2,移动管理网元注册信息中包括接入管理网元标识,针对终端设备从第一接入管理网元移动到第二接入管理网元时,即上述场景一的场景,第二接入管理网元在4G网络内,则接入管理网元标识为第一接入管理网元的标识;并且移动管理网元注册信息中还包含清除指示,清除指示用于指示第一接入管理网元已经分离。Case 2, the mobility management network element registration information includes the access management network element identifier. When the terminal device moves from the first access management network element to the second access management network element, that is, the scenario of the above scenario 1, the second access management network element If the management network element is in the 4G network, the access management network element identifier is the identifier of the first access management network element; and the registration information of the mobility management network element also includes a clear indication, and the clear indication is used to indicate the first access management network element. Elements have been separated.
Case3,移动管理网元注册信息中包括接入管理网元标识,针对终端设备从第一接入管理网元移动到第二接入管理网元时,上述场景二的场景,第二接入管理网元在5G网络内,则接入管理网元标识为第二接入管理网元的标识,并且移动管理网元注册信息中还包含第二接入管理网元支持的特性,指示第二接入管理网元不支持网络切片鉴权功能。Case 3, the registration information of the mobility management network element includes the access management network element identifier. When the terminal device moves from the first access management network element to the second access management network element, the above scenario of the second access management network element, the second access management network element If the network element is in the 5G network, the access management network element identifier is the identifier of the second access management network element, and the mobility management network element registration information also includes the features supported by the second access management network element, indicating the second access management network element. The inbound management NE does not support the network slice authentication function.
第二切片鉴权网元根据接收到的移动管理网元注册信息的具体内容执行不同的处理:The second slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:
A、如果移动管理网元注册信息中包含接入管理网元的标识,并且清除指示指示接入管理网元分离,或者支持的特性信息指示接入管理网元不支持网络切片鉴权功能,即上述case2或3,第二切片鉴权网元执行S504a和S505a。A. If the mobile management network element registration information contains the identity of the access management network element, and the clear indication indicates that the access management network element is separated, or the supported feature information indicates that the access management network element does not support the network slice authentication function, that is In the above case 2 or 3, the second slice authentication network element executes S504a and S505a.
S504a:第二切片鉴权网元发送签约数据更新请求消息给数据管理网元,消息中包含切片标识S-NSSAI。可选的,消息中还包含鉴权结果。S504a: The second slice authentication network element sends a subscription data update request message to the data management network element, where the message includes the slice identifier S-NSSAI. Optionally, the message also includes the authentication result.
具体的,第二切片鉴权网元根据步骤S501中收到的AAA协议消息,如果AAA服务器触发的是鉴权结果撤回流程,则签约数据更新请求消息用于通知数据管理网元修改鉴权结果,签约数据更新请求消息携带鉴权结果且鉴权结果为EAP失败。如果AAA服务器触发的是重鉴权流程,则签约数据更新请求消息用于通知数据管理网元删除鉴权结果,签约数据更新请求消息可以不包含鉴权结果,或者包含空的鉴权结果,或者包含鉴权结果并且还包含删除指示信息。相应的,如果AAA服务器触发的是鉴权结果撤回流程,则第二切片鉴权网元将数据管理网元上的签约数据中切片标识S-NSSAI对应的鉴权结果修改为EAP失败;如果AAA服务器触发的是重鉴权流程,则第二切片鉴权网元将数据管理网元上的签约数据中切片标识S-NSSAI对应的鉴权结果删除。Specifically, according to the AAA protocol message received by the second slice authentication network element in step S501, if the AAA server triggers the authentication result withdrawal process, the subscription data update request message is used to notify the data management network element to modify the authentication result , the subscription data update request message carries the authentication result and the authentication result is EAP failure. If the AAA server triggers the re-authentication process, the subscription data update request message is used to notify the data management network element to delete the authentication result. The subscription data update request message may not contain the authentication result, or contain an empty authentication result, or Contains the authentication result and also contains deletion indication information. Correspondingly, if the AAA server triggers the authentication result withdrawal process, the second slice authentication network element modifies the authentication result corresponding to the slice identifier S-NSSAI in the subscription data on the data management network element to EAP failure; The server triggers the re-authentication process, and the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the subscription data on the data management network element.
S505a:数据管理网元回复签约数据更新响应消息给第二切片鉴权网元,用于指示签约数据更新成功或者失败。S505a: The data management network element replies a subscription data update response message to the second slice authentication network element, which is used to indicate whether the subscription data update succeeds or fails.
B、如果移动管理网元注册信息中包含接入管理网元的标识,并且清除指示指示接入管理网元没有分离,或者移动管理网元注册信息中没有包含清除指示信息,并且支持的特性信息指示接入管理网元支持网络切片鉴权功能,即上述case1,第二切片鉴权网元执行步骤S504b及之后的步骤或S504c及之后的步骤。B. If the registration information of the mobility management network element contains the identification of the access management network element, and the clear indication indicates that the access management network element is not separated, or the registration information of the mobility management network element does not contain the clear indication information, and the supported feature information Indicates that the access management network element supports the network slice authentication function, that is, the above case 1, the second slice authentication network element performs step S504b and subsequent steps or S504c and subsequent steps.
下面对鉴权结果撤回和重鉴权流程进行区分介绍。The following describes the procedures for withdrawing the authentication result and re-authentication.
如果AAA服务器触发重鉴权流程,则执行:If the AAA server triggers the re-authentication process, execute:
S504b:第二切片鉴权网元发送重鉴权通知消息给第一接入管理网元,消息中包含用户标识和切片标识S-NSSAI。S504b: The second slice authentication network element sends a re-authentication notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
S505b:第一接入管理网元回复重鉴权通知响应消息。S505b: The first access management network element replies with a re-authentication notification response message.
S506b:第一接入管理网元针对重鉴权的网络切片触发网络切片鉴权流程,具体流程和图1流程相同。S506b: The first access management network element triggers a network slice authentication process for the re-authenticated network slice, and the specific process is the same as the process in FIG. 1 .
S507b:第一接入管理网元发送签约数据更新请求消息给数据管理网元,签约数据更新请求消息中携带切片标识和重鉴权后获得的鉴权结果。S507b: The first access management network element sends a subscription data update request message to the data management network element, where the subscription data update request message carries the slice identifier and the authentication result obtained after re-authentication.
S508:数据管理网元回复签约数据更新响应消息给第一接入管理网元,用于指示签约数据更新成功或者失败。S508: The data management network element replies a subscription data update response message to the first access management network element, which is used to indicate whether the subscription data update succeeds or fails.
如果AAA服务器触发鉴权结果撤回流程,则执行:If the AAA server triggers the authentication result revocation process, execute:
S504c:第二切片鉴权网元发送鉴权结果撤回通知消息给第一接入管理网元,消息中包含用户标识和切片标识S-NSSAI。S504c: The second slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
S505c:第一接入管理网元回复鉴权结果撤回通知响应消息。S505c: The first access management network element replies with an authentication result withdrawal notification response message.
S506a:第一接入管理网元发送签约数据更新请求消息给数据管理网元,消息中包含切片标识S-NSSAI及其鉴权结果。消息用于将切片标识S-NSSAI对应的鉴权结果修改为EAP失败。数据管理网元收到消息后,更新签约数据,将鉴权结果存储到签约数据中切片标识S-NSSAI对应的数据中。S506a: The first access management network element sends a subscription data update request message to the data management network element, where the message includes the slice identifier S-NSSAI and its authentication result. The message is used to modify the authentication result corresponding to the slice identifier S-NSSAI to EAP failure. After receiving the message, the data management network element updates the subscription data, and stores the authentication result in the data corresponding to the slice identifier S-NSSAI in the subscription data.
S507a:数据管理网元回复签约数据更新响应消息给第一接入管理网元,用于指示签 约数据更新成功或者失败。S507a: The data management network element replies a subscription data update response message to the first access management network element, which is used to indicate success or failure of the subscription data update.
需要说明的是,上述流程中,S507b和S506a也可以由第二切片鉴权网元执行,将重鉴权后获得的鉴权结果存储到终端设备的签约数据中,或者将切片标识S-NSSAI对应的鉴权结果修改为EAP失败。It should be noted that, in the above process, S507b and S506a can also be performed by the second slice authentication network element, and the authentication result obtained after re-authentication is stored in the subscription data of the terminal device, or the slice identifier S-NSSAI is stored. The corresponding authentication result is changed to EAP failure.
在上述实施例一中,第一接入管理网元在网络切片鉴权过程中在数据管理网元上存储鉴权结果,使得终端设备在上述场景一和场景二所列的移动场景中,第三接入管理网元可以从数据管理网元上获取所述鉴权结果,进而不需要针对网络切片执行网络切片鉴权流程,节省网络信令开销,同时终端设备也不需要等待第三接入管理网元执行完网络切片鉴权流程后才能建立到特定网络切片的会话,加速了业务建立的过程,可以提升终端设备的业务体验。另外,当数据管理网元存储鉴权结果后,AAA服务器还可以触发的重鉴权或者鉴权结果撤回流程,提升了网络切片鉴权的灵活性。In the above-mentioned first embodiment, the first access management network element stores the authentication result on the data management network element during the network slice authentication process, so that the terminal device in the mobile scenarios listed in the above-mentioned first and second scenarios, the first The three access management network elements can obtain the authentication results from the data management network elements, so that the network slice authentication process does not need to be performed for network slices, which saves network signaling overhead, and the terminal equipment does not need to wait for the third access A session to a specific network slice can be established only after the management NE completes the network slice authentication process, which speeds up the process of service establishment and improves the service experience of terminal devices. In addition, after the data management network element stores the authentication result, the AAA server can also trigger the re-authentication or authentication result withdrawal process, which improves the flexibility of network slice authentication.
实施例二Embodiment 2
本实施例主要介绍:鉴权结果存储在数据管理网元上,第一切片鉴权网元在网络切片鉴权过程中去数据管理网元上存储;第三接入管理网元向第二切片鉴权网元请求鉴权结果,第二切片鉴权网元向数据管理网元请求鉴权结果。可选的,在AAA服务器触发的重鉴权或者鉴权结果撤回流程中,第二切片鉴权网元修改数据管理网元上的鉴权结果。This embodiment mainly introduces: the authentication result is stored on the data management network element, the first slice authentication network element is stored on the data management network element during the network slice authentication process; the third access management network element reports to the second The slice authentication network element requests the authentication result, and the second slice authentication network element requests the authentication result from the data management network element. Optionally, in the process of re-authentication or authentication result withdrawal triggered by the AAA server, the second slice authentication network element modifies the authentication result on the data management network element.
与实施例一的区别包括:实施例二是鉴权结果由切片鉴权网元储存到数据管理网元,也由切片鉴权网元从数据管理网元中获取;而实施例一中鉴权结果由接入管理网元存储到数据管理网元,也由接入管理网元从数据管理网元中获取。The differences from the first embodiment include: in the second embodiment, the authentication result is stored in the data management network element by the slice authentication network element, and is also obtained from the data management network element by the slice authentication network element; The result is stored in the data management network element by the access management network element, and is also obtained from the data management network element by the access management network element.
如图6所示,为本申请实施例提供的另一种具体的切片鉴权方法的流程图,该方法可以应用于图2所示的网络架构中,方法包括:As shown in FIG. 6 , a flowchart of another specific slice authentication method provided by an embodiment of the present application, the method can be applied to the network architecture shown in FIG. 2 , and the method includes:
S601、第一接入管理网元触发网络切片鉴权流程。S601. A first access management network element triggers a network slice authentication process.
具体的,终端设备接入第一接入管理网元,第一接入管理网元从数据管理网元获取终端设备的签约数据,第一接入管理网元根据签约数据中包含的切片标识S-NSSAI,及其网络切片鉴权指示信息获知S-NSSAI所标识的网络切片(相当于上文中的第一切片)需要执行网络切片鉴权,则第一接入管理网元触发网络切片鉴权流程,具体流程和图1流程相同。其中第一接入管理网元对应图1中的接入管理网元,第一切片鉴权网元对应图1中的切片鉴权功能。Specifically, the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element obtains the subscription data of the terminal device according to the slice identifier S included in the subscription data. -NSSAI, and its network slice authentication indication information If the network slice identified by S-NSSAI (equivalent to the first slice above) needs to perform network slice authentication, the first access management network element triggers the network slice authentication The specific process is the same as that in Figure 1. The first access management network element corresponds to the access management network element in FIG. 1 , and the first slice authentication network element corresponds to the slice authentication function in FIG. 1 .
当第一切片鉴权网元获知网络切片的鉴权结果(即执行完图1所示的S1011)后,继续执行如下步骤:When the first slice authentication network element learns the authentication result of the network slice (that is, after performing S1011 shown in FIG. 1 ), it continues to perform the following steps:
S602:第一切片鉴权网元发送请求消息给数据管理网元,消息中包含切片标识S-NSSAI及其鉴权结果。数据管理网元收到消息后,存储切片标识S-NSSAI及其鉴权结果。S602: The first slice authentication network element sends a request message to the data management network element, where the message includes the slice identifier S-NSSAI and its authentication result. After receiving the message, the data management network element stores the slice identifier S-NSSAI and its authentication result.
可选的,数据管理网元可以判断终端设备的签约数据中是否签约切片标识S-NSSAI,如果终端设备的签约数据中不存在切片标识S-NSSAI,则数据管理网元不存储切片标识S-NSSAI及其鉴权结果。Optionally, the data management network element may determine whether the subscription slice identifier S-NSSAI is in the subscription data of the terminal device. If the slice identifier S-NSSAI does not exist in the subscription data of the terminal device, the data management network element does not store the slice identifier S-NSSAI. NSSAI and its authentication results.
S603:数据管理网元回复响应消息给第一切片鉴权网元,用于指示鉴权结果更新成功或者失败。S603: The data management network element replies a response message to the first slice authentication network element, which is used to indicate whether the update of the authentication result succeeds or fails.
需要说明的是,终端设备可以签约多个需要执行网络切片鉴权的切片标识S-NSSAI,第一切片鉴权网元可以执行多次请求,每次请求用以存储一个或者多个切片标识S-NSSAI,及其对应的鉴权结果。It should be noted that the terminal device can subscribe to multiple slice identifiers S-NSSAI that need to perform network slice authentication, and the first slice authentication network element can perform multiple requests, and each request is used to store one or more slice identifiers. S-NSSAI, and its corresponding authentication result.
上面S601~S603介绍了第一切片鉴权网元将鉴权结果储存到数据管理网元的过程,接下来介绍终端设备发生移动后,新的接入管理网元(第三接入管理网元)从数据管理网元获取鉴权结果的过程。The above S601 to S603 describe the process that the first slice authentication network element stores the authentication result in the data management network element. element) the process of obtaining the authentication result from the data management network element.
终端设备发生移动的场景可以参考实施例一中的场景一和场景二,此处不再赘述。For a scenario in which the terminal device moves, reference may be made to scenario 1 and scenario 2 in Embodiment 1, and details are not described herein again.
请继续参见图6,在终端设备从第二接入管理网元移动到第三接入管理网元流程中,终端设备触发注册更新流程:Please continue to refer to FIG. 6 , in the process of moving the terminal device from the second access management network element to the third access management network element, the terminal device triggers the registration update process:
S604:终端设备发送注册更新请求消息给第三接入管理网元。S604: The terminal device sends a registration update request message to the third access management network element.
S605:在注册更新流程中,第三接入管理网元向第二切片鉴权网元发送鉴权结果请求消息(第一请求消息),用于获取终端设备的鉴权结果,该消息中包含终端设备的标识,还包含一个或者多个切片标识S-NSSAI。S605: In the registration update process, the third access management network element sends an authentication result request message (the first request message) to the second slice authentication network element to obtain the authentication result of the terminal device, and the message includes The identifier of the terminal device also includes one or more slice identifiers S-NSSAI.
S606:第二切片鉴权网元发送获取鉴权结果请求消息给数据管理网元,消息中包含终端设备的标识,还包含一个或者多个切片标识S-NSSAI。S606: The second slice authentication network element sends a request message for obtaining the authentication result to the data management network element, where the message includes the identifier of the terminal device and also includes one or more slice identifiers S-NSSAI.
S607:数据管理网元回复获取鉴权结果响应消息给第二切片鉴权网元,消息中包含其鉴权结果。S607: The data management network element replies the obtaining authentication result response message to the second slice authentication network element, and the message includes the authentication result.
可选的,消息中还可以包含切片标识S-NSSAI。Optionally, the message may also include the slice identifier S-NSSAI.
可选的,鉴权结果响应消息具体可以包含多个切片标识S-NSSAI,及每个切片对应的鉴权结果。Optionally, the authentication result response message may specifically include multiple slice identifiers S-NSSAI, and an authentication result corresponding to each slice.
S608:第二切片鉴权网元回复获取鉴权结果响应消息(第一响应消息)给第三接入管理网元,获取鉴权结果响应消息中包含鉴权结果。可选的,获取鉴权结果响应消息中还包含切片标识S-NSSAI。S608: The second slice authentication network element replies to the third access management network element with a response message for obtaining the authentication result (the first response message), and the response message for obtaining the authentication result includes the authentication result. Optionally, the obtaining authentication result response message also includes the slice identifier S-NSSAI.
具体的,鉴权结果响应消息可以包含一个或者多个切片标识S-NSSAI,及其鉴权结果。Specifically, the authentication result response message may include one or more slice identifiers S-NSSAI and the authentication result thereof.
当第一切片鉴权网元将鉴权结果存储到鉴权结果数据中后,AAA服务还可以触发鉴权结果撤回或者重鉴权的流程。以下介绍AAA服务触发鉴权结果撤回或者重鉴权流程的方法。After the first slice authentication network element stores the authentication result in the authentication result data, the AAA service may also trigger the process of withdrawing the authentication result or re-authentication. The following describes the method for the AAA service to trigger the authentication result withdrawal or re-authentication process.
如图7所示,为本申请实施例提供的另一种鉴权结果撤回方法的流程图,该方法可以应用于图2所示的网络架构,具体可以在终端设备在第一接入管理网元或者第二接入管理网元接入时执行。方法包括:As shown in FIG. 7 , a flowchart of another authentication result withdrawal method provided in this embodiment of the present application can be applied to the network architecture shown in FIG. 2 . Executed when the network element or the second access management network element is accessed. Methods include:
S701:AAA服务器向第二切片鉴权网元发送AAA协议消息,用于触发鉴权结果撤回或重鉴权流程。S701: The AAA server sends an AAA protocol message to the second slice authentication network element, which is used to trigger an authentication result withdrawal or re-authentication process.
S701的具体实现过程可以参见上文中的S501的具体实现过程,这里不再赘述。For the specific implementation process of S701, reference may be made to the specific implementation process of S501 above, which will not be repeated here.
S702:第二切片鉴权网元收到消息后,发送请求消息给数据管理网元,该请求消息用于查询服务终端设备的移动管理网元注册信息。S702: After receiving the message, the second slice authentication network element sends a request message to the data management network element, where the request message is used to query the registration information of the mobility management network element of the service terminal device.
S703:数据管理网元回复响应消息给第二切片鉴权网元,消息中包含移动管理网元注册信息,移动管理网元注册信息中包含接入管理网元标识。例如,接入管理网元标识为NF Instance ID。S703: The data management network element replies a response message to the second slice authentication network element, where the message includes the mobility management network element registration information, and the mobility management network element registration information includes the access management network element identifier. For example, the access management network element is identified as NF Instance ID.
移动管理网元注册信息的内容可以参考实施例一中的三种情况(Case1、Case2、Case3),这里不再赘述。For the content of the registration information of the mobility management network element, reference may be made to the three cases (Case1, Case2, and Case3) in the first embodiment, which will not be repeated here.
进一步的,第二切片鉴权网元根据接收到的移动管理网元注册信息的具体内容执行不同的处理:Further, the second slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:
A、如果移动管理网元注册信息中包含接入管理网元的标识,并且清除指示指示接入 管理网元分离,或者支持的特性信息指示接入管理网元不支持网络切片鉴权功能,即上述case2或3,第二切片鉴权网元执行S704a和S705a。A. If the mobile management network element registration information contains the identity of the access management network element, and the clear indication indicates that the access management network element is separated, or the supported feature information indicates that the access management network element does not support the network slice authentication function, that is In the above case 2 or 3, the second slice authentication network element executes S704a and S705a.
S704a:第二切片鉴权网元发送鉴权结果更新请求消息给数据管理网元,鉴权结果更新请求消息中包含切片标识S-NSSAI。可选的,鉴权结果更新请求消息中还包含鉴权结果。S704a: The second slice authentication network element sends an authentication result update request message to the data management network element, where the authentication result update request message includes the slice identifier S-NSSAI. Optionally, the authentication result update request message further includes the authentication result.
数据管理网元收到鉴权结果更新请求消息后,如果AAA服务器触发的是鉴权结果撤回流程,则第二切片鉴权网元将鉴权结果数据中所述切片标识S-NSSAI对应的鉴权结果修改为EAP失败;如果AAA服务器触发的是重鉴权流程,则第二切片鉴权网元将签约数据中切片标识S-NSSAI对应的鉴权结果删除。After the data management network element receives the authentication result update request message, if the AAA server triggers the authentication result withdrawal process, the second slice authentication network element will authenticate the slice identifier S-NSSAI corresponding to the authentication result data. The authorization result is modified to EAP failure; if the AAA server triggers the re-authentication process, the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the subscription data.
具体的,第二切片鉴权网元根据步骤S701中收到的AAA协议消息,如果AAA服务器触发的是鉴权结果撤回流程,则鉴权结果更新请求消息用于通知数据管理网元修改鉴权结果,签约数据更新请求消息携带鉴权结果且鉴权结果为EAP失败。如果AAA服务器触发的是重鉴权流程,则鉴权结果更新请求消息用于通知数据管理网元删除鉴权结果,签约数据更新请求消息可以不包含鉴权结果,或者包含空的鉴权结果,或者包含鉴权结果并且还包含删除指示信息。Specifically, according to the AAA protocol message received by the second slice authentication network element in step S701, if the AAA server triggers the authentication result withdrawal process, the authentication result update request message is used to notify the data management network element to modify the authentication As a result, the subscription data update request message carries the authentication result and the authentication result is EAP failure. If the AAA server triggers the re-authentication process, the authentication result update request message is used to notify the data management network element to delete the authentication result. The subscription data update request message may not contain the authentication result, or contain an empty authentication result. Or include the authentication result and also include deletion indication information.
需要说明的是,本实施例中将切片标识S-NSSAI和鉴权结果存储在数据管理网元的鉴权结果数据中,和实施例一的不同之处在于,实施例一将鉴权结果存储在数据管理网元的签约数据中切片标识S-NSSAI对应的数据中,所以在本实施例S704a中第二切片鉴权网元发送鉴权结果更新请求消息给数据管理网元,而在实施例一S504a中第二切片鉴权网元发送签约数据更新请求消息给数据管理网元。It should be noted that, in this embodiment, the slice identifier S-NSSAI and the authentication result are stored in the authentication result data of the data management network element. The difference from Embodiment 1 is that Embodiment 1 stores the authentication result. In the subscription data of the data management network element, the slice identifier S-NSSAI corresponds to the data, so in this embodiment S704a, the second slice authentication network element sends an authentication result update request message to the data management network element, while in the embodiment In S504a, the second slice authentication network element sends a subscription data update request message to the data management network element.
S705a:数据管理网元回复鉴权结果更新响应消息给第二切片鉴权网元,用于指示所述鉴权结果数据更新成功或者失败。S705a: The data management network element replies an authentication result update response message to the second slice authentication network element, which is used to indicate whether the authentication result data update succeeds or fails.
B、如果移动管理网元注册信息中包含接入管理网元的标识,并且清除指示指示接入管理网元没有分离,或者移动管理网元注册信息中没有包含清除指示信息,并且支持的特性信息指示接入管理网元支持网络切片鉴权功能,即上述case1,第二切片鉴权网元执行步骤S704b及之后的步骤或S704c及之后的步骤。B. If the registration information of the mobility management network element contains the identification of the access management network element, and the clear indication indicates that the access management network element is not separated, or the registration information of the mobility management network element does not contain the clear indication information, and the supported feature information Indicates that the access management network element supports the network slice authentication function, that is, the above case 1, the second slice authentication network element executes step S704b and subsequent steps or S704c and subsequent steps.
下面对鉴权结果撤回和重鉴权流程进行区分介绍。The following describes the procedures for withdrawing the authentication result and re-authentication.
如果AAA服务器触发重鉴权流程,则执行:If the AAA server triggers the re-authentication process, execute:
S704b:第二切片鉴权网元发送重鉴权通知消息给第一接入管理网元,消息中包含用户标识和切片标识S-NSSAI。S704b: The second slice authentication network element sends a re-authentication notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
S705b:第一接入管理网元回复重鉴权通知响应消息。S705b: The first access management network element replies with a re-authentication notification response message.
S706b:第一接入管理网元针对重鉴权的网络切片触发网络切片鉴权流程,具体流程和图1流程相同。S706b: The first access management network element triggers a network slice authentication process for the re-authenticated network slice, and the specific process is the same as the process in FIG. 1 .
S707b:第二切片鉴权网元发送鉴权结果更新请求消息给数据管理网元,消息中携带切片标识和重鉴权后获得的鉴权结果。S707b: The second slice authentication network element sends an authentication result update request message to the data management network element, where the message carries the slice identifier and the authentication result obtained after re-authentication.
S708:数据管理网元回复鉴权结果更新响应消息给第二切片鉴权网元,用于指示签约数据更新成功或者失败。S708: The data management network element replies an authentication result update response message to the second slice authentication network element, which is used to indicate whether the subscription data update succeeds or fails.
如果AAA服务器触发鉴权结果撤回流程,则执行:If the AAA server triggers the authentication result revocation process, execute:
S704c:第二切片鉴权网元发送鉴权结果撤回通知消息给第一接入管理网元,消息中包含用户标识和切片标识S-NSSAI;S704c: The second slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI;
S705c:第一接入管理网元回复鉴权结果撤回通知响应消息;S705c: The first access management network element replies with an authentication result withdrawal notification response message;
S706a:第二切片鉴权网元发送鉴权结果更新请求消息给数据管理网元,所述消息中包含切片标识S-NSSAI及其鉴权结果。所述消息用于将切片标识S-NSSAI对应的鉴权结果修改为EAP失败。所述数据管理网元收到消息后,存储所述切片标识S-NSSAI及其鉴权结果。S706a: The second slice authentication network element sends an authentication result update request message to the data management network element, where the message includes the slice identifier S-NSSAI and the authentication result. The message is used to modify the authentication result corresponding to the slice identifier S-NSSAI to EAP failure. After receiving the message, the data management network element stores the slice identifier S-NSSAI and its authentication result.
S707a:数据管理网元回复鉴权结果更新响应消息给第二切片鉴权网元,用于指示所述鉴权结果更新成功或者失败。S707a: The data management network element replies an authentication result update response message to the second slice authentication network element, which is used to indicate whether the authentication result update succeeds or fails.
在上述实施例二中,第一切片鉴权网元在网络切片鉴权过程中在数据管理网元上存储鉴权结果,使得终端设备在上述场景一和场景二所列的移动场景中,第三接入管理网元可以从数据管理网元上获取所述鉴权结果,进而不需要针对网络切片执行网络切片鉴权流程,节省网络信令开销,同时终端设备也不需要等待第三接入管理网元执行完网络切片鉴权流程后才能建立到特定网络切片的会话,加速了业务建立的过程,可以提升终端设备的业务体验。另外,当数据管理网元存储鉴权结果后,AAA服务器还可以触发的重鉴权或者鉴权结果撤回流程,提升了网络切片鉴权的灵活性。In the above-mentioned second embodiment, the first slice authentication network element stores the authentication result on the data management network element during the network slice authentication process, so that the terminal device in the mobile scenarios listed in the above-mentioned first and second scenarios, The third access management network element can obtain the authentication result from the data management network element, so that the network slice authentication process does not need to be performed for the network slice, which saves network signaling overhead, and the terminal device does not need to wait for the third access management network element. A session to a specific network slice can be established only after the inbound management NE completes the network slice authentication process, which speeds up the process of service establishment and improves the service experience of terminal devices. In addition, after the data management network element stores the authentication result, the AAA server can also trigger the re-authentication or authentication result withdrawal process, which improves the flexibility of network slice authentication.
实施例三Embodiment 3
本实施例主要介绍:鉴权结果存储在第一切片鉴权网元上,第一切片鉴权网元在网络切片鉴权过程中存储鉴权结果,第一切片鉴权网元还将第一切片鉴权网元注册信息注册到数据管理网元;第三接入管理网元向第二切片鉴权网元请求鉴权结果,而第二切片鉴权网元从数据管理网元上获得第一切片鉴权网元注册信息,根据第一切片鉴权网元注册信息向第一切片鉴权网元请求鉴权结果。可选的,在AAA服务器触发的重鉴权或者鉴权结果撤回流程中,第二切片鉴权网元通知第一切片鉴权网元更新鉴权结果。This embodiment mainly introduces: the authentication result is stored on the first slice authentication network element, the first slice authentication network element stores the authentication result during the network slice authentication process, and the first slice authentication network element also Register the registration information of the first slice authentication network element to the data management network element; the third access management network element requests the authentication result from the second slice authentication network element, and the second slice authentication network element obtains the authentication result from the data management network element. The element obtains the registration information of the first slice authentication network element, and requests the authentication result from the first slice authentication network element according to the registration information of the first slice authentication network element. Optionally, in the process of re-authentication or authentication result withdrawal triggered by the AAA server, the second slice authentication network element notifies the first slice authentication network element to update the authentication result.
如图8所示,为本实施例提供的另一种具体的切片鉴权方法,该方法可以应用于图2所示的网络架构中,方法包括:As shown in FIG. 8, another specific slice authentication method provided in this embodiment can be applied to the network architecture shown in FIG. 2, and the method includes:
S801、第一接入管理网元触发网络切片鉴权流程。S801. A first access management network element triggers a network slice authentication process.
具体的,终端设备接入第一接入管理网元,第一接入管理网元从数据管理网元获取终端设备的签约数据,第一接入管理网元根据签约数据中包含的切片标识S-NSSAI,及其网络切片鉴权指示信息获知S-NSSAI所标识的网络切片(相当于上文中的第一切片)需要执行网络切片鉴权,则第一接入管理网元触发网络切片鉴权流程,具体流程和图1流程相同。其中第一接入管理网元对应图1中的接入管理节点,第一切片鉴权网元对应图1中的切片鉴权功能。Specifically, the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element obtains the subscription data of the terminal device according to the slice identifier S included in the subscription data. -NSSAI, and its network slice authentication indication information If the network slice identified by S-NSSAI (equivalent to the first slice above) needs to perform network slice authentication, the first access management network element triggers the network slice authentication The specific process is the same as that in Figure 1. The first access management network element corresponds to the access management node in FIG. 1 , and the first slice authentication network element corresponds to the slice authentication function in FIG. 1 .
当第一切片鉴权网元获知网络切片的鉴权结果(即执行完图1所示的S1011)后,继续执行如下步骤:When the first slice authentication network element learns the authentication result of the network slice (that is, after performing S1011 shown in FIG. 1 ), it continues to perform the following steps:
S802:所述第一切片鉴权网元保存用户标识,网络切片S-NSSAI和鉴权结果。S802: The first slice authentication network element stores the user identifier, the network slice S-NSSAI and the authentication result.
S803:第一切片鉴权网元发送注册请求消息给数据管理网元,用于将第一切片鉴权网元信息注册到数据管理网元中,所述消息中包含用户标识,网络切片S-NSSAI和第一切片鉴权网元标识。例如,所述第一切片鉴权网元标识可以为网络功能实例标识。S803: The first slice authentication network element sends a registration request message to the data management network element, which is used to register the information of the first slice authentication network element in the data management network element, where the message includes the user identifier, the network slice S-NSSAI and first slice authentication network element identifier. For example, the first slice authentication network element identifier may be a network function instance identifier.
S804:数据管理网元回复注册响应消息给第一切片鉴权网元,用于指示第一切片鉴权网元信息注册成功或者失败。S804: The data management network element replies a registration response message to the first slice authentication network element, which is used to indicate whether the registration of the first slice authentication network element information succeeds or fails.
S805:数据管理网元保存所述第一切片鉴权网元注册信息。S805: The data management network element stores the registration information of the first slice authentication network element.
上面S801~S805介绍了第一切片鉴权网元存储鉴权结果以及将第一切片鉴权网元注册信息注册到数据管理网元的过程,接下来介绍终端设备发生移动后,新的接入管理网元(第 三接入管理网元)从第一切片鉴权网元获取鉴权结果的过程。The above S801 to S805 describe the process of storing the authentication result of the first slice authentication network element and registering the registration information of the first slice authentication network element to the data management network element. A process in which the access management network element (third access management network element) obtains the authentication result from the first slice authentication network element.
终端设备发生移动的场景可以参考实施例一中的场景一和场景二,此处不再赘述。For a scenario in which the terminal device moves, reference may be made to scenario 1 and scenario 2 in Embodiment 1, and details are not repeated here.
请继续参见图8,在终端设备从第二接入管理网元移动到第三接入管理网元的流程中,终端设备触发注册更新流程:Please continue to refer to FIG. 8 , in the process of moving the terminal device from the second access management network element to the third access management network element, the terminal device triggers the registration update process:
S806:在注册流程中,终端设备发送注册更新请求消息给第三接入管理网元;S806: In the registration process, the terminal device sends a registration update request message to the third access management network element;
S807:在注册流程中,第三接入管理网元选择第二切片鉴权网元,向第二切片鉴权网元发送获取鉴权结果请求消息(第一请求消息),消息中包含用户标识、网络切片S-NSSAI。S807: In the registration process, the third access management network element selects the second slice authentication network element, and sends a request message for obtaining the authentication result (the first request message) to the second slice authentication network element, and the message includes the user ID , Network slice S-NSSAI.
S808:第二切片鉴权网元本地没有用户标识和网络切片S-NSSAI对应的鉴权结果,发送获取切片鉴权注册信息消息给数据管理网元,消息中包含用户标识和网络切片S-NSSAI。S808: The second slice authentication network element does not have an authentication result corresponding to the user identifier and the network slice S-NSSAI locally, and sends a message of obtaining slice authentication registration information to the data management network element, where the message includes the user identifier and the network slice S-NSSAI .
S809:数据管理网元回复获取切片鉴权注册信息响应消息给第二切片鉴权网元,消息中包含切片鉴权网元注册信息,切片鉴权网元注册信息包含第一切片鉴权网元的标识。S809: The data management network element replies a response message for obtaining slice authentication registration information to the second slice authentication network element, where the message includes slice authentication network element registration information, and the slice authentication network element registration information includes the first slice authentication network element Element ID.
可选的,切片鉴权网元注册信息还包含网络切片S-NSSAI。Optionally, the slice authentication network element registration information further includes the network slice S-NSSAI.
数据管理网元根据步骤S807消息中的参数,查询与参数对应的切片鉴权网元注册信息,将切片鉴权网元注册信息发送给第二切片鉴权网元。The data management network element queries the slice authentication network element registration information corresponding to the parameter according to the parameters in the message in step S807, and sends the slice authentication network element registration information to the second slice authentication network element.
S8010:第二切片鉴权网元根据第一切片鉴权的标识,向第一切片鉴权网元发送获取鉴权结果请求消息,消息中包含用户标识和网络切片S-NSSAI。S8010: The second slice authentication network element sends a request message for obtaining the authentication result to the first slice authentication network element according to the identifier of the first slice authentication, where the message includes the user identifier and the network slice S-NSSAI.
S8011:第一切片鉴权网元回复获取鉴权结果响应消息给第二切片鉴权网元,鉴权结果响应消息中包含鉴权结果。S8011: The first slice authentication network element replies a response message for obtaining the authentication result to the second slice authentication network element, where the authentication result response message includes the authentication result.
可选的,鉴权结果响应消息中还包含用户标识、网络切片S-NSSAI。Optionally, the authentication result response message further includes the user identifier and the network slice S-NSSAI.
S8012:第二切片鉴权网元回复获取鉴权结果响应消息给第三接入管理网元(第一响应消息),鉴权结果响应消息中包含鉴权结果。S8012: The second slice authentication network element replies an acquisition authentication result response message to the third access management network element (the first response message), where the authentication result response message includes the authentication result.
可选的,鉴权结果响应消息中还可以包含用户标识,网络切片S-NSSAI。Optionally, the authentication result response message may further include the user identifier, the network slice S-NSSAI.
需要说明的是,终端设备可以签约多个需要执行网络切片鉴权的切片标识S-NSSAI,第二切片鉴权网元可以执行多次获取鉴权结果的请求,每次请求用以请求一个或者多个切片标识S-NSSAI,及其对应的鉴权结果。It should be noted that the terminal device can subscribe to multiple slice identifiers S-NSSAI that need to perform network slice authentication, and the second slice authentication network element can perform multiple requests to obtain the authentication results, and each request is used to request one or more S-NSSAI. Multiple slices identify S-NSSAI and their corresponding authentication results.
应理解,上述获取切片鉴权注册信息的流程中,也可以由接入管理网元去数据管理网元获取切片鉴权注册信息,进而获取网络切片的鉴权结果,具体为,S807-S8012替换为以下步骤1)~4):It should be understood that, in the above process of obtaining slice authentication registration information, the access management network element may also go to the data management network element to obtain slice authentication registration information, and then obtain the authentication result of the network slice. Specifically, S807-S8012 are replaced by For the following steps 1) to 4):
1)第三接入管理网元发送获取切片鉴权注册信息消息给数据管理网元,消息中包含用户标识和网络切片S-NSSAI。1) The third access management network element sends a message of obtaining slice authentication registration information to the data management network element, and the message includes the user identifier and the network slice S-NSSAI.
2)数据管理网元回复获取切片鉴权注册信息响应消息给第三接入管理网元,消息中包含切片鉴权网元注册信息,切片鉴权网元注册信息包含网络切片S-NSSAI和第一切片鉴权网元的标识。2) The data management network element replies to the third access management network element with a response message for obtaining slice authentication registration information. The message includes the slice authentication network element registration information, and the slice authentication network element registration information includes the network slice S-NSSAI and the third access management network element. Identifier of all slice authentication network elements.
3)第三接入管理网元根据第一切片鉴权网元的标识,向第一切片鉴权网元发送获取鉴权结果请求消息,消息中包含用户标识和网络切片S-NSSAI。3) The third access management network element sends a request message for obtaining the authentication result to the first slice authentication network element according to the identifier of the first slice authentication network element, and the message includes the user identifier and the network slice S-NSSAI.
4)第一切片鉴权网元回复获取鉴权结果响应消息,消息中包含用户标识,网络切片S-NSSAI和鉴权结果。4) The first slice authentication network element replies with a response message for obtaining the authentication result, and the message includes the user identifier, the network slice S-NSSAI and the authentication result.
当第一切片鉴权网元保存鉴权结果后,AAA服务还可以触发鉴权结果撤回或者重鉴权的流程。After the first slice authentication network element saves the authentication result, the AAA service may also trigger the process of withdrawing the authentication result or re-authentication.
以下介绍AAA服务触发鉴权结果撤回或者重鉴权流程的方法。The following describes the method for the AAA service to trigger the authentication result withdrawal or re-authentication process.
如图9所示,为本申请实施例提供的另一种鉴权结果撤回方法的流程图,该方法可以应用于图2所示的网络架构,具体可以在终端设备在第一接入管理网元或者第二接入管理网元接入时执行。方法包括:As shown in FIG. 9 , it is a flowchart of another method for withdrawing an authentication result provided by an embodiment of the present application. The method can be applied to the network architecture shown in FIG. 2 . Executed when the network element or the second access management network element is accessed. Methods include:
S901:AAA服务器向第二切片鉴权网元发送AAA协议消息,用于触发鉴权结果撤回或重鉴权流程。S901: The AAA server sends an AAA protocol message to the second slice authentication network element, which is used to trigger an authentication result withdrawal or re-authentication process.
S901的具体实现过程可以参见上文中S501的具体实现过程,这里不再赘述。For the specific implementation process of S901, reference may be made to the specific implementation process of S501 above, which will not be repeated here.
S902:第二切片鉴权网元收到消息后,发送请求消息给数据管理网元,该请求消息用于查询服务终端设备的移动管理网元注册信息。S902: After receiving the message, the second slice authentication network element sends a request message to the data management network element, where the request message is used to query the registration information of the mobility management network element of the service terminal device.
S903:数据管理网元回复响应消息给第二切片鉴权网元,消息中包含移动管理网元注册信息,移动管理网元注册信息中包含接入管理网元标识。例如,接入管理网元标识为NF Instance ID。S903: The data management network element replies a response message to the second slice authentication network element, where the message includes the mobility management network element registration information, and the mobility management network element registration information includes the access management network element identifier. For example, the access management network element is identified as NF Instance ID.
移动管理网元注册信息的内容可以参考实施例一中的三种情况(Case1、Case2、Case3),这里不再赘述。For the content of the registration information of the mobility management network element, reference may be made to the three cases (Case1, Case2, and Case3) in the first embodiment, which will not be repeated here.
进一步的,第二切片鉴权网元根据接收到的移动管理网元注册信息的具体内容执行不同的处理:Further, the second slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:
A、如果移动管理网元注册信息中包含接入管理网元的标识,并且清除指示指示接入管理网元分离,或者支持的特性信息指示接入管理网元不支持网络切片鉴权功能,即上述case2或3,第二切片鉴权网元执行步骤S904、S905、S906a和S907a。可选的,还可以执行步骤S908a和S909a。A. If the mobile management network element registration information contains the identity of the access management network element, and the clear indication indicates that the access management network element is separated, or the supported feature information indicates that the access management network element does not support the network slice authentication function, that is In the above case 2 or 3, the second slice authentication network element performs steps S904, S905, S906a and S907a. Optionally, steps S908a and S909a may also be performed.
S904:第二切片鉴权网元本地没有用户标识和网络切片S-NSSAI对应的鉴权结果,发送获取切片鉴权注册信息消息给数据管理网元,消息中包含用户标识和网络切片S-NSSAI。S904: The second slice authentication network element does not have the authentication result corresponding to the user identifier and the network slice S-NSSAI locally, and sends a message of obtaining slice authentication registration information to the data management network element, where the message includes the user identifier and the network slice S-NSSAI .
S905:数据管理网元回复获取切片鉴权注册信息响应消息给第二切片鉴权网元,消息中包含切片鉴权网元注册信息,切片鉴权网元注册信息包含网络切片S-NSSAI和第一切片鉴权网元的标识。具体的,数据管理网元根据S904消息中的参数,查询与参数对应的切片鉴权网元注册信息,将切片鉴权网元注册信息发送给第二切片鉴权网元。S906a:第二切片鉴权网元发送更新鉴权结果请求消息给第一切片鉴权网元,消息中包含用户标识,切片标识S-NSSAI及其鉴权结果。第一切片鉴权网元收到消息后,更新鉴权结果。如果AAA服务器触发的是鉴权结果撤回流程,则第二切片鉴权网元将第一切片鉴权网元中切片标识S-NSSAI对应的鉴权结果修改为EAP失败。如果AAA服务器触发的是重鉴权流程,则第二切片鉴权网元将第一切片鉴权网元中切片标识S-NSSAI对应的鉴权结果删除。S905: The data management network element replies a response message for obtaining slice authentication registration information to the second slice authentication network element, where the message includes the slice authentication network element registration information, and the slice authentication network element registration information includes the network slice S-NSSAI and the first slice authentication network element. Identifier of all slice authentication network elements. Specifically, the data management network element queries the slice authentication network element registration information corresponding to the parameters according to the parameters in the S904 message, and sends the slice authentication network element registration information to the second slice authentication network element. S906a: The second slice authentication network element sends an update authentication result request message to the first slice authentication network element, where the message includes the user identifier, the slice identifier S-NSSAI and its authentication result. After receiving the message, the first slice authentication network element updates the authentication result. If the AAA server triggers the authentication result withdrawal process, the second slice authentication network element modifies the authentication result corresponding to the slice identifier S-NSSAI in the first slice authentication network element to EAP failure. If the AAA server triggers the re-authentication process, the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the first slice authentication network element.
S907a:第一切片鉴权网元回复更新鉴权结果响应消息给第二切片鉴权网元,用于指示鉴权结果更新成功或者失败。S907a: The first slice authentication network element replies an update authentication result response message to the second slice authentication network element, which is used to indicate whether the authentication result update succeeds or fails.
如果S906a中,针对AAA服务器触发的是重鉴权流程,第一切片鉴权网元中的切片标识S-NSSAI对应的鉴权结果需要删除,则第一切片鉴权网元执行S908a和S909a。If in S906a, the re-authentication process is triggered by the AAA server, and the authentication result corresponding to the slice identifier S-NSSAI in the first slice authentication network element needs to be deleted, then the first slice authentication network element executes S908a and S909a.
S908a:第一切片鉴权网元发送去注册请求消息给数据管理网元,消息中包含切片标识S-NSSAI,还可以包含第一切片鉴权网元的标识。S908a: The first slice authentication network element sends a deregistration request message to the data management network element, where the message includes the slice identifier S-NSSAI, and may also include the identifier of the first slice authentication network element.
S909a:数据管理网元回复去注册响应消息给第一切片鉴权网元,用于指示第一切片鉴权网元去注册成功或者失败。S909a: The data management network element replies a de-registration response message to the first slice authentication network element, which is used to indicate the success or failure of the first slice authentication network element to de-register.
如果移动管理网元注册信息中包含接入管理网元的标识,并且清除指示指示接入管理网元没有分离,或者移动管理网元注册信息中没有包含清除指示信息,并且支持的特性信 息指示接入管理网元支持网络切片鉴权功能,即上述case1,第二切片鉴权网元执行步骤S904、S905、S906b或S906c及之后的步骤。If the registration information of the mobility management network element contains the identity of the access management network element, and the clear indication indicates that the access management network element is not separated, or the registration information of the mobility management network element does not contain the clear indication information, and the supported feature information indicates that the access management network element is not separated The incoming management network element supports the network slice authentication function, that is, the above case 1, and the second slice authentication network element performs steps S904, S905, S906b or S906c and subsequent steps.
S904:第二切片鉴权网元本地没有用户标识和网络切片S-NSSAI对应的鉴权结果,发送获取切片鉴权注册信息消息给数据管理网元,消息中包含用户标识和网络切片S-NSSAI。S904: The second slice authentication network element does not have the authentication result corresponding to the user identifier and the network slice S-NSSAI locally, and sends a message of obtaining slice authentication registration information to the data management network element, where the message includes the user identifier and the network slice S-NSSAI .
S905:数据管理网元回复获取切片鉴权注册信息响应消息给第二切片鉴权网元,消息中包含切片鉴权网元注册信息,切片鉴权网元注册信息包含网络切片S-NSSAI和第一切片鉴权网元的标识。具体的,数据管理网元根据S904消息中的参数,查询与参数对应的切片鉴权网元注册信息,将切片鉴权网元注册信息发送给第二切片鉴权网元。S905: The data management network element replies a response message for obtaining slice authentication registration information to the second slice authentication network element, where the message includes the slice authentication network element registration information, and the slice authentication network element registration information includes the network slice S-NSSAI and the first slice authentication network element. Identifier of all slice authentication network elements. Specifically, the data management network element queries the slice authentication network element registration information corresponding to the parameters according to the parameters in the S904 message, and sends the slice authentication network element registration information to the second slice authentication network element.
这里对AAA服务器触发的权结果撤回流程和重鉴权流程进行区分介绍。Here, the process of withdrawing the right result triggered by the AAA server and the process of re-authentication are introduced separately.
1)AAA服务器触发重鉴权:1) AAA server triggers re-authentication:
S906b:第二切片鉴权网元发送重鉴权通知消息给第一接入管理网元,消息中包含用户标识和切片标识S-NSSAI。S906b: The second slice authentication network element sends a re-authentication notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
S907b:第一接入管理网元回复重鉴权通知响应消息。S907b: The first access management network element replies with a re-authentication notification response message.
S908b:第一接入管理网元针对重鉴权的网络切片触发网络切片鉴权流程,具体流程和图1流程相同。S908b: The first access management network element triggers a network slice authentication process for the re-authenticated network slice, and the specific process is the same as that in FIG. 1 .
S909b:第二切片鉴权网元在网络切片鉴权流程获得AAA服务器发送的鉴权结果后,通知第一切片鉴权网元更新网络切片的鉴权结果。S909b: After obtaining the authentication result sent by the AAA server in the network slice authentication process, the second slice authentication network element notifies the first slice authentication network element to update the authentication result of the network slice.
具体实现过程结可参考S906a和S907a,这里不再详细介绍。For the detailed implementation process, please refer to S906a and S907a, which will not be described in detail here.
2)AAA服务器触发鉴权结果撤回流程:2) The AAA server triggers the authentication result withdrawal process:
S906c:第二切片鉴权网元发送鉴权结果撤回通知消息给第一接入管理网元,消息中包含用户标识和切片标识S-NSSAI。S906c: The second slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
S907c:第一接入管理网元回复鉴权结果撤回通知响应消息。S907c: The first access management network element replies with an authentication result withdrawal notification response message.
S908c:第二切片鉴权网元在收到AAA服务器的鉴权结果撤回后,通知第一切片鉴权网元更新网络切片的鉴权结果,将鉴权结果改为EAP失败。S908c: After receiving the withdrawal of the authentication result from the AAA server, the second slice authentication network element notifies the first slice authentication network element to update the authentication result of the network slice, and changes the authentication result to EAP failure.
具体实现过程结可参考S906a和S907a,这里不再详细介绍。For the detailed implementation process, please refer to S906a and S907a, which will not be described in detail here.
在上述实施例三中,第一切片鉴权网元在网络切片鉴权过程储存鉴权结果,且将第一切片鉴权网元注册信息注册到数据管理网元,使得终端设备在上述场景一和场景二所列的移动场景中,第三接入管理网元可以通过第二切片鉴权网元获得鉴权结果(即触发第二切片鉴权网元从数据管理网元上获得第一切片鉴权网元注册信息,根据第一切片鉴权网元注册信息从第一切片鉴权网元获得鉴权结果后,返回鉴权结果给第三接入管理网元),进而不需要针对网络切片执行网络切片鉴权流程,节省网络信令开销,同时终端设备也不需要等待第三接入管理网元执行完网络切片鉴权流程后才能建立到特定网络切片的会话,加速了业务建立的过程,可以提升终端设备的业务体验。另外,当数据管理网元存储鉴权结果后,AAA服务器还可以触发的重鉴权或者鉴权结果撤回流程,提升了网络切片鉴权的灵活性。In the above-mentioned third embodiment, the first slice authentication network element stores the authentication result in the network slice authentication process, and registers the registration information of the first slice authentication network element to the data management network element, so that the terminal device is in the above-mentioned In the mobile scenarios listed in Scenario 1 and Scenario 2, the third access management network element can obtain the authentication result through the second slice authentication network element (that is, triggering the second slice authentication network element to obtain the first slice authentication network element from the data management network element. All slice authentication network element registration information, after obtaining the authentication result from the first slice authentication network element according to the first slice authentication network element registration information, return the authentication result to the third access management network element), Furthermore, it is not necessary to perform the network slice authentication process for the network slice, which saves network signaling overhead, and the terminal device does not need to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice. The process of establishing a service is accelerated, and the service experience of the terminal device can be improved. In addition, after the data management network element stores the authentication result, the AAA server can also trigger the re-authentication or authentication result withdrawal process, which improves the flexibility of network slice authentication.
实施例四Embodiment 4
本实施例主要介绍:鉴权结果存储在第一切片鉴权网元上,第一切片鉴权网元在网络切片鉴权过程中存储鉴权结果;第三接入管理网元向第一切片鉴权网元请求鉴权结果。可选的,在AAA服务器触发的重鉴权或者鉴权结果撤回流程中,AAA服务器直接通知第一切片鉴权网元更新鉴权结果。This embodiment mainly introduces: the authentication result is stored on the first slice authentication network element, and the first slice authentication network element stores the authentication result during the network slice authentication process; the third access management network element reports to the first slice authentication network element. All slice authentication network elements request the authentication result. Optionally, in the re-authentication or authentication result withdrawal process triggered by the AAA server, the AAA server directly notifies the first slice authentication network element to update the authentication result.
实施例四和实施例三的区别包括:本实施例四中,第一切片鉴权网元不需要将第一切片鉴权网元注册信息注册到数据管理网元,第三接入管理网元可直接从第一切片鉴权网元获得鉴权结果。例如,本实施例可适用于当前网络仅布局一个切片鉴权网元(即,上述第一切片鉴权网元)的场景。The differences between Embodiment 4 and Embodiment 3 include: in Embodiment 4, the first slice authentication network element does not need to register the registration information of the first slice authentication network element to the data management network element, and the third access management The network element may directly obtain the authentication result from the first slice authentication network element. For example, this embodiment may be applicable to a scenario in which only one slice authentication network element (ie, the above-mentioned first slice authentication network element) is deployed in the current network.
如图10所示,为本实施例提供的另一种具体的切片鉴权方法,该方法可以应用于图2所示的网络架构中,方法包括:As shown in FIG. 10 , another specific slice authentication method provided in this embodiment can be applied to the network architecture shown in FIG. 2 , and the method includes:
S1001、第一接入管理网元触发网络切片鉴权流程。S1001. A first access management network element triggers a network slice authentication process.
具体的,终端设备接入第一接入管理网元,第一接入管理网元从数据管理网元获取终端设备的签约数据,第一接入管理网元根据签约数据中包含的切片标识S-NSSAI,及其网络切片鉴权指示信息获知S-NSSAI所标识的网络切片(相当于上文中的第一切片)需要执行网络切片鉴权,则第一接入管理网元触发网络切片鉴权流程,具体流程和图1流程相同。其中第一接入管理网元对应图1中的接入管理节点,第一切片鉴权网元对应图1中的切片鉴权功能。Specifically, the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element obtains the subscription data of the terminal device according to the slice identifier S included in the subscription data. -NSSAI, and its network slice authentication indication information If the network slice identified by S-NSSAI (equivalent to the first slice above) needs to perform network slice authentication, the first access management network element triggers the network slice authentication The specific process is the same as that in Figure 1. The first access management network element corresponds to the access management node in FIG. 1 , and the first slice authentication network element corresponds to the slice authentication function in FIG. 1 .
当第一切片鉴权网元获知网络切片的鉴权结果(即执行完图1所示的S1011)后,继续执行如下步骤:When the first slice authentication network element learns the authentication result of the network slice (that is, after performing S1011 shown in FIG. 1 ), it continues to perform the following steps:
S1002:所述第一切片鉴权网元保存用户标识,网络切片S-NSSAI和鉴权结果。S1002: The first slice authentication network element stores the user identifier, the network slice S-NSSAI and the authentication result.
上面S1001~S1002介绍了第一切片鉴权网元存储鉴权结果的过程,接下来介绍终端设备发生移动后,新的接入管理网元(第三接入管理网元)从第一切片鉴权网元获取鉴权结果的过程。The above S1001 to S1002 describe the process of the first slice authentication network element storing the authentication result. Next, it is introduced that after the terminal device moves, the new access management network element (third access management network element) starts from the first slice of the authentication network element. The process of obtaining the authentication result by the slice authentication network element.
终端设备发生移动的场景可以参考实施例一中的场景一和场景二,此处不再赘述。For a scenario in which the terminal device moves, reference may be made to scenario 1 and scenario 2 in Embodiment 1, and details are not repeated here.
请继续参见图10,在终端设备从第二接入管理网元移动到第三接入管理网元的流程中,终端设备触发注册更新流程:Please continue to refer to FIG. 10 , in the process of moving the terminal device from the second access management network element to the third access management network element, the terminal device triggers the registration update process:
S1003、在注册流程中,终端设备发送注册更新请求消息给第三接入管理网元;S1003. In the registration process, the terminal device sends a registration update request message to a third access management network element;
S1004:第三接入管理网元向第一切片鉴权网元发送获取鉴权结果请求消息(第一请求消息),消息中包含用户标识和网络切片S-NSSAI。S1004: The third access management network element sends a request message (first request message) for obtaining the authentication result to the first slice authentication network element, where the message includes the user identifier and the network slice S-NSSAI.
具体的,消息中可以包含一个或者多个网络切片标识S-NSSAI。Specifically, the message may contain one or more network slice identifiers S-NSSAI.
S1005:第一切片鉴权网元回复获取鉴权结果响应消息(第一响应消息),消息中包含鉴权结果。S1005: The first slice authentication network element replies with a response message for obtaining the authentication result (a first response message), and the message includes the authentication result.
可选的,鉴权结果响应消息还包含用户标识,网络切片S-NSSAI。Optionally, the authentication result response message further includes the user identifier, the network slice S-NSSAI.
当第一切片鉴权网元保存鉴权结果后,AAA服务还可以触发鉴权结果撤回或者重鉴权的流程。After the first slice authentication network element saves the authentication result, the AAA service may also trigger the process of withdrawing the authentication result or re-authentication.
以下介绍AAA服务触发鉴权结果撤回或者重鉴权流程的方法。The following describes the method for the AAA service to trigger the authentication result withdrawal or re-authentication process.
如图11所示,为本申请实施例提供的另一种鉴权结果撤回方法的流程图,该方法可以应用于图2所示的网络架构,具体可以在终端设备在第一接入管理网元或者第二接入管理网元接入时执行。方法包括:As shown in FIG. 11 , it is a flowchart of another authentication result withdrawal method provided in this embodiment of the present application. The method can be applied to the network architecture shown in FIG. 2 . Executed when the network element or the second access management network element is accessed. Methods include:
S1101:AAA服务器向第一切片鉴权网元发送AAA协议消息,用于触发鉴权结果撤回或重鉴权流程。S1101: The AAA server sends an AAA protocol message to the first slice authentication network element, which is used to trigger an authentication result withdrawal or re-authentication process.
具体的,AAA服务器上由于配置信息修改等,触发鉴权结果撤回(即图11所示的S1101a),或者重鉴权流程(即图11所示的S1101b)。其中鉴权结果撤回应用于鉴权结果为EAP成功的网络切片,将鉴权结果改为EAP失败;重鉴权流程用于通知接入管理网元 触发网络切片鉴权流程,对网络切片重新进行EAP鉴权。AAA服务器发送对应的AAA协议消息给第一切片鉴权网元。Specifically, the AAA server triggers the withdrawal of the authentication result (ie S1101a shown in FIG. 11 ) or the re-authentication process (ie, S1101b shown in FIG. 11 ) due to the modification of configuration information. The authentication result revocation is used for the network slice whose authentication result is EAP success, and the authentication result is changed to EAP failure; EAP authentication. The AAA server sends a corresponding AAA protocol message to the first slice authentication network element.
S1102:第一切片鉴权网元收到AAA协议消息后,发送请求消息给数据管理网元,该请求消息用于查询服务终端设备的移动管理网元注册信息。S1102: After receiving the AAA protocol message, the first slice authentication network element sends a request message to the data management network element, where the request message is used to query the mobile management network element registration information of the service terminal device.
S1103:数据管理网元回复响应消息给第一切片鉴权网元,消息中包含移动管理网元注册信息,移动管理网元注册信息中包含接入管理网元标识。例如,接入管理网元标识为NF Instance ID。S1103: The data management network element replies a response message to the first slice authentication network element, where the message includes mobility management network element registration information, and the mobility management network element registration information includes an access management network element identifier. For example, the access management network element is identified as NF Instance ID.
移动管理网元注册信息的内容可以参考实施例一中的三种情况(Case1、Case2、Case3),这里不再赘述。For the content of the registration information of the mobility management network element, reference may be made to the three cases (Case1, Case2, and Case3) in the first embodiment, which will not be repeated here.
进一步的,第一切片鉴权网元根据接收到的移动管理网元注册信息的具体内容执行不同的处理:Further, the first slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:
A、如果移动管理网元注册信息中包含接入管理网元的标识,并且清除指示指示接入管理网元分离,或者支持的特性信息指示接入管理网元不支持网络切片鉴权功能,即上述case2或3,则执行S1104c。A. If the mobile management network element registration information contains the identity of the access management network element, and the clear indication indicates that the access management network element is separated, or the supported feature information indicates that the access management network element does not support the network slice authentication function, that is In case 2 or 3 above, execute S1104c.
S1104c:第一切片鉴权网元更新本地存储的切片标识S-NSSAI对应的鉴权结果。S1104c: The first slice authentication network element updates the locally stored authentication result corresponding to the slice identifier S-NSSAI.
具体的,如果是鉴权结果撤回,第一切片鉴权网元将鉴权结果改为EAP失败,如果是重鉴权,第一切片鉴权网元删除鉴权结果。Specifically, if the authentication result is withdrawn, the first slice authentication network element changes the authentication result to EAP failure, and if it is re-authentication, the first slice authentication network element deletes the authentication result.
B、如果移动管理网元注册信息中包含接入管理网元的标识,并且清除指示指示接入管理网元没有分离,或者移动管理网元注册信息中没有包含清除指示信息,并且支持的特性信息指示接入管理网元支持网络切片鉴权功能,即上述case1,第一切片鉴权网元执行步骤S1104a或S1104b及之后的步骤。B. If the registration information of the mobility management network element contains the identification of the access management network element, and the clear indication indicates that the access management network element is not separated, or the registration information of the mobility management network element does not contain the clear indication information, and the supported feature information Indicates that the access management network element supports the network slice authentication function, that is, the above case 1, the first slice authentication network element performs step S1104a or S1104b and subsequent steps.
这里对AAA服务器触发的鉴权结果撤回流程和重鉴权流程进行区分介绍。Here, the process of withdrawing the authentication result triggered by the AAA server and the process of re-authentication are introduced separately.
1)AAA服务器触发重鉴权:1) AAA server triggers re-authentication:
S1104a:第一切片鉴权网元发送重鉴权通知消息给第一接入管理网元,消息中包含用户标识和切片标识S-NSSAI。S1104a: The first slice authentication network element sends a re-authentication notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
S1105a:第一接入管理网元回复重鉴权通知响应消息。S1105a: The first access management network element replies with a re-authentication notification response message.
S1106a:第一接入管理网元针对重鉴权的网络切片触发网络切片鉴权流程,具体流程和图1流程相同。S1106a: The first access management network element triggers a network slice authentication process for the re-authenticated network slice, and the specific process is the same as the process in FIG. 1 .
S1107a:第一切片鉴权网元在网络切片鉴权流程获得AAA服务器发送的鉴权结果后,更新本地存储的网络切片的鉴权结果,将鉴权结果改为EAP失败。S1107a: After obtaining the authentication result sent by the AAA server in the network slice authentication process, the first slice authentication network element updates the locally stored authentication result of the network slice, and changes the authentication result to EAP failure.
2)AAA服务器触发鉴权结果撤回流程:2) The AAA server triggers the authentication result withdrawal process:
S1104b:第一切片鉴权网元发送鉴权结果撤回通知消息给第一接入管理网元,消息中包含用户标识和切片标识S-NSSAI。S1104b: The first slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, where the message includes the user identifier and the slice identifier S-NSSAI.
S1105b:第一接入管理网元回复鉴权结果撤回通知响应消息。S1105b: The first access management network element replies with an authentication result withdrawal notification response message.
S1106b:第一切片鉴权网元更新鉴权结果,删除本地存储的网络切片的鉴权结果。S1106b: The first slice authentication network element updates the authentication result, and deletes the locally stored authentication result of the network slice.
在上述实施例四中,第一切片鉴权网元在网络切片鉴权过程储存鉴权结果,使得终端设备在上述场景一和场景二所列的移动场景中,第三接入管理网元可以直接从第一切片鉴权网元获得鉴权结果,进而不需要针对网络切片执行网络切片鉴权流程,节省网络信令开销,同时终端设备也不需要等待第三接入管理网元执行完网络切片鉴权流程后才能建立到特定网络切片的会话,加速了业务建立的过程,可以提升终端设备的业务体验。另外,当 数据管理网元存储鉴权结果后,AAA服务器还可以触发的重鉴权或者鉴权结果撤回流程,提升了网络切片鉴权的灵活性。In the above-mentioned Embodiment 4, the first slice authentication network element stores the authentication result in the network slice authentication process, so that the third access management network element in the mobile scenarios listed in the above-mentioned scenarios 1 and 2 for the terminal device The authentication result can be obtained directly from the first slice authentication network element, so that the network slice authentication process does not need to be performed for the network slice, which saves network signaling overhead, and the terminal device does not need to wait for the third access management network element to execute. A session to a specific network slice can be established only after the network slice authentication process is completed, which speeds up the process of service establishment and improves the service experience of terminal devices. In addition, after the data management network element stores the authentication result, the AAA server can also trigger the re-authentication or authentication result withdrawal process, which improves the flexibility of network slice authentication.
需要说明的是,在图3~图11所示的实施例中,介绍是终端设备移动至新的接入管理网元(第三接入管理网元)后,旧的接入管理网元不支持网络切片鉴权功能的场景下,新的接入管理网元从指定网元获取鉴权结果的方案。在实际应用中,如果旧的接入管理网元支持网络切片鉴权功能且保存有鉴权结果(例如,第二接入管理网元支持网络切片鉴权功能),则新的接入管理网元除了可以从旧的接入管理网元获取鉴权结果(例如从第二接入管理网元获取用户上下文,用户上下文中携带鉴权结果)之外,也可以按照本申请实施例提供方法,从指定网元获取鉴权结果。It should be noted that, in the embodiments shown in FIG. 3 to FIG. 11 , it is introduced that after the terminal equipment moves to the new access management network element (third access management network element), the old access management network element does not In the scenario where the network slice authentication function is supported, the new access management network element obtains the authentication result from the specified network element. In practical applications, if the old access management network element supports the network slice authentication function and saves the authentication result (for example, the second access management network element supports the network slice authentication function), the new access management network element In addition to obtaining the authentication result from the old access management network element (for example, obtaining the user context from the second access management network element, the user context carries the authentication result), the method can also be provided according to the embodiment of the present application, Obtain the authentication result from the specified network element.
以上结合附图3~图11介绍了本申请实施例提供的方法,以下结合附图12~图15介绍本申请实施例提供的装置。The methods provided by the embodiments of the present application are described above with reference to FIGS. 3 to 11 , and the apparatuses provided by the embodiments of the present application are described below with reference to FIGS. 12 to 15 .
参见图12,基于同一技术构思,本申请实施例提供一种切片鉴权装置1200,可以例如为第三接入管理节网元或者设置在第三接入管理节网元内部的芯片,该装置包括用于执行上述图3~图11所示的方法实施例中第三接入管理节网元所执行的方法的模块。Referring to FIG. 12 , based on the same technical concept, an embodiment of the present application provides a slice authentication device 1200, which may be, for example, a third access management node network element or a chip set inside the third access management node network element. It includes a module for executing the method executed by the network element of the third access management node in the method embodiments shown in FIG. 3 to FIG. 11 .
示例性的,该装置1200可以包括:Exemplarily, the apparatus 1200 may include:
发送单元1201,用于:在终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的所述装置后,向第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;The sending unit 1201 is configured to: after the terminal device moves from the second access management network element that does not support the network slice authentication function to the device that supports the network slice authentication function, send a first request message to the first network element , wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
接收单元1202,用于接收来自所述第一网元的第一响应消息,所述第一响应消息包括所述第一切片对应的鉴权结果。The receiving unit 1202 is configured to receive a first response message from the first network element, where the first response message includes an authentication result corresponding to the first slice.
一种可能的实施方式中,所述第一网元为数据管理网元、第一切片鉴权网元、或第二切片鉴权网元。In a possible implementation manner, the first network element is a data management network element, a first slice authentication network element, or a second slice authentication network element.
一种可能的实施方式中,所述装置还包括处理单元1203;在终端设备从所述第二接入管理网元移动到所述装置之后,所述装置向第一网元发送第一请求消息之前,所述处理单元1203用于:In a possible implementation manner, the apparatus further includes a processing unit 1203; after the terminal device moves from the second access management network element to the apparatus, the apparatus sends a first request message to the first network element Previously, the processing unit 1203 was used to:
所述第二接入管理网元为4G网络的MME,则确定所述第二接入管理网元不支持网络切片鉴权功能;或者,If the second access management network element is an MME of the 4G network, it is determined that the second access management network element does not support the network slice authentication function; or,
从所述第二接入管理网元获取所述终端设备的用户上下文,其中,所述用户上下文中不包含所述第一切片对应的鉴权结果,则确定所述第二接入管理网元不支持网络切片鉴权功能;或者,Obtain the user context of the terminal device from the second access management network element, wherein the user context does not contain the authentication result corresponding to the first slice, then determine that the second access management network Meta does not support the network slice authentication function; or,
从所述第二接入管理网元获取所述第二接入管理网元支持的特性列表,根据所述支持的特性列表确定所述第二接入管理网元不支持网络切片鉴权功能。Obtain a feature list supported by the second access management network element from the second access management network element, and determine according to the supported feature list that the second access management network element does not support the network slice authentication function.
其中,图12中的虚线框用于表示处理单元1203对于装置1200是可选的。The dashed box in FIG. 12 is used to indicate that the processing unit 1203 is optional for the apparatus 1200 .
应理解,上述方法实施例涉及的各步骤的所有相关内容均可以援引到对应功能模块的功能描述,在此不再赘述。It should be understood that, all relevant contents of the steps involved in the above method embodiments can be cited in the functional descriptions of the corresponding functional modules, which will not be repeated here.
参见图13,基于同一技术构思,本申请实施例提供一种切片鉴权装置1300,可以例如为数据管理网元或者设置在数据管理网元内部的芯片,该装置包括用于执行上述图3~图11所示的方法实施例中由数据管理网元所执行的方法的模块。Referring to FIG. 13 , based on the same technical concept, an embodiment of the present application provides a slice authentication apparatus 1300, which may be, for example, a data management network element or a chip arranged inside the data management network element. The modules of the method executed by the data management network element in the method embodiment shown in FIG. 11 .
示例性的,该装置1300可以包括:Exemplarily, the apparatus 1300 may include:
接收单元1301,用于在终端设备从不支持网络切片鉴权功能的第二接入管理网元移动 到支持网络切片鉴权功能的第三接入管理网元后,接收来自所述第三接入管理网元的请求消息,所述请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;The receiving unit 1301 is configured to, after the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function, to receive the information from the third access management network element. A request message for entering a management network element, the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
发送单元1302,用于发送响应消息给所述第三接入管理网元,所述响应消息包括所述第一切片对应的鉴权结果。The sending unit 1302 is configured to send a response message to the third access management network element, where the response message includes an authentication result corresponding to the first slice.
一种可能的实施方式中,所述接收单元1301用于:接收第二切片鉴权网元发送的请求消息,其中所述第二切片鉴权网元发送的请求消息是所述第三接入管理网元发送给所述第二切片鉴权网元的;In a possible implementation manner, the receiving unit 1301 is configured to: receive a request message sent by a second slice authentication network element, wherein the request message sent by the second slice authentication network element is the third access sent by the management network element to the second slice authentication network element;
所述发送单元1302用于:将响应消息发送给所述第二切片鉴权网元,通过所述第二切片鉴权网元将所述响应消息发送给所述第三接入管理网元。The sending unit 1302 is configured to: send a response message to the second slice authentication network element, and send the response message to the third access management network element through the second slice authentication network element.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元;In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function. moving the access management network element to the second access management network element;
所述接收单元1301还用于:接收来自第一接入管理网元或第一切片鉴权网元的第一切片对应的鉴权结果;The receiving unit 1301 is further configured to: receive the authentication result corresponding to the first slice from the first access management network element or the first slice authentication network element;
所述装置还包括储存单元1303,用于储存所述第一切片对应的鉴权结果。The apparatus further includes a storage unit 1303 for storing the authentication result corresponding to the first slice.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备位于所述第二接入管理网元的服务范围时;In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element the scope of services;
所述接收单元1301还用于:接收来自第一切片鉴权网元或第二切片鉴权网元的第一消息;所述装置还包括处理单元1304,用于根据所述第一消息将所述装置储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,The receiving unit 1301 is further configured to: receive the first message from the first slice authentication network element or the second slice authentication network element; the apparatus further includes a processing unit 1304, configured to send the message according to the first message. The authentication result corresponding to the first slice stored by the device is modified as authentication failure; or,
所述接收单元1301还用于:接收来自第一切片鉴权网元或第二切片鉴权网元的第二消息;所述装置还包括处理单元1304,用于根据所述第二消息,将所述装置储存的所述第一切片对应的鉴权结果删除。The receiving unit 1301 is further configured to: receive a second message from the first slice authentication network element or the second slice authentication network element; the apparatus further includes a processing unit 1304, configured to, according to the second message, The authentication result corresponding to the first slice stored by the device is deleted.
其中,图13中的虚线框用于表示储存单元1303和处理单元1304对于装置1300是可选的。The dotted box in FIG. 13 is used to indicate that the storage unit 1303 and the processing unit 1304 are optional to the apparatus 1300 .
应理解,上述方法实施例涉及的各步骤的所有相关内容均可以援引到对应功能模块的功能描述,在此不再赘述。It should be understood that, all relevant contents of the steps involved in the above method embodiments can be cited in the functional descriptions of the corresponding functional modules, which will not be repeated here.
参见图14,基于同一技术构思,本申请实施例提供一种切片鉴权装置1400,可以例如为第一切片鉴权网元或者设置在第一切片鉴权网元内部的芯片,该装置包括用于执行上述图3~图11所示的方法实施例中第一切片鉴权网元所执行的方法的模块。Referring to FIG. 14, based on the same technical concept, an embodiment of the present application provides a slice authentication device 1400, which may be, for example, a first slice authentication network element or a chip arranged inside the first slice authentication network element. It includes a module for executing the method executed by the first slice authentication network element in the method embodiments shown in FIG. 3 to FIG. 11 .
示例性的,该装置1400可以包括:Exemplarily, the apparatus 1400 may include:
接收单元1401,用于:在终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,接收来自第二切片鉴权网元的请求消息,所述请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;The receiving unit 1401 is configured to: after the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function A request message from a network element for authorization, the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
发送单元1402,用于发送响应消息给所述第二切片鉴权网元,所述响应消息包括所述第一切片对应的鉴权结果。The sending unit 1402 is configured to send a response message to the second slice authentication network element, where the response message includes an authentication result corresponding to the first slice.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述装置还包括:In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function. The access management network element is moved to the second access management network element, and the apparatus further includes:
储存单元1403,用于在所述第一切片对应的鉴权完成之后,保存所述第一切片对应的 鉴权结果;Storage unit 1403 is used to save the authentication result corresponding to the first slice after the authentication corresponding to the first slice is completed;
处理单元1404,将所述装置的标识注册到数据管理网元。The processing unit 1404 registers the identifier of the device with the data management network element.
一种可能的实施方式中,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备位于所述第二接入管理网元的服务范围时;In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device is located in the second access management network element the scope of services;
所述接收单元1401还用于:接收来自AAA服务器的鉴权撤回消息;所述装置还包括处理单元1404,用于根据所述鉴权撤回消息将储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,The receiving unit 1401 is further configured to: receive an authentication revocation message from the AAA server; the apparatus further includes a processing unit 1404, configured to store the authentication corresponding to the first slice according to the authentication revocation message The result is modified to authentication failure; or,
所述接收单元1401还用于:接收来自AAA服务器的重鉴权消息;所述装置还包括处理单元1404,用于根据所述重鉴权消息,将储存的所述第一切片对应的鉴权结果删除;或者,The receiving unit 1401 is further configured to: receive a re-authentication message from the AAA server; the apparatus further includes a processing unit 1404, configured to, according to the re-authentication message, store the authentication corresponding to the first slice. the right to result deletion; or,
所述接收单元1401还用于:接收来自第二切片鉴权网元的第三消息;所述装置还包括处理单元1404,用于根据所述第三消息将储存的所述第一切片对应的鉴权结果修改为鉴权失败;或者,The receiving unit 1401 is further configured to: receive a third message from the second slice authentication network element; the apparatus further includes a processing unit 1404, configured to correspond to the stored first slice according to the third message. The authentication result of is modified to authentication failure; or,
所述接收单元1401还用于:接收来自第二切片鉴权网元的第四消息;所述装置还包括处理单元1404,用于根据所述第四消息,将储存的所述第一切片对应的鉴权结果删除。The receiving unit 1401 is further configured to: receive a fourth message from the second slice authentication network element; the apparatus further includes a processing unit 1404, configured to store the stored first slice according to the fourth message The corresponding authentication result is deleted.
其中,图14中的虚线框用于表示储存单元1403和处理单元1404对于装置1400是可选的。The dotted box in FIG. 14 is used to indicate that the storage unit 1403 and the processing unit 1404 are optional to the apparatus 1400 .
应理解,上述方法实施例涉及的各步骤的所有相关内容均可以援引到对应功能模块的功能描述,在此不再赘述。It should be understood that, all relevant contents of the steps involved in the above method embodiments can be cited in the functional descriptions of the corresponding functional modules, which will not be repeated here.
基于同一技术构思,参见图15,本申请实施例还提供一种通信装置1500,包括:Based on the same technical concept, referring to FIG. 15 , an embodiment of the present application further provides a communication apparatus 1500, including:
至少一个处理器1501;以及与所述至少一个处理器1501通信连接的通信接口1503;所述至少一个处理器1501通过执行存储器1502存储的指令,使得所述装置通过所述通信接口1503执行上述图3~图11所示的方法实施例中任意一个网元所执行的方法步骤。At least one processor 1501; and a communication interface 1503 communicatively connected to the at least one processor 1501; the at least one processor 1501 executes the instructions stored in the memory 1502 by executing the at least one processor 1502, so that the apparatus executes the above-mentioned diagrams through the communication interface 1503. 3 to the method steps performed by any network element in the method embodiment shown in FIG. 11 .
可选的,所述存储器1502位于所述装置1500之外。Optionally, the memory 1502 is located outside the apparatus 1500 .
可选的,所述装置1500包括所述存储器1502,所述存储器1502与所述至少一个处理器1501相连,所述存储器1502存储有可被所述至少一个处理器1501执行的指令。Optionally, the apparatus 1500 includes the memory 1502, the memory 1502 is connected to the at least one processor 1501, and the memory 1502 stores instructions executable by the at least one processor 1501.
可选的,所述存储器1502位于所述装置1500之外。Optionally, the memory 1502 is located outside the apparatus 1500 .
可选的,所述装置1500包括所述存储器1502,所述存储器1502与所述至少一个处理器1501相连,所述存储器1502存储有可被所述至少一个处理器1501执行的指令。附图15用虚线表示存储器1502对于装置1500是可选的。Optionally, the apparatus 1500 includes the memory 1502, the memory 1502 is connected to the at least one processor 1501, and the memory 1502 stores instructions executable by the at least one processor 1501. Figure 15 shows with dashed lines that memory 1502 is optional to apparatus 1500.
其中,所述处理器1501和所述存储器1502可以通过接口电路耦合,也可以集成在一起,这里不做限制。The processor 1501 and the memory 1502 may be coupled through an interface circuit, or may be integrated together, which is not limited here.
本申请实施例中不限定上述处理器1501、存储器1502以及通信接口1503之间的具体连接介质。本申请实施例在图15中以处理器1501、存储器1502以及通信接口1503之间通过总线1504连接,总线在图15中以粗线表示,其它部件之间的连接方式,仅是进行示意性说明,并不引以为限。所述总线可以分为地址总线、数据总线、控制总线等。为便于表示,图15中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。The specific connection medium between the processor 1501, the memory 1502, and the communication interface 1503 is not limited in the embodiments of the present application. In this embodiment of the present application, the processor 1501, the memory 1502, and the communication interface 1503 are connected through a bus 1504 in FIG. 15. The bus is represented by a thick line in FIG. 15. The connection between other components is only for schematic illustration. , is not limited. The bus can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in FIG. 15, but it does not mean that there is only one bus or one type of bus.
应理解,本申请实施例中提及的处理器可以通过硬件实现也可以通过软件实现。当通过硬件实现时,该处理器可以是逻辑电路、集成电路等。当通过软件实现时,该处理器可以是一个通用处理器,通过读取存储器中存储的软件代码来实现。It should be understood that the processor mentioned in the embodiments of the present application may be implemented by hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, or the like. When implemented in software, the processor may be a general-purpose processor implemented by reading software codes stored in memory.
示例性的,处理器可以是中央处理单元(Central Processing Unit,CPU),还可以是其他通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现成可编程门阵列(Field Programmable Gate Array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。Exemplarily, the processor may be a central processing unit (Central Processing Unit, CPU), or other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application specific integrated circuit (Application Specific Integrated Circuit, ASIC) , Off-the-shelf Programmable Gate Array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general purpose processor may be a microprocessor or the processor may be any conventional processor or the like.
应理解,本申请实施例中提及的存储器可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Eate SDRAM,DDR SDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synchlink DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DR RAM)。It should be understood that the memory mentioned in the embodiments of the present application may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Wherein, the non-volatile memory may be a read-only memory (Read-Only Memory, ROM), a programmable read-only memory (Programmable ROM, PROM), an erasable programmable read-only memory (Erasable PROM, EPROM), an electrically programmable read-only memory (Erasable PROM, EPROM). Erase programmable read-only memory (Electrically EPROM, EEPROM) or flash memory. Volatile memory may be Random Access Memory (RAM), which acts as an external cache. By way of illustration and not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (Double Data Eate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (Enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (Synchlink DRAM, SLDRAM) ) and direct memory bus random access memory (Direct Rambus RAM, DR RAM).
需要说明的是,当处理器为通用处理器、DSP、ASIC、FPGA或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件时,存储器(存储模块)可以集成在处理器中。It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components, the memory (storage module) can be integrated in the processor.
应注意,本文描述的存储器旨在包括但不限于这些和任意其它适合类型的存储器。It should be noted that the memory described herein is intended to include, but not be limited to, these and any other suitable types of memory.
基于同一技术构思,本申请实施例还提供一种计算机可读存储介质,包括程序或指令,当所述程序或指令在计算机上运行时,使得上述图3~图11所示的方法实施例中任意一个网元所执行的方法被执行。Based on the same technical concept, an embodiment of the present application further provides a computer-readable storage medium, including a program or an instruction. When the program or instruction is run on a computer, the above-mentioned method embodiments shown in FIG. 3 to FIG. 11 are implemented. The method executed by any one network element is executed.
基于同一技术构思,本申请实施例还提供一种芯片,所述芯片与存储器耦合,用于读取并执行所述存储器中存储的程序指令,使得上述图3~图11所示的方法实施例中任意一个网元所执行的方法被执行。Based on the same technical concept, an embodiment of the present application further provides a chip, which is coupled to a memory and used to read and execute program instructions stored in the memory, so that the method embodiments shown in FIG. 3 to FIG. 11 above are The method executed by any one of the network elements is executed.
基于同一技术构思,本申请实施例还提供一种计算机程序产品,包括指令,当其在计算机上运行时,使得上述图3~图11所示的方法实施例中任意一个网元所执行的方法被执行。Based on the same technical concept, an embodiment of the present application further provides a computer program product, which includes instructions, when running on a computer, to make the method executed by any one of the network elements in the method embodiments shown in FIG. 3 to FIG. 11 above. be executed.
由于本申请实施例提供的装置1200、装置1300、装置1400、以及装置1500、可用于执行图3~图11所示的实施例中相应的实施例所提供的方法,因此其所能获得的技术效果可参考上述方法实施例,在此不再赘述。Since the apparatus 1200, the apparatus 1300, the apparatus 1400, and the apparatus 1500 provided in the embodiments of the present application can be used to execute the methods provided by the corresponding embodiments in the embodiments shown in FIG. 3 to FIG. For the effect, reference may be made to the above method embodiments, and details are not described herein again.
本申请实施例是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。The embodiments of the present application are described with reference to flowcharts and/or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It will be understood that each flow and/or block in the flowchart illustrations and/or block diagrams, and combinations of flows and/or blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to the processor of a general purpose computer, special purpose computer, embedded processor or other programmable data processing device to produce a machine such that the instructions executed by the processor of the computer or other programmable data processing device produce Means for implementing the functions specified in a flow or flow of a flowchart and/or a block or blocks of a block diagram.
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。 当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机程序指令时,全部或部分地产生按照本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(digital subscriber line,DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、光介质(例如,数字通用光盘(digital versatile disc,DVD))、或者半导体介质(例如,固态硬盘(solid state disk,SSD))等。In the above-mentioned embodiments, it may be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented in software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general purpose computer, special purpose computer, computer network, or other programmable device. The computer instructions may be stored in or transmitted from one computer-readable storage medium to another, for example, from a website site, computer, server, or data center via Transmission to another website site, computer, server, or data center by wired (eg, coaxial cable, optical fiber, digital subscriber line, DSL) or wireless (eg, infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes an integration of one or more available media. The available media may be magnetic media (eg, floppy disks, hard disks, magnetic tapes), optical media (eg, digital versatile discs (DVDs)), or semiconductor media (eg, solid state disks (SSDs) ))Wait.
显然,本领域的技术人员可以对本申请实施例进行各种改动和变型而不脱离本申请的精神和范围。这样,倘若本申请实施例的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims (30)

  1. 一种切片鉴权方法,其特征在于,包括:A method for slice authentication, comprising:
    终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,所述第三接入管理网元向第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;After the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function, the third access management network element sends a message to the first network element. sending a first request message, wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
    所述第三接入管理网元接收来自所述第一网元的第一响应消息,所述第一响应消息包括所述第一切片对应的鉴权结果。The third access management network element receives a first response message from the first network element, where the first response message includes an authentication result corresponding to the first slice.
  2. 如权利要求1所述的方法,其特征在于,所述第一网元为数据管理网元;The method of claim 1, wherein the first network element is a data management network element;
    在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述方法还包括:Before the terminal equipment moves from the second access management network element to the third access management network element, the terminal equipment moves from the first access management network element supporting the network slice authentication function to the third access management network element. The second access management network element, the method further includes:
    所述第一接入管理网元或第一切片鉴权网元将所述第一切片对应的鉴权结果储存到所述数据管理网元。The first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice in the data management network element.
  3. 如权利要求1所述的方法,其特征在于,所述第一网元为第二切片鉴权网元。The method of claim 1, wherein the first network element is a second slice authentication network element.
  4. 如权利要求3所述的方法,其特征在于,在所述第三接入管理网元向第一网元发送第一请求消息之后,所述方法还包括:The method according to claim 3, wherein after the third access management network element sends the first request message to the first network element, the method further comprises:
    所述第二切片鉴权网元向数据管理网元发送所述第一切片的标识信息;The second slice authentication network element sends the identification information of the first slice to the data management network element;
    所述第二切片鉴权网元接收来自所述数据管理网元的所述第一切片对应的鉴权结果;The second slice authentication network element receives the authentication result corresponding to the first slice from the data management network element;
    所述第二切片鉴权网元向所述第三接入管理网元发送所述第一切片对应的鉴权结果。The second slice authentication network element sends the authentication result corresponding to the first slice to the third access management network element.
  5. 如权利要求4所述的方法,其特征在于,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述方法还包括:The method according to claim 4, wherein, before the terminal device moves from the second access management network element to the third access management network element, the terminal device switches from the network slice authentication support moving the first access management network element of the authorization function to the second access management network element, and the method further includes:
    所述第一接入管理网元或第一切片鉴权网元将所述第一切片对应的鉴权结果储存到所述数据管理网元。The first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice in the data management network element.
  6. 如权利要求3所述的方法,其特征在于,在所述第三接入管理网元向第一网元发送第一请求消息之后,所述方法还包括:The method according to claim 3, wherein after the third access management network element sends the first request message to the first network element, the method further comprises:
    所述第二切片鉴权网元向第一切片鉴权网元发送所述第一切片的标识信息;sending, by the second slice authentication network element, the identification information of the first slice to the first slice authentication network element;
    所述第二切片鉴权网元接收来自所述第一切片鉴权网元的所述第一切片对应的鉴权结果;The second slice authentication network element receives the authentication result corresponding to the first slice from the first slice authentication network element;
    所述第二切片鉴权网元向所述第三接入管理网元发送所述第一切片对应的鉴权结果。The second slice authentication network element sends the authentication result corresponding to the first slice to the third access management network element.
  7. 如权利要求6所述的方法,其特征在于,在所述第二切片鉴权网元向第一切片鉴权网元发送第三请求消息之前,所述方法还包括:The method according to claim 6, wherein before the second slice authentication network element sends a third request message to the first slice authentication network element, the method further comprises:
    所述第二切片鉴权网元向数据管理网元发送请求消息;The second slice authentication network element sends a request message to the data management network element;
    所述第二切片鉴权网元接收来自所述数据管理网元的所述第一切片鉴权网元的标识;The second slice authentication network element receives the identifier of the first slice authentication network element from the data management network element;
    所述第二切片鉴权网元向第一切片鉴权网元发送第三请求消息,包括:The second slice authentication network element sends a third request message to the first slice authentication network element, including:
    所述第二切片鉴权网元根据所述第一切片鉴权网元的标识,向所述第一切片鉴权网元发送所述第一切片的标识信息。The second slice authentication network element sends the identification information of the first slice to the first slice authentication network element according to the identifier of the first slice authentication network element.
  8. 如权利要求7所述的方法,其特征在于,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述方法还包括:The method according to claim 7, wherein before the terminal equipment moves from the second access management network element to the third access management network element, the method further comprises:
    在所述第一切片对应的鉴权完成之后,所述第一切片鉴权网元保存所述第一切片对应的鉴权结果,并将所述第一切片鉴权网元的标识注册到所述数据管理网元。After the authentication corresponding to the first slice is completed, the first slice authentication network element saves the authentication result corresponding to the first slice, and stores the authentication result corresponding to the first slice authentication network element. The identity is registered with the data management network element.
  9. 如权利要求1所述的方法,其特征在于,所述第一网元为第一切片鉴权网元;The method of claim 1, wherein the first network element is a first slice authentication network element;
    在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述方法还包括:Before the terminal equipment moves from the second access management network element to the third access management network element, the terminal equipment moves from the first access management network element supporting the network slice authentication function to the third access management network element. The second access management network element, the method further includes:
    所述第一切片鉴权网元储存所述第一切片对应的鉴权结果。The first slice authentication network element stores the authentication result corresponding to the first slice.
  10. 一种切片鉴权方法,其特征在于,包括:A method for slice authentication, comprising:
    终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,所述第三接入管理网元向第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;After the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function, the third access management network element sends a message to the first network element. sending a first request message, wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
    所述第三接入管理网元接收来自所述第一网元的第一响应消息,所述第一响应消息包括所述第一切片对应的鉴权结果。The third access management network element receives a first response message from the first network element, where the first response message includes an authentication result corresponding to the first slice.
  11. 如权利要求10所述的方法,其特征在于,所述第一网元为数据管理网元、第一切片鉴权网元、或第二切片鉴权网元。The method of claim 10, wherein the first network element is a data management network element, a first slice authentication network element, or a second slice authentication network element.
  12. 一种切片鉴权方法,其特征在于,包括:A method for slice authentication, comprising:
    终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,数据管理网元接收来自所述第三接入管理网元的请求消息,所述请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;After the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function, the data management network element receives data from the third access management network element. element request message, the request message includes the identification information of the first slice, and the first slice is the slice that needs to be authenticated;
    所述数据管理网元返回响应消息给所述第三接入管理网元,所述响应消息包括所述第一切片对应的鉴权结果。The data management network element returns a response message to the third access management network element, where the response message includes the authentication result corresponding to the first slice.
  13. 如权利要求12所述的方法,其特征在于,数据管理网元接收来自所述第三接入管理网元的请求消息,包括:The method according to claim 12, wherein the data management network element receives the request message from the third access management network element, comprising:
    数据管理网元接收第二切片鉴权网元发送的请求消息,其中所述第二切片鉴权网元发送的请求消息是所述第三接入管理网元发送给所述第二切片鉴权网元的;The data management network element receives the request message sent by the second slice authentication network element, wherein the request message sent by the second slice authentication network element is sent by the third access management network element to the second slice authentication network element network element;
    所述数据管理网元返回响应消息给所述第三接入管理网元,包括:The data management network element returns a response message to the third access management network element, including:
    所述数据管理网元将响应消息发送给所述第二切片鉴权网元,通过所述第二切片鉴权网元将所述响应消息发送给所述第三接入管理网元。The data management network element sends a response message to the second slice authentication network element, and sends the response message to the third access management network element through the second slice authentication network element.
  14. 如权利要求12所述的方法,其特征在于,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元,所述方法还包括:The method according to claim 12, wherein, before the terminal device moves from the second access management network element to the third access management network element, the terminal device switches from the network slice authentication support moving the first access management network element of the authorization function to the second access management network element, and the method further includes:
    所述数据管理网元接收来自第一接入管理网元或第一切片鉴权网元的第一切片对应的鉴权结果;所述数据管理网元储存所述第一切片对应的鉴权结果。The data management network element receives the authentication result corresponding to the first slice from the first access management network element or the first slice authentication network element; the data management network element stores the corresponding authentication result of the first slice. Authentication result.
  15. 一种切片鉴权系统,其特征在于,包括:终端设备、不支持网络切片鉴权功能的第二接入管理网元、支持网络切片鉴权功能的第三接入管理网元以及第一网元;A slice authentication system, comprising: a terminal device, a second access management network element that does not support the network slice authentication function, a third access management network element that supports the network slice authentication function, and a first network element Yuan;
    其中,所述第三接入管理网元用于:在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元后,向所述第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;Wherein, the third access management network element is configured to: after the terminal device moves from the second access management network element to the third access management network element, send the message to the first network element A first request message, wherein the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
    所述第一网元用于:接收所述第一请求消息,并发送第一响应消息给所述第三接入管理网元,所述第一响应消息包括所述第一切片对应的鉴权结果;The first network element is configured to: receive the first request message, and send a first response message to the third access management network element, where the first response message includes the authentication corresponding to the first slice. right result;
    所述第三接入管理网元还用于:接收来自所述第一网元的所述第一响应消息。The third access management network element is further configured to: receive the first response message from the first network element.
  16. 如权利要求15所述的系统,其特征在于,所述第一网元为数据管理网元,所述系统还包括第一接入管理网元和第一切片鉴权网元;在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元;The system according to claim 15, wherein the first network element is a data management network element, and the system further comprises a first access management network element and a first slice authentication network element; Before the terminal equipment moves from the second access management network element to the third access management network element, the terminal equipment moves from the first access management network element supporting the network slice authentication function to the second access management network element access management network element;
    所述第一接入管理网元或第一切片鉴权网元用于:将所述第一切片对应的鉴权结果储存到所述数据管理网元。The first access management network element or the first slice authentication network element is used for: storing the authentication result corresponding to the first slice in the data management network element.
  17. 如权利要求15所述的系统,其特征在于,所述第一网元为第二切片鉴权网元。The system of claim 15, wherein the first network element is a second slice authentication network element.
  18. 如权利要求17所述的系统,其特征在于,所述第二切片鉴权网元用于:在所述第三接入管理网元向第一网元发送第一请求消息之后,向数据管理网元发送所述第一切片的标识信息;接收来自所述数据管理网元的所述第一切片对应的鉴权结果;向所述第三接入管理网元发送所述第一切片对应的鉴权结果。The system according to claim 17, wherein the second slice authentication network element is configured to: after the third access management network element sends the first request message to the first network element, send the data management network element to the data management network element. The network element sends the identification information of the first slice; receives the authentication result corresponding to the first slice from the data management network element; sends the first information to the third access management network element The authentication result corresponding to the slice.
  19. 如权利要求18所述的系统,其特征在于,所述系统还包括第一接入管理网元和第一切片鉴权网元;在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元;The system according to claim 18, wherein the system further comprises a first access management network element and a first slice authentication network element; Before moving to the third access management network element, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element;
    所述第一接入管理网元或第一切片鉴权网元用于:将所述第一切片对应的鉴权结果储存到所述数据管理网元。The first access management network element or the first slice authentication network element is used for: storing the authentication result corresponding to the first slice in the data management network element.
  20. 如权利要求17所述的系统,其特征在于,所述系统还包括所述第一切片鉴权网元;The system of claim 17, wherein the system further comprises the first slice authentication network element;
    所述第二切片鉴权网元用于:在所述第三接入管理网元向第一网元发送第一请求消息之后,向第一切片鉴权网元发送所述第一切片的标识信息;The second slice authentication network element is configured to: after the third access management network element sends the first request message to the first network element, send the first slice to the first slice authentication network element identification information;
    所述第一切片鉴权网元用于:接收来自所述第二切片鉴权网元的所述第一切片的标识信息,向所述第二切片鉴权网元发送所述第一切片对应的鉴权结果;The first slice authentication network element is configured to: receive the identification information of the first slice from the second slice authentication network element, and send the first slice to the second slice authentication network element. The authentication result corresponding to the slice;
    所述第二切片鉴权网元还用于:接收来自所述第一切片鉴权网元的所述第一切片对应的鉴权结果;向所述第三接入管理网元发送所述第一切片对应的鉴权结果。The second slice authentication network element is further configured to: receive the authentication result corresponding to the first slice from the first slice authentication network element; The authentication result corresponding to the first slice is described.
  21. 如权利要求20所述的系统,其特征在于,所述第二切片鉴权网元还用于:在所述第二切片鉴权网元向第一切片鉴权网元发送第三请求消息之前,向数据管理网元发送请求消息;接收来自所述数据管理网元的所述第一切片鉴权网元的标识;The system according to claim 20, wherein the second slice authentication network element is further configured to: send a third request message to the first slice authentication network element at the second slice authentication network element before, sending a request message to the data management network element; receiving the identifier of the first slice authentication network element from the data management network element;
    所述第二切片鉴权网元在向第一切片鉴权网元发送第三请求消息时,具体用于:根据所述第一切片鉴权网元的标识,向所述第一切片鉴权网元发送所述第一切片的标识信息。When the second slice authentication network element sends the third request message to the first slice authentication network element, it is specifically configured to: according to the identifier of the first slice authentication network element, send the request message to the first slice authentication network element. The slice authentication network element sends the identification information of the first slice.
  22. 如权利要求21所述的系统,其特征在于,所述第一切片鉴权网元还用于:在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,在所述第一切片对应的鉴权完成之后,保存所述第一切片对应的鉴权结果,并将所述第一切片鉴权网元的标识注册到所述数据管理网元。The system according to claim 21, wherein the first slice authentication network element is further configured to: when the terminal equipment moves from the second access management network element to the third access network element Before managing the network element, after the authentication corresponding to the first slice is completed, save the authentication result corresponding to the first slice, and register the identity of the authentication network element of the first slice to the Data management network element.
  23. 如权利要求15所述的系统,其特征在于,所述第一网元为第一切片鉴权网元;在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元;The system according to claim 15, wherein the first network element is a first slice authentication network element; when the terminal device moves from the second access management network element to the third Before accessing the management network element, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element;
    所述第一切片鉴权网元还用于:储存所述第一切片对应的鉴权结果。The first slice authentication network element is further configured to: store an authentication result corresponding to the first slice.
  24. 一种切片鉴权装置,其特征在于,包括:A slice authentication device, comprising:
    发送单元,用于:在终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到 支持网络切片鉴权功能的所述装置后,向第一网元发送第一请求消息,其中所述第一请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;a sending unit, configured to: after the terminal device moves from the second access management network element that does not support the network slice authentication function to the device that supports the network slice authentication function, send the first request message to the first network element, The first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
    接收单元,用于接收来自所述第一网元的第一响应消息,所述第一响应消息包括所述第一切片对应的鉴权结果。A receiving unit, configured to receive a first response message from the first network element, where the first response message includes an authentication result corresponding to the first slice.
  25. 如权利要求24所述的装置,其特征在于,所述第一网元为数据管理网元、第一切片鉴权网元、或第二切片鉴权网元。The apparatus of claim 24, wherein the first network element is a data management network element, a first slice authentication network element, or a second slice authentication network element.
  26. 一种切片鉴权装置,其特征在于,包括:A slice authentication device, comprising:
    接收单元,用于在终端设备从不支持网络切片鉴权功能的第二接入管理网元移动到支持网络切片鉴权功能的第三接入管理网元后,接收来自所述第三接入管理网元的请求消息,所述请求消息包括第一切片的标识信息,所述第一切片为需要进行鉴权的切片;a receiving unit, configured to receive an access from the third access management network element after the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function a request message for the management network element, where the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;
    发送单元,用于发送响应消息给所述第三接入管理网元,所述响应消息包括所述第一切片对应的鉴权结果。A sending unit, configured to send a response message to the third access management network element, where the response message includes an authentication result corresponding to the first slice.
  27. 如权利要求26所述的装置,其特征在于,所述接收单元用于:接收第二切片鉴权网元发送的请求消息,其中所述第二切片鉴权网元发送的请求消息是所述第三接入管理网元发送给所述第二切片鉴权网元的;The apparatus according to claim 26, wherein the receiving unit is configured to: receive a request message sent by a second slice authentication network element, wherein the request message sent by the second slice authentication network element is the sent by the third access management network element to the second slice authentication network element;
    所述发送单元用于:将响应消息发送给所述第二切片鉴权网元,通过所述第二切片鉴权网元将所述响应消息发送给所述第三接入管理网元。The sending unit is configured to: send a response message to the second slice authentication network element, and send the response message to the third access management network element through the second slice authentication network element.
  28. 如权利要求26所述的装置,其特征在于,在所述终端设备从所述第二接入管理网元移动到所述第三接入管理网元之前,所述终端设备从支持网络切片鉴权功能的第一接入管理网元移动到所述第二接入管理网元;The apparatus according to claim 26, wherein before the terminal device moves from the second access management network element to the third access management network element, the terminal device switches from the network slice authentication support moving the first access management network element of the authorization function to the second access management network element;
    所述接收单元还用于:接收来自第一接入管理网元或第一切片鉴权网元的第一切片对应的鉴权结果;The receiving unit is further configured to: receive an authentication result corresponding to the first slice from the first access management network element or the first slice authentication network element;
    所述装置还包括储存单元,用于储存所述第一切片对应的鉴权结果。The device further includes a storage unit for storing the authentication result corresponding to the first slice.
  29. 一种通信装置,其特征在于,包括:A communication device, characterized in that it includes:
    至少一个处理器;以及与所述至少一个处理器通信连接的存储器、通信接口;at least one processor; and a memory, a communication interface communicatively coupled to the at least one processor;
    其中,所述存储器存储有可被所述至少一个处理器执行的指令,所述至少一个处理器通过执行所述存储器存储的指令,使得所述装置通过所述通信接口执行如权利要求10-11或12-14中任一项所述的方法。Wherein, the memory stores instructions that can be executed by the at least one processor, and the at least one processor executes the instructions stored in the memory to cause the apparatus to perform the method according to claims 10-11 through the communication interface or the method of any one of 12-14.
  30. 一种计算机可读存储介质,其特征在于,包括程序或指令,当所述程序或指令在计算机上运行时,使得如权利要求10-11或12-14中任一项所述的方法被执行。A computer-readable storage medium, characterized in that it includes a program or an instruction, which, when the program or instruction is run on a computer, causes the method according to any one of claims 10-11 or 12-14 to be executed .
PCT/CN2021/093587 2020-08-07 2021-05-13 Slice authentication method and corresponding apparatus WO2022028030A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202010791231.4A CN114095925A (en) 2020-08-07 2020-08-07 Slice authentication method and corresponding device
CN202010791231.4 2020-08-07

Publications (1)

Publication Number Publication Date
WO2022028030A1 true WO2022028030A1 (en) 2022-02-10

Family

ID=80116978

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/093587 WO2022028030A1 (en) 2020-08-07 2021-05-13 Slice authentication method and corresponding apparatus

Country Status (2)

Country Link
CN (1) CN114095925A (en)
WO (1) WO2022028030A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109413702A (en) * 2017-08-16 2019-03-01 中国移动通信有限公司研究院 A kind of method for switching network, device and core net
CN110876174A (en) * 2018-08-31 2020-03-10 华为技术有限公司 Network slice selection method, equipment and system
CN111182543A (en) * 2018-11-12 2020-05-19 华为技术有限公司 Method and device for switching network
CN111328112A (en) * 2018-12-14 2020-06-23 华为技术有限公司 Method, device and system for isolating security context

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109413702A (en) * 2017-08-16 2019-03-01 中国移动通信有限公司研究院 A kind of method for switching network, device and core net
CN110876174A (en) * 2018-08-31 2020-03-10 华为技术有限公司 Network slice selection method, equipment and system
CN111182543A (en) * 2018-11-12 2020-05-19 华为技术有限公司 Method and device for switching network
CN111328112A (en) * 2018-12-14 2020-06-23 华为技术有限公司 Method, device and system for isolating security context

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
HUAWEI, HISILICON: "Content in Slicing Clause X.X.2", 3GPP DRAFT; S3-194045, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. Reno, US; 20191118 - 20191122, 11 November 2019 (2019-11-11), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051824361 *

Also Published As

Publication number Publication date
CN114095925A (en) 2022-02-25

Similar Documents

Publication Publication Date Title
TWI679543B (en) Mobile edge platform servers and ue context migration management methods thereof
JP7184922B2 (en) Method, Apparatus, and System for Configuring Policy for UE
EP3742672A1 (en) Network slice-based communication method and apparatus
JP6908720B2 (en) Core network control plane device selection method and equipment
EP3863324A1 (en) Network slice access control method and device
US11032872B2 (en) Apparatus and method for deleting session context
CN111031538B (en) Authentication method and device
WO2019205027A1 (en) Session establishment method, relay device selection method and registration method and device
CN110049578B (en) Wireless connection modification method, device and system
WO2021203947A1 (en) Communication method and apparatus
US9225579B2 (en) Renewing registrations for a plurality of client applications that are associated with the same host server via an explicit piggybacking scheme
WO2019037500A1 (en) Method and apparatus for selecting radio access network device
US20230232356A1 (en) Storage of network slice authorization status
JP2021528007A (en) Communication method and communication device
JP2022528383A (en) Methods and devices for synchronizing the status of QoS flows in communication systems
JP5818047B2 (en) Communications system
WO2022062889A1 (en) Slice management method and apparatus, and communication device
KR102268412B1 (en) Handover method, device and system
WO2019091174A1 (en) Short message sending method and device
WO2013075308A1 (en) Method, device and system for processing closed subscriber group subscription data request
WO2022028030A1 (en) Slice authentication method and corresponding apparatus
KR20170021876A (en) Offloading of a wireless node authentication with core network
CN113259924A (en) Private network subscription information updating method and device
CN113573297B (en) Communication method and device
CN114423074A (en) Communication method and device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21853310

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21853310

Country of ref document: EP

Kind code of ref document: A1