WO2022127879A1 - 一种寻址、寻址信息的生成方法、设备及存储介质 - Google Patents

一种寻址、寻址信息的生成方法、设备及存储介质 Download PDF

Info

Publication number
WO2022127879A1
WO2022127879A1 PCT/CN2021/138934 CN2021138934W WO2022127879A1 WO 2022127879 A1 WO2022127879 A1 WO 2022127879A1 CN 2021138934 W CN2021138934 W CN 2021138934W WO 2022127879 A1 WO2022127879 A1 WO 2022127879A1
Authority
WO
WIPO (PCT)
Prior art keywords
aanf
service
kid
ausf
addressing information
Prior art date
Application number
PCT/CN2021/138934
Other languages
English (en)
French (fr)
Inventor
黄震宁
宋月
黄晓婷
魏彬
Original Assignee
中国移动通信有限公司研究院
中国移动通信集团有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中国移动通信有限公司研究院, 中国移动通信集团有限公司 filed Critical 中国移动通信有限公司研究院
Publication of WO2022127879A1 publication Critical patent/WO2022127879A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0433Key management protocols

Definitions

  • the present disclosure relates to the technical field of wireless communication, and in particular, to a method, device and storage medium for generating addressing and addressing information.
  • Figure 1 is one of the schematic diagrams of the 5G architecture
  • Figure 2 is the second schematic diagram of the 5G architecture.
  • 5G adopts a service-based approach to design control plane network elements and interfaces between network elements.
  • the network architecture is shown in Figures 1 and 2.
  • FIG 3 is a schematic diagram of the AKMA architecture, and the system architecture of the application's authentication and key management architecture (Architecture for Authentication and Key Management for Applications, AKMA) is shown in Figure 3.
  • the Application Function can directly obtain the authentication of the terminal and the application according to the authentication information on the network side.
  • AUSF Authentication Server Function
  • AF Application Function
  • NEF Network Exposure Function
  • the present disclosure provides a method, device and storage medium for addressing and addressing information, so as to solve the problem that the AUSF, AF or NEF cannot address the correct AAnF.
  • An addressing method that includes:
  • the core network device receives addressing information carrying the determined or selected AAnF;
  • the core network device determines or selects the AAnF according to the addressing information.
  • the addressing information is carried in an A-KID and/or a field indicating addressing information.
  • the addressing information is carried by the terminal or the AUSF in the process of generating the A-KID.
  • the addressing information includes one or a combination of the following information:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the AUSF, AF, or NEF configures the SUPI service range of the AAnF service after the last four digits, it is carried in the A-KID suffix, and the AAnF identifier passes through. The last four digits of SUPI.
  • the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the A-KID calculated value of the AAnF registration service at the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF, Or when the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or A-KID calculation value.
  • the A-KID or A-KID calculation value to determine the AAnF that meets the service scope it is based on the last 4 strings of A-KID, or according to the hash value of A-KID, or according to the hash value of A-KID. characters are determined.
  • the addressing information is the identity that AAnF registers AAnF to provide services in the NRF, and when the AUSF, AF, or NEF configures the correspondence between the AAnF service and the identity, it is based on the identity that the user issues to the terminal or AUSF during registration or The correspondence between AAnF services and identifiers is selected according to the AAnF service scope.
  • the implementation further includes:
  • the corresponding relationship between the domain name of the network element registered by the AAnF on the NRF and the AAnF identifier is obtained from the NRF, which is used for addressing by the AAnF.
  • a method for generating addressing information comprising:
  • the addressing information carrying the determined or selected AAnF is sent to the core network device.
  • the addressing information is carried by the terminal or the AUSF in the process of generating the A-KID.
  • the addressing information includes one or a combination of the following information:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the AUSF, AF, or NEF configures the SUPI service range of the AAnF service after the last four digits, it is carried in the A-KID suffix, and the AAnF identifier is passed. The last four digits of SUPI.
  • the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the A-KID calculated value of the AAnF registration service at the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF, Or when the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or A-KID calculation value.
  • the A-KID or A-KID calculation value to determine the AAnF that meets the service scope it is based on the last 4 strings of A-KID, or according to the hash value of A-KID, or according to the hash value of A-KID. characters are determined.
  • the addressing information is the identity that AAnF registers AAnF to provide services in the NRF, and when the AUSF, AF, or NEF configures the correspondence between the AAnF service and the identity, it is based on the identity that the user issues to the terminal or AUSF during registration or The correspondence between AAnF services and identifiers is selected according to the AAnF service scope.
  • a core network device including:
  • the processor for reading the program in memory, performs the following processes:
  • a transceiver for receiving and transmitting data under the control of the processor.
  • the addressing information is carried in an A-KID and/or a field indicating addressing information.
  • the addressing information is carried by the terminal or the AUSF in the process of generating the A-KID.
  • the addressing information includes one or a combination of the following information:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the AUSF, AF, or NEF configures the SUPI service range of the AAnF service after the last four digits, it is carried in the A-KID suffix, and the AAnF identifier passes through. The last four digits of SUPI.
  • the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the A-KID calculated value of the AAnF registration service at the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF, Or when the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or A-KID calculation value.
  • the A-KID or A-KID calculation value to determine the AAnF that meets the service scope it is based on the last 4 strings of A-KID, or according to the hash value of A-KID, or according to the hash value of A-KID. characters are determined.
  • the addressing information is the identity that AAnF registers AAnF to provide services in the NRF, and when the AUSF, AF, or NEF configures the correspondence between the AAnF service and the identity, it is based on the identity that the user issues to the terminal or AUSF during registration or The correspondence between AAnF services and identifiers is selected according to the AAnF service scope.
  • the implementation further includes:
  • the corresponding relationship between the domain name of the network element registered by the AAnF on the NRF and the AAnF identifier is obtained from the NRF, which is used for addressing by the AAnF.
  • a core network device including:
  • the core network device receiving module is used to receive addressing information carrying the determined or selected AAnF;
  • the core network device determining module is configured to determine or select the AAnF according to the addressing information.
  • the core network device receiving module is further configured to receive the addressing information carried in the A-KID and/or the field indicating the addressing information.
  • the core network device receiving module is further configured to receive the addressing information carried by the terminal or the AUSF in the process of generating the A-KID.
  • the core network device receiving module is further configured to receive the addressing information including one of the following information or a combination thereof:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the AUSF, AF, or NEF configures the SUPI service range of the AAnF service after the last four digits, it is carried in the A-KID suffix, and the AAnF identifier is passed. The last four digits of SUPI.
  • the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the A-KID calculated value of the AAnF registration service at the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF, Or when the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or A-KID calculation value.
  • the core network device determination module is further used to determine the AAnF that meets the service scope according to the A-KID or the A-KID calculation value, which is based on the last 4 character strings of the A-KID, or according to the hash value of the A-KID, or Determined according to the last few characters of the hash of A-KID.
  • the addressing information is the identity that AAnF registers AAnF to provide services in the NRF, and when the AUSF, AF, or NEF configures the correspondence between the AAnF service and the identity, it is based on the identity that the user issues to the terminal or AUSF during registration or The correspondence between AAnF services and identifiers is selected according to the AAnF service scope.
  • the implementation further includes:
  • the core network device acquisition module is used to acquire the correspondence between the domain name of the network element registered by the AAnF on the NRF and the AAnF identifier from the NRF, so as to be used for addressing by the AAnF.
  • a communication device comprising:
  • the processor for reading the program in memory, performs the following processes:
  • a transceiver for receiving and transmitting data under the control of the processor.
  • the addressing information is carried in an A-KID and/or a field indicating addressing information.
  • the addressing information is carried by the terminal or the AUSF in the process of generating the A-KID.
  • the addressing information includes one or a combination of the following information:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the AUSF, AF, or NEF configures the SUPI service range of the AAnF service after the last four digits, it is carried in the A-KID suffix, and the AAnF identifier is passed. The last four digits of SUPI.
  • the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the A-KID calculated value of the AAnF registration service at the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF, Or when the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or A-KID calculation value.
  • the A-KID or A-KID calculation value to determine the AAnF that meets the service scope it is based on the last 4 strings of A-KID, or according to the hash value of A-KID, or according to the hash value of A-KID. characters are determined.
  • the addressing information is the identification of the AAnF registering the AAnF service in the NRF.
  • the AUSF, AF, or NEF configures the corresponding relationship between the AAnF service and the identification, it is based on the identification issued by the user to the terminal or the AUSF during registration or The correspondence between AAnF services and identifiers is selected according to the AAnF service scope.
  • a communication device comprising:
  • the communication device sending module is configured to send addressing information carrying the determined or selected AAnF to the core network device.
  • the implementation further includes:
  • a communication device generation module configured to carry the addressing information in the A-KID and/or a field indicating addressing information.
  • the communication device generation module is further configured to carry the addressing information in the process of generating the A-KID by the terminal or the AUSF.
  • the communication device generation module is further configured to generate the addressing information including one of the following information or a combination thereof:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the communication device generation module is further configured to, when the addressing information is the SUPI range of the AAnF registered service in the NRF, or the last four-digit service range of the SUPI service of the AAnF service configured by the AUSF, AF, or NEF, is in the A- For the addressing information carried by the KID suffix, the AAnF identifier is identified by the last four digits of SUPI.
  • the communication device generation module is further configured to, when the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the calculated value of the A-KID of the AAnF registration service at the NRF, or by AUSF, AF, or NEF.
  • the AAnF that meets the service range is determined according to the A-KID or the A-KID calculation value.
  • the communication device generation module is further used to determine the AAnF that meets the service scope according to the A-KID or the A-KID calculation value, which is according to the last 4 character strings of the A-KID, or according to the hash value of the A-KID, or Determined according to the last few characters of the hash of A-KID.
  • the communication device generation module is further used for when the addressing information is that the AAnF registers the AAnF to provide the service at the NRF, and when the AUSF, AF, or NEF configures the correspondence between the AAnF service and the identification, it is based on the user's registration status.
  • the identity sent to the terminal or the AUSF or the corresponding relationship between the AAnF service and the identity select the AAnF that conforms to the service scope.
  • a computer-readable storage medium storing a computer program for executing an addressing method and/or a generating method of addressing information.
  • the addressing information for determining or selecting the AAnF since the addressing information for determining or selecting the AAnF is carried, the problem that the AUSF, the AF or the NEF cannot be correctly addressed to the AAnF can be solved.
  • FIG. 1 is a schematic diagram 1 of a 5G architecture in the background art
  • FIG. 2 is a schematic diagram 2 of a 5G architecture in the background technology
  • FIG. 3 is a schematic diagram of the AKMA architecture in the background technology
  • FIG. 4 is a schematic flowchart of implementing an addressing method on a core network device side in an embodiment of the present disclosure
  • FIG. 5 is a schematic flowchart of an implementation of a method for generating addressing information in an embodiment of the present disclosure
  • FIG. 6 is a schematic structural diagram of a core network device in an embodiment of the present disclosure.
  • FIG. 7 is a schematic structural diagram of a communication device in an embodiment of the present disclosure.
  • AKMA AKMA application key generation process for a special application is as follows.
  • the AUSF sends the AKMA anchor key (AKMA Anchor Key, K AKMA ) to the AAnF.
  • AKMA Anchor Key K AKMA
  • AF key generation mainly includes:
  • the terminal directly interacts with the application server application identification (A-KID);
  • AF holds the application server ID (AF ID) and application identifier (A-KID) to request AKMA key authentication from the network;
  • AAnF uses K AKMA to generate the AF key, and returns it to the AF, and returns the expiration time at the same time.
  • the AF initiates the application, it can also request the AF Key from the AAnF via the NEF.
  • the above problem will be solved by adding a hash value or an indication bit representing the user in the A-KID, or adding a negotiation flag between the application and the network, or using AAnF to register the A-KID.
  • KID calculation scheme, AUSF and terminal refer to this calculation scheme to generate A-KID when generating A-KID, so that when AF and NEF send messages, they can calculate the correct AAnF address according to this algorithm.
  • the A-KID suffix is supplemented to represent AAnF The identifier of an address or address field.
  • FIG. 4 is a schematic flowchart of the implementation of the addressing method on the core network device side. As shown in the figure, it may include:
  • Step 401 the core network device receives addressing information that carries the AAnF determined or selected;
  • Step 402 The core network device determines or selects the AAnF according to the addressing information.
  • the core network device determines or selects the AAnF that generates the AF key according to the addressing information. It may be that the core network device determines, according to the addressing information, the AAnF that generates the AF key in the AKMA key authentication.
  • the NEF will identify the AAnF that generates the AF key (The NEF will identify the AAnF which genrate the KAF).
  • the NEF will identify the AAnF serve the AF (The NEF will identify the AAnF serve the AF).
  • FIG. 5 is a schematic flowchart of the implementation of the method for generating addressing information. As shown in the figure, it may include:
  • Step 501 determine AAnF
  • Step 502 generating the addressing information carrying the AAnF determined or selected
  • Step 503 Send addressing information carrying the determined or selected AAnF to the core network device.
  • the addressing information is carried in an A-KID and/or a field indicating addressing information.
  • the addressing information is carried by the terminal or the AUSF in the process of generating the A-KID.
  • the A-KID contains the addressing information of the AAnF.
  • This addressing information may be used to indicate an AAnF, or to indicate a group of AAnFs.
  • the information can be a description indication in the A-KID, or can be obtained by converting the A-KID through a certain algorithm.
  • AF and NEF can perform AAnF addressing according to the AAnF identifier stored and/or carried by the A-KID or other fields.
  • the AAnF can register the corresponding relationship between its own network element domain name and the AAnF identifier on the NRF, which facilitates the addressing of network elements such as AF and NEF. That is, in the implementation, it can further include:
  • the corresponding relationship between the domain name of the network element registered by the AAnF on the NRF and the AAnF identifier is obtained from the NRF, which is used for addressing by the AAnF.
  • the addressing information may include one or a combination of the following information:
  • AAnF registers the SUPI scope of the service in the Network Repository Function (NRF), and AUSF, AF, or NEF configures the last four service scope of the SUPI of the AAnF service, AAnF registers the A-KID of the service in the NRF, and AAnF registers in the NRF
  • the range of the calculated A-KID value of the service, the A-KID of the AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculated value of the AAnF service is configured by AUSF, AF, or NEF
  • the AAnF is registered in the NRF and provided by AAnF
  • the identifier of the service, the corresponding relationship between the AAnF service and the identifier is configured by the AUSF, AF, or NEF.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the last four digits of the SUPI service range of the AAnF service are configured by AUSF, AF, or NEF, it is carried in the A-KID suffix, and the AAnF identifies It is identified by the last four digits of SUPI.
  • the logo can be realized by the last four digits of SUPI.
  • the main process can be as follows:
  • the addressing information is the A-KID of the AAnF registration service in the NRF, or the range of the A-KID calculated value of the AAnF registration service in the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF , or when the range of the A-KID calculation value of the AAnF service is configured by the AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or the A-KID calculation value.
  • the AAnF that conforms to the service scope is determined according to the calculated value of A-KID or A-KID, according to the last 4 character strings of A-KID, or according to the hash value of A-KID, or according to the hash value of A-KID A few characters are determined.
  • the AAnF identifier can be carried through the A-KID calculation, and the AAnF identifier can be obtained through the A-KID calculation. Specifically, it can be as follows:
  • AUSF selects AAnF, select the AAnF that meets the service range according to the A-KID and/or A-KID calculation value (for example, according to the last 4 strings of A-KID, or according to the hash of A-KID, or according to A-KID hash after a few characters, etc.);
  • AAnF select the AAnF that meets the service scope according to the A-KID and/or A-KID calculation value (for example, according to the last 4 strings of A-KID, or according to the hash of A-KID, or according to A-KID hash after a few characters, etc.); or,
  • AAnFs When selecting AAnFs by NEF, select AAnFs that fit the service range based on A-KID and/or A-KID calculated values (for example, based on the last 4 strings of A-KID, or based on the hash of A-KID, or based on A-KID A few characters after the hash of the KID, etc.).
  • A-KID A-KID calculated values
  • the addressing information is the identity of the AAnF registered with the NRF to provide the service.
  • the AUSF, AF, or NEF configures the corresponding relationship between the AAnF service and the identity, it is based on the identity issued by the user to the terminal or AUSF during registration. Or the corresponding relationship between the AAnF service and the identifier is selected from the AAnF that conforms to the service scope.
  • AAnF registers the identity of the service provided by AAnF in the NRF, or AUSF, AF, and NEF configure the corresponding relationship between the AAnF service and the identity;
  • the unified data management entity Unified Data Management, UDM
  • the unified data repository Unified Data Repository, UDR
  • contract identification is issued to the terminal and the AUSF when the user registers;
  • AAnF is selected by NEF, AAnF is selected according to the flag.
  • the embodiments of the present disclosure also provide a core network device, a communication device, and a computer-readable storage medium.
  • a core network device for the implementation of these devices, reference may be made to the implementation of the method, and repeated details will not be repeated.
  • FIG. 6 is a schematic diagram of the structure of the core network equipment. As shown in the figure, the equipment includes:
  • the processor 600 is configured to read the program in the memory 620, and execute the following processes:
  • the transceiver 610 is used for receiving and transmitting data under the control of the processor 600 .
  • the addressing information is carried in an A-KID and/or a field indicating addressing information.
  • the addressing information is carried by the terminal or the AUSF in the process of generating the A-KID.
  • the addressing information includes one or a combination of the following information:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the AUSF, AF, or NEF configures the SUPI service range of the AAnF service after the last four digits, it is carried in the A-KID suffix, and the AAnF identifier is passed. The last four digits of SUPI.
  • the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the A-KID calculated value of the AAnF registration service at the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF, Or when the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or A-KID calculation value.
  • the A-KID or A-KID calculation value to determine the AAnF that meets the service scope it is based on the last 4 strings of A-KID, or according to the hash value of A-KID, or according to the hash value of A-KID. characters are determined.
  • the addressing information is the identification of the AAnF registering the AAnF service in the NRF.
  • the AUSF, AF, or NEF configures the corresponding relationship between the AAnF service and the identification, it is based on the identification issued by the user to the terminal or the AUSF during registration or The correspondence between the AAnF service and the identifier is selected from the AAnF that conforms to the service scope.
  • the implementation further includes:
  • the corresponding relationship between the domain name of the network element registered by the AAnF on the NRF and the AAnF identifier is obtained from the NRF, which is used for addressing by the AAnF.
  • the bus architecture may include any number of interconnected buses and bridges, specifically one or more processors represented by processor 600 and various circuits of memory represented by memory 620 are linked together.
  • the bus architecture may also link together various other circuits, such as peripherals, voltage regulators, and power management circuits, which are well known in the art and, therefore, will not be described further herein.
  • the bus interface provides the interface.
  • Transceiver 610 may be a number of elements, including a transmitter and a receiver, that provide a means for communicating with various other devices over a transmission medium.
  • the processor 600 is responsible for managing the bus architecture and general processing, and the memory 620 may store data used by the processor 600 in performing operations.
  • the embodiments of the present disclosure also provide a core network device, including:
  • the core network device receiving module is used to receive addressing information carrying the determined or selected AAnF;
  • the core network device determining module is configured to determine or select the AAnF according to the addressing information.
  • the addressing information is carried in an A-KID and/or a field indicating addressing information.
  • the core network device receiving module is further configured to receive the addressing information carried by the terminal or the AUSF in the process of generating the A-KID.
  • the core network device receiving module is further configured to receive the addressing information including one of the following information or a combination thereof:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the AUSF, AF, or NEF configures the SUPI service range of the AAnF service after the last four digits, it is carried in the A-KID suffix, and the AAnF identifier is passed. The last four digits of SUPI.
  • the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the A-KID calculated value of the AAnF registration service at the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF, Or when the range of the A-KID calculation value of the AAnF service is configured by the AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or the A-KID calculation value.
  • the core network device determination module is further used to determine the AAnF that meets the service scope according to the A-KID or the A-KID calculation value, which is based on the last 4 character strings of the A-KID, or according to the hash value of the A-KID, or Determined according to the last few characters of the hash of A-KID.
  • the addressing information is the identity that AAnF registers AAnF to provide services in the NRF, and when the AUSF, AF, or NEF configures the correspondence between the AAnF service and the identity, it is based on the identity that the user issues to the terminal or AUSF during registration or The correspondence between AAnF services and identifiers is selected according to the AAnF service scope.
  • the implementation further includes:
  • the core network device acquisition module is used to acquire the correspondence between the domain name of the network element registered by the AAnF on the NRF and the AAnF identifier from the NRF, so as to be used for addressing by the AAnF.
  • each part of the device described above is divided into various modules or units by function and described respectively.
  • the functions of each module or unit may be implemented in one or more software or hardware.
  • Figure 7 is a schematic structural diagram of a communication device, as shown in the figure, the device includes:
  • the processor 700 is configured to read the program in the memory 720 and perform the following processes:
  • the transceiver 710 is used to receive and transmit data under the control of the processor 700 .
  • the addressing information is carried in an A-KID and/or a field indicating addressing information.
  • the addressing information is carried by the terminal or the AUSF in the process of generating the A-KID.
  • the addressing information includes one or a combination of the following information:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the addressing information is the SUPI range of the AAnF registration service in the NRF, or when the AUSF, AF, or NEF configures the SUPI service range of the AAnF service after the last four digits, it is carried in the A-KID suffix, and the AAnF identifier is passed. The last four digits of SUPI.
  • the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the A-KID calculated value of the AAnF registration service at the NRF, or the A-KID of the AAnF service configured by AUSF, AF, or NEF, Or when the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF, the AAnF that conforms to the service range is determined according to the A-KID or A-KID calculation value.
  • the A-KID or A-KID calculation value to determine the AAnF that meets the service scope it is based on the last 4 strings of A-KID, or according to the hash value of A-KID, or according to the hash value of A-KID. characters are determined.
  • the addressing information is the identity that AAnF registers AAnF to provide services in the NRF, and when the AUSF, AF, or NEF configures the correspondence between the AAnF service and the identity, it is based on the identity that the user issues to the terminal or AUSF during registration or The correspondence between AAnF services and identifiers is selected according to the AAnF service scope.
  • the bus architecture may include any number of interconnected buses and bridges, specifically one or more processors represented by processor 700 and various circuits of memory represented by memory 720 are linked together.
  • the bus architecture may also link together various other circuits, such as peripherals, voltage regulators, and power management circuits, which are well known in the art and, therefore, will not be described further herein.
  • the bus interface provides the interface.
  • Transceiver 710 may be a number of elements, ie, including a transmitter and a receiver, that provide a means for communicating with various other devices over a transmission medium.
  • the processor 700 is responsible for managing the bus architecture and general processing, and the memory 720 may store data used by the processor 700 in performing operations.
  • Embodiments of the present disclosure also provide a communication device, including:
  • the communication device generation module is used to generate addressing information carrying the determined or selected AAnF;
  • the communication device sending module is configured to send addressing information carrying the determined or selected AAnF to the core network device.
  • the addressing information is carried in an A-KID and/or a field indicating addressing information.
  • the communication device generation module is further configured to carry the addressing information in the process of generating the A-KID by the terminal or the AUSF.
  • the communication device generation module is further configured to generate the addressing information including one of the following information or a combination thereof:
  • the SUPI range of AAnF registration service in NRF is configured by AUSF, AF, or NEF
  • the A-KID of AAnF registration service in NRF the range of A-KID calculation value of AAnF registration service in NRF
  • the A-KID of AAnF service is configured by AUSF, AF, or NEF
  • the range of A-KID calculation value of AAnF service is configured by AUSF, AF, or NEF
  • AAnF registers the identifier of AAnF service provided by AUSF, AF, Or the NEF configures the correspondence between AAnF services and identifiers.
  • the communication device generation module is further configured to, when the addressing information is the SUPI range of the AAnF registered service in the NRF, or the last four-digit service range of the SUPI service of the AAnF service configured by the AUSF, AF, or NEF, is in the A- For the addressing information carried by the KID suffix, the AAnF identifier is identified by the last four digits of SUPI.
  • the communication device generation module is further configured to, when the addressing information is the A-KID of the AAnF registration service at the NRF, or the range of the calculated value of the A-KID of the AAnF registration service at the NRF, or by AUSF, AF, or NEF.
  • the AAnF that meets the service range is determined according to the A-KID or the A-KID calculation value.
  • the communication device generation module is further used to determine the AAnF that meets the service scope according to the A-KID or the A-KID calculation value, which is according to the last 4 character strings of the A-KID, or according to the hash value of the A-KID, or Determined according to the last few characters of the hash of A-KID.
  • the communication device generation module is further used for when the addressing information is that the AAnF registers the AAnF to provide the service at the NRF, and when the AUSF, AF, or NEF configures the correspondence between the AAnF service and the identification, it is based on the user's registration status.
  • the identity sent to the terminal or the AUSF or the corresponding relationship between the AAnF service and the identity select the AAnF that conforms to the service scope.
  • each part of the device described above is divided into various modules or units by function and described respectively.
  • the functions of each module or unit may be implemented in one or more software or hardware.
  • Embodiments of the present disclosure also provide a computer-readable storage medium, where the computer-readable storage medium stores a computer program for executing the addressing method and/or the addressing information generation method.
  • the terminal and the AUSF in the process of generating the A-KID, include the addressing information of the AAnF in the A-KID; other fields are included.
  • This addressing information may be used to indicate an AAnF, or to indicate a group of AAnFs.
  • the information may be a description indication in a bearer field (such as A-KID), and may be obtained by converting the bearer field (such as A-KID) through a certain algorithm.
  • a bearer field such as A-KID
  • the AF and NEF perform AAnF addressing according to the AAnF identifier stored and/or carried by the A-KID or other fields.
  • the AAnF can also register the corresponding relationship between its own network element domain name and the AAnF identifier on the NRF, which facilitates the addressing of network elements such as AF and NEF.
  • embodiments of the present disclosure may be provided as a method, system, or computer program product. Accordingly, the present disclosure may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present disclosure may take the form of a computer program product embodied on one or more computer-usable storage media having computer-usable program code embodied therein, including but not limited to disk storage, optical storage, and the like.
  • These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory result in an article of manufacture comprising instruction means, the instructions
  • the apparatus implements the functions specified in the flow or flow of the flowcharts and/or the block or blocks of the block diagrams.
  • modules, units, sub-modules, sub-units, etc. can be implemented in one or more Application Specific Integrated Circuits (ASIC), Digital Signal Processing (DSP), digital signal processing equipment ( DSP Device, DSPD), Programmable Logic Device (Programmable Logic Device, PLD), Field-Programmable Gate Array (Field-Programmable Gate Array, FPGA), general-purpose processor, controller, microcontroller, microprocessor, for in other electronic units or combinations thereof that perform the functions described in this disclosure.
  • ASIC Application Specific Integrated Circuits
  • DSP Digital Signal Processing
  • DSP Device digital signal processing equipment
  • PLD Programmable Logic Device
  • Field-Programmable Gate Array Field-Programmable Gate Array
  • FPGA Field-Programmable Gate Array

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

一种寻址、寻址信息的生成方法、设备及介质,该方法包括:生成携带确定或选择出AAnF的寻址信息;向核心网设备发送携带AAnF的寻址信息;核心网设备根据所述寻址信息确定AAnF。

Description

一种寻址、寻址信息的生成方法、设备及存储介质
相关申请的交叉引用
本申请主张在2020年12月18日在中国提交的中国专利申请号No.202011503479.2的优先权,其全部内容通过引用包含于此。
技术领域
本公开涉及无线通信技术领域,特别涉及一种寻址、寻址信息的生成方法、设备及存储介质。
背景技术
图1为5G架构示意图之一,图2为5G架构示意图之二,5G采用服务化方式设计控制面网元以及网元间的接口,网络架构如图1、2所示。
图3为AKMA架构示意图,应用程序的身份验证和密钥管理体系结构(Architecture for Authentication and Key Management for Applications,AKMA)的系统架构如图3所示。
应用功能(Application Function,AF)可以根据网络侧的鉴权信息,直接获取终端和应用的鉴权。
相关技术的不足在于:鉴权服务功能(Authentication Server Function,AUSF)、应用功能(Application Function,AF)或网络开放功能(Network Exposure Function,NEF)不能寻址到正确的AKMA锚定网元(AKMA Anchor Function,AAnF)。
发明内容
本公开提供了一种寻址、寻址信息的生成方法、设备及存储介质,用以解决AUSF、AF或NEF不能寻址到正确AAnF的问题。
本公开提供以下技术方案:
一种寻址方法,包括:
核心网设备接收携带有确定或选择出AAnF的寻址信息;
核心网设备根据所述寻址信息确定或选择出AAnF。
实施中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
实施中,所述寻址信息是终端或AUSF在生成A-KID过程中携带的。
实施中,所述寻址信息包括以下信息之一或者其组合:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
实施中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
实施中,进一步包括:
从NRF获取AAnF注册在NRF上的网元域名和AAnF标识的对应关系,用以供AAnF的寻址。
一种寻址信息的生成方法,包括:
确定AAnF;
向核心网设备发送携带有确定或选择出AAnF的寻址信息。
实施中,所述寻址信息是终端或AUSF在生成A-KID过程中携带的。
实施中,所述寻址信息包括以下信息之一或者其组合:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
实施中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
一种核心网设备,包括:
处理器,用于读取存储器中的程序,执行下列过程:
接收携带有确定或选择出AAnF的寻址信息;
根据所述寻址信息确定或选择出AAnF;
收发机,用于在处理器的控制下接收和发送数据。
实施中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
实施中,所述寻址信息是终端或AUSF在生成A-KID过程中携带的。
实施中,所述寻址信息包括以下信息之一或者其组合:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
实施中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
实施中,进一步包括:
从NRF获取AAnF注册在NRF上的网元域名和AAnF标识的对应关系,用以供AAnF的寻址。
一种核心网设备,包括:
核心网设备接收模块,用于接收携带有确定或选择出AAnF的寻址信息;
核心网设备确定模块,用于根据所述寻址信息确定或选择出AAnF。
实施中,核心网设备接收模块进一步用于接收在A-KID和/或指示寻址信 息的字段中携带的所述寻址信息。
实施中,核心网设备接收模块进一步用于接收终端或AUSF在生成A-KID过程中携带的所述寻址信息。
实施中,核心网设备接收模块进一步用于接收包括以下信息之一或者其组合的所述寻址信息:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
实施中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,核心网设备确定模块进一步用于根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
实施中,进一步包括:
核心网设备获取模块,用于在从NRF获取AAnF注册在NRF上的网元域名和AAnF标识的对应关系,用以供AAnF的寻址。
一种通信设备,包括:
处理器,用于读取存储器中的程序,执行下列过程:
确定AAnF;
向核心网设备发送携带有确定或选择出AAnF的寻址信息;
收发机,用于在处理器的控制下接收和发送数据。
实施中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
实施中,所述寻址信息是终端或AUSF在生成A-KID过程中携带的。
实施中,所述寻址信息包括以下信息之一或者其组合:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
实施中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
一种通信设备,包括:
通信设备确定模块,用于确定AAnF;
通信设备发送模块,用于向核心网设备发送携带有确定或选择出AAnF的寻址信息。
实施中,进一步包括:
通信设备生成模块,用于在A-KID和/或指示寻址信息的字段中携带所述寻址信息。
实施中,通信设备生成模块进一步用于在终端或AUSF在生成A-KID过程中携带所述寻址信息。
实施中,通信设备生成模块进一步用于生成包括以下信息之一或者其组合所述寻址信息:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,通信设备生成模块进一步用于在所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的所述寻址信息,AAnF标识通过SUPI的后四位标识。
实施中,通信设备生成模块进一步用于在所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,通信设备生成模块进一步用于在根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,通信设备生成模块进一步用于在所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识 的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
一种计算机可读存储介质,所述计算机可读存储介质存储有执行寻址方法和/或寻址信息的生成方法的计算机程序。
本公开有益效果如下:
本公开实施例提供的技术方案中,由于携带有确定或选择出AAnF的寻址信息,因此能够解决AUSF、AF或NEF不能正确寻址到AAnF的问题。
附图说明
此处所说明的附图用来提供对本公开的进一步理解,构成本公开的一部分,本公开的示意性实施例及其说明用于解释本公开,并不构成对本公开的不当限定。在附图中:
图1为背景技术中5G架构示意图1;
图2为背景技术中5G架构示意图2;
图3为背景技术中AKMA架构示意图;
图4为本公开实施例中核心网设备侧的寻址方法实施流程示意图;
图5为本公开实施例中寻址信息的生成方法实施流程示意图;
图6为本公开实施例中核心网设备结构示意图;
图7为本公开实施例中通信设备结构示意图。
具体实施方式
发明人注意到:
下面对AKMA应用密钥生成流程进行说明。
AKMA中,一个特殊应用的AKMA应用密钥生成流程如下。
A、AUSF向AAnF发送AKMA锚定密钥(AKMA Anchor Key,K AKMA)。
B-1、AF发起应用时,向AAnF请求AF Key(AF秘钥)。AF秘钥生成主要包括:
1、终端直接和应用服务器交互应用标识(A-KID);
2、AF持应用服务器ID(AF ID)和应用标识(A-KID)向网络请求AKMA 密钥认证;
3、AAnF利用K AKMA生成AF密钥,并返回给AF,同时返回失效时间。
B-2、AF发起应用时,也可以经由NEF向AAnF请求AF Key。
也即,当前技术中,由于AF或NEF没有补充用于寻址AAnF的标记,从而无法解决AUSF、AF或NEF寻址到正确AAnF的问题。
基于此,本公开实施例提供的技术方案中,将通过在A-KID中增加代表用户的哈希值或指示位,或者增加应用和网络的协商标记来解决上述问题,或者采用AAnF注册A-KID的计算方案,AUSF和终端在生成A-KID时参考该计算方案生成A-KID,从而便于AF、NEF发送消息时,依据该算法计算出正确AAnF地址,例如在A-KID后缀补充代表AAnF地址或地址域的标识。
下面结合附图对本公开的具体实施方式进行说明。
在说明过程中,将分别从AF、AUSF、NEF、AAnF等核心网设备与终端侧的实施进行说明,然后还将给出它们配合实施的实例以更好地理解本公开实施例中给出的方案的实施。这样的说明方式并不意味着它们必须配合实施、或者必须单独实施,实际上,当它们分开实施时,其也各自解决自身一侧的问题,而它们结合使用时,会获得更好的技术效果。
图4为核心网设备侧的寻址方法实施流程示意图,如图所示,可以包括:
步骤401、核心网设备接收携带有确定或选择出AAnF的寻址信息;
步骤402、核心网设备根据所述寻址信息确定或选择出AAnF。
具体的,核心网设备根据所述寻址信息确定或选择出生成AF密钥的AAnF。可以是核心网设备根据所述寻址信息确定出在AKMA密钥认证中生成AF密钥的AAnF。
具体的可以是:NEF将识别产生AF密钥的AAnF(The NEF will identify the AAnF which genrate the KAF)。
或者是:NEF将识别为AF服务的AAnF(The NEF will identify the AAnF serve the AF)。
该方案的实施将主要以AF、NEF的实施进行说明。
图5为寻址信息的生成方法实施流程示意图,如图所示,可以包括:
步骤501、确定AAnF;
步骤502、生成携带有确定或选择出AAnF的寻址信息;
步骤503、向核心网设备发送携带有确定或选择出AAnF的寻址信息。
具体的,可以确定生成AF密钥的AAnF;生成携带有确定生成AF密钥的AAnF的寻址信息;向核心网设备发送携带有确定生成AF密钥的AAnF的寻址信息。
该方案的实施将主要以用户设备(User Equipment,UE)、AUSF的实施进行说明。
实施中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
实施中,所述寻址信息是终端或AUSF在生成A-KID过程中携带的。
具体的,终端和AUSF分别在生成A-KID过程中,在A-KID中包含AAnF的寻址信息。该寻址信息可以用于指示AAnF,或者指示一组AAnF。该信息可以为A-KID中的一段描述指示,也可以通过A-KID通过某种算法转换得到。
例如:在A-KID中携带用户签约永久标识(Subscription Permanent Identifier,SUPI)对应的后四位,hash(哈希)后得到的字符串;A-KID生成的最后两位字符等,均可以作为AAnF的标识;
AF、NEF则可以根据A-KID或者其他字段存储和/或携带的AAnF标识进行AAnF寻址。
进一步的,AAnF可以将自己的网元域名和AAnF标识的对应关系注册在NRF上,便于AF、NEF等网元进行寻址。也即,实施中,还可以进一步包括:
从NRF获取AAnF注册在NRF上的网元域名和AAnF标识的对应关系,用以供AAnF的寻址。
实施中,所述寻址信息可以包括以下信息之一或者其组合:
AAnF在网络存储功能(Network Repository Function,NRF)注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
下面以实例分别进行说明。
实施例1
本例中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
具体的,通过A-KID后缀携带AAnF标识的方案,标识可以通过SUPI的后四位实现,主要流程可以如下:
1、AAnF在NRF注册服务的SUPI范围,或者AUSF、AF、NEF配置AAnF服务的SUPI后四位服务范围;
2、在UE和AUSF生成A-KID时,在A-KID最后补充4个字符,填写终端的SUPI最后四位;
3、在AUSF选择AAnF时,根据SUPI选择符合服务范围的AAnF;
4、在AF选择AAnF时,根据A-KID的最后4个字符选择AAnF;
或者,在NEF选择AAnF时,根据A-KID的最后4个字符选择AAnF。
实施例2
本例中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
具体实施中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
具体的,可以通过A-KID计算携带AAnF标识的方式,AAnF标识可以通过A-KID计算得到。具体可以如下:
1、AAnF在NRF注册服务的A-KID和/或A-KID计算值的范围,或者AUSF、AF、NEF配置AAnF服务的A-KID和/或A-KID计算值的范围;
2、在AUSF选择AAnF时,根据A-KID和/或A-KID计算值选择符合服务范围的AAnF(例如,根据A-KID的最后4个字符串,或者根据A-KID的hash,或者根据A-KID的hash后几个字符等);
3、在AF选择AAnF时,根据A-KID和/或A-KID计算值选择符合服务范围的AAnF(例如,根据A-KID的最后4个字符串,或者根据A-KID的hash,或者根据A-KID的hash后几个字符等);或者,
在NEF选择AAnF时,根据A-KID和/或A-KID计算值选择符合服务范围的AAnF(例如,根据A-KID的最后4个字符串,或者根据A-KID的hash,或者根据A-KID的hash后几个字符等)。该AAnF的发现可以通过NRF辅助发现。
实施例3
本例中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
具体的,可以用通过其他字段携带AAnF标识的方式,具体可以如下:
1、AAnF在NRF注册AAnF提供服务的标识,或者AUSF、AF、NEF配置AAnF服务和标识的对应关系;
2、统一数据管理实体(Unified Data Management,UDM)、统一数据存储库(Unified Data Repository,UDR)签约标识,在用户注册时将标识下发给终端和AUSF;
3、在AUSF选择AAnF时,根据标识选择符合服务范围的AAnF;
4、在AF选择AAnF时,根据标识选择AAnF;或者,
在NEF选择AAnF时,根据标识选择AAnF。
基于同一发明构思,本公开实施例中还提供了一种核心网设备、通信设备、及计算机可读存储介质,由于这些设备解决问题的原理与寻址方法、寻址信息的生成方法相似,因此这些设备的实施可以参见方法的实施,重复之处不再赘述。
在实施本公开实施例提供的技术方案时,可以按如下方式实施。
图6为核心网设备结构示意图,如图所示,设备中包括:
处理器600,用于读取存储器620中的程序,执行下列过程:
接收携带有确定或选择出AAnF的寻址信息;
根据所述寻址信息确定或选择出AAnF;
收发机610,用于在处理器600的控制下接收和发送数据。
实施中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
实施中,所述寻址信息是终端或AUSF在生成A-KID过程中携带的。
实施中,所述寻址信息包括以下信息之一或者其组合:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
实施中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
实施中,进一步包括:
从NRF获取AAnF注册在NRF上的网元域名和AAnF标识的对应关系,用以供AAnF的寻址。
其中,在图6中,总线架构可以包括任意数量的互联的总线和桥,具体 由处理器600代表的一个或多个处理器和存储器620代表的存储器的各种电路链接在一起。总线架构还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口提供接口。收发机610可以是多个元件,即包括发送机和接收机,提供用于在传输介质上与各种其他装置通信的单元。处理器600负责管理总线架构和通常的处理,存储器620可以存储处理器600在执行操作时所使用的数据。
本公开实施例中还提供了一种核心网设备,包括:
核心网设备接收模块,用于接收携带有确定或选择出AAnF的寻址信息;
核心网设备确定模块,用于根据所述寻址信息确定或选择出AAnF。
实施中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
实施中,核心网设备接收模块进一步用于接收终端或AUSF在生成A-KID过程中携带的所述寻址信息。
实施中,核心网设备接收模块进一步用于接收包括以下信息之一或者其组合的所述寻址信息:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
实施中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,核心网设备确定模块进一步用于根据A-KID或A-KID计算值确 定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
实施中,进一步包括:
核心网设备获取模块,用于在从NRF获取AAnF注册在NRF上的网元域名和AAnF标识的对应关系,用以供AAnF的寻址。
为了描述的方便,以上所述装置的各部分以功能分为各种模块或单元分别描述。当然,在实施本公开时可以把各模块或单元的功能在同一个或多个软件或硬件中实现。
图7为通信设备结构示意图,如图所示,设备中包括:
处理器700,用于读取存储器720中的程序,执行下列过程:
确定AAnF;
生成携带有确定或选择出AAnF的寻址信息;
向核心网设备发送携带有确定或选择出AAnF的寻址信息;
收发机710,用于在处理器700的控制下接收和发送数据。
实施中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
实施中,所述寻址信息是终端或AUSF在生成A-KID过程中携带的。
实施中,所述寻址信息包括以下信息之一或者其组合:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携 带的,AAnF标识通过SUPI的后四位标识。
实施中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
其中,在图7中,总线架构可以包括任意数量的互联的总线和桥,具体由处理器700代表的一个或多个处理器和存储器720代表的存储器的各种电路链接在一起。总线架构还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口提供接口。收发机710可以是多个元件,即包括发送机和接收机,提供用于在传输介质上与各种其他装置通信的单元。处理器700负责管理总线架构和通常的处理,存储器720可以存储处理器700在执行操作时所使用的数据。
本公开实施例中还提供了一种通信设备,包括:
通信设备确定模块,用于确定AAnF;
通信设备生成模块,用于生成携带有确定或选择出AAnF的寻址信息;
通信设备发送模块,用于向核心网设备发送携带有确定或选择出AAnF的寻址信息。
实施中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
实施中,通信设备生成模块进一步用于在终端或AUSF在生成A-KID过程中携带所述寻址信息。
实施中,通信设备生成模块进一步用于生成包括以下信息之一或者其组 合所述寻址信息:
AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
实施中,通信设备生成模块进一步用于在所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的所述寻址信息,AAnF标识通过SUPI的后四位标识。
实施中,通信设备生成模块进一步用于在所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
实施中,通信设备生成模块进一步用于在根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
实施中,通信设备生成模块进一步用于在所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
为了描述的方便,以上所述装置的各部分以功能分为各种模块或单元分别描述。当然,在实施本公开时可以把各模块或单元的功能在同一个或多个软件或硬件中实现。
本公开实施例中还提供了一种计算机可读存储介质,所述计算机可读存储介质存储有执行寻址方法和/或寻址信息的生成方法的计算机程序。
具体实施中可以参见寻址方法和/或寻址信息的生成方法的实施。
综上所述,本公开实施例提供的技术方案中,终端和AUSF在生成A-KID的过程中,在A-KID中包含AAnF的寻址信息;该寻址信息可以在除了A-KID的其他字段中包含。该寻址信息可以用于指示AAnF,或者指示一组AAnF。
该信息可以为承载字段(如A-KID)中的一段描述指示,可以通过承载字段(如A-KID)通过某种算法转换得到。
AF、NEF根据A-KID或者其他字段存储和/或携带的AAnF标识进行AAnF寻址。
进一步,AAnF还可以将自己的网元域名和AAnF标识的对应关系注册在NRF上,便于AF、NEF等网元进行寻址。
可见,采用本方案能够解决AAnF寻址问题。
本领域内的技术人员应明白,本公开的实施例可提供为方法、系统、或计算机程序产品。因此,本公开可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本公开可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本公开是参照根据本公开实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上, 使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
可以理解的是,本公开实施例描述的这些实施例可以用硬件、软件、固件、中间件、微码或其组合来实现。对于硬件实现,模块、单元、子模块、子单元等可以实现在一个或多个专用集成电路(Application Specific Integrated Circuits,ASIC)、数字信号处理器(Digital Signal Processing,DSP)、数字信号处理设备(DSP Device,DSPD)、可编程逻辑设备(Programmable Logic Device,PLD)、现场可编程门阵列(Field-Programmable Gate Array,FPGA)、通用处理器、控制器、微控制器、微处理器、用于执行本公开所述功能的其它电子单元或其组合中。
显然,本领域的技术人员可以对本公开进行各种改动和变型而不脱离本公开的精神和范围。这样,倘若本公开的这些修改和变型属于本公开权利要求及其等同技术的范围之内,则本公开也意图包含这些改动和变型在内。

Claims (22)

  1. 一种寻址方法,包括:
    核心网设备接收携带有确定或选择出应用程序的身份验证和密钥管理体系结构锚定网元AAnF的寻址信息;
    核心网设备根据所述寻址信息确定或选择出AAnF。
  2. 如权利要求1所述的方法,其中,所述寻址信息是在应用服务器交互应用标识A-KID和/或指示寻址信息的字段中携带的。
  3. 如权利要求1所述的方法,其中,所述寻址信息是终端或鉴权服务功能AUSF在生成A-KID过程中携带的。
  4. 如权利要求1所述的方法,其中,所述寻址信息包括以下信息之一或者其组合:
    AAnF在网络存储功能NRF注册服务的签约永久标识SUPI范围,由AUSF、应用功能AF、或网络开放功能NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
  5. 如权利要求4所述的方法,其中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
  6. 如权利要求4所述的方法,其中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值 确定符合服务范围的AAnF。
  7. 如权利要求6所述的方法,其中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的哈希hash值,或者根据A-KID的hash后几个字符确定的。
  8. 如权利要求4所述的方法,其中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
  9. 如权利要求1至8任一所述的方法,其中,进一步包括:
    从NRF获取AAnF注册在NRF上的网元域名和AAnF标识的对应关系,用以供AAnF的寻址。
  10. 一种寻址信息的生成方法,包括:
    确定AAnF;
    向核心网设备发送携带有确定或者选择出AAnF的寻址信息。
  11. 如权利要求10所述的方法,其中,所述寻址信息是在A-KID和/或指示寻址信息的字段中携带的。
  12. 如权利要求10所述的方法,其中,所述寻址信息是终端或AUSF在生成A-KID过程中携带的。
  13. 如权利要求10所述的方法,其中,所述寻址信息包括以下信息之一或者其组合:
    AAnF在NRF注册服务的SUPI范围,由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围,AAnF在NRF注册服务的A-KID,AAnF在NRF注册服务的A-KID计算值的范围,由AUSF、AF、或NEF配置AAnF服务的A-KID,由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围,AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系。
  14. 如权利要求13所述的方法,其中,所述寻址信息是AAnF在NRF注册服务的SUPI范围,或由AUSF、AF、或NEF配置AAnF服务的SUPI后四位服务范围时,是在A-KID后缀携带的,AAnF标识通过SUPI的后四位标识。
  15. 如权利要求13所述的方法,其中,所述寻址信息是AAnF在NRF注册服务的A-KID,或AAnF在NRF注册服务的A-KID计算值的范围,或由AUSF、AF、或NEF配置AAnF服务的A-KID,或由AUSF、AF、或NEF配置AAnF服务的A-KID计算值的范围时,是根据A-KID或A-KID计算值确定符合服务范围的AAnF。
  16. 如权利要求15所述的方法,其中,根据A-KID或A-KID计算值确定符合服务范围的AAnF,是根据A-KID的最后4个字符串,或者根据A-KID的hash值,或者根据A-KID的hash后几个字符确定的。
  17. 如权利要求13所述的方法,其中,所述寻址信息是AAnF在NRF注册AAnF提供服务的标识,由AUSF、AF、或NEF配置AAnF服务和标识的对应关系时,是根据用户在注册时下发给终端或AUSF的标识或者AAnF服务和标识的对应关系选择符合服务范围的AAnF的。
  18. 一种核心网设备,包括:
    处理器,用于读取存储器中的程序,执行下列过程:
    接收携带有确定或选择出AAnF的寻址信息;
    根据所述寻址信息确定AAnF;
    收发机,用于在处理器的控制下接收和发送数据。
  19. 一种核心网设备,包括:
    核心网设备接收模块,用于接收携带有确定或选择出AAnF的寻址信息;
    核心网设备确定模块,用于根据所述寻址信息确定出AAnF。
  20. 一种通信设备,包括:
    处理器,用于读取存储器中的程序,执行下列过程:
    确定AAnF;
    向核心网设备发送携带有确定或选择出AAnF的寻址信息;
    收发机,用于在处理器的控制下接收和发送数据。
  21. 一种通信设备,包括:
    通信设备确定模块,用于确定AAnF;
    通信设备发送模块,用于向核心网设备发送携带有确定或选择出AAnF的寻址信息。
  22. 一种计算机可读存储介质,所述计算机可读存储介质存储有执行权利要求1至17任一所述方法的计算机程序。
PCT/CN2021/138934 2020-12-18 2021-12-16 一种寻址、寻址信息的生成方法、设备及存储介质 WO2022127879A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202011503479.2 2020-12-18
CN202011503479.2A CN114650534B (zh) 2020-12-18 2020-12-18 一种寻址、寻址信息的生成方法、设备及存储介质

Publications (1)

Publication Number Publication Date
WO2022127879A1 true WO2022127879A1 (zh) 2022-06-23

Family

ID=81990125

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/138934 WO2022127879A1 (zh) 2020-12-18 2021-12-16 一种寻址、寻址信息的生成方法、设备及存储介质

Country Status (2)

Country Link
CN (1) CN114650534B (zh)
WO (1) WO2022127879A1 (zh)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109391914A (zh) * 2017-08-09 2019-02-26 中国移动通信有限公司研究院 一种进行会话寻址的方法和设备
WO2020152087A1 (en) * 2019-01-21 2020-07-30 Telefonaktiebolaget Lm Ericsson (Publ) Key revocation for the authentication and key management for applications feature in 5g

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110048951B (zh) * 2018-01-16 2020-11-27 中国移动通信有限公司研究院 一种pcf寻址方法及装置、设备、存储介质

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109391914A (zh) * 2017-08-09 2019-02-26 中国移动通信有限公司研究院 一种进行会话寻址的方法和设备
WO2020152087A1 (en) * 2019-01-21 2020-07-30 Telefonaktiebolaget Lm Ericsson (Publ) Key revocation for the authentication and key management for applications feature in 5g

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
ERICSSON: "AKMA Anchor Function selection clause", 3GPP DRAFT; S3-203213, vol. SA WG3, 30 October 2020 (2020-10-30), pages 1 - 3, XP051949789 *
ERICSSON: "AKMA Anchor Function selection clause", 3GPP DRAFT; S3-203494, vol. SA WG3, 21 November 2020 (2020-11-21), pages 1 - 3, XP051956961 *
ZTE: "Discussion on the format of A-TID", 3GPP DRAFT; S3-200970, vol. SA WG3, 1 May 2020 (2020-05-01), pages 1 - 2, XP051879670 *

Also Published As

Publication number Publication date
CN114650534A (zh) 2022-06-21
CN114650534B (zh) 2023-08-15

Similar Documents

Publication Publication Date Title
EP3902199A1 (en) Identity check method for network function service, and related device
US10492048B2 (en) Service layer resource propagation across domains
EP3668042B1 (en) Registration method and apparatus based on service-oriented architecture
JP7411774B2 (ja) コアネットワークドメインにおける証明書ハンドリングのための技法
US8452974B2 (en) Image processing apparatus, electronic signature generation system, electronic signature key generation method, image processing method, and program
RU2019116772A (ru) Системы и способы создания универсальной записи
CN101960814B (zh) Ip地址委派
CN108965484A (zh) 一种物联网数据的传输方法、系统及终端
CN110086755B (zh) 实现物联网服务的方法、应用服务器、物联网设备和介质
CN108632216A (zh) 网络功能授权方法、装置、可读存储介质及实体设备
TW200419535A (en) Group judgment device
US20200272446A1 (en) METHOD FOR INTEROPERATING BETWEEN BUNDLE DOWNLOAD PROCESS AND eSIM PROFILE DOWNLOAD PROCESS BY SSP TERMINAL
CN103069742B (zh) 用于将密钥绑定到名称空间的方法和装置
CN109861996B (zh) 基于区块链的关系证明方法、装置、设备及存储介质
US20210081527A1 (en) Service API Invoking Method and Related Apparatus
CN106548043A (zh) 一种应用程序的授权方法、安装方法、安装端及系统
WO2022042417A1 (zh) 认证方法、装置及系统
CN104410635A (zh) 一种基于dane的ndn安全认证方法
WO2022127879A1 (zh) 一种寻址、寻址信息的生成方法、设备及存储介质
WO2019196696A1 (zh) 数字证书处理方法及装置、区块链节点、存储介质
CN112887199B (zh) 网关和云平台及其配置方法、装置、计算机可读存储介质
CN105516134B (zh) 一种系统集成的认证方法及系统
CN113938879A (zh) 一种通信方法及通信装置
CN105453519A (zh) 一种信息安全验证方法及设备
US9043592B1 (en) Communicating trust models to relying parties

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21905805

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 26/09/2023)

122 Ep: pct application non-entry in european phase

Ref document number: 21905805

Country of ref document: EP

Kind code of ref document: A1