WO2025065293A1 - 信息处理方法、终端、接入网设备、通信系统及存储介质 - Google Patents
信息处理方法、终端、接入网设备、通信系统及存储介质 Download PDFInfo
- Publication number
- WO2025065293A1 WO2025065293A1 PCT/CN2023/121800 CN2023121800W WO2025065293A1 WO 2025065293 A1 WO2025065293 A1 WO 2025065293A1 CN 2023121800 W CN2023121800 W CN 2023121800W WO 2025065293 A1 WO2025065293 A1 WO 2025065293A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- network
- terminal
- credential holder
- holder
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/72—Subscriber identity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W40/00—Communication routing or communication path finding
- H04W40/02—Communication route or path selection, e.g. power-based or shortest path routing
- H04W40/22—Communication route or path selection, e.g. power-based or shortest path routing using selective relaying for reaching a BTS [Base Transceiver Station] or an access point
Definitions
- the present disclosure relates to the field of communication technology, and in particular to an information processing method, a terminal, an access network device, a communication system and a storage medium.
- a non-5G-capable over WLAN device can access a public land mobile network (PLMN) or a stand-alone non-public network (SNPN) through a non-3rd Generation Partnership Project (Non-3GPP) approach.
- PLMN public land mobile network
- SNPN stand-alone non-public network
- Non-3GPP non-3rd Generation Partnership Project
- the embodiments of the present disclosure provide an information processing method, a terminal, an access network device, a communication system and a storage medium.
- an embodiment of the present disclosure provides an information processing method, the method comprising:
- the terminal sends first information to the access network device, where the first information includes information related to the first credential holder and/or information related to the first non-public network.
- an embodiment of the present disclosure provides an information processing method, the method comprising:
- the access network device receives first information sent by the terminal, where the first information includes information related to the first certificate holder and/or information related to the first non-public network.
- an embodiment of the present disclosure provides a terminal, wherein the terminal includes:
- the transceiver module is configured to send first information to the access network device, where the first information includes information related to the first certificate holder and/or information related to the first non-public network.
- an embodiment of the present disclosure provides an access network device, wherein the first device includes:
- the transceiver module is configured to receive first information sent by the terminal, where the first information includes information related to the first credential holder and/or information related to the first non-public network.
- an embodiment of the present disclosure provides a terminal, including:
- processors one or more processors
- an embodiment of the present disclosure provides an access network device, including:
- processors one or more processors
- an embodiment of the present disclosure proposes a communication system, comprising a terminal and an access network device, wherein the terminal is configured to implement the information processing method described in the first aspect, and the access network device is configured to implement the information processing method described in the second aspect.
- an embodiment of the present disclosure proposes a storage medium, which stores instructions.
- the instructions When the instructions are executed on a communication device, the communication device executes the information processing method described in the first aspect or the second aspect.
- the access network device can route the message to the correct non-public network, and enable the correct non-public network to route the message to the correct first certificate holder, so that the terminal can reliably achieve non-3GPP access.
- FIG1 is an exemplary schematic diagram of the architecture of a communication system provided according to an embodiment of the present disclosure.
- FIG. 2 is an exemplary interaction diagram of an information processing method provided according to an embodiment of the present disclosure.
- FIG. 3A is a schematic diagram of an exemplary flow chart of an information processing method provided according to an embodiment of the present disclosure.
- FIG. 4A is a schematic diagram of an exemplary flow chart of an information processing method provided according to an embodiment of the present disclosure.
- FIG. 4B is a schematic diagram of an exemplary flow chart of an information processing method provided according to an embodiment of the present disclosure.
- FIG. 4C is a schematic diagram of an exemplary flow chart of an information processing method provided according to an embodiment of the present disclosure.
- FIG. 5 is an exemplary interaction diagram of an information processing method provided according to an embodiment of the present disclosure.
- FIG. 6A is a schematic diagram of an exemplary flow chart of an information processing method provided according to an embodiment of the present disclosure.
- FIG. 6B is a schematic diagram of an exemplary flow chart of an information processing method provided according to an embodiment of the present disclosure.
- FIG. 7A is a schematic diagram of an exemplary structure of a terminal provided according to an embodiment of the present disclosure.
- FIG. 7B is a schematic diagram of an exemplary structure of a network device provided according to an embodiment of the present disclosure.
- FIG8A is a schematic diagram of an exemplary structure of a communication device provided according to an embodiment of the present disclosure.
- FIG8B is a schematic diagram of an exemplary structure of a communication device provided according to an embodiment of the present disclosure.
- the embodiments of the present disclosure provide an information processing method, a terminal, an access network device, a communication system, and a storage medium.
- an embodiment of the present disclosure provides an information processing method, the method comprising:
- the terminal sends first information to the access network device, where the first information includes information related to the first credential holder and/or information related to the first non-public network.
- the terminal may send the first information including the information related to the first credential holder and/or the information related to the first non-public network to the access network device, so that the access network device can reliably route the message (e.g., authentication-related message) to the correct non-public network based on the information related to the first non-public network, and the correct non-public network can route the message to the correct first credential holder based on the information related to the first credential holder.
- the message may be an authentication-related message.
- the first credential holder is any one of the following:
- NPN Non-public network
- a certificate holder based on a Public Land Mobile Network PLMN.
- the access network device can send messages to the corresponding non-public network based on the information related to the above-mentioned first non-public network, and the corresponding non-public network can send messages to the corresponding credential owner based on the information related to the above-mentioned first credential owner, thereby ensuring that the terminal can access the network based on the credential holder.
- the first credential holder is the credential holder based on the AAA server, and the information related to the first credential holder includes: realm information (realm information) of the AAA server.
- the terminal can send the area information of the AAA server so that the access network device can send the message to the corresponding non-public network based on the information related to the above-mentioned first non-public network, and enable the network element or device in the corresponding non-public network to accurately determine the credential holder based on the AAA server according to the area information of the AAA server, and then route the message to the credential holder, thereby ensuring that the terminal can reliably access the network using the credential holder based on the AAA server.
- the first credential holder is the NPN-based credential holder
- the information related to the first credential holder includes at least one of the following:
- the NPN-based credential holder's mobile country code The NPN-based credential holder's mobile country code.
- the terminal can send one or more of the above information of the NPN-based credential holder so that the access network device can send a message to the corresponding non-public network based on the information related to the above-mentioned first non-public network, and enable the network element or device in the corresponding non-public network to determine the NPN-based credential holder according to the above information, and then send the message to the credential holder, thereby ensuring that the terminal can reliably access the network using the NPN-based credential holder.
- the first credential holder is the PLMN-based credential holder
- the information related to the first credential holder includes at least one of the following:
- the PLMN-based certificate holder's Mobile Country Code The PLMN-based certificate holder's Mobile Country Code.
- the terminal can send one or more of the above information of the PLMN-based credential holder so that the access network device sends a message to the corresponding non-public network based on the information related to the above-mentioned first non-public network, and enables the network element or device in the corresponding first non-public network to determine the PLMN-based credential holder according to the above information, and then send the message to the credential holder, thereby ensuring that the terminal can reliably access the network using the PLMN-based credential holder.
- the first non-public network-related information includes at least one of the following:
- the mobile country code of the first non-public network is the mobile country code of the first non-public network.
- the first non-public network is any one of the following:
- the non-public network that the terminal is accessing
- a serving non-public network (serving NPN) of the terminal A serving non-public network (serving NPN) of the terminal;
- a non-public network associated with the first credential holder A non-public network associated with the first credential holder.
- the terminal can enable the access network device to accurately determine the non-public network that the terminal is currently accessing, the terminal's service non-public network, or the non-public network associated with the first credential holder, thereby ensuring that the access network device can send the message to the correct non-public network.
- the non-public network associated with the first credential holder is any one of the following:
- the access network device may also be enabled to determine independent non-public networks associated with different credential holders.
- the terminal is a terminal that does not support 5G over a wireless local area network (non-5G-capable over WLAN device, N5CW device), and the access network device is a trusted wireless local area network access network (trusted WLAN access network, TWAN) device.
- a wireless local area network non-5G-capable over WLAN device, N5CW device
- the access network device is a trusted wireless local area network access network (trusted WLAN access network, TWAN) device.
- the access network device includes devices related to a trusted wireless LAN access point (TWAP) and devices related to a trusted wireless LAN interworking function (TWIF).
- TWAP trusted wireless LAN access point
- TWIF trusted wireless LAN interworking function
- the terminal sends the first information to the access network device, including:
- the terminal sends the first information to the TWIF-related device through the TWAP-related device.
- the first information also includes an indicator, which is used to indicate that the information related to the first certificate holder and/or the information related to the first non-public network is used for trusted non-3GPP access of terminals that do not support 5G on the wireless local area network.
- N5CW devices that do not support 5G on the wireless LAN can access the network through TWAN in a non-3GPP manner, thereby ensuring the communication performance of the N5CW devices.
- an embodiment of the present disclosure provides an information processing method, the method comprising:
- the access network device receives first information sent by the terminal, where the first information includes information related to the first certificate holder and/or information related to the first non-public network.
- the first credential holder is any one of the following:
- a certificate holder based on a Public Land Mobile Network PLMN.
- the first credential holder is the credential holder based on the AAA server, and the information related to the first credential holder includes: realm information (realm information) of the AAA server.
- the first credential holder is the NPN-based credential holder
- the information related to the first credential holder includes at least one of the following:
- the NPN-based credential holder's mobile country code The NPN-based credential holder's mobile country code.
- the first credential holder is the PLMN-based credential holder
- the information related to the first credential holder includes at least one of the following:
- the mobile network code of the PLMN-based certificate holder
- the PLMN-based certificate holder's Mobile Country Code The PLMN-based certificate holder's Mobile Country Code.
- the first non-public network-related information further includes at least one of the following:
- the mobile country code of the first non-public network is the mobile country code of the first non-public network.
- the first non-public network is any one of the following:
- the non-public network that the terminal is accessing
- the service network of the terminal is not a public network
- a non-public network associated with the first credential holder A non-public network associated with the first credential holder.
- the non-public network associated with the first credential holder is any one of the following:
- the method further includes:
- the access network device deletes the information related to the first non-public network in the first information to generate second information.
- the method further includes:
- the access network device sends the second information to the first non-public network.
- the access network device can delete the information related to the first non-public network in the first information, so that the network elements or devices in the first non-public network (such as network functions such as AMF and/or SEAF and/or UDM and/or NSSAAF in the first non-public network) do not need to support decorated NAI, or the network elements or devices in the first non-public network do not need to perform further operations on the first information, which effectively reduces the impact on the information processing of the network equipment and helps to smoothly upgrade the network.
- the network elements or devices in the first non-public network such as network functions such as AMF and/or SEAF and/or UDM and/or NSSAAF in the first non-public network
- the terminal is a terminal that does not support 5G on a wireless local area network
- the access network device is a trusted wireless local area network access network TWAN device.
- the access network device includes a device related to a trusted wireless LAN access point TWAP and a device related to a trusted wireless LAN interaction function TWIF.
- the access network device receives first information sent by a terminal, including:
- the TWIF-related device receives the first information sent by the terminal through the TWAP-related device.
- the first information also includes an indicator, which is used to indicate that the information related to the first certificate holder and/or the information related to the first non-public network is used for trusted non-3GPP access of the terminal.
- an embodiment of the present disclosure provides a terminal, wherein the terminal includes:
- the transceiver module is configured to send first information to the access network device, where the first information includes information related to the first certificate holder and/or information related to the first non-public network.
- an embodiment of the present disclosure provides an access network device, wherein the first device includes:
- the transceiver module is configured to receive first information sent by the terminal, where the first information includes information related to the first credential holder and/or information related to the first non-public network.
- an embodiment of the present disclosure proposes a terminal, which includes: one or more processors; a memory for storing processor-executable instructions; wherein the processor is configured to execute an optional implementation method of the first aspect.
- an embodiment of the present disclosure proposes an access network device, which includes: one or more processors; a memory for storing processor executable instructions; wherein the processor is configured to execute the optional implementation method of the second aspect.
- an embodiment of the present disclosure proposes a communication system, which includes: a terminal and an access network device; wherein the terminal is configured to execute the method described in the optional implementation manner of the first aspect, and the access network device is configured to execute the method described in the optional implementation manner of the second aspect.
- an embodiment of the present disclosure proposes a storage medium, wherein the storage medium stores instructions, and when the instructions are executed on a communication device, the communication device executes the method described in the optional implementation of the first and second aspects.
- an embodiment of the present disclosure proposes a program product.
- the communication device executes the method described in the optional implementation of the first and second aspects.
- an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the optional implementation of the first and second aspects.
- an embodiment of the present disclosure provides a chip or a chip system, wherein the chip or the chip system includes a processing circuit configured to execute the method described in the optional implementation of the first and second aspects above.
- the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method, which will not be repeated here.
- the embodiments of the present disclosure provide information processing methods, terminals, access network devices, communication systems, and storage media.
- the terms information processing method, information sending method, communication method, etc. can be replaced with each other
- the terms information processing device, information sending device, communication device, etc. can be replaced with each other
- the terms information processing system, communication system, etc. can be replaced with each other.
- each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined.
- a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged.
- the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined, for example, some or all of the steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
- elements expressed in the singular form such as “a”, “an”, “the”, “above”, “said”, “aforementioned”, “this”, etc., may mean “one and only one", or “one or more”, “at least one”, etc.
- the noun after the article may be understood as a singular expression or a plural expression.
- plurality refers to two or more.
- the terms "at least one of”, “one or more”, “a plurality of”, “multiple”, etc. can be used interchangeably.
- "at least one of A and B", “A and/or B", “A in one case, B in another case”, “in response to one case A, in response to another case B”, etc. may include the following technical solutions according to the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). When there are more branches such as A, B, C, etc., the above is also similar.
- the recording method of "A or B” may include the following technical solutions according to the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed).
- A A is executed independently of B
- B B is executed independently of A
- execution is selected from A and B (A and B are selectively executed).
- prefixes such as “first” and “second” in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute restrictions on the position, order, priority, quantity or content of the description objects.
- the statement of the description object refers to the description in the context of the claims or embodiments, and should not constitute unnecessary restrictions due to the use of prefixes.
- the description object is a "field”
- the ordinal number before the "field” in the "first field” and the "second field” does not limit the position or order between the "fields”
- the "first” and “second” do not limit whether the "fields” they modify are in the same message, nor do they limit the order of the "first field” and the "second field”.
- the description object is a "level”
- the ordinal number before the "level” in the “first level” and the “second level” does not limit the priority between the "levels”.
- the number of description objects is not limited by the ordinal number, and can be one or more. Taking the "first device” as an example, the number of "devices” can be one or more.
- the objects modified by different prefixes may be the same or different. For example, if the description object is "device”, then the “first device” and the “second device” may be the same device or different devices, and their types may be the same or different. For another example, if the description object is "information”, then the "first information” and the “second information” may be the same information or different information, and their contents may be the same or different.
- “including A”, “comprising A”, “used to indicate A”, and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
- time/frequency refers to the time domain and/or the frequency domain.
- terms such as “greater than”, “greater than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, and “above” can be replaced with each other, and terms such as “less than”, “less than or equal to”, “not greater than”, “less than”, “less than or equal to”, “no more than”, “lower than”, “lower than or equal to”, “not higher than”, and “below” can be replaced with each other.
- devices and the like may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments.
- Terms such as “device”, “equipment”, “device”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, and “subject” may be used interchangeably. Interchangeable.
- network may be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
- terminal In some embodiments, the terms "terminal”, “terminal device”, “user equipment (UE)”, “user terminal” “mobile station (MS)”, “mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client and the like can be used interchangeably.
- the access network device, the core network device, or the network device can be replaced by a terminal.
- the various embodiments of the present disclosure can also be applied to a structure in which the access network device, the core network device, or the network device and the communication between the terminals is replaced by the communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.).
- D2D device-to-device
- V2X vehicle-to-everything
- it can also be set as a structure in which the terminal has all or part of the functions of the access network device.
- terms such as "uplink” and "downlink” can also be replaced by terms corresponding to communication between terminals (for example, "side”).
- uplink channels, downlink channels, etc. can be replaced by side channels
- uplinks, downlinks, etc. can be replaced by side links.
- the terminal may be replaced by an access network device, a core network device, or a network device.
- the access network device, the core network device, or the network device may also be configured to have a structure that has all or part of the functions of the terminal.
- the acquisition of data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
- data, information, etc. may be obtained with the user's consent.
- each element, each row, or each column in the table of the embodiments of the present disclosure may be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns may also be implemented as an independent embodiment.
- FIG1A is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
- a communication system 100 includes a terminal 101 and an access network device 102 .
- the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited to these.
- a mobile phone a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device
- the access network device 102 is, for example, a node or device that accesses a terminal to a wireless network.
- the access network device may include an evolved Node B (eNB), a next generation evolved Node B (ng-eNB), a next generation Node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.
- eNB evolved Node B
- ng-eNB next generation evolved Node B
- gNB next generation Node B
- the technical solution of the present disclosure may be applicable to the Open RAN architecture.
- the interfaces between access network devices or within access network devices involved in the embodiments of the present disclosure may become internal interfaces of Open RAN, and the processes and information interactions between these internal interfaces may be implemented through software or programs.
- the access network device 103 may be composed of a central unit (CU) and a distributed unit (CU).
- the CU-DU structure can be used to split the protocol layer of the access network device, with some functions of the protocol layer being centrally controlled by the CU, and the remaining part or all of the functions of the protocol layer being distributed in the DU, which is centrally controlled by the CU, but is not limited to this.
- the access network device 103 may be a trusted WLAN access network (TWAN) device.
- the access network device includes a trusted WLAN access point (TWAP)-related device and a trusted WLAN interworking function (TWIF)-related device.
- TWAP-related device may be, for example, a base station or a WLAN router.
- TWIF-related device may be, for example, provided as a TWIF network element.
- the terminal 101 is a non-5G-capable over WLAN (N5CW) device on a wireless local area network.
- the terminal 101 can access the NPN through a trusted WLAN using a credential provided by a credential holder.
- the NPN may include an access network device 102 and a core network device.
- the core network device may be a device including a first network element, a second network element, a third network element, a fourth network element, a fifth network element, etc., or may be a plurality of devices or a group of devices, including all or part of the first network element, the second network element, the third network element, the fourth network element, the fifth network element, etc., respectively.
- the network element may be virtual or physical.
- the core network for example, includes at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
- EPC Evolved Packet Core
- 5GCN 5G Core Network
- the first network element is, for example, an authentication management function (AMF) network element.
- AMF authentication management function
- the first network element is, for example, a security anchor function (SEAF) network element.
- SEAF security anchor function
- the second network element is, for example, an authentication service function (AUSF) network element.
- AUSF authentication service function
- the third network element is, for example, a unified data management (UDM) network element.
- UDM unified data management
- the fourth network element is, for example, a network slice-specific authentication and authorization function (NSSAAF) network element.
- NSSAAF network slice-specific authentication and authorization function
- the fifth network element is, for example, an Authentication, Authorization, Accounting (AAA) server.
- AAA Authentication, Authorization, Accounting
- the second network element, the third network element, the fourth network element, and the fifth network element may belong to the certificate holder.
- the second network element and the third network element may be used to construct the credential holder.
- the fifth network element may be used alone to construct the credential holder.
- FIG1B is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
- a communication system 100 may include a terminal 101 , an access network device 102 , a first non-public network 103 , and a first credential holder 104 .
- the terminal 101 may be connected to the access network device 102.
- the terminal 102 may access the first non-public network 103 through the access network device 102.
- the terminal 102 may also access the second network 105 through the access network device 102. It is understood that the access network device 102 may be a device in the first non-public network 103 or a device in the second network 105.
- the access network device 102 includes a TWAP 1021 and a TWIF 1022.
- the TWAP 1021 and the TWIF 1022 can exchange data.
- the terminal 101 can send the first information to the access network device 102.
- the access network device 102 determines that the terminal 101 needs to send authentication-related information to the first non-public network 103, such as the first network element 1031 (such as the AMF network element and/or the SEAF network element) in the first non-public network 103 based on the information related to the first non-public network 103 in the first information.
- the access network device 102 can delete the information related to the first non-public network 103 in the first information, reformat it, and send the reformatted data to the first non-public network 103.
- the terminal 101 may send the first information to the TWIF 1022.
- the terminal 101 sends the first message to the TWIF 1022 via the TWAP 1021.
- the TWIF 1022 may determine that the terminal 101 needs to send the authentication-related information to the first non-public network 103 based on the information related to the first non-public network 103 in the first information.
- a device or network element (e.g., first network element 1031) in the first non-public network 103 may determine that the terminal needs to send a message to the first credential holder 104 based on the information related to the first credential holder 104 in the first information.
- the first non-public network 103 sends a message to the first credential holder 104, such as an AUSF or AAA server in the network where the first credential holder 104 is located, so that the first credential holder 104 authenticates the terminal 101.
- the network where the first credential holder 104 is located and the first non-public network may be in different realms.
- the network where the first credential holder 104 is located may be built based on PLMN, may be built based on NPN, or may be built based on AAA server, which is not limited in the embodiments of the present disclosure.
- the network where the first credential holder 104 is located may be constructed based on an NPN, and the NPN may be a first non-public network or a second non-public network different from the first non-public network, which is not limited in the embodiments of the present disclosure.
- the access network device 102 can not only route authentication-related information to the first non-public network 103, but also route other messages to the first non-public network 103 or the second network 105, such as messages related to the slice information of the terminal 101, etc.
- the present disclosed embodiment does not limit this.
- the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure.
- a person of ordinary skill in the art can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.
- the following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1 , or part of the subject, but are not limited thereto.
- the subjects shown in FIG1 are examples, and the communication system may include all or part of the subjects in FIG1 , or may include other subjects other than FIG1 , and the number and form of the subjects are arbitrary, and the subjects may be physical or virtual, and the connection relationship between the subjects is an example, and the subjects may be connected or disconnected, and the connection may be in any manner, and may be a direct connection or an indirect connection, and may be a wired connection or a wireless connection.
- LTE Long Term Evolution
- LTE-A LTE-Advanced
- LTE-B LTE-Beyond
- SUPER 3G IMT-Advanced
- 4G the fourth generation mobile communication system
- 5G 5G new radio
- FAA Future Radio Access
- RAT New Radio
- NR New Radio
- NX New radio access
- the present invention relates to wireless communication systems such as LTE, Wi-Fi (X), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) network, Device to Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle to Everything (V2X), systems using other communication methods, and next-generation systems expanded based on them.
- PLMN Public Land Mobile Network
- D2D Device to Device
- M2M Machine to Machine
- IoT Internet of Things
- V2X Vehicle to Everything
- systems using other communication methods and next-generation systems expanded based on them.
- next-generation systems expanded based on them.
- a combination of multiple systems for example, a combination of
- the credential holder in order for the N5CW device to access the NPN, the credential holder will use the credential to authenticate the N5CW device and provide the authentication result to the NPN. If the NPN and the credential holder are in different realms, the authentication information of the N5CW should be routed through two different realms (i.e., the NPN realm and the credential holder realm).
- the credential holder itself can be built based on the AAA server, NPN or PLMN, which means that the NPN accessed by the N5CW device can be connected to the NPN or PLMN.
- the information of the N5CW device should be able to be routed to different types of credential holders.
- FIG2 is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG2 , the present disclosure embodiment relates to an information processing method, and the method includes:
- Step S2101 The terminal sends first information to the access network device.
- the first information includes information related to the first credential holder and/or information related to the first non-public network.
- the first information may be constructed by the terminal based on information related to the first credential holder and/or information related to the first non-public network.
- the access network device may be connected to multiple networks, such as multiple non-public networks (NPN).
- NPN non-public networks
- the terminal may access the multiple networks through the access network device.
- the multiple networks include at least the first non-public network.
- the first credential holder and the first non-public network are in different realms.
- the first information is used by the access network device to determine the first non-public network.
- the terminal determines the first non-public network based on information related to the first non-public network.
- the terminal is a non-5G-capable over WLAN (N5CW) device that does not support 5G on a wireless local area network.
- the access network device is a trusted wireless local area network access network (TWAN) device.
- the access network device includes a trusted wireless local area network access point (TWAP)-related device and a trusted wireless local area network interworking function (TWIF)-related device.
- TWAP trusted wireless local area network access point
- TWIF trusted wireless local area network interworking function
- the TWAP-related The TWIF-related device may be, for example, a base station or a WLAN router.
- the TWIF-related device may be provided as a TWIF network element.
- the terminal may hold a certificate provided by the first certificate holder.
- the certificate is used by the first certificate holder to verify the terminal.
- the terminal may determine the first certificate holder based on the certificate.
- the terminal may also determine information related to the first certificate holder based on the certificate.
- the first information is used for trusted non-3GPP access of the terminal.
- the first information is used for trusted wireless local area network access (trusted WLAM access) of the terminal.
- the first information includes an indicator, which is used to indicate the trusted non-3GPP access of the terminal of information related to the first credential holder and/or information related to the first non-public network.
- the terminal sends the first information to the access network device, so that the access network device routes the authentication-related information to the first non-public network based on the first information, and then the non-public network sends the authentication-related information to the first credential holder.
- the first credential holder After the first credential holder and the terminal complete mutual authentication, the first credential holder provides the corresponding key to the non-public network, so that the terminal and the non-public network can be securely connected based on the key, thereby completing the trusted non-3GPP access of the terminal.
- the first information may be a Subscription concealed Identifier (SUCI).
- the first information may be a network access identifier (NAI).
- NAI network access identifier
- the first information may be a decorated network access identifier (NAI).
- the name of the first information is not limited, and may be, for example, "routing indication information", “access authentication information”, “network indication information”, etc., which is not limited in the embodiments of the present disclosure.
- the first credential holder may be created based on an AAA server. Alternatively, the first credential holder may be created based on an NPN. Alternatively, the first credential holder may be created based on a PLMN.
- the first credential holder is any one of the following:
- the certificate held by the terminal may be provided by any of the above certificate holders.
- the terminal has the ability to access the corresponding network through any of the above certificate holders.
- the information related to the first non-public network includes at least one of the following: a network identifier of the first non-public network, such as NID (Network Identifier); a mobile network code of the first non-public network, such as MNC (mobile network code); a mobile country code of the first non-public network, such as MCC (mobile country code).
- NID Network Identifier
- MNC mobile network code
- MCC mobile country code
- the mobile network code of the first non-public network may be 00 or 02, and the mobile country code may be 460.
- the first non-public network is any one of the following: a non-public network being visited by the terminal; a service non-public network of the terminal; a non-public network associated with the first credential holder.
- the first credential holder can be deployed in a variety of ways.
- the first credential holder can be a credential holder using AAA server for primary authentication and authorization.
- the first credential holder can also be a credential holder using UDM and AUSF for primary authentication and authorization.
- the non-public network associated with the first credential holder is any one of the following: an independent non-public network associated with the first credential holder who uses an AAA server for initial authentication and authorization, that is, the independent non-public network is a non-public network connected to the credential holder built based on the AAA server; an independent non-public network associated with the first credential holder who uses UDM and AUSF for initial authentication and authorization, that is, the independent non-public network is a non-public network connected to the credential holder built based on UDM and AUSF.
- the first information may further include terminal identification information.
- the terminal identification information is used to identify the terminal.
- the terminal identification information is used by the access network device to determine that the first information is sent by the terminal.
- the first credential holder is a credential holder based on an AAA server
- the information related to the first credential holder includes: realm information of the AAA server.
- the relevant information of the first credential holder may also include a fully qualified domain name (FQDN) of the AAA server.
- FQDN fully qualified domain name
- the first information can be constructed in the following form: "nai.5gc-nn.AAArealm ⁇ AAArealm>! ⁇ 5G_device_unique_identity>@nai.5gc-nn.nid ⁇ servingNID>.mnc ⁇ servingMNC>.mcc ⁇ servingMCC>.3gppnetwork.org".
- AAArealm represents the area information of the AAA server, for example, it can be the FQDN of the AAA server.
- servingNID The servingMNC and servingMCC represent the NID, MNC and MCC of the first non-public network, respectively.
- ⁇ 5G_device_unique_identity> is used to identify the terminal.
- 5gc-nn indicates that the NAI is used for trusted non-3GPP access of the N5CW terminal.
- the first credential holder is an NPN-based credential holder
- the information related to the first credential holder includes at least one of the following: a network identifier of the NPN-based credential holder; a mobile network code of the NPN-based credential holder; a mobile country code of the NPN-based credential holder.
- the first information can be constructed in the following form: "nai.5gc-nn.nid ⁇ NID_CH>.mnc ⁇ MNC_CH>.mcc ⁇ MCC_CH>.3gppnetwork.org! ⁇ 5G_device_unique_identity>@nai.5gc-nn.nid ⁇ servingNID>.mnc ⁇ servingMNC>.mcc ⁇ servingMCC>.3gppnetwork.org".
- NID_CH, MNC_CH and MCC_CH represent the NID, MNC and MCC of the NPN-based credential holder respectively.
- servingNID, servingMNC and servingMCC represent the NID, MNC and MCC of the first non-public network respectively.
- ⁇ 5G_device_unique_identity> is used to identify the terminal. 5gc-nn indicates that the NAI is used for trusted non-3GPP access of the N5CW terminal.
- the first credential holder is a PLMN-based credential holder
- the information related to the first credential holder includes at least one of the following: a mobile network code of the PLMN-based credential holder; and a mobile country code of the PLMN-based credential holder.
- the first information can be constructed in the following form: "nai.5gc-nn.mnc ⁇ MNC_CH>.mcc ⁇ MCC_CH>.3gppnetwork.org! ⁇ 5G_device_unique_identity>@nai.5gc-nn.nid ⁇ servingNID>.mnc ⁇ servingMNC>.mcc ⁇ servingMCC>.3gppnetwork.org".
- MNC_CH and MCC_CH represent the MNC and MCC of the PLMN-based certificate holder, respectively.
- servingNID, servingMNC and servingMCC represent the NID, MNC and MCC of the first non-public network, respectively.
- ⁇ 5G_device_unique_identity> is used to identify the terminal. 5gc-nn indicates that the NAI is used for trusted non-3GPP access of the N5CW terminal.
- the first information in the above example may not include MNC_CH and/or MCC_CH.
- MNC_CH and MCC_CH and ⁇ 5G_device_unique_identity> may be replaced with an International Mobile Subscriber Identity (IMSI), etc.
- IMSI International Mobile Subscriber Identity
- the access network device receives the first information.
- the access network device determines information related to the first credential holder and/or information related to the first non-public network based on the first information.
- the access network device determines the first non-public network based on the first information.
- Step S2102 The access network device deletes information related to the first non-public network in the first information to obtain second information.
- the access network device deletes the information related to the first non-public network in the first information and reformats it to obtain the second information.
- a TWIF-related device (such as a TWIF network element) deletes the information related to the first non-public network in the first information to obtain the second information.
- a TWIF-related device deletes the information related to the first non-public network in the first information and reformats it to obtain the second information.
- the access network device determines the second information based on the information related to the first credential holder.
- the access network device determines the second information based on the information related to the first credential holder and the terminal identification information.
- the access network device reformats the information related to the first credential holder to obtain the second information.
- the access network device reformats the information related to the first credential holder and the terminal identification information to obtain the second information.
- the second information is an NAI.
- the second information is an NAI different from the first information, for example, the first information may be a first NAI, and the second information may be a second NAI.
- the access network device deletes information related to the first non-public network in the first information and constructs a new NAI.
- the second information may be constructed in the following format: “ ⁇ 5G_device_unique_identity>@nai.5gc-nn.nid ⁇ NID_CH>.mnc ⁇ MNC_CH>.mcc ⁇ MCC_CH>.3gppnetwork.org”.
- the second information may be constructed in the following format: “ ⁇ 5G_device_unique_identity>@nai.5gc-nn.mnc ⁇ MNC_CH>.mcc ⁇ MCC_CH>.3gppnetwork.org”.
- the second information may be constructed in the following format: “ ⁇ 5G_device_unique_identity>@nai.5gc-nn.AAArealm ⁇ AAAArealm>”.
- NID_CH, MNC_CH and MCC_CH respectively represent the NID, MNC and MCC of the first credential holder
- AAAArealm represents the area information of the AAA server
- ⁇ 5G_device_unique_identity> is used to identify the terminal.
- Step S2103 The access network device sends second information to the first non-public network.
- the access network device routes the second information to the first non-public network.
- the first non-public network includes an AMF or SEAF network element, and the access network device routes the second information to the AMF network element or SEAF network element of the first non-public network.
- a TWIF-related device routes the second information to the first non-public network.
- a TWIF-related device routes the second information to the AMF network element or SEAF network element of the first non-public network.
- the first non-public network may further route the second information to the first credential holder.
- the terminal may exchange information with the first credential holder through the first non-public network, thereby enabling the first credential holder to authenticate the terminal.
- the first non-public network such as an AMF network element in the first non-public network, routes the second information to the first credential holder according to information related to the first credential holder.
- the first non-public network routes the second information to an AAA server, PLMN or NPN corresponding to the first credential holder according to information related to the first credential holder.
- the first non-public network routes the second information to an AUSF or AAA server in the network where the first credential holder is located according to information related to the first credential holder.
- the second information is used for routing the message by the first non-public network.
- the second information is used for the first non-public network to route the message to the first credential holder.
- the second information is used to indicate that the first non-public network determines the first credential holder.
- the second information is used to indicate the AAA server, PLMN or NPN corresponding to the first credential holder.
- the first credential holder receives the second information sent by the first non-public network.
- the first credential holder authenticates the terminal according to the second information.
- the AAA server, PLMN or NPN corresponding to the first credential holder receives the second information.
- the AAA server, PLMN or NPN corresponding to the first credential holder authenticates the terminal according to the second information.
- the AUSF network function and/or UDM network function in the network where the first credential holder is located authenticates the terminal according to the second information.
- the AAA server in the network where the first credential holder is located authenticates the terminal according to the second information.
- the second information may be “routing indication information”, “authentication information”, “identity information”, etc.
- the embodiment of the present disclosure does not limit the name of the second information.
- the names of information, etc. are not limited to the names recorded in the embodiments, and terms such as “information”, “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “domain”, “field”, “symbol”, “symbol”, “code element”, “codebook”, “codeword”, “codepoint”, “bit”, “data”, “program”, and “chip” can be used interchangeably.
- radio wireless
- RAN radio access network
- AN access network
- RAN-based and the like
- obtain can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from high levels, obtaining by self-processing, autonomous implementation, etc.
- terms such as “certain”, “preset”, “preset”, “set”, “indicated”, “some”, “any”, and “first” can be interchangeable, and "specific A”, “preset A”, “preset A”, “set A”, “indicated A”, “some A”, “any A”, and “first A” can be interpreted as A pre-defined in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., and can also be interpreted as specific A, some A, any A, or first A, etc., but is not limited to this.
- the determination or judgment can be performed by a value represented by 1 bit (0 or 1), by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited to this.
- the communication method involved in the embodiment of the present disclosure may include at least one of steps S2101 to S2103.
- step S2101 may be implemented as an independent embodiment
- step S2102 may be implemented as an independent embodiment
- step S2103 may be implemented as an independent embodiment
- steps S2101+S2102 may be implemented as an independent embodiment, but are not limited thereto.
- step S2102 and step S2103 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
- step S2101 and step S2103 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
- FIG3A is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG3A , the present disclosure embodiment relates to an information processing method, which is executed by a terminal, and the method includes:
- Step S3101 sending the first information.
- step S3101 can refer to the optional implementation of step S2101 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- the terminal sends the first information to the access network device, but is not limited to this, and the first information may also be sent to other entities.
- the above-mentioned first information is used by the access network device to determine the second information.
- the first information is used by the access network device to send the second information to the first non-public network.
- the access network device sends the second information to the first credential holder through the first non-public network (e.g., the AMF/SEAF network element in the first non-public network).
- the first non-public network e.g., the AMF/SEAF network element in the first non-public network.
- the first information includes first credential holder related information and/or first non-public network related information.
- the first credential holder is any one of the following:
- a certificate holder based on a Public Land Mobile Network PLMN.
- the first credential holder is a credential holder based on an AAA server
- the information related to the first credential holder includes: area information of the AAA server.
- the first credential holder is a NPN-based credential holder
- the information related to the first credential holder includes at least one of the following:
- the mobile country code of the credential holder based on the NPN.
- the first credential holder is a PLMN-based credential holder
- the information related to the first credential holder includes at least one of the following:
- the mobile network code of the certificate holder based on the PLMN The mobile network code of the certificate holder based on the PLMN;
- the mobile country code of the certificate holder based on the PLMN The mobile country code of the certificate holder based on the PLMN.
- the first non-public network-related information includes at least one of the following:
- the mobile country code of the first non-public network is the mobile country code of the first non-public network.
- the first non-public network is any one of the following:
- the non-public network that the terminal is accessing
- the terminal's service is not a public network
- a non-public network associated with the first credential holder A non-public network associated with the first credential holder.
- the non-public network associated with the first credential holder is any of the following:
- the terminal is a terminal on a wireless local area network that does not support 5G
- the access network device is a trusted wireless local area network access network TWAN device.
- the access network device includes a trusted wireless LAN access point TWAP-related device and a trusted wireless LAN interaction function TWIF-related device.
- the terminal sends first information to the access network device, including:
- the terminal sends the first information to the TWIF-related device through the TWAP-related device.
- the first information also includes an indicator, wherein the indicator is used to indicate that the information related to the first credential holder and/or the information related to the first non-public network is used for trusted non-3GPP access of terminals that do not support 5G on the wireless local area network.
- FIG4A is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG4A , the present disclosure embodiment relates to an information processing method, which is executed by an access network device, and the method includes:
- Step S4101 obtaining first information.
- step S4101 can refer to the optional implementation of step S2101 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- the access network device receives the first information sent by the terminal, but is not limited thereto, and may also receive the first information sent by other entities.
- the access network device obtains first information specified by a protocol.
- the access network device obtains the first information from an upper layer(s).
- the access network device performs processing to obtain the first information.
- step S4101 is omitted, and the access network device autonomously implements the function indicated by the first information, or the above function is default or default.
- Step S4102 determine the second information.
- the access network device determines the second information based on the first information.
- the access network device determines the second information based on information related to the first credential holder.
- the access network device determines the second information based on information related to the first credential holder and terminal identification information.
- step S4102 can refer to the optional implementation of step S2102 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4103 sending the second information.
- the access network device sends the second information to the first non-public network, but is not limited thereto, and the second information may also be sent to other entities.
- the access network device sends the second information to the first credential holder via the first non-public network.
- the second information is used by the first credential holder to authenticate the terminal.
- the optional implementation method can refer to other related parts in the embodiment involved in FIG. 2, which will not be repeated here.
- step S4101 may be implemented as an independent embodiment
- step S4102 may be implemented as an independent embodiment
- step S4103 may be implemented as an independent embodiment
- step S4101+S4102 may be implemented as an independent embodiment, but is not limited thereto.
- step S4102 and step S4103 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
- step S4101 and step S4103 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
- FIG4B is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG4B , the present disclosure embodiment relates to an information processing method, which is executed by an access network device. The method includes:
- Step S4201 obtaining first information.
- step S4201 can refer to step S2101 in Figure 2, the optional implementation of step S4101 in Figure 4A, and other related parts in the embodiments involved in Figures 2 and 4A, which will not be repeated here.
- Step S4202 determine the second information.
- step S4202 can refer to the optional implementation of step S2101 in Figure 2, step S4102 in Figure 4A, and other related parts in the embodiments involved in Figures 2 and 4A, which will not be repeated here.
- the communication method involved in the embodiment of the present disclosure may include at least one of step S4201 to step S4202.
- step S4201 may be implemented as an independent embodiment
- step S4202 may be implemented as an independent embodiment.
- step S4201 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
- step S4202 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
- FIG4C is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG4C , the present disclosure embodiment relates to an information processing method, which is executed by an access network device, and the method includes:
- Step S4301 obtaining first information.
- step S4301 can refer to the optional implementation of step S2101 in Figure 2, step S4101 in Figure 4A, step S4201 in Figure 4B, and other related parts in the embodiments involved in Figures 2, 4A, and 4B, which will not be repeated here.
- the first information includes first credential holder related information and/or first non-public network related information.
- the first credential holder is any one of the following:
- a certificate holder based on a Public Land Mobile Network PLMN.
- the first credential holder is a credential holder based on an AAA server
- the information related to the first credential holder includes: area information of the AAA server.
- the first credential holder is a NPN-based credential holder
- the information related to the first credential holder includes at least one of the following:
- the mobile country code of the credential holder based on the NPN.
- the first credential holder is a PLMN-based credential holder
- the information related to the first credential holder includes at least one of the following:
- the mobile network code of the certificate holder based on the PLMN The mobile network code of the certificate holder based on the PLMN;
- the mobile country code of the certificate holder based on the PLMN The mobile country code of the certificate holder based on the PLMN.
- the first non-public network-related information further includes at least one of the following:
- the mobile country code of the first non-public network is the mobile country code of the first non-public network.
- the first non-public network is any one of the following:
- the non-public network that the terminal is accessing
- the terminal's service is not a public network
- a non-public network associated with the first credential holder A non-public network associated with the first credential holder.
- the non-public network associated with the first credential holder is any of the following:
- the method further comprises:
- the access network device deletes the information related to the first non-public network in the first information to generate the second information.
- the method further comprises:
- the access network device sends the second information to the first non-public network.
- the access network device includes a trusted wireless LAN access point TWAP-related device and a trusted wireless LAN interaction function TWIF-related device.
- the access network device receives first information sent by the terminal, including:
- the TWIF-related device receives the first information sent by the terminal through the TWAP-related device.
- the first information further includes an indicator, where the indicator is used to indicate that the first credential holder-related information and/or the first non-public network-related information are used for trusted non-3GPP access of the terminal.
- FIG5 is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG5 , an embodiment of the present disclosure relates to an information processing method, and the method includes:
- Step S5101 The terminal sends first information to the access network device.
- step S5101 can refer to the optional implementation methods of step S2101 in Figure 2, step S3101 in Figure 3A, step S4101 in Figure 4A, step S4201 in Figure 4B, and step S4301 in Figure 4C, as well as other related parts in the embodiments involved in Figures 2, 3A, 4A, 4B, and 4C, which will not be repeated here.
- the above method may include the method described in the above embodiments related to the core network device side, terminal side, etc., which will not be repeated here.
- FIG6A is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG6A , the present disclosure embodiment relates to an information processing method, which is executed by an N5CW device. The method includes:
- Step S6101 the N5CW device builds a decorated NAI.
- a decorated NAI constructed by the N5CW device enables the access network to route authentication information to a credential holder based on an AAA server, PLMN or NPN.
- the N5CW device needs to send a NAI containing NPN realm information and credential holder realm information to TWAN.
- the N5CW device should be able to establish the following NAI:
- NID_CH, MNC_CH and MCC_CH represent the NID, MNC and MCC of the NPN-based credential holder, respectively.
- servingNID, servingMNC and servingMCC represent the NID, MNC and MCC of the NPN serving the N5CW device, respectively.
- the N5CW device should be able to establish the following NAI:
- MNC_CH and MCC_CH represent the MNC and MCC of the PLMN-based credential holder, respectively.
- servingNID, servingMNC and servingMCC represent the NID, MNC and MCC of the NPN serving the N5CW device, respectively.
- the N5CW should be able to establish the following NAI:
- AAArealm indicates the realm information of the AAA server, such as the FQDN of the AAA server.
- servingNID, servingMNC, and servingMCC respectively indicate the NID, MNC, and MCC of the NPN serving the N5CW device.
- Step S6201 the WLAN AN device receives the NAI sent by the N5CW device.
- the WLAN AN device should be able to understand the NAI sent by the N5CW device.
- the format of the NAI is as follows:
- NID_CH, MNC_CH and MCC_CH represent the NID, MNC and MCC of the NPN-based credential holder, respectively.
- servingNID, servingMNC and servingMCC represent the NID, MNC and MCC of the NPN that the N5CW device is accessing, respectively.
- the format of the NAI is as follows:
- MNC_CH and MCC_CH represent the MNC and MCC of the PLMN-based credential holder, respectively.
- servingNID, servingMNC and servingMCC represent the NID, MNC and MCC of the NPN serving the N5CW device, respectively.
- the format of the NAI is as follows:
- the WLAN AN device should be able to delete the information of the NPN serving the N5CW device, reformat the NAI, and construct at least one new NAI as follows:
- the decorated NAI constructed by the N5CW device is sent from the N5CW device to the TWAN, which is shared by multiple NPNs and belongs to multiple NPNs.
- TWAN selects a correct NPN according to the information of the NPN in the decorated NAI, such as the first non-public network in the above embodiment, and then sends the decorated NAI to the AMF of the NPN after removing the NPN information.
- the AMF routes the message to the first credential holder according to the obtained NAI with the NPN information removed.
- the AMF can directly route the message to the AUSF of the first credential holder, or the AMF can directly route the message to the AAA server belonging to the first credential owner, or the AMF can indirectly route the message to the AAA server belonging to the first credential owner through network elements such as AUSF.
- TWAN directly routes the message to the AAA server belonging to the first credential owner according to the information of the first credential owner in the decorated NAI.
- Figure 7A is a schematic diagram of the structure of the terminal proposed in an embodiment of the present disclosure.
- the terminal 7100 may include: at least one of a transceiver module 7101, a processing module 7102, etc.
- the processing module 7102 can be used to construct a first message.
- the above-mentioned transceiver module 7101 is used to send a first message to an access network device, and the first information includes information related to a first credential holder and/or information related to a first non-public network.
- the above-mentioned transceiver module 7101 is used to execute at least one of the communication steps such as sending and/or receiving (for example, step S2101, but not limited to this) performed by the terminal in any of the above methods, which is not included here.
- the processing module 7102 is used to execute other steps (such as constructing the first information, but not limited thereto) executed by the terminal in any of the above methods, which will not be described in detail here.
- FIG7B is a schematic diagram of the structure of the access network device proposed in the embodiment of the present disclosure.
- the access network device 7200 may include: at least one of a transceiver module 7201, a processing module 7202, etc.
- the transceiver module 7201 is used to receive a first message sent by a terminal, wherein the first message includes information related to a first certificate holder and/or information related to a first non-public network.
- the transceiver module 7201 is used to execute at least one of the communication steps such as sending and/or receiving (for example, step S2101, step S2103, but not limited thereto) performed by the access network device in any of the above methods, which will not be repeated here.
- the processing module 7202 is used to execute at least one of the other steps performed by the access network device in any of the above methods (for example, S2102, but not limited thereto), which will not be repeated here.
- the transceiver module may include a sending module and/or a receiving module, and the sending module and the receiving module may be separate or integrated.
- the transceiver module may be interchangeable with the transceiver.
- the processing module can be a module or include multiple submodules.
- the multiple submodules respectively execute all or part of the steps required to be executed by the processing module.
- the processing module can be replaced with the processor.
- FIG8A is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure.
- the communication device 8100 may be an access network device (e.g., an access network device, a core network device, etc.), or a terminal (e.g., a user device, etc.), or a chip, a chip system, or a processor that supports an access network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods.
- the communication device 8100 may be used to implement the method described in the above method embodiment, and the details may refer to the description in the above method embodiment.
- the communication device 8100 further includes one or more transceivers 8102.
- the transceiver 8102 performs at least one of the communication steps such as sending and/or receiving in the above method (for example, step S2101, step S2103, but not limited thereto), and the processor 8101 performs at least one of the other steps (for example, step S2102, but not limited thereto).
- the transceiver may include a receiver and/or a transmitter, and the receiver and the transmitter may be separated or integrated together.
- the terms such as transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, interface, etc. may be replaced with each other, the terms such as transmitter, transmitting unit, transmitter, transmitting circuit, etc. may be replaced with each other, and the terms such as receiver, receiving unit, receiver, receiving circuit, etc. may be replaced with each other.
- the communication device 8100 further includes one or more memories 8103 for storing data.
- the memories 8103 may also be outside the communication device 8100.
- the communication device 8100 may include one or more interface circuits 8104.
- the interface circuit 8104 is connected to the memory 8102, and the interface circuit 8104 may be used to receive data from the memory 8102 or other devices, and may be used to send data to the memory 8102 or other devices.
- the interface circuit 8104 may read the data stored in the memory 8102 and send the data to the processor 8101.
- the communication device 8100 described in the above embodiments may be an access network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8A.
- the communication device may be an independent device or may be part of a larger device.
- FIG. 8B is a schematic diagram of the structure of a chip 8200 provided in an embodiment of the present disclosure.
- the communication device 8100 may be a chip or a chip system
- the chip 8200 includes one or more processors 8201, and the chip 8200 is used to execute any of the above methods.
- the chip 8200 includes one or more processors 8201.
- the chip 8200 is configured to execute any of the above methods.
- the chip 8200 further includes one or more interface circuits 8202.
- the terms such as interface circuit, interface, transceiver pin, etc. can be used interchangeably.
- the chip 8200 further includes one or more memories 8203 for storing data.
- all or part of the memory 8203 can be outside the chip 8200.
- the interface circuit 8202 is connected to the memory 8203, and the interface circuit 8202 can be used to receive data from the memory 8203 or other devices, and the interface circuit 8202 can be used to send data to the memory 8203 or other devices.
- the interface circuit 8202 can read the data stored in the memory 8203 and send the data to the memory 8203. Sent to processor 8201.
- the interface circuit 8202 performs at least one of the communication steps such as sending and/or receiving in the above method (for example, step S2101, step S2103, but not limited thereto).
- the interface circuit 8202 performs the communication steps such as sending and/or receiving in the above method, for example, means that the interface circuit 8202 performs data interaction between the processor 8201, the chip 8200, the memory 8203, or the transceiver device.
- the processor 8201 performs at least one of the other steps (for example, step S2102, but not limited thereto).
- modules and/or devices described in the embodiments such as virtual devices, physical devices, chips, etc. can be combined or separated as needed.
- some or all steps can also be performed by multiple modules and/or devices in collaboration, which is not limited here.
- the present disclosure also proposes a storage medium, on which instructions are stored, and when the instructions are executed on the communication device 8100, the communication device 8100 executes any of the above methods.
- the storage medium is an electronic storage medium.
- the storage medium is a computer-readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices.
- the storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a temporary storage medium.
- the present disclosure also proposes a program product, which, when executed by the communication device 8100, enables the communication device 8100 to execute any of the above methods.
- the program product is a computer program product.
- the present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to execute any one of the above methods.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
一种信息处理方法、终端、接入网设备、通信系统及存储介质,该方法包括:终端向接入网设备发送第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。能够有效地确保接入网设备可以将消息路由至正确的非公共网络,并使得正确的非公共网络可以将消息路由至正确的第一凭证持有者,使得终端能够可靠地实现非3GPP接入。
Description
本公开涉及通信技术领域,尤其涉及信息处理方法、终端、接入网设备、通信系统及存储介质。
无线局域网上不支持5G的设备(non-5G-capable over WLAN device,N5CW device)可以通过非第三代合作伙伴计划(Non-3rd Generation Partnership Project,Non-3GPP)的方式接入公共陆地移动网络(Public Land Mobile Network,PLMN)或独立非公共网络(Stand-alone Non-Public Network,SNPN)。
发明内容
如何确保终端的非3GPP接入的可靠性是亟待解决的问题。
本公开实施例提出了一种信息处理方法、终端、接入网设备、通信系统及存储介质。
第一方面,本公开实施例提出了一种信息处理方法,所述方法包括:
终端向接入网设备发送第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
第二方面,本公开实施例提出了一种信息处理方法,所述方法包括:
接入网设备接收终端发送的第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
第三方面,本公开实施例提出了一种终端,所述终端包括:
收发模块,被配置为向接入网设备发送第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
第四方面,本公开实施例提出了一种接入网设备,所述第一设备包括:
收发模块,被配置为接收终端发送的第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
第五方面,本公开实施例提出了一种终端,包括:
一个或多个处理器;
耦合于所述一个或多个处理器的存储器,所述存储器包括可执行指令,当所述可执行指令被所述一个或多个处理器执行时,使所述终端执行第一方面中所述的信息处理方法。
第六方面,本公开实施例提出了一种接入网设备,包括:
一个或多个处理器;
耦合于所述一个或多个处理器的存储器,所述存储器包括可执行指令,当所述可执行指令被所述一个或多个处理器执行时,使所述接入网设备设备执行第二方面中所述的信息处理方法。
第七方面,本公开实施例提出了一种通信系统,包括终端和接入网设备,其中,所述终端被配置为实现第一方面中所述的信息处理方法,所述接入网设备被配置为实现第二方面中所述的信息处理方法。
第八方面,本公开实施例提出了一种存储介质,所述存储介质存储有指令,当所述指令在通信设备上运行时,使得所述通信设备执行如第一方面或第二方面中所述的信息处理方法。
能够有效地确保接入网设备可以将消息路由至正确的非公共网络,并使得正确的非公共网络可以将消息路由至正确的第一凭证持有者,使得终端能够可靠地实现非3GPP接入。
为了更清楚地说明本公开实施例中的技术方案,以下对实施例描述所需的附图进行介绍,以下附图仅仅是本公开的一些实施例,不对本公开的保护范围造成具体限制。
图1是根据本公开实施例提供的通信系统的架构的一个示例性示意图。
图2是根据本公开实施例提供的信息处理方法的一个示例性交互示意图。
图3A是根据本公开实施例提供的信息处理方法的一个示例性流程示意图。
图4A是根据本公开实施例提供的信息处理方法的一个示例性流程示意图。
图4B是根据本公开实施例提供的信息处理方法的一个示例性流程示意图。
图4C是根据本公开实施例提供的信息处理方法的一个示例性流程示意图。
图5是根据本公开实施例提供的信息处理方法的一个示例性交互示意图。
图6A是根据本公开实施例提供的信息处理方法的一个示例性流程示意图。
图6B是根据本公开实施例提供的信息处理方法的一个示例性流程示意图。
图7A是根据本公开实施例提供的终端的一个示例性结构示意图。
图7B是根据本公开实施例提供的网络设备的一个示例性结构示意图。
图8A是根据本公开实施例提供的通信设备的一个示例性结构示意图。
图8B是根据本公开实施例提供的通信设备的一个示例性结构示意图。
本公开实施例提出了信息处理方法、终端、接入网设备、通信系统及存储介质。
第一方面,本公开实施例提出了一种信息处理方法,所述方法包括:
终端向接入网设备发送第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
在上述实施例中,终端可以向接入网设备发送包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息的第一信息,可以使得接入网设备可以可靠地基于第一非公共网络相关的信息,将消息(例如认证相关的消息)路由(route)至正确的非公共网络,并使得正确的非公共网络可以基于第一凭证持有者相关的信息将消息路由(route)至正确的第一凭证持有者。所述消息可以是与认证相关的消息。
结合第一方面的一些实施例,在一些实施例中,所述第一凭证持有者为以下任意一者:
基于验证、授权和记账(authentication,authorization and accounting,AAA)服务器的凭证持有者;
基于非公共网络(non-public network,NPN)的凭证持有者;
基于公共陆地移动网络PLMN的凭证持有者。
在上述实施例中,可以使得接入网设备能够基于上述第一非公共网络相关的信息,将消息发送至对应的非公共网络,并使得对应的非公共网络可以基于上述第一凭证所有者相关的信息,将消息发送至对应的凭证所有者,确保了终端能够基于凭证持有者接入网络。
结合第一方面的一些实施例,在一些实施例中,所述第一凭证持有者为所述基于AAA服务器的凭证持有者,所述第一凭证持有者相关的信息包括:所述AAA服务器的区域信息(realm information)。
在上述实施例中,终端可以通过发送AAA服务器的区域信息,使得接入网设备能够基于上述第一非公共网络相关的信息,将消息发送至对应的非公共网络,并使得对应的非公共网络中的网元或设备能够根据该AAA服务器的区域信息准确地确定基于AAA服务器的凭证持有者,进而将消息路由(route)至该凭证持有者,确保了终端能够利用基于AAA服务器的凭证持有者可靠地接入网络。
结合第一方面的一些实施例,在一些实施例中,所述第一凭证持有者为所述基于NPN的凭证持有者,所述第一凭证持有者相关的信息包括以下至少一者:
所述基于NPN的凭证持有者的网络标识;
所述基于NPN的凭证持有者的移动网络代码;
所述基于NPN的凭证持有者的移动国家代码。
在上述实施例中,终端可以通过发送基于NPN的凭证持有者的上述信息中的一者或多者,使得接入网设备能够基于上述第一非公共网络相关的信息,将消息发送至对应的非公共网络,并使得对应的非公共网络中的网元或设备能够根据上述信息确定基于NPN的凭证持有者,进而将消息发送至该凭证持有者,确保了终端能够利用基于NPN的凭证持有者可靠地接入网络。
结合第一方面的一些实施例,在一些实施例中,所述第一凭证持有者为所述基于PLMN的凭证持有者,所述第一凭证持有者相关的信息包括以下至少一者:
所述基于PLMN的凭证持有者的移动网络代码;
所述基于PLMN的凭证持有者的移动国家代码。
在上述实施例中,终端可以通过发送基于PLMN的凭证持有者的上述信息中的一者或多者,使得接入网设备基于上述第一非公共网络相关的信息,将消息发送至对应的非公共网络,并使得对应的第一非公共网络中的网元或设备能够根据上述信息确定基于PLMN的凭证持有者,进而将消息发送至该凭证持有者,确保了终端能够利用基于PLMN的凭证持有者可靠地接入网络。
结合第一方面的一些实施例,在一些实施例中,所述第一非公共网络相关的信息包括以下至少一者:
所述第一非公共网络的网络标识;
所述第一非公共网络的移动网络代码;
所述第一非公共网络的移动国家代码。
结合第一方面的一些实施例,在一些实施例中,所述第一非公共网络为以下任意一者:
所述终端正在访问的非公共网络;
所述终端的服务非公共网络(serving NPN);
与所述第一凭证持有者相关联的非公共网络。
在上述实施例中,终端通过发送第一非公共网络相关的上述信息中的至少一者,可以使得接入网设备准确地确定终端目前正在访问的非公共网络、终端的服务非公共网络或者与第一凭证持有者相关联的非公共网络,进而确保了接入网设备能够将消息发送至正确的非公共网络。
结合第一方面的一些实施例,在一些实施例中,所述与所述第一凭证持有者相关联的非公共网络为以下任意一者:
与使用AAA服务器进行初始认证与授权的第一凭证持有者相关联的独立非公共网络(SNPN with Credentials Holder using AAA Server for primary authentication and authorization);
与使用统一数据管理(unified data management,UDM)和鉴权服务功能(Authentication Server Function,AUSF)进行初始认证与授权的第一凭证持有者相关联的独立非公共网络(SNPN with Credentials Holder using AUSF and UDM for primary authentication and authorization)。
在上述实施例中,还可以使得接入网设备能够确定与不同的凭证持有者相关联的独立非公共网络。
结合第一方面的一些实施例,在一些实施例中,所述终端为无线局域网上不支持5G的终端(non-5G-capable over WLAN device,N5CW device),所述接入网设备为可信无线局域网接入网(trusted wlan access network,TWAN)设备。
结合第一方面的一些实施例,在一些实施例中,所述接入网设备包括可信的无线局域网接入点(trusted wlan access point,TWAP)相关的设备和可信无线局域网交互功能(trusted wlan interworking function,TWIF)相关的设备。
结合第一方面的一些实施例,在一些实施例中,所述终端向接入网设备发送第一信息,包括:
所述终端通过所述TWAP相关的设备,向所述TWIF相关的设备发送所述第一信息。
结合第一方面的一些实施例,在一些实施例中,所述第一信息还包括指示符,所述指示符用于指示所述第一凭证持有者相关的信息和/或所述第一非公共网络相关的信息用于无线局域网上不支持5G的终端的可信非3GPP接入。
在上述实施例中,可以使得无线局域网上不支持5G的N5CW设备能够通过TWAN以非3GPP的方式接入网络,确保了N5CW设备的通信性能。
第二方面,本公开实施例提出了一种信息处理方法,所述方法包括:
接入网设备接收终端发送的第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
结合第二方面的一些实施例,在一些实施例中,所述第一凭证持有者为以下任意一者:
基于验证、授权和记账AAA服务器的凭证持有者;
基于非公共网络NPN的凭证持有者;
基于公共陆地移动网络PLMN的凭证持有者。
结合第二方面的一些实施例,在一些实施例中,所述第一凭证持有者为所述基于AAA服务器的凭证持有者,所述第一凭证持有者相关的信息包括:所述AAA服务器的区域信息(realm information)。
结合第二方面的一些实施例,在一些实施例中,所述第一凭证持有者为所述基于NPN的凭证持有者,所述第一凭证持有者相关的信息包括以下至少一者:
所述基于NPN的凭证持有者的网络标识;
所述基于NPN的凭证持有者的移动网络代码;
所述基于NPN的凭证持有者的移动国家代码。
结合第二方面的一些实施例,在一些实施例中,所述第一凭证持有者为所述基于PLMN的凭证持有者,所述第一凭证持有者相关的信息包括以下至少一者:
所述基于PLMN的凭证持有者的移动网络代码;
所述基于PLMN的凭证持有者的移动国家代码。
结合第二方面的一些实施例,在一些实施例中,所述第一非公共网络相关的信息还包括以下至少一者:
第一非公共网络的网络标识;
所述第一非公共网络的移动网络代码;
所述第一非公共网络的移动国家代码。
结合第二方面的一些实施例,在一些实施例中,所述第一非公共网络为以下任意一者:
所述终端正在访问的非公共网络;
所述终端的服务非公共网络;
与所述第一凭证持有者相关联的非公共网络。
结合第二方面的一些实施例,在一些实施例中,所述与所述第一凭证持有者相关联的非公共网络为以下任意一者:
与使用AAA服务器进行初始认证与授权的第一凭证持有者相关联的独立非公共网络;
与使用UDM和AUSF进行初始认证与授权的第一凭证持有者相关联的独立非公共网络。
结合第二方面的一些实施例,在一些实施例中,所述方法还包括:
所述接入网设备删除所述第一信息中所述第一非公共网络相关的信息以生成第二信息。
结合第二方面的一些实施例,在一些实施例中,所述方法还包括:
所述接入网设备将所述第二信息发送至所述第一非公共网络。
在上述实施例中,接入网设备可以将第一信息中与第一非公共网络相关的信息删除,使得第一非公共网络中的网元或设备(例如第一非公共网络中的AMF和/或SEAF和/或UDM和/或NSSAAF等网络功能)无需支持decorated NAI,或者使得第一非公共网络中的网元或设备无需对第一信息进行进一步的操作,有效地减少了对于网络设备信息处理的影响,有助于网络平滑升级。
结合第二方面的一些实施例,在一些实施例中,所述终端为无线局域网上不支持5G的终端,所述接入网设备为可信无线局域网接入网TWAN设备。
结合第二方面的一些实施例,在一些实施例中,所述接入网设备包括可信的无线局域网接入点TWAP相关的设备和可信无线局域网交互功能TWIF相关的设备。
结合第二方面的一些实施例,在一些实施例中,所述接入网设备接收终端发送的第一信息,包括:
所述TWIF相关的设备通过所述TWAP相关的设备,接收所述终端发送的第一信息。
结合第二方面的一些实施例,在一些实施例中,所述第一信息还包括指示符,所述指示符用于指示所述第一凭证持有者相关的信息和/或所述第一非公共网络相关的信息用于所述终端的可信非3GPP接入。
第三方面,本公开实施例提出了一种终端,所述终端包括:
收发模块,被配置为向接入网设备发送第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
第四方面,本公开实施例提出了一种接入网设备,所述第一设备包括:
收发模块,被配置为接收终端发送的第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
第五方面,本公开实施例提出了终端,上述终端包括:一个或多个处理器;用于存储处理器可执行指令的存储器;其中,所述处理器被配置为执行第一方面的可选实现方式。
第六方面,本公开实施例提出了接入网设备,上述接入网设备包括:一个或多个处理器;用于存储处理器可执行指令的存储器;其中,所述处理器被配置为执行第二方面的可选实现方式。
第七方面,本公开实施例提出了通信系统,上述通信系统包括:终端、接入网设备;其中,上述终端被配置为执行如第一方面的可选实现方式所描述的方法,上述接入网设备被配置为执行如第二方面的可选实现方式所描述的方法。
第八方面,本公开实施例提出了存储介质,上述存储介质存储有指令,当上述指令在通信设备上运行时,使得上述通信设备执行如第一方面和第二方面的可选实现方式所描述的方法。
第九方面,本公开实施例提出了程序产品,上述程序产品被通信设备执行时,使得上述通信设备执行如第一方面和第二方面的可选实现方式所描述的方法。
第十方面,本公开实施例提出了计算机程序,当其在计算机上运行时,使得计算机执行如第一方面和第二方面的可选实现方式所描述的方法。
第十一方面,本公开实施例提供了一种芯片或芯片系统。该芯片或芯片系统包括处理电路,被配置为执行根据上述第一方面和第二方面的可选实现方式所描述的方法。
可以理解地,上述终端、接入网设备、通信系统、存储介质、程序产品、计算机程序、芯片或芯片系统均用于执行本公开实施例所提出的方法。因此,其所能达到的有益效果可以参考对应方法中的有益效果,此处不再赘述。
本公开实施例提出了信息处理方法、终端、接入网设备、通信系统及存储介质。在一些实施例中,信息处理方法与信息发送方法、通信方法等术语可以相互替换,信息处理装置与信息发送装置、通信装置等术语可以相互替换,信息处理系统、通信系统等术语可以相互替换。
本公开实施例并非穷举,仅为部分实施例的示意,不作为对本公开保护范围的具体限制。在不矛盾的情况下,某一实施例中的每个步骤均可以作为独立实施例来实施,且各步骤之间可以任意组合,例如,在某一实施例中去除部分步骤后的方案也可以作为独立实施例来实施,且在某一实施例中各步骤的顺序可以任意交换,另外,某一实施例中的可选实现方式可以任意组合;此外,各实施例之间可以任意组合,例如,不同实施例的部分或全部步骤可以任意组合,某一实施例可以与其他实施例的可选实现方式任意组合。
在各本公开实施例中,如果没有特殊说明以及逻辑冲突,各实施例之间的术语和/或描述具有一致性,且可以互相引用,不同实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
本公开实施例中所使用的术语只是为了描述特定实施例的目的,而并非作为对本公开的限制。
在本公开实施例中,除非另有说明,以单数形式表示的元素,如“一个”、“一种”、“该”、“上述”、“所述”、“前述”、“这一”等,可以表示“一个且只有一个”,也可以表示“一个或多个”、“至少一个”等。例如,在翻译中使用如英语中的“a”、“an”、“the”等冠词(article)的情况下,冠词之后的名词可以理解为单数表达形式,也可以理解为复数表达形式。
在本公开实施例中,“多个”是指两个或两个以上。
在一些实施例中,“至少一者(至少一项、至少一个)(at least one of)”、“一个或多个(one or more)”、“多个(a plurality of)”、“多个(multiple)等术语可以相互替换。
在一些实施例中,“A、B中的至少一者”、“A和/或B”、“在一情况下A,在另一情况下B”、“响应于一情况A,响应于另一情况B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行);在一些实施例中A和B(A和B都被执行)。当有A、B、C等更多分支时也类似上述。
在一些实施例中,“A或B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行)。当有A、B、C等更多分支时也类似上述。
本公开实施例中的“第一”、“第二”等前缀词,仅仅为了区分不同的描述对象,不对描述对象的位置、顺序、优先级、数量或内容等构成限制,对描述对象的陈述参见权利要求或实施例中上下文的描述,不应因为使用前缀词而构成多余的限制。例如,描述对象为“字段”,则“第一字段”和“第二字段”中“字段”之前的序数词并不限制“字段”之间的位置或顺序,“第一”和“第二”并不限制其修饰的“字段”是否在同一个消息中,也不限制“第一字段”和“第二字段”的先后顺序。再如,描述对象为“等级”,则“第一等级”和“第二等级”中“等级”之前的序数词并不限制“等级”之间的优先级。再如,描述对象的数量并不受序数词的限制,可以是一个或者多个,以“第一装置”为例,其中“装置”的数量可以是一个或者多个。此外,不同前缀词修饰的对象可以相同或不同,例如,描述对象为“装置”,则“第一装置”和“第二装置”可以是相同的装置或者不同的装置,其类型可以相同或不同;再如,描述对象为“信息”,则“第一信息”和“第二信息”可以是相同的信息或者不同的信息,其内容可以相同或不同。
在一些实施例中,“包括A”、“包含A”、“用于指示A”、“携带A”,可以解释为直接携带A,也可以解释为间接指示A。
在一些实施例中,“时频(time/frequency)”、“时频域”等术语是指时域和/或频域。
在一些实施例中,“响应于……”、“响应于确定……”、“在……的情况下”、“在……时”、“当……时”、“若……”、“如果……”等术语可以相互替换。
在一些实施例中,“大于”、“大于或等于”、“不小于”、“多于”、“多于或等于”、“不少于”、“高于”、“高于或等于”、“不低于”、“以上”等术语可以相互替换,“小于”、“小于或等于”、“不大于”、“少于”、“少于或等于”、“不多于”、“低于”、“低于或等于”、“不高于”、“以下”等术语可以相互替换。
在一些实施例中,装置等可以解释为实体的、也可以解释为虚拟的,其名称不限定于实施例中所记载的名称,“装置”、“设备(equipment)”、“设备(device)”、“电路”、“网元”、“节点”、“功能”、“单元”、“部件(section)”、“系统”、“网络”、“芯片”、“芯片系统”、“实体”、“主体”等术语可以相
互替换。
在一些实施例中,“网络”可以解释为网络中包含的装置(例如,接入网设备、核心网设备等)。
在一些实施例中,“接入网设备(access network device,AN device)”、“无线接入网设备(radio access network device,RAN device)”、“基站(base station,BS)”、“无线基站(radio base station)”、“固定台(fixed station)”、“节点(node)”、“接入点(access point)”、“发送点(transmission point,TP)”、“接收点(reception point,RP)”、“发送和/或接收点(transmission/reception point,TRP)”、“面板(panel)”、“天线面板(antenna panel)”、“天线阵列(antenna array)”、“小区(cell)”、“宏小区(macro cell)”、“小型小区(small cell)”、“毫微微小区(femto cell)”、“微微小区(pico cell)”、“扇区(sector)”、“小区组(cell group)”、“服务小区”、“载波(carrier)”、“分量载波(component carrier)”、“带宽部分(bandwidth part,BWP)”等术语可以相互替换。
在一些实施例中,“终端(terminal)”、“终端设备(terminal device)”、“用户设备(user equipment,UE)”、“用户终端(user terminal)”、“移动台(mobile station,MS)”、“移动终端(mobile terminal,MT)”、订户站(subscriber station)、移动单元(mobile unit)、订户单元(subscriber unit)、无线单元(wireless unit)、远程单元(remote unit)、移动设备(mobile device)、无线设备(wireless device)、无线通信设备(wireless communication device)、远程设备(remote device)、移动订户站(mobile subscriber station)、接入终端(access terminal)、移动终端(mobile terminal)、无线终端(wireless terminal)、远程终端(remote terminal)、手持设备(handset)、用户代理(user agent)、移动客户端(mobile client)、客户端(client)等术语可以相互替换。
在一些实施例中,接入网设备、核心网设备、或网络设备可以被替换为终端。例如,针对将接入网设备、核心网设备、或网络设备以及终端间的通信置换为多个终端间的通信(例如,设备对设备(device-to-device,D2D)、车联网(vehicle-to-everything,V2X)等)的结构,也可以应用本公开的各实施例。在该情况下,也可以设为终端具有接入网设备所具有的全部或部分功能的结构。此外,“上行”、“下行”等术语也可以被替换为与终端间通信对应的术语(例如,“侧行(side)”)。例如,上行信道、下行信道等可以被替换为侧行信道,上行链路、下行链路等可以被替换为侧行链路。
在一些实施例中,终端可以被替换为接入网设备、核心网设备、或网络设备。在该情况下,也可以设为接入网设备、核心网设备、或网络设备具有终端所具有的全部或部分功能的结构。
在一些实施例中,获取数据、信息等可以遵照所在地国家的法律法规。
在一些实施例中,可以在得到用户同意后获取数据、信息等。
此外,本公开实施例的表格中的每一元素、每一行、或每一列均可以作为独立实施例来实施,任意元素、任意行、任意列的组合也可以作为独立实施例来实施。
图1A是根据本公开实施例示出的通信系统的架构示意图。如图1A所示,通信系统100包括终端(terminal)101、接入网设备102。
在一些实施例中,终端101例如包括手机(mobile phone)、可穿戴设备、物联网设备、具备通信功能的汽车、智能汽车、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、工业控制(industrial control)中的无线终端设备、无人驾驶(self-driving)中的无线终端设备、远程手术(remote medical surgery)中的无线终端设备、智能电网(smart grid)中的无线终端设备、运输安全(transportation safety)中的无线终端设备、智慧城市(smart city)中的无线终端设备、智慧家庭(smart home)中的无线终端设备中的至少一者,但不限于此。
在一些实施例中,接入网设备102例如是将终端接入到无线网络的节点或设备,接入网设备可以包括5G通信系统中的演进节点B(evolved NodeB,eNB)、下一代演进节点B(next generation eNB,ng-eNB)、下一代节点B(next generation NodeB,gNB)、节点B(node B,NB)、家庭节点B(home node B,HNB)、家庭演进节点B(home evolved nodeB,HeNB)、无线回传设备、无线网络控制器(radio network controller,RNC)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、基带单元(base band unit,BBU)、移动交换中心、6G通信系统中的基站、开放型基站(Open RAN)、云基站(Cloud RAN)、其他通信系统中的基站、Wi-Fi系统中的接入节点中的至少一者,但不限于此。
在一些实施例中,本公开的技术方案可适用于Open RAN架构,此时,本公开实施例所涉及的接入网设备间或者接入网设备内的接口可变为Open RAN的内部接口,这些内部接口之间的流程和信息交互可以通过软件或者程序实现。
在一些实施例中,接入网设备103可以由集中单元(central unit,CU)与分布式单元(distributed
unit,DU)组成的,其中,CU也可以称为控制单元(control unit),采用CU-DU的结构可以将接入网设备的协议层拆分开,部分协议层的功能放在CU集中控制,剩下部分或全部协议层的功能分布在DU中,由CU集中控制DU,但不限于此。
在一些实施例中,接入网设备103可以是可信无线局域网接入网(trusted wlan access network,TWAN)设备。可选地,接入网设备包括可信无线局域网接入点(trusted WLAN access point,TWAP)相关的设备和可信无线局域网交互功能(trusted WLAN interworking function,TWIF)相关的设备。可选地,TWAP相关的设备例如可以是基站或者WLAN路由器等设备。可选地,TWIF相关的设备例如可以被提供为TWIF网元。
在一些实施例中,终端101是无线局域网上不支持5G(non-5G-capable over WLAN,N5CW)设备。可选地,终端101可以使用凭证持有者提供的凭证,通过可信WLAN接入NPN。可选地,NPN中可以包括接入网设备102与核心网设备。可选地,核心网设备可以是一个设备,包括第一网元、第二网元、第三网元、第四网元、第五网元等,也可以是多个设备或设备群,分别包括第一网元、第二网元、第三网元、第四网元、第五网元等中的全部或部分。网元可以是虚拟的,也可以是实体的。核心网例如包括演进分组核心(Evolved Packet Core,EPC)、5G核心网络(5G Core Network,5GCN)、下一代核心(Next Generation Core,NGC)中的至少一者。
在一些实施例中,第一网元例如是认证管理功能(authentication management function,AMF)网元。
在另一些实施例中,第一网元例如是安全锚点功能(Security Anchor Function,SEAF)网元。
在一些实施例中,第二网元例如是鉴权服务功能(Authentication Server Function,AUSF)网元。
在一些实施例中,第三网元例如是统一数据管理(Unified Data Management,UDM)网元
在一些实施例中,第四网元例如是网络切片选择的认证和授权功能(Network Slice-Specific Authentication and Authorization Function,NSSAAF)网元。
在一些实施例中,第五网元例如是验证、授权和记账(Authentication、Authorization、Accounting,AAA)服务器。
在一些实施例中,第二网元、第三网元、第四网元与第五网元可以属于凭证持有者。
在一些实施例中,第二网元与第三网元可以用于构建凭证持有者。可选地,第五网元可以单独用于构建凭证持有者。
图1B是根据本公开实施例示出的通信系统的架构示意图。如图1B所示,通信系统100可以包括终端101、接入网设备102、第一非公共网络103以及第一凭证持有者104。
参照图1B所示,终端101可以与接入网设备102连接。可选地,终端102可以通过接入网设备102接入第一非公共网络103。在一些实施例中,终端102还可以通过接入网设备102接入第二网络105。可以理解的是,上述接入网设备102可以是第一非公共网络103中的设备,也可以是第二网络105中的设备。
在一些实施例中,接入网设备102包括TWAP 1021与TWIF1022。可选地,TWAP 1021与TWIF 1022能够进行数据交互。
在一些实施例中,终端101若想要接入第一网络102,则需要第一凭证持有者104对其进行认证。可选地,终端101可以向接入网设备102发送第一信息。可选地,接入网设备102根据第一信息中的第一非公共网络103相关的信息确定终端101需要将认证相关的信息发送至第一非公共网络103,例如第一非公共网络103中的第一网元1031(如AMF网元和/或SEAF网元)。可选地,接入网设备102可以将第一信息中与第一非公共网络103相关的信息删除后进行重新格式化,并将重新格式化后的数据发送至第一非公共网络103。
在一些实施例中,终端101可以向TWIF 1022发送第一信息。可选地,终端101通过TWAP 1021向TWIF 1022发送第一消息。可选地,TWIF 1022可以根据第一信息中根据第一信息中的第一非公共网络103相关的信息确定终端101需要将认证相关的信息发送至第一非公共网络103。
可选地,第一非公共网络103中的设备或网元(例如第一网元1031)可以根据第一信息中与第一凭证持有者104相关的信息确定终端需要将消息发送至第一凭证持有者104。可选地,第一非公共网络103将消息发送至第一凭证持有者104,例如第一凭证持有者104所处的网络中的AUSF或者AAA服务器,以使得第一凭证持有者104对终端101进行认证。可选地,第一凭证持有者104所处的网络与第一非公共网络可以处于不同的领域(realm)。可选地,第一凭证持有者104所处的网络可以是基于PLMN构建的,也可以是基于NPN构建的,或者也可以是基于AAA服务器构建的,本公开实施例对此不作限定。
在一些实施例中,第一凭证持有者104所处的网络可以是基于NPN构建的,该NPN可以是第一非公开网络,也可以是区别于该第一非公开网络的第二非公开网络,本公开实施例对此不作限定。
值得说明的是,在上述实施例中,仅是以终端101认证的过程作为示例,接入网设备102不仅可以将认证相关的信息路由至第一非公共网络103,还可以将其他消息路由至第一非公共网络103或者第二网络105,例如终端101切片信息相关的消息等等,本公开实施例对此不作限定。
可以理解的是,本公开实施例描述的通信系统是为了更加清楚的说明本公开实施例的技术方案,并不构成对于本公开实施例提出的技术方案的限定,本领域普通技术人员可知,随着系统架构的演变和新业务场景的出现,本公开实施例提出的技术方案对于类似的技术问题同样适用。
下述本公开实施例可以应用于图1所示的通信系统100、或部分主体,但不限于此。图1所示的各主体是例示,通信系统可以包括图1中的全部或部分主体,也可以包括图1以外的其他主体,各主体数量和形态为任意,各主体可以是实体的也可以是虚拟的,各主体之间的连接关系是例示,各主体之间可以不连接也可以连接,其连接可以是任意方式,可以是直接连接也可以是间接连接,可以是有线连接也可以是无线连接。
本公开各实施例可以应用于长期演进(Long Term Evolution,LTE)、LTE-Advanced(LTE-A)、LTE-Beyond(LTE-B)、SUPER 3G、IMT-Advanced、第四代移动通信系统(4th generation mobile communication system,4G)、)、第五代移动通信系统(5th generation mobile communication system,5G)、5G新空口(new radio,NR)、未来无线接入(Future Radio Access,FRA)、新无线接入技术(New-Radio Access Technology,RAT)、新无线(New Radio,NR)、新无线接入(New radio access,NX)、未来一代无线接入(Future generation radio access,FX)、Global System for Mobile communications(GSM(注册商标))、CDMA2000、超移动宽带(Ultra Mobile Broadband,UMB)、IEEE 802.11(Wi-Fi(注册商标))、IEEE 802.16(WiMAX(注册商标))、IEEE 802.20、超宽带(Ultra-WideBand,UWB)、蓝牙(Bluetooth(注册商标))、陆上公用移动通信网(Public Land Mobile Network,PLMN)网络、设备到设备(Device-to-Device,D2D)系统、机器到机器(Machine to Machine,M2M)系统、物联网(Internet of Things,IoT)系统、车联网(Vehicle-to-Everything,V2X)、利用其他通信方法的系统、基于它们而扩展的下一代系统等。此外,也可以将多个系统组合(例如,LTE或者LTE-A与5G的组合等)应用。
在一些实施例中,为使N5CW设备能够访问NPN,凭证持有者将使用凭证对N5CW设备进行验证,并将验证结果提供给NPN。如NPN和凭证持有者位于不同领域(realm),N5CW的认证信息应通过两个不同领域(即NPN领域和凭证持有者领域)进行路由。
在一些实施例中,可信无线局域网接入点(TWAP)可能连接多个NPN,为使TWAP能将信息路由到正确的NPN,N5CW设备需要向TWAN发送包含NPN领域和凭证持有者领域的NAI。
在一些实施例中,凭证持有者本身可基于AAA服务器、NPN或者PLMN构建,这表明N5CW设备访问的NPN可连接到NPN或PLMN。换句话说,N5CW设备的信息应能路由到不同类型的凭证持有者。
图2是根据本公开实施例示出的信息处理方法的交互示意图。如图2所示,本公开实施例涉及信息处理方法,上述方法包括:
步骤S2101,终端向接入网设备发送第一信息。
在一些实施例中,第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。可选地,第一信息可以是终端根据第一凭证持有者相关的信息和/或第一非公共网络相关的信息构建得到的。在一些实施例中,接入网设备可以连接多个网络,如多个非公共网络(non-public network,NPN)。可选地,终端可以通过该接入网设备接入该多个网络。可选地,多个网络至少包括第一非公共网络。可选地,第一凭证持有者与第一非公共网络处于不同的领域(realm)。可选地,第一信息用于接入网设备确定第一非公共网络。可选地,终端根据第一非公共网络相关的信息确定第一非公共网络。
在一些实施例中,第一消息用于接入网设备进行消息的路由。可选地,第一信息包括该消息。可选地,该消息例如可以是认证相关的信息。可选地,第一消息用于接入网设备将认证相关的消息路由至相应的第一非公共网络。
在一些实施例中,终端为无线局域网上不支持5G(non-5G-capable over WLAN,N5CW)设备。可选地,接入网设备为可信无线局域网接入网(trusted wlan access network,TWAN)设备。可选地,接入网设备包括可信的无线局域网接入点(trusted WLAN access point,TWAP)相关的设备和可信无线局域网交互功能(trusted WLAN interworking function,TWIF)相关的设备。可选地,TWAP相
关的设备例如可以是基站或者WLAN路由器等设备。可选地,TWIF相关的设备例如可以被提供为TWIF网元。
在一些实施例中,终端可以持有第一凭证持有者提供的凭证。可选地,该凭证用于第一凭证持有者对终端进行验证。可选地,终端可以根据该凭证确定第一凭证持有者。可选地,终端还可以根据该凭证确定第一凭证持有者相关的信息。
在一些实施例中,可选地,第一信息用于终端的可信非3GPP接入(trusted non-3GPP access)。可选地,第一信息用于终端的可信无线局域网接入(trusted WLAM access)。可选地,第一信息包括指示符,该指示符用于指示第一凭证持有者相关的信息和/或第一非公共网络相关的信息终端的可信非3GPP接入。示例地,终端将第一信息发送至接入网设备,使得接入网设备基于第一信息将认证相关的信息路由至第一非公共网络,进而使得非公共网络将认证相关的信息发送至第一凭证持有者,第一凭证持有者与终端完成相互认证之后,第一凭证持有者向非公共网络提供相应的密钥,使得终端与非公共网络能够基于该密钥进行安全连接,进而完成终端的可信非3GPP接入。
在一些实施例中,第一信息可以是用户隐藏标识符(Subscriptionconcealed Identifier,SUCI)。可选地,第一信息可以是网络接入标识符(network access identifier,NAI)。可选地,第一信息可以是装饰的网络接入标识符(decorated network access identifier,decorated NAI)。在一些实施例中,第一信息的名称不做限定,其例如可以是“路由指示信息”、“接入认证信息”、“网络指示信息”等,本公开实施例对此不作限定。
在一些实施例中,第一凭证持有者可以是基于AAA服务器创建的。可选地,第一凭证持有者可以是基于NPN创建的。可选地,第一凭证持有者可以是基于PLMN创建的。
在一些实施例中,第一凭证持有者为以下任意一者:
基于验证、授权和记账AAA服务器的凭证持有者(AAA server based Credentials Holder);
基于非公共网络NPN的凭证持有者(NPN based Credentials Holder);
基于公共陆地移动网络PLMN的凭证持有者(PLMN based Credentials Holder)。
可选地,终端持有的凭证可以是上述任意一个凭证持有者提供的。可选地,终端具备沟通过上述任意一个凭证持有者接入相应的网络的能力。
在一些实施例中,第一非公共网络相关的信息包括以下至少一者:第一非公共网络的网络标识,如NID(Network Identifier);第一非公共网络的移动网络代码,如MNC(mobile network code);第一非公共网络的移动国家代码,如MCC(mobile country code)。
示例地,若第一非公共网络是中国移动提供的网络,则该第一非公共网络的移动网络代码可以是00或02,移动国家代码可以是460。
在一些实施例中,所述第一非公共网络为以下任意一者:终端正在访问的非公共网络;终端的服务非公共网络;与第一凭证持有者相关联的非公共网络。
在一些实施例中,第一凭证持有者可以由多种方式部署得到。第一凭证持有者可以是使用AAA服务器进行初始认证与授权的凭证持有者(Credentials Holder using AAA Server for primary authentication and authorization)。可选地,第一凭证持有者也可以是使用UDM和AUSF进行初始认证与授权的凭证持有者(Credentials Holder using AUSF and UDM for primary authentication and authorization)。
在一些实施例中,与第一凭证持有者相关联的非公共网络为以下任意一者:与使用AAA服务器进行初始认证与授权的第一凭证持有者相关联的独立非公共网络,即所述独立非公共网络是与基于AAA服务器构建的凭证持有者相连接的非公共网络;与使用UDM和AUSF进行初始认证与授权的第一凭证持有者相关联的独立非公共网络,即所述独立非公共网络是与基于UDM和AUSF构建的凭证持有者相连接的非公共网络。
在一些实施例中,第一信息还可以包括终端标识信息。可选地,终端标识信息用于标识该终端。可选地,终端标识信息用于接入网设备确定第一信息是由该终端发送的。
在一些实施例中,第一凭证持有者为基于AAA服务器的凭证持有者,第一凭证持有者相关的信息包括:AAA服务器的区域信息(realm information)。可选地,第一凭证持有者的相关信息还可以包括AAA服务器的完全限定域名(fully qualified domain name,FQDN)。
示例地,以第一信息为decorated NAI为例,第一信息可以被构建为以下形式:"nai.5gc-nn.AAArealm<AAArealm>!<5G_device_unique_identity>@nai.5gc-nn.nid<servingNID>.mnc<servingMNC>.mcc<servingMCC>.3gppnetwork.org"。
其中,AAArealm表示AAA服务器的区域信息,例如可以是AAA服务器的FQDN。servingNID、
servingMNC和servingMCC分别表示第一非公共网络的NID、MNC和MCC。<5G_device_unique_identity>用于标识该终端。5gc-nn指示所述NAI用于N5CW终端的可信非3GPP接入。在一些实施例中,第一凭证持有者为基于NPN的凭证持有者,第一凭证持有者相关的信息包括以下至少一者:基于NPN的凭证持有者的网络标识;基于NPN的凭证持有者的移动网络代码;基于NPN的凭证持有者的移动国家代码。
示例地,以第一信息为decorated NAI为例,第一信息可以被构建为以下形式:"nai.5gc-nn.nid<NID_CH>.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org!<5G_device_unique_identity>@nai.5gc-nn.nid<servingNID>.mnc<servingMNC>.mcc<servingMCC>.3gppnetwork.org"。
其中,NID_CH、MNC_CH和MCC_CH分别表示基于NPN的凭证持有者的NID、MNC和MCC。servingNID、servingMNC和servingMCC分别表示第一非公共网络的NID、MNC和MCC。<5G_device_unique_identity>用于标识该终端。5gc-nn指示所述NAI用于N5CW终端的可信非3GPP接入。
在一些实施例中,第一凭证持有者为基于PLMN的凭证持有者,第一凭证持有者相关的信息包括以下至少一者:基于PLMN的凭证持有者的移动网络代码;基于PLMN的凭证持有者的移动国家代码。
示例地,以第一信息为decorated NAI为例,第一信息可以被构建为以下形式:"nai.5gc-nn.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org!<5G_device_unique_identity>@nai.5gc-nn.nid<servingNID>.mnc<servingMNC>.mcc<servingMCC>.3gppnetwork.org"。
其中,MNC_CH和MCC_CH分别表示基于PLMN的凭证持有者的MNC和MCC。servingNID、servingMNC和servingMCC分别表示第一非公共网络的NID、MNC和MCC。<5G_device_unique_identity>用于标识该终端。5gc-nn指示所述NAI用于N5CW终端的可信非3GPP接入。
可以理解是,在上述示例中的第一信息中,部分信息可以缺省或替换。例如,在第一凭证持有者为基于NPN的凭证持有者的情况下,第一信息可以不包括MNC_CH和/或MCC_CH。在第一凭证持有者为基于PLMN的凭证持有者的情况下,MNC_CH和MCC_CH以及<5G_device_unique_identity>可以被替换为国际移动用户识别码(International Mobile Subscriber Identity,IMSI)等等。本公开实施例对此不作限定。
在一些实施例中,接入网设备接收第一信息。可选地,接入网设备根据第一信息确定第一凭证持有者相关的信息和/或第一非公共网络相关的信息。可选地,接入网设备根据第一信息确定第一非公共网络。
步骤S2102,接入网设备删除第一信息中与第一非公共网络相关的信息得到第二信息。
在一些实施例中,接入网设备删除第一信息中第一非公共网络相关的信息并进行重新格式化得到第二信息。可选地,TWIF相关的设备(如TWIF网元)删除第一信息中第一非公共网络相关的信息得到第二信息。可选地,TWIF相关的设备删除第一信息中第一非公共网络相关的信息并进行重新格式化得到第二信息。
在一些实施例中,接入网设备根据第一凭证持有者相关的信息确定第二信息。可选地,接入网设备根据第一凭证持有者相关的信息以及终端标识信息确定第二信息。可选地,接入网设备对第一凭证持有者相关的信息重新格式化得到第二信息。可选地,接入网设备根据第一凭证持有者相关的信息以及终端标识信息重新格式化得到第二信息。
在一些实施例中,第二信息为NAI。可选地,第二信息为区别于第一信息的NAI,例如,第一信息可以是第一NAI,第二信息可以是第二NAI。可选地,接入网设删除第一信息中与第一非公共网络相关的信息并构建新的NAI。
示例地,若第一凭证持有者为基于NPN的凭证持有者,第二信息可以被构建为以下形式:“<5G_device_unique_identity>@nai.5gc-nn.nid<NID_CH>.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org”。
若第一凭证持有者为基于PLMN的凭证持有者,第二信息可以被构建为以下形式:“<5G_device_unique_identity>@nai.5gc-nn.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org”。
若第一凭证持有者为基于AAA服务器的凭证持有者,第二信息可以被构建为以下形式:“<5G_device_unique_identity>@nai.5gc-nn.AAArealm<AAAArealm>”。
其中,NID_CH、MNC_CH和MCC_CH分别表示第一凭证持有者的NID、MNC和MCC,AAAArealm表示AAA服务器的区域信息,<5G_device_unique_identity>用于标识该终端。
步骤S2103,接入网设备向第一非公共网络发送第二信息。
在一些实施例中,接入网设备将第二信息路由至第一非公共网络。可选地,第一非公共网络包括AMF或SEAF网元,接入网设备将第二信息路由至第一非公共网络的AMF网元或SEAF网元。可选地,TWIF相关的设备将第二信息路由至第一非公共网络。可选地,TWIF相关的设备将第二信息路由至第一非公共网络的AMF网元或SEAF网元。
在一些实施例中,第一非公共网络可以进一步将第二信息路由至第一凭证持有者。可选地,终端可以通过第一非公共网络与第一凭证持有者进行信息交互,进而实现第一凭证持有者对终端的认证。
可选地,第一非公共网络,例如第一非公共网络中的AMF网元,根据第一凭证持有者相关的信息,将第二信息路由至第一凭证持有者。可选地,第一非公共网络根据第一凭证持有者相关的信息,将第二信息路由至第一凭证持有者对应的AAA服务器、PLMN或者NPN。可选地,第一非公共网络根据第一凭证持有者相关的信息,将第二信息路由至第一凭证持有者所处的网络中的AUSF或者AAA服务器。
在一些实施例中,第二信息用于第一非公共网络进行消息的路由。可选地,第二信息用于第一非公共网络将消息路由至第一凭证持有者。可选地,第二信息用于指示第一非公共网络确定第一凭证持有者。可选地,第二信息用于指示第一凭证持有者对应的AAA服务器、PLMN或者NPN。
在一些实施例中,第一凭证持有者接收第一非公共网络发送的第二信息。可选地,第一凭证持有者根据第二信息对终端进行认证。可选地,第一凭证持有者对应的AAA服务器、PLMN或者NPN接收第二信息。可选地,第一凭证持有者对应的AAA服务器、PLMN或者NPN根据第二信息对终端进行认证。示例地,第一凭证持有者所处的网络中的AUSF网络功能和\或UDM网络功能根据第二信息对终端进行认证。示例地,第一凭证持有者所处的网络中的AAA服务器根据第二信息对终端进行认证。
在一些实施例中,第二信息可以是“路由指示信息”、“认证信息”、“身份信息”等,本公开实施例对第二信息的名称不作限定。
在一些实施例中,信息等的名称不限定于实施例中所记载的名称,“信息(information)”、“消息(message)”、“信号(signal)”、“信令(signaling)”、“报告(report)”、“配置(configuration)”、“指示(indication)”、“指令(instruction)”、“命令(command)”、“信道”、“参数(parameter)”、“域”、“字段”、“符号(symbol)”、“码元(symbol)”、“码本(codebook)”、“码字(codeword)”、“码点(codepoint)”、“比特(bit)”、“数据(data)”、“程序(program)”、“码片(chip)”等术语可以相互替换。
在一些实施例中,“无线(radio)”、“无线(wireless)”、“无线接入网(radio access network,RAN)”、“接入网(access network,AN)”、“基于RAN的(RAN-based)”等术语可以相互替换。
在一些实施例中,“获取”、“获得”、“得到”、“接收”、“传输”、“双向传输”、“发送和/或接收”可以相互替换,其可以解释为从其他主体接收,从协议中获取,从高层获取,自身处理得到、自主实现等多种含义。
在一些实施例中,“发送”、“发射”、“上报”、“下发”、“传输”、“双向传输”、“发送和/或接收”等术语可以相互替换。
在一些实施例中,“特定(certain)”、“预定(preseted)”、“预设”、“设定”、“指示(indicated)”、“某一”、“任意”、“第一”等术语可以相互替换,“特定A”、“预定A”、“预设A”、“设定A”、“指示A”、“某一A”、“任意A”、“第一A”可以解释为在协议等中预先规定的A,也可以解释为通过设定、配置、或指示等得到的A,也可以解释为特定A、某一A、任意A、或第一A等,但不限于此。
在一些实施例中,判定或判断可以通过以1比特表示的值(0或1)来进行,也可以通过以真(true)或者假(false)表示的真假值(布尔值(boolean))来进行,也可以通过数值的比较(例如,与预定值的比较)来进行,但不限于此。
本公开实施例所涉及的通信方法可以包括步骤S2101~步骤S2103中的至少一者。例如,步骤S2101可以作为独立实施例来实施,步骤S2102可以作为独立实施例来实施,步骤S2103可以作为独立实施例来实施,步骤S2101+S2102可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S2102与步骤S2103是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S2101与步骤S2103是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,可参见图2所对应的说明书之前或之后记载的其他可选实现方式。
图3A是根据本公开实施例示出的信息处理方法的流程示意图。如图3A所示,本公开实施例涉及信息处理方法,由终端执行,上述方法包括:
步骤S3101,发送第一信息。
步骤S3101的可选实现方式可以参见图2的步骤S2101的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,终端向接入网设备发送第一信息,但不限于此,也可以向其他主体发送第一信息。
可选地,上述第一信息用于接入网设备确定第二信息。可选地,第一信息用于接入网设备将第二信息发送至第一非公共网络。可选地,接入网设备通过第一非公共网络(例如第一非公共网络中的AMF/SEAF网元)将第二信息发送至第一凭证持有者。其可选实现方式可以参见图2的步骤S2102和/或步骤S2103的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
在一些实施例中,第一凭证持有者为以下任意一者:
基于验证、授权和记账AAA服务器的凭证持有者;
基于非公共网络NPN的凭证持有者;
基于公共陆地移动网络PLMN的凭证持有者。
在一些实施例中,第一凭证持有者为基于AAA服务器的凭证持有者,第一凭证持有者相关的信息包括:AAA服务器的区域信息。
在一些实施例中,第一凭证持有者为基于NPN的凭证持有者,第一凭证持有者相关的信息包括以下至少一者:
基于NPN的凭证持有者的网络标识;
基于NPN的凭证持有者的移动网络代码;
基于NPN的凭证持有者的移动国家代码。
在一些实施例中,第一凭证持有者为基于PLMN的凭证持有者,第一凭证持有者相关的信息包括以下至少一者:
基于PLMN的凭证持有者的移动网络代码;
基于PLMN的凭证持有者的移动国家代码。
在一些实施例中,第一非公共网络相关的信息包括以下至少一者:
第一非公共网络的网络标识;
第一非公共网络的移动网络代码;
第一非公共网络的移动国家代码。
在一些实施例中,第一非公共网络为以下任意一者:
终端正在访问的非公共网络;
终端的服务非公共网络;
与第一凭证持有者相关联的非公共网络。
在一些实施例中,与第一凭证持有者相关联的非公共网络为以下任意一者:
与使用AAA服务器进行初始认证与授权的第一凭证持有者相关联的独立非公共网络;
与使用UDM和AUSF进行初始认证与授权的第一凭证持有者相关联的独立非公共网络。
在一些实施例中,终端为无线局域网上不支持5G的终端,接入网设备为可信无线局域网接入网TWAN设备。
在一些实施例中,接入网设备包括可信的无线局域网接入点TWAP相关的设备和可信无线局域网交互功能TWIF相关的设备。
在一些实施例中,终端向接入网设备发送第一信息,包括:
终端通过TWAP相关的设备,向TWIF相关的设备发送所述第一信息。
在一些实施例中,第一信息还包括指示符,指示符用于指示第一凭证持有者相关的信息和/或第一非公共网络相关的信息用于无线局域网上不支持5G的终端的可信非3GPP接入。
图4A是根据本公开实施例示出的信息处理方法的流程示意图。如图4A所示,本公开实施例涉及信息处理方法,由接入网设备执行,上述方法包括:
步骤S4101,获取第一信息。
步骤S4101的可选实现方式可以参见图2的步骤S2101的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,接入网设备接收由终端发送的第一信息,但不限于此,也可以接收由其他主体发送的第一信息。
在一些实施例中,接入网设备获取由协议规定的第一信息。
在一些实施例中,接入网设备从高层(upper layer(s))获取第一信息。
在一些实施例中,接入网设备进行处理从而得到第一信息。
在一些实施例中,步骤S4101被省略,接入网设备自主实现第一信息所指示的功能,或上述功能为缺省或默认。
步骤S4102,确定第二信息。
在一些实施例中,接入网设备根据第一信息确定第二信息。可选地,接入网设备根据第一凭证持有者相关的信息确定第二信息。可选地,接入网设备根据第一凭证持有者相关的信息以及终端标识信息确定第二信息。
步骤S4102的可选实现方式可以参见图2的步骤S2102的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4103,发送第二信息。
在一些实施例中,接入网设备向所述第一非公共网络发送第二信息,但不限于此,也可以向其他主体发送第二信息。可选地,接入网设备通过第一非公共网络向第一凭证持有者发送第二信息。
可选地,上述第二信息用于第一凭证持有者对终端进行认证。其可选实现方式可以参见图2所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的通信方法可以包括步骤S4101~步骤S4103中的至少一者。例如,步骤S4101可以作为独立实施例来实施,步骤S4102可以作为独立实施例来实施,步骤S4103可以作为独立实施例来实施,步骤S4101+S4102可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S4102与步骤S4103是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S4101与步骤S4103是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
图4B是根据本公开实施例示出的信息处理方法的流程示意图。如图4B所示,本公开实施例涉及信息处理方法,由接入网设备执行,上述方法包括:
步骤S4201,获取第一信息。
步骤S4201的可选实现方式可以参见图2的步骤S2101、图4A的步骤S4101的可选实现方式、及图2、图4A所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4202,确定第二信息。
步骤S4202的可选实现方式可以参见图2的步骤S2101、图4A的步骤S4102的可选实现方式、及图2、图4A所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的通信方法可以包括步骤S4201~步骤S4202中的至少一者。例如,步骤S4201可以作为独立实施例来实施,步骤S4202可以作为独立实施例来实施。
在一些实施例中,步骤S4201是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S4202是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
图4C是根据本公开实施例示出的信息处理方法的流程示意图。如图4C所示,本公开实施例涉及信息处理方法,由接入网设备执行,上述方法包括:
步骤S4301,获取第一信息。
步骤S4301的可选实现方式可以参见图2的步骤S2101、图4A的步骤S4101、图4B的步骤S4201的可选实现方式、及图2、图4A、图4B所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
在一些实施例中,第一凭证持有者为以下任意一者:
基于验证、授权和记账AAA服务器的凭证持有者;
基于非公共网络NPN的凭证持有者;
基于公共陆地移动网络PLMN的凭证持有者。
在一些实施例中,第一凭证持有者为基于AAA服务器的凭证持有者,第一凭证持有者相关的信息包括:AAA服务器的区域信息。
在一些实施例中,第一凭证持有者为基于NPN的凭证持有者,第一凭证持有者相关的信息包括以下至少一者:
基于NPN的凭证持有者的网络标识;
基于NPN的凭证持有者的移动网络代码;
基于NPN的凭证持有者的移动国家代码。
在一些实施例中,第一凭证持有者为基于PLMN的凭证持有者,第一凭证持有者相关的信息包括以下至少一者:
基于PLMN的凭证持有者的移动网络代码;
基于PLMN的凭证持有者的移动国家代码。
在一些实施例中,第一非公共网络相关的信息还包括以下至少一者:
第一非公共网络的网络标识;
第一非公共网络的移动网络代码;
第一非公共网络的移动国家代码。
在一些实施例中,第一非公共网络为以下任意一者:
终端正在访问的非公共网络;
终端的服务非公共网络;
与第一凭证持有者相关联的非公共网络。
在一些实施例中,与第一凭证持有者相关联的非公共网络为以下任意一者:
与使用AAA服务器进行初始认证与授权的第一凭证持有者相关联的独立非公共网络;
与使用UDM和AUSF进行初始认证与授权的第一凭证持有者相关联的独立非公共网络。
在一些实施例中,该方法还包括:
接入网设备删除第一信息中第一非公共网络相关的信息以生成第二信息。
在一些实施例中,该方法还包括:
接入网设备将第二信息发送至第一非公共网络。
在一些实施例中,终端为无线局域网上不支持5G的终端,接入网设备为可信无线局域网接入网TWAN设备。
在一些实施例中,接入网设备包括可信的无线局域网接入点TWAP相关的设备和可信无线局域网交互功能TWIF相关的设备。
在一些实施例中,接入网设备接收终端发送的第一信息,包括:
TWIF相关的设备通过TWAP相关的设备,接收终端发送的第一信息。
在一些实施例中,第一信息还包括指示符,指示符用于指示第一凭证持有者相关的信息和/或第一非公共网络相关的信息用于终端的可信非3GPP接入。
图5是根据本公开实施例示出的信息处理方法的交互示意图。如图5所示,本公开实施例涉及信息处理方法,上述方法包括:
步骤S5101,终端向接入网设备发送第一信息。
步骤S5101的可选实现方式可以参见图2的步骤S2101、图3A的步骤S3101、图4A的步骤S4101、图4B的步骤S4201、图4C的步骤S4301的可选实现方式、及图2、图3A、图4A、图4B、图4C所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,上述方法可以包括上述与核心网设备侧、终端侧等的实施例所述的方法,此处不再赘述。
图6A是根据本公开实施例示出的信息处理方法的流程示意图。如图6A所示,本公开实施例涉及信息处理方法,由N5CW设备执行,上述方法包括:
步骤S6101,N5CW设备构建decorated NAI。
可选地,N5CW设备构建的decorated NAI可使接入网络将认证信息路由至基于AAA服务器、PLMN或NPN的凭证持有者。
在一些实施例中,考虑到TWAN可能连接多个NPN,为使TWAN能将信息路由到正确的NPN,N5CW设备需要向TWAN发送包含NPN领域信息(realm information)和凭证持有者领域信息(realm information)的NAI。
在一些实施例中,要将信息路由至基于NPN的凭证持有者,N5CW设备应能建立以下NAI:
"nai.5gc-nn.nid<NID_CH>.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org!<5G_device_unique_identity>@nai.5gc-nn.nid<servingNID>.mnc<servingMNC>.mcc<servingMCC>.3gppnetwork.org"。
其中,NID_CH、MNC_CH和MCC_CH分别表示基于NPN的凭证持有者的NID、MNC和MCC。servingNID、servingMNC和servingMCC分别表示为N5CW设备服务的NPN的NID、MNC和MCC。
在一些实施例中,要将信息路由至基于PLMN的凭证持有者,N5CW设备应能建立以下NAI:
"nai.5gc-nn.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org!<5G_device_unique_identity>@nai.5gc-nn.nid<servingNID>.mnc<servingMNC>.mcc<servingMCC>.3gppnetwork.org"。
其中,MNC_CH和MCC_CH分别表示基于PLMN的凭证持有者的MNC和MCC。servingNID、servingMNC和servingMCC分别表示为N5CW设备服务的NPN的NID、MNC和MCC。
在一些实施例中,要将信息路由至基于AAA的凭证持有者,N5CW应能建立以下NAI:
"nai.5gc-nn.AAArealm<AAArealm>!<5G_device_unique_identity>@nai.5gc-nn.nid<servingNID>.mnc<servingMNC>.mcc<servingMCC>.3gppnetwork.org"。
其中,AAArealm表示AAA服务器的区域信息,如AAA服务器的FQDN。servingNID、servingMNC和servingMCC分别表示为N5CW设备服务的NPN的NID、MNC和MCC。
图6B是根据本公开实施例示出的信息处理方法的流程示意图。如图6B所示,本公开实施例涉及信息处理方法,由无线局域网接入网(Wireless local area network access network,WLAN AN)设备执行,上述方法包括:
步骤S6201,WLAN AN设备接收N5CW设备发送的NAI。
在一些实施例中,WLAN AN设备应能理解N5CW设备发送的NAI。
在一些实施例中,NAI的格式如下:
"nai.5gc-nn.nid<NID_CH>.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org!<5G_device_unique_identity>@nai.5gc-nn.nid<NID>.mnc<MNC>.mcc<MCC>.3gppnetwork.org"。
其中,NID_CH、MNC_CH和MCC_CH分别表示基于NPN的凭证持有者的NID、MNC和MCC。servingNID、servingMNC和servingMCC分别表示N5CW设备正在访问的NPN的NID、MNC和MCC。
在一些实施例中,NAI的格式如下:
"nai.5gc-nn.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org!<5G_device_unique_identity>@nai.5gc-nn.nid<NID>.mnc<MNC>.mcc<MCC>.3gppnetwork.org"。
其中,MNC_CH和MCC_CH分别表示基于PLMN的凭证持有者的MNC和MCC。servingNID、servingMNC和servingMCC分别表示为N5CW设备服务的NPN的NID、MNC和MCC。
在一些实施例中,NAI的格式如下:
"nai.5gc-nn.AAArealm<AAArealm>!<5G_device_unique_identity>@nai.5gc-nn.nid<NID>.mnc<MNC>.mcc<MCC>.3gppnetwork.org"。
其中,AAArealm表示AAA服务器的区域信息,如AAA服务器的FQDN。servingNID、servingMNC和servingMCC分别表示为N5CW服务的NPN的NID、MNC和MCC。
在一些实施例中,WLAN AN设备应能删除为N5CW设备服务的NPN的信息,并对NAI进行重新格式化,并构建如下至少一种新的NAI:
<5G_device_unique_identity>@nai.5gc-nn.nid<NID_CH>.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org;
<5G_device_unique_identity>@nai.5gc-nn.mnc<MNC_CH>.mcc<MCC_CH>.3gppnetwork.org;
<5G_device_unique_identity>@nai.5gc-nn.AAArealm<AAAArealm>。
在一示例中,N5CW设备构建得到的decorated NAI从N5CW设备发送到TWAN,该TWAN同时被多个NPN共享,其归属于多个NPN。
可选地,TWAN根据decorated NAI中的NPN的信息选择正确的NPN,例如上述实施例中的第一非公共网络,然后将decorated NAI去除NPN信息之后发送到所述NPN的AMF,AMF根据得到的去除NPN信息的NAI,将消息路由至第一凭证持有者处,例如AMF可以直接将消息路由至第一凭证持有者的AUSF,或者AMF可以直接将消息路由至归属于第一凭证所有者的AAA服务器或者AMF可以间接通过AUSF等网元将消息路由至归属于第一凭证所有者的AAA服务器。可选地,TWAN根据decorated NAI中的第一凭证所有者信息直接将消息路由至归属于第一凭证所有者的AAA服务器。
图7A是本公开实施例提出的终端的结构示意图。如图7A所示,终端7100可以包括:收发模块7101、处理模块7102等中的至少一者。在一些实施例中,处理模型7102可以用于构建第一信息。在一些实施例中,上述收发模块7101用于向接入网设备发送第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。可选地,上述收发模块7101用于执行以上任一方法中终端执行的发送和/或接收等通信步骤(例如步骤S2101,但不限于此)中的至少一者,此处不
再赘述。可选地,上述处理模块7102用于执行以上任一方法中终端执行的其他步骤(例如构建第一信息,但不限于此),此处不再赘述。
图7B是本公开实施例提出的接入网设备的结构示意图。如图7B所示,接入网设备7200可以包括:收发模块7201、处理模块7202等中的至少一者。在一些实施例中,上述收发模块7201用于接收终端发送的第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。可选地,上述收发模块7201用于执行以上任一方法中接入网设备执行的发送和/或接收等通信步骤(例如步骤S2101、步骤S2103,但不限于此)中的至少一者,此处不再赘述。可选地,上述处理模块7202用于执行以上任一方法中接入网设备执行的其他步骤中的至少一者(例如S2102,但不限于此),此处不再赘述。
在一些实施例中,收发模块可以包括发送模块和/或接收模块,发送模块和接收模块可以是分离的,也可以集成在一起。可选地,收发模块可以与收发器相互替换。
在一些实施例中,处理模块可以是一个模块,也可以包括多个子模块。可选地,上述多个子模块分别执行处理模块所需执行的全部或部分步骤。可选地,处理模块可以与处理器相互替换。
图8A是本公开实施例提出的通信设备8100的结构示意图。通信设备8100可以是接入网设备(例如接入网设备、核心网设备等),也可以是终端(例如用户设备等),也可以是支持接入网设备实现以上任一方法的芯片、芯片系统、或处理器等,还可以是支持终端实现以上任一方法的芯片、芯片系统、或处理器等。通信设备8100可用于实现上述方法实施例中描述的方法,具体可以参见上述方法实施例中的说明。
如图8A所示,通信设备8100包括一个或多个处理器8101。处理器8101可以是通用处理器或者专用处理器等,例如可以是基带处理器或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,基站、基带芯片,终端设备、终端设备芯片,DU或CU等)进行控制,执行程序,处理程序的数据。可选地,通信设备8100用于执行以上任一方法。可选地,一个或多个处理器8101用于调用指令以使得通信设备8100执行以上任一方法。
在一些实施例中,通信设备8100还包括一个或多个收发器8102。在通信设备8100包括一个或多个收发器8102时,收发器8102执行上述方法中的发送和/或接收等通信步骤(例如步骤S2101、步骤S2103,但不限于此)中的至少一者,处理器8101执行其他步骤(例如步骤S2102,但不限于此)中的至少一者。在可选的实施例中,收发器可以包括接收器和/或发送器,接收器和发送器可以是分离的,也可以集成在一起。可选地,收发器、收发单元、收发机、收发电路、接口电路、接口等术语可以相互替换,发送器、发送单元、发送机、发送电路等术语可以相互替换,接收器、接收单元、接收机、接收电路等术语可以相互替换。
在一些实施例中,通信设备8100还包括用于存储数据的一个或多个存储器8103。可选地,全部或部分存储器8103也可以处于通信设备8100之外。在可选的实施例中,通信设备8100可以包括一个或多个接口电路8104。可选地,接口电路8104与存储器8102连接,接口电路8104可用于从存储器8102或其他装置接收数据,可用于向存储器8102或其他装置发送数据。例如,接口电路8104可读取存储器8102中存储的数据,并将该数据发送给处理器8101。
以上实施例描述中的通信设备8100可以是接入网设备或者终端,但本公开中描述的通信设备8100的范围并不限于此,通信设备8100的结构可以不受图8A的限制。通信设备可以是独立的设备或者可以是较大设备的一部分。例如所述通信设备可以是:1)独立的集成电路IC,或芯片,或,芯片系统或子系统;(2)具有一个或多个IC的集合,可选地,上述IC集合也可以包括用于存储数据,程序的存储部件;(3)ASIC,例如调制解调器(Modem);(4)可嵌入在其他设备内的模块;(5)接收机、终端设备、智能终端设备、蜂窝电话、无线设备、手持机、移动单元、车载设备、接入网设备、云设备、人工智能设备等等;(6)其他等等。
图8B是本公开实施例提出的芯片8200的结构示意图。对于通信设备8100可以是芯片或芯片系统的情况,可以参见图8B所示的芯片8200的结构示意图,但不限于此。
芯片8200包括一个或多个处理器8201,芯片8200用于执行以上任一方法。
芯片8200包括一个或多个处理器8201。芯片8200用于执行以上任一方法。
在一些实施例中,芯片8200还包括一个或多个接口电路8202。可选地,接口电路、接口、收发管脚等术语可以相互替换。在一些实施例中,芯片8200还包括用于存储数据的一个或多个存储器8203。可选地,全部或部分存储器8203可以处于芯片8200之外。可选地,接口电路8202与存储器8203连接,接口电路8202可以用于从存储器8203或其他装置接收数据,接口电路8202可用于向存储器8203或其他装置发送数据。例如,接口电路8202可读取存储器8203中存储的数据,并将该数据发
送给处理器8201。
在一些实施例中,接口电路8202执行上述方法中的发送和/或接收等通信步骤(例如步骤S2101、步骤S2103,但不限于此)中的至少一者。接口电路8202执行上述方法中的发送和/或接收等通信步骤例如是指:接口电路8202执行处理器8201、芯片8200、存储器8203或收发器件之间的数据交互。在一些实施例中,处理器8201执行其他步骤(例如步骤S2102,但不限于此)中的至少一者。
虚拟装置、实体装置、芯片等各实施例中所描述的各模块和/或器件可以根据情况任意组合或者分离。可选地,部分或全部步骤也可以由多个模块和/或器件协作执行,此处不做限定。
本公开还提出存储介质,上述存储介质上存储有指令,当上述指令在通信设备8100上运行时,使得通信设备8100执行以上任一方法。可选地,上述存储介质是电子存储介质。可选地,上述存储介质是计算机可读存储介质,但不限于此,其也可以是其他装置可读的存储介质。可选地,上述存储介质可以是非暂时性(non-transitory)存储介质,但不限于此,其也可以是暂时性存储介质。
本公开还提出程序产品,上述程序产品被通信设备8100执行时,使得通信设备8100执行以上任一方法。可选地,上述程序产品是计算机程序产品。
本公开还提出计算机程序,当其在计算机上运行时,使得计算机执行以上任一方法。
Claims (32)
- 一种信息处理方法,其特征在于,所述方法包括:终端向接入网设备发送第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
- 根据权利要求1所述的方法,其特征在于,所述第一凭证持有者为以下任意一者:基于验证、授权和记账AAA服务器的凭证持有者;基于非公共网络NPN的凭证持有者;基于公共陆地移动网络PLMN的凭证持有者。
- 根据权利要求2所述的方法,其特征在于,所述第一凭证持有者为所述基于AAA服务器的凭证持有者,所述第一凭证持有者相关的信息包括:所述AAA服务器的区域信息。
- 根据权利要求2或3所述的方法,其特征在于,所述第一凭证持有者为所述基于NPN的凭证持有者,所述第一凭证持有者相关的信息包括以下至少一者:所述基于NPN的凭证持有者的网络标识;所述基于NPN的凭证持有者的移动网络代码;所述基于NPN的凭证持有者的移动国家代码。
- 根据权利要求2-4任一项所述的方法,其特征在于,所述第一凭证持有者为所述基于PLMN的凭证持有者,所述第一凭证持有者相关的信息包括以下至少一者:所述基于PLMN的凭证持有者的移动网络代码;所述基于PLMN的凭证持有者的移动国家代码。
- 根据权利要求1-5任一项所述的方法,其特征在于,所述第一非公共网络相关的信息包括以下至少一者:所述第一非公共网络的网络标识;所述第一非公共网络的移动网络代码;所述第一非公共网络的移动国家代码。
- 根据权利要求1-6任一项所述的方法,其特征在于,所述第一非公共网络为以下任意一者:所述终端正在访问的非公共网络;所述终端的服务非公共网络;与所述第一凭证持有者相关联的非公共网络。
- 根据权利要求7所述的方法,其特征在于,所述与所述第一凭证持有者相关联的非公共网络为以下任意一者:与使用AAA服务器进行初始认证与授权的第一凭证持有者相关联的独立非公共网络;与使用UDM和AUSF进行初始认证与授权的第一凭证持有者相关联的独立非公共网络。
- 根据权利要求1-8任一项所述的方法,其特征在于,所述终端为无线局域网上不支持5G的终端,所述接入网设备为可信无线局域网接入网TWAN设备。
- 根据权利要求9所述的方法,其特征在于,所述接入网设备包括可信的无线局域网接入点TWAP相关的设备和可信无线局域网交互功能TWIF相关的设备。
- 根据权利要求9所述的方法,其特征在于,所述终端向接入网设备发送第一信息,包括:所述终端通过所述TWAP相关的设备,向所述TWIF相关的设备发送所述第一信息。
- 根据权利要求1-10任一项所述的方法,其特征在于,所述第一信息还包括指示符,所述指示符用于指示所述第一凭证持有者相关的信息和/或所述第一非公共网络相关的信息用于无线局域网上不支持5G的终端的可信非3GPP接入。
- 一种信息处理方法,其特征在于,所述方法包括:接入网设备接收终端发送的第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
- 根据权利要求13所述的方法,其特征在于,所述第一凭证持有者为以下任意一者:基于验证、授权和记账AAA服务器的凭证持有者;基于非公共网络NPN的凭证持有者;基于公共陆地移动网络PLMN的凭证持有者。
- 根据权利要求14所述的方法,其特征在于,所述第一凭证持有者为所述基于AAA服务器的凭证持有者,所述第一凭证持有者相关的信息包括:所述AAA服务器的区域信息。
- 根据权利要求14或15所述的方法,其特征在于,所述第一凭证持有者为所述基于NPN的凭证持有者,所述第一凭证持有者相关的信息包括以下至少一者:所述基于NPN的凭证持有者的网络标识;所述基于NPN的凭证持有者的移动网络代码;所述基于NPN的凭证持有者的移动国家代码。
- 根据权利要求14-16任一项所述的方法,其特征在于,所述第一凭证持有者为所述基于PLMN的凭证持有者,所述第一凭证持有者相关的信息包括以下至少一者:所述基于PLMN的凭证持有者的移动网络代码;所述基于PLMN的凭证持有者的移动国家代码。
- 根据权利要求13或17任一项所述的方法,其特征在于,所述第一非公共网络相关的信息还包括以下至少一者:所述第一非公共网络的网络标识;所述第一非公共网络的移动网络代码;所述第一非公共网络的移动国家代码。
- 根据权利要求13-18任一项所述的方法,其特征在于,所述第一非公共网络为以下任意一者:所述终端正在访问的非公共网络;所述终端的服务非公共网络;与所述第一凭证持有者相关联的非公共网络。
- 根据权利要求19所述的方法,其特征在于,所述与所述第一凭证持有者相关联的非公共网络为以下任意一者:与使用AAA服务器进行初始认证与授权的第一凭证持有者相关联的独立非公共网络;与使用UDM和AUSF进行初始认证与授权的第一凭证持有者相关联的独立非公共网络。
- 根据权利要求13-20任一项所述的方法,其特指在于,所述方法还包括:所述接入网设备删除所述第一信息中所述第一非公共网络相关的信息以生成第二信息。
- 根据权利要求21所述的方法,其特征在于,所述方法还包括:所述接入网设备将所述第二信息发送至所述第一非公共网络。
- 根据权利要求13-22任一项所述的方法,其特征在于,所述终端为无线局域网上不支持5G的终端,所述接入网设备为可信无线局域网接入网TWAN设备。
- 根据权利要求23所述的方法,其特征在于,所述接入网设备包括可信的无线局域网接入点TWAP相关的设备和可信无线局域网交互功能TWIF相关的设备。
- 根据权利要求24所述的方法,其特征在于,所述接入网设备接收终端发送的第一信息,包括:所述TWIF相关的设备通过所述TWAP相关的设备,接收所述终端发送的第一信息。
- 根据权利要求13-25任一项所述的方法,其特征在于,所述第一信息还包括指示符,所述指示符用于指示所述第一凭证持有者相关的信息和/或所述第一非公共网络相关的信息用于所述终端的可信非3GPP接入。
- 一种终端,其特征在于,所述终端包括:收发模块,被配置为向接入网设备发送第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
- 一种接入网设备,其特征在于,所述第一设备包括:收发模块,被配置为接收终端发送的第一信息,所述第一信息包括第一凭证持有者相关的信息和/或第一非公共网络相关的信息。
- 一种终端,其特征在于,包括:一个或多个处理器;耦合于所述一个或多个处理器的存储器,所述存储器包括可执行指令,当所述可执行指令被所述一个或多个处理器执行时,使所述终端执行权利要求1-12中任一项所述的信息处理方法。
- 一种接入网设备,其特征在于,包括:一个或多个处理器;耦合于所述一个或多个处理器的存储器,所述存储器包括可执行指令,当所述可执行指令被所述一个或多个处理器执行时,使所述接入网设备执行权利要求13-26中任一项所述的信息处理方法。
- 一种通信系统,其特征在于,包括终端和接入网设备,其中,所述终端被配置为实现权利要求1-12中任一项所述的信息处理方法,所述接入网设备被配置为实现权利要求13-26中任一项所述的信息处理方法。
- 一种存储介质,所述存储介质存储有指令,其特征在于,当所述指令在通信设备上运行时,使得所述通信设备执行如权利要求1-12或权利要求13-26中任一项所述的信息处理方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202380011272.9A CN117546501A (zh) | 2023-09-26 | 2023-09-26 | 信息处理方法、终端、接入网设备、通信系统及存储介质 |
| PCT/CN2023/121800 WO2025065293A1 (zh) | 2023-09-26 | 2023-09-26 | 信息处理方法、终端、接入网设备、通信系统及存储介质 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2023/121800 WO2025065293A1 (zh) | 2023-09-26 | 2023-09-26 | 信息处理方法、终端、接入网设备、通信系统及存储介质 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025065293A1 true WO2025065293A1 (zh) | 2025-04-03 |
Family
ID=89794321
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/121800 Pending WO2025065293A1 (zh) | 2023-09-26 | 2023-09-26 | 信息处理方法、终端、接入网设备、通信系统及存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN117546501A (zh) |
| WO (1) | WO2025065293A1 (zh) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115038080A (zh) * | 2021-03-05 | 2022-09-09 | 联发科技股份有限公司 | 启用snpn的用户设备的参数处理方法及用户设备 |
| WO2022211588A1 (en) * | 2021-04-02 | 2022-10-06 | Samsung Electronics Co., Ltd. | Method and apparatus for operating enhanced non-public networks |
| WO2022237516A1 (zh) * | 2021-05-08 | 2022-11-17 | 华为技术有限公司 | 一种无线通信方法及通信装置 |
| WO2023014097A1 (en) * | 2021-08-04 | 2023-02-09 | Samsung Electronics Co., Ltd. | Method and apparatus for supporting enhanced non-public networks operation in communication system |
| CN116567615A (zh) * | 2022-01-28 | 2023-08-08 | 华为技术有限公司 | 一种接入网设备选择方法和装置 |
-
2023
- 2023-09-26 CN CN202380011272.9A patent/CN117546501A/zh active Pending
- 2023-09-26 WO PCT/CN2023/121800 patent/WO2025065293A1/zh active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115038080A (zh) * | 2021-03-05 | 2022-09-09 | 联发科技股份有限公司 | 启用snpn的用户设备的参数处理方法及用户设备 |
| WO2022211588A1 (en) * | 2021-04-02 | 2022-10-06 | Samsung Electronics Co., Ltd. | Method and apparatus for operating enhanced non-public networks |
| WO2022237516A1 (zh) * | 2021-05-08 | 2022-11-17 | 华为技术有限公司 | 一种无线通信方法及通信装置 |
| WO2023014097A1 (en) * | 2021-08-04 | 2023-02-09 | Samsung Electronics Co., Ltd. | Method and apparatus for supporting enhanced non-public networks operation in communication system |
| CN116567615A (zh) * | 2022-01-28 | 2023-08-08 | 华为技术有限公司 | 一种接入网设备选择方法和装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN117546501A (zh) | 2024-02-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2025010741A1 (zh) | 信息处理方法、设备、通信系统及存储介质 | |
| CN111726808A (zh) | 通信方法和装置 | |
| US20240244431A1 (en) | Method and apparatus for processing user-related data service and network element | |
| US12375909B2 (en) | Key identifier generation method and related apparatus | |
| CN113873520B (zh) | 一种通信方法、终端设备和无线接入网设备 | |
| WO2025025122A1 (zh) | 消息接收方法、装置 | |
| WO2025152246A1 (zh) | 通信方法、终端、网络设备、系统及存储介质 | |
| WO2025007317A1 (zh) | 通信方法、物联网终端、网元、调用方、核心网设备 | |
| WO2024234313A1 (zh) | 信息处理方法及装置、通信设备、通信系统、存储介质 | |
| WO2025035417A1 (zh) | 信息处理方法、装置及存储介质 | |
| EP3422750B1 (en) | Method and apparatus for providing service provider identifier, access device, and terminal device | |
| WO2025065642A1 (zh) | 中继通信方法、中继设备、终端、通信系统及存储介质 | |
| WO2025015612A1 (zh) | 资源配置方法及装置、存储介质 | |
| WO2025030300A1 (zh) | 信息指示方法、第一api调用者、第一网络功能和存储介质 | |
| WO2025065293A1 (zh) | 信息处理方法、终端、接入网设备、通信系统及存储介质 | |
| WO2025035325A1 (zh) | 通信处理方法、第一实体、第二实体、第三实体 | |
| WO2025030327A1 (zh) | 信息确定方法、网元、终端 | |
| WO2025043723A1 (zh) | 一种信息处理方法及其装置 | |
| WO2025007295A1 (zh) | 通信方法和装置、通信设备、通信系统及存储介质 | |
| WO2025054785A1 (zh) | 通信方法、终端、网络设备以及通信系统 | |
| WO2025208537A1 (zh) | 通信方法、网络功能、通信系统及存储介质 | |
| WO2025054998A1 (zh) | 信息处理方法、终端、通信系统及存储介质 | |
| WO2025147966A1 (zh) | 通信方法、核心网设备、通信系统和存储介质 | |
| WO2025213348A1 (zh) | 通信方法、装置和存储介质 | |
| WO2025213399A1 (zh) | 用户认证方法、通信设备及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23953451 Country of ref document: EP Kind code of ref document: A1 |