[go: up one dir, main page]

CN115811728A - Network element selection method, communication device and communication system - Google Patents

Network element selection method, communication device and communication system Download PDF

Info

Publication number
CN115811728A
CN115811728A CN202111074886.0A CN202111074886A CN115811728A CN 115811728 A CN115811728 A CN 115811728A CN 202111074886 A CN202111074886 A CN 202111074886A CN 115811728 A CN115811728 A CN 115811728A
Authority
CN
China
Prior art keywords
nswo
network
network element
identification information
authentication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202111074886.0A
Other languages
Chinese (zh)
Inventor
李�赫
吴�荣
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN202111074886.0A priority Critical patent/CN115811728A/en
Priority to PCT/CN2022/117644 priority patent/WO2023040728A1/en
Publication of CN115811728A publication Critical patent/CN115811728A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/11Allocation or use of connection identifiers

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The application provides a network element selection method, a communication device and a communication system. The method comprises the following steps: receiving identification information and indication information of a first home network, wherein the indication information indicates that terminal equipment accesses the network in a NSWO mode; and selecting a first uniform data management network element corresponding to the identification information of the first home network according to the indication information, wherein the first uniform data management network element has NSWO authentication capability. The method can realize the selection of a uniform data management network element with NSWO authentication capability, so that the uniform data management network element can provide NSWO authentication service for the terminal equipment which accesses the network by using the NSWO mode, and the method is favorable for realizing the quick and correct access of the terminal equipment.

Description

一种网元的选择方法、通信装置及通信系统A network element selection method, communication device and communication system

技术领域technical field

本申请涉及通信技术领域,尤其涉及一种网元的选择方法、通信装置及通信系统。The present application relates to the technical field of communication, and in particular to a method for selecting a network element, a communication device and a communication system.

背景技术Background technique

终端设备可以通过有缝无线局域网分流(non-seamless wireless local areanetwork offload,NSWO)方式接入网络,从而实现通过非第三代合作伙伴计划(non-3rdgeneration partnership project,non-3GPP)技术接入网络。Terminal devices can access the network through non-seamless wireless local area network offload (NSWO), so as to realize access to the network through non-3rd generation partnership project (non-3GPP) technology .

终端设备通过NSWO方式接入网络之前,需要通过核心网网元对终端设备进行鉴权,然而如何选择具有NSWO鉴权能力的网元,目前还没有解决方案。Before the terminal device accesses the network through NSWO, the terminal device needs to be authenticated by the network element of the core network. However, there is no solution for how to select the network element with NSWO authentication capability.

发明内容Contents of the invention

本申请实施例提供一种网元的选择方法、通信装置及通信系统,用于选择具有NSWO鉴权能力的网元。Embodiments of the present application provide a method for selecting a network element, a communication device, and a communication system for selecting a network element with NSWO authentication capability.

第一方面,本申请实施例提供一种网元的选择方法,该方法可以由网络存储功能网元或用于网络存储功能网元的模块(如芯片)执行,或者由认证服务功能网元或用于认证服务功能网元的模块(如芯片)执行。该方法包括:接收第一归属网络的标识信息和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络;根据该指示信息,选择与该第一归属网络的标识信息对应的第一统一数据管理网元,该第一统一数据管理网元具有NSWO鉴权能力。In the first aspect, the embodiment of the present application provides a method for selecting a network element, which can be performed by a network element with a network storage function or a module (such as a chip) for a network element with a network storage function, or by a network element with an authentication service function or Execute by modules (such as chips) used to authenticate service function network elements. The method includes: receiving identification information and indication information of the first home network, the indication information instructing the terminal device to use NSWO to access the network; according to the indication information, selecting the first unified network corresponding to the identification information of the first home network Data management network element, the first unified data management network element has NSWO authentication capability.

根据上述方案,可以实现选择一个具有NSWO鉴权能力的统一数据管理网元,从而该统一数据管理网元可以为使用NSWO的方式接入网络的终端设备提供NSWO鉴权服务,有助于实现终端设备的快速和正确接入。According to the above scheme, it is possible to select a unified data management network element with NSWO authentication capability, so that the unified data management network element can provide NSWO authentication services for terminal devices connected to the network in NSWO mode, which helps to realize terminal Fast and correct access of equipment.

作为一种可能的实现方法,根据该指示信息,从第一映射关系中选择与该第一归属网络的标识信息对应的该第一统一数据管理网元,该第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的统一数据管理网元之间的映射关系。As a possible implementation method, the first unified data management network element corresponding to the identification information of the first home network is selected from the first mapping relationship according to the indication information, and the first mapping relationship includes the identification information of the home network The mapping relationship between information and unified data management network elements with NSWO authentication capabilities.

根据上述方案,可以预先定义归属网络的标识信息与具有NSWO鉴权能力的统一数据管理网元之间的映射关系,从而可以根据该映射关系选择统一数据管理网元,有助于实现快速准确地选择具有NSWO鉴权能力的统一数据管理网元。According to the above solution, the mapping relationship between the identification information of the home network and the unified data management network element with NSWO authentication capability can be defined in advance, so that the unified data management network element can be selected according to the mapping relationship, which is helpful to realize fast and accurate Select a unified data management network element with NSWO authentication capability.

作为一种可能的实现方法,接收第二归属网络的标识信息;从第二映射关系中选择与该第二归属网络的标识信息对应的第二统一数据管理网元,该第二统一数据管理网元不具有NSWO鉴权能力,该第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的统一数据管理网元之间的映射关系。As a possible implementation method, the identification information of the second home network is received; the second unified data management network element corresponding to the identification information of the second home network is selected from the second mapping relationship, and the second unified data management network element The element does not have the NSWO authentication capability, and the second mapping relationship includes the mapping relationship between the identification information of the home network and the unified data management network element that does not have the NSWO authentication capability.

根据上述方案,还可以根据预定义的归属网络的标识信息与不具有NSWO鉴权能力的统一数据管理网元之间的映射关系,选择不具有NSWO鉴权能力的统一数据管理网元,从而该方法可以实现在同时存在具有NSWO鉴权能力的统一数据管理网元和不具有NSWO鉴权能力的统一数据管理网元的场景中,根据需要选择相应的统一数据管理网元。According to the above solution, it is also possible to select a unified data management network element without NSWO authentication capability according to the mapping relationship between the predefined identification information of the home network and the unified data management network element without NSWO authentication capability, so that the The method can select the corresponding unified data management network element according to the requirement in the scene where the unified data management network element with NSWO authentication capability and the unified data management network element without NSWO authentication capability exist at the same time.

作为一种可能的实现方法,接收第一路由标识;根据该指示信息,选择与该第一归属网络的标识信息和该第一路由标识对应的该第一统一数据管理网元。As a possible implementation method, the first routing identifier is received; according to the indication information, the first unified data management network element corresponding to the identification information of the first home network and the first routing identifier is selected.

根据上述方案,根据归属网络的标识信息和该路由标识选择统一数据管理网元,可以实现在一个归属网络对应多个统一数据管理网元,并通过不同的路由标识对这些统一数据管理网元进行区分。由于存在多个统一数据管理网元可以使用,从而可以提升选择的灵活性以及降低每个统一数据管理网元的负载。According to the above solution, the unified data management network element is selected according to the identification information of the home network and the routing identification, so that multiple unified data management network elements corresponding to one home network can be implemented, and these unified data management network elements can be implemented through different routing identifications. distinguish. Since there are multiple unified data management network elements that can be used, the flexibility of selection can be improved and the load of each unified data management network element can be reduced.

作为一种可能的实现方法,根据该指示信息,从第三映射关系中选择与该第一归属网络的标识信息和该第一路由标识对应的该第一统一数据管理网元,该第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的统一数据管理网元之间的映射关系。As a possible implementation method, according to the indication information, the first unified data management network element corresponding to the identification information of the first home network and the first routing identifier is selected from the third mapping relationship, and the third mapping The relationship includes the mapping relationship between the combination of the identification information of the home network and the routing identification and the unified data management network element with NSWO authentication capability.

根据上述方案,可以预先定义归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的统一数据管理网元之间的映射关系,从而可以根据该映射关系选择统一数据管理网元,有助于实现快速准确地选择具有NSWO鉴权能力的统一数据管理网元。According to the above scheme, the mapping relationship between the combination of the identification information of the home network and the routing identification and the unified data management network element with NSWO authentication capability can be defined in advance, so that the unified data management network element can be selected according to the mapping relationship, which is helpful To realize fast and accurate selection of unified data management network elements with NSWO authentication capabilities.

作为一种可能的实现方法,接收来自认证服务功能网元的该第一归属网络的标识信息和该指示信息;向该认证服务功能网元发送该第一统一数据管理网元的标识信息。As a possible implementation method, the identification information of the first home network and the indication information from the authentication service functional network element are received; and the identification information of the first unified data management network element is sent to the authentication service functional network element.

第二方面,本申请实施例提供一种网元的选择方法,该方法可以由网络存储功能网元或用于网络存储功能网元的模块(如芯片)执行,或者由NSWO网元或用于NSWO网元的模块(如芯片)执行。该方法包括:接收第一归属网络的标识信息和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络;根据该指示信息,选择与该第一归属网络的标识信息对应的第一认证服务功能网元,该第一认证服务功能网元具有NSWO鉴权能力。In the second aspect, the embodiment of the present application provides a network element selection method, which can be executed by a network storage function network element or a module (such as a chip) used for a network storage function network element, or by a NSWO network element or a network element used for Modules (such as chips) of NSWO network elements are implemented. The method includes: receiving identification information and indication information of the first home network, the indication information instructing the terminal device to use NSWO to access the network; according to the indication information, selecting the first authentication corresponding to the identification information of the first home network The service function network element, the first authentication service function network element has NSWO authentication capability.

根据上述方案,可以实现选择一个具有NSWO鉴权能力的认证服务功能网元,从而该认证服务功能网元可以为使用NSWO的方式接入网络的终端设备提供NSWO鉴权服务,有助于实现终端设备的快速和正确接入。According to the above scheme, it is possible to select an authentication service function network element with NSWO authentication capability, so that the authentication service function network element can provide NSWO authentication services for terminal devices that use NSWO to access the network, which helps to realize terminal Fast and correct access of equipment.

作为一种可能的实现方法,根据该指示信息,从第一映射关系中选择与该第一归属网络的标识信息对应的该第一认证服务功能网元,该第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, according to the indication information, select the first authentication service function network element corresponding to the identification information of the first home network from the first mapping relationship, the first mapping relationship includes the identification of the home network The mapping relationship between the information and the authentication service function network element with NSWO authentication capability.

根据上述方案,可以预先定义归属网络的标识信息与具有NSWO鉴权能力的认证服务功能网元之间的映射关系,从而可以根据该映射关系选择认证服务功能网元,有助于实现快速准确地选择具有NSWO鉴权能力的认证服务功能网元。According to the above solution, the mapping relationship between the identification information of the home network and the authentication service function network element with NSWO authentication capability can be defined in advance, so that the authentication service function network element can be selected according to the mapping relationship, which is helpful to realize fast and accurate Select an authentication service functional network element with NSWO authentication capability.

作为一种可能的实现方法,接收第二归属网络的标识信息;从第二映射关系中选择与该第二归属网络的标识信息对应的第二认证服务功能网元,该第二认证服务功能网元不具有NSWO鉴权能力,该第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the identification information of the second home network is received; the second authentication service function network element corresponding to the identification information of the second home network is selected from the second mapping relationship, and the second authentication service function network element The element does not have the NSWO authentication capability, and the second mapping relationship includes the mapping relationship between the identification information of the home network and the authentication service function network element that does not have the NSWO authentication capability.

根据上述方案,还可以根据预定义的归属网络的标识信息与不具有NSWO鉴权能力的认证服务功能网元之间的映射关系,选择不具有NSWO鉴权能力的认证服务功能网元,从而该方法可以实现在同时存在具有NSWO鉴权能力的认证服务功能网元和不具有NSWO鉴权能力的认证服务功能网元的场景中,根据需要选择相应的认证服务功能网元。According to the above solution, it is also possible to select an authentication service function network element without NSWO authentication capability according to the mapping relationship between the predefined identification information of the home network and the authentication service function network element without NSWO authentication capability, so that the The method can select the corresponding authentication service function network element according to the requirement in the scenario where there are authentication service function network elements with NSWO authentication capability and authentication service function network elements without NSWO authentication capability at the same time.

作为一种可能的实现方法,接收第一路由标识;根据该指示信息,选择与该第一归属网络的标识信息和该第一路由标识对应的该第一认证服务功能网元。As a possible implementation method, the first routing identifier is received; according to the indication information, the first authentication service function network element corresponding to the identification information of the first home network and the first routing identifier is selected.

根据上述方案,根据归属网络的标识信息和该路由标识选择认证服务功能网元,可以实现在一个归属网络对应多个认证服务功能网元,并通过不同的路由标识对这些认证服务功能网元进行区分。由于存在多个认证服务功能网元可以使用,从而可以提升选择的灵活性以及降低每个认证服务功能网元的负载。According to the above solution, the authentication service function network element is selected according to the identification information of the home network and the routing identifier, so that a home network corresponds to multiple authentication service function network elements, and these authentication service function network elements are implemented through different routing identifiers. distinguish. Since there are multiple authentication service function network elements that can be used, the flexibility of selection can be improved and the load of each authentication service function network element can be reduced.

作为一种可能的实现方法,根据该指示信息,从第三映射关系中选择与该第一归属网络的标识信息和该第一路由标识对应的该第一认证服务功能网元,该第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, according to the indication information, the first authentication service function network element corresponding to the identification information of the first home network and the first routing identifier is selected from the third mapping relationship, and the third mapping The relationship includes the mapping relationship between the combination of the identification information of the home network and the routing identification and the authentication service function network element with NSWO authentication capability.

根据上述方案,可以预先定义归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的认证服务功能网元之间的映射关系,从而可以根据该映射关系选择认证服务功能网元,有助于实现快速准确地选择具有NSWO鉴权能力的认证服务功能网元。According to the above scheme, the mapping relationship between the combination of the identification information of the home network and the routing identification and the authentication service function network element with NSWO authentication capability can be defined in advance, so that the authentication service function network element can be selected according to the mapping relationship, which is helpful In order to realize fast and accurate selection of authentication service functional network elements with NSWO authentication capabilities.

作为一种可能的实现方法,接收来自NSWO网元的该第一归属网络的标识信息和该指示信息;向该NSWO网元发送该第一认证服务功能网元的标识信息。As a possible implementation method, the identification information of the first home network and the indication information from the NSWO network element are received; and the identification information of the first authentication service function network element is sent to the NSWO network element.

第三方面,本申请实施例提供一种网元的选择方法,该方法可以由网络存储功能网元或用于网络存储功能网元的模块(如芯片)执行。该方法包括:接收第一消息,该第一消息包含第一归属网络的标识信息;根据该第一消息确定终端设备使用NSWO的方式接入网络,则选择与该第一归属网络的标识信息对应的第一认证服务功能网元,该第一认证服务功能网元具有NSWO鉴权能力。In a third aspect, the embodiment of the present application provides a method for selecting a network element, and the method may be executed by a network element with a network storage function or a module (such as a chip) used for the network element with a network storage function. The method includes: receiving a first message, the first message including the identification information of the first home network; according to the first message, it is determined that the terminal device uses NSWO to access the network, and then selecting the The first authentication service function network element, the first authentication service function network element has NSWO authentication capability.

根据上述方案,可以实现选择一个具有NSWO鉴权能力的认证服务功能网元,从而该认证服务功能网元可以为使用NSWO的方式接入网络的终端设备提供NSWO鉴权服务,有助于实现终端设备的快速和正确接入。According to the above scheme, it is possible to select an authentication service function network element with NSWO authentication capability, so that the authentication service function network element can provide NSWO authentication services for terminal devices that use NSWO to access the network, which helps to realize terminal Fast and correct access of equipment.

作为一种可能的实现方法,从第一映射关系中选择与该第一归属网络的标识信息对应的该第一认证服务功能网元,该第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the first authentication service function network element corresponding to the identification information of the first home network is selected from the first mapping relationship, the first mapping relationship includes the identification information of the home network and the The mapping relationship between authentication service function network elements of authorization capabilities.

根据上述方案,可以预先定义归属网络的标识信息与具有NSWO鉴权能力的认证服务功能网元之间的映射关系,从而可以根据该映射关系选择认证服务功能网元,有助于实现快速准确地选择具有NSWO鉴权能力的认证服务功能网元。According to the above solution, the mapping relationship between the identification information of the home network and the authentication service function network element with NSWO authentication capability can be defined in advance, so that the authentication service function network element can be selected according to the mapping relationship, which is helpful to realize fast and accurate Select an authentication service functional network element with NSWO authentication capability.

作为一种可能的实现方法,接收第二消息,该第二消息包含第二归属网络的标识信息;根据该第二消息确定终端设备未使用NSWO的方式接入网络,则从第二映射关系中选择与该第二归属网络的标识信息对应的第二认证服务功能网元,该第二认证服务功能网元不具有NSWO鉴权能力,该第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the second message is received, and the second message includes the identification information of the second home network; according to the second message, it is determined that the terminal device does not use the NSWO method to access the network, then from the second mapping relationship Selecting a second authentication service function network element corresponding to the identification information of the second home network, the second authentication service function network element does not have the NSWO authentication capability, and the second mapping relationship includes the identification information of the home network and the network element without NSWO The mapping relationship between authentication service function network elements of authentication capabilities.

根据上述方案,还可以根据预定义的归属网络的标识信息与不具有NSWO鉴权能力的认证服务功能网元之间的映射关系,选择不具有NSWO鉴权能力的认证服务功能网元,从而该方法可以实现在同时存在具有NSWO鉴权能力的认证服务功能网元和不具有NSWO鉴权能力的认证服务功能网元的场景中,根据需要选择相应的认证服务功能网元。According to the above solution, it is also possible to select an authentication service function network element without NSWO authentication capability according to the mapping relationship between the predefined identification information of the home network and the authentication service function network element without NSWO authentication capability, so that the The method can select the corresponding authentication service function network element according to the requirement in the scenario where there are authentication service function network elements with NSWO authentication capability and authentication service function network elements without NSWO authentication capability at the same time.

作为一种可能的实现方法,该第一消息中还包含第一路由标识;选择与该第一归属网络的标识信息和该第一路由标识对应的该第一认证服务功能网元。As a possible implementation method, the first message further includes a first routing identifier; and the first authentication service function network element corresponding to the first home network identification information and the first routing identifier is selected.

根据上述方案,根据归属网络的标识信息和该路由标识选择认证服务功能网元,可以实现在一个归属网络对应多个认证服务功能网元,并通过不同的路由标识对这些认证服务功能网元进行区分。由于存在多个认证服务功能网元可以使用,从而可以提升选择的灵活性以及降低每个认证服务功能网元的负载。According to the above solution, the authentication service function network element is selected according to the identification information of the home network and the routing identifier, so that a home network corresponds to multiple authentication service function network elements, and these authentication service function network elements are implemented through different routing identifiers. distinguish. Since there are multiple authentication service function network elements that can be used, the flexibility of selection can be improved and the load of each authentication service function network element can be reduced.

作为一种可能的实现方法,从第三映射关系中选择与该第一归属网络的标识信息和该第一路由标识对应的该第一认证服务功能网元,该第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the first authentication service function network element corresponding to the identification information of the first home network and the first routing identifier is selected from the third mapping relationship, where the third mapping relationship includes the identification information of the home network The mapping relationship between the combination of identification information and routing identification and the authentication service function network element with NSWO authentication capability.

根据上述方案,可以预先定义归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的认证服务功能网元之间的映射关系,从而可以根据该映射关系选择认证服务功能网元,有助于实现快速准确地选择具有NSWO鉴权能力的认证服务功能网元。According to the above scheme, the mapping relationship between the combination of the identification information of the home network and the routing identification and the authentication service function network element with NSWO authentication capability can be defined in advance, so that the authentication service function network element can be selected according to the mapping relationship, which is helpful In order to realize fast and accurate selection of authentication service functional network elements with NSWO authentication capabilities.

作为一种可能的实现方法,第一消息包含指示NSWO网络功能的网络功能类型;根据该网络功能类型,确定该终端设备使用NSWO的方式接入网络。As a possible implementation method, the first message includes a network function type indicating the NSWO network function; according to the network function type, it is determined that the terminal device uses NSWO to access the network.

作为一种可能的实现方法,根据该第一消息的名称,确定该终端设备使用NSWO的方式接入网络。As a possible implementation method, according to the name of the first message, it is determined that the terminal device uses NSWO to access the network.

作为一种可能的实现方法,接收来自NSWO网元的该第一消息;向该NSWO网元发送该第一认证服务功能网元的标识信息。As a possible implementation method, the first message from the NSWO network element is received; and the identification information of the first authentication service function network element is sent to the NSWO network element.

第四方面,本申请实施例提供一种通信装置,该装置可以是网络存储功能网元或应用于网络存储功能网元中的模块(如芯片),或者是认证服务功能网元或应用于认证服务功能网元中的模块(如芯片)。该装置具有实现上述第一方面的任意实现方法的功能。该功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块。In the fourth aspect, the embodiment of the present application provides a communication device, which can be a network storage function network element or a module (such as a chip) applied to a network storage function network element, or an authentication service function network element or an authentication service function network element A module (such as a chip) in a service function network element. The device has the function of realizing any realization method of the first aspect above. This function may be implemented by hardware, or may be implemented by executing corresponding software on the hardware. The hardware or software includes one or more modules corresponding to the above functions.

第五方面,本申请实施例提供一种通信装置,该装置可以是网络存储功能网元或应用于网络存储功能网元中的模块(如芯片),或者是NSWO网元或应用于NSWO网元中的模块(如芯片)。该装置具有实现上述第二方面的任意实现方法的功能。该功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块。In the fifth aspect, the embodiment of the present application provides a communication device, which can be a network storage function network element or a module (such as a chip) applied to a network storage function network element, or a NSWO network element or a NSWO network element Modules (such as chips) in . The device has the function of implementing any implementation method of the second aspect above. This function may be implemented by hardware, or may be implemented by executing corresponding software on the hardware. The hardware or software includes one or more modules corresponding to the above functions.

第六方面,本申请实施例提供一种通信装置,该装置可以是网络存储功能网元或应用于网络存储功能网元中的模块(如芯片)。该装置具有实现上述第三方面的任意实现方法的功能。该功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块。In a sixth aspect, the embodiment of the present application provides a communication device, which may be a network storage function network element or a module (such as a chip) applied to a network storage function network element. The device has the function of realizing any realization method of the third aspect above. This function may be implemented by hardware, or may be implemented by executing corresponding software on the hardware. The hardware or software includes one or more modules corresponding to the above functions.

第七方面,本申请实施例提供一种通信装置,包括处理器和存储器;该存储器用于存储计算机指令,当该装置运行时,该处理器执行该存储器存储的计算机指令,以使该装置执行上述第一方面至第三方面中的任意实现方法。In the seventh aspect, the embodiment of the present application provides a communication device, including a processor and a memory; the memory is used to store computer instructions, and when the device is running, the processor executes the computer instructions stored in the memory so that the device executes Any implementation method in the first aspect to the third aspect above.

第八方面,本申请实施例提供一种通信装置,包括用于执行上述第一方面至第三方面中的任意实现方法的各个步骤的单元或手段(means)。In an eighth aspect, the embodiment of the present application provides a communication device, including a unit or means (means) for performing each step of any implementation method in the first aspect to the third aspect.

第九方面,本申请实施例提供一种通信装置,包括处理器和接口电路,所述处理器用于通过接口电路与其它装置通信,并执行上述第一方面至第三方面中的任意实现方法。该处理器包括一个或多个。In a ninth aspect, the embodiment of the present application provides a communication device, including a processor and an interface circuit, the processor is configured to communicate with other devices through the interface circuit, and execute any implementation method in the first aspect to the third aspect above. The processor includes one or more.

第十方面,本申请实施例提供一种通信装置,包括与存储器耦合的处理器,该处理器用于调用所述存储器中存储的程序,以执行上述第一方面至第三方面中的任意实现方法。该存储器可以位于该装置之内,也可以位于该装置之外。且该处理器可以是一个或多个。In the tenth aspect, the embodiment of the present application provides a communication device, including a processor coupled to the memory, and the processor is used to call the program stored in the memory to execute any implementation method in the first aspect to the third aspect above . The memory may be located within the device or external to the device. And there may be one or more processors.

第十一方面,本申请实施例还提供一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,当其在通信装置上运行时,使得上述第一方面至第三方面中的任意实现方法被执行。In the eleventh aspect, the embodiment of the present application also provides a computer-readable storage medium, the computer-readable storage medium stores instructions, and when it is run on a communication device, the above-mentioned first to third aspects Any implementation method of is executed.

第十二方面,本申请实施例还提供一种计算机程序产品,该计算机程序产品包括计算机程序或指令,当计算机程序或指令被通信装置运行时,使得上述第一方面至第三方面中的任意实现方法被执行。In the twelfth aspect, the embodiment of the present application also provides a computer program product, the computer program product includes a computer program or instruction, when the computer program or instruction is run by a communication device, any of the above first to third aspects The implementation method is executed.

第十三方面,本申请实施例还提供一种芯片系统,包括:处理器,用于执行上述第一方面至第三方面中的任意实现方法。In a thirteenth aspect, the embodiment of the present application further provides a chip system, including: a processor, configured to execute any implementation method in the first aspect to the third aspect above.

第十四方面,本申请实施例还提供一种通信系统,包括认证服务功能网元和网络存储功能网元。其中,认证服务功能网元,用于向网络存储功能网元发送第一归属网络的标识信息和指示信息,所述指示信息指示终端设备使用NSWO的方式接入网络。网络存储功能网元,用于执行第一方面的任意实现方法。In a fourteenth aspect, the embodiment of the present application further provides a communication system, including an authentication service function network element and a network storage function network element. Wherein, the authentication service function network element is used to send the identification information and indication information of the first home network to the network storage function network element, and the indication information instructs the terminal device to use NSWO to access the network. A network element with a network storage function, configured to execute any implementation method in the first aspect.

第十五方面,本申请实施例还提供一种通信系统,包括NSWO网元和认证服务功能网元。其中,NSWO网元,用于向认证服务功能网元发送第一归属网络的标识信息和指示信息,所述指示信息指示终端设备使用NSWO的方式接入网络。认证服务功能网元,用于执行第一方面的任意实现方法。In a fifteenth aspect, the embodiment of the present application further provides a communication system, including a NSWO network element and an authentication service function network element. Wherein, the NSWO network element is configured to send the identification information and indication information of the first home network to the network element with the authentication service function, and the indication information instructs the terminal equipment to use NSWO to access the network. The authentication service function network element is configured to execute any implementation method in the first aspect.

第十六方面,本申请实施例还提供一种通信系统,包括NSWO网元和网络存储功能网元。其中,NSWO网元,用于向网络存储功能网元发送第一归属网络的标识信息和指示信息,所述指示信息指示终端设备使用NSWO的方式接入网络。网络存储功能网元,用于执行第二方面的任意实现方法。In a sixteenth aspect, the embodiment of the present application further provides a communication system, including a NSWO network element and a network storage function network element. Wherein, the NSWO network element is configured to send the identification information and indication information of the first home network to the network storage functional network element, and the indication information instructs the terminal device to use the NSWO mode to access the network. A network storage function network element, configured to implement any implementation method in the second aspect.

第十七方面,本申请实施例还提供一种通信系统,包括NSWO网元和网络存储功能网元。其中,NSWO网元,用于向网络存储功能网元发送第一消息,所述第一消息包含第一归属网络的标识信息。网络存储功能网元,用于执行第三方面的任意实现方法。In a seventeenth aspect, the embodiment of the present application further provides a communication system, including a NSWO network element and a network storage function network element. Wherein, the NSWO network element is configured to send a first message to the network storage functional network element, where the first message includes identification information of the first home network. A network element with a network storage function, configured to implement any implementation method in the third aspect.

附图说明Description of drawings

图1为4G系统中非3GPP接入架构的示意图;FIG. 1 is a schematic diagram of a non-3GPP access architecture in a 4G system;

图2为5G网络架构示意图;Figure 2 is a schematic diagram of the 5G network architecture;

图3为5G中的NSWO架构示意图;Figure 3 is a schematic diagram of the NSWO architecture in 5G;

图4为本申请实施例提供的一种网元的选择方法的流程示意图;FIG. 4 is a schematic flowchart of a method for selecting a network element provided in an embodiment of the present application;

图5为本申请实施例提供的一种网元的选择方法的流程示意图;FIG. 5 is a schematic flowchart of a method for selecting a network element provided in an embodiment of the present application;

图6为本申请实施例提供的一种网元的选择方法的流程示意图;FIG. 6 is a schematic flowchart of a method for selecting a network element provided in an embodiment of the present application;

图7为本申请实施例提供的一种网元的选择方法的流程示意图;FIG. 7 is a schematic flowchart of a method for selecting a network element provided in an embodiment of the present application;

图8为本申请实施例提供的一种网元的选择方法的流程示意图;FIG. 8 is a schematic flowchart of a method for selecting a network element provided in an embodiment of the present application;

图9为本申请实施例提供的一种通信装置示意图;FIG. 9 is a schematic diagram of a communication device provided by an embodiment of the present application;

图10为本申请实施例提供的一种通信装置示意图。FIG. 10 is a schematic diagram of a communication device provided by an embodiment of the present application.

具体实施方式Detailed ways

本申请实施例提供的技术方案可以应用于各种通信系统,例如:第五代(5thgeneration,5G)系统或新无线(new radio,NR)或者未来的3GPP系统等。The technical solutions provided by the embodiments of the present application may be applied to various communication systems, for example, a fifth generation (5th generation, 5G) system or a new radio (new radio, NR) or a future 3GPP system.

通常来说,传统的通信系统支持的连接数有限,也易于实现,然而,随着通信技术的发展,移动通信系统将不仅支持传统的通信,还将支持例如,设备到设备(device todevice,D2D)通信,机器到机器(machine to machine,M2M)通信,机器类型通信(machinetype communication,MTC),车辆与万物(vehicle to everything,V2X)通信(也可以称为车联网通信),例如,车辆与车辆(vehicle to vehicle,V2V)通信(也可以称为车到车通信)、车辆与基础设施(vehicle to infrastructure,V2I)通信(也可以称为车到基础设施通信),车辆与行人(vehicle to pedestrian,V2P)通信(也可以称为车到人通信),车辆与网络(vehicle to network,V2N)通信(也可以称为车到网络通信)。Generally speaking, the number of connections supported by traditional communication systems is limited and easy to implement. However, with the development of communication technologies, mobile communication systems will not only support traditional communication, but also support, for example, device-to-device (D2D ) communication, machine to machine (machine to machine, M2M) communication, machine type communication (machine type communication, MTC), vehicle to everything (vehicle to everything, V2X) communication (also called vehicle networking communication), for example, vehicle and Vehicle (vehicle to vehicle, V2V) communication (also known as vehicle-to-vehicle communication), vehicle-to-infrastructure (V2I) communication (also known as vehicle-to-infrastructure communication), vehicle-to-pedestrian (vehicle to pedestrian (V2P) communication (also called vehicle-to-person communication), and vehicle-to-network (V2N) communication (also called vehicle-to-network communication).

图1提供了第四代(4th generation,4G)系统中非3GPP接入架构的示意图。非3GPP接入,是指终端设备通过非3GPP接入技术接入到运营商网络,并使用运营商网络资源。非3GPP接入技术包括无线局域网(wireless local area network,WLAN),码分多址(codedivision multiple access,CDMA)等接入技术。FIG. 1 provides a schematic diagram of a non-3GPP access architecture in a fourth generation (4th generation, 4G) system. Non-3GPP access means that terminal equipment accesses the operator's network through non-3GPP access technology and uses the operator's network resources. The non-3GPP access technologies include wireless local area network (wireless local area network, WLAN), code division multiple access (code division multiple access, CDMA) and other access technologies.

下面结合图1对本申请实施例中可能涉及的各个网元分别进行说明。Each network element that may be involved in the embodiment of the present application will be described respectively below with reference to FIG. 1 .

1、终端设备:可以称为用户设备(user equipment,UE)、终端、接入终端、用户单元、用户站、移动站、移动台、远方站、远程终端、移动设备、用户终端、无线通信设备、用户代理或用户装置。终端设备还可以是蜂窝电话、无绳电话、会话启动协议(sessioninitiation protocol,SIP)电话、无线本地环路(wireless local loop,WLL)站、个人数字助理(personal digital assistant,PDA)、具有无线通信功能的手持设备、计算设备或连接到无线调制解调器的其它处理设备、车载设备、可穿戴设备,5G网络中的UE或者未来演进的公用陆地移动通信网络(public land mobile network,PLMN)中或者非陆地网络(non-terrestrial networks,NTN)的UE等,还可以是逻辑实体,智能设备,如手机,智能终端等设备,或者服务器,网关,基站,控制器等通信设备,或者物联网设备,如传感器,电表,水表等物联网(internet of things,IoT)设备。还可以是具有通信功能的无人机(unmannedaerial vehicle或uncrewed aerial vehicle,UAV)。本申请实施例对此并不限定。1. Terminal equipment: can be called user equipment (user equipment, UE), terminal, access terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication device , User Agent, or User Device. The terminal device can also be a cellular phone, a cordless phone, a session initiation protocol (sessioninitiation protocol, SIP) phone, a wireless local loop (wireless local loop, WLL) station, a personal digital assistant (personal digital assistant, PDA), with a wireless communication function Handheld devices, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, UEs in 5G networks or future evolutions of public land mobile networks (public land mobile network, PLMN) or non-terrestrial networks (non-terrestrial networks, NTN) UE, etc., can also be logical entities, smart devices, such as mobile phones, smart terminals, etc., or communication devices such as servers, gateways, base stations, controllers, or Internet of Things devices, such as sensors, Internet of things (IoT) devices such as electric meters and water meters. It may also be an unmanned aerial vehicle (unmannedaerial vehicle or uncrewed aerial vehicle, UAV) with a communication function. The embodiment of the present application does not limit this.

2、归属签约用户服务器(home subscriber server,HSS):HSS是演进的分组系统(evolved packet system,EPS)中用于存储用户签约信息的服务器,主要负责管理用户的签约数据及移动用户的位置信息。2. Home subscriber server (HSS): HSS is a server used to store user subscription information in the evolved packet system (EPS), and is mainly responsible for managing user subscription data and mobile user location information .

3、策略与计费规则功能单元(policy and charging rules function,PCRF):PCRF是业务数据流和网际互连协议(internet protocol,IP)承载资源的策略与计费控制策略决策点,它为策略与计费执行功能单元选择及提供可用的策略和计费控制决策。3. Policy and charging rules function (Policy and charging rules function, PCRF): PCRF is the policy and charging control policy decision point for service data flow and internet protocol (internet protocol, IP) bearer resources. The charging and charging execution function unit selects and provides available policies and charging control decisions.

4、公共数据网(public data network,PDN)网关:PDN网关包含提供用户的会话管理和承载控制、数据转发、IP地址分配以及非3GPP用户接入等功能。它是3GPP接入和非3GPP接入公用数据网络的锚点。4. Public data network (PDN) gateway: The PDN gateway includes functions such as providing user session management and bearer control, data forwarding, IP address allocation, and non-3GPP user access. It is the anchor point for 3GPP access and non-3GPP access to public data networks.

5、验证、授权和记账(authentication、authorization、accounting,AAA)服务器:AAA服务器是一个能够处理用户访问请求的服务器程序,提供验证授权以及帐户服务,主要目的是管理用户访问网络服务器,对具有访问权的用户提供服务。AAA服务器通常同网络访问控制、网关服务器、数据库以及用户信息目录等协同工作。5. Authentication, authorization, and accounting (authentication, authorization, accounting, AAA) server: AAA server is a server program that can handle user access requests, and provides authentication authorization and account services. The main purpose is to manage user access to the network server. Services provided to users with access rights. AAA servers usually work in conjunction with network access control, gateway servers, databases, and user information directories.

6、IP多媒体系统(IP multimedia subsystem,IMS):IMS是一种全新的多媒体业务形式,它能够满足终端客户的更加新颖和多样化的多媒体业务需求。6. IP multimedia subsystem (IP multimedia subsystem, IMS): IMS is a brand-new multimedia service form, which can meet the more novel and diversified multimedia service requirements of terminal customers.

从图1中可以看出,终端设备可以基于S2a接口,通过信任的非3GPP接入到4G网络,或者也可以基于Swu+S2b接口,Swa接口或STa接口,通过不信任的非3GPP接入到4G网络。It can be seen from Figure 1 that the terminal device can access the 4G network through the trusted non-3GPP based on the S2a interface, or it can also access the 4G network through the untrusted non-3GPP based on the Swu+S2b interface, Swa interface or STa interface. 4G network.

4G系统中终端设备通过非3GPP接入网络时,经过HSS、3GPP AAA服务器等网元,而不经过移动性管理实体(mobility management entity,MME)。例如,终端设备通过NSWO方式接入网络时,可以经过WLAN接入点接入网络,而不经过MME。其中,不经过MME指的是接入网络的流程中不涉及终端设备和MME的直接交互或间接交互。When a terminal device in a 4G system accesses a network through a non-3GPP, it passes through network elements such as an HSS and a 3GPP AAA server instead of a mobility management entity (MME). For example, when a terminal device accesses the network through NSWO, it can access the network through the WLAN access point instead of the MME. Wherein, not passing through the MME means that the process of accessing the network does not involve direct or indirect interaction between the terminal device and the MME.

在4G演进到5G的过程中,5G网络考虑了终端设备通过S2a和S2b接口接入到5G网络的情况,但是没有考虑Swa接口和STa接口。因此,现在正在考虑终端设备如何通过Swa接口和STa接口接入到5G网络。Swa接口和STa接口的特点是终端设备通过不信任的非3GPP接入后,需要通过3GPP AAA服务器和HSS之间的交互完成鉴权,再对终端设备鉴权成功后,终端设备可以直接使用不信任的非3GPP接入技术进行网络接入。在这种情况下,终端设备的流量数据可以直接走到PDN网关,并由PDN网关转发给外部网络,或者是终端设备的流量数据也可以直接走到外部网络,不经过PDN网关。During the evolution from 4G to 5G, the 5G network considers the situation that the terminal equipment accesses the 5G network through the S2a and S2b interfaces, but does not consider the Swa interface and the STa interface. Therefore, how the terminal equipment accesses the 5G network through the Swa interface and the STa interface is now being considered. The characteristic of the Swa interface and the STa interface is that after the terminal device accesses through an untrusted non-3GPP, it needs to complete the authentication through the interaction between the 3GPP AAA server and the HSS. After the terminal device is successfully authenticated, the terminal device can directly use the Trusted non-3GPP access technology for network access. In this case, the traffic data of the terminal device can go directly to the PDN gateway and be forwarded to the external network by the PDN gateway, or the traffic data of the terminal device can also go directly to the external network without passing through the PDN gateway.

图2示出了当前的5G网络架构。下面结合图2对本申请实施例中可能涉及的各个网元分别进行说明。Figure 2 shows the current 5G network architecture. Each network element that may be involved in the embodiment of the present application will be described respectively below with reference to FIG. 2 .

1、终端设备:具体参见前面的描述。1. Terminal equipment: refer to the previous description for details.

2、接入网(access network,AN):接入网用于为特定区域的授权用户提供入网功能,并能够根据用户的级别,业务的需求等使用不同质量的传输隧道。接入网可以为采用不同接入技术的接入网络。目前的无线接入技术有两种类型:3GPP接入技术(例如3G、4G或5G系统中采用的无线接入技术或未来3GPP无线接入技术)和非第三代合作伙伴计划(non-3GPP)接入技术。3GPP接入技术是指符合3GPP标准规范的接入技术,采用3GPP接入技术的接入网络称为无线接入网(radio access network,RAN),其中,5G系统中的接入网设备称为下一代基站节点(next generation Node Base station,gNB)。非3GPP接入技术是指不符合3GPP标准规范的接入技术,例如,以无线保真(wireless fidelity,Wi-Fi)中的接入点(access point,AP)为代表的空口技术。2. Access network (AN): The access network is used to provide network access functions for authorized users in a specific area, and can use transmission tunnels of different qualities according to user levels and service requirements. The access network may be an access network using different access technologies. There are currently two types of radio access technologies: 3GPP access technologies (such as those used in 3G, 4G or 5G systems or future 3GPP radio access technologies) and non-3GPP access technologies (non-3GPP ) access technology. 3GPP access technology refers to the access technology that complies with 3GPP standards and specifications. The access network using 3GPP access technology is called radio access network (radio access network, RAN). Among them, the access network equipment in the 5G system is called Next generation Node Base station (gNB). The non-3GPP access technology refers to an access technology that does not conform to the 3GPP standard specification, for example, an air interface technology represented by an access point (access point, AP) in wireless fidelity (wireless fidelity, Wi-Fi).

基于无线通信技术实现接入网络功能的接入网可以称为无线接入网(RAN)。无线接入网能够管理无线资源,为终端设备提供接入服务,进而完成控制信号和用户数据在终端设备和核心网之间的转发。An access network that implements access network functions based on wireless communication technology may be referred to as a radio access network (RAN). The wireless access network can manage wireless resources, provide access services for terminal equipment, and then complete the forwarding of control signals and user data between terminal equipment and the core network.

接入网设备例如可以是基站(NodeB)、演进型基站(evolved NodeB,eNB或eNodeB)、5G移动通信系统中的基站(gNB)、未来移动通信系统中的基站或Wi-Fi系统中的AP等,还可以是云无线接入网络(cloud radio access network,CRAN)场景下的无线控制器,或者该接入网设备可以为中继站、接入点、车载设备、可穿戴设备以及未来5G网络中的网络设备或者未来演进的PLMN中的网络设备等。本申请的实施例对接入网设备所采用的具体技术和具体设备形态不做限定。The access network equipment can be, for example, a base station (NodeB), an evolved base station (evolved NodeB, eNB or eNodeB), a base station (gNB) in a 5G mobile communication system, a base station in a future mobile communication system, or an AP in a Wi-Fi system etc., it can also be a wireless controller in a cloud radio access network (cloud radio access network, CRAN) scenario, or the access network device can be a relay station, an access point, a vehicle-mounted device, a wearable device, or a device in a future 5G network. network equipment or network equipment in the future evolved PLMN. The embodiment of the present application does not limit the specific technology and specific equipment form adopted by the access network equipment.

3、接入和移动管理功能(access and mobility management function,AMF)网元:AMF网元主要用于移动性管理和接入管理等,可以用于实现MME功能中除会话管理之外的其它功能,例如,合法监听、或接入授权(或鉴权)等功能。3. Access and mobility management function (AMF) network elements: AMF network elements are mainly used for mobility management and access management, etc., and can be used to implement other functions in MME functions except session management , for example, functions such as lawful interception, or access authorization (or authentication).

4、认证服务功能(authentication server function,AUSF)网元:AUSF网元主要用于用户鉴权等。4. Authentication server function (authentication server function, AUSF) network element: the AUSF network element is mainly used for user authentication and the like.

5、统一数据管理(unified data management,UDM)网元:UDM网元用于处理用户标识、接入鉴权、注册、或移动性管理等。5. Unified data management (unified data management, UDM) network element: the UDM network element is used to process user identification, access authentication, registration, or mobility management.

6、网络开放功能(network exposure function,NEF)网元:NEF网元用于支持能力和事件的开放。6. Network exposure function (network exposure function, NEF) network element: The NEF network element is used to support the exposure of capabilities and events.

7、网络存储功能(network repository function,NRF)网元:NRF网元用于提供网元发现功能,基于其他网元的请求,提供网元类型对应的网元信息。NRF还提供网元管理服务,如网元注册、更新、去注册以及网元状态订阅和推送等。7. Network repository function (network repository function, NRF) network element: The NRF network element is used to provide a network element discovery function, and based on the request of other network elements, provide network element information corresponding to the network element type. NRF also provides network element management services, such as network element registration, update, de-registration, network element status subscription and push, etc.

8、策略控制功能(policy control function,PCF)网元:PCF网元包含负责针对会话、业务流级别进行计费、服务质量(quality of service,QoS)带宽保障及移动性管理、终端策略决策等策略控制功能。8. Policy control function (policy control function, PCF) network element: PCF network element includes billing for sessions and service flow levels, quality of service (quality of service, QoS) bandwidth guarantee and mobility management, terminal policy decisions, etc. Policy control function.

9、用户面功能(user plane function,UPF)网元:UFP网元作为和数据网络的接口,包含完成用户面数据转发、基于会话/流级的计费统计,带宽限制等功能。9. User plane function (user plane function, UPF) network element: UFP network element is used as an interface with the data network, including functions such as completing user plane data forwarding, session/flow-based charging statistics, and bandwidth limitation.

10、会话管理功能(session management function,SMF)网元,包含执行会话管理、PCF下发控制策略的执行、UPF的选择、终端设备的IP地址分配等功能。10. A session management function (session management function, SMF) network element, including functions such as executing session management, executing control policies issued by the PCF, selecting UPF, and assigning IP addresses to terminal equipment.

在图2所示的网络架构中,N1接口为终端设备与AMF网元之间的参考点;N2接口为AN和AMF网元的参考点,用于非接入层(non-access stratum,NAS)消息的发送等;N3接口为(R)AN和UPF网元之间的参考点,用于传输用户面的数据等;N4接口为SMF网元和UPF网元之间的参考点,用于传输例如N3连接的隧道标识信息,数据缓存指示信息,以及下行数据通知消息等信息;N6接口为UPF网元和据网络(data network,DN)之间的参考点,用于传输用户面的数据等。In the network architecture shown in Figure 2, the N1 interface is the reference point between the terminal equipment and the AMF network element; the N2 interface is the reference point between the AN and the AMF network element, and is used for the non-access stratum (NAS ) messages, etc.; N3 interface is the reference point between (R)AN and UPF network elements, used to transmit user plane data, etc.; N4 interface is the reference point between SMF network elements and UPF network elements, used for Transmit information such as the tunnel identification information of the N3 connection, data cache indication information, and downlink data notification messages; the N6 interface is the reference point between the UPF network element and the data network (DN), and is used to transmit data on the user plane wait.

应理解,上述图2所示的网络架构可以应用于本申请实施例,此外,适用本申请实施例的网络架构并不局限于此,任何能够实现上述各个网元的功能的网络架构都适用于本申请实施例。It should be understood that the above-mentioned network architecture shown in FIG. 2 can be applied to the embodiment of the present application. In addition, the network architecture applicable to the embodiment of the present application is not limited thereto. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to Example of this application.

还应理解,图2中所示的AMF网元、SMF网元、UPF网元、NEF网元、AUSF网元、NRF网元、PCF网元、UDM网元可以理解为核心网中用于实现不同功能的网元,例如可以按需组合成网络切片。这些核心网网元可以各自独立的设备,也可以集成于同一设备中实现不同的功能,本申请对此不做限定。需要说明的是,上述“网元”也可以称为实体、设备、装置或模块等,本申请并未特别限定。It should also be understood that the AMF network element, SMF network element, UPF network element, NEF network element, AUSF network element, NRF network element, PCF network element, and UDM network element shown in FIG. Network elements with different functions, for example, can be combined into network slices on demand. These network elements of the core network may be independent devices, or may be integrated into the same device to implement different functions, which is not limited in this application. It should be noted that the foregoing "network element" may also be referred to as an entity, device, device, or module, etc., which are not specifically limited in this application.

还应理解,上述命名仅为用于区分不同的功能,并不代表这些网元分别为独立的物理设备,本申请对于上述网元的具体形态不作限定,例如,可以集成在同一个物理设备中,也可以分别是不同的物理设备。此外,上述命名仅为便于区分不同的功能,而不应对本申请构成任何限定,本申请并不排除在5G网络以及未来其它的网络中采用其他命名的可能。例如,在6G网络中,上述各个网元中的部分或全部可以沿用5G中的术语,也可能采用其他名称等。在此进行统一说明,以下不再赘述。It should also be understood that the above naming is only used to distinguish different functions, and does not mean that these network elements are independent physical devices. This application does not limit the specific form of the above network elements. For example, they can be integrated in the same physical device , can also be different physical devices. In addition, the above naming is only for the convenience of distinguishing different functions, and should not constitute any limitation to this application, and this application does not exclude the possibility of using other naming in 5G network and other networks in the future. For example, in a 6G network, some or all of the above network elements may use the terms in 5G, or may use other names. A unified description will be made here, and details will not be repeated below.

还应理解,图2中的各个网元之间基于服务化接口进行通信,例如各个网元之间使用服务化接口进行信息交互或调用服务。图2中的各个网元之间的接口名称只是一个示例,具体实现中接口的名称可能为其他的名称,本申请对此不作具体限定。此外,上述各个网元之间的所传输的消息(或信令)的名称也仅仅是一个示例,对消息本身的功能不构成任何限定。It should also be understood that the communication between network elements in FIG. 2 is based on the service-oriented interface, for example, the service-oriented interface is used between network elements to perform information exchange or call services. The name of the interface between network elements in FIG. 2 is just an example, and the name of the interface in a specific implementation may be another name, which is not specifically limited in this application. In addition, the name of the message (or signaling) transmitted between the above network elements is only an example, and does not constitute any limitation on the function of the message itself.

在该网络架构中,RAN支持2种接入技术,即3GPP接入技术和非3GPP接入技术。从图2中可以看出,终端设备如果通过非3GPP技术接入到5G核心网是需要经过AMF网元的,例如需要AMF网元执行主鉴权流程,完成终端设备和网络侧的互相认证。事实上,在3GPP和非3GPP融合的背景下,终端设备通过3GPP和非3GPP接入技术接入5G核心网并进行鉴权时都经过AMF网元。在这种情况下,如果终端设备可以通过非3GPP接入完成用户面数据交互,那么需要接入5G核心网就会导致AMF网元处理、信令交互等负担较重,影响网络的通信效率。另外,终端设备通过非3GPP技术接入到5G核心网的网络架构还未进行实际部署,而且部署该网络架构需要的花销非常大。In this network architecture, RAN supports two access technologies, namely 3GPP access technologies and non-3GPP access technologies. It can be seen from Figure 2 that if a terminal device accesses the 5G core network through a non-3GPP technology, it needs to pass through the AMF network element. For example, the AMF network element needs to perform the main authentication process to complete the mutual authentication between the terminal device and the network side. In fact, in the context of the integration of 3GPP and non-3GPP, terminal equipment accesses the 5G core network through 3GPP and non-3GPP access technologies and performs authentication through AMF network elements. In this case, if the terminal device can complete the user plane data interaction through non-3GPP access, then the need to access the 5G core network will lead to heavy burdens such as AMF network element processing and signaling interaction, which will affect the communication efficiency of the network. In addition, the network architecture in which terminal devices are connected to the 5G core network through non-3GPP technologies has not yet been actually deployed, and the deployment of this network architecture requires a very high cost.

鉴于4G系统中NSWO模式下,终端设备可以经过WLAN接入点而不经过MME接入网络,且终端设备通过NSWO模式接入网络的架构已经基本部署完毕,因此目前业内提出终端设备通过NSWO模式接入5G核心网的方案。参考图3,为5G中的NSWO架构示意图。在5G NSWO架构中,新增NSWO网络功能(network funciton,NF)网元,NSWONF网元通过Swa接口与不信任的非3GPP接入网连接,以及通过Nx(x代表还没有定义接口编号)接口与AUSF连接。NSWO NF网元具有Swa接口与Nx接口之间的协议转换功能。其中,Swa接口可以是基于远程用户拨号认证系统(Remote Authentication Dial-In User Service,RADIUS)协议或者Diameter协议,Nx接口可以是基于业务的接口(service-based interface,SBI)接口。本申请实施例对NSWO NF网元的名称不做限定,在未来通信中也可以对NSWO NF网元的名字进行更换。本申请实施例中,NSWO网元也可以称为NSWO NF网元,或者简称为NSWO NF。In view of the NSWO mode in the 4G system, the terminal device can access the network through the WLAN access point instead of the MME, and the architecture of the terminal device accessing the network through the NSWO mode has basically been deployed. A solution for accessing the 5G core network. Referring to Figure 3, it is a schematic diagram of the NSWO architecture in 5G. In the 5G NSWO architecture, a new NSWO network function (network funciton, NF) network element is added. The NSWONF network element is connected to the untrusted non-3GPP access network through the Swa interface, and through the Nx (x represents that the interface number has not been defined) interface Connect with AUSF. The NSWO NF network element has the protocol conversion function between the Swa interface and the Nx interface. Wherein, the Swa interface may be based on Remote Authentication Dial-In User Service (RADIUS) protocol or Diameter protocol, and the Nx interface may be a service-based interface (service-based interface, SBI) interface. The embodiment of the present application does not limit the name of the NSWO NF network element, and the name of the NSWO NF network element can also be changed in future communications. In the embodiment of the present application, the NSWO network element may also be referred to as the NSWO NF network element, or as the NSWO NF for short.

为方便描述,本申请实施例中将统一数据管理(UDM)网元简称为UDM,将认证服务功能网元(AUSF)网元简称为AUSF,将网络存储功能(NRF)网元简称为NRF。For convenience of description, in the embodiments of the present application, the unified data management (UDM) network element is referred to as UDM, the authentication service function network element (AUSF) network element is referred to as AUSF, and the network storage function (NRF) network element is referred to as NRF.

本申请实施例中,归属网络的标识信息指的是用于标识归属网络的标识信息,归属网络的标识信息可以是归属网络标识(home network identifier,HNI),也可以是其它能够标识归属网络的信息,这里做统一说明,后面不做赘述。为便于描述,本申请实施例中,以归属网络的标识信息是HNI为例进行说明。In this embodiment of the present application, the identification information of the home network refers to the identification information used to identify the home network, and the identification information of the home network may be a home network identifier (home network identifier, HNI), or other information that can identify the home network. Information, here is a unified explanation, and I won’t repeat it later. For ease of description, in the embodiment of the present application, the identification information of the home network is HNI as an example for illustration.

本申请实施例中,路由标识(routing ID,RID)用于为终端设备选择可以服务的AUSF和/或UDM。In this embodiment of the present application, a routing ID (routing ID, RID) is used to select a serviceable AUSF and/or UDM for a terminal device.

本申请实施例中,UDM具有NSWO鉴权能力,也可以理解为是UDM能够选择出一个用于NSWO鉴权的鉴权方法,或者理解为UDM能够识别指示终端设备使用NSWO的方式接入网络的指示信息。并且,在目前的5G网络中,未升级的UDM不具有NSWO鉴权能力,升级后的UDM具有NSWO鉴权能力,因此本申请实施例中,具有NSWO鉴权能力的UDM可以理解为是升级后的UDM。In the embodiment of this application, UDM has NSWO authentication capability, which can also be understood as UDM can select an authentication method for NSWO authentication, or it can be understood as UDM can identify and instruct terminal equipment to use NSWO to access the network Instructions. Moreover, in the current 5G network, the unupgraded UDM does not have the NSWO authentication capability, and the upgraded UDM has the NSWO authentication capability. Therefore, in the embodiment of this application, the UDM with the NSWO authentication capability can be understood as the upgraded UDMs.

本申请实施例中,AUSF具有NSWO鉴权能力,也可以理解为是AUSF能够识别指示终端设备使用NSWO的方式接入网络的指示信息。并且,在目前的5G网络中,未升级的AUSF不具有NSWO鉴权能力,升级后的AUSF具有NSWO鉴权能力,因此本申请实施例中,具有NSWO鉴权能力的AUSF可以理解为是升级后的AUSF。In the embodiment of the present application, the AUSF has the NSWO authentication capability, which can also be understood as the AUSF being able to identify the indication information instructing the terminal device to use the NSWO method to access the network. Moreover, in the current 5G network, the unupgraded AUSF does not have the NSWO authentication capability, and the upgraded AUSF has the NSWO authentication capability. Therefore, in the embodiment of this application, the AUSF with the NSWO authentication capability can be understood as the upgraded AUSF AUSF.

参考图4,为本申请实施例提供的一种网元的选择方法的流程图。该方法用于选择具有NSWO鉴权能力的UDM。该方法可以由AUSF或用于AUSF的模块(如芯片)执行,或者也可以由NRF或用于NRF的模块(如芯片)执行。Referring to FIG. 4 , it is a flow chart of a method for selecting a network element provided in an embodiment of the present application. This method is used to select a UDM with NSWO authentication capability. The method may be executed by the AUSF or a module (such as a chip) for the AUSF, or may also be executed by the NRF or a module (such as a chip) for the NRF.

该方法包括以下步骤:The method includes the following steps:

步骤401,接收第一HNI和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络。Step 401, receiving the first HNI and indication information, the indication information instructing the terminal device to use NSWO to access the network.

该指示信息也可以用NSWO indicator表示,或者用其它名称表示,本申请实施例不做限定。这里做统一描述,后面不再赘述。The indication information may also be expressed by NSWO indicator, or by other names, which is not limited in this embodiment of the present application. A unified description is made here and will not be repeated later.

作为一种实现方法,本申请实施例中的指示信息可以包括在服务网络名称(serving network name,SNN)中,或者可以是能够用于指示终端设备使用NSWO的方式接入网络的SNN;或者该指示信息可以包括在用户隐藏标识(subscription concealedidentifier,SUCI)中,或者可以是网络接入标识(network access identifier,NAI)格式的SUCI;或者该指示信息是一个单独的信息(例如比特信息),这里做统一描述,后面不再赘述。As an implementation method, the indication information in this embodiment of the present application may be included in a serving network name (serving network name, SNN), or may be an SNN that can be used to instruct the terminal device to access the network using NSWO; or the The indication information may be included in a user concealed identifier (subscription concealed identifier, SUCI), or may be a SUCI in a network access identifier (network access identifier, NAI) format; or the indication information is a separate piece of information (such as bit information), where Do a unified description, and will not repeat them later.

该指示信息指示终端设备使用NSWO的方式接入网络,也可以理解为该指示信息指示对处于NSWO鉴权流程的终端设备进行鉴权,或者理解为该指示信息指示当前处于NSWO鉴权流程,这里做统一说明,后面不做赘述。The indication information indicates that the terminal device uses the NSWO method to access the network. It can also be understood that the indication information indicates that the terminal equipment in the NSWO authentication process is authenticated, or that the indication information indicates that it is currently in the NSWO authentication process. Here Make a unified description, and will not repeat it later.

步骤402,根据指示信息,选择与第一HNI对应的第一UDM,该第一UDM具有NSWO鉴权能力。Step 402: Select the first UDM corresponding to the first HNI according to the indication information, and the first UDM has NSWO authentication capability.

可以理解为,该指示信息触发执行:选择一个具有NSWO鉴权能力的UDM。It can be understood that the indication information triggers the execution of selecting a UDM with NSWO authentication capability.

根据上述方案,可以实现选择一个具有NSWO鉴权能力的UDM,从而该UDM可以为使用NSWO的方式接入网络的终端设备提供NSWO鉴权服务,有助于实现终端设备的快速和正确接入。According to the above solution, it is possible to select a UDM with NSWO authentication capability, so that the UDM can provide NSWO authentication services for terminal devices accessing the network in NSWO mode, which helps to realize fast and correct access of terminal devices.

下面介绍上述方法的一种应用场景。在目前的5G网络中,UDM(可以是未升级的UDM或升级后的UDM)支持两种鉴权方法,即可扩展认证协议-认证和密钥协商(extensibleauthentication protocol-authentication and key agreement,EAP-AKA’)鉴权方法和5G-AKA鉴权方法。目前,在终端设备使用NSWO的方式接入网络的场景中,已经确定只能使用EAP-AKA’鉴权方法对终端设备进行鉴权。为实现在终端设备使用NSWO的方式接入网络的场景中,让UDM能够选择到EAP-AKA’鉴权方法,一种可能的实现方法是:向UDM发送一个指示信息,该指示信息指示终端设备使用NSWO的方式接入网络,当该UDM收到该指示信息,则触发该UDM选择EAP-AKA’鉴权方法,而不选择5G-AKA鉴权方法。然而,根据前面的描述,如果该UDM是未升级的UDM,则该UDM不具有NSWO鉴权能力,因此该UDM不能识别该指示信息,从而无法保证该UDM一定可以选择到EAP-AKA’鉴权方法。如果该UDM是升级后的UDM,则该UDM具有NSWO鉴权能力,因此该UDM能够识别该指示信息,从而可以保证该UDM可以选择到EAP-AKA’鉴权方法。因此,结合上述图4对应的方法实施例,可以实现选择一个具有NSWO鉴权能力的UDM(即升级后的UDM),进而在终端设备使用NSWO的方式接入网络的场景中,该具有NSWO鉴权能力的UDM能够识别收到的上述指示信息,从而确保该UDM根据该指示信息能够选择到EAP-AKA’鉴权方法。An application scenario of the above method is introduced below. In the current 5G network, UDM (which can be a non-upgraded UDM or an upgraded UDM) supports two authentication methods, that is, extensible authentication protocol-authentication and key agreement (EAP- AKA') authentication method and 5G-AKA authentication method. At present, in the scenario where the terminal device uses NSWO to access the network, it has been determined that only the EAP-AKA' authentication method can be used to authenticate the terminal device. In order to enable the UDM to select the EAP-AKA' authentication method in the scenario where the terminal device uses NSWO to access the network, a possible implementation method is to send an indication message to the UDM, which indicates the terminal device Using NSWO to access the network, when the UDM receives the indication information, the UDM is triggered to select the EAP-AKA' authentication method instead of the 5G-AKA authentication method. However, according to the above description, if the UDM is not upgraded, the UDM does not have the NSWO authentication capability, so the UDM cannot recognize the indication information, so it cannot be guaranteed that the UDM can definitely select EAP-AKA' authentication method. If the UDM is an upgraded UDM, the UDM has NSWO authentication capability, so the UDM can recognize the indication information, thereby ensuring that the UDM can select the EAP-AKA' authentication method. Therefore, in combination with the method embodiment corresponding to Figure 4 above, it is possible to select a UDM with NSWO authentication capability (that is, an upgraded UDM), and then in the scenario where the terminal device uses NSWO to access the network, the NSWO authentication capability can be selected. The UDM with authorization capability can identify the received indication information, so as to ensure that the UDM can select the EAP-AKA' authentication method according to the indication information.

作为一种实现方法,本申请实施例可以预定义HNI与UDM之间的映射关系,该映射关系可以通过表格的形式定义,或者通过函数的形式定义,本申请实施例对于该映射关系的定义形式不做限定。以下以表格的定义形式为例进行说明。As an implementation method, the embodiment of the present application can predefine the mapping relationship between HNI and UDM. The mapping relationship can be defined in the form of a table or in the form of a function. The definition form of the mapping relationship in the embodiment of the present application No limit. The definition form of the table is taken as an example to illustrate below.

其中,HNI与UDM之间的映射关系可以存储在NRF或AUSF上,或者也可以存储于一个独立于NRF或AUSF的数据库中。Wherein, the mapping relationship between HNI and UDM can be stored in NRF or AUSF, or can also be stored in a database independent of NRF or AUSF.

示例性的,以下表1-1为HNI与具有NSWO鉴权能力的UDM之间的映射关系示例。Exemplarily, the following table 1-1 is an example of the mapping relationship between HNI and UDM with NSWO authentication capability.

表1-1Table 1-1

HNIHNI 具有NSWO鉴权能力的UDMUDM with NSWO authentication capability HNI 1HNI 1 UDM1的标识信息或UDM集合1的标识信息Identification information of UDM1 or identification information of UDM set 1 HNI 2HNI 2 UDM 2的标识信息或UDM集合2的标识信息Identification information of UDM 2 or identification information of UDM set 2 HNI 3HNI 3 UDM 3的标识信息或UDM集合3的标识信息Identification information of UDM 3 or identification information of UDM set 3

其中,上述表1-1所示的映射关系中的每个UDM都是具有NSWO鉴权能力的UDM,即升级后的UDM。本申请实施例中,将HNI与具有NSWO鉴权能力的UDM之间的映射关系称为第一映射关系。Wherein, each UDM in the mapping relationship shown in Table 1-1 above is a UDM with NSWO authentication capability, that is, an upgraded UDM. In the embodiment of the present application, the mapping relationship between the HNI and the UDM with NSWO authentication capability is referred to as the first mapping relationship.

作为一种实现方法,本申请实施例中还可以定义HNI与不具有NSWO鉴权能力的UDM之间的映射关系。本申请实施例中,将HNI与不具有NSWO鉴权能力的UDM之间的映射关系称为第二映射关系。As an implementation method, in the embodiment of the present application, the mapping relationship between the HNI and the UDM without NSWO authentication capability can also be defined. In the embodiment of the present application, the mapping relationship between the HNI and the UDM without NSWO authentication capability is referred to as the second mapping relationship.

示例性的,以下表1-2为HNI与不具有NSWO鉴权能力的UDM之间的映射关系示例。Exemplarily, the following table 1-2 is an example of the mapping relationship between HNI and UDM without NSWO authentication capability.

表1-2Table 1-2

HNIHNI 不具有NSWO鉴权能力的UDMUDM without NSWO authentication capability HNI 1HNI 1 UDM4的标识信息或UDM集合4的标识信息Identification information of UDM4 or identification information of UDM set 4 HNI 2HNI 2 UDM 5的标识信息或UDM集合5的标识信息Identification information of UDM 5 or identification information of UDM set 5 HNI 3HNI 3 UDM 6的标识信息或UDM集合6的标识信息Identification information of UDM 6 or identification information of UDM set 6

其中,上述表1-2所示的映射关系中的每个UDM都是不具有NSWO鉴权能力的UDM,即未升级的UDM网元。Wherein, each UDM in the mapping relationship shown in Table 1-2 above is a UDM without NSWO authentication capability, that is, a UDM network element that has not been upgraded.

上述第一映射关系或第二映射关系中,一个HNI可以唯一对应一个UDM的标识信息,该标识信息可以是实例标识(instance ID)、地址(address)或完全限定域名(fullyqualified domain name,FQDN)。一个HNI也可以对应一个UDM集合的标识信息(set ID),该UDM集合内包含多个UDM的标识信息。当根据一个HNI得到该HNI对应的UDM集合时,则可以进一步从该UDM集合中选择一个UDM,比如可以是按照预设的规则选择一个UDM,或者是从UDM集合中随机选择一个UDM,本申请实施例对从UDM集合中选择一个UDM的实现方法不做限定。In the first mapping relationship or the second mapping relationship above, one HNI can uniquely correspond to the identification information of one UDM, and the identification information can be an instance ID (instance ID), an address (address) or a fully qualified domain name (fullyqualified domain name, FQDN) . One HNI may also correspond to the identification information (set ID) of a UDM set, and the UDM set includes identification information of multiple UDMs. When the UDM set corresponding to the HNI is obtained according to an HNI, a UDM can be further selected from the UDM set, for example, a UDM can be selected according to a preset rule, or a UDM can be randomly selected from the UDM set. The embodiment does not limit the implementation method of selecting a UDM from the UDM set.

本申请实施例中,一个HNI包括移动国家码(mobile country code,MCC)和移动网络码(mobile network code,MNC),因此上述第一映射关系或第二映射关系中,一个HNI也可以用MCC和MNC的组合进行替换。比如,上述表1-1中的HNI 1可以用(MCC=A,MNC=B)进行替换,HNI 2可以用(MCC=A,MNC=C)进行替换,HNI 3可以用(MCC=E,MNC=F)进行替换。上述表1-2也可以用类似的方法进行替换。In the embodiment of the present application, an HNI includes a mobile country code (mobile country code, MCC) and a mobile network code (mobile network code, MNC). Therefore, in the above-mentioned first mapping relationship or second mapping relationship, an HNI can also use MCC and MNC combination to replace. For example, HNI 1 in the above Table 1-1 can be replaced by (MCC=A, MNC=B), HNI 2 can be replaced by (MCC=A, MNC=C), HNI 3 can be replaced by (MCC=E, MNC=F) for substitution. The above Tables 1-2 can also be replaced by a similar method.

作为一种实现方法,上述步骤402,具体可以是:根据指示信息,从上述第一映射关系中选择与第一HNI对应的第一UDM。As an implementation method, the above step 402 may specifically be: selecting the first UDM corresponding to the first HNI from the above first mapping relationship according to the indication information.

作为一种实现方法,如果NRF或AUSF接收到第二HNI,但没有收到指示终端设备使用NSWO的方式接入网络的指示信息,则NRF或AUSF可以从上述第二映射关系中选择与第二HNI对应的第二UDM,该第二UDM不具有NSWO鉴权能力。As an implementation method, if the NRF or AUSF receives the second HNI, but does not receive the indication information instructing the terminal device to access the network through NSWO, the NRF or AUSF can select the second HNI from the above-mentioned second mapping relationship. The second UDM corresponding to the HNI does not have the NSWO authentication capability.

作为另一种实现方法,如果NRF或AUSF接收到第二HNI,但没有收到指示终端设备使用NSWO的方式接入网络的指示信息,则NRF或AUSF可以基于现有的选择逻辑,根据第二HNI选择UDM,该UDM既可以具有NSWO鉴权能力,也可以不具有NSWO鉴权能力,也就是说,NRF或AUSF所选择的UDM是否具有NSWO鉴权能力,是不确定的。As another implementation method, if the NRF or AUSF receives the second HNI, but does not receive the indication information instructing the terminal device to use the NSWO method to access the network, the NRF or AUSF can base on the existing selection logic, according to the second HNI selects UDM, which may or may not have NSWO authentication capability. In other words, it is uncertain whether the UDM selected by NRF or AUSF has NSWO authentication capability.

作为再一种实现方法,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者AUSF可以根据本地策略,从上述第一映射关系中选择与第二HNI对应的具有NSWO鉴权能力的一个UDM,或者从上述第二映射关系中选择与第二HNI对应的不具有NSWO鉴权能力的一个UDM。比如,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者AUSF根据本地策略,优先从第一映射关系中选择与第二HNI对应的具有NSWO鉴权能力的一个UDM。再比如,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者AUSF根据本地策略,优先从第二映射关系中选择与第二HNI对应的不具有NSWO鉴权能力的一个UDM。As yet another implementation method, in the case of not receiving the instruction information instructing the terminal device to use NSWO to access the network, the NRF or AUSF can select the HNI corresponding to the second HNI from the above-mentioned first mapping relationship according to the local policy. A UDM with NSWO authentication capability, or a UDM without NSWO authentication capability corresponding to the second HNI selected from the second mapping relationship. For example, in the case of not receiving the instruction information instructing the terminal device to use NSWO to access the network, the NRF or AUSF will preferentially select the NSWO authentication capability corresponding to the second HNI from the first mapping relationship according to the local policy. A UDM. For another example, in the case of not receiving the instruction information instructing the terminal device to use the NSWO method to access the network, the NRF or AUSF, according to the local policy, preferentially selects the second HNI corresponding to the second HNI without NSWO authentication from the second mapping relationship. A UDM of capabilities.

作为一种实现方法,本申请实施例中,终端设备的签约数据(也称为用户签约数据)可以存储于数据库(unified data repository,UDR)上,该UDR上的同一个用户签约数据可以由多个UDM进行获取,比如可以由对应相同HNI的不同UDM去UDR获取相同的用户签约数据。结合上面介绍的各种选择UDM的实现方法,不管NRF或AUSF所选择的UDM是否具有NSWO鉴权能力,只要这些UDM对应相同的HNI,则这些UDM均可以从UDR获取相同的用户签约数据,该用户签约数据对应该HNI。下面结合一个示例说明。比如,如果NRF或AUSF收到HNI 1和指示终端设备使用NSWO的方式接入网络的指示信息,NRF或AUSF根据上述表1-1,选择具有NSWO鉴权能力的UDM 1。如果NRF或AUSF收到HNI 1,且没有收到指示终端设备使用NSWO的方式接入网络的指示信息,假设NRF或AUSF根据上述表1-2,选择不具有NSWO鉴权能力的UDM4。该示例中,UDM 1和UDM 4均对应HNI 1,因此UDM 1和UDM 4均可以从同一个UDR中获取相同的用户签约数据,该用户签约数据对应该HNI 1。As an implementation method, in the embodiment of the present application, the subscription data (also called user subscription data) of the terminal device may be stored in a database (unified data repository, UDR), and the same user subscription data on the UDR may be stored by multiple For example, different UDMs corresponding to the same HNI can go to UDR to obtain the same user subscription data. Combined with the implementation methods of selecting UDM introduced above, regardless of whether the UDM selected by NRF or AUSF has NSWO authentication capability, as long as these UDMs correspond to the same HNI, these UDMs can obtain the same user subscription data from the UDR. The user subscription data corresponds to the HNI. The following is combined with an example. For example, if NRF or AUSF receives HNI 1 and instruction information instructing the terminal device to use NSWO to access the network, NRF or AUSF selects UDM 1 with NSWO authentication capability according to the above Table 1-1. If the NRF or AUSF receives HNI 1 and does not receive the instruction information instructing the terminal device to use NSWO to access the network, it is assumed that the NRF or AUSF selects UDM4 without NSWO authentication capability according to the above table 1-2. In this example, both UDM 1 and UDM 4 correspond to HNI 1, so both UDM 1 and UDM 4 can obtain the same user subscription data from the same UDR, and the user subscription data corresponds to HNI 1.

下面结合上述表1-1和表1-2,给出上述图4对应的方法实施例的一个具体示例。以NRF执行上述图4对应的方法实施例为例。A specific example of the method embodiment corresponding to the above-mentioned FIG. 4 is given below in conjunction with the above-mentioned Table 1-1 and Table 1-2. Take the NRF executing the method embodiment corresponding to FIG. 4 above as an example.

在一个示例中,NRF收到HNI1和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络,则该指示信息触发NRF从上述表1-1中选择一个具有NSWO鉴权能力的UDM,具体的,选择的是UDM 1,或者选择的是UDM集合1的标识信息所指示的UDM集合内的一个UDM。NRF根据该指示信息,不会从表1-2中选择不具有NSWO鉴权能力的UDM(即升级前的UDM)。通过该方法,使用该指示信息,触发NRF从上述表1-1中选择一个具有NSWO鉴权能力的UDM。In an example, the NRF receives HNI1 and indication information, the indication information indicates that the terminal device uses NSWO to access the network, and the indication information triggers the NRF to select a UDM with NSWO authentication capability from the above table 1-1, Specifically, UDM 1 is selected, or a UDM in the UDM set indicated by the identification information of UDM set 1 is selected. According to the indication information, the NRF will not select the UDM without NSWO authentication capability (that is, the UDM before the upgrade) from Table 1-2. Through this method, the indication information is used to trigger the NRF to select a UDM with NSWO authentication capability from the above Table 1-1.

在又一个示例中,NRF收到HNI1,但没有收到上述指示终端设备使用NSWO的方式接入网络的指示信息,则NRF从上述表1-2中选择一个不具有NSWO鉴权能力的UDM,具体的,选择的是UDM 4,或者选择的是UDM集合4的标识信息所指示的UDM集合内的一个UDM。由于没有收到上述指示信息,则NRF不会从表1-1中选择具有NSWO鉴权能力的UDM。通过该方法,NRF从上述表1-2中选择一个不具有NSWO鉴权能力的UDM。In yet another example, NRF receives HNI1, but does not receive the above indication information instructing the terminal device to use NSWO to access the network, then NRF selects a UDM without NSWO authentication capability from the above table 1-2, Specifically, UDM 4 is selected, or a UDM in the UDM set indicated by the identification information of UDM set 4 is selected. Since the above indication information has not been received, the NRF will not select a UDM with NSWO authentication capability from Table 1-1. Through this method, NRF selects a UDM without NSWO authentication capability from the above table 1-2.

在又一个示例中,NRF收到HNI1,但没有收到上述指示终端设备使用NSWO的方式接入网络的指示信息,则NRF既可以从上述表1-1中选择一个具有NSWO鉴权能力的UDM,也可以从上述表1-2中选择一个不具有NSWO鉴权能力的UDM,具体如何选择,取决于实现,比如根据本地策略进行选择。可以理解的是,如果没有收到上述指示信息,则NRF选择的UDM可能具有NSWO鉴权能力,也可能不具有NSWO鉴权能力。In another example, NRF receives HNI1, but does not receive the above indication information instructing the terminal device to use NSWO to access the network, then NRF can select a UDM with NSWO authentication capability from the above table 1-1 , you can also select a UDM that does not have NSWO authentication capability from the above table 1-2. The specific selection depends on the implementation, such as selection according to local policies. It can be understood that if the above indication information is not received, the UDM selected by the NRF may or may not have the NSWO authentication capability.

作为一种实现方法,本申请实施例还可以建立上述指示信息与上述第一映射关系或第二映射关系之间的关联。As an implementation method, this embodiment of the present application may further establish an association between the foregoing indication information and the foregoing first mapping relationship or the second mapping relationship.

一种实现方法是,建立指示信息与上述第一映射关系的关联,通过该指示信息可以找到该第一映射关系。One implementation method is to establish an association between the indication information and the above-mentioned first mapping relationship, and the first mapping relationship can be found through the indication information.

另一种实现方法是,将上述第一映射关系与第二映射关系进行结合,以及将该指示信息作为结合后的映射关系的一部分,该指示信息指示终端设备使用NSWO的方式接入网络。以上述表1-1和表1-2为例,可以将上述表1-1与上述表1-2进行结合,并在结合后的表中增加指示信息,可以得到如表1-3所示的映射关系。Another implementation method is to combine the above-mentioned first mapping relationship with the second mapping relationship, and use the indication information as part of the combined mapping relationship, the indication information instructing the terminal device to use NSWO to access the network. Taking the above Table 1-1 and Table 1-2 as an example, the above Table 1-1 can be combined with the above Table 1-2, and the instruction information can be added to the combined table, as shown in Table 1-3. mapping relationship.

表1-3Table 1-3

Figure BDA0003261882390000131
Figure BDA0003261882390000131

其中,上述表1-3中,UDM 1、UDM2、UDM 3、UDM集合1内的UDM、UDM集合2内的UDM以及UDM集合3内的UDM均是具有NSWO鉴权能力的UDM。UDM 4、UDM 5、UDM 6、UDM集合4内的UDM、UDM集合5内的UDM以及UDM集合6内的UDM均是不具有NSWO鉴权能力的UDM。Among them, in the above Tables 1-3, UDM 1, UDM 2, UDM 3, UDMs in UDM set 1, UDMs in UDM set 2, and UDMs in UDM set 3 are all UDMs with NSWO authentication capability. UDM 4, UDM 5, UDM 6, UDMs in UDM set 4, UDMs in UDM set 5, and UDMs in UDM set 6 are UDMs without NSWO authentication capability.

作为一个示例,如果NRF或AUSF接收到HNI 1,则可以根据表1-3确定HNI 1对应的UDM 4或UDM集合4内的一个UDM。如果NRF或AUSF收到HNI 1和指示信息,则根据表1-3确定HNI 1对应的UDM 1或UDM集合1内的一个UDM。As an example, if the NRF or AUSF receives the HNI 1, the UDM 4 corresponding to the HNI 1 or a UDM in the UDM set 4 can be determined according to Table 1-3. If the NRF or AUSF receives HNI 1 and indication information, it determines the UDM 1 corresponding to HNI 1 or a UDM in UDM set 1 according to Table 1-3.

作为一种实现方法,在上述步骤401中还可以接收第一RID,且上述步骤402,具体是:根据上述指示信息,选择与第一HNI和第一RID对应的第一UDM。也即,该方法中,是通过HNI和RID的组合,去找到相应的UDM。As an implementation method, the first RID may also be received in the above step 401, and the above step 402, specifically: according to the above indication information, select the first UDM corresponding to the first HNI and the first RID. That is, in this method, the corresponding UDM is found through the combination of the HNI and the RID.

本申请实施例中,可以定义HNI和RID的组合与UDM之间的映射关系,也即通过HNI和RID的组合去找到相应的UDM。该映射关系可以通过表格的形式定义,或者通过函数的形式定义,本申请实施例对于该映射关系的定义形式不做限定。以下以表格的定义形式为例进行说明。其中,HNI和RID的组合与UDM之间的映射关系可以存储在NRF或AUSF上,或者也可以存储于一个独立于NRF或AUSF的数据库中。In the embodiment of the present application, the mapping relationship between the combination of the HNI and the RID and the UDM can be defined, that is, the corresponding UDM can be found through the combination of the HNI and the RID. The mapping relationship may be defined in the form of a table or in the form of a function, and the embodiment of the present application does not limit the definition form of the mapping relationship. The definition form of the table is taken as an example to illustrate below. Wherein, the mapping relationship between the combination of HNI and RID and UDM can be stored in NRF or AUSF, or can also be stored in a database independent of NRF or AUSF.

示例性的,以下表2-1为HNI和RID的组合与具有NSWO鉴权能力的UDM之间的映射关系示例。Exemplarily, the following table 2-1 is an example of the mapping relationship between the combination of HNI and RID and the UDM with NSWO authentication capability.

表2-1table 2-1

Figure BDA0003261882390000141
Figure BDA0003261882390000141

其中,上述表2-1所示的映射关系中的每个UDM都是具有NSWO鉴权能力的UDM,即升级后的UDM。本申请实施例中,将HNI和RID的组合与具有NSWO鉴权能力的UDM之间的映射关系称为第三映射关系。Wherein, each UDM in the mapping relationship shown in Table 2-1 above is a UDM with NSWO authentication capability, that is, an upgraded UDM. In the embodiment of the present application, the mapping relationship between the combination of the HNI and the RID and the UDM having the NSWO authentication capability is referred to as the third mapping relationship.

作为一种实现方法,表2-1中HNI3对应的RID为空可以理解为,其可以表示在收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,不管收到哪一个RID,都选择到UDM6。或者理解为,当收到指示终端设备使用NSWO的方式接入网络的指示信息和HNI 3的情况下,根据该HNI 3即可确定相应的UDM,不需要再参考收到的RID。As an implementation method, it can be understood that the RID corresponding to HNI3 in Table 2-1 is empty, which can mean that it can indicate that in the case of receiving the instruction information instructing the terminal device to use the NSWO method to access the network , choose to UDM6. Or it can be understood that, when receiving the instruction information and the HNI 3 instructing the terminal device to use the NSWO method to access the network, the corresponding UDM can be determined according to the HNI 3 without referring to the received RID.

另外需要说明的是,表2-1中的RID的取值范围只是举例,本实施例不限制具体的HNI与RID的个数关系。比如,可以理解为HNI1对应的网络一共配置了3个RID值,HNI2对应的网络一共配置了2个RID值。还可以理解为,以HNI1对应的网络举例,HNI1对应的网络配置了3个以上的RID的值,但是在表2-1中只包括可以用于NSWO鉴权的RID0、RID 1和RID 2,其他RID值不在此表范围内。当接收到不包括在表2-1里的HNI的RID值(例如RID3)时,可以使用如表2-2展示的映射关系进行查询。In addition, it should be noted that the value range of the RID in Table 2-1 is just an example, and this embodiment does not limit the specific relationship between the number of HNIs and RIDs. For example, it can be understood that the network corresponding to HNI1 is configured with 3 RID values in total, and the network corresponding to HNI2 is configured with 2 RID values in total. It can also be understood that, taking the network corresponding to HNI1 as an example, the network corresponding to HNI1 is configured with more than 3 RID values, but only RID0, RID 1 and RID 2 that can be used for NSWO authentication are included in Table 2-1. Other RID values are not within the scope of this table. When receiving the RID value of the HNI not included in Table 2-1 (such as RID3), you can use the mapping relationship shown in Table 2-2 to query.

作为一种实现方法,本申请实施例中还可以定义HNI和RID的组合与不具有NSWO鉴权能力的UDM之间的映射关系。本申请实施例中,将HNI和RID的组合与不具有NSWO鉴权能力的UDM之间的映射关系称为第四映射关系。As an implementation method, in the embodiment of the present application, the mapping relationship between the combination of the HNI and the RID and the UDM without NSWO authentication capability can also be defined. In the embodiment of the present application, the mapping relationship between the combination of the HNI and the RID and the UDM without NSWO authentication capability is referred to as the fourth mapping relationship.

示例性的,以下表2-2为HNI和RID的组合与不具有NSWO鉴权能力的UDM之间的映射关系示例。Exemplarily, the following table 2-2 is an example of the mapping relationship between the combination of HNI and RID and the UDM without NSWO authentication capability.

表2-2Table 2-2

Figure BDA0003261882390000151
Figure BDA0003261882390000151

其中,上述表2-2所示的映射关系中的每个UDM都是不具有NSWO鉴权能力的UDM,即未升级的UDM网元。Wherein, each UDM in the mapping relationship shown in Table 2-2 above is a UDM without NSWO authentication capability, that is, a UDM network element that has not been upgraded.

上述第三映射关系或第四映射关系中,一个HNI和RID的组合可以唯一对应一个UDM的标识信息,该标识信息可以是实例标识(instance ID)、地址(address)或FQDN。一个HNI和RID的组合也可以对应一个UDM集合的标识信息(set ID),该UDM集合内包含多个UDM的标识信息。当根据一个HNI得到该HNI对应的UDM集合时,则可以进一步从该UDM集合中选择一个UDM,比如可以是按照预设的规则选择一个UDM,或者是从UDM集合中随机选择一个UDM,本申请实施例对从UDM集合中选择一个UDM的实现方法不做限定。In the above third mapping relationship or fourth mapping relationship, a combination of an HNI and a RID may uniquely correspond to a UDM identification information, and the identification information may be an instance ID (instance ID), address (address) or FQDN. A combination of HNI and RID may also correspond to identification information (set ID) of a UDM set, and the UDM set includes identification information of multiple UDMs. When the UDM set corresponding to the HNI is obtained according to an HNI, a UDM can be further selected from the UDM set, for example, a UDM can be selected according to a preset rule, or a UDM can be randomly selected from the UDM set. The embodiment does not limit the implementation method of selecting a UDM from the UDM set.

本申请实施例中,一个HNI包括MCC和MNC,因此上述第三映射关系或第四映射关系中,一个HNI也可以用MCC和MNC的组合进行替换。具体参考前述描述。In the embodiment of the present application, one HNI includes MCC and MNC. Therefore, in the third mapping relationship or the fourth mapping relationship, one HNI may also be replaced by a combination of MCC and MNC. Refer to the foregoing description for details.

作为一种实现方法,上述步骤402,具体可以是:根据指示信息,从上述第三映射关系中选择与第一HNI和第一RID对应的第一UDM。As an implementation method, the above step 402 may specifically be: selecting the first UDM corresponding to the first HNI and the first RID from the above third mapping relationship according to the indication information.

作为一种实现方法,如果NRF或AUSF接收到第三HNI,但没有收到指示终端设备使用NSWO的方式接入网络的指示信息,则NRF或AUSF可以从上述第四映射关系中选择与第三HNI对应的不具有NSWO鉴权能力的UDM。As an implementation method, if the NRF or AUSF receives the third HNI, but does not receive the indication information instructing the terminal device to access the network in the way of NSWO, the NRF or AUSF can select the third HNI from the above fourth mapping relationship. UDM corresponding to HNI without NSWO authentication capability.

作为另一种实现方法,如果NRF或AUSF接收到第三HNI,但没有收到指示终端设备使用NSWO的方式接入网络的指示信息,则NRF或AUSF可以基于现有的选择逻辑,根据第三HNI选择UDM,该UDM既可以具有NSWO鉴权能力,也可以不具有NSWO鉴权能力,也就是说,NRF或AUSF所选择的UDM是否具有NSWO鉴权能力,是不确定的。As another implementation method, if the NRF or AUSF receives the third HNI, but does not receive the indication information instructing the terminal device to use the NSWO method to access the network, the NRF or AUSF can base on the existing selection logic, according to the third HNI selects UDM, which may or may not have NSWO authentication capability. In other words, it is uncertain whether the UDM selected by NRF or AUSF has NSWO authentication capability.

作为再一种实现方法,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者AUSF可以根据本地策略,从上述第三映射关系中选择与第三HNI对应的具有NSWO鉴权能力的一个UDM,或者从上述第四映射关系中选择与第三HNI对应的不具有NSWO鉴权能力的一个UDM。比如,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者AUSF根据本地策略,优先从第三映射关系中选择与第三HNI对应的具有NSWO鉴权能力的一个UDM。再比如,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者AUSF根据本地策略,优先从第四映射关系中选择与第三HNI对应的不具有NSWO鉴权能力的一个UDM。As yet another implementation method, in the case of not receiving the instruction information instructing the terminal device to access the network in NSWO mode, the NRF or AUSF can select the third HNI corresponding to the third HNI from the above-mentioned third mapping relationship according to the local policy. A UDM with NSWO authentication capability, or a UDM without NSWO authentication capability corresponding to the third HNI selected from the fourth mapping relationship. For example, in the case of not receiving the instruction information instructing the terminal device to use NSWO to access the network, the NRF or AUSF, according to the local policy, preferentially selects the third HNI corresponding to the third HNI and has the NSWO authentication capability. A UDM. For another example, in the case of not receiving the instruction information instructing the terminal device to use NSWO to access the network, the NRF or AUSF, according to the local policy, preferentially selects the third HNI corresponding to the third HNI from the fourth mapping relationship without NSWO authentication. A UDM of capabilities.

作为一种实现方法,本申请实施例中,终端设备的签约数据(也称为用户签约数据)可以存储于UDR上,该UDR上的同一个用户签约数据可以由多个UDM进行获取,比如可以由对应相同HNI的不同UDM去UDR获取相同的用户签约数据。结合上面介绍的各种选择UDM的实现方法,不管NRF或AUSF所选择的UDM是否具有NSWO鉴权能力,只要这些UDM对应相同的HNI和RID的组合,则这些UDM均可以从UDR获取相同的用户签约数据,该用户签约数据对应该HNI。下面结合一个示例说明。比如,如果NRF或AUSF收到HNI 1、RID 0和指示终端设备使用NSWO的方式接入网络的指示信息,NRF或AUSF根据上述表2-1,选择具有NSWO鉴权能力的UDM 1。如果NRF或AUSF收到HNI 1和RID 0,且没有收到指示终端设备使用NSWO的方式接入网络的指示信息,假设NRF或AUSF根据上述表2-2,选择不具有NSWO鉴权能力的UDM 7。该示例中,UDM 1和UDM 7均对应HNI 1和RID 0的组合,因此UDM 1和UDM 7均可以从同一个UDR中获取相同的用户签约数据,该用户签约数据对应该HNI 1和RID 0的组合。As an implementation method, in the embodiment of this application, the subscription data (also called user subscription data) of the terminal device can be stored on the UDR, and the same user subscription data on the UDR can be obtained by multiple UDMs, for example, The same user subscription data is obtained from different UDMs corresponding to the same HNI to UDR. Combined with the implementation methods of selecting UDM introduced above, regardless of whether the UDM selected by NRF or AUSF has NSWO authentication capability, as long as these UDMs correspond to the same combination of HNI and RID, these UDMs can obtain the same user from UDR Subscription data, the user's subscription data corresponds to the HNI. The following is combined with an example. For example, if NRF or AUSF receives HNI 1, RID 0 and instruction information instructing terminal equipment to use NSWO to access the network, NRF or AUSF selects UDM 1 with NSWO authentication capability according to the above Table 2-1. If the NRF or AUSF receives HNI 1 and RID 0, and does not receive the instruction information instructing the terminal device to access the network through NSWO, it is assumed that the NRF or AUSF selects UDM without NSWO authentication capability according to the above table 2-2 7. In this example, both UDM 1 and UDM 7 correspond to the combination of HNI 1 and RID 0, so both UDM 1 and UDM 7 can obtain the same user subscription data from the same UDR, and the user subscription data corresponds to the HNI 1 and RID 0 The combination.

下面结合上述表2-1和表2-2,给出上述图4对应的方法实施例的一个具体示例。以NRF执行上述图4对应的方法实施例为例。A specific example of the method embodiment corresponding to the above-mentioned FIG. 4 is given below in conjunction with the above-mentioned Table 2-1 and Table 2-2. Take the NRF executing the method embodiment corresponding to FIG. 4 above as an example.

在一个示例中,NRF收到HNI1、RID 0和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络,则该指示信息触发NRF从上述表2-1中选择一个具有NSWO鉴权能力的UDM,具体的,选择的是UDM 1,或者选择的是UDM集合1的标识信息所指示的UDM集合内的一个UDM。NRF根据该指示信息,不会从表2-2中选择不具有NSWO鉴权能力的UDM(即升级前的UDM)。通过该方法,使用该指示信息,触发NRF从上述表2-1中选择一个具有NSWO鉴权能力的UDM。In an example, the NRF receives HNI1, RID 0 and indication information, the indication information indicates that the terminal device uses NSWO to access the network, and the indication information triggers the NRF to select a NSWO authentication capability from the above table 2-1 Specifically, UDM 1 is selected, or a UDM in the UDM set indicated by the identification information of UDM set 1 is selected. According to the indication information, NRF will not select UDM without NSWO authentication capability (that is, UDM before upgrade) from Table 2-2. Through this method, the indication information is used to trigger the NRF to select a UDM with NSWO authentication capability from the above Table 2-1.

在又一个示例中,NRF收到HNI1和RID 0,但没有收到上述指示终端设备使用NSWO的方式接入网络的指示信息,则NRF从上述表2-2中选择一个不具有NSWO鉴权能力的UDM,具体的,选择的是UDM 7,或者选择的是UDM集合7的标识信息所指示的UDM集合内的一个UDM。由于没有收到上述指示信息,则NRF不会从表2-1中选择具有NSWO鉴权能力的UDM。通过该方法,NRF从上述表2-2中选择一个不具有NSWO鉴权能力的UDM。In yet another example, NRF receives HNI1 and RID 0, but does not receive the above indication information instructing the terminal device to access the network through NSWO, then NRF selects one from the above table 2-2 that does not have NSWO authentication capability Specifically, the UDM 7 is selected, or a UDM in the UDM set indicated by the identification information of the UDM set 7 is selected. Since the above indication information has not been received, the NRF will not select a UDM with NSWO authentication capability from Table 2-1. Through this method, NRF selects a UDM without NSWO authentication capability from the above table 2-2.

在又一个示例中,NRF收到HNI1和RID 0,但没有收到上述指示终端设备使用NSWO的方式接入网络的指示信息,则NRF既可以从上述表2-1中选择一个具有NSWO鉴权能力的UDM,也可以从上述表2-2中选择一个不具有NSWO鉴权能力的UDM,具体如何选择,取决于实现,比如根据本地策略进行选择。可以理解的是,如果没有收到上述指示信息,则NRF选择的UDM可能具有NSWO鉴权能力,也可能不具有NSWO鉴权能力。In another example, the NRF receives HNI1 and RID 0, but does not receive the above instruction information instructing the terminal device to access the network in the way of NSWO, then the NRF can select one from the above table 2-1 with NSWO authentication Capability UDM, you can also select a UDM without NSWO authentication capability from the above table 2-2. The specific selection depends on the implementation, such as selection according to local policies. It can be understood that if the above indication information is not received, the UDM selected by the NRF may or may not have the NSWO authentication capability.

作为一种实现方法,本申请实施例还可以建立上述指示信息与上述第三映射关系或第四映射关系之间的关联。As an implementation method, this embodiment of the present application may further establish an association between the foregoing indication information and the foregoing third or fourth mapping relationship.

一种实现方法是,建立指示信息与上述第三映射关系的关联,通过该指示信息可以找到该第一映射关系。An implementation method is to establish an association between the indication information and the above-mentioned third mapping relationship, and the first mapping relationship can be found through the indication information.

另一种实现方法是,将上述第三映射关系与第四映射关系进行结合,以及将该指示信息作为结合后的映射关系的一部分,该指示信息指示终端设备使用NSWO的方式接入网络。以上述表2-1和表2-2为例,可以将上述表2-1与上述表2-2进行结合,并在结合后的表中增加指示信息,可以得到如表2-3所示的映射关系。Another implementation method is to combine the above-mentioned third mapping relationship with the fourth mapping relationship, and use the indication information as part of the combined mapping relationship, the indication information instructing the terminal device to use the NSWO method to access the network. Taking the above Table 2-1 and Table 2-2 as an example, the above Table 2-1 can be combined with the above Table 2-2, and the instruction information can be added to the combined table, as shown in Table 2-3. mapping relationship.

表2-3Table 2-3

Figure BDA0003261882390000171
Figure BDA0003261882390000171

其中,上述表2-3中,UDM 1至UDM6,以及UDM集合1至UDM集合6内的UDM均是具有NSWO鉴权能力的UDM。UDM 7至UDM13,以及UDM集合7至UDM集合13内的UDM均是不具有NSWO鉴权能力的UDM。Wherein, in the above-mentioned Table 2-3, UDM 1 to UDM 6, and UDMs in UDM set 1 to UDM set 6 are all UDMs with NSWO authentication capability. UDM 7 to UDM 13, and UDMs in UDM set 7 to UDM set 13 are all UDMs without NSWO authentication capability.

作为一个示例,如果NRF或AUSF接收到HNI 1和RID 0,则可以根据表2-3确定HNI 1和RID 0的组合对应的UDM 7或UDM集合7内的一个UDM。如果NRF或AUSF收到HNI 1、RID 0和指示信息,则根据表2-3确定HNI 1对应的UDM 1或UDM集合1内的一个UDM。As an example, if the NRF or AUSF receives HNI 1 and RID 0, it can determine the UDM 7 or a UDM in the UDM set 7 corresponding to the combination of HNI 1 and RID 0 according to Table 2-3. If the NRF or AUSF receives HNI 1, RID 0, and indication information, it determines the UDM 1 corresponding to HNI 1 or a UDM in UDM set 1 according to Table 2-3.

作为一种实现方法,如果上述图4对应的方法实施例是由NRF执行,则上述步骤401具体可以是:NRF接收来自AUSF的第一HNI和指示信息,或者NRF接收来自AUSF的第一HNI、第一RID和指示信息。进一步的,在上述步骤402之后,NRF还可以向AUSF发送确定的具有NSWO鉴权能力的第一UDM的标识信息。As an implementation method, if the above method embodiment corresponding to Figure 4 is executed by NRF, the above step 401 may specifically be: NRF receives the first HNI and indication information from AUSF, or NRF receives the first HNI from AUSF, The first RID and indication information. Further, after the above step 402, the NRF may also send the identified identification information of the first UDM with NSWO authentication capability to the AUSF.

作为一种实现方法,上述步骤401中,可以从接收到的SUCI中获取到第一HNI,或者从接收到的SUCI中获取到第一HNI和第一RID。As an implementation method, in the above step 401, the first HNI may be obtained from the received SUCI, or the first HNI and the first RID may be obtained from the received SUCI.

根据上述图4对应的方法实施例,AUSF进行UDM的选择,选择了一个UDM实例,该UDM实例用于执行归属地公共陆地移动网络(home public land mobile network,hPLMN)中的终端设备和UDM之间的NSWO鉴权。AUSF可以自己选择UDM实例,比如通过本地配置的方法从本地选择UDM实例,或者AUSF利用NRF发现UDM实例。According to the method embodiment corresponding to FIG. 4 above, the AUSF selects a UDM, and selects a UDM instance, which is used to execute the connection between the terminal device and the UDM in the home public land mobile network (home public land mobile network, hPLMN). Inter-NSWO authentication. AUSF can select a UDM instance by itself, such as selecting a UDM instance locally through local configuration, or AUSF uses NRF to discover a UDM instance.

也就是说,可以在AUSF上配置UDM选择功能,该UDM选择功能可以从本地配置中选择一个可用的UDM实例或者利用NRF发现UDM实例,该UDM实例具有NSWO鉴权能力。其中,AUSF中的UDM选择功能在选择UDM实例时,用到了以下信息:1、SUCI中的HNI或者SUCI中的HNI和RID;2、指示信息(NSWO indicator)。That is to say, the UDM selection function can be configured on the AUSF, and the UDM selection function can select an available UDM instance from the local configuration or use NRF to discover the UDM instance, and the UDM instance has NSWO authentication capability. Wherein, the UDM selection function in the AUSF uses the following information when selecting a UDM instance: 1. HNI in SUCI or HNI and RID in SUCI; 2. Indicator information (NSWO indicator).

参考图5,为本申请实施例提供的一种网元的选择方法的流程图。该方法用于选择具有NSWO鉴权能力的AUSF。该方法可以由NSWO NF或用于NSWO NF的模块(如芯片)执行,或者也可以由NRF或用于NRF的模块(如芯片)执行。Referring to FIG. 5 , it is a flow chart of a method for selecting a network element provided in an embodiment of the present application. This method is used to select AUSF with NSWO authentication capability. The method may be executed by NSWO NF or a module (such as a chip) for NSWO NF, or may also be executed by NRF or a module (such as a chip) for NRF.

该方法包括以下步骤:The method includes the following steps:

步骤501,接收第一HNI和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络。Step 501, receiving the first HNI and indication information, the indication information instructing the terminal device to use NSWO to access the network.

该指示信息也可以用NSWO indicator表示,或者用其它名称表示,本申请实施例不做限定。The indication information may also be expressed by NSWO indicator, or by other names, which is not limited in this embodiment of the present application.

步骤502,根据指示信息,选择与第一HNI对应的第一AUSF,该第一AUSF具有NSWO鉴权能力。Step 502: Select the first AUSF corresponding to the first HNI according to the indication information, and the first AUSF has NSWO authentication capability.

可以理解为,该指示信息触发执行:选择一个具有NSWO鉴权能力的AUSF。It can be understood that the indication information triggers the execution of selecting an AUSF with NSWO authentication capability.

根据上述方案,可以实现选择一个具有NSWO鉴权能力的AUSF,从而该AUSF可以为使用NSWO的方式接入网络的终端设备提供NSWO鉴权服务,有助于实现终端设备的快速和正确接入。According to the above solution, it is possible to select an AUSF with NSWO authentication capability, so that the AUSF can provide NSWO authentication services for terminal devices accessing the network in NSWO mode, which helps to realize fast and correct access of terminal devices.

下面介绍上述方法的一种应用场景。根据前面描述,在目前的5G网络中,UDM支持两种鉴权方法,即EAP-AKA’鉴权方法和5G-AKA鉴权方法,并且是通过AUSF向具有NSWO鉴权能力的UDM发送用于指示终端设备使用NSWO的方式接入网络的指示信息,触发该UDM根据该指示信息选择EAP-AKA’鉴权方法,该EAP-AKA’鉴权方法用于NSWO鉴权流程。为了能够向具有NSWO鉴权能力的UDM发送上述指示信息,则首先需要保证AUSF能够识别该指示信息,因此需要选择一个具有NSWO鉴权能力的AUSF。也即,需要选择一个具有NSWO鉴权能力的AUSF,该AUSF可以识别上述指示信息,并将该指示信息发送给具有NSWO鉴权能力的UDM,然后该指示信息触发该UDM选择EAP-AKA’鉴权方法。An application scenario of the above method is introduced below. According to the previous description, in the current 5G network, UDM supports two authentication methods, namely the EAP-AKA' authentication method and the 5G-AKA authentication method, and AUSF sends the UDM with NSWO authentication capability for The indication information instructing the terminal device to use the NSWO method to access the network triggers the UDM to select the EAP-AKA' authentication method according to the indication information, and the EAP-AKA' authentication method is used in the NSWO authentication process. In order to be able to send the above indication information to the UDM with NSWO authentication capability, it is first necessary to ensure that the AUSF can recognize the indication information, so it is necessary to select an AUSF with NSWO authentication capability. That is, it is necessary to select an AUSF with NSWO authentication capability. The AUSF can recognize the above indication information and send the indication information to the UDM with NSWO authentication capability. Then the indication information triggers the UDM to select EAP-AKA' authentication. right method.

作为一种实现方法,本申请实施例可以预定义HNI与AUSF之间的映射关系,该映射关系可以通过表格的形式定义,或者通过函数的形式定义,本申请实施例对于该映射关系的定义形式不做限定。以下以表格的定义形式为例进行说明。As an implementation method, the embodiment of the present application can predefine the mapping relationship between HNI and AUSF, and the mapping relationship can be defined in the form of a table or in the form of a function. The definition form of the mapping relationship in the embodiment of the present application No limit. The definition form of the table is taken as an example to illustrate below.

其中,HNI与AUSF之间的映射关系可以存储在NRF或NSWO NF上,或者也可以存储于一个独立于NRF或NSWO NF的数据库中。Wherein, the mapping relationship between HNI and AUSF can be stored in NRF or NSWO NF, or can also be stored in a database independent of NRF or NSWO NF.

示例性的,以下表3-1为HNI与具有NSWO鉴权能力的AUSF之间的映射关系示例。Exemplarily, the following Table 3-1 is an example of the mapping relationship between the HNI and the AUSF with NSWO authentication capability.

表3-1Table 3-1

HNIHNI 具有NSWO鉴权能力的AUSFAUSF with NSWO authentication capability HNI 1HNI 1 AUSF1的标识信息或AUSF集合1的标识信息Identification information of AUSF1 or identification information of AUSF set 1 HNI 2HNI 2 AUSF 2的标识信息或AUSF集合2的标识信息Identification information of AUSF 2 or identification information of AUSF set 2 HNI 3HNI 3 AUSF 3的标识信息或AUSF集合3的标识信息Identification information of AUSF 3 or identification information of AUSF set 3

其中,上述表3-1所示的映射关系中的每个AUSF都是具有NSWO鉴权能力的AUSF,即升级后的AUSF。本申请实施例中,将HNI与具有NSWO鉴权能力的AUSF之间的映射关系称为第一映射关系。Wherein, each AUSF in the mapping relationship shown in Table 3-1 above is an AUSF with NSWO authentication capability, that is, an upgraded AUSF. In the embodiment of the present application, the mapping relationship between the HNI and the AUSF with NSWO authentication capability is referred to as the first mapping relationship.

作为一种实现方法,本申请实施例中还可以定义HNI与不具有NSWO鉴权能力的AUSF之间的映射关系。本申请实施例中,将HNI与不具有NSWO鉴权能力的AUSF之间的映射关系称为第二映射关系。As an implementation method, in the embodiment of the present application, the mapping relationship between the HNI and the AUSF without NSWO authentication capability can also be defined. In the embodiment of the present application, the mapping relationship between the HNI and the AUSF without NSWO authentication capability is referred to as the second mapping relationship.

示例性的,以下表3-2为HNI与不具有NSWO鉴权能力的AUSF之间的映射关系示例。Exemplarily, the following Table 3-2 is an example of the mapping relationship between the HNI and the AUSF that does not have the NSWO authentication capability.

表3-2Table 3-2

HNIHNI 不具有NSWO鉴权能力的AUSFAUSF without NSWO authentication capability HNI 1HNI 1 AUSF4的标识信息或AUSF集合4的标识信息Identification information of AUSF4 or identification information of AUSF set 4 HNI 2HNI 2 AUSF 5的标识信息或AUSF集合5的标识信息Identification information of AUSF 5 or identification information of AUSF set 5 HNI 3HNI 3 AUSF 6的标识信息或AUSF集合6的标识信息Identification information of AUSF 6 or identification information of AUSF set 6

其中,上述表3-2所示的映射关系中的每个AUSF都是不具有NSWO鉴权能力的AUSF,即未升级的AUSF网元。Wherein, each AUSF in the mapping relationship shown in Table 3-2 above is an AUSF without NSWO authentication capability, that is, an AUSF network element that has not been upgraded.

上述第一映射关系或第二映射关系中,一个HNI可以唯一对应一个AUSF的标识信息,该标识信息可以是实例标识(instance ID)、地址(address)或FQDN。一个HNI也可以对应一个AUSF集合的标识信息(set ID),该AUSF集合内包含多个AUSF的标识信息。当根据一个HNI得到该HNI对应的AUSF集合时,则可以进一步从该AUSF集合中选择一个AUSF,比如可以是按照预设的规则选择一个AUSF,或者是从AUSF集合中随机选择一个AUSF,本申请实施例对从AUSF集合中选择一个AUSF的实现方法不做限定。In the first mapping relationship or the second mapping relationship above, one HNI may uniquely correspond to one AUSF identification information, and the identification information may be instance ID, address or FQDN. One HNI may also correspond to the identification information (set ID) of one AUSF set, and the AUSF set includes identification information of multiple AUSFs. When the AUSF set corresponding to the HNI is obtained according to an HNI, an AUSF can be further selected from the AUSF set, for example, an AUSF can be selected according to a preset rule, or an AUSF can be randomly selected from the AUSF set. This application The embodiment does not limit the implementation method of selecting an AUSF from the AUSF set.

本申请实施例中,一个HNI包括MCC和MNC,因此上述第一映射关系或第二映射关系中,一个HNI也可以用MCC和MNC的组合进行替换。比如,上述表3-1中的HNI 1可以用(MCC=A,MNC=B)进行替换,HNI 2可以用(MCC=A,MNC=C)进行替换,HNI 3可以用(MCC=E,MNC=F)进行替换。上述表3-2也可以用类似的方法进行替换。In the embodiment of the present application, one HNI includes MCC and MNC. Therefore, in the first mapping relationship or the second mapping relationship, one HNI may also be replaced by a combination of MCC and MNC. For example, HNI 1 in the above Table 3-1 can be replaced by (MCC=A, MNC=B), HNI 2 can be replaced by (MCC=A, MNC=C), HNI 3 can be replaced by (MCC=E, MNC=F) for substitution. The above Table 3-2 can also be replaced by a similar method.

作为一种实现方法,上述步骤502,具体可以是:根据指示信息,从上述第一映射关系中选择与第一HNI对应的第一AUSF。As an implementation method, the above step 502 may specifically be: selecting the first AUSF corresponding to the first HNI from the above first mapping relationship according to the indication information.

作为一种实现方法,如果NRF或NSWO NF接收到第二HNI,但没有收到指示终端设备使用NSWO的方式接入网络的指示信息,则NRF或NSWO NF可以从上述第二映射关系中选择与第二HNI对应的第二AUSF,该第二AUSF不具有NSWO鉴权能力。As an implementation method, if the NRF or NSWO NF receives the second HNI, but does not receive the indication information instructing the terminal device to use the NSWO method to access the network, the NRF or NSWO NF can select from the above-mentioned second mapping relationship and The second AUSF corresponding to the second HNI does not have the NSWO authentication capability.

作为另一种实现方法,如果NRF或NSWO NF接收到第二HNI,但没有收到指示终端设备使用NSWO的方式接入网络的指示信息,则NRF或NSWO NF可以基于现有的选择逻辑,根据第二HNI选择AUSF,该AUSF既可以具有NSWO鉴权能力,也可以不具有NSWO鉴权能力,也就是说,NRF或NSWO NF所选择的AUSF是否具有NSWO鉴权能力,是不确定的。As another implementation method, if the NRF or NSWO NF receives the second HNI, but does not receive the indication information instructing the terminal device to use the NSWO method to access the network, the NRF or NSWO NF can base on the existing selection logic, according to The second HNI selects the AUSF, and the AUSF may or may not have the NSWO authentication capability. That is to say, it is uncertain whether the AUSF selected by the NRF or the NSWO NF has the NSWO authentication capability.

作为再一种实现方法,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者NSWO NF可以根据本地策略,从上述第一映射关系中选择与第二HNI对应的具有NSWO鉴权能力的一个AUSF,或者从上述第二映射关系中选择与第二HNI对应的不具有NSWO鉴权能力的一个AUSF。比如,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者NSWO NF根据本地策略,优先从第一映射关系中选择与第二HNI对应的具有NSWO鉴权能力的一个AUSF。再比如,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者NSWO NF根据本地策略,优先从第二映射关系中选择与第二HNI对应的不具有NSWO鉴权能力的一个AUSF。As yet another implementation method, in the case of not receiving the instruction information instructing the terminal device to use NSWO to access the network, the NRF or NSWO NF can select from the above-mentioned first mapping relationship to correspond to the second HNI according to the local policy. An AUSF with NSWO authentication capability, or select an AUSF without NSWO authentication capability corresponding to the second HNI from the second mapping relationship. For example, in the case of not receiving the instruction information instructing the terminal device to use the NSWO method to access the network, the NRF or NSWO NF will preferentially select the NSWO authentication capability corresponding to the second HNI from the first mapping relationship according to the local policy. of an AUSF. For another example, in the case of not receiving the instruction information instructing the terminal device to use NSWO to access the network, the NRF or NSWO NF, according to the local policy, preferentially selects the HNI corresponding to the second HNI from the second mapping relationship without NSWO authentication. An AUSF of power.

作为一种实现方法,本申请实施例中,终端设备的签约数据(也称为用户签约数据)可以存储于UDR上,该UDR上的同一个用户签约数据可以由多个AUSF进行获取,比如可以由对应相同HNI的不同AUSF去UDR获取相同的用户签约数据。结合上面介绍的各种选择AUSF的实现方法,不管NRF或NSWO NF所选择的AUSF是否具有NSWO鉴权能力,只要这些AUSF对应相同的HNI,则这些AUSF均可以从UDR获取相同的用户签约数据,该用户签约数据对应该HNI。下面结合一个示例说明。比如,如果NRF或NSWO NF收到HNI 1和指示终端设备使用NSWO的方式接入网络的指示信息,NRF或NSWO NF根据上述表3-1,选择具有NSWO鉴权能力的AUSF1。如果NRF或NSWO NF收到HNI 1,且没有收到指示终端设备使用NSWO的方式接入网络的指示信息,假设NRF或NSWO NF根据上述表3-1,选择不具有NSWO鉴权能力的AUSF 4。该示例中,AUSF 1和AUSF 4均对应HNI 1,因此AUSF 1和AUSF 4均可以从同一个UDR中获取相同的用户签约数据,该用户签约数据对应该HNI 1。As an implementation method, in the embodiment of this application, the subscription data (also called user subscription data) of the terminal device can be stored on the UDR, and the same user subscription data on the UDR can be obtained by multiple AUSFs, for example, The same user subscription data is obtained by UDR from different AUSFs corresponding to the same HNI. Combined with the implementation methods of selecting AUSF introduced above, regardless of whether the AUSF selected by NRF or NSWO NF has NSWO authentication capability, as long as these AUSFs correspond to the same HNI, these AUSFs can obtain the same user subscription data from UDR, The user subscription data corresponds to the HNI. The following is combined with an example. For example, if NRF or NSWO NF receives HNI 1 and the instruction information instructing the terminal device to use NSWO to access the network, NRF or NSWO NF selects AUSF1 with NSWO authentication capability according to the above Table 3-1. If the NRF or NSWO NF receives the HNI 1 and does not receive the instruction information instructing the terminal device to access the network through NSWO, it is assumed that the NRF or NSWO NF selects the AUSF 4 that does not have the NSWO authentication capability according to the above Table 3-1 . In this example, both AUSF 1 and AUSF 4 correspond to HNI 1, so both AUSF 1 and AUSF 4 can obtain the same user subscription data from the same UDR, and the user subscription data corresponds to the HNI 1.

下面结合上述表3-1和表3-2,给出上述图5对应的方法实施例的一个具体示例。以NRF执行上述图5对应的方法实施例为例。A specific example of the method embodiment corresponding to the above-mentioned FIG. 5 is given below in conjunction with the above-mentioned Table 3-1 and Table 3-2. Take the NRF executing the method embodiment corresponding to FIG. 5 above as an example.

在一个示例中,NRF收到HNI1和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络,则该指示信息触发NRF从上述表3-1中选择一个具有NSWO鉴权能力的AUSF,具体的,选择的是AUSF 1,或者选择的是AUSF集合1的标识信息所指示的AUSF集合内的一个AUSF。NRF根据该指示信息,不会从表3-2中选择不具有NSWO鉴权能力的AUSF(即升级前的AUSF)。通过该方法,使用该指示信息,触发NRF从上述表3-1中选择一个具有NSWO鉴权能力的AUSF。In an example, the NRF receives HNI1 and indication information, the indication information indicates that the terminal device uses NSWO to access the network, and the indication information triggers the NRF to select an AUSF with NSWO authentication capability from the above table 3-1, Specifically, AUSF 1 is selected, or an AUSF in the AUSF set indicated by the identification information of AUSF set 1 is selected. According to the indication information, the NRF will not select the AUSF without NSWO authentication capability (that is, the AUSF before the upgrade) from Table 3-2. Through this method, the indication information is used to trigger the NRF to select an AUSF with NSWO authentication capability from the above Table 3-1.

在又一个示例中,NRF收到HNI1,但没有收到上述指示终端设备使用NSWO的方式接入网络的指示信息,则NRF从上述表3-2中选择一个不具有NSWO鉴权能力的AUSF,具体的,选择的是AUSF 4,或者选择的是AUSF集合4的标识信息所指示的AUSF集合内的一个AUSF。由于没有收到上述指示信息,则NRF不会从表3-1中选择具有NSWO鉴权能力的AUSF。通过该方法,NRF从上述表3-2中选择一个不具有NSWO鉴权能力的AUSF。In another example, NRF receives HNI1, but does not receive the above indication information instructing the terminal device to use NSWO to access the network, then NRF selects an AUSF that does not have NSWO authentication capability from the above Table 3-2, Specifically, AUSF 4 is selected, or an AUSF in the AUSF set indicated by the identification information of AUSF set 4 is selected. Since the above indication information has not been received, the NRF will not select the AUSF with NSWO authentication capability from Table 3-1. Through this method, NRF selects an AUSF that does not have NSWO authentication capability from the above table 3-2.

在又一个示例中,NRF收到HNI1,但没有收到上述指示终端设备使用NSWO的方式接入网络的指示信息,则NRF既可以从上述表3-1中选择一个具有NSWO鉴权能力的AUSF,也可以从上述表3-2中选择一个不具有NSWO鉴权能力的AUSF,具体如何选择,取决于实现,比如根据本地策略进行选择。可以理解的是,如果没有收到上述指示信息,则NRF选择的AUSF可能具有NSWO鉴权能力,也可能不具有NSWO鉴权能力。In another example, NRF receives HNI1, but does not receive the above instruction information instructing the terminal device to access the network through NSWO, then NRF can select an AUSF with NSWO authentication capability from the above table 3-1 , you can also select an AUSF that does not have NSWO authentication capability from the above Table 3-2. The specific selection depends on the implementation, such as selection according to local policies. It can be understood that if the above indication information is not received, the AUSF selected by the NRF may or may not have the NSWO authentication capability.

作为一种实现方法,本申请实施例还可以建立上述指示信息与上述第一映射关系或第二映射关系之间的关联。As an implementation method, this embodiment of the present application may further establish an association between the foregoing indication information and the foregoing first mapping relationship or the second mapping relationship.

一种实现方法是,建立指示信息与上述第一映射关系的关联,通过该指示信息可以找到该第一映射关系。One implementation method is to establish an association between the indication information and the above-mentioned first mapping relationship, and the first mapping relationship can be found through the indication information.

另一种实现方法是,将上述第一映射关系与第二映射关系进行结合,以及将该指示信息作为结合后的映射关系的一部分,该指示信息指示终端设备使用NSWO的方式接入网络。以上述表3-1和表3-2为例,可以将上述表3-1与上述表3-2进行结合,并在结合后的表中增加指示信息,可以得到如表3-3所示的映射关系。Another implementation method is to combine the above-mentioned first mapping relationship with the second mapping relationship, and use the indication information as part of the combined mapping relationship, the indication information instructing the terminal device to use NSWO to access the network. Taking the above Table 3-1 and Table 3-2 as an example, the above Table 3-1 can be combined with the above Table 3-2, and the instruction information can be added to the combined table, as shown in Table 3-3. mapping relationship.

表3-3Table 3-3

Figure BDA0003261882390000211
Figure BDA0003261882390000211

其中,上述表3-3中,AUSF 1、AUSF 2、AUSF 3、AUSF集合1内的AUSF、AUSF集合2内的AUSF以及AUSF集合3内的AUSF均是具有NSWO鉴权能力的AUSF。AUSF 4、AUSF 5、AUSF 6、AUSF集合4内的AUSF、AUSF集合5内的AUSF以及AUSF集合6内的AUSF均是不具有NSWO鉴权能力的AUSF。Among them, in the above Table 3-3, AUSF 1, AUSF 2, AUSF 3, AUSF in AUSF set 1, AUSF in AUSF set 2, and AUSF in AUSF set 3 are all AUSFs with NSWO authentication capability. AUSF 4, AUSF 5, AUSF 6, AUSF in AUSF set 4, AUSF in AUSF set 5, and AUSF in AUSF set 6 are all AUSFs without NSWO authentication capability.

作为一个示例,如果NRF或NSWO NF接收到HNI 1,则可以根据表3-3确定HNI 1对应的AUSF 4或AUSF集合4内的一个AUSF。如果NRF或NSWO NF收到HNI 1和指示信息,则根据表3-3确定HNI 1对应的AUSF 1或AUSF集合1内的一个AUSF。As an example, if NRF or NSWO NF receives HNI 1, it can determine AUSF 4 corresponding to HNI 1 or an AUSF in AUSF set 4 according to Table 3-3. If NRF or NSWO NF receives HNI 1 and indication information, it will determine AUSF 1 corresponding to HNI 1 or an AUSF in AUSF set 1 according to Table 3-3.

作为一种实现方法,在上述步骤501中还可以接收第一RID,且上述步骤502,具体是:根据上述指示信息,选择与第一HNI和第一RID对应的第一AUSF。也即,该方法中,是通过HNI和RID的组合,去找到相应的AUSF。As an implementation method, the first RID may also be received in the above step 501, and the above step 502, specifically: according to the above indication information, select the first AUSF corresponding to the first HNI and the first RID. That is, in this method, the corresponding AUSF is found through the combination of HNI and RID.

本申请实施例中,可以定义HNI和RID的组合与AUSF之间的映射关系,也即通过HNI和RID的组合去找到相应的AUSF。该映射关系可以通过表格的形式定义,或者通过函数的形式定义,本申请实施例对于该映射关系的定义形式不做限定。以下以表格的定义形式为例进行说明。其中,HNI和RID的组合与AUSF之间的映射关系可以存储在NRF或NSWO NF上,或者也可以存储于一个独立于NRF或NSWO NF的数据库中。In the embodiment of the present application, the mapping relationship between the combination of the HNI and the RID and the AUSF can be defined, that is, the corresponding AUSF can be found through the combination of the HNI and the RID. The mapping relationship may be defined in the form of a table or in the form of a function, and the embodiment of the present application does not limit the definition form of the mapping relationship. The definition form of the table is taken as an example to illustrate below. Wherein, the mapping relationship between the combination of HNI and RID and AUSF can be stored in NRF or NSWO NF, or can also be stored in a database independent of NRF or NSWO NF.

示例性的,以下表4-1为HNI和RID的组合与具有NSWO鉴权能力的AUSF之间的映射关系示例。Exemplarily, the following table 4-1 is an example of the mapping relationship between the combination of HNI and RID and the AUSF with NSWO authentication capability.

表4-1Table 4-1

Figure BDA0003261882390000221
Figure BDA0003261882390000221

其中,上述表4-1所示的映射关系中的每个AUSF都是具有NSWO鉴权能力的AUSF,即升级后的AUSF。本申请实施例中,将HNI和RID的组合与具有NSWO鉴权能力的AUSF之间的映射关系称为第三映射关系。Wherein, each AUSF in the mapping relationship shown in Table 4-1 above is an AUSF with NSWO authentication capability, that is, an upgraded AUSF. In the embodiment of the present application, the mapping relationship between the combination of the HNI and the RID and the AUSF with NSWO authentication capability is referred to as the third mapping relationship.

作为一种实现方法,表4-1中HNI3对应的RID为空可以理解为,其可以表示在收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,不管收到哪一个RID,都选择到AUSF6。或者理解为,当收到指示终端设备使用NSWO的方式接入网络的指示信息和HNI 3的情况下,根据该HNI 3即可确定相应的AUSF,不需要再参考收到的RID。As an implementation method, it can be understood that the RID corresponding to HNI3 in Table 4-1 is empty, which can mean that it can indicate that in the case of receiving the instruction information instructing the terminal device to use the NSWO method to access the network, no matter which RID is received , all selected to AUSF6. Or it can be understood that, when receiving the instruction information and the HNI 3 instructing the terminal device to use the NSWO method to access the network, the corresponding AUSF can be determined according to the HNI 3 without referring to the received RID.

另外需要说明的是,表4-1中的RID的取值范围只是举例,本实施例不限制具体的HNI与RID的个数关系。比如,可以理解为HNI1对应的网络一共配置了3个RID值,HNI 2对应的网络一共配置了2个RID值。还可以理解为,以HNI 1对应的网络举例,HNI 1对应的网络配置了3个以上的RID的值,但是在表4-1中只包括可以用于NSWO鉴权的RID0、RID 1和RID 2,其他RID值不在此表范围内。当接收到不包括在表4-1里的HNI的RID值时,可以使用如表4-2展示的映射关系进行查询。In addition, it should be noted that the value range of the RID in Table 4-1 is just an example, and this embodiment does not limit the specific relationship between the number of HNIs and RIDs. For example, it can be understood that the network corresponding to HNI1 is configured with 3 RID values in total, and the network corresponding to HNI 2 is configured with 2 RID values in total. It can also be understood that, taking the network corresponding to HNI 1 as an example, the network corresponding to HNI 1 is configured with more than 3 RID values, but only RID0, RID 1 and RID that can be used for NSWO authentication are included in Table 4-1 2. Other RID values are not within the scope of this table. When receiving the RID value of the HNI not included in Table 4-1, you can use the mapping relationship shown in Table 4-2 to query.

作为一种实现方法,本申请实施例中还可以定义HNI和RID的组合与不具有NSWO鉴权能力的AUSF之间的映射关系。本申请实施例中,将HNI和RID的组合与不具有NSWO鉴权能力的AUSF之间的映射关系称为第四映射关系。As an implementation method, in the embodiment of the present application, the mapping relationship between the combination of the HNI and the RID and the AUSF that does not have the NSWO authentication capability can also be defined. In the embodiment of the present application, the mapping relationship between the combination of the HNI and the RID and the AUSF without NSWO authentication capability is referred to as the fourth mapping relationship.

示例性的,以下表4-2为HNI和RID的组合与不具有NSWO鉴权能力的AUSF之间的映射关系示例。Exemplarily, the following table 4-2 is an example of the mapping relationship between the combination of HNI and RID and the AUSF without NSWO authentication capability.

表4-2Table 4-2

Figure BDA0003261882390000222
Figure BDA0003261882390000222

Figure BDA0003261882390000231
Figure BDA0003261882390000231

其中,上述表4-2所示的映射关系中的每个AUSF都是不具有NSWO鉴权能力的AUSF,即未升级的AUSF网元。Wherein, each AUSF in the mapping relationship shown in Table 4-2 above is an AUSF without NSWO authentication capability, that is, an AUSF network element that has not been upgraded.

上述第三映射关系或第四映射关系中,一个HNI和RID的组合可以唯一对应一个AUSF的标识信息,该标识信息可以是实例标识(instance ID)、地址(address)或FQDN。一个HNI和RID的组合也可以对应一个AUSF集合的标识信息(set ID),该AUSF集合内包含多个AUSF的标识信息。当根据一个HNI得到该HNI对应的AUSF集合时,则可以进一步从该AUSF集合中选择一个AUSF,比如可以是按照预设的规则选择一个AUSF,或者是从AUSF集合中随机选择一个AUSF,本申请实施例对从AUSF集合中选择一个AUSF的实现方法不做限定。In the above third or fourth mapping relationship, a combination of an HNI and a RID may uniquely correspond to an identification information of an AUSF, and the identification information may be an instance ID, address or FQDN. A combination of HNI and RID may also correspond to identification information (set ID) of an AUSF set, and the AUSF set includes identification information of multiple AUSFs. When the AUSF set corresponding to the HNI is obtained according to an HNI, an AUSF can be further selected from the AUSF set, for example, an AUSF can be selected according to a preset rule, or an AUSF can be randomly selected from the AUSF set. This application The embodiment does not limit the implementation method of selecting an AUSF from the AUSF set.

本申请实施例中,一个HNI包括MCC和MNC,因此上述第三映射关系或第四映射关系中,一个HNI也可以用MCC和MNC的组合进行替换。具体参考前述描述。In the embodiment of the present application, one HNI includes MCC and MNC. Therefore, in the third mapping relationship or the fourth mapping relationship, one HNI may also be replaced by a combination of MCC and MNC. Refer to the foregoing description for details.

作为一种实现方法,上述步骤502,具体可以是:根据指示信息,从上述第三映射关系中选择与第一HNI和第一RID对应的第一AUSF。As an implementation method, the above step 502 may specifically be: selecting the first AUSF corresponding to the first HNI and the first RID from the above third mapping relationship according to the indication information.

作为一种实现方法,如果NRF或NSWO NF接收到第三HNI,但没有收到指示终端设备使用NSWO的方式接入网络的指示信息,则NRF或NSWO NF可以从上述第四映射关系中选择与第三HNI对应的不具有NSWO鉴权能力的AUSF。As an implementation method, if the NRF or NSWO NF receives the third HNI, but does not receive the indication information instructing the terminal device to use the NSWO method to access the network, then the NRF or NSWO NF can choose from the above fourth mapping relationship with The third HNI corresponds to the AUSF that does not have the NSWO authentication capability.

作为另一种实现方法,如果NRF或NSWO NF接收到第三HNI,但没有收到指示终端设备使用NSWO的方式接入网络的指示信息,则NRF或NSWO NF可以基于现有的选择逻辑,根据第三HNI选择AUSF,该AUSF既可以具有NSWO鉴权能力,也可以不具有NSWO鉴权能力,也就是说,NRF或NSWO NF所选择的AUSF是否具有NSWO鉴权能力,是不确定的。As another implementation method, if the NRF or NSWO NF receives the third HNI, but does not receive the indication information instructing the terminal device to use the NSWO method to access the network, then the NRF or NSWO NF can base on the existing selection logic, according to The third HNI selects the AUSF, and the AUSF may or may not have the NSWO authentication capability. That is to say, it is uncertain whether the AUSF selected by the NRF or the NSWO NF has the NSWO authentication capability.

作为再一种实现方法,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者NSWO NF可以根据本地策略,从上述第三映射关系中选择与第三HNI对应的具有NSWO鉴权能力的一个AUSF,或者从上述第四映射关系中选择与第三HNI对应的不具有NSWO鉴权能力的一个AUSF。比如,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者NSWO NF根据本地策略,优先从第三映射关系中选择与第三HNI对应的具有NSWO鉴权能力的一个AUSF。再比如,在没有收到指示终端设备使用NSWO的方式接入网络的指示信息的情况下,NRF或者NSWO NF根据本地策略,优先从第四映射关系中选择与第三HNI对应的不具有NSWO鉴权能力的一个AUSF。As another implementation method, in the case of not receiving the instruction information instructing the terminal device to access the network through NSWO, the NRF or NSWO NF can select the third HNI corresponding to the above third mapping relationship according to the local policy. An AUSF with NSWO authentication capability, or select an AUSF without NSWO authentication capability corresponding to the third HNI from the fourth mapping relationship. For example, in the case of not receiving the instruction information instructing the terminal device to use the NSWO method to access the network, the NRF or NSWO NF will preferentially select from the third mapping relationship the third HNI corresponding to the NSWO authentication capability according to the local policy. of an AUSF. For another example, when no instruction information indicating that the terminal device uses NSWO to access the network is received, the NRF or NSWO NF, according to the local policy, preferentially selects the third HNI corresponding to the third HNI from the fourth mapping relationship without NSWO authentication. An AUSF of power.

作为一种实现方法,本申请实施例中,终端设备的签约数据(也称为用户签约数据)可以存储于UDR上,该UDR上的同一个用户签约数据可以由多个AUSF进行获取,比如可以由对应相同HNI的不同AUSF去UDR获取相同的用户签约数据。结合上面介绍的各种选择AUSF的实现方法,不管NRF或NSWO NF所选择的AUSF是否具有NSWO鉴权能力,只要这些AUSF对应相同的HNI和RID的组合,则这些AUSF均可以从UDR获取相同的用户签约数据,该用户签约数据对应该HNI。下面结合一个示例说明。比如,如果NRF或NSWO NF收到HNI 1、RID 0和指示终端设备使用NSWO的方式接入网络的指示信息,NRF或NSWO NF根据上述表4-1,选择具有NSWO鉴权能力的AUSF 1。如果NRF或NSWO NF收到HNI 1和RID 0,且没有收到指示终端设备使用NSWO的方式接入网络的指示信息,假设NRF或NSWO NF根据上述表4-2,选择不具有NSWO鉴权能力的AUSF 7。该示例中,AUSF 1和AUSF 7均对应HNI 1和RID 0的组合,因此AUSF 1和AUSF7均可以从同一个UDR中获取相同的用户签约数据,该用户签约数据对应该HNI 1和RID 0的组合。As an implementation method, in the embodiment of this application, the subscription data (also called user subscription data) of the terminal device can be stored on the UDR, and the same user subscription data on the UDR can be obtained by multiple AUSFs, for example, The same user subscription data is obtained by UDR from different AUSFs corresponding to the same HNI. Combined with the various implementation methods for selecting AUSF introduced above, regardless of whether the AUSF selected by NRF or NSWO NF has NSWO authentication capability, as long as these AUSFs correspond to the same combination of HNI and RID, these AUSFs can obtain the same from UDR. User subscription data, which corresponds to the HNI. The following is combined with an example. For example, if NRF or NSWO NF receives HNI 1, RID 0 and instruction information instructing terminal equipment to use NSWO to access the network, NRF or NSWO NF selects AUSF 1 with NSWO authentication capability according to the above Table 4-1. If the NRF or NSWO NF receives HNI 1 and RID 0, and does not receive the instruction information instructing the terminal device to use NSWO to access the network, it is assumed that the NRF or NSWO NF does not have the NSWO authentication capability according to the above table 4-2 AUSF 7. In this example, both AUSF 1 and AUSF 7 correspond to the combination of HNI 1 and RID 0, so both AUSF 1 and AUSF7 can obtain the same user subscription data from the same UDR, which corresponds to the HNI 1 and RID 0 combination.

下面结合上述表4-1和表4-2,给出上述图5对应的方法实施例的一个具体示例。以NRF执行上述图5对应的方法实施例为例。A specific example of the method embodiment corresponding to the above-mentioned FIG. 5 is given below in conjunction with the above-mentioned Table 4-1 and Table 4-2. Take the NRF executing the method embodiment corresponding to FIG. 5 above as an example.

在一个示例中,NRF收到HNI1、RID 0和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络,则该指示信息触发NRF从上述表4-1中选择一个具有NSWO鉴权能力的AUSF,具体的,选择的是AUSF 1,或者选择的是AUSF集合1的标识信息所指示的AUSF集合内的一个AUSF。NRF根据该指示信息,不会从表4-2中选择不具有NSWO鉴权能力的AUSF(即升级前的AUSF)。通过该方法,使用该指示信息,触发NRF从上述表4-1中选择一个具有NSWO鉴权能力的AUSF。In an example, the NRF receives HNI1, RID 0 and indication information, the indication information indicates that the terminal device uses NSWO to access the network, and the indication information triggers the NRF to select a NSWO authentication capability from the above table 4-1 The AUSF, specifically, AUSF 1 is selected, or an AUSF in the AUSF set indicated by the identification information of AUSF set 1 is selected. According to the indication information, the NRF will not select the AUSF without NSWO authentication capability (that is, the AUSF before the upgrade) from Table 4-2. Through this method, the indication information is used to trigger the NRF to select an AUSF with NSWO authentication capability from the above Table 4-1.

在又一个示例中,NRF收到HNI1和RID 0,但没有收到上述指示终端设备使用NSWO的方式接入网络的指示信息,则NRF从上述表4-2中选择一个不具有NSWO鉴权能力的AUSF,具体的,选择的是AUSF 7,或者选择的是AUSF集合7的标识信息所指示的AUSF集合内的一个AUSF。由于没有收到上述指示信息,则NRF不会从表2-1中选择具有NSWO鉴权能力的AUSF。通过该方法,NRF从上述表4-2中选择一个不具有NSWO鉴权能力的AUSF。In yet another example, NRF receives HNI1 and RID 0, but does not receive the above indication information instructing the terminal device to access the network through NSWO, then NRF selects one from the above table 4-2 that does not have NSWO authentication capability The AUSF, specifically, AUSF 7 is selected, or an AUSF in the AUSF set indicated by the identification information of the AUSF set 7 is selected. Since the above indication information is not received, the NRF will not select the AUSF with NSWO authentication capability from Table 2-1. Through this method, NRF selects an AUSF that does not have NSWO authentication capability from the above table 4-2.

在又一个示例中,NRF收到HNI1和RID 0,但没有收到上述指示终端设备使用NSWO的方式接入网络的指示信息,则NRF既可以从上述表4-1中选择一个具有NSWO鉴权能力的AUSF,也可以从上述表4-2中选择一个不具有NSWO鉴权能力的AUSF,具体如何选择,取决于实现,比如根据本地策略进行选择。可以理解的是,如果没有收到上述指示信息,则NRF选择的AUSF可能具有NSWO鉴权能力,也可能不具有NSWO鉴权能力。In another example, the NRF receives HNI1 and RID 0, but does not receive the above instruction information instructing the terminal device to access the network in the way of NSWO, then the NRF can select one from the above table 4-1 with NSWO authentication The AUSF with the capability can also select an AUSF without NSWO authentication capability from the above table 4-2. The specific selection depends on the implementation, such as selection according to local policies. It can be understood that if the above indication information is not received, the AUSF selected by the NRF may or may not have the NSWO authentication capability.

作为一种实现方法,本申请实施例还可以建立上述指示信息与上述第三映射关系或第四映射关系之间的关联。As an implementation method, this embodiment of the present application may further establish an association between the foregoing indication information and the foregoing third or fourth mapping relationship.

一种实现方法是,建立指示信息与上述第三映射关系的关联,通过该指示信息可以找到该第一映射关系。An implementation method is to establish an association between the indication information and the above-mentioned third mapping relationship, and the first mapping relationship can be found through the indication information.

另一种实现方法是,将上述第三映射关系与第四映射关系进行结合,以及将该指示信息作为结合后的映射关系的一部分,该指示信息指示终端设备使用NSWO的方式接入网络。以上述表4-1和表4-2为例,可以将上述表4-1与上述表4-2进行结合,并在结合后的表中增加指示信息,可以得到如表4-3所示的映射关系。Another implementation method is to combine the above-mentioned third mapping relationship with the fourth mapping relationship, and use the indication information as part of the combined mapping relationship, the indication information instructing the terminal device to use the NSWO method to access the network. Taking the above Table 4-1 and Table 4-2 as an example, the above Table 4-1 can be combined with the above Table 4-2, and the instruction information can be added to the combined table, as shown in Table 4-3. mapping relationship.

表4-3Table 4-3

Figure BDA0003261882390000241
Figure BDA0003261882390000241

Figure BDA0003261882390000251
Figure BDA0003261882390000251

其中,上述表4-3中,AUSF 1至AUSF6,以及AUSF集合1至AUSF集合6内的AUSF均是具有NSWO鉴权能力的AUSF。AUSF 7至AUSF13,以及AUSF集合7至AUSF集合13内的AUSF均是不具有NSWO鉴权能力的AUSF。Wherein, in the above-mentioned Table 4-3, AUSF 1 to AUSF 6, and AUSFs in AUSF set 1 to AUSF set 6 are all AUSFs with NSWO authentication capability. AUSF 7 to AUSF 13, and the AUSFs in AUSF set 7 to AUSF set 13 are all AUSFs without NSWO authentication capability.

作为一个示例,如果NRF或NSWO NF接收到HNI 1和RID 0,则可以根据表4-3确定HNI 1和RID 0的组合对应的AUSF 7或AUSF集合7内的一个AUSF。如果NRF或NSWO NF收到HNI1、RID 0和指示信息,则根据表4-3确定HNI 1对应的AUSF 1或AUSF集合1内的一个AUSF。As an example, if NRF or NSWO NF receives HNI 1 and RID 0, it can determine AUSF 7 or an AUSF in AUSF set 7 corresponding to the combination of HNI 1 and RID 0 according to Table 4-3. If NRF or NSWO NF receives HNI1, RID 0 and indication information, it will determine AUSF 1 corresponding to HNI 1 or an AUSF in AUSF set 1 according to Table 4-3.

作为一种实现方法,如果上述图5对应的方法实施例是由NRF执行,则上述步骤501具体可以是:NRF接收来自NSWO NF的第一HNI和指示信息,或者NRF接收来自NSWO NF的第一HNI、第一RID和指示信息。进一步的,在上述步骤502之后,NRF还可以向NSWO NF发送确定的具有NSWO鉴权能力的第一AUSF的标识信息。As an implementation method, if the above method embodiment corresponding to Figure 5 is executed by NRF, the above step 501 may specifically be: NRF receives the first HNI and indication information from NSWO NF, or NRF receives the first HNI from NSWO NF HNI, first RID and indication information. Further, after the above step 502, the NRF may also send the identified identification information of the first AUSF with NSWO authentication capability to the NSWO NF.

作为一种实现方法,上述步骤501中,可以从接收到的SUCI中获取到第一HNI,或者从接收到的SUCI中获取到第一HNI和第一RID。As an implementation method, in the above step 501, the first HNI may be obtained from the received SUCI, or the first HNI and the first RID may be obtained from the received SUCI.

根据上述图5对应的方法实施例,NSWO NF进行AUSF的选择,选择了一个AUSF实例,该AUSF实例用于执行hPLMN中的终端设备和UDM之间的NSWO鉴权。NSWO NF可以自己选择AUSF实例,比如通过本地配置的方法从本地选择AUSF实例,或者NSWO NF利用NRF发现AUSF实例。According to the method embodiment corresponding to FIG. 5 above, the NSWO NF selects an AUSF, and selects an AUSF instance, which is used to perform NSWO authentication between the terminal device in the hPLMN and the UDM. The NSWO NF can select the AUSF instance by itself, for example, select the AUSF instance locally through the local configuration method, or the NSWO NF uses NRF to discover the AUSF instance.

也就是说,可以在NSWO NF上配置AUSF选择功能,该AUSF选择功能可以从本地配置中选择一个可用的AUSF实例或者利用NRF发现AUSF实例,该AUSF实例具有NSWO鉴权能力。其中,NSWO NF中的AUSF选择功能在选择AUSF实例时,用到了以下信息:1、SUCI中的HNI或者SUCI中的HNI和RID;2、指示信息(NSWO indicator)。That is to say, the AUSF selection function can be configured on the NSWO NF. The AUSF selection function can select an available AUSF instance from the local configuration or use NRF to discover the AUSF instance. The AUSF instance has NSWO authentication capability. Wherein, the AUSF selection function in NSWO NF uses the following information when selecting an AUSF instance: 1. HNI in SUCI or HNI and RID in SUCI; 2. Indicator information (NSWO indicator).

参考图6,为本申请实施例提供的一种网元的选择方法的流程图。该方法用于选择具有NSWO鉴权能力的AUSF。该方法可以由NRF或用于NRF的模块(如芯片)执行。Referring to FIG. 6 , it is a flow chart of a method for selecting a network element provided in an embodiment of the present application. This method is used to select AUSF with NSWO authentication capability. The method can be performed by the NRF or a module (such as a chip) for the NRF.

该方法包括以下步骤:The method includes the following steps:

步骤601,接收第一消息,该第一消息包含第一HNI。Step 601: Receive a first message, where the first message includes a first HNI.

该第一消息可以来自NSWO NF。This first message may be from NSWO NF.

作为一种实现方法,该第一消息中包含SUCI,该SUCI中包含第一HNI。As an implementation method, the first message includes the SUCI, and the SUCI includes the first HNI.

步骤602,根据该第一消息确定终端设备使用NSWO的方式接入网络,则选择与第一HNI对应的第一AUSF,该第一AUSF具有NSWO鉴权能力。Step 602: According to the first message, it is determined that the terminal device uses NSWO to access the network, and then select the first AUSF corresponding to the first HNI, and the first AUSF has NSWO authentication capability.

作为一种实现方法,可以根据第一消息的来源,判断终端设备是否使用NSWO的方式接入网络。比如,确定第一消息来源于NSWO NF,则确定终端设备使用NSWO的方式接入网络。As an implementation method, according to the source of the first message, it may be determined whether the terminal device uses NSWO to access the network. For example, if it is determined that the first message is from the NSWO NF, then it is determined that the terminal device accesses the network in a NSWO manner.

作为另一种实现方法,该第一消息中包含指示NSWO网络功能(NSWO NF)的网络功能类型(NF type),则可以根据该网络功能类型,确定终端设备使用NSWO的方式接入网络。也即确定收到的第一消息是来自NSWO NF,则触发选择一个与第一HNI对应的具有NSWO鉴权能力的AUSF。As another implementation method, the first message includes a network function type (NF type) indicating a NSWO network function (NSWO NF), and according to the network function type, it can be determined that the terminal device uses NSWO to access the network. That is, if it is determined that the received first message is from the NSWO NF, trigger selection of an AUSF corresponding to the first HNI with NSWO authentication capability.

作为另一种实现方法,可以根据第一消息的名称,确定终端设备使用NSWO的方式接入网络。也即该第一消息的名称本身能够指示终端设备使用NSWO的方式接入网络,从而触发选择一个具有NSWO鉴权能力的AUSF。As another implementation method, according to the name of the first message, it may be determined that the terminal device accesses the network in a NSWO manner. That is, the name of the first message itself can instruct the terminal device to use NSWO to access the network, thereby triggering selection of an AUSF with NSWO authentication capability.

根据上述方案,可以实现选择一个具有NSWO鉴权能力的AUSF,从而该AUSF可以为使用NSWO的方式接入网络的终端设备提供NSWO鉴权服务,有助于实现终端设备的快速和正确接入。According to the above solution, it is possible to select an AUSF with NSWO authentication capability, so that the AUSF can provide NSWO authentication services for terminal devices accessing the network in NSWO mode, which helps to realize fast and correct access of terminal devices.

其中,NRF选择与第一HNI对应的第一AUSF的方法,与图5对应的方法实施例中选择与第一HNI对应的第一AUSF的方法相同,具体的,可以根据第一映射关系或第三映射关系确定第一AUSF,具体可以参考前述描述。Wherein, the method for the NRF to select the first AUSF corresponding to the first HNI is the same as the method for selecting the first AUSF corresponding to the first HNI in the method embodiment corresponding to FIG. The first AUSF is determined by the three mapping relationships, for details, reference may be made to the foregoing description.

作为一种实现方法,NRF还可以接收第二消息,该第二消息中包含第二HNI。NRF根据该第二消息确定终端设备未使用NSWO的方式接入网络,则NRF从第二映射关系或第四映射关系中选择与第二HNI对应的第二AUSF,该第二AUSF不具有NSWO鉴权能力。该第二映射关系与图5对应的方法实施例中的第二映射关系相同,该第四映射关系与图5对应的方法实施例中的第四映射关系相同,可以参考前述描述。As an implementation method, the NRF may also receive a second message, where the second message includes the second HNI. According to the second message, the NRF determines that the terminal device does not use NSWO to access the network, then the NRF selects the second AUSF corresponding to the second HNI from the second mapping relationship or the fourth mapping relationship, and the second AUSF does not have NSWO authentication. power. The second mapping relationship is the same as the second mapping relationship in the method embodiment corresponding to FIG. 5 , and the fourth mapping relationship is the same as the fourth mapping relationship in the method embodiment corresponding to FIG. 5 , and reference may be made to the foregoing description.

作为一种实现方法,则上述步骤501具体可以是:接收来自NSWO NF的第一HNI和指示信息,或者NRF接收来自NSWO NF的第一HNI、第一RID和指示信息。进一步的,在上述步骤502之后,还可以向NSWO NF发送确定的具有NSWO鉴权能力的第一AUSF的标识信息。As an implementation method, the above step 501 may specifically be: receiving the first HNI and indication information from NSWO NF, or the NRF receiving the first HNI, first RID and indication information from NSWO NF. Further, after the above step 502, the identification information of the determined first AUSF having NSWO authentication capability may also be sent to the NSWO NF.

下面介绍终端设备的NSWO鉴权流程,该NSWO鉴权流程中涉及选择具有NSWO鉴权能力的UDM和选择具有NSWO鉴权能力的AUSF。以下实施例中的选择具有NSWO鉴权能力的AUSF的方法可以是前述图4至图6对应的方法中的一个,也可以是其它方法。以下实施例中的选择具有NSWO鉴权能力的UDM的方法可以是前述图4至图6对应的方法中的一个,也可以是其它方法。下面分别说明。The following describes the NSWO authentication process of the terminal device. The NSWO authentication process involves selecting a UDM with NSWO authentication capability and selecting an AUSF with NSWO authentication capability. The method for selecting an AUSF with NSWO authentication capability in the following embodiments may be one of the methods corresponding to the preceding Fig. 4 to Fig. 6 , or may be other methods. The method for selecting a UDM with NSWO authentication capability in the following embodiments may be one of the methods corresponding to the preceding Fig. 4 to Fig. 6 , or may be other methods. Instructions are given below.

参考图7,为本申请实施例提供的一种网元的选择方法的流程图。该方法用于实现终端设备的NSWO鉴权。该方法包括以下步骤:Referring to FIG. 7 , it is a flow chart of a method for selecting a network element provided in an embodiment of the present application. This method is used to realize NSWO authentication of terminal equipment. The method includes the following steps:

步骤701,终端设备与非3GPP接入网元建立连接。Step 701, the terminal device establishes a connection with a non-3GPP access network element.

示例性地,终端设备使用的非3GPP接入技术可以是WLAN。若非3GPP接入技术是WLAN,则非3GPP接入网元是一个Wi-Fi AP。下面以Wi-Fi AP为例进行说明。Exemplarily, the non-3GPP access technology used by the terminal device may be WLAN. If the non-3GPP access technology is WLAN, then the non-3GPP access network element is a Wi-Fi AP. The following uses a Wi-Fi AP as an example for description.

应理解,终端设备所接入的Wi-Fi AP网络可以只支持NSWO方式或者只支持非NSWO方式,还可以既支持NSWO方式,也支持非NSWO方式,因此当一个终端设备收到来自Wi-Fi AP的消息,要先判断是使用非NSWO方式还是NSWO方式接入。这里的消息属于终端设备与Wi-FiAP之间建立连接的过程中,Wi-Fi AP向终端设备发送的消息,终端设备与Wi-Fi AP之间建立连接的过程的信息交互可以参考IEEE802.11中相关的信息交互。作为一个示例,在参考IEEE802.11中相关的信息交互时,可以直接延用其中的信息交互,并且将Wi-Fi AP发送给终端设备的消息作为触发终端设备判断是非NSWO方式还是NSWO方式接入网络的触发条件。或者,作为另一个示例,也可以在IEEE802.11中相关的信息交互的基础上,在Wi-Fi AP发送给终端设备的消息中加入指示终端设备判断是使用非NSWO方式还是NSWO方式接入网络的指示信息。It should be understood that the Wi-Fi AP network connected to the terminal device may only support the NSWO mode or only the non-NSWO mode, and may also support both the NSWO mode and the non-NSWO mode. For AP messages, it is first necessary to determine whether to use non-NSWO or NSWO access. The message here belongs to the message sent by the Wi-Fi AP to the terminal device during the process of establishing a connection between the terminal device and the Wi-Fi AP. For information exchange during the process of establishing a connection between the terminal device and the Wi-Fi AP, please refer to IEEE802.11 related information exchange. As an example, when referring to the relevant information interaction in IEEE802.11, the information interaction can be directly used, and the message sent by the Wi-Fi AP to the terminal device can be used as a trigger for the terminal device to determine whether to access in a non-NSWO or NSWO mode Network trigger conditions. Or, as another example, on the basis of the relevant information exchange in IEEE802.11, it is also possible to add in the message sent by the Wi-Fi AP to the terminal device to instruct the terminal device to judge whether to use the non-NSWO method or the NSWO method to access the network. instructions for the .

关于终端设备判断是使用非NSWO方式还是NSWO方式接入网络,可以通过如下方式,比如,终端设备可以本地保存的列表,本地策略或者终端设备使用者手动选择等方式确定选择哪种接入方式。Regarding whether the terminal device judges whether to use the non-NSWO method or the NSWO method to access the network, the following methods can be used to determine which access method to choose, for example, a list that the terminal device can store locally, a local policy, or a manual selection by the terminal device user.

作为一个示例,终端设备本地保存有一张Wi-Fi AP或者服务集标识(service setidentifier,SSID)或者WLAN网络的名称的列表,符合该列表的则优先使用非NSWO接入,或者优先使用NSWO接入。该列表运营商可以通过多种方式配置给终端设备,例如空中下载(over the air,OTA),或者,通过NAS消息传递给终端设备,比如用户设备参数更新(UEParameters Update,UPU)流程等,或者还可以通过其他方式,本申请对此不做限定。As an example, the terminal device locally stores a list of Wi-Fi APs or service set identifiers (service setidentifier, SSID) or WLAN network names, and those that match the list will preferentially use non-NSWO access, or preferentially use NSWO access . The list operator can be configured to the terminal device in a variety of ways, such as downloading over the air (over the air, OTA), or passing it to the terminal device through a NAS message, such as a user equipment parameter update (UEParameters Update, UPU) process, etc., or Other methods can also be used, which are not limited in this application.

作为另一个示例,本地策略,可以是一种选网逻辑,或者一种选择接入方法的逻辑,其可以包括一种或多种策略形式,例如白名单、黑名单、接入方法优先级排序等。本地策略则可以是运营商通过OTA或者通过NAS消息传递给终端设备,比如通过NAS消息传递UE路由选择策略(UE route selection policy,URSP),该URSP中可以指示当终端设备接入一个Wi-Fi AP的时候,是优先选择使用非NSWO接入还是NSWO接入方法。本地策略还可以指示终端设备优先使用非NSWO接入,在不成功后,才可以选择NSWO接入方法。本地的策略的配置方法可以有多种,其目的是使终端设备按照一定的入网逻辑接入网络。终端设备的使用者可以通过手机屏幕选择一个网络,当该网络可以同时使用非NSWO和NSWO接入的时候,用户可以根据屏幕弹框选择想要的接入方式。As another example, a local policy may be a network selection logic, or a logic for selecting an access method, which may include one or more policy forms, such as whitelist, blacklist, and priority ordering of access methods wait. The local policy can be transmitted by the operator to the terminal device through OTA or NAS message, for example, the UE route selection policy (UE route selection policy, URSP) is transmitted through NAS message, and the URSP can indicate that when the terminal device accesses a Wi-Fi When connecting to an AP, it is preferred to use a non-NSWO access method or a NSWO access method. The local policy can also instruct the terminal device to use non-NSWO access first, and only select the NSWO access method if it fails. There are many ways to configure the local policy, the purpose of which is to enable the terminal device to access the network according to a certain network access logic. The user of the terminal device can select a network through the screen of the mobile phone. When the network can be accessed by non-NSWO and NSWO at the same time, the user can select the desired access method according to the pop-up box on the screen.

步骤702,Wi-Fi AP向终端设备发送EAP请求/认证(EAP-Request/Identity)消息,用于触发EAP鉴权。相应的,终端设备接收该EAP请求/认证消息。In step 702, the Wi-Fi AP sends an EAP-Request/Identity (EAP-Request/Identity) message to the terminal device for triggering EAP authentication. Correspondingly, the terminal device receives the EAP request/authentication message.

或者,该消息还可以替换为EAP-Request/AKA’-Identity消息。Alternatively, this message can also be replaced by an EAP-Request/AKA'-Identity message.

步骤703,终端设备生成SUCI。Step 703, the terminal device generates SUCI.

当终端设备已经通过3GPP或者非NSWO方式接入过网络,终端设备本地可能保存着有效的5G-GUTI、NAS安全上下文。在此上述情形下,如果终端设备正在使用3GPP接入,那么终端设备本地不仅保存着有效的5G全局唯一的临时标识(5G-globally unique temporaryidentity,5G-GUTI)、NAS安全上下文,还有接入层(access stratum,AS)安全上下文。当终端设备确定使用NSWO模式接入后,终端设备不使用本地保存的5G-GUTI和有效的安全上下文,而是根据用户永久标识(subscription permanent identifier,SUPI)生成SUCI。这是因为5G-GUTI对应的SUPI是保存在AMF上的,如果要发送5G-GUTI,则终端设备要将5G-GUTI发给相应的AMF,然后AMF将该5G-GUTI对应的SUPI给UDM,但是NSWO接入方式是不经过AMF的,因此终端设备不能使用5G-GUTI。也即,当终端设备确定使用NSWO模式接入后,终端设备会根据SUPI生成SUCI。When the terminal device has been connected to the network through 3GPP or non-NSWO, the terminal device may locally store valid 5G-GUTI and NAS security contexts. In the above situation, if the terminal device is using 3GPP access, the terminal device not only saves the effective 5G globally unique temporary identity (5G-globally unique temporary identity, 5G-GUTI), NAS security context, but also the access Layer (access stratum, AS) security context. When the terminal device determines to use the NSWO mode for access, the terminal device does not use the locally saved 5G-GUTI and effective security context, but generates SUCI according to the subscription permanent identifier (SUPI). This is because the SUPI corresponding to the 5G-GUTI is stored on the AMF. If the 5G-GUTI is to be sent, the terminal device must send the 5G-GUTI to the corresponding AMF, and then the AMF sends the SUPI corresponding to the 5G-GUTI to the UDM. However, the NSWO access method does not pass through AMF, so terminal equipment cannot use 5G-GUTI. That is, after the terminal device determines to use the NSWO mode for access, the terminal device generates SUCI according to the SUPI.

其中,SUCI中包含HNI和RID,可选的,该SUCI中还包含指示信息,该指示信息指示终端设备使用NSWO的方式接入网络,或者指示需要使用EAP-AKA’鉴权方法。Wherein, the SUCI includes the HNI and the RID, and optionally, the SUCI also includes indication information, which indicates that the terminal device uses NSWO to access the network, or indicates that the EAP-AKA' authentication method needs to be used.

示例性的,该SUCI可以是NAI格式的SUCI。Exemplarily, the SUCI may be a SUCI in NAI format.

步骤704,终端设备向Wi-Fi AP发送EAP响应/认证消息。相应的,Wi-Fi AP接收该EAP响应/认证消息。Step 704, the terminal device sends an EAP response/authentication message to the Wi-Fi AP. Correspondingly, the Wi-Fi AP receives the EAP response/authentication message.

该EAP响应/认证消息中包含SUCI。The EAP Response/Authentication message contains the SUCI.

步骤705,Wi-Fi AP向NSWO NF发送EAP响应/认证消息。相应的,NSWO NF接收该EAP响应/认证消息。Step 705, Wi-Fi AP sends EAP response/authentication message to NSWO NF. Correspondingly, the NSWO NF receives the EAP response/authentication message.

该EAP响应/认证消息中包含SUCI。The EAP Response/Authentication message contains the SUCI.

步骤706,NSWO NF选择具有NSWO鉴权能力的AUSF。Step 706, NSWO NF selects AUSF with NSWO authentication capability.

NSWO NF收到SUCI之后,可以根据该SUCI确定终端设备使用NSWO的方式接入网络,进而NSWO NF决定选择一个具有NSWO鉴权能力的AUSF。After the NSWO NF receives the SUCI, it can determine that the terminal device uses the NSWO method to access the network according to the SUCI, and then the NSWO NF decides to select an AUSF with NSWO authentication capability.

或者,NSWO NF收到SUCI之后,该SUCI中包含指示信息,该指示信息指示终端设备使用NSWO的方式接入网络,或者指示需要使用EAP-AKA’鉴权方法,则NSWO NF可以根据该指示信息决定选择一个具有NSWO鉴权能力的AUSF。Or, after the NSWO NF receives the SUCI, the SUCI contains indication information, the indication information indicates that the terminal equipment uses the NSWO method to access the network, or indicates that the EAP-AKA' authentication method needs to be used, then the NSWO NF can use the indication information Decided to choose an AUSF with NSWO authentication capability.

或者,NSWO本身就是个NSWO流程相关的网元,因此NSWO NF确定选择具有NSWO鉴权能力的AUSF。Alternatively, NSWO itself is a network element related to the NSWO process, so the NSWO NF determines to select the AUSF with NSWO authentication capability.

其中,NSWO NF选择一个具有NSWO鉴权能力的AUSF的具体实现方法可以参考前述图5对应的方法实施例中的描述,即根据SUCI中的HNI,以及预定义的第一映射关系确定一个具有NSWO鉴权能力的AUSF,或者是根据SUCI中的HNI和RID,以及预定义的第三映射关系确定一个具有NSWO鉴权能力的AUSF,具体参考前述描述。Among them, the specific implementation method for the NSWO NF to select an AUSF with NSWO authentication capability can refer to the description in the method embodiment corresponding to Figure 5 above, that is, according to the HNI in SUCI and the predefined first mapping relationship, determine an AUSF with NSWO authentication capability. An AUSF with authentication capability, or an AUSF with NSWO authentication capability is determined according to the HNI and RID in SUCI and the third predefined mapping relationship, refer to the foregoing description for details.

步骤707,NSWO NF向AUSF发送认证请求消息(Nausf_UEAuthentication_Request)。相应的,AUSF接收该认证请求消息。Step 707, NSWO NF sends an authentication request message (Nausf_UEAuthentication_Request) to AUSF. Correspondingly, the AUSF receives the authentication request message.

作为一种实现方法,该认证请求消息中携带SUCI和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络。该指示信息可以是一个单独的指示信息,也可以是携带于SNN中。As an implementation method, the authentication request message carries SUCI and indication information, and the indication information instructs the terminal device to use NSWO to access the network. The indication information may be a single indication information, or may be carried in the SNN.

作为另一种实现方法,该认证请求消息中携带SUCI,该SUCI中包含指示信息,该指示信息指示终端设备使用NSWO的方式接入网络。As another implementation method, the authentication request message carries SUCI, and the SUCI includes indication information, and the indication information instructs the terminal device to use NSWO to access the network.

作为一种实现方法,如果NSWO NF收到的SUCI中包含指示信息,则NSWO NF向AUSF发送的指示信息可以是与收到的SUCI中的指示信息相同,或者是NSWO NF根据收到的SUCI中的指示信息重新生成的。As an implementation method, if the SUCI received by NSWO NF contains indication information, the indication information sent by NSWO NF to AUSF can be the same as the indication information in the received SUCI, or the NSWO NF can The instructions are regenerated.

作为另一种实现方法,如果NSWO NF收到的SUCI中不包含指示信息,则NSWO NF向AUSF发送的指示信息可以是NSWO NF生成的。As another implementation method, if the SUCI received by the NSWO NF does not contain indication information, the indication information sent by the NSWO NF to the AUSF may be generated by the NSWO NF.

步骤708,AUSF选择具有NSWO鉴权能力的UDM。Step 708, AUSF selects a UDM with NSWO authentication capability.

AUSF根据指示终端设备使用NSWO的方式接入网络的指示信息,触发AUSF选择一个具有NSWO鉴权能力的UDM。该指示信息是收到的SUCI中的指示信息,或者是收到的一个单独的指示信息,或者是收到的SNN中的一个指示信息。The AUSF triggers the AUSF to select a UDM with NSWO authentication capability according to the indication information instructing the terminal equipment to use the NSWO mode to access the network. The indication information is the indication information in the received SUCI, or a single received indication information, or a received indication information in the SNN.

或者,AUSF确定收到的认证请求消息来源于NSWO NF,则确定选择具有NSWO鉴权能力的UDM。Alternatively, the AUSF determines that the received authentication request message comes from the NSWO NF, and then determines to select a UDM with NSWO authentication capability.

其中,AUSF选择一个具有NSWO鉴权能力的UDM的具体实现方法可以参考前述图4对应的方法实施例中的描述,即根据SUCI中的HNI,以及预定义的第一映射关系确定一个具有NSWO鉴权能力的UDM,或者是根据SUCI中的HNI和RID,以及预定义的第三映射关系确定一个具有NSWO鉴权能力的UDM,具体参考前述描述。Among them, the specific implementation method for AUSF to select a UDM with NSWO authentication capability can refer to the description in the method embodiment corresponding to Figure 4 above, that is, determine a UDM with NSWO authentication according to the HNI in SUCI and the predefined first mapping relationship. A UDM with NSWO authentication capability, or a UDM with NSWO authentication capability is determined according to the HNI and RID in SUCI and the predefined third mapping relationship. For details, refer to the foregoing description.

作为另一种实现方法,还可以预先建立RID与具有NSWO鉴权能力的UDM之间的映射关系。如果上述步骤706中是根据SUCI中的HNI和RID选择的AUSF,则在选择AUSF后,AUSF可以确定该AUSF对应的一个UDM集合,进而根据RID与UDM之间的映射关系,从AUSF对应的UDM集合中选择一个与SUCI中的RID对应的UDM。其中,AUSF对应的UDM集合中的UDM均具有NSWO鉴权能力。As another implementation method, the mapping relationship between the RID and the UDM with NSWO authentication capability may also be established in advance. If the AUSF is selected according to the HNI and RID in SUCI in the above step 706, after selecting the AUSF, the AUSF can determine a UDM set corresponding to the AUSF, and then according to the mapping relationship between RID and UDM, from the UDM corresponding to the AUSF Select a UDM corresponding to the RID in SUCI in the set. Wherein, the UDMs in the UDM set corresponding to the AUSF all have the NSWO authentication capability.

步骤709,AUSF向UDM发送认证获取请求消息(Nudm_UEAuthentication_GetRequest)。相应的,UDM接收该认证获取请求消息。In step 709, the AUSF sends an authentication acquisition request message (Nudm_UEAuthentication_GetRequest) to the UDM. Correspondingly, the UDM receives the authentication acquisition request message.

作为一种实现方法,该认证获取请求消息中携带SUCI和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络。该指示信息可以是一个单独的指示信息,也可以是携带于SNN中的一个指示信息。As an implementation method, the authentication acquisition request message carries SUCI and indication information, and the indication information instructs the terminal device to use NSWO to access the network. The indication information may be a single indication information, or may be an indication information carried in the SNN.

作为另一种实现方法,该认证获取请求消息中携带SUCI,该SUCI中包含指示信息,该指示信息指示终端设备使用NSWO的方式接入网络。As another implementation method, the authentication acquisition request message carries SUCI, and the SUCI includes indication information, and the indication information instructs the terminal device to use NSWO to access the network.

作为一种实现方法,AUSF向UDM发送的指示信息可以是与AUSF从NSWO NF收到的指示信息相同,或者是AUSF根据从NSWO NF收到的指示信息重新生成的。As an implementation method, the indication information sent by AUSF to UDM may be the same as the indication information received by AUSF from NSWO NF, or AUSF may regenerate it according to the indication information received from NSWO NF.

步骤710,UDM根据指示信息,选择EAP-AKA’鉴权方法。Step 710, UDM selects the EAP-AKA' authentication method according to the indication information.

具体的,该指示信息触发UDM选择EAP-AKA’鉴权方法,而不选择5G-AKA鉴权方法。其中,UDM选择EAP-AKA’鉴权方法的过程可以是:UDM先SUCI解密获得SUPI,然后获取与该SUPI对应的EAP-AKA’鉴权方法。Specifically, the indication information triggers the UDM to select the EAP-AKA' authentication method instead of the 5G-AKA authentication method. The process for the UDM to select the EAP-AKA' authentication method may be: the UDM first decrypts the SUCI to obtain the SUPI, and then obtains the EAP-AKA' authentication method corresponding to the SUPI.

步骤711,UDM向AUSF发送认证获取响应消息(Nudm_UEAuthentication_GetResponse)。相应的,AUSF接收该认证获取响应消息。In step 711, the UDM sends an authentication acquisition response message (Nudm_UEAuthentication_GetResponse) to the AUSF. Correspondingly, the AUSF receives the authentication acquisition response message.

该认证获取响应消息携带认证向量(authentication vector,AV)和SUPI。The authentication acquisition response message carries an authentication vector (authentication vector, AV) and SUPI.

其中,该AV是与EAP-AKA’鉴权方法对应的AV。Wherein, the AV is an AV corresponding to the EAP-AKA' authentication method.

步骤712,AUSF确定使用EAP-AKA’鉴权方法,并通过NSWO NF和Wi-Fi AP向终端设备发送EAP请求/AKA’邀请(EAP Request/AKA’-Challenge)消息。Step 712, the AUSF determines to use the EAP-AKA' authentication method, and sends an EAP Request/AKA'-Challenge (EAP Request/AKA'-Challenge) message to the terminal device through the NSWO NF and the Wi-Fi AP.

步骤713,终端设备验证网络侧的真实性。Step 713, the terminal device verifies the authenticity of the network side.

上述方案可以实现终端设备使用NSWO的方式接入网络过程中对终端设备进行NSWO鉴权,可以保证通信的安全性。并且上述方法中选择的AUSF和UDM均具有NSWO鉴权能力,从而可以保证整个NSWO鉴权流程的顺利执行,有助于提升NSWO鉴权流程的效率。该方法中是由NSWO NF选择AUSF,以及AUSF选择UDM。The above solution can implement NSWO authentication on the terminal device during the process of accessing the network by using the NSWO method, which can ensure the security of communication. In addition, the AUSF and UDM selected in the above method both have NSWO authentication capabilities, thereby ensuring the smooth execution of the entire NSWO authentication process and helping to improve the efficiency of the NSWO authentication process. In this approach, NSWO NF selects AUSF, and AUSF selects UDM.

参考图8,为本申请实施例提供的一种网元的选择方法的流程图。该方法用于实现终端设备的NSWO鉴权。该方法包括以下步骤:Referring to FIG. 8 , it is a flowchart of a method for selecting a network element provided in an embodiment of the present application. This method is used to realize NSWO authentication of terminal equipment. The method includes the following steps:

步骤801至步骤805,同步骤701至步骤705。Step 801 to step 805 are the same as step 701 to step 705.

步骤806a,NSWO NF向NRF发送发现请求(Nnrf_AUSFDiscovery_Request)消息。相应的,NRF接收该发现请求消息。In step 806a, the NSWO NF sends a discovery request (Nnrf_AUSFDiscovery_Request) message to the NRF. Correspondingly, the NRF receives the discovery request message.

作为一种实现方法,该发现请求消息中包含SUCI。As an implementation method, the discovery request message includes SUCI.

作为另一种实现方法,该发现请求消息中包含SUCI和用于指示选择具有NSWO鉴权能力的AUSF的指示信息。As another implementation method, the discovery request message includes SUCI and indication information used to indicate selection of an AUSF with NSWO authentication capability.

作为另一种实现方法,该发现请求消息中包含SUCI和NSWO NF类型,该NSWO NF类型指示发送该发现请求消息的网元是一个NSWO NF。As another implementation method, the discovery request message includes SUCI and NSWO NF type, and the NSWO NF type indicates that the network element sending the discovery request message is a NSWO NF.

步骤806b,NRF选择具有NSWO鉴权能力的AUSF。Step 806b, NRF selects AUSF with NSWO authentication capability.

如果发现请求消息中包含SUCI和用于指示选择具有NSWO鉴权能力的AUSF的指示信息,则该指示信息触发NRF选择一个具有NSWO鉴权能力的AUSF。If the discovery request message includes SUCI and indication information for indicating selection of an AUSF capable of NSWO authentication, the indication information triggers the NRF to select an AUSF capable of NSWO authentication.

如果发现请求消息中包含SUCI和NSWO NF类型,则NRF根据该NSWO NF类型确定选择一个具有NSWO鉴权能力的AUSF。If the discovery request message contains SUCI and NSWO NF type, the NRF determines to select an AUSF with NSWO authentication capability according to the NSWO NF type.

如果发现请求消息中包含SUCI,则NRF可以根据发送发现请求消息的名称,确定选择一个具有NSWO鉴权能力的AUSF。If the discovery request message contains SUCI, the NRF can determine to select an AUSF with NSWO authentication capability according to the name of the discovery request message.

或者,NRF确定该发现请求消息来源于NSWO NF,则确定选择一个具有NSWO鉴权能力的AUSF。Alternatively, the NRF determines that the discovery request message is from the NSWO NF, and determines to select an AUSF with NSWO authentication capability.

其中,NRF选择一个具有NSWO鉴权能力的AUSF的方法,可以是:NRF根据SUCI中的HNI选择一个具有NSWO鉴权能力的AUSF,或根据SUCI中的HNI和RID选择一个具有NSWO鉴权能力的AUSF。其中,NRF选择AUSF的具体方法可以参考图5对应的方法实施例中的描述。Among them, the method for NRF to select an AUSF with NSWO authentication capability may be: NRF selects an AUSF with NSWO authentication capability according to the HNI in SUCI, or selects an AUSF with NSWO authentication capability according to the HNI and RID in SUCI AUSF. For the specific method for the NRF to select the AUSF, reference may be made to the description in the method embodiment corresponding to FIG. 5 .

步骤806c,NRF向NSWO NF发送发现响应(Nnrf_AUSFDiscovery_Response)消息。相应的,NSWO NF接收该发现响应消息。In step 806c, the NRF sends a discovery response (Nnrf_AUSFDiscovery_Response) message to the NSWO NF. Correspondingly, the NSWO NF receives the discovery response message.

该发现响应消息中包含AUSF的标识信息,该标识信息可以是实例标识、地址或FQDN。The discovery response message includes identification information of the AUSF, and the identification information may be instance identification, address or FQDN.

步骤807,同步骤707。Step 807 is the same as step 707.

步骤808a,AUSF向NRF发送发现请求(Nnrf_UDMDiscovery_Request)消息。相应的,NRF接收该发现请求消息。In step 808a, the AUSF sends a discovery request (Nnrf_UDMDiscovery_Request) message to the NRF. Correspondingly, the NRF receives the discovery request message.

作为另一种实现方法,该发现请求消息中包含SUCI和用于指示选择具有NSWO鉴权能力的UDM的指示信息。As another implementation method, the discovery request message includes SUCI and indication information used to indicate selection of a UDM with NSWO authentication capability.

步骤808b,NRF选择具有NSWO鉴权能力的UDM。In step 808b, the NRF selects a UDM with NSWO authentication capability.

该发现请求消息中的指示信息触发NRF选择一个具有NSWO鉴权能力的UDM。The indication information in the discovery request message triggers the NRF to select a UDM with NSWO authentication capability.

其中,NRF选择一个具有NSWO鉴权能力的UDM的方法,可以是:NRF根据SUCI中的HNI选择一个具有NSWO鉴权能力的UDM,或根据SUCI中的HNI和RID选择一个具有NSWO鉴权能力的UDM。其中,NRF选择UDM的具体方法可以参考图4对应的方法实施例中的描述。Wherein, the method for NRF to select a UDM with NSWO authentication capability may be: NRF selects a UDM with NSWO authentication capability according to the HNI in SUCI, or selects a UDM with NSWO authentication capability according to the HNI and RID in SUCI UDM. For the specific method for the NRF to select the UDM, reference may be made to the description in the method embodiment corresponding to FIG. 4 .

步骤808c,NRF向AUSF发送发现响应(Nnrf_UDMDiscovery_Response)消息。相应的,AUSF接收该发现响应消息。In step 808c, the NRF sends a discovery response (Nnrf_UDMDiscovery_Response) message to the AUSF. Correspondingly, the AUSF receives the discovery response message.

该发现响应消息中包含UDM的标识信息,该标识信息可以是实例标识、地址或FQDN。The discovery response message includes UDM identification information, and the identification information may be instance identification, address or FQDN.

步骤809至步骤813,同步骤709至步骤713。Step 809 to step 813 are the same as step 709 to step 713.

上述方案可以实现终端设备使用NSWO的方式接入网络过程中对终端设备进行NSWO鉴权,可以保证通信的安全性。并且上述方法中选择的AUSF和UDM均具有NSWO鉴权能力,从而可以保证整个NSWO鉴权流程的顺利执行,有助于提升NSWO鉴权流程的效率。该方法中是由NRF选择AUSF和UDM。The above solution can implement NSWO authentication on the terminal device during the process of accessing the network by using the NSWO method, which can ensure the security of communication. In addition, the AUSF and UDM selected in the above method both have NSWO authentication capabilities, thereby ensuring the smooth execution of the entire NSWO authentication process and helping to improve the efficiency of the NSWO authentication process. In this method, AUSF and UDM are selected by NRF.

可以理解的是,为了实现上述实施例中功能,NRF、AUSF和NSWO NF包括了执行各个功能相应的硬件结构和/或软件模块。本领域技术人员应该很容易意识到,结合本申请中所公开的实施例描述的各示例的单元及方法步骤,本申请能够以硬件或硬件和计算机软件相结合的形式来实现。某个功能究竟以硬件还是计算机软件驱动硬件的方式来执行,取决于技术方案的特定应用场景和设计约束条件。It can be understood that, in order to realize the functions in the above embodiments, NRF, AUSF and NSWO NF include hardware structures and/or software modules corresponding to each function. Those skilled in the art should easily realize that the present application can be implemented in the form of hardware or a combination of hardware and computer software with reference to the units and method steps of the examples described in the embodiments disclosed in the present application. Whether a certain function is executed by hardware or computer software drives the hardware depends on the specific application scenario and design constraints of the technical solution.

图9和图10为本申请的实施例提供的可能的通信装置的结构示意图。这些通信装置可以用于实现上述方法实施例中NRF、AUSF或NSWO NF的功能,因此也能实现上述方法实施例所具备的有益效果。在本申请的实施例中,该通信装置可以是NRF、AUSF或NSWO NF,也可以是应用于NRF、AUSF或NSWO NF的模块(如芯片)。FIG. 9 and FIG. 10 are schematic structural diagrams of possible communication devices provided by the embodiments of the present application. These communication devices can be used to implement the functions of the NRF, AUSF or NSWO NF in the above method embodiments, and therefore can also realize the beneficial effects of the above method embodiments. In the embodiment of the present application, the communication device may be NRF, AUSF or NSWO NF, or a module (such as a chip) applied to NRF, AUSF or NSWO NF.

如图9所示,通信装置900包括处理单元910和收发单元920。通信装置900用于实现上述方法实施例中NRF、AUSF或NSWO NF的功能。As shown in FIG. 9 , a communication device 900 includes a processing unit 910 and a transceiver unit 920 . The communication device 900 is configured to implement the functions of the NRF, AUSF or NSWO NF in the above method embodiments.

当该通信装置用于实现上述图4对应的方法实施例时,收发单元920,用于接收第一归属网络的标识信息和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络;处理单元910,用于根据该指示信息,选择与该第一归属网络的标识信息对应的第一统一数据管理网元,该第一统一数据管理网元具有NSWO鉴权能力。When the communication device is used to implement the above-mentioned method embodiment corresponding to FIG. 4 , the transceiver unit 920 is configured to receive identification information and indication information of the first home network, the indication information instructing the terminal device to use NSWO to access the network; processing The unit 910 is configured to select a first unified data management network element corresponding to the identification information of the first home network according to the indication information, where the first unified data management network element has NSWO authentication capability.

作为一种可能的实现方法,处理单元910,用于根据该指示信息,从第一映射关系中选择与该第一归属网络的标识信息对应的该第一统一数据管理网元,该第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的统一数据管理网元之间的映射关系。As a possible implementation method, the processing unit 910 is configured to select the first unified data management network element corresponding to the identification information of the first home network from the first mapping relationship according to the indication information, and the first mapping The relationship includes the mapping relationship between the identification information of the home network and the unified data management network element with NSWO authentication capability.

作为一种可能的实现方法,收发单元920,用于接收第二归属网络的标识信息;处理单元910,用于从第二映射关系中选择与该第二归属网络的标识信息对应的第二统一数据管理网元,该第二统一数据管理网元不具有NSWO鉴权能力,该第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的统一数据管理网元之间的映射关系。As a possible implementation method, the transceiver unit 920 is configured to receive the identification information of the second home network; the processing unit 910 is configured to select from the second mapping relationship the second uniform corresponding to the identification information of the second home network. For the data management network element, the second unified data management network element does not have the NSWO authentication capability, and the second mapping relationship includes the mapping relationship between the identification information of the home network and the unified data management network element without the NSWO authentication capability.

作为一种可能的实现方法,收发单元920,用于接收第一路由标识;处理单元910,用于根据该指示信息,选择与该第一归属网络的标识信息和该第一路由标识对应的该第一统一数据管理网元。As a possible implementation method, the transceiver unit 920 is configured to receive the first routing identifier; the processing unit 910 is configured to select the first routing identifier corresponding to the identifier information of the first home network and the first routing identifier according to the indication information. The first unified data management network element.

作为一种可能的实现方法,处理单元910,用于根据该指示信息,从第三映射关系中选择与该第一归属网络的标识信息和该第一路由标识对应的该第一统一数据管理网元,该第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的统一数据管理网元之间的映射关系。As a possible implementation method, the processing unit 910 is configured to select the first unified data management network corresponding to the identification information of the first home network and the first routing identification from the third mapping relationship according to the indication information The third mapping relationship includes the mapping relationship between the combination of the identification information of the home network and the routing identification and the unified data management network element with NSWO authentication capability.

作为一种可能的实现方法,收发单元920,用于接收来自认证服务功能网元的该第一归属网络的标识信息和该指示信息;向该认证服务功能网元发送该第一统一数据管理网元的标识信息。As a possible implementation method, the transceiver unit 920 is configured to receive the identification information of the first home network and the indication information from the authentication service functional network element; and send the first unified data management network to the authentication service functional network element. Identification information for the element.

当该通信装置用于实现上述图5对应的方法实施例时,收发单元920,用于接收第一归属网络的标识信息和指示信息,该指示信息指示终端设备使用NSWO的方式接入网络;处理单元910,用于根据该指示信息,选择与该第一归属网络的标识信息对应的第一认证服务功能网元,该第一认证服务功能网元具有NSWO鉴权能力。When the communication device is used to implement the above method embodiment corresponding to FIG. 5 , the transceiver unit 920 is configured to receive the identification information and indication information of the first home network, and the indication information indicates that the terminal equipment uses NSWO to access the network; process The unit 910 is configured to select, according to the indication information, a first authentication service functional network element corresponding to the identification information of the first home network, where the first authentication service functional network element has NSWO authentication capability.

作为一种可能的实现方法,处理单元910,用于根据该指示信息,从第一映射关系中选择与该第一归属网络的标识信息对应的该第一认证服务功能网元,该第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the processing unit 910 is configured to select the first authentication service function network element corresponding to the identification information of the first home network from the first mapping relationship according to the indication information, and the first mapping The relationship includes the mapping relationship between the identification information of the home network and the authentication service function network element with NSWO authentication capability.

作为一种可能的实现方法,收发单元920,用于接收第二归属网络的标识信息;处理单元910,用于从第二映射关系中选择与该第二归属网络的标识信息对应的第二认证服务功能网元,该第二认证服务功能网元不具有NSWO鉴权能力,该第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the transceiver unit 920 is configured to receive the identification information of the second home network; the processing unit 910 is configured to select the second authentication corresponding to the identification information of the second home network from the second mapping relationship. The service function network element, the second authentication service function network element does not have the NSWO authentication capability, and the second mapping relationship includes the mapping relationship between the identification information of the home network and the authentication service function network element without the NSWO authentication capability.

作为一种可能的实现方法,收发单元920,用于接收第一路由标识;处理单元910,用于根据该指示信息,选择与该第一归属网络的标识信息和该第一路由标识对应的该第一认证服务功能网元。As a possible implementation method, the transceiver unit 920 is configured to receive the first routing identifier; the processing unit 910 is configured to select the first routing identifier corresponding to the identifier information of the first home network and the first routing identifier according to the indication information. The first authentication service function network element.

作为一种可能的实现方法,处理单元910,用于根据该指示信息,从第三映射关系中选择与该第一归属网络的标识信息和该第一路由标识对应的该第一认证服务功能网元,该第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the processing unit 910 is configured to select the first authentication service functional network corresponding to the identification information of the first home network and the first routing identifier from the third mapping relationship according to the indication information The third mapping relationship includes the mapping relationship between the combination of the identification information of the home network and the routing identification and the authentication service function network element with NSWO authentication capability.

作为一种可能的实现方法,收发单元920,用于接收来自NSWO网元的该第一归属网络的标识信息和该指示信息;向该NSWO网元发送该第一认证服务功能网元的标识信息。As a possible implementation method, the transceiver unit 920 is configured to receive the identification information of the first home network and the indication information from the NSWO network element; and send the identification information of the first authentication service function network element to the NSWO network element .

当该通信装置用于实现上述图6对应的方法实施例时,收发单元920,用于接收第一消息,该第一消息包含第一归属网络的标识信息;处理单元910,用于根据该第一消息确定终端设备使用NSWO的方式接入网络,则选择与该第一归属网络的标识信息对应的第一认证服务功能网元,该第一认证服务功能网元具有NSWO鉴权能力。When the communication device is used to implement the above method embodiment corresponding to FIG. 6 , the transceiver unit 920 is configured to receive a first message, the first message includes identification information of the first home network; If a message confirms that the terminal device uses NSWO to access the network, select the first authentication service function network element corresponding to the identification information of the first home network, and the first authentication service function network element has NSWO authentication capability.

作为一种可能的实现方法,处理单元910,用于从第一映射关系中选择与该第一归属网络的标识信息对应的该第一认证服务功能网元,该第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the processing unit 910 is configured to select the first authentication service function network element corresponding to the identification information of the first home network from a first mapping relationship, where the first mapping relationship includes the identity information of the home network The mapping relationship between identification information and authentication service function network elements with NSWO authentication capabilities.

作为一种可能的实现方法,收发单元920,用于接收第二消息,该第二消息包含第二归属网络的标识信息;处理单元910,用于根据该第二消息确定终端设备未使用NSWO的方式接入网络,则从第二映射关系中选择与该第二归属网络的标识信息对应的第二认证服务功能网元,该第二认证服务功能网元不具有NSWO鉴权能力,该第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the transceiver unit 920 is configured to receive a second message, the second message includes identification information of the second home network; the processing unit 910 is configured to determine that the terminal device does not use the NSWO access to the network in the same way, select the second authentication service function network element corresponding to the identification information of the second home network from the second mapping relationship, the second authentication service function network element does not have the NSWO authentication capability, the second The mapping relationship includes the mapping relationship between the identification information of the home network and the authentication service function network element that does not have the NSWO authentication capability.

作为一种可能的实现方法,该第一消息中还包含第一路由标识;处理单元910,用于选择与该第一归属网络的标识信息和该第一路由标识对应的该第一认证服务功能网元。As a possible implementation method, the first message further includes a first routing identifier; a processing unit 910 is configured to select the first authentication service function corresponding to the first home network identification information and the first routing identifier network element.

作为一种可能的实现方法,处理单元910,用于从第三映射关系中选择与该第一归属网络的标识信息和该第一路由标识对应的该第一认证服务功能网元,该第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。As a possible implementation method, the processing unit 910 is configured to select the first authentication service function network element corresponding to the identification information of the first home network and the first routing identifier from the third mapping relationship, and the third The mapping relationship includes the mapping relationship between the combination of the identification information of the home network and the routing identification and the authentication service function network element with NSWO authentication capability.

作为一种可能的实现方法,第一消息包含指示NSWO网络功能的网络功能类型;处理单元910,用于根据该网络功能类型,确定该终端设备使用NSWO的方式接入网络。As a possible implementation method, the first message includes a network function type indicating the NSWO network function; and the processing unit 910 is configured to determine that the terminal device uses NSWO to access the network according to the network function type.

作为一种可能的实现方法,处理单元910,用于根据该第一消息的名称,确定该终端设备使用NSWO的方式接入网络。As a possible implementation method, the processing unit 910 is configured to determine, according to the name of the first message, that the terminal device uses NSWO to access the network.

作为一种可能的实现方法,收发单元920,用于接收来自NSWO网元的该第一消息;向该NSWO网元发送该第一认证服务功能网元的标识信息。As a possible implementation method, the transceiver unit 920 is configured to receive the first message from the NSWO network element; and send the identification information of the first authentication service function network element to the NSWO network element.

有关上述处理单元910和收发单元920更详细的描述可以直接参考上述方法实施例中相关描述直接得到,这里不加赘述。More detailed descriptions about the processing unit 910 and the transceiver unit 920 can be directly obtained by referring to related descriptions in the above method embodiments, and details are not repeated here.

如图10所示,通信装置1000包括处理器1010,作为一种实现方法,该通信装置1000还可以包括接口电路1020。处理器1010和接口电路1020之间相互耦合。可以理解的是,接口电路1020可以为收发器或输入输出接口。作为一种实现方法,通信装置1000还可以包括存储器1030,用于存储处理器1010执行的指令或存储处理器1010运行指令所需要的输入数据或存储处理器1010运行指令后产生的数据。As shown in FIG. 10 , the communication device 1000 includes a processor 1010 , and as an implementation method, the communication device 1000 may further include an interface circuit 1020 . The processor 1010 and the interface circuit 1020 are coupled to each other. It can be understood that the interface circuit 1020 may be a transceiver or an input-output interface. As an implementation method, the communication device 1000 may further include a memory 1030 for storing instructions executed by the processor 1010 or storing input data required by the processor 1010 to execute the instructions or storing data generated by the processor 1010 after executing the instructions.

当通信装置1000用于实现上述方法实施例时,处理器1010用于实现上述处理单元910的功能,接口电路1020用于实现上述收发单元920的功能。When the communication device 1000 is used to implement the above method embodiments, the processor 1010 is used to implement the functions of the processing unit 910 , and the interface circuit 1020 is used to implement the functions of the transceiver unit 920 .

可以理解的是,本申请的实施例中的处理器可以是中央处理单元(centralprocessing unit,CPU),还可以是其它通用处理器、数字信号处理器(digital signalprocessor,DSP)、专用集成电路(application specific integrated circuit,ASIC)、现场可编程门阵列(field programmable gate array,FPGA)或者其它可编程逻辑器件、晶体管逻辑器件,硬件部件或者其任意组合。通用处理器可以是微处理器,也可以是任何常规的处理器。It can be understood that the processor in the embodiment of the present application may be a central processing unit (central processing unit, CPU), and may also be other general processors, digital signal processors (digital signal processor, DSP), application specific integrated circuits (application specific integrated circuit (ASIC), field programmable gate array (field programmable gate array, FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. A general-purpose processor can be a microprocessor, or any conventional processor.

本申请的实施例中的方法步骤可以通过硬件的方式来实现,也可以由处理器执行软件指令的方式来实现。软件指令可以由相应的软件模块组成,软件模块可以被存放于随机存取存储器、闪存、只读存储器、可编程只读存储器、可擦除可编程只读存储器、电可擦除可编程只读存储器、寄存器、硬盘、移动硬盘、CD-ROM或者本领域熟知的任何其它形式的存储介质中。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于ASIC中。另外,该ASIC可以位于基站或终端中。当然,处理器和存储介质也可以作为分立组件存在于基站或终端中。The method steps in the embodiments of the present application may be implemented by means of hardware, or may be implemented by means of a processor executing software instructions. Software instructions can be composed of corresponding software modules, and software modules can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only Memory, registers, hard disk, removable hard disk, CD-ROM or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such the processor can read information from, and write information to, the storage medium. Of course, the storage medium may also be a component of the processor. The processor and storage medium can be located in the ASIC. In addition, the ASIC can be located in the base station or the terminal. Certainly, the processor and the storage medium may also exist in the base station or the terminal as discrete components.

在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机程序或指令。在计算机上加载和执行所述计算机程序或指令时,全部或部分地执行本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、基站、用户设备或者其它可编程装置。所述计算机程序或指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机程序或指令可以从一个网站站点、计算机、服务器或数据中心通过有线或无线方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是集成一个或多个可用介质的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质,例如,软盘、硬盘、磁带;也可以是光介质,例如,数字视频光盘;还可以是半导体介质,例如,固态硬盘。该计算机可读存储介质可以是易失性或非易失性存储介质,或可包括易失性和非易失性两种类型的存储介质。In the above embodiments, all or part of them may be implemented by software, hardware, firmware or any combination thereof. When implemented using software, it may be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer programs or instructions. When the computer program or instructions are loaded and executed on the computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer may be a general purpose computer, a special purpose computer, a computer network, a base station, user equipment or other programmable devices. The computer program or instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer program or instructions may be downloaded from a website, computer, A server or data center transmits to another website site, computer, server or data center by wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center integrating one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disk; and it may also be a semiconductor medium, such as a solid state disk. The computer readable storage medium may be a volatile or a nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.

在本申请的各个实施例中,如果没有特殊说明以及逻辑冲突,不同的实施例之间的术语和/或描述具有一致性、且可以相互引用,不同的实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。In each embodiment of the present application, if there is no special explanation and logical conflict, the terms and/or descriptions between different embodiments are consistent and can be referred to each other, and the technical features in different embodiments are based on their inherent Logical relationships can be combined to form new embodiments.

本申请中,“至少一个”是指一个或者多个,“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B的情况,其中A,B可以是单数或者复数。在本申请的文字描述中,字符“/”,一般表示前后关联对象是一种“或”的关系;在本申请的公式中,字符“/”,表示前后关联对象是一种“相除”的关系。In this application, "at least one" means one or more, and "multiple" means two or more. "And/or" describes the association relationship of associated objects, indicating that there may be three types of relationships, for example, A and/or B, which can mean: A exists alone, A and B exist simultaneously, and B exists alone, where A, B can be singular or plural. In the text description of this application, the character "/" generally indicates that the contextual objects are an "or" relationship; in the formulas of this application, the character "/" indicates that the contextual objects are a "division" Relationship.

可以理解的是,在本申请的实施例中涉及的各种数字编号仅为描述方便进行的区分,并不用来限制本申请的实施例的范围。上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定。It can be understood that the various numbers involved in the embodiments of the present application are only for convenience of description, and are not used to limit the scope of the embodiments of the present application. The size of the serial numbers of the above-mentioned processes does not mean the order of execution, and the execution order of each process should be determined by its functions and internal logic.

Claims (28)

1.一种网元的选择方法,其特征在于,包括:1. A method for selecting a network element, comprising: 接收第一归属网络的标识信息和指示信息,所述指示信息指示终端设备使用有缝无线局域网分流NSWO的方式接入网络;Receive identification information and indication information of the first home network, where the indication information instructs the terminal device to access the network by using a slotted wireless local area network to offload NSWO; 根据所述指示信息,选择与所述第一归属网络的标识信息对应的第一统一数据管理网元,所述第一统一数据管理网元具有NSWO鉴权能力。According to the indication information, select a first unified data management network element corresponding to the identification information of the first home network, and the first unified data management network element has NSWO authentication capability. 2.如权利要求1所述的方法,其特征在于,所述根据所述指示信息,选择与所述第一归属网络的标识信息对应的第一统一数据管理网元,包括:2. The method according to claim 1, wherein the selecting the first unified data management network element corresponding to the identification information of the first home network according to the indication information comprises: 根据所述指示信息,从第一映射关系中选择与所述第一归属网络的标识信息对应的所述第一统一数据管理网元,所述第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的统一数据管理网元之间的映射关系。According to the indication information, select the first unified data management network element corresponding to the identification information of the first home network from the first mapping relationship, the first mapping relationship includes the identification information of the home network and the NSWO The unified data of authentication capability manages the mapping relationship between network elements. 3.如权利要求1或2所述的方法,其特征在于,所述方法还包括:3. the method as claimed in claim 1 or 2, is characterized in that, described method also comprises: 接收第二归属网络的标识信息;receiving identification information of the second home network; 从第二映射关系中选择与所述第二归属网络的标识信息对应的第二统一数据管理网元,所述第二统一数据管理网元不具有NSWO鉴权能力,所述第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的统一数据管理网元之间的映射关系。Select a second unified data management network element corresponding to the identification information of the second home network from the second mapping relationship, the second unified data management network element does not have NSWO authentication capability, and the second mapping relationship includes The mapping relationship between the identification information of the home network and the unified data management network element without NSWO authentication capability. 4.如权利要求1所述的方法,其特征在于,所述方法还包括:4. The method of claim 1, further comprising: 接收第一路由标识;receiving the first routing identifier; 所述根据所述指示信息,选择与所述第一归属网络的标识信息对应的第一统一数据管理网元,包括:The selecting the first unified data management network element corresponding to the identification information of the first home network according to the indication information includes: 根据所述指示信息,选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一统一数据管理网元。According to the indication information, select the first unified data management network element corresponding to the identification information of the first home network and the first routing identification. 5.如权利要求4所述的方法,其特征在于,所述根据所述指示信息,选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一统一数据管理网元,包括:5. The method according to claim 4, wherein, according to the indication information, the first unified data management system corresponding to the identification information of the first home network and the first routing identification is selected. Network elements, including: 根据所述指示信息,从第三映射关系中选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一统一数据管理网元,所述第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的统一数据管理网元之间的映射关系。According to the indication information, select the first unified data management network element corresponding to the identification information of the first home network and the first routing identifier from a third mapping relationship, where the third mapping relationship includes the belonging The mapping relationship between the combination of network identification information and routing identification and the unified data management network element with NSWO authentication capability. 6.如权利要求1至5中任一项所述的方法,其特征在于,所述接收第一归属网络的标识信息和指示信息,包括:6. The method according to any one of claims 1 to 5, wherein the receiving the identification information and indication information of the first home network comprises: 接收来自认证服务功能网元的所述第一归属网络的标识信息和所述指示信息;receiving the identification information of the first home network and the indication information from the authentication service function network element; 所述方法还包括:The method also includes: 向所述认证服务功能网元发送所述第一统一数据管理网元的标识信息。Sending the identification information of the first unified data management network element to the authentication service function network element. 7.一种网元的选择方法,其特征在于,包括:7. A method for selecting a network element, comprising: 接收第一归属网络的标识信息和指示信息,所述指示信息指示终端设备使用有缝无线局域网分流NSWO的方式接入网络;Receive identification information and indication information of the first home network, where the indication information instructs the terminal device to access the network by using a slotted wireless local area network to offload NSWO; 根据所述指示信息,选择与所述第一归属网络的标识信息对应的第一认证服务功能网元,所述第一认证服务功能网元具有NSWO鉴权能力。According to the indication information, select a first authentication service function network element corresponding to the identification information of the first home network, and the first authentication service function network element has NSWO authentication capability. 8.如权利要求7所述的方法,其特征在于,所述根据所述指示信息,选择与所述第一归属网络的标识信息对应的第一认证服务功能网元,包括:8. The method according to claim 7, wherein the selecting the first authentication service function network element corresponding to the identification information of the first home network according to the indication information comprises: 根据所述指示信息,从第一映射关系中选择与所述第一归属网络的标识信息对应的所述第一认证服务功能网元,所述第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。According to the indication information, select the first authentication service function network element corresponding to the identification information of the first home network from the first mapping relationship, the first mapping relationship includes the identification information of the home network and the NSWO The mapping relationship between authentication service function network elements of authentication capabilities. 9.如权利要求7或8所述的方法,其特征在于,所述方法还包括:9. The method according to claim 7 or 8, further comprising: 接收第二归属网络的标识信息;receiving identification information of the second home network; 从第二映射关系中选择与所述第二归属网络的标识信息对应的第二认证服务功能网元,所述第二认证服务功能网元不具有NSWO鉴权能力,所述第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的认证服务功能网元之间的映射关系。Select a second authentication service function network element corresponding to the identification information of the second home network from the second mapping relationship, the second authentication service function network element does not have the NSWO authentication capability, and the second mapping relationship includes The mapping relationship between the identification information of the home network and the authentication service function network element that does not have the NSWO authentication capability. 10.如权利要求7所述的方法,其特征在于,所述方法还包括:10. The method of claim 7, further comprising: 接收第一路由标识;receiving the first routing identifier; 所述根据所述指示信息,选择与所述第一归属网络的标识信息对应的第一认证服务功能网元,包括:The selecting the first authentication service function network element corresponding to the identification information of the first home network according to the indication information includes: 根据所述指示信息,选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一认证服务功能网元。Selecting the first authentication service function network element corresponding to the identification information of the first home network and the first routing identifier according to the indication information. 11.如权利要求10所述的方法,其特征在于,所述根据所述指示信息,选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一认证服务功能网元,包括:11. The method according to claim 10, wherein the first authentication service function corresponding to the identification information of the first home network and the first routing identification is selected according to the indication information Network elements, including: 根据所述指示信息,从第三映射关系中选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一认证服务功能网元,所述第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。According to the indication information, select the first authentication service function network element corresponding to the identification information of the first home network and the first routing identifier from a third mapping relationship, where the third mapping relationship includes The mapping relationship between the combination of the identification information of the network and the routing identification and the authentication service function network element with NSWO authentication capability. 12.如权利要求7至11中任一项所述的方法,其特征在于,所述接收第一归属网络的标识信息和指示信息,包括:12. The method according to any one of claims 7 to 11, wherein the receiving the identification information and indication information of the first home network comprises: 接收来自NSWO网元的所述第一归属网络的标识信息和所述指示信息;receiving the identification information of the first home network and the indication information from a NSWO network element; 所述方法还包括:The method also includes: 向所述NSWO网元发送所述第一认证服务功能网元的标识信息。Sending the identification information of the first authentication service function network element to the NSWO network element. 13.一种网元的选择方法,其特征在于,包括:13. A method for selecting a network element, comprising: 接收第一消息,所述第一消息包含第一归属网络的标识信息;receiving a first message, where the first message includes identification information of a first home network; 根据所述第一消息确定终端设备使用有缝无线局域网分流NSWO的方式接入网络,则选择与所述第一归属网络的标识信息对应的第一认证服务功能网元,所述第一认证服务功能网元具有NSWO鉴权能力。According to the first message, it is determined that the terminal device accesses the network using a slotted wireless local area network to offload NSWO, then select the first authentication service function network element corresponding to the identification information of the first home network, and the first authentication service Functional network elements have NSWO authentication capabilities. 14.如权利要求13所述的方法,其特征在于,所述选择与所述第一归属网络的标识信息对应的第一认证服务功能网元,包括:14. The method according to claim 13, wherein the selecting the first authentication service function network element corresponding to the identification information of the first home network comprises: 从第一映射关系中选择与所述第一归属网络的标识信息对应的所述第一认证服务功能网元,所述第一映射关系包含归属网络的标识信息与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。Select the first authentication service function network element corresponding to the identification information of the first home network from the first mapping relationship, the first mapping relationship includes the identification information of the home network and the authentication service with NSWO authentication capability The mapping relationship between functional network elements. 15.如权利要求13或14所述的方法,其特征在于,所述方法还包括:15. The method of claim 13 or 14, further comprising: 接收第二消息,所述第二消息包含第二归属网络的标识信息;receiving a second message, where the second message includes identification information of a second home network; 根据所述第二消息确定终端设备未使用NSWO的方式接入网络,则从第二映射关系中选择与所述第二归属网络的标识信息对应的第二认证服务功能网元,所述第二认证服务功能网元不具有NSWO鉴权能力,所述第二映射关系包含归属网络的标识信息与不具有NSWO鉴权能力的认证服务功能网元之间的映射关系。According to the second message, it is determined that the terminal device does not use NSWO to access the network, then select the second authentication service function network element corresponding to the identification information of the second home network from the second mapping relationship, and the second The authentication service function network element does not have the NSWO authentication capability, and the second mapping relationship includes the mapping relationship between the identification information of the home network and the authentication service function network element without the NSWO authentication capability. 16.如权利要求13所述的方法,其特征在于,所述第一消息中还包含第一路由标识;16. The method according to claim 13, wherein the first message further comprises a first routing identifier; 所述选择与所述第一归属网络的标识信息对应的第一认证服务功能网元,包括:The selecting the first authentication service function network element corresponding to the identification information of the first home network includes: 选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一认证服务功能网元。Selecting the first authentication service function network element corresponding to the identification information of the first home network and the first routing identification. 17.如权利要求16所述的方法,其特征在于,所述选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一认证服务功能网元,包括:17. The method according to claim 16, wherein the selecting the first authentication service function network element corresponding to the identification information of the first home network and the first routing identification comprises: 从第三映射关系中选择与所述第一归属网络的标识信息和所述第一路由标识对应的所述第一认证服务功能网元,所述第三映射关系包含归属网络的标识信息和路由标识的组合与具有NSWO鉴权能力的认证服务功能网元之间的映射关系。Select the first authentication service function network element corresponding to the identification information of the first home network and the first route identification from a third mapping relationship, where the third mapping relationship includes the identification information and routing of the home network The mapping relationship between the combination of identifiers and the authentication service function network element with NSWO authentication capability. 18.如权利要求13至17中任一项所述的方法,其特征在于,第一消息包含指示NSWO网络功能的网络功能类型;18. The method according to any one of claims 13 to 17, wherein the first message includes a network function type indicating a NSWO network function; 所述根据所述第一消息确定终端设备使用NSWO的方式接入网络,包括:The determining that the terminal device uses NSWO to access the network according to the first message includes: 根据所述网络功能类型,确定所述终端设备使用NSWO的方式接入网络。According to the network function type, it is determined that the terminal device uses NSWO to access the network. 19.如权利要求13至17中任一项所述的方法,其特征在于,所述根据所述第一消息确定终端设备使用NSWO的方式接入网络,包括:19. The method according to any one of claims 13 to 17, wherein the determining that the terminal device uses NSWO to access the network according to the first message includes: 根据所述第一消息的名称,确定所述终端设备使用NSWO的方式接入网络。According to the name of the first message, it is determined that the terminal device uses NSWO to access the network. 20.如权利要求13至19中任一项所述的方法,其特征在于,所述接收第一消息,包括:20. The method according to any one of claims 13 to 19, wherein the receiving the first message comprises: 接收来自NSWO网元的所述第一消息;receiving said first message from a NSWO network element; 所述方法还包括:The method also includes: 向所述NSWO网元发送所述第一认证服务功能网元的标识信息。Sending the identification information of the first authentication service function network element to the NSWO network element. 21.一种通信装置,其特征在于,包括用于执行如权利要求1至6中任一项所述方法的模块,或用于执行如权利要求7至12中任一项所述方法的模块,或用于执行如权利要求13至20中任一项所述方法的模块。21. A communication device, characterized by comprising a module for performing the method according to any one of claims 1 to 6, or a module for performing the method according to any one of claims 7 to 12 , or a module for performing the method according to any one of claims 13 to 20. 22.一种通信装置,其特征在于,包括处理器和存储器;所述存储器用于存储计算机指令,当所述装置运行时,所述处理器执行所述存储器存储的所述计算机指令,以使所述装置执行上述权利要求1至6中任一项所述方法,或执行上述权利要求7至12中任一项所述方法,或执行上述权利要求13至20中任一项所述方法。22. A communication device, characterized in that it includes a processor and a memory; the memory is used to store computer instructions, and when the device is running, the processor executes the computer instructions stored in the memory, so that The device executes the method described in any one of claims 1 to 6 above, or executes the method described in any one of claims 7 to 12 above, or executes the method described in any one of claims 13 to 20 above. 23.一种通信装置,其特征在于,包括处理器和接口电路,所述接口电路用于接收来自所述通信装置之外的其它通信装置的信号并传输至所述处理器或将来自所述处理器的信号发送给所述通信装置之外的其它通信装置,所述处理器通过逻辑电路或执行代码指令用于实现如权利要求1至6中任一项所述的方法,或用于实现如权利要求7至12中任一项所述的方法,或用于实现如权利要求13至20中任一项所述的方法。23. A communication device, characterized in that it includes a processor and an interface circuit, and the interface circuit is used to receive signals from other communication devices other than the communication device and transmit them to the processor or transfer signals from the communication device to the processor. The signal of the processor is sent to other communication devices other than the communication device, and the processor is used to implement the method according to any one of claims 1 to 6 through a logic circuit or execute code instructions, or to implement The method according to any one of claims 7 to 12, or used to implement the method according to any one of claims 13 to 20. 24.一种通信系统,其特征在于,包括:24. A communication system, comprising: 认证服务功能网元,用于向网络存储功能网元发送第一归属网络的标识信息和指示信息,所述指示信息指示终端设备使用有缝无线局域网分流NSWO的方式接入网络;The authentication service function network element is used to send the identification information and indication information of the first home network to the network storage function network element, and the indication information instructs the terminal device to access the network by using the slotted wireless local area network to offload NSWO; 所述网络存储功能网元,用于执行如权利要求1至5中任一项所述的方法。The network storage function network element is configured to execute the method according to any one of claims 1-5. 25.一种通信系统,其特征在于,包括:25. A communication system, characterized in that it comprises: 有缝无线局域网分流NSWO网元,用于向认证服务功能网元发送第一归属网络的标识信息和指示信息,所述指示信息指示终端设备使用NSWO的方式接入网络;Slit WLAN offloading NSWO network elements, used to send identification information and indication information of the first home network to the authentication service function network element, the indication information instructs terminal equipment to use NSWO to access the network; 所述认证服务功能网元,用于执行如权利要求1至5中任一项所述的方法。The authentication service function network element is configured to execute the method according to any one of claims 1-5. 26.一种通信系统,其特征在于,包括:26. A communication system, comprising: 有缝无线局域网分流NSWO网元,用于向网络存储功能网元发送第一归属网络的标识信息和指示信息,所述指示信息指示终端设备使用NSWO的方式接入网络;The slotted wireless local area network offloads the NSWO network element, which is used to send the identification information and indication information of the first home network to the network storage function network element, and the indication information instructs the terminal device to use the NSWO mode to access the network; 所述网络存储功能网元,用于执行如权利要求7至11中任一项所述的方法。The network storage function network element is configured to execute the method according to any one of claims 7-11. 27.一种通信系统,其特征在于,包括:27. A communication system, comprising: 有缝无线局域网分流NSWO网元,用于向网络存储功能网元发送第一消息,所述第一消息包含第一归属网络的标识信息;The slotted wireless local area network offloads the NSWO network element, which is used to send the first message to the network storage function network element, and the first message includes the identification information of the first home network; 所述网络存储功能网元,用于执行如权利要求13至19中任一项所述的方法。The network storage function network element is configured to execute the method according to any one of claims 13-19. 28.一种计算机可读存储介质,其特征在于,所述存储介质中存储有计算机程序或指令,当所述计算机程序或指令被通信装置执行时,实现如权利要求1至20中任一项所述的方法。28. A computer-readable storage medium, wherein a computer program or instruction is stored in the storage medium, and when the computer program or instruction is executed by a communication device, any one of claims 1 to 20 can be realized. the method described.
CN202111074886.0A 2021-09-14 2021-09-14 Network element selection method, communication device and communication system Pending CN115811728A (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202111074886.0A CN115811728A (en) 2021-09-14 2021-09-14 Network element selection method, communication device and communication system
PCT/CN2022/117644 WO2023040728A1 (en) 2021-09-14 2022-09-07 Network element selection method, communication apparatus, and communication system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202111074886.0A CN115811728A (en) 2021-09-14 2021-09-14 Network element selection method, communication device and communication system

Publications (1)

Publication Number Publication Date
CN115811728A true CN115811728A (en) 2023-03-17

Family

ID=85481498

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202111074886.0A Pending CN115811728A (en) 2021-09-14 2021-09-14 Network element selection method, communication device and communication system

Country Status (2)

Country Link
CN (1) CN115811728A (en)
WO (1) WO2023040728A1 (en)

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103024738A (en) * 2011-09-26 2013-04-03 中兴通讯股份有限公司 Seaming service shunt control implementation method and system
EP3046363A1 (en) * 2015-01-16 2016-07-20 Alcatel Lucent WLAN offload from an evolved packet core network
EP3661263B1 (en) * 2017-10-20 2022-06-08 Guangdong Oppo Mobile Telecommunications Corp., Ltd. Method and device for handing over service bearer network
CN112087724A (en) * 2019-06-13 2020-12-15 华为技术有限公司 A communication method, network equipment, user equipment and access network equipment
CN112583628A (en) * 2019-09-30 2021-03-30 中兴通讯股份有限公司 Method and system for calling core network capability

Also Published As

Publication number Publication date
WO2023040728A1 (en) 2023-03-23

Similar Documents

Publication Publication Date Title
CN113228570B (en) Apparatus, method, medium for new radio core network system
US12225626B2 (en) Apparatus and method for providing subscription data to non-subscriber registered terminal in wireless communication system
CN111801961B (en) A method and device for determining SSC mode
WO2022033558A1 (en) Relay management method and communication apparatus
CN113873492B (en) Communication method and related device
US20230379806A1 (en) Method and apparatus for supporting information acquisition, device, and readable storage medium
WO2022194262A1 (en) Security communication method and apparatus
CN115942305A (en) A session establishment method and related device
CN116390203A (en) Methods and means for selecting a network
WO2023185620A1 (en) Communication method and apparatus
WO2023142887A1 (en) Communication method and communication apparatus
WO2023040728A1 (en) Network element selection method, communication apparatus, and communication system
WO2023143212A1 (en) Communication method and apparatus
KR102719952B1 (en) Apparatus and method for provisioning subscription data to non-subscription registered user equipment in wireless communication system
KR20230043969A (en) Access control method, device and communication device
WO2023082858A1 (en) Method for determining mobility management policy, communication apparatus, and communication system
WO2025059958A1 (en) A method for registration through dual radio network
WO2024222735A1 (en) Communication method and communication apparatus
WO2023246649A1 (en) Communication method, communication apparatus and communication system
WO2025081940A1 (en) Communication method, communication apparatus and communication system
WO2023197737A1 (en) Message sending method, pin management method, communication apparatus, and communication system
WO2024082880A1 (en) Communication method and apparatus
CN119922527A (en) A communication method, device and system
WO2025066815A1 (en) Communication method, apparatus and system
CN118042558A (en) Communication method, communication device and communication system

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination