Sign In to Follow Application
View All Documents & Correspondence

Core Network Device, Communication Terminal, Communication System, Authentication Method, And Communication Method

Abstract: The purpose of the present invention is to provide a core network device with which it is possible to efficiently implement secondary authentication which is performed for each network slice. A core network device (10) of the present disclosure is provided with: an authentication unit (11) which, during a registration process for registering a communication terminal in a core network, performs a first authentication process concerning whether the communication terminal is a communication terminal of which registration in the core network is permitted; a communication unit (13) which receives permission list information indicating at least one network slice that the communication terminal can utilize in a serving network; and an authentication unit (12) which, during the registration process for registering the communication terminal in the core network, implements a second authentication process concerning whether the communication terminal is a communication terminal for which utilization of a network slice included in the permission list information is permitted.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
27 March 2021
Publication Number
19/2021
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
archana@anandandanand.com
Parent Application
Patent Number
Legal Status
Grant Date
2024-07-31
Renewal Date

Applicants

NEC CORPORATION
7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Inventors

1. SUZUKI Naoaki
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001
2. TAMURA Toshiyuki
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001
3. PRASAD Anand Raghawa
c/o NEC Corporation, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Specification

Title of invention: core network device, communication terminal, communication system, authentication method, and communication method
Technical field
[0001]
 The present disclosure relates to core network devices, communication terminals, communication systems, authentication methods, and communication methods.
Background technology
[0002]
 In 5G (5 Generation) networks, it is being considered to provide services using network slices. A network slice is at least one logical network defined on a physical network. A network slice may be, for example, a network slice that provides a Public Safety Service. Further, the other network slice may be a network slice that guarantees an extremely short delay time, or may be a network slice that accommodates a large number of IoT (Internet Of Things) terminals at the same time.
[0003]
 In 5G networks, it is also envisioned that carriers will lease network slices to third parties that have their own subscriber database. In this case, in addition to the authentication of the communication terminal that accesses the PLMN (Public Land Mobile Network), the authentication of the communication terminal that accesses the network slice is being considered. The communication terminal that accesses the PLMN and the communication terminal that accesses the network slice are the same communication terminal. Authentication of the communication terminal that accesses the PLMN is referred to as, for example, primary authentication. Authentication of a communication terminal that accesses a network slice is referred to as, for example, secondary authentication. Secondary authentication also includes an authorization process for accessing a network slice, and may be paraphrased as slice-specific secondary authentication and authorization.
[0004]
 Non-Patent Document 1 describes an outline of primary authentication and secondary authentication performed on a UE (User Equipment) which is a communication terminal. Primary authentication is performed between the UE and core network devices such as AMF (Access Management Function) entity and AUSF (Authentication Server Function) entity based on the authentication information specified in 3GPP (3rd Generation Partnership Project). To. On the other hand, secondary authentication is performed between the UE and an AAA (Authentication, Authorization and Accounting) server managed by a third party based on authentication information not specified in 3GPP. The authentication information specified in 3GPP may be, for example, the authentication information used when the UE accesses the PLMN. The authentication information not specified in 3GPP may be, for example, authentication information managed by a third party. Specifically, the authentication information managed by the third party may be user IDs (User IDs) and passwords (credentials) managed by the AAA server.
[0005]
 Further, Non-Patent Document 1 describes an outline of an authentication process at the time of establishing a PDU Session, which authenticates for accessing the network slice when trying to establish a PDU Session for the first time in a specific network slice.
Prior art literature
Non-patent literature
[0006]
Non-Patent Document 1: 3GPP TS 23.740 V0.5.0 (2018-08), Section 6.3.1, Section 6.3.2
Outline of the invention
Problems to be solved by the invention
[0007]
 The UE can access multiple network slices. For example, the subscriber information of a UE includes identification information of a plurality of network slices that the UE may access. The network slice that the UE may access may be, for example, a network slice that the user operating the UE has applied for or contracted in advance.
[0008]
 If the subscriber information contains multiple network slices that the UE may access, secondary authentication is performed on a network slice-by-network slice during the UE Registration process. Therefore, as the number of network slices included in the subscriber information increases, the time and processing load required for secondary authentication increase, and the time and processing load required for the UE to execute communication using the network slice increases. There's a problem.
[0009]
 An object of the present disclosure is to provide a core network device, a communication terminal, a communication system, an authentication method, and a communication method capable of efficiently performing secondary authentication executed for each network slice.
Means to solve problems
[0010]
 The core network device according to the first aspect of the present disclosure is the first method of determining whether or not the communication terminal is a communication terminal that is permitted to be registered in the core network during the registration process for registering the communication terminal in the core network. The communication terminal is registered in the core network, the first authentication unit that executes the authentication process of the above, the communication unit that receives the permissible list information indicating at least one network slice that can be used by the communication terminal in the serving network, and the core network. During the registration process, the communication terminal includes a second authentication unit that performs a second authentication process of whether or not the communication terminal is a communication terminal that is permitted to use the network slice included in the allowable list information.
[0011]
 The communication terminal according to the second aspect of the present disclosure is a second authentication process of whether or not the communication terminal is a communication terminal permitted to use the network slice during the registration process of registering the communication terminal in the core network. It is provided with a communication unit that transmits capability information indicating whether or not the processing associated with the above can be executed to the core network device.
[0012]
 The communication system according to the third aspect of the present disclosure is the first method of determining whether or not the communication terminal is a communication terminal that is permitted to be registered in the core network during the registration process for registering the communication terminal in the core network. During the registration process of executing the authentication process and registering the communication terminal in the core network, a second authentication process of whether or not the communication terminal is permitted to use the network slice and is a communication terminal is performed, and the second authentication process is performed. The registration process is completed by receiving the information indicating the first core network device that transmits the information indicating the network slice in which the second authentication process is executed and the network slice in which the second authentication process is executed. Later, when the communication terminal first uses the network slice, it is determined whether or not the second authentication process for the communication terminal has been performed, and if the second authentication process has not been performed, It includes a second core network device that performs the second authentication process and does not perform the second authentication process when the second authentication process is performed.
[0013]
 The authentication method according to the fourth aspect of the present disclosure is the first method of determining whether or not the communication terminal is a communication terminal that is permitted to be registered in the core network during the registration process for registering the communication terminal in the core network. During the registration process of executing the authentication process, receiving the permissible list information indicating at least one network slice available to the communication terminal in the serving network, and registering the communication terminal in the core network, the communication terminal said The second authentication process of whether or not the communication terminal is permitted to use the network slice included in the permissible list information is performed.
[0014]
 The communication method according to the fifth aspect of the present disclosure is a second authentication process of whether or not the communication terminal is a communication terminal permitted to use the network slice during the registration process of registering the communication terminal in the core network. Generates capacity information indicating whether or not the processing associated with the above can be executed, and transmits the capacity information to the core network device.
Effect of the invention
[0015]
 The present disclosure can provide a core network device, a communication terminal, a communication system, an authentication method, and a communication method capable of efficiently performing secondary authentication executed for each network slice.
A brief description of the drawing
[0016]
FIG. 1 is a configuration diagram of a core network device according to a first embodiment.
FIG. 2 is a configuration diagram of a communication system according to a second embodiment.
FIG. 3 is a diagram showing a flow of Registration processing according to the second embodiment.
FIG. 4 is a configuration diagram of a communication terminal according to a third embodiment.
FIG. 5 is a diagram showing a flow of Registration processing according to the third embodiment.
FIG. 6 is a diagram showing a flow of Registration processing according to the fourth embodiment
[FIG. 7] FIG. 7 is a diagram showing a flow of authentication processing at the time of establishing a PDU Session according to the fifth embodiment.
FIG. 8 is a diagram showing a flow of authentication processing at the time of establishing a PDU Session according to the fifth embodiment.
FIG. 9 is a diagram of a communication terminal and a UE according to each embodiment.
FIG. 10 is a configuration diagram of a core network device and an AMF according to each embodiment.
Mode for carrying out the invention
[0017]
 (Embodiment 1)
 Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. A configuration example of the core network device 10 according to the first embodiment will be described with reference to FIG. The core network device 10 may be a computer device operated by the processor executing a program stored in the memory.
[0018]
 The core network device 10 has an authentication unit 11, an authentication unit 12, and a communication unit 13. The authentication unit 11, the authentication unit 12, and the communication unit 13 may be software or modules whose processing is executed by the processor executing a program stored in the memory. Alternatively, the authentication unit 11, the authentication unit 12, and the communication unit 13 may be hardware such as a circuit or a chip.
[0019]
 The authentication unit 11 executes an authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network during the registration process of registering the communication terminal in the core network. The authentication of the communication terminal performed by the authentication unit 11 corresponds to the primary authentication. The communication terminal may be, for example, a mobile phone terminal, a smartphone terminal, or a tablet terminal. Alternatively, the communication terminal may be an IoT (Internet Of Things) terminal or an MTC (Machine Type Communication) terminal. Alternatively, the communication terminal may be a UE used as a general term for communication terminals in 3GPP.
[0020]
 The core network is a network that is included in the 5G network. The 5G network includes an access network directly accessed by a communication terminal and a core network that aggregates a plurality of access networks.
[0021]
 The registration process may be executed, for example, after the communication terminal has transitioned from the power-off state to the power-on state. Alternatively, the registration process may be executed after a lapse of a predetermined period from the previous registration process. The registration process may be, for example, a Registration process whose operation is specified in 3GPP. When the communication terminal is registered in the core network, the core network manages the movement of the communication terminal, session management, and the like.
[0022]
 The communication unit 13 receives the permissible list information indicating at least one network slice available to the communication terminal in the serving network. The serving network is a network that provides communication services to the area where the communication terminal is located. The serving network may be an HPLMN (Home Public Land Mobile Network) that manages subscriber information of a communication terminal, or may be a roaming destination VPLMN (Visited PLMN).
[0023]
 All network slices that the communication terminal may access are included in the subscriber information of the communication terminal. The network slice that can be provided to the communication terminal differs for each serving network. Therefore, the communication terminal may not be able to use all the network slices included in the subscriber information in the currently connected serving network. The network slice included in the permissible list information is a network slice that can be used in the serving network among the network slices included in the subscriber information of the communication terminal. Therefore, the network slices included in the tolerated list information may be part of all the network slices included in the subscriber information.
[0024]
 The communication unit 13 may receive the permissible list information from other core network devices arranged in the HPLMN, or may receive the permissible list information from other core network devices arranged in the VPLMN. ..
[0025]
 During the registration process of registering the communication terminal in the core network, the authentication unit 12 performs an authentication process of whether or not the communication terminal is a communication terminal that is permitted to use the network slice included in the allowable list information. The authentication performed by the authentication unit 12 corresponds to the secondary authentication. When the permissible list information includes a plurality of network slices, the authentication unit 12 may perform the authentication process of the communication terminal in cooperation with each third party that manages each network slice.
[0026]
 As described above, the authentication unit 12 of the core network device 10 executes the authentication process for the number of network slices included in the permissible list information. Here, the number of network slices included in the tolerated list information is smaller than the number of network slices included in the subscriber information. Therefore, the time required for the authentication process performed by the authentication unit 12 during the registration process for registering the communication terminal in the core network is shorter than the time required for the authentication process for the number of network slices included in the subscriber information. Will be done.
[0027]
 Further, the core network device 10 implements the following authentication method. First, the core network device 10 executes a first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network during the registration process of registering the communication terminal in the core network. Next, the core network device 10 receives the permissible list information indicating at least one network slice available to the communication terminal in the serving network. Next, the core network device 10 is second whether or not the communication terminal is a communication terminal that is permitted to use the network slice included in the allowable list information during the registration process for registering the communication terminal in the core network. Perform authentication processing.
[0028]
 (Embodiment 2)
 Subsequently, a configuration example of the communication system according to the second embodiment will be described with reference to FIG. The communication system of FIG. 2 has a UE 20, a Serving PLMN 30, an HPLMN 40, and a 3rd party network 50. It is assumed that the UE 20 is located in an area where the Serving PLMN 30 provides a communication service. The UE 20 corresponds to a communication terminal. Serving PLMN30 corresponds to a serving network. In FIG. 2, the Serving PLMN 30 may be paraphrased as a VPLMN. The 3rd party network 50 may be a network managed by a telecommunications carrier that manages the Serving PLMN 30 and a telecommunications carrier that is different from the telecommunications carrier that manages the HPLMN 40. The 3rd party network 50 may be, for example, a network managed by a business operator that provides an application service.
[0029]
 The Serving PLMN30 includes an AMF (Access Management Function) entity 31 (hereinafter referred to as AMF31), a V-SMF (Visited Session Management Function) entity 32 (hereinafter referred to as V-SMF32), and an UPF (User Plane Function) entity 33. (Hereinafter referred to as UPF33). The AMF 31 corresponds to the core network device 10 of FIG.
[0030]
 The HPLMN40 is a UDM (Unified Data Management) entity 41 (hereinafter referred to as UDM41), an AUSF (Authentication Server Function) entity 42 (hereinafter referred to as AUSF42), and an NSSF (Network Slice Selection Function) entity 43 (hereinafter referred to as NSSF43). ), NEF (Network Exposure Function) entity 44 (hereinafter referred to as NEF44), H-SMF entity 45 (hereinafter referred to as H-SMF45), and UPF entity 46 (hereinafter referred to as UPF46).
[0031]
 The 3rd party network 50 has an AAA (Authentication, Authorization and Accounting) Server 51.
[0032]
 The AMF 31 manages access, mobility, and the like related to the UE 20. Further, the AMF 31 performs the primary authentication process related to the UE 20 in cooperation with the AUSF 42, the UDM 41, and the like. The V-SMF 32 manages the session related to the UE 20. Session management includes establishing, modifying, and deleting sessions. The UPF 33 routes or transfers user plane data between the UE 20 and the UPF 46.
[0033]
 The UDM 41 manages subscriber information about the UE 20. The subscriber information includes identification information of a plurality of network slices that the UE 20 may access. The network slice that the UE 20 may access may be, for example, a network slice that the user operating the UE 20 has applied for or contracted in advance.
[0034]
 The AUSF42 manages the authentication information about the UE 20. The authentication information may be, for example, a security key and an authentication algorithm for the UE 20. The NSSF 43 transmits the identification information of the network slice that can be used by the UE 20 in the Serving PLMN 30 to the AMF 31. The network slice identification information may be, for example, NSSAI (Network Slice Selection Assistance Information). Further, the AUSF 42 relays the data transmitted between the AAA Server 51 arranged in the 3rd party network 50 and the node device arranged in the HPLMN 40.
[0035]
 The NEF44 relays data transmitted between the AAA Server 51 located in the 3rd party network 50 and the node device located in the HPLMN 40. The H-SMF 45, together with the V-SMF 32, manages the session related to the UE 20. The UPF46 routes or transfers user plane data between the UPF33 and the 3rd party network 50. For example, the UPF 46 may route user plane data between the application server (not shown) located in the 3rd party network 50 and the UPF 33.
[0036]
 The V-SMF32, UPF33, H-SMF45, and UPF46 constitute the network slice 60. Each of V-SMF32, UPF33, H-SMF45, and UPF46 may be used only for the network slice 60 or may be shared with other network slices. The network slice 60 is a network slice managed by the 3rd party network 50. That is, when the UE 20 uses the service provided by the 3rd party network 50, it connects to the network slice 60.
[0037]
 The AAA Server 51 performs a secondary authentication process for the UE 20 that uses the network slice 60.
[0038]
 In the configuration example of FIG. 2, the AUSF42 and the NEF44 relay the data transmitted between the AMF31 and the AAA Server51, but they are different from the AUSF42 and the NEF44, and are different independent node devices (not shown). May be configured to relay data. Further, the communication system may be configured such that the NEF 44 is not deployed and the AUSF 42 relays the data transmitted between the AMF 31 and the AAA Server 51. The node device that relays the data transmitted between the AMF 31 and the AAA Server 51 may be AAA-F (AAA proxy function).
[0039]
 Subsequently, the flow of Registration processing for the UE 20 will be described with reference to FIG. First, the UE 20 transmits a Registration Request message to the AMF 31 (S11). Registration Request includes Requested NSSAI. The Requested NSSAI is an NSSAI provided from the UE 20 to the Serving PLMN30. In other words, the Requested NSSAI is an NSSAI that indicates the network slice that the UE 20 wants to use or connect to in the Serving PLMN30. S-NSSAI (Single Network Slice Selection Assistance Information) is identification information indicating one network slice, and NSSAI may include a plurality of S-NSSAI.
[0040]
 The AMF 31 may acquire the Requested NSSAI by a message other than the Registration Request message (S11). For example, in step S12, the AMF 31 sends a NAS Security Mode Command message to the UE 20, and the UE 20 returns a NAS Security Mode Complete message to the AMF 31 in response. In this case, the UE 20 may set the Requested NSSAI in the NAS Security Mode Complete message, and the AMF 31 may acquire the Requested NSSAI. Further, for example, before step S12, the AMF 31 may send an Identity Request message to the UE 20, and the UE 20 may return an Identity Response message to the AMF 31 as a response. In this case, the UE 20 may set the Requested NSSAI in the Identity Response message, and the AMF 31 may acquire the Requested NSSAI.
[0041]
 Further, the AMF 31 may receive a message including the Requested NSSAI from any node device other than the UE 20 to acquire the Requested NSSAI. For example, any node device may receive a message including Requested NSSAI transmitted by the UE 20. In this case, the AMF 31 may acquire the Requested NSSAI by receiving a message including the Requested NSSAI from the arbitrary node device.
[0042]
 Next, in the UE 20, AMF 31, and AUSF 42, a security procedure for accessing the existing PLMN is executed (S12). Existing PLMNs are, for example, Serving PLMN30 and HPLMN40. Specifically, in step S12, the primary authentication process for the UE 20 is performed. For example, the AMF 31 uses the authentication information received from the AUSF 42 to perform the primary authentication process for the UE 20. The authentication information received by AMF31 from AUSF42 may be referred to as, for example, 3GPP credentials. That is, the authentication information received by the AMF 31 from the AUSF 42 may be the authentication information specified in 3GPP. The 3GPP credentials may include, for example, a SUPI (Subscription Permanent Identifier) ​​which is a user ID of the UE 20, and authentication information used when the UE 20 accesses the Serving PLMN 30.
[0043]
 The primary authentication process is, for example, to authenticate SUPI in AKA (Authentication and Key Agreement) implemented between AMF31 and UE20. That is, the AMF 31 authenticates the SUPI indicating the UE 20 in the AKA performed with the UE 20. Further, the primary authentication process may include an authorization process for the UE 20. For example, the primary authentication process may include authorizing the UE 20 to use the Serving PLMN 30 using the subscriber information of the UE 20 acquired from the UDM 41. That is, the AMF 31 may authorize the UE 20 to use the Serving PLMN 30 by using the subscriber information of the UE 20 acquired from the UDM 41. The primary authentication process may be paraphrased as the primary authentication and authorization process.
[0044]
 Next, the AMF 31 sends a Nudm_SDM_Get message to the UDM 41 (S13). Next, the UDM 41 transmits a Nudm_SDM_Get response message to the AMF 31 (S14). The Nudm_SDM_Get response message contains Subscribed S (Single) -NSSAI. S-NSSAI is identification information indicating one network slice. Subscribed S-NSSAI is identification information indicating a network slice included in the subscriber information. The Nudm_SDM_Get response message may contain multiple Subscribed S-NSSAIs (Subscribed S-NSSAIs).
[0045]
 Next, the AMF 31 transmits a Nnssf_NSSelection_Get message to the NSSF43 (S15). Next, the NSSF 43 transmits a Nnssf_NSSelection_Get response message to the AMF 31 (S16). The Nnssf_NSSelection_Get response message contains Allowed NSSAI. The Allowed NSSAI includes network slice identification information (S-NSSAI) that can be used by the UE 20 in the Serving PLMN 30 among the plurality of Subscribed S-NSSAI. Allowed NSSAI may include a plurality of S-NSSAI (S-NSSAIs). Here, it is assumed that the number of S-NSSAI included in the Allowed NSSAI is smaller than the number of a plurality of Subscribed S-NSSAI included in the Nudm_SDM_Get response message. That is, the S-NSSAI included in the Allowed NSSAI is part of the multiple Subscribed S-NSSAI contained in the Nudm_SDM_Get response message. The NSSF 43 may, for example, acquire the Subscribed S-NSSAI for the UE 20 from the UDM 41 and manage the S-NSSAI indicating the network slices that the UE 20 can use in the Serving PLMN 30.
[0046]
 Next, the AMF 31 checks whether or not the secondary authentication process is applied to the network slice indicated by each S-NSSAI included in the Allowed NSSAI (S17). The AMF 31 may use a policy server or the like to check whether or not the secondary authentication process is applied to each network slice included in the Allowed NSSAI. For example, in the 3rd party network, there is also a 3rd party network that has a policy that the secondary authentication process is not applied when using the network slice managed by the 3rd party network.
[0047]
 The policy server may manage information about whether each network slice requires secondary authentication for the UE 20. In addition, information regarding whether or not to request secondary authentication for the UE 20 may be managed in a node device other than the policy server. In this case, the AMF 31 may perform the check in step S17 by using the node device in which the information regarding whether or not to request the secondary authentication regarding the UE 20 is managed.
[0048]
 For example, the AMF 31 may use the UDM 41 to perform the check in step S17. In this case, the AMF 31 may receive information regarding whether or not the secondary authentication process is applied in the network slice indicated by Subscribed S-NSSAI in the Nudm_SDM_Get response message (S14). Further, the AMF 31 may perform the check in step S17 using the received information.
[0049]
 Next, the UE 20, AMF 31, AUSF 42, and AAA Server 51 carry out a security procedure for accessing the network slice 60 to which the secondary authentication process is applied (S18). Specifically, in step S18, the secondary authentication process for the UE 20 is performed. For example, in the secondary authentication, authentication information managed by a third party may be used. The authentication information managed by the third party may include a user ID used by the UE 20 when using the network slice 60 and a password managed by the AAA Server 51.
[0050]
 In the secondary authentication process, an authentication procedure using EAP (Extensible Authentication Protocol) may be performed. For example, the AMF 31 notifies the UE 20 of S-NSSAI and sends a request message requesting transmission of the user ID and password used in S-NSSAI. Further, the AMF 31 transmits the user ID and password received from the UE 20 to the AAA Server 51 via the AUSF 42. The AAA Server 51 may authenticate the user ID related to the UE 20 received from the AUSF 42, that is, the UE 20, and further authorize the UE 20 to use the network slice 60 by using the user ID and the password received from the UE 20. The secondary authentication process may include authenticating the UE 20 and authorizing the UE 20 to use the network slice 60. Alternatively, the secondary authentication process may be paraphrased as a secondary authentication process and a secondary authorization process.
[0051]
 The secondary authentication process is performed for each network slice in the Registration process for the UE 20. In other words, among the S-NSSAI included in the Allowed NSSAI, the secondary authentication process is repeated in the Registration process as many times as the number of S-NSSAI indicating the network slice to which the secondary authentication process is applied.
[0052]
 As described above, the number of S-NSSAI contained in Allowed NSSAI is smaller than the number of Subscribed S-NSSAI transmitted from UDM41. Furthermore, among the network slices indicated by S-NSSAI included in Allowed NSSAI, there are also network slices to which the secondary authentication process is not applied. Therefore, the number of network slices to which the secondary authentication process is applied is smaller than the number of network slices indicated by S-NSSAI included in Allowed NSSAI. As a result, in the communication system of FIG. 2, the number of secondary authentication processes performed in the Registration process for the UE 20 is compared with the case where the secondary authentication process is repeated the same number of times as the number of Subscribed S-NSSAI transmitted from the UDM 41. There are few. As a result, the UE 20, AMF 31, AAA Server 51, and AAA Server 51 can shorten the time required for the secondary authentication process in the registration process as compared with the case where the secondary authentication process is repeated the same number of times as the number of Subscribed S-NSSAI. it can. Further, the UE 20, AMF 31, AUSF 42, and AAA Server 51 can reduce the processing load required for the secondary authentication process.
[0053]
 Further, the process of registering the UE 20 in the core network is performed for each access network. Therefore, the UE 20 can send a Registration Request message to the AMF 31 via the respective access networks such as 3GPP Access and Non-3GPP Access. 3GPP Access is an access network that supports the wireless communication method defined in 3GPP. Non-3GPP Access is an access network that supports a wireless communication system different from the wireless communication system defined in 3GPP.
[0054]
 The AMF 31 receives the Registration Request message from the UE 20 via either 3GPP Access or Non-3GPP Access, and performs secondary authentication. For example, it is assumed that AMF31 receives a Registration Request message via 3GPP Access and performs secondary authentication. Here, when the AMF 31 receives the Registration Request message via Non-3GPP Access, the AMF 31 may be omitted without performing the secondary authentication in the network slice that has already performed the secondary authentication for the UE 20. This makes it possible to prevent duplicate authentication for the same UE in the same network slice. As a result, the time required for the secondary authentication process in the Registration process can be shortened as compared with the case where the secondary authentication process is not omitted, and the processing load required for the secondary authentication process can be reduced. Similarly, when the secondary authentication is performed based on the Registration Request message received via Non-3GPP Access, the secondary authentication based on the Registration Request message received via 3GPP Access may be omitted.
[0055]
 Further, the AMF 31 replaces the S-NSSAI provided to the UE 20 by the Allowed N-SSAI with another S-NSSAI to the UE 20 when the secondary authentication related to the S-NSSAI of the UE 20 fails or the secondary authentication succeeds. May be provided. For example, the replaced S-NSSAI may be the default S-NSSAI. Further, the S-NSSAI after the replacement may be given an identifier indicating that it has been replaced or an identifier indicating the S-NSSAI before the replacement. The UE 20 recognizes that the access to the network slice indicated by the replacement S-NSSAI is authorized. As a result, the AMF 31 can avoid the situation where the UE 20 cannot access any of the network slices. In other words, the AMF 31 can direct a UE 20 that cannot authenticate to access a particular network slice.
[0056]
 (Embodiment 3)
 Subsequently, a configuration example of the communication terminal 70 according to the third embodiment will be described with reference to FIG. The communication terminal 70 may be a computer device operated by the processor executing a program stored in the memory. Further, as the core network device that communicates with the communication terminal 70, the core network device 10 described in the first embodiment is used.
[0057]
 The communication terminal 70 has a control unit 71 and a communication unit 72. The control unit 71 and the communication unit 72 may be software or modules whose processing is executed by the processor executing a program stored in the memory. Alternatively, the control unit 71 and the communication unit 72 may be hardware such as a circuit or a chip.
[0058]
 During the registration process of registering the communication terminal 70 in the core network, the control unit 71 can execute the process associated with the authentication process of whether or not the communication terminal 70 is a communication terminal permitted to use the network slice. Generate ability information indicating whether or not.
[0059]
 The authentication process of whether or not the communication terminal is permitted to use the network slice corresponds to the secondary authentication process. The process associated with the authentication process of whether or not the communication terminal is permitted to use the network slice includes a process in which the communication terminal 70 receives a message or the like transmitted from the core network device 10 in the secondary authentication process. Further, the process associated with the authentication process of whether or not the communication terminal is permitted to use the network slice includes a process of reading the parameters and the like set in the received message. Further, the process associated with the authentication process of whether or not the communication terminal is permitted to use the network slice includes a process of transmitting or responding to a message to the core network device 10 in order to continue the secondary authentication process normally.
[0060]
 The communication unit 72 transmits the capability information generated by the control unit 71 to the core network device 10.
[0061]
 The core network device 10 determines whether or not the capability information received from the communication terminal 70 indicates whether or not the communication terminal 70 can execute the process associated with the secondary authentication process. When the core network device 10 determines that the communication terminal 70 can execute the process associated with the secondary authentication process, the core network device 10 executes the secondary authentication process for the communication terminal 70 during the registration process for registering the communication terminal 70 in the core network. To do. If the core network device 10 does not receive the capability information from the communication terminal 70, the core network device 10 may determine that the communication terminal 70 cannot execute the process associated with the secondary authentication process.
[0062]
 For example, when the core network device 10 executes the secondary authentication process for the communication terminal that cannot perform the process associated with the secondary authentication, the core network device 10 cannot receive the information required for the secondary authentication process from the communication terminal. In other words, the core network device 10 wastes time related to the secondary authentication process even though the secondary authentication fails.
[0063]
 On the other hand, the communication terminal 70 according to the third embodiment can transmit the capability information indicating whether or not the processing associated with the secondary processing can be performed to the core network device 10. Further, for the communication terminal 70 determined that the processing associated with the secondary processing cannot be performed, the core network device 10 performs secondary authentication for the communication terminal 70 during the registration process for registering the communication terminal 70 in the core network. The process is not executed, and the secondary authentication process is regarded as successful or unsuccessful and the process is continued. As a result, the time and processing load related to the secondary authentication process can be reduced.
[0064]
 Whether the core network device 10 considers the secondary authentication process to be successful or unsuccessful for the communication terminal 70 determined to be unable to perform the process associated with the secondary process for each network slice. You may decide. For example, one S-NSSAI may be considered a success, while another S-NSSAI may be considered a failure.
[0065]
 Further, the communication terminal 70 implements the following communication method. First, the communication terminal 70 executes a process associated with the second authentication process of whether or not the communication terminal is a communication terminal permitted to use the network slice during the registration process of registering the communication terminal in the core network. Generates ability information that indicates whether or not it can be done. Next, the communication terminal 70 transmits the capability information to the core network device.
[0066]
 Subsequently, the flow of Registration processing for the UE 80 will be described with reference to FIG. The UE 80 corresponds to the communication terminal 70. First, the UE 80 transmits a Registration Request message to the AMF 31 (S21). Registration Request includes Requested NSSAI and UE capability. The UE capability corresponds to capability information indicating whether or not the UE 80 can execute the process associated with the secondary authentication process. UE capability may be represented by Security capability, or any other expression.
[0067]
 The AMF 31 may acquire the Requested NSSAI and / or UE capability by a message other than the Registration Request message (S21). For example, when the AMF 31 sends a NAS Security Mode Command message to the UE 80 in step S22, the UE 80 returns a NAS Security Mode Complete message to the AMF 31 in response. In this case, the UE 80 may set the Requested NSSAI and / or UE capability in the NAS Security Mode Complete message, and the AMF 31 may acquire the Requested NSSAI and / or the UE capability. Further, for example, when the AMF 31 sends an Identity Request message to the UE 80 before step S22, the UE 80 may return the Identity Response message to the AMF 31 as a response. In this case, the UE 80 may set the Requested NSSAI and / or UE capability in the Identity Response message, and the AMF 31 may acquire the Requested NSSAI and / or the UE capability.
[0068]
 Further, the AMF 31 may receive a message including the Requested NSSAI and / or the UE capability from any node device other than the UE 80 to acquire the Requested NSSAI and / or the UE capability. For example, any node device may receive a message including Requested NSSAI and / or UE capability transmitted by the UE 80. In this case, the AMF 31 may acquire the Requested NSSAI and / or the UE capability by receiving the message including the Requested NSSAI and / or the UE capability from any node device that has received the message.
[0069]
 Since steps S22 to S27 are the same as steps S12 to 17 in FIG. 3, detailed description thereof will be omitted.
[0070]
 Next, the AMF 31 performs the secondary authentication in step S28 when the predetermined requirement is satisfied, and does not perform the secondary authentication in the step S28 when the predetermined requirement is not satisfied. Even if it is shown that the processing associated with the secondary authentication process can be executed and the network slice requesting the connection is the network slice to which the secondary authentication is applied if the predetermined requirements are met. Good. If the prescribed requirements are not met, it has not been shown that the processing associated with the secondary authentication process can be performed, or the network slice requesting the connection is not the network slice to which the secondary authentication is applied. You may.
[0071]
 The fact that the AMF 31 does not carry out the secondary authentication may mean that the authentication procedure using EAP is not carried out. For example, the fact that the AMF 31 does not perform secondary authentication may mean that the AMF 31 does not send a request message to the UE 80 requesting the transmission of the user ID and password used in the network slice indicated by S-NSSAI.
[0072]
 Further, the fact that the AMF 31 does not perform the secondary authentication may mean that the AMF 31 returns a Registration Reject message including a specific cause code in response to the Registration Request message (S21). A particular cause code may be paraphrased as a particular 5 GMM cause value. For example, the specific cause code may mean that the AMF 31 does not perform the secondary authentication, or may mean that the AMF 31 determines that the UE 80 cannot execute the process associated with the secondary authentication process. ..
[0073]
 Further, when receiving the Registration Reject message including such a specific cause code, the UE 80 may change the S-NSSAI included in the Requested NSSAI and send the Registration Request message (S21). For example, the modified S-NSSAI may be the default S-NSSAI. Alternatively, the UE 80 may select another PLMN different from the PLMN to which the Registration Reject message was sent, change the PLMN, and send the Registration Request message (S21).
[0074]
 FIG. 5 shows, but is not limited to, in step S27, AMF31 checks whether the secondary authentication process is applied in the network slice indicated by each S-NSSAI included in the Allowed NSSAI. .. For example, the AMF 31 may check whether the secondary authentication process is applied to the network slice indicated by each of the plurality of Subscribed S-NSSAIs received in step S24.
[0075]
 As described above, the UE 80 according to the third embodiment can transmit the UE capability indicating whether or not the process associated with the secondary authentication process can be executed to the AMF 31. From this, the AMF 31 executes the secondary authentication to the UE 80 only when the UE 80 can execute the process associated with the secondary authentication process. As a result, when the UE 80 cannot execute the process associated with the secondary authentication, the time and processing load related to the secondary authentication process can be reduced.
[0076]
 (Embodiment 4)
 Subsequently, the flow of Registration processing related to the UE 90 will be described with reference to FIG. It is assumed that the UE 90 has the same configuration as the communication terminal 70 shown in FIG.
[0077]
 First, the UE 90 transmits a Registration Request message to the AMF 31 (S31). The Registration Request includes information on the preferred network slice, which is the network slice that the UE 90 accesses immediately after the registration process is completed. The preferred network slice may be paraphrased as a highly urgent network slice. The number of preferred network slices may be one or two or more. For example, when the Requested NSSAI includes a plurality of S-NSSAIs, the Requested NSSAI may include an S-NSSAI indicating a preferred network slice and an S-NSSAI indicating a network slice that is not a preferred network slice. Immediately after the completion of the registration process may be, for example, a timing after the completion of the registration process and before the elapse of a predetermined period.
[0078]
 Since steps S32 to S37 are the same as steps S22 to S27 in FIG. 5, detailed description thereof will be omitted.
[0079]
 Next, AMF 31 performs secondary authentication for network slices that meet the predetermined requirements, and does not perform secondary authentication for network slices that do not meet the predetermined requirements (S38).
[0080]
 For example, the AMF 31 performs secondary authentication in step S38 with respect to a network slice that is a preferred network slice and a network slice to which secondary authentication is applied. In this case, the AMF 31 does not perform the secondary authentication in step S38 for the network slice that is not the preferred network slice and the network slice to which the secondary authentication is applied. In other words, AMF31 does not perform secondary authentication in the Registration process for network slices that are not preferred network slices and to which secondary authentication is applied.
[0081]
 Secondary authentication for a network slice that is not a preferred network slice and a network slice to which secondary authentication is applied may be performed when the UE 90 first accesses the network slice. In other words, secondary authentication for a network slice that is not a preferred network slice and a network slice to which secondary authentication is applied may be performed when the UE 90 establishes a PDU Session with the network slice.
[0082]
 Further, as described with reference to FIG. 5, when the UE 90 transmits the UE capability to the AMF 31 together with the information of the priority network slice, the AMF 31 may perform the secondary authentication according to the following requirements. For example, the AMF 31 may perform secondary authentication on the preferred network slice and the network slice to which the secondary authentication is applied when the UE 90 can execute the process associated with the secondary authentication. That is, when the UE 90 cannot execute the process associated with the secondary authentication, the AMF 31 does not have to perform the secondary authentication related to the UE 90 in the priority network slice and the network slice to which the secondary authentication is applied.
[0083]
 As described above, the UE 90 according to the fourth embodiment can transmit the information indicating the priority network slice to the AMF 31. As a result, the AMF 31 can perform only the secondary authentication for the preferred network slice without performing the secondary authentication for all the network slices determined to be the network slices to which the secondary authentication is applied in step S37. As a result, when the AMF 31 performs only the secondary authentication for the preferred network slice as compared with the case where the secondary authentication is performed for all the network slices, the time required for the secondary authentication can be shortened, and the secondary authentication process can be performed. It is possible to reduce the processing load related to.
[0084]
 (Embodiment 5)
 Subsequently, the flow of the authentication process at the time of establishing the PDU Session according to the fifth embodiment will be described with reference to FIG. 7. FIG. 7 describes a processing flow in the communication system described with reference to FIG. If the secondary authentication process in the Registration process and the authentication process at the time of establishing the PDU Session are executed independently, the following problems occur.
[0085]
 The authentication process at the time of establishing the PDU Session is started by SMF. At this time, if the SMF does not recognize that the secondary authentication process of the UE in the specific network slice is executed in the Registration process, the secondary authentication process of the UE in the specific network slice is executed when the PDU Session is established. To do. Therefore, there arises a problem that the secondary authentication process is executed in duplicate at the time of Registration process and at the time of establishing PDU Session.
[0086]
 Therefore, in the fifth embodiment, the AMF 31 notifies the V-SMF 32 or the H-SMF 45 of the information regarding the network slice for which the secondary authentication has been executed. As a result, it is possible to prevent the secondary authentication process from being executed twice when the Registration process and the PDU Session are established.
[0087]
 First, the UE 20 transmits a NAS message including a PDU Session Establishment Request to the AMF 31 (S41). The PDU Session Establishment Request includes S-NSSAI indicating the network slice to connect to.
[0088]
 Next, the AMF 31 selects V-SMF 32 and sends an Nsmf_PDUSession_CreateSMContext Request to the V-SMF 32 (S42). Nsmf_PDUSession_UpdateSMContext Request may be sent instead of Nsmf_PDUSession_CreateSMContext Request.
[0089]
 The Nsmf_PDUSession_CreateSMContext Request includes a SUPI (Subscription Permanent Identifier) ​​of the UE 20, a flag indicating that the authentication process of the UE 20 in the network slice indicated by the S-NSSAI has been performed. The S-NSSAI is the S-NSSAI included in the message received in step S41. The AMF 31 notifies the V-SMF 32 that the secondary authentication of the UE 20 in a specific network slice has been performed by including the flag in the Nsmf_PDUSession_CreateSMContext Request.
[0090]
 Next, V-SMF32 transmits Nsmf_PDUSession_CreateSMContext Response to AMF31 as a response to Nsmf_PDUSession_CreateSMContext Request (S43).
[0091]
 Next, the V-SMF 32 transmits the Nsmf_PDUSession_CreateSMContext Request received in step S42 to the H-SMF 45 (S44). By receiving the Nsmf_PDUSession_CreateSMContext Request, the H-SMF 45 can determine whether or not the secondary authentication process of the UE 20 has been performed in the network slice indicated by the S-NSSAI.
[0092]
 Next, the H-SMF 45 acquires the subscriber data (Subscription data) corresponding to the SUPI included in the Nsmf_PDUSession_CreateSMContext Request from the UDM 41 (S45).
[0093]
 Next, when the flag is not included in the Nsmf_PDUSession_CreateSMContext Request, the H-SMF45 starts EAP Authentication in order to execute the secondary authentication process for the UE 20 (S46). On the other hand, when the flag is included in the Nsmf_PDUSession_CreateSMContext Request, the H-SMF45 determines that the authentication process for the UE 20 has been performed, and does not start the EAP Authentication in step S46.
[0094]
 Subsequently, with reference to FIG. 8, the flow of the authentication process at the time of establishing the PDU Session according to the fifth embodiment different from that of FIG. 7 will be described.
[0095]
 First, N4 Session Establishment is executed between V-SMF32 and UPF33 (S51). Next, the V-SMF 32 transmits an Authentication / Authorization Request to the AAA Server 51 via the UPF 33 (S52). Next, the AAA Server 51 transmits an Authentication / Authorization Response to the V-SMF 32 via the UPF 33 (S53). Next, the V-SMF 32 transmits a Namf_Communication_N1N2Message Transfer including an Authentication message transmitted from the AAA Server 51 to the AMF 31 (S54).
[0096]
 Next, the AMF 31 transmits a Response to the V-SMF 32 as a response to the Namf_Communication_N1N2Message Transfer (S55). The AMF 31 includes a flag in the Response indicating that the secondary authentication process of the UE 20 in the network slice to which the UE 20 should connect has been performed.
[0097]
 Next, the AMF 31 transmits the NAS SM Transport including the Authentication message to the UE 20 (S56). Next, the UE 20 transmits a NAS SM Transport including an Authentication message to the AMF 31 (S57). Next, the AMF 31 transmits an Nsmf_PDUSession_UpdateSMContext including an Authentication message to the V-SMF 32 (S58). Next, the V-SMF 32 transmits a Response to the AMF 31 (S59).
[0098]
 Here, if the V-SMF 32 has not received the flag indicating that the secondary authentication process of the UE 20 has been performed in step S55, the V-SMF 32 transmits an Authentication / Authorization Request to the AAA Server 51 via the UPF 33 (S60). ). The Authentication / Authorization Request includes an Authentication message. The AAA Server 51 transmits the Authentication / Authorization Response to the V-SMF 32 via the UPF 33 after executing the authentication process of the UE 20 in the specific network slice (S61).
[0099]
 If the V-SMF 32 receives the flag in step S55 indicating that the secondary authentication process of the UE 20 in the network slice to be connected by the UE 20 has been performed, the process after step S60 is not performed.
[0100]
 Although the process of including the flag in the Response of step S55 is described in FIG. 8, the flag may be included in the Nsmf_PDUSession_UpdateSMContext of step S58. Alternatively, the AMF 31 may transmit the flag to the V-SMF 32 or the H-SMF 45 independently of the PDU Session establishment process after executing the Registration process, not when the PDU Session is established. In this case, V-SMF32 or H-SMF45 may be omitted without performing the processing after step S52.
[0101]
 As described above, the AMF 31 can notify the V-SMF 32 or the H-SMF 45 of information regarding the secondary authentication process that has already been performed. As a result, it is possible to prevent the secondary authentication process from being performed twice when the Registration process and when the PDU Session is established. As a result, the time related to the secondary authentication can be shortened, and the processing load related to the secondary authentication process can be reduced.
[0102]
 The present disclosure is not limited to the above embodiment, and can be appropriately modified without departing from the spirit.
[0103]
 Subsequently, the configuration examples of the core network device 10, AMF31, SMF, the communication terminal 70, the UE20, the UE80, and the UE90 described in the plurality of embodiments described above will be described below.
[0104]
 FIG. 9 is a block diagram showing a configuration example of the communication terminal 70, UE 20, UE 80, and UE 90. Radio Frequency (RF) transceiver 1101 performs analog RF signal processing to communicate with the base station. The analog RF signal processing performed by the RF transceiver 1101 includes frequency up-conversion, frequency down-conversion, and amplification. The RF transceiver 1101 is coupled with the antenna 1102 and the baseband processor 1103. That is, the RF transceiver 1101 receives the modulation symbol data (or OFDM symbol data) from the baseband processor 1103, generates a transmission RF signal, and supplies the transmission RF signal to the antenna 1102. Further, the RF transceiver 1101 generates a baseband reception signal based on the reception RF signal received by the antenna 1102, and supplies the baseband reception signal to the baseband processor 1103.
[0105]
 The baseband processor 1103 performs digital baseband signal processing (data plane processing) and control plane processing for wireless communication. Digital baseband signal processing includes (a) data compression / decompression, (b) data segmentation / concatenation, and (c) transmission format (transmission frame) generation / decomposition. In addition, digital baseband signal processing includes (d) transmission path coding / decoding, (e) modulation (symbol mapping) / demodulation, and (f) OFDM symbol data by Inverse Fast Fourier Transform (IFFT) (baseband OFDM). Includes signal) generation and the like. Control plane processing, on the other hand, includes layer 1 (eg, transmit power control), layer 2 (eg, radio resource management, and hybrid automatic repeat request (HARQ) processing), and layer 3 (eg, attach, mobility, and call management). Includes communication management of).
[0106]
 For example, for LTE and 5G, digital baseband signal processing by the baseband processor 1103 may include signal processing at the Packet Data Convergence Protocol (PDCP) layer, Radio Link Control (RLC) layer, MAC layer, and PHY layer. .. Further, the control plane processing by the baseband processor 1103 may include the processing of the Non-Access Stratum (NAS) protocol, the RRC protocol, and the MAC CE.
[0107]
 The baseband processor 1103 includes a modem processor (eg, Digital Signal Processor (DSP)) that performs digital baseband signal processing, a protocol stack processor (eg, Central Processing Unit (CPU)) that performs control plane processing, or a Micro Processing Unit. (MPU)) may be included. In this case, the protocol stack processor that performs the control plane processing may be shared with the application processor 1104 described later.
[0108]
 The application processor 1104 is also referred to as a CPU, MPU, microprocessor, or processor core. The application processor 1104 may include a plurality of processors (a plurality of processor cores). The application processor 1104 realizes various functions of the communication terminals 70, UE 20, UE 80, and UE 90 by executing a system software program (Operating System (OS)) read from the memory 1106 or a memory (not shown). Alternatively, the application processor 1104 realizes various functions of the communication terminal 70, the UE 20, the UE 80, and the UE 90 by executing various application programs read from the memory 1106 or a memory (not shown). The application program may be, for example, a call application, a WEB browser, a mailer, a camera operation application, or a music playback application.
[0109]
 In some implementations, the baseband processor 1103 and the application processor 1104 may be integrated on one chip, as shown by the broken line (1105) in FIG. In other words, the baseband processor 1103 and the application processor 1104 may be implemented as one System on Chip (SoC) device 1105. SoC devices are sometimes referred to as system large scale integration (LSI) or chipsets.
[0110]
 The memory 1106 is a volatile memory, a non-volatile memory, or a combination thereof. The memory 1106 may include a plurality of physically independent memory devices. Volatile memory is, for example, Static Random Access Memory (SRAM) or Dynamic RAM (DRAM), or a combination thereof. The non-volatile memory can be a mask Read Only Memory (MROM), an Electrically Erasable Programmable ROM (EEPROM), a flash memory, or a hard disk drive, or any combination thereof. For example, memory 1106 may include external memory devices accessible from baseband processor 1103, application processor 1104, and SoC 1105. The memory 1106 may include a built-in memory device integrated in the baseband processor 1103, in the application processor 1104, or in the SoC 1105. Further, the memory 1106 may include the memory in the Universal Integrated Circuit Card (UICC).
[0111]
 The memory 1106 may store a software module (computer program) including instructions and data for processing by the communication terminals 70, UE 20, UE 80, and UE 90 described in the plurality of embodiments described above. In some implementations, the baseband processor 1103 or application processor 1104 may be configured to read the software module from memory 1106 and execute it to perform the processes described in the embodiments described above.
[0112]
 FIG. 10 is a block diagram showing a configuration example of the core network device 10, AMF31, and SMF. Referring to FIG. 10, the core network device 10, AMF31, and SMF include a network interface 1201, a processor 1202, and a memory 1203. The network interface 1201 is used to communicate with other network node devices that make up the communication system. The network interface 1201 may include, for example, an IEEE 802.3 series compliant network interface card (NIC).
[0113]
 The processor 1202 reads the software (computer program) from the memory 1203 and executes it to perform the processing of the core network devices 10, AMF 31, and SMF described with reference to the sequence diagram and the flowchart in the above-described embodiment. The processor 1202 may be, for example, a microprocessor, an MPU (Micro Processing Unit), or a CPU (Central Processing Unit). Processor 1202 may include a plurality of processors.
[0114]
 The memory 1203 is composed of a combination of a volatile memory and a non-volatile memory. Memory 1203 may include storage located away from processor 1202. In this case, processor 1202 may access memory 1203 via an I / O interface (not shown).
[0115]
 In the example of FIG. 10, memory 1203 is used to store software modules. The processor 1202 can perform the processing of the core network device 10, the AMF 31, and the SMF described in the above-described embodiment by reading these software modules from the memory 1203 and executing them.
[0116]
 As described with reference to FIG. 10, each of the processors included in the core network device 10, AMF31, and SMF is a program containing one or more instructions for causing a computer to perform the algorithm described with reference to the drawings. To execute.
[0117]
 In the above example, the program can be stored and supplied to a computer using various types of non-transitory computer readable media. Non-transitory computer-readable media include various types of tangible storage media. Examples of non-temporary computer-readable media include magnetic recording media, magneto-optical recording media (eg, magneto-optical disks), CD-ROMs (Read Only Memory), CD-Rs, CD-R / Ws, and semiconductor memories. The magnetic recording medium may be, for example, a flexible disk, a magnetic tape, or a hard disk drive. The semiconductor memory may be, for example, a mask ROM, a PROM (Programmable ROM), an EPROM (Erasable PROM), a flash ROM, or a RAM (Random Access Memory). The program may also be supplied to the computer by various types of transient computer readable media. Examples of temporary computer-readable media include electrical, optical, and electromagnetic waves. The temporary computer-readable medium can supply the program to the computer via a wired communication path such as an electric wire and an optical fiber, or a wireless communication path.
[0118]
 In the present specification, a user terminal (User Equipment, UE) (or including a mobile station, a mobile terminal, a mobile device, a wireless device, etc.) is referred to as a wireless terminal. An entity connected to a network through an interface.
[0119]
 The UE of the present specification is not limited to a dedicated communication device, and may be any device as described below having a communication function as a UE described in the present specification.
[0120]
 The terms "user equipment (UE)" (as a word used in 3GPP), "mobile station", "mobile terminal", "mobile device", and "wireless terminal" are generally synonymous with each other. It may be a stand-alone mobile station such as a terminal, a mobile phone, a smartphone, a tablet, a cellular IoT terminal, an IoT device, and the like.
[0121]
 It will be understood that the terms "UE" and "wireless terminal" also include devices that have been stationary for a long period of time.
[0122]
 UE also includes, for example, production equipment / manufacturing equipment and / or energy related machinery (for example, boilers, engines, turbines, solar panels, wind generators, hydraulic generators, thermal power generators, nuclear generators, storage batteries, nuclear systems. , Nuclear equipment, heavy electrical equipment, pumps including vacuum pumps, compressors, fans, blowers, hydraulic equipment, pneumatic equipment, metal processing machines, manipulators, robots, robot application systems, tools, molds, rolls, conveyors , Lifting equipment, cargo handling equipment, textile machinery, sewing machinery, printing machinery, printing related machinery, paperworking machinery, chemical machinery, mining machinery, mining related machinery, construction machinery, construction related machinery, agricultural machinery and / or equipment, forestry Machinery and / or equipment, fishing machinery and / or equipment, safety and / or environmental protection equipment, tractors, bearings, precision bearings, chains, gears, power transmissions, lubricators, valves, pipe joints, and / Or any device or machine application system mentioned above).
[0123]
 UE is also, for example, transportation equipment (for example, vehicles, automobiles, two-wheeled vehicles, bicycles, trains, buses, rearcars, rickshaws, ships and other watercraft, airplanes, rockets, artificial satellites, drones, balloons, etc.) It may be.
[0124]
 Further, the UE may be, for example, an information communication device (for example, a computer and related devices, a communication device and related devices, electronic components, etc.).
[0125]
 UE also includes, for example, refrigerating machines, refrigerating machine application products and equipment, commercial and service equipment, vending machines, automatic service machines, office machinery and equipment, consumer electrical and electronic machinery and equipment (for example, audio equipment and speakers). , Radio, video equipment, TV, oven range, rice cooker, coffee maker, dishwasher, washing machine, dryer, electric fan, ventilation fan and related products, vacuum cleaner, etc.).
[0126]
 Further, the UE may be, for example, an electronic application system or an electronic application device (for example, an X-ray device, a particle accelerator, a radioactive material application device, a sound wave application device, an electromagnetic application device, a power application device, etc.).
[0127]
 UEs are, for example, light bulbs, lighting, weighing machines, analytical instruments, testing machines and measuring machines (for example, smoke alarms, personal alarm sensors, motion sensors, wireless tags, etc.), watches or clocks, physics and chemistry machines. , Optical machinery, medical equipment and / or medical systems, weapons, clockwork tools, or hand tools.
[0128]
 The UE also includes, for example, a personal digital assistant or device having a wireless communication function (for example, an electronic device (for example, a personal computer, an electronic measuring instrument, etc.) configured to attach or insert a wireless card, a wireless module, or the like. )) May be.
[0129]
 The UE may also be, for example, a device or part thereof that provides the following applications, services, and solutions in the "Internet of Things (IoT)" using wired or wireless communication technology.
[0130]
 IoT devices (or things) include suitable electronic devices, software, sensors, network connections, etc. that allow devices to collect and exchange data with each other and with other communication devices.
[0131]
 Further, the IoT device may be an automated device that complies with software instructions stored in the internal memory.
[0132]
 IoT devices may also operate without the need for human supervision or response.
The IoT device may also remain inactive for a long period of time and / or for a long period of time.
[0133]
 IoT devices can also be implemented as part of a stationary device. IoT devices can be embedded in non-stationary devices (such as vehicles) or attached to animals or people that are monitored / tracked.
[0134]
 It will be appreciated that IoT technology can be implemented on any communication device that can be connected to a communication network that sends and receives data regardless of human input control or software instructions stored in memory.
[0135]
 It is understandable that IoT devices are sometimes referred to as Machine Type Communication (MTC) devices, or Machine to Machine (M2M) communication devices, NB-IoT (Narrow Band-IoT) UEs. ..
[0136]
 It will also be appreciated that UEs can support one or more IoT or MTC applications.
[0137]
 Some examples of MTC applications are listed in the table below (Source: 3GPP TS22.368 V13.2.0 (2017-01-13) Annex B, the contents of which are incorporated herein by reference). This list is not exhaustive and shows an example MTC application.

[0138]
 Applications, services, and solutions include, for example, MVNO (Mobile Virtual Network Operator) services / systems, disaster prevention wireless services / systems, and premises wireless telephone (PBX (Private Branch eXchange)) services / System, PHS / Digital Cordless Telephone Service / System, POS (Point of sale) System, Advertising Service / System, Multimedia Broadcast and Multicast Service (MBMS) Service / System, V2X (Vehicle to Everything: Vehicle-to-Vehicle Communication and Road-to-vehicle / pedestrian communication) services / systems, in-train mobile wireless services / systems, location information-related services / systems, disaster / emergency wireless communication services / systems, IoT (Internet of Things) services / systems, Community service / system, video distribution service / system, Femto cell application service / system, VoLTE (Voice over LTE) service / system, wireless TAG service / system, billing service / system, radio on-demand service / system, roaming service / system , User behavior monitoring service / system, Communication carrier / Communication NW selection service / system, Function restriction service / system, PoC (Proof of Concept) service / system, Personal information management service / system for terminals, Display / video service for terminals / It may be a system, a non-communication service / system for terminals, an ad hoc NW / DTN (Delay Tolerant Networking) service / system, or the like.
[0139]
 The UE category described above is merely an application example of the technical idea and the embodiment described in the present specification. Of course, those skilled in the art can make various changes without being limited to these examples.
[0140]
 Although the invention of the present application has been described above with reference to the embodiments, the invention of the present application is not limited to the above. Various changes that can be understood by those skilled in the art can be made within the scope of the invention in the configuration and details of the invention of the present application.
[0141]
 This application claims priority on the basis of Japanese application Japanese Patent Application No. 2018-185420 filed on September 28, 2018, the entire disclosure of which is incorporated herein by reference.
[0142]
 Some or all of the above embodiments may also be described, but not limited to:
 (Appendix 1)
 During the registration process of registering a communication terminal in the core network, the first authentication of executing the first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network is executed.  During the registration process of registering the communication terminal in the core network, the communication terminal
 receives the permissible list information indicating at least one network slice available to the communication terminal in the serving network.
A core network device including a second authentication means for performing a second authentication process of whether or not the communication terminal is permitted to use the network slice included in the allow list information.
 (Appendix 2)
 When the
 allowable list information includes a plurality of the network slices, the second authentication means determines whether or not the second authentication process is required to be performed in each network slice. The core network device according to Appendix 1, wherein the second authentication process is performed for each network slice for which the second authentication process is required to be performed.
 (Supplementary Note 3) The  description in Appendix 1 or 2,
 wherein the communication means
transmits the identification information of the communication terminal used by the communication terminal when using the network slice to the authentication server associated with the network slice. Core network device.
 (Appendix 4)

 The core network device according to Appendix 3,  wherein the communication means acquires identification information of the communication terminal from the communication terminal for each network slice included in the permissible list information.
 (Appendix 5)
 The second authentication means is
 described when the second authentication process is performed during the registration process in which the communication terminal registers the communication terminal in the core network via the first access network. The core network according to any one of Appendix 1 to 4, wherein the second authentication process is omitted during the registration process in which the communication terminal registers the communication terminal in the core network via the second access network. apparatus.
 (Appendix 6)
 When the second authentication means
 determines that the communication terminal is not a communication terminal permitted to use the network slice included in the permissible list information, the predetermined network slice identification information The core network device according to any one of Appendix 1 to 5, which notifies the communication terminal of the above.
 (Appendix 7)
 Registering a communication terminal in the core network During the registration process, a Registration Request message including information indicating whether or not the communication terminal supports Slice-Specific Authentication and Authorization is received from the communication terminal. Communication means and
 A core network device comprising an authentication means that performs processing related to the Slice-Specific Authentication and Authorization when the information indicates that the communication terminal supports Slice-Specific Authentication and Authorization.
 (Appendix 8) If the  information
 indicates that the
communication terminal does not support Slice-Specific Authentication and Authorization , the authentication means does not execute the process related to Slice-Specific Authentication and Authorization. 7. The core network device according to 7.
 (Appendix 9)
 When the
 authentication means does not execute the process related to the Slice-Specific Authentication and Authorization , the communication means transmits a Registration Reject message including a specific cause code for the Registration Request message to the communication terminal. The core network device according to Appendix 7 or 8.
 (Appendix 10) A
 communication terminal including a communication means for transmitting a Registration Request message including information indicating whether or not the communication terminal supports Slice-Specific Authentication and Authorization to a core network device.
 (Appendix 11) If the
 communication terminal does not support the Slice-Specific Authentication and Authorization, the core network device that has received the Registration Request message does not execute the process related to the Slice-Specific Authentication and Authorization. Described communication terminal.
 (Appendix 12)
 When the
 core network device does not execute the process related to the Slice-Specific Authentication and Authorization , the communication means receives a Registration Reject message including a specific cause code for the Registration Request message from the core network device. The communication terminal according to Appendix 10 or 11.
 (Appendix 13)
 During the registration process of registering a communication terminal in the core network, the first authentication of executing the first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network is executed. Means,
 a communication means for receiving information on a plurality of network slices requested to be used from the communication terminal, and information on a network slice to be preferentially used among the plurality of network slices.
 During the registration process of registering the communication terminal in the core network, a second authentication process of whether or not the communication terminal is permitted to use the network slice preferentially used by the communication terminal is performed. Authentication means and a core network device.
 (Appendix 14)
 The second authentication means performs the second authentication
 when the communication terminal first uses the network slice on which the second authentication process has not been performed after the registration process is completed. The core network device according to Appendix 13, wherein the process is performed.
 (Appendix 15)
 During the registration process for registering a communication terminal in the core network, information on a plurality of network slices requested to be used and information on a network slice to be preferentially used among the plurality of network slices are provided in the core network. A communication terminal including a communication means for transmitting to a device.
 (Supplementary note 16) The
 communication means transmits the
 Registration Request message including information on the network slice to be preferentially used and information on a network slice different from the network slice to be preferentially used. The communication terminal described in.
 (Appendix 17)
 During the registration process of registering the communication terminal in the core network, the first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network is executed, and the communication terminal is registered in the core network. Information indicating the network slice in which the communication terminal is permitted to use the network slice and the second authentication process is performed to determine whether or not the communication terminal is a communication terminal, and the second authentication process is performed during the registration process. The
 communication terminal first uses the network slice after receiving the information indicating the first core network device and the network slice on which the second authentication process has been executed and the registration process is completed. At that time, it is determined whether or not the second authentication process for the communication terminal has been performed, and if the second authentication process has not been performed, the second authentication process is performed and the second authentication process is performed. A communication system including a second core network device that does not perform the second authentication process when the authentication process of the above is performed.
 (Supplementary Note 18)  The communication system according to Supplementary Note 17,
 wherein the first core network device
transmits information indicating a network slice in which the second authentication process has been performed during the PDU Session establishment process.
 (Appendix 19)
 During the registration process of registering a communication terminal in the core network, the first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network is executed, and in the
 serving network. Receiving acceptable list information indicating at least one network slice available to the communication terminal,
 During the registration process of registering the communication terminal in the core network, a second authentication process of whether or not the communication terminal is a communication terminal permitted to use the network slice included in the permissible list information is performed. Authentication method for core network devices.
 (Appendix 20)
 During the registration process of registering a communication terminal in the core network, it is possible to execute a process associated with the second authentication process of whether or not the communication terminal is a communication terminal permitted to use the network slice.
 A communication method in a communication terminal that generates capability information indicating whether or not the capability information is generated and transmits the capability information to a core network device.
Code description
[0143]
 10 core network device
 11 authenticating unit
 12 authenticating unit
 13 communication unit
 20 UE
 30 Serving PLMN
 31 AMF
 32
 V-SMF
 33 UPF
 40 HPLMN
 41 UDM
 42 Ausf
 43 NSSF
 44 NEF
 45 H-SMF 46
 UPF 50 3rd: party network
 51 AAA Server
 60 Network slice
 70 Communication terminal
 71 Control unit
 72 Communication unit
 80 UE
 90 UE
The scope of the claims
[Claim 1]
 During the registration process of registering a communication terminal in the core network, a first authentication means for executing the first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network, and
 serving.
 During the registration process of registering the communication terminal in the core network and the communication means for receiving the permissible list information indicating at least one network slice available to the communication terminal in the network, the communication terminal is added to the permissible list information. A core network device including a second authentication means for performing a second authentication process of whether or not the communication terminal is permitted to use the included network slice.
[Claim 2]
 When the
 allowable list information includes a plurality of the network slices, the second authentication means determines whether or not each network slice is required to perform the second authentication process, and determines whether or not the second authentication process is required. The core network device according to claim 1, wherein the second authentication process is performed for each network slice for which the authentication process of the above is required.
[Claim 3]

 The core network device according to claim 1 or 2,  wherein the communication means transmits identification information of the communication terminal used by the communication terminal when using the network slice to an authentication server associated with the network slice. ..
[Claim 4]

 The core network device according to claim 3,  wherein the communication means acquires identification information of the communication terminal from the communication terminal for each network slice included in the permissible list information.
[Claim 5]
 In the second authentication means, when the
 communication terminal performs the second authentication process during the registration process of registering the communication terminal in the core network via the first access network, the communication terminal is second. The core network device according to any one of claims 1 to 4, wherein the second authentication process is omitted during the registration process of registering the communication terminal in the core network via the access network of 2.
[Claim 6]
 When the second authentication means
 determines that the communication terminal is not a communication terminal that is permitted to use the network slice included in the permissible list information, the communication terminal uses predetermined network slice identification information. The core network device according to any one of claims 1 to 5, which is notified to.
[Claim 7]
 Registering a communication terminal in the core network During the registration process, a communication means that receives a Registration Request message from the communication terminal that includes information indicating whether or not the communication terminal supports Slice-Specific Authentication and Authorization.
 A core network device comprising an authentication means that performs processing related to the Slice-Specific Authentication and Authorization when the information indicates that the communication terminal supports Slice-Specific Authentication and Authorization.
[Claim 8]
 The authentication means according to claim 7,
 wherein when the information indicates that the communication terminal does not support Slice-Specific Authentication and Authorization , the authentication means does not execute the process related to the Slice-Specific Authentication and Authorization. Core network equipment.
[Claim 9]
 The communication means
 transmits a Registration Reject message including a specific cause code for the Registration Request message to the communication terminal when the authentication means does not execute the process related to the Slice-Specific Authentication and Authorization. 8. The core network device according to 8.
[Claim 10]
 A communication terminal comprising a communication means for transmitting a Registration Request message including information indicating whether or not the communication terminal supports Slice-Specific Authentication and Authorization to a core network device.
[Claim 11]
 The communication according to claim 10, wherein when the communication terminal does not support the Slice-Specific Authentication and Authorization, the core network device that has received the Registration Request message does not execute the process related to the Slice-Specific Authentication and Authorization. Terminal.
[Claim 12]
 Claim that the communication means
 receives a Registration Reject message including a specific cause code for the Registration Request message from the core network device when the core network device does not execute the process related to the Slice-Specific Authentication and Authorization. The communication terminal according to 10 or 11.
[Claim 13]
 During the registration process of registering a communication terminal in the core network, the first authentication means for executing the first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network, and the
 above-mentioned A communication means for receiving information on a plurality of network slices requested to be used and information on a network slice to be preferentially used among the plurality of network slices from a
 communication terminal, and registering the communication terminal in the core network. A core network including a second authentication means for performing a second authentication process of whether or not the communication terminal is permitted to use the network slice preferentially used by the communication terminal during the registration process. apparatus.
[Claim 14]
 The second authentication means performs
 the second authentication process when the communication terminal first uses the network slice on which the second authentication process has not been performed after the registration process is completed. The core network device according to claim 13.
[Claim 15]
 During the registration process of registering a communication terminal in the core network, information about a plurality of network slices requested to be used and information about a network slice to be preferentially used among the plurality of network slices are transmitted to the core network device. A communication terminal provided with a communication means.
[Claim 16]
 15. The communication means according
 to claim 15, wherein the registration request message includes information about the preferentially used network slice and information about a network slice different from the preferentially used network slice. Communication terminal.
[Claim 17]
 During the registration process of registering the communication terminal in the core network, the first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network is executed, and the communication terminal is registered in the core network. Information indicating the network slice in which the communication terminal is permitted to use the network slice and the second authentication process is performed to determine whether or not the communication terminal is a communication terminal, and the second authentication process is performed during the registration process. The
 communication terminal first uses the network slice after receiving the information indicating the first core network device and the network slice on which the second authentication process has been executed and the registration process is completed. At that time, it is determined whether or not the second authentication process for the communication terminal has been performed, and if the second authentication process has not been performed, the second authentication process is performed and the second authentication process is performed. A communication system including a second core network device that does not perform the second authentication process when the authentication process of the above is performed.
[Claim 18]

 The communication system according to claim 17,  wherein the first core network device transmits information indicating a network slice in which the second authentication process has been performed during the PDU Session establishment process.
[Claim 19]
 During the registration process of registering a communication terminal in the core network, the first authentication process of whether or not the communication terminal is a communication terminal permitted to be registered in the core network is executed, and the
 communication terminal is executed in the serving network.
 During the registration process of receiving the permissible list information indicating at least one available network slice and registering the communication terminal in the core network, the communication terminal is permitted to use the network slice included in the permissible list information. An authentication method in a core network device that performs a second authentication process of whether or not the terminal is a communication terminal.
[Claim 20]
 During the registration process of registering a communication terminal in the core network, whether or not the process associated with the second authentication process of whether or not the communication terminal is a communication terminal permitted to use the network slice can be executed.
 A communication method in a communication terminal that generates the ability information to be shown and transmits the ability information to a core network device.

Documents

Application Documents

# Name Date
1 202117013710-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [27-03-2021(online)].pdf 2021-03-27
2 202117013710-STATEMENT OF UNDERTAKING (FORM 3) [27-03-2021(online)].pdf 2021-03-27
3 202117013710-REQUEST FOR EXAMINATION (FORM-18) [27-03-2021(online)].pdf 2021-03-27
4 202117013710-PRIORITY DOCUMENTS [27-03-2021(online)].pdf 2021-03-27
5 202117013710-POWER OF AUTHORITY [27-03-2021(online)].pdf 2021-03-27
6 202117013710-NOTIFICATION OF INT. APPLN. NO. & FILING DATE (PCT-RO-105) [27-03-2021(online)].pdf 2021-03-27
7 202117013710-FORM 18 [27-03-2021(online)].pdf 2021-03-27
8 202117013710-FORM 1 [27-03-2021(online)].pdf 2021-03-27
9 202117013710-DRAWINGS [27-03-2021(online)].pdf 2021-03-27
10 202117013710-DECLARATION OF INVENTORSHIP (FORM 5) [27-03-2021(online)].pdf 2021-03-27
11 202117013710-COMPLETE SPECIFICATION [27-03-2021(online)].pdf 2021-03-27
12 202117013710-CLAIMS UNDER RULE 1 (PROVISIO) OF RULE 20 [27-03-2021(online)].pdf 2021-03-27
13 202117013710-MARKED COPIES OF AMENDEMENTS [07-04-2021(online)].pdf 2021-04-07
14 202117013710-FORM 13 [07-04-2021(online)].pdf 2021-04-07
15 202117013710-AMMENDED DOCUMENTS [07-04-2021(online)].pdf 2021-04-07
16 202117013710-FORM 3 [20-09-2021(online)].pdf 2021-09-20
17 202117013710.pdf 2021-10-19
18 202117013710-FER.pdf 2022-02-09
19 202117013710-certified copy of translation [07-04-2022(online)].pdf 2022-04-07
20 202117013710-Others-200422.pdf 2022-04-22
21 202117013710-Correspondence-200422.pdf 2022-04-22
22 202117013710-Proof of Right [03-08-2022(online)].pdf 2022-08-03
23 202117013710-PETITION UNDER RULE 137 [03-08-2022(online)].pdf 2022-08-03
24 202117013710-Information under section 8(2) [03-08-2022(online)].pdf 2022-08-03
25 202117013710-FORM 3 [03-08-2022(online)].pdf 2022-08-03
26 202117013710-FER_SER_REPLY [06-08-2022(online)].pdf 2022-08-06
27 202117013710-COMPLETE SPECIFICATION [06-08-2022(online)].pdf 2022-08-06
28 202117013710-CLAIMS [06-08-2022(online)].pdf 2022-08-06
29 202117013710-ABSTRACT [06-08-2022(online)].pdf 2022-08-06
30 202117013710-US(14)-HearingNotice-(HearingDate-01-03-2024).pdf 2024-01-29
31 202117013710-US(14)-ExtendedHearingNotice-(HearingDate-10-04-2024).pdf 2024-02-26
32 202117013710-REQUEST FOR ADJOURNMENT OF HEARING UNDER RULE 129A [26-02-2024(online)].pdf 2024-02-26
33 202117013710-Correspondence to notify the Controller [05-04-2024(online)].pdf 2024-04-05
34 202117013710-Response to office action [09-04-2024(online)].pdf 2024-04-09
35 202117013710-FORM-26 [10-04-2024(online)].pdf 2024-04-10
36 202117013710-Written submissions and relevant documents [24-04-2024(online)].pdf 2024-04-24
37 202117013710-PatentCertificate31-07-2024.pdf 2024-07-31
38 202117013710-IntimationOfGrant31-07-2024.pdf 2024-07-31
39 202117013710-MARKED COPIES OF AMENDEMENTS [27-02-2025(online)].pdf 2025-02-27
40 202117013710-FORM 13 [27-02-2025(online)].pdf 2025-02-27
41 202117013710-AMENDED DOCUMENTS [27-02-2025(online)].pdf 2025-02-27

Search Strategy

1 Search_Strategy_202117013710E_03-02-2022.pdf

ERegister / Renewals

3rd: 17 Oct 2024

From 25/09/2021 - To 25/09/2022

4th: 17 Oct 2024

From 25/09/2022 - To 25/09/2023

5th: 17 Oct 2024

From 25/09/2023 - To 25/09/2024

6th: 17 Oct 2024

From 25/09/2024 - To 25/09/2025

7th: 22 Sep 2025

From 25/09/2025 - To 25/09/2026