百科全书
2026-07-24 15:47:28
5G核心网如何跟踪UE状态、身份与访问权限?
从注册与连接状态、UE上下文、SUPI、SUCI、5G-GUTI、寻呼标识符及移动性限制,说明5GC如何管理用户设备可达性与核心网资源。

贝克电信

5G核心网如何跟踪UE状态、身份与访问权限?

在5G网络中,移动性管理不只是跟踪手机从一个基站小区移动到另一个小区。它是一套控制逻辑,用来告诉5G核心网:UE是否已注册、是否可被寻呼、是否处于连接或空闲状态、是否获准使用服务,以及是否受到位置或签约策略限制。缺少这一层,网络就无法判断何时应保留用户上下文、何时释放信令资源、何时寻呼设备,以及在注册和安全流程中应使用哪一种身份标识。

5G核心网通过AMF、NAS信令、UE上下文、临时标识符、隐藏式签约标识符及移动性限制规则来管理设备移动。UE可能在早上开机并向网络注册,之后长时间保持空闲,需要数据服务时再恢复连接,并在一天内跨越多个跟踪区。网络必须支持这些行为,同时保护空口资源、N2信令资源和用户隐私。

显示RM已注册与未注册状态、CM空闲与连接状态,以及AMF创建UE上下文的5GC移动性管理图
5G移动性管理会综合注册状态、连接状态和UE上下文处理结果,以判断设备是否可达以及能否使用5G服务。

注册状态决定网络可达性

注册管理用于描述UE是否已向5G核心网完成注册。两个主要状态是RM-DEREGISTEREDRM-REGISTERED。在未注册状态下,UE尚未注册到核心网。AMF不知道UE所在位置,不会为其保留可用的UE上下文,也不能将该设备视为可达。

UE成功完成注册后,便会进入已注册状态。此时,UE可访问5GC服务,而AMF也获得了足够的信息,可按所需精度掌握用户位置并维护UE上下文。这并不代表UE一定正在主动传输用户数据,只表示UE与核心网之间已经建立有效关系。

状态转换十分清晰。刚开机的设备会从未注册状态开始。如果注册流程被接受,UE就会进入已注册状态。若注册被拒绝,或网络主动发起去注册,UE便会保持或返回未注册状态。这套状态模型在概念上与4G EMM的已注册和未注册逻辑相似,但由5G核心网架构负责处理。

连接状态有助于节省资源

连接管理用于说明UE当前是否与网络保持有效的信令关系。两个主要状态是CM-IDLECM-CONNECTED。在空闲状态下,UE不会通过N2信令保持主动连接,AMF也不需要维持连接运行时所需的同等主动连接资源。

在已连接状态下,AMF可以更准确地掌握UE位置,UE也能通过已建立的连接访问5GC服务。网络还可以建立或维护服务处理所需的UE上下文。当UE没有主动服务需求时,网络可以释放N2连接资源,让UE回到空闲运行状态。

这种设计能够维持网络效率。如果所有已注册UE整天都保持完全连接,无线资源、N2信令和用户面准备资源都会被浪费。更合理的做法是保留UE的注册状态,但在不需要时释放主动连接资源。当用户之后开始浏览网页、流媒体播放、通话或使用应用程序时,UE可以触发服务请求或相关流程,再次回到连接状态。

可以用酒店入住作为实际类比。注册就像办理入住并建立住客信息;连接则像实际使用客房内的灯光、空调或电梯等资源。即使暂时没有使用这些资源,住客仍保持入住状态。同样,UE可以继续保持注册,同时释放主动连接来节省资源。

UE上下文保存关键数据

UE上下文是UE完成注册后由AMF保存的信息。它为网络提供管理访问、安全、位置、签约限制和移动性行为所需的运行数据。这个上下文不是单一字段,而是由标识符、能力信息、位置信息和策略相关参数组成。

重要的UE上下文项目包括SUPIPEIGPSI、签约UE-AMBR、5GMM能力、所选PCF信息、禁止区域列表、服务区域限制和移动性管理上下文。MM上下文还可能包括接入类型、NAS安全模式、UE安全能力、允许的NSSAI、最后注册TAI、RM状态、注册区域和当前用户位置信息。

这些字段可以帮助网络回答多项运行问题:签约用户是谁?使用的是哪一种设备?涉及哪种接入类型?支持哪些安全算法?UE可以访问哪些网络切片?上次在哪里注册?哪些区域允许或受限?这些答案会影响注册处理、服务访问、寻呼、移动性更新和策略控制。

标识符可以保护用户隐私

5G移动性管理高度依赖身份标识设计。网络必须识别签约用户和设备,但应尽量避免在空口上暴露永久标识符。因此,5G会根据不同用途使用多种相互关联的标识符。

SUPI是永久签约标识符,最常见的形式是IMSI;另一种形式可在非3GPP接入中使用NAI。PEI用于识别设备,通常与IMEI或IMEISV相关。GPSI是公共签约标识符,常以MSISDN表示,也可以使用username@realm等外部标识符格式。

临时身份可以降低永久信息暴露的风险。5G-GUTI是由AMF分配、全球唯一的临时身份,由与AMF相关的标识符GUAMI和5G-TMSI组成。5G-S-TMSI是5G-GUTI的一部分,用于寻呼。这一区分十分重要,因为寻呼过程不应暴露签约用户的永久身份。

SUCI对5G安全尤其重要。它是通过加密SUPI相关信息生成的隐藏式签约标识符。在4G中,某些身份识别流程可能获取IMSI,从而在空口上造成隐私风险。在5G中,注册时如果可以使用5G-GUTI,就应优先使用;如果没有5G-GUTI,则改用SUCI。明文IMSI不应作为注册身份。

SUCI采用非对称加密生成。UE会使用存储在USIM中或设备可获取的公钥来隐藏签约身份。隐藏后的标识符会经过接入网和核心网传送至归属网络,再由私钥还原SUPI。即使部分身份信息已被隐藏,路由指示符仍可帮助核心网将信令消息路由到正确的归属网络功能。

显示SUPI、SUCI、PEI、GPSI、5G-GUTI、5G-S-TMSI和路由指示符的5GC用户身份结构,用于安全移动性管理
5G通过永久、公共、临时和隐藏式标识符的配合,使网络能够管理签约用户,同时降低敏感身份信息暴露的风险。

限制规则控制服务区域

移动性管理也包含各类限制。并非每个UE都能使用所有无线技术、所有跟踪区或所有服务区域。5G核心网会利用移动性限制规则,控制UE可以在何处以及以何种方式使用网络服务。

注册区域是分配给UE的一组跟踪区。在此范围内,服务不受限制,UE也不必因每次小幅移动而更新注册。RAT限制来自签约数据,可以阻止UE使用特定无线接入技术,例如5G。禁止区域则是该UE不得访问5G服务的一组区域。

服务区域限制可以定义允许区域和不允许区域。在允许区域内,UE可以访问5G服务;在不允许区域内,服务访问会按策略被阻止或限制。这些限制可用于签约控制、漫游控制、专网规划、服务分区和法规要求。

注册管理、连接管理、UE上下文、安全标识符和移动性限制共同构成5G核心网的移动性基础。其目的不只是知道设备位于何处,更重要的是在需要时保持设备可达、在空闲时节省网络资源、保护身份隐私,并按签约内容和所在位置执行访问规则。

常见问题

为什么5G要将注册与连接分开?

分开处理可以让核心网持续掌握UE,而不必一直保留主动信令资源。当大量设备已经注册但未持续使用服务时,这种方式可以提高整体效率。

为什么寻呼使用5G-S-TMSI?

5G-S-TMSI来源于临时身份结构,因此可以在不通过无线接口暴露永久签约信息的情况下完成寻呼。

SUCI与SUPI有什么不同?

SUPI是永久签约身份;SUCI则是隐藏形式,用于在无法使用临时身份的流程中保护该永久身份。

AMF为什么需要UE上下文?

AMF需要UE上下文来管理UE的安全、接入类型、注册状态、位置信息、允许的切片、服务限制和移动性相关决策。

移动性限制如何影响服务访问?

移动性限制会根据注册区域、禁止区域、服务区域策略和签约数据,决定UE是否可以使用特定区域或无线技术。

推荐产品
目录
客服 电话
We use cookie to improve your online experience. By continuing to browse this website, you agree to our use of cookie.

Cookies

This Cookie Policy explains how we use cookies and similar technologies when you access or use our website and related services. Please read this Policy together with our Terms and Conditions and Privacy Policy so that you understand how we collect, use, and protect information.

By continuing to access or use our Services, you acknowledge that cookies and similar technologies may be used as described in this Policy, subject to applicable law and your available choices.

Updates to This Cookie Policy

We may revise this Cookie Policy from time to time to reflect changes in legal requirements, technology, or our business practices. When we make updates, the revised version will be posted on this page and will become effective from the date of publication unless otherwise required by law.

Where required, we will provide additional notice or request your consent before applying material changes that affect your rights or choices.

What Are Cookies?

Cookies are small text files placed on your device when you visit a website or interact with certain online content. They help websites recognize your browser or device, remember your preferences, support essential functionality, and improve the overall user experience.

In this Cookie Policy, the term “cookies” also includes similar technologies such as pixels, tags, web beacons, and other tracking tools that perform comparable functions.

Why We Use Cookies

We use cookies to help our website function properly, remember user preferences, enhance website performance, understand how visitors interact with our pages, and support security, analytics, and marketing activities where permitted by law.

We use cookies to keep our website functional, secure, efficient, and more relevant to your browsing experience.

Categories of Cookies We Use

Strictly Necessary Cookies

These cookies are essential for the operation of the website and cannot be disabled in our systems where they are required to provide the service you request. They are typically set in response to actions such as setting privacy preferences, signing in, or submitting forms.

Without these cookies, certain parts of the website may not function correctly.

Functional Cookies

Functional cookies enable enhanced features and personalization, such as remembering your preferences, language settings, or previously selected options. These cookies may be set by us or by third-party providers whose services are integrated into our website.

If you disable these cookies, some services or features may not work as intended.

Performance and Analytics Cookies

These cookies help us understand how visitors use our website by collecting information such as traffic sources, page visits, navigation behavior, and general interaction patterns. In many cases, this information is aggregated and does not directly identify individual users.

We use this information to improve website performance, usability, and content relevance.

Targeting and Advertising Cookies

These cookies may be placed by our advertising or marketing partners to help deliver more relevant ads and measure the effectiveness of campaigns. They may use information about your browsing activity across different websites and services to build a profile of your interests.

These cookies generally do not store directly identifying personal information, but they may identify your browser or device.

First-Party and Third-Party Cookies

Some cookies are set directly by our website and are referred to as first-party cookies. Other cookies are set by third-party services, such as analytics providers, embedded content providers, or advertising partners, and are referred to as third-party cookies.

Third-party providers may use their own cookies in accordance with their own privacy and cookie policies.

Information Collected Through Cookies

Depending on the type of cookie used, the information collected may include browser type, device type, IP address, referring website, pages viewed, time spent on pages, clickstream behavior, and general usage patterns.

This information helps us maintain the website, improve performance, enhance security, and provide a better user experience.

Your Cookie Choices

You can control or disable cookies through your browser settings and, where available, through our cookie consent or preference management tools. Depending on your location, you may also have the right to accept or reject certain categories of cookies, especially those used for analytics, personalization, or advertising purposes.

Please note that blocking or deleting certain cookies may affect the availability, functionality, or performance of some parts of the website.

Restricting cookies may limit certain features and reduce the quality of your experience on the website.

Cookies in Mobile Applications

Where our mobile applications use cookie-like technologies, they are generally limited to those required for core functionality, security, and service delivery. Disabling these essential technologies may affect the normal operation of the application.

We do not use essential mobile application cookies to store unnecessary personal information.

How to Manage Cookies

Most web browsers allow you to manage cookies through browser settings. You can usually choose to block, delete, or receive alerts before cookies are stored. Because browser controls vary, please refer to your browser provider’s support documentation for details on how to manage cookie settings.

Contact Us

If you have any questions about this Cookie Policy or our use of cookies and similar technologies, please contact us at support@becke.cc .