Method of accessing a network, communication system and communication device
By receiving and processing access type information through the mobile management network element, the problem of user equipment being unable to distinguish access types is solved, access control of terminal devices is implemented, and access is ensured to comply with network policies.
Patent Information
- Application Number
- CN202010756365.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-31
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2040-07-31
AI Technical Summary
In the prior art, user equipment cannot distinguish between direct access and indirect access through non-3GPP access, resulting in the network being unable to effectively perform access control.
The access type information of the terminal device is received through the mobility management network element, its access type is determined, and control is performed according to the access type, including sending a registration rejection message to prohibit unallowed access types.
It achieves effective access control of terminal devices, ensures that the access type complies with network policies, and avoids illegal or unauthorized access.
Smart Images

Figure CN114071639B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communications, and more particularly, to a method of accessing a network, a communication system and a communication device. BACKGROUND
[0002] The fifth generation (5G) network defined by the third generation partnership project (3GPP) supports multiple access types. A terminal device supporting multiple access types can select one of the access types to access a 5G core (5GCN) according to a configuration, or can select multiple access types to access the 5GCN simultaneously. An operator can perform access control for different access types based on its own network configuration and user subscription permission, allowing a terminal device to access from a specific access type and rejecting the terminal device to access from other access types.
[0003] 3GPP supports the deployment of non-public networks (NPN). NPN is also known as a private network, which is different from the traditional cellular network. NPN allows certain terminal devices with specific permissions to access. A standalone NPN (SNPN) is referred to as an independently deployed NPN. Currently, the access types supported by the 5GCN of the SNPN include: 3GPP access and access to the SNPN through a public land mobile network (PLMN), the former being direct access and the latter being indirect access. In addition, the SNPN can also support non-3GPP access for direct access.
[0004] Because of the introduction of SNPN, the access types supported by the 5GCN of the PLMN include: 3GPP access, access through SNPN, and non-3GPP access.
[0005] When a user equipment (UE) requests registration, the 5GCN needs to identify the access type currently used by the UE to perform access control on the UE. However, in the prior art, the UE and the 5GCN can distinguish between direct 3GPP access and direct non-3GPP access. However, it cannot distinguish between two access types through non-3GPP access: direct access through non-3GPP access and indirect access through SNPN access or through PLMN access SNPN. SUMMARY
[0006] The application provides a network access method, a communication system and a communication device, so that a mobile management network element in a first network can learn an access type of a terminal device accessing the first network, thereby enabling access control of the terminal device.
[0007] In a first aspect, a network access method is provided, comprising: a mobile management network element in a first network receiving access type information of a terminal device, the access type information indicating an access type of the terminal device accessing the first network; and the mobile management network element performing access control of the terminal device according to the access type information.
[0008] Optionally, the access type is accessing the first network through a second network, wherein the first network is a non-public network and the second network is a public network; or the first network is a public network and the second network is a non-public network.
[0009] For example, the public network is a PLMN and the non-public network is a SNPN.
[0010] Optionally, the access type is non-3GPP (non-3GPP) access.
[0011] According to the network access method provided by the application, the mobile management network element can learn the access type of the terminal device accessing the first network according to the access type information, thereby enabling access control of the terminal device. For example, if the first network is a SNPN, the mobile management network element can determine whether the terminal device accesses the SNPN directly through non-3GPP access or indirectly through a PLMN according to the access type information, thereby enabling access control of the corresponding type of access. For another example, if the first network is a PLMN, the mobile management network element can determine whether the terminal device accesses the PLMN directly through non-3GPP or indirectly through a SNPN according to the access type information, thereby enabling access control of the corresponding type of access.
[0012] In combination with the first aspect, in a possible implementation manner of the first aspect, the mobile management network element in the first network receiving the access type information of the terminal device comprises: the mobile management network element receiving a registration request message from the terminal device, the registration request message comprising the access type information.
[0013] Based on this scheme, the mobile management network element can determine the access type of the terminal device accessing the first network according to the access type information in the registration request message of the terminal device.
[0014] With reference to the first aspect, in a possible implementation form of the first aspect, the mobile management network element receives the access type information of the terminal device, including: the mobile management network element receives an N2 interface message from the interworking network element in the first network, and the N2 interface message includes the access type information.
[0015] Based on the scheme, the mobile management network element can determine the access type of the terminal device accessing the first network according to the access type information in the N2 interface message of the interworking network element in the first network.
[0016] With reference to the first aspect, in a possible implementation form of the first aspect, the mobile management network element performs access control on the terminal device according to the access type information, including: in a case where the terminal device is not allowed to access the first network through the second network, the mobile management network element sends a registration rejection message to the terminal device, and the registration rejection message includes a cause value, and the cause value is used to indicate that the terminal device is not allowed to access the first network through the second network.
[0017] Based on the scheme, after the terminal device receives the cause value, it can know that it cannot access the first network through the second network, and therefore it will not initiate a registration request to the first network through the user plane of the registered second network in the future, for example, the terminal device can disable the capability of accessing the first network through the second network.
[0018] With reference to the first aspect, in a possible implementation form of the first aspect, the mobile management network element performs access control on the terminal device according to the access type information, including: in a case where the terminal device is not allowed to access the first network through the non-3GPP access, the mobile management network element sends a registration rejection message to the terminal device, and the registration rejection message includes a cause value, and the cause value is used to indicate that the terminal device is not allowed to access the first network through the non-3GPP access.
[0019] Based on the scheme, after the terminal device receives the cause value, it can know that it cannot access the first network through the non-3GPP access, and therefore it will not initiate a registration request to the first network through the non-3GPP access in the future, for example, the terminal device can disable the capability of accessing the first network through the non-3GPP access.
[0020] In a second aspect, a method for accessing a network is provided, comprising: sending, by a terminal device, access type information of the terminal device to a mobility management network element in a first network, the access type information indicating an access type of the terminal device accessing the first network; and receiving, by the terminal device, a registration reject message from the mobility management network element, the registration reject message including a cause value indicating that the terminal device is not allowed to access the first network through the access type indicated by the access type information.
[0021] Optionally, the access type is accessing the first network through a second network, where the first network is a non-public network and the second network is a public network, or the first network is a public network and the second network is a non-public network.
[0022] For example, the public network is a PLMN and the non-public network is a SNPN.
[0023] Optionally, the access type is non-3rd Generation Partnership Project (non-3GPP) access.
[0024] According to the method for accessing a network provided in the present application, the mobility management network element can learn the access type of the terminal device accessing the first network according to the access type information provided by the terminal device, so as to perform access control on the terminal device. For example, if the first network is a SNPN, the mobility management network element can determine whether the terminal device accesses the SNPN directly through non-3GPP access or accesses the SNPN indirectly through a PLMN according to the access type information, so as to perform access control on the corresponding type of access, such as rejecting the terminal device from accessing the first network through the access type indicated by the access type information.
[0025] With reference to the second aspect, in some implementations of the second aspect, the terminal device sends the access type information to the mobility management network element, comprising: the terminal device sends a registration request message to the mobility management network element through the second network, the registration request message including the access type information.
[0026] Based on this scheme, the mobility management network element can determine that the access type of the terminal device accessing the first network is accessing the first network through the second network according to the access type information in the registration request message of the terminal device.
[0027] With reference to the second aspect, in some implementations of the second aspect, the terminal device sends the access type information to the mobility management network element, comprising: the terminal device sends a registration request message to the mobility management network element through the non-3GPP access, the registration request message including the access type information.
[0028] Based on the scheme, the mobile management network element can determine, according to access type information in the registration request message of the terminal device, that the access type of the terminal device accessing the first network is accessing the first network through non-3GPP access.
[0029] In a third aspect, a method for accessing a network is provided, including: receiving, by an interworking network element in a first network, a non-access stratum (NAS) message from a terminal device; determining, by the interworking network element, an access type of the terminal device accessing the first network corresponding to the NAS message; and sending, by the interworking network element, access type information to a mobile management network element in the first network, the access type information being used to indicate the access type.
[0030] Based on the scheme, the interworking network element in the first network can determine the access type of the terminal device accessing the first network according to the NAS message of the terminal device, and can send the access type to the mobile management network element, so that the mobile management network element can determine the access type of the terminal device accessing the first network. Further, the mobile management network element can perform access control on the terminal device according to the access type.
[0031] With reference to the third aspect, in some implementations of the third aspect, determining, by the interworking network element, the access type of the terminal device accessing the first network corresponding to the NAS message includes: if the NAS message is from a user plane of a second network, determining, by the interworking network element, that the access type is accessing the first network through the second network, wherein the first network is a non-public network, and the second network is a public network; or the first network is a public network, and the second network is a non-public network.
[0032] With reference to the third aspect, in some implementations of the third aspect, determining, by the interworking network element, the access type of the terminal device accessing the first network corresponding to the NAS message includes: if the NAS message is from a signaling connection between the terminal device and the interworking network element, determining, by the interworking network element, that the access type is non-3GPP access.
[0033] Based on the above scheme, the interworking network element can determine the access type of the terminal device accessing the first network according to whether the NAS message of the terminal device is from a user plane or a signaling connection.
[0034] With reference to the third aspect, in some implementations of the third aspect, the NAS message is a registration request message.
[0035] In a fourth aspect, a communication system is provided, comprising: a mobile management network element in a first network and a terminal device; the terminal device is configured to send access type information to the mobile management network element, the access type information indicating an access type of the terminal device accessing the first network; and the mobile management network element is configured to receive the access type information from the terminal device, and perform access control on the terminal device according to the access type information.
[0036] According to the communication system provided in the present application, the mobile management network element in the first network can learn the access type of the terminal device accessing the first network according to the access type information provided by the terminal device, so as to perform access control on the terminal device. For example, if the first network is an SNPN, the mobile management network element can determine whether the terminal device accesses the SNPN through a non-3GPP access or accesses the SNPN through a PLMN according to the access type information, so as to perform access control on the corresponding type of access.
[0037] With reference to the fourth aspect, in some implementations of the fourth aspect, the performing access control on the terminal device according to the access type information comprises: sending a registration rejection message to the terminal device, the registration rejection message comprising a cause value, the cause value being used to indicate that the terminal device is not allowed to access the first network through the access type.
[0038] With reference to the fourth aspect, in some implementations of the fourth aspect, the access type is an access to the first network through a second network, wherein the first network is a non-public network and the second network is a public network, or the first network is a public network and the second network is a non-public network.
[0039] With reference to the fourth aspect, in some implementations of the fourth aspect, the access type is a non-third generation mobile partner plan (3GPP) access.
[0040] In a fifth aspect, a communication system is provided, comprising: a mobile management network element in a first network and an interworking network element in the first network; the interworking network element is configured to send access type information to the mobile management network element, the access type information indicating an access type of the terminal device accessing the first network; and the mobile management network element is configured to receive the access type information from the interworking network element, and perform access control on the terminal device according to the access type information.
[0041] According to the communication system provided in the present application, the mobile management network element in the first network can learn the access type of the terminal device accessing the first network according to the access type information provided by the interworking network element, so as to perform access control on the terminal device. For example, if the first network is an SNPN, the mobile management network element can determine whether the terminal device accesses the SNPN through a non-3GPP access or accesses the SNPN through a PLMN according to the access type information, so as to perform access control on the corresponding type of access.
[0042] With reference to the fifth aspect, in some implementations of the fifth aspect, the interworking network element is further configured to: receive a non-access stratum (NAS) message from the terminal device; and determine the access type of the terminal device corresponding to the NAS message.
[0043] With reference to the fifth aspect, in some implementations of the fifth aspect, the performing access control on the terminal device according to the access type information comprises: sending a registration rejection message to the terminal device, wherein the registration rejection message comprises a cause value, and the cause value is used to indicate that the terminal device is not allowed to access the first network through the access type.
[0044] With reference to the fifth aspect, in some implementations of the fifth aspect, the access type is an access to the first network through a second network, wherein the first network is a non-public network, and the second network is a public network; or the first network is a public network, and the second network is a non-public network.
[0045] With reference to the fifth aspect, in some implementations of the fifth aspect, the access type is a non-third generation partnership project (3GPP) access.
[0046] The sixth aspect provides a communication apparatus, comprising various modules or units for performing the method in the first aspect to the third aspect or any possible implementation manner of the first aspect to the third aspect.
[0047] The seventh aspect provides an apparatus comprising a processor. The processor is coupled with a memory and is configured to execute instructions in the memory to cause the apparatus to perform the method in the first aspect to the third aspect or any possible implementation manner of the first aspect to the third aspect. Optionally, the apparatus further comprises the memory. Optionally, the apparatus further comprises an interface circuit, and the processor is coupled with the interface circuit.
[0048] The eighth aspect provides a processor comprising an input circuit, an output circuit and a processing circuit. The processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor performs the method in the first aspect to the third aspect or any possible implementation manner of the first aspect to the third aspect.
[0049] In the implementation process, the processor can be a chip, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be a transistor, a gate circuit, a flip-flop, and various logic circuits. The input signal received by the input circuit can be received and input by, for example but not limited to, a receiver, the output signal output by the output circuit can be output to and transmitted by, for example but not limited to, a transmitter, and the input circuit and the output circuit can be the same circuit which is used as the input circuit and the output circuit at different times. The embodiments of the present application do not limit the specific implementation of the processor and various circuits.
[0050] In a ninth aspect, a processing apparatus is provided, including a processor and a memory. The processor is configured to read instructions stored in the memory, and can receive a signal through a receiver and transmit a signal through a transmitter to execute the method in the first aspect to the third aspect or any possible implementation manner of the first aspect to the third aspect.
[0051] Optionally, the processor is one or more, and the memory is one or more.
[0052] Optionally, the memory can be integrated with the processor, or the memory and the processor are separately arranged.
[0053] In the implementation process, the memory can be a non-transitory memory, for example, a read only memory (ROM), which can be integrated with the processor on the same chip, or can be separately arranged on different chips. The embodiments of the present application do not limit the type of memory and the arrangement of the memory and the processor.
[0054] The processing apparatus in the ninth aspect above can be a chip, and the processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading software code stored in the memory. The memory can be integrated in the processor or exist independently outside the processor.
[0055] In a tenth aspect, a computer program product is provided, including a computer program (also referred to as code or instructions), which, when executed, causes a computer to execute the method in the first aspect to the third aspect or any possible implementation manner of the first aspect to the third aspect.
[0056] In an eleventh aspect, a computer readable medium is provided, and the computer readable medium stores a computer program (which can also be referred to as code or instructions) which, when run on a computer, causes the computer to perform the method of the first aspect to the third aspect or any possible implementation of the first aspect to the third aspect.
[0057] In a twelfth aspect, a communication system is provided, and the communication system comprises one or more of the following: a mobility management network element in a first network, an interworking network element in the first network, and a terminal device. BRIEF DESCRIPTION OF DRAWINGS
[0058] Figure 1 is a schematic diagram of a communication system provided by the present application.
[0059] Figure 2 is a schematic diagram of a UE directly accessing an SNPN through a non-3GPP access and indirectly accessing the SNPN through a PLMN.
[0060] Figure 3 is a schematic diagram of a UE directly accessing a PLMN through a non-3GPP access and indirectly accessing the PLMN through an SNPN.
[0061] Figure 4 is a schematic diagram of a protocol structure of a UE when the UE directly accesses an SNPN through a non-3GPP access and indirectly accesses the SNPN through a PLMN.
[0062] Figure 5 is a schematic diagram of a protocol structure of a UE when the UE directly accesses a PLMN through a non-3GPP access and indirectly accesses the PLMN through an SNPN.
[0063] Figure 6 is a schematic flowchart of a method of accessing a network provided by the present application.
[0064] Figure 7 is a schematic flowchart of a specific example of a method of accessing a network provided by the present application.
[0065] Figure 8 is a schematic flowchart of a specific example of a method of accessing a network provided by the present application.
[0066] Figure 9 is a schematic flowchart of a specific example of a method of accessing a network provided by the present application.
[0067] Figure 10 is a schematic flowchart of a specific example of a method of accessing a network provided by the present application.
[0068] Figure 11 is a schematic block diagram of a communication apparatus provided by the present application.
[0069] Figure 12 is a schematic block diagram of another communication device provided by the application.
[0070] Figure 13 is a schematic block diagram of a terminal device provided by the application. DETAILED DESCRIPTION
[0071] The technical solutions in the application will be described below with reference to the drawings.
[0072] The technical solutions of the embodiments of the application can be applied to various communication systems, for example, a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), a 5th generation (5G) system, a new radio (NR), or other communication systems that may appear in the future.
[0073] The network elements or devices mainly involved in the application include:
[0074] (1) A terminal device, which can refer to a user equipment (UE), an access terminal, a terminal in V2X communication, a user unit, a user station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal device, a wireless communication device, a user agent, or a user apparatus. The terminal can also be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device, or other processing devices connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a future 5G network, or a terminal device in a future evolved public land mobile network (PLMN), etc. The embodiments of the application are not limited in this regard. The terminal can also include a V2X device, such as a vehicle or an on board unit (OBU) in a vehicle.
[0075] (2) A mobility management network element, which mainly performs access and mobility management control.
[0076] (3) Intercommunication network element: It can realize the intercommunication between different networks. For example, it can realize the intercommunication between the core network of non-public network and public network. For another example, it can realize the intercommunication between non-3GPP access network and the core network of non-public network, or realize the intercommunication between non-3GPP access network and the core network of public network.
[0077] This application provides a communication system, which is described below. Figure 1 Explain this.
[0078] Figure 1 2 is a schematic diagram of another communication system provided by the present application. The system 200 may include a mobility management network element 210 in a first network and an intercommunication network element 220 in the first network. Optionally, the system 200 may further include a terminal device 230.
[0079] The intercommunication network element 220 is configured to send access type information to the mobility management network element 210, where the access type information indicates an access type of the terminal device 230 accessing the first network;
[0080] The mobility management network element 210 is configured to receive the access type information from the intercommunication network element 220 ; and perform access control on the terminal device 230 according to the access type information.
[0081] Optionally, the intercommunication network element 220 is further configured to: receive a non-access stratum (NAS) message from the terminal device 230; and determine the access type of the terminal device 230 corresponding to the NAS message.
[0082] Optionally, performing access control on the terminal device 230 based on the access type information includes: sending a registration rejection message to the terminal device 230, the registration rejection message including a reason value, and the reason value is used to indicate that the terminal device 230 is not allowed to access the first network through the access type.
[0083] Optionally, the access type is accessing the first network through the second network, wherein the first network is a non-public network and the second network is a public network; or, the first network is a public network and the second network is a non-public network.
[0084] Optionally, the access type is that the terminal device 230 accesses through non-3GPP.
[0085] According to the communication system provided in the present application, the mobile management network element in the first network can learn the access type of the terminal device accessing the first network according to the access type information provided by the interworking network element, so as to perform access control on the terminal device. For example, if the first network is NPN, the mobile management network element can determine whether the terminal device accesses the NPN through non-3GPP access or accesses the NPN through the public network according to the access type information, so as to perform access control on the corresponding type of access.
[0086] It should be understood that the other network elements in the system 200 except the terminal device can be implemented by one device or jointly implemented by multiple devices, and the embodiments of the present application do not make specific limitation thereon. It can be understood that the functions of each network element can be implemented by hardware, software or a combination of hardware and software.
[0087] It should also be understood that the mobile management network element and the interworking network element are only names, and the names do not constitute limitation on the devices themselves. In the 5G network and other future networks, the above network elements can also have other names. In addition, the above network elements can also be implemented by other network elements. Figure 1 It should also be understood that the mobile management network element and the interworking network element are only names, and the names do not constitute limitation on the devices themselves. In the 5G network and other future networks, the above network elements can also have other names. In addition, the above network elements can also be implemented by other network elements.
[0088] Figure 1 The system shown can be implemented by a 5G system and other possible future systems, and the embodiments of the present application do not make specific limitation thereon. When any of the above systems is implemented by a 5G system, the terminal device, the mobile management network element and the interworking network element in the above system can correspond to the UE, the AMF and the N3IWF in the 5G system respectively.
[0089] Next, the system architecture to which the present application is applied will be introduced with the 5G system as an example. Figure 2 and Figure 3
[0090] Firstly, the network elements involved in the Figure 2 and Figure 3 will be briefly introduced.
[0091] (1) Radio access network (RAN): including but not limited to: evolved Node B (eNB), radio network controller (RNC), Node B (NB), base station controller (BSC), base transceiver station (BTS), home evolved NodeB (or home Node B, HNB), baseband unit (BBU), access point (AP) in a wireless fidelity (WIFI) system, wireless relay node, wireless backhaul node, transmission point (TP), or transmission and reception point (TRP), etc., and can also be a gNB or transmission point (TRP or TP) in a fifth generation (5G) system, such as a new radio (NR), an antenna panel or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or a network node constituting a gNB or transmission point, such as a building baseband unit (BBU) or a distributed unit (DU), etc.
[0092] (2) Access and mobility management function (AMF): functions related to access and mobility, such as connection management, mobility management, registration management, access authentication and authorization, reachability management, security context management, etc.
[0093] (3) Session management function (SMF): mainly for session management, execution of control policies issued by a policy control function (PCF), selection of a UPF, UE IP address allocation, etc.
[0094] (4) User plane function (UPF): functions related to the user plane, such as data packet routing and transmission, packet detection, service usage reporting, QoS processing, lawful interception, uplink packet detection, downlink data packet storage, etc.
[0095] (5) Data network (DN): an operator network providing data transmission service for users, such as IP Multi-media Service (IMS), Internet, and the like.
[0096] (6) N3 inter-working function (N3IWF): can realize interworking between different networks. For example, interworking between the core networks of a non-public network and a public network can be realized. For another example, interworking between the core networks of a non-public network and a non-3GPP access network, or interworking between the core networks of a non-3GPP access network and a public network can be realized.
[0097] Figure 2 and Figure 3 respectively show a system architecture schematic diagram. In Figure 2 and Figure 3 , the NPN ( Figure 2 and Figure 3 take the SNPN as an example) and the PLMN have independent radio access networks (RAN) and core networks (CN). The core networks of the SNPN and the PLMN are connected through the N3IWF, and the user plane and the control plane can be interworked through the N3IWF.
[0098] Referring to Figure 2 , the UE can access the SNPN through the PLMN, which is an indirect access mode, or directly access the SNPN through a non-3GPP access. However, the AMF in the SNPN does not know whether the UE indirectly accesses the NPN through the PLMN or directly accesses the SNPN through the non-3GPP access, which is a problem to be solved by the present application.
[0099] Referring to Figure 3 , the UE can access the PLMN through the SNPN, which is an indirect access mode, or directly access the PLMN through a non-3GPP access. However, the AMF in the PLMN does not know whether the UE indirectly accesses the PLMN through the SNPN or directly accesses the PLMN through the non-3GPP access, which is another problem to be solved by the present application.
[0100] It should be understood that each network element shown in Figure 2 and Figure 3 may be a hardware device, or a chip, or a software function running on a dedicated hardware, or a virtualized function instantiated on a platform (for example, a cloud platform). It should also be understood that Figure 3 and Figure 4Some of the network elements shown can be deployed in the same location (e.g., on the same hardware device or software function), and some can be deployed separately, which is not limited herein. Figure 4 and Figure 4 The interfaces between the network elements in the architecture shown are only an example, and the interfaces between the network elements can be different from those shown in the figure in different communication systems or as the system evolves, which is not limited herein.
[0101] Figure 5 An example of a protocol structure of a UE is shown when the UE accesses an SNPN directly through a non-3GPP access and indirectly through a PLMN.
[0102] Referring to Figure 5 , the UE accessing an SNPN includes an SNPN non-access stratum (NAS) and an SNPN access stratum (AS) inside, and the SNPN NAS is above the SNPN AS. The SNPN AS includes two: an SNPN 3GPP AS and an SNPN non-3GPP AS. The SNPN 3GPP AS supports 3GPP access, including NR, etc. The SNPN 3GPP AS includes a service data adaptation protocol (SDAP) layer and a radio resource control (RRC) layer. The SNPN 3GPP AS supports the UE accessing the SNPN directly through 3GPP access. Since the UE supports accessing the SNPN indirectly through a PLMN, the SNPN NAS of the UE regards the PLMN NAS as a component of the SNPN non-3GPP AS, so that the SNPN non-3GPP AS includes the PLMN NAS and an SNPN non-3GPP AS sublayer, and the SNPN non-3GPP AS sublayer further includes a management entity and a non-3GPP access (e.g., WiFi). The PLMN NAS supports the UE accessing the SNPN indirectly through the PLMN, and the SNPN non-3GPP AS sublayer supports the UE accessing the SNPN directly through a non-3GPP access.
[0103] Figure 6 An example of a protocol structure of a UE is shown when the UE accesses a PLMN through a non-3GPP access and an SNPN.
[0104] Referring to Figure 2The UE accessing the PLMN includes a PLMN NAS and a PLMN AS, and the PLMN NAS is above the PLMN AS. The PLMN AS includes two: a PLMN 3GPP AS and a PLMN non-3GPP AS. The PLMN 3GPP AS supports 3GPP access, including NR and the like. The PLMN 3GPP AS includes an SDAP layer and an RRC layer. The PLMN 3GPP AS supports the UE to access the PLMN directly through 3GPP access. Since the UE supports to access the PLMN indirectly through the SNPN, the PLMN NAS of the UE regards the SNPN NAS as a component of the PLMN non-3GPP AS, so that the PLMN non-3GPP AS includes the SNPN NAS and a PLMN non-3GPP AS sublayer, and the PLMN non-3GPP AS sublayer further includes a management entity and a non-3GPP access (such as WiFi). The SNPN NAS supports the UE to access the PLMN indirectly through the SNPN, and the PLMN non-3GPP AS sublayer supports the UE to access the PLMN directly through non-3GPP access.
[0105] The method of accessing a network provided in the present application is described below.
[0106] Figure 3 is a schematic flowchart of a method of accessing a network provided in the present application. The method can be applied in the system architecture shown in Figure 7 or Figure 7 The method 500 is described below.
[0107] S510, a mobile management network element in the first network receives access type information of a terminal device.
[0108] The access type information indicates an access type of the terminal device accessing the first network.
[0109] Optionally, the access type can be accessing the first network through the second network, where the first network is a non-public network, and the second network is a public network; or the first network is a public network, and the second network is a non-public network.
[0110] Alternatively, the access type can be non-3GPP access.
[0111] In this document, the public network can be a PLMN; the non-public network can be an SNPN, or a public network integrated NPN (PNI-NPN).
[0112] Accessing a PLMN via an SNPN can also be referred to as: accessing PLMN services via an SNPN or to access PLMN services via an SNPN. A UE is accessing PLMN services via an SNPN when the UE is connecting to the 5GCN of the PLMN using the 3GPP access of the SNPN.
[0113] Accessing an SNPN via a PLMN can also be referred to as: accessing SNPN services via a PLMN or to access SNPN services via a PLMN. A UE is accessing SNPN services via a PLMN when the UE is connecting to the 5GCN of the SNPN using the 3GPP access of the PLMN.
[0114] Non-3GPP access refers to that a UE accesses the core network of a PLMN or SNPN via an access layer connection between the UE and the N3IWF. The access layer connection between the UE and the N3IWF is an untrusted non-3GPP access, for example, Wireless Fidelity (WiFi). This access type is distinguished from that the UE accesses the core network of a PLMN or SNPN via an access layer connection between the UE and a Radio Access Network (RAN). The access layer connection between the UE and the Radio Access Network (RAN) is a 3GPP access, for example, NR in a 5G system.
[0115] In one manner, S510 can specifically be: the mobility management network element receives a registration request message from the terminal device.
[0116] Specifically, when the terminal device accesses the first network through the access type indicated by the access type information currently, the terminal device sends a registration request message to the mobility management network element, where the registration request message includes the access type information.
[0117] In another way, S510 can be specifically that the mobility management network element receives the access type information from the interworking network element.
[0118] Specifically, the terminal device can send a NAS message to the interworking network element in the first network, and the interworking network element can determine the access type of the terminal device accessing the first network corresponding to the NAS message. Then, the interworking network element sends the access type information to the mobility management network element in the first network.
[0119] S520, the mobility management network element performs access control on the terminal device according to the access type information.
[0120] For example, if the terminal device is not allowed to access the first network through the access type indicated by the access type information, the mobility management network element can send a registration rejection message to the terminal device, where the registration rejection message includes a cause value, and the cause value is used to indicate that the terminal device is not allowed to access the first network through the access type indicated by the access type information. For another example, if the terminal device is allowed to access the first network through the access type indicated by the access type information, the mobility management network element can send a registration acceptance message to the terminal device, where the registration acceptance message indicates that the terminal device is allowed to access the first network through the access type indicated by the access type information.
[0121] According to the method for accessing a network provided in the present application, the mobility management network element can know the access type of the terminal device accessing the first network according to the access type information, so as to perform access control on the terminal device.
[0122] The following further describes several different examples of the method 500 in combination with the access type indicated by the access type information and two implementation manners of step S510.
[0123] It should be noted that, for the sake of understanding, the following description is made by taking the naming of network elements in a 5G network as an example, and taking a public network as a PLMN and a non-public network as a SNPN.
[0124] I. The first network is a SNPN
[0125] Manner 1: The access type information is provided by the UE.
[0126] In combination with the flowchart shown in Figure 7 for description.
[0127] Referring to Figure 2 ,Figure 8 is a schematic flowchart of a method of accessing a network provided by the present application. The method 600 can be applied in the network shown in Figure 8 .
[0128] S601, the UE sends a registration request message #1 to an AMF in the SNPN via the PLMN. Accordingly, the AMF receives the registration request message #1 sent by the UE.
[0129] Specifically, if the UE currently accesses the SNPN via the PLMN, the UE can send the registration request message #1 to the AMF in the SNPN. The registration request message #1 includes access type information #1, which indicates that the access type is access SNPN via PLMN, i.e., access SNPN via PLMN.
[0130] It can be understood that the registration request message #1 is encapsulated as a NAS PDU, which can be sent to the N3IWF in the SNPN via the user plane (such as the UPF) of the PLMN, and further sent to the AMF by the N3IWF.
[0131] It should be understood that the registration request message #1 can also be transmitted to the N3IWF in the SNPN through the control plane of the PLMN, which is not limited by the present application.
[0132] S602, the AMF performs access control on the UE according to the access type information #1.
[0133] For example, if the core network of the SNPN does not allow the UE to access the SNPN via the PLMN, i.e., does not allow access SNPN via PLMN, the AMF performs:
[0134] S603a, the AMF sends a registration reject message #1 (i.e., an example of a registration reject message) to the UE. Accordingly, the UE receives the registration reject message #1 from the AMF.
[0135] The registration reject message #1 includes a cause value, which is used to indicate that the UE is not allowed to access the SNPN via the PLMN, i.e., access SNPN via PLMN is rejected. For example, the cause value is: access SNPN via PLMN not allowed.
[0136] After receiving the cause value, the UE can know that it cannot access the SNPN via the PLMN, so it will not initiate a registration request to the SNPN via the user plane of the registered PLMN in the future, for example, the UE can disable the access SNPN via PLMN capability.
[0137] For another example, if the UE is allowed to access the SNPN via the PLMN, i.e., allowed to access SNPN via PLMN, the AMF can perform:
[0138] S603b, the AMF sends a registration accept message #1 (i.e., an example of the registration accept message) to the UE. Accordingly, the UE receives the registration accept message #1 from the AMF.
[0139] The registration accept message #1 is used to indicate that the UE is allowed to access the SNPN via the PLMN, i.e., allowed to access SNPN via PLMN.
[0140] S604, the UE sends a registration request message #2 to the AMF via non-3GPP access. Accordingly, the AMF receives the registration request message #2 sent by the UE.
[0141] If the UE currently accesses the SNPN directly via non-3GPP access (such as wifi), the UE can send a registration request message #2 to the AMF in the SNPN, the registration request message including access type information #2, the access type information #2 indicating that the access type is non-3GPP access.
[0142] The registration request message can be sent to the N3IWF in the SNPN through an access layer Nwu connection between the UE and the N3IWF, and further sent to the AMF by the N3IWF.
[0143] S605, the AMF performs access control on the UE according to the access type information #2.
[0144] For example, if the UE is not allowed to access the SNPN directly via non-3GPP access, i.e., not allowed to access SNPN directly via non-3GPP access, the AMF performs:
[0145] S606a, the AMF sends a registration reject message #2 (i.e., another example of the registration reject message) to the UE. Accordingly, the UE receives the registration reject message #2 from the AMF.
[0146] The registration reject message #2 can include a cause value, which is used to indicate that the UE is not allowed to access the SNPN directly via non-3GPP access, i.e., to reject to access SNPN directly via non-3GPP access. For example, the cause value is specifically: non-3GPP access not allowed.
[0147] After receiving the cause, the UE can know that the SNPN cannot be directly accessed through the non-3GPP access, and thus subsequent registration requests to the SNPN are no longer initiated through the non-3GPP access. For example, the UE can disable the access capability of directly accessing the SNPN through the non-3GPP access.
[0148] For another example, if the UE is allowed to directly access the SNPN through the non-3GPP access, i.e., allowed to directly access the SNPN through the non-3GPP access, the AMF can perform the following operations:
[0149] In S606b, the AMF sends a registration accept message #2 (i.e., another example of the registration accept message) to the UE. Accordingly, the UE receives the registration accept message #2 from the AMF.
[0150] The registration accept message #2 is used to indicate that the UE is allowed to directly access the SNPN through the non-3GPP access, i.e., allowed to directly access the SNPN through the non-3GPP access.
[0151] According to the method for accessing a network provided in the present application, the UE can select whether to directly access the SNPN through the non-3GPP access, indirectly access the SNPN through the PLMN, or access both, based on its own capabilities and configurations. When initiating a registration request to the core network of the SNPN through the selected access type, the UE can carry corresponding access type information to the core network of the SNPN, so that the core network of the SNPN can identify the access type of the registration request initiated by the UE according to the access type information carried by the UE, and thus can perform different access type control according to the network configuration and the user's subscription information, implement the access control requirements of the operator for different access types, and improve the network operation efficiency.
[0152] It should be noted that based on the capabilities and configurations of the UE, the UE can only perform one of steps S601 and S604, or can perform both. For example, if the UE supports accessing the SNPN through the PLMN, it can perform S601, otherwise it can not perform S601. If the UE supports directly accessing the SNPN through the non-3GPP access, it can perform S604, otherwise it can not perform S604. If the UE supports both accessing the SNPN through the PLMN and directly accessing the SNPN through the non-3GPP access, it can perform both S601 and S604, or can only perform one of the two.
[0153] Method 2: The access type information is provided by the N3IWF in the SNPN.
[0154] In combination with Figure 8 The flowchart shown in the figure illustrates this.
[0155] Referring toFigure 9 , Figure 9 is a schematic flowchart of a method of accessing a network provided by the present application. The method 700 is described below.
[0156] S701, the UE sends a NAS message #1 to a N3IWF in a SNPN. Accordingly, the N3IWF receives the NAS message #1 from the UE.
[0157] If the UE currently accesses the SNPN via a PLMN, the UE can send a NAS message #1 (i.e., an example of a NAS message) to the N3IWF in the SNPN via a user plane (e.g., a UPF) in the PLMN. For example, the NAS message #1 can be a registration request message.
[0158] S702, the N3IWF determines an access type of the UE accessing the first network corresponding to the NAS message #1.
[0159] If the N3IWF receives the NAS message #1 via the user plane, the N3IWF can determine that the access type of the UE accessing the first network corresponding to the NAS message #1 is access SNPN via PLMN.
[0160] S703, the N3IWF sends access type information #1 to an AMF in the SNPN. Accordingly, the AMF receives the access type information #1 from the N3IWF (i.e., an example of access type information).
[0161] For example, the access type information #1 is used to indicate the access type, i.e., access SNPN via PLMN.
[0162] Optionally, the N3IWF can carry the access type information #1 via an interface message (e.g., an N2 interface message) between the N3IWF and the AMF. For example, the interface message can be an initial UE message.
[0163] S704, the AMF performs access control on the UE according to the access type information #1.
[0164] For example, if the UE is not allowed to access the SNPN via the PLMN, i.e., not allowed to access SNPN via PLMN, the AMF performs:
[0165] S705a, the AMF sends a registration reject message #1 (i.e., an example of a registration reject message) to the UE. Accordingly, the UE receives the registration reject message #1 from the AMF.
[0166] The steps S705a and S603a are the same, and for details, refer to S603a.
[0167] For another example, if the UE is allowed to access the SNPN via PLMN, i.e., allowed access SNPN via PLMN, the AMF can perform:
[0168] S705b, the AMF sends a registration accept message #1 (i.e., an example of a registration accept message) to the UE. Accordingly, the UE receives the registration accept message #1 from the AMF.
[0169] S705b is the same as S603b, and can be referred to S603b for details.
[0170] S706, the UE sends a NAS message #2 to the N3IWF in the SNPN. Accordingly, the N3IWF receives the NAS message #2 from the UE.
[0171] If the UE currently accesses the SNPN directly via non-3GPP (such as wifi), the UE can send the NAS message #2 (i.e., another example of a NAS message) to the N3IWF via a signaling connection between the UE and the N3IWF in the SNPN. For example, the NAS message #2 can be a registration request message.
[0172] S707, the N3IWF determines an access type of the UE corresponding to the NAS message #2 to access the first network.
[0173] If the N3IWF receives the NAS message #2 via a signaling connection between the UE and the N3IWF, the N3IWF can determine that the access type of the UE corresponding to the NAS message #2 to access the first network is non-3GPP access.
[0174] S708, the N3IWF sends access type information #2 (i.e., another example of access type information) to the AMF in the SNPN. Accordingly, the AMF receives the access type information from the N3IWF.
[0175] The access type information #2 is used to indicate the access type, i.e., non-3GPP access.
[0176] Optionally, the N3IWF can carry the access type information #2 via an interface message (for example, an N2 interface message) between the N3IWF and the AMF. For example, the interface message can be an initial UE message.
[0177] S709, the AMF performs access control on the UE according to the access type information #2.
[0178] For example, if the UE is not allowed to access the SNPN directly via non-3GPP, the AMF performs:
[0179] S710a, the AMF sends a registration reject message #2 (i.e., another example of the registration accept message) to the UE. Accordingly, the UE receives the registration reject message #2 from the AMF.
[0180] Step S710a is the same as S606a, and can be specifically referred to S606a.
[0181] For another example, if the UE is allowed to directly access the SNPN through the non-3GPP access, the AMF can perform:
[0182] S710b, the AMF sends a registration accept message #2 (i.e., another example of the registration accept message) to the UE. Accordingly, the UE receives the registration accept message #2 from the AMF.
[0183] Step S710b is the same as S606b, and can be specifically referred to S606b.
[0184] According to the method for accessing a network provided in the present application, the N3IWF determines the access type currently selected by the UE according to whether the NAS message sent by the UE is from the user plane or the signaling connection, and sends the access type information of the determined access type to the SNPN, so that the SNPN can identify the access type of the registration request initiated by the UE according to the access type information carried by the N3IWF, and thus can perform different access type control according to the network configuration and the user's subscription information, realize the access control requirements of the operator for different access types, and improve the network operation efficiency.
[0185] It should be noted that, based on the capability and configuration of the UE, the UE can only perform one of steps S701 and S706, or can perform both. For example, if the UE supports accessing the SNPN through the PLMN, S701 can be performed, otherwise S701 can not be performed. If the UE supports directly accessing the SNPN through the non-3GPP access, S706 can be performed, otherwise S706 can not be performed. If the UE supports accessing the SNPN through the PLMN and directly accessing the SNPN through the non-3GPP access, S701 and S706 can be performed, or only one of the two can be performed.
[0186] II. The first network is a PLMN
[0187] Method 1: The access type information is provided by the UE.
[0188] In combination with Figure 9 The flowchart shown in the figure illustrates this.
[0189] Referring to Figure 3 , Figure 10is a schematic flowchart of a method of accessing a network provided by the present application. The method 900 can be applied to Figure 10 in the network structure shown.
[0190] S901, the UE sends a registration request message #3 to an AMF in the PLMN via the SNPN. Accordingly, the AMF receives the registration request message #3 sent by the UE.
[0191] Specifically, if the UE currently accesses the PLMN via the SNPN, the UE can send a registration request message #3 to the AMF in the PLMN. The registration request message #3 includes access type information #3, which indicates that the access type is to access the PLMN via the SNPN, i.e., access PLMN via SNPN.
[0192] It can be understood that the registration request message #3 is encapsulated as a NAS PDU and can be sent to the N3IWF in the PLMN through the user plane (such as the UPF) of the SNPN, and further sent to the AMF by the N3IWF.
[0193] It should be understood that the registration request message #3 can also be transmitted to the N3IWF in the PLMN through the control plane of the SNPN, which is not limited by the present application.
[0194] S902, the AMF performs access control on the UE according to the access type information #3.
[0195] For example, if the UE is not allowed to access the PLMN via the SNPN, i.e., access PLMN via SNPN is not allowed, the AMF performs:
[0196] S903a, the AMF sends a registration rejection message #3 (i.e., an example of a registration rejection message) to the UE. Accordingly, the UE receives the registration rejection message #3 from the AMF.
[0197] The registration rejection message #3 includes a cause value, which is used to indicate that the UE is not allowed to access the PLMN via the SNPN, i.e., access PLMN via SNPN is rejected. For example, the cause value is specifically: access PLMN via SNPN not allowed.
[0198] After receiving the cause, the UE can know that it cannot access the PLMN via the SNPN, so it will not initiate a registration request to the PLMN through the user plane of the registered SNPN in the future, for example, the UE can disable the access capability of accessing the PLMN via the SNPN.
[0199] For example, if the UE is allowed to access the PLMN via SNPN, that is, access PLMN via SNPN is allowed, the AMF may perform:
[0200] S903b, the AMF sends a Registration Accept message #3 (i.e., an example of a Registration Accept message) to the UE. Correspondingly, the UE receives the Registration Accept message #3 from the AMF.
[0201] Registration Accept message #3 is used to indicate that the UE is allowed to access the PLMN through the SNPN, that is, it is allowed to access the PLMN through accessPLMN via SNPN.
[0202] S904: The UE sends a Registration Request message #4 to the AMF via non-3GPP access. Accordingly, the AMF receives the Registration Request message #4 sent by the UE.
[0203] If the UE currently directly accesses the PLMN through non-3GPP access, the UE can send a registration request message #4 to the AMF in the PLMN. The registration request message includes access type information #4, and the access type information #4 indicates that the access type is non-3GPP access.
[0204] Among them, the registration request message can be sent to the N3IWF in the PLMN through the access layer Nwu connection between the UE and the N3IWF, and further sent to the AMF by the N3IWF.
[0205] S905: AMF performs access control on the UE based on the access type information #4.
[0206] For example, if the UE is not allowed to directly access the PLMN via non-3GPP access, the AMF performs:
[0207] S906a: The AMF sends a Registration Reject message #4 (i.e., another example of a Registration Reject message) to the UE. Accordingly, the UE receives Registration Reject message #4 from the AMF.
[0208] The registration reject message #4 includes a cause value indicating that the UE is not allowed to directly access the PLMN via non-3GPP access, i.e., the UE is denied direct access to the PLMN via non-3GPP access. For example, the cause value is specifically: non-3GPP access not allowed.
[0209] After receiving the cause, the UE can know that the PLMN cannot be directly accessed through the non-3GPP access, and therefore subsequent registration requests to the PLMN are no longer initiated through the non-3GPP access, for example, the UE can disable the access capability of directly accessing the PLMN through the non-3GPP access.
[0210] For another example, if the UE is allowed to directly access the PLMN through the non-3GPP access, the AMF can perform the following operations:
[0211] S906b, the AMF sends a registration accept message #4 (i.e., another example of a registration accept message) to the UE. Accordingly, the UE receives the registration accept message #4 from the AMF.
[0212] The registration accept message #4 is used to indicate that the UE is allowed to directly access the PLMN through the non-3GPP access.
[0213] According to the method for accessing a network provided in the present application, the UE can select whether to directly access the PLMN through the non-3GPP access, indirectly access the PLMN through the SNPN, or access both, based on its own capabilities and configurations. When initiating a registration request to the core network of the PLMN through the selected access type, the UE can carry corresponding access type information to the core network of the PLMN, so that the core network of the PLMN can identify the access type of the UE initiating the registration request according to the access type information carried by the UE, and thus can perform different access type control according to the network configuration and user subscription information, implement the access control requirements of the operator for different access types, and improve the network operation efficiency.
[0214] It should be noted that based on the capabilities and configurations of the UE, the UE can only perform one of steps S901 and S904, or can perform both. For example, if the UE supports accessing the PLMN through the SNPN, it can perform S901, otherwise it can not perform S901. If the UE supports directly accessing the PLMN through the non-3GPP access, it can perform S904, otherwise it can not perform S904. If the UE supports accessing the PLMN through the SNPN and directly accessing the PLMN through the non-3GPP access, it can perform both S901 and S904, or can only perform one of the two.
[0215] Method 2: The access type information is provided by the N3IWF in the PLMN.
[0216] In combination with Figure 10 The flowchart shown illustrates this.
[0217] Referring to Figure 6 to Figure 10 , Figure 11 to Figure 13 is a schematic flowchart of a method for accessing a network provided in the present application. The method 1000 will be described below.
[0218] S1001, the UE sends a NAS message #3 to a N3IWF in the PLMN. Accordingly, the N3IWF receives the NAS message #3 from the UE.
[0219] If the UE currently accesses the PLMN via the SNPN, the UE can send a NAS message #3 (i.e., an example of a NAS message) to the N3IWF in the PLMN via a user plane in the SNPN. For example, the NAS message #3 can be a registration request message.
[0220] S1002, the N3IWF determines an access type of the UE accessing the first network corresponding to the NAS message #3.
[0221] If the N3IWF receives the NAS message #3 via the user plane, the N3IWF can determine that the access type of the UE accessing the first network corresponding to the NAS message #3 is access PLMN via SNPN.
[0222] S1003, the N3IWF sends access type information #3 to an AMF in the PLMN. Accordingly, the AMF receives the access type information #3 from the N3IWF (i.e., an example of access type information).
[0223] The access type information #3 is used to indicate the access type, i.e., access PLMN via SNPN.
[0224] Optionally, the N3IWF can carry the access type information #3 via an interface message (e.g., an N2 interface message) between the N3IWF and the AMF. For example, the interface message can be an initial UE message.
[0225] S1004, the AMF performs access control on the UE according to the access type information #3.
[0226] For example, if the UE is not allowed to access the PLMN via the SNPN, i.e., not allowed to access PLMN via SNPN, the AMF performs:
[0227] S1005a, the AMF sends a registration reject message #3 (i.e., an example of a registration reject message) to the UE. Accordingly, the UE receives the registration reject message #3 from the AMF.
[0228] Step S1005a is the same as S903a, and can refer to S903a for details.
[0229] For another example, if the UE is allowed to access the PLMN via SNPN, i.e., allowed to access the PLMN via SNPN, the AMF can perform:
[0230] S1005b, the AMF sends a registration accept message #3 (i.e., an example of a registration accept message) to the UE. Accordingly, the UE receives the registration accept message #3 from the AMF.
[0231] S1005b is the same as S903b, and can be referred to S903b for details.
[0232] S1006, the UE sends a NAS message #4 (i.e., another example of a NAS message) to the N3IWF in the PLMN. Accordingly, the N3IWF receives the NAS message #4 from the UE.
[0233] If the UE currently accesses the PLMN directly via non-3GPP access, the UE can send the NAS message #4 (i.e., another example of a NAS message) to the N3IWF in the PLMN via a signaling connection between the UE and the N3IWF. For example, the NAS message #4 can be a registration request message.
[0234] S1007, the N3IWF determines the access type of the UE corresponding to the NAS message #4 to access the first network.
[0235] If the N3IWF receives the NAS message #4 via the signaling connection between the UE and the N3IWF, the N3IWF can determine that the access type of the UE corresponding to the NAS message #4 to access the first network is non-3GPP access.
[0236] S1008, the N3IWF sends access type information #4 (i.e., another example of access type information) to the AMF in the PLMN. Accordingly, the AMF receives the access type information from the N3IWF.
[0237] The access type information #4 is used to indicate the access type, i.e., non-3GPP access.
[0238] Optionally, the N3IWF can carry the access type information #4 via an interface message (e.g., an N2 interface message) between the N3IWF and the AMF. For example, the interface message can be an initial UE message.
[0239] S1009, the AMF performs access control on the UE according to the access type information #4.
[0240] For example, if the UE is not allowed to access the PLMN directly via non-3GPP access, the AMF performs:
[0241] S1010a, the AMF sends a registration reject message #4 (i.e., another example of a registration accept message) to the UE. Accordingly, the UE receives the registration reject message #4 from the AMF.
[0242] The step S1010a is the same as S906a, and details can be referred to S906a.
[0243] For another example, if the UE is allowed to directly access the PLMN through the non-3GPP access, the AMF can perform:
[0244] S1010b, the AMF sends a registration accept message #4 (i.e., another example of a registration accept message) to the UE. Accordingly, the UE receives the registration accept message #4 from the AMF.
[0245] The step S1010b is the same as S906b, and details can be referred to S906b.
[0246] According to the method for accessing a network provided in the present application, after determining the access type currently selected by the UE according to whether the NAS message sent by the UE is from a user plane or a signaling connection, the N3IWF can send the access type information of the determined access type to the PLMN, so that the PLMN can identify the access type of the registration request initiated by the UE according to the access type information carried by the N3IWF, and thus different access type control can be performed according to the network configuration and the subscription information of the user, realizing the access control requirements of the operator for different access types and improving the network operation efficiency.
[0247] It should be noted that based on the capability and configuration of the UE, the UE can only perform one of steps S1001 and S1006, or can perform both. For example, if the UE supports accessing the PLMN through the SNPN, S1001 can be performed, otherwise S1001 can not be performed. If the UE supports directly accessing the PLMN through the non-3GPP access, S1006 can be performed, otherwise S1006 can not be performed. If the UE supports accessing the PLMN through the SNPN and directly accessing the PLMN through the non-3GPP access, S1001 and S1006 can be performed, or only one of the two can be performed.
[0248] It should be understood that the various schemes of the embodiments of the present application can be reasonably combined for use, and the explanations or descriptions of various terms appearing in the embodiments can be mutually referenced or explained in various embodiments, and this is not limited.
[0249] It should also be understood that the size of the sequence number of each process described above does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic. The various digital numbers or sequence numbers involved in each of the above processes are only distinguished for the convenience of description, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0250] The above, in combination with Figure 11 The method provided by the embodiments of the present application is described in detail. The following, in combination with Figure 11 The device provided by the embodiments of the present application is described in detail.
[0251] Figure 12 is a schematic block diagram of the communication device provided by the embodiments of the present application. As Figure 12 indicated, the communication device 2000 can include a transceiver unit 2010 and a processing unit 2020.
[0252] The transceiver unit 2010 can be used to send information to other devices or receive information from other devices. The processing unit 2020 can be used for internal processing of the device.
[0253] In an implementation manner, the communication device 2000 corresponds to the mobile management network element (such as AMF in PLMN or SNPN) in the first network described above. The communication device 2000 can be a mobile management network element in the first network or a chip configured in the mobile management network element in the first network, which can include units for performing operations performed by the mobile management network element in the first network.
[0254] Specifically, the transceiver unit 2010 is configured to receive access type information of a terminal device, the access type information indicating an access type of the terminal device accessing the first network; and the processing unit 2020 is configured to perform access control on the terminal device according to the access type information.
[0255] Optionally, the access type is to access the first network through a second network, wherein the first network is a non-public network and the second network is a public network; or the first network is a public network and the second network is a non-public network.
[0256] Optionally, the access type is non-third generation partnership project (3GPP) access.
[0257] Optionally, the receiving unit is specifically configured to receive a registration request message from the terminal device, the registration request message including the access type information.
[0258] Optionally, the receiving unit is specifically configured to receive an N2 interface message from an interworking network element in the first network, and the N2 interface message comprises the access type information.
[0259] Optionally, the receiving unit is specifically configured to send a registration reject message to the terminal device in a case where the terminal device is not allowed to access the first network through the second network, and the registration reject message comprises a cause value indicating that the terminal device is not allowed to access the first network through the second network.
[0260] Optionally, the receiving unit is specifically configured to send a registration reject message to the terminal device in a case where the terminal device is not allowed to access the first network through the non-3GPP access, and the registration reject message comprises a cause value indicating that the terminal device is not allowed to access the first network through the non-3GPP access.
[0261] In another implementation, the communication apparatus 2000 corresponds to the terminal device (e.g., UE) in the method embodiments described above. The communication apparatus 2000 can be a terminal device or a chip configured in a terminal device, and can comprise units for performing operations performed by the terminal device.
[0262] The transceiver 2010 is configured to send access type information of the communication apparatus 2000 to a mobility management network element in a first network, the access type information indicating an access type of the communication apparatus 2000 accessing the first network, and to receive a registration reject message from the mobility management network element, the registration reject message comprising a cause value indicating that the communication apparatus 2000 is not allowed to access the first network through the access type indicated by the access type information.
[0263] Optionally, the access type is an access to the first network through a second network, wherein the first network is a non-public network and the second network is a public network, or the first network is a public network and the second network is a non-public network.
[0264] Optionally, the transceiver 2010 is specifically configured to send a registration request message to the mobility management network element through the second network, and the registration request message comprises the access type information.
[0265] Optionally, the access type is a non-third generation partnership project (3GPP) access.
[0266] Optionally, the transceiver 2010 is specifically configured to send a registration request message to the mobility management network element through the non-3GPP access, and the registration request message comprises the access type information.
[0267] In yet another implementation, the communication apparatus 2000 corresponds to an interworking network element in a first network (e.g., N3IWF in a PLMN or SNPN) in the above-described method embodiments. The communication apparatus 2000 can be the interworking network element in the first network or a chip configured to the interworking network element in the first network, which can include units for performing operations performed by the interworking network element in the first network.
[0268] Specifically, the transceiver 2010 is configured to receive a non-access stratum (NAS) message from a terminal device; the processing unit 2020 is configured to determine an access type of the terminal device accessing the first network corresponding to the NAS message; and the transceiver 2010 is further configured to send access type information to a mobility management network element in the first network, the access type information being used to indicate the access type.
[0269] Optionally, the processing unit 2020 is specifically configured to: if the NAS message received by the receiving unit is from a user plane of a second network, determine that the access type is to access the first network through the second network, wherein the first network is a non-public network, and the second network is a public network; or the first network is a public network, and the second network is a non-public network.
[0270] Optionally, the processing unit 2020 is specifically configured to: if the NAS message received by the receiving unit is from a signaling connection between the terminal device and the communication apparatus 2000, determine that the access type is non-3rd generation partnership project (3GPP) access.
[0271] Optionally, the NAS message is a registration request message.
[0272] It should be understood that the specific processes of each unit performing the corresponding steps described above have been described in detail in the above-described method embodiments, and for the sake of brevity, will not be described here.
[0273] It should also be understood that when the communication apparatus 2000 corresponds to the mobility management network element in the first network or the interworking network element in the first network, the transceiver 2010 in the communication apparatus 2000 can correspond to the communication interface 3200 in the communication apparatus 3000 shown in FIG. 3, and the processing unit 2020 in the communication apparatus 2000 can correspond to the processor 3100 in the communication apparatus 3000 shown in FIG. 3. Figure 13 It should also be understood that when the communication apparatus 2000 corresponds to the mobility management network element in the first network or the interworking network element in the first network, the transceiver 2010 in the communication apparatus 2000 can correspond to the communication interface 3200 in the communication apparatus 3000 shown in FIG. 3, and the processing unit 2020 in the communication apparatus 2000 can correspond to the processor 3100 in the communication apparatus 3000 shown in FIG. 3. Figure 13 It should also be understood that when the communication apparatus 2000 corresponds to the mobility management network element in the first network or the interworking network element in the first network, the transceiver 2010 in the communication apparatus 2000 can correspond to the communication interface 3200 in the communication apparatus 3000 shown in FIG. 3, and the processing unit 2020 in the communication apparatus 2000 can correspond to the processor 3100 in the communication apparatus 3000 shown in FIG. 3. Figure 12 It should also be understood that when the communication apparatus 2000 corresponds to the mobility management network element in the first network or the interworking network element in the first network, the transceiver 2010 in the communication apparatus 2000 can correspond to the communication interface 3200 in the communication apparatus 3000 shown in FIG. 3, and the processing unit 2020 in the communication apparatus 2000 can correspond to the processor 3100 in the communication apparatus 3000 shown in FIG. 3. Figure 12The processor 4001 or the processing device 4004 in the terminal device 4000 shown in FIG. 4.
[0274] Figure 12 A schematic block diagram of another communication apparatus 3000 provided by the present application is shown. Any network element involved in the method embodiments described above, such as a mobility management network element in the first network or an interworking network element in the first network, etc., can be implemented by the communication apparatus shown in FIG. 3. Figure 13
[0275] It should be understood that the communication apparatus 3000 can be a physical device, a component (for example, an integrated circuit, a chip, etc.) of a physical device, or a functional module in a physical device.
[0276] As shown in FIG. 3, the communication apparatus 3000 includes one or more processors 3100. The processor 3100 can store execution instructions for executing the method of the embodiments of the present application. Optionally, the processor 3100 can invoke a communication interface 3200 to implement the receiving and sending functions. The communication interface 3200 can be a logical interface or a physical interface, which is not limited. For example, the communication interface 3200 can be a transceiver circuit, an interface circuit, a transceiver, or a transceiver circuit for implementing the receiving and sending functions. The sending function and the receiving function of the communication interface 3200 can be separate or integrated together. The transceiver circuit or the interface circuit described above can be used for reading and writing of code / data, or the transceiver circuit or the interface circuit described above can be used for transmission or transfer of signals. Figure 13
[0277] Optionally, the communication apparatus 3000 can further include a memory 3300. The embodiments of the present application do not make specific limitations on the specific deployment location of the memory 3300. The memory 3300 can be integrated in the processor 3100 or independent of the processor 3100. For the case that the communication apparatus 3000 does not include the memory, the communication apparatus 3000 has processing functions, and the memory can be deployed at other locations (for example, a cloud system).
[0278] The processor 3100, the memory 3300 and the communication interface 3200 communicate with each other through internal connection paths to transfer control and / or data signals.
[0279] It can be understood that, although not shown, the communication apparatus 3000 can further include other apparatuses, for example, an input apparatus, an output apparatus, a battery, etc.
[0280] Optionally, in some embodiments, the memory 3300 can store execution instructions for performing the methods of the embodiments of the present application. The processor 3100 can execute the instructions stored in the memory 3300 to complete the steps of the method execution shown below in combination with other hardware (for example, the communication interface 3200), and the specific working process and benefits can be referred to the description of the method embodiments above.
[0281] The method disclosed in the embodiments of the present application can be applied to the memory 3300 or implemented by the memory 3300. The memory 3300 can be an integrated circuit chip with signal processing capability. In the implementation process, the steps of the method can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The processor mentioned above can be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component. The disclosed methods, steps and logic block diagrams in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in a random access memory (RAM), a flash memory, a read-only memory (ROM), a programmable read-only memory or an electrically erasable programmable memory, a register or other mature storage medium in the art. The storage medium is located in the memory, and the processor reads the instructions in the memory in combination with the hardware to complete the steps of the above method.
[0282] It is to be appreciated that the memory 3300 can be volatile memory or nonvolatile memory, or can include both volatile and nonvolatile memory. In one non-limiting example embodiment, nonvolatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically EPROM (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), which acts as external cache. By way of example and not limitation, many forms of RAM are suitable, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It is to be appreciated that the memory described herein is intended to include, without being limited to, these and any other suitable types of memory.
[0283] FIG. 4 is a schematic diagram of a terminal device 4000 according to an embodiment of the present application. As shown in the figure, the terminal device 4000 includes a processor 4001 and a transceiver 4002. Optionally, the terminal device 4000 can further include a memory 4003. The processor 4001, the transceiver 4002 and the memory 4003 can communicate with each other through internal connection paths, and transfer control and / or data signals. The memory 4003 is configured to store a computer program. The processor 4001 is configured to invoke and execute the computer program stored in the memory 4003, so as to control the transceiver 4002 to transceive signals.
[0284] The processor 4001 and the memory 4003 described above can be combined into a processing apparatus 4004. The processor 4001 is configured to execute the program code stored in the memory 4003 to realize the functions of the terminal device in the above method embodiments. It should be understood that the processing apparatus 4004 shown in the figure is only an example. In a specific implementation, the memory 4003 can also be integrated in the processor 4001, or independent of the processor 4001. The present application does not make any limitation in this regard.
[0285] The terminal device 4000 shown above can also include an antenna 4010 for transmitting uplink data or uplink control signaling output by the transceiver 4002 through wireless signals.
[0286] It should be understood that The terminal device 4000 shown can implement each process of the terminal device involved in the foregoing method embodiments. The operation or function of each module in the terminal device 4000 is respectively for implementing the corresponding flow in the foregoing method embodiments. For details, reference can be made to the description in the foregoing method embodiments, and the detailed description is appropriately omitted here to avoid repetition.
[0287] Optionally, the terminal device 4000 shown above can also include a power supply 4005 for providing power supply to various devices or circuits in the terminal device.
[0288] In addition, in order to make the function of the terminal device more perfect, the terminal device 4000 can also include one or more of an input unit 4006, a display unit 4007, an audio circuit 4011, a camera 4009, and a sensor 4008, etc. The audio circuit 4011 can also include a speaker 40081, a microphone 40082, etc.
[0289] It should be understood that the processing device 4004 or the processor 4001 can be one chip. For example, the processing device 4004 or the processor 4001 can be a field programmable gate array (FPGA), can be a general processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, can also be a system chip (SoC), can also be a central processing unit (CPU), can also be a network processor (NP), can also be a digital signal processing circuit (digital signal processor, DSP), can also be a micro controller (MCU), can also be a programmable logic device (PLD) or other integrated chip. The general processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as hardware code processing performed by the processor, or executed by a combination of hardware and software modules in the code processing. The software module can be located in a random memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, etc. The storage medium in the art. The storage medium is located in the memory, and the processor reads the information in the memory, and combines the hardware to complete the steps of the above method.
[0290] The memory 4003 can be any form of memory described in the foregoing, which will not be repeated here.
[0291] The present application also provides a computer program product, which comprises computer program code, when the computer program code runs on the computer, so that the computer executes the method of the terminal device side, the mobile management network element side in the first network or the interworking network element side in the first network in any one of the preceding method embodiments.
[0292] The application further provides a computer readable medium storing program codes, which, when executed on a computer, cause the computer to perform the method of the terminal device side, the mobile management network element side in the first network, or the interworking network element side in the first network in the foregoing method embodiments.
[0293] The application further provides a system including one or more of the following: a terminal device, a mobile management network element in the first network, and an interworking network element in the first network.
[0294] In the foregoing embodiments, the entire or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, the entire or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the entire or part of the processes or functions according to the embodiments of the application are produced. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center through a wired (for example, coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available medium can be a magnetic medium (for example, floppy disk, hard disk, magnetic tape), an optical medium (for example, high-density digital video disc (digital video disc, DVD)), or a semiconductor medium (for example, solid state disc (solid state disc, SSD)) and the like.
[0295] The network device in each of the foregoing apparatus embodiments and the network device or terminal device in the method embodiments fully correspond, and the corresponding steps are performed by the corresponding modules or units, for example, the communication unit (transceiver) performs the steps of receiving or transmitting in the method embodiments, and the other steps except for transmitting and receiving can be performed by the processing unit (processor). The functions of the specific units can refer to the corresponding method embodiments. The processor can be one or more.
[0296] As used in the present specification, the terms "component," "module," "system" and the like are intended to refer to a computer-related entity, either hardware, firmware, a combination of hardware and software, software, or software in execution. For example, a component can be, but is not limited to being, a process running on a processor, a processor, an object, an executable, a thread of execution, a program, or a computer. By way of illustration, both an application running on a computing device and the computing device can be a component. One or more components can reside within a process or thread of execution and a component can be localized, either in whole or in part, in a single computer or distributed among multiple computers. In addition, these components can execute from various computer-readable media having various data structures stored thereon. The components can communicate by way of local or remote processes such as in accordance with a signal having one or more data packets (e.g., data from one component interacting with another component in a local system, distributed system, or across the Internet with another system, e.g., via an application program interface or other means).
[0297] It should be understood that the "embodiments" mentioned throughout the specification mean that the specific features, structures or characteristics related to the embodiments are included in at least one of the embodiments of the present application. Therefore, the various embodiments throughout the specification do not necessarily refer to the same embodiments. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner.
[0298] It should be understood that in the embodiments of the present application, the numbers "first", "second", … are only used to distinguish different objects, such as to distinguish different network devices, and do not limit the scope of the embodiments of the present application, and the embodiments of the present application are not limited thereto.
[0299] It should also be understood that in the present application, "when", "if" and "if" all refer to the corresponding processing of the network element under certain objective conditions, and are not limited by time, and do not require the network element to have a judgment action when implemented, nor does it mean that there are other limitations.
[0300] It should also be understood that in the present application, "at least one" means one or more, and "multiple" means two or more.
[0301] It should also be understood that in the embodiments of the present application, "A corresponds to B" means that B is associated with A and B can be determined according to A. However, it should also be understood that the determination of B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0302] It should also be understood that the term "and / or" in this paper is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the existence of A alone, the existence of A and B, and the existence of B alone. In addition, the character " / " in this paper generally represents an "or" relationship between the associated objects before and after it.
[0303] In the present application, the meaning of the expression similar to "the item includes one or more of the following: A, B, and C" is generally that the item can be any one of the following: A; B; C; A and B; A and C; B and C; A, B and C; A and A; A, A and A; A, A and B; A, A and C, A, B and B; A, C and C; B and B, B, B and B, B, B and C, C and C; C, C and C, and other combinations of A, B and C. The above is an example of three elements A, B and C to illustrate the optional items of the item. When the expression is "the item includes at least one of the following: A, B, …, and X", that is, the expression has more elements, the item can also be applied to the items according to the above rules.
[0304] It can be understood that the terminal device and / or the network device in the embodiments of the present application can perform some or all of the steps in the embodiments of the present application, and these steps or operations are only examples, and the embodiments of the present application can also perform other operations or variations of various operations. In addition, each step can be performed in a different order according to the embodiments of the present application, and it is possible that not all operations in the embodiments of the present application are performed.
[0305] Those skilled in the art can appreciate that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0306] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.
[0307] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented by other manners. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.
[0308] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0309] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit.
[0310] The functions, if realized in the form of software functional units and sold or used as independent products, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application or the part of the present application that essentially contributes to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk, and various program code storage media.
[0311] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for accessing a network, characterized in that: include: A mobility management network element in the first network receives access type information of a terminal device, where the access type information indicates an access type of the terminal device for accessing the first network; The mobility management network element performs access control on the terminal device according to the access type information, The access type includes accessing the first network through a second network, or accessing the first network through a non-Third Generation Mobile Partnership Project 3GPP, the first network is a non-public network, and the second network is a public network; or, the first network is a public network, and the second network is a non-public network.
2. The method according to claim 1, wherein The mobility management network element in the first network receives the access type information of the terminal device, including: The mobility management network element receives a registration request message from the terminal device, where the registration request message includes the access type information.
3. The method according to claim 1 or 2, wherein: The mobility management network element in the first network receives the access type information of the terminal device, including: The mobility management network element receives an N2 interface message from an intercommunication network element in the first network, where the N2 interface message includes the access type information.
4. The method according to claim 1 or 2, wherein: The mobility management network element performs access control on the terminal device according to the access type information, including: In the case that the terminal device is not allowed to access the first network through the second network, the mobility management network element sends a registration rejection message to the terminal device, and the registration rejection message includes a reason value, and the reason value is used to indicate that the terminal device is not allowed to access the first network through the second network.
5. The method according to claim 4, wherein The mobility management network element performs access control on the terminal device according to the access type information, including: In a case where the terminal device is not allowed to access the first network through the non-3GPP, the mobility management network element sends a registration rejection message to the terminal device, where the registration rejection message includes a cause value, and the cause value is used to indicate that the terminal device is not allowed to access the first network through the non-3GPP.
6. A method for accessing a network, characterized in that: include: The terminal device sends the access type information of the terminal device to the mobility management network element in the first network, where the access type information indicates the access type of the terminal device to access the first network; The terminal device receives a registration rejection message from the mobility management network element, where the registration rejection message includes a cause value, where the cause value is used to indicate that the terminal device is not allowed to access the first network through the access type indicated by the access type information. The access type includes accessing the first network through a second network, or accessing the first network through a non-Third Generation Mobile Partnership Project 3GPP, the first network is a non-public network, and the second network is a public network; or, the first network is a public network, and the second network is a non-public network.
7. The method according to claim 6, wherein The terminal device sending the access type information to the mobility management network element includes: The terminal device sends a registration request message to the mobility management network element through the second network, and the registration request message includes the access type information.
8. The method according to claim 6 or 7, wherein: The terminal device sending the access type information to the mobility management network element includes: The terminal device sends a registration request message to the mobility management network element through the non-3GPP access, where the registration request message includes the access type information.
9. A method for accessing a network, characterized in that: include: The intercommunication network element in the first network receives a non-access stratum NAS message from the terminal device; The intercommunication network element determines the access type of the terminal device corresponding to the NAS message to the first network; The intercommunication network element sends access type information to the mobility management network element in the first network, where the access type information is used to indicate the access type. The access type includes accessing the first network through a second network, or accessing the first network through a non-Third Generation Mobile Partnership Project 3GPP, the first network is a non-public network, and the second network is a public network; or, the first network is a public network, and the second network is a non-public network.
10. The method according to claim 9, wherein The intercommunication network element determines the access type of the terminal device corresponding to the NAS message to the first network, including: If the NAS message comes from the user plane of the second network, the intercommunication network element determines that the access type is access to the first network through the second network.
11. The method according to claim 9, wherein The intercommunication network element determines the access type of the terminal device corresponding to the NAS message to the first network, including: If the NAS message comes from a signaling connection between the terminal device and the interworking network element, the interworking network element determines that the access type is non-3rd Generation Mobile Partnership Project 3GPP access.
12. The method according to any one of claims 9 to 11, characterized in that The NAS message is a registration request message.
13. A communication system, characterized in that: include: a mobility management network element in the first network and an intercommunication network element in the first network; The intercommunication network element is configured to send access type information to the mobility management network element, where the access type information indicates an access type of the terminal device accessing the first network; The mobility management network element is used to receive the access type information from the intercommunication network element; and perform access control on the terminal device according to the access type information. The access type includes accessing the first network through a second network, or accessing the first network through a non-Third Generation Mobile Partnership Project 3GPP, the first network is a non-public network, and the second network is a public network; or, the first network is a public network, and the second network is a non-public network.
14. The system according to claim 13, wherein: The intercommunication network element is further used for: Receive non-access stratum NAS messages from terminal devices; Determine the access type of the terminal device corresponding to the NAS message.
15. The system according to claim 13 or 14, characterized in that The performing access control on the terminal device according to the access type information includes: A registration rejection message is sent to the terminal device, where the registration rejection message includes a cause value, where the cause value is used to indicate that the terminal device is not allowed to access the first network through the access type.
16. A communication device, characterized in that: The apparatus comprises a unit or module for performing the method according to any one of claims 1 to 5, or any one of claims 6 to 8, or any one of claims 9 to 12.
Citation Information
Patent Citations
Access control method and device
CN111194095A