Method, node and medium for realizing unified data management network function in communication network
By introducing UDM network functions into the 5G communication network, mutually exclusive access control for network slices is achieved, security vulnerabilities in network slice management are solved, and network security and policy management are improved.
Patent Information
- Application Number
- CN202210443282.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-07-14
- Filing Date
- 2022-04-25
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2042-04-25
AI Technical Summary
In existing 5G communication networks, there are security vulnerabilities in the mutually exclusive access management of network slices, which can easily lead to network tampering and unauthorized activities, and lack effective management methods.
The unified data management (UDM) network function is introduced, through the network slice access control function, the UE's access to network slices is managed based on the policy, and the mutually exclusive access control of network slices is realized, including restricting or allowing UE to access multiple network slices at the same time.
Improve the security and management efficiency of network slicing access, prevent unauthorized network activities, and enhance network security and policy control.
Smart Images

Figure CN115701162B_ABST
Abstract
Description
Background Art
[0001] In 5th generation (5G) cellular networks, network slicing can be deployed. Network slicing can refer to a networking architecture that enables the partitioning of physical network infrastructure into virtual components. In particular, network slicing can allow the creation of multiple logical networks (e.g., network slices) on a common physical network infrastructure. Each network slice can be an isolated network that includes dedicated resources and / or shared resources for a specific use case. BRIEF DESCRIPTION OF THE DRAWINGS
[0002] For a more complete understanding of the present disclosure, examples of the various features described herein may be more readily understood by reference to the following detailed description taken in conjunction with the accompanying drawings, wherein like reference numerals denote like structural elements, wherein
[0003] Figure 1 is a block diagram of a communication network including a unified data management (UDM) node for managing mutually exclusive access for user equipment (UE) to a network slice according to an example;
[0004] Figure 2 is a flow chart of a method of managing mutually exclusive access for UEs to network slices in a communication network according to an example;
[0005] Figure 3 is a flow chart of a method of managing mutually exclusive access for UEs to network slices in a communication network according to another example;
[0006] Figure 4 is a flowchart of a method for determining whether a session registration request for a UE to access a first network slice in a communication network is allowed or denied according to an example; and
[0007] Figure 5 is a block diagram of an example UDM node comprising processing resources and a computer-readable storage medium encoded with example instructions for managing mutually exclusive access to a network slice for a UE. DETAILED DESCRIPTION
[0008] As described above, a 5G cellular network can include multiple network slices. In some examples, each network slice can support a specific use case or operate as a separate network on which services can be delivered to a subset of devices (e.g., connected vehicles, smartphones, industrial equipment, and / or any device capable of accessing the network). In an illustrative example, a 5G cellular network can provide personal phone services via a first network slice, critical services (e.g., public safety) via a second network slice, and Internet of Things (IoT) services (e.g., sensors, machines, etc.) via a third network slice.
[0009] Unlike public communication networks, private communication networks or non-public communication networks using 5G technology can provide / enable organizations to improve customization and control over their own connectivity. For example, private institutions such as colleges, large manufacturing facilities, hospitals, etc. can deploy their own 5G networks. In non-public communication networks, network resources and services associated with one or more network slices can be provided according to one or more policies. In an example, these policies can be configurable policies and customer-customized policies to support security requirements or other operational requirements. For example, in a manufacturing facility, access to a network slice configured for maintenance of industrial equipment can be restricted, while access to another network slice configured for monitoring / control of industrial equipment in a specific operating area can be restricted.
[0010] In some examples, a device may be restricted to accessing a threshold number of network slices simultaneously, which may be referred to as mutually exclusive access to network slices. Available methods for controlling mutually exclusive access to network slices may include providing or indicating to a given device which network slices it is allowed or restricted to access simultaneously. However, these methods may introduce network security flaws and may be susceptible to network tampering or other malicious or unauthorized activity.
[0011] The systems and methods disclosed herein are directed to a secure and simple method for managing mutually exclusive access to network slices in a 5G communication network. In particular, the systems and methods described herein can enable management of mutually exclusive access to network slices through a unified data management (UDM) network function of the 5G communication network. The UDM network function is a network function in the core network of a 5G communication network within the control of the operator of the 5G communication network. The UDM network function tracks a user's subscription data via a via-vis device (e.g., a smartphone, tablet computer, etc.) and manages requests from user devices to access network slices (i.e., access requests). In addition to managing access requests, the examples described herein can enable the UDM network function to manage mutually exclusive access to network slices. In this way, the systems and methods described herein can enable a single network function such as a UDM network function to provide overall management of access to network slices in a 5G communication network.
[0012] In some examples, a unified data management (UDM) node implementing a UDM network function of a 5G communication network may receive a session registration request for accessing a first network slice that a user equipment (UE) seeks to access from a session management function (SMF) node. The SMF node may implement the SMF of the 5G communication network. In response to receiving the session registration request, the UDM node may determine that a network slice access control function is applied to the UE. The network slice access control function may define a policy for accessing the first network slice. In response to determining that the network slice access control function is applied to the UE, the UDM node may determine whether the UE has an active session registration for a second network slice. In response to determining that the UE has an active session registration for the second network slice, the UDM node may selectively reject the session registration request for accessing the first network slice based on the defined policy.
[0013] The subject systems and methods will refer to Figures 1 to 4 Further description is given. It should be noted that the description and drawings, together with the examples described herein, illustrate the principles of the present subject matter only and should not be construed as limiting the present subject matter. Therefore, it should be understood that various arrangements that embody the principles of the present subject matter, although not explicitly described or shown herein, may be envisioned. Although some examples may be described herein with reference to two network slices, the examples may be used for more than two network slices. Furthermore, any function described herein as performed by a component (e.g., user equipment) or network function (e.g., SMF and UDM) in a communication network may be performed by at least one processing resource that executes instructions (stored on a computer-readable storage medium) to perform the functions described herein. Various implementations of the present subject matter are described below with reference to several examples.
[0014] For ease of explanation, the disclosure herein uses terms and names defined in standards for 5G communication networks (e.g., Third Generation Partnership Project (3GPP) specifications). However, the disclosure is not limited to these terms and names.
[0015] Figure 1 1 is a block diagram illustrating a network environment 100 for implementing the examples described herein. In one example, the network environment 100 can include at least some components of a 5G communication network. The network environment 100 can enable multiple wireless users to share resources, including wireless bandwidth, and otherwise access content, including but not limited to voice, data, video, messaging, broadcasts, and the like.
[0016] In the examples described herein, the network environment 100 may be a stand-alone non-public network (SNPN) for non-public use. Examples of SNPNs may be manufacturing sites, institutions, enterprises, and the like. The SNPN may be operated by an operator (e.g., a service provider or network operator) and may not rely on network functionality provided by a public land mobile network (PLMN) according to 3GPP specifications. The SNPN may be identified by a combination of a PLMN identifier (PLMN ID) and a network identifier (NID).
[0017] Each UE 106 in the network environment 100 can be uniquely identified, located, and tracked by a subscription permanent identifier (SUPI) or a hidden SUPI (commonly referred to as a subscription hidden identifier (SUCI)) assigned to the SIM card of the UE 106 .
[0018] The network environment 100 may include at least two component networks: a radio access network (RAN) 102 and a core network 104. The RAN 102 may allow users to connect to the core network 104 via mobile devices (also referred to herein as user equipment (UE)) 106-1, 106-2, ... 106-n (collectively, "UE 106"). Examples of UE 106 may include smartphones, tablet computers, laptop computers, vehicle-implemented communication devices, etc.
[0019] RAN 102 may include radio network resources such as cellular towers 103 that maintain network signal strength across large and small distances. In some examples, cellular towers 103 may include network nodes such as Node Bs, eNode Bs, gNBs, etc. Figure 1 In the example of FIG, gNB 103 is illustrated. Cell tower 103 may include multiple-input multiple-output (MIMO) antennas that transmit wireless signals to and / or receive wireless signals from UE 106. Although for simplicity, Figure 1 A single cellular tower 103 is shown, but the RAN 102 may include any number of cellular towers, base stations, other radio network resources such as masts, home / building-based resources, and the like.
[0020] The core network 104 may include mobile switching and data networks for managing connections made via the RAN 102. In some examples, the core network 104 may utilize network function virtualization (the instantiation of network functions (NFs) using virtual machines via the cloud) to improve response times and speed up connectivity according to specific applications, industries, or other criteria. As described above, network slicing may be used to customize support for the UE 106 based on the type of service being utilized. In an example, multiple network slices may be established in the network environment 100 for different use cases. Example use cases may include services that rely on connected vehicles, services that rely on the Internet of Things (IoT), services for mobile broadband, etc. Depending on the manner in which the multiple network slices are established in the network environment 100, a given UE 106 may request to connect to multiple network slices, for example, up to eight network slices at the same time.
[0021] The core network 104 may include certain network functions (NFs), including, for example, a core access and mobility management function (AMF) 110, a session management function (SMF) 120, and a unified data management (UDM) network function 130. Other example core networks may include a network repository function (NRF), a network slice selection function (NSSF), an authentication server function (AUSF), and / or any number of other network functions for serving the core network. Although one of each network function is shown for illustrative purposes, any number and combination of network functions may be implemented in the core network 104. Further, as described herein, in some examples, the NFs may be implemented in a single node or distributed nodes to perform their functionality.
[0022] As used herein, the term "node" may refer to one or more computing devices that are configured to emulate one or more or all of the functions described herein. As used herein, a "computing device" may be a server, a server cluster, a storage array, a computer device, a workstation, a desktop computer, a laptop computer, a switch, a router, or any other processing device or equipment that includes a processing resource. In an example, a node may include a processing resource (e.g., processing resource 134) that is communicatively coupled to at least one non-transient computer-readable storage medium (e.g., computer-readable storage medium 135), the at least one non-transient computer-readable storage medium including instructions that, when executed by the processing resource, cause the node to perform certain actions and functions as described herein.
[0023] In the examples described herein, processing resources may include, for example, one or more processors, which are included in a single computing device or are distributed across multiple computing devices. As used herein, a "processor" may be at least one of the following: a central processing unit (CPU), a semiconductor-based microprocessor, a graphics processing unit (GPU), a field programmable gate array (FPGA) configured to retrieve and execute instructions, other electronic circuit systems suitable for retrieving and executing instructions stored on a computer-readable storage medium, or a combination thereof. In the examples described herein, processing resources may retrieve, decode, and execute instructions stored on a storage medium to perform the functions described about instructions stored on a computer-readable medium. In other examples, functions related to any instruction described herein may be implemented in the form of an electronic circuit system, in the form of executable instructions encoded on a computer-readable medium, or in a combination thereof. A computer-readable storage medium may be located in a computing device that executes instructions, or away from a computing device but accessible to a computing device (e.g., via a computer network) for execution. In the examples illustrated herein, a node may be implemented by a computer-readable storage medium or multiple computer-readable storage media.
[0024] As used herein, a "computer-readable storage medium" may be any electronic storage device, magnetic storage device, optical storage device, or other physical storage device to contain or store information such as executable instructions, data, etc. For example, any computer-readable storage medium described herein may be at least one of the following: RAM, EEPROM, volatile memory, non-volatile memory, flash memory, storage drive (e.g., HDD, SSD), any type of storage disk (e.g., compact disk, DVD, etc.), etc., or a combination thereof. Further, any computer-readable storage medium described herein may be a non-transitory computer-readable storage medium.
[0025] exist Figure 1 In the example shown, the core network 104 may include an AMF node 112 that implements the AMF 110, an SMF node 122 that implements the SMF 120, and a UDM node 132 that implements the UDM network function 130. In some examples, although Figure 1 Separate nodes (i.e., AMF node 112 and SMF node 122) are shown for implementing AMF 110 and SMF 120, but AMF 110 and SMF 120 may be implemented on a single node.
[0026] The AMF node 112 may be connected to the cellular tower 103 in the RAN 102. The AMF 110 implemented on the AMF node 112 may handle connection and mobility management tasks for the UE 106. For example, the AMF 110 may be responsible for authenticating the UE 106 for accessing one or more of a plurality of network slices (e.g., handling protocol data unit (PDU) session establishment requests), forwarding session management messages (e.g., non-access stratum (NAS) messages, N2 messages), mobility management, etc.
[0027] In some examples, SMF node 122 can be connected to AMF node 112. SMF 120 implemented on SMF node 122 can configure routing of traffic in network environment 100. In some examples, SMF 120 can perform functions such as managing IP addresses and assigning them to UE 106, managing PDU session establishment requests of UE 106, controlling policy enforcement and quality of service (QoS), providing downlink data notification, etc.
[0028] The UDM node 132 may be connected to the AMF node 112 and the SMF node 122. In some examples, a UDM network function 130 implemented on the UDM node 132 may manage the user's data. The user's data may refer to data such as subscription data (e.g., SUPI and SUCI), authentication information and encryption keys for user registration information, access authentication, and network profiles of the UE 106 belonging to the user. In particular, the UDM network function 130 may generate authentication credentials for a given UE 106 based on the subscription data and authorize access to a given network slice. In an example, the UDM network function 130 may store the user's data in a unified data repository (UDR) 140. As illustrated, the UDR 140 may be implemented in a UDR node 142. In some other examples, the UDR 140 may be implemented in the UDM node 132. In addition to the user's data, the UDR 140 may include other data, such as application data, exposure data, subscription policy data, and the like.
[0029] In some examples, the functionality of the UDM network function 130 can be extended to further include a network slice access control function 133 for managing mutually exclusive access to network slices in the network environment 100. The network slice access control function 133 can control a given UE 106 from accessing two or more of the multiple network slices simultaneously. In some examples, the network slice access control function 133 can restrict (multiple) UEs 106 from accessing mutually exclusive network slices simultaneously, even if the given UE 106 is subscribed to those mutually exclusive network slices. In the examples described herein, the network slice access control function 133 can be associated with a policy 136 for managing mutually exclusive access to network slices (referred to herein as "mutually exclusive access policy 136"). In one example, a network operator can define the network slice access control function 133 within the UDM node 132 and store and / or configure the mutually exclusive access policy 136 in a computer-readable storage medium 135 of the UDM node 132. The network operator can define the network slice access control function 133 as part of a subscription setting, such as a system-level setting or a subscriber-level setting. In some examples, subscriber-level settings may override system-level settings.
[0030] The functionality of the UDM node 132 for managing mutually exclusive access to network slices in the network environment 100 may be performed by processing resources 134 of the UDM node 132 based on a mutually exclusive access policy 136 and instructions 138 stored in a computer-readable storage medium 135. Based on the subscription settings, when the UE(s) 106 seek access to a given network slice from among the plurality of network slices, the UDM node 132 may apply a network slice access control function 133 to the UE(s) 106. The network slice access control function 133 may be applied to all requests to access the network slices, resulting in some requests being allowed access to some of the network slices while some other requests being denied access to some other of the network slices.
[0031] In one example, the mutually exclusive access policy 136 may include information related to restrictions on access of (multiple) UEs 106 to certain network slices in certain scenarios. In some examples, the mutually exclusive access policy 136 may include a first policy that specifies (multiple) restricted network slices corresponding to one or more network slices. The (multiple) restricted network slices specified for a given network slice may represent (multiple) network slices that the given UE 106 cannot access when the given UE 106 accesses the given network slice. Thus, the given network slice and the corresponding restricted slices are referred to as mutually exclusive network slices. In one example, the first policy may include a first list of mutually exclusive network slices. Table 1 shows an example first list of mutually exclusive network slices. Table 1 includes restricted network slices of a network slice: slice A, slice B, and slice D in an example SNPN (identified by PLMN+NID). In Table 1, slice A, slice B, and slice D are mutually exclusive network slices. Therefore, simultaneous access to at least two of slices A, slice B, and slice D is restricted.
[0032] PLMN+NID Network slicing (Multiple) Restricted Network Slices 333+021+HPE Slice A Slice B, Slice D 333+021+HPE Slice B Slice A, Slice D 333+021+HPE Slice D Slice A, Slice B
[0033] Table 1: First example list of mutually exclusive network slices
[0034] In some examples, the mutually exclusive access policy 136 may include a second policy that specifies access to a particular network slice (referred to herein as a primary network slice) during a specific time period. For example, in a manufacturing facility, access to network slices related to maintenance activities is allowed at night (e.g., between 5 p.m. and 9 p.m.). In some examples, the second policy may include a second list of primary network slices. Table 2 shows an example second list of primary network slices, which includes primary network slices and certain time periods for accessing the primary network slices in an example SNPN. In Table 2, slice A is the primary network slice from 7 a.m. to 5 p.m. (7am to 5pm), slice B is the primary network slice from 5 p.m. to 9 p.m. (5pm to 9pm), and slice D is the primary network slice from 9 p.m. to 7 a.m. (9pm to 7am). Therefore, slice A can be accessed from 7 a.m. to 5 p.m., slice B can be accessed from 5 p.m. to 9 p.m., and slice D can be accessed from 9 p.m. to 7 a.m. In some examples, the example second list of primary network slices may also include restricted network slices for each primary network slice.
[0035] PLMN+NID Time period Main network slice 333+021+HPE 7 a.m. to 5 p.m. Slice A 333+021+HPE 5pm to 9pm Slice B 333+021+HPE 9 p.m. to 7 a.m. Slice D
[0036] Table 2: Second example list of primary network slices
[0037] In some examples, the second policy may specify access to a given primary network slice during a specific time period and restrict access to another network slice during that time period.
[0038] In some examples, the exclusive access policy 136 may include a third policy that specifies access to network slices based on priority values of the network slices. The priority value may indicate a priority for accessing a given network slice. In some examples, the exclusive access policy 136 may allow access to a network slice with a low priority value and restrict access to another network slice with a high priority value. In some examples, the third policy may include a third list of network slices with priority values. For example, Table 3 shows a third example list of network slices with priority values in an example SNPN. As shown in Table 3, the priority value of slice A is lower than the priority values of slices B and slice D. Therefore, since slice A has a lower priority value compared to the priority values of slices B and slice D, access to slice A may be allowed. In this case, if a given UE 106 seeks access to slice A while accessing slice B, slice B will be disconnected, and access to slice A will be allowed after slice B is disconnected.
[0039] PLMN+NID Priority value Network slicing 333+021+HPE 1 Slice A 333+021+HPE 2 Slice B 333+021+HPE 5 Slice D
[0040] Table 3: Third example list of network slices with priority values
[0041] In order to receive services in the network environment 100, a given UE 106 (e.g., UE 106-1) may obtain authorization to allow mobility tracking and data reception. To this end, the AMF 110 may register the UE 106-1 in the network environment 100 via a registration procedure.
[0042] Once UE 106-1 is registered, UE 106-1 may initiate a protocol data unit (PDU) session establishment procedure to access one of the multiple network slices in network environment 100. A PDU session may refer to a logical connection between a device (e.g., UE 106-1) and a data network. A PDU session may be associated with a particular network slice. The PDU session establishment corresponding to the PDU session may allow data transfer in the network slice associated with the PDU session. In one example, a device may request multiple PDU sessions associated with different network slices. In one example, UE 106-1 may initiate a first PDU session establishment procedure to access a first network slice of network environment 100. The first PDU session establishment procedure may be initiated by transmitting a non-access stratum (NAS) message containing a first PDU session establishment request. In some examples, the NAS message may include single network slice selection assistance information (S-NSSAI) for the first network slice, a PDU session identifier of the first PDU session establishment request (referred to herein as the "first PDU session ID"), and a request type. As used herein, the term "S-NSSAI" is an identifier for a network slice in a 5G communication network. The request type may indicate an initial request or an existing request, as described in the 3GPP specifications. The NAS message sent by UE 106-1 may be encapsulated by RAN 102 in an N2 message sent to AMF node 112. The N2 message may also include location information (i.e., user location information) of UE 106-1.
[0043] The AMF node 112 may receive an N2 message including a NAS message and user location information from the RAN 102. The AMF node 112 may determine that the NAS message corresponds to a first PDU session establishment request based on the request type and the S-NSSAI of the first network slice. As described in the 3GPP specification, the AMF node 112 may forward the first PDU session establishment request (indicated by the dashed arrow 114) to the SMF node 122. In one example, the AMF node 112 may forward the first PDU session establishment request along with the SUPI, the S-NSSAI of the first network slice, the first PDU session ID, the AMF ID of the AMF node 112, the user location information, an identification of the network (PLMN ID and NID), etc.
[0044] In response to receiving the first PDU session establishment request from the AMF node 112, the SMF node 122 may send a session registration request (referred to herein as a first SMF session registration request and indicated by a dotted arrow 124) including the first PDU session establishment request. The first SMF session registration request may also include the SUPI, the S-NSSAI of the first network slice, the PLMN ID and NID, the first PDU session ID, the user location information, and the SMF ID of the SMF node 122. The SMF node 122 may send the first SMF session registration request to the UDM node 132 to verify the first PDU session establishment request.
[0045] In response to receiving the first SMF session registration request, the UDM node 132 may retrieve subscription data for the UE 106-1 from the UDR 140. The subscription data for the UE 106-1 may be retrieved using the SUPI. Once the UDM node 132 successfully retrieves the subscription data for the UE 106-1, the UDM node 132 may perform several functionalities for managing mutually exclusive access to network slices in the network environment 100. In the example described herein, the UDM node 132 may determine whether the UE 106-1 may access the first network slice based on a mutually exclusive access policy 136 in order to manage mutually exclusive access to the network slices. In the example, the functionality performed by the UDM node 132 may be performed by a processing resource 134 that executes instructions 138 stored in a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) 135. hereinafter with the aid of Figure 2 、 Figure 3 and Figure 4 A flowchart is provided to describe the functionality performed by the UDM node 132 for managing mutually exclusive access to network slices.
[0046] Figure 2 and Figure 3 Flowcharts depict example methods 200 and 300 for managing mutually exclusive access to network slices in a network environment 100. In particular, Figure 2 and Figure 3 Flowcharts depict example methods 200 and 300 for determining that a UE (e.g., UE 106-1) can access a given network slice (e.g., a first network slice) when the UDM node 132 receives a session registration request (e.g., a first SMF session registration request) from the SMF node 122 for accessing the first network slice. Figure 2 and Figure 3 The example methods 200 and 300 of FIG. 1 and 2 show a specific order for performing certain functions, but the methods are not limited to such order. For example, the functionality shown in sequence in the flowcharts may be performed in a different order, may be performed concurrently, may be partially concurrently, or a combination thereof.
[0047] exist Figure 2 , according to an example, a flowchart depicting an example method 200 for managing mutually exclusive access to network slices in the network environment 100 is presented. In an example, the example method 200 may be performed by the UDM node 132, and specifically, by the processing resources 134 of the UDM node 132.
[0048] At block 202, the UDM node 132 may receive a first SMF session registration request from the selected SMF node 122. The first SMF session registration request may correspond to a first PDU session establishment request of the UE 106-1 to access the first network slice, as described above.
[0049] At block 204, the UDM node 132 may determine that the network slice access control functionality 133 is applied to the UE 106-1. In an example, the UDM node 132 may retrieve subscription data of the UE 106-1 from the UDR 140 and determine that the network slice access control functionality 133 is applied to the UE 106-1 based on the retrieved subscription data.
[0050] At block 206, UDM node 132 may perform a check to determine whether UE 106-1 has an active session registration for the second network slice. An active session registration may refer to an SMF session registration (e.g., a second SMF session registration) to access the second network slice that was being used when the first SMF session registration request was received. In an example, UE 106-1 may access the second network slice when UDM node 132 receives the first SMF registration request. In some examples, UDM node 132 may have registered the second SMF session registration after verifying that UE 106-1 may access the second network slice based on exclusive access policy 136.
[0051] To determine whether UE 106-1 has an active session registration, UDM node 132 may retrieve subscription data for UE 106-1 from UDR 140 and determine whether the subscription data may include information related to any active session registrations. In some examples, the absence of any active session registrations in the subscription data may indicate that UE 106-1 is not connected to the second network slice. In some examples, the presence of any active session registrations in the subscription data may indicate that UE 106-1 has an active session registration for the second network slice and is connected to the second network slice.
[0052] In this manner, at block 206, if it is determined that UE 106-1 does not have any active session registrations, UDM node 132 may allow the first SMF session registration request at block 208. In these examples, UDM node 132 may perform the first SMF session registration corresponding to the first SMF session registration request and store information related to the first SMF session registration in UDR 140.
[0053] At block 206, if it is determined that UE 106-1 has an active session registration, UDM node 132 may selectively deny the first SMF session registration request based on the exclusive access policy 136 at block 210. As used herein, the term "selectively deny" may mean that UDM node 132 determines whether to deny the first SMF session registration request for access to the first network slice based on the exclusive access policy 136. In some examples, UDM node 132 may determine whether to allow or restrict access to the first network slice based on the exclusive access policy 136, and thus may allow or deny the first SMF session registration.
[0054] Steering Figure 3 According to another example, a flowchart depicting an example method 300 for managing mutually exclusive access to network slices in the network environment 100 is presented. In one example, the example method 300 may be performed by the UDM node 132, and specifically, by the processing resources 134 of the UDM node 132. Figure 3 The example method 300 includes Figure 2 Some method blocks are similar to one or more method blocks described herein, and for the sake of brevity, the details of these method blocks are not repeated herein. By way of example, Figure 3 Box 302, box 304, box 306 and box 308 are respectively Figure 2 Box 202 , box 204 , box 206 , and box 208 are similar.
[0055] At block 302, the UDM node 132 may receive a first SMF session registration request from the SMF node 122. At block 304, the UDM node 132 may determine that the network slice access control function 133-1 is applied to the UE 106. At block 306, the UDM node 132 may perform a check to determine whether the UE 106-1 has an active session registration for the second network slice. At block 306, if it is determined that the UE 106-1 does not have any active session registration, the UDM node 132 may allow the first SMF session registration request at block 308.
[0056] At block 306, if it is determined that UE 106-1 has an active session registration for the second network slice, UDM node 132 may perform a check at block 310 to determine whether to allow access to the first network slice based on mutual exclusion policy 136. To determine whether to allow access to the first network slice, UDM node 132 may apply mutual exclusion access policy 136. In some examples, UDM node 132 may apply at least a first policy, a second policy, or a third policy of mutual exclusion access policy 136.
[0057] In this manner, at block 310, if it is determined that access to the first network slice is allowed, the UDM node 132 may deregister the active session registration for the second network slice to disconnect the second network slice of the UE 106-1 at block 312. The method 300 may then proceed to block 308. At block 308, the UDM node 132 may allow the first session registration request after deregistering the active session registration.
[0058] Referring again to box 310, at box 310, if it is determined that access to the first network slice is not allowed, at box 314, the UDM node 132 can reject the first SMF session registration request.
[0059] refer to Figure 4 In some examples, a flowchart depicting an example method 400 for determining whether to allow or restrict access to a first network slice is presented. In some examples, Figure 4 The example method 400 depicts performing Figure 3 In an example, the example method 400 may be performed by the UDM node 132, and in particular, by the processing resources 134 of the UDM node 132. Figure 4 The example method 400 may include Figure 3 Some method blocks are similar to one or more method blocks described herein, and for the sake of brevity, the details of these method blocks are not repeated herein. By way of example, Figure 4 Box 406, box 410 and box 412 are respectively Figure 3 Box 312, box 308 and box 314 are similar.
[0060] In some examples, the UDM node 132 may determine whether to allow or restrict access to the first network slice based on a first policy of the mutually exclusive access policy 136. At block 402, the UDM node 132 may perform a check to determine whether the first network slice and the second network slice are mutually exclusive based on the first policy (as shown in Table 1). At block 402, if it is determined that the first network slice and the second network slice are mutually exclusive, the UDM node 132 may determine that access to the first network slice is not allowed. The method 400 then proceeds to block 412. At block 412, the UDM node 132 may deny the first SMF session registration request for accessing the first network slice.
[0061] Referring again to block 402, if it is determined that the first network slice and the second network slice are not mutually exclusive, the UDM node 132 may determine that access to the first network slice is allowed. The method 400 may then proceed to block 410. At block 410, the UDM node 132 may allow the first SMF session registration request for access to the first network slice.
[0062] In some examples, the UDM node 132 may determine whether to allow or restrict access to the first network slice based on a second policy of the mutually exclusive access policy 136. At block 404, the UDM node 132 may perform a check to determine whether the first network slice is a primary network slice at a point in time based on a second policy (e.g., Table 2). At block 404, if it is determined at that point in time that the first network slice is the primary network slice, the UDM node 132 may determine that access to the first network slice is allowed. In some examples, if the second network slice and the second network slice are mutually exclusive, at block 408, the UDM node 132 may deregister the active session registration to disconnect the second network slice for the UE 106-1 and proceed to block 410. At block 410, the UDM node 132 may allow the first SMF session registration request for access to the first network slice after deregistering the active session registration.
[0063] Referring again to block 404, if it is determined at that point in time that the first network slice is not the primary network slice, the UDM node 132 may determine that access to the first network slice is not permitted. The method 400 may then proceed to block 412. At block 412, the UDM node 132 may deny the first SMF session registration request for access to the first network slice.
[0064] In some examples, the UDM node 132 may determine whether to allow or restrict access to the first network slice based on a third policy of the mutually exclusive access policy 136. At block 406, the UDM node 132 may perform a check to determine whether the priority value of the first network slice is lower than the priority value of the second network slice based on the third policy (e.g., Table 3). At block 406, if it is determined that the priority value of the first network slice is lower than the priority value of the second network slice, the UDM node 132 may determine that access to the first network slice is allowed. The method 400 may then proceed to block 408. At block 408, the UDM node 132 may deregister the active session registration to disconnect the second network slice of the UE 106-1, and at block 410, allow the first SMF session registration request for access to the first network slice after deregistering the active session registration.
[0065] Referring again to 406, if it is determined that the priority value of the first network slice is higher than the priority value of the second network slice, the UDM node 132 may determine that access to the first network slice is not allowed. The method 400 may then proceed to block 412. At block 412, the UDM node 132 may deny the first SMF session registration request for access to the first network slice.
[0066] As described, if the UDM node 132 determines that access to the first network slice is allowed based on the mutually exclusive access policy 136, the UDM node 132 may allow the first SMF session registration request. On the other hand, if the UDM node 132 determines that access to the first network slice is not allowed based on the mutually exclusive access policy 136, the UDM node 132 may reject the first SMF session registration request. In this manner, the UDM node 132 may selectively reject the first SMF session registration request based on the mutually exclusive access policy 136.
[0067] In some examples, when the UDM node 132 rejects the first SMF session registration request, the SMF node 122 may reject the first PDU session establishment request for accessing the first network slice. In other cases, when the UDM node 132 allows the first SMF session registration request, the SMF node 122 may allow the first PDU session establishment request for accessing the first network slice.
[0068] In some examples, UDM node 132 may determine whether to allow or restrict access to the first network slice based on a combination of at least two of the first policy, the second policy, and the third policy.
[0069] Figure 5 is a block diagram of a computing device 500 including processing resources 502 and computer-readable storage media 504 utilizing a method for managing a communication network (e.g., Figure 1 A given UE (e.g., Figure 1 1) encodes example instructions for mutually exclusive access of a network slice by a UE 106-1 in the network. The computer-readable storage medium 504 may be a non-transitory computer-readable storage medium and alternatively referred to as a non-transitory computer-readable storage medium 504. As described in detail herein, the computer-readable storage medium 404 may be encoded with executable instructions 506, 508, 510, and 512 (hereinafter collectively referred to as instructions (506-512)) for managing mutually exclusive access of a network slice by a UE 106-1.
[0070] In some examples, computer-readable storage medium 504 can be accessed by processing resource 502. In some examples, computing device 500 can be included in a UDM node (e.g., Figure 1 In some examples, processing resource 502 may represent an example of processing resource 134 of UDM node 132. Additionally, computer-readable storage medium 504 may represent an example of computer-readable storage medium 135 of UDM node 132. In some examples, processing resource 502 may retrieve, decode, and execute commands for executing Figure 2 Instructions 506 through 512 stored in the computer-readable storage medium 504 may be executed by one or more of the method blocks of the example method 200. Although not shown, in some examples, without limiting the scope of the present disclosure, the computer-readable storage medium 504 may be encoded with certain additional executable instructions to perform the following steps: Figure 3 Example method 300 and / or Figure 4 One or more of the method blocks of the example method 400 and / or any other operations performed by the UDM node 132 .
[0071] Instructions 506, when executed by processing resource 502, may cause processing resource 502 to receive a first SMF session registration request from selected SMF node 122, the first SMF session registration request corresponding to a first PDU session establishment request for UE 106-1 to access a first network slice. Furthermore, instructions 508, when executed by processing resource 502, may cause processing resource 502 to determine, in response to receiving the first SMF session registration request from the SMF, that network slice access control function 133 is applied to UE 106-1. Furthermore, instructions 510, when executed by processing resource 502, may cause processing resource 502 to determine, in response to determining that network slice access control function 133 is applied to UE 106-1, whether UE 106-1 has an active session registration for a second network slice. In some examples, UDM node 132 may determine that UE 106-1 has an active session registration for the second network slice. In addition, the instructions 512, when executed by the processing resource 502, may cause the processing resource 502 to selectively reject the first SMF session registration request based on the exclusive access policy 136 in response to determining that the UE 106-1 has an active session registration for the second network slice.
[0072] In the examples described herein, functions described as being performed by "instructions" may be understood as functions that may be performed by those instructions when executed by a processing resource. In other examples, the functionality described with respect to instructions may be implemented by one or more modules, which may be any combination of hardware and programming to implement the functionality of the module(s).
[0073] For the purpose of illustration and description, the foregoing description of various examples has been presented. The foregoing description is not intended to be exhaustive or limiting of the disclosed examples, and modifications and variations may be made in accordance with the above teachings, or modifications and variations may be obtained from the practice of the various examples. The examples discussed herein are selected and described to explain the principles and properties of the various examples of the present disclosure and their practical applications, so that those skilled in the art can utilize the present disclosure and various modifications as appropriate for the intended specific use in various examples. The features of the examples described herein may be combined in all possible combinations of methods, devices, modules, systems, and computer program products, except for combinations in which at least some of such features are mutually exclusive.
Claims
1. A method for communication, comprising: Receiving, by a UDM node implementing a unified data management (UDM) network function, from a session management function (SMF) node, a session registration request for accessing a first network slice of a communication network that a user equipment (UE) seeks to access; Determining, by the UDM node, that a network slice access control function is applied to the UE; In response to determining that the network slice access control function is applied to the UE, determining, by the UDM node, whether the UE has an active session registration for a second network slice in the communications network; as well as In response to determining that the UE has the active session registration for the second network slice, selectively rejecting, by the UDM node, the session registration request based on a combination of a first network slice access control policy and a second network slice access control policy, wherein the first network slice access control policy specifies a restricted network slice corresponding to one or more network slices, wherein the second network slice access control policy specifies different primary network slices for different time periods, and wherein selectively rejecting the session registration request comprises: In response to determining that the first network slice and the second network slice are mutually exclusive based on the first network slice access control policy, determining, by the UDM node, whether the first network slice is a primary network slice based on the second network slice access control policy and an instantaneous time; as well as In response to determining that the first network slice is the primary network slice, deregistering the active session registration for the second network slice, and allowing the session registration request after deregistering the active session registration.
2. The method according to claim 1, wherein the session registration request corresponds to a protocol data unit (PDU) session registration request from the UE for accessing the first network slice.
3. The method according to claim 1, further comprising: In response to determining that the first network slice and the second network slice are not mutually exclusive based on the first network slice access control policy, allowing the session registration request.
4. The method of claim 1 , wherein the session registration request is rejected in response to determining that the first network slice is not the primary network slice.
5. The method according to claim 1, further comprising: In response to determining that the UE has the active session registration for the second network slice, selectively rejecting, by the UDM node, the session registration request based on a combination of the first network slice access control policy, the second network slice access control policy, and a third network slice access control policy, wherein the third network slice access control policy specifies a priority value associated with one or more network slices, and wherein selectively rejecting the session registration request comprises: In response to determining that the first network slice and the second network slice are mutually exclusive based on the first network slice access control policy and the second network slice access control policy, determining, by the UDM node based on the third network slice access control, whether the priority value of the first network slice is lower than the priority value of the second network slice; In response to determining that the priority value of the first network slice is lower than the priority value of the second network slice, deregistering, by the UDM node, the active session registration for the second network slice; and After deregistering the active session registration, the session registration request is allowed by the UDM node.
6. The method of claim 5, wherein the session registration request is rejected in response to determining that the priority value of the first network slice is not lower than the priority value of the second network slice.
7. A UDM node for implementing a unified data management (UDM) network function in a communication network, comprising: Processing resources; as well as A computer-readable storage medium comprising instructions that, when executed by the processing resource, cause the processing resource to: receiving, from a session management function (SMF) node, a session registration request for accessing a first network slice of the communications network to which a user equipment (UE) seeks access; Determining that a network slice access control function is applied to the UE; In response to determining that the network slice access control function is applied on the UE, determining whether the UE has an active session registration for a second network slice in the communications network; as well as In response to determining that the UE has the active session registration for the second network slice, selectively denying the session registration request for accessing the first network slice based on a combination of a first network slice access control policy and a second network slice access control policy, wherein the first network slice access control policy specifies a restricted network slice corresponding to one or more network slices, wherein the second network slice access control policy specifies different primary network slices for different time periods, and wherein selectively denying the session registration request comprises: In response to determining that the first network slice and the second network slice are mutually exclusive based on the first network slice access control policy, determining whether the first network slice is a primary network slice based on the second network slice access control policy and an instantaneous time; as well as In response to determining that the first network slice is the primary network slice, deregistering the active session registration for the second network slice, and allowing the session registration request after deregistering the active session registration.
8. The UDM node according to claim 7, wherein the session registration request corresponds to a protocol data unit (PDU) session registration request from the UE for accessing the first network slice.
9. The UDM node of claim 8, wherein the instructions include instructions for performing the following: In response to determining that the UE has the active session registration for the second network slice, selectively rejecting the session registration request based on a combination of the first network slice access control policy, the second network slice access control policy, and a third network slice access control policy, wherein the third network slice access control policy specifies a priority value associated with one or more network slices, and wherein selectively rejecting the session registration request comprises: In response to determining that the first network slice and the second network slice are mutually exclusive based on the first network slice access control policy and the second network slice access control policy, determining whether the priority value of the first network slice is lower than the priority value of the second network slice based on the third network slice access control policy; In response to determining that the priority value of the first network slice is lower than the priority value of the second network slice, deregistering the active session registration for the second network slice; as well as After deregistering the active session registration, allowing the session registration request for accessing the first network slice.
10. The UDM node of claim 9, wherein the instructions include instructions for performing the following: In response to determining that the priority value of the first network slice is not lower than the priority value of the second network slice, rejecting the session registration request.
11. The UDM node of claim 7, wherein the instructions include instructions for performing the following: in response to determining that the first network slice and the second network slice are mutually exclusive based on the first network slice access control policy, rejecting the session registration request.
12. The UDM node of claim 7, wherein the instructions include instructions for performing the following: In response to determining that the first network slice is not the primary network slice, rejecting the session registration request.
13. A non-transitory computer-readable storage medium comprising instructions that, when executed by a processing resource of a Unified Data Management (UDM) node implementing a Unified Data Management (UDM) network function in a communication network, cause the processing resource to: receiving, from a session management function (SMF) node, a session registration request for accessing a first network slice of a communication network that a user equipment (UE) seeks to access; Determining that a network slice access control function is applied to the UE; In response to determining that the network slice access control function is applied on the UE, determining whether the UE has an active session registration for a second network slice in the communications network; as well as In response to determining that the UE has the active session registration for the second network slice, determining whether the session registration request for accessing the first network slice is allowed based on a combination of a first network slice access control policy and a second network slice access control policy, wherein the first network slice access control policy specifies a restricted network slice corresponding to one or more network slices, wherein the second network slice access control policy specifies different primary network slices for different time periods, and wherein determining whether the session registration request for accessing the first network slice is allowed includes: In response to determining that the first network slice and the second network slice are mutually exclusive based on the first network slice access control policy, determining, by the UDM node, whether the first network slice is a primary network slice based on the second network slice access control policy and an instantaneous time; In response to determining that the first network slice is the primary network slice, determining that the session registration request is allowed; and In response to determining that the first network slice is not the primary network slice, determining that the session registration request is not allowed.
14. The non-transitory computer-readable storage medium of claim 13, wherein the instructions include instructions for: In response to determining that the UE has the active session registration for the second network slice, determining whether the session registration request for accessing the first network slice is allowed based on a combination of the first network slice access control policy, the second network slice access control policy, and a third network slice access control policy, wherein the third network slice access control policy specifies a priority value associated with one or more network slices, and wherein determining whether the session registration request for accessing the first network slice is allowed comprises: In response to determining that the first network slice and the second network slice are mutually exclusive based on the first network slice access control policy and the second network slice access control policy, determining whether the priority value of the first network slice is lower than the priority value of the second network slice based on the third network slice access control policy; In response to determining that the priority value of the first network slice is lower than the priority value of the second network slice, determining that the session registration request is allowed; as well as In response to determining that the priority value of the first network slice is not lower than the priority value of the second network slice, determining that the session registration request is not allowed.
Citation Information
Patent Citations
SMF Selection for Isolated Network Slice
US20190159015A1
Radio resource management configuration device and method
US20190223088A1