Network Slicing Determination Method, System, Network Device, and Storage Medium

By using a security identifier generated by the PCF to associate APP IDs with S-NSSAI, the method ensures secure and efficient network slice access, preventing unauthorized applications from accessing network slices and maintaining differentiated service delivery.

CN115913964BActive Publication Date: 2025-07-15CHINA TELECOM CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211367324.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-02
Publication Date
2025-07-15
Estimated Expiration
2042-11-02

AI Technical Summary

Technical Problem

In the prior art, since the application ID (APP ID) is not a security identifier, it is easily tampered with by malicious applications, resulting in non-contracted applications transmitting traffic within the network slice, destroying the operator's differential service guarantee mechanism.

Method used

Introduce security identifiers, generate the correspondence between the application APP ID and the slice identifier S-NSSAI through the policy control function (PCF) network element, establish a preset NSSP policy, and the user equipment determines the network slices to which the target application should access based on the security identifier.

Benefits of technology

It realizes APP-level slice secure transmission, prevents access to non-contracted applications, improves network slice detection efficiency, and ensures that operators provide differentiated service guarantees for contracted applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913964B_ABST
    Figure CN115913964B_ABST
Patent Text Reader

Abstract

The present disclosure is about a network slice determination method, system, network device and storage medium, and relates to the field of communication technology. The method includes: when the target application APP initiates an access request, the user equipment UE determines the slice identifier S-NSSAI of the target network slice that the target application APP should access from the preset NSSP policy based on the application APP ID and the corresponding security identifier carried in the access request. The security identifier is generated by the policy control function PCF network element according to the slice signing request of the application server. The preset NSSP policy is used to characterize the correspondence between the application APP ID, the security identifier and the slice identifier S-NSSAI. The user equipment UE forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI. In this way, by adding a security identifier, the NSSP policy enhancement in the URSP rule is realized, ensuring that the contracted APP can access the corresponding slice, preventing the non-contracted APP from accessing the corresponding slice, and realizing the APP-level slice security transmission and detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of communication technologies, and in particular, to a method, a system, a network device, and a storage medium for determining a network slice. Background Art

[0002] In the network slice selection policy (NSSP) of the user equipment routing selection rule (URSP), the terminal is specified to use the application identifier (APP ID) to map to the accessed network slice (NS), that is, in the terminal, according to the correspondence between the APP ID and the single network slice selection assistance information (S-NSSAI) in the NSSP policy, the accessed network slice is selected for the APP. However, since the APP ID is not a security identifier and is filled in by the APP or service on the terminal, there will be problems such as APP ID impersonation. For example, if the UE downloads a second application program (possibly a malicious APP) in different application stores and has the same APP ID as the first application program, the traffic will be transmitted according to the slice corresponding to the first application program according to the NSSP policy in the URSP rule in the terminal. This may disrupt the operator network's differential service guarantee mechanism for signed and unsigned APPs through network slices.

[0003] However, since the APP ID is not a security identifier and is filled in by the APP or service on the terminal, there will be problems such as APP ID impersonation, that is, malicious applications tamper with the APP ID information, resulting in unsigned APPs transmitting traffic within the slice.

[0004] It should be noted that the information disclosed in the above background art is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] To overcome the problems existing in the related art, the present disclosure provides a method, a system, a network device, and a storage medium for determining a network slice.

[0006] According to an aspect of the present disclosure, a method for determining a network slice is provided, and the method includes:

[0007] When the target application APP initiates an access request, the user equipment UE determines the slice identifier S-NSSAI of the target network slice to which the target application APP should be connected from a preset NSSP policy based on the application APPID carried in the access request and the corresponding security identifier; the security identifier is generated by the policy control function PCF network element according to the slice subscription request of the application server, and the preset NSSP policy is used to represent the corresponding relationship between the application APP ID, the security identifier, and the slice identifier S-NSSAI;

[0008] The user equipment UE forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI.

[0009] Optionally, the method further includes:

[0010] In response to the network slice subscription request of the application server for the target application APP, the PCF network element performs a network slice instantiation operation and determines the slice identifier S-NSSAI of the target network slice to which the target application APP should be connected and the security identifier corresponding to the application APP ID based on the network slice subscription related information;

[0011] The PCF network element returns the application APP ID and the corresponding security identifier to the application server.

[0012] Optionally, the method further includes:

[0013] The PCF network element establishes the preset NSSP policy based on the corresponding relationship between the application APP ID, the security identifier, and the slice identifier S-NSSAI.

[0014] Optionally, the method further includes:

[0015] The PCF issues the preset NSSP policy to the user equipment UE.

[0016] Optionally, the method further includes:

[0017] The user equipment UE detects whether the security identifier carried in the access request or access traffic of the target application APP is valid information according to the preset NSSP policy issued by the PCF network element;

[0018] If the security identifier is the valid information, perform the operation that the user equipment UE determines the target slice S-NSSAI to which the access traffic of the target application APP should be connected from the preset NSSP policy based on the application APP ID and the corresponding security identifier;

[0019] If the security identifier is not the valid information or there is no security identifier, the user equipment UE rejects the target application APP from accessing traffic to the target slice S-NSSAI.

[0020] According to one aspect of the present disclosure, a network slice determination system is provided, which includes:

[0021] A user equipment UE, when a target application APP initiates an access request, determines a slice identifier S-NSSAI of the target application APP to access a target network slice from a preset NSSP policy based on the application APP ID and the corresponding security identifier carried in the access request; the security identifier is generated by a policy control function PCF network element according to a slice subscription request of an application server, and the preset NSSP policy is used to represent the corresponding relationship between the application APP ID, the security identifier, and the slice identifier S-NSSAI; forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI.

[0022] Optionally, the system further includes:

[0023] The PCF network element performs a network slice instantiation operation in response to a network slice subscription request of the application server for the target application APP, and determines a slice identifier S-NSSAI of the target application APP to access the target network slice and a security identifier corresponding to the application APP ID based on network slice subscription related information; returns the application APP ID and the corresponding security identifier to the application server.

[0024] Optionally, the system further includes:

[0025] The PCF network element establishes the preset NSSP policy based on the corresponding relationship between the application APP ID, the security identifier, and the slice identifier S-NSSAI.

[0026] Optionally, the system further includes:

[0027] The PCF network element distributes the preset NSSP policy to the user equipment UE.

[0028] Optionally, the system further includes:

[0029] The user equipment UE detects whether the security identifier carried in the target application APP access request or access traffic is valid information according to the preset NSSP policy issued by the PCF network element; if the security identifier is the valid information, the user equipment UE determines the target slice S-NSSAI that the target application APP access traffic should access from the preset NSSP policy based on the application APP ID and the corresponding security identifier; if the security identifier is not the valid information or there is no security identifier, the user equipment UE refuses the target application APP access traffic to access the target slice S-NSSAI.

[0030] According to one aspect of the present disclosure, a network device is provided, including:

[0031] Processor; and

[0032] A memory, configured to store executable instructions of the processor;

[0033] Wherein, the processor is configured to execute any one of the network slice determination methods described above by executing the executable instructions.

[0034] According to one aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the network slice determination method described in any one of the above is implemented.

[0035] In summary, the network slice determination method provided by the embodiment of the present invention can determine the slice identifier S-NSSAI of the target network slice that the target application APP should access from the preset NSSP policy based on the application APP ID and the corresponding security identifier carried in the access request when the target application APP initiates an access request. The security identifier is generated by the policy control function PCF network element according to the slice signing request of the application server. The preset NSSP policy is used to characterize the correspondence between the application APP ID, the security identifier and the slice identifier S-NSSAI. The user equipment UE forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI. In this way, by adding a security identifier, on the one hand, the NSSP policy in the URSP rule can be enhanced to ensure that the contracted APP can access the corresponding slice and prevent the non-contracted APP from accessing the corresponding slice, thereby realizing the APP-level slice security transmission and detection, and also preventing the operator from being unable to safely provide differentiated service guarantees for different application APPs through the contracted network slices due to the impersonation of the APP ID. On the other hand, there is no need to transmit the session request to the core network UPF, thereby improving the efficiency of network slice detection.

[0036] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present disclosure. Brief Description of the Drawings

[0037] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0038] Figure 1 Schematically showing an architecture diagram of a wireless communication system provided by an embodiment of the present disclosure;

[0039] Figure 2 Schematically showing a flowchart of steps of a method for determining a network slice provided by an embodiment of the present disclosure;

[0040] Figure 3 Schematically showing a flowchart of steps of allocating a slice identifier provided by an embodiment of the present disclosure;

[0041] Figure 4 Schematically showing a schematic diagram of a network slice determination process provided by an embodiment of the present disclosure;

[0042] Figure 5 Schematically showing a schematic diagram of network slice determination provided by an embodiment of the present disclosure;

[0043] Figure 6 Schematically showing a schematic diagram of the structure of a network device provided by an embodiment of the present disclosure. Detailed Embodiments

[0044] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present disclosure. However, those skilled in the art will realize that the technical solutions of the present disclosure can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be used. In other cases, well-known technical solutions are not shown or described in detail to avoid obscuring the various aspects of the present disclosure.

[0045] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0046] To facilitate the understanding of the technical solutions of the embodiments of the present application, a brief introduction to the related technologies of the present application is given as follows:

[0047] A network slice (NS), also known as a sliced network or simply a slice, refers to a customized different logical network on a physical or virtual network infrastructure according to the service requirements of different tenants' services. A network slice can be a complete end-to-end network including user equipment (UE), access network, transport network, core network, and service server, or it can be a complete end-to-end network including only the core network but supplemented by UE, access network, transport network, and service server, capable of providing complete communication services and having certain network capabilities. A network slice can be communication resources that ensure the bearer service or service can meet the requirements of the service level agreement, or it can be considered as a combination of network functions and communication resources required to complete a certain communication service or certain communication services. A network slice can be identified by single network slice selection assistance information (S-NSSAI). S-NSSAI consists of slice / service type (SST) and slice differentiator (SD). Among them, SST and SD can be defined by standards or customized by operators; SD is optional information to supplement SST to distinguish multiple network slices with the same SST. For example, it can be used to characterize the attribution relationship of network slices. The types and functions of NSSAI defined in the 23.501 standard are shown in Table 1 below.

[0048] Table 1

[0049]

[0050] In addition, after introducing slice authentication and authorization, there is still a pending NSSAI (which can be called pending NSSAI), and the pending NSSAI can also be called the NSSAI that needs authentication and authorization or the NSSAI to be processed. After the pending NSSAI passes authentication and authorization, it can be included in the allowed NSSAI, that is, after the pending NSSAI passes authentication and authorization, the UE is allowed to access.

[0051] Protocol data unit (PDU) session: An association that provides a PDU connection service between a UE and a data network. In a communication system (such as a 5G network or a 5G communication system), a PDU session can include one or more quality of service (QoS) flows. A QoS flow refers to a data transmission channel in which the UE meets specific QoS quality requirements in the communication system (such as within a 5G network or a 5G communication system), and can be identified by a QoS flow identity (QFI). On the UE and network sides, a PDU session can include the following attribute information: data network name (DNN), address information (such as Internet protocol (IP) address, media access control (MAC) address, etc.), S-NSSAI, service and session continuity (SSC) mode, etc. A PDU session is usually identified by a PDU session identifier, and the PDU session identifier can be assigned by the UE.

[0052] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0053] As Figure 1 shown, it is a schematic diagram of a communication system architecture provided by an embodiment of the present application. As Figure 1 shown, the communication system includes: a UE, a radio access network (RAN / AN), and a core network. Further, the communication system may also include a data network (DN), and the DN may refer to a service network that provides data transmission services for users, such as an IP multimedia service (IMS), the Internet, etc.

[0054] Among them, the UE can be a terminal equipment (TE), a handheld terminal, a laptop computer, a subscriber unit, a cellular phone, a smart phone, a wireless data card, a personal digital assistant (PDA) computer, a tablet computer, a vehicle-mounted terminal, a wearable device, a wireless modem, a handheld device, a laptop computer, a cordless phone, a wireless local loop (WLL) station, a machine type communication (MTC) terminal, or other devices that can access the network. The UE and the access network device communicate with each other using a certain air interface technology.

[0055] In addition, the access network is used to implement functions related to wireless access. The access network may include a 3rd generation partnership project (3GPP) access network and a non-3GPP access network. The access network device may refer to a device that provides access services for the UE, including RAN devices and AN devices. RAN devices are mainly wireless network devices in the 3GPP network, and AN may be an access network device defined by non-3GPP. RAN devices are mainly responsible for functions such as radio resource management on the air interface side, quality of service (QoS) management, data compression, and encryption. RAN devices may include various forms of base stations, such as: macro base stations, micro base stations (also known as small stations), relay stations, access points, etc. In systems adopting different radio access technologies, the names of devices with base station functions may be different. For example, in the 5th generation (5G) system, it is called RAN or gNB (5G NodeB); in the LTE system, it is called evolved NodeB (eNB or eNodeB); in the 3rd generation (3G) system, it is called Node B, etc. AN devices allow the UE and the 3GPP core network to interconnect using non-3GPP technologies. Among them, non-3GPP technologies include, for example, wireless fidelity (Wi-Fi), worldwide interoperability for microwave access (WiMAX), code division multiple access (CDMA) networks, etc.

[0056] Furthermore, the core network may include the following logical network elements: session management function (SMF) network element, access and mobility management function (AMF) network element, authentication server function (AUSF) network element, user plane function (UPF) network element, application function (AF) network element, unified data management (UDM) network element, policy control function (PCF) network element, network repository function (NRF) network element, network exposure function (NEF) network element, network slice selection function (NSSF) network element, etc. The functions of different core network elements are introduced and described separately as follows.

[0057] SMF network element: A core network control plane network element, mainly responsible for session management in the mobile network, such as session establishment, modification, and release; specific functions include allocating IP addresses for users, selecting UPFs that provide packet forwarding functions, etc.

[0058] AMF network element: A core network control plane network element, mainly responsible for mobility management in the mobile network, such as user location update, user registration to the network, user handover, etc.

[0059] AUSF network element: A core network control plane network element provided by the operator, used to perform authentication, such as performing authentication of its subscribed users by the 3GPP network.

[0060] UPF network element: A core network user plane network element, responsible for forwarding and receiving user data in the UE. It can receive user data from the DN and transmit it to the UE through the access network device; the UPF network element can also receive user data from the UE through the access network device and forward it to the DN.

[0061] AF network element: Mainly supports interacting with the 3GPP core network to provide services, such as influencing data routing decisions, policy control functions, or providing some third-party services to the network side.

[0062] UDM Network Element: A core network control plane network element used to store user subscription data, generate authentication credentials, handle user identification (such as storing and managing the user's permanent identity, etc.), access authorization control, and subscription data management, etc.

[0063] PCF Network Element: A core network control plane network element that mainly supports providing a unified policy framework to control network behavior, providing policy rules to control layer network functions, and is also responsible for obtaining user subscription information related to policy decisions.

[0064] NRF Network Element: A core network control plane network element used to support service discovery functions, and can also be used to maintain information about available network function network elements and the services they support, etc.

[0065] NEF Network Element: A core network control plane network element mainly responsible for the external exposure of mobile network capabilities.

[0066] NSSF Network Element: A core network control plane network element mainly used for 5G slice services. For example, it is responsible for the selection of target network slice instances (NSIs). Optionally, the NSSF network element can also be replaced by a network slice specific authentication and authorization function (NSSAAF) network element.

[0067] Optionally, in order to implement functions related to authentication and authorization for slices, a network slice specific authentication and authorization function (NSSAAF) network element can be introduced.

[0068] In Figure 1 In the communication system shown, the UE can communicate with the AMF network element through the N1 interface, the R(AN) device can communicate with the AMF network element through the N2 interface, the R(AN) device can communicate with the UPF network element through the N3 interface, and the UPF network element can communicate with the DN through the N4 interface. In addition, the network elements in the core network can communicate through service-based interfaces. For example, the service-based interfaces can include: Nnssf interface, Nnef interface, Nnrf interface, Npcf interface, Nudm interface, Naf interface, Nausf interface, NAMF interface, and Nnsm interface, etc. It can be understood that in the above Figure 1 In the communication system shown, the functions and interfaces of each network element are only exemplary, and not all functions are necessary when each network element is applied to the embodiments of the present application.

[0069] Further, in the present application, the communication system may also include: an authentication, authorization and accounting (AAA) server, and the AAA server (server) may also be referred to as AAA-S. AAA-S may communicate with the AMF network element through an intermediate network element that supports communication between AAA-S and the AMF network element, and the intermediate network element may be an AUSF network element, a NEF network element, an NSSAAF network element, or other network elements used for authentication and authorization processes, etc. Optionally, the communication system may also include: an authentication, authorization and accounting proxy (AAA-P). When AAA-S communicates with the AMF network element, AAA-S may first communicate with AAA-P, and AAA-P sends the communication information of AAA-S to the AMF network element through intermediate network elements such as AUSF network elements, NEF network elements, or NSSAAF network elements; similarly, the AMF network element sends the communication information to AAA-P through intermediate network elements such as AUSF network elements, NEF network elements, or NSSAAF network elements, and AAA-P sends it to AAA-S.

[0070] Figure 2 A flowchart of a method for determining a network slice provided by an embodiment of the present disclosure is schematically shown. Figure 2 As shown, the method may include:

[0071] Step S101: When the target application APP initiates an access request, the user equipment UE determines from the preset NSSP policy the slice identifier S-NSSAI of the target network slice that the target application APP should access based on the application APP ID and the corresponding security identifier carried in the access request; the security identifier is generated by the policy control function PCF network element according to the slice signing request of the application server, and the preset NSSP policy is used to characterize the correspondence between the application APP ID, the security identifier and the slice identifier S-NSSAI.

[0072] In the embodiment of the present disclosure, when the application service provider develops an application, a unique application APPID will be set for each application. In order for the application to be able to be used normally on the Internet, the application service provider can also send a network slice contract application for the application to the policy control function PCF network element. Accordingly, the PCF network element can return the access slice information assigned to the application and the security identifier corresponding to the application. Therefore, the user equipment UE downloads or updates to the target application APP from the application server, and the target application APP carries the application APP ID and the corresponding security identifier. Among them, the security identifier can be determined by the PCF network element for the target application APP. The security identifier can be generated according to the application APP ID slice application time source, or it can be generated according to the message authentication code (Message Authentication Code, MAC), or it can be a random number set according to other conditions, and this disclosure does not limit this.

[0073] In the disclosed embodiment of the present invention, when the target application APP initiates an access request, that is, the target application APP initiates a networking request, the user equipment UE can determine the target slice identifier S-NSSAI that the target application APP should access from the preset NSSP policy based on the application APP ID and the corresponding security identifier, wherein the preset NSSP policy can be used to characterize the correspondence between the application APP ID, the security identifier and the slice identifier S-NSSAI, that is, the slice identifier that the application APP should access can be determined by searching the application APP ID and the security identifier.

[0074] Step S102: The user equipment UE forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI.

[0075] In the embodiment of the present disclosure, the target UPF network element indicated by the slice identifier S-NSSAI may be determined first, and then the user equipment UE may directly forward the access request traffic of the target application APP to the target UPF network element, so that the target application APP can access the target slice and establish a communication connection with the target UPF network element.

[0076] In summary, the network slice determination method provided by the embodiment of the present invention can determine the slice identifier S-NSSAI of the target network slice that the target application APP should access from the preset NSSP policy based on the application APP ID and the corresponding security identifier carried in the access request when the target application APP initiates an access request. The security identifier is generated by the policy control function PCF network element according to the slice signing request of the application server. The preset NSSP policy is used to characterize the correspondence between the application APP ID, the security identifier and the slice identifier S-NSSAI. The user equipment UE forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI. In this way, by adding a security identifier, on the one hand, the NSSP policy in the URSP rule can be enhanced to ensure that the contracted APP can access the corresponding slice and prevent the non-contracted APP from accessing the corresponding slice, thereby realizing the APP-level slice security transmission and detection, and also preventing the operator from being unable to safely provide differentiated service guarantees for different application APPs through the contracted network slices due to the impersonation of the APP ID. On the other hand, there is no need to transmit the session request to the core network UPF, thereby improving the efficiency of network slice detection.

[0077] Optionally, in the above-mentioned slice determination method, the embodiment of the present disclosure may include: Figure 3 As shown, it may also include:

[0078] Step S201, in response to the application server's network slice signing request for the target application APP, the PCF network element performs a network slice instantiation operation and determines, based on the network slice signing-related information, that the target application APP should access the slice identifier S-NSSAI of the target network slice and the security identifier corresponding to the application APP ID.

[0079] In the disclosed embodiment, the operator's 5G core network PCF network element may receive a network slice signing request for a target application APP sent by an application server. In response to the network slice signing request, the PCF network element instantiates the network slice and determines the network slice to which the target application APP should access. Moreover, the PCF network element generates a security identifier corresponding to the application APP ID of the target application APP based on the application APP ID of the target application APP carried in the slice signing request and the slice identifier S-NSSAI of the network slice to which the target application APP should access.

[0080] Step S202: The PCF network element returns the application APP ID and the corresponding security identifier to the application server.

[0081] In the disclosed embodiment, the PCF network element may return the security identifier corresponding to the application APP ID to the application server, so that the application server configures the security identifier into the target application APP and associates it with the application AAP ID, thereby preventing other application APPs from impersonating the APP ID.

[0082] Optionally, the network slice determination method in the embodiment of the present disclosure may further include:

[0083] The PCF network element establishes the preset NSSP policy based on the correspondence between the application APP ID, the security identifier and the target slice identifier S-NSSAI.

[0084] In the disclosed embodiment, the PCF network element may establish a corresponding relationship association table according to the application APP ID of each application APP, the corresponding security identifier, and the allocated slice identifier S-NSSAI of the network slice to be accessed, and generate a preset NSSP policy. For example, the preset NSSP policy may be represented by the content of the following Table 1: Appid1 corresponding to the target application APP1, the security identifier is identifier 1, and the allocated network slice identifier is S-NSSAI1; Appid2 corresponding to the target application APP2, the security identifier is identifier 2, and the allocated network slice identifier is S-NSSAI2.

[0085] Table 1

[0086]

[0087] Optionally, the network slice determination method in the embodiment of the present disclosure may further include:

[0088] The PCF sends the preset NSSP policy to the user equipment UE.

[0089] In the disclosed embodiment, the PCF network element may return the application ID and the corresponding security identifier of the target application APP to the application server, and the PCF network element sends the established preset NSSP policy to the UE. When the target application APP initiates an access request, the UE determines the target slice identifier S-NSSAI that the target application APP should access from the preset NSSP policy based on the application APP ID and the corresponding security identifier.

[0090] Optionally, the network slice determination method in the embodiment of the present disclosure may further include:

[0091] The user equipment UE detects whether the security identifier carried in the access request or access traffic of the target application APP is valid information according to the preset NSSP policy sent by the PCF network element; if the security identifier is the valid information, the user equipment UE performs the operation of determining the target slice S-NSSAI to which the access traffic of the target application APP should be connected from the preset NSSP policy based on the application APP ID and the corresponding security identifier; if the security identifier is not the valid information or there is no security identifier, the user equipment UE rejects the access of the access traffic of the target application APP to the target network.

[0092] In the implementation of this disclosure, the user equipment UE can detect whether the security identifier carried in the access request or access traffic of the target application APP is valid information. When the security identifier is valid information, that is, the information of the security identifier is not empty and the information of the security identifier and the associated application APP ID are consistent with those recorded in the preset NSSP policy, the user equipment UE can perform the operation of determining the target slice identifier S-NSSAI to which the target application APP should be connected from the preset NSSP policy based on the application APP ID and the corresponding security identifier; when the security identifier is not valid information, that is, the information of the security identifier is empty information, or the information of the security identifier is inconsistent with that recorded in the preset NSSP policy, or the application APP ID associated with the security identifier is inconsistent with that recorded in the preset NSSP policy, if any of the above situations occurs, the user equipment UE can reject the access request initiated by the target application APP. It should be noted that, in one implementation manner, if the security identifier is not valid information or there is no security identifier, after the user equipment UE rejects the access of the access traffic of the target application APP to the target network slice, the access traffic of the target application APP can be transferred to the default network slice, where the default network slice can be a pre-set public network slice.

[0093] Exemplarily, Figure 4 A schematic diagram showing a network slice determination process provided by an embodiment of the present disclosure is schematically shown, as Figure 4As shown in the figure, in S301, the application server develops an APP service and configures an application APP ID for the target application APP; in S302, the application server applies to the operator's PCF network element to enable a slice service for the application APP ID. For example, an acceleration slice is enabled; in S303, when the PCF network element instantiates a network slice and allocates a slice identifier S-NSSAI for the application APP ID, it can also allocate a security identifier for the target application APP; in S304, the PCF network element can generate or update a preset NSSP policy according to the correspondence between the APP ID, the APP security identifier, and the S-NSSAI; in S305, the PCF network element returns the application APP ID and the corresponding security identifier to the application service provider AF; in S306, the PCF network element distributes the preset NSSP policy to the UE; in S307, when the UE downloads or updates the target application APP, it can obtain the application APP ID of the target application APP and the corresponding security identifier; in S308, when the target application APP initiates a service request to the UE, it can carry the APP ID and the security identifier; in S309, during the session establishment process, the UE determines the network slice identifier S-NSSAI to which the target application APP should be connected according to the preset NSSP policy, and establishes a connection between the target application APP and the slice with the slice identifier S-NSSAI; in S310, the UE forwards the traffic of the application APP ID to the UPF network element corresponding to the S-NSSAI.

[0094] Exemplarily, Figure 5 Schematically shows a schematic diagram of network slice determination provided by an embodiment of the present disclosure. As Figure 5 shown, the application APP1 developed by the application server 1 and the configured application APP ID. The application server 1 applies to the PCF network element in the operator's 5G core network 42 to enable a slice service for the application APP ID. The PCF allocates a security identifier and the corresponding slice identifier S-NSSAI for the APP1, and generates or updates a preset NSSP policy according to the correspondence between the APP ID, the APP security identifier, and the S-NSSAI. The PCF distributes the preset NSSP policy to the terminal 43. During the session establishment process of the APP1, according to the preset NSSP policy, it determines the network slice identifier S-NSSAI to which the APP1 should be connected, and forwards the traffic of the APP1 to the UPF1 corresponding to the network slice identifier S-NSSAI.

[0095] A network slice determination system provided by an embodiment of the present disclosure may include:

[0096] When the target application APP initiates an access request, the user equipment UE determines from the preset NSSP policy the slice identifier S-NSSAI of the target network slice that the target application APP should access based on the application APP ID and the corresponding security identifier carried in the access request; the security identifier is generated by the policy control function PCF network element according to the slice signing request of the application server, and the preset NSSP policy is used to characterize the correspondence between the application APP ID, the security identifier and the slice identifier S-NSSAI; the access traffic of the target application APP is forwarded to the target user plane function UPF network element indicated by the slice identifier S-NSSAI.

[0097] In summary, the network slice determination system provided by the embodiment of the present invention can determine the slice identifier S-NSSAI of the target network slice that the target application APP should access from the preset NSSP policy based on the application APP ID and the corresponding security identifier carried in the access request when the target application APP initiates an access request. The security identifier is generated by the policy control function PCF network element according to the slice signing request of the application server. The preset NSSP policy is used to characterize the correspondence between the application APP ID, the security identifier and the slice identifier S-NSSAI. The user equipment UE forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI. In this way, by adding a security identifier, on the one hand, the NSSP policy in the URSP rule can be enhanced to ensure that the contracted APP can access the corresponding slice and prevent the non-contracted APP from accessing the corresponding slice, thereby realizing APP-level slice security transmission and detection, and also preventing the operator from being unable to safely provide differentiated service guarantees for different application APPs through the contracted network slices due to the impersonation of the APP ID. On the other hand, there is no need to transmit the session request to the core network UPF, thereby improving the efficiency of network slice detection.

[0098] The system further comprises:

[0099] The PCF network element, in response to the application server's slice signing request for the target application APP, performs a network slice instantiation operation and determines, based on the network slice signing related information, that the target application APP should access the slice identifier S-NSSAI of the target network slice and the security identifier corresponding to the application APP ID; and returns the application APP ID and the corresponding security identifier to the application server.

[0100] Optionally, the system further includes:

[0101] The PCF network element establishes the preset NSSP policy based on the correspondence relationship among the application APP ID, the security identifier, and the slice identifier S-NSSAI.

[0102] Optionally, the system further includes:

[0103] The PCF network element distributes the preset NSSP policy to the user equipment UE.

[0104] Optionally, the system further includes:

[0105] The user equipment UE detects whether the security identifier carried in the target application APP access request or access traffic is valid information according to the preset NSSP policy distributed by the PCF network element; if the security identifier is the valid information, the user equipment UE performs the operation of determining the target slice S-NSSAI to which the target application APP access traffic should be connected from the preset NSSP policy based on the application APP ID and the corresponding security identifier; if the security identifier is not the valid information or there is no security identifier, the user equipment UE rejects the access of the target application APP access traffic to the target slice S-NSSAI and may transfer the target application APP access traffic to the default network slice.

[0106] The specific details of each network element or device in the above network slice determination system have been described in detail in the corresponding network slice determination method, so they will not be elaborated here.

[0107] It should be noted that although several modules or units of the devices for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.

[0108] In addition, although the steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be executed in this specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0109] It should be noted that the division of modules in the embodiments of this application is illustrative, merely a logical function division. In actual implementation, there may be other division methods. Additionally, in each embodiment of this application, each functional unit may be integrated in a processing unit, may exist independently physically, or two or more units may be integrated in one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0110] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.

[0111] Based on the same concept as the above network slice determination method, as Figure 6 shown, the embodiments of this application also provide a schematic structural diagram of a network device 600. The device 600 can be used to implement the methods described in the above method embodiments, and reference can be made to the descriptions in the above method embodiments.

[0112] The device 600 includes one or more processors 601. The processor 601 can be a general-purpose processor or a dedicated processor, etc. For example, it can be a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control a network device (such as a base station, a terminal, or a chip, etc.), execute software programs, and process the data of software programs. The network device may include a transceiver unit for implementing signal input (reception) and output (transmission). For example, the transceiver unit can be a transceiver, a radio frequency chip, etc.

[0113] The device 600 includes one or more of the processors 601, and the one or more processors 601 can implement the methods in the above-mentioned embodiments. Optionally, in addition to implementing the methods in the above-mentioned embodiments, the processor 601 can also implement other functions.

[0114] Optionally, in one design, the processor 601 may execute instructions to cause the device 600 to perform the methods described in the foregoing method embodiments. The instructions may be stored in whole or in part within the processor, such as instruction 603, or may be stored in whole or in part in a memory 602 coupled to the processor, such as instruction 604, or the device 600 may be caused to perform the methods described in the foregoing method embodiments by instructions 603 and 604 together.

[0115] In yet another possible design, the network device 600 may also include circuitry that can implement the functions in the foregoing method embodiments.

[0116] In yet another possible design, the device 600 may include one or more memories 602 having instructions 604 stored thereon, and the instructions may be run on the processor to cause the device 600 to perform the methods described in the foregoing method embodiments. Optionally, data may also be stored in the memory. Optionally, instructions and / or data may also be stored in the processor. For example, the one or more memories 602 may store the corresponding relationships described in the foregoing embodiments, or relevant parameters or tables involved in the foregoing embodiments. The processor and the memory may be provided separately or integrated together.

[0117] In yet another possible design, the device 600 may further include a transceiver 605 and an antenna 606. The processor 601 may be referred to as a processing unit for controlling the apparatus (terminal or base station). The transceiver 605 may be referred to as a transceiver, a transceiver circuit, or a transceiver unit, etc., and is used to implement the transceiver function of the apparatus through the antenna 606.

[0118] It should be noted that the processor in the embodiments of the present application may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the above method embodiments can be completed by the integrated logic circuit in the hardware of the processor or instructions in the form of software. The above processor may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0119] It can be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include but not be limited to these and any other suitable types of memory.

[0120] The embodiments of the present application also provide a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a computer, the network slice determination method described in any of the above method embodiments is implemented.

[0121] The embodiments of the present application also provide a computer program product, and when the computer program product is executed by a computer, the network slice determination method described in any of the above method embodiments is implemented.

[0122] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in the form of a computer program product in whole or in part. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a high-definition digital video disc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0123] The embodiments of the present application also provide a processing device, including a processor and an interface; the processor is configured to execute the network slice determination method described in any of the above method embodiments.

[0124] It should be understood that the above processing device can be a chip. The processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor that is implemented by reading software code stored in a memory. The memory can be integrated in the processor or can exist independently outside the processor.

[0125] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0126] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0127] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings, direct couplings, or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or units, and can also be electrical, mechanical, or other forms of connection.

[0128] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of this application.

[0129] In addition, the functional units in each embodiment of this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0130] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by hardware, firmware, or a combination thereof. When implemented using software, the above functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, where communication media includes any medium that facilitates the transfer of a computer program from one place to another. The storage media can be any available medium that can be accessed by a computer. By way of example but not limitation: computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disc storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer. In addition, any connection can suitably be a computer-readable medium. For example, if software is transmitted using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave from a website, server, or other remote source, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of the medium. As used in this application, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc, where disks typically reproduce data magnetically, while discs reproduce data optically with a laser. The above combinations should also be included within the scope of protection of computer-readable media.

[0131] In summary, the above description is only a preferred embodiment of the technical solution of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A method for determining network slices, characterized in that The method includes: When the target application APP initiates an access request, the user equipment UE determines the slice identifier S-NSSAI of the target application APP to access the target network slice from a preset NSSP policy based on the application APP ID and the corresponding security identifier carried in the access request; the security identifier is generated by the policy control function PCF network element according to the slice subscription request of the application server, and the preset NSSP policy is used to represent the corresponding relationship between the application APP ID, the security identifier, and the slice identifier S-NSSAI; specifically, the security identifier is: determined and assigned by the PCF network element for the target application APP; or, generated according to the slice time source applied for by the application APP ID; or, generated according to the message authentication code MAC; or, a random number. The user equipment UE forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI. The user equipment UE detects whether the security identifier carried in the access request or access traffic of the target application APP is valid information according to the preset NSSP policy issued by the PCF network element. If the security identifier is not the valid information or there is no security identifier, the user equipment UE rejects the access traffic of the target application APP from accessing the target network slice.

2. The method according to claim 1, characterized in that The security identifier is: determined by the PCF network element in response to the network slice subscription request of the application server for the target application APP, performing network slice instantiation operations and based on network slice subscription related information.

3. The method according to claim 2, wherein The preset NSSP policy is: established by the PCF network element based on the corresponding relationship between the application APP ID, the security identifier, and the slice identifier S-NSSAI.

4. The method according to claim 1, wherein The method further includes: If the security identifier is the valid information, perform the operation that the user equipment UE determines the slice identifier S-NSSAI of the target application APP to access the target network slice from the preset NSSP policy based on the application APP ID and the corresponding security identifier carried in the access request.

5. A network slice determination system, characterized in that, The system includes: The user equipment UE, when the target application APP initiates an access request, determines from the preset NSSP policy the slice identifier S-NSSAI of the target network slice that the target application APP should access based on the application APP ID and the corresponding security identifier carried in the access request; the security identifier is generated by the policy control function PCF network element according to the slice signing request of the application server, and the preset NSSP policy is used to characterize the correspondence between the application APPID, the security identifier and the slice identifier S-NSSAI; forwards the access traffic of the target application APP to the target user plane function UPF network element indicated by the slice identifier S-NSSAI; the security identifier is specifically: allocated and determined by the PCF network element for the target application APP; or, generated according to the slice time source of the application APP ID; or, generated according to the message authentication code MAC; or, a random number; The user equipment UE detects whether the security identifier carried in the access request or access traffic of the target application APP is valid information according to the preset NSSP policy issued by the PCF network element; if the security identifier is not the valid information or there is no security identifier, the user equipment UE refuses the target application APP access traffic to access the target slice S-NSSAI.

6. The system according to claim 5, wherein The system further comprises: The PCF network element performs a network slice instantiation operation in response to the network slice contract request of the target application APP from the application server, and determines, based on the network slice contract related information, that the target application APP should access the slice identifier S-NSSAI of the target network slice and the security identifier corresponding to the application APP ID; and returns the application APP ID and the corresponding security identifier to the application server.

7. The system according to claim 6, wherein The system further comprises: The PCF network element establishes the preset NSSP policy based on the correspondence between the application APP ID, the security identifier and the slice identifier S-NSSAI.

8. A network device, characterized in that, include: processor; as well as A memory, configured to store executable instructions of the processor; Wherein, the processor is configured to execute the network slice determination method described in any one of claims 1-4 by executing the executable instructions.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer-readable storage medium includes: computer software instructions; When the computer software instructions are executed in a network device, the network device implements the network slice determination method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Network slice management method and device

    CN110768836A