Communication authorization method and apparatus, network element, and storage medium
By acquiring and sending communication policy information, authorization control is exercised over data packets associated with PIN elements, thus resolving the problem of unauthorized communication interference between PIN elements and ensuring communication security between devices.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- VIVO MOBILE COMM CO LTD
- Filing Date
- 2021-10-12
- Publication Date
- 2026-04-24
AI Technical Summary
In existing communication mechanisms, there is a risk that unauthorized devices may interfere with normal communication during communication between PIN elements. This is especially true when the application is attacked, which could lead to unauthorized devices accessing the PIN elements and interfering with normal communication.
Policy information is obtained through the first and second network elements, and authorization control is performed on the data packets associated with the PIN element based on the policy information, including obtaining and sending communication policies, to ensure that only devices with communication permissions can communicate with each other.
It enables communication between devices under authorized conditions, prevents communication between devices without communication permissions, improves communication security, and prevents PIN element attacks.
Smart Images

Figure CN115967942B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, and specifically relates to a communication licensing method, apparatus, network element, and storage medium. Background Technology
[0002] Third Generation Partnership Program (3) rd The Generation Partnership Project (3GPP) has introduced the concept of a Personal IoT Network (PIN). A PIN is a group consisting of at least one PIN element, where each PIN element represents a terminal or a 3GPP non-device. PIN elements within the same PIN can communicate directly with each other or indirectly through a communication network. Summary of the Invention
[0003] This application provides a communication authorization method, apparatus, network element, and storage medium to ensure secure communication between devices.
[0004] In a first aspect, embodiments of this application provide a communication authorization method, including:
[0005] The first network element acquires policy information, the policy information including: the communication policy of the first PIN element;
[0006] The first network element performs authorization control on the data packets associated with the first PIN element according to the policy information.
[0007] This approach, which authorizes data packets associated with PIN elements based on policy information, prevents communication between devices without communication permissions and ensures secure communication between devices.
[0008] Secondly, embodiments of this application provide a communication authorization method, including:
[0009] The second network element obtains the first communication strategy of the first person's IoT PIN element;
[0010] The second network element sends policy information to the first network element. The policy information includes: the second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is determined according to the first communication policy of the first PIN element.
[0011] In this way, the second network element sends policy information to the first network element, enabling the first network element to authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0012] Thirdly, embodiments of this application provide a communication authorization device, including:
[0013] The acquisition module is used to acquire policy information, which includes: the communication policy of the first human IoT PIN element;
[0014] The control module is used to perform authorization control on the data packets associated with the first PIN element according to the policy information.
[0015] This approach, which authorizes data packets associated with PIN elements based on policy information, prevents communication between devices without communication permissions and ensures secure communication between devices.
[0016] Fourthly, embodiments of this application provide a communication authorization device, including:
[0017] The acquisition module is used to acquire the first communication strategy of the first person's IoT PIN element;
[0018] The sending module is used to send policy information to the first network element. The policy information includes: the second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is determined according to the first communication policy of the first PIN element.
[0019] In this way, the second network element sends policy information to the first network element, enabling the first network element to authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0020] Fifthly, embodiments of this application provide a network element, which is a first network element, including: a memory, a processor, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, they implement the steps in the communication authorization method on the first network element side provided in embodiments of this application.
[0021] This allows for authorization control of data packets associated with PIN elements based on policy information, thereby preventing communication between devices without communication permissions and ensuring secure communication between devices.
[0022] Sixthly, embodiments of this application provide a network element, which is a first network element, including a processor and a communication interface, wherein the processor or communication interface is used to: acquire policy information, the policy information including: a communication policy of a first PIN element; and perform authorization control on data packets associated with the first PIN element according to the policy information.
[0023] This allows for authorization control of data packets associated with PIN elements based on policy information, thereby preventing communication between devices without communication permissions and ensuring secure communication between devices.
[0024] In a seventh aspect, embodiments of this application provide a network element, which is a second network element, including: a memory, a processor, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, they implement the steps in the communication authorization method on the second network element side provided in embodiments of this application.
[0025] This allows policy information to be sent to the first network element, enabling the first network element to authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0026] Eighthly, this application provides a network element, which is a second network element, including a processor and a communication interface, wherein the processor or communication interface is used to: obtain a first communication strategy of a first Internet of Things (IoT) PIN element; and send strategy information to the first network element, wherein the strategy information includes a second communication strategy of the first PIN element, wherein the second communication strategy of the first PIN element is determined based on the first communication strategy of the first PIN element.
[0027] This allows policy information to be sent to the first network element, enabling the first network element to authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0028] Ninthly, embodiments of this application provide a readable storage medium storing a program or instructions, wherein when the program or instructions are executed by a processor, they implement the steps in the communication authorization method on the first network element side provided in embodiments of this application, or, when the program or instructions are executed by a processor, they implement the steps in the communication authorization method on the second network element side provided in embodiments of this application.
[0029] This allows for authorization control of data packets associated with PIN elements based on policy information, thereby preventing communication between devices without communication permissions and ensuring secure communication between devices. Alternatively, policy information can be sent to the first network element, enabling the first network element to authorize and control data packets associated with PIN elements according to the policy information, thus preventing communication between devices without communication permissions and ensuring secure communication between devices.
[0030] In a tenth aspect, a computer program / program product is provided, which is stored in a non-transient storage medium. The program / program product is executed by at least one processor to implement the steps in the communication authorization method on the first network element side provided in the embodiments of this application, or the program / program product is executed by at least one processor to implement the steps in the communication authorization method on the second network element side provided in the embodiments of this application.
[0031] This allows for authorization control of data packets associated with PIN elements based on policy information, thereby preventing communication between devices without communication permissions and ensuring secure communication between devices. Alternatively, policy information can be sent to the first network element, enabling the first network element to authorize and control data packets associated with PIN elements according to the policy information, thus preventing communication between devices without communication permissions and ensuring secure communication between devices. Attached Figure Description
[0032] Figure 1 This diagram illustrates a block diagram of a wireless communication system to which embodiments of this application may be applied;
[0033] Figure 2 This is a flowchart of a communication authorization method provided in an embodiment of this application;
[0034] Figure 3 This is a flowchart of a communication authorization method provided in an embodiment of this application;
[0035] Figure 4 This is a schematic diagram illustrating a communication authorization provided in an embodiment of this application;
[0036] Figure 5 This is a schematic diagram illustrating another communication authorization provided in an embodiment of this application;
[0037] Figure 6 This is a schematic diagram illustrating another communication authorization provided in an embodiment of this application;
[0038] Figure 7 This is a schematic diagram illustrating another communication authorization provided in an embodiment of this application;
[0039] Figure 8 This is a schematic diagram illustrating another communication authorization provided in an embodiment of this application;
[0040] Figure 9 This is a structural diagram of a communication licensing device provided in an embodiment of this application;
[0041] Figure 10 This is a structural diagram of another communication licensing device provided in the embodiments of this application;
[0042] Figure 11This is a structural diagram of the communication device provided in the embodiments of this application;
[0043] Figure 12 This is a structural diagram of a first network element provided in an embodiment of this application;
[0044] Figure 13 This is a structural diagram of a second network element provided in an embodiment of this application. Detailed Implementation
[0045] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0046] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0047] Figure 1 This diagram illustrates a block diagram of a wireless communication system to which embodiments of this application may be applied. The wireless communication system includes a PIN, a Radio Access Network (RAN), and a core network.
[0048] The PIN includes at least one PIN element, which represents a terminal or a non-3GPP device. A non-3GPP device refers to a device that does not use 3GPP-defined credentials, does not support 3GPP-defined Non-Access-Stratum (NAS) protocols, or does not support 3GPP access technologies (such as 3G / 4G / 5G air interface technologies) but only supports non-3GPP access technologies (such as WiFi, fixed-line networks, Bluetooth, etc.).
[0049] Additionally, a PIN can contain one or more PIN elements with gateway capability. These PIN elements can communicate with each other, for example, through a direct connection or indirectly through a communication network. PIN elements can also communicate with other devices outside the PIN. In this case, the gateway-capable PIN element can be used to forward communication data between the PIN elements and other devices outside the PIN.
[0050] The terminal, also known as a terminal device or user equipment (UE), can be a mobile phone, tablet computer, laptop computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, vehicle-mounted device (VUE), pedestrian terminal (PUE), smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), etc. Wearable devices include: smartwatches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart necklaces, smart anklets, smart wristbands, etc.), smart clothing, game consoles, etc. It should be noted that the specific type of terminal is not limited in this application embodiment.
[0051] It is worth noting that the radio access network described in this application is not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), and other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used not only in the systems and radio technologies mentioned above, but also in other systems and radio technologies, such as non-3GPP access systems (e.g., WLAN, fixed access systems, Bluetooth, etc.). The following description describes a New Radio (NR) system for illustrative purposes, and NR terminology is used in most of the following description. These technologies can also be applied to applications other than NR systems, such as 6th Generation (6G) communication systems.
[0052] The core network described above may include: Session Management Function (SMF), Access and Mobility Management Function (AMF), User Port Function (UPF), Policy Control Function (PCF), and Unified Data Management (UDM). In this embodiment, the core network may further include: Access Right Function (ARF). This ARF may exist independently, be co-located with other core network elements, or be implemented by other core network elements. For example, the PCF or UDM supports the functionality of the ARF in this embodiment.
[0053] In this embodiment, the PIN element can also be referred to as a PIN device. For example, a user's mobile phone, a home printer, and a robot vacuum cleaner are all PIN elements, which together form a PIN. The mobile phone can communicate with the printer to specify the document to be printed. The mobile phone can also communicate with the robot vacuum cleaner to create and execute a cleaning plan.
[0054] Existing communication mechanisms may pose risks, as other devices besides the PIN or other devices within the PIN may also send print commands to the printer or cleaning commands to the robot vacuum cleaner. If an application is used to control communication permissions, these permissions may be compromised if the application is attacked, leading to unauthorized UE access to the PIN element and disrupting normal communication between PIN elements within the PIN. For example, this could cause the printer or robot vacuum cleaner to perform tasks it shouldn't. Therefore, this application proposes an authorization method for inter-device communication to ensure that communication between devices can only occur under authorized conditions.
[0055] The following description, in conjunction with the accompanying drawings, details a communication authorization method, apparatus, network element, and storage medium provided in this application through some embodiments and application scenarios.
[0056] Please see Figure 2 , Figure 2 This is a flowchart of a communication authorization method provided in an embodiment of this application, such as... Figure 2 As shown, it includes the following steps:
[0057] Step 201: The first network element obtains policy information, which includes the communication policy of the first PIN element.
[0058] In this embodiment of the application, the first network element may include the following:
[0059] UPF, first PIN element, target PIN element;
[0060] The target PIN element is the PIN element with gateway capability among the PIN elements to which the first PIN element belongs.
[0061] The first network element can obtain policy information by receiving policy information from the second network element, for example, by receiving policy information from an AMF or SMF receiver.
[0062] The first PIN element mentioned above can be one or more PIN elements in a PIN.
[0063] The communication strategy of the first PIN element may include at least one of a bidirectional communication strategy and a unidirectional communication strategy. The bidirectional communication strategy includes descriptive information of the PIN elements that can communicate with each other.
[0064] The description information of the PIN element in the embodiments of this application may include at least one of the following:
[0065] The IP address of the PIN element;
[0066] The MAC address of the PIN element;
[0067] PIN element identification;
[0068] The Virtual Local Area Network (VLAN) identifier used by the data packets sent by the PIN element;
[0069] The User Datagram Protocol (UDP) port number used by the data packets sent by the PIN element.
[0070] The PIN element may include, but is not limited to, external identifiers such as: Generic Public Subscription Identifier (GPSI), Fully Qualified Domain Name (FQDN), International Mobile Subscriber Identification Number (IMSI), Subscription Permanent Identifier (SUPI), Subscription Concealed Identifier (SUCI), Temporary Identifier, or a unique identifier within the PIN.
[0071] A one-way communication policy indicates which PIN elements a first PIN element can send data packets to, or which PIN elements a first PIN element can receive data packets from. Specifically, the one-way communication policy may include descriptive information about these PIN elements.
[0072] It should be noted that the communication strategy of the first PIN element in this embodiment can also be referred to as the access permission or access policy of the first PIN element, that is, the policy can control the communication behavior of the PIN element or other devices accessing the first PIN element. The description information of the PIN element in this embodiment can also be referred to as the indication information of the PIN element or the identification information of the PIN element.
[0073] Step 202: The first network element performs authorization control on the data packets associated with the first PIN element according to the policy information.
[0074] The data packet associated with the first PIN element can be a data packet whose destination address indicates the first PIN element. Specifically, this can be achieved by: the destination IP address of the data packet being the IP address of the first PIN element; the destination MAC address of the data packet being the MAC address of the first PIN element; or the data packet header including an identifier of the first PIN element to indicate that the destination of this data packet is the first PIN element. Through the above steps, authorization control can be implemented for data packets whose destination address indicates the first PIN element. This authorization control can be achieved by sending, receiving, or discarding the data packet associated with the first PIN element according to the communication policy of the first PIN element.
[0075] In some implementations, the data packet associated with the first PIN element can also be a data packet whose source address indicates the first PIN element. This source address can be: the source IP address of the data packet is the IP address of the first PIN element; the source MAC address of the data packet is the MAC address of the first PIN element; or the data packet header includes an identifier of the first PIN element to indicate that the source of this data packet is the first PIN element. The above steps can achieve authorization control for data packets whose source address indicates the first PIN element. The authorization control for the data packet associated with the first PIN element can be achieved by determining whether the data packet associated with the first PIN can be sent to the device indicated by the destination address of the data packet. For example, if the destination address of the data packet indicates the second PIN element, if the communication policy allows the first PIN element to communicate with the second PIN element, or allows the first PIN element to send data packets to the second PIN element, then the data packet is forwarded; otherwise, the data packet is discarded.
[0076] The authorization control of the data packets associated with the first PIN element can be achieved by sending, receiving, or discarding the data packets associated with the first PIN element according to the communication policy of the first PIN element, specifically determined by the aforementioned communication policy.
[0077] The embodiments of this application can achieve authorization control of data packets associated with PIN elements based on policy information through the above steps, thereby avoiding communication between devices without communication permissions, ensuring communication security between devices, and preventing PIN elements from being attacked by other devices without communication permissions.
[0078] As one possible implementation, the authorization control of the data packets associated with the first PIN element described above includes at least one of the following:
[0079] Send the first data packet associated with the first PIN element to the first PIN element;
[0080] Discard the second data packet associated with the first PIN element;
[0081] Receive the third data packet associated with the first PIN element.
[0082] Sending the first data packet associated with the first PIN element to the first PIN element can be achieved by forwarding the first data packet associated with the first PIN element to the first PIN element. For example, if the first network element is a UPF, it can forward the first data packet associated with the first PIN element to the first PIN element. Forwarding the first data packet to the first PIN element can be done through the session channel of the first PIN element, or by forwarding to the PIN to which the first PIN element belongs, for example, forwarding to a PIN element with gateway capabilities among the PIN elements to which the first PIN element belongs.
[0083] The aforementioned discarding of the second data packet associated with the first PIN element can be achieved by either discarding the second data packet upon receipt or by not forwarding the data packet to the first PIN element.
[0084] The aforementioned receipt of the third data packet associated with the first PIN element may be that the first PIN element receives the third data packet via the aforementioned communication strategy.
[0085] In the case of sending the first data packet associated with the first PIN element to the first PIN element, the first network element may include a UPF or the aforementioned target PIN element;
[0086] In the event that the second data packet associated with the first PIN element is discarded, the first network element may include a UPF, the first PIN element, or the target PIN element;
[0087] When receiving a third data packet associated with the first PIN element, the first network element may include a UPF, the first PIN element, or a target PIN element.
[0088] In this embodiment, the security of the PIN element can be improved by sending, discarding, or receiving data packets as described above.
[0089] Optionally, sending the first data packet associated with the first PIN element to the first PIN element includes:
[0090] If the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive data packets sent by the second PIN element, a first data packet associated with the first PIN element is sent to the first PIN element, wherein the first data packet is a data packet sent by the second PIN element to the first PIN element.
[0091] The second PIN element mentioned above can be one or more elements, and the corresponding communication strategy can be configured according to the actual situation.
[0092] In this implementation, data packets for PIN elements that are allowed to be sent by the communication policy can be sent only to the first PIN element.
[0093] Optionally, discarding the second data packet associated with the first PIN element includes:
[0094] If the communication policy of the first PIN element includes a policy that prohibits the first PIN element from receiving data packets sent by the third PIN element, then the second data packet associated with the first PIN element is discarded, wherein the second data packet is a data packet sent by the third PIN element to the first PIN element; or
[0095] If the communication policy of the first PIN element does not include a communication policy that allows the first PIN element to receive data packets sent by the third PIN element, the second data packet associated with the first PIN element is discarded, wherein the second data packet is a data packet sent by the third PIN element to the first PIN element.
[0096] The third PIN mentioned above can be one or more PIN elements.
[0097] In this implementation, a communication policy can be implemented to prevent the first PIN element from receiving data packets sent by the PIN element.
[0098] Optionally, receiving the third data packet associated with the first PIN element includes:
[0099] If the communication strategy of the first PIN element includes a communication strategy that allows the first PIN element to receive data packets sent by the second PIN element, then the third data packet associated with the first PIN element sent by the second PIN element is received.
[0100] In this implementation, the first PIN element can only receive data packets sent by PIN elements that the communication policy allows the first PIN element to receive.
[0101] As one possible implementation, the first network element is a UPF, and the acquisition of policy information by the first network element includes: the first network element receiving the policy information from the SMF.
[0102] The first network element can receive the policy information from the SMF through the N4 interface between the UPF and the SMF. This policy information can be an N4 rule, which is determined by the SMF based on the first communication policy of the first PIN element after receiving it. The N4 rule can indicate which data packets the UPF can send to the first PIN element, and / or, it can indicate which data packets the UPF cannot send to the first PIN element.
[0103] This implementation allows the UPF to authorize and control the data packets associated with the first PIN element according to the communication policy of the first PIN element.
[0104] Optionally, the communication strategy of the first PIN element includes:
[0105] Packet Detection Rules (PDR) and Forwarding Action Rules (FAR);
[0106] For example, the PDR includes at least one of the following:
[0107] First detection information that allows the first PIN element to receive data packets;
[0108] The second detection information for preventing the first PIN element from receiving data packets;
[0109] The FAR is used to indicate at least one of the following:
[0110] Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN element;
[0111] If a second data packet matching the second detection information is received, the second data packet is discarded.
[0112] When the above communication strategy allows the first PIN element to receive data packets from the second PIN element, the first detection information may include the description information of the second PIN element; when the above communication strategy prohibits the first PIN element from receiving data packets from the third PIN element, the second detection information may include the description information of the third PIN element.
[0113] The aforementioned receiving of the first data packet that conforms to the first detection information can be receiving a data packet sent by the PIN element that conforms to the first detection information, such as receiving a data packet of the aforementioned second PIN element.
[0114] The aforementioned receiving of the second data packet that conforms to the second detection information can be receiving a data packet sent by the PIN element that conforms to the second detection information, such as receiving a data packet sent by the aforementioned third PIN element.
[0115] For example, the communication policy of the first PIN element describes that the first PIN element can receive data packets from the second PIN element. The PDR included in the N4 rule includes detection information of data packets from the second PIN element. This detection information may include descriptive information of the second PIN element. The FAR associated with this PDR indicates that when the UPF receives a data packet that matches the detection information of the second PIN element, it should forward the data packet to the first PIN element. For example, the action of the FAR is indicated as forwarding, and the destination interface is indicated as the access side.
[0116] Additionally, the PDR may include detection information describing data packets other than the second PIN element, such as detection information for data packets including the third PIN element. This detection information may include descriptive information about the third PIN element. The FAR associated with the PDR instructs the UPF to discard a data packet containing detection information matching the third PIN element when it receives such a packet.
[0117] It should be noted that when the communication strategy only includes the above-mentioned PDR, the first network element can send the data packet corresponding to the first detection information according to the first detection information, or discard the data packet corresponding to the second detection information according to the second detection information.
[0118] When the communication strategy only includes the aforementioned FAR, the FAR includes at least one of the aforementioned first detection information and second detection information, thereby directly sending or discarding the corresponding data packet according to the FAR.
[0119] In this embodiment, the PDR and FAR described above enable the UPF to authorize and control the data packets associated with the first PIN element according to the communication policy of the first PIN element. Of course, in some embodiments, the communication policy of the first PIN element obtained by the UPF is not limited to the PDR and FAR described above. For example, the communication policy of the first PIN element can be represented by other information, and this application embodiment does not limit this.
[0120] In one possible implementation, the first network element is the first PIN element or the target PIN element, and the first network element obtains policy information, including: the first network element receives the policy information from the AMF.
[0121] This implementation allows the first PIN element or the target PIN element to perform authorization control on the data packets associated with the first PIN element according to the communication policy of the first PIN element.
[0122] In this embodiment, the first network element acquires policy information, which includes a communication policy for a first Internet of Things (IoT) PIN element. Based on the policy information, the first network element performs authorization control on data packets associated with the first PIN element. This authorization control of data packets associated with the PIN element based on the policy information avoids communication between devices without communication permissions, thus ensuring communication security between devices.
[0123] Please see Figure 3 , Figure 3 This is a flowchart of another communication authorization method provided in the embodiments of this application, such as... Figure 3 As shown, it includes the following steps:
[0124] Step 301: The second network element obtains the first communication strategy of the first human IoT PIN element;
[0125] Step 302: The second network element sends policy information to the first network element. The policy information includes: the second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is determined according to the first communication policy of the first PIN element.
[0126] The second communication strategy of the first PIN element is as follows: Figure 2 The communication strategy of the first PIN element in the illustrated embodiment.
[0127] The second communication strategy of the first PIN element may be the same as the first communication strategy of the first PIN element, or the second communication strategy of the first PIN element may be a communication rule generated by the second network element according to the first communication strategy of the first PIN element, or a communication strategy that is different from the first communication strategy in form and / or content.
[0128] In this embodiment, by sending policy information to the first network element, the first network element can perform authorization control on the data packets associated with the first PIN element according to the second communication policy of the first PIN element, thereby improving the security of the PIN element.
[0129] Optionally, the second communication strategy of the first PIN element includes at least one of the following:
[0130] A communication strategy that allows the first PIN element to receive data packets sent by the second PIN element;
[0131] A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
[0132] For the second communication strategy of the first PIN element mentioned above, please refer to [link / reference needed]. Figure 2 The corresponding descriptions of the embodiments shown are not repeated here.
[0133] Optionally, the first communication strategy for the second network element to obtain the first PIN element includes:
[0134] The second network element receives the first communication strategy of the first PIN element from the PIN element communication strategy network element; or
[0135] The second network element receives the communication strategy of the PIN to which the first PIN element belongs from the PIN element communication strategy network element. The communication strategy of the PIN includes the first communication strategy of the first PIN element.
[0136] The aforementioned PIN element communication strategy network element can be either UDM or PCF.
[0137] The communication strategy of the aforementioned PIN may include a first communication strategy for one or more PIN elements, for example: a first communication strategy that includes one or more or all PIN elements within the PIN.
[0138] In this embodiment, receiving the communication strategy from the PIN element communication strategy network element can be either receiving the communication strategy actively sent by the PIN element communication strategy network element, or requesting and obtaining the communication strategy from the PIN element communication strategy network element.
[0139] Optionally, the method further includes:
[0140] The second network element sends a communication policy request to the PIN element communication policy network element. The communication policy request includes the description information of the first PIN element, or the communication policy request includes the description information of the PIN to which the first PIN element belongs.
[0141] The aforementioned communication policy request can be a session management subscription data request message, or a subscription data management - get request service (Nudm_SDM_Get request service). The aforementioned PIN element communication policy network element can send a communication policy through a communication policy response, which can be a session management subscription data response message or a Nudm_SDM_Get service response.
[0142] Alternatively, the aforementioned communication policy request can be a session management policy connection establishment request message or an Npcf_SMPolicyControl_Create (session management policy control creation) service request; the communication policy response can be a session management policy connection establishment response message or an Npcf_SMPolicyControl_Create (session management policy control creation) service response.
[0143] In this embodiment, a communication strategy is requested from the PIN element communication strategy network element through the aforementioned communication strategy request.
[0144] Optionally, the second network element includes one of the following:
[0145] SMF serving the first PIN element, AMF serving the first PIN element, the first PIN element, and the target PIN element;
[0146] The target PIN element is the PIN element with gateway capability among the PIN elements to which the first PIN element belongs.
[0147] In this embodiment, a second communication strategy can be implemented to send the first PIN element to the first network element via the SMF serving the first PIN element, the AMF serving the first PIN element, the first PIN element, or the target PIN element.
[0148] Optionally, the second network element is an SMF serving the first PIN element, and the second network element obtains the first communication strategy of the first PIN element by: the second network element obtaining the first communication strategy of the first PIN element during the session establishment process of the first PIN element.
[0149] The first communication strategy of the first PIN element obtained during the session establishment process of the first PIN element can be that the SMF obtains the first communication strategy of the first PIN element from the PIN element communication strategy network element when it receives the PDU session establishment request initiated by the first PIN element.
[0150] Optionally, the second network element is an AMF serving the first PIN element, and the second network element obtains the first communication strategy of the first PIN element by: the second network element obtaining the first communication strategy of the first PIN element during the registration process or session establishment process of the first PIN element.
[0151] The acquisition of the first communication strategy of the first PIN element during the registration process or session establishment process can be achieved by the AMF obtaining the first communication strategy of the first PIN element from the PIN element communication strategy network element upon receiving a registration request or PDU session establishment request initiated by the first PIN element. Optionally, the AMF can obtain the first communication strategy of the first PIN element from the PIN element communication strategy network element through the SMF serving the first PIN element.
[0152] Optionally, the second network element is an SMF serving the first PIN element, and the second network element sends policy information to the first network element, including: the second network element sending the policy information to the first network element, and the first network element including a UPF.
[0153] For details regarding the policy information sent from the SMF to the UPF, please refer to [link / reference needed]. Figure 2 The corresponding descriptions of the embodiments shown are not repeated here.
[0154] Optionally, the second communication strategy for the first PIN element includes:
[0155] PDR and FAR;
[0156] The PDR includes at least one of the following:
[0157] First detection information that allows the first PIN element to receive data packets;
[0158] The second detection information for preventing the first PIN element from receiving data packets;
[0159] The FAR is used to indicate at least one of the following:
[0160] Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN;
[0161] If a second data packet matching the second detection information is received, the second data packet is discarded.
[0162] Please refer to the above PDR and FAR. Figure 2 The corresponding descriptions of the embodiments shown are not repeated here.
[0163] Optionally, the second network element is an SMF serving the first PIN element, and the second network element sends policy information to the first network element, including: the second network element sending the policy information to the first network element through an AMF;
[0164] Wherein, the first network element includes a target PIN element, which is a PIN element with gateway capability among the PINs to which the first PIN element belongs; or
[0165] The first network element includes the first PIN element.
[0166] The second network element sending the policy information to the first network element via the AMF can be achieved by the SMF sending the policy information to the AMF of the target PIN element, which then sends the policy information to the first network element. For example, the SMF sends a message transmission request message or a communication transmission request message (Namf_Communication_N1N2MessageTransfer service) to the AMF to send the second communication policy of the PIN element. Optionally, the message transmission request message or the communication transmission request message (Namf_Communication_N1N2MessageTransfer service) includes a session management container (N1SMcontainer) containing the second communication policy of the first PIN element.
[0167] Optionally, the second network element is an AMF serving the first PIN element, and the second network element sends policy information to the first network element, including: the second network element sending the policy information to the first network element;
[0168] Wherein, the first network element includes a target PIN element, which is a PIN element with gateway capability among the PINs to which the first PIN element belongs; or
[0169] The first network element includes the first PIN element.
[0170] The second network element sending the policy information to the first network element can be achieved by the AMF receiving the first communication policy of the first PIN element from the PIN element communication policy network element or the SMF, and then sending the second communication policy of the first PIN element to the first network element.
[0171] It should be noted that this embodiment is as a comparison with... Figure 2 The implementation method of the second network element in the illustrated embodiment can be found in the following examples. Figure 2 To avoid repetition, the relevant descriptions of the embodiments shown will not be repeated in this embodiment.
[0172] In this embodiment, by sending policy information to the first network element, the first network element can perform authorization control on the data packets associated with the first PIN element according to the second communication policy of the first PIN element, thereby improving the security of the PIN element.
[0173] The methods provided in the embodiments of this application are illustrated below with several examples:
[0174] Example 1:
[0175] This embodiment illustrates the authorization control of data packets for PIN elements using a UPF serving the PIN element. Figure 4 As shown, taking the session of the first PIN element as an example of a PDU session, the method embodiment includes the following steps:
[0176] Step 1: Obtain the PIN element access policy from the network element (e.g., UDM or PCF).
[0177] The access strategy for the PIN element may include at least one of the following:
[0178] Two-way communication strategy, which refers to the description information of PIN elements / devices that can communicate with each other;
[0179] One-way communication strategy, that is, which PIN elements / devices can send data to, or which PIN elements / devices can receive data from;
[0180] The description information for the PIN element / device may include at least one of the following:
[0181] The IP address of the PIN element / device;
[0182] The MAC address of the PIN element / device;
[0183] The identifier of the PIN element / device includes, but is not limited to, external identifiers, GPSI, FQDN, IMSI, SUCI or SUPI, temporary identifiers, and unique identifiers within the PIN;
[0184] The VLAN identifier used by the data packets sent by this PIN element / device;
[0185] The UPD port number used by the data packets sent by this PIN element / device.
[0186] Step 2: The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
[0187] Optionally, the NAS message may include PDU session establishment parameters, such as the Data Network Name (DNN) and / or network slice selection assistance information (NSSAI).
[0188] Step 3: The AMF receives the NAS message and forwards the PDU session establishment request to the SMF.
[0189] Optionally, the AMF can select the SMF based on the PDU session establishment parameters, or the AMF can select the SMF based on the configuration information.
[0190] Step 4: The SMF obtains the communication policy (e.g., access policy) of the PIN element from the PIN element communication policy network element.
[0191] SMF can obtain the PIN element communication policy of the PIN to which the PIN element belongs, and can also obtain the communication policy related to the first PIN element in the PIN element communication policy.
[0192] In one possible approach, the SMF is an SMF configured to serve the PIN element or the PIN to which the PIN element belongs. After obtaining the communication policy of the PIN element in step 1, the PIN element communication policy network element can send the communication policy of the PIN element to the SMF.
[0193] In another possible approach, the SMF sends a communication policy request message for the PIN element to the PIN element communication policy network element. This request message may include the identifier of the first PIN element, or the identifier of the PIN to which the first PIN element belongs. Optionally, it may also include a communication policy request indication for the PIN element. The SMF receives a communication policy response message for the PIN element from the PIN element communication policy network element. This response message includes the communication policy of the PIN element.
[0194] For example, the communication policy request message of a PIN element can be a session management subscription data request message or a Nudm_SDM_Get service request message; the communication policy response message of a PIN element can be a session management subscription data response message or a Nudm_SDM_Get service response.
[0195] Alternatively, for example, the communication policy request message of the PIN element can be a session management policy connection establishment request message or an Npcf_SMPolicyControl_Create service; the communication policy response message of the PIN element can be a session management policy connection establishment response message or an Npcf_SMPolicyControl_Create service response.
[0196] Step 5: The SMF sends an N4 rule to the UPF serving the PDU session. The N4 rule indicates which data packets the UPF can send to the first PIN element, or which data packets the UPF cannot send to the first PIN element.
[0197] SMF determines the N4 rule based on the communication strategy of the PIN element.
[0198] For example, the communication policy of the PIN element describes that the first PIN element can receive data from the second PIN element. The N4 rule includes PDR and FAR. The PDR includes detection information for the data packets of the second PIN element. This detection information may include the description information of the second PIN element, which can refer to the description information of the PIN element in step 1. The FAR associated with the PDR indicates that when the UPF receives a data packet that matches the detection information of the data packet of the second PIN element, it forwards the data packet to PIN element1. For example, the action of the FAR indicates forwarding, and the destination interface indicates the access side.
[0199] Optionally, the PDR may also include detection information describing data packets other than the second PIN element. For example, the detection information may include description information of the third PIN element, which can refer to the description information of the PIN element in step 1. The FAR associated with the PDR instructs the UPF to discard the data packet when it receives a data packet that matches the detection information of the data packet excluding the second PIN element.
[0200] Step 6a: The UPF receives the data packet of the second PIN element and forwards the data packet according to the N4 rule;
[0201] Step 6b: When the UPF receives a data packet from a third PIN element or other UE or device, the UPF discards the data packet according to the N4 rule.
[0202] In this embodiment, data packets sent from the second PIN element to the first PIN element are forwarded according to the communication policy, while data packets sent from the third PIN element to the first PIN element are discarded. This enables authorization control of data packets associated with PIN elements based on policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0203] Example 2:
[0204] This embodiment illustrates the authorization control of data packets from a PIN element with gateway capabilities. Figure 5 As shown, taking the session of the first PIN element as an example of a PDU session, the method embodiment includes the following steps:
[0205] Step 1: Obtain the PIN element access policy from the network element (e.g., UDM or PCF).
[0206] Step 2: The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
[0207] Step 3: The AMF receives the NAS message and forwards the PDU session establishment request to the SMF.
[0208] Step 4: The SMF obtains the communication policy (e.g., access policy) of the PIN element from the PIN element communication policy network element.
[0209] Steps 1 to 4 are described in accordance with the description in Example 1, and will not be repeated here.
[0210] Step 5: SMF sends N4 rules to UPF to establish an N4 session.
[0211] Steps 1-5 are optional.
[0212] Step 6: The SMF sends the communication policy (e.g., access policy) of the PIN element to the AMF that serves the PIN element with gateway capability.
[0213] For example, the SMF sends a message transfer request message or the Namf_Communication_N1N2MessageTransfer service to the AMF, which includes the access policy of the PIN element.
[0214] Optionally, the message transfer request message or the Namf_Communication_N1N2MessageTransfer service may include an N1 SM container, which includes the access policy for the PIN element.
[0215] Step 7: AMF sends the communication policy of the PIN element received in step 6 to the PIN element with gateway capabilities.
[0216] Step 8a: The PIN element with gateway capability receives the data packet from the second PIN element and forwards the data packet according to the access policy of the PIN element;
[0217] Step 8b: When a PIN element with gateway capabilities receives a data packet from a third PIN element or other UE or device, it discards the data packet according to the PIN element's access policy.
[0218] For a description and examples of the communication strategy for PIN elements, please refer to the description in Example 1.
[0219] In this embodiment, data packets sent from the second PIN element to the first PIN element are forwarded according to the communication policy, while data packets sent from the third PIN element to the first PIN element are discarded. This enables authorization control of data packets associated with PIN elements based on policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0220] Example 3:
[0221] This embodiment illustrates the authorization control of data packets from the first PIN element to the PIN element, as shown in the example. Figure 6 As shown, taking the session of the first PIN element as an example of a PDU session, the method embodiment includes the following steps:
[0222] Step 1: Obtain the PIN element access policy from the network element (e.g., UDM or PCF).
[0223] Step 2: The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
[0224] Step 3: The AMF receives the NAS message and forwards the PDU session establishment request to the SMF.
[0225] Step 4: The SMF obtains the communication policy (e.g., access policy) of the PIN element from the PIN element communication policy network element.
[0226] Step 5: SMF sends N4 rules to UPF to establish an N4 session.
[0227] Steps 1 to 5 are described in accordance with the description in Embodiment 2, and will not be repeated here. Steps 1 to 5 are optional.
[0228] Step 6: The SMF sends the communication policy (e.g., access policy) of the PIN element to the AMF. This AMF is the AMF serving the first PIN element.
[0229] For example, the SMF sends a message transfer request message or the Namf_Communication_N1N2MessageTransfer service to the AMF, which includes the access policy of the PIN element.
[0230] Optionally, the N1 SM container included in the message transfer request message or the Namf_Communication_N1N2MessageTransfer service includes an access policy for the PIN element.
[0231] Step 7: AMF sends the communication strategy of the PIN element received in step 6 to the first PIN element.
[0232] Step 8a: The first PIN element receives the data packet from the second PIN element, and receives the data packet according to the PIN element's condition;
[0233] Step 8b: When the first PIN element receives a data packet from the third PIN element or other UE or device, it discards the data packet according to the PIN element's communication policy.
[0234] For a description and examples of the communication strategy for PIN elements, please refer to the description in Example 1.
[0235] In this embodiment, data packets sent from the second PIN element to the first PIN element are received according to the communication policy, while data packets sent from the third PIN element to the first PIN element are discarded. This enables authorization control of data packets associated with PIN elements based on policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0236] Example 4:
[0237] This embodiment illustrates the authorization control of data packets from a PIN element with gateway capabilities. Figure 7 As shown, taking the session of the first PIN element as an example of a PDU session, the method embodiment includes the following steps:
[0238] Step 1: Obtain the PIN element access policy from the network element (e.g., UDM or PCF).
[0239] Step 2: The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
[0240] Step 3: The AMF receives the NAS message and forwards the PDU session establishment request to the SMF.
[0241] Steps 1 to 3 are described in accordance with the description in Embodiment 2, and will not be repeated here. Steps 1 to 3 are optional.
[0242] Step 4: The AMF obtains the communication policy (e.g., access policy) of the PIN element from the PIN element communication policy network element.
[0243] This step can be referred to step 4 of Embodiment 1, except that SMF is replaced with AMF. The Session Management Subscription Data Request Message is replaced with a Subscription Data Request Message. Mobility Management Policy Request Message or UE / PIN Element Policy Request Message is also used.
[0244] For example, the communication policy request message of a PIN element can be a subscription data request message or a Nudm_SDM_Get service request; the communication policy response message of a PIN element can be a subscription data response message or a Nudm_SDM_Get service response.
[0245] Alternatively, for example, the communication policy request message for the PIN element can be a mobility management policy connection establishment request message, a mobility management policy connection modification request message, a UE / PIN element policy control establishment request message, a UE / PIN element policy control modification request message, an Npcf_AMPolicyControl_Create service, an Npcf_AMPolicyControl_Update service, an Npcf_UEPolicyControl_Create service, or an Npcf_UEPolicyControl_Update service; the access policy response message for the PIN element can be a mobility management policy connection establishment response message, a mobility management policy connection modification response message, a UE / PIN element policy control establishment response message, a UE / PIN element policy control modification response message, an Npcf_AMPolicyControl_Create service response, an Npcf_AMPolicyControl_Update service response, an Npcf_UEPolicyControl_Create service response, or an Npcf_UEPolicyControl_Update service response.
[0246] This step can also be performed after step 6, or when the first PIN element is registered to the AMF.
[0247] Step 5: SMF sends N4 rules to UPF to establish an N4 session.
[0248] Step 6: SMF sends a session establishment response message to AMF.
[0249] Step 7: AMF sends the communication policy of the PIN element received in step 6 to the PIN element with gateway capabilities.
[0250] Step 8a: The PIN element with gateway capability receives the data packet from the second PIN element and forwards the data packet according to the access policy of the PIN element;
[0251] Step 8b: When a PIN element with gateway capabilities receives a data packet from a third PIN element or other UE or device, it discards the data packet according to the PIN element's access policy.
[0252] Steps 7 and 8 are described in accordance with the description in Example 2, and will not be repeated here.
[0253] For a description and examples of the communication strategy for PIN elements, please refer to the description in Example 1.
[0254] In this embodiment, data packets sent from the second PIN element to the first PIN element are forwarded according to the communication policy, while data packets sent from the third PIN element to the first PIN element are discarded. This enables authorization control of data packets associated with PIN elements based on policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0255] Example 5:
[0256] This embodiment illustrates the authorization control of data packets from the first PIN element to the PIN element, as shown in the example. Figure 8 As shown, taking the session of the first PIN element as an example of a PDU session, the method embodiment includes the following steps:
[0257] Step 1: Obtain the PIN element access policy from the network element (e.g., UDM or PCF).
[0258] Step 2: The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
[0259] Step 3: The AMF receives the NAS message and forwards the PDU session establishment request to the SMF.
[0260] Step 4: The AMF obtains the communication policy (e.g., access policy) of the PIN element from the PIN element communication policy network element.
[0261] Step 5: SMF sends N4 rules to UPF to establish an N4 session.
[0262] Step 6: SMF sends a session establishment response message to AMF.
[0263] Steps 1 to 6 are described in accordance with the description in Example 4, and will not be repeated here.
[0264] Step 7: AMF sends the communication strategy of the PIN element received in step 6 to the first PIN element.
[0265] Step 8a: The first PIN element receives the data packet from the second PIN element, and receives the data packet according to the PIN element's condition;
[0266] Step 8b: When the first PIN element receives a data packet from the third PIN element or other UE or device, it discards the data packet according to the PIN element's communication policy.
[0267] Steps 7 and 8 are described in accordance with the description in Example 3, and will not be repeated here.
[0268] For a description and examples of the communication strategy for PIN elements, please refer to the description in Example 1.
[0269] In this embodiment, data packets sent from the second PIN element to the first PIN element are forwarded according to the communication policy, while data packets sent from the third PIN element to the first PIN element are discarded. This enables authorization control of data packets associated with PIN elements based on policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0270] It should be noted that the above embodiments 1 to 5 are all illustrated using the data packet as the destination address indicating the first PIN element. In the embodiments of this application, the data packet associated with the first PIN element may also include a source address indicating the first PIN element. For example, when the communication strategy of the first PIN element includes allowing the first PIN element to communicate with the second PIN element and prohibiting the first PIN element from communicating with the third PIN element:
[0271] For example, the PIN element access policy describes that the first PIN element can send data to the second PIN element. Optionally, the PIN element access policy describes that the first PIN element is prohibited from sending data to the third PIN element. In the above embodiment 1, steps 6a and 6b are as follows:
[0272] Step 6a: The UPF receives a data packet sent by the first PIN element whose destination address indicates the second PIN element. The UPF forwards the data packet to the second PIN element according to the N4 rule.
[0273] Step 6b: The UPF receives a data packet whose destination address is indicated by the third PIN element sent by the first PIN element. The UPF discards the data packet according to the N4 rule.
[0274] In the above embodiment 2, steps 8a and 8b are as follows:
[0275] Step 8a: The PIN element with gateway capability receives a data packet sent by the first PIN element whose destination address indicates the second PIN element, and forwards the data packet to the second PIN element according to the PIN element's communication policy;
[0276] Step 8b: When a PIN element with gateway capability receives a data packet sent by the first PIN element with a destination address indicating the third PIN element, it discards the data packet according to the PIN element's access policy.
[0277] In the above embodiment 3, steps 8a and 8b are as follows:
[0278] Step 8a: When the first PIN element needs to send a data packet whose destination address indicates the second PIN element, the data packet is sent to the second PIN element according to the PIN element's communication strategy.
[0279] Step 8b: When the first PIN element needs to send a data packet whose destination address indicates the third PIN element, the data packet is discarded according to the PIN element's communication policy, or the data packet whose destination address indicates the third PIN element is not sent.
[0280] In the above embodiment 4, steps 8a and 8b are as follows:
[0281] Step 8a: The PIN element with gateway capability receives a data packet sent by the first PIN element whose destination address indicates the second PIN element, and forwards the data packet to the second PIN element according to the PIN element's communication policy;
[0282] Step 8b: When a PIN element with gateway capability receives a data packet sent by the first PIN element with a destination address indicating the third PIN element, it discards the data packet according to the PIN element's access policy.
[0283] In the above embodiment 5, steps 8a and 8b are as follows:
[0284] Step 8a: The first PIN element needs to send a data packet with the destination address indicating the second PIN element, and send the data packet to the second PIN element according to the PIN element's communication strategy;
[0285] Step 8b: The first PIN element needs to send a data packet whose destination address indicates the third PIN element. The data packet is discarded according to the PIN element's communication policy, or the data packet whose destination address indicates the third PIN element is not sent.
[0286] In this embodiment, authorization control can be implemented on data packets whose source address indicates the first PIN element according to policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0287] Please see Figure 9 , Figure 9 This is a structural diagram of a communication licensing device provided in an embodiment of this application, such as... Figure 9 As shown, it includes:
[0288] The acquisition module 901 is used to acquire strategy information, which includes: the communication strategy of the first human Internet of Things PIN element;
[0289] The control module 902 is used to perform authorization control on the data packets associated with the first PIN element according to the policy information.
[0290] The aforementioned communication authorization device is included within the first network element, or the first network element includes the aforementioned communication authorization device. The first network element is described in the corresponding description of the above method embodiments, and will not be repeated here.
[0291] Optionally, the authorization control of the data packets associated with the first PIN element includes at least one of the following:
[0292] Send the first data packet associated with the first PIN element to the first PIN element;
[0293] Discard the second data packet associated with the first PIN element;
[0294] Receive the third data packet associated with the first PIN element.
[0295] Optionally, sending the first data packet associated with the first PIN element to the first PIN element includes:
[0296] If the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive data packets sent by the second PIN element, a first data packet associated with the first PIN element is sent to the first PIN element, wherein the first data packet is a data packet sent by the second PIN element to the first PIN element.
[0297] Optionally, discarding the second data packet associated with the first PIN element includes:
[0298] If the communication policy of the first PIN element includes a policy that prohibits the first PIN element from receiving data packets sent by the third PIN element, then the second data packet associated with the first PIN element is discarded, wherein the second data packet is a data packet sent by the third PIN element to the first PIN element; or
[0299] If the communication policy of the first PIN element does not include a communication policy that allows the first PIN element to receive data packets sent by the third PIN element, the second data packet associated with the first PIN element is discarded, wherein the second data packet is a data packet sent by the third PIN element to the first PIN element.
[0300] Optionally, receiving the third data packet associated with the first PIN element includes:
[0301] If the communication strategy of the first PIN element includes a communication strategy that allows the first PIN element to receive data packets sent by the second PIN element, then the third data packet associated with the first PIN element sent by the second PIN element is received.
[0302] Optionally, the first network element includes one of the following:
[0303] User-facing UPF, first PIN element, target PIN element;
[0304] The target PIN element is the PIN element with gateway capability among the PIN elements to which the first PIN element belongs.
[0305] Optionally, the first network element is a User Plane Function (UPF), and the first network element obtains policy information, including: the first network element receives the policy information from a Session Management Function (SMF).
[0306] Optionally, the first network element is the first PIN element or the target PIN element, and the first network element obtains policy information, including: the first network element receives the policy information from the Access and Mobility Management Function (AMF).
[0307] Optionally, the communication strategy of the first PIN element includes at least one of the following:
[0308] Packet Inspection Rules (PDR) and Forwarding Behavior Rules (FAR);
[0309] The PDR includes at least one of the following:
[0310] First detection information that allows the first PIN element to receive data packets;
[0311] The second detection information for preventing the first PIN element from receiving data packets;
[0312] The FAR is used to indicate at least one of the following:
[0313] Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN element;
[0314] If a second data packet matching the second detection information is received, the second data packet is discarded.
[0315] The communication authorization device in this application embodiment performs authorization control on the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0316] The communication authorization device in this application embodiment can be a device, a device with an operating system or an electronic device, or a component, integrated circuit or chip in the first network element.
[0317] The communication authorization device provided in this application embodiment can achieve... Figure 2 The various processes implemented in the method embodiments achieve the same technical effect, and will not be described again here to avoid repetition.
[0318] Please see Figure 10 , Figure 10 This is a structural diagram of a communication licensing device provided in an embodiment of this application, such as... Figure 10 As shown, it includes:
[0319] Module 1001 is used to acquire the first communication strategy of the first human IoT PIN element;
[0320] The sending module 1002 is used to send policy information to the first network element. The policy information includes: the second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is determined according to the first communication policy of the first PIN element.
[0321] The aforementioned communication authorization device is included in the second network element, or the second network element includes the aforementioned communication authorization device. The first network element is described in the corresponding description of the above method embodiments, and will not be repeated here.
[0322] Optionally, the second communication strategy of the first PIN element includes at least one of the following:
[0323] A communication strategy that allows the first PIN element to receive data packets sent by the second PIN element;
[0324] A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
[0325] Optionally, the first communication strategy for obtaining the first PIN element includes:
[0326] Receive the first communication strategy of the first PIN element from the PIN element communication strategy network element; or
[0327] The communication strategy of the PIN to which the first PIN element belongs is received from the PIN element communication strategy network element, wherein the PIN communication strategy includes the first communication strategy of the first PIN element.
[0328] Optionally, the device further includes:
[0329] The request module is used to send a communication policy request to the PIN element communication policy network element. The communication policy request includes the description information of the first PIN element, or the communication policy request includes the description information of the PIN to which the first PIN element belongs.
[0330] Optionally, the second network element includes one of the following:
[0331] Session management function (SMF) serving the first PIN element, access and mobility management function (AMF) serving the first PIN element, the first PIN element, and the target PIN element;
[0332] The target PIN element is the PIN element with gateway capability among the PIN elements to which the first PIN element belongs.
[0333] Optionally, the second network element is an SMF serving the first PIN element, and the first communication strategy for obtaining the first PIN element includes: obtaining the first communication strategy for the first PIN element during the session establishment process of the first PIN element; or
[0334] The second network element is an AMF that serves the first PIN element. The first communication strategy for obtaining the first PIN element includes: obtaining the first communication strategy for the first PIN element during the registration process or session establishment process of the first PIN element.
[0335] Optionally, the second network element is an SMF serving the first PIN element, and sending policy information to the first network element includes sending the policy information to the first network element, wherein the first network element includes a User Plane Function (UPF).
[0336] Optionally, the second communication strategy of the first PIN element includes at least one of the following:
[0337] Packet Inspection Rules (PDR) and Forwarding Behavior Rules (FAR);
[0338] The PDR includes at least one of the following:
[0339] First detection information that allows the first PIN element to receive data packets;
[0340] The second detection information prohibits the first PIN element from receiving data packets;
[0341] The FAR is used to indicate at least one of the following:
[0342] Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN;
[0343] If a second data packet matching the second detection information is received, the second data packet is discarded.
[0344] Optionally, the second network element is an SMF serving the first PIN element, and sending policy information to the first network element includes: sending the policy information to the first network element through an AMF;
[0345] Wherein, the first network element includes a target PIN element, which is a PIN element with gateway capability among the PINs to which the first PIN element belongs; or
[0346] The first network element includes the first PIN element.
[0347] Optionally, the second network element is an AMF serving the first PIN element, and sending policy information to the first network element includes: sending the policy information to the first network element;
[0348] Wherein, the first network element includes a target PIN element, which is a PIN element with gateway capability among the PINs to which the first PIN element belongs; or
[0349] The first network element includes the first PIN element.
[0350] In this embodiment, the communication authorization device sends policy information to the first network element, enabling the first network element to authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0351] The communication authorization device in the embodiments of this application can be a device, a device with an operating system or an electronic device, or a component, integrated circuit or chip in the second network element.
[0352] The communication authorization device provided in this application embodiment can achieve... Figure 3 The various processes implemented in the method embodiments achieve the same technical effect, and will not be described again here to avoid repetition.
[0353] Optional, such as Figure 11As shown, this application embodiment also provides a communication device 1100, including a processor 1101, a memory 1102, and a program or instructions stored in the memory 1102 and executable on the processor 1101. For example, when the communication device 1100 is a first network element, the program or instructions, when executed by the processor 1101, implement the various processes of the communication authorization method embodiment on the first network element side described above, and achieve the same technical effect. When the communication device 1100 is a second network element, the program or instructions, when executed by the processor 1101, implement the various processes of the communication authorization method embodiment on the second network element side described above, and achieve the same technical effect. To avoid repetition, this will not be repeated here. The communication device is a terminal or a network-side device.
[0354] This application embodiment also provides a communication device, including a processor and a communication interface, wherein the processor or the communication interface is used to: acquire policy information, the policy information including: a communication policy of a first PIN element; and perform authorization control on data packets associated with the first PIN element according to the policy information.
[0355] Alternatively, the communication interface is used to: obtain a first communication strategy of the first PIN element; send strategy information to the first network element, the strategy information including: a second communication strategy of the first PIN element, wherein the second communication strategy of the first PIN element is determined based on the first communication strategy of the first PIN element.
[0356] In this embodiment, authorization control of data packets associated with PIN elements can be implemented based on policy information, thereby preventing communication between devices without communication permissions and ensuring communication security between devices. Alternatively, policy information can be sent to the first network element, enabling the first network element to perform authorization control of data packets associated with PIN elements according to the policy information, thereby preventing communication between devices without communication permissions and ensuring communication security between devices.
[0357] This communication device embodiment is similar to the one described above. Figure 2 and Figure 3 The various implementation processes and methods of the above-described method embodiments can be applied to this communication device embodiment and can achieve the same technical effect.
[0358] Specifically, Figure 12 This is a schematic diagram of the hardware structure of a first network element according to an embodiment of this application. It should be noted that in this embodiment, the first network element is used as a PIN element, and the PIN element is used as a terminal for illustrative purposes.
[0359] The first network element 1200 includes, but is not limited to, at least some of the following components: radio frequency unit 1201, network module 1202, audio output unit 1203, input unit 1204, sensor 1205, display unit 1206, user input unit 1207, interface unit 1208, memory 1209, and processor 1210.
[0360] Those skilled in the art will understand that the first network element 1200 may also include a power supply (such as a battery) for supplying power to various components. The power supply can be logically connected to the processor 1210 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system. Figure 12 The first network element structure shown does not constitute a limitation on the communication equipment. The first network element may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0361] It should be understood that, in this embodiment, the input unit 1204 may include a graphics processing unit (GPU) 12041 and a microphone 12042. The GPU 12041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 1206 may include a display panel 12061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1207 includes a touch panel 12071 and other input devices 12072. The touch panel 12071 is also called a touch screen. The touch panel 12071 may include a touch detection device and a touch controller. Other input devices 12072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.
[0362] In this embodiment, the radio frequency unit 1201 receives downlink data from the network-side device and processes it for the processor 1210; additionally, it sends uplink data to the network-side device. Typically, the radio frequency unit 1201 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, etc.
[0363] The memory 1209 can be used to store software programs or instructions and various data. The memory 1209 may primarily include a program or instruction storage area and a data storage area. The program or instruction storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 1209 may include high-speed random access memory and non-volatile memory, wherein the non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. For example, at least one disk storage device, flash memory device, or other non-volatile solid-state storage device.
[0364] Processor 1210 may include one or more processing units; optionally, processor 1210 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications or instructions, and the modem processor mainly handles wireless communication, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 1210.
[0365] The radio frequency unit 1201 or processor 1210 is used to acquire policy information, which includes: the communication policy of the first human Internet of Things PIN element; and to perform authorization control on the data packets associated with the first PIN element according to the policy information.
[0366] Optionally, the authorization control of the data packets associated with the first PIN element includes at least one of the following:
[0367] Send the first data packet associated with the first PIN element to the first PIN element;
[0368] Discard the second data packet associated with the first PIN element;
[0369] Receive the third data packet associated with the first PIN element.
[0370] Optionally, sending the first data packet associated with the first PIN element to the first PIN element includes:
[0371] If the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive data packets sent by the second PIN element, a first data packet associated with the first PIN element is sent to the first PIN element, wherein the first data packet is a data packet sent by the second PIN element to the first PIN element.
[0372] Optionally, discarding the second data packet associated with the first PIN element includes:
[0373] If the communication policy of the first PIN element includes a policy that prohibits the first PIN element from receiving data packets sent by the third PIN element, then the second data packet associated with the first PIN element is discarded, wherein the second data packet is a data packet sent by the third PIN element to the first PIN element; or
[0374] If the communication policy of the first PIN element does not include a communication policy that allows the first PIN element to receive data packets sent by the third PIN element, the second data packet associated with the first PIN element is discarded, wherein the second data packet is a data packet sent by the third PIN element to the first PIN element.
[0375] Optionally, receiving the third data packet associated with the first PIN element includes:
[0376] If the communication strategy of the first PIN element includes a communication strategy that allows the first PIN element to receive data packets sent by the second PIN element, then the third data packet associated with the first PIN element sent by the second PIN element is received.
[0377] Optionally, the first network element includes one of the following:
[0378] User-facing UPF, first PIN element, target PIN element;
[0379] The target PIN element is the PIN element with gateway capability among the PIN elements to which the first PIN element belongs.
[0380] Optionally, the first network element is a User Plane Function (UPF), and the acquisition of policy information includes: receiving the policy information from a Session Management Function (SMF).
[0381] Optionally, the first network element is the first PIN element or the target PIN element, and the acquisition of policy information includes: receiving the policy information from the Access and Mobility Management Function (AMF).
[0382] Optionally, the communication strategy of the first PIN element includes at least one of the following:
[0383] Packet Inspection Rules (PDR) and Forwarding Behavior Rules (FAR);
[0384] The PDR includes at least one of the following:
[0385] First detection information that allows the first PIN element to receive data packets;
[0386] The second detection information prohibits the first PIN element from receiving data packets;
[0387] The FAR is used to indicate at least one of the following:
[0388] Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN element;
[0389] If a second data packet matching the second detection information is received, the second data packet is discarded.
[0390] The aforementioned first network element performs authorization control on the data packets associated with the PIN element based on the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0391] Specifically, the terminal in this embodiment of the invention further includes: instructions or programs stored in memory 1209 and executable on processor 1210, wherein processor 1210 calls the instructions or programs in memory 1209 to execute. Figure 9 The methods executed by each module shown achieve the same technical effect, and to avoid repetition, they will not be described in detail here.
[0392] Specifically, this application embodiment also provides a second network element. In this embodiment, the second network element is used as an example of a core network element for illustration: such as... Figure 13 As shown, the second network element 1300 includes: a transceiver device 1301.
[0393] The transceiver 1301 is used to acquire a first communication strategy of a first PIN element; and to send strategy information to a first network element, the strategy information including a second communication strategy of the first PIN element, wherein the second communication strategy of the first PIN element is determined based on the first communication strategy of the first PIN element.
[0394] Optionally, the second communication strategy of the first PIN element includes at least one of the following:
[0395] A communication strategy that allows the first PIN element to receive data packets sent by the second PIN element;
[0396] A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
[0397] Optionally, the first communication strategy for obtaining the first PIN element includes:
[0398] Receive the first communication strategy of the first PIN element from the PIN element communication strategy network element; or
[0399] The communication strategy of the PIN to which the first PIN element belongs is received from the PIN element communication strategy network element, wherein the PIN communication strategy includes the first communication strategy of the first PIN element.
[0400] Optionally, the transceiver 1301 is also used for:
[0401] A communication policy request sent to the PIN element communication policy network element, wherein the communication policy request includes description information of the first PIN element, or the communication policy request includes description information of the PIN to which the first PIN element belongs.
[0402] Optionally, the second network element includes one of the following:
[0403] Session management function (SMF) serving the first PIN element, access and mobility management function (AMF) serving the first PIN element, the first PIN element, and the target PIN element;
[0404] The target PIN element is the PIN element with gateway capability among the PIN elements to which the first PIN element belongs.
[0405] Optionally, the second network element is an SMF serving the first PIN element, and the first communication strategy for obtaining the first PIN element includes: obtaining the first communication strategy for the first PIN element during the session establishment process of the first PIN element; or
[0406] The second network element is an AMF that serves the first PIN element. The first communication strategy for obtaining the first PIN element includes: obtaining the first communication strategy for the first PIN element during the registration process or session establishment process of the first PIN element.
[0407] Optionally, the second network element is an SMF serving the first PIN element, and sending policy information to the first network element includes sending the policy information to the first network element, wherein the first network element includes a User Plane Function (UPF).
[0408] Optionally, the second communication strategy of the first PIN element includes at least one of the following:
[0409] Packet Inspection Rules (PDR) and Forwarding Behavior Rules (FAR);
[0410] The PDR includes at least one of the following:
[0411] First detection information that allows the first PIN element to receive data packets;
[0412] The second detection information prohibits the first PIN element from receiving data packets;
[0413] The FAR is used to indicate at least one of the following:
[0414] Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN;
[0415] If a second data packet matching the second detection information is received, the second data packet is discarded.
[0416] Optionally, the second network element is an SMF serving the first PIN element, and sending policy information to the first network element includes: sending the policy information to the first network element through an AMF;
[0417] Wherein, the first network element includes a target PIN element, which is a PIN element with gateway capability among the PINs to which the first PIN element belongs; or
[0418] The first network element includes the first PIN element.
[0419] Optionally, the second network element is an AMF serving the first PIN element, and sending policy information to the first network element includes: sending the policy information to the first network element;
[0420] Wherein, the first network element includes a target PIN element, which is a PIN element with gateway capability among the PINs to which the first PIN element belongs; or
[0421] The first network element includes the first PIN element.
[0422] The second network element sends policy information to the first network element, enabling the first network element to authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication security between devices.
[0423] Specifically, the second network element in this embodiment of the invention further includes: instructions or programs stored in the memory 1302 and executable on the processor 1303, wherein the processor 1303 calls the instructions or programs in the memory 1302 to execute. Figure 10 The methods executed by each module shown achieve the same technical effect, and to avoid repetition, they will not be described in detail here.
[0424] This application embodiment also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the steps in the communication authorization method on the first network element side provided in this application embodiment, or the program or instructions, when executed by a processor, implement the steps in the communication authorization method on the second network element side provided in this application embodiment.
[0425] The processor is the processor in the first network element or the second network element described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0426] This application embodiment also provides a system, which includes a first network element and a second network element, wherein the first network element is used to: acquire policy information, the policy information including: a communication policy of a first Internet of Things (IoT) PIN element; and perform authorization control on data packets associated with the first PIN element according to the policy information;
[0427] The second network element is used to obtain the first communication strategy of the first IoT PIN element; and to send strategy information to the first network element, the strategy information including: the second communication strategy of the first PIN element, wherein the second communication strategy of the first PIN element is determined according to the first communication strategy of the first PIN element.
[0428] This application also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described communication authorization method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0429] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0430] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0431] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0432] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A communication authorization method, characterized in that, include: The first network element acquires strategy information, which includes: the communication strategy of the first human Internet of Things (IoT) PIN element; The first network element performs authorization control on the data packets associated with the first PIN element according to the policy information; The first network element includes the following: User face function UPF, the first PIN element; The communication strategy of the first PIN element includes at least one of the following: Packet Inspection Rules (PDR) and Forwarding Behavior Rules (FAR); The PDR includes at least one of the following: First detection information that allows the first PIN element to receive data packets; The second detection information for preventing the first PIN element from receiving data packets; The FAR is used to indicate at least one of the following: Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN element; If a second data packet matching the second detection information is received, the second data packet is discarded.
2. The method as described in claim 1, characterized in that, The authorization control of the data packet associated with the first PIN element includes at least one of the following: Send the first data packet associated with the first PIN element to the first PIN element; Discard the second data packet associated with the first PIN element; Receive the third data packet associated with the first PIN element.
3. The method as described in claim 2, characterized in that, Sending the first data packet associated with the first PIN element to the first PIN element includes: If the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive data packets sent by the second PIN element, a first data packet associated with the first PIN element is sent to the first PIN element, wherein the first data packet is a data packet sent by the second PIN element to the first PIN element.
4. The method as described in claim 2, characterized in that, The discarding of the second data packet associated with the first PIN element includes: If the communication policy of the first PIN element includes a policy that prohibits the first PIN element from receiving data packets sent by the third PIN element, then the second data packet associated with the first PIN element is discarded, wherein the second data packet is a data packet sent by the third PIN element to the first PIN element; or If the communication policy of the first PIN element does not include a communication policy that allows the first PIN element to receive data packets sent by the third PIN element, the second data packet associated with the first PIN element is discarded, wherein the second data packet is a data packet sent by the third PIN element to the first PIN element.
5. The method as described in claim 2, characterized in that, Receiving the third data packet associated with the first PIN element includes: If the communication strategy of the first PIN element includes a communication strategy that allows the first PIN element to receive data packets sent by the second PIN element, then the third data packet associated with the first PIN element sent by the second PIN element is received.
6. The method as described in claim 1, characterized in that, The first network element is a User Plane Function (UPF). The first network element obtains policy information, including: the first network element receives the policy information from the Session Management Function (SMF).
7. The method as described in claim 1, characterized in that, The first network element is the first PIN element. The first network element obtains policy information, including: the first network element receives the policy information from the Access and Mobility Management Function (AMF).
8. A communication authorization method, characterized in that, include: The second network element obtains the first communication strategy of the first person's IoT PIN element; The second network element sends policy information to the first network element. The policy information includes: the second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is determined according to the first communication policy of the first PIN element, and the policy information is used to perform authorization control on the data packets associated with the first PIN element. The first network element includes the following: User face function UPF, the first PIN element; The second communication strategy of the first PIN element includes at least one of the following: Packet Inspection Rules (PDR) and Forwarding Behavior Rules (FAR); The PDR includes at least one of the following: First detection information that allows the first PIN element to receive data packets; The second detection information for preventing the first PIN element from receiving data packets; The FAR is used to indicate at least one of the following: Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN; If a second data packet matching the second detection information is received, the second data packet is discarded.
9. The method as described in claim 8, characterized in that, The second communication strategy of the first PIN element includes at least one of the following: A communication strategy that allows the first PIN element to receive data packets sent by the second PIN element; A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
10. The method as described in claim 8 or 9, characterized in that, The first communication strategy for the second network element to obtain the first PIN element includes: The second network element receives the first communication strategy of the first PIN element from the PIN element communication strategy network element; or The second network element receives the communication strategy of the PIN to which the first PIN element belongs from the PIN element communication strategy network element. The communication strategy of the PIN includes the first communication strategy of the first PIN element.
11. The method as described in claim 10, characterized in that, The method further includes: The second network element sends a communication policy request to the PIN element communication policy network element. The communication policy request includes the description information of the first PIN element, or the communication policy request includes the description information of the PIN to which the first PIN element belongs.
12. The method as described in claim 8 or 9, characterized in that, The second network element includes the following: Session management function (SMF) serving the first PIN element, access and mobility management function (AMF) serving the first PIN element, the first PIN element, and the target PIN element; The target PIN element is the PIN element with gateway capability among the PIN elements to which the first PIN element belongs.
13. The method as described in claim 12, characterized in that, The second network element is an SMF serving the first PIN element. The second network element obtains the first communication strategy for the first PIN element by: the second network element obtaining the first communication strategy for the first PIN element during the session establishment process of the first PIN element; or The second network element is an AMF that serves the first PIN element. The second network element obtains the first communication strategy of the first PIN element by: the second network element obtaining the first communication strategy of the first PIN element during the registration process or session establishment process of the first PIN element.
14. The method as described in claim 12, characterized in that, The second network element is an SMF serving the first PIN element. The second network element sends policy information to the first network element, including: the second network element sending the policy information to the first network element, the first network element including a User Plane Function (UPF).
15. The method as described in claim 12, characterized in that, The second network element is an SMF serving the first PIN element. The second network element sends policy information to the first network element, including: the second network element sending the policy information to the first network element through an AMF.
16. The method as described in claim 13, characterized in that, The second network element is an AMF serving the first PIN element. The second network element sends policy information to the first network element, including: the second network element sending the policy information to the first network element. The first network element includes the first PIN element.
17. A communication authorization device, characterized in that, include: The acquisition module is used to acquire policy information, which includes: the communication policy of the first human IoT PIN element; The control module is used to perform authorization control on the data packets associated with the first PIN element according to the policy information; The first network element corresponding to the device includes the following: User face function UPF, the first PIN element; The communication strategy of the first PIN element includes at least one of the following: Packet Inspection Rules (PDR) and Forwarding Behavior Rules (FAR); The PDR includes at least one of the following: First detection information that allows the first PIN element to receive data packets; The second detection information for preventing the first PIN element from receiving data packets; The FAR is used to indicate at least one of the following: Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN element; If a second data packet matching the second detection information is received, the second data packet is discarded.
18. The apparatus as claimed in claim 17, characterized in that, The authorization control of the data packet associated with the first PIN element includes at least one of the following: Send the first data packet associated with the first PIN element to the first PIN element; Discard the second data packet associated with the first PIN element; Receive the third data packet associated with the first PIN element.
19. A communication authorization device, characterized in that, include: The acquisition module is used to acquire the first communication strategy of the first person's IoT PIN element; The sending module is used to send policy information to the first network element. The policy information includes: a second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is determined according to the first communication policy of the first PIN element, and the policy information is used to perform authorization control on the data packets associated with the first PIN element. The first network element includes the following: User face function UPF, the first PIN element; The second communication strategy of the first PIN element includes at least one of the following: Packet Inspection Rules (PDR) and Forwarding Behavior Rules (FAR); The PDR includes at least one of the following: First detection information that allows the first PIN element to receive data packets; The second detection information for preventing the first PIN element from receiving data packets; The FAR is used to indicate at least one of the following: Upon receiving a first data packet that matches the first detection information, the first data packet is forwarded to the first PIN; If a second data packet matching the second detection information is received, the second data packet is discarded.
20. The apparatus as claimed in claim 19, characterized in that, The second communication strategy of the first PIN element includes at least one of the following: A communication strategy that allows the first PIN element to receive data packets sent by the second PIN element; A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
21. A network element, wherein the network element is a first network element, characterized in that, include: A memory, a processor, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the communication authorization method as described in any one of claims 1 to 7.
22. A network element, wherein the network element is a second network element, characterized in that, include: A memory, a processor, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the communication authorization method as described in any one of claims 8 to 16.
23. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the communication authorization method as described in any one of claims 1 to 7, or, when executed by a processor, implement the steps of the communication authorization method as described in any one of claims 8 to 16.
Citation Information
Patent Citations
Rule processing method and device
CN109756430A