Method, system and medium for 5gsa network iot terminal access and access restriction
By introducing a network manager and policy control module into the 5G SA network, combined with GUAMI and tracking area coding, precise campus-wide access control for users is achieved, solving the problems of frequent signaling interactions and signaling plane congestion, and improving the reliability and security of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2026-03-20
AI Technical Summary
Existing 5G IoT terminal access restriction technologies are insufficient to achieve precise control over the user's campus area, resulting in frequent signaling interactions and signaling plane congestion, which affects business usage and makes it difficult to guarantee high reliability and security.
By introducing a network manager into the 5G SA network, and utilizing the radio access network, access management module, network slice selection module, and policy control module, combined with GUAMI information and tracking area coding, precise control over the user's subscribed network slices can be achieved, and access policies can be dynamically adjusted to ensure that users only access within the campus and block traffic outside the campus.
It enables precise access control for users within the campus, reduces signaling interactions, ensures high reliability and security, avoids signaling plane congestion, and improves the user experience.
Smart Images

Figure CN116033377B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of Internet of Things, and in particular to a method and system for limiting access of a 5G SA network Internet of Things terminal and a medium. BACKGROUND
[0002] In a 5G customized network scenario, many users will choose to access network element devices built by an operator that multiplexes an access plane and a control plane, such as an AMF and an SMF, for the purpose of low latency and high reliability, and select a lightweight UPF to sink to a park where the user is located, and access internal services using a specific DNN.
[0003] In the prior art, the most common method for limiting access of a 5G Internet of Things terminal is to determine whether the user is in a list of allowed access based on an AMF ID or MME host name reported by the user, thereby achieving regional restriction at the province level. In the scheme in which a policy control module controls user access based on tracking area codes, the tracking area codes cover a relatively large range, and it is difficult to accurately control the park range, and the wireless side needs to re-plan and adjust the tracking area codes. For an operator, it is difficult to adjust the tracking area codes that have been planned. If the policy control module controls user session policies based on base stations or cell levels, frequent location updates by the user when moving will bring about a large amount of signaling interaction, causing congestion on the signaling side and affecting service use.
[0004] Therefore, how to simply and timely control access of an Internet of Things terminal to control the user to access an internal network only within a controllable smaller park range and prohibit access to services when the user moves out of the range, thereby ensuring higher reliability and security, needs to be solved. SUMMARY
[0005] The technical problem to be solved by the present application is to control a user to access an internal network only within a controllable smaller park range and prohibit access to services when the user moves out of the range, thereby ensuring higher reliability and security.
[0006] In a first aspect, an embodiment of the present application provides a method for limiting access of a 5G SA network Internet of Things terminal, which is applied to an SA network Internet of Things system, the system including an Internet of Things terminal, a network manager, and a user terminal, the network manager establishing network connections with the Internet of Things terminal and the user terminal to realize transmission of data information, the network manager being provided with a radio access network, an access management module, a network slice selection module, and a policy control module, and the method including the following steps:
[0007] If the network manager receives an attachment request from the Internet of Things terminal, the user terminal is controlled to send an access network message.
[0008] The network manager receives the access network message, and the radio access network determines an access management module corresponding to the access network message;
[0009] The determined access management module obtains a user subscription network slice corresponding to the access network message from a preset slice database;
[0010] It is judged whether the determined access management module can process the user subscription network slice;
[0011] If the determined access management module cannot process the user subscription network slice, the network slice selection module obtains an allowed slice and a target access management module corresponding to the user subscription network slice;
[0012] The network slice selection module re-sends the allowed slice to the target access management module;
[0013] The target access management module obtains a pre-stored user subscription policy corresponding to the allowed slice from the policy control module;
[0014] The user subscription policy is sent to the Internet of Things terminal, so that the Internet of Things terminal accesses the target access management module.
[0015] Preferably, the radio access network determines an access management module corresponding to the access network message, comprising:
[0016] The access network message is parsed to obtain corresponding GUAMI information;
[0017] It is judged whether a matching access management module can be obtained according to the GUAMI information;
[0018] If a matching access management module can be obtained according to the GUAMI information, a matching access management module is determined as the determined access management module;
[0019] If a matching access management module cannot be obtained according to the GUAMI information, an access management module corresponding to the requested slice in the access network message is determined.
[0020] Preferably, before the access management module corresponding to the requested slice in the access network message is determined, the method further comprises:
[0021] It is judged whether the access network message contains a requested slice;
[0022] If the access network message contains a requested slice, the step of determining the access management module corresponding to the requested slice in the access network message is performed;
[0023] If the access network message does not contain a request slice, a registration request is sent to a default access management module.
[0024] Preferably, the target access management module obtains a pre-stored user subscription policy from the policy control module, including:
[0025] The policy control module subscribes to the switching between tracking areas for a single user based on a pre-set tracking area code to obtain the user subscription policy.
[0026] Preferably, the network manager is further provided with a session management module, and the policy control module performs session policy control on the user based on a pre-set tracking area code; the policy control module subscribes to the switching between tracking areas for a single user to obtain the user subscription policy, including:
[0027] If a signal of the tracking area switching sent by the user terminal is received, a location is actively reported to update the access network message;
[0028] The radio access network re-determines the access management module corresponding to the updated access network message;
[0029] The newly corresponding access management module reports the updated access network message to the policy control module through a pre-set interface;
[0030] The policy control module performs session policy control on the tracking area code carried in the session management module.
[0031] Preferably, the policy control module performs policy control on the tracking area code carried in the session management module, including:
[0032] If the tracking area code is in the allowed list of the session management module, a dynamic policy is issued to ensure that a first policy is output; the first policy is a higher quality of service policy;
[0033] If the tracking area code is not in the allowed list of the session management module, a blocking instruction is issued to ensure that a second policy is output, thereby blocking all traffic of the user, so as to realize that the user traffic does not go out of the park; the second policy is a corresponding business rule with the highest global priority.
[0034] Preferably, the determined access management module obtains a user subscription network slice corresponding to the access network message from a pre-set slice database, further including:
[0035] If the target access management module obtains the user subscription policy, it is judged whether the request slice, the user subscription network slice and the allowed slice can be combined to form an intersection slice;
[0036] if the intersection slice can be formed, allowing the user terminal to access;
[0037] if the intersection slice cannot be formed, rejecting the user terminal to access.
[0038] In a second aspect, the embodiments of the present application provide a system for 5G SA network IOT terminal access and access restriction, which comprises an IOT terminal, a network manager and a user terminal, the network manager establishes network connection with the IOT terminal and the user terminal respectively to realize data information transmission;
[0039] The system comprises an attachment request unit arranged in the IOT terminal, a first sending unit arranged in the user terminal, a receiving unit, a first obtaining unit, a judging unit, a second obtaining unit, a second sending unit, a third obtaining unit and a third sending unit arranged in the network manager;
[0040] The attachment request unit is used for the network manager to receive an attachment request from the IOT terminal;
[0041] The first sending unit is used for, if the network manager receives an attachment request from the IOT terminal, controlling the user terminal to send an access network message;
[0042] The receiving unit is used for the network manager to receive the access network message, and the radio access network determines an access management module corresponding to the access network message;
[0043] The first obtaining unit is used for the determined access management module to obtain a user subscription network slice corresponding to the access network message from a preset slice database;
[0044] The judging unit is used for judging whether the determined access management module can process the user subscription network slice;
[0045] The second obtaining unit is used for, if the determined access management module cannot process the user subscription network slice, the network slice selection module obtains an allowed slice and a target access management module corresponding to the user subscription network slice;
[0046] The second sending unit is used for the network slice selection module to resend the allowed slice to the target access management module;
[0047] The third obtaining unit is used for the target access management module to obtain a preset user subscription policy corresponding to the allowed slice from the policy control module;
[0048] A third sending unit is configured to send the user subscription policy to the IoT terminal, so that the IoT terminal accesses the target access management module.
[0049] In a third aspect, the embodiments of the present application further provide a system for 5G SA network IoT terminal access and access restriction, which comprises an IoT terminal, a network manager and a user terminal, the IoT terminal comprises a first memory, a first processor and a first computer program stored in the first memory and executable on the first processor, the network manager comprises a second memory, a second processor and a second computer program stored in the second memory and executable on the second processor, and the user terminal comprises a third memory, a third processor and a third computer program stored in the third memory and executable on the third processor, wherein the first processor executes the first computer program, the second processor executes the second computer program, and the third processor executes the third computer program, and the system collectively implements the method for 5G SA network IoT terminal access and access restriction as described in the first aspect.
[0050] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, which stores a first computer program, a second computer program and a third computer program, wherein the first computer program is executed by a first processor, the second computer program is executed by a second processor, and the third computer program is executed by a third processor, and the first computer program, the second computer program and the third computer program collectively implement the method for 5G SA network IoT terminal access and access restriction as described in the first aspect.
[0051] Compared with the prior art, the present application has at least one of the following beneficial technical effects:
[0052] If the network manager receives an attachment request from the Internet of Things terminal, the user terminal is controlled to send an access network message; the network manager receives the access network message, the radio access network determines an access management module corresponding to the access network message; the determined access management module obtains a user subscription network slice corresponding to the access network message from a preset slice database; it is judged whether the determined access management module can process the user subscription network slice; if the determined access management module cannot process the user subscription network slice, the network slice selection module obtains an allowed slice and a target access management module corresponding to the user subscription network slice; the network slice selection module re-sends the allowed slice to the target access management module; the target access management module obtains a pre-stored user subscription policy corresponding to the allowed slice from the policy control module; the user subscription policy is sent to the Internet of Things terminal, so that the Internet of Things terminal accesses the target access management module.
[0053] The policy control module performs tracking area switching subscription for a single user, and when the user terminal switches the tracking area, actively reports a location update message, and the policy control module performs policy control on the tracking area code carried in the session message of the session management module: when the tracking area code is in the allowed list, a dynamic control policy such as quality of service guarantee is issued; when the tracking area code is not in the allowed list, all traffic of the user is blocked, so as to realize that the user traffic does not go out of the park. BRIEF DESCRIPTION OF DRAWINGS
[0054] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0055] Figure 1 The flowchart of the method for limiting access and access of 5G SA network Internet of Things terminal provided by the embodiment of the present application.
[0056] Figure 2 The scene diagram of the method for limiting access and access of 5G SA network Internet of Things terminal provided by the embodiment of the present application.
[0057] Figure 3 Another flowchart of the method for limiting access and access of 5G SA network Internet of Things terminal provided by the embodiment of the present application.
[0058] Figure 4A sub-flow schematic diagram of the method for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0059] Figure 5 Another sub-flow schematic diagram of the method for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0060] Figure 6 Still another sub-flow schematic diagram of the method for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0061] Figure 7 Still another sub-flow schematic diagram of the method for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0062] Figure 8 Still another sub-flow schematic diagram of the method for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0063] Figure 9 Another application scenario schematic diagram of the method for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0064] Figure 10 Still another application scenario schematic diagram of the method for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0065] Figure 11 Still another application scenario schematic diagram of the method for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0066] Figure 12 A schematic block diagram of the system for 5G SA network IOT terminal access and access restriction is provided for the embodiment of the present application.
[0067] Figure 13 A schematic block diagram of the computer device is provided for the embodiment of the present application. DETAILED DESCRIPTION
[0068] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0069] It should be understood that the terms "comprises" and "comprising," when used in this specification and the following claims, indicate the presence of the described features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0070] It should also be understood that the terms used in the specification and the following claims are merely for the purpose of describing particular embodiments and do not intend to limit the application. As used in the specification and the appended claims, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0071] It should be further understood that the term "and / or" used in the specification and the following claims indicates one or more of the associated listed items, as well as all possible combinations of these items, and includes these combinations.
[0072] Please refer to Figure 1 and Figure 2 , Figure 1 the flowchart of the method for 5G SA network Internet of Things terminal access and access restriction provided by the embodiments of the application, Figure 2 the application scenario diagram of the method for 5G SA network Internet of Things terminal access and access restriction provided by the embodiments of the application; the method for 5G SA network Internet of Things terminal access and access restriction is applied to an SA network Internet of Things system 10, the system 10 includes an Internet of Things terminal 11, a network manager 12, and a user terminal 13, the method for 5G SA network Internet of Things terminal access and access restriction is executed by application software installed in the Internet of Things terminal 11, the network manager 12, and the user terminal 13, wherein the user terminal 13 is a terminal device for wireless communication connection with the network manager 12 based on a SIM card, such as a smart watch, a smart sound, a smart phone, and other smart devices, the network manager 12 is a gateway server for network bridging and management, the network manager 12 can be used for transmission management of network access requests, the Internet of Things terminal 11 is a platform server for providing network information services for the user terminal 13. The network manager 12 establishes network connections with the Internet of Things terminal 11 and the user terminal 13 to realize transmission of data information, the user terminal 13 can send a network access request to the network manager 12, the Internet of Things terminal 11 can provide corresponding network services for the user terminal 13 according to the network access request processed by the network manager 12, and the network manager 12 is provided with a radio access network RAN, an access management module AMF, a network slice selection module, and a policy control module PCF. As shown in Figure 1 the method includes steps S110-S180.
[0073] S110, if the network manager receives an attachment request from the Internet of Things terminal, controlling the user terminal 13 to send an access network message.
[0074] The network manager can receive an attachment request from the Internet of Things terminal, and if the network manager receives the attachment request, a feedback signal is sent to the user terminal 13, and the user terminal 13 receives the feedback signal and sends an access network message to the network manager.
[0075] S120, the network manager receives the access network message, and the radio access network RAN determines the access management module AMF corresponding to the access network message.
[0076] As shown in Figure 3 In one embodiment, step S120 further includes sub-steps S111, S112 and S113.
[0077] S111, determine whether the access network message contains a request slice R; S112, if the access network message contains a request slice R, execute the step of determining the corresponding access management module AMF according to the request slice R in the access network message; S113, if the access network message does not contain a request slice R, send a registration request to the default access management module AMF.
[0078] As shown in Figure 4 In one embodiment, step S120 includes sub-steps S121, S122, S123 and S124.
[0079] S121, parse the access network message to obtain the corresponding GUAMI information; S122, determine whether the matching access management module AMF can be obtained according to the GUAMI information; in another embodiment, the matching access management module AMF can be replaced by the system default access management module AMF; S123, if the matching access management module AMF can be obtained according to the GUAMI information, obtain a matching access management module AMF as the determined access management module AMF; S124, if the matching access management module AMF cannot be obtained according to the GUAMI information, determine the corresponding access management module AMF according to the request slice R in the access network message.
[0080] Wherein, the access management module AMF is the main functional unit of the 5G (fifth generation mobile communication technology) core network, used to complete the access and mobility management of terminal users; the GUAMI information is the unique identifier of the access management module AMF. Wherein, in the case of 5G access, the AN parameter (access network parameter) in the access network message includes GUAMI information, request slice R, etc.
[0081] S130, the determined access management module AMF obtains the user subscription network slice S corresponding to the access network message from the preset slice database.
[0082] The network manager is further provided with a unified data management module UDM. The unified data management module UDM provides a management architecture that can uniformly manage network, security, storage and other basic IT infrastructures, and serves as a unified management hub for the IT system, helping users to more effectively manage, utilize and protect data assets. The preset slice database is located in the unified data management module UDM, and the slice database includes three types: a requested slice R (optional), a subscription network slice S, and an allowed slice A.
[0083] As shown in FIG. 13, in a specific embodiment, step S130 is followed by steps S131, S132 and S133. Figure 5
[0084] S131, if the target access management module AMF obtains the user subscription policy, it is determined whether the requested slice R, the user subscription network slice S and the allowed slice A can be combined to form an intersection slice; S132, if the intersection slice can be formed, the user terminal 13 is allowed to access; S133, if the intersection slice cannot be formed, the user terminal 13 is rejected to access. The slice accessed by the end user terminal 13 is the intersection of the requested slice R (if any), the subscription network slice S and the allowed slice A. If there is no result after the intersection of the three, the user terminal 13 is rejected to access, and the access process fails.
[0085] S140, it is determined whether the determined access management module AMF can process the user subscription network slice S.
[0086] If the determined access management module AMF can process the user subscription network slice S, the target access management module AMF obtains the pre-stored user subscription policy corresponding to the allowed slice A from the policy control module PCF, and sends the user subscription policy to the Internet of Things terminal, so that the Internet of Things terminal accesses the target access management module AMF. The policy control module PCF is similar to the PCRF (policy and charging rules function) in the 4G network element, and is mainly used for charging, dynamic policy control, etc.
[0087] S150, if the determined access management module AMF cannot process the user subscription network slice S, the network slice selection module obtains the allowed slice A corresponding to the user subscription network slice S and the target access management module AMF.
[0088] S160, the network slice selection module re-sends the allowed slice A to the target access management module AMF.
[0089] S170, the target access management module AMF obtains the pre-stored user subscription policy corresponding to the allowed slice A from the policy control module PCF.
[0090] like Figure 6 As shown, in a specific embodiment, step S170 specifically comprises step 171: the policy control module PCF performs a switching subscription between tracking area TAs for a single user based on a preset tracking area code (TAC) to obtain the user's subscription policy. More specifically, the policy control module PCF performs session policy control on the user based on the preset tracking area code (TAC); session policy control involves the policy control module PCF performing a switching subscription between tracking area TAs for a single user to obtain the user's subscription policy.
[0091] The Tracking Area Code (TAC) is the area used for paging and location updates. Its planning must ensure unrestricted paging channel capacity, minimize location update overhead at area boundaries, and be easy to manage. Proper planning of the TAC can balance paging load and location update signaling flow, effectively controlling system signaling load.
[0092] like Figure 7 As shown, the Network Manager also includes a Session Management Module (SMF). The SMF is primarily responsible for interacting with the separated data plane, creating, updating, and deleting PDU sessions, and managing the session environment with the User Plane Function (UPF). A PDU session refers to the communication process between a user terminal 13 and the data network DN. The User Plane Function (UPF) is a fundamental component of the 5G core network infrastructure system architecture defined by 3GPP (3rd Generation Partnership Project). Operators can use the UPF to rate limit, charge, and legally intercept user data transmissions, and record traffic usage. The 5G UPF can be deployed on demand, reducing network latency, increasing transmission rates, and accessing the user's intranet, ensuring traffic doesn't leave the campus and meeting different user needs. The ability to deploy the UPF is a result of the separation of the 5G control plane and user plane, representing a significant advancement in 5G technology compared to 4G.
[0093] In one specific embodiment, step S171 includes sub-steps S1711, S1712, S1713 and S1714.
[0094] S1711, if the user terminal 13 sends a signal of tracking area TA switching, actively report the location to update the access network message; S1712, the radio access network RAN re-determines the access management module AMF corresponding to the updated access network message; S1713, the newly corresponding access management module AMF reports the updated access network message to the policy control module PCF through a preset interface; S1714, the policy control module PCF controls the session policy of the tracking area code TAC carried in the session management module SMF.
[0095] As shown in Figure 8 in a specific embodiment, step S1714 includes sub-steps S1715 and S1716.
[0096] S1715, if the tracking area code TAC is in the allowed list of the session management module SMF, a dynamic policy is issued to ensure that the first policy is output; the first policy is a higher service quality policy; S1716, if the tracking area code TAC is not in the allowed list of the session management module SMF, a blocking instruction is issued to ensure that the second policy is output, thereby blocking all user traffic, so as to realize that the user traffic does not go out of the park; the second policy is the highest global priority of the corresponding service rule.
[0097] S180, the user subscription policy is sent to the Internet of Things terminal, so that the Internet of Things terminal accesses the target access management module AMF.
[0098] Because the number of slices configurable by the 5G core network and the wireless base station is limited, it is impossible to achieve one slice for each customer for access control. Therefore, in the present application, a smaller number of public slices are selected for access restriction, and the allowed slice A is added in the base station and the core network element related to the park. The network slice selection module configures the slice supported by each tracking area code TAC, and the access management module AMF subscribes to the information of the tracking area code TAC and the slice through the network slice selection module, and obtains the slice configured under the tracking area code TAC. Because the range of the tracking area code TAC is generally large, a smaller number of public slices can meet the needs of most users.
[0099] The policy control module PCF subscribes to the tracking area TA inter-switching for a single user, actively reports the location update message when the user terminal 13 switches between tracking areas TA, and controls the policy of the tracking area code TAC carried in the session message of the session management module SMF: when the tracking area code TAC is in the allowed list, a dynamic control policy such as service quality guarantee is issued; when the tracking area code TAC is not in the allowed list, all user traffic is blocked, so as to realize that the user traffic does not go out of the park.
[0100] The main scenarios involved are exemplified as follows:
[0101] As shown in FIG. 1, scenario one: the park 1 is defined as the coverage range of the base station 3, and the base station 1, the base station 2 and the base station 3 are all under the same tracking area code TAC. Figure 9
[0102] In this scenario, only the access restriction at the tracking area code TAC level configured by the policy control module PCF can accurately control the access to the park 1. Therefore, the base station 1 or the base station 2 is configured with the default slice A0, the base station 3 is configured with the park public slice A1, and the policy control module PCF is configured with the corresponding session control policy according to the tracking area code TAC1.
[0103] For the user of the park, the subscribed network slice is S1, S1=A1 in this scenario, and the slice R requested by the user terminal 13 is empty. Therefore, the final allowed slice is A1 in this scenario, and the user subscribed to S1 can normally complete the registration access process. After the session is established, the policy control module PCF judges that the tracking area code TAC1 is in the allowed list, and then issues a higher priority service policy. When the user moves to an area outside the base station 3, the final allowed slice A1 is empty, and the user access is rejected.
[0104] For the user of the park, the subscribed network slice is S1, S1=A1 in this scenario, and the slice R requested by the user terminal 13 is empty. Therefore, the final allowed slice is A1 in this scenario, and the user subscribed to S1 can normally complete the registration access process. After the session is established, the policy control module PCF judges that the tracking area code TAC1 is in the allowed list, and then issues a higher priority service policy. When the user moves to an area outside the base station 3, the final allowed slice A1 is empty, and the user access is rejected.
[0105] According to the above analysis result, in this scenario, it can be ensured that the user outside the park cannot access the intranet no matter where he is located, and the user in the park can access the intranet and enjoy higher service quality when he is in the park, and the access is rejected when he moves out of the park, thereby realizing the bidirectional safe access restriction.
[0106] If different customers are all configured with the same slice, the terminal may access through other base stations outside the park. In this scenario, the location restriction of the tracking area code TAC needs to be superimposed, that is, the tracking area code TAC location control policy is issued by the policy control module PCF to realize the area restriction of different parks under the same slice (without the need to re-adjust the tracking area code TAC).
[0107] As shown in FIG. 2, scenario two: the park 1 is defined as the coverage range of the base station 3, the park 2 is defined as the coverage range of the base station 4, and the base station 1, the base station 2 and the base station 3 are all under the same tracking area code TAC. Figure 10
[0108] Base stations 1 and 2 are configured with the default slice A0, and base stations 3 and 4 are configured with the campus public slice A1. At the same time, the policy control module PCF configures the corresponding session control policies according to the tracking area code TAC1 and tracking area code TAC2 respectively. The tracking area code TAC that users in campus 1 are allowed to access is TAC1, and the tracking area code TAC that users in campus 2 are allowed to access is TAC2.
[0109] For users in Park 1 and Park 2, the contracted network slice is S1. In this scenario, S1 = A1, and the slice R requested by user terminal 13 is empty by default. Therefore, in this scenario, Park 1 and Park 2 are ultimately allowed to use slice A1, and users who have signed up for S1 can complete the registration and access process normally.
[0110] In this scenario, the access restrictions for Campus 1 under Tracking Area Code (TAC1) are consistent with those in Scenario 1. If a user in Campus 1 moves to Campus 2, a location reporting event is triggered. Since they share the same public slice, the user in Campus 1 can still access Campus 2 normally. After entering the session establishment process, the Policy Control Module (PCF) determines that the reported Tracking Area Code (TAC2) is not in the allowed access list and issues a traffic blocking policy. This results in normal access, but the user cannot access the intranet of Campus 1. If the user moves back to Campus 1, reports a location update to the PCF, and normal service is restored in real time.
[0111] For users in Park 2, services can only be accessed normally within the coverage area of base station 4. The reasons for blocking in other situations are the same as those in Park 1.
[0112] Based on the above analysis, in this scenario, it can be ensured that users in this park cannot access the network when they move to different parks under the same slice. Users can only access the intranet and enjoy higher service quality when they are in the park.
[0113] like Figure 11 As shown in Scenario 3: Park 1 is defined as the coverage area of base station 3, and Park 2 is defined as the coverage area of base station 4 and base station 5. Base station 1, base station 2, base station 3, base station 4, and base station 5 are all under the same Tracking Area Code (TAC).
[0114] Base stations 1 and 2 are configured with the default slice A0, base station 3 is configured with the campus public slice A1, and base stations 4 and 5 are configured with the campus public slice A2. At the same time, the policy control module PCF configures the corresponding session control policy according to the tracking area code TAC1, and configures the tracking area code TAC that users in campus 1 and campus 2 are allowed to access to be the tracking area code TAC1.
[0115] For the user of park 1, the subscribed network slice is S1, S1=A1 in this scenario, and the terminal request slice R is empty by default. For the user of park 2, the subscribed network slice is S2, S1=A2 in this scenario, and the terminal request slice R is empty by default. Therefore, the final allowed slice of park 1 is A1, and the final allowed slice of park 2 is A2 in this scenario.
[0116] In this scenario, if the user of park 1 moves to park 2, the user of park 1 cannot normally access due to different slices. Similarly, if the user of park 1 moves to park 2, the user of park 2 cannot normally access due to different slices.
[0117] The analysis of park 1 and park 2 accessing areas outside the tracking area code TAC1 is the same as scenario 1, which will not be repeated here.
[0118] According to the above analysis results, in this scenario, it can be ensured that when the users of different parks under the same tracking area code TAC move to different parks under the same tracking area code TAC, they cannot access the intranet, and can only access the intranet when they are in the park, and enjoy higher service quality.
[0119] The embodiment of the application also provides a 5G SA network Internet of Things terminal access and access restriction system, which is used to execute any embodiment of the foregoing 5G SA network Internet of Things terminal access and access restriction method. Specifically, please refer to Figure 12 , Figure 12 The 5G SA network Internet of Things terminal access and access restriction system provided by the embodiment of the application is shown in the schematic block diagram.
[0120] As Figure 12 shown, the system includes an Internet of Things terminal 11, a network manager 12, and a user terminal 13. The network manager 12 establishes network connections with the Internet of Things terminal 11 and the user terminal 13 respectively to realize transmission of data information. The system includes an attachment request unit 111 configured in the Internet of Things terminal 11, a first sending unit 131 configured in the user terminal 13, a receiving unit 121, a first acquisition unit 122, a judgment unit 123, a second acquisition unit 124, a second sending unit 125, a third acquisition unit 126, and a third sending unit 127 configured in the network manager 12.
[0121] The attachment request unit 111 is used for the network manager 12 to receive an attachment request from the Internet of Things terminal 11.
[0122] The first sending unit 131 is used for controlling the user terminal 13 to send an access network message if the network manager 12 receives an attachment request from the Internet of Things terminal 11.
[0123] The receiving unit 121 is configured to receive, by the network manager 12, an access network message, and determine, by the radio access network (RAN), an access management module (AMF) corresponding to the access network message.
[0124] The first obtaining unit 122 is configured to obtain, by the determined access management module (AMF), a user-subscribed network slice (S) corresponding to the access network message from a preset slice database.
[0125] The determining unit 123 is configured to determine whether the determined access management module (AMF) can process the user-subscribed network slice (S).
[0126] The second obtaining unit 124 is configured to, if the determined access management module (AMF) cannot process the user-subscribed network slice (S), obtain, by the network slice selection module, an allowed slice (A) corresponding to the user-subscribed network slice (S) and a target access management module (AMF).
[0127] The second sending unit 125 is configured to resend, by the network slice selection module, the allowed slice (A) to the target access management module (AMF).
[0128] The third obtaining unit 126 is configured to obtain, by the target access management module (AMF), a user-subscribed policy corresponding to the allowed slice (A) from a policy control module (PCF).
[0129] The third sending unit 127 is configured to send, by the target access management module (AMF), the user-subscribed policy to the IoT terminal 11, so that the IoT terminal 11 accesses the target access management module (AMF).
[0130] The above-mentioned method for limiting access and access of the 5G SA network IoT terminal can be implemented in the form of a computer program, and the IoT terminal 11 and the network manager 12 in the system for limiting access and access of the 5G SA network IoT terminal can be implemented as computer devices. The computer program can run on the computer device as shown in Figure 13 .
[0131] Here, the IoT terminal 11 includes a first memory, a first processor, and a first computer program stored in the first memory and executable on the first processor. The network manager 12 includes a second memory, a second processor, and a second computer program stored in the second memory and executable on the second processor. The user terminal 13 includes a third memory, a third processor, and a third computer program stored in the third memory and executable on the third processor. When the first processor executes the first computer program, the second processor executes the second computer program, and the third processor executes the third computer program, the above-mentioned method for limiting access and access of the 5G SA network IoT terminal is collectively implemented.
[0132] Please refer to Figure 13 .Figure 13 is a schematic block diagram of a computer device provided by an embodiment of the present application. The computer device can be used to execute the method for 5G SA network IoT terminal access and access restriction to implement that the network manager judges whether the user terminal can access the intranet according to the attachment request of the IoT terminal and the access network message sent by the user terminal.
[0133] Referring to Figure 13 The computer device 500 includes a processor 502, a memory and a network interface 505 connected through a system bus 501, wherein the memory can include a storage medium 503 and an internal memory 504.
[0134] The storage medium 503 can store an operating system 5031 and a computer program 5032. The computer program 5032, when executed, can cause the processor 502 to execute the method for 5G SA network IoT terminal access and access restriction, wherein the storage medium 503 can be a volatile storage medium or a non-volatile storage medium.
[0135] The processor 502 is configured to provide computing and control capabilities to support the operation of the entire computer device 500.
[0136] The internal memory 504 provides an environment for the execution of the computer program 5032 in the storage medium 503, and the computer program 5032, when executed by the processor 502, can cause the processor 502 to execute the method for 5G SA network IoT terminal access and access restriction.
[0137] The network interface 505 is configured to perform network communication to provide transmission of data information, and the network communication can be wired network communication and / or wireless network communication. Those skilled in the art can understand that Figure 10 The structure shown in the figure is only a block diagram of part of the structure related to the present application scheme, and does not constitute a limitation on the computer device 500 to which the present application scheme is applied. The specific computer device 500 can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0138] The processor 502 is configured to run the computer program 5032 stored in the memory to implement the corresponding functions in the above-mentioned method for 5G SA network IoT terminal access and access restriction.
[0139] Those skilled in the art can understand that Figure 13The embodiments of the computer device shown in the figures do not constitute a limitation on the specific structure of the computer device, and in other embodiments, the computer device can include more or fewer components than shown, or combine certain components, or arrange the components differently. For example, in some embodiments, the computer device can only include the memory and the processor, and in such embodiments, the structure and function of the memory and the processor are consistent with the embodiments shown. Figure 13
[0140] It should be understood that, in the embodiments of the present application, the processor 502 can be a central processing unit (CPU), and the processor 502 can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0141] In another embodiment of the present application, a computer readable storage medium is provided. The computer readable storage medium can be a volatile or non-volatile computer readable storage medium. The computer readable storage medium stores a first computer program, a second computer program or a third computer program, which, when executed by a first processor, a second processor and a third processor, respectively, collectively implement the steps included in the above-mentioned SIM card-based Internet of Things directional traffic management method.
[0142] In several embodiments provided by the present application, it should be understood that the disclosed system, device and unit can be implemented by other means. For example, the above-described device embodiments are only schematic, and the division of the units is only a logical function division, and there can be another division manner in actual implementation, or a plurality of units or components with the same function can be combined into one unit, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can also be electrical, mechanical or other forms of connection.
[0143] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e. may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment of the present application.
[0144] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0145] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the present application, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a computer readable storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned computer readable storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a magnetic disk or an optical disk, and various program code storage media.
[0146] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for restricting access and access to IoT terminals in a 5G SA network, characterized in that, The method is applied to an SA network Internet of Things (IoT) system, which includes IoT terminals, a network manager, and user terminals. The network manager establishes network connections with both the IoT terminals and the user terminals to transmit data. The network manager includes a radio access network, an access management module, a network slice selection module, and a policy control module. The method includes: If the network manager receives an attach request from the IoT terminal, it controls the user terminal to send an access network message; The network manager receives the access network message, and the radio access network determines the access management module corresponding to the access network message; The access management module determines that it obtains the user-subscribed network slice corresponding to the access network message from a preset slice database. Determine whether the determined access management module can process the user's subscribed network slice; If the determined access management module cannot process the user's subscribed network slice, the network slice selection module obtains the allowed slice and target access management module corresponding to the user's subscribed network slice. The network slice selection module resends the allowed slice to the target access management module; The target access management module obtains the pre-stored user subscription policy corresponding to the allowed slice from the policy control module; The user subscription policy is sent to the IoT terminal so that the IoT terminal can access the target access management module; The target access management module obtains the pre-stored user subscription policy corresponding to the allowed slice from the policy control module, including: The policy control module switches between tracking zones for a single user corresponding to an allowed slice based on a preset tracking zone code, in order to obtain the user subscription policy. The network manager also includes a session management module. The policy control module controls user session policies based on a preset tracking zone code. The policy control module switches between tracking zones for a single user to obtain the user's subscription policy, including: If the tracking area switching signal is received from the user terminal, the location is actively reported to update the access network message; The radio access network re-identifies and updates the access network message to the corresponding access management module; The corresponding access management module reports the updated access network message to the policy control module through a preset interface; The policy control module performs session policy control on the tracking area code carried in the session management module.
2. The method for restricting access to and access to IoT terminals in a 5G SA network according to claim 1, characterized in that, The radio access network determines the access management module corresponding to the access network message, including: The access network message is parsed to obtain the corresponding GUAMI information; Determine whether a matching access management module can be obtained based on the GUAMI information; If a matching access management module can be obtained based on the GUAMI information, then obtaining one matching access management module is considered a determined access management module. If a matching access management module cannot be obtained based on the GUAMI information, the corresponding access management module is determined based on the request slice in the access network message.
3. The method for restricting access to and access to IoT terminals in a 5G SA network according to claim 2, characterized in that, Before determining the corresponding access management module based on the request slice in the access network message, the method further includes: Determine whether the access network message contains a request slice; If the access network message contains a request slice, then the step of determining the corresponding access management module based on the request slice in the access network message is executed; If the access network message does not contain a slice request, a registration request is sent to the default access management module.
4. The method for restricting access to and access to IoT terminals in a 5G SA network according to claim 1, characterized in that, The policy control module performs policy control on the tracking area encoding carried in the session management module, including: If the tracking zone code is in the allowed list of the session management module, a dynamic policy is issued to ensure the output of the first policy; the first policy is a higher quality of service policy. If the tracking area code is not in the allowed list of the session management module, a blocking instruction is issued to ensure the output of the second strategy, thereby blocking all user traffic and ensuring that user traffic does not leave the park; the second strategy is the highest global priority of the corresponding business rule.
5. The method for restricting access to and access to IoT terminals in a 5G SA network according to claim 2, characterized in that, The determined access management module obtains the user-subscribed network slice corresponding to the access network message from a preset slice database, and further includes: If the target access management module obtains the user subscription policy, it determines whether the requested slice, the user subscription network slice, and the allowed slice can be combined to form an intersection slice; If an intersection slice can be formed, then the user terminal is allowed to access; If an intersection slice cannot be formed, the user terminal access is rejected.
6. A system for restricting access to and access to IoT terminals in a 5G SA network, characterized in that, The system includes an IoT terminal, a network manager, and a user terminal. The network manager establishes network connections with the IoT terminal and the user terminal respectively to realize the transmission of data information. The system includes an attach request unit configured in the IoT terminal, a first sending unit configured in the user terminal, and a receiving unit, a first acquiring unit, a judging unit, a second acquiring unit, a second sending unit, a third acquiring unit, and a third sending unit configured in the network manager. An attach request unit is used when the network manager receives an attach request from the IoT terminal; The first sending unit is configured to control the user terminal to send an access network message if the network manager receives an attach request from the IoT terminal. The receiving unit is used for the network manager to receive the access network message, and the radio access network to determine the access management module corresponding to the access network message; The first acquisition unit is used to obtain the user-subscribed network slice corresponding to the access network message from a preset slice database by the determined access management module. The judgment unit is used to determine whether the determined access management module can process the user's subscribed network slice; The second acquisition unit is used to acquire the allowed slice and target access management module corresponding to the user's subscribed network slice if the determined access management module cannot process the user's subscribed network slice. The second sending unit is used by the network slice selection module to resend the allowed slice to the target access management module; The third acquisition unit is used by the target access management module to acquire the pre-stored user subscription policy corresponding to the allowed slice from the policy control module; The third sending unit is used to send the user subscription policy to the Internet of Things terminal so that the Internet of Things terminal can access the target access management module; The target access management module obtains the pre-stored user subscription policy corresponding to the allowed slice from the policy control module, including: The policy control module switches between tracking zones for a single user corresponding to an allowed slice based on a preset tracking zone code, in order to obtain the user subscription policy. The network manager also includes a session management module. The policy control module controls user session policies based on a preset tracking zone code. The policy control module switches between tracking zones for a single user to obtain the user's subscription policy, including: If the tracking area switching signal is received from the user terminal, the location is actively reported to update the access network message; The radio access network re-identifies and updates the access network message to the corresponding access management module; The corresponding access management module reports the updated access network message to the policy control module through a preset interface; The policy control module performs session policy control on the tracking area code carried in the session management module.
7. A system for restricting access to and access to IoT terminals in a 5G SA network, characterized in that, The system includes an IoT terminal, a network manager, and a user terminal. The IoT terminal includes a first memory, a first processor, and a first computer program stored in the first memory and executable on the first processor. The network manager includes a second memory, a second processor, and a second computer program stored in the second memory and executable on the second processor. The user terminal includes a third memory, a third processor, and a third computer program stored in the third memory and executable on the third processor. The system is characterized in that the first processor executing the first computer program, the second processor executing the second computer program, and the third processor executing the third computer program jointly implement the method for 5GSA network IoT terminal access and access restriction as described in any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a first computer program, a second computer program, and a third computer program, which, when the first computer program is executed by a first processor, the second computer program is executed by a second processor, and the third computer program is executed by a third processor, jointly implement the method for access and access restriction of 5G SA network IoT terminals as described in any one of claims 1 to 5.
Citation Information
Patent Citations
5G network communication control method, device, platform and system
CN110719571A
Method and device for policy control
CN113709766A