Differentiated Control Method and Device, Equipment and Storage of User Terminal
By applying for virtual identification for user terminals and associating storage, the problem that the mobile core network cannot perform differentiated control of access gateway user terminals is solved, and differentiated management and service quality control of user terminals are realized.
Patent Information
- Application Number
- CN202210069544.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-21
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-01-21
AI Technical Summary
In the prior art, the mobile core network cannot perform differentiated control and management of user terminals accessing the gateway, and cannot meet the needs of differentiated strategy control for individual users in actual applications.
By applying for a virtual identity for each user terminal, the physical address and virtual identity of the user terminal are associated with the virtual identity to be stored in the home gateway, and the user terminal is then differentiatedly controlled according to the virtual identity.
It realizes differentiated control and management of user terminals that access the gateway, meeting the differentiated needs of different user terminals in service quality and policy control.
Smart Images

Figure CN116527733B_ABST
Abstract
Description
Background Art
[0002] In the prior art, for the solution of non-3GPP (3rd Generation Partnership Project) accessing the 5G core network (5GCN, 5th Generation Mobile Communication Technology Core Network), a wired access method can be adopted. Wired access means that a gateway inserted with a 5G subscriber identity module (SIM) accesses the 5GC of a manufacturer.
[0003] In the prior art wired access solution, the gateway of the 5G subscriber identity module is regarded as a separate user, and the 5GC performs access control on it. However, the 5GC does not consider the policy control of the user terminals accessed under the gateway, and cannot perform differentiated control and management on the user terminals accessing the gateway. In actual applications, there are many scenarios that require differentiated policy control for individual users. For example, a residential gateway (RG) used in a library needs to provide high-quality of service (QoS) guarantee for administrators and low-quality of service guarantee for visitors, and a residential gateway used at home provides high-quality of service guarantee for family members and low-quality of service guarantee for visitors.
[0004] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0005] The present disclosure provides a method and device, equipment and storage for differentiated control of user terminals, which at least overcome to a certain extent the problem that the mobile core network in the related art cannot perform differentiated control and management on user terminals accessing the gateway.
[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or will be learned in part through the practice of the present disclosure.
[0007] According to one aspect of the present disclosure, a method for differentiated control of user terminals is provided, including: when a home gateway receives an attachment request from one or more user terminals, applying a virtual identifier for each user terminal; associating and storing the physical address and the corresponding virtual identifier of each user terminal in the home gateway; and performing differentiated control on each user terminal under the home gateway according to the physical address and the corresponding virtual identifier of each user terminal associated and stored in the home gateway.
[0008] In an embodiment of the present disclosure, when the home gateway receives an attachment request from one or more user terminals, a virtual identifier is applied for each user terminal, including: when the home gateway receives an attachment request from one or more user terminals, a virtual identifier application request for each user terminal is initiated to the RVIM platform for managing the virtual identifier of the home gateway through the home gateway, wherein a plurality of virtual identifiers are pre-deployed in the RVIM platform, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of each user terminal; the virtual identifiers of each user terminal returned by the RVIM platform are received through the home gateway, wherein the RVIM platform is further configured to associatively store the physical address, virtual identifier, and gateway identifier of each user terminal and synchronize them to the core network.
[0009] In an embodiment of the present disclosure, differential control is performed on each user terminal under the home gateway according to the physical addresses and corresponding virtual identifiers of each user terminal associatively stored in the home gateway, including: when the home gateway receives a service request initiated by one or more user terminals, the corresponding virtual identifier is obtained according to the physical address of each user terminal; a session establishment request is initiated to the core network according to the virtual identifier of each user terminal.
[0010] According to another aspect of the present disclosure, a method for differential control of a user terminal is provided, including: receiving a virtual identifier application request from a home gateway, wherein the virtual identifier application request is used to apply for corresponding virtual identifiers for one or more user terminals attached to the home gateway, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of each user terminal; according to the virtual identifier application request, the virtual identifiers of each user terminal are returned to the home gateway, wherein the home gateway associatively stores the physical addresses and corresponding virtual identifiers of each user terminal to perform differential control on each user terminal under the home gateway.
[0011] In an embodiment of the present disclosure, after returning one or more virtual identifiers to the home gateway according to the virtual identifier application request, the method further includes: associatively storing the physical address, virtual identifier, and gateway identifier of each user terminal.
[0012] In one embodiment of the present disclosure, a differential control system for a user terminal is provided, which is characterized by including: a core network, a Home Gateway Virtual Identity Management (RVIM) platform, a home gateway, and one or more user terminals attached to the home gateway; wherein, the home gateway is configured to initiate a virtual identity application request for each user terminal to the RVIM platform when receiving an attachment request from one or more user terminals; the RVIM platform is configured to allocate a virtual identity for each user terminal according to the received virtual identity application request and return it to the home gateway; the core network communicates with the home gateway and is configured to perform differential control on each user terminal under the home gateway according to the physical addresses and corresponding virtual identities of the user terminals under the home gateway.
[0013] According to another aspect of the present disclosure, an electronic device is provided, including: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the differential control method of the user terminal as described above by executing the executable instructions.
[0014] According to yet another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the differential control method of the user terminal as described above is implemented.
[0015] The differential control method, device, equipment, and storage for the user terminal provided by the embodiments of the present disclosure, by applying for a virtual identity for each user terminal, associating the physical addresses of the user terminals with the corresponding virtual identities, and then performing differential control on each user terminal according to the differences in the virtual identities. In the embodiments of the present disclosure, since the physical addresses of the user terminals are associated with the corresponding virtual identities, the mobile core network can distinguish the user terminals accessing the gateway, which helps to perform differential control and management on the user terminals.
[0016] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0018] Figure 1 A schematic diagram showing the structure of a differential control system for a user terminal in an embodiment of the present disclosure;
[0019] Figure 2 Shows the flowchart of a differential control method for a user terminal in an embodiment of the present disclosure;
[0020] Figure 3 Shows the flowchart of another differential control method for a user terminal in an embodiment of the present disclosure;
[0021] Figure 4 Shows the schematic diagram of a differential control system for a user terminal in an embodiment of the present disclosure;
[0022] Figure 5 Shows the schematic diagram of the architecture of a differential control system for a user terminal in an embodiment of the present disclosure;
[0023] Figure 6 Shows the operation flowchart of a differential control system for a user terminal in an embodiment of the present disclosure;
[0024] Figure 7 Shows the home gateway authentication process in a differential control method for a user terminal in an embodiment of the present disclosure;
[0025] Figure 8 Shows the user terminal authentication process in a differential control method for a user terminal in an embodiment of the present disclosure;
[0026] Figure 9 Shows the schematic diagram of a differential control device for a user terminal in an embodiment of the present disclosure;
[0027] Figure 10 Shows the schematic diagram of another differential control device for a user terminal in an embodiment of the present disclosure;
[0028] Figure 11 Shows the block diagram of the structure of an electronic device in an embodiment of the present disclosure;
[0029] Figure 12 Shows the schematic diagram of a computer-readable storage medium in an embodiment of the present disclosure. Detailed implementation manners
[0030] Now, example embodiments will be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.
[0031] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0032] For ease of understanding, several terms related to the present disclosure are first explained as follows:
[0033] Home Gateway: Residential Gateway, RG.
[0034] Home Gateway Virtual-IMSI Management: Residential Gateway Virtual-IMSI Management, RVIM.
[0035] International Mobile Subscriber Identity: IMSI, International Mobile Subscriber Identity, is an identification code used to distinguish different users in a cellular network and is not repeated in all cellular networks.
[0036] User Equipment: User Equipment, UE.
[0037] Physical Address: Media Access Control, MAC, the actual address corresponding to the storage unit in the network card physical address memory is called the physical address, which corresponds to the logical address.
[0038] Wireline Access Gateway Function: Wireline Access Gateway Function, W-AGF.
[0039] User Plane Function: User Plane Function, UPF, as a user plane network element in the 5GC network, mainly supports the routing and forwarding of UE service data, data and service identification, action and policy execution, etc.
[0040] Unified Data Storage and Management Device: unifieddata manager, UDM.
[0041] Authentication Server: Authentication Server Function, AUSF.
[0042] The Extensible Authentication Protocol (EAP) is a commonly used authentication framework protocol that supports multiple authentication methods and is mainly used for network access authentication. EAP can be applied to both wireless and wired networks.
[0043] Wireless network communication technology: Wi-Fi is a trademark of Wi-Fi Alliance manufacturers for product brand authentication and is used to wirelessly connect network devices to each other.
[0044] 3rd Generation Partnership Project: 3GPP
[0045] Quality of Service (QoS) refers to a network's ability to use various underlying technologies to provide better service capabilities for specified network communications. It is a security mechanism of the network and a technology used to solve problems such as network latency and congestion.
[0046] Protocol Data Unit: PDU
[0047] Protocol Data Unit Session is a new abstract concept in the 5G system that provides a service for PDU transfer between the UE and the DN.
[0048] Data Network, such as operator services, the Internet, or third-party services, etc.
[0049] The following will explain this exemplary embodiment in detail with reference to the accompanying drawings and embodiments.
[0050] First, Figure 1 A schematic diagram of an exemplary system architecture of a differential control method for a user terminal or a differential control method device for a user terminal that can be applied to the embodiments of the present disclosure is shown.
[0051] As Figure 1 shown, the system architecture 100 may include a terminal device 101, a network 102, and a server 103.
[0052] Among them, the terminal device 101 sends an attachment request to the server 103 through the network 102. When the server 103 receives the attachment requests of one or more terminal devices, it applies for a virtual identifier for each terminal device; the server 103 associates and stores the physical addresses of each terminal device and the corresponding virtual identifiers in the server 103; according to the physical addresses of each terminal device and the corresponding virtual identifiers associated and stored in the server 103, differential control is performed on each terminal device under the server 103.
[0053] In an embodiment of the present disclosure, the above-mentioned server 103 is further configured to: when the server receives the attachment requests of one or more terminal devices, initiate a virtual identifier application request for each terminal device to the Home Gateway Virtual Identifier Management RVIM platform through the server 103, where a plurality of virtual identifiers are pre-deployed in the RVIM platform, and the virtual identifier application request includes: the gateway identifier of the server 103 and the physical addresses of each terminal device; receive the virtual identifiers of each terminal device returned by the RVIM platform through the server 103, where the RVIM platform is further configured to associate and store the physical address, virtual identifier, and gateway identifier of each terminal device and synchronize them to the core network.
[0054] In an embodiment of the present disclosure, the above-mentioned server 103 is further configured to: when the server receives the service requests initiated by each terminal device, obtain the corresponding virtual identifier according to the physical address of each terminal device; initiate a session establishment request to the core network according to the virtual identifier of each terminal device.
[0055] It should be noted that the above-mentioned network 102 is a medium for providing a communication link between the terminal device 101 and the server 103, which can be a wired network or a wireless network.
[0056] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network. In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec), etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can be used to replace or supplement the above data communication technologies.
[0057] The terminal device 101 can be various electronic devices, including but not limited to smartphones, tablets, laptop computers, desktop computers, wearable devices, augmented reality devices, virtual reality devices, etc.
[0058] Optionally, the clients of the application programs installed on different terminal devices 101 are the same, or are clients of the same type of application program based on different operating systems. Depending on the different terminal platforms, the specific form of the client of the application program can also be different. For example, the client of the application program can be a mobile client, a PC client, etc.
[0059] The server 103 can be a server that provides various services, such as a background management server that supports the operations performed by the user using the terminal device 101. The background management server can analyze and process data such as requests received, and feedback the processing results to the terminal device.
[0060] Optionally, the server may be an independent physical server, a residential gateway (RG), or a server cluster or distributed system composed of multiple physical servers. It may also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The terminal may be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The terminal and the server may be directly or indirectly connected through wired or wireless communication methods, and this application does not make any restrictions here.
[0061] Those skilled in the art can know that Figure 1 the numbers of the terminal devices, networks, and servers in
[0062] In the embodiments of the present disclosure, a method for differential control of a user terminal is provided, and this method can be executed by any electronic device with computing and processing capabilities.
[0063] Figure 2 The flowchart of a method for differential control of a user terminal in the embodiments of the present disclosure is shown. As Figure 2 shown, the method for differential control of a user terminal provided in the embodiments of the present disclosure includes the following steps:
[0064] S202, when the home gateway receives an attachment request from one or more user terminals, apply a virtual identifier for each user terminal.
[0065] It should be noted that the above home gateway RG is a device that allows a local area network (LAN) to be connected to a wide area network (WAN) in a telecommunications network. The above user terminal may be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The above attachment request, whose English name is Attach Request, is a NAS (Non-Access Stratum) signaling. When the home gateway has not established a default bearer, data transmission with the user terminal is performed through NAS signaling. The above virtual identifier may be a string of characters, which is used to mark different user terminals for distinguishing user terminals.
[0066] In an embodiment of the present disclosure, when the home gateway receives an attachment request from one or more user terminals, applying a virtual identifier for each user terminal may include: when the home gateway receives an attachment request from one or more user terminals, initiating a virtual identifier application request for each user terminal to the home gateway virtual identifier management RVIM platform through the home gateway, where multiple virtual identifiers are pre-deployed in the RVIM platform, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of each user terminal; receiving, through the home gateway, the virtual identifiers of each user terminal returned by the RVIM platform, where the RVIM platform is further configured to store the physical address, virtual identifier, and gateway identifier of each user terminal in an associated manner and synchronize them to the core network.
[0067] For example, in one instance, when the user terminal UE registers, the RG applies for a virtual identifier from the RVIM. First, the RG identifies whether the identity of the online user terminal is an administrator or a visitor (for example, the RG stores a database in which the MAC addresses of administrator devices are stored. If the MAC address of the online user terminal is not in the database, it is determined as a visitor). In this way, when the RG applies for a virtual identifier, it can carry a label indicating the quality of service. The administrator device applies for a virtual identifier with high QOS, and the visitor device applies for a virtual identifier with low qos. This virtual identifier itself can represent different QoS through the difference of a certain bit. In this way, when the subsequent user terminal UE conducts data services, the 5GC can directly determine whether to provide high QOS or low QOS for the user terminal UE according to the virtual identifier.
[0068] In the embodiments of the present disclosure, by allocating virtual identifiers to user terminals, different user terminals are distinguished by the virtual identifiers, which helps to perform differential control and management on the user terminals.
[0069] S204, storing the physical addresses of each user terminal and the corresponding virtual identifiers in an associated manner in the home gateway.
[0070] It should be noted that the above user terminals may be smart phones, tablet computers, laptop computers, desktop computers, smart speakers, smart watches, etc., but are not limited thereto. The above physical address may be a MAC address, which is the address of the host of the user terminal that sends data when transmitting data. The corresponding virtual identifier is a string of characters allocated for each user terminal to distinguish different user terminals.
[0071] In the embodiments of the present disclosure, by storing the association relationship between the physical addresses of each user terminal and the corresponding virtual identifiers in the home gateway, it helps to perform differential control and management on the user terminals when establishing a session in the home gateway.
[0072] S206. Differentially control each user terminal under the home gateway according to the physical addresses and corresponding virtual identifiers of each user terminal associated and stored in the home gateway.
[0073] It should be noted that the above home gateway is a device that allows a local area network (LAN) to connect to a wide area network (WAN) in a telecommunications network. The above user terminals may be smart phones, tablet computers, laptop computers, desktop computers, smart speakers, smart watches, etc., but are not limited thereto. The above physical address may be a MAC address, which is the address of the host of the user terminal that sends data when transmitting data. The above corresponding virtual identifier is a string of characters assigned to each user terminal for differentiating different user terminals. The above differential control means that different user terminals can be managed differently according to the virtual identifier corresponding to the user terminal.
[0074] In an embodiment of the present disclosure, differentially controlling each user terminal under the home gateway according to the physical addresses and corresponding virtual identifiers of each user terminal associated and stored in the home gateway may include: when the home gateway receives service requests initiated by each user terminal, obtaining the corresponding virtual identifier according to the physical address of each user terminal; and initiating a session establishment request to the core network according to the virtual identifier of each user terminal.
[0075] For example, in a 5GC scenario of a library, many users connect to the RG of this 5GC via Wi-Fi. Among them, the mobile phone of the library administrator (equivalent to the above user terminal) requires a high QS, and a number with the sixth digit of the IMSI (equivalent to the above virtual identifier) being two is assigned. The mobile phone of the library visitor requires a low QS, and a number with the sixth digit of the IMSI being one is assigned, so as to differentially control the mobile phone of the administrator and the mobile phone of the visitor under the RG (equivalent to the above each user terminal).
[0076] In the embodiment of the present disclosure, through the physical addresses and corresponding virtual identifiers of each user terminal associated and stored in the home gateway, the mobile core network can differentially control and manage the user terminals accessing the gateway.
[0077] In an embodiment of the present disclosure, as Figure 3 shown, the embodiment of the present disclosure also provides a method for differentially controlling a user terminal, including the following steps:
[0078] S302. Receive a virtual identity application request from the home gateway. The virtual identity application request is used to apply for corresponding virtual identities for one or more user terminals attached to the home gateway. The virtual identity application request includes the gateway identity of the home gateway and the physical addresses of the respective user terminals.
[0079] It should be noted that the above home gateway is a device that allows a local area network to connect to a wide area network in a telecommunications network. The above virtual identity can be a string of characters used to mark different user terminals for differentiating them. The above user terminals can be smart phones, tablet computers, laptop computers, desktop computers, smart speakers, smart watches, etc., but are not limited thereto. The above gateway identity is the IMSI. The above physical address is the MAC address, which is the address of the user terminal that sends data during data transmission.
[0080] In the embodiments of the present disclosure, different user terminals are distinguished by using virtual identities, which helps to perform differential control and management on the user terminals.
[0081] S304. According to the virtual identity application request, return the virtual identities of one or more user terminals to the home gateway. The home gateway associates and stores the physical addresses of the respective user terminals with the corresponding virtual identities to perform differential control on the respective user terminals under the home gateway.
[0082] It should be noted that the above virtual identity can be a string of characters used to mark different user terminals for differentiating them. The above home gateway is a device that allows a local area network to connect to a wide area network in a telecommunications network.
[0083] In the embodiments of the present disclosure, through the physical addresses of the respective user terminals associated and stored in the home gateway and the corresponding virtual identities, the mobile core network can perform differential control and management on the user terminals accessing the gateway.
[0084] In an embodiment of the present disclosure, as Figure 4 shown, the embodiments of the present disclosure also provide a schematic diagram of a differential control system for user terminals, including a core network 401, a home gateway virtual identity management RVIM platform 402, a home gateway 403, and one or more user terminals 404 attached to the home gateway.
[0085] Among them, the home gateway is used to initiate a virtual identity application request for each user terminal to the RVIM platform when receiving an attachment request from one or more user terminals;
[0086] The RVIM platform is used to allocate a virtual identity for each user terminal according to the received virtual identity application request and return it to the home gateway;
[0087] The core network communicates with the home gateway and is used to perform differential control on each user terminal under the home gateway according to the physical addresses and corresponding virtual identifiers of the user terminals under the home gateway.
[0088] In the embodiments of the present disclosure, through the physical addresses and corresponding virtual identifiers of each user terminal associated and stored in the home gateway, the mobile core network can perform differential control and management on the user terminals accessing the gateway.
[0089] In one embodiment of the present disclosure, as Figure 5 shown, the embodiments of the present disclosure also provide a schematic diagram of the architecture of a differential control system for user terminals, which includes:
[0090] 5G RG502 is respectively connected to UE501, RVIM503, and W-AGF504. W-AGF is respectively connected to AMF505 and UPF506. RVIM is connected to UDM507. UDM is connected to AUSF508. AUSF is connected to AMF.
[0091] RVIM503 is used to set a certain number of temporary number (IMSI) pools and synchronize them to UDM in real time. In the RG registration process, after successful registration, UDM needs to notify the RVIM platform through New Interface1 that the RG has been accessed. RVIM saves a list of currently authenticated numbers and updates it in real time. When the UE / Device (equivalent to the above user terminal) attaches to 5G-RG through the Y1 interface, 5G-RG applies to RVIM for a virtual identifier (carrying the IMSI of 5G RG and the MAC address of the UE / Device) through New Interface1. RVIM is used to allocate a temporary number (equivalent to the above virtual identifier) to the above UE / Device and save the binding relationship between the temporary number and the device MAC address.
[0092] 5G-RG is used to apply to RVIM for a virtual identifier (carrying the IMSI of 5G RG and the MAC address of the UE / Device) through New Interface1 after the UE / Device attaches to 5G-RG through the Y1 interface. After obtaining the temporary number from RVIM, 5G-RG also establishes a binding relationship between the temporary number and the device MAC address. 5G-RG supports the ability to initiate multiple authentications and establish multiple PDU Sessions to W-AGF with multiple IMSIs.
[0093] UDM is used to synchronize all the temporary numbers in RVIM in real time and notify the RVIM platform that the 5G-RG has been accessed after the 5G-RG authentication is successful.
[0094] In one embodiment, in the 5G RG registration process, when the registration is successful, UDM notifies RVIM that the RG has been authenticated. RVIM should save a list of currently authenticated numbers and update it in real time. When the UE / Device attaches to the 5G-RG through the Y1 interface, the 5G-RG applies to RVIM for a virtual identifier (carrying the IMSI of the 5G RG and the MAC address of the UE / Device) through New Interface1. RVIM assigns a temporary number to the UE / Device and saves the binding relationship between the temporary number and the device MAC address. After the RG obtains the temporary number, it also establishes a binding relationship between the temporary number and the device MAC address. Subsequently, the RG initiates registration with the W-AGF again with the temporary number. When the UE / Device initiates a data service through the Y1 interface, the 5G-RG uses the PDU Session establishment to initiate to the W-AGF.
[0095] In one embodiment of the present disclosure, Figure 6 As shown, the present disclosure also provides Figure 6 A flow chart of a differentiated control system operation for a user terminal, including:
[0096] S601, RVIM and UDM synchronize temporary number information in real time;
[0097] S602, 5G RG (equivalent to the above-mentioned home gateway RG) goes online and performs the RG authentication process;
[0098] S603, the Device (equivalent to the user terminal) attaches to the 5G RG and executes the Device authentication process. The 5G RG binds the Device MAC address (equivalent to the physical address of the user terminal) to the temporary number (equivalent to the virtual identifier);
[0099] S604, Device initiates data service, 5G RG uses temporary number to initiate session establishment process to W-AGF, after session establishment, data service can be transmitted in the session;
[0100] S605, when multiple devices initiate data services, the RG will allocate different temporary numbers to each device and establish different sessions to achieve differentiated management of different devices.
[0101] In the disclosed embodiment, the device MAC address is bound to a temporary number through the 5G RG, so that the RGC can perform differentiated control and management of different devices accessing the gateway.
[0102] In one embodiment of the present disclosure, Figure 7As shown in the figure, in an embodiment of the present disclosure, a RG authentication process in a differential control method for a user terminal is further provided, including the following steps:
[0103] S701, The 5G RG goes online and establishes a connection with the W-AGF;
[0104] S702, The 5G RG and the W-AGF perform a standard EAP authentication;
[0105] S703, The 5G RG performs a standard EAP authentication with the AMF via the W-AGF;
[0106] S704, The 5G RG performs a standard EAP authentication with the AUSF via the W-AGF;
[0107] S705, The AMF and the AUSF exchange user subscription information (specific service information subscribed when the user subscribes to a service);
[0108] S706, The AUSF sends EAP authentication success to the AMF;
[0109] S707, The AMF sends EAP authentication success to the W-AGF;
[0110] S708, The W-AGF sends EAP authentication success to the 5G RG;
[0111] S709, The 5G RG and the W-AGF perform a standard NAS authentication;
[0112] S710, The 5G RG performs a standard NAS authentication with the AMF via the W-AGF;
[0113] S711, The 5G RG performs a standard NAS authentication between the W-AGF and the AUSF;
[0114] S712, The 5G RG performs a standard NAS authentication between the W-AGF and the UDM;
[0115] S713, The UDM notifies the RVIM of the authentication result of the 5G RG, and the RVIM obtains the message that the RG has completed the authentication.
[0116] Among them, from S702 to S708, the 5G RG performs a standard EAP authentication between the W-AGF and the AMF / AUSF / UDM.
[0117] From S709 to S712, the 5G RG performs a standard NAS authentication between the W-AGF and the AMF / AUSF / UDM.
[0118] In an embodiment of the present disclosure, as Figure 8As shown, in the embodiments of the present disclosure, a user terminal authentication process in a differential control method for a user terminal is further provided, including the following steps:
[0119] S801, 802.1x user attachment;
[0120] S802, request to allocate a temporary number (carrying the Device MAC address and RG IMSI);
[0121] S803, RG authentication result;
[0122] S804, allocate a temporary number;
[0123] S805, save the binding relationship between the RG IMSI, Device MAC address, and the temporary number;
[0124] S806, save the binding relationship between the RG IMSI, Device MAC address, and the temporary number;
[0125] S807, use the temporary number to perform authentication again.
[0126] For example, in an embodiment of the present disclosure, the Device attaches successfully to the 5G RG; the 5G RG carries the Device MAC address and RG IMSI to apply for a temporary number from the RVIM; the RVIM queries the saved RG authentication result, allocates a temporary number to the 5G RG, and at the same time saves the binding relationship between the RG IMSI, Device MAC address, and the temporary number; the RVIM saves the binding relationship between the RG IMSI, Device MAC address, and the temporary number, and then uses the temporary number to initiate authentication to the W-AGF again.
[0127] Based on the same inventive concept, in the embodiments of the present disclosure, a differential control device for a user terminal is further provided, as described in the following embodiments. Since the principle of solving problems in this device embodiment is similar to that of the above method embodiment, the implementation of this device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be elaborated.
[0128] Figure 9 A schematic diagram of a differential control device for a user terminal in the embodiments of the present disclosure is shown, as Figure 9 shown, the device includes:
[0129] A number application module 901, configured to apply a virtual identifier for each user terminal when the home gateway receives an attachment request from one or more user terminals;
[0130] A number association module 902, configured to associate and store the physical address of each user terminal and the corresponding virtual identifier in the home gateway;
[0131] The differentiation control module 903 is configured to perform differentiation control on each user terminal under the home gateway according to the physical addresses and corresponding virtual identifiers of each user terminal associated and stored in the home gateway.
[0132] In an embodiment of the present disclosure, the number application module 901 is specifically configured to: when the home gateway receives an attachment request from one or more user terminals, initiate a virtual identifier application request for each user terminal to the home gateway virtual identifier management RVIM platform through the home gateway, where a plurality of virtual identifiers are pre-deployed in the RVIM platform, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of each user terminal; receive the virtual identifiers of each user terminal returned by the RVIM platform through the home gateway, where the RVIM platform is further configured to associate and store the physical address, virtual identifier, and gateway identifier of each user terminal, and synchronize them to the core network.
[0133] In an embodiment of the present disclosure, the differentiation control module 903 is specifically configured to: when the home gateway receives a service request initiated by each user terminal, obtain the corresponding virtual identifier according to the physical address of each user terminal; initiate a session establishment request to the core network according to the virtual identifier of each user terminal.
[0134] Figure 10 The schematic diagram of another user terminal differentiation control device in the embodiment of the present disclosure is shown, as Figure 10 shown, the device includes:
[0135] The request receiving module 1001 is configured to receive a virtual identifier application request from the home gateway, where the virtual identifier application request is used to apply for corresponding virtual identifiers for one or more user terminals attached to the home gateway, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of each user terminal;
[0136] The response module 1002 is configured to return the virtual identifiers of each user terminal to the home gateway according to the virtual identifier application request, where the home gateway associates and stores the physical addresses of each user terminal and the corresponding virtual identifiers to perform differentiation control on each user terminal under the home gateway.
[0137] In an embodiment, the device further includes: an association storage module 1003 configured to associate and store the physical address, virtual identifier, and gateway identifier of each user terminal.
[0138] Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, a method, or a program product. Therefore, various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuits", "modules", or "systems" here.
[0139] Reference will be made below Figure 11 to describe the electronic device 1100 according to such an embodiment of the present disclosure. Figure 11 The shown electronic device 1100 is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.
[0140] As Figure 11 shown, the electronic device 1100 is presented in the form of a general-purpose computing device. The components of the electronic device 1100 may include, but are not limited to: at least one of the above-mentioned processing units 1110, at least one of the above-mentioned storage units 1120, and a bus 1130 connecting different system components (including the storage unit 1120 and the processing unit 1110).
[0141] Among them, the storage unit stores program codes, and the program codes can be executed by the processing unit 1110, so that the processing unit 1110 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.
[0142] For example, the processing unit 1110 may execute the following steps of the above method embodiment: when the home gateway receives an attachment request from one or more user terminals, apply a virtual identifier for each user terminal; associate and store the physical addresses of the respective user terminals and the corresponding virtual identifiers in the home gateway; perform differential control on the respective user terminals under the home gateway according to the physical addresses of the respective user terminals and the corresponding virtual identifiers associated and stored in the home gateway.
[0143] For example, when the processing unit 1110 executes the step of applying a virtual identifier for each user terminal when the home gateway receives an attachment request from one or more user terminals, it may further include: when the home gateway receives an attachment request from one or more user terminals, initiate a virtual identifier application request for each user terminal through the home gateway to the home gateway virtual identifier management RVIM platform, where multiple virtual identifiers are pre-deployed in the RVIM platform, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of the respective user terminals; receive, through the home gateway, the virtual identifiers of the respective user terminals returned by the RVIM platform, where the RVIM platform is further configured to associate and store the physical address, virtual identifier, and gateway identifier of each user terminal and synchronize them to the core network.
[0144] For example, when the processing unit 1110 executes the step of differentially controlling each user terminal under the home gateway according to the physical addresses and corresponding virtual identifiers of the respective user terminals associated and stored in the home gateway, it may further include: when the home gateway receives service requests initiated by each user terminal, obtaining the corresponding virtual identifier according to the physical address of each user terminal; and initiating a session establishment request to the core network according to the virtual identifier of each user terminal.
[0145] For example, the processing unit 1110 may execute the following steps of the above method embodiment: receiving a virtual identifier application request from the home gateway, where the virtual identifier application request is used to apply for corresponding virtual identifiers for one or more user terminals attached to the home gateway, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of the respective user terminals; and returning one or more virtual identifiers of the user terminals to the home gateway according to the virtual identifier application request, where the home gateway associates and stores the physical addresses and corresponding virtual identifiers of the respective user terminals to differentially control each user terminal under the home gateway.
[0146] For example, after the processing unit 1110 executes the step of returning one or more virtual identifiers to the home gateway according to the virtual identifier application request, it may further include: associating and storing the physical address, virtual identifier, and gateway identifier of each user terminal.
[0147] The storage unit 1120 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 11201 and / or a cache storage unit 11202, and may further include a read-only storage unit (ROM) 11203.
[0148] The storage unit 1120 may further include a program / utilities 11204 having a set (at least one) of program modules 11205. Such program modules 11205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.
[0149] The bus 1130 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.
[0150] The electronic device 1100 can also communicate with one or more external devices 1140 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 1100, and / or communicate with any device that enables the electronic device 1100 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 1150. Moreover, the electronic device 1100 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 1160. As shown in the figure, the network adapter 1160 communicates with other modules of the electronic device 1100 through the bus 1130. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 1100, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0151] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the methods according to the embodiments of the present disclosure.
[0152] In an exemplary embodiment of the present disclosure, there is also provided a computer-readable storage medium, which can be a readable signal medium or a readable storage medium. Figure 12 A schematic diagram showing a computer-readable storage medium in an embodiment of the present disclosure is as Figure 12 shown. A program product capable of implementing the above method of the present disclosure is stored on the computer-readable storage medium 1200. In some possible implementation manners, various aspects of the present disclosure can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to enable the terminal device to execute the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Method" section above in this specification.
[0153] For example, when the program product in the embodiments of the present disclosure is executed by a processor, a method with the following steps is implemented: when the home gateway receives an attachment request from one or more user terminals, apply a virtual identifier for each user terminal; associate and store the physical address of each user terminal and the corresponding virtual identifier in the home gateway; perform differential control on each user terminal under the home gateway according to the physical address of each user terminal and the corresponding virtual identifier associated and stored in the home gateway.
[0154] Further, in some embodiments, when the program product in the embodiments of the present disclosure is executed by a processor, a method with the following steps can also be implemented: when the home gateway receives an attachment request from one or more user terminals, initiate a virtual identifier application request for each user terminal to the home gateway virtual identifier management RVIM platform through the home gateway, where multiple virtual identifiers are pre-deployed in the RVIM platform, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical address of each user terminal; receive the virtual identifier of each user terminal returned by the RVIM platform through the home gateway, where the RVIM platform is further configured to associate and store the physical address, virtual identifier, and gateway identifier of each user terminal and synchronize them to the core network.
[0155] Further, in some embodiments, when the program product in the embodiments of the present disclosure is executed by a processor, a method with the following steps can also be implemented: when the home gateway receives a service request initiated by each user terminal, obtain the corresponding virtual identifier according to the physical address of each user terminal; initiate a session establishment request to the core network according to the virtual identifier of each user terminal.
[0156] In some embodiments, when the program product in the embodiments of the present disclosure is executed by a processor, a method with the following steps can also be implemented: receive a virtual identifier application request from the home gateway, where the virtual identifier application request is used to apply corresponding virtual identifiers for one or more user terminals attached to the home gateway, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical address of each user terminal; return the virtual identifier of one or more user terminals to the home gateway according to the virtual identifier application request, where the home gateway associates and stores the physical address of each user terminal and the corresponding virtual identifier to perform differential control on each user terminal under the home gateway.
[0157] Further, in some embodiments, when the program product in the embodiments of the present disclosure is executed by a processor, a method with the following steps can also be implemented: after returning one or more virtual identifiers to the home gateway according to the virtual identifier application request, associate and store the physical address, virtual identifier, and gateway identifier of each user terminal.
[0158] More specific examples of the computer-readable storage medium in this disclosure may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0159] In this disclosure, the computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0160] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the above.
[0161] In a specific implementation, the program code for performing the operations of this disclosure may be written in any combination of one or more programming languages. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as an independent software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0162] It should be noted that although several modules or units of the devices for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of this disclosure, the features and functions of the two or more modules or units described above may be embodied in one module or unit. Conversely, the features and functions of one module or unit described above may be further divided and embodied by multiple modules or units.
[0163] In addition, although the various steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in that specific order, or that all of the steps shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.
[0164] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of the present disclosure.
[0165] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common general knowledge or conventional technical means in the technical field not disclosed herein. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.
Claims
1. A differential control method for a user terminal, characterized in that, including: When the home gateway receives an attachment request from one or more user terminals, apply a virtual identifier for each user terminal; Associate and store the physical address of each user terminal and the corresponding virtual identifier in the home gateway; Differentially control each user terminal under the home gateway according to the physical addresses of each user terminal and the corresponding virtual identifiers associated and stored in the home gateway; Among them, the differentially controlling each user terminal under the home gateway according to the physical addresses of each user terminal and the corresponding virtual identifiers associated and stored in the home gateway includes: when the home gateway receives a service request initiated by each user terminal, obtain the corresponding virtual identifier according to the physical address of each user terminal; initiate a session establishment request to the core network according to the virtual identifier of each user terminal.
2. The differential control method of the user terminal according to claim 1, wherein When the home gateway receives an attachment request from one or more user terminals, applying a virtual identifier for each user terminal includes: When the home gateway receives an attachment request from one or more user terminals, initiate a virtual identifier application request for each user terminal to the Home Gateway Virtual Identifier Management (RVIM) platform through the home gateway, where a plurality of virtual identifiers are pre-deployed in the RVIM platform, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of each user terminal; Receive the virtual identifiers of each user terminal returned by the RVIM platform through the home gateway, where the RVIM platform is further configured to associate and store the physical address, virtual identifier, and gateway identifier of each user terminal and synchronize them to the core network.
3. A differential control method for a user terminal, characterized in that, including: Receive a virtual identifier application request from the home gateway, where the virtual identifier application request is used to apply corresponding virtual identifiers for one or more user terminals attached to the home gateway, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of each user terminal; According to the virtual identifier application request, return the virtual identifiers of one or more user terminals to the home gateway, where the home gateway associates and stores the physical address of each user terminal and the corresponding virtual identifier and synchronizes them to the core network, so that the core network differentially controls each user terminal under the home gateway based on the virtual identifier.
4. The differential control method of the user terminal according to claim 3, wherein After returning one or more virtual identifiers to the home gateway according to the virtual identifier application request, the method further includes: Associate and store the physical address, virtual identifier, and gateway identifier of each user terminal.
5. A differential control system for a user terminal, characterized in that, including: Core network, Home Gateway Virtual Identifier Management (RVIM) platform, home gateway, and one or more user terminals attached to the home gateway; Among them, the home gateway is configured to initiate a virtual identifier application request for each user terminal to the RVIM platform when receiving an attachment request from one or more user terminals; The RVIM platform is configured to allocate a virtual identifier for each user terminal according to the received virtual identifier application request and return it to the home gateway; The core network communicates with the home gateway and is used to perform differential control on each user terminal under the home gateway according to the physical addresses and corresponding virtual identifiers of the user terminals under the home gateway.
6. A differential control device for a user terminal, characterized in that, It includes: A number application module, which is used to apply a virtual identifier for each user terminal when the home gateway receives an attachment request from one or more user terminals. A number association module, which is used to associate and store the physical addresses and corresponding virtual identifiers of each user terminal in the home gateway. A differential control module, which is used to perform differential control on each user terminal under the home gateway according to the physical addresses and corresponding virtual identifiers of each user terminal associated and stored in the home gateway. The differential control module is further used to, when the home gateway receives service requests initiated by each user terminal, obtain the corresponding virtual identifier according to the physical address of each user terminal; and initiate a session establishment request to the core network according to the virtual identifier of each user terminal.
7. A differential control device for a user terminal, characterized in that, It includes: A request receiving module, which is used to receive a virtual identifier application request from the home gateway. The virtual identifier application request is used to apply corresponding virtual identifiers for one or more user terminals attached to the home gateway, and the virtual identifier application request includes: the gateway identifier of the home gateway and the physical addresses of each user terminal. A response module, which is used to return the virtual identifiers of each user terminal to the home gateway according to the virtual identifier application request. The home gateway associates and stores the physical addresses and corresponding virtual identifiers of each user terminal and synchronizes them to the core network, so that the core network performs differential control on each user terminal under the home gateway based on the virtual identifiers.
8. An electronic device, characterized in that, It includes: A processor; And A memory, which is used to store the executable instructions of the processor. Wherein, the processor is configured to execute the differential control method of the user terminal according to any one of claims 1 to 4 by executing the executable instructions.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the differential control method of the user terminal according to any one of claims 1 to 4.
Citation Information
Patent Citations
Protocol conversion module and inter-network calling method between IMS network and family network
CN101645887A
SIM-card registration method, terminal and SIM-card activation device
CN104661210A