An authorization method and apparatus

By having the core network equipment promptly request communication authorization from the second authorized device when the UAV moves to a new area, the problem of flight interruption caused by the UAV going out of the USS area is solved, and continuous communication authorization for the UAV and system efficiency are improved.

CN116567050BActive Publication Date: 2026-01-13HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210112998.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-29
Publication Date
2026-01-13
Estimated Expiration
2042-01-29

AI Technical Summary

Technical Problem

In existing technologies, drones cannot continue flying when they go beyond the area of ​​their authorized drone service provider (USS) during flight, which may lead to flight accidents, and communication authorization is inefficient.

Method used

The core network equipment receives the first authorization information and determines that when the terminal device moves outside the area corresponding to the first authorization device, it requests communication authorization from the second authorization device to ensure that multiple authorizations are performed without interrupting communication, thus optimizing the C2 communication authorization process.

Benefits of technology

This improved system efficiency, reduced signaling overhead, decreased the load on core network equipment, ensured continuous communication authorization for the UAV during flight, and prevented flight accidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116567050B_ABST
    Figure CN116567050B_ABST
Patent Text Reader

Abstract

The application provides an authorization method and device, and relates to the technical field of communication, wherein the method comprises the following steps: a core network device learns that a first authorization device successfully authorizes a terminal device to communicate, and when the terminal device moves out of a region corresponding to the first authorization device, if it is determined that the terminal device moves out of a region corresponding to a second authorization device, the core network device can further request the second authorization device to re-authorize the terminal device to communicate; and the core network device can learn the result of the second authorization device authorizing the terminal device to communicate according to second authorization information of the second authorization device. Through the above method, when the first authorization device successfully authorizes the terminal device to communicate, if the terminal device moves out of the region corresponding to the first authorization device, the second authorization device can be requested to re-authorize the terminal device to communicate, so that the terminal device is authorized multiple times under the premise of uninterrupted communication, and the system efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a licensed method and apparatus. Background Technology

[0002] Unmanned aerial vehicles (UAVs) are autonomous, unmanned aircraft that can perform various tasks through manual or autonomous control. With the maturation of UAV research and development technology and a significant reduction in manufacturing costs, UAVs have been widely used in various fields, including agricultural plant protection, power line inspection, law enforcement, geological exploration, environmental monitoring, forest fire prevention, and aerial filming.

[0003] A drone and its controller (UAV-C) together constitute an unmanned aerial system (UAS). The UAV controller (hereinafter referred to as the controller) commands and controls the drone by sending control data. The data communication link between the controller and the drone is called the command and control (C2) link, and the communication between the controller and the drone can also be called C2 communication.

[0004] When a drone establishes a C2 communication connection, such as establishing or modifying a session (e.g., a Protocol Data Unit (PDU) session), C2 communication authorization is required. The Session Management Function (SMF) assists the drone in C2 communication authorization and senses C2 communication authorization information. If authorization fails, the network will not establish a C2 communication connection for that drone.

[0005] Currently, when granting communication authorization to drones, it is assumed that the area covered by the UAV service provider (USS) during the drone's flight will not change, so authorization only needs to be requested from that USS. However, the area covered by a single USS is limited. When a drone exceeds the area covered by its authorized USS, it will be unable to continue flying, potentially causing flight accidents and other problems. Summary of the Invention

[0006] This application provides an authorization method and apparatus that optimizes the C2 communication authorization process for unmanned aerial vehicles (UAVs).

[0007] Firstly, this application provides an authorization method, which can be executed by a core network device or a module (such as a chip) applied to the core network device. The method includes: the core network device receiving first authorization information from a first authorization device, and determining that the first authorization device has successfully authorized communication for a terminal device; when the terminal device moves outside the area corresponding to the first authorization device, sending a request message to a second authorization device, the request message requesting the second authorization device to authorize communication for the terminal device, the second authorization device being the authorization device corresponding to the area where the terminal device is located after moving out of the area corresponding to the first authorization device; and receiving second authorization information from the second authorization device, and determining the result of the second authorization device authorizing communication for the terminal device.

[0008] Using the above method, after the first authorizing device successfully authorizes communication with the terminal device, if the terminal device moves outside the area corresponding to the first authorizing device, it can request the second authorizing device to re-authorize communication with the terminal device, thereby ensuring that multiple authorizations can be performed on the terminal device without interrupting communication and improving system efficiency.

[0009] In one possible implementation, the method further includes: obtaining first information from a first authorizing device; the first information is used to instruct the terminal device to re-authorize communication; sending a request message to a second authorizing device includes: sending a request message to the second authorizing device based on the first information.

[0010] By implementing the above method, the first authorized device can trigger the core network device to re-authorize communication with the terminal device through the first information, which can accurately determine the timing of re-authorizing communication with the terminal device and improve system efficiency.

[0011] In one possible implementation, the first information is one or more of the following: information indicating a change of authorized device, information indicating the invalidation of the first authorized device's authorization, or identification information of the second authorized device.

[0012] In one possible implementation, the method further includes: determining that the terminal device has moved outside the area corresponding to the first authorized device.

[0013] In one possible implementation, determining that the terminal device has moved outside the area corresponding to the first authorized device includes:

[0014] Obtain the location information of the terminal device; determine, based on the location information and the area corresponding to the first authorized device, that the terminal device has moved to a location outside the area corresponding to the first authorized device.

[0015] By implementing the above method, the location information of the terminal device can be used to accurately determine whether the terminal device has moved outside the area corresponding to the first authorized device, avoiding repeated authorization of the terminal device and reducing signaling overhead.

[0016] In one possible implementation, determining that the terminal device has moved outside the area corresponding to the first authorized device includes:

[0017] Send a request message to the mobility management device, the request message being used to request notification that the terminal device has moved outside the area corresponding to the first authorized device; receive a notification message from the mobility management device, and determine that the terminal device has moved outside the area corresponding to the first authorized device based on the notification message.

[0018] By implementing the above method, and using the request message from the mobile management device to determine that the terminal device has moved to a region outside the area corresponding to the first authorized device, the complexity of the core network equipment can be reduced, and the load on the core network equipment can be lowered.

[0019] In one possible implementation, the method further includes: receiving information about the region corresponding to the first authorized device from the first authorized device.

[0020] In one possible implementation, before sending the request message to the second authorized device, the method further includes: obtaining the identification information of the second authorized device.

[0021] In one possible implementation, obtaining the identification information of the second authorized device includes: receiving the identification information of the second authorized device from the terminal device, the first authorized device, or the data management network element; or, obtaining the location information of the terminal device and obtaining the identification information of the second authorized device based on the location information of the terminal device and the area information corresponding to one or more authorized devices.

[0022] By implementing the above method, the second authorized device can be determined through the terminal device, the first authorized device, or the data management network element, thereby enabling timely determination of the second authorized device and improving the communication authorization efficiency of the terminal device.

[0023] In one possible implementation, the method is executed by a network open function device, and the method further includes: when the second authorization information indicates authorization failure, the network open function device sends information to the session management device indicating that the second authorization device has failed to authorize communication with the terminal device.

[0024] In one possible implementation, the method is executed by a session management device, and the method further includes: establishing a session for the terminal device based on the first authorization information.

[0025] In one possible implementation, the method further includes: releasing the session established for the terminal device based on the first authorization information when the second authorization information indicates authorization failure.

[0026] By implementing the above method, when the second authorization information indicates that authorization has failed, the terminal device's session is released, which can prevent the terminal device from performing actions beyond its permissions and improve system security.

[0027] Secondly, this application provides an authorization method, which can be executed by a first authorization device or a module (such as a chip) applied to the first authorization device. The method includes: the first authorization device sending authorization information to a core network device, the authorization information indicating the result of the first authorization device granting communication authorization to a terminal device; and when the terminal device moves outside the area corresponding to the first authorization device, sending first information to the core network device, the first information indicating that communication authorization be re-granted to the terminal device.

[0028] In one possible implementation, the first information is one or more of the following: information indicating the replacement of the authorized device, information indicating the invalidation of the authorization of the first authorized device, or identification information of the second authorized device, wherein the second authorized device is the authorized device corresponding to the area where the terminal device is located after it has moved out of the area corresponding to the first authorized device.

[0029] In one possible implementation, when the first information is the identification information of the second authorized device, the method further includes: obtaining the location information of the terminal device; and obtaining the identification information of the second authorized device based on the location information of the terminal device and the area information corresponding to one or more authorized devices.

[0030] In one possible implementation, the method further includes: obtaining location information of the terminal device; determining, based on the location information and the area information corresponding to the first authorized device, that the terminal device has moved outside the area corresponding to the first authorized device; or, receiving a notification message from a mobility management device and determining, based on the notification message, that the terminal device has moved outside the area corresponding to the first authorized device.

[0031] In one possible implementation, before sending the first information to the core network device, the method further includes: determining that communication authorization for the terminal device has been successfully granted.

[0032] Thirdly, this application provides an authorization method, which can be executed by a core network device or a module (such as a chip) applied to the core network device. The method includes: when the mobile path of a terminal device passes through an area corresponding to a first authorization device and an area corresponding to a second authorization device, obtaining identification information of the first authorization device; sending a first request message to the first authorization device, the first request message being used to request the first authorization device to grant communication authorization to the terminal device; obtaining identification information of the second authorization device; sending a second request message to the second authorization device, the first request message being used to request the second authorization device to grant communication authorization to the terminal device; receiving first authorization information from the first authorization device, receiving second authorization information from the second authorization device, wherein the first authorization information is used to indicate the result of the first authorization device granting communication authorization to the terminal device, and the second authorization information is used to indicate the result of the second authorization device granting communication authorization to the terminal device; and obtaining the authorization result based on the first authorization information and the second authorization information.

[0033] By implementing the above method, when the mobile path of a terminal device passes through the areas corresponding to multiple authorized devices, the core network device can simultaneously request communication authorization from multiple authorized devices for the terminal device. When multiple authorized devices successfully authorize the terminal device, a session is then established for the terminal device, thereby enabling multiple authorizations for the terminal device, reducing signaling overhead, and improving system efficiency.

[0034] In one possible implementation, the identification information of the first authorized device and the identification information of the second authorized device come from the terminal device.

[0035] In one possible implementation, obtaining the identification information of the second authorized device includes: receiving the identification information of the second authorized device from the first authorized device.

[0036] By implementing the above method, the first authorized device directly sends the identification information of the second authorized device to the core network device, which enables the core network device to identify the second authorized device in a timely manner and improves the communication authorization efficiency of the terminal device.

[0037] In one possible implementation, obtaining the identification information of the second authorized device includes: receiving first indication information from the first authorized device, the first indication information being used to indicate that other authorized devices are required to authorize communication with the terminal device or to indicate that the first authorized device cannot authorize communication with the terminal device alone; and obtaining the identification information of the second authorized device based on the first indication information.

[0038] By implementing the above method, the first instruction information indicates that the terminal device still needs other authorized devices for communication authorization, thereby enabling the second authorized device to be determined in a timely manner based on the first instruction information, thus improving the communication authorization efficiency of the terminal device.

[0039] In one possible implementation, obtaining the identification information of the second authorized device according to the first instruction information includes: requesting the identification information of other authorized devices from the terminal device or data management device according to the first instruction information; and receiving the identification information of the second authorized device from the terminal device or data management device.

[0040] In one possible implementation, the authorization result is obtained based on the first authorization information and the second authorization information, including:

[0041] If the first authorization message indicates successful authorization and the second authorization message indicates successful authorization, then the authorization for communication with the terminal device is determined to be successful; or, if the first authorization message indicates authorization failure or the second authorization message indicates authorization failure, then the authorization for communication with the terminal device is determined to be failed.

[0042] In one possible implementation, determining that communication authorization to the terminal device is successful includes: accepting the session establishment request from the terminal device; determining that communication authorization to the terminal device fails includes: rejecting the session establishment request from the terminal device.

[0043] In one possible implementation, the method further includes: if the communication authorization for the terminal device is successful, sending a message indicating successful authorization to the session management network element; if the authorization for the terminal device fails, sending a message indicating failed authorization to the session management network element.

[0044] In one possible implementation, if it is determined that authorization to the terminal device has failed, the identification information of the authorized device that failed to authorize the terminal device is sent to the terminal device.

[0045] By implementing the above method, the terminal device can identify the authorized device that failed to grant authorization. The terminal device can then determine whether to change its movement path based on the actual situation, thereby avoiding the area corresponding to the authorized device that failed to grant authorization.

[0046] Fourthly, this application provides an authorization method, which can be executed by a first authorization device or a module (such as a chip) applied to the first authorization device. The method includes: the first authorization device receiving a request message from a core network device, the request message requesting communication authorization for a terminal device, the request message including information about the terminal device's movement path; when the terminal device's movement path passes through areas corresponding to multiple authorization devices, the first authorization device sends authorization information to the core network device, as well as first indication information or identification information of a second authorization device among the multiple authorization devices; wherein the authorization information indicates the result of the first authorization device granting communication authorization to the terminal device, and the first indication information indicates that the terminal device requires authorization from other authorization devices or indicates that the first authorization device cannot grant communication authorization to the terminal device alone.

[0047] In one possible implementation, if the authorization information indicates successful authorization, a first instruction message or the identification information of a second authorized device is sent to the core network device.

[0048] Fifthly, this application provides an authorization method, which can be executed by a terminal device or a module (such as a chip) applied to the terminal device. The method includes: the terminal device determining that its movement path passes through an area corresponding to a first authorization device and an area corresponding to a second authorization device; the terminal device sending a session establishment request message to a core network device, the session establishment request message being used to request the establishment of a session for the terminal device, the session establishment request message including identification information of the first authorization device and the second authorization device.

[0049] By implementing the above method, when a terminal device determines that its movement path passes through the areas corresponding to multiple authorized devices, it can simultaneously request communication authorization from multiple authorized devices, thereby enabling it to request communication authorization from multiple authorized devices with a single message, reducing signaling overhead and improving system efficiency.

[0050] In one possible implementation, the method further includes: if the first authorizing device or the second authorizing device fails to authorize the terminal device, the terminal device receives authorization result information from the core network device, the authorization result information being used to indicate the authorizing device that failed to authorize the terminal device to communicate.

[0051] Sixthly, this application also provides a communication device capable of implementing any method or implementation mode provided in any of the first to fifth aspects. This communication device can be implemented in hardware, in software, or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the aforementioned functions.

[0052] In one possible implementation, the communication device can be an authorized device, a terminal device, or a core network device.

[0053] In one possible implementation, the communication device includes a processor configured to support the communication device in performing the method described in the first aspect above. The communication device may further include a memory coupled to the processor, which stores necessary program instructions and data for the communication device. Optionally, the communication device may also include interface circuitry for supporting communication between the communication device and other communication devices.

[0054] In one possible implementation, the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method examples, as described in any of the first to fifth aspects, and will not be repeated here.

[0055] In a seventh aspect, embodiments of this application provide a computer-readable storage medium storing computer-readable instructions, which, when read and executed by a computer, cause the computer to implement any of the possible designs in the first to fifth aspects described above.

[0056] Eighthly, embodiments of this application provide a computer program product that, when read and executed by a computer, enables the computer to implement any of the possible designs in the first to third aspects described above.

[0057] Ninthly, embodiments of this application provide a chip, the chip including a processor coupled to a memory, for reading and executing software programs stored in the memory to implement the methods in any of the possible designs of the first to fifth aspects described above.

[0058] In a tenth aspect, a communication device is provided, including a processor and an interface circuit. The interface circuit is configured to receive signals from other communication devices outside the communication device and transmit them to the processor, or to send signals from the processor to other communication devices outside the communication device. The processor is configured to implement any of the possible design methods of the first to fifth aspects by means of logic circuits or by executing computer programs or instructions.

[0059] Eleventhly, a communication device is provided, including a processor and a memory, the processor and the memory being coupled, the processor being configured to execute a computer program or instructions stored in the memory, such that the communication device implements the method in any of the possible designs of the first to fifth aspects described above.

[0060] In a twelfth aspect, a chip is provided, the chip including a processor and further including a memory for executing a computer program or instructions stored in the memory, such that the chip system implements the methods in any of the possible designs of the first to fifth aspects described above.

[0061] In a thirteenth aspect, a communication system is provided, the system comprising means for implementing the first aspect and means for implementing the second aspect.

[0062] In a fourteenth aspect, a communication system is provided, the system comprising means for implementing the third aspect, means for implementing the fourth aspect, and means for implementing the fifth aspect.

[0063] These or other aspects of this application will become more apparent from the description of the following embodiments. Attached Figure Description

[0064] Figure 1 This is a schematic diagram of a 5G network architecture applicable to this application;

[0065] Figure 2 A schematic diagram of a drone movement provided in an embodiment of this application;

[0066] Figure 3 This is a schematic flowchart of an authorization method provided in an embodiment of this application;

[0067] Figure 4 This is a schematic flowchart of an authorization method provided in an embodiment of this application;

[0068] Figure 5 This is a schematic flowchart of an authorization method provided in an embodiment of this application;

[0069] Figure 6 This is a schematic flowchart of an authorization method provided in an embodiment of this application;

[0070] Figure 7 This is a schematic diagram of a communication device structure provided in an embodiment of this application;

[0071] Figure 8 This is a schematic diagram of a communication device structure provided in an embodiment of this application. Detailed Implementation

[0072] The embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0073] like Figure 1 The diagram shown is a schematic of the fifth-generation (5G) network architecture based on a service-oriented architecture. Figure 1 The 5G network architecture shown can be divided into three parts: terminal equipment, data network (DN), and operator network. The functions of some of these network elements are briefly described below.

[0074] The operator network may include one or more of the following network elements: Network Exposure Function (NEF) network elements, Policy Control Function (PCF) network elements, Unified Data Management (UDM) network elements, Network Repository Function (NRF) network elements, Application Function (AF) network elements, Access and Mobility Management Function (AMF) network elements, Session Management Function (SMF) network elements, Radio Access Network (RAN), Unified Data Repository (UDR) network elements, and User Plane Function (UPF) network elements. The portion of the operator network excluding the radio access network can be referred to as the core network portion.

[0075] Figure 1 The network elements included are just examples and may include other network elements, such as gateway mobile location centers (GMLCs), which are mainly used to provide location services to external clients or AF network elements.

[0076] Figure 1 Nnef, Nnrf, Npcf, Nudm, Naf, Namf, Nsmf, Nudr, N1, N2, N3, N4, and N6 are interface sequence numbers. The meanings of these interface sequence numbers can be found in the definitions of the 3rd Generation Partnership Project (3GPP) standard protocols, and are not limited here.

[0077] Figure 1 In this context, the user equipment (UE), RAN, UPF, and DN are generally referred to as data plane network functions and entities. UE data traffic can be transmitted through the PDU session established between the UE and DN, and the transmission will pass through the two network function entities, RAN and UPF. The other parts are referred to as control plane network functions and entities, which are mainly responsible for functions such as authentication and authorization, registration management, session management, mobility management, and policy control, thereby achieving reliable and stable transmission of user layer traffic.

[0078] In this application, user equipment, also known as terminal equipment, is a device with wireless transceiver capabilities. It can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as on ships); and it can be deployed in the air (such as on airplanes, balloons, and satellites). Terminal equipment can be mobile phones, tablets, computers with wireless transceiver capabilities, virtual reality (VR) terminals, augmented reality (AR) terminals, wireless terminals in industrial control, wireless terminals in self-driving (such as remote controls, drones), wireless terminals in remote medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. The terminal equipment in this application mainly relates to remote controls and drones.

[0079] The aforementioned terminal devices can establish connections with the operator's network through interfaces provided by the operator's network (such as N1), and use data and / or voice services provided by the operator's network. The terminal devices can also access the DN (Network Provider) through the operator's network, and use operator services deployed on the DN, and / or services provided by third parties. These third parties can be service providers outside of the operator's network and terminal devices, and can provide other data and / or voice services to the terminal devices. The specific form of these third parties can be determined based on the actual application scenario and is not limited here.

[0080] RAN (Access Network Controller) is a subnetwork of a carrier network, serving as the implementation system between service nodes and terminal equipment within the carrier network. For a terminal device to access the carrier network, it first passes through the RAN, and then connects to the carrier network's service nodes via the RAN. The RAN equipment in this application is a device that provides wireless communication functions for terminal equipment; RAN equipment is also called access network equipment. The RAN equipment in this application includes, but is not limited to: next-generation base stations (g node B, gNB), evolved node B (eNB), radio network controllers (RNC), node Bs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved node B, or home node B, HNB), baseband units (BBUs), transmitting and receiving points (TRPs), transmitting points (TPs), and mobile switching centers, etc.

[0081] User plane network elements: These act as the interface with the data network, performing functions such as user plane data forwarding, session / flow-level billing and statistics, and bandwidth limiting. This includes packet routing and forwarding, as well as Quality of Service (QoS) processing for user plane data. In 5G communication systems, this user plane network element can be a UPF (User Plane Function) element.

[0082] Mobility Management Element (AMF): Primarily used for mobility management and access management. In 5G communication systems, this AMF can be an AMF (Active Mobile Function) element, mainly performing mobility management, access authentication / authorization, and other functions. It is also responsible for transmitting user policies between the terminal and the PCF (Programmable Component Function) element.

[0083] Session management network element: mainly used for session management, allocation and management of Internet Protocol (IP) addresses for user equipment, selection of endpoints for manageable user plane functions, policy control and charging function interfaces, and downlink data notification, etc.

[0084] In a 5G communication system, this session management network element can be an SMF network element, which completes terminal IP address allocation, UPF selection, and billing and QoS policy control, etc.

[0085] Data network: Provides services such as carrier services, internet access, or third-party services, including servers. The server side performs tasks such as video source encoding and rendering. In a 5G communication system, this data network can be a data network (DN). A data network is a network located outside the carrier network. Multiple DNs can be connected to the carrier network, and various services can be deployed on the DN, providing data and / or voice services to terminal devices. For example, a DN might be the private network of a smart factory. Sensors installed in the workshop can be terminal devices. A control server for these sensors is deployed within the DN, providing services to the sensors. Sensors can communicate with the control server, receive instructions, and transmit collected sensor data to the control server accordingly. Another example is a DN that serves as an internal office network for a company. Employees' mobile phones or computers can be terminal devices, accessing information and data resources on the company's internal office network.

[0086] In a 5G communication system, the unified data management network element can be a UDM network element, used to store user data, such as subscription information and authentication / authorization information.

[0087] In a 5G communication system, the unified data management network element can be a UDR network element, which provides storage and retrieval of subscription data, such as storing and retrieving policy data for PCF, storing and retrieving structured data, and NEF application data.

[0088] In 5G communication systems, the policy control network element can be a NEF (Network Function) element, primarily used to support the opening of capabilities and events. In this application, the NEF can also be replaced by a UAS (User Area Service) network function element, mainly used to provide the USS (User Area Service) with the opening of capabilities and events, including UAV authentication or authorization, C2 communication authorization, UAV mobility path authorization, C2 communication QoS control, location reporting, etc. Specifically, a separate NEF element can be deployed to provide the functionality of a UAS NF (Network Function) element.

[0089] In a 5G communication system, the policy control network element can be an AF (Action Center) network element, responsible for providing services to the 3rd Generation Partnership Project (3GPP) network, such as influencing service routing and interacting with the PCF (Policy Control Function) for policy control. In this application, the USS (United States Storage System) can serve as an AF network element.

[0090] In 5G communication systems, the policy control network element can be a PCF network element, which is responsible for providing policies to the AMF and SMF, such as Quality of Service (QoS) policies and slice selection policies.

[0091] In 5G communication systems, the network function repository function network element, which can be an NRF network element, provides network capabilities and event exposure capabilities to third-party entities, such as application functions, edge computing, and expected terminal device behaviors.

[0092] In this application, network elements can also be referred to as devices. For example, an AMF network element can be referred to as an AMF device, and an SMF network element can be referred to as an SMF device, etc., which will not be elaborated here.

[0093] Currently, when a UAV requests to establish a communication connection (establish or modify a session) for C2 communication, the USS (United States Service) needs to grant C2 communication authorization. This C2 communication authorization includes UAV pairing authorization and / or UAV movement path authorization. UAV pairing authorization authorizes the UAV to be controlled and directed by a specific controller, while UAV movement path authorization authorizes the UAV to fly according to a specific movement path.

[0094] In this application, the SMF can assist the UAV in C2 communication authorization and sense C2 communication authorization information. If authorization fails, the network will not establish a C2 communication connection for the UAV. Since one USS is responsible for only one area, when the UAV is flying in an area, it only needs to authorize C2 communication through the USS corresponding to that area. If the UAV moves to the area of ​​another USS, it will further need to authorize C2 communication through the USS corresponding to that area to establish a session. For example, if... Figure 2 As shown, after USS1 authorizes C2 communication for the drone, the drone moves within area 1 corresponding to USS1. When the drone moves along the path to area 2 corresponding to USS2, in area 2, if the drone needs to continue C2 communication, it requires USS2 to authorize C2 communication for the drone.

[0095] When a drone passes through an area covered by multiple UAV service providers (USS) during its flight, this application provides a method to improve the efficiency of C2 communication authorization for the drone, thereby improving system efficiency.

[0096] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0097] It is understood that the various numerical designations used in this application are merely for descriptive convenience and are not intended to limit the scope of this application. The order of the process numbers does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.

[0098] In this application, "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "Multiple" in this application refers to two or more objects.

[0099] In the description of this application, the terms "first," "second," etc., are used only for the purpose of distinguishing descriptions and should not be construed as indicating or implying relative importance or order.

[0100] In the embodiments of this application, the term "exemplary" is used to indicate that it is an example, illustration, or description. Any embodiment or design that is described as "exemplary" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the use of the term "exemplary" is intended to present the concept in a specific manner.

[0101] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0102] An authorized device can be responsible for the flight management of an unmanned aerial vehicle (UAV) in an area. The size and location of this area can be configured according to actual conditions, and this application does not limit it. In this application, the area managed by the authorized device can be referred to as the area corresponding to the authorized device. The authorized device can be an AF device, and the AF device can deploy relevant functions of USS (Unmanned Aerial Vehicle).

[0103] This application allows multiple authorized devices to authorize communication for terminal devices through various implementation methods. In the following description, the terminal device can be a drone, and the core network device can be an SMF or a NEF. The different implementation methods are described below.

[0104] Implementation Method 1:

[0105] In the first implementation of this application, the terminal device first establishes a communication connection for C2 communication, such as a user plane session, through the core network device. During the user plane session establishment process, the core network device requests the first authorizing device to authorize the terminal device's C2 communication. Once authorization is granted, a session is established for the terminal device. When the first authorizing device determines, based on the terminal device's location information and its own management area, that the terminal device has moved to an area outside its management area, it instructs the core network device (SMF or NEF) to change the authorizing device or indicates authorization failure. The core network device then re-authorizes communication for the terminal device through the second authorizing device. For details, please refer to the description in the following process.

[0106] like Figure 3 The diagram shown is a schematic flowchart of an authorization method provided in an embodiment of this application.

[0107] S301: The terminal device sends a session establishment request message or a session modification request message to the SMF. The session establishment request message can be used to request the establishment of a session, and the session modification request message can be used to request the modification of a session.

[0108] The session that the terminal device requests to establish or modify can be a user plane session, such as a PDU session. The session establishment request or session modification request message may include at least one of the following information:

[0109] The identification information of the first authorized device; C2 aviation payload; identification of the terminal device.

[0110] The terminal device can determine that it is within the area corresponding to the first authorized device (hereinafter referred to as the first area) based on its current location information, and thus can carry the identification information of the first authorized device in the session establishment or modification request message. The identification information of the first authorized device can be the Internet Protocol (IP) address or the fully qualified domain name (FQDN) of the first authorized device.

[0111] C2 airborne payloads may include at least one of UAV pairing information and flight authorization information. The UAV pairing information may include the controller's identification information, which can be used to control the movement of the terminal device. The controller's identification information may be the controller's Civil Aviation Administration (CAA) level UAV identifier (ID), IP address, subscription permanent identifier (SUPI), subscription concealed identifier (SUCI), or generic public subscription identifier (GPSI), etc. The flight authorization information includes movement path information, which may indicate at least one of the terminal device's flight route, flight start position, and flight end position.

[0112] The identifier for a terminal device can be its CAA-level UAV ID. This CAA-level UAV ID is assigned to the terminal device by the USS and pre-configured within it. It uniquely identifies a UAV and is used for remote identification and tracking. A terminal device can contain multiple CAA-level UAV IDs, and each CAA-level UAV ID can be associated with one or more authorized devices. This association can be configured by the SMF or through other devices.

[0113] In this application, the identification information of the first authorized device may also be information carried in a specific field of the CAA-level UAV ID of the terminal device.

[0114] When the terminal device is in the first region corresponding to the first authorized device, the CAA-level UAV ID of the terminal device included in the session establishment or modification request message can be assigned to the terminal device by the first authorized device.

[0115] S302: SMF sends a first request message to the first authorized device.

[0116] This step can also be replaced by the SMF sending at least one of the following information to the first authorized device: the identification information of the first authorized device; the C2 aviation payload; and the identification of the terminal device.

[0117] The first request message is used to request communication authorization for the terminal device, specifically a request for C2 communication authorization for the terminal device. The first request message may include at least one of the following: the identification information of the first authorized device, the C2 payload, and the identification of the terminal device. The specific name of the first request message is not limited; it may be an Authorization Request message or another name.

[0118] In this application, messages between the SMF and the first or second authorized device can be relayed through the NEF. For example, taking a first request message as an example, the SMF first sends the first request message to the NEF, and the NEF then forwards the message content of the first request message to the first authorized device. In order to ensure that the NEF accurately forwards the message content of the first request message to the first authorized device, the SMF can indicate the address information of the first authorized device to the NEF, and the NEF can send the message content of the first request message to the first authorized device through this address information.

[0119] After NEF obtains the first request message, if the identification information of the first authorized device in the first request message is the IP address or FQDN of the first authorized device, then NEF can use the identification information of the first authorized device as the address information of the first authorized device; if the identification information of the first authorized device in the first request message is information carried in a specific field of the CAA-level UAV ID of the terminal device, NEF can pre-configure the association relationship between the identification information and address information of different authorized devices, and NEF can use the address information that is associated with the identification information of the first authorized device as the address information of the first authorized device.

[0120] In one implementation, after NEF determines the address information of the first authorized device, it can forward at least one of the C2 airborne payload and the identifier of the terminal device in the first request message to the first authorized device.

[0121] S303: The first authorized device sends the first authorization information to the SMF.

[0122] The first authorization information is used to indicate the result of the first authorization device's communication authorization to the terminal device. Specifically, the first authorization information can indicate whether the first authorization device's communication authorization to the terminal device was successful or failed. Accordingly, the SMF learns the result of the first authorization device's communication authorization to the terminal device.

[0123] In this application, the specific factors the first authorizing device uses to determine whether authorization is successful are not limited. For example, in one implementation, the first authorizing device may authorize based on whether the terminal device is allowed to communicate with the UAV-C paired with it, and whether the terminal device can fly in the requested mobility path. If the terminal device is allowed to communicate with the UAV-C and can fly in the requested mobility path, then the first authorizing device can indicate successful authorization through the first authorization information. If the terminal device is not allowed to communicate with the UAV-C, or cannot fly in the requested mobility path, then the first authorizing device can indicate authorization failure through the first authorization information.

[0124] In another implementation, the first authorizing device may authorize communication solely based on whether the terminal device allows communication with the UAV-C paired with it, regardless of whether the terminal device can fly within the requested mobility path. If communication between the terminal device and the UAV-C is permitted, the first authorizing device can indicate successful authorization via the first authorization information. If communication between the terminal device and the UAV-C is not permitted, the first authorizing device can indicate authorization failure via the first authorization information.

[0125] If authorization is required for a terminal device to fly in the requested movement path, the terminal device can initiate an authorization process again. This authorization process can be parallel to and independent of the process that authorizes communication between the terminal device and the controller UAV-C paired with the terminal device. The specific process of the authorization process for the movement path can refer to any of the implementation methods one to four of this application.

[0126] In another implementation, the first authorizing device may authorize the terminal device solely based on whether it can fly along the requested mobility path, regardless of whether the terminal device is allowed to communicate with its paired UAV-C. If the terminal device can fly along the requested mobility path, the first authorizing device can indicate successful authorization via the first authorization information. If the terminal device cannot fly along the requested mobility path, the first authorizing device can indicate authorization failure via the first authorization information.

[0127] If authorization is required to allow communication between a terminal device and its paired UAV-C, the terminal device can initiate an authorization process again. This authorization process can be parallel to and independent of the terminal device's mobile path authorization process.

[0128] The first authorizing device can send first authorizing information to the SMF via the NEF. For example, the first authorizing device can send a first authorizing response message to the SMF, which includes the first authorizing information. The NEF then forwards the first authorizing information from the first authorizing response message to the SMF. Alternatively, the first authorizing device can send the first authorizing information to the NEF, and the NEF can forward the first authorizing information to the SMF. After receiving the first authorizing information, both the NEF and the SMF can store it.

[0129] After obtaining the first authorization information, the SMF can authorize communication for the terminal device based on this information. Specifically, if the first authorization information indicates successful authorization, the SMF establishes a session for the terminal device. For example, taking the establishment of a PDU session as an example, the process may include the following steps:

[0130] Step 1. The SMF selects a PCF for the terminal device, and the SMF requests policy rules from the PCF.

[0131] Step 2. SMF selects a UPF for the terminal device.

[0132] Step 3. The SMF reports session-related information to the PCF (such as the IP address / prefix of the terminal device, trigger status, etc.).

[0133] Step 4. SMF sends tunnel information to UPF, including group detection, execution, and reporting rule information.

[0134] Step 5. The SMF sends the PDU session identifier, N2 session management information (N2 SM Information), and N1 SM container to the AMF. The N2 SM Information is sent to the RAN and forwarded to the RAN by the AMF. The N1 SM container contains the assigned IP address information and is sent to the terminal device, which is forwarded to the terminal device by the RAN and AMF.

[0135] Step 6. The AMF sends an N2 PDU session request to the RAN, which includes N2 SM Information and an N1 SM container. The N1 SM container contains the assigned IP address information.

[0136] Step 7. RAN forwards N1 SM Container from Step 6, and the terminal device receives N1 SM Container sent by the network side.

[0137] The above process can complete the establishment of a PDU session. The PDU session establishment process may also include other procedures. For details, please refer to the descriptions in existing standards. They will not be elaborated here.

[0138] If the first authorization message indicates that authorization has failed, then the SMF can refuse to establish a PDU session for the terminal device, that is, refuse to establish a session.

[0139] Optionally, the first authorizing device can also determine whether the terminal device's movement path passes through the areas corresponding to other authorizing devices based on the movement path information in the C2 airborne payload. For example, if the first authorizing device determines that the terminal device's movement path passes through the second area corresponding to the second authorizing device, it can also interact with the second authorizing device to determine the result of the first authorizing device's communication authorization for the terminal device based on the result of the second authorizing device's communication authorization for the terminal device. For instance, when the first authorizing device determines that the second authorizing device has successfully authorized communication for the terminal device, it can indicate successful authorization through the first authorization information.

[0140] In this application, if the first authorization information indicates authorization failure, the first authorization device can execute a procedure to refuse to establish a session with devices such as SMF; the specific process will not be elaborated further. If the first authorization information indicates authorization success, that is, if the first authorization device agrees to authorize communication with the terminal device, the first authorization device can also execute S304 and S305.

[0141] S304: The first authorized device obtains the location information of the terminal device.

[0142] The first authorized device can obtain the location information of the terminal device in a variety of ways.

[0143] In the first implementation, the first authorized device can subscribe to the location information of the terminal device from the network, such as subscribing to the location information of the terminal device from the AMF or GMLC. The AMF or GMLC can periodically send the location information of the terminal device to the first authorized device.

[0144] In the second implementation, the terminal device can proactively report its location information to the first authorized device. For example, the terminal device can periodically report its location information to the first authorized device through the application layer.

[0145] In this application, the location information of the terminal device can be the latitude and longitude coordinates of the terminal device, or other types of location information.

[0146] The above is just an example. The first authorized device can also obtain the location information of the terminal device through other means, which will not be elaborated here.

[0147] S305: When it is determined that the terminal device has moved outside the first area corresponding to the first authorized device, the first authorized device sends the first information to NEF.

[0148] The first information can be used to instruct the terminal device to re-authorize communication, or the first information can be used to instruct the terminal device to re-authorize C2 communication.

[0149] In one possible implementation, the first information may include information instructing the replacement of the authorized device, or the first information may instruct the replacement of the authorized device. Alternatively, the first information itself may be used to instruct the replacement of the authorized device, or information instructing the replacement of the authorized device.

[0150] In the second possible implementation, the first information includes information for indicating that the authorization of the first authorized device has expired, or the first information itself can be used to indicate that the authorization of the first authorized device has expired.

[0151] Optionally, the first information may also indicate the reason for the authorization failure (the reason for authorization failure may also be called the reason for re-authorizing communication), for example, the reason for failure is that the terminal device has moved outside the first area.

[0152] In the third possible implementation, the first information includes the identification information of the second authorized device, or the first information itself is the identification information of the second authorized device. The first authorized device can obtain or pre-configure regions corresponding to multiple authorized devices. Therefore, the first authorized device can determine the second authorized device based on the location information of the terminal device. The region where the terminal device is located after moving out of the first region is the second region corresponding to the second authorized device. The specific content of the identification information of the second authorized device can be found in the description of the identification information of the first authorized device, and will not be repeated here.

[0153] In other words, information indicating the replacement of the authorized device, information indicating the expiration of the authorization, and information including the identification information of the second authorized device can all be understood as the first information used to indicate the re-authorization of communication for the terminal device. It can be understood that any information that enables the NEF (or SMF) to know to re-authorize the terminal device (i.e., to initiate an authorization request to the second authorized device) can be called the first information in this application.

[0154] The first information may also indicate other information, such as the identifier of the terminal device, etc., which is not limited in this application.

[0155] This application does not limit how the first authorized device determines that the terminal device has moved outside the first area. For example, in a first implementation, the first authorized device can use the location information of the terminal device to determine that the terminal device has moved outside the first area based on the location information of the terminal device and the first area.

[0156] In the second implementation, the first authorized device can send a subscription request message (or a message requesting a notification that the terminal device has moved outside the first area) to the mobility management device. The subscription request message is used to subscribe to the notification that the terminal device has moved outside the first area. When the first authorized device receives a notification message from the mobility management device, it can determine that the terminal device has moved outside the first area based on the notification message. The notification message can be used to instruct the terminal device to move outside the first area.

[0157] The mobile management device can be an AMF or a gateway mobile location (GLMC) device, etc., and this application does not limit it.

[0158] In the third implementation method, when the terminal device moves outside the first area, the mobility management device actively sends a notification message to the first authorized device, and the first authorized device can determine that the terminal device has moved outside the first area based on the notification message.

[0159] In addition, the first information can be carried through messages such as authorization notification messages, reauthorization request messages, or USS replacement request messages, and this application does not limit this.

[0160] Step S305 can also be replaced by: the first authorized device determining that the terminal device has moved to the edge of the first area corresponding to the first authorized device, or the first authorized device determining that the terminal device is about to move out of the first area corresponding to the first authorized device, and the first authorized device sending first information to NEF.

[0161] Specifically, the first authorized device can determine whether the terminal device has moved to the edge of the first area corresponding to the first authorized device or whether the terminal device is about to move out of the first area corresponding to the first authorized device based on the location information of the terminal device and the first area information. The first area information can be used to indicate the first area corresponding to the first authorized device.

[0162] As mentioned above, in this application, the core network device can be either NEF or SMF. When the core network device is NEF, it can execute S306 to S308.

[0163] Optionally, S306: NEF obtains the identification information of the second authorized device.

[0164] If the first information indicates the identification information of the second authorized device, then S306 may not be executed.

[0165] If the first information does not indicate the identification information of the second authorized device, then NEF can obtain the identification information of the second authorized device in any of the following ways.

[0166] In the first implementation, the NEF can request the identification information of the second authorized device from the terminal device, thereby obtaining the identification information of the second authorized device from the terminal device. Specifically, the NEF can request the identification information of the second authorized device from the terminal device through the SMF, and the terminal device determines the second authorized device based on the location information of the terminal device, thereby providing the identification information of the second authorized device.

[0167] The second implementation involves the NEF acquiring or pre-configuring the mapping between different authorized devices and different regions (i.e., the identification information of the authorized devices and their corresponding region information). The NEF can obtain the location information of the terminal device from the mobility management device, and based on the location information of the terminal device and the region information corresponding to one or more authorized devices, it can obtain the identification information of a second authorized device, where the one or more authorized devices include the second authorized device. Specifically, the SMF determines the region where the terminal device is located based on the location information of the terminal device. If it is determined that the terminal device is located in the second region corresponding to the second authorized device within the region corresponding to one or more authorized devices, the NEF can then determine the identification information of the second authorized device. The NEF can obtain the mapping between different authorized devices and different regions from the first authorized device, the UDM device, or the UDR device.

[0168] In the third implementation, the NEF obtains or pre-configures the correspondence between different authorized devices and different regions. The NEF obtains the identifier of the terminal device (which can be obtained through S301 or through the first information). This identifier can be the CAA Level UAV ID of the terminal device. The NEF obtains the location information of the terminal device from the mobility management device. The NEF can determine the identifier information of the second authorized device based on the region corresponding to the authorized device associated with the CAA Level UAV ID and the location information of the terminal device.

[0169] Specifically, NEF can determine candidate authorized devices based on the authorized devices associated with the CAA Level UAV ID, and then use the candidate authorized devices corresponding to the region where the terminal device is located as the second authorized devices, thereby determining the identification information of the second authorized devices. NEF can obtain the correspondence between different authorized devices and different regions from the first authorized device, UDM device, or UDR device.

[0170] S307: NEF sends a second request message to the second authorized device.

[0171] The second request message is used to request communication authorization for the terminal device, specifically a request for a second authorizing device to grant C2 communication authorization to the terminal device. The second request message may include at least one of the following: the identification information of the second authorizing device, C2 airborne payload, and the identification of the terminal device.

[0172] NEF can obtain the C2 airborne payload and the identifier of the terminal device from the terminal device, or it can obtain the above information through other means, which is not limited in this application.

[0173] The identifier of the terminal device included in the second request message may be the same as or different from the identifier of the terminal device included in the first request message in S302. If the identifier of the terminal device included in the second request message is different from the identifier of the terminal device included in the first request message, then the identifier may be the CAA Level UAV ID assigned to the terminal device by the second authorizing device. This identifier may be obtained by the NEF from the terminal device or may be obtained through other means; this application does not limit this.

[0174] S308: NEF receives second authorization information from the second authorization device.

[0175] The second authorization information is used to indicate the result of the second authorization device's communication authorization to the terminal device. The second authorization information can indicate whether the authorization was successful or failed. Accordingly, the NEF learns the result of the second authorization device's communication authorization to the terminal device.

[0176] After receiving the second authorization information from the second authorization device, NEF stores the second authorization information, or deletes the first authorization information and stores the second authorization information, or updates the first authorization information according to the second authorization information.

[0177] When the second authorization information indicates successful authorization, the NEF can determine that the terminal device has been successfully authorized. Since both the first and second authorization information indicate successful authorization, the NEF does not need to further notify the SMF. In this case, the user plane session of the terminal device's C2 communication remains unchanged, i.e., the PDU session remains unchanged. Optionally, the NEF may also forward the second authorization information to the SMF.

[0178] When the second authorization information indicates authorization failure, the NEF can determine that the terminal device's authorization has failed. In this case, the NEF can send an indication message to the SMF, which can either instruct the second authorizing device that the communication authorization for the terminal device has failed or instruct the SMF to release the terminal device's C2 communication user plane session (i.e., release the PDU session). Alternatively, the NEF can forward the second authorization information to the SMF. Correspondingly, when the SMF determines that the terminal device's C2 communication authorization has failed or that the terminal device's C2 communication user plane session needs to be released based on the NEF's indication message or the second authorization information, the SMF can trigger the release of the terminal device's C2 communication user plane session. The specific process of releasing the user plane session is not limited in this application and will not be elaborated upon here.

[0179] In this application, when the core network equipment is an SMF, S306 to S308 can be replaced by the following steps:

[0180] S309: NEF sends the first message to SMF.

[0181] After obtaining the first information, SMF can determine whether it is necessary to re-authorize communication or re-authorize C2 communication for the terminal device.

[0182] Optionally, S310: SMF obtains the identification information of the second authorized device.

[0183] If the first information indicates the identification information of the second authorized device, then S310 may not need to be executed.

[0184] If the first information does not indicate the identification information of the second authorized device, then the SMF may obtain the identification information of the second authorized device in any of the following ways.

[0185] In the first implementation, the SMF can request the identification information of the second authorized device from the terminal device, thereby obtaining the identification information of the second authorized device from the terminal device.

[0186] The second implementation involves the SMF acquiring or pre-configuring the mapping between different authorized devices and different regions (i.e., the identification information of the authorized devices and their corresponding region information). The SMF can request the location information of the terminal device from the mobility management device and obtain the identification information of a second authorized device based on the location information of the terminal device and the region information corresponding to one or more authorized devices, where the one or more authorized devices include the second authorized device. Specifically, the SMF determines the region where the terminal device is located based on the location information of the terminal device. If it is determined that the terminal device is located in the second region corresponding to the second authorized device within the region corresponding to one or more authorized devices, the SMF can then determine the identification information of the second authorized device. The SMF can obtain the mapping between different authorized devices and different regions from the first authorized device, the UDM device, or the UDR device.

[0187] In the third implementation, the SMF obtains or pre-configures the correspondence between different authorized devices and different regions. The SMF obtains the identifier of the terminal device (which can be obtained through S301 or through the first information). This identifier can be the CAA Level UAV ID of the terminal device. The SMF obtains the location information of the terminal device from the mobility management device. The NEF can determine the identifier information of the second authorized device based on the region corresponding to the authorized device associated with the CAA Level UAV ID and the location information of the terminal device.

[0188] Specifically, SMF can determine candidate authorized devices based on the authorized devices associated with the CAA Level UAV ID, and then use the candidate authorized devices corresponding to the region where the terminal device is located as the second authorized devices, thereby determining the identification information of the second authorized devices.

[0189] S311: The SMF sends a second request message to the second authorized device, which is used to request communication authorization for the terminal device.

[0190] The second request message may include at least one of the identification information of the second authorized device, the identification of the C2 airborne payload, and the identification of the terminal device.

[0191] This step can also be replaced by the SMF sending at least one piece of information to the second authorized device via the NEF: the identification information of the first authorized device; the C2 airborne payload; and the identification of the terminal device.

[0192] The SMF can obtain the C2 airborne payload and the identifier of the terminal device from the terminal device, or it can obtain the above information through other means, which is not limited in this application.

[0193] S312: SMF receives second authorization information from the second authorization device.

[0194] Specifically, the SMF receives second authorization information from the second authorization device via the NEF. Accordingly, the SMF learns the result of the second authorization device granting communication authorization to the terminal device.

[0195] Specifically, when the second authorization information indicates successful authorization, the SMF can retain the session established for the terminal device based on the first authorization information, or keep the user plane session of the terminal device's C2 communication unchanged, that is, keep the PDU session unchanged.

[0196] When the second authorization information indicates authorization failure, the SMF can release the session established for the terminal device based on the first authorization information, or release the user plane session of the terminal device's C2 communication, i.e., release the PDU session. The specific process of releasing the user plane session is not limited in this application and will not be described in detail here.

[0197] Using the above method, when the first authorized device determines that the terminal device has moved outside the first area, it can notify the core network device, which in turn requests the second authorized device to re-authorize the terminal device for communication. This ensures that multiple authorizations can be granted to the terminal device without interrupting communication, thereby improving system efficiency.

[0198] Implementation Method Two:

[0199] In the second implementation method of this application, after the first authorized device successfully authorizes C2 communication for the terminal device, when the core network device (SMF or NEF) determines that the terminal device has moved from the first area corresponding to the first authorized device to the second area corresponding to the second authorized device, it can request the second authorized device to authorize communication for the terminal device. For details, please refer to the description in the following process.

[0200] like Figure 4 The diagram shown is a schematic flowchart of an authorization method provided in an embodiment of this application.

[0201] S401: The terminal device sends a session establishment request or session modification request message to the SMF.

[0202] The session that a terminal device requests to establish or modify can be a PDU session.

[0203] S402: SMF sends a first request message to the first authorized device.

[0204] For details on S401 to S402, please refer to the descriptions in S301 to S302, which will not be repeated here.

[0205] S403: The first authorized device sends the first authorization information and the first area information to NEF.

[0206] The first authorization information is used to indicate the result of the first authorization device granting communication authorization to the terminal device. The first authorization information can indicate whether the authorization was successful or failed. The first area information can be used to indicate the first area corresponding to the first authorization device. Accordingly, NEF learns the result of the first authorization device granting communication authorization to the terminal device.

[0207] The first authorized device can send the first authorization information and the first area information to NEF through the first authorization response message.

[0208] Optionally, in S403, the first authorization information and the first area information can indicate that: the first authorization information is valid when the terminal device is in the first area; and the first authorization information is invalid when the terminal device is outside the first area. Alternatively, the first authorization device can indicate the above content through other indication information.

[0209] Optionally, when the first authorization information indicates successful authorization, the first authorization device sends the first area information to NEF.

[0210] Optionally, when the first authorizing device determines that the terminal device's movement path passes through the second area corresponding to the second authorizing device based on the terminal device's movement path information, the first authorizing device may send the identification information of the second authorizing device to the NEF. The movement path information is included in the first request message in step S402.

[0211] Optionally, when the first authorized device determines that the terminal device's movement path passes through the second area corresponding to the second authorized device based on the terminal device's movement path information, the first authorized device sends the identification information of the second authorized device and the second area information corresponding to the second authorized device to NEF.

[0212] In this application, the core network device can be either NEF or SMF. If the core network device is SMF, and the first authorization information indicates successful authorization, the following process is also included:

[0213] S404: NEF forwards the first authorization information and the first area information to SMF.

[0214] Optionally, when the first authorized device sends the identification information of the second authorized device to the NEF, the NEF also forwards the identification information of the second authorized device to the SMF. Accordingly, the SMF learns the result of the first authorized device's communication authorization to the terminal device.

[0215] Optionally, when the first authorized device sends the identification information of the second authorized device and the second area information to the NEF, the NEF also sends the identification information of the second authorized device and the second area information to the SMF.

[0216] After obtaining the first authorization information, the SMF can authorize communication for the terminal device based on the first authorization information. Specifically, if the first authorization information indicates successful authorization, then the SMF establishes a PDU session for the terminal device, i.e., establishes a session. The specific process is not limited in this application and will not be elaborated here. If the first authorization information indicates authorization failure, then the SMF can refuse to establish a PDU session for the terminal device, i.e., refuse to establish a session.

[0217] The first authorization information and the first area information can indicate that the first authorization information is valid when the terminal device is in the first area, and invalid when the terminal device is outside the first area. Alternatively, NEF can indicate the above through other indication information.

[0218] Optionally, S405: The SMF sends a subscription request message to the mobility management device.

[0219] The subscription request message includes first area information and is used to request a notification that the terminal device has moved outside the first area corresponding to the first authorized device. When the terminal device moves outside the first area, the mobility management device executes the following process:

[0220] S406: The Mobility Management Device sends a notification message to the SMF, which instructs the terminal device to move outside the first area. The notification message may also include the location information of the terminal device.

[0221] SMF can also choose not to send subscription request messages. When the terminal device moves outside the first area corresponding to the first authorized device, the mobility management device can proactively send a notification message to SMF.

[0222] S405 and S406 can also be replaced by the following steps:

[0223] Step 1: SMF sends a subscription message to the mobility management device.

[0224] The subscription message is used to subscribe to the location information of the terminal device. Optionally, the subscription message may include periodic information, which indicates the period at which the mobility management device reports the location information of the terminal device.

[0225] Step 2: The SMF receives the location information of the terminal device from the mobility management device, and determines whether the terminal device has moved outside the first area based on the location information of the terminal device and the first area information.

[0226] In the first implementation, if the SMF receives the notification message, or if the SMF determines that the terminal device has moved outside the first area based on the terminal device's location information and the first area information, it can indicate authorization failure to the terminal device and release the C2 communication user plane session, i.e., release the PDU session. In this implementation, steps S407 to S409 can be omitted.

[0227] In the second implementation, the SMF determines that the terminal device has moved outside the first area corresponding to the first authorized device based on the notification message, or the SMF determines that the terminal device has moved outside the first area based on the terminal device's location information and the first area information, thereby determining to re-authorize communication for the terminal device. In this implementation, assuming the terminal device moves to the second area corresponding to the second authorized device, the SMF can also execute the following process:

[0228] Optionally, S407: SMF obtains the identification information of the second authorized device.

[0229] SMF can obtain the identification information of the second authorized device through any of the following methods.

[0230] In the first implementation, the SMF obtains the identification information of the second authorized device through a terminal device, a first authorized device, or a UDM. For example, the SMF sends an identification information request message to the terminal device, the first authorized device, or the UDM. This identification information request message includes the location information of the terminal device. This identification information request message can be used to request the identification information of the authorized device corresponding to the area containing the location information. Upon receiving the identification information request message, the terminal device, the first authorized device, or the UDM can determine the identification information of the second authorized device based on the location information, and thus send the identification information of the second authorized device to the SMF.

[0231] The second implementation involves the SMF including the mapping between different authorized devices and different regions (i.e., the identification information of the authorized devices and their corresponding region information). The SMF obtains the identification information of a second authorized device based on the location information of the terminal device and the region information corresponding to one or more authorized devices, where the one or more authorized devices include the second authorized device. Specifically, the SMF determines the region where the terminal device is located based on its location information. Within the regions corresponding to one or more authorized devices, if it is determined that the terminal device is in the second region corresponding to the second authorized device, the SMF can then determine the identification information of the second authorized device. The SMF can obtain the mapping between different authorized devices and different regions from the first authorized device, the UDM device, or the UDR device.

[0232] In the third implementation, in S404, the SMF receives the identification information of the second authorized device from the NEF. Furthermore, the SMF can also receive the second region information of the second authorized device from the NEF.

[0233] The fourth implementation involves the SMF acquiring or pre-configuring the mapping between different authorized devices and different regions. The SMF acquires the identifier of the terminal device (which can be obtained via S401), which can be the CAA Level UAV ID of the terminal device. The SMF obtains the location information of the terminal device from the mobility management device. The NEF can determine the identifier information of the second authorized device based on the region corresponding to the authorized device associated with the CAA Level UAV ID and the location information of the terminal device.

[0234] Specifically, SMF can determine candidate authorized devices based on the authorized devices associated with the CAA Level UAV ID, and then use the candidate authorized devices corresponding to the region where the terminal device is located as the second authorized devices, thereby determining the identification information of the second authorized devices.

[0235] In this application, if the SMF cannot obtain the identification information of the second authorized device, it can release the user plane session of the terminal device C2 communication, that is, release the PDU session.

[0236] S408: The SMF sends a second request message to the second authorized device, which is used to request communication authorization for the terminal device.

[0237] S409: SMF receives second authorization information from the second authorization device.

[0238] Specifically, the SMF can determine whether to retain or release the session established for the terminal device based on the first authorization information, according to the second authorization information. Accordingly, the SMF learns the result of the second authorization device's communication authorization to the terminal device.

[0239] For details on S408 to S409, please refer to the descriptions in S311 to S312, which will not be repeated here.

[0240] When the core network device is NEF and the first authorization information indicates successful authorization, S405 to S409 can be replaced with the following steps:

[0241] Optionally, S410: NEF sends a subscription request message to the mobility management device.

[0242] The subscription request message includes first area information and is used to request a notification that the terminal device has moved outside the first area corresponding to the first authorized device. When the terminal device moves outside the first area, the mobility management device executes the following process:

[0243] S411: The mobility management device sends a notification message to the NEF, which instructs the terminal device to move outside the first area. The notification message may also include the location information of the terminal device.

[0244] SMF can also choose not to send subscription request messages. When the terminal device moves outside the first area corresponding to the first authorized device, the mobility management device can proactively send a notification message to SMF.

[0245] In another implementation, S410 and S411 can be replaced by the following steps:

[0246] Step 1: NEF sends a subscription message to the mobility management device.

[0247] The subscription message is used to subscribe to the location information of the terminal device. Optionally, the subscription message may include periodic information, which indicates the period at which the mobility management device reports the location information of the terminal device.

[0248] Step 2: NEF receives the location information of the terminal device from the mobility management device, and determines whether the terminal device has moved outside the first area based on the location information of the terminal device and the first area information.

[0249] NEF can periodically obtain the location information of the terminal device from the mobility management device. NEF can determine whether the terminal device has moved outside the first area based on the location information of the terminal device and the first area information.

[0250] When the NEF determines, based on the notification message, that the terminal device has moved outside the first area corresponding to the first authorized device, or when the NEF determines, based on the terminal device's location information and the first area information, that the terminal device has moved outside the first area, it can determine to re-authorize communication for the terminal device. Assuming the terminal device moves to the second area corresponding to the second authorized device, the NEF can also execute the following procedure:

[0251] S412: NEF obtains the identification information of the second authorized device.

[0252] For details on how NEF obtains the identification information of the second authorized device, please refer to the description in S407, which will not be repeated here.

[0253] S413: NEF sends a second request message to the second authorized device, the second request message being used to request communication authorization for the terminal device.

[0254] S414: NEF receives second authorization information from the second authorization device.

[0255] The second authorization information is used to indicate the result of the second authorization device's communication authorization to the terminal device. The second authorization information can indicate whether the authorization was successful or failed. Accordingly, the NEF learns the result of the second authorization device's communication authorization to the terminal device.

[0256] After receiving the second authorization information from the second authorization device, NEF stores the second authorization information, or deletes the first authorization information and stores the second authorization information, or updates the first authorization information according to the second authorization information.

[0257] When the second authorization information indicates successful authorization, the NEF can determine that the terminal device has been successfully authorized. Since both the first and second authorization information indicate successful authorization, the NEF does not need to further notify the SMF. In this case, the user plane session of the terminal device's C2 communication remains unchanged, i.e., the PDU session remains unchanged. Optionally, the NEF may also forward the second authorization information to the SMF.

[0258] When the second authorization information indicates authorization failure, the NEF can determine that the terminal device's authorization has failed. In this case, the NEF can send an indication message to the SMF, which can either instruct the second authorizing device that the communication authorization for the terminal device has failed or instruct the SMF to release the terminal device's C2 communication user plane session (i.e., release the PDU session). Alternatively, the NEF can forward the second authorization information to the SMF. Correspondingly, when the SMF determines that the terminal device's C2 communication authorization has failed or that the terminal device's C2 communication user plane session needs to be released based on the NEF's indication message or the second authorization information, the SMF can trigger the release of the terminal device's C2 communication user plane session. The specific process of releasing the user plane session is not limited in this application and will not be elaborated upon here.

[0259] For details on S412 to S414, please refer to the descriptions in S306 to S308, which will not be repeated here.

[0260] Using the above method, when the core network device determines that the terminal device has moved outside the first area, it can request the second authorizing device to re-authorize the terminal device for communication, thereby ensuring that multiple authorizations can be granted to the terminal device without interrupting communication and improving system efficiency.

[0261] Implementation method three:

[0262] In the third implementation of this application, during the user plane session establishment process, the core network device requests the first authorizing device to authorize C2 communication for the terminal device. If the first authorizing device determines that authorization from other authorizing devices is also required, it can instruct the core network device to request communication authorization from other authorizing devices for the terminal device. For details, please refer to the description in the following process.

[0263] like Figure 5 The diagram shown is a schematic flowchart of an authorization method provided in an embodiment of this application.

[0264] S501: The terminal device sends a session establishment request or session modification request message to the SMF. This session establishment request or session modification request message can be used to request the establishment of a session.

[0265] The session that a terminal device requests to establish or modify can be a PDU session.

[0266] S502: SMF sends a first request message to the first authorized device.

[0267] For details on S501 to S502, please refer to the descriptions in S301 to S302, which will not be repeated here.

[0268] In this application, the core network equipment can be NEF or SMF. If the first authorizing device determines that authorization has failed, the first authorizing device can execute a procedure to refuse to establish a session with the SMF or other equipment; the specific process will not be described in detail.

[0269] If the first authorizing device determines that the authorization is successful, that is, if the first authorizing device agrees to authorize the terminal device to communicate, the following process may also be included when the core network device is NEF.

[0270] S503: The first authorized device sends the first authorization information to NEF.

[0271] The first authorizing device can also send the identification information or first instruction information of the second authorizing device to the NEF. Accordingly, the NEF learns the result of the first authorizing device's authorization of communication with the terminal device.

[0272] When the first authorizing device confirms successful authorization, it can determine whether the terminal device's movement path passes through areas corresponding to other authorizing devices based on the terminal device's movement path information. If the terminal device's movement path passes through areas corresponding to other authorizing devices (e.g., the area corresponding to the second authorizing device), it can also send the identification information or first indication information of the second authorizing device. The first indication information indicates that the terminal device requires authorization from other authorizing devices, or it indicates that the first authorizing device cannot authorize communication with the terminal device independently. These other authorizing devices can be replaced by multiple authorizing devices, including the first authorizing device and the second authorizing device. The second authorizing device is the authorizing device corresponding to the second area traversed by the terminal device's movement path, as determined by the first authorizing device based on the movement path information. The terminal device's movement path information may also pass through areas corresponding to multiple authorizing devices; this application only uses the second authorizing device as an example for illustration.

[0273] When the core network device is NEF, if the first authorized device does not send the identification information of the second authorized device to NEF, but instead sends the first indication information, then NEF can obtain the identification information of the second authorized device. Specifically:

[0274] S504: NEF obtains the identification information of the second authorized device based on the first instruction information.

[0275] In one possible implementation, the NEF sends second instruction information to the terminal device or data management device based on the first instruction information. The NEF can also receive identification information of a second authorized device from the terminal device or data management device. The data management device can be a device such as a UDM, and the second instruction information is used to request the identification information of an authorized device corresponding to the area traversed by the terminal device's movement path.

[0276] In another possible implementation, the NEF sends second instruction information to the terminal device based on the first instruction information. The NEF can receive movement path information from the terminal device. Based on the movement path information of the terminal device, the NEF can determine that the movement path of the terminal device passes through one or more authorized devices' corresponding areas, thereby determining the identification information of the one or more authorized devices. This application describes the example of the terminal device's movement path passing through a first area corresponding to the first authorized device and a second area corresponding to the second authorized device, but it is not limited to only passing through the first and second areas.

[0277] NEF can also obtain the identification information of the second authorized device in accordance with S306, the specific process of which will not be elaborated here.

[0278] S505: NEF sends a second request message to the second authorized device, the second request message being used to request communication authorization for the terminal device.

[0279] Optionally, NEF can also forward the first authorization information to the second authorization device.

[0280] The specific details of S505 can be described in S302 or S307, and will not be repeated here.

[0281] S506: NEF receives second authorization information from the second authorization device.

[0282] Accordingly, NEF learns the result of the second authorized device granting communication authorization to the terminal device.

[0283] Optionally, if NEF does not forward the first authorization information to the second authorization device, then when the second authorization device determines that the authorization was successful, it can determine whether the terminal device's movement path has passed through the area corresponding to other authorization devices based on the terminal device's movement path information. If the terminal device's movement path has passed through the area corresponding to other authorization devices (e.g., the area corresponding to the first authorization device), it can also send the identification information or first indication information of the first authorization device. The first indication information is used to indicate that the terminal device needs authorization from multiple authorization devices or other authorization devices. The first authorization device is the authorization device corresponding to the first area passed through by the terminal device's movement path, as determined by the second authorization device based on the movement path information.

[0284] If NEF forwards the first authorization information to the second authorization device, then the second authorization device will not send the identification information or the first instruction information of the first authorization device.

[0285] S507: NEF obtains the authorization result based on the first authorization information and the second authorization information.

[0286] If both the first and second authorization messages indicate successful authorization, the NEF determines that the authorization result is successful for communication with the terminal device. The NEF can send a message to the SMF indicating successful authorization for the terminal device, and the SMF can then accept the terminal device's session establishment request or session modification request message, or establish a session for the terminal device, thereby establishing a C2 communication connection for the terminal device. The specific process will not be elaborated further.

[0287] If either the first authorization message or the second authorization message indicates authorization failure, the NEF determines that the authorization result is a failure to authorize communication with the terminal device. The NEF can send a message to the SMF indicating that the authorization for the terminal device has failed. Consequently, the SMF will reject the terminal device's session establishment request or session modification request message, or refuse to establish a session for the terminal device. The SMF will not establish a C2 communication connection for the terminal device. The specific process will not be elaborated further.

[0288] Optionally, the SMF can also send a session establishment response or session modification response message to the terminal device. This message may include authorization result information, which indicates whether the session establishment or modification is accepted or rejected. For example, if both the first and second authorization messages indicate successful authorization, the authorization result information indicates acceptance of the session establishment or modification. If either the first or second authorization message indicates authorization failure—that is, if either the first or second authorization device failed to authorize the terminal device—the authorization result information indicates rejection of the session establishment or modification, and / or includes identification information indicating the authorization device that failed to authorize the terminal device. For instance, if the second authorization message sent by the second authorization device indicates authorization failure, the authorization result information could indicate that the second authorization device failed to authorize the terminal device.

[0289] If the first authorized device confirms successful authorization, when the core network device is SMF, S503 to S507 can be replaced with the following steps.

[0290] S508: The first authorized device sends the first authorization information and the identification information or first instruction information of the second authorized device to the SMF.

[0291] Accordingly, the SMF learns the result of the first authorized device granting communication authorization to the terminal device.

[0292] If the first authorized device does not send the identification information of the second authorized device, but instead sends the first indication information, then the SMF can obtain the identification information of the second authorized device. Specifically:

[0293] S509: SMF obtains the identification information of the second authorized device based on the first instruction information.

[0294] SMF can obtain the identification information of the second authorized device in accordance with S306 or S504, and the specific process will not be described in detail.

[0295] S510: The SMF sends a second request message to the second authorized device, which is used to request communication authorization for the terminal device.

[0296] The specific details of S510 can be described in S302 or S311, and will not be repeated here.

[0297] S511: The SMF receives the second authorization information from the second authorization device and obtains the authorization result based on the first authorization information and the second authorization information.

[0298] Accordingly, the SMF learns the result of the second authorized device granting communication authorization to the terminal device.

[0299] If both the first and second authorization messages indicate successful authorization, the SMF determines the authorization result as successful authorization for communication with the terminal device. The SMF can accept session establishment requests or session modification requests from the terminal device, or establish a session for the terminal device, thereby establishing a C2 communication connection for the terminal device. The specific process will not be elaborated further.

[0300] If either the first authorization message or the second authorization message indicates authorization failure, the SMF determines the authorization result as a failure to authorize communication with the terminal device. The SMF may reject the terminal device's session establishment request or session modification request message, or refuse to establish a session for the terminal device. Therefore, the SMF will not establish a C2 communication connection for the terminal device. The specific process will not be elaborated further.

[0301] Optionally, the SMF can also send a session establishment response or session modification response message to the terminal device. This message may include authorization result information, which indicates whether the session establishment or modification is accepted or rejected. For example, if both the first and second authorization messages indicate successful authorization, the authorization result information indicates acceptance of the session establishment or modification. If either the first or second authorization message indicates authorization failure—that is, if either the first or second authorization device failed to authorize the terminal device—the authorization result information indicates rejection of the session establishment or modification, and / or includes identification information indicating the authorization device that failed to authorize the terminal device. For instance, if the second authorization message sent by the second authorization device indicates authorization failure, the authorization result information could indicate that the second authorization device failed to authorize the terminal device.

[0302] Using the above method, when the mobile path of a terminal device passes through the areas corresponding to multiple authorized devices, the core network device can simultaneously request communication authorization from multiple authorized devices for the terminal device. When multiple authorized devices successfully authorize the terminal device, a session is then established for the terminal device, thereby enabling multiple authorizations for the terminal device and improving system efficiency.

[0303] Implementation Method 4:

[0304] In the fourth implementation method of this application, the terminal device determines whether it passes through the area corresponding to multiple authorized devices. If it passes through the area corresponding to multiple authorized devices, the terminal device can request communication authorization from multiple authorized devices through the core network device when requesting to establish a session. For details, please refer to the description in the following process.

[0305] like Figure 6 The diagram shown is a schematic flowchart of an authorization method provided in an embodiment of this application.

[0306] S601: The terminal device sends a session establishment request or session modification request message to the SMF. This session establishment request or session modification request message can be used to request the establishment of a session.

[0307] The session that the terminal device requests to establish or modify can be a PDU session. Taking the terminal device's movement path passing through the area corresponding to the first authorized device and the area corresponding to the second authorized device as an example, the session establishment request or session modification request message may include at least one of the following information:

[0308] Identification information of the first authorized device and the second authorized device; C2 air payload; identification of the terminal device.

[0309] When the mobile path of a terminal device passes through the area corresponding to other authorized devices, the session establishment request or session modification request message may include the identification information of the corresponding authorized device, which will not be elaborated here.

[0310] In this application, the terminal device pre-configures or obtains the regions corresponding to multiple authorized devices from other network devices. When the terminal device determines that its movement path passes through one or more regions corresponding to authorized devices based on the movement path information, it determines that authorization from those one or more authorized devices is required. Therefore, it can provide the identification information of those one or more authorized devices to the SMF via a session establishment request message. This application describes the scenario where the terminal device's movement path passes through a first region corresponding to a first authorized device and a second region corresponding to a second authorized device, but it is not limited to only passing through the first and second regions.

[0311] When the identifier of the terminal device is its CAA-level UAV ID, the session establishment request or session modification request message may include two CAA-level UAV IDs, such as a first CAA-level UAV ID and a second CAA-level UAV ID. The first CAA-level UAV ID may be assigned to the terminal device by the first authorizing device, and the second CAA-level UAV ID may be assigned to the terminal device by the second authorizing device.

[0312] In this application, the core network device can be either NEF or SMF. Assuming the core network device is NEF, the following process is also included:

[0313] S602: SMF sends the first authorization request message to NEF.

[0314] The first authorization request message includes a C2 airborne payload and is used to request a first authorizing device to authorize communication for the terminal device. The first authorization request message also includes identification information for both the first and second authorizing devices.

[0315] S603: NEF sends a first request message to the first authorized device.

[0316] The specific details of S603 can be described in S302 or S307, and will not be repeated here.

[0317] S604: NEF receives first authorization information from the first authorization device.

[0318] Accordingly, NEF learns the result of the first authorized device granting communication authorization to the terminal device.

[0319] S605: NEF sends a second request message to the sending second authorization device.

[0320] The specific details of S605 can be described in S302 or S307, and will not be repeated here.

[0321] S606: NEF receives second authorization information from the second authorization device.

[0322] Accordingly, NEF learns the result of the second authorized device granting communication authorization to the terminal device.

[0323] S607: NEF obtains the authorization result based on the first authorization information and the second authorization information.

[0324] For details on S607, please refer to the description in S507, which will not be repeated here.

[0325] Assuming the core network equipment is SMF, then S602 to S607 can be replaced by the following process:

[0326] S608: SMF sends a first request message to the first authorized device via NEF.

[0327] The specific details of S608 can be described in S302 or S311, and will not be repeated here.

[0328] S609: The SMF receives the first authorization information from the first authorization device via the NEF.

[0329] Accordingly, the SMF learns the result of the first authorized device granting communication authorization to the terminal device.

[0330] S610: SMF sends a second request message to the second authorized device via NEF.

[0331] The specific details of S610 can be described in S302 or S311, and will not be repeated here.

[0332] S611: The SMF receives second authorization information from the second authorization device via the NEF.

[0333] Accordingly, the SMF learns the result of the second authorized device granting communication authorization to the terminal device.

[0334] S612: SMF obtains the authorization result based on the first authorization information and the second authorization information.

[0335] For details on S612, please refer to the description in S511, which will not be repeated here.

[0336] Using the above method, when a terminal device determines that its movement path passes through the areas corresponding to multiple authorized devices, it can simultaneously request communication authorization from multiple authorized devices, thereby achieving communication authorization requests from multiple authorized devices with a single message and improving system efficiency.

[0337] In the embodiments provided above, the methods provided by the embodiments of this application have been described from the perspective of interaction between various devices. To implement the functions of the methods provided in the embodiments of this application, the authorized device, terminal device, or core network device may include hardware structures and / or software modules, implementing the above functions in the form of hardware structures, software modules, or a combination of hardware structures and software modules. Whether a particular function is executed in the form of hardware structures, software modules, or a combination of hardware structures and software modules depends on the specific application and design constraints of the technical solution.

[0338] The module division in this embodiment is illustrative and represents only one logical functional division; in actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0339] Similar to the above concept, such as Figure 7 As shown, this application embodiment also provides an apparatus 700 for implementing the functions of the authorized device, terminal device, or core network device in the above method. For example, the apparatus can be a software module or a chip system. In this application embodiment, the chip system can be composed of chips or may include chips and other discrete devices. The apparatus 700 may include: a processing unit 701 and a communication unit 702.

[0340] In this embodiment of the application, the communication unit may also be called a transceiver unit, which may include a sending unit and / or a receiving unit, respectively used to perform the steps of sending and receiving by the authorized device, terminal device or core network device in the above method embodiment.

[0341] The following, combined with Figures 7 to 8 This application provides a detailed description of the communication device provided in its embodiments. It should be understood that the descriptions of the device embodiments correspond to the descriptions of the method embodiments; therefore, any content not described in detail here will be referred to the method embodiments above, and for the sake of brevity, will not be repeated here.

[0342] A communication unit can also be called a transceiver, transceiver device, or transceiver unit. A processing unit can also be called a processor, processing board, processing module, or processing device. Optionally, the device in communication unit 702 used to implement the receiving function can be considered a receiving unit, and the device in communication unit 702 used to implement the transmitting function can be considered a transmitting unit; that is, communication unit 702 includes a receiving unit and a transmitting unit. A communication unit can sometimes also be called a transceiver, transceiver unit, or transceiver circuit. A receiving unit can sometimes be called a receiver, receiver, or receiving circuit. A transmitting unit can sometimes be called a transmitter, transmitter, or transmitting circuit.

[0343] The communication device 700 performs the functions described in the above embodiment. Figure 3 Or, in the process shown in 4, the core network equipment functions as follows:

[0344] A communication unit is used to receive first authorization information from the first authorization device;

[0345] The processing unit is configured to determine, based on the first authorization information, that the first authorized device has successfully authorized communication with the terminal device;

[0346] The communication unit is configured to send a request message to the second authorized device when the terminal device moves outside the area corresponding to the first authorized device. The request message is used to request the second authorized device to grant communication authorization to the terminal device. The second authorized device is the authorized device corresponding to the area where the terminal device is located after moving out of the area corresponding to the first authorized device. The unit also receives second authorization information from the second authorized device.

[0347] The processing unit is used to obtain the result of the second authorized device granting communication authorization to the terminal device based on the second authorization information.

[0348] The communication device 700 performs the functions described in the above embodiment. Figure 3 Or, in the process shown in 4, when the first authorized device performs its function:

[0349] The communication unit is used to send authorization information to the core network equipment, the authorization information being used to indicate the result of the first authorization equipment granting communication authorization to the terminal equipment; when the terminal equipment moves outside the area corresponding to the first authorization equipment, it sends first information to the core network equipment, the first information being used to instruct the terminal equipment to re-grant communication authorization.

[0350] The communication device 700 performs the functions described in the above embodiment. Figure 5 Or, in the process shown in 6, the core network equipment functions as follows:

[0351] The communication unit is configured to, when the movement path of the terminal device passes through the area corresponding to the first authorized device and the area corresponding to the second authorized device, acquire the identification information of the first authorized device; send a first request message to the first authorized device, the first request message being used to request the first authorized device to grant communication authorization to the terminal device; acquire the identification information of the second authorized device; send a second request message to the second authorized device, the first request message being used to request the second authorized device to grant communication authorization to the terminal device; receive first authorization information from the first authorized device; and receive second authorization information from the second authorized device, wherein the first authorization information is used to indicate the result of the first authorized device granting communication authorization to the terminal device, and the second authorization information is used to indicate the result of the second authorized device granting communication authorization to the terminal device.

[0352] The processing unit is used to obtain the authorization result based on the first authorization information and the second authorization information.

[0353] The communication device 700 performs the functions described in the above embodiment. Figure 5 Or, in the process shown in 6, when the first authorized device performs its function:

[0354] The communication unit is used to receive a request message from the core network equipment. The request message requests communication authorization for the terminal device and includes information about the terminal device's movement path. When the terminal device's movement path passes through areas corresponding to multiple authorized devices, it sends authorization information and first indication information or identification information of a second authorized device among the multiple authorized devices to the core network equipment. The authorization information indicates the result of the first authorized device granting communication authorization to the terminal device, and the first indication information indicates that the terminal device needs authorization from other authorized devices or that the first authorized device cannot grant communication authorization to the terminal device alone.

[0355] The communication device 700 performs the functions described in the above embodiment. Figure 6 The functions of the terminal device in the process shown are as follows:

[0356] The processing unit is used to determine the area corresponding to the first authorized device and the area corresponding to the second authorized device through which the mobile path of the terminal device passes.

[0357] The communication unit is used to send a session establishment request message to the core network equipment. The session establishment request message is used to request the establishment of a session for the terminal equipment. The session establishment request message includes the identification information of the first authorized device and the identification information of the second authorized device.

[0358] The above are just examples. Processing unit 701 and communication unit 702 can also perform other functions. For a more detailed description, please refer to the relevant descriptions in the method embodiments shown above. They will not be repeated here.

[0359] like Figure 8 The image shown is of the apparatus 800 provided in an embodiment of this application. Figure 8 The device shown can be Figure 7 The illustrated device represents one hardware circuit implementation. This communication device can be applied to the flowchart shown above to perform the functions of the authorized device, terminal device, or core network device in the method embodiments described above. For ease of explanation, Figure 8 Only the main components of the communication device are shown.

[0360] like Figure 8 As shown, the communication device 800 includes a processor 810 and an interface circuit 820. The processor 810 and the interface circuit 820 are coupled to each other. It is understood that the interface circuit 820 can be a transceiver, pins, interface circuitry, or input / output interface. Optionally, the communication device 800 may also include a memory 830 for storing instructions executed by the processor 810, or storing input data required by the processor 810 to execute instructions, or storing data generated after the processor 810 executes instructions.

[0361] When the communication device 800 is used to implement the method described above, the processor 810 is used to implement the function of the processing unit 701, and the interface circuit 820 is used to implement the function of the communication unit 702.

[0362] It is understood that the processor in the embodiments of this application can be a central processing unit, or other general-purpose processors, digital signal processors, application-specific integrated circuits, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor.

[0363] In the embodiments of this application, the memory may be random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, register, hard disk, portable hard disk, or any other form of storage medium known in the art.

[0364] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, optical storage, etc.) containing computer-usable program code.

[0365] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0366] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0367] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. An authorization method, characterized by, The method comprises: receiving first authorization information from a first authorization device, and learning that the first authorization device successfully authorizes terminal device command and control communication; when the terminal device moves out of a region corresponding to the first authorization device, sending a request message to a second authorization device, the request message being used to request the second authorization device to authorize the terminal device command and control communication, the second authorization device being an authorization device corresponding to a region where the terminal device is located after moving out of the region corresponding to the first authorization device; receiving second authorization information from the second authorization device, and learning a result of the second authorization device authorizing the terminal device command and control communication.

2. The method of claim 1, wherein, The method further comprises: obtaining first information from the first authorization device, the first information being used to indicate that the terminal device is re-authorized for communication; sending the request message to the second authorization device comprises: sending the request message to the second authorization device according to the first information.

3. The method of claim 2, wherein, The first information is one or more of the following: information indicating to replace the authorization device, information indicating that the first authorization device authorization is invalid, or identification information of the second authorization device.

4. The method of claim 1, wherein, The method further comprises: determining that the terminal device moves out of the region corresponding to the first authorization device.

5. The method of claim 4, wherein, The determination that the terminal device moves out of the region corresponding to the first authorization device comprises: obtaining location information of the terminal device; determining, according to the location information and the region corresponding to the first authorization device, that the terminal device moves out of the region corresponding to the first authorization device.

6. The method of claim 5, wherein, The determination that the terminal device moves out of the region corresponding to the first authorization device comprises: sending a request message to a mobility management device, the request message being used to notify that the terminal device moves out of the region corresponding to the first authorization device; receiving a notification message from the mobility management device, and determining, according to the notification message, that the terminal device moves out of the region corresponding to the first authorization device.

7. The method according to claim 5 or 6, characterized in that, The method further comprises: receiving, from the first authorization device, information of the region corresponding to the first authorization device.

8. The method according to any one of claims 1 to 7, characterized in that, Before the request message is sent to the second authorization device, the method further comprises: obtaining identification information of the second authorization device.

9. The method of claim 8, wherein, The obtaining of the identification information of the second authorization device comprises: receiving the identification information of the second authorization device from the terminal device or the first authorization device or a data management network element; or, obtaining location information of the terminal device, and obtaining the identification information of the second authorization device according to the location information of the terminal device and region information corresponding to one or more authorization devices.

10. The method according to any one of claims 1 to 9, characterized in that, The execution subject of the method is a network exposure function device, and the method further comprises: when the second authorization information indicates authorization failure, the network exposure function device sends, to a session management device, information indicating that the second authorization device fails to authorize the terminal device communication.

11. The method according to any one of claims 1 to 9, characterized in that, The execution subject of the method is a session management device, and the method further comprises: establishing a session for the terminal device according to the first authorization information.

12. The method of claim 11, wherein, The method further comprises: releasing a session established for the terminal device according to the first authorization information when the second authorization information indicates an authorization failure.

13. An authorization method, characterized by, The method comprises: The first authorization device sends authorization information to the core network device, the authorization information being used to indicate the result of the first authorization device authorizing the terminal device to communicate in a command and control mode; When the terminal device moves out of the area corresponding to the first authorization device, the first information is sent to the core network device, the first information being used to indicate that the terminal device is re-authorized to communicate in a command and control mode.

14. The method of claim 13, wherein, The first information is one or more of the following: information indicating a change of authorization device, information indicating that the first authorization device is no longer valid, or identification information of a second authorization device corresponding to the area where the terminal device is located after moving out of the area corresponding to the first authorization device.

15. The method of claim 14, wherein, When the first information is the identification information of the second authorization device, the method further comprises: obtaining the location information of the terminal device; obtaining the identification information of the second authorization device according to the location information of the terminal device and the area information corresponding to one or more authorization devices.

16. The method according to any one of claims 13 to 15, characterized in that, The method further comprises: obtaining the location information of the terminal device; and determining that the terminal device moves out of the area corresponding to the first authorization device according to the location information and the area information corresponding to the first authorization device; or, receiving a notification message from a mobility management device and determining that the terminal device moves out of the area corresponding to the first authorization device according to the notification message.

17. The method of claim 16, wherein, Before the first information is sent to the core network device, the method further comprises: determining that the terminal device is successfully authorized to communicate.

18. An authorization method, characterized by, The method comprises: When the terminal device moves along a path through an area corresponding to a first authorization device and an area corresponding to a second authorization device, obtaining the identification information of the first authorization device; sending a first request message to the first authorization device, the first request message being used to request the first authorization device to authorize the terminal device to communicate in a command and control mode; obtaining the identification information of the second authorization device; sending a second request message to the second authorization device, the first request message being used to request the second authorization device to authorize the terminal device to communicate in a command and control mode; receiving first authorization information from the first authorization device and second authorization information from the second authorization device, wherein the first authorization information is used to indicate the result of the first authorization device authorizing the terminal device to communicate in a command and control mode, and the second authorization information is used to indicate the result of the second authorization device authorizing the terminal device to communicate in a command and control mode; obtaining the result of the command and control authorization according to the first authorization information and the second authorization information.

19. The method of claim 18, wherein, The identification information of the first authorization device and the identification information of the second authorization device are obtained from the terminal device.

20. The method of claim 18, wherein, The method of obtaining the identification information of the second authorization device comprises: receiving the identification information of the second authorization device from the first authorization device.

21. The method of claim 18 or 19, wherein, The method of obtaining the identification information of the second authorization device comprises: receiving first indication information from the first authorization device, the first indication information being used to indicate that the terminal device needs authorization of other authorization devices for communication or being used to indicate that the first authorization device is unable to independently authorize the terminal device for communication; obtaining identification information of the second authorization device according to the first indication information.

22. The method of claim 21, wherein, The method further comprises: requesting identification information of other authorization devices from the terminal device or a data management device according to the first indication information; receiving the identification information of the second authorization device from the terminal device or the data management device.

23. The method of any one of claims 18 to 22, wherein, The method further comprises: if the first authorization information indicates authorization success and the second authorization information indicates authorization success, determining that the terminal device is successfully authorized for communication; or, if the first authorization information indicates authorization failure or the second authorization information indicates authorization failure, determining that the terminal device fails to be authorized for communication.

24. The method of claim 23, wherein, The method further comprises: if the terminal device is successfully authorized for communication, sending information indicating that the terminal device is successfully authorized to a session management network element; and 25. The method of claim 23, wherein, if the terminal device fails to be authorized, sending information indicating that the terminal device fails to be authorized to the session management network element. The method further comprises: if the terminal device is successfully authorized for communication, sending identification information of an authorization device that fails to authorize the terminal device to the terminal device.

26. The method of any one of claims 23-25, wherein, The method further comprises:

27. An authorization method, characterized by a first authorization device receiving a request message from a core network device, the request message being used to request authorization of a terminal device for command and control communication, the request message comprising information of a mobile path of the terminal device; when the mobile path passes through areas corresponding to a plurality of authorization devices, the first authorization device sending authorization information, first indication information or identification information of a second authorization device in the plurality of authorization devices to the core network device; wherein the authorization information is used to indicate a result of the first authorization device authorizing the terminal device for command and control communication, and the first indication information is used to indicate that the terminal device needs authorization of other authorization devices for command and control or to indicate that the first authorization device is unable to independently authorize the terminal device for command and control communication. if the authorization information indicates authorization success, sending the first indication information or the identification information of the second authorization device to the core network device.

28. The method of claim 27, wherein, The communication device comprises a processor and a memory, and the processor is configured to execute a computer program or instructions stored in the memory, so that the communication device implements the method in any one of claims 1 to 12.

29. A communications device, characterized by ​ 30. A communications device, characterized by comprises a processor and a memory, the processor being configured to execute computer programs or instructions stored in the memory, so that the communication device implements the method of any one of claims 13 to 17.

31. A communications device, characterized by comprises a processor and a memory, the processor being configured to execute computer programs or instructions stored in the memory, so that the communication device implements the method of any one of claims 18 to 26.

32. A communications device, characterized by comprises a processor and a memory, the processor being configured to execute computer programs or instructions stored in the memory, so that the communication device implements the method of any one of claims 27 to 28.

33. A computer-readable storage medium, comprising: a computer program or instructions stored in the memory, when the computer program or instructions are executed on a computer, so that the computer implements the method of any one of claims 1 to 12, or so that the computer implements the method of any one of claims 13 to 17, or so that the computer implements the method of any one of claims 18 to 26, or so that the computer implements the method of any one of claims 27 to 28.

34. A computer program product, characterised in that, a computer program or instructions stored in the memory, when the computer program or instructions are executed on a computer, so that the computer implements the method of any one of claims 1 to 12, or so that the computer implements the method of any one of claims 13 to 17, or so that the computer implements the method of any one of claims 18 to 26, or so that the computer implements the method of any one of claims 27 to 28.

Citation Information

Patent Citations

  • Network switching method and device

    CN111182543A