Access control method, communication apparatus, and storage medium
Patent Information
- Application Number
- CN202311371904.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-20
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2043-10-20
AI Technical Summary
[0005]本申请提供一种接入控制方法、通信装置及存储介质,用以解决当终端的归属地是非SA网络,拜访地支持SA网络时,SA/NSA终端尝试注册至拜访地SA网络的过程中存在通信信令冗余,占用过多通信资源,进而对网络指标和性能产生不必要的影响,用户体验不佳的问题
Smart Images

Figure CN117676537B_ABST
Abstract
Description
Technical Field
[0001] This application relates to communication technology, and more particularly to an access control method, a communication device, and a storage medium. Background Technology
[0002] The fifth-generation mobile communication technology (5G) is currently being deployed on a large scale. In the early stages of network construction, the 5G network mainly adopts a dual-mode architecture of standalone (SA) + non-standalone (NSA).
[0003] In roaming scenarios, there may be situations where the visited network has built and activated an SA network, while the home network has not built an SA network or has shut down its SA network. Only when both the home and visited networks have built and activated SA networks can 5G terminals that support both SA and NSA networks (such as mobile phones, tablets, etc., hereinafter referred to as SA / NSA terminals) access the visited SA network and achieve 5G communication. However, if the visited network supports SA networks, even if the home network does not support SA networks, the SA / NSA terminal will still attempt to access the visited SA network, although it will ultimately fail.
[0004] Currently, when a terminal's home network is a non-SA network but the visited network supports an SA network, there is communication signaling redundancy during the process of an SA / NSA terminal attempting to register with the visited SA network. This consumes excessive communication resources, which in turn has an unnecessary impact on network metrics and performance, resulting in a poor user experience. Summary of the Invention
[0005] This application provides an access control method, communication device, and storage medium to solve the problem that when the home network of a terminal is a non-SA network and the visited network supports SA networks, the SA / NSA terminal attempts to register with the visited SA network, resulting in redundant communication signaling, excessive consumption of communication resources, unnecessary impact on network indicators and performance, and poor user experience.
[0006] In a first aspect, this application provides an access control method, which is applied to an access management network element of a visited network, the method comprising:
[0007] The terminal receives a registration request message, which carries the identifier of the terminal's home network; the terminal supports the networking mode of the visited network.
[0008] If the identifier of the home network does not exist in the list of home networks that do not support the networking mode of the visited network, a discovery request message is sent to the network storage element of the gateway office of the visited network. The discovery request message carries the identifier of the home network.
[0009] Receive a discovery response message returned by the network storage element, wherein the discovery response message is used to indicate that the home network does not support the networking mode of the visited network;
[0010] Based on the discovery response message, the home network is added to the list of home networks that do not support the networking mode of the visited network, and a registration rejection message is returned to the terminal.
[0011] Optionally, the method further includes:
[0012] If the identifier of the home network exists in the list of home networks that do not support the networking mode of the visited network, a registration rejection message is returned to the terminal.
[0013] Optionally, the registration rejection message carries indication information, which instructs the terminal to stop initiating a registration request to the visited network.
[0014] Optionally, the method further includes:
[0015] Send a subscription request to the network storage element, the subscription request being used to request subscription to information on changes in the networking mode of the home network to the visited network;
[0016] If a subscription response is received from the network storage element, the home network is removed from the list of home networks that do not support the visited network's networking mode, and the subscription response carries the change information.
[0017] Secondly, this application provides an access control method, which is applied to an access management network element of a visited network, the method comprising:
[0018] The terminal receives a registration request message, which carries the identifier of the terminal's home network; the terminal supports the networking mode of the visited network.
[0019] Send a discovery request message to the network storage element of the visited network, the discovery request message carrying the identifier of the home network;
[0020] Receive a discovery response message returned by the network storage element, wherein the discovery response message is used to indicate that the home network does not support the networking mode of the visited network;
[0021] Based on the discovery response message, a registration rejection message is returned to the terminal; the registration rejection message carries indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network.
[0022] Thirdly, this application provides an access control method, which is applied to a terminal that supports a visited network topology. The method includes:
[0023] Send a registration request message to the access management network element of the visited network, the registration request carrying the identifier of the terminal's home network;
[0024] The terminal receives a registration rejection message returned by the access management network element; the registration rejection message carries indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network.
[0025] Based on the instruction, stop initiating registration requests to the visited network.
[0026] Fourthly, this application provides an access control method, which is applied to a network storage element in a visited network, the method comprising:
[0027] The terminal receives a discovery request message sent by the access management network element of the visited network. The discovery request message is triggered by the access management network element when it receives a registration request message sent by the terminal. The discovery request message carries the identifier of the home network of the terminal carried in the registration request message. The terminal supports the networking mode of the visited network.
[0028] Determine whether the home network supports the networking mode of the visited network;
[0029] If not supported, a discovery response message is returned to the access management network element. The discovery response message is used to indicate that the home network does not support the networking mode of the visited network.
[0030] Optionally, the method further includes:
[0031] The system receives a subscription request from the access management network element, the subscription request being used to request subscription to information on changes in the networking mode of the home network to the visited network.
[0032] When the home network supports the networking mode of the visited network, a subscription response is sent to the access management network element, and the subscription response is used to indicate the change information.
[0033] Fifthly, this application provides an access control device applied to an access management network element of a visited network, the device comprising:
[0034] The first receiving module is used to receive a registration request message sent by the terminal, wherein the registration request message carries the identifier of the terminal's home network; and the terminal supports the networking mode of the visited network.
[0035] The sending module is configured to send a discovery request message to the network storage element of the gateway office of the visited network if the identifier of the home network does not exist in the list of home networks that do not support the networking mode of the visited network. The discovery request message carries the identifier of the home network.
[0036] The second receiving module is used to receive a discovery response message returned by the network storage element, wherein the discovery response message is used to indicate that the home network does not support the networking mode of the visited network;
[0037] The addition module is used to add the home network to the list of home networks that do not support the networking mode of the visited network, based on the discovery response message, and return a registration rejection message to the terminal.
[0038] Sixthly, this application provides an access control device, which is applied to an access management network element of a visited network, the method comprising:
[0039] The first receiving module is used to receive a registration request message sent by the terminal, wherein the registration request message carries the identifier of the terminal's home network; and the terminal supports the networking mode of the visited network.
[0040] The sending module is used to send a discovery request message to the network storage element of the visited network, the discovery request message carrying the identifier of the home network;
[0041] The second receiving module is used to receive a discovery response message returned by the network storage element, wherein the discovery response message is used to indicate that the home network does not support the networking mode of the visited network;
[0042] The return module is used to return a registration rejection message to the terminal based on the discovery response message; the registration rejection message carries indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network.
[0043] Seventhly, this application provides an access control device, which is applied to a terminal that supports a visited network topology. The device includes:
[0044] The sending module is used to send a registration request message to the access management network element of the visited network, wherein the registration request carries the identifier of the home network of the terminal;
[0045] The receiving module is used to receive a registration rejection message returned by the access management network element; the registration rejection message carries indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network;
[0046] The initiating module is used to stop initiating registration requests to the visited network based on the indicated information.
[0047] Eighthly, this application provides an access control device applied to a network storage element of a visited network, the device comprising:
[0048] The receiving module is used to receive a discovery request message sent by the access management network element of the visited network. The discovery request message is triggered by the access management network element when it receives a registration request message sent by the terminal. The discovery request message carries the identifier of the home network of the terminal carried in the registration request message. The terminal supports the networking mode of the visited network.
[0049] The determination module is used to determine whether the home network supports the networking mode of the visited network;
[0050] The return module is used to return a discovery response message to the access management network element if the network is not supported. The discovery response message is used to indicate that the home network does not support the networking mode of the visited network.
[0051] Ninthly, this application provides a communication device, the communication device comprising:
[0052] A processor, and a memory and a communication interface communicatively connected to the processor;
[0053] The memory stores computer-executed instructions;
[0054] The processor executes computer execution instructions stored in the memory to implement the method as described in any one of the first, second, third, or fourth aspects.
[0055] In a tenth aspect, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the access control method as described in any one of the first, second, third, or fourth aspects.
[0056] In one aspect, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method as described in any one of the first, second, third, or fourth aspects.
[0057] The access control method, communication device, and storage medium provided in this application firstly involve the terminal sending a registration request message to the visited access management network element. Then, the access management network element determines whether the identifier of the home network exists in the list of home networks that do not support the visited network's networking mode. If not, the access management network element sends a discovery request message to the network storage network element at the visited network's roaming gateway. Subsequently, the network storage network element determines whether the home network supports the visited network's networking mode. If not, the network storage network element returns a discovery response message to the access management network element. Finally, based on the discovery response message, the access management network element adds the home network to the list of home networks that do not support the visited network's networking mode and returns a registration rejection message to the terminal.
[0058] Because the visited access management network element stores a list of home networks that do not support the visited network's networking mode, when a terminal attempts to register to the visited network, the access management network element can directly determine whether the terminal is eligible to register to the visited network based on this list, i.e., whether the terminal's home location supports the target network. If the terminal's home location is listed in the category of home networks that do not support the visited network's networking mode, a registration rejection message can be directly sent to the terminal without requiring communication signaling transmission between the visited access management network element and the visited roaming gateway. In other words, this method reduces unnecessary communication signaling transmission when the terminal's home location does not support the visited network, thereby reducing the consumption of communication resources, minimizing the impact on communication indicators and performance, and ultimately improving the user experience.
[0059] Furthermore, since the above method does not configure the visited access management network element manually, but instead automatically configures its own home network list that does not support the visited network based on the discovery response message sent by the visited roaming gateway, this method avoids the waste of human resources caused by manually configuring the visited access management network element, and is simple and quick to operate. Attached Figure Description
[0060] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0061] Figure 1This is a network architecture diagram related to an embodiment of this application;
[0062] Figure 2 A flowchart illustrating an access control method provided by existing technology;
[0063] Figure 3 A flowchart illustrating the first access control method provided in this application;
[0064] Figure 4 A flowchart illustrating the second access control method provided in this application;
[0065] Figure 5 A flowchart illustrating the third access control method provided in this application;
[0066] Figure 6 This is a schematic diagram of the structure of the first type of access control device provided in this application;
[0067] Figure 7 This is a schematic diagram of the structure of the second type of access control device provided in this application;
[0068] Figure 8 This is a schematic diagram of the structure of the third type of access control device provided in this application;
[0069] Figure 9 This is a schematic diagram of the structure of the fourth type of access control device provided in this application;
[0070] Figure 10 This is a schematic diagram of the structure of a communication device 100 provided in this application.
[0071] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0072] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0073] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0074] First, let me explain the terms used in this application:
[0075] Roaming refers to the ability of a terminal to continue providing service to another user even after it leaves its registered service area (home region) and moves to a different service area (visited region). Currently, roaming is only possible between regions with compatible network standards and existing internet connections, or between regions that have signed bilateral roaming agreements. User roaming involves two concepts: roaming in and roaming out, which are corresponding concepts. Roaming in refers to a terminal from another region roaming into this region, while roaming out refers to a number from this region roaming to another region.
[0076] Gateway exchange: Generally known as a Gateway Mobile Switching Center (GMSC), it primarily performs tandem switching functions. For example, it is used for relay interconnection between different communication networks, such as for telecom operators. The gateway exchange is the point of entry and exit from the network. In roaming scenarios, the terminal accesses the visited network through the roaming gateway exchange.
[0077] Figure 1 This is a network architecture diagram related to an embodiment of this application. For example, such as... Figure 1 As shown, the 5G network architecture released by the 3rd Generation Partnership Project (3GPP) standards group includes: access network equipment, access and mobility management function (AMF) network elements, session management function (SMF) network elements, unified data management (UDM) network elements, authentication server function (AUSF) network elements, and network repository function (NRF) network elements.
[0078] Those skilled in the art will understand that Figure 1The network architecture shown is not intended to limit the network architecture. In actual implementation, the network architecture may include more or fewer network elements than shown, or combine certain network elements, etc. Furthermore, it should be understood that... Figure 1 The network architecture diagram shown can be a network architecture diagram of any communication standard, such as a 5G network architecture diagram, or a schematic diagram of the network architecture of a future communication standard.
[0079] In the above network architecture, access network equipment refers to equipment on the access network side, while AMF, SMF, UDM, AUSF, and NRF network elements are network elements on the core network side (referred to as core network elements).
[0080] The AMF (Automatic Facilitation Module) network element manages whether terminal devices can access the core network. The SMF (Supply-Side Module) network element manages session connections established by terminal devices through the core network; each session connection transmits user plane data of the terminal device. The UDM (User Dedicated Module) network element stores the terminal's subscription data. The AUSF (Automatic User Dedicated Module) network element receives requests from the AMF network element to authenticate the UE, requests a key from the UDM, and then forwards the key issued by the UDM to the AMF for authentication processing. The NRF (Network RF) network element performs network element registration, management, and status detection, achieving automated management of all network elements. The technical solutions provided in this application can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, 5th Generation (5G) mobile communication systems, Wireless-Fidelity (WiFi) systems, Frequency Division Duplex (FDD) systems, future communication systems, or systems integrating multiple communication systems, etc., and this application does not limit the scope. 5G can also be referred to as New Radio (NR).
[0081] The technical solutions provided in this application can be applied to various communication scenarios, such as one or more of the following: enhanced mobile broadband (eMBB) communication, ultra-reliable and low latency communication (URLLC), machine-type communication (MTC), mMTC, device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, vehicle-to-vehicle (V2V) communication, and the Internet of Things (IoT). Optionally, mMTC may include one or more of the following communications: communication in industrial wireless sensor networks (IWSN), communication in video surveillance scenarios, and communication in wearable devices.
[0082] The terminal in the embodiments of this application may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal equipment, wireless communication equipment, user agent, or user device. The terminal in the embodiments of this application may be a mobile phone, tablet computer, computer with wireless transceiver capabilities, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal in industrial control, wireless terminal in autonomous driving, wireless terminal in telemedicine, wireless terminal in smart grids, wireless terminal in transportation safety, wireless terminal in smart cities, wireless terminal in smart homes, cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication capabilities, computing device, vehicle-mounted device, wearable device, terminal device in a 5G network, or terminal device in a future evolved public land mobile network (PLMN), etc. It should be understood that this application does not limit the specific form of the terminal.
[0083] The network device in this application embodiment can be a device with wireless transceiver capabilities in the access network. This device includes, but is not limited to: base stations, evolved node Bs (eNBs), radio network controllers (RNCs), node Bs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved node Bs, or home node Bs (HNBs), baseband units (BBUs), access points (APs), wireless relay nodes, wireless backhaul nodes, transmission points (TPs), or transmission and reception points (TRPs) in a wireless fidelity (WIFI) system. This device can also be a network node constituting a next-generation base station (gNB) or a transmission point, such as a baseband unit (BBU) or a distributed unit (DU).
[0084] Currently, there are two networking methods for 5G networks: SA (Standalone) and NSA (Non-Standalone). NSA refers to deploying 5G networks on top of 4G infrastructure, with 4G and 5G base stations coexisting. Non-Standalone networking still uses the 4G core network, only adding 5G base stations to allow 5G end users to enjoy broadband capabilities. SA refers to building a network by constructing independent 5G base stations, requiring a completely new 5G core network (i.e., the 5G network architecture released by the 3GPP standards group) to be operational.
[0085] During the advancement of 5G technology, some regions have built and activated SA networks, while others have not, for example, only NSA networks or 4G networks. In roaming scenarios, only if the terminal is an SA / NSA terminal, and both the terminal's home and visited locations have built and activated SA networks, can the terminal access the SA network in the visited location and achieve 5G communication.
[0086] When an SA / NSA terminal whose home network is not an SA network attempts to access a visited network, it will prioritize registering with the visited SA network if the visited network supports SA networks. Figure 2 A flowchart illustrating an access control method provided for existing technologies, such as... Figure 2 As shown, when an SA / NSA terminal attempts to access the visited SA network, it first sends a registration request message to the visited AMF network element via the 5G base station. The visited AMF network element then sends a discovery request message to the NRF network element at the visited roaming gateway to request the discovery of the AUSF network element used for authenticating the terminal's registration permissions. Subsequently, the NRF network element at the visited roaming gateway performs a Public Land Mobile Network (PLMN) discovery process to attempt to discover the aforementioned AUSF network element.
[0087] Since the SA / NSA terminal's home location does not support SA networks, the NRF network element at the visited gateway is not configured with the home NRF network element address. This means it cannot discover the AUSF network element used for authenticating terminal registration permissions through the home NRF network element. In this case, the NRF network element at the visited gateway sends a discovery request response to the visited AMF network element, indicating an empty discovery result, meaning the AUSF network element cannot be discovered. Upon receiving the discovery request response, the visited AMF network element sends a registration rejection message to the SA / NSA terminal via the 5G base station to reject the terminal's registration request. Subsequently, if the visited location supports other networks, the terminal will attempt to access other networks, such as a 4G network.
[0088] However, because the visited location supports SA networks, the SA / NSA terminal can always search for the visited SA network signal. Even if access has been denied, the terminal will repeatedly attempt to access the visited SA network after a period of time, and registration will still fail. This repeated registration attempt process creates redundancy in communication signaling, unnecessarily impacting network metrics and communication performance, and also affecting user experience.
[0089] In existing technologies, access can be denied to specific home network terminals by configuring the visited AMF network element. Specifically, if a home terminal supporting SA networks sends a registration request message to the visited AMF network element, the visited AMF network element can terminate the registration request of the roaming terminal. However, the existing configuration method requires manual configuration of global AMF network elements, which is cumbersome.
[0090] The inventors considered that if the number of communication signaling messages during the repeated registration process of the terminal could be reduced, or if the repeated registration of the terminal could be avoided, the impact on network indicators and communication performance could be reduced, thereby improving the user experience.
[0091] In view of this, this application provides an access control method. This method, when the terminal's home location does not support an SA network but the visited location does, controls the process of the terminal registering with the visited SA network at the AMF network element in the visited location, and / or at the terminal itself. This reduces communication signaling during repeated terminal registration processes, or avoids repeated registration processes altogether. This approach reduces the amount of redundant communication signaling, thereby minimizing the impact on communication metrics and performance, and improving the user's communication experience.
[0092] The technical solution of this application and how it solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings. It should be understood that the access control method provided by this application can be applied to access control of SA networks, and can also be applied to access control of any other network, such as future networks.
[0093] Figure 3 A flowchart illustrating the first access control method provided in this application is shown below. Figure 3 As shown, the method may include the following steps:
[0094] S101. The terminal sends a registration request message to the access management network element of the visited location.
[0095] The terminal here can be any SA / NSA terminal. The aforementioned terminal supports the network topology of the visited network. The visited network refers to the network the terminal is currently registering with; the visited network can be, for example, a network that... Figure 1 The network setup shown is an SA network. This application does not limit whether the visited location has other networks. For example, if the visited location network is an SA network, then the visited location may also support 5G NSA and / or 4G networks. The aforementioned registration request message carries the identifier of the terminal's home network. The identifier of the home network mentioned here is the Public Land Mobile Network (PLMN) identifier.
[0096] The type of the access management network element mentioned above is related to the visited network. For example, if the visited network is an SA network, the access management network element may be an AMF network element.
[0097] In this step, the terminal sends a registration request message to the visited access management network element to register with the visited network, so that the terminal can communicate through the visited network in the future. For example, the terminal first sends a registration request message to the visited base station, such as a gNB, and then the visited base station forwards the registration request message to the visited access management network element.
[0098] Correspondingly, the visited access management network element receives the registration request message sent by the terminal.
[0099] S102. The access management network element determines whether the identifier of the home network exists in the list of home networks for networking modes that do not support visited networks.
[0100] The access management network element stores a list of home networks that do not support the visited network topology. This list records the home network identifiers for the network topology that does not support the visited network topology. In this step, the access management network element determines whether the identifier of the home network exists in the list of home networks that do not support the visited network topology, and then determines whether the terminal has permission to register to the visited network.
[0101] If the identifier of the home network does not exist in the list of home networks that do not support the networking mode of the visited network, it indicates that the terminal of the home network may be trying to access the visited network for the first time, or the home network supports the networking mode of the visited network. Therefore, further judgment is required, and step S103 is executed.
[0102] Optionally, if the identifier of the home network exists in the list of home networks that do not support the visited network, it indicates that the terminal does not have permission to register to the visited network for communication, then step S107 is executed.
[0103] S103. The access management network element sends a discovery request message to the network storage network element of the visited network roaming into the gateway office. The discovery request message carries the identifier of the home network.
[0104] The type of the aforementioned network storage element is related to the visited network. For example, if the visited network is an SA network, the network storage element could be an NRF element. In this step, the access management network element sends a discovery request message to the network storage element at the roaming gateway office of the visited network to request the discovery of a network element used for registration authorization authentication. This is specifically related to the visited network; if the visited network is an SA network, the network element could be an AUSF element.
[0105] Correspondingly, the network storage element of the visited network roams into the gateway office and receives the discovery request message sent by the access management element of the visited network.
[0106] S104. The network storage element determines whether the home network supports the networking mode of the visited network.
[0107] In this step, the network storage element determines whether the home network supports the networking mode of the visited network, and then determines whether the terminal has permission to register to the visited network.
[0108] For example, a network storage element can check whether it is configured with the address of the network storage element of the terminal's home network. If it is configured, it indicates that the terminal's home network supports the visited network topology; if it is not configured, it indicates that the terminal's home network does not support the visited network topology.
[0109] If not supported, it indicates that the terminal does not have permission to register to the visited network, and then proceed to step S105.
[0110] S105. The network storage element returns a discovery response message to the access management element.
[0111] The aforementioned discovery response message is used to indicate that the home network does not support the networking mode of the visited network.
[0112] For example, the discovery response message may include an error code and a home network identifier. This application does not limit the representation of the error code. The error code and home network identifier in the discovery response message indicate that the home network does not support the networking method of the visited network.
[0113] Correspondingly, the access management network element receives the discovery response message returned by the network storage network element.
[0114] S106. Based on the discovery response message, the access management network element adds the home network to the list of home networks for networking modes that do not support visited networks.
[0115] In this step, the access management network element adds the home network to the list of home networks that do not support visited networks based on the discovery response message. Subsequently, if the terminal, or another terminal whose home network is the same as the terminal's home network, attempts to register to the visited network, the access management network element can directly return a registration rejection message to the attempting terminal based on the list of home networks that do not support visited networks. This eliminates the need to send a discovery request message to the network storage network element at the visited network's roaming gateway to authenticate whether the terminal in the home network has permission to access the visited network. This method saves unnecessary communication signaling, reduces the consumption of communication resources by unnecessary signaling, and thus improves network communication performance and user communication experience.
[0116] S107. The access management network element returns a registration rejection message to the terminal.
[0117] In this step, the access management network element returns a registration rejection message to the terminal, informing the terminal that it does not have permission to register to the visited network. Optionally, if the visited network also supports other communication networks besides the target network, the terminal can try to register to other communication networks, such as a 4G network.
[0118] It should be understood that this application does not limit the order in which steps S106 and S107 are executed, and they can also be executed in parallel.
[0119] Correspondingly, the terminal receives a registration rejection message returned by the access management network element.
[0120] In this embodiment, firstly, the terminal sends a registration request message to the visited access management network element; then, the access management network element determines whether the identifier of the home network exists in the list of home networks that do not support the networking mode of the visited network; if not, the access management network element sends a discovery request message to the network storage network element of the visited network roaming gateway office; subsequently, the network storage network element determines whether the home network supports the networking mode of the visited network; if not, the network storage network element returns a discovery response message to the access management network element; subsequently, the access management network element adds the home network to the list of home networks that do not support the networking mode of the visited network according to the discovery response message, and returns a registration rejection message to the terminal.
[0121] Because the visited access management network element stores a list of home networks that do not support the visited network's networking mode, when a terminal attempts to register to the visited network, the access management network element can directly determine whether the terminal is qualified to register to the visited network based on this list, i.e., whether the terminal's home network supports the target network. If the terminal's home network exists in the category of home networks that do not support the visited network's networking mode, a registration rejection message can be directly sent to the terminal without needing to perform communication signaling transmission between the visited access management network element and the visited roaming gateway. In other words, this method reduces unnecessary communication signaling transmission when the terminal's home network does not support the visited network, thereby reducing the consumption of communication resources, minimizing the impact on communication indicators and performance, and ultimately improving the user experience. When the access control method provided in this application is applied to roaming scenarios where the terminal's home network does not support SA networks, but the visited network does, redundancy in communication signaling caused by the terminal repeatedly attempting to access the visited SA network can be avoided, thus improving performance.
[0122] Furthermore, since the above method does not configure the visited access management network element manually, but instead automatically configures its own home network list that does not support the visited network based on the discovery response message sent by the visited roaming gateway, this method avoids the waste of human resources caused by manually configuring the visited access management network element, and is simple and quick to operate.
[0123] Optionally, in the above embodiments, the registration rejection message may also carry indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network.
[0124] Since the terminal's home network does not support the visited network, subsequent attempts to register with the visited network will fail. Therefore, if the registration rejection message also carries indication information, the terminal can be prevented from initiating further registration requests to the visited network. This further reduces unnecessary communication signaling transmission between the terminal and the visited access management network element, minimizing unnecessary communication resource consumption and thus improving network communication performance and user communication experience.
[0125] Optionally, the access management network element can also automatically update the list of home networks for networking methods that do not support visited networks, based on the terminal's home network situation. Specifically, Figure 4 A flowchart illustrating the second access control method provided in this application is shown below. Figure 4 As shown, the method may include the following steps:
[0126] S201. The access management network element sends a subscription request to the network storage network element.
[0127] This subscription request is used to request information on changes in the networking mode of the home network that supports the visited network.
[0128] In this step, the access management network element sends a subscription request to the network storage network element so that if the terminal's home network supports the visited network topology, the access management network element can be promptly informed of the change.
[0129] Correspondingly, the network storage element receives the subscription request message sent by the access management element.
[0130] The subscription response carries the aforementioned change information. That is, if the networking mode of the home network configured by the network storage network element changes, the network storage network element will automatically send a subscription response to the access management network element to inform it of the change information.
[0131] Correspondingly, the access management network element receives the subscription response returned by the network storage network element.
[0132] S203. The access management network element removes the home network from the list of home networks in networking modes that do not support visited networks.
[0133] In this step, since the access management network element receives the subscription response returned by the network storage network element, it can find the home network identifier corresponding to the subscription response from the list of home networks for networking modes that do not support visited networks, and then delete the home network from the list. Subsequently, if a terminal of the home network attempts to access the visited network, since the home network is not included in the list of home networks for networking modes that do not support visited networks, the access management network element will send a discovery request message to the network storage network element to enable subsequent registration requests for terminals of the home network.
[0134] In this embodiment, the access management network element sends a subscription request to the network storage network element to subscribe to information regarding changes in the networking mode of the home network that supports the visited network. Subsequently, if the networking mode of the home network configured by the network storage network element changes, the network storage network element sends a subscription response to the access management network element, instructing the access management network element to remove the home network from the list of home networks that do not support the visited network's networking mode. This method enables automatic updates to the list of home networks whose networking modes are not supported by the visited network, simplifying the operation and further improving the usability of the access control method provided in this application.
[0135] Besides reducing unnecessary signaling transmissions when a terminal whose home network does not support the visited network attempts to access the visited network, control can also be implemented solely from the terminal side to reduce these unnecessary signaling transmissions. Specific embodiments are described below. Contents identical or similar to those described above can be referred to the above embodiments and will not be repeated here.
[0136] Figure 5 A flowchart illustrating the third access control method provided in this application is shown below. Figure 5 As shown, the method includes the following steps:
[0137] S301. The terminal sends a registration request message to the access management network element of the visited network.
[0138] The registration request message carries the identifier of the terminal's home network. The aforementioned terminal supports the visited network topology.
[0139] Correspondingly, the access management network element receives the registration request message sent by the terminal.
[0140] S302. The access management network element sends a discovery request message to the network storage network element of the visited network. The discovery request message carries the identifier of the home network.
[0141] In this step, the access management network element directly sends a discovery request message to the network storage network element of the visited network to request the discovery of a network element used to determine whether the terminal has the permission to register with the visited network.
[0142] Correspondingly, the network storage element receives the discovery request message sent by the access management element.
[0143] S303. The network storage element determines whether the home network supports the networking mode of the visited network.
[0144] If not supported, it indicates that the terminal does not have permission to register to the visited network, and then proceed to step S204.
[0145] S304. The network storage element returns a discovery response message to the access management element.
[0146] The discovery response message is used to indicate that the home network does not support the networking mode of the visited network.
[0147] Correspondingly, the access management network element receives the discovery response message returned by the network storage network element.
[0148] S305. The access management network element returns a registration rejection message to the terminal based on the discovery response message.
[0149] The registration rejection message carries an instruction that instructs the terminal to stop initiating a registration request to the visited network.
[0150] Correspondingly, the terminal receives a registration rejection message returned by the access management network element.
[0151] S306. The terminal stops initiating registration requests to the visited network according to the instruction information.
[0152] In this step, since the terminal has obtained the instruction information, the terminal will no longer send registration request messages to the access management network element, that is, it will stop initiating registration requests to the visited network.
[0153] In this embodiment, firstly, the terminal sends a registration request message to the access management network element of the visited network; then, the access management network element sends a discovery request message to the network storage network element of the visited network; subsequently, the network storage network element returns a discovery response message to the access management network element. Based on the discovery response message, the access management network element returns a registration rejection message to the terminal; then, the terminal, according to the indication information, stops initiating registration requests to the visited network. In this way, after any terminal whose home network does not support the visited network fails to register to the visited network, that terminal and any other terminal in that home network will not attempt to register to the visited network again. In other words, this method reduces unnecessary communication signaling transmission between the terminal and the network storage network element of the visited network's gateway when the terminal's home network does not support the visited network, thereby reducing the consumption of communication resources, minimizing the impact on communication indicators and performance, and improving the user experience.
[0154] Figure 6 A schematic diagram of the structure of the first access control device provided in this application is shown below. Figure 6 As shown, the device is applied to the access management network element of the visited network. The device includes: a first acquisition module 11, a sending module 12, a second receiving module 13, and an adding module 14.
[0155] The first receiving module 11 is used to receive a registration request message sent by the terminal, wherein the registration request message carries the identifier of the terminal's home network; and the terminal supports the networking mode of the visited network.
[0156] The sending module 12 is used to send a discovery request message to the network storage element of the gateway office of the visited network if the identifier of the home network does not exist in the list of home networks that do not support the networking mode of the visited network. The discovery request message carries the identifier of the home network.
[0157] The second receiving module 13 is used to receive a discovery response message returned by the network storage element, wherein the discovery response message is used to indicate that the home network does not support the networking mode of the visited network.
[0158] The addition module 14 is used to add the home network to the list of home networks that do not support the networking mode of the visited network according to the discovery response message, and return a registration rejection message to the terminal.
[0159] Optionally, the sending module 12 is further configured to return a registration rejection message to the terminal if the identifier of the home network exists in the list of home networks that do not support the networking mode of the visited network.
[0160] Optionally, the registration rejection message carries indication information, which instructs the terminal to stop initiating a registration request to the visited network.
[0161] Optionally, the sending module 12 is further configured to send a subscription request to the network storage element, the subscription request being used to request subscription to the change information of the home network supporting the networking mode of the visited network; if a subscription response is received from the network storage element, the home network is deleted from the list of home networks that do not support the networking mode of the visited network, and the subscription response carries the change information.
[0162] The access control device provided in this embodiment can execute the access control method executed by the access management network element in the above method embodiments. Its implementation principle and technical effects are similar, and will not be repeated here. It should be noted that the above... Figure 6 The division of modules shown is merely illustrative. This application does not limit the division of modules or the naming of modules.
[0163] Figure 7 This is a schematic diagram of the structure of a second access control device provided in this application. The device is applied to the access management network element of the visited network and includes: a receiving module 21, a sending module 22, a second receiving module 23, and a return module 24.
[0164] The receiving module 21 is used to receive a registration request message sent by the terminal, wherein the registration request message carries the identifier of the terminal's home network; and the terminal supports the networking mode of the visited network.
[0165] The sending module 22 is used to send a discovery request message to the network storage element of the visited network, the discovery request message carrying the identifier of the home network.
[0166] The second receiving module 23 is used to receive a discovery response message returned by the network storage element, wherein the discovery response message is used to indicate that the home network does not support the networking mode of the visited network.
[0167] Return module 24 is used to return a registration rejection message to the terminal based on the discovery response message; the registration rejection message carries indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network.
[0168] The access control device provided in this embodiment can execute the access control method executed by the access management network element in the above method embodiments. Its implementation principle and technical effects are similar, and will not be repeated here. It should be noted that the above... Figure 7The division of modules shown is merely illustrative. This application does not limit the division of modules or the naming of modules.
[0169] Figure 8 This is a schematic diagram of the structure of a third access control device provided in this application. The device is applied to a terminal, which supports a visited network topology. The device includes: a sending module 31, a receiving module 32, and an initiating module 33.
[0170] The sending module 31 is used to send a registration request message to the access management network element of the visited network, wherein the registration request carries the identifier of the home network of the terminal.
[0171] The receiving module 32 is used to receive a registration rejection message returned by the access management network element; the registration rejection message carries indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network.
[0172] The initiating module 33 is used to stop initiating a registration request to the visited network based on the instruction information.
[0173] The access control device provided in this embodiment can execute the access control method executed by the terminal in the above method embodiments. Its implementation principle and technical effects are similar, and will not be repeated here. It should be noted that the above... Figure 8 The division of modules shown is merely illustrative. This application does not limit the division of modules or the naming of modules.
[0174] Figure 9 This is a schematic diagram of the fourth access control device provided in this application. The device is applied to a network storage element in a visited network and includes: a receiving module 41, a determining module 42, and a returning module 43. Optionally, the device may also include a subscription module 44.
[0175] The receiving module 41 is used to receive a discovery request message sent by the access management network element of the visited network. The discovery request message is triggered by the access management network element when it receives a registration request message sent by the terminal. The discovery request message carries the identifier of the home network of the terminal carried in the registration request message. The terminal supports the networking mode of the visited network.
[0176] The determination module 42 is used to determine whether the home network supports the networking mode of the visited network.
[0177] The return module 43 is used to return a discovery response message to the access management network element if it is not supported. The discovery response message is used to indicate that the home network does not support the networking mode of the visited network.
[0178] Optionally, the subscription module 44 is configured to receive a subscription request sent by the access management network element, the subscription request being used to request subscription to information on changes in the networking mode of the home network supporting the visited network; when the home network supports the networking mode of the visited network, the subscription module 44 sends a subscription response to the access management network element, the subscription response being used to indicate the changes.
[0179] The access control device provided in this embodiment can execute the access control method executed by the network storage network element in the above method embodiment. Its implementation principle and technical effects are similar, and will not be repeated here. It should be noted that the above... Figure 9 The division of modules shown is merely illustrative. This application does not limit the division of modules or the naming of modules.
[0180] Figure 10 This is a schematic diagram of the structure of a communication device 100 provided in this application. Figure 10 As shown, the communication device may include at least one processor 101, a memory 102, and a communication interface 103.
[0181] The memory 102 is used to store programs. Specifically, the program may include program code, which includes computer operation instructions.
[0182] The memory 102 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.
[0183] The processor 101 is used to execute computer execution instructions stored in the memory 102 to implement the access control method described in the foregoing method embodiments. The processor 101 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application.
[0184] The communication device 100 can also communicate and interact with external devices through the communication interface 103. These external devices can be, for example, terminal devices (e.g., mobile phones, tablets). In specific implementations, if the communication interface 103, memory 102, and processor 101 are implemented independently, they can be interconnected via a bus to complete communication. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc., but this does not imply that there is only one bus or one type of bus.
[0185] Optionally, in a specific implementation, if the communication interface 103, memory 102 and processor 101 are integrated on a single chip, then the communication interface 103, memory 102 and processor 101 can communicate through an internal interface.
[0186] This application also provides a computer-readable storage medium, which may include various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk. Specifically, the computer-readable storage medium stores program instructions, which are used in the access control method described in the above embodiments.
[0187] This application also provides a computer program product including executable instructions stored in a readable storage medium. At least one processor of an electronic device can read the executable instructions from the readable storage medium, and the processor executes the executable instructions to cause the electronic device to implement the access control methods provided in the various embodiments described above.
[0188] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0189] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. An access control method, characterized in that, The method is applied to the access management network element of the visited network, and the method includes: The terminal receives a registration request message, which carries the identifier of the terminal's home network; the terminal supports the networking mode of the visited network. If the identifier of the home network does not exist in the list of home networks that do not support the networking mode of the visited network, a discovery request message is sent to the network storage element of the gateway office of the visited network. The discovery request message carries the identifier of the home network. Receive a discovery response message returned by the network storage element, wherein the discovery response message is used to indicate that the home network does not support the networking mode of the visited network; Based on the discovery response message, the home network is added to the list of home networks that do not support the networking mode of the visited network, and a registration rejection message is returned to the terminal.
2. The method according to claim 1, characterized in that, The method further includes: If the identifier of the home network exists in the list of home networks that do not support the networking mode of the visited network, a registration rejection message is returned to the terminal.
3. The method according to claim 1 or 2, characterized in that, The registration rejection message carries an instruction message, which instructs the terminal to stop initiating a registration request to the visited network.
4. The method according to claim 1 or 2, characterized in that, The method further includes: Send a subscription request to the network storage element, the subscription request being used to request subscription to information on changes in the networking mode of the home network to the visited network; If a subscription response is received from the network storage element, the home network is removed from the list of home networks that do not support the visited network's networking mode, and the subscription response carries the change information.
5. An access control method, characterized in that, The method is applied to the access management network element of the visited network, and the method includes: The terminal receives a registration request message, which carries the identifier of the terminal's home network; the terminal supports the networking mode of the visited network. Send a discovery request message to the network storage element of the visited network, the discovery request message carrying the identifier of the home network; Receive a discovery response message returned by the network storage element, wherein the discovery response message is used to indicate that the home network does not support the networking mode of the visited network; Based on the discovery response message, a registration rejection message is returned to the terminal; the registration rejection message carries indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network.
6. An access control method, characterized in that, The method is applied to a terminal that supports a visited network topology, and the method includes: Send a registration request message to the access management network element of the visited network, the registration request carrying the identifier of the terminal's home network; The terminal receives a registration rejection message returned by the access management network element; the registration rejection message carries indication information, which is used to instruct the terminal to stop initiating a registration request to the visited network; the registration rejection message is received when the home network does not support the networking mode of the visited network; Based on the instruction, stop initiating registration requests to the visited network.
7. An access control method, characterized in that, The method is applied to a network storage element in a visited network, and the method includes: The terminal receives a discovery request message sent by the access management network element of the visited network. The discovery request message is triggered by the access management network element when it receives a registration request message sent by the terminal. The discovery request message carries the identifier of the home network of the terminal carried in the registration request message. The terminal supports the networking mode of the visited network. Determine whether the home network supports the networking mode of the visited network; If not supported, a discovery response message is returned to the access management network element. The discovery response message is used to indicate that the home network does not support the networking mode of the visited network.
8. The method according to claim 7, characterized in that, The method further includes: The system receives a subscription request from the access management network element, the subscription request being used to request subscription to information on changes in the networking mode of the home network to the visited network. When the home network supports the networking mode of the visited network, a subscription response is sent to the access management network element, and the subscription response is used to indicate the change information.
9. A communication device, characterized in that, The communication device includes: A processor, and a memory and a communication interface communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the access control method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Discovery request processing method, device and system
CN115484669A
Radio-access-technology-specific access restrictions
US20220194493A1