Communication method, electronic equipment and storage medium
By obtaining the target attribute information of the pending terminal and associating its network contract group, the problem that the management equipment cannot accurately identify and control industrial equipment is solved, effective access control and data interaction are achieved, and the management efficiency of the management equipment is improved.
Patent Information
- Application Number
- CN202311598085.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
In the industrial Internet, management equipment cannot accurately confirm whether each industrial equipment falls within its jurisdiction, resulting in the inability to effectively conduct access control, affecting the efficiency of data interaction.
The target attribute information of the pending terminal is obtained based on the network contract group, including the network identifier. The network contract group includes multiple terminals that are contracted with the core network equipment, belong to the same area, and use the same data network resources. Based on this information, the pending terminal is associated with the core network group and the local area network, and communicates through the access control interface.
Accurate distinction and identification of the terminal to be processed is realized, allowing the management equipment to effectively control access, and improving the management efficiency of the management equipment for the terminal and the accuracy of data interaction.
Smart Images

Figure CN120050685A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and particularly to a communication method, an electronic device, and a storage medium. Background Art
[0002] With the application and development of the 5th Generation Mobile Communication Technology (5G) in various industries, service data in different industries will be accessed to the 5G communication network through 5G terminals. For example, industrial devices with 5G communication capabilities transmit the industrial data they collect to the 5G communication network, so as to transmit the industrial data to a remote management device through the 5G communication network.
[0003] However, in the industrial Internet, there are multiple local area networks with different usage functions, and each local area network includes multiple industrial devices. When each industrial device in different local area networks sends the industrial data it collects to a remote management device through the 5G network, the management device cannot confirm whether each industrial device is a device under its jurisdiction, and thus cannot accurately perform access control on each industrial device that expects to access. Summary of the Invention
[0004] This application provides a communication method, an electronic device, and a storage medium.
[0005] An embodiment of this application provides a communication method, which is applied to a management device and includes: obtaining target attribute information of a to-be-processed terminal based on a network subscription group, where the target attribute information of the to-be-processed terminal includes a network identifier to which the to-be-processed terminal belongs, and the network subscription group includes multiple terminals that are subscribed with a core network device, belong to the same slice area, and use the same data network resources; associating a core network group corresponding to the to-be-processed terminal with a local area network based on the network identifier to which the to-be-processed terminal belongs; and performing communication management on the to-be-processed terminal based on an access control interface corresponding to the to-be-processed terminal.
[0006] An embodiment of this application provides a communication method, which is applied to a core network device and includes: responding to a session establishment request sent by a to-be-processed terminal, subscribing with the to-be-processed terminal, and determining target attribute information of the to-be-processed terminal, where the target attribute information of the to-be-processed terminal includes a network identifier to which the to-be-processed terminal belongs; and sending the target attribute information of the to-be-processed terminal to a management device.
[0007] An embodiment of this application provides an electronic device, including: one or more processors; a memory, on which one or more programs are stored, and when the one or more programs are executed by the one or more processors, the one or more processors implement any one of the communication methods in the embodiments of this application.
[0008] An embodiment of the present application provides a readable storage medium storing a computer program, which when executed by a processor implements any one of the communication methods in the embodiments of the present application.
[0009] According to the communication method, electronic device, and storage medium of the embodiments of the present application, by obtaining the target attribute information of the terminal to be processed based on the network subscription group, the target attribute information of the terminal to be processed includes the network identifier to which the terminal to be processed belongs, and the network subscription group includes multiple terminals that are subscribed to the core network device, belong to the same slice area, and use the same data network resources, and can accurately distinguish the terminal to be processed based on the network identifier to which the terminal to be processed belongs; associating the core network group corresponding to the terminal to be processed with the local area network based on the network identifier to which the terminal to be processed belongs, so that the management device in the local area network can identify the terminal to be processed; performing communication management on the terminal to be processed based on the access control interface corresponding to the terminal to be processed, enabling the management device to perform access control on the terminal to be processed that expects to access, and enabling each terminal to be processed to timely interact communication data with the management device, thereby improving the management efficiency of the management device for the terminal.
[0010] More descriptions about the above embodiments and other aspects of the present application and their implementation manners are provided in the accompanying drawings, specific implementation manners, and claims. Description of the Drawings
[0011] Figure 1 A flowchart showing a communication method provided by an embodiment of the present application.
[0012] Figure 2 A flowchart showing a communication method provided by an embodiment of the present application.
[0013] Figure 3 A block diagram showing the composition of a management device provided by an embodiment of the present application.
[0014] Figure 4 A block diagram showing the composition of a core network device provided by an embodiment of the present application.
[0015] Figure 5 A schematic diagram showing the composition of a communication system provided by an embodiment of the present application.
[0016] Figure 6 A schematic diagram showing the information interaction between devices in the communication system provided by an embodiment of the present application.
[0017] Figure 7 A block diagram showing the composition of an electronic device provided by an embodiment of the present application. Detailed Description of the Embodiments
[0018] To make the objectives, technical solutions, and advantages of this application more clear and understandable, the embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined arbitrarily with each other.
[0019] Figure 1 The flowchart shows a communication method provided by an embodiment of this application. This communication method can be applied to a management device. As Figure 1 shown, the communication method in the embodiments of this application includes but is not limited to the following steps.
[0020] Step S101, obtain the target attribute information of the terminal to be processed based on the network subscription group.
[0021] Among them, the target attribute information of the terminal to be processed includes the network identifier to which the terminal to be processed belongs (for example, the identifier of a virtual network (VN)), and the network subscription group includes multiple terminals that are subscribed to the core network device, belong to the same slice area, and use the same data network (DN) resources.
[0022] For example, the network subscription group can be a VN group, which is a group determined by the core network device based on slice technology and / or data traffic forwarding methods for dividing the communication network and each network element device in the communication network, etc.
[0023] Step S102, associate the core network group corresponding to the terminal to be processed with the local area network based on the network identifier to which the terminal to be processed belongs.
[0024] Step S103, perform communication management on the terminal to be processed based on the access control interface corresponding to the terminal to be processed.
[0025] In this embodiment, by obtaining the target attribute information of the terminal to be processed based on the network subscription group, where the target attribute information of the terminal to be processed includes the network identifier to which the terminal to be processed belongs, and the network subscription group includes multiple terminals that are subscribed to the core network device, belong to the same slice area, and use the same data network resources, it is possible to accurately distinguish the terminal to be processed based on the network identifier to which the terminal to be processed belongs; associate the core network group corresponding to the terminal to be processed with the local area network based on the network identifier to which the terminal to be processed belongs, so that the management device in the local area network can identify the terminal to be processed; perform communication management on the terminal to be processed based on the access control interface corresponding to the terminal to be processed, enabling the management device to perform access control on the terminal to be processed that expects to access, so that each terminal to be processed can timely perform communication data interaction with the management device, improving the management efficiency of the management device for the terminal.
[0026] In some exemplary embodiments, before performing communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal in step S103, it further includes: establishing an access control interface corresponding to the to-be-processed terminal between the session control device and the access control device in the local area network.
[0027] Among them, the access control interface corresponding to the to-be-processed terminal is used to perform access control on the to-be-processed terminal.
[0028] For example, the session control device in the local area network sends an interface establishment request to the access control device, and in response to the interface establishment response feedback by the access control device, it is determined that the access control interface corresponding to the to-be-processed terminal is successfully established.
[0029] By establishing an access control interface corresponding to the to-be-processed terminal between the session control device and the access control device in the local area network, it is convenient to use the access control interface to perform access control on the to-be-processed terminal and enhance the recognition accuracy of the to-be-processed terminal.
[0030] In some exemplary embodiments, the communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal in step S103 includes:
[0031] When the target attribute information of the to-be-processed terminal conforms to the preset access control policy, communicate with the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal and the preset access control policy;
[0032] When the target attribute information of the to-be-processed terminal does not conform to the preset access control policy, do not communicate with the to-be-processed terminal.
[0033] Among them, the preset access control policy includes preset attribute information, and the preset attribute information includes a preset network identifier (for example, a preset virtual group identifier).
[0034] It should be noted that when the target attribute information of the to-be-processed terminal conforms to the preset access control policy, it indicates that the management device successfully verifies the to-be-processed terminal; when the target attribute information of the to-be-processed terminal does not conform to the preset access control policy, it indicates that the management device fails to verify the to-be-processed terminal.
[0035] By matching the target attribute information of the to-be-processed terminal with the preset access control policy, the verification speed of the to-be-processed terminal can be accelerated; further, based on the verification result of the to-be-processed terminal, performing access control on the to-be-processed terminal can prevent the to-be-processed terminal that does not conform to the preset access control policy from communicating with the management device, reduce the proportion of useless data received by the management device, enable the management device to communicate with the to-be-processed terminal that conforms to the preset access control policy efficiently and quickly, and improve the management efficiency of the management device for the to-be-processed terminal.
[0036] In some exemplary embodiments, before performing communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal in step S103, the method further includes: determining a preset access control policy according to preset attribute information and information of the management device.
[0037] Wherein, the preset network identifier corresponds to the information of the management device one by one. For example, the information of the management device includes the identifier of its corresponding local area network, and the preset virtual group identifier corresponds to the identifier of the local area network corresponding to the management device one by one.
[0038] For example, if the preset virtual group identifier is set as VNm and the identifier of the local area network corresponding to the management device is LANm, then the preset access control policy can be characterized as VNm-LANm, which means that only the terminals with the virtual group identifier VNm can access the resources in the local area network (the identifier of the local area network is LANm) under the jurisdiction of the management device, and other terminals with virtual group identifiers other than VNm cannot perform data interaction with the management device, let alone obtain the resources in the local area network under the jurisdiction of the management device.
[0039] Determining the preset access control policy in the above manner can facilitate the management device to use the preset access control policy to verify multiple to-be-processed terminals expected to access the management device, thereby accelerating the verification speed of the to-be-processed terminals and improving the management efficiency of the management device for the to-be-processed terminals.
[0040] In some exemplary embodiments, communicating with the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal and the preset access control policy includes: generating an access control identifier when the target attribute information of the to-be-processed terminal conforms to the preset access control policy; based on the access control interface corresponding to the to-be-processed terminal, transmitting the access control identifier and the preset communication data to the to-be-processed terminal through the core network device.
[0041] Wherein, the access control identifier indicates that the verification of the to-be-processed terminal is successful.
[0042] For example, if the preset access control policy is set as VNm-LANm, then when the information of the VN group of the to-be-processed terminal includes the preset virtual group identifier VNm, it can be determined that the to-be-processed terminal conforms to the preset access control policy, and then an access control identifier indicating that the verification of the to-be-processed terminal is successful is generated; if the information of the VN group of the to-be-processed terminal does not include the preset virtual group identifier VNm, it can be determined that the to-be-processed terminal does not conform to the preset access control policy, and then a rejection communication identifier indicating that the verification of the to-be-processed terminal fails is generated.
[0043] By adopting a preset access control policy to verify the terminal to be processed, it is possible to quickly and accurately verify whether the terminal to be processed can access the resources under the jurisdiction of the management device. Further, based on the access control identifier indicating the successful verification of the terminal to be processed, the management device can forward the communication data between it and the terminal to be processed through the core network device, so that communication can be carried out between the terminal to be processed and the management device, improving the communication efficiency.
[0044] In some exemplary embodiments, the preset attribute information further includes: a preset physical address and / or a preset network address; the target attribute information includes the target physical address of the terminal to be processed and / or the target network address of the terminal to be processed.
[0045] When the preset access control policy includes a preset physical address (such as a preset Media Access Control Address (MAC), etc.), if the preset physical address is set to MACm, the preset access control policy can be represented as MACm-LANm, which means that only the terminal with the physical address of MACm can access the resources in the local area network (the identifier of the local area network is LANm) under the jurisdiction of the management device, and other terminals with physical addresses other than MACm cannot interact with the management device and cannot obtain the resources in the local area network under the jurisdiction of the management device.
[0046] When the preset access control policy includes a preset network address (such as a preset Internet Protocol Address (IP), etc.), if the preset network address is set to IPm, the preset access control policy can be represented as IPm-LANm, which means that only the terminal with the network address of IPm can access the resources in the local area network (the identifier of the local area network is LANm) under the jurisdiction of the management device, and other terminals with network addresses other than IPm cannot interact with the management device and cannot obtain the resources in the local area network under the jurisdiction of the management device.
[0047] When the preset access control policy includes a preset physical address and a preset network address, the preset access control policy can be represented as MACm-IPm-LANm, which means that only the terminal with the network address of IPm and the physical address of MACm can access the resources in the local area network (the identifier of the local area network is LANm) under the jurisdiction of the management device, and other terminals with other network addresses or other physical addresses cannot interact with the management device and cannot obtain the resources in the local area network under the jurisdiction of the management device.
[0048] In some embodiments, the preset access control policy can also be characterized as LANm-VNm-MACm-IPm, which means that when the physical address of the terminal in the virtual network with the virtual group identifier VNm is MACm and the network address corresponding to the terminal is IPm, the terminal can access the resources in the local area network with the identifier LANm under the jurisdiction of the management device.
[0049] When the preset access control policy is characterized as LANm-VNm-MACm, if the virtual group identifier of the terminal to be processed is VNm, and / or the physical address of the terminal to be processed is MACm, it means that the management device has successfully verified the terminal to be processed. By verifying the virtual group identifier of the terminal to be processed and / or the physical address of the terminal to be processed, the verification speed of the terminal to be processed can be accelerated, enabling the management device to quickly identify the terminal to be processed that conforms to the preset access control policy and improving the management efficiency of the management device for the terminal to be processed.
[0050] Furthermore, by determining the preset access control policy through the above-mentioned various different policies, the management device can also manage the terminal to be processed from different dimensions, manage the terminal to be processed within different ranges using different preset access control policies, and enable the management device to freely control the access control range for the terminal to be processed.
[0051] Figure 2 The flowchart of a communication method provided by an embodiment of the present application is shown. This communication method can be applied to a core network device. As Figure 2 shown, the communication method in the embodiment of the present application includes but is not limited to the following steps.
[0052] Step S201: In response to a session establishment request sent by the terminal to be processed, sign a contract with the terminal to be processed and determine the target attribute information of the terminal to be processed.
[0053] Among them, the target attribute information of the terminal to be processed includes the network identifier to which the terminal to be processed belongs.
[0054] For example, the network identifier to which the terminal to be processed belongs is the identifier of the virtual network VN group, and each VN group includes multiple terminals signed by the core network device, belonging to the same slice area, and using the same data network resources.
[0055] Step S202: Send the target attribute information of the terminal to be processed to the management device.
[0056] When the management device receives the target attribute information of the terminal to be processed, the management device can associate the core network group corresponding to the terminal to be processed with the local area network based on the target attribute information and perform communication management on the terminal to be processed based on the access control interface corresponding to the terminal to be processed.
[0057] Among them, the target attribute information of the terminal to be processed includes the network identifier to which the terminal to be processed belongs (for example, the identifier of the VN), and the network subscription group includes multiple terminals that are subscribed to the core network device, belong to the same slice area, and use the same DN resource.
[0058] In this embodiment, by responding to the session establishment request sent by the terminal to be processed, subscribing to the terminal to be processed, and determining the target attribute information of the terminal to be processed, the target attribute information of the terminal to be processed includes the network identifier to which the terminal to be processed belongs, so that the network identifier reflects the network to which the terminal to be processed belongs, that is, the terminal to be processed is one of multiple terminals that are subscribed to the core network device, belong to the same slice area, and use the same data network resource, thereby facilitating the differentiation of the terminal to be processed; sending the target attribute information of the terminal to be processed to the management device, so that the management device can associate the core network group corresponding to the terminal to be processed with the local area network based on the network identifier to which the terminal to be processed belongs; performing communication management on the terminal to be processed based on the access control interface corresponding to the terminal to be processed. In other words, enabling the management device to perform access control on the terminal to be processed that expects to access through the access control interface corresponding to the terminal to be processed, so that each terminal to be processed can timely interact communication data with the management device, improving the management efficiency of the management device for the terminal.
[0059] In some exemplary embodiments, after sending the target attribute information of the terminal to be processed to the management device in step S202, the method further includes: determining the verification result of the management device for the terminal to be processed in response to the response message feedback by the management device; forwarding the communication data between the terminal to be processed and the management device when the verification result is verification success; and sending a rejection communication identifier to the terminal to be processed when the verification result is verification failure.
[0060] Among them, the response message includes: an access control identifier, or, a rejection communication identifier. The access control identifier indicates that the verification of the terminal to be processed is successful, and the rejection communication identifier indicates that the management device refuses to communicate with the terminal to be processed.
[0061] Through the different identifiers carried in the response message, clarify the verification result of the management device for the terminal to be processed, and based on different verification results, use the above two different methods to process the communication data sent by the terminal to be processed, improving the processing efficiency of the communication data.
[0062] In some embodiments, after sending the rejection communication identifier to the terminal to be processed, the core network device will also discard the communication data sent by the terminal to be processed to reduce the redundant information stored in the core network device and expand the storage space of the core network device.
[0063] Next, in combination with the accompanying drawings, each device in the present application will be introduced in detail.Figure 3 The block diagram showing the composition of a management device provided by an embodiment of the present application is as follows. As Figure 3 shown, the management device 300 includes but is not limited to the following modules.
[0064] An obtaining module 301, configured to obtain target attribute information of a to-be-processed terminal based on a network subscription group, where the target attribute information of the to-be-processed terminal includes a network identifier to which the to-be-processed terminal belongs, and the network subscription group includes multiple terminals that are subscribed to a core network device, belong to the same slice area, and use the same data network resource.
[0065] An association module 302, configured to associate a core network group corresponding to the to-be-processed terminal with a local area network based on the network identifier to which the to-be-processed terminal belongs.
[0066] A management module 303, configured to perform communication management on the to-be-processed terminal based on an access control interface corresponding to the to-be-processed terminal.
[0067] It should be noted that the management device 300 in this embodiment can implement any communication method applied to the management device in the embodiments of the present application.
[0068] According to the management device of the embodiment of the present application, the obtaining module obtains the target attribute information of the to-be-processed terminal based on the network subscription group, where the target attribute information of the to-be-processed terminal includes the network identifier to which the to-be-processed terminal belongs, and the network subscription group includes multiple terminals that are subscribed to the core network device, belong to the same slice area, and use the same data network resource, and can accurately distinguish the to-be-processed terminal based on the network identifier to which the to-be-processed terminal belongs; the association module is used to associate the core network group corresponding to the to-be-processed terminal with the local area network based on the network identifier to which the to-be-processed terminal belongs, so that the management device in the local area network can identify the to-be-processed terminal; the management module is used to perform communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal, so that the management device performs access control on the to-be-processed terminal expected to access, enabling each to-be-processed terminal to timely perform communication data interaction with the management device, and improving the management efficiency of the management device for the terminal.
[0069] Figure 4 The block diagram showing the composition of a core network device provided by an embodiment of the present application is as follows. As Figure 4 shown, the core network device 400 includes but is not limited to the following modules.
[0070] A determination module 401, configured to sign a contract with the to-be-processed terminal in response to a session establishment request sent by the to-be-processed terminal, and determine the target attribute information of the to-be-processed terminal.
[0071] Among them, the target attribute information of the to-be-processed terminal includes the network identifier to which the to-be-processed terminal belongs.
[0072] A sending module 402, configured to send target attribute information of a to-be-processed terminal to a management device, so that the management device associates a core network group corresponding to the to-be-processed terminal with a local area network based on the target attribute information, and performs communication management on the to-be-processed terminal based on an access control interface corresponding to the to-be-processed terminal.
[0073] It should be noted that the core network device 400 in this embodiment can implement any communication method applied to the core network device in the embodiments of the present application.
[0074] According to the core network device of the embodiment of the present application, a determination module responds to a session establishment request sent by a to-be-processed terminal, signs a contract with the to-be-processed terminal, and determines the target attribute information of the to-be-processed terminal. The target attribute information of the to-be-processed terminal includes a network identifier to which the to-be-processed terminal belongs, so that the network identifier reflects the network to which the to-be-processed terminal belongs, that is, the to-be-processed terminal is one of multiple terminals that are signed with the core network device, belong to the same slice area, and use the same data network resources, thereby facilitating the differentiation of the to-be-processed terminal; the sending module is used to send the target attribute information of the to-be-processed terminal to the management device, so that the management device can associate the core network group corresponding to the to-be-processed terminal with the local area network based on the network identifier to which the to-be-processed terminal belongs; perform communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal. In other words, the management device can perform access control on the to-be-processed terminal expected to access through the access control interface corresponding to the to-be-processed terminal, so that each to-be-processed terminal can timely perform communication data interaction with the management device, improving the management efficiency of the management device for the terminal.
[0075] Figure 5 The composition schematic diagram of a communication system provided by the embodiment of the present application is shown. As Figure 5 shown, the communication system includes but is not limited to the following devices: at least one to-be-processed terminal (for example, a first terminal 531, a second terminal 532, a third terminal 533, a fourth terminal 534, and a fifth terminal 535, etc.), at least one management device (for example, a first management device 541 and a second management device 542, etc.), and a core network device 510.
[0076] A management device, configured to execute any communication method applied to the management device in the present application.
[0077] For example, the management device obtains the target attribute information of the to-be-processed terminal based on the network subscription group; associates the core network group corresponding to the to-be-processed terminal with the local area network based on the network identifier to which the to-be-processed terminal belongs; performs communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal.
[0078] Among them, the target attribute information of the terminal to be processed includes the network identifier to which the terminal to be processed belongs. The network subscription group includes multiple terminals that are subscribed to the core network device, belong to the same slice area, and use the same data network resources.
[0079] As Figure 5 shown, the first management device 541 is used to manage the resources within the first local area network 5411, and the second management device 542 is used to manage the resources within the second local area network 5421.
[0080] The core network device 510 is configured to execute any one of the communication methods applied to the core network device in this application.
[0081] For example, in response to a session establishment request sent by the terminal to be processed, the core network device 510 subscribes to the terminal to be processed and determines the target attribute information of the terminal to be processed; and sends the target attribute information of the terminal to be processed to the management device.
[0082] As Figure 5 shown, the core network device 510 includes: a User Plane Function (UPF) entity 511, a Session Management function (SMF) entity 512, an Access and Mobility Management Function (AMF) entity 513, an ApplicationFunction (AF) entity 514, a Unified Data Management (UDM) entity 515, an Authentication Server Function (AUSF) entity 516, a PolicyControl function (PCF) entity 517, and a Network Exposure Function (NEF) entity 518.
[0083] The UPF entity 511 is respectively connected to the first base station 521 and the second base station 522. Among them, the communication coverage area of the first base station 521 includes the first terminal 531 and the second terminal 532. In other words, the first terminal 531 and the second terminal 532 are terminals subscribed to the core network device 510 that belong to the same slice area and use the same data network resources, that is, they are both terminals within the first virtual network 5211.
[0084] Similarly, within the communication coverage of the second base station 522, there are a third terminal 533, a fourth terminal 534, and a fifth terminal 535. In other words, the third terminal 533, the fourth terminal 534, and the fifth terminal 535 are terminals that are subscribed by the core network device 510 and belong to the same slice area and use the same data network resources, that is, they are all terminals within the second virtual network 5221.
[0085] The terminal to be processed is configured to send a session establishment request to the core network device 510, so that the core network device 510 subscribes with the terminal to be processed, determines the network identifier to which the terminal to be processed belongs. For example, the core network device allocates information of a VN group for the terminal to be processed and forwards the information of the VN group of the terminal to be processed to the management device; the management device determines whether the information of the VN group of the terminal to be processed conforms to a preset access control policy, and when the information of the VN group of the terminal to be processed conforms to the preset access control policy, communicates with the terminal to be processed according to the access control interface corresponding to the terminal to be processed and the preset access control policy.
[0086] Among them, the management device can directly send communication data to the terminal to be processed through the access control interface corresponding to the terminal to be processed; it can also forward the communication data between the management device and the terminal to be processed through the core network device 510. This application does not limit this.
[0087] Among them, the preset access control policy is a policy determined based on preset attribute information and information of the management device. The information of the management device includes the identifier of the local area network corresponding to the management device; the preset attribute information includes at least one of the following: preset network identifier (including preset virtual group identifier), preset physical address, and preset network address.
[0088] The preset access control policy can be represented in at least one of the following forms:
[0089] Identifier of the local area network corresponding to the management device - preset virtual group identifier;
[0090] Identifier of the local area network corresponding to the management device - preset virtual group identifier - preset physical address;
[0091] Identifier of the local area network corresponding to the management device - preset virtual group identifier - preset physical address - preset network address.
[0092] For example, if it is set that the identifier of the local area network corresponding to the first management device 541 is LAN1, the preset virtual group identifier is VN1, the preset physical address is MAC1, and the preset network address is IP1, then the preset access control policy can be represented in at least one of the following forms: LAN1-VN1; LAN1-VN1-MAC1; LAN1-VN1-MAC1-IP1.
[0093] For another example, if the identifier of the local area network corresponding to the second management device 542 is set as LAN2, the preset virtual group identifier is VN2, the preset physical address is MAC2, and the preset network address is IP2, the preset access control policy can be represented in at least one of the following forms: LAN2-VN2; LAN2-VN2-MAC2; LAN2-VN2-MAC2-IP2.
[0094] If the virtual group identifier of the terminal to be processed is VN2, the terminal to be processed can only access the resources in the second local area network 5421 under the jurisdiction of the second management device 542, and cannot access the resources in the first local area network 5411 under the jurisdiction of the first management device 541.
[0095] If the virtual group identifier of the terminal to be processed is different from the preset virtual group identifier in the preset access control policy of the first management device 541, and the virtual group identifier of the terminal to be processed is also different from the preset virtual group identifier in the preset access control policy of the second management device 542, the terminal to be processed will not be able to access the resources in the local area networks managed by the above two management devices.
[0096] Figure 6 The figure shows a schematic diagram of information interaction between devices in the communication system provided by the embodiments of the present application. As Figure 6 shown, the information interaction between devices in the communication system includes but is not limited to the following steps.
[0097] Step S601, the terminal to be processed interacts registration information with the access and mobility management function entity 513 through the base station, so that the terminal to be processed can be registered in the core network device 510.
[0098] Among them, when the core network device 510 receives a session establishment request sent by the terminal to be processed, the core network device 510 will sign a contract with the terminal to be processed and determine the target attribute information of the terminal to be processed. The target attribute information of the terminal to be processed includes the network identifier to which the terminal to be processed belongs. Thus, the terminal to be processed can be registered in the core network device 510.
[0099] The terminal to be processed includes a first terminal 531 and a second terminal 532. The terminal to be processed first accesses the base station (for example, a 5G base station), and then the base station sends the physical address (such as MAC address, device number, etc.) and / or the network address (such as IP address, etc.) of the terminal to be processed to the access and mobility management function entity 513, so that the access and mobility management function entity 513 can sign a contract with the terminal to be processed and allocate information of a corresponding VN group to the terminal to be processed.
[0100] It should be noted that different VN groups correspond to different service types. Multiple terminals in each VN group use the same data network resource, and the multiple terminals belong to the same slice area.
[0101] The access and mobility management function entity 513 also updates the network address of the to-be-processed terminal according to the subscription information. For example, the access and mobility management function entity 513 updates the network address of the to-be-processed terminal according to the subscription information, network area and other information of the to-be-processed terminal.
[0102] Among them, the target attribute information of the to-be-processed terminal includes at least one of the following: information of the VN group of the to-be-processed terminal, physical address of the to-be-processed terminal (such as MAC address, device number, etc.), and network address of the to-be-processed terminal (such as updated IP address, etc.).
[0103] Step S602, the to-be-processed terminal performs session message-based interaction with the session management function entity 512 through the base station and the access and mobility management function entity 513, so that a session link based on the Protocol Data Unit (PDU) can be successfully established between the to-be-processed terminal and the session management function entity 512.
[0104] Among them, the to-be-processed terminal and the session management function entity 512 can establish the above PDU session link based on multiple different communication protocols, and this application does not limit this.
[0105] Step S603, the session management function entity 512 sends the target attribute information of the to-be-processed terminal to the first management device 541 through the user plane function entity 511.
[0106] Among them, the first management device 541 is used to manage the resources within the first local area network 5411; if the to-be-processed terminal expects to access the resources within the first local area network 5411, it needs to pass the verification of the first management device 541.
[0107] Step S604, after receiving the target attribute information of the to-be-processed terminal, the first management device 541 matches the target attribute information of the to-be-processed terminal with the preset access control policy to verify the to-be-processed terminal, and feeds back the verification result to the session management function entity 512, so that the session management function entity 512 forwards the verification result to the to-be-processed terminal.
[0108] Among them, the verification result includes: the to-be-processed terminal is verified successfully, or, the to-be-processed terminal is verified failed.
[0109] When the target attribute information of the terminal to be processed conforms to the preset access control policy, it is determined that the verification of the terminal to be processed is successful, and communication is carried out with the terminal to be processed based on the access control interface corresponding to the terminal to be processed according to the preset access control policy; when the target attribute information of the terminal to be processed does not conform to the preset access control policy, it is determined that the verification of the terminal to be processed fails, and communication is not carried out with the terminal to be processed.
[0110] Among them, the preset access control policy includes preset attribute information, and the preset attribute information includes a preset network identifier (for example, a preset virtual group identifier). The information of the first management device 541 includes the identifier of the local area network corresponding to the first management device 541, and the preset attribute information includes at least one of the following: a preset virtual group identifier, a preset physical address, and a preset network address.
[0111] The preset access control policy can be represented in at least one of the following forms:
[0112] The identifier of the local area network corresponding to the first management device 541 - preset virtual group identifier;
[0113] The identifier of the local area network corresponding to the first management device 541 - preset physical address;
[0114] The identifier of the local area network corresponding to the first management device 541 - preset virtual group identifier - preset physical address;
[0115] The identifier of the local area network corresponding to the first management device 541 - preset virtual group identifier - preset physical address - preset network address.
[0116] For example, if the identifier of the local area network corresponding to the first management device 541 is set as LAN1, the preset virtual group identifier is set as VN1, the preset physical address is set as MAC1, and the preset network address is set as IP1, then the preset access control policy can be represented in at least one of the following forms: LAN1 - VN1; LAN1 - VN1 - MAC1; LAN1 - VN1 - MAC1 - IP1.
[0117] After receiving the target attribute information of the terminal to be processed, the first management device 541 will respectively match the virtual group information of the terminal to be processed, the target physical address of the terminal to be processed, and the target network address of the terminal to be processed with the above preset access control policy to implement the verification of the terminal to be processed.
[0118] For example, it is set that the information of the VN group of the terminal to be processed includes the target virtual group identifier as VNx, the target physical address of the terminal to be processed is MACx, and the target network address of the terminal to be processed is IPx.
[0119] If it is detected that VNx is the same as VN1, and / or, MACx is the same as MAC1, and / or, IPx is the same as IP1, it indicates that the first management device 541 has successfully verified the to-be-processed terminal. At this time, the first management device 541 generates an access control identifier (e.g., Y), and this access control identifier indicates that the first management device 541 has successfully verified the to-be-processed terminal.
[0120] Correspondingly, if it is detected that VNx is different from VN1, and / or, MACx is different from MAC1, it indicates that the first management device 541 has failed to verify the to-be-processed terminal. The first management device 541 generates a reject communication identifier (e.g., N), and this reject communication identifier indicates that the first management device 541 has failed to verify the to-be-processed terminal. At this time, the first management device 541 will not communicate with the to-be-processed terminal and rejects receiving the messages sent by the to-be-processed terminal.
[0121] In some embodiments, an encryption policy can also be first adopted to encrypt the messages in the above interaction process, and then the encrypted messages are used for transmission between various devices to ensure the security of the messages during the transmission process.
[0122] Among them, the encryption policy includes: an encryption method based on the Internet Protocol Security (IPSec), and / or, an encryption method based on the Secure Socket Layer (SSL).
[0123] The encryption method based on IPSec is a method of encrypting and authenticating the packets of the IP protocol, which can protect the messages of the network transport protocol stack that supports the IP protocol. The encryption method based on SSL is an encryption method implemented on the transport communication protocol (e.g., Transmission Control Protocol / Internet Protocol (TCP / IP), etc.). Among them, the public key method can be adopted for data encryption and decryption processing.
[0124] Correspondingly, for the second management device 542, the verification and interaction process of the to-be-processed terminal expected to access it is the same as the processing process of the first management device 541, which will not be elaborated here.
[0125] In this embodiment, through the above steps, the management device can perform access control on the to-be-processed terminals expected to access, enabling the terminals in different virtual groups in the 5G network to access the resources within the local area network under the jurisdiction of the management device corresponding to the information of their virtual groups. In other words, the 5G network can be applied to different industries to achieve vertical management and improve the management efficiency of the management device for terminals in different local area networks.
[0126] It should be clear that this application is not limited to the specific configurations and processes described and illustrated in the above embodiments. For the convenience and brevity of description, the detailed descriptions of known methods are omitted here. The specific working processes of the systems, modules, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.
[0127] Figure 7 The block diagram showing the composition of an electronic device provided by an embodiment of this application is shown.
[0128] As Figure 7 shown, the electronic device includes: at least one processor 701, at least one memory 702, and one or more I / O interfaces 703. Among them, the processor 701, the memory 702, and the I / O interface 703 are interconnected through a bus 704. The memory 702 stores one or more computer programs, and the one or more computer programs are executed by at least one processor 701 to enable at least one processor 701 to implement any one of the communication methods described in the above embodiments.
[0129] An embodiment of this application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements any one of the communication methods described in the above embodiments. The computer-readable storage medium can be a volatile or non-volatile computer-readable storage medium.
[0130] The above is only an exemplary embodiment of this application and is not used to limit the protection scope of this application. Generally speaking, various embodiments of this application can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. For example, some aspects can be implemented in hardware, while other aspects can be implemented in firmware or software that can be executed by a controller, a microprocessor, or other computing devices, although this application is not limited thereto.
[0131] Embodiments of the present application may be implemented by a processor executing computer program instructions, such as in a processor entity, or by hardware, or by a combination of software and hardware. The computer program instructions may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages.
[0132] The block diagram of any logic flow in the accompanying drawings of the present application can represent program steps, or can represent interconnected logic circuits, modules and functions, or can represent a combination of program steps and logic circuits, modules and functions. The computer program can be stored on a memory. The memory can have any type suitable for the local technical environment and can be implemented using any suitable data storage technology, such as but not limited to read-only memory (ROM), random access memory (RAM), optical memory device and system (digital versatile disc DVD or CD disc), etc. Computer-readable media may include non-transient storage media. The processor can be any type suitable for the local technical environment, such as but not limited to a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a programmable logic device (FGPA) and a processor based on a multi-core processor architecture.
[0133] Example embodiments have been disclosed herein, and although specific terms are employed, they are used and should be interpreted only in a general illustrative sense and not for limiting purposes. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly noted, features, characteristics, and / or elements described in conjunction with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in conjunction with other embodiments. Therefore, those skilled in the art will appreciate that various changes in form and detail may be made without departing from the scope of the present disclosure as set forth in the appended claims.
Claims
1. A communication method, wherein, applied to a management device, includes: obtaining target attribute information of a to-be-processed terminal based on a network subscription group, the target attribute information of the to-be-processed terminal including a network identifier to which the to-be-processed terminal belongs, and the network subscription group including multiple terminals that are subscribed to a core network device, belong to the same slice area, and use the same data network resources; associating a core network group corresponding to the to-be-processed terminal with a local area network based on the network identifier to which the to-be-processed terminal belongs; performing communication management on the to-be-processed terminal based on an access control interface corresponding to the to-be-processed terminal.
2. The method according to claim 1, wherein, the performing communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal includes: when the target attribute information of the to-be-processed terminal conforms to a preset access control policy, communicating with the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal and the preset access control policy; when the target attribute information of the to-be-processed terminal does not conform to the preset access control policy, not communicating with the to-be-processed terminal; wherein the preset access control policy includes preset attribute information, and the preset attribute information includes a preset network identifier.
3. The method according to claim 1, wherein, before the performing communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal, the method further includes: establishing an access control interface corresponding to the to-be-processed terminal between a session control device and an access control device in the local area network, and the access control interface corresponding to the to-be-processed terminal is used to perform access control on the to-be-processed terminal.
4. The method according to claim 2, wherein, before the performing communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal, the method further includes: determining the preset access control policy according to the preset attribute information and the information of the management device; wherein the preset network identifier corresponds one-to-one with the information of the management device.
5. The method according to claim 2, wherein, the preset attribute information further includes: a preset physical address and / or a preset network address; the target attribute information includes a target physical address of the to-be-processed terminal, and / or a target network address of the to-be-processed terminal.
6. The method according to claim 2, wherein, the communicating with the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal and the preset access control policy includes: when the target attribute information of the to-be-processed terminal conforms to the preset access control policy, generating an access control identifier, and the access control identifier represents that the verification of the to-be-processed terminal is successful; transmitting the access control identifier and preset communication data to the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal.
7. A communication method, wherein, applied to a core network device, includes: In response to a session establishment request sent by a to-be-processed terminal, sign a contract with the to-be-processed terminal and determine the target attribute information of the to-be-processed terminal, where the target attribute information of the to-be-processed terminal includes the network identifier to which the to-be-processed terminal belongs; Send the target attribute information of the to-be-processed terminal to a management device, so that the management device associates the core network group corresponding to the to-be-processed terminal with a local area network based on the target attribute information, and performs communication management on the to-be-processed terminal based on the access control interface corresponding to the to-be-processed terminal.
8. The method according to claim 7, wherein, after sending the target attribute information of the to-be-processed terminal to the management device, the method further includes: In response to a response message fed back by the management device, determine the verification result of the management device on the to-be-processed terminal; When the verification result is successful verification, forward the communication data between the to-be-processed terminal and the management device; When the verification result is failed verification, send a rejection communication identifier to the to-be-processed terminal, where the rejection communication identifier indicates that the management device rejects to communicate with the to-be-processed terminal.
9. An electronic device, wherein, including: one or more processors; a memory, on which one or more programs are stored, and when the one or more programs are executed by the one or more processors, the one or more processors implement the communication method according to any one of claims 1 to 6, or the communication method according to any one of claims 7 to 8.
10. A readable storage medium, wherein, the readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the communication method according to any one of claims 1 to 6, or the communication method according to any one of claims 7 to 8.