Security countermeasures for distributed network slice admission control

By receiving and verifying the number of UE or PDU sessions associated with the service area in a 5G wireless network, network performance degradation caused by forgery or incorrect number is solved, and higher network slicing performance and reliability are achieved.

CN120052022APending Publication Date: 2025-05-27ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101085.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-10-14
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In 5G wireless networks, the performance of network slices is reduced by the number of fake or incorrect UE or PDU sessions, resulting in a degradation in network performance.

Method used

The admission control process is performed by receiving a message from the second device in the first device, updating or reporting the number of admissions for UE or PDU sessions associated with a particular service area and verifying that the number of UE or PDU sessions counted by the third device.

Benefits of technology

The accuracy of the number of UE or PDU sessions is effectively verified, preventing performance degradation caused by forgery or incorrect number, and improving the performance and reliability of network slices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120052022A_ABST
    Figure CN120052022A_ABST
Patent Text Reader

Abstract

Example embodiments of the present disclosure relate to security countermeasures for distributed network slice admission control (NSAC). Specifically, a first device receives, from a second device, a first message for updating or reporting a number of admission for a user equipment (UE) or packet data unit (PDU) session associated with a service area corresponding to the second device, where the number of admission is specific to slice or single network slice selection assistance information (S-NSSAI). The first device then determines a first number of slice-or S-NSSAI-specific UE or PDU sessions counted by the at least one third device such that the number of admission is verified with the first number, and performs an admission control procedure based at least in part on the first number.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunications, and in particular, to methods, devices, apparatuses, and computer-readable storage media for security countermeasures for distributed network slice admission control (NSAC). Background Art

[0002] The 3rd Generation Partnership Project (3GPP) 5th Generation (5G) technology is the next-generation radio system and network architecture, which can provide extreme broadband, ultra-robust, and low-latency connectivity. The 5G technology improves various telecommunications services provided to end-users and helps support massive broadband that provides gigabytes per second of bandwidth for both uplink and downlink transmissions on demand.

[0003] In a 5G wireless network, network slicing is a concept for operating multiple logical networks as virtually independent service operations on a common physical infrastructure. Generally, a slice can be identified by a single Slice Network Slice Selection Assistance Information (S-NSSAI). In addition, the slice network requires an NSAC process. That is, the number of User Equipment (UE) or Packet Data Unit (PDU) sessions is controlled by using a pre-configured maximum number of UE or PDU sessions. However, if the number of UE or PDU sessions is forged or incorrect, the performance of the slice network will be degraded thereby. Summary of the Invention

[0004] In a first aspect of the present disclosure, a first device is provided. The first device includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first device to at least perform: receiving a first message from a second device, the first message for updating or reporting an admission number of a UE or a PDU session associated with a service area corresponding to the second device, the admission number being specific to a slice or an S-NSSAI; and determining a first number of UE or PDU sessions specific to a slice or an S-NSSAI counted by at least one third device such that the admission number is verified with the first number; and performing an admission control process at least partially based on the first number.

[0005] In a second aspect of the present disclosure, a third device is provided. The third device includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third device to at least perform: receiving a second message from the first device, the second message for requesting a second number of UE or PDU sessions associated with a service area corresponding to the second device, the second number being counted by the third device and specific to a slice or an S-NSSAI; generating a third message indicating the second number; and sending the third message to the second device.

[0006] In a third aspect of the present disclosure, a fourth device is provided. The fourth device includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fourth device to at least perform: receiving a registration request from a user device; and in response to the completion of registration of the user device, sending a fifth message to a third device, the fifth message including information about one or more permitted S-NSSAIs.

[0007] In a fourth aspect of the present disclosure, a fifth device is provided. The fifth device includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fifth device to at least perform: receiving a fourth message from a first device, the fourth message indicating that an exception has occurred at a second device or in a service area where the second device is located, the second device being a distributed access control device; and triggering a security process to handle the exception.

[0008] In a fifth aspect of the present disclosure, a sixth device is provided. The sixth device includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the sixth device to at least perform: collecting information from multiple devices, the information being associated with multiple numbers of user devices or PDU sessions specific to a slice or S-NSSAI; and determining, at least in part based on the information, an operating state of a second device that is a distributed access control device.

[0009] In a sixth aspect of the present disclosure, a method is provided. The method includes: receiving, at a first device, a first message from a second device, the first message being for updating or reporting an admission number of UEs or PDU sessions associated with a service area corresponding to the second device, the admission number being specific to a slice or S-NSSAI; determining a first number of UEs or PDU sessions specific to a slice or S-NSSAI counted by at least one third device such that the admission number is verified with the first number; and performing an access control process at least in part based on the first number.

[0010] In a seventh aspect of the present disclosure, a method is provided. The method includes: receiving, at a third device and from a first device, a second message for requesting a second number of UEs or PDU sessions associated with a service area corresponding to the second device, the second number being counted by the third device and being specific to a slice or S-NSSAI; generating a third message indicating the second number; and sending the third message to the second device.

[0011] In an eighth aspect of the present disclosure, a method is provided. The method includes: receiving a registration request from a user equipment at a fourth device; and in response to the completion of the registration of the user equipment, sending a fifth message to a third device, the fifth message including information about one or more permitted S-NSSAIs.

[0012] In a ninth aspect of the present disclosure, a method is provided. The method includes: receiving a fourth message from a first device at a fifth device, the fourth message indicating that an exception has occurred at a second device or in a service area where the second device is located, the second device being a distributed access control device; and triggering a security process to handle the exception.

[0013] In a tenth aspect of the present disclosure, a method is provided. The method includes: collecting information from a plurality of devices at a sixth device, the information being associated with a plurality of numbers of user equipment or PDU sessions specific to a slice or S-NSSAI; and determining, at least in part based on the information, an operating state of a second device that is a distributed access control device.

[0014] In an eleventh aspect of the present disclosure, a first apparatus is provided. The first apparatus includes: means for receiving a first message from a second apparatus, the first message for updating or reporting an access number of a UE or PDU session associated with a service area corresponding to the second apparatus, the access number being specific to a slice or S-NSSAI; means for determining a first number of UEs or PDU sessions specific to a slice or S-NSSAI counted by at least one third apparatus, such that the access number is verified with the first number; and means for performing an access control process at least in part based on the first number.

[0015] In a twelfth aspect of the present disclosure, a third apparatus is provided. The third apparatus includes: means for receiving a second message from a first apparatus, the second message for requesting a second number of UEs or PDU sessions associated with a service area corresponding to the second apparatus, the second number being counted by the third apparatus and specific to a slice or S-NSSAI; means for generating a third message indicating the second number; and means for sending the third message to the second apparatus.

[0016] In a thirteenth aspect of the present disclosure, a fourth apparatus is provided. The fourth apparatus includes: means for receiving a registration request from a user equipment; and means for sending a fifth message to a third apparatus in response to the completion of the registration of the user equipment, the fifth message including information about one or more permitted S-NSSAIs.

[0017] In a fourteenth aspect of the present disclosure, a fifth device is provided. The fifth device includes: a component for receiving a fourth message from a first device, the fourth message indicating that an abnormality has occurred at a second device or in a service area where the second device is located, the second device being a distributed access control device; and a component for triggering a security process to handle the abnormality.

[0018] In a fifteenth aspect of the present disclosure, a sixth device is provided. The sixth device includes: a component for collecting information from a plurality of devices, the information being associated with a plurality of numbers of user equipment or PDU sessions specific to a slice or S-NSSAI; and a component for determining, at least in part based on the information, an operating state of a second device that is a distributed access control device.

[0019] In a sixteenth aspect of the present disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon that, when executed by a device, cause the device to at least perform the method according to the sixth aspect.

[0020] In a seventeenth aspect of the present disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon that, when executed by a device, cause the device to at least perform the instructions of the method according to the seventh aspect.

[0021] In an eighteenth aspect of the present disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon that, when executed by a device, cause the device to at least perform the instructions of the method according to the eighth aspect.

[0022] In a nineteenth aspect of the present disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon that, when executed by a device, cause the device to at least perform the instructions of the method according to the ninth aspect.

[0023] In a twentieth aspect of the present disclosure, a computer-readable medium is provided. The computer-readable medium includes instructions stored thereon that, when executed by a device, cause the device to at least perform the instructions of the method according to the tenth aspect.

[0024] It should be understood that the summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become readily apparent through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Some example embodiments will now be described with reference to the accompanying drawings, in which:

[0026] Figure 1 An example communication environment in which example embodiments of the present disclosure can be implemented is shown;

[0027] Figure 2AShows a hierarchical NSACF architecture according to some example embodiments;

[0028] Figure 2B Shows a signaling diagram for a maximum number of NSAC checks for a UE according to some example embodiments;

[0029] Figure 2C Shows a signaling diagram for a maximum number of NSAC checks for a PDU session according to some example embodiments;

[0030] Figure 2D Shows a signaling diagram for a local maximum number of redistributions according to some example embodiments;

[0031] Figure 3 Shows a signaling diagram for communication according to some example embodiments of the present disclosure;

[0032] Figure 4 Shows another signaling diagram for communication according to some example embodiments of the present disclosure;

[0033] Figure 5 Shows a flowchart of a method implemented at a first device according to some example embodiments of the present disclosure;

[0034] Figure 6 Shows a flowchart of a method implemented at a third device according to some example embodiments of the present disclosure;

[0035] Figure 7 Shows a flowchart of a method implemented at a fourth device according to some example embodiments of the present disclosure;

[0036] Figure 8 Shows a flowchart of a method implemented at a fifth device according to some example embodiments of the present disclosure;

[0037] Figure 9 Shows a flowchart of a method implemented at a sixth device according to some example embodiments of the present disclosure;

[0038] Figure 10 Shows a simplified block diagram of a device suitable for implementing example embodiments of the present disclosure; and

[0039] Figure 11 Shows a block diagram of an example computer-readable medium according to some example embodiments of the present disclosure.

[0040] Throughout the drawings, the same or similar reference numerals denote the same or similar elements. Detailed Description

[0041] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that these embodiments are for illustrative purposes only and help those skilled in the art to understand and implement the present disclosure, without implying any limitation on the scope of the present disclosure. The embodiments described herein can be implemented in various ways other than those described below.

[0042] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0043] References in the present disclosure to "an embodiment", "embodiment", "example embodiment", etc. mean that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is considered within the knowledge of those skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments (whether or not explicitly described).

[0044] It should be understood that although the terms "first", "second", etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the example embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.

[0045] As used herein, "at least one of the following: <list of two or more elements>" and "at least one of <list of two or more elements>" and similar phrases (where the list of two or more elements is joined by "and" or "or") refer to at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0046] As used herein, unless explicitly stated, performing a step "in response to A" does not mean that the step is performed immediately after A occurs, but may include one or more intermediate steps.

[0047] The terms used in this document are for the purpose of describing particular embodiments only and are not intended to limit the example embodiments. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. It should also be understood that the terms "comprises", "comprising", "has" and / or "including", when used herein, specify the presence of the stated features, elements and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.

[0048] As used in this application, the term "circuitry" can refer to one or more or all of the following: (a) Only hardware circuit implementations (such as implementations in only analog / or digital circuits); (b) Combinations of hardware circuits and software, such as, if applicable: (i) Combinations of (multiple) analog and / or digital hardware circuits and software / firmware, and (ii) Any part of a hardware processor with software (including (multiple) digital signal processors), software, and (multiple) memories, which work together to enable a device such as a mobile phone or a server to perform various functions); and (c) (Multiple) hardware circuits and / or (multiple) processors that require software (e.g., firmware) for operation, such as (multiple) microprocessors or a part of (multiple) microprocessors, but the software may not be present when not needed for operation.

[0049] This definition of circuitry applies to all uses of the term in this application, including in any claims. As another example, as used in this application, the term circuitry also encompasses implementations of only hardware circuits or processors (or multiple processors) or a part of a hardware circuit or processor with its accompanying software and / or firmware. For example and if applicable to a particular claim element, the term circuitry also encompasses a baseband integrated circuit or a processor integrated circuit for a mobile device, or a similar integrated circuit in a server, a cellular network device, or other computing or network devices.

[0050] As used herein, the term "communication network" refers to a network that complies with any suitable communication standard, such as New Radio (NR), Long-Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. In addition, the communication between the terminal device and the network device in the communication network can be performed according to any suitable generation communication protocol, including but not limited to the first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, fifth generation (5G) communication protocol and / or any other protocol currently known or to be developed in the future. Embodiments of the present disclosure can be applied to various communication systems. Considering the rapid development of communication, there are of course future types of communication technologies and systems in which the present disclosure can be implemented. It should not be regarded as limiting the scope of the present disclosure to the above systems only.

[0051] As used herein, the term "network device" refers to a node in a communication network through which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, Node B (NodeB or NB), evolved Node B (eNodeB or eNB), NR NB (also referred to as gNB), Remote Radio Unit (RRU), Radio Head (RH), Remote Radio Head (RRH), repeater, Integrated Access and Backhaul (IAB) node, low-power node (such as femto, pico), Non-Terrestrial Network (NTN) or non-terrestrial network device (such as satellite network device, Low Earth Orbit (LEO) satellite and Geostationary Earth Orbit (GEO) satellite, aircraft network device, etc.), depending on the terms and technologies applied. In some example embodiments, the Radio Access Network (RAN) split architecture includes a Centralized Unit (CU) and a Distributed Unit (DU) at the IAB donor node. The IAB node includes a Mobile Terminal (IAB-MT) part that behaves like a UE towards the parent node, while the DU part of the IAB node behaves like a base station towards the next-hop IAB node.

[0052] The term "terminal device" refers to any terminal device capable of wireless communication. By way of example and not limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smart phones, Internet Protocol voice (VoIP) phones, wireless local loop phones, tablet computers, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), game terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop devices (LME), USB dongles, smart devices, wireless customer premise equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMD), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in an industrial and / or automation processing chain environment), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, etc. A terminal device may also correspond to the mobile terminal (MT) part of an IAB node (e.g., a relay node). In the following description, the terms "terminal device", "communication device", "terminal", "user equipment", and "UE" may be used interchangeably.

[0053] As used herein, the terms "resource", "transmission resource", "resource block", "physical resource block" (PRB), "uplink resource", or "downlink resource" may refer to any resource used to perform communication (e.g., communication between a terminal device and a network device), such as a resource in the time domain, a resource in the frequency domain, a resource in the spatial domain, a resource in the code domain, or any other resource for enabling communication, etc. In the following, unless explicitly stated, resources in the frequency domain and the time domain will be used as examples of transmission resources for describing some example embodiments of the present disclosure. Note that the example embodiments of the present disclosure are equally applicable to other resources in other domains.

[0054] As used herein, the term "primary access control device" refers to any entity / function / device / apparatus responsible for access control for at least one slice with a globally maximum value valid across a service area. In some example embodiments, the primary access control device is located in the central area of the 5G core network / home public land mobile network (HPLMN). By way of example and not limitation, the primary access control device may be the primary NSACF.

[0055] Furthermore, the terms "primary access control device", "primary NSACF", "centralized NSACF", or "central NSACF" may be used interchangeably.

[0056] As used herein, the term "distributed access control device" refers to any entity / function / device / apparatus responsible for access control for a service area (or visited public land mobile network, VPLMN). In some example embodiments, the distributed access control device is located at the edge of a network (such as an HPLMN or VPLMN) and can communicate with a primary access control device. By way of example and not limitation, the distributed access control device may be a distributed NSACF.

[0057] Furthermore, the terms "distributed access control device", "local access control device", "distributed NSACF" or "local NSACF" may be used interchangeably.

[0058] As used herein, the term "control device" refers to any entity / function / device / apparatus for control. In some example embodiments, the control device is a control plane component / device and is used to control a data plane such as a PDU session.

[0059] Responsible for controlling signaling, sessions (such as PDU sessions), etc.

[0060] By way of example and not limitation, the control device may be an access and mobility management function (AMF) or a session management function (SMF).

[0061] As used herein, the term "user data management device" refers to any entity / function / device / apparatus responsible for maintaining user data in a network. In some example embodiments, the user data management device may be located in the central area of a 5G core network / HPLMN. Furthermore, in some example embodiments, the user data management device may be accessed by a primary access control device, one or more control devices, one or more analysis devices, etc. By way of example and not limitation, the user data management device may be a user data management (UDM).

[0062] As used herein, the term "management device" refers to any entity / function / device / apparatus responsible for operation, supervision, management, maintenance, etc. By way of example and not limitation, the management device may be an operation, administration and maintenance (OAM).

[0063] As used herein, the term "analysis device" refers to any entity / function / device / apparatus that can collect and analyze logs, traces, reports, data and other operational information in a network. In some example embodiments, the analysis device operates based on artificial intelligence (AI) / machine learning (ML). By way of example and not limitation, the analysis device may be a network data analytics function (NWDAF), a management data analytics service (MDAS) producer, and any AI / ML network function / node.

[0064] In 3GPP Release 18, it is expected to enhance the NSAC feature with the following characteristics: improved network control of UE behavior and support for deploying multiple NSACFs. That is, there may be more than one service area associated with an S-NSSAI. For example, a PLMN is divided into multiple service areas. In this case, there will be more than one NSACF to handle the UE, and the example scenarios include: Multi-NSACF deployed within a PLMN: More than one service is defined within a PLMN. In addition, for each service area, one NSACF or a set of NSACFs is deployed for NSAC (including control of the maximum number of UEs or PDU sessions). Roaming: When the user equipment resides in a visited PLMN (VPLMN), NSAC (such as the maximum number of PDU sessions) can be controlled by the NSACF in the VPLMN (e.g., for local interruption of PDU sessions) or the NSACF in the HPLMN (e.g., for home routing of PDU sessions). Evolved Packet System (EPS) interworking: When the user equipment establishes a home-routed PDN connection in the EPS network and later moves to the 5G system, the NSACF selected by the SMF + Packet Data Network Gateway Control Plane Function (PGW-C) and the AMF (e.g., the maximum number of user equipments) may be different.

[0065] In addition, as mentioned above, generally, a slice can be identified by an S-NSSAI, and further, for a slice / S-NSSAI, there is only one configured global maximum allowed value for NSAC (i.e., the maximum number of UEs or PDU sessions). In the case of multiple NSACFs, admission control aims to match the allocated quota. However, when additional features are added to the admission control mechanism, potential problems of Denial of Service (DoS) attacks target legitimate user equipments. For example, maliciously distributed NSACFs in the service area can provide forged or false information about the number of UEs or PDU sessions.

[0066] In some cases, the security controls in different service areas / (V)PLMNs can be different. In particular, the security controls at the network edge are not as strict as those in the data center, which results in a potentially higher attack surface at the network edge than in the data center. Therefore, compromised / maliciously distributed NSACFs in some high-risk service areas / networks may trigger DoS or other attacks on the home network.

[0067] For example, a damaged / malicious distributed NSACF at the network edge may forge a situation where the number of UEs reaches the local maximum number allocated to the serving area, and may send a message of Nnsacf_NSAC_NumberUpdate_Request to the master NSACF to obtain a new quota. The master NSACF may allocate the new quota to the damaged / malicious distributed NSACF. As a result, the available quota for other normal serving areas may decrease. In other words, the admission service for normal serving areas may be affected because the global maximum number has been exhausted by the damaged / malicious distributed NSACF(s).

[0068] In addition, in some cases, even if the user equipment does not use a network slice, the user equipment can still be counted towards the quota usage of the S-NSSAI it is registered to.

[0069] In summary, there are various situations that may lead to an incorrect number of UEs or PDU sessions. In the case where the number of UEs or PDU sessions is forged or incorrect, the performance of the network will be degraded accordingly.

[0070] In view of the above, it is desirable to propose a solution to identify a forged or incorrect number of user equipment / PDU sessions.

[0071] According to some exemplary embodiments of the present disclosure, a solution for distributed security countermeasures for a distributed NSAC network is provided. Specifically, a device (such as a master NSACF or an analysis device) may obtain information associated with a more accurate number of user equipment or PDU sessions specific to a slice or S-NSSAI. Using such information, the damaged / malicious distributed NSACF / AMF / SMF(s) can be identified.

[0072] The principles and implementation manners of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0073] It should be noted that any section / subsection headings provided herein are not intended to be restrictive. Embodiments are described throughout this document, and any type of embodiment may be included under any section / subsection. In addition, the embodiments disclosed in any section / subsection may be combined with any other embodiments described in the same section / subsection and / or different sections / subsections in any manner. Example environment

[0074] Figure 1 An example communication environment 100 is shown in which example embodiments of the present disclosure may be implemented.

[0075] In Figure 1In a specific example, the communication environment 100 includes multiple communication devices, a first device 110, and more than one second device (such as second devices 120-1 and 120-2), more than one third device (such as third devices 130-1 and 130-2), one or more fifth devices (such as fifth device 150), and one or more sixth devices (such as sixth device 160).

[0076] Hereinafter, for illustrative purposes, some example embodiments are described, in which the first device 110 operates as a primary access control device (such as a primary NSACF), the second device 120 operates as a distributed access control device (such as a distributed NSACF, which can be implemented as one NSACF instance or a set of NSACFs), the third device 130 operates as a user data management device (such as a UDM), the fifth device 150 operates as a management device (such as an OAM), and the sixth device 160 operates as an analysis device (such as an NWDAF or an MDAS producer).

[0077] In some example embodiments, each second device 120 corresponds to a service area / VPLMN. Additionally, in some example embodiments, each service area / VPLMN may include multiple fourth devices 140 to control signaling, PDU sessions, etc. In Figure 1 a specific example, fourth devices 140-1 and 140-2 are connected to second device 120-1, and fourth devices 140-3 and 140-4 are connected to second device 120-2. Additionally, the fourth device 140 may be an AMF or an SMF. As a specific embodiment, fourth devices 140-1 and 140-3 may be AMFs, and fourth devices 140-2 and 140-4 may be SMFs.

[0078] In some example embodiments, more than one slice may be deployed in the communication environment 100, and each slice may be identified by a corresponding S-NSSAI.

[0079] Furthermore, in some example embodiments, for a slice / S-NSSAI, a global maximum allowed value (i.e., the maximum number of UEs and PDU sessions) is configured for NSAC. In some example embodiments, the first device 110 performs NSAC for each slice / S-NSSAI based on the global maximum allowed value and allocates corresponding quotas to the service areas.

[0080] In some example embodiments, a hierarchical NSACF architecture is supported in the communication environment 100. Specifically, for a slice / S-NSSAI, one NSACF acting as the primary NSACF is introduced, such as Figure 1 the first device 110 in. Each other NSACF (such as,Figure 1 The second device 120) in serves a service area. The master NSACF enables centralized management of the global maximum allowed values. As a specific example embodiment, the service level agreement (SLA) attributes (i.e., the global maximum values valid across the service area) are only configured at the master NSACF and are shared between different (multiple) service areas / VPLMNs.

[0081] For better understanding, reference is now made to Figure 2A , which shows a hierarchical NSACF architecture 200 according to some example embodiments.

[0082] In some example embodiments, the distributed NSACF is deployed based on the service area, which can be an NSACF instance or a set of NSACFs. Additionally, each distributed NSACF independently performs the control of the maximum number of registered user devices or established PDU sessions. In this case, due to reaching the local maximum number of UEs / PDU sessions at the current serving NSACF, UE registration or PDU session establishment can be rejected by the network, even though the maximum number is still available at other NSACFs.

[0083] For better understanding, reference is now made to Figures 2B to 2D , in which Figure 2B shows a signaling diagram 220 for NSAC checking of the maximum number of UEs according to some example embodiments, Figure 2C shows a signaling diagram 240 for NSAC checking of the maximum number of PDU sessions according to some example embodiments, and Figure 2D shows a signaling diagram 260 for redistribution of the local maximum number according to some example embodiments.

[0084] It should be understood that Figure 1 the number of devices shown in and their connections are for illustrative purposes only and do not imply any limitation. In other example embodiments, the communication environment 100 may include any suitable number of devices configured to implement the example embodiments of the present disclosure.

[0085] Communication in the communication environment 100 can be implemented according to any suitable communication protocol, including but not limited to cellular communication protocols of the first generation (1G), second generation (2G), third generation (3G), fourth generation (4G), fifth generation (5G), sixth generation (6G), etc., wireless local area network communication protocols such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocol known currently or developed in the future. In addition, the communication can utilize any appropriate wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplexing (FDD), Time Division Duplexing (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple Access (OFDM), Discrete Fourier Transform Spread OFDM (DFT-s-OFDM), and / or any other technology known currently or developed in the future. Principle of operation and example signaling for communication

[0086] According to some example embodiments of the present disclosure, a solution for security countermeasures for distributed NSAC is provided.

[0087] In this solution, a device (such as a primary NSACF or an analysis device) can obtain information associated with a more accurate number of user devices or PDU sessions specific to a slice or S-NSSAI. Using such information, compromised / malicious distributed NSACF / AMF / SMF(s) can be identified.

[0088] Now refer to Figure 3 , which shows a signaling diagram 300 for communication according to some example embodiments of the present disclosure. As Figure 3 shown, the signaling diagram 300 involves a first device 110, a second device 120, third device(s) 130, fourth device(s) 140, and a fifth device 150.

[0089] In addition, in a specific example of Figure 3 , the NSAC process involves at least multiple UEs and multiple PDU sessions.

[0090] For the purpose of discussion, the signaling diagram 300 is described with reference to Figure 1 . For better understanding only, in the following example embodiments, the first device 110 is described as a primary access control device, the second device 120 is described as a distributed access control device, the third device 130 is described as a user data management device, and the fifth device 150 is described as a management device (such as OAM). It should be understood that in other embodiments, the first device 110 to the fifth device 150 can be any suitable device type. The present disclosure is not limited in this regard.

[0091] In Figure 3In a particular embodiment, the second device 120 may correspond to a serving area / VPLM and may be served by one or more slices. In addition, one or more fourth devices 140 (such as, (multiple) AMFs and (multiple) SMFs) may be located in the serving area corresponding to the second device 120.

[0092] In some example embodiments, one or more third devices 130 are deployed in the communication environment 100. Each third device 130 may be responsible for maintaining user data for one or more user groups, one or more serving areas / VPLMNs, one or more subnets, etc. In short, the total user / user data may be divided to be maintained by one or more third devices 130 in any suitable manner. The present disclosure is not limited in this regard.

[0093] In some example embodiments, at least a portion of one or more third devices 130 may be accessed by (multiple) fourth devices 140 according to network deployment and configuration.

[0094] In some example embodiments, the first device 110 and one or more third devices 130 are located in the central area of the communication environment 100, and the first device 110 may access all of the one or more third devices 130.

[0095] In some example embodiments, the third device 130 may provide a more accurate number of UEs or PDU sessions by interacting with (multiple) fourth devices 140, as discussed in Figure 3 discussed.

[0096] As Figure 3 shown, after receiving a registration request from a user equipment, in response to the completion of the registration of the user equipment, the fourth device 140 sends a fifth message 305 to the third device 130. In some example embodiments, the fifth message includes information about one or more allowed S-NSSAIs. Using such information, the third device 130 may establish (multiple) associations between the fourth device 140, the registered user equipment, and the allowed S-NSSAIs. Additionally, in some example embodiments, the fourth device 140 that processes the registration request may be an AMF.

[0097] In a particular example embodiment, the fourth device 140 (such as, an AMF) receives a registration request from a user equipment. After completing the primary authentication and authorization for the user equipment, the fourth device 140 sends a message of Nudm_UECM_Registration to the third device 130 to notify the allowed slice list. For example, the registration message includes one or more allowed S-NSSAIs.

[0098] In theory, a malicious AMF could forge messages of Nudm_UECM_Registration. However, as a feature that links the increased home control to subsequent processes, this type of threat can be addressed. Another possibility is that the AMF could forge the S-NSSAI as the S-NSSAI it wants to attack. However, since the total number of registered user devices cannot be forged and in any case the S-NSSAI should be part of the subscribed S-NSSAI of the user device, it is difficult for a malicious AMF to utilize general signaling (such as messages of Nudm_UECM_Registration) to achieve a DoS attack without involving a large number of real user devices.

[0099] In view of the above, the third device 130 may have the ability to provide a more accurate number of (registered) user devices.

[0100] In some example embodiments, the third device 130 may also communicate with a fourth device 140 (such as an SMF) to obtain a more accurate number of PDU sessions. As Figure 3 shown, after creating a PDU session for a user device on a slice, the fourth device 140 sends a message of 310Nudm_UECM_Registration to the third device 130 to register the PDU session, where the message of Nudm_UECM_Registration includes the permitted S-NSSAI. Using such information, the third device 130 can establish an association between the fourth device 140, the established PDU session, and the S-NSSAI.

[0101] In theory, a malicious SMF could forge messages of Nudm_UECM_Registration. However, since the total number of registered user devices cannot be forged, the number of PDU sessions for one user device is limited. Therefore, similar to the AMF, it is difficult for a malicious SMF to utilize general signaling (such as Nudm_UECM_Registration) to achieve a DoS attack without involving a large number of real user devices.

[0102] In view of the above, the third device 130 may also have the ability to provide a more accurate number of PDU sessions. Additionally, with enhanced features, the third device 130 can generate reports on the number of registered user devices or PDU sessions for each network slice of a specific VPLMN / service area / (multiple) AMF / (multiple) SMF.

[0103] Considering the enhancements to the third device 130, enhanced security countermeasures for the NSAC can be implemented, as described below.

[0104] In some example embodiments, the second device 120 sends 310 a first message to the first device 110 for updating one or more admission numbers of a user equipment or a PDU session. Alternatively, in some example embodiments, the second device 120 sends 310 a first message to the first device 110 for reporting one or more admission numbers of a user equipment or a PDU session. In particular, each admission number is associated with a service area / VPLMN corresponding to the second device 130 and is specific to a particular S-NSSAI.

[0105] In some example embodiments, the sending of the first message is triggered by one or more specific events. One example event is that the number of UEs or PDU sessions reaches / has reached the maximum admission number assigned to the corresponding service area (such as the local maximum number of UEs or PDU sessions). Another example is that the number of UEs or PDU sessions exceeds a predefined threshold number. Another event is that the increase rate of the user equipment or PDU session exceeds a predefined threshold rate.

[0106] It should be understood that the above example events are given for illustrative purposes and do not imply any limitation. In some other embodiments, the transmission of the first message can be triggered by any suitable event. In addition, the above events and other suitable events can be used alone or in combination. The present disclosure is not limited in this regard.

[0107] Alternatively, in some other embodiments, the first message is sent periodically. The period can be a default parameter specified by a wireless standard (such as 3GPP) or configured by a network device or a network operator.

[0108] In summary, the present disclosure is not limited to how the first message is sent.

[0109] In some example embodiments, the admission number included in the first message indicates the maximum admission number assigned to the service area. In this case, the first device 110 can be notified that the number of UEs or PDU sessions reaches / has reached the maximum admission number assigned to the service area.

[0110] Alternatively or additionally, the admission number included in the first message indicates the current admission number determined by the second device 120. In this way, the first device can understand the operation information of the service area.

[0111] As a specific example embodiment, the second device 120 (VPLMN or distributed NSACF in a specific service area) sends a message of Nnsacf_NSAC_NumberOfUEsUpdate_Request or Nnsacf_NSAC_NumberOfPDUSUpdate_Request to the first device 110 (primary NSACF), which means that the local maximum or pre-configured threshold number of user equipment / PDU sessions for triggering reporting has been reached / has reached.

[0112] As described above, the admission number determined by the second device 120 may be forged or incorrect. Thus, as Figure 3 shown, after receiving the first message, the first device 110 may determine a first number of UEs or PDU sessions specific to a slice or S-NSSAI. In particular, the first number is counted by at least one third device 130.

[0113] As described above, the number of UEs or PDU sessions counted by at least one third device 130 is more accurate. Thus, the admission number indicated by the first message can be verified with the first number.

[0114] Next, the first device may perform an admission control process at least partially based on the first number. Specifically, in some example embodiments, the first device 110 compares the first number with an admission control number (such as the local maximum number included in the message of Nnsacf_NSAC_NumberOfUEsUpdate_Request or Nnsacf_NSAC_NumberOfPDUsUpdate_Request) 355 to determine whether the first number matches the admission control number.

[0115] In some example embodiments, if the difference between the first number and the admission control number is less than a threshold difference, it is determined that the first number matches the admission control number, otherwise it is determined that the first number does not match the admission control number.

[0116] Next, in some example embodiments, if the first number matches the admission control number, the first device 110 performs the 360NSAC process at least in part based on the first message. As a specific example embodiment, the second device 120 (i.e., the distributed NSACF) sends a message of Nnsacf_NSAC_NumberUpdate_Request (i.e., the first message) to the first device 110 (i.e., the master NSACF). The first message includes the S-NSSAI, the requested local maximum number of user equipment / PDU sessions, that is, to increase the local maximum number of user equipment / PDU sessions / admission number. If the first number matches the admission control number, the first device 110 checks the global maximum number of user equipment / PDU sessions and determines whether to accept or reject the requested local maximum number of user equipment / PDU sessions, that is, whether the update of the local maximum number of user equipment / PDU sessions of the second device 120 is accepted. If the first device 110 has no more available quota, the first device 110 may indicate to the second device 120 to reject any new increase requests. Otherwise, the first device 110 may accept the requested local maximum number of user equipment / PDU sessions.

[0117] Then, the first device 110 returns a response message of Nnsacf_NSAC_NumberUpdate_Response. The response message may include the newly allocated local maximum PDU session number, or it may return an indication with a cause code to reject any other new user registration / PDU session.

[0118] Alternatively, in some example embodiments, if the first number does not match the admission control number, the first device may determine that a potential anomaly has occurred in the second device 120 or the service area.

[0119] In this case, the first device 110 may handle such a potential anomaly. In some example embodiments, the first device 110 may stop the NSAC process for the first message because the second device 120 may be a compromised / malicious device.

[0120] Alternatively or additionally, in some example embodiments, the first device 110 may adjust the admission control number according to the first number because the first number counted by the third device(s) 130 is more accurate than the admission control number indicated by the first message.

[0121] Alternatively or additionally, in some example embodiments, the first device 110 may send a fourth message 370 to the fifth device 150, where the fourth message may indicate that an exception has occurred at the second device 120 or in the service area, and the fifth device 150 may be a management device (such as, OAM). With the fourth message, the fifth device 150 may trigger 380 a security process to handle such an exception, such as redeploying the second device 120 or other related network functions / nodes.

[0122] In some example embodiments, the fourth message may indicate at least one of the following: the identity of the second device 120 (e.g., NSACF identity), or the identity of the service area / VPLMN corresponding to the second device 120.

[0123] Additionally, in some example embodiments, the first device 110 may send 375 a response message to the first message, where the response message may indicate whether the requested update indicated by the first message is successful (accepted) or failed (rejected). As a specific example embodiment, the first device 110 returns a response message of Nnsacf_NSAC_NumberUpdate_Response, where the response message may include the newly allocated local maximum PDU session number, or it may return an indication with a cause code to reject any further new user registration / PDU session.

[0124] Given that the verification admission control requires additional processes, the verification operation may be configured to be conditionally executed. In some example embodiments, before determining the first number (i.e., performing the verification), the first device 110 may determine whether the verification admission number is required according to a preconfigured policy. The preconfigured policy may be associated with multiple factors. One example factor is the threat surface of the second device 120. Another example factor is the S-NSSAI. Another example is the identity of the PLMN corresponding to the first device 110. Other example factors include but are not limited to: the identity of the VPLMN corresponding to the second device 120, the preconfigured threshold number of UEs or PDU sessions, and the security control policy of the service area.

[0125] In a specific example embodiment, the verification may be triggered based on a preconfigured threshold configuration for each second device 120 (i.e., service area). For example, if the number of UEs or PDU sessions exceeds the preconfigured threshold but does not reach the maximum value, the first device 110 may trigger to verify the admission number. Similarly, when the number of UEs or PDU sessions drops below another threshold number, the first device 110 may also trigger to verify the admission number.

[0126] It should be understood that the above exemplary factors are given for illustrative purposes and do not imply any limitation. In some other embodiments, the preconfigured policy may be associated with any suitable factor. Additionally, the above factors and other suitable factors may be used alone or in combination. The present disclosure is not limited in this regard.

[0127] When the preconfigured policy is introduced, in some example embodiments, the verification process may be skipped. In some example embodiments, if it is determined that the admission count does not need to be verified, the first device 110 performs the NSAC process at least partially based on the first message as described above. In this way, it is possible to perform the verification of the admission count more flexibly. For example, the verification process is only performed for high-risk service areas, or only performed when the reported admission count is higher than a predefined threshold.

[0128] In the following, a detailed process for determining the first count will be discussed.

[0129] Since the (multiple) fourth devices 140 located in the service area may access more than one third device 130 during the UE registration and PDU session establishment processes, the first device 110 needs to communicate with more than one third device 130 to obtain the first count.

[0130] As Figure 3 shown, the first device 110 sends a second message 335 to each relevant third device 130. In particular, the second message is used to request the second count of UEs or PDU sessions associated with the service area and is specific to a slice or S-NSSAI.

[0131] In some example embodiments, before sending the second message to each relevant third device 130, the first device 110 first determines 330 the relevant (multiple) third devices 130. In some example embodiments, the first device 110 determines the relevant (multiple) third devices 130 by scanning all accessible third devices 130. Alternatively, in some other embodiments, the first device 110 determines the relevant (multiple) third devices 130 by performing a discovery process of the third devices 130 according to preconfigured rules. Additionally, the preconfigured rules may be stored locally or in a network repository function (NRF).

[0132] In some example embodiments, to contact relevant third device(s) 130, the NRF discovery service is enhanced to return respective instances of third device 130 that hold all subscribers. For example, if third device 130-1 is configured to support subscribers in a first area, and third device 130-2 is configured to support subscribers in a second area, the NRF will return both third device 130-1 and third device 130-2. Alternatively, the NRF may return all instances of third device 130, and the first device 110 may determine a group of third device 130 based on the network function profile of third device 130.

[0133] In some example embodiments, the second message may include a parameter indicating a requirement associated with a second number. One example parameter is S-NSSAI. Another example parameter is an identification of the serving area or an identification of the VPLMN associated with the second device 120. Another parameter is at least one identification of at least one fourth device 140 located in the serving area, such as a list of AMF / SMF identifications.

[0134] In this way, the first device 110 may request each of the relevant third devices 130 to obtain the number of UEs registered in the AMF / SMF of a specific VPLMN or HPLMN for a specific slice / S-NSSAI, or the number of PDU sessions established in the AMF / SMF of a specific VPLMN or HPLMN for a specific slice / S-NSSAI.

[0135] Additionally, considering that the AMF / SMF identification is identifiable to the relevant third device 130, before sending the second message, the first device 110 may first determine 325 at least one identification of at least one fourth device 140 in the serving area. In some example embodiments, the first device 110 determines at least one identification of at least one fourth device based on a first mapping of the second device 120 and at least the fourth device 140. Alternatively, in some example embodiments, the first device 110 determines at least one identification of at least one fourth device based on a second mapping of the serving area and at least the fourth device 140.

[0136] In some example embodiments, the first / second mapping is pre-configured at the first device 110. Alternatively, in some other example embodiments, the fourth device 140 updates the user equipment / PDU session count to the second device 120, and the second device 120 conveys information about the fourth device 140 to the first device 110.

[0137] As described above, the third device 130 has the ability to provide a more accurate number of UEs or PDU sessions. In addition, the third device 130 has also established associations between the fourth device 140, the registered user equipment, the allowed S-NSSAI, and / or the established PDU sessions. Therefore, after receiving the second message, the third device can generate 340 a third message indicating the requested second number.

[0138] Additionally, the second number can be reported at any suitable granularity. In some example embodiments, the second number is specific to the second device 120. Alternatively, in some example embodiments, the second number is specific to the service area. Alternatively, in some example embodiments, the second number is specific to at least one fourth device 140 located in the service area. In short, the second number can be counted flexibly, and the present disclosure is not limited in this regard.

[0139] Next, the third device 130 sends 345 the third message to the first device 110. In this way, the first device 110 can obtain the second number from each of the relevant third devices 130. In some example embodiments, the first device 110 determines the first number by combining 350 at least one second number received from at least one relevant third device 130.

[0140] According to the above process, the admission number reported by the second device 120 can be verified by the first device 110. As a result, a compromised / malicious second device 120 / fourth device 140 can be identified in a timely manner.

[0141] Additionally, according to some example embodiments of the present disclosure, an analysis device (such as an AI / ML-based network function) can also identify anomalies in the second device 120 / service area / fourth device 140.

[0142] Now refer to Figure 4 , which shows a signaling diagram 400 for communication according to some example embodiments of the present disclosure. As Figure 4 shown, the signaling diagram 400 involves a sixth device 160, a fifth device 150, and multiple devices.

[0143] For the purpose of discussion, refer to Figure 1 to describe the signaling diagram 400. Only for better understanding, in the following example embodiments, the fifth device 150 is described as a management device (such as an OAM), and the sixth device 160 is described as an analysis device (such as an NWDAF or MDAS producer).

[0144] In operation, the sixth device 160 collects 410 information associated with multiple numbers of user equipment or PDU sessions specific to a slice or S-NSSAI from multiple devices.

[0145] In some example embodiments, the multiple devices include, but are not limited to: a primary access control device (such as, Figure 1 the first device 110 in Figure 1 ), at least one distributed access control device (such as, Figure 1 the second device 120 in Figure 1 ), at least one control device (such as,

[0146] the fourth device 140 in

[0147] ), at least one user data management device (such as,

[0148] the first device 130 in

[0149] ), or at least one analysis device. That is, the sixth device 160 can collect relevant information from any suitable device. The present disclosure is not limited in this regard. Figure 4 the fourth device 140 in

[0150] Additionally, in some example embodiments, the information collected may be the number of UEs or PDU sessions determined by the corresponding device. Alternatively or additionally, in some example embodiments, the information collected may be a trace (or log) recorded on the corresponding device. Alternatively or additionally, in some example embodiments, the information collected may be load or congestion information / reports generated by the corresponding device. That is, the information collected can be represented in any suitable form. The present disclosure is not limited in this regard.

[0151] In addition, in a specific example embodiment, the NWDAF / MDAF may also collect a more accurate number of UEs or PDU sessions counted by the UDM and / or additional data (e.g., information / logs / traces from the (multiple) AMF / (multiple) SMF, load information of the slice, congestion reports of the slice, etc.). Then, the NWDAF / MDAF compares the quota with the more accurate number of UEs or PDU sessions. If a malicious / compromised distributed NSACF is detected, the NWDAF / MDAF may generate an analysis report (such as a fourth message) to warn / report the potentially malicious / compromised distributed NSACF. Alternatively or additionally, if a malicious / compromised distributed NSACF is detected, the NWDAF / MDAF may also trigger to reduce the quota for the distributed NSACF, or trigger to redeploy the distributed NSACF and other network functions in the same service area or VPLMN.

[0152] In this way, the anomalies of the second device 120 or the service area can be identified and processed in a timely manner. Example method

[0153] Figure 5 A flowchart of an example method 500 implemented at a first device 110 according to some example embodiments of the present disclosure is shown. For the purpose of discussion, method 500 will be described from the perspective of the first device 110 in Figure 1 the first device 110.

[0154] At block 510, the first device 110 receives a first message from the second device 120 for updating or reporting an admission number of UEs or PDU sessions associated with a service area corresponding to the second device 120, the admission number being specific to a slice or S-NSSAI.

[0155] At block 520, the first device 110 determines a first number of UEs or PDU sessions specific to a slice or S-NSSAI counted by at least one third device 130 such that the admission number is verified with the first number.

[0156] At block 530, the first device 110 performs an admission control process at least partially based on the first number.

[0157] In some example embodiments, the admission number indicates one of the following: the maximum admission number allocated to the service area, or the current admission number determined by the second device 120.

[0158] In some exemplary embodiments, it further includes: before determining the first number, determining whether it is necessary to verify the access number according to a pre-configured policy associated with at least one of the following: the threat surface of the second device 120, S-NSSAI, the identifier of the PLMN corresponding to the first device 110, the service area, the identifier of the VPLMN corresponding to the second device 120, or the security control policy of the service area.

[0159] In some example embodiments, it further includes: if it is determined that it is not necessary to verify the access number, performing the NSAC process at least partially based on the first message.

[0160] In some example embodiments, determining the first number includes: sending a second message to each of at least one third device 130 for requesting a second number of UEs or PDU sessions associated with the service area, the second number being counted by the corresponding third device 130 among at least one third device 130 and specific to a slice or S-NSSAI; receiving a third message indicating the second number from each of at least one third device 130; and determining the first number by combining at least one second number received from at least one third device 130.

[0161] In some example embodiments, the second message includes at least one of the following: S-NSSAI, the identifier of the service area, the identifier of the visited PLMN (VPLMN) associated with the second device 120, or at least one identifier of at least one fourth device 140 located in the service area, and each of at least one fourth device 140 is a control device.

[0162] In some example embodiments, the first device 110 determines at least one identifier of at least one fourth device 140 according to one of the following mappings: the first mapping between the second device 120 and at least one fourth device 140, or the second mapping between the service area and at least one fourth device 140.

[0163] In some example embodiments, the second number is specific to one of the following: the second device 120, the service area, or at least one fourth device 140 located in the service area, and each of at least one fourth device 140 is a control device.

[0164] In some example embodiments, before sending the second message to each of at least one third device 130, the first device 110 determines at least one third device 130 by one of the following: scanning all accessible third devices 130, or performing a discovery process of the third device 130 according to pre-configured rules.

[0165] In some example embodiments, performing an admission control process at least partially based on a first number includes: comparing the first number with an admission control number; if the first number matches the admission control number, performing an NSAC process at least partially based on a first message; and if the first number does not match the admission control number, performing at least one of the following: stopping the NSAC process; adjusting the admission control number according to the first number; or sending a fourth message to a fifth device 150, the fourth message indicating that an anomaly has occurred at the second device 120 or in the service area.

[0166] In some example embodiments, the fifth device 150 is a management device.

[0167] In some example embodiments, the first device 110 is a primary admission control device, the second device 120 is a distributed admission control device, and the third device 130 is a user data management device.

[0168] Figure 6 A flowchart showing an example method 600 implemented at a third device 120 according to some example embodiments of the present disclosure. For purposes of discussion, method 600 will be described from the perspective of the third device 130 in Figure 1 which follows.

[0169] At block 610, the third device 130 receives a second message from the first device 110 for requesting a second number of UEs or PDU sessions associated with a service area corresponding to the second device 120, the second number being counted by the third device 130 and specific to a slice or S-NSSAI.

[0170] At block 620, the third device 130 generates a third message indicating the second number.

[0171] At block 630, the third device 130 sends the third message to the second device 120.

[0172] In some example embodiments, the second message includes at least one of the following: an NSSAI, an identifier of the service area, an identifier of a VPLMN associated with the second device 120, or at least one identifier of at least one fourth device 140 located in the service area, each of the at least one fourth device 140 being a control device.

[0173] In some example embodiments, the second number is specific to one of the following: the second device 120, the service area, at least one fourth device 140 located in the service area, each of the at least one fourth device 140 being a control device.

[0174] In some example embodiments, it further includes: receiving, from a fourth device 140, a fifth message including information about one or more permitted S-NSSAIs, the fifth message being sent by the fourth device 140 in response to the completion of the registration for the user equipment, and the fourth device 140 being the AMF.

[0175] In some example embodiments, the first device 110 is a primary access control device or an analysis device, the second device 120 is a distributed access control device, and the third device 130 is a user data management device.

[0176] Figure 7 A flowchart of an example method 700 implemented at a fourth device 140 according to some example embodiments of the present invention is shown. For the purpose of discussion, method 700 will be described from the perspective of the fourth device 140 in Figure 1 which.

[0177] At block 710, the fourth device 140 receives a registration request from the user equipment.

[0178] At block 720, in response to the completion of the registration of the user equipment, the fourth device 140 sends a fifth message including information about one or more permitted S-NSSAIs to the third device 130.

[0179] In some example embodiments, the fourth device 140 is the AMF, and the third device 130 is a user data management device.

[0180] Figure 8 A flowchart of an example method 800 implemented at a fifth device 150 according to some example embodiments of the present disclosure is shown. For the purpose of discussion, method 800 will be described from the perspective of the fifth device 150 in Figure 1 which.

[0181] At block 810, the fifth device 150 receives a fourth message from the first device 110, the fourth message indicating that an abnormality has occurred in the second device 120 or the service area where the second device 120 is located, and the second device 120 being a distributed access control device.

[0182] At block 820, the fifth device 150 triggers a security process to handle the abnormality.

[0183] In some example embodiments, the first device 110 is a primary access control device or an analysis device, and the fifth device 150 is a management device.

[0184] Figure 9 A flowchart of an example method 900 implemented at a sixth device 160 according to some example embodiments of the present disclosure is shown. For the purpose of discussion, method 900 will be described from the perspective of the sixth device 160 in Figure 1 which.

[0185] At block 910, a sixth device 160 collects information associated with a plurality of numbers of user equipment or PDU sessions specific to a slice or S-NSSAI from a plurality of devices.

[0186] At block 920, the sixth device 160 determines an operating state of a second device 120 as a distributed access control device based at least in part on the information.

[0187] In some example embodiments, the information associated with the plurality of numbers includes at least one of the following: the number of UEs or PDU sessions determined by respective devices among the plurality of devices, traces recorded on respective devices among the plurality of devices, or load or congestion information reports generated by respective devices among the plurality of devices.

[0188] In some example embodiments, it further includes: if the operating state is determined to be abnormal, sending a fourth message to a fifth device 150, the fourth message indicating that an abnormality has occurred at the second device 120 or in the service area.

[0189] In some exemplary embodiments, the sixth device 160 is an analysis device, and the plurality of devices includes at least one of the following: a primary access control device, at least one distributed access control device, at least one control device, at least one user data management device, or at least one analysis device. Example apparatus, device, and medium

[0190] In some example embodiments, a first apparatus (e.g., Figure 1 the first device 110 in Figure 1 that) capable of performing any of the methods 500 may include components for performing the corresponding operations of the method 500. The components may be implemented in any suitable form. For example, the components may be implemented in circuitry or software modules. The first apparatus may be implemented as Figure 1 the first device 110 in

[0191] In some example embodiments, the first apparatus includes: a component for receiving a first message from a second apparatus, the first message for updating or reporting an access number of UEs or PDU sessions associated with a service area corresponding to the second apparatus, the access number being specific to a slice or S-NSSAI; a component for determining a first number of UEs or PDU sessions specific to a slice or S-NSSAI counted by at least one third apparatus such that the access number is verified with the first number; and a component for performing an access control process based at least in part on the first number.

[0192] In some exemplary embodiments, the admission number indicates one of the following: the maximum admission number assigned to the service area, or the current admission number determined by the second device.

[0193] In some example embodiments, it further includes: a component for determining whether it is necessary to verify the admission number according to a preconfigured policy associated with at least one of the following before determining the first number: the threat surface of the second device, S-NSSAI, the identifier of the PLMN corresponding to the first device, the service area, the identifier of the VPLMN corresponding to the second device, or the security control policy of the service area.

[0194] In some example embodiments, it further includes: a component for performing the NSAC process at least partially based on the first message if it is determined that the admission number does not need to be verified.

[0195] In some example embodiments, the component for determining the first number includes: a component for sending a second message to each of at least one third device, the second message being used to request a second number of UEs or PDU sessions associated with the service area, the second number being counted by the corresponding third device in at least one third device and specific to a slice or S-NSSAI; a component for receiving a third message indicating the second number from each of at least one third device; and a component for determining the first number by combining at least one second number received from at least one third device.

[0196] In some exemplary embodiments, the second message includes at least one of the following: S-NSSAI, the identifier of the service area, the identifier of the VPLMN associated with the second device, or at least one identifier of at least one fourth device located in the service area, and each of at least one fourth device is a control device.

[0197] In some example embodiments, it further includes: a component for determining at least one identifier of at least one fourth device according to one of the following mappings: a first mapping between the second device and at least one fourth device, or a second mapping between the service area and at least one fourth device.

[0198] In some exemplary embodiments, the second number is specific to one of the following: the second device, the service area, or at least one fourth device located in the service area, and each of at least one fourth device is a control device.

[0199] In some example embodiments, it further includes: a component for determining at least one third device by one of the following before sending the second message to each of at least one third device: scanning all accessible third devices, or performing a discovery process of the third device according to preconfigured rules.

[0200] In some example embodiments, the component for performing an admission control process based at least in part on a first number includes: a component for comparing the first number with an admission control number; a component for performing an NSAC process based at least in part on a first message if the first number matches the admission control number; and a component for, if the first number does not match the admission control number, performing at least one of the following: stopping the NSAC process; adjusting the admission control number according to the first number; or a component for sending a fourth message to a fifth device, the fourth message indicating that an abnormality has occurred at the second device or in the service area.

[0201] In some example embodiments, the fifth device is a management device.

[0202] In some example embodiments, the first device is a primary admission control device, the second device is a distributed admission control device, and the third device is a user data management device.

[0203] In some example embodiments, the first device further includes a component for performing other operations in some example embodiments of method 500 or the first device 110. In some example embodiments, the device includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first device to perform.

[0204] In some example embodiments, the third device (e.g., Figure 1 the third device 130 in Figure 1 that can perform any of the methods 600) may include components for performing the corresponding operations of method 600. The component can be implemented in any suitable form. For example, the component can be implemented in a circuit or a software module. The third device can be implemented as Figure 1 the third device 130 in

[0205] In some example embodiments, the third device includes: a component for receiving a second message from the first device, the second message for requesting a second number of UEs or PDU sessions associated with a service area corresponding to the second device, the second number being counted by the third device and specific to a slice or S-NSSAI; a component for generating a third message indicating the second number; and a component for sending the third message to the second device.

[0206] In some example embodiments, the second message includes at least one of the following: an NSSAI, an identifier of the service area, an identifier of a VPLMN associated with the second device, or at least one identifier of at least one fourth device located in the service area, each of the at least one fourth device being a control device.

[0207] In some example embodiments, the second number is specific to one of the following: a second device, a service area, at least one fourth device located in the service area, each of the at least one fourth device being a control device.

[0208] In some example embodiments, the third device further comprises: means for receiving a fifth message from a fourth device, the fifth message comprising information about one or more permitted S-NSSAIs, the fifth message being sent by the fourth device in response to the completion of registration for a user equipment, the fourth device being an AMF.

[0209] In some example embodiments, the first device is a primary access control device or an analysis device, the second device is a distributed access control device, and the third device is a user data management device.

[0210] In some example embodiments, the third device further comprises means for performing other operations in some example embodiments of method 600 or the third device 130. In some example embodiments, the means comprises at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the third device to perform.

[0211] In some example embodiments, a fourth device (e.g., Figure 1 the fourth device 140 in) capable of performing any of method 700 may comprise means for performing the corresponding operations of method 700. The means may be implemented in any suitable form. For example, the means may be implemented in a circuit or a software module. The fourth device may be implemented as Figure 1 the fourth device 140 in or be included in Figure 1 the fourth device 140 in.

[0212] In some example embodiments, the fourth device comprises: means for receiving a registration request from a user equipment; and means for sending, in response to the completion of registration for the user equipment, a fifth message comprising information about one or more permitted S-NSSAIs to the third device.

[0213] In some example embodiments, the fourth device is an AMF, and the third device is a user data management device.

[0214] In some example embodiments, the fourth device further comprises means for performing other operations in some example embodiments of method 700 or the fourth device 140. In some example embodiments, the means comprises at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the third device to perform.

[0215] In some example embodiments, a fifth device (e.g., Figure 1 the fifth device 150 in Figure 1 ) that can perform any one of the methods 800 may include components for performing the corresponding operations of the method 800. The components may be implemented in any suitable form. For example, the components may be implemented in a circuit or a software module. The fifth device may be implemented as Figure 1 the fifth device 150 in

[0216] In some example embodiments, the fifth device includes: a component for receiving a fourth message from a first device, the fourth message indicating that an exception has occurred in a second device or in the service area where the second device is located, the second device being a distributed access control device; and a component for triggering a security process to handle the exception.

[0217] In some example embodiments, the first device is a primary access control device or an analysis device, and the fifth device is a management device.

[0218] In some example embodiments, the fifth device further includes components for performing other operations in some example embodiments of the method 800 or the fifth device 150. In some example embodiments, the components include at least one processor; and at least one memory that stores instructions that, when executed by the at least one processor, cause the fourth device to execute.

[0219] In some example embodiments, a sixth device (e.g., Figure 1 the sixth device 160 in Figure 1 ) that can perform any one of the methods 900 may include components for performing the corresponding operations of the method 900. The components may be implemented in any suitable form. For example, the components may be implemented in a circuit or a software module. The sixth device may be implemented as Figure 1 the sixth device 160 in

[0220] In some example embodiments, the sixth device includes: a component for collecting information from a plurality of devices, the information being associated with a plurality of numbers of user equipment or PDU sessions specific to a slice or S-NSSAI; and a component for determining, at least in part based on the information, an operating state of a second device that is a distributed access control device.

[0221] In some example embodiments, the information associated with the plurality of numbers includes at least one of the following: the number of UEs or PDU sessions determined by the respective devices in the plurality of devices, traces recorded on the respective devices in the plurality of devices, or load or congestion information reports generated by the respective devices in the plurality of devices.

[0222] In some example embodiments, the sixth device further includes: a component for sending a fourth message to the fifth device if the operating state is determined to be abnormal, the fourth message indicating that an abnormality has occurred at the second device or in the service area.

[0223] In some example embodiments, the sixth device is an analysis device, and the plurality of devices includes at least one of the following: a main access control device, at least one distributed access control device, at least one control device, at least one user data management device, or at least one analysis device.

[0224] In some example embodiments, the sixth device further includes: a component for performing method 900 or other operations in some example embodiments of the sixth device 160. In some example embodiments, the component includes at least one processor; and at least one memory that stores instructions that, when executed by the at least one processor, cause the fifth device to execute.

[0225] Figure 10 is a simplified block diagram of a device 1000 suitable for implementing example embodiments of the present disclosure. The device 1000 may be provided to implement a communication device, for example, such as Figure 1 shown in the first device 110, the third device 130, the fourth device 140, the fifth device 150, or the sixth device 160. As shown, the device 1000 includes one or more processors 1010, one or more memories 1020 coupled to the processors 1010, and one or more communication modules 1040 coupled to the processors 1010.

[0226] The communication module 1040 is for two-way communication. The communication module 1040 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interface may represent any interface necessary for communicating with other network elements. In some example embodiments, the communication module 1040 may include at least one antenna.

[0227] As a non-limiting example, the processor 1010 may be of any type suitable for a local technical network and may include one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. The device 1000 may have multiple processors, such as an application-specific integrated circuit chip that is subordinate to a clock synchronized with the main processor in time.

[0228] The memory 1020 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1024, electrically programmable read-only memory (EPROM), flash memory, hard disk, optical disc (CD), digital video disc (DVD), optical disc, laser disc, and other magnetic storage and / or optical storage devices. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1022 and other volatile memories that will not persist during a power outage duration.

[0229] The computer program 1030 includes computer-executable instructions executed by the associated processor 1010. The instructions of the program 1030 may include instructions for performing the operations / actions of some example embodiments of the present disclosure. The program 1030 may be stored in a memory (such as ROM 1024). The processor 1010 may execute any suitable actions and processes by loading the program 1030 into the RAM 1022.

[0230] Example embodiments of the present disclosure may be implemented by means of the program 1030 such that the device 1000 may execute any process of the present disclosure as discussed with reference to Figures 3 to 9 Example embodiments of the present disclosure may also be implemented by hardware or a combination of software and hardware.

[0231] In some example embodiments, the program 1030 may be tangibly embodied in a computer-readable medium, which may be included in the device 1000 (such as in the memory 1020) or other storage devices accessible by the device 1000. The device 1000 may load the program 1030 from the computer-readable medium into the RAM 1022 for execution. In some example embodiments, the computer-readable medium may include any type of non-transitory storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. As used herein, the term "non-transitory" is a limitation of the medium itself (i.e., tangible rather than a signal), rather than a limitation on data storage persistence (e.g., RAM vs. ROM).

[0232] Figure 11 An example of a computer-readable medium 1100 is shown, which may be in the form of a CD, DVD, or other optical storage disc. The computer-readable medium 1100 has the program 1030 stored thereon.

[0233] Generally, the various embodiments of the present disclosure may be implemented in hardware or special-purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device. Although the various aspects of the embodiments of the present disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, by way of non-limiting example, the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, special-purpose circuits or logic, general-purpose hardware or controllers, or other computing devices, or some combination thereof.

[0234] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer-readable medium (such as, a non-transitory computer-readable medium). The computer program product includes computer-executable instructions, such as those included in program modules, that are executed in a device on a target physical or virtual processor to perform any of the methods described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The functions of the program modules may be combined or split among the program modules as needed in various embodiments. The machine-executable instructions for the program modules may be executed within a local or distributed device. In a distributed device, the program modules may be located in local and remote storage media.

[0235] The program code for performing the methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus such that the program code, when executed by the processor or controller, causes the implementation of the functions / operations specified in the flowchart and / or block diagram. The program code may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0236] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier such that a device, apparatus, or processor can perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.

[0237] A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a computer-readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0238] Moreover, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these details should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments, unless expressly stated otherwise.

[0239] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it is to be understood that the disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. A first device, include: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the first device to at least perform: receiving a first message from a second device, the first message being used to update or report an admitted number of user equipment (UE) or packet data unit (PDU) sessions associated with a service area corresponding to the second device, the admitted number being specific to a slice or single network slice selection assistance information (S-NSSAI); as well as determining a first number of UE or PDU sessions specific to the slice or the S-NSSAI counted by at least one third device, such that the admission number is verified with the first number; and An admission control procedure is performed based at least in part on the first number.

2. The first device according to claim 1, wherein the admission number indicates one of the following: the maximum number of admissions allocated to the service area, or A current admission number determined by the second device.

3. The first device according to claim 1, wherein the first device is further configured to perform: Before determining the first number, determining whether the admission number needs to be verified according to a preconfigured policy associated with at least one of the following: the threat surface of the second device, The S-NSSAI, an identifier of a public land mobile network (PLMN) corresponding to the first device; The service area, an identifier of a visited PLMN (VPLMN) corresponding to the second device, or The security control policy of the service area.

4. The first device according to claim 3, wherein the first device is further configured to perform: If it is determined that verification of the admission number is not required, a network slice admission control (NSAC) process is performed based at least in part on the first message.

5. The first device according to claim 1, wherein determining the first number include: sending a second message to each of the at least one third device, the second message being used to request a second number of UE or PDU sessions associated with the service area, the second number being counted by a corresponding third device of the at least one third device and being specific to the slice or the S-NSSAI; receiving, from each of the at least one third device, a third message indicating the second number; as well as The first number is determined by combining at least one second number received from the at least one third device.

6. The first device according to claim 5, wherein the second message comprises at least one of the following: The S-NSSAI, an identification of the service area, an identity of a visited PLMN (VPLMN) associated with the second device, or At least one identification of at least one fourth device located in the service area, each of the at least one fourth device being a control device.

7. The first device of claim 6, wherein the first device is further configured to perform: Determine the at least one identifier of the at least one fourth device according to one of the following mapping relationships: a first mapping of the second device and the at least fourth device, or A second mapping of the service area and the at least fourth device.

8. The first device of claim 5, wherein the second number is specific to the second device, the service area, or At least one fourth device is located in the service area, and each of the at least one fourth device is a control device.

9. The first device of claim 5, wherein the first device is further configured to perform: Before sending the second message to each of the at least one third device, determining the at least one third device by one of the following: Scan all accessible third-party devices, or According to the preconfigured rules, a discovery process of the third device is performed.

10. The first device of claim 1, wherein the admission control process is performed based at least in part on the first number. include: comparing the first number with the admission control number; If the first number matches the admission control number, performing a network slice admission control (NSAC) procedure based at least in part on the first message; and If the first number does not match the admission control number, performing at least one of the following: stopping the NSAC process; Adjust the admission control number according to the first number; or A fourth message is sent to a fifth device, the fourth message indicating that an abnormality has occurred at the second device or in the service area. The first device according to claim 10 , wherein the fifth device is a management device.

12. The first device according to any one of claims 1 to 11, wherein the first device is a master admission control device, the second device is a distributed admission control device, and the third device is a user data management device.

13. A third device, include: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the third device to at least perform: receiving a second message from the first device, the second message being used to request a second number of user equipment (UE) or packet data unit (PDU) sessions associated with a service area corresponding to the second device, the second number being counted by the third device and being specific to a slice or single network slice selection assistance information (S-NSSAI); generating a third message indicating the second number; as well as The third message is sent to the second device.

14. The third device according to claim 13, wherein the second message comprises at least one of the following: Said-NSSAI, an identification of the service area, an identity of a visited PLMN (VPLMN) associated with the second device, or At least one identification of at least one fourth device located in the service area, each of the at least one fourth device being a control device.

15. The third device of claim 13, wherein the second number is specific to one of: the second device, The service area, At least one fourth device is located in the service area, and each of the at least one fourth device is a control device.

16. The third device according to claim 13, wherein the third device is further configured to execute: A fifth message is received from a fourth device, the fifth message including information about one or more allowed single network slice selection assistance information (S-NSSAI), the fifth message being sent by the fourth device in response to registration completion of a user equipment, the fourth device being an access and mobility management function (AMF).

17. The third device according to any one of claims 13 to 16, wherein the first device is a master admission control device or an analysis device, the second device is a distributed admission control device, and the third device is a user data management device.

18. A fourth device, include: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the fourth device to at least perform: receiving a registration request from a user device; as well as In response to the registration of the user equipment being completed, a fifth message is sent to the third device, the fifth message including information about one or more allowed single network slice selection assistance information (S-NSSAI).

19. The fourth device according to claim 18, wherein the fourth device is an access and mobility management function (AMF) and the third device is a user data management device.

20. A fifth device, include: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the fifth device to at least perform: receiving a fourth message from the first device, the fourth message indicating that an exception occurs in the second device or in a service area where the second device is located, the second device being a distributed admission control device; as well as A security process is triggered to handle the exception.

21. The fifth device according to claim 20, wherein the first device is a master admission control device or an analysis device, and the fifth device is a management device.

22. A sixth device, include: at least one processor; as well as at least one memory storing instructions that, when executed by the at least one processor, cause the sixth device to at least perform: collecting information from a plurality of devices, the information associated with a plurality of numbers of user devices or packet data unit (PDU) sessions specific to a slice or single network slice selection assistance information (S-NSSAI); and An operational status of a second device that is a distributed admission control device is determined based at least in part on the information.

23. The sixth device according to claim 22, wherein the information associated with the plurality of numbers comprises at least one of the following: a number of UE or PDU sessions determined by a corresponding device of the plurality of devices, a trace recorded on a corresponding device in the plurality of devices, or A load or congestion information report generated by a corresponding device of the plurality of devices.

24. The sixth device according to claim 22, wherein the sixth device is further configured to perform: If the operation status is determined to be abnormal, a fourth message is sent to a fifth device, the fourth message indicating that an abnormality has occurred at the second device or in the service area.

25. The sixth device according to any one of claims 22 to 24, wherein the sixth device is an analysis device, and the plurality of devices comprises at least one of the following: Master admission control device, at least one distributed admission control device, at least one control device, at least one user data management device; or At least one analytical device.

26. A method, include: receiving, at a first device, from a second device, a first message for updating or reporting an admitted number of user equipment (UE) or packet data unit (PDU) sessions associated with a service area corresponding to the second device, the admitted number being specific to a slice or single network slice selection assistance information (S-NSSAI); as well as determining a first number of UE or PDU sessions specific to the slice or the S-NSSAI counted by at least one third device, such that the admission number is verified with the first number; and An admission control procedure is performed based at least in part on the first number.

27. The method of claim 26, wherein the admission number indicates one of: the maximum number of admissions allocated to the service area, or A current admission number determined by the second device.

28. The method according to claim 26, further comprising: include: Before determining the first number, determining whether the admission number needs to be verified according to a preconfigured policy associated with at least one of the following: the threat surface of the second device, The S-NSSAI, an identifier of a public land mobile network (PLMN) corresponding to the first device; The service area, an identifier of a visited PLMN (VPLMN) corresponding to the second device, or The security control policy of the service area.

29. The method according to claim 28, further comprising: include: If it is determined that verification of the admission number is not required, a network slice admission control (NSAC) process is performed based at least in part on the first message.

30. The method of claim 26, wherein determining the first number include: sending a second message to each of the at least one third device, the second message being used to request a second number of UE or PDU sessions associated with the service area, the second number being counted by a corresponding third device of the at least one third device and being specific to the slice or the S-NSSAI; receiving, from each of the at least one third device, a third message indicating the second number; as well as The first number is determined by combining at least one second number received from the at least one third device.

31. The method of claim 30, wherein the second message comprises at least one of the following: The S-NSSAI, an identification of the service area, an identity of a visited PLMN (VPLMN) associated with the second device, or At least one identification of at least one fourth device located in the service area, each of the at least one fourth device being a control device.

32. The method according to claim 31, further comprising: include: Determine the at least one identifier of the at least one fourth device according to one of the following mapping relationships: a first mapping of the second device and the at least fourth device, or A second mapping of the service area and the at least fourth device.

33. The method of claim 30, wherein the second number is specific to one of: the second device, the service area, or At least one fourth device is located in the service area, and each of the at least one fourth device is a control device.

34. The method according to claim 30, further comprising: include: Before sending the second message to each of the at least one third device, determining the at least one third device by one of the following: Scan all accessible third-party devices, or According to the preconfigured rules, a discovery process of the third device is performed.

35. The method of claim 26, wherein the admission control process is performed based at least in part on the first number include: comparing the first number with the admission control number; If the first number matches the admission control number, performing a network slice admission control (NSAC) procedure based at least in part on the first message; and If the first number does not match the admission control number, performing at least one of the following: stopping the NSAC process; Adjust the admission control number according to the first number; or A fourth message is sent to a fifth device, the fourth message indicating that an abnormality has occurred in the second device or in the service area. The method of claim 35 , wherein the fifth device is a management device.

37. The method according to any one of claims 26 to 36, wherein the first device is a master admission control device, the second device is a distributed admission control device, and the third device is a user data management device.

38. A method, include: receiving, at a third device and from the first device, a second message for requesting a second number of user equipment (UE) or packet data unit (PDU) sessions associated with a service area corresponding to the second device, the second number being counted by the third device and being specific to a slice or single network slice selection assistance information (S-NSSAI); generating a third message indicating the second number; as well as The third message is sent to the second device.

39. The method of claim 38, wherein the second message comprises at least one of: Said-NSSAI, an identification of the service area, an identity of a visited PLMN (VPLMN) associated with the second device, or At least one identification of at least one fourth device located in the service area, each of the at least one fourth device being a control device.

40. The method of claim 38, wherein the second number is specific to one of: the second device, The service area, At least one fourth device is located in the service area, and each of the at least one fourth device is a control device.

41. The method according to claim 38, further comprising: include: A fifth message is received from a fourth device, the fifth message including information about one or more allowed single network slice selection assistance information (S-NSSAI), the fifth message being sent by the fourth device in response to registration completion of a user equipment, the fourth device being an access and mobility management function (AMF).

42. The method according to any one of claims 38 to 41, wherein the first device is a master admission control device or an analysis device, the second device is a distributed admission control device, and the third device is a user data management device.

43. A method, include: receiving, at a fourth device, a registration request from a user device; as well as In response to the registration of the user equipment being completed, a fifth message is sent to the third device, the fifth message including information about one or more allowed single network slice selection assistance information (S-NSSAI).

44. The method of claim 43, wherein the fourth device is an Access and Mobility Management Function (AMF) and the third device is a User Data Management Device.

45. A method, include: receiving, at a fifth device, a fourth message from a first device, the fourth message indicating that an abnormality has occurred at a second device or at a service area where the second device is located, the second device being a distributed admission control device; as well as A security process is triggered to handle the exception.

46. ​​The method of claim 45, wherein the first device is a master admission control device or an analysis device, and the fifth device is a management device.

47. A method, include: collecting, at a sixth device, information from a plurality of devices, the information associated with a plurality of numbers of user devices or packet data unit (PDU) sessions specific to a slice or single network slice selection assistance information (S-NSSAI); and An operational status of a second device that is a distributed admission control device is determined based at least in part on the information.

48. The method of claim 47, wherein the information associated with the plurality of numbers comprises at least one of: a number of UE or PDU sessions determined by a corresponding device of the plurality of devices, a trace recorded on a corresponding device in the plurality of devices, or A load or congestion information report generated by a corresponding device of the plurality of devices.

49. The method according to claim 47, further comprising: include: If the operating state is determined to be abnormal, a fourth message is sent to a fifth device, the fourth message indicating that the abnormality has occurred at the second device or in the service area.

50. The method of any one of claims 47 to 49, wherein the sixth device is an analytical device, and the plurality of devices comprises at least one of: Master admission control device, at least one distributed admission control device, at least one control device, at least one user data management device; or At least one analytical device.

51. A first device, include: means for receiving a first message from a second device, the first message being for updating or reporting an admitted number of user equipment (UE) or packet data unit (PDU) sessions associated with a service area corresponding to the second device, the admitted number being specific to a slice or single network slice selection assistance information (S-NSSAI); as well as means for determining a first number of UE or PDU sessions specific to said slice or said S-NSSAI counted by at least one third means such that said admission number is verified with said first number; as well as Means for performing an admission control procedure based at least in part on the first number.

52. A third device, include: means for receiving a second message from the first device, the second message being for requesting a second number of UEs or packet data unit (PDU) sessions associated with a service area corresponding to the second device, the second number being counted by the third device and being specific to a slice or single network slice selection assistance information (S-NSSAI); means for generating a third message indicating said second number; as well as Means for sending the third message to the second device.

53. A fourth device, include: means for receiving a registration request from a user device; as well as A component for sending a fifth message to a third device in response to completion of registration for the user equipment, the fifth message including information about one or more allowed single network slice selection assistance information (S-NSSAI).

54. A fifth device, include: a component for receiving a fourth message from a first device, the fourth message indicating that an abnormality has occurred at the second device or at a service area where the second device is located, the second device being a distributed admission control device; as well as A component for triggering a safety procedure to handle the exception.

55. A sixth device, include: means for collecting information from a plurality of devices, the information being associated with a plurality of numbers of user equipment or packet data unit (PDU) sessions specific to a slice or single network slice selection assistance information (S-NSSAI); as well as Means for determining an operational status of a second device as a distributed admission control device based at least in part on the information.

56. A computer-readable medium comprising instructions stored thereon, the instructions being used to cause an apparatus to at least perform the method of any one of claims 26 to 37, or the method of any one of claims 38 to 42, or the method of any one of claims 43 to 44, or the method of any one of claims 45 to 46, or the method of any one of claims 47 to 50.