Access control method and network side equipment
Through the first network function, the information is received from the second network function and the terminal registration request is judged, or the information is obtained from the access network node and sent to the second network function, and the voice resource request is processed in combination with the third network function, the problem of terminal access control in indirect network sharing is solved, and secure and compliant access and voice service management is realized.
Patent Information
- Application Number
- CN202410048233.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-11
- Publication Date
- 2025-07-11
AI Technical Summary
In the indirect network sharing scenario, how to effectively control the terminal to access the home network services through the participant network, especially when the home network is shared with multiple participant networks, how to ensure that only terminals that have signed indirect network sharing services can access.
The first network function receives network information from the second network function, and accepts or rejects the terminal's registration request based on the information, or obtains information from the access network node and sends information to the second network function to assist in judging the access permissions of the terminal. At the same time, the third network function processes the terminal's voice resource request, and realizes effective control of terminal access and voice services.
It realizes effective control of terminal access, ensuring that only terminals that have signed indirect network sharing services can access, improving the security and compliance of network access, and effectively managing voice services.
Smart Images

Figure CN120302378A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technologies, and particularly relates to an access control method and a network-side device. Background Art
[0002] In indirect network sharing, when a terminal accesses a network, it can request to access a participating party network, and the participating party network controls the terminal to use the network services of the home network through the participating party network. Specifically, when the participating party network receives an access request from the terminal, it can determine whether the terminal is a terminal of the participating party network. If not, it further determines whether the terminal has subscribed to the indirect network sharing service. If the terminal has subscribed to the indirect network sharing service, it allows the terminal to access; if the terminal has not subscribed to the indirect network sharing service, it does not allow the terminal to access. However, in some scenarios, the home network may perform network sharing with multiple participating party networks simultaneously. In this case, not all terminals of the home network can access the network through these participating parties. Therefore, how to control the access of the participating parties needs to be solved urgently. Summary of the Invention
[0003] Embodiments of this application provide an access control method and a network-side device, which can solve the problem of how a participating party network controls terminal access in indirect network sharing.
[0004] In a first aspect, an access control method is provided, which is executed by a first network function. The method includes:
[0005] The first network function performs at least one of the following:
[0006] A first operation;
[0007] A second operation;
[0008] Wherein, the first operation includes:
[0009] Receiving a registration request from a terminal;
[0010] Receiving first network information from a second network function;
[0011] Accepting or rejecting the registration request according to the first network information;
[0012] Wherein, the second operation includes:
[0013] Receiving second network information from an access network node, where the second network information indicates the network selected by the terminal;
[0014] Sending the second network information to the second network function.
[0015] In a second aspect, an access control method is provided, which is executed by a second network function. The method includes:
[0016] The second network function performs at least one of the following:
[0017] A third operation;
[0018] A fourth operation;
[0019] Wherein, the third operation includes:
[0020] Sending first network information to the first network function;
[0021] Wherein, the fourth operation includes:
[0022] Receiving second network information sent by the first network function;
[0023] Sending second indication information to the first network function based on the second network information, the second indication information being used to indicate rejection of registration, acceptance of registration, non - permission of registration, permission of registration, registration error, registration failure, or successful registration.
[0024] In a third aspect, an access control method is provided, which is executed by a third network function, and the method includes:
[0025] The third network function receives first information from the first network function;
[0026] The third network function receives a voice resource request from the fourth network function;
[0027] The third network function processes the voice resource request according to the first information.
[0028] In a fourth aspect, an access control device is provided, including at least one of the following:
[0029] A first module;
[0030] A second module;
[0031] Wherein, the first module includes:
[0032] A first receiving module, configured to receive a registration request from a terminal; receive first network information from the second network function;
[0033] A processing module, configured to accept or reject the registration request according to the first network information;
[0034] Wherein, the second module includes:
[0035] A second receiving module, configured to receive second network information from an access network node, the second network information indicating the network selected by the terminal;
[0036] A second sending module, configured to send the second network information to the second network function.
[0037] In a fifth aspect, an access control device is provided, including at least one of the following:
[0038] A third module;
[0039] A fourth module;
[0040] Wherein, the third module includes:
[0041] A third sending module, configured to send first network information to a first network function;
[0042] Wherein, the fourth module includes:
[0043] A fourth receiving module, configured to receive second network information sent by the first network function;
[0044] A fourth sending module, configured to send second indication information to the first network function based on the second network information, where the second indication information is used to indicate rejection of registration, acceptance of registration, non - permission of registration, permission of registration, registration error, registration failure, or successful registration.
[0045] In a sixth aspect, an access control device is provided, including:
[0046] A receiving module, configured to receive first information from a first network function and receive a voice resource request from a fourth network function;
[0047] A processing module, configured to process the voice resource request according to the first information.
[0048] In a seventh aspect, a network - side device is provided, the network - side device includes a processor and a memory, the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, it implements the steps of the method described in the first aspect, or implements the steps of the method described in the second aspect, or implements the steps of the method described in the third aspect.
[0049] In an eighth aspect, a network-side device is provided, including a processor and a communication interface. The communication interface is configured to receive a registration request from a terminal and receive first network information from a second network function; the processor is configured to accept or reject the registration request according to the first network information; or, the communication interface is configured to receive second network information from an access network node, where the second network information indicates a network selected by the terminal, and send the second network information to the second network function; or, the communication interface is configured to send the first network information to a first network function; or, the communication interface is configured to receive second network information sent by the first network function, and send second indication information to the first network function based on the second network information, where the second indication information is used to indicate rejection of registration, acceptance of registration, non-permission of registration, permission of registration, registration error, registration failure, or successful registration; or, the communication interface is configured to receive first information from the first network function and receive a voice resource request from a fourth network function; the processor is configured to process the voice resource request according to the first information.
[0050] In a ninth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect are implemented.
[0051] In a tenth aspect, a wireless communication system is provided, including: a terminal and a network-side device, where the network-side device can be configured to execute the steps of the method described in the first aspect, or execute the steps of the method described in the second aspect, or execute the steps of the method described in the third aspect.
[0052] In an eleventh aspect, a chip is provided, including a processor and a communication interface, where the communication interface is coupled to the processor, and the processor is configured to run a program or instruction to implement the method described in the first aspect, or implement the method described in the second aspect, or implement the method described in the third aspect.
[0053] In a twelfth aspect, a computer program / program product is provided, where the computer program / program product is stored in a storage medium, and the computer program / program product is executed by at least one processor to implement the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect, or implement the steps of the method described in the third aspect.
[0054] In the embodiments of the present application, when a terminal requests to use the network services of the home network through a participating network, the first network function can receive the first network information from the second network function and accept or reject the registration request of the terminal according to the first network information. Thus, effective control over the access of the terminal can be achieved. Alternatively, the first network function can also obtain the second network information from the access network node and send the second network information to the second network function to assist the second network function in determining whether to accept or reject the registration request of the terminal. Thus, effective control over the access of the terminal can also be achieved. After the terminal is successfully registered or successfully accessed, since the third network function can process the voice resource request of the terminal according to the first information, effective control over the voice service can also be achieved. Description of the Drawings
[0055] Figure 1 is a schematic diagram of a wireless communication system according to an embodiment of the present application;
[0056] Figure 2 is a schematic flowchart of an access control method according to an embodiment of the present application;
[0057] Figure 3 is a schematic flowchart of an access control method according to an embodiment of the present application;
[0058] Figure 4 is a schematic flowchart of an access control method according to an embodiment of the present application;
[0059] Figure 5 is a schematic flowchart of an access control method according to an embodiment of the present application;
[0060] Figure 6 is a schematic flowchart of an access control method according to an embodiment of the present application;
[0061] Figure 7 is a schematic flowchart of an access control method according to an embodiment of the present application;
[0062] Figure 8 is a schematic flowchart of an access control method according to an embodiment of the present application;
[0063] Figure 9 is a schematic flowchart of an access control method according to an embodiment of the present application;
[0064] Figure 10 is a schematic flowchart of a voice service control method according to an embodiment of the present application;
[0065] Figure 11 is a schematic structural diagram of an access control device according to an embodiment of the present application;
[0066] Figure 12It is a schematic structural diagram of an access control device according to an embodiment of the present application;
[0067] Figure 13 It is a schematic structural diagram of an access control device according to an embodiment of the present application;
[0068] Figure 14 It is a schematic structural diagram of a communication device according to an embodiment of the present application;
[0069] Figure 15 It is a schematic structural diagram of a network-side device according to an embodiment of the present application. Detailed implementation manners
[0070] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.
[0071] The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first" and "second" are usually of the same type, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "or" in the present application means at least one of the connected objects. For example, "A or B" covers three scenarios, namely, Scenario 1: including A and not including B; Scenario 2: including B and not including A; Scenario 3: including both A and B. The character " / " generally indicates an "or" relationship between the associated objects before and after.
[0072] The term "indicate" in the present application can be either a direct indication (or an explicit indication) or an indirect indication (or an implicit indication). Among them, a direct indication can be understood as that the sender clearly tells the receiver specific information, operations to be performed, or request results, etc. in the sent indication; an indirect indication can be understood as that the receiver determines the corresponding information according to the indication sent by the sender, or makes a judgment and determines the operations to be performed or request results, etc. according to the judgment result.
[0073] It should be noted that the technology described in the embodiments of the present application is not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, and can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used in the above-mentioned systems and radio technologies, as well as in other systems and radio technologies. The following description describes the New Radio (NR) system for example purposes, and the NR term is used in most of the following descriptions, but these technologies can also be applied to systems other than the NR system, such as the 6th Generation (6 th Generation, 6G) communication system.
[0074] In the embodiments of the present application, the first network function may be a network-side device of the participating network. Optionally, in some embodiments, the first network function may be the AMF of the participating network. The second network function may be a network-side device of the home network. Optionally, in some embodiments, the second network function may be the UDM of the home network. The third network function may be a network-side device of the participating network. Optionally, in some embodiments, the third network function may be the SMF or UPF of the participating network.
[0075] Figure 1The block diagram of a wireless communication system to which the embodiments of the present application can be applied is shown. The wireless communication system includes a terminal 11 and a network-side device 12. Among them, the terminal 11 can be a mobile phone, a tablet personal computer, a laptop computer, a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device, a flight vehicle, a vehicle user equipment (VUE), a shipborne device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, TVs, washing machines, or furniture, etc.), a game console, a personal computer (PC), a teller machine, or a self-service machine, etc. Wearable devices include: smart watches, smart bracelets, smart earphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart ankle chains, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle user equipment can also be called a vehicle terminal, a vehicle controller, a vehicle module, a vehicle component, a vehicle chip, or a vehicle unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiments of the present application. The network-side device 12 can include an access network device or a core network device. Among them, the access network device can also be called a radio access network (RAN) device, a radio access network function, or a radio access network unit. The access network device can include a base station, a wireless local area network (WLAN) access point (AP), or a wireless fidelity (WiFi) node, etc.Among them, the base station may be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), home Node B (HNB), home evolved Node B, Transmission Reception Point (TRP), or some other suitable term in the art. As long as the same technical effect is achieved, the base station is not limited to specific technical terms. It should be noted that in the embodiments of this application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.
[0076] The core network device may include but is not limited to at least one of the following: core network node, core network function, Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), etc. It should be noted that in the embodiments of this application, only the core network devices in the NR system are taken as examples for introduction, and the specific types of core network devices are not limited.but not limited to at least one of the following: core network node, core network function, Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), etc. It should be noted that in the embodiments of the present application, only the core network devices in the NR system are taken as examples for introduction, and the specific types of core network devices are not limited.
[0077] The access control method and network-side device provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings through some embodiments and their application scenarios.
[0078] As Figure 2 shown, the embodiments of the present application provide an access control method 200. This access control method can be executed by a first network function. In other words, this access control method can be executed by software or hardware installed in the first network function. The access control method includes the following steps.
[0079] S202: The first network function receives a registration request from the terminal.
[0080] When a terminal wants to use the network services of its home network through a participating party network, the terminal can send a registration request to a first network function under the participating party network, and the first network function can receive the registration request from the terminal.
[0081] Optionally, in some embodiments, the registration request of the terminal may carry Public Land Mobile Network (PLMN) information or Non-Public Network (NPN) information selected by the terminal, such as a PLMN ID or an NPN ID.
[0082] S204: The first network function receives first network information from a second network function.
[0083] When the first network function receives the registration request of the terminal, it can receive the first network information from the second network function. The first network information can be used by the first network function to determine whether to allow the terminal to register or access.
[0084] Optionally, in some embodiments, the first network information may include at least one of the following:
[0085] First PLMN information;
[0086] First NPN information.
[0087] The first PLMN information may be information of a PLMN that allows the terminal to access, such as a PLMN ID or a list of PLMN IDs, etc., which is not specifically limited here. The first NPN information may be information of an NPN that allows the terminal to access, such as an NPN ID or a list of NPN IDs, etc., which is also not specifically limited here.
[0088] S206: The first network function accepts or rejects the registration request according to the first network information.
[0089] After receiving the first network information, the first network function can accept or reject the registration request of the terminal according to the first network information. For example, if the first network information includes the first PLMN information, and the first PLMN information includes a PLMN ID that allows the terminal to access, and this PLMN ID includes the PLMN ID carried in the registration request of the terminal, then the first network function can accept the registration request of the terminal. Conversely, if this PLMN ID does not include the PLMN ID carried in the registration request of the terminal, then the first network function can reject the registration request of the terminal.
[0090] Optionally, in some embodiments, when the first network function receives a registration request from a terminal, it may further send first indication information to the second network function. The first indication information may be used to indicate at least one of whether the first network function supports or does not support receiving first network information, supports or does not support processing first network information, supports or does not support network sharing, and supports or does not support indirect network sharing. For example, the first network function may send indication information about its capabilities of supporting or not supporting network sharing and indirect network sharing to the second network function. For the second network function, after receiving the first indication information, it may determine whether to send the first network information to the first network function based on the first indication information. For example, if the first indication information indicates that the first network function supports receiving or processing the first network information, and supports network sharing or indirect network sharing, then the second network function may send the first network information to the first network function; if the first indication information indicates that the first network function does not support receiving or processing the first network information, and does not support network sharing or indirect network sharing, then the second network function may not send the first network information to the first network function. For the first network function, if it receives the first network information, it may accept or reject the terminal's registration request based on the first network information; if it does not receive the first network information, it may reject the terminal's registration request.
[0091] Optionally, in some embodiments, when the first network function receives a registration request from a terminal, it may also receive second network information from an access network node. The access network node may be a base station. The second network information may indicate the network selected by the terminal. Optionally, the second network information may include at least one of the following:
[0092] Second PLMN information;
[0093] Second NPN information.
[0094] The second PLMN information may be information about the PLMN selected by the terminal, such as a PLMN ID, etc., which is not specifically limited here. The second NPN information may be information about the NPN selected by the terminal, such as an NPN ID, etc., which is also not specifically limited here.
[0095] When the first network function receives the second network information from the access network node, when accepting or rejecting the terminal's registration request based on the first network information, it may specifically accept or reject the terminal's registration request based on the first network information and the second network information. For example, the first network information includes first PLMN information, and the second network information includes second PLMN information. If the first PLMN information includes the second PLMN information, then the first network function may accept the terminal's registration request; conversely, if the first PLMN information does not include the second PLMN information, then the first network function may reject the terminal's registration request.
[0096] Optionally, in some embodiments, the first network function may further perform the following operations:
[0097] Send a first piece of information to a third network function, where the first piece of information is used to indicate processing of a voice resource request based on the first piece of information.
[0098] Specifically, the first network function may send the first piece of information to the third network function when receiving a registration request from a terminal. For the third network function, after receiving the first piece of information, it may process the voice resource request according to the first piece of information. For the specific implementation manner of the third network function processing the voice resource request according to the first piece of information, reference may be made to Figure 8 the embodiments shown, which will not be elaborated here in detail.
[0099] In the embodiments of the present application, when a terminal requests to use network services of a home network through a participating party network, the first network function may receive first network information from a second network function and accept or reject the registration request of the terminal according to the first network information, thereby effectively controlling the access of the terminal. Optionally, after the terminal is successfully registered or successfully accessed, since the third network function may process the voice resource request of the terminal according to the first piece of information, effective control of voice services may also be achieved.
[0100] As Figure 3 shown, the embodiments of the present application provide an access control method 300. This access control method may be executed by the first network function. In other words, this access control method may be executed by software or hardware installed in the first network function. The access control method includes the following steps.
[0101] S302: The first network function receives second network information from an access network node, where the second network information indicates the network selected by the terminal.
[0102] When a terminal requests to use network services of a home network through a participating party network, the access network node may send the second network information to the first network function under the participating party network, and the first network function may receive the second network information from the access network node. The access network node may be a base station. The second network information may indicate the network selected by the terminal.
[0103] Optionally, in some embodiments, the second network information includes at least one of the following:
[0104] Second PLMN information;
[0105] Second NPN information.
[0106] The second PLMN information may be information of the PLMN selected by the terminal, such as the PLMN ID, etc., which is not specifically limited here. The second NPN information may be information of the NPN selected by the terminal, such as the NPN ID, etc., which is also not specifically limited here.
[0107] S304: The first network function sends second network information to the second network function.
[0108] In the case of receiving the second network information, the first network function may send the second network information to the second network function. The second network information may assist the second network function in determining whether to allow the terminal to register or access.
[0109] Optionally, in some embodiments, after sending the second network information to the second network function, the first network function may further perform the following operations:
[0110] Receive second indication information from the second network function, where the second indication information is used to indicate rejection of registration, acceptance of registration, non - allowance of registration, allowance of registration, registration error, registration failure, or registration success.
[0111] In the case of receiving the second indication information, the first network function may reject or accept the registration request of the terminal according to the second indication information. For example, if the second indication information indicates rejection of registration, non - allowance of registration, registration error, or registration failure, the first network function may reject the registration request of the terminal; if the second indication information indicates allowance of registration or registration success, the first network function may accept the registration request of the terminal.
[0112] Optionally, in some embodiments, the first network function may further perform the following operations:
[0113] Send first information to the third network function, where the first information is used to indicate processing of a voice resource request based on the first information.
[0114] Specifically, the first network function may send the first information to the third network function in the case of accepting the registration request of the terminal. For the third network function, after receiving the first information, it may process the voice resource request according to the first information. The specific implementation manner of the third network function processing the voice resource request according to the first information may refer to Figure 8 the embodiments shown, which will not be elaborated here in detail.
[0115] In an embodiment of the present application, when a terminal requests to use network services of a home network through a participating party network, a first network function may obtain second network information from an access network node and send the second network information to a second network function to assist the second network function in determining whether to accept or reject the terminal's registration request. Thus, effective control of the terminal's access can be achieved. Optionally, after the terminal successfully registers or accesses, since a third network function can process the terminal's voice resource request according to the first information, effective control of voice services can also be implemented.
[0116] As Figure 4 shown, an embodiment of the present application provides an access control method 400. This access control method may be executed by a first network function. In other words, this access control method may be executed by software or hardware installed in the first network function. The access control method includes the following steps.
[0117] S402: The first network function receives a registration request from the terminal.
[0118] When the terminal wants to use network services of the home network through the participating party network, the terminal may send a registration request to the first network function under the participating party network, and the first network function may receive the registration request from the terminal.
[0119] Optionally, in some embodiments, the terminal's registration request may carry PLMN information or NPN information selected by the terminal, such as a PLMN ID or an NPN ID.
[0120] S404: The first network function receives second network information from the access network node, and the second network information indicates the network selected by the terminal.
[0121] The access network node may be a base station. Optionally, the second network information may include at least one of the following:
[0122] Second PLMN information;
[0123] Second NPN information.
[0124] The second PLMN information may be information of the PLMN selected by the terminal, such as a PLMN ID, etc., which is not specifically limited here. The second NPN information may be information of the NPN selected by the terminal, such as an NPN ID, etc., which is also not specifically limited here.
[0125] S406: The first network function sends the second network information to the second network function.
[0126] When the first network function receives the second network information, it can send the second network information to the second network function. The second network information can assist the second network function in determining whether to allow the terminal to register or access.
[0127] S408: The first network function receives the first network information from the second network function.
[0128] The first network information can be used by the first network function to determine whether to allow the terminal to register or access. Optionally, in some embodiments, the first network information may include at least one of the following:
[0129] The first PLMN information;
[0130] The first NPN information.
[0131] The first PLMN information may be the information of the PLMN that allows the terminal to access, such as the PLMN ID or a list of PLMN IDs, etc., which is not specifically limited here. The first NPN information may be the information of the NPN that allows the terminal to access, such as the NPN ID or a list of NPN IDs, etc., which is also not specifically limited here.
[0132] S410: The first network function accepts or rejects the registration request according to the first network information.
[0133] After receiving the first network information, the first network function can accept or reject the terminal's registration request according to the first network information. For example, if the first network information includes the first PLMN information, and the first PLMN information includes the PLMN ID that allows the terminal to access, and this PLMN ID includes the PLMN ID selected by the terminal, then the first network function can accept the terminal's registration request. Conversely, if this PLMN ID does not include the PLMN ID selected by the terminal, then the first network function can reject the terminal's registration request.
[0134] Optionally, in some embodiments, the first network function accepts or rejects the registration request according to the first network information, which may be to accept or reject the registration request according to the first network information and the second network information. For example, if the first network information includes the first PLMN information and the second network information includes the second PLMN information, if the first PLMN information includes the second PLMN information, then the first network function can accept the terminal's registration request. Conversely, if the first PLMN information does not include the second PLMN information, then the first network function can reject the terminal's registration request.
[0135] Optionally, in some embodiments, the first network function may also receive second indication information from the second network function, where the second indication information is used to indicate rejection of registration, acceptance of registration, non - permission for registration, permission for registration, registration error, registration failure, or registration success. When accepting or rejecting the terminal's registration request, the first network function may accept or reject the terminal's registration request according to the second indication information. For example, if the second indication information indicates rejection of registration, non - permission for registration, registration error, or registration failure, the first network function may reject the terminal's registration request; if the second indication information indicates permission for registration or registration success, the first network function may accept the terminal's registration request. Alternatively, the terminal's registration request may also be accepted or rejected according to the second indication information and the first network information. For example, if the second indication information indicates permission for registration and the first network information includes first PLMN information, if the first PLMN information includes the PLMN ID selected by the terminal, the first network function may accept the terminal's registration request; if the first PLMN information does not include the PLMN ID selected by the terminal, the first network function may reject the terminal's registration request.
[0136] Optionally, in some embodiments, when the first network function sends second network information to the second network function, it may also send first indication information to the second network function, where the first indication information may be used to indicate at least one of whether the first network function supports or does not support receiving the first network information, supports or does not support processing the first network information, supports or does not support network sharing, and supports or does not support indirect network sharing. For example, the first network function may send indication information about its capabilities of supporting or not supporting network sharing and indirect network sharing to the second network function. For the second network function, after receiving the first indication information, it may determine whether to send the first network information to the first network function according to the first indication information. For example, if the first indication information indicates that the first network function supports receiving or processing the first network information, supports network sharing or indirect network sharing, the second network function may send the first network information to the first network function; if the first indication information indicates that the first network function does not support receiving or processing the first network information, does not support network sharing or indirect network sharing, the second network function may not send the first network information to the first network function. For the first network function, if it receives the first network information, it may accept or reject the terminal's registration request according to the first network information; if it does not receive the first network information, it may reject the terminal's registration request, or accept or reject the terminal's registration request according to the second indication information (if any) sent by the second network function.
[0137] Optionally, in some embodiments, the first network function may also perform the following operations:
[0138] Send first information to a third network function, where the first information is used to indicate processing of a voice resource request based on the first information.
[0139] Specifically, when the first network function receives a registration request from a terminal, it may send the first information to the third network function. For the third network function, after receiving the first information, it may process a voice resource request according to the first information. For the specific implementation of the third network function processing the voice resource request according to the first information, reference may be made to Figure 8 the embodiments shown, which will not be elaborated here in detail.
[0140] In the embodiments of the present application, when a terminal requests to use a network service of a home network through a participating network, the first network function may receive first network information from the second network function and accept or reject the terminal's registration request according to the first network information, thereby effectively controlling the access of the terminal. Alternatively, the first network function may also obtain second network information from an access network node and send the second network information to the second network function to assist the second network function in determining whether to accept or reject the terminal's registration request, thereby also effectively controlling the access of the terminal. Optionally, after the terminal successfully registers or accesses, since the third network function may process the terminal's voice resource request according to the first information, effective control of voice services can also be achieved.
[0141] As Figure 5 shown, embodiments of the present application provide an access control method 500. This access control method may be executed by the second network function. In other words, this access control method may be executed by software or hardware installed in the second network function. The access control method includes the following steps.
[0142] S502: The second network function sends the first network information to the first network function.
[0143] When a terminal wants to use a network service of a home network through a participating network and sends a registration request to the first network function under the participating network, the second network function under the home network may send the first network information to the first network function.
[0144] Optionally, in some embodiments, the first network information includes at least one of the following:
[0145] The first PLMN information;
[0146] The first NPN information.
[0147] The first PLMN information may be information of a PLMN that allows the terminal to access, such as a PLMN ID or a list of PLMN IDs, etc., which is not specifically limited here. The first NPN information may be information of an NPN that allows the terminal to access, such as an NPN ID or a list of NPN IDs, etc., which is also not specifically limited here.
[0148] For the first network function, after receiving the first network information from the second network function, it can accept or reject the registration request of the terminal according to the first network information. For the specific implementation method, reference can be made to Figure 2 or Figure 4 the embodiments shown, which will not be elaborated here.
[0149] Optionally, in some embodiments, the second network function can also perform the following operations:
[0150] Receive the first indication information from the first network function;
[0151] Send the first network information to the first network function based on the first indication information.
[0152] The first indication information can be used to indicate at least one of whether the first network function supports or does not support receiving the first network information, supports or does not support processing the first network information, supports or does not support network sharing, and supports or does not support indirect network sharing. For example, the first indication information can be the ability indication information of whether the first network function supports network sharing and indirect network sharing. If the first indication information indicates that the first network function supports receiving or processing the first network information, supports network sharing or indirect network sharing, then the second network function can send the first network information to the first network function. If the first indication information indicates that the first network function does not support receiving or processing the first network information, does not support network sharing or indirect network sharing, then the second network function can not send the first network information to the first network function. For the first network function, if it receives the first network information, it can accept or reject the registration request of the terminal according to the first network information. If it does not receive the first network information, it can reject the registration request of the terminal, or determine whether to accept or reject the registration request of the terminal according to other information (such as the second indication information sent by the second network function).
[0153] In the embodiments of the present application, when the terminal requests to use the network service of the home network through the participating network, the second network function can send the first network information to the first network function, and the first network function can accept or reject the registration request of the terminal according to the first network information. Thus, effective control of the terminal access can be achieved.
[0154] As Figure 6 shown, the embodiments of the present application provide an access control method 600. This access control method can be executed by the second network function. In other words, this access control method can be executed by the software or hardware installed in the second network function. This access control method includes the following steps.
[0155] S602: The second network function receives the second network information sent by the first network function.
[0156] In the case where a terminal requests to use a network service of a home network through a participating party network, a first network function under the participating party network may send second network information to a second network function under the home network, and the second network function may receive the second network information from the first network function. The second network information may indicate the network selected by the terminal.
[0157] The second network information includes at least one of the following:
[0158] Second PLMN information;
[0159] Second NPN information.
[0160] The second PLMN information may be information of the PLMN selected by the terminal, such as a PLMN ID, etc., which is not specifically limited here. The second NPN information may be information of the NPN selected by the terminal, such as an NPN ID, etc., which is also not specifically limited here.
[0161] S604: The second network function sends second indication information to the first network function based on the second network information, and the second indication information is used to indicate rejection of registration, acceptance of registration, non - permission of registration, permission of registration, registration error, registration failure, or successful registration.
[0162] After receiving the second network information, the second network function may determine whether to allow the terminal to access the participating party network according to the second network information, and send second indication information to the first network function according to the determination result. The second indication information is used to indicate rejection of registration, acceptance of registration, non - permission of registration, permission of registration, registration error, registration failure, or successful registration. In the case of receiving the second indication information, the first network function may reject or accept the registration request of the terminal according to the second indication information. For example, if the second indication information indicates rejection of registration, non - permission of registration, registration error, or registration failure, the first network function may reject the registration request of the terminal; if the second indication information indicates permission of registration or successful registration, the first network function may accept the registration request of the terminal.
[0163] In the embodiments of the present application, in the case where a terminal requests to use a network service of a home network through a participating party network, the second network function may receive the second network information from the first network function, and send second indication information to the second network function according to the second network information to indicate the first network function to accept or reject the registration request of the terminal. Thus, the access of the terminal can be effectively controlled.
[0164] Such as Figure 7As shown in the figure, an embodiment of this application provides an access control method 700. This access control method can be executed by a second network function. In other words, this access control method can be executed by software or hardware installed in the second network function. The access control method includes the following steps.
[0165] S702: The second network function receives second network information sent by the first network function.
[0166] In the case where a terminal requests to use network services of a home network through a participating network, the first network function under the participating network can send second network information to the second network function under the home network, and the second network function can receive the second network information from the first network function. The second network information can indicate the network selected by the terminal.
[0167] Optionally, in some embodiments, the second network information includes at least one of the following:
[0168] Second PLMN information;
[0169] Second NPN information.
[0170] The second PLMN information can be information of the PLMN selected by the terminal, such as a PLMN ID, etc., which is not specifically limited here. The second NPN information can be information of the NPN selected by the terminal, such as an NPN ID, etc., which is also not specifically limited here.
[0171] S704: The second network function sends second indication information to the first network function based on the second network information. The second indication information is used to indicate rejection of registration, acceptance of registration, non - permission of registration, permission of registration, registration error, registration failure, or successful registration.
[0172] After receiving the second network information, the second network function can determine whether to allow the terminal to access the participating network according to the second network information, and send second indication information to the first network function according to the determination result. The second indication information is used to indicate rejection of registration, acceptance of registration, non - permission of registration, permission of registration, registration error, registration failure, or successful registration.
[0173] S706: The second network function sends first network information to the first network function.
[0174] In the case where a terminal wants to use network services of a home network through a participating network, the second network function can also send first network information to the first network function.
[0175] Optionally, in some embodiments, the first network information includes at least one of the following:
[0176] First PLMN information;
[0177] First NPN information.
[0178] The first PLMN information may be information of the PLMN that allows the terminal to access, such as a PLMN ID or a list of PLMN IDs, etc., which is not specifically limited here. The first NPN information may be information of the NPN that allows the terminal to access, such as an NPN ID or a list of NPN IDs, etc., which is also not specifically limited here.
[0179] For the first network function, after receiving the first network information and the second indication information from the second network function, it may accept or reject the registration request of the terminal according to at least one of the first network information and the second indication information. The specific implementation manner may refer to Figure 4 the embodiments shown, which will not be repeated here.
[0180] Optionally, in some embodiments, the second network function may also perform the following operations:
[0181] Receive the first indication information from the first network function;
[0182] Send the first network information to the first network function based on the first indication information.
[0183] The first indication information may be used to indicate at least one of whether the first network function supports or does not support receiving the first network information, supports or does not support processing the first network information, supports or does not support network sharing, and supports or does not support indirect network sharing. For example, the first indication information may be an ability indication information of whether the first network function supports network sharing and indirect network sharing. If the first indication information indicates that the first network function supports receiving or processing the first network information, supports network sharing or indirect network sharing, then the second network function may send the first network information to the first network function. If the first indication information indicates that the first network function does not support receiving or processing the first network information, does not support network sharing or indirect network sharing, then the second network function may not send the first network information to the first network function. For the first network function, if it receives the first network information, it may accept or reject the registration request of the terminal according to the first network information, or according to the first network information and the second indication information. If it does not receive the first network information, it may reject the registration request of the terminal, or determine to accept or reject the registration request of the terminal according to the second indication information.
[0184] In an embodiment of the present application, when a terminal requests to use a network service of a home network through a participating party network, a second network function may send first network information to a first network function, and the first network function may accept or reject the registration request of the terminal according to the first network information. Alternatively, the second network function may receive second network information from the first network function, and send second indication information to the second network function according to the second network information to instruct the first network function to accept or reject the registration request of the terminal. Thus, effective control of terminal access can be achieved.
[0185] As Figure 8 shown, an embodiment of the present application provides an access control method 800. This access control method may be executed by a third network function. In other words, this access control method may be executed by software or hardware installed in the third network function. The access control method includes the following steps.
[0186] S802: The third network function receives first information from the first network function.
[0187] When the first network function under the participating party network allows a terminal of the home network to access or accepts the registration request of the terminal, it may send first information to the third network function under the participating party network, and the third network function may receive the first information from the first network function. The first information may be used to instruct the third network function to process a voice resource request according to the first information.
[0188] S804: The third network function receives a voice resource request from the fourth network function.
[0189] After the terminal accesses the participating party network, it may send a calling request to the fourth network function, or another terminal sends a calling request to the fourth network function for the terminal. When the fourth network function receives the calling request or called request of the terminal, it may send a voice resource request to the third network function, and the third network function may receive the voice resource request from the fourth network function. Among them, the fourth network function may be a Proxy-Call Session Control Function (P-CSCF) under the participating party network.
[0190] S806: The third network function processes the voice resource request according to the first information.
[0191] Optionally, in some embodiments, the third network function processes the voice resource request according to the first information, which may include at least one of the following:
[0192] The third network function establishes voice resources for the terminal according to the first information, or establishes / increases a voice QoS flow, or rejects the establishment of voice resources, or rejects the establishment / increase of a voice QoS flow;
[0193] The third network function sends third indication information to the terminal according to the first information, and the third indication information is used to indicate at least one of fallback, rejection, reselection, and other networks.
[0194] Specifically, the third network function can determine whether the network supports Voice over New Radio (VoNR) services. If it supports, it can establish voice resources for the terminal or establish / increase voice QoS flows. If it does not support, it can reject the establishment of voice resources or reject the establishment / increase of voice QoS flows. When the third network function rejects the establishment of voice resources or rejects the establishment / increase of voice QoS flows, it can also send third indication information to the terminal, and the third indication information is used to indicate at least one of fallback, rejection, reselection, and other networks. Optionally, when the third network function sends the third indication information to the terminal, it can send the third indication information to the terminal through the first network function, that is, the first network function forwards the third indication information to the terminal.
[0195] In the embodiments of the present application, after the terminal successfully registers or successfully accesses the participating party network, since the third network function under the participating party network can process the voice resource request of the terminal according to the first information indicated by the first network function, effective control of voice services can be achieved.
[0196] To facilitate understanding of the access control method provided in the embodiments of the present application, the following can be used as Figure 9 and Figure 10 a more specific implementation manner shown for illustration.
[0197] Figure 9 is a schematic flowchart of the access control method according to the embodiments of the present application, which may include the following steps.
[0198] Step 1: The terminal sends a registration request to the AMF, and the registration request carries the PLMN information selected by the terminal.
[0199] The AMF is the AMF under the participating party network. When the terminal sends a registration request to the AMF, it can send a Non-Access Stratum (NAS) message to the AMF. The PLMN information can be the PLMN ID.
[0200] Step 2: The AMF sends at least one of the terminal-related information, the capability indication information, and the PLMN information to the UDM.
[0201] The terminal-related information can be, for example, the terminal ID, etc. The capability indication information is used to indicate whether the AMF supports the capability of indirect network sharing. The PLMN information is the PLMN information carried in the terminal's registration request.
[0202] Step 3: The UDM decides whether to allow or not allow the terminal to access the network based on at least one of the PLMN information, the subscription information of the terminal, and the capability indication information.
[0203] Step 4: UDM instructs AMF to allow or deny terminal access.
[0204] When UDM indicates to AMF that terminal access is allowed, it can also indicate the PLMN information that the terminal is allowed to access, such as PLMN ID or PLMN ID list.
[0205] Step 5: Based on the instruction from UDM, AMF decides whether to allow or not allow the terminal to access the network.
[0206] For example, if the UDM indicates the PLMN information that the terminal is allowed to access, and the PLMN information selected by the terminal is in the PLMN information indicated by the UDM, the terminal is allowed to access, otherwise it is decided not to allow the terminal to access. For another example, if the UDM indicates that the terminal is not allowed to access, it is decided not to allow the terminal to access.
[0207] Step 6: AMF sends a response to the terminal based on the judgment result.
[0208] For example, sending a registration response or a registration rejection.
[0209] Step 7: The terminal initiates a session establishment or update request to the AMF.
[0210] For example, sending a PDU Session Establishment / Modification Request message.
[0211] Step 8: AMF sends an instruction message to SMF, instructing the terminal to access through indirect network sharing.
[0212] Step 9: SMF sends return information to AMF.
[0213] Step 10: AMF sends a session establishment or update response to the terminal.
[0214] Figure 10 It is a schematic flow chart of a voice service control method according to an embodiment of the present application, which may include the following steps.
[0215] Step 1: The terminal initiates a voice call to the P-CSCF.
[0216] For example, the terminal sends an INVITE message of the IP Multimedia Subsystem (IMS).
[0217] Step 2: The P-CSCF indicates a request for voice resources to the SMF via the 5G network.
[0218] Indicating a request for voice resources, for example, it can be to indicate a Quality of Service (QoS) flow with a 5G Quality of Service Identifier (5QI) = 1.
[0219] It should be noted that Step 1 is an optional step. In the case of not executing Step 1, the P-CSCF in Step 2 can indicate a request for voice resources to the SMF via the 5G network when receiving a called request sent to the terminal.
[0220] Step 3: The SMF determines whether to allow voice resources based on the context of the terminal.
[0221] For example, by learning from the Subscription Permanent Identifier (SUPI) information that the home network of the terminal is a party sharing the network indirectly with this network, or from the indication information sent by the AMF ( Figure 9 Step 8 as shown) to learn that the terminal accesses through the indirect network sharing method.
[0222] Step 4: The SMF sends a session update request or a fallback indication to the terminal.
[0223] If this network supports VoNR, the SMF can send a session update request to the terminal to reserve relevant voice resources. Otherwise, the SMF can send a fallback indication to the terminal, or send a service failure indication to the AMF, and then the AMF sends a fallback indication to the terminal.
[0224] Step 5a: The terminal responds to the session update request.
[0225] Step 5b: The terminal exits the access to this network and re-selects other networks for access to perform voice services.
[0226] Based on Figure 9 and Figure 10 the embodiments shown, access control and voice service control can be achieved when the terminal requests to use the network services of the home network through the participating network.
[0227] For the access control method provided in the embodiments of the present application, the execution subject can be an access control device. In the embodiments of the present application, taking the access control device executing the access control method as an example, the access control device provided in the embodiments of the present application is described.
[0228] Figure 11 is a schematic structural diagram of the access control device according to the embodiments of the present application. This device can correspond to the first network function in other embodiments. AsFigure 11 As shown, the apparatus 1100 includes at least one of the following first module 1101 and second module 1102.
[0229] Wherein, the first module 1101 includes:
[0230] A first receiving module, configured to receive a registration request from a terminal; and receive first network information from a second network function;
[0231] A processing module, configured to accept or reject the registration request according to the first network information;
[0232] Wherein, the second module 1102 includes:
[0233] A second receiving module, configured to receive second network information from an access network node, where the second network information indicates a network selected by a terminal;
[0234] A second sending module, configured to send the second network information to the second network function.
[0235] Optionally, in some embodiments, the first network information includes at least one of the following:
[0236] First public land mobile network (PLMN) information;
[0237] First non-public network (NPN) information;
[0238] The second network information includes at least one of the following:
[0239] Second PLMN information;
[0240] Second NPN information.
[0241] Optionally, in some embodiments, the first module 1101 further includes a first sending module;
[0242] The first sending module is configured to send first indication information to the second network function, where the first indication information is used to indicate at least one of the following:
[0243] Support or not support receiving the first network information;
[0244] Support or not support processing the first network information;
[0245] Support or not support network sharing;
[0246] Support or not support indirect network sharing.
[0247] Optionally, in some embodiments, the first receiving module is further configured to receive second network information from an access network node, where the second network information indicates the network selected by the terminal;
[0248] The processing module is configured to accept or reject the registration request according to the first network information and the second network information.
[0249] Optionally, in some embodiments, the second receiving module is further configured to:
[0250] Receive second indication information from the second network function, where the second indication information is used to indicate rejection of registration, acceptance of registration, non - permission of registration, permission of registration, registration error, registration failure, or registration success.
[0251] Optionally, in some embodiments, the first sending module or the second sending module is further configured to:
[0252] Send first information to a third network function, where the first information is used to indicate processing a voice resource request based on the first information.
[0253] The apparatus 1100 according to an embodiment of the present application may refer to the processes of methods 200, 300, or 400 corresponding to embodiments of the present application. Moreover, each unit / module in the apparatus 1100 and the above - mentioned other operations and / or functions respectively implement the corresponding processes in methods 200, 300, or 400, and can achieve the same or equivalent technical effects. For the sake of brevity, details are not described herein again.
[0254] Figure 12 It is a schematic structural diagram of an access control apparatus according to an embodiment of the present application, and this apparatus may correspond to a first network function in other embodiments. As Figure 12 shown, the apparatus 1200 includes at least one of the following third module 1201 and fourth module 1202.
[0255] Among them, the third module 1201 includes:
[0256] A third sending module, configured to send first network information to a first network function;
[0257] Among them, the fourth module 1202 includes:
[0258] A fourth receiving module, configured to receive second network information sent by a first network function;
[0259] A fourth sending module, configured to send second indication information to the first network function based on the second network information, where the second indication information is used to indicate rejection of registration, acceptance of registration, non - permission of registration, permission of registration, registration error, registration failure, or successful registration.
[0260] Optionally, in some embodiments, the first network information includes at least one of the following:
[0261] First PLMN information;
[0262] First NPN information;
[0263] The second network information includes at least one of the following:
[0264] Second PLMN information;
[0265] Second NPN information.
[0266] Optionally, in some embodiments, the third module 1201 further includes a third receiving module; the third receiving module is further configured to receive first indication information from the first network function;
[0267] The third sending module is further configured to send the first network information to the first network function based on the first indication information.
[0268] The apparatus 1200 according to the embodiments of the present application may refer to the processes of the methods 500, 600, or 700 corresponding to the embodiments of the present application. Moreover, each unit / module in the apparatus 1200 and the above other operations and / or functions respectively are for implementing the corresponding processes in the methods 500, 600, or 700, and can achieve the same or equivalent technical effects. For the sake of brevity, they will not be described herein again.
[0269] Figure 13 is a schematic structural diagram of an access control apparatus according to the embodiments of the present application, and this apparatus may correspond to the first network function in other embodiments. As Figure 13 shown, the apparatus 1300 includes the following modules.
[0270] A receiving module 1301, configured to receive first information from a first network function; receive a voice resource request from a fourth network function;
[0271] A processing module 1302, configured to process the voice resource request according to the first information.
[0272] Optionally, in some embodiments, the processing module 1302 is configured to perform at least one of the following:
[0273] Establish a voice resource for a terminal, or establish / increase a voice QoS flow, or reject the establishment of a voice resource, or reject the establishment / increase of a voice QoS flow according to the first information;
[0274] Send third indication information to the terminal according to the first information, where the third indication information is used to indicate at least one of fallback, rejection, reselection, and other networks.
[0275] Optionally, in some embodiments, the processing module 1302 is configured to send the third indication information to the terminal through the first network function.
[0276] The apparatus 1300 according to the embodiment of the present application may refer to the process of the method 800 corresponding to the embodiment of the present application. Moreover, each unit / module in the apparatus 1300 and the above other operations and / or functions respectively implement the corresponding processes in the method 800 and can achieve the same or equivalent technical effects. For the sake of brevity, they will not be described herein again.
[0277] The access control apparatus in the embodiment of the present application may be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip. The electronic device may be a terminal or other devices other than the terminal. Exemplarily, the terminal may include, but is not limited to, the types of the terminal 11 listed above, and other devices may be a server, a Network Attached Storage (NAS), etc. The embodiment of the present application does not make specific limitations.
[0278] The access control apparatus provided by the embodiment of the present application can implement Figures 2 to 8 each process implemented by the method embodiment and achieve the same technical effect. To avoid repetition, it will not be described here again.
[0279] As Figure 14 shown, the embodiment of the present application further provides a communication device 1400, including a processor 1401 and a memory 1402. A program or instruction that can run on the processor 1401 is stored on the memory 1402. For example, when the communication device 1400 is a network-side device, when the program or instruction is executed by the processor 1401, it implements each step of the above access control method embodiment and can achieve the same technical effect. To avoid repetition, it will not be described here again.
[0280] The embodiment of the present application further provides a network-side device. As Figure 15 shown, the network-side device 1500 includes: a processor 1501, a network interface 1502, and a memory 1503. Among them, the network interface 1502 is, for example, a common public radio interface (CPRI).
[0281] Specifically, the network-side device 1500 in the embodiments of the present invention further includes: instructions or programs stored on the memory 1503 and executable on the processor 1501. The processor 1501 calls the instructions or programs in the memory 1503 to execute Figures 11 to 13 the methods executed by the modules shown in the figure, and achieve the same technical effects. To avoid repetition, they will not be elaborated here.
[0282] The embodiments of the present application further provide a readable storage medium. Programs or instructions are stored on the readable storage medium. When the programs or instructions are executed by a processor, the various processes of the above access control method embodiments are implemented, and the same technical effects can be achieved. To avoid repetition, they will not be elaborated here.
[0283] Wherein, the processor is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs, etc. In some examples, the readable storage medium may be a non-transitory readable storage medium.
[0284] The embodiments of the present application further provide a chip. The chip includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above access control method embodiments, and the same technical effects can be achieved. To avoid repetition, they will not be elaborated here.
[0285] It should be understood that the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.
[0286] The embodiments of the present application further provide a computer program / program product. The computer program / program product is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above access control method embodiments, and the same technical effects can be achieved. To avoid repetition, they will not be elaborated here.
[0287] The embodiments of the present application further provide a wireless communication system, including: a terminal and a network-side device. The network-side device can be used to execute the steps of the access control method described above.
[0288] It should be noted that in this article, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may also be added, omitted or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0289] From the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of a computer software product plus a necessary general hardware platform, and of course, can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes several instructions for causing a terminal or a network-side device to execute the methods described in the various embodiments of the present application.
[0290] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms of embodiments without departing from the purpose of the present application and the scope protected by the claims. These embodiments are all within the protection scope of the present application.
Claims
1. An access control method, characterized in that, Comprising: The first network function performs at least one of the following: The first operation; The second operation; Wherein, the first operation includes: Receiving a registration request from a terminal; Receiving first network information from a second network function; Accepting or rejecting the registration request according to the first network information; Wherein, the second operation includes: Receiving second network information from an access network node, the second network information indicating the network selected by the terminal; Sending the second network information to the second network function.
2. The method according to claim 1, characterized in that, The first network information includes at least one of the following: First Public Land Mobile Network (PLMN) information; First Non-Public Network (NPN) information; The second network information includes at least one of the following: Second PLMN information; Second NPN information.
3. The method according to claim 1 or 2, characterized in that, The first operation further includes: Sending first indication information to the second network function, the first indication information being used to indicate at least one of the following: Supporting or not supporting receiving the first network information; Supporting or not supporting processing the first network information; Supporting or not supporting network sharing; Supporting or not supporting indirect network sharing.
4. The method according to claim 1 or 2, characterized in that, The accepting or rejecting the registration request according to the first network information includes: Receiving second network information from an access network node, the second network information indicating the network selected by the terminal; Accepting or rejecting the registration request according to the first network information and the second network information.
5. The method according to claim 1 or 2, characterized in that, The second operation further includes: Receiving second indication information from the second network function, the second indication information being used to indicate rejecting registration, accepting registration, not allowing registration, allowing registration, registration error, registration failure, or successful registration.
6. The method according to any one of claims 1 to 5, characterized in that The method further includes: The first network function sending first information to a third network function, the first information being used to indicate processing a voice resource request based on the first information.
7. An access control method, characterized in that, Comprising: The second network function performs at least one of the following: The third operation; The fourth operation; Wherein, the third operation includes: Sending first network information to the first network function; Wherein, the fourth operation includes: Receiving second network information sent by the first network function; Sending second indication information to the first network function based on the second network information, the second indication information being used to indicate rejecting registration, accepting registration, not allowing registration, allowing registration, registration error, registration failure, or successful registration.
8. The method according to claim 7, wherein The first network information includes at least one of the following: First PLMN information; First NPN information; The second network information includes at least one of the following: Second PLMN information; Second NPN information.
9. The method according to claim 7 or 8, characterized in that, The third operation further includes: Receiving first indication information from the first network function; Sending the first network information to the first network function based on the first indication information.
10. An access control method, characterized in that, Comprising: The third network function receives first information from the first network function; The third network function receives a voice resource request from a fourth network function; The third network function processes the voice resource request according to the first information.
11. The method according to claim 10, characterized in that, The third network function processing the voice resource request according to the first information includes at least one of the following: The third network function establishes voice resources for the terminal according to the first information, or establishes / augments a voice QoS flow, or rejects the establishment of voice resources, or rejects the establishment / augmentation of a voice QoS flow; The third network function sends third indication information to the terminal according to the first information, and the third indication information is used to indicate at least one of fallback, rejection, reselection, and other networks.
12. The method according to claim 11, wherein The third network function sends the third indication information to the terminal through the first network function.
13. An access control device, characterized in that, Includes at least one of the following: The first module; The second module; Wherein, the first module includes: The first receiving module is used to receive a registration request from the terminal; and receive first network information from the second network function; The processing module is used to accept or reject the registration request according to the first network information; Wherein, the second module includes: The second receiving module is used to receive second network information from an access network node, and the second network information indicates the network selected by the terminal; The second sending module is used to send the second network information to the second network function.
14. The device according to claim 13, characterized in that, The first network information includes at least one of the following: First public land mobile network (PLMN) information; First non-public network (NPN) information; The second network information includes at least one of the following: Second PLMN information; Second NPN information.
15. The device according to claim 13 or 14, characterized in that, The first module further includes a first sending module; the first sending module is used to: Send first indication information to the second network function, and the first indication information is used to indicate at least one of the following: Support or not support receiving the first network information; Support or not support processing the first network information; Support or not support network sharing; Support or not support indirect network sharing.
16. The device according to claim 13 or 14, wherein The first receiving module is further used to receive second network information from an access network node, and the second network information indicates the network selected by the terminal; The processing module is used to accept or reject the registration request according to the first network information and the second network information.
17. The device according to claim 13 or 14, characterized in that, The second receiving module is further used to: Receive second indication information from the second network function, and the second indication information is used to indicate rejection of registration, acceptance of registration, non-permission of registration, permission of registration, registration error, registration failure, or successful registration.
18. The device according to any one of claims 13 to 17, characterized in that, The first sending module or the second sending module is further used to: Send first information to the third network function, and the first information is used to indicate processing of a voice resource request based on the first information.
19. An access control device, characterized in that, Includes at least one of the following: The third module; The fourth module; Wherein, the third module includes: The third sending module is used to send first network information to the first network function; Wherein, the fourth module includes: The fourth receiving module is used to receive second network information sent by the first network function; The fourth sending module is used to send second indication information to the first network function based on the second network information, and the second indication information is used to indicate rejection of registration, acceptance of registration, non-permission of registration, permission of registration, registration error, registration failure, or successful registration.
20. The device according to claim 19, characterized in that, The first network information includes at least one of the following: First PLMN information; First NPN information; The second network information includes at least one of the following: Second PLMN information; Second NPN information.
21. The device according to claim 19 or 20, characterized in that, The third module further includes a third receiving module; the third receiving module is further configured to receive first indication information from the first network function; The third sending module is further configured to send the first network information to the first network function based on the first indication information.
22. An access control device, characterized in that, Comprising: A receiving module, configured to receive first information from a first network function; Receive a voice resource request from a fourth network function; A processing module, configured to process the voice resource request according to the first information.
23. The device according to claim 22, characterized in that, The processing module is configured to perform at least one of the following: Establish a voice resource for the terminal according to the first information, or establish / increase a voice QoS flow, or reject the establishment of a voice resource, or reject the establishment / increase of a voice QoS flow; Send third indication information to the terminal according to the first information, where the third indication information is used to indicate at least one of fallback, rejection, reselection, and other networks.
24. The device according to claim 23, characterized in that, The processing module is configured to send the third indication information to the terminal through the first network function.
25. A network-side device, characterized in that Comprising a processor and a memory, the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, it implements the steps of the access control method according to any one of claims 1 to 6, or implements the steps of the access control method according to any one of claims 7 to 9, or implements the steps of the access control method according to any one of claims 10 to 12.
26. A readable storage medium, characterized in that, A program or instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, it implements the steps of the access control method according to any one of claims 1 to 6, or implements the steps of the access control method according to any one of claims 7 to 9, or implements the steps of the access control method according to any one of claims 10 to 12.