Access control method and 5G network system

By generating and writing target contract data through the network management server, AMF controls the terminal base station switching, solving the problems of high professional knowledge requirements and poor flexibility in the existing technology of 5G terminal frequency-locked access control, and realizing efficient and flexible access control.

CN120614673APending Publication Date: 2025-09-09SHENZHEN AI LINK CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510892121.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

In existing technologies, the frequency-locked access control of 5G terminals relies on manual configuration, which requires high professional knowledge, a large configuration workload, poor flexibility, and is unable to adapt to dynamic network changes in a timely manner.

Method used

The target subscription data of the terminal is generated by the network management server, including a list of base stations allowed to be accessed. The AMF controls the base station switching of the terminal according to the switching request message and the target subscription data to achieve an automatic frequency locking effect.

Benefits of technology

It reduces the workload of manual configuration, improves the flexibility and efficiency of access control, and can adapt to network changes in a timely manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614673A_ABST
    Figure CN120614673A_ABST
Patent Text Reader

Abstract

The invention provides an access control method and a 5G network system, and the method comprises the steps that a network management server obtains the identification of industrial equipment reported by a terminal and the identification of a currently accessed base station, and the industrial equipment is the industrial equipment connected to the terminal; the network management server generates target subscription data of the terminal according to the identifier of the industrial equipment and the identifier of the currently accessed base station and writes the target subscription data into a network security domain where the terminal is located, and the target subscription data comprises a base station list allowing the terminal to access; the AMF in the network security domain where the terminal is located determines whether to switch the terminal from the currently accessed base station to the target base station according to the target subscription data and a switching request message sent by the currently accessed base station, and the switching request message comprises an identifier of the target base station; and the access control of the industrial equipment connected with the terminal is efficiently and flexibly realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and more specifically, to an access control method and a 5G network system. Background Art

[0002] In the 5G network, the frequency locking function can lock 5G terminals such as mobile phones and routers to a specified frequency band, frequency point or physical cell to prevent the 5G terminals from automatically switching networks.

[0003] Currently, access control for 5G terminals requires manual frequency locking, which requires high operator expertise and is prone to errors. Furthermore, when deploying a large number of UEs on-site, the configuration workload is heavy, labor-intensive, and inefficient. Furthermore, manual frequency locking configuration is inflexible. When network failures occur or optimization and upgrades are required, manual reconfiguration is slow to respond and cannot adapt to dynamic network changes.

[0004] Therefore, the frequency-locked access control for 5G terminals in the existing technology has certain limitations. Summary of the Invention

[0005] The purpose of this application is to provide an access control method and a 5G network system to address the deficiencies in the above-mentioned prior art, so as to solve the practical problem that the frequency-locked access control for 5G terminals in the prior art has certain limitations.

[0006] To achieve the above objectives, the technical solutions adopted in the embodiments of the present application are as follows:

[0007] In a first aspect, an embodiment of the present application provides an access control method applied to a 5G network system, wherein the 5G network system includes: a network management server and multiple network security domains, each network security domain includes at least: an AMF and a base station; the method includes:

[0008] The network management server obtains the identifier of the industrial device reported by the terminal and the identifier of the currently connected base station, wherein the industrial device is the industrial device connected to the terminal;

[0009] The network management server generates target subscription data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station and writes the target subscription data into the network security domain where the terminal is located, wherein the target subscription data includes a list of base stations that the terminal is allowed to access;

[0010] The AMF in the network security domain where the terminal is located determines whether to switch the terminal from the currently accessed base station to the target base station based on the target subscription data and the switching request message sent by the currently accessed base station, and the switching request message includes the identifier of the target base station.

[0011] As an optional implementation, the network management server generates target contract data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station and writes the target contract data of the terminal into the network security domain where the terminal is located, including:

[0012] The network management server writes the initial contract data of the terminal into each network security domain, wherein the initial contract data is used to instruct the industrial equipment connected to the terminal to allow access to the base station in each network security domain;

[0013] The network management server modifies the initial contract data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station, obtains the target contract data of the terminal, and writes the target contract data into the network security domain where the terminal is located.

[0014] As an optional implementation, each of the network security domains further includes: a UDM function; wherein the network management server serves as a database master node, the UDM function of each network security domain serves as a database slave node, and the UDM function of each network security domain establishes a data synchronization relationship with the network management server;

[0015] The network management server writes the initial contract data of the terminal into each network security domain, including:

[0016] The network management server uses a data synchronization mechanism to write the initial contract data of the terminal into the UDM function of each network security domain.

[0017] As an optional implementation, the network management server modifies the initial contract data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station, obtains the target contract data of the terminal, and writes it into the network security domain where the terminal is located, including:

[0018] The network management server determines a list of base stations that the terminal is allowed to access based on the identifier of the industrial device and a pre-stored access mapping table;

[0019] The network management server determines the network security domain where the terminal is located according to the identifier of the currently accessed base station, and uses the list of base stations that the terminal is allowed to access as the target subscription data of the terminal;

[0020] The network management server uses the data synchronization mechanism to write the target subscription data of the terminal into the UDM function of the network security domain where the terminal is located.

[0021] As an optional implementation manner, the AMF in the network security domain where the terminal is located determines whether to switch the terminal from the currently accessed base station to the target base station according to the target subscription data and the handover request message sent by the currently accessed base station, including:

[0022] The AMF subscribes to the data change event of the UDM function to obtain the target subscription data of the terminal through the data change event.

[0023] As an optional implementation manner, the AMF in the network security domain where the terminal is located determines whether to switch the terminal from the currently accessed base station to the target base station according to the target subscription data and the handover request message sent by the currently accessed base station, further comprising:

[0024] When the terminal detects that the signal strength of base stations other than the currently connected base station is stronger than the signal strength of the currently connected base station, the terminal reports the measurement information of each base station to the currently connected base station;

[0025] The currently accessed base station determines the target base station according to the measurement information, generates a switching request message according to the identifier of the target base station, and sends it to the AMF in the network security domain where the terminal is located.

[0026] As an optional implementation manner, the AMF in the network security domain where the terminal is located determines whether to switch the terminal from the currently accessed base station to the target base station according to the target subscription data and the handover request message sent by the currently accessed base station, including:

[0027] The AMF uses the identifier of the target base station in the handover request message as an index, queries the identifier of the target base station in the target subscription data, and obtains a query result;

[0028] The AMF determines whether to switch the terminal from the currently connected base station to the target base station based on the query result.

[0029] As an optional implementation manner, the AMF determines, based on the query result, whether to switch the terminal from the currently connected base station to the target base station, including:

[0030] If the AMF does not find the identifier of the target base station in the target subscription data, it refuses to switch the terminal from the currently connected base station to the target base station.

[0031] As an optional implementation manner, the refusing to switch the terminal from the currently connected base station to the target base station includes:

[0032] The AMF generates a handover preparation failure message and sends it to the currently accessed base station;

[0033] After receiving the handover preparation failure message, the currently connected base station continues to maintain the connection with the terminal and refuses the terminal from switching to the target base station.

[0034] In a second aspect, an embodiment of the present application provides a 5G network system, comprising: a network management server and multiple network security domains, each network security domain comprising at least: an access and mobility management function AMF and a base station; the 5G network system is used to execute the steps of the access control method described in the first aspect above.

[0035] The beneficial effects of this application are:

[0036] The present application provides an access control method and a 5G network system, wherein a network management server obtains the identifier of the industrial equipment reported by the terminal and the identifier of the currently connected base station, and generates the target contract data of the terminal based on the identifier of the industrial equipment connected to the terminal and the identifier of the currently connected base station, wherein the target contract data includes a list of base stations that the terminal is allowed to access. The network management server writes the target contract data including the list of base stations that the terminal is allowed to access into the network security domain where the terminal is located. When the AMF in the network security domain where the terminal is located receives a switching request message sent by the base station currently connected to the terminal, the AMF determines whether to switch the terminal from the currently connected base station to the target base station based on the identifier of the target base station in the switching request message and the target contract data of the terminal written by the network management server, so as to control the base station switching of the terminal. When the base station switching is not allowed, the terminal is locked in the currently connected base station, thereby achieving terminal access control similar to the frequency locking effect, and then performing access control on the industrial equipment connected to the terminal. By generating the target contract data of the terminal through the network management server, the workload of manual configuration when the terminal and industrial equipment are frequency locked is reduced, and the flexibility and efficiency of access control are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0038] Figure 1 A schematic diagram of the architecture of a 5G network system provided in an embodiment of the present application;

[0039] Figure 2 Schematic diagram of the access control method provided in this embodiment of the application Figure 1 ;

[0040] Figure 3 Schematic diagram of the access control method provided in this embodiment of the application Figure 2 ;

[0041] Figure 4 Schematic diagram of the access control method provided in this embodiment of the application Figure 3 ;

[0042] Figure 5 Schematic diagram of the access control method provided in this embodiment of the application Figure 4 ;

[0043] Figure 6 Schematic diagram of the access control method provided in this embodiment of the application Figure 5 ;

[0044] Figure 7 Schematic diagram of the access control method provided in this embodiment of the application Figure 6 ;

[0045] Figure 8 Schematic diagram of the access control method provided in this embodiment of the application Figure 7 . DETAILED DESCRIPTION

[0046] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of illustration and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowcharts can be implemented out of sequence, and steps without logical context can be reversed or implemented simultaneously. In addition, those skilled in the art, under the guidance of the contents of this application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart.

[0047] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application.

[0048] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.

[0049] In 5G networks, in order to prevent 5G terminals from automatically switching networks, it is necessary to lock 5G terminals such as mobile phones and routers to a specified frequency band, frequency point or physical cell through the frequency locking function. At present, access control of 5G terminals is mainly achieved through manually configured frequency locking, which requires high professional knowledge of operators and is prone to misoperation. Moreover, when a large number of UEs are deployed on site, the configuration workload is large, consumes a lot of manpower, and is inefficient. In addition, the flexibility of manual frequency locking configuration is poor. When the network fails or needs to be optimized and upgraded, the manual reconfiguration response speed is slow and cannot adapt to the dynamic changes of the network in a timely manner. In other words, the frequency locking access control for 5G terminals in the existing technology has certain limitations.

[0050] Based on the above-mentioned problems, an embodiment of the present application provides an access control method, in which the Access and Mobility Management Function (AMF) in each network security domain performs base station switching control of the terminal according to the identifier of the target base station carried in the switching request message reported by the base station currently accessed by the terminal. After receiving the switching request message from the base station, the AMF obtains a list of base stations that the terminal is allowed to access from the network management server. If the target base station is not in the list of base stations that the terminal is allowed to access, the base station switching of the terminal is rejected, and the terminal is locked in the connection of the current base station, thereby efficiently and flexibly realizing access control of the industrial equipment connected to the terminal, that is, realizing access control similar to the frequency locking effect.

[0051] Figure 1 The schematic diagram of the 5G network system architecture provided in the embodiment of the present application is as follows: Figure 1 As shown, the 5G network system includes: a network management server and multiple network security domains, each network security domain includes at least: an AMF and a base station.

[0052] Reference Figure 1 The 5G network system includes a network management server and multiple network security domains. In each network security domain, an independent small 5G independent network is deployed, including at least AMF and base stations. Among them, each base station communicates with each 5G user equipment (UE) or each terminal through the Uu interface. Each terminal is connected to industrial equipment, that is, each industrial equipment accesses each base station through each terminal. It should be noted that Figure 1 The three network security domains shown in FIG are only examples. The number of network security domains may be other values ​​according to actual needs and is not specifically limited here.

[0053] Figure 1 The 5G network system includes the following functional units:

[0054] 1. UE: Also known as a 5G terminal, it performs uplink data communications with industrial equipment. The UE connects to the Radio Access Network (RAN) via the Uu interface, enabling wireless communication with the 5G network system. The RAN is a base station.

[0055] 2. Industrial equipment: It is a data collection or execution device in industrial control and is connected to the base station RAN through UE.

[0056] 3. Base station RAN: Provides wireless access services to UEs and communicates downlink data with them through the Uu interface. The base station RAN connects to the AMF through the N2 interface and to the User Plane Function (UPF) through the N3 interface, enabling wireless transmission of signaling and data between the UE and the 5G core network.

[0057] 4. Network management server: It is connected to the Unified Data Management (UDM) function and UPF respectively, and receives the industrial equipment identification reported by the UE, the currently connected base station identification and the UE's Subscription Permanent Identifier (SUPI) through the UPF network element connected to the base station RAN to generate the UE's target subscription data and write it into the network security domain where the UE is located through the UDM function.

[0058] 5. AMF: Connects to the UE via the N1 interface and is responsible for UE access control and mobility management. It connects to the base station RAN via the N2 interface and exchanges signaling with the Session Management Function (SMF) via the Namf interface. It subscribes to UDM data change events through the Namf interface to obtain UE subscription data.

[0059] 6. SMF: Interacts with the UPF through the N4 interface and with the AMF through the Nsmf interface. The SMF network element is used to manage UE sessions, such as the establishment, modification, and release of Protocol Data Unit (PDU) sessions.

[0060] 7. UPF network element: Interacts with the base station RAN through the N3 interface and with the SMF through the N4 interface. The UPF is responsible for forwarding user data. By connecting to the base station NG and processing and forwarding data according to the instructions of the SMF network element, it plays a key role in data transmission in the 5G network system.

[0061] 8. UDM function: interacts with AMF through the Nudm interface, and as a database slave node, establishes a data synchronization relationship with the network management server as the database master node, is used to obtain and store the UE's contract data from the network management server, and provide data support for AMF.

[0062] Figure 2 Schematic diagram of the access control method provided in this embodiment of the application Figure 1 , applied to the above Figure 1 The 5G network system shown in Figure 1 is as follows. Figure 2 As shown, the method includes:

[0063] S101. A network management server obtains an identifier of an industrial device reported by a terminal and an identifier of a currently connected base station, where the industrial device is an industrial device connected to the terminal.

[0064] Optionally, after the UE accesses the network security domain through the base station, it reports the identifier of the connected industrial device and the identifier of the currently connected base station to the network management server. The identifier of the industrial device can be the Internet Protocol (IP) address or device name of the industrial device.

[0065] Specifically, continue to refer to Figure 1 Taking the UE in the 5G-2 network, i.e., network security domain-2, as an example, the UE reports the identifier of the downstream industrial equipment and the identifier of the currently connected base station to the base station RAN through the Uu interface. The base station RAN sends the identifier of the downstream industrial equipment and the identifier of the currently connected base station sent by the UE to the UPF through the N3 interface. The UPF forwards the identifier of the downstream industrial equipment and the identifier of the currently connected base station sent by the UE to the network management server through the N6 interface.

[0066] S102. The network management server generates target subscription data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station and writes the target subscription data into the network security domain where the terminal is located. The target subscription data includes a list of base stations that the terminal is allowed to access.

[0067] Optionally, the network management server determines the list of base stations that the UE is allowed to access based on the identifier of the industrial equipment reported by the UE and the identifier of the currently connected base station, and generates the target subscription data of the UE based on the list of base stations that the UE is allowed to access, so that the target subscription data includes the list of base stations that the UE is allowed to access. Since the industrial equipment accesses the base station through the UE, the target subscription data includes the list of base stations that the UE is allowed to access for the industrial equipment connected to the base station. The network management server writes the target subscription data of the UE into the network security domain where the UE is located, and provides access control data support for the AMF in the network security domain where the UE is located.

[0068] For example, if Figure 1 The industrial equipment connected to the UE in Network Security Domain-2 is only allowed to be used in Network Security Domain-2. The target subscription data of the UE includes a list of base stations to which the industrial equipment connected to the UE is allowed to access, that is, only the base station RAN in Network Security Domain-2. The target subscription data of the UE indicates that the industrial equipment connected to the UE can only access the base station RAN in Network Security Domain-2, and cannot access the base station RAN in Network Security Domain-1 or Network Security Domain-3. The network management server writes the target subscription data of the UE into Network Security Domain-2 where the UE is located, so that the AMF in Network Security Domain-2 can control access to the UE based on the target subscription data of the UE, and further control access to the industrial equipment connected to the UE.

[0069] S103. The AMF in the network security domain where the terminal is located determines whether to switch the terminal from the currently connected base station to the target base station based on the target subscription data and the switching request message sent by the currently connected base station, where the switching request message includes an identifier of the target base station.

[0070] Optionally, when the AMF in the network security domain where the UE is located receives a switching request message sent by the base station to which the UE is currently connected, it performs a base station switching judgment based on the identifier of the target base station in the switching request message and the target subscription data of the terminal written by the network management server, and determines whether to switch the UE from the currently connected base station to the target base station, and controls the base station switching of the UE according to the base station switching judgment result, so as to lock the UE in the currently connected base station when base station switching is not allowed, thereby achieving UE access control similar to the frequency locking effect.

[0071] For example, if Figure 1If the target subscription data of the UE in the network security domain-2 only includes the base station RAN in the network security domain-2, then when the AMF in the network security domain-2 receives the switching request message sent by the base station RAN, it determines whether to switch the UE from the currently connected base station to the target base station based on the identifier of the target base station in the switching request message (such as the base station RAN in the network security domain-1 or network security domain-3) and the target subscription data of the UE (including only the base station RAN in the network security domain-2). Since the target subscription data of the UE only allows the industrial equipment connected to the UE to access the base station RAN in the network security domain-2, the AMF in the network security domain-2 does not allow the UE to switch base stations, so as to lock the UE in the base station RAN in the currently connected network security domain-2, thereby achieving UE access control similar to the frequency locking effect, and preventing the UE from switching to the base station RAN in the network security domain-1 or network security domain-3.

[0072] In this embodiment, the network management server obtains the identifier of the industrial equipment reported by the terminal and the identifier of the currently connected base station, and generates the target contract data of the terminal based on the identifier of the industrial equipment connected to the terminal and the identifier of the currently connected base station, wherein the target contract data includes a list of base stations that the terminal is allowed to access. The network management server writes the target contract data including the list of base stations that the terminal is allowed to access into the network security domain where the terminal is located. When the AMF in the network security domain where the terminal is located receives the switching request message sent by the base station currently connected to the terminal, it determines whether to switch the terminal from the currently connected base station to the target base station based on the identifier of the target base station in the switching request message and the target contract data of the terminal written by the network management server to control the base station switching of the terminal. When the base station switching is not allowed, the terminal is locked in the currently connected base station, achieving terminal access control similar to the frequency locking effect, and then performing access control on the industrial equipment connected to the terminal. By generating the target contract data of the terminal through the network management server, the workload of manual configuration when the terminal and industrial equipment are locked is reduced, and the flexibility and efficiency of access control are improved.

[0073] Figure 3 Schematic diagram of the access control method provided in this embodiment of the application Figure 2 ,like Figure 3 As shown, in the above step S102, the network management server generates the target contract data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station and writes it into the network security domain where the terminal is located, including:

[0074] S201. The network management server writes the initial contract data of the terminal into each network security domain. The initial contract data is used to instruct the industrial equipment connected to the terminal to access the base station in each network security domain.

[0075] Optionally, the network management server initially configures the UE to allow access to base stations in all network security domains. Based on this initial configuration, the network management server generates initial subscription data for the terminal, such that the initial subscription data indicates that a list of base stations that the UE's connected industrial equipment is allowed to access includes base stations in all network security domains. The network management server writes the UE's initial subscription data into each network security domain, so that the UE can access base stations in any network security domain upon initial access.

[0076] For example, Figure 1 For example, the network management server generates the initial subscription data of the UE, instructing the industrial equipment connected to the UE to access any base station RAN in Network Security Domain-1, Network Security Domain-2, or Network Security Domain-3. The network management server writes the initial subscription data of the UE into Network Security Domain-1, Network Security Domain-2, and Network Security Domain-3 respectively, so that the AMFs in Network Security Domain-1, Network Security Domain-2, and Network Security Domain-3 can all allow the UE to access based on the initial subscription data, that is, allow the industrial equipment connected to the UE to access.

[0077] Based on this, the UE can access any base station RAN in network security domain-1, network security domain-2 or network security domain-3 during initial access, thereby improving the flexibility of the UE's initial access.

[0078] S202: The network management server modifies the initial contract data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station, obtains the target contract data of the terminal, and writes the target contract data into the network security domain where the terminal is located.

[0079] Optionally, after the UE accesses a base station in any network security domain, the network management server modifies the list of base stations allowed to be accessed by the UE based on the identifier of the industrial device reported by the UE and the identifier of the currently accessed base station, thereby obtaining a modified list of base stations allowed to be accessed by the UE. This means that the UE's initial subscription data is modified to obtain the UE's target subscription data.

[0080] The modified UE's target subscription data no longer allows the UE to access base stations in any network security domain. Instead, the UE's base station connection range is narrowed, making it easier to lock the UE into a specific network security domain. The network management server writes the UE's target subscription data into the network security domain where the UE is located, providing data support for the AMF in the network security domain where the UE is located to control base station handover.

[0081] For example, the network management server will Figure 1The initial subscription data of the UE in the network security domain-2 allows the UE to access any base station RAN in the network security domain-1, network security domain-2 and network security domain-3, so that the UE is only allowed to connect to the base station RAN in a specific network security domain. For example, the UE is only allowed to connect to the base station RAN in the network security domain-2, and the target subscription data of the UE only includes the base station RAN in the network security domain-2. After the target subscription data of the UE is written into the network security domain-2, the AMF in the network security domain-2 can continuously lock the UE in the network security domain-2 to prevent the UE from switching to the network security domain-1 or network security domain-3.

[0082] In this embodiment, the network management server initially sets the terminal to allow access to base stations in all network security domains, and generates the initial contract data of the terminal, so that the initial contract data indicates that the list of base stations that the industrial equipment connected to the terminal is allowed to access includes base stations in each network security domain. The network management server writes the initial contract data of the terminal into each network security domain, so that the terminal can access the base station in any network security domain when it first accesses. After the terminal accesses a base station in any network security domain, the network management server modifies the initial contract data of the terminal according to the identifier of the industrial equipment reported by the terminal and the identifier of the currently accessed base station, and obtains the target contract data of the terminal. The modified target contract data of the terminal no longer allows the terminal to access the base station in any network security domain, which makes it easier to lock the terminal in a specific network security domain and achieve a frequency locking effect.

[0083] As an optional implementation, each network security domain also includes: UDM function; wherein, the network management server serves as the database master node, the UDM function of each network security domain serves as the database slave node, and the UDM function of each network security domain establishes a data synchronization relationship with the network management server.

[0084] Optionally, continue with reference to Figure 1 , Network security domain-1, network security domain-2 and network security domain-3 all include UDM functions, and each UDM function communicates with the network management server. Specifically, the network management server acts as the database master node (Primary) and maintains different data tables for different network security domains, including data table 5G-1, data table 5G-2 and data table 5G-3. The UDM function in each network security domain acts as a database slave node (Secondary) and establishes a data synchronization relationship with the network management server, so that the UDM function in each network security domain maintains the data table corresponding to the network security domain locally. Among them, the data table contains the UE's contract data, that is, the data table is the initial contract data of the UE before modification or the target contract data of the UE after modification.

[0085] For example, the UDM function in Network Security Domain-1 establishes a data synchronization relationship with the network management server to maintain data table 5G-1 in Network Security Domain-1. Correspondingly, the UDM function in Network Security Domain-2 establishes a data synchronization relationship with the network management server to maintain data table 5G-2 in Network Security Domain-2. The UDM function in Network Security Domain-3 establishes a data synchronization relationship with the network management server to maintain data table 5G-3 in Network Security Domain-3.

[0086] As an optional implementation, in step S201 above, the network management server writes the initial contract data of the terminal into each network security domain, including:

[0087] The network management server uses a data synchronization mechanism to write the initial contract data of the terminal into the UDM function of each network security domain.

[0088] Optionally, since the network management server has established a data synchronization relationship with the UDM function of each network security domain, the network management server uses a data synchronization mechanism to write the UE's initial signing data into the UDM function of each network security domain, so that each network security domain can allow the UE to access based on the UE's initial signing data.

[0089] For example, referring to Figure 1 The network management server locally maintains data tables 5G-1, 5G-2, and 5G-3. At this point, data tables 5G-1, 5G-2, and 5G-3 all contain the UE's initial subscription data. The network management server uses a data synchronization mechanism to write data table 5G-1, which contains the UE's initial subscription data, to the UDM function in network security domain 1, data table 5G-2, which contains the UE's initial subscription data, to the UDM function in network security domain 2, and data table 5G-3, which contains the UE's initial subscription data, to the UDM function in network security domain 3.

[0090] In this embodiment, the network management server serves as the database master node, and the UDM function of each network security domain serves as the database slave node. Each network security domain's UDM function establishes a data synchronization relationship with the network management server. The network management server uses a data synchronization mechanism to write the terminal's initial subscription data to the UDM function of each network security domain. This allows each network security domain to allow terminal access based on the terminal's initial subscription number. Using this data synchronization mechanism to write the terminal's initial subscription data improves the flexibility of initial terminal access.

[0091] Figure 4 Schematic diagram of the access control method provided in this embodiment of the application Figure 3 ,like Figure 4As shown, in the above step S202, the network management server modifies the initial contract data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station, obtains the target contract data of the terminal and writes it into the network security domain where the terminal is located, including:

[0092] S301: The network management server determines a list of base stations that a terminal is allowed to access based on an identification of the industrial device and a pre-stored access mapping table.

[0093] Optionally, the network management server pre-acquires and stores an access mapping table input by the network administrator. The access mapping table is used to represent a list of base stations that the industrial equipment connected to the UE is allowed to access. The access mapping table can be expressed as<device_ID,[gNB_ID]> , device_ID is the identifier of the industrial device, and gNB_ID is the identifier of the base station.

[0094] The network management server uses the identifier of the industrial device reported by the UE as an index, searches a locally pre-stored access mapping table, and obtains a list of base stations that the industrial device connected to the UE is allowed to access.

[0095] For example, if the list of base stations that the industrial equipment connected to the UE is allowed to access in the access mapping table pre-set by the network administrator only includes the base station RAN in the network security domain-2, the network management server uses the identifier of the industrial equipment reported by the UE as an index, and queries to obtain the list of base stations that the industrial equipment connected to the UE is allowed to access, which only includes the base station RAN in the network security domain-2.

[0096] S302: The network management server determines the network security domain where the terminal is located according to the identifier of the currently accessed base station, and uses the list of base stations that the terminal is allowed to access as the target subscription data of the terminal.

[0097] Optionally, the network management server determines the network security domain in which the UE resides based on the identifier of the base station currently accessed reported by the UE, and uses the obtained list of base stations that the industrial equipment connected to the UE is allowed to access as the target subscription data of the UE.

[0098] For example, if the identifier of the base station currently accessed reported by the UE is the identifier of the base station RAN in the network security domain-2, the network management server determines that the UE resides in the network security domain-2, and uses the list of base stations that the industrial equipment connected to the UE is allowed to access (only including the base station RAN in the network security domain-2) obtained by the query as the target subscription data of the UE.

[0099] S303: The network management server uses a data synchronization mechanism to write the target contract data of the terminal into the UDM function of the network security domain where the terminal is located.

[0100] Optionally, since the network management server has established a data synchronization relationship with the UDM function of each network security domain, the network management server uses a data synchronization mechanism to write the UE's target subscription data into the network security domain where the UE resides, so that the AMF in the network security domain where the UE resides can control the UE's base station switching based on the UE's target subscription data.

[0101] For example, continue to refer to Figure 1 The network management server locally maintains data tables 5G-1, 5G-2, and 5G-3. After determining that the UE resides in network security domain 2, the network management server modifies the UE's initial subscription data in data table 5G-2 so that data table 5G-2 is replaced with the UE's target subscription data. The network management server uses a data synchronization mechanism to write data table 5G-2 containing the UE's target subscription data to the UDM function of network security domain 2 where the UE resides.

[0102] In this embodiment, the network management server pre-acquires and stores the access mapping table input by the network administrator, and the access mapping table is used to represent the list of base stations that the industrial equipment connected to the terminal is allowed to access. The network management server uses the identifier of the industrial equipment reported by the terminal as an index, queries the access mapping table pre-stored locally, and obtains the list of base stations that the industrial equipment connected to the terminal is allowed to access. The network management server determines the network security domain in which the terminal resides based on the identifier of the base station to which it is currently connected reported by the terminal, and uses the list of base stations that the industrial equipment connected to the terminal obtained from the query is allowed to access as the target contract data of the terminal. Since the network management server has established a data synchronization relationship with the UDM function of each network security domain, the network management server uses a data synchronization mechanism to write the target contract data of the terminal into the network security domain in which the terminal resides, so that the AMF in the network security domain in which the terminal resides can control the base station switching of the terminal based on the target contract data of the terminal. The target contract data of the terminal is written using a data synchronization mechanism to improve the configurability and efficiency of controlling terminal access switching.

[0103] As an optional implementation manner, the AMF in the network security domain where the terminal is located in step S103 above determines whether to switch the terminal from the currently accessed base station to the target base station according to the target subscription data and the handover request message sent by the currently accessed base station, including:

[0104] The AMF subscribes to the data change event of the UDM function to obtain the target subscription data of the terminal through the data change event.

[0105] Optionally, the AMF in the network security domain where the UE is located acts as a subscriber, interacts with the UDM function through the Nudm interface, and subscribes to data change events in the UDM function using the Nudm_SDM_Subscribe service. When the data table in the UDM function changes from the UE's initial subscription data to the UE's target subscription event, that is, when a data change event occurs in the UDM function, the UDM function notifies the AMF through the Nudm interface that a data change event has occurred in the UDM function and the UE's subscription data has changed. Based on the data change event that occurs in the UDM function, the AMF obtains and stores the updated UE's target subscription data from the UDM function through the Nudm_SDM_Get service, so as to control the UE's base station switching according to the updated UE's target subscription data.

[0106] For example, Figure 1 The data in the data table 5G-2 of the UDM in the network security domain-2 where the UE is located changes from the initial subscription data of the UE to the target subscription event of the UE. A data change event occurs. The UDM in the network security domain-2 acts as the subscriber and informs the subscriber, that is, the AMF in the network security domain-2 where the UE is located, that a data change event has occurred in the UDM in the network security domain-2. The AMF obtains and stores the updated target subscription data of the UE from the UDM function through the Nudm_SDM_Get service.

[0107] In this embodiment, the AMF in the network security domain where the terminal is located acts as a subscriber and subscribes to data change events in the UDM function. When the data table in the UDM function changes from the initial subscription data of the terminal to the target subscription event of the terminal, that is, when a data change event occurs in the UDM function, the UDM function notifies the AMF of the data change event. Based on the data change event that occurs in the UDM function, the AMF obtains and stores the updated target subscription data of the terminal from the UDM function, so as to control base station switching of the terminal based on the updated target subscription data of the terminal.

[0108] Figure 5 Schematic diagram of the access control method provided in this embodiment of the application Figure 4 ,like Figure 5 As shown, the AMF in the network security domain where the terminal is located in the above step S103 determines whether to switch the terminal from the currently accessed base station to the target base station according to the target subscription data and the handover request message sent by the currently accessed base station, further comprising:

[0109] S401: When the terminal detects that the signal strengths of base stations other than the currently connected base station are stronger than the signal strength of the currently connected base station, the terminal reports measurement information of each base station to the currently connected base station.

[0110] Optionally, after accessing the currently connected base station, the UE continuously detects the signal strength of base stations in each network security domain, and when it detects that the signal strength of base stations other than the currently connected base station is stronger than the signal strength of the currently connected base station, the UE reports measurement information of each base station to the currently connected base station. The measurement information includes at least the signal strength of the base station and the identifier of the base station.

[0111] Exemplarily, after accessing the base station RAN in network security domain-2, the UE continuously detects the signal strength of the base station RAN in network security domain-1, network security domain-2 and network security domain-3. When it is detected that the signal strength of the base station RAN in network security domain-1 or network security domain-3 is stronger than the signal strength of the base station RAN in the currently accessed network security domain-2, the UE reports the measurement information of these three base stations to the base station RAN in the currently accessed network security domain-2.

[0112] S402. The currently connected base station determines the target base station according to the measurement information, generates a handover request message according to the identifier of the target base station, and sends the message to the AMF in the network security domain where the terminal is located.

[0113] Optionally, the base station to which the UE is currently connected compares the base station with the strongest signal strength as the target base station based on the measurement information reported by the UE, and generates a switching request message based on the identifier of the target base station, and sends the switching request message to the AMF in the network security domain where the UE is located through the N2 interface to prompt the AMF that the UE accessed in the network security domain requests to switch to the network security domain where the target base station is located.

[0114] For example, the base station RAN in the network security domain-2 to which the UE is currently accessing has the strongest signal strength according to the measurement information reported by the UE, so the target base station is determined to be the base station RAN in the network security domain-1, and a switching request message is generated according to the identifier of the base station RAN in the network security domain-1, and sent to the AMF in the network security domain-2 through the N2 interface to prompt the AMF in the network security domain-2 to request that the UE currently accessing request to switch to the network security domain where the target base station is located, that is, the network security domain-1.

[0115] In this embodiment, when the terminal detects that the signal strength of other base stations other than the currently connected base station is stronger than the signal strength of the currently connected base station, the terminal reports the measurement information of each base station to the currently connected base station. The base station currently connected to the terminal determines the base station with the strongest signal strength as the target base station based on the measurement information, generates a switching request message based on the identifier of the target base station, and sends it to the AMF in the network security domain where the terminal is located, so as to prompt the UE accessed in the AMF network security domain to request switching to the network security domain where the target base station is located. So that the AMF in the network security domain where the terminal is located can control the base station switching of the terminal according to the switching request message and the target subscription data of the terminal.

[0116] Figure 6 Schematic diagram of the access control method provided in this embodiment of the application Figure 5 ,like Figure 6 As shown, the AMF in the network security domain where the terminal is located in the above step S103 determines whether to switch the terminal from the currently accessed base station to the target base station according to the target subscription data and the handover request message sent by the currently accessed base station, including:

[0117] S501. AMF uses the identifier of the target base station in the handover request message as an index, queries the identifier of the target base station in the target subscription data, and obtains the query result.

[0118] Optionally, the AMF in the network security domain where the UE is located uses the identifier of the target base station in the received switching request message as an index, queries whether the identifier of the target base station exists in the list of base stations to which the UE's downstream industrial equipment is allowed to access in the UE's target subscription data, and obtains the query result.

[0119] Exemplarily, the AMF in network security domain-2 uses the identifier of the base station RAN in network security domain-1 as an index, queries whether the identifier of the base station RAN in network security domain-1 exists in the target subscription data of the UE, and obtains the query result.

[0120] S502. The AMF determines whether to switch the terminal from the currently connected base station to the target base station based on the query result.

[0121] Optionally, the AMF in the network security domain where the UE is located makes a base station switching judgment based on the query result, determines whether to switch the UE from the currently connected base station to the target base station, and controls the base station switching of the UE based on the base station switching judgment result, so as to lock the UE in the currently connected base station when base station switching is not allowed, thereby achieving UE access control similar to the frequency locking effect.

[0122] Exemplarily, the AMF in network security domain-2 determines, based on the query result, whether to switch the UE from the base station RAN in network security domain-2 currently connected to the base station RAN in network security domain-1, so as to lock the UE in network security domain-2 or switch it to network security domain-1 based on the judgment result.

[0123] In this embodiment, the AMF in the network security domain where the terminal is located uses the identifier of the target base station in the received handover request message as an index to query the list of base stations in the terminal's target subscription data that allow the terminal to connect to industrial equipment to determine whether the identifier of the target base station exists, and obtains a query result. Based on the query result, a base station handover judgment is made to determine whether to switch the terminal from the currently connected base station to the target base station. Based on the base station handover judgment result, the terminal's base station handover is controlled. If base station handover is not allowed, the terminal is locked to the currently connected base station, achieving terminal access control similar to frequency locking.

[0124] As an optional implementation manner, in the above step S502, the AMF determines whether to switch the terminal from the currently connected base station to the target base station based on the query result, including:

[0125] If the AMF does not find the identifier of the target base station in the target subscription data, it refuses to switch the terminal from the currently connected base station to the target base station.

[0126] Optionally, if the AMF in the network security domain where the UE is located does not find the identifier of the target base station in the list of base stations to which the UE's downstream industrial equipment is allowed to access in the UE's target subscription data, it is determined that the UE is not allowed to access the target base station, and the AMF in the network security domain where the UE is located refuses to switch the UE from the currently connected base station to the target base station.

[0127] For example, when the AMF in network security domain-2 does not find the identifier of the base station RAN in network security domain-1 in the list of base stations to which the UE is allowed to connect to industrial equipment in the target subscription data of the UE, it refuses to switch the UE from the base station RAN in the currently connected network security domain-2 to the base station RAN in the network security domain-1, and locks the UE in the currently connected network security domain-2 to achieve a frequency locking effect.

[0128] In this embodiment, if the AMF in the network security domain where the terminal is located does not find the identifier of the target base station in the list of base stations to which the terminal's downlinked industrial equipment is allowed to access in the terminal's target subscription data, it is determined that the terminal is not allowed to access the target base station, and the AMF in the network security domain where the terminal is located refuses to switch the terminal from the currently connected base station to the target base station. Frequency locking control of the terminal is achieved.

[0129] Figure 7Schematic diagram of the access control method provided in this embodiment of the application Figure 6 ,like Figure 7 As shown, the above steps of refusing to switch the terminal from the currently connected base station to the target base station include:

[0130] S601. AMF generates a handover preparation failure message and sends it to the currently connected base station.

[0131] Optionally, when the AMF in the network security domain where the UE is located fails to find the identifier of the base station RAN in the network security domain-1 in the list of base stations to which the UE's downstream industrial equipment is allowed to access in the UE's target subscription data, a handover prepare failure (Handover Prepare Failure) message is generated and sent to the base station to which the UE is currently accessing through the N2 interface.

[0132] For example, when the AMF in network security domain-2 fails to find the identifier of the base station RAN in network security domain-1 in the list of base stations to which the UE's industrial equipment is allowed to be connected in the UE's target subscription data, it generates a switching preparation failure message and sends it to the base station RAN in network security domain-2 through the N2 interface.

[0133] S602: After receiving the handover preparation failure message, the currently connected base station continues to maintain the connection with the terminal and refuses the terminal to switch to the target base station.

[0134] Optionally, after receiving the handover preparation failure message sent by the AMF, the base station currently accessed by the UE continues to maintain the connection with the UE and refuses the UE to switch to the target base station. For example, after receiving the handover preparation failure message sent by the AMF, the base station RAN in network security domain-2 continues to maintain the connection with the UE, locks the UE in network security domain-2, and refuses the UE to switch to the base station RAN in network security domain-1.

[0135] In this embodiment, when the AMF in the network security domain where the terminal is located fails to find the identifier of the base station RAN in network security domain-1 in the list of base stations to which the terminal is allowed to connect to industrial equipment in the terminal's target subscription data, a handover preparation failure message is generated and sent to the base station currently connected to the terminal. After receiving the handover preparation failure message sent by the AMF, the base station currently connected to the terminal continues to maintain the connection with the terminal and refuses the terminal to switch to the target base station. This allows for convenient and efficient terminal frequency locking.

[0136] Figure 8 Schematic diagram of the access control method provided in this embodiment of the application Figure 7 , combined with Figure 8 , describes the overall interaction process of the access control method provided in this application.

[0137] Reference Figure 8 Taking the UE currently deployed in network security domain-2 as an example, the process of interaction between the network management server, the base station RAN, AMF, SMF, UDM function, UPF in the network security domain-2 and the UE deployed in the network security domain-2 in the 5G network system to implement UE access control includes:

[0138] S701: The network management server obtains and stores an access mapping table preset by a network administrator.

[0139] S702. The network management server generates initial subscription data for the UE.

[0140] S703 : The UDM function acts as a database slave node and adopts a data synchronization mechanism to obtain and store the initial subscription data of the UE.

[0141] S704: After being deployed in network security domain-2, the UE sends an access request to the base station RAN.

[0142] S705. The base station RAN forwards the access request to the AMF.

[0143] S706. AMF sends the UE's SUIP in the access request to SMF.

[0144] S707. The SMF sends a query request for the UE's initial subscription data to the UDM function using the UE's SUIP as an index.

[0145] S708. The UDM function sends the UE's initial subscription data to the SMF.

[0146] S709. SMF sends the data forwarding rules to UPF based on the UE's initial subscription data.

[0147] S710. SMF sends a PDU session establishment request to AMF.

[0148] S711. AMF forwards the PDU session establishment request to the base station RAN.

[0149] S712: The base station RAN sends radio resource configuration information to the UE and establishes a PDU session with the UE.

[0150] S713. AMF subscribes to the data change event of UDM.

[0151] S714 : The UE sends the identifier of the industrial device and the identifier of the currently connected base station to the base station RAN.

[0152] S715 : The base station RAN sends the identifier of the industrial device and the identifier of the currently connected base station to the UPF.

[0153] S716. The UPF forwards the identifier of the industrial device and the identifier of the currently connected base station to the network management server.

[0154] S717. The network management server modifies the initial subscription data of the UE according to the identifier of the industrial device and the identifier of the currently connected base station, and generates the target subscription data of the UE.

[0155] S718. The UDM function acts as a database slave node and adopts a data synchronization mechanism to obtain and store the target subscription data of the UE.

[0156] S719. AMF obtains and stores the target subscription data of the UE through the data change event.

[0157] S720: The UE detects the signal strength of the base stations in each network security domain, and reports the measurement information of each base station to the base station RAN.

[0158] S721. The base station RAN determines the target base station based on the measurement information of each base station, generates a handover request message according to the identifier of the target base station, and sends it to the AMF.

[0159] S722. AMF queries the target subscription data of the UE using the identifier of the target base station as an index.

[0160] S713. When the AMF finds that the identifier of the target base station is not in the target subscription data of the UE, it sends a handover preparation failure message to the base station RAN.

[0161] S724. The base station RAN receives the handover preparation failure message sent by the AMF, maintains the connection with the UE, and refuses to handover the UE to the target base station.

[0162] The specific execution methods of the above steps have been described in detail in the above embodiments and will not be repeated here.

[0163] An embodiment of the present application also provides a 5G network system, which includes: a network management server and multiple network security domains, each network security domain including at least: an AMF and a base station; the 5G network system is used to execute the steps of the access control method described in the aforementioned embodiment.

[0164] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.

[0165] In addition, the functional units in the various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0166] The above is only a specific implementation method of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the protection scope of the present application.

Claims

1. An access control method, characterized in that: Applied to a 5G network system, the 5G network system includes: a network management server and multiple network security domains, each network security domain includes at least: an access and mobility management function AMF and a base station; the method includes: The network management server obtains the identifier of the industrial device reported by the terminal and the identifier of the currently connected base station, wherein the industrial device is the industrial device connected to the terminal; The network management server generates target subscription data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station and writes the target subscription data into the network security domain where the terminal is located, wherein the target subscription data includes a list of base stations that the terminal is allowed to access; The AMF in the network security domain where the terminal is located determines whether to switch the terminal from the currently accessed base station to the target base station based on the target subscription data and the switching request message sent by the currently accessed base station, and the switching request message includes the identifier of the target base station.

2. The method according to claim 1, characterized in that The network management server generates target subscription data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station and writes the target subscription data of the terminal into the network security domain where the terminal is located, including: The network management server writes the initial contract data of the terminal into each network security domain, wherein the initial contract data is used to instruct the industrial equipment connected to the terminal to access the base station in each network security domain; The network management server modifies the initial contract data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station, obtains the target contract data of the terminal, and writes the target contract data into the network security domain where the terminal is located.

3. The method according to claim 2, characterized in that Each of the network security domains further includes: a unified data management (UDM) function; wherein the network management server serves as a database master node, the UDM function of each network security domain serves as a database slave node, and the UDM function of each network security domain establishes a data synchronization relationship with the network management server; The network management server writes the initial contract data of the terminal into each network security domain, including: The network management server uses a data synchronization mechanism to write the initial contract data of the terminal into the UDM function of each network security domain.

4. The method according to claim 3, characterized in that The network management server modifies the initial contract data of the terminal according to the identifier of the industrial device and the identifier of the currently connected base station, obtains the target contract data of the terminal, and writes the target contract data into the network security domain where the terminal is located, including: The network management server determines a list of base stations that the terminal is allowed to access based on the identifier of the industrial device and a pre-stored access mapping table; The network management server determines the network security domain where the terminal is located according to the identifier of the currently accessed base station, and uses the list of base stations that the terminal is allowed to access as the target subscription data of the terminal; The network management server uses the data synchronization mechanism to write the target subscription data of the terminal into the UDM function of the network security domain where the terminal is located.

5. The method according to claim 1, wherein Before the AMF in the network security domain where the terminal is located determines, according to the target subscription data and the handover request message sent by the currently accessed base station, whether to switch the terminal from the currently accessed base station to the target base station, including: The AMF subscribes to the data change event of the UDM function to obtain the target subscription data of the terminal through the data change event.

6. The method according to claim 1, characterized in that Before the AMF in the network security domain where the terminal is located determines, based on the target subscription data and the handover request message sent by the currently connected base station, whether to switch the terminal from the currently connected base station to the target base station, the method further includes: When the terminal detects that the signal strength of base stations other than the currently connected base station is stronger than the signal strength of the currently connected base station, the terminal reports the measurement information of each base station to the currently connected base station; The currently accessed base station determines the target base station according to the measurement information, generates a switching request message according to the identifier of the target base station, and sends it to the AMF in the network security domain where the terminal is located.

7. The method according to claim 1, characterized in that The AMF in the network security domain where the terminal is located determines, according to the target subscription data and the handover request message sent by the currently connected base station, whether to switch the terminal from the currently connected base station to the target base station, including: The AMF uses the identifier of the target base station in the handover request message as an index, queries the identifier of the target base station in the target subscription data, and obtains a query result; The AMF determines whether to switch the terminal from the currently connected base station to the target base station based on the query result.

8. The method according to claim 7, characterized in that The AMF determines, based on the query result, whether to switch the terminal from the currently connected base station to the target base station, including: If the AMF does not find the identifier of the target base station in the target subscription data, it refuses to switch the terminal from the currently connected base station to the target base station.

9. The method according to claim 8, characterized in that The refusing to switch the terminal from the currently connected base station to the target base station includes: The AMF generates a handover preparation failure message and sends it to the currently accessed base station; After receiving the handover preparation failure message, the currently connected base station continues to maintain the connection with the terminal and refuses the terminal from switching to the target base station.

10. A 5G network system, characterized in that: The 5G network system includes: a network management server and multiple network security domains, each network security domain includes at least: an access and mobility management function AMF and a base station; the 5G network system is used to execute the steps of the access control method described in any one of claims 1-9.

Citation Information

Patent Citations

  • Admission control method and device

    CN101945390A

  • 5G SA network Internet of Things terminal access and access restriction method and system, and medium

    CN116033377A

  • Robot collaborative operation method, control server and local network management server

    CN116634470A

  • Access control method, device, and storage medium

    WO2021046782A1

  • Multi-mode terminal access control method and apparatus, electronic device, and storage medium

    WO2023279776A1