A method, system, product, and media for authorizing special network resources
By introducing an automated forced reconnection mechanism and multi-dimensional diagnostics, the delay and failure issues of authorization control for special network resources in mobile communication networks have been resolved, achieving real-time and accurate authorization control and efficient resource management, thereby improving user experience and network resource utilization efficiency.
Patent Information
- Application Number
- CN202511156731.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2045-08-19
AI Technical Summary
In existing technologies, when mobile communication networks are controlling the authorization of special network resources, the strong binding between PDU sessions and data network names causes policy execution delays or failures when a complete switch of network identity is required, reducing the efficiency of high-security-level network resource authorization control.
An automated forced reconnection mechanism is introduced, which triggers a completely new network connection process by detecting changes in user location. This avoids complex policy modifications to existing connections and ensures that each access is assigned to the correct network based on real-time location and identity information. Multi-dimensional diagnostics and service-aware optimization switching strategies are adopted, combined with resource reservation and behavior pattern judgment, to optimize the authorization control process.
It achieves real-time and accurate authorization control, avoids delays caused by failed session modification, optimizes the efficiency of authorization control for special network resources, stabilizes user experience, and reduces resource waste and business interruption.
Smart Images

Figure CN120676359B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of electric digital data processing, and in particular to a method, system, product and medium for authorizing special network resources. BACKGROUND
[0002] With the in-depth development of the fifth generation mobile communication technology (5G) and the popularity of Internet of Things applications, the services carried by mobile networks are increasingly diversified and complex. In key scenarios such as enterprise parks, intelligent factories, and emergency communications, the network needs to provide dynamic, location-dependent differentiated services for specific users or devices. In order to support such network services, a special policy and control node is usually deployed in the mobile communication network. Among them, the AAA authentication platform is a core service component in the network architecture responsible for performing authentication, authorization, and accounting functions. By centrally managing user identity information and security policies, it verifies the legitimacy of users or devices attempting to access the network and allocates corresponding service permissions and resources to them.
[0003] In related technologies, in order to solve the problem of dynamic policy control based on user location, a scheme based on the core network policy control function (PCF) is proposed: the policy control function (PCF) subscribes to the location change events of the user to the access and mobility management function (AMF); when the user equipment moves into or leaves the target area set in advance, the AMF will actively report this location event to the PCF; after receiving the notification, the PCF will generate an update decision according to the pre-set policy, and issue this decision to the session management function (SMF), which is responsible for modifying the currently established protocol data unit (PDU) session, thereby adjusting the quality of service or updating the routing rules of the service flow.
[0004] However, when the special network resources are not just higher quality of service, but another completely isolated data network in the architecture (i.e. with a different data network name DNN / APN), modifying on the existing PDU session may cause logical conflicts, because a PDU session is strongly bound to the corresponding DNN from the beginning, and forcibly changing the target network affiliation exceeds the ability of the session modification mechanism. This underlying architectural limitation leads to delays or even failures in policy execution in scenarios where a complete network identity switch is required, thereby reducing the efficiency of high-security level network resource authorization control at critical moments. SUMMARY
[0005] The present application provides a method, system, product and medium for authorizing special network resources, which improves the efficiency of special network resource authorization control.
[0006] A method for authorizing special network resources is provided in the first aspect of the application, and the method comprises:
[0007] The system calls the accounting message, generates a first internal trigger signaling and sends it to the authorization module when detecting that the user location information in the accounting message moves from the preset non-special area to the preset special area, calls and sends a first reconnection instruction to the special session management function network element to trigger the user terminal to disconnect the current network and initiate reconnection, sends an authorization special network resource instruction to the authorization module after the system receives an access request message and a special network authorization judgment result, generates a second internal trigger signaling and sends it to the authorization module when the system detects that the user location information moves from the special area to the non-special area, calls and sends a second reconnection instruction to the general session management function network element, and sends an authorization general network resource instruction to the authorization module after the system receives an access request message.
[0008] In the above embodiment, by adopting the technical solution, the automatic forced reconnection mechanism is introduced, and the technical barrier that the existing technology cannot cross different data networks (DNNs) by modifying the PDU session is bypassed. When detecting the change of the user location, instead of attempting to make complex policy modifications on the existing connection, the scheme triggers a new network connection process, ensures that each access can be allocated to the correct network (whether special or general) according to real-time location and identity information, eliminates the authorization delay caused by the failure of session modification, ensures the immediate and accurate execution of the authorization control instruction, and improves the efficiency of the authorization control of the special network resources.
[0009] In combination with some embodiments of the first aspect, in some embodiments, the system calls the accounting message, generates a first internal trigger signaling and sends it to the authorization module when detecting that the user location information in the accounting message moves from the preset non-special area to the preset special area, and specifically comprises:
[0010] The system calls the accounting message, records the number of area switching times of the user within a preset time window when detecting that the user location information in the accounting message moves from the preset non-special area to the preset special area, acquires the real-time service type currently being processed by the user when the system judges that the number of area switching times exceeds a preset switching time threshold, generates a first internal trigger signaling and sends it to the authorization module if the system judges that the real-time service type is a preset key service type until the key service processing is completed, and generates a first internal trigger signaling and sends it to the authorization module if the system judges that the user continuously stays in the same area for a fixed duration that exceeds a preset fixed duration threshold during the delay period of processing the key service processing.
[0011] In the above embodiment, by introducing the judgment on the region switching frequency, firstly, the invalid reconnection caused by signal jitter at the region boundary is avoided, and on this basis, the perception ability of the real-time service type of the user is further integrated, by identifying and preferentially guaranteeing the preset key service, the system will immediately switch the strategy, and the flexible and timely switching is optimized, the reconnection operation is actively delayed until the key service is completed. Not only avoid the waste of resources on invalid switching, but also prevent the service interruption and its chain negative effect caused by improper switching time, so as to make the whole authorization control process more smooth and effective, thereby improving the efficiency of special network resource authorization control.
[0012] In combination with some embodiments of the first aspect, in some embodiments, the type of the real-time service currently being performed by the user is obtained, specifically comprising:
[0013] The system obtains a list of all concurrent services currently being performed by the user; the system identifies the type of each service in the concurrent service list; when the system determines that there are multiple key services corresponding to the preset key service types in the concurrent service list, the system obtains the predicted remaining processing time length of each key service; the system takes the longest predicted remaining processing time length as the delay waiting time length; within the delay waiting time length, the system periodically detects the change of the concurrent service list according to the preset delay detection period; in the case that the system detects that there is a new service in the concurrent service list and the new service type corresponding to the new service belongs to the key service type, the delay waiting time length is updated.
[0014] In the above embodiment, by obtaining and analyzing the concurrent service list of the user, the decision basis is improved from a single task to the overall working state, ensuring the comprehensiveness of the decision. By linking the delay time length with the longest predicted remaining processing time length of all key services, a safe waiting period that can completely cover all important activities of the user is constructed, avoiding the problem that other concurrent key services are interrupted due to considering only a single task. It is ensured that the network reconnection instruction is always executed at the optimal timing point with the least impact on the user, which not only guarantees the continuity of the key service, but also eliminates the risk of service interruption caused by improper timing, making the whole authorization instruction issuing process more smooth and improving the efficiency of special network resource authorization control.
[0015] In combination with some embodiments of the first aspect, in some embodiments, after the system receives the access request message and the special network authorization judgment result, the authorization special network resource instruction is sent to the authorization module, specifically comprising:
[0016] In the case that the system receives the access request message, the special network authorization judgment result, and detects that the first access request message is a retransmission request, the system obtains the historical reconnection success rate of the user, the network signal strength of the current location, and the load state of the special session management function network element; the system determines whether the backup access condition is met according to the historical reconnection success rate, the network signal strength, and the load state; when the backup access condition is met, the system forwards the access request message to the preset backup special session management function network element; after receiving the access response of the backup special session management function network element, the system sends the authorized special network resource instruction to the authorization module.
[0017] In the above embodiment, by triggering multi-dimensional diagnosis when detecting a retransmission request, the authorization control is upgraded from passive instruction execution to active fault analysis and response capability, not relying on a single indicator, but through comprehensive evaluation of user history, current environment and network load, a robust fault prediction model is constructed, which can identify scenarios that are highly likely to fail repeatedly, thereby avoiding wasting system resources and user time on invalid retries, and the request can be forwarded to a backup special session management function network element. This operation of bypassing potential fault points in advance shortens the delay of obtaining authorized access by the user in complex or poor network environments, ensures the final success rate of connection, and improves the efficiency of special network resource authorization control.
[0018] In combination with some embodiments of the first aspect, in some embodiments, the system forwards the access request message to the preset backup special session management function network element, specifically comprising:
[0019] The system obtains a state list of all backup special session management function network elements in the special area; when the load states of all backup special session management function network elements in the state list are higher than the preset load threshold, the system obtains the service priority of the user; the system obtains a service priority list of all users currently accessing the backup special session management function network element; when the service priority of the user is higher than the lowest priority in the service priority list, the system sends a session release instruction to the low-priority backup special session management function network element currently accessed by the low-priority user corresponding to the lowest priority; after detecting that the session release instruction is executed, the system forwards the access request message to the low-priority backup special session management function network element.
[0020] In the above embodiment, in the face of a scenario where the standby resource is also completely exhausted, by introducing the key criterion of service priority, the authorization control is upgraded from the first-come-first-served resource allocation mode to the value-based dynamic resource scheduling mode, and by comparing the priorities of the requesting users and the accessed users, it can be identified which connection request should be prioritized when the resources are extremely scarce. The step of sending the session release instruction is a decisive operation to realize resource scheduling, which actively recovers the resources occupied by low-value services, ensuring that even at the most congested moment of the network, high-priority critical service requests can squeeze out non-critical services to obtain the necessary network authorization and connection, so as to prioritize the use of limited resources to key services, turning a dead end that would lead to authorization failure into a successful operation that guarantees the continuity of critical services, thereby improving the efficiency of special network resource authorization control.
[0021] In combination with some embodiments of the first aspect, in some embodiments, before the system detects that the user location information in the accounting message moves from the preset non-special area to the preset special area, the first internal trigger signaling is generated and sent to the authorization module, the system further includes:
[0022] The system obtains the location change trend and the moving speed of the user through the user location information in the accounting message; when the location change trend points to the special area, and it is judged according to the moving speed that the user will arrive at the special area within the first time, the system calculates the number of special users entering the special area within the first time; the system determines the reserved quota of the special network resource according to the number of special users; the system sends a resource reservation instruction to the special session management function network element; the system allocates the special network resource from the reserved quota when the user enters the special area; when the first time ends, the system releases the unused reserved quota.
[0023] In the above embodiment, by analyzing the location change trend and the moving speed of the user, the transition from post-response to pre-preparation is realized. By calculating the total number of special users within the predicted time to determine the resource reservation quota, the resource planning is extended from a single user to a user group, which can cope with the scenario of team concentrated entry and high concurrency. When the user actually arrives, there is no need to go through the cumbersome real-time application, queuing and resource arbitration, but directly obtains the service from the ensured reserved quota, which compresses the authorization delay and eliminates the access pressure caused by instantaneous congestion, thereby improving the efficiency of special network resource authorization control.
[0024] In combination with some embodiments of the first aspect, in some embodiments, before the system detects that the user location information in the accounting message moves from the preset non-special area to the preset special area, the first internal trigger signaling is generated and sent to the authorization module, the system further includes:
[0025] The system records the number of area switching times of the user within a preset time window; when the number of area switching times exceeds a preset threshold of switching area times, the system respectively acquires the residence duration of the user in the special area and the non-special area within the time window; the system calculates the cumulative residence duration proportion of the user in the special area; when the cumulative residence duration proportion is higher than a preset proportion threshold, the system marks the user as a boundary user; the system keeps the access state of the current special network resource or the ordinary network resource for the boundary user; every preset detection time, the system recalculates the cumulative residence duration proportion, and when it is detected that the cumulative residence duration proportion is not higher than the preset proportion threshold, the boundary user mark is cancelled.
[0026] In the above embodiment, by recording the number of area switching times of the user, the abnormal behavior pattern of frequently moving at the area boundary can be recognized, so that the authorization control is changed from the location triggering to the intelligent judgment based on the behavior pattern. When the number of switching times exceeds the threshold, the cumulative residence duration proportion of the user in the special area is further calculated, which can distinguish whether the user really leaves or just wanders at the boundary. Based on this judgment, the user who mainly resides in the special area is marked as a boundary user, and the strategy of keeping the current network access state is adopted, which directly avoids a large number of and continuous resource release and reapplication signaling interaction. The inhibition of invalid switching not only stabilizes the service experience of the user, but also eliminates the invalid occupation of the core network signaling resource, so that the authorization control logic is no longer frequently disturbed by the instantaneous physical location, and the efficiency of the authorization control of the special network resource is improved.
[0027] In a second aspect, the embodiments of the present application provide a system for authorizing special network resources, the system comprising: one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is configured to store computer program codes, the computer program codes comprising computer instructions, and the one or more processors are configured to invoke the computer instructions to enable the system for authorizing special network resources to perform the method described in the first aspect and any possible implementation manner of the first aspect.
[0028] In a third aspect, the embodiments of the present application provide a computer program product comprising instructions, which, when executed on a system for authorizing special network resources, enable the system for authorizing special network resources to perform the method described in the first aspect and any possible implementation manner of the first aspect.
[0029] In a fourth aspect, the embodiments of the present application provide a computer readable storage medium comprising instructions, which, when executed on a system for authorizing special network resources, enable the system for authorizing special network resources to perform the method described in the first aspect and any possible implementation manner of the first aspect.
[0030] It can be understood that the system for authorizing special network resources provided in the second aspect, the computer program product provided in the third aspect, and the computer storage medium provided in the fourth aspect are all used to execute the method for authorizing special network resources provided in the embodiments of the present application. Therefore, the beneficial effects that can be achieved are referable to the beneficial effects in the corresponding method, which will not be repeated here.
[0031] The one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:
[0032] By adopting the technical solutions, the automatic forced reconnection mechanism is introduced, the technical barrier that the modification of the PDU session cannot cross different data networks (DNNs) in the prior art is bypassed. When the user location change is detected, instead of attempting to make complex policy modification on the existing connection, a brand-new network connection process is triggered, ensuring that each access can be allocated to the correct network (whether special or normal) according to real-time location and identity information, eliminating the authorization delay caused by the failure of session modification, ensuring the instant and accurate execution of the authorization control instruction, and improving the efficiency of the authorization control of the special network resources.
[0033] By introducing the judgment on the region switching frequency, the invalid reconnection caused by signal jitter at the region boundary is avoided, and on this basis, the real-time service type of the user is further perceived, the preset key service is identified and preferentially guaranteed, the system will immediately switch the strategy to flexible and timely switching, and the reconnection operation is actively delayed until the key service is completed. Not only the waste of resources on invalid switching is avoided, but also the service interruption and its chain negative effects caused by improper switching time are prevented, so that the entire authorization control process is smoother and more effective, and thus the efficiency of the authorization control of the special network resources is improved.
[0034] 3、By recording the number of region switching of the user, the abnormal behavior pattern of frequent movement at the region boundary can be identified, so that the authorization control is changed from the location trigger to the intelligent judgment based on the behavior pattern. When the number of switching exceeds the threshold, the proportion of the cumulative residence duration of the user in the special region is further calculated, which can distinguish whether the user really leaves or just wanders at the boundary. Based on this judgment, the user who mainly resides in the special region is marked as a boundary user, and the strategy of maintaining the current network access state is kept, directly avoiding a large number of and continuous resource release and reapplication signaling interaction. This inhibition of invalid switching not only stabilizes the service experience of the user, but also eliminates the invalid occupation of the signaling resources of the core network, so that the authorization control logic is no longer frequently disturbed by the instantaneous physical location, and the efficiency of the authorization control of the special network resources is improved. BRIEF DESCRIPTION OF DRAWINGS
[0035] Figure 1 is a flowchart of a method for authorizing special network resources in an embodiment of the present application;
[0036] Figure 2 is another flowchart of a method for authorizing special network resources in an embodiment of the present application;
[0037] Figure 3 is an exemplary hardware structure diagram of a system for authorizing special network resources in an embodiment of the present application. DETAILED DESCRIPTION
[0038] The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments and are not intended to be limiting of the present application. As used in the specification and the appended claims of the application, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "and / or," as used in the specification and in the claims, are used to allow for any and all possible combinations of one or more of the associated listed items.
[0039] Hereinafter, the terms "first" and "second" are only for the purpose of description and cannot be understood as implying or suggesting relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first" and "second" can explicitly or implicitly include one or more of the features, and in the description of the embodiments of the present application, the meaning of "a plurality of" is two or more, unless otherwise specified.
[0040] In the related art, in order to solve the problem of dynamic policy control based on user location, the existing scheme usually relies on the policy control function (PCF) of the core network to implement. Its working mode is: the PCF subscribes to the user location change event of the access and mobility management function (AMF), when the user enters or leaves a certain area, the AMF reports the event, and the PCF instructs the session management function (SMF) to modify the currently established protocol data unit (PDU) session to change the service. However, when the special network resource and the ordinary network resource are two independent networks that are completely isolated in architecture and have different data network names (DNNs), a PDU session is strongly bound to its DNN from the beginning of its establishment. Trying to modify an existing session in the ordinary network to switch to a completely new special network exceeds the ability of the session modification mechanism. This limitation of the underlying architecture causes the policy execution to be delayed or even failed due to logical conflicts, thereby reducing the efficiency and reliability of the authorization control of the special network resource.
[0041] In the embodiment of the present application, an innovative forced reconnection mechanism is adopted. When the system detects that the user location has changed across areas through the accounting message, it no longer attempts to modify the existing session which is difficult to change. Instead, the authorization module generates and sends a reconnection instruction to actively trigger the user terminal to disconnect the current connection and immediately initiate a new network access request. The authentication and authorization module can guide the user to the correct target network according to the user's current accurate location (special or non-special area) and confirmed identity (whether it is a special user) from the beginning in this new process, allocate the corresponding session management function network element and authorize resources. This push-down reconstruction strategy bypasses the restrictions on modification of the existing session, enabling the network home switch instruction to be executed immediately and accurately, improving the efficiency of special network resource authorization control.
[0042] Figure 1 is a flowchart of a method for authorizing special network resources in the embodiment of the present application, including the following steps:
[0043] S101, the system calls the accounting message, and when it detects that the user location information in the accounting message moves from a preset non-special area to a preset special area, generates a first internal trigger signaling and sends it to the authorization module.
[0044] Wherein, the system refers to the system for authorizing special network resources, which is an integrated network policy and control entity responsible for decision-making and scheduling of the entire authorization process, including the AAA platform, wherein the AAA platform includes an authentication template, an authorization template and an accounting template; the accounting message indicates a data packet carrying user session statistical information, such as the Accounting-Request message in the RADIUS protocol or the Credit-Control-Request (CCR) message in the Diameter protocol, which contains information such as the user's online duration, traffic usage, current location, etc., obtained by continuously parsing the accounting module; the non-special area and the special area refer to two different service level areas logically divided by a preset strategy (such as a set of TAI list or a geofence polygon), the special area is usually associated with higher quality or specific access rights network resources; the first internal trigger signaling refers to a logical signal for starting the special resource authorization process transmitted between the modules in the system, which can be a function call, a message in a message queue or a change in a shared memory state; the accounting module is used to receive and parse the accounting message.
[0045] Specifically, the billing module, as a continuously running daemon process or service, constantly listens to periodic billing update messages sent from network access servers (NAS) or session management function (SMF) network elements. Upon receiving a billing message, the billing module parses the user location information field therein. The system internally predefines one or more lists of definitions of special areas, which map specific location identifiers (such as TAI / CGI lists) to special area attributes. The system compares the newly parsed location information with the last recorded location information of the same user. When and only when the last location is in a non-special area and the current location has entered a special area, the system determines that the user has crossed the border into the special area, instantiates a first internal trigger signaling, and routes the first internal trigger signaling to the authorization module, where the first internal trigger signaling carries the user identifier, target area information, and other contexts.
[0046] In some embodiments, after the system detects that the user has entered a special area, an intelligent delay switching mechanism based on service awareness can also be introduced to perform network switching under the premise of guaranteeing the continuity of key services, thereby avoiding user service interruption caused by forced reconnection and improving user experience.
[0047] When the system first detects that the user has entered a special area, a state monitor is first activated. The state monitor maintains a moving history record queue with a preset time window for the user session. Each time a crossing event from a non-special area to a special area occurs, the system adds a timestamp to the queue. At the same time, the system calculates the total number of such events within the time window, i.e., the number of area switching. When the number of area switching exceeds the preset switching threshold, the system determines that the current state is potentially unstable border roaming. The theoretical basis of this determination is that frequent area switching in a short period of time means that the user's geographic location is unstable, and immediately performing a network reconnection operation (such as S102) with a higher cost is likely to become meaningless after the user moves next time, but will instead cause unnecessary signaling overhead and service interruption.
[0048] When the system confirms that the user has unstable border roaming or directly determines that service protection is needed, the decision logic goes from macro location state analysis to user service flow analysis.
[0049] The system first acquires the list of all concurrent services currently being conducted by the user. In terms of technical implementation, this can be accomplished in two main ways: through deep linkage with the core network policy control function (PCF), the system can query the policy information associated with the user PDU session, which usually contains the service flow descriptor (SDF template) or the corresponding QoS flow identifier (QFI), thereby indirectly identifying the service type; or the system can integrate or call the deep packet inspection (DPI) function, which analyzes the IP five-tuple, protocol feature code, signaling interaction, etc. to directly identify the type of each service flow, such as VoIP, video conference, online payment, etc.
[0050] After obtaining the service list, the system compares the list with the internal preset key service type policy library. This policy library is configurable and defines which service types (such as financial transaction, real-time communication, large data transmission) have zero tolerance for network interruption, i.e. key services. If the system finds one or more key services being conducted in the concurrent service list, it will temporarily suspend the generation of the first internal trigger signaling. Because forced reconnection will cause TCP connection interruption and UDP stream loss, which is fatal to these key services, the system calculates an appropriate delay waiting duration at this time.
[0051] In order to calculate the delay duration, the system evaluates the estimated remaining processing duration of each key service. This evaluation depends on the service type: for file download / upload and other services with a clear size, the transmitted byte number and the total file size (usually obtained from the Content-Length field in the HTTP Header) can be used for estimation; for streaming media or online conference services with indefinite duration, the session duration parameter in the session establishment signaling (such as SIP INVITE) can be analyzed, or a more conservative preset default duration can be used. The system will iterate through all concurrent key services and take the longest estimated remaining processing duration as the final delay waiting duration, which ensures that the last service to end among all key services is also fully protected. During the delay waiting period, the system will continuously poll the user's service list at a short delay detection period (such as every 5 seconds), and if a new key service is detected, the system will recalculate the total delay waiting duration and update the current waiting timer with a new, possibly longer time.
[0052] There are two exits for the termination of the delay waiting state. One is normal exit: when the delay waiting time ends, it means that all critical services have been naturally completed, at which time the system generates and sends the first internal trigger signaling. The second is timeout forced exit: in order to prevent an abnormal service (such as a download that can never be completed) from causing the system to wait indefinitely, the system also has a fixed time threshold (for example, 3 minutes). If the system monitors that the user stays in a special area for more than the fixed time threshold, regardless of whether the service is completed, the system will forcibly generate the first internal trigger signaling to ensure the final execution of the network switching strategy.
[0053] Through the technical steps, the system fully considers the stability of the network state and the continuity of the user service before executing the network switching, thereby improving the overall efficiency of the special network resource authorization control. Through the boundary state stability judgment, the system can filter out invalid or high-risk switching trigger requests generated by the user's frequent movement at the boundary of the area, avoid starting the authorization and reconnection process that may be invalidated due to the user moving out again, and reduce unnecessary signaling interaction and system internal processing overhead. Through the critical service continuity guarantee, the system intelligently coordinates the execution time of the authorization control with the service state of the user, preventing critical services from failing due to forced switching and avoiding the user having to initiate reconnection, re-authentication, and a new round of authorization requests due to service interruption. In summary, this method makes the authorization control behavior more accurate by reducing invalid triggers and avoiding failed retries, thereby improving the efficiency of special network resource authorization control.
[0054] In some embodiments, before the user enters the special area, the system can also reserve network resources in batches in advance to deal with sudden and high-density user access scenarios, thereby reducing the resource allocation delay when the user switches to the special network.
[0055] Specifically, the trigger point of resource allocation is moved from post-response to pre-prediction, so that the time-sensitive resource application and allocation process is divided into two stages: non-real-time reservation and real-time allocation. First, the system continuously and dynamically calls and analyzes the accounting messages of the user. In modern mobile communication networks (such as 5G), these accounting messages are usually generated by the Access and Mobility Management Function (AMF) or the Session Management Function (SMF), and contain user location information such as Tracking Area Identifier (TAI) or Cell Global Identifier (CGI). By performing time series analysis on the accounting messages with timestamps generated continuously by a user, the system can construct a mobile model of the user. By comparing two or more location points before and after, the system can not only calculate the instantaneous speed of the user, but also infer the trend of location change, i.e., the direction and path of movement, by using algorithms such as Kalman filtering and trajectory prediction based on a longer sequence of location data.
[0056] Secondly, when the system determines that the movement trend of one or more users is clearly directed to a certain preset special area, and calculates that it will arrive at the area within a certain time window (i.e. the first time, such as within 1 minute in the future) according to the movement speed, the predictive analysis stage enters the resource planning stage. The system real-time statistics the total number of users that meet the above prediction conditions, i.e. the number of special users. Based on this dynamically calculated number of special users that will arrive, further determine the special network resource reservation quota that needs to be reserved for this batch of users. The calculation of this quota can be based on various strategies, such as simple per capita allocation (each user reserves one standard resource unit), or more detailed quota calculation according to the average user service model analyzed from historical data (for example, among the predicted 100 users, 30% may need high-definition video bandwidth, and 70% need ordinary browsing bandwidth). The advantage of this is that the originally scattered resource requests that may be generated concurrently when the user arrives are converged into a batch of unified resource planning tasks, reducing the instantaneous pressure of the resource management system.
[0057] Finally, the system sends a resource reservation instruction carrying this reservation quota information to a special session management function network element (which can be understood as a dedicated SMF or policy control unit) responsible for managing special network resources. After receiving the instruction, the network element will reserve a resource pool of corresponding quantity and specification in the underlying network infrastructure (such as UPF). When subsequent users (such as S101) actually enter the special area and initiate access requests, the system does not need to go through complex resource searching, negotiation and creation processes, but directly allocates from this already prepared reservation quota pool. In order to ensure resource utilization, after the first time window used for prediction ends, the system will trigger a recycling mechanism to release all unused resources in the quota pool back to the general resource pool, completing a complete resource reservation and recycling closed-loop management.
[0058] The above technical steps front-load and batch the resource allocation link in the authorization control process. Through prediction, the system converts a large number of concurrent and time-sensitive real-time authorization applications into a one-time and non-real-time batch resource reservation. When the user really needs authorization access, the most time-consuming resource preparation work has been completed, and the system only needs to perform fast allocation, effectively avoiding inefficient situations such as resource competition, allocation failure or authorization timeout caused by the influx of users, and improving the efficiency of authorization control as a whole.
[0059] S102, the system calls and sends a first reconnection instruction to the special session management function network element to trigger the user terminal to disconnect the current network and initiate reconnection.
[0060] Among them, the special session management function network element (Special SMF) refers to a network function entity in the 5G core network, which is specially responsible for establishing and managing PDU (Protocol Data Unit) sessions for special area users, and can allocate resources with special QoS policy or access to specific data network (DNN); The first reconnection instruction refers to a signaling initiated by the system, which requires the network side to forcibly interrupt the current session of the specific user, which is usually Disconnect-Request (also known as PoD, Packet of Disconnect) in RADIUS protocol, and ASR (Abort-Session-Request) in Diameter, which is generated after the authorization module responds to the first internal trigger signaling; The user terminal refers to the user's mobile device, such as a smartphone, a notebook computer, etc.
[0061] Specifically, after the authorization module confirms that the first internal trigger signaling in S101 is received and processed, the first reconnection instruction is generated. The generation process of the instruction includes: determining the user session identifier (such as Acct-Session-Id) that needs to be disconnected, the unique identifier of the user (such as User-Name), and the address of the network access point currently providing service for the user (such as NAS-IP-Address), and encapsulating these information into a standard format of reconnection instruction data packet, and the system calls and sends to the network element (which may be a normal SMF or its associated UPF / PGW) currently managing the user session. After receiving and verifying the instruction, the network element will immediately remove the user's PDU session, and this action will eventually be transmitted to the user terminal, which will be manifested as network connection interruption. According to the reconnection policy of the terminal, a new network connection request will be automatically initiated immediately.
[0062] In some embodiments, the forced reconnection of the user session can be achieved in various ways: optionally, through the standard mechanism of the AAA protocol: after responding to the internal signaling, the authorization module queries the key attributes of the RADIUS session of the user from the session cache of the system, including Acct-Session-Id, User-Name, NAS-IP-Address and NAS-Identifier; The system constructs a RADIUS Disconnect-Request message, fills the above attributes into the message, and signs it using the shared key with the NAS; The system sends the message to the network device corresponding to the NAS-IP-Address to trigger the user to forcibly log out.
[0063] It can be understood that other ways can also be used to achieve user reconnection, such as sending instructions to AMF to trigger UE to re-register, etc., as long as the effect of making the user re-initiate access request can be achieved, which is not limited here.
[0064] S103, after the system receives the access request message and the special network authorization judgment result, sends an authorization special network resource instruction to the authorization module.
[0065] The access request message refers to a network connection request reinitiated by the user terminal after being forcibly disconnected, which is embodied as an Access-Request message in the AAA system; the special network authorization judgment result is a Boolean type logical conclusion, and the condition for its value being true is that the logical and operation result of two sub-conditions is true, the first sub-condition is that the authentication module confirms that the user identity is legal and the user portrait or subscription information thereof indicates that it has special user qualifications; the second sub-condition is that the authorization module re-verifies the location information in the access request and confirms that the user is indeed located in the preset special area. The authorization special network resource instruction refers to a successful response message generated by the system after completing all judgments, which contains specific authorization parameters, such as RADIUS Access-Accept, which carries special APN, high priority QoS Profile, specific IP address pool and other attributes.
[0066] Specifically, when the access request message arrives at the system, the system will concurrently perform authentication and authorization checks. The authentication module will extract the user credentials (such as username / password or certificate) in the request, compare them with the user information in the background database (such as HSS / UDM), verify the legality, and check whether the subscription profile contains the special user mark. At the same time, the authorization module will parse the location information in the request message and match it with the definition of the special area in the system to prevent the user from moving out of the special area during reconnection. Only when the authentication module returns “special user, legal” and the authorization module returns “location matching”, the special network authorization judgment result is successful. At this time, the system triggers the authorization module to construct an authorization special network resource instruction, which carries a series of preset VSA (Vendor-Specific Attributes) for allocating special resources, and sends it as a response to the network access device, finally completing the special network resource authorization.
[0067] S104, when the system detects that the user location information moves from the special area to the non-special area, a second internal trigger signaling is generated and sent to the authorization module.
[0068] The second internal trigger signaling is similar to the first internal trigger signaling, which is a communication signal between internal modules of the system, but the intention is opposite, which is used to start the process of switching the user from the special network resource back to the ordinary network resource.
[0069] Specifically, the execution logic of this step is symmetrical to S101, which is the trigger mechanism when the user leaves the special area. The billing module in the system also continuously receives and analyzes the user's billing update messages. The system will continuously compare the latest user location information carried in the message with the user's historical location state. When the system detects that the user's last recorded location belongs to the special area, and the location information in the billing message received this time has changed to a non-special area, it is determined that the user has left the special area, and a second internal trigger signaling is generated. The second internal trigger signaling explicitly indicates that the event type is leaving the special area, and contains the necessary user identification information, and then sends it to the authorization module. After receiving it, the authorization module begins to prepare to perform the downgrade or recovery operation of network resources.
[0070] In some embodiments, the detection of the leaving event can be achieved in various ways: optionally, based on the timeout mechanism of billing updates: after the user enters the special area and successfully accesses the special network, the system sets a special timer (e.g. 60 seconds) for its session; the billing module resets the timer every time it receives a billing update from the user and the location information is still within the special area; if the timer expires, it means that the system has not received proof of the user's location within the special area within the specified time, and the system determines that the user has left and generates a second internal trigger signaling. It can be understood that multiple ways can be combined for judgment, for example, only when billing timeout and AMF switching event occur at the same time is the user confirmed to have left, to increase the accuracy of the judgment, which is not limited here.
[0071] S105, the system sends a second reconnection instruction to the normal session management function network element.
[0072] Among them, the normal session management function network element (Normal SMF) refers to a network function entity in the 5G core network that is responsible for providing standard PDU session management services for ordinary users or users in non-special areas; the second reconnection instruction is essentially the same as the first reconnection instruction, both of which are a signaling that forces the user session to be interrupted, but the context and target are different, aiming to interrupt the user's connection with the special network.
[0073] Specifically, this step is a proactive measure taken by the system after the user leaves the special area. After the authorization module responds to the second internal trigger signaling in S104, the system generates a second reconnection instruction, and the target of the instruction is the special SMF currently providing special network services for the user. The system encapsulates the user's session identification and other information into the instruction and sends it to the special SMF or its associated access device. After receiving the instruction, the special SMF removes the current user's PDU session and forces the user terminal to reinitiate a network connection. Since the user is now in a non-special area, the new connection request will be directed to a normal SMF by the routing strategy in the network, thereby achieving smooth degradation of the network.
[0074] In some embodiments, the switching to the normal network can be achieved in various ways: optionally, a seamless switching policy modification manner: after the response, the system (as a PCF) sends an SM PolicyControl Update message to the currently serving special SMF; instead of releasing the session, the message contains a set of normal policy set, for example, the QoS parameter (such as 5QI) is reduced to the normal level, and the SMF is instructed to switch the traffic flow to the UPF path connected to the normal data network; the special SMF performs policy update, and under the premise of not interrupting the PDU session, the quality of service and network access of the user are downgraded to the normal standard, realizing a smoother experience. Optionally, a DNS redirection-based switching manner: after responding to the second internal trigger signaling, the system updates the internal DNS or service discovery record, and points the service request of the user to a normal SMF pool; the system then sends a second reconnection instruction to the special SMF, forcing the user to log out; when the user terminal reconnects, the AMF will select a new SMF in the normal pool for the user according to the (updated) DNS query result, thereby completing the switching. It can be understood that the selection of the implementation manner depends on the trade-off between the business continuity and the signaling overhead of the operator, which is not limited here.
[0075] S106, after the system receives the access request message, an authorization normal network resource instruction is sent to the authorization module.
[0076] The authorization normal network resource instruction refers to a successful response message containing normal and standard authorization parameters generated by the system after confirming that the user should be granted standard service, which is received by the authorization module to authorize the user to access normal network resources, such as an Access-Accept message not carrying any special VSA.
[0077] Specifically, after the user terminal is forced to log out and reinitiates connection, an access request message is sent to the system. After the system receives this message, the authorization module will execute the standard authorization logic, and since the location information in the request message at this time has been confirmed as a non-special area, the policy matching logic of the authorization module will fall back to apply the default, globally applicable normal user policy. The system triggers the authorization module to generate an authorization normal network resource instruction accordingly. The instruction only contains basic and standard network service parameters, such as standard QoS configuration, default APN / DNN, and an address from a normal IP address pool. This instruction is sent back to the network side, and the end user terminal is granted normal network resources, completing the complete switching from the special to the normal network.
[0078] In some embodiments, the authorization of the common resource can be implemented in various ways: optionally, application based on a default policy set: the system receives an access request message, parses the user identity and its current location (non-special area); the policy engine of the authorization module matches the policy rules in priority order, and since the location does not match, all high-priority special area policies are matched unsuccessfully; the engine finally matches the default global policy with the lowest priority, which contains the standard network parameters defined for all common users. The system generates an Access-Accept response based on this policy. It can be understood that other authorization methods can also be used, such as applying different common policies according to the type of the non-special area where the user is currently located (such as a business district or a residential area) to achieve more refined standard services, which are not limited here.
[0079] In the above embodiments, by using the technical solutions described above, by introducing an automatic forced reconnection mechanism, the technical barrier that the modification of the PDU session cannot cross different data networks (DNNs) in the prior art is bypassed. When detecting a change in the user's location, instead of attempting to make complex policy modifications on the existing connection, the scheme triggers a brand new network connection process, ensuring that each access can be allocated to the correct network (whether special or common) according to real-time location and identity information, eliminating authorization delays caused by session modification failures, ensuring the immediate and accurate execution of authorization control instructions, and improving the efficiency of special network resource authorization control.
[0080] In some embodiments of the present application, when a sudden large-scale service request occurs in a special area, causing the primary and backup special network resources to be in an extremely congested state of high load, all new service requests can be rejected, causing service impact. By using the method for authorizing special network resources provided by the present application, a pre-emptive access policy based on service priority can be started to actively release resources occupied by low-priority users and provide resources to high-priority users in priority.
[0081] As shown in Figure 2 , another flowchart of the method for authorizing special network resources provided by the embodiments of the present application, comprising the following steps:
[0082] S201, the system calls an accounting message, and when detecting that the user location information in the accounting message moves from a preset non-special area to a preset special area, generates a first internal trigger signaling and sends it to the authorization module.
[0083] Step S201 is similar to step S101 in the embodiment shown in Figure 1 , and reference can be made to the description in step S101, which will not be repeated here.
[0084] In some embodiments, for the scenario that users frequently move at the boundary of special and non-special areas, the system can also introduce a boundary user identification and access state maintenance mechanism to optimize the resource authorization control logic by suppressing invalid network switching, thereby improving the stability and efficiency of the overall system.
[0085] Firstly, the system continuously monitors and preliminarily filters the user's moving behavior, records the number of area switching between special and non-special areas within a preset time window (e.g., the past 5 minutes) by analyzing the user's continuous billing messages or location reporting events. When the number of switching exceeds a preset threshold of switching area number, the system identifies the user as a boundary wandering user, filters out a large number of stable residence or one-way moving users, and focuses only on the target individuals with high-frequency moving characteristics, thereby reducing the overall system analysis load.
[0086] Secondly, for boundary wandering users, the system traces back the complete moving trajectory of the user within the same time window, calculates the cumulative residence time in the special area and the cumulative residence time in the non-special area. Then, the system calculates the cumulative residence time ratio by the formula cumulative residence time ratio = cumulative residence time in special area / (cumulative residence time in special area + cumulative residence time in non-special area), and further analyzes the user's behavior. For example, a user may switch 10 times, but 99% of the time is in the non-special area, which is only a short cross-border; while another user may only switch 4 times, but 50% of the time is in the special area, which is a boundary activity.
[0087] Next, the system compares the calculated cumulative residence time ratio with a preset ratio threshold. When the ratio is higher than the threshold, the system formally marks the user as a boundary user. The network resource state of the boundary user is temporarily frozen, i.e., the access state of the current special network resource or ordinary network resource is maintained. This means that if the user is marked while using special network resources, the system will not immediately reclaim resources even if he moves temporarily to a non-special area; conversely, if he is using ordinary resources at the time, the system will not immediately initiate a special resource authorization process for him even if he temporarily enters a special area.
[0088] Finally, the system re-executes the above-mentioned cumulative residence time ratio calculation for all marked boundary users at a preset detection time (e.g., every 1 minute). Once it is found that the latest ratio of a certain user is no longer higher than (i.e., equal to or lower than) the preset threshold, the boundary user mark is immediately canceled, and the user returns to the regular, immediate response authorization control logic.
[0089] The technical step effectively avoids the massive redundant signaling caused by the user at the boundary of the area by introducing a state retention strategy, avoids triggering the complete resource application, authorization, establishment and release process by identifying the boundary user and taking a non-response strategy for the temporary location change of the boundary user, reduces the invalid processing load of the control plane network element (such as the authorization module and the session management function network element), and can more efficiently serve the user request that truly needs to establish or change the service, thereby improving the efficiency of the special network resource authorization control.
[0090] S202, the system calls and sends a first reconnection instruction to a special session management function network element to trigger the user terminal to disconnect the current network and initiate reconnection.
[0091] S203, after the system receives the access request message and the special network authorization judgment result, an authorization special network resource instruction is sent to the authorization module.
[0092] Steps S202-S203 are similar to steps S102-S103 in the embodiment shown in Figure 1 The steps S102-S103 in the embodiment shown in
[0093] S204, in the case where the system receives the access request message, the special network authorization judgment result, and detects that the first access request message is a retransmission request, the historical reconnection success rate of the user, the network signal strength of the current location, and the load state of the special session management function network element are obtained.
[0094] The retransmission request refers to a reconnection attempt initiated by the user terminal (UE) automatically due to the fact that the user terminal (UE) does not receive an effective response from the network side within a preset time after the first access request, and is a direct indicator of initial connection failure. The historical reconnection success rate is a statistical indicator for a specific user, which is calculated by the ratio of the number of successful attempts to the total number of attempts for the user to connect or reconnect to the special network within a period of time (for example, the past month) in the history, and is used to evaluate the inherent stability of the user's connection behavior. The network signal strength is a real-time physical measurement value indicating the wireless channel quality at the location of the user terminal, which is usually measured by the terminal and included in the access request message, and the key parameters can be the reference signal received power (RSRP) or the reference signal received quality (RSRQ). The load state of the special session management function network element refers to the resource utilization rate and processing capacity saturation of the main service network element at a certain time, which can be comprehensively represented by a series of performance counters such as CPU occupancy, memory usage, current active session number, and signaling processing queue depth.
[0095] Specifically, the trigger condition of execution is that the system confirms that the user has special network access permission, but the user's access behavior is a failure retransmission, which indicates that the authorization itself has no problem, and the fault point may exist in the wireless link or the network core side. Once triggered, the system will start concurrent information acquisition from three completely independent dimensions to build a fault scene snapshot. First, query the user data management center (such as UDR / UDSF in 5G) to retrieve the historical performance profile of the user to obtain the historical reconnection success rate for longitudinal analysis in the user dimension; second, analyze the current received retransmission request message to extract the network signal strength parameters reported by the terminal for horizontal analysis in the wireless environment dimension; third, the system initiates a real-time state query to the original special session management function network element that is supposed to process the request through internal operation and maintenance (OAM) interface or service call to obtain its load state, which is the state analysis in the network core dimension. The system converts the access failure phenomenon from a single event into a set of quantifiable, multi-dimensional root cause analysis data.
[0096] S205, the system determines whether the backup access condition is met according to the historical reconnection success rate, the network signal strength, and the load state.
[0097] Among them, the backup access condition refers to a set of pre-configured logical judgment rules for starting a backup path, which constitutes the core basis for system decision, and at least two of the three conditions that the historical reconnection success rate is lower than the pre-set reconnection success rate threshold, the network signal strength is lower than the pre-set signal strength threshold, and the load state is higher than the pre-set load threshold are met. These thresholds are configurable and serve as the baseline for measuring whether each indicator is in a poor state.
[0098] Specifically, after collecting three-dimensional state data in S204, the system enters the decision-making process, compares the actual value of the historical reconnection success rate with the reconnection success rate threshold, compares the actual value of the network signal strength with the signal strength threshold, and compares the actual value of the load state with the load threshold. The core of this process is the "majority decision" or "two out of three" logical design, which ensures the robustness and high reliability of the decision, and avoids unnecessary network switching caused by the instantaneous fluctuation of a single dimension. For example, just because the user moves to a weak signal point (only the network signal strength is lower than the threshold) at a moment, the system will not determine that the main path is unavailable, but requires at least two dimensions of negative evidence to exist at the same time, such as poor signal strength and high load of the main network element, or poor signal strength and the user has always connected failure historically, the system will make a judgment that the current main access path has systematic and persistent problems. The decision result is a Boolean value (yes / no), which directly determines whether path switching needs to be performed subsequently.
[0099] S206, when the backup access condition is met, the system forwards the access request message to the preset backup special session management function network element.
[0100] Among them, the backup special session management function network element refers to one or more redundant backup network elements pre-specified in the network architecture, which are equivalent in function to the main network element and are in hot standby or warm standby state at all times, ready to take over the main network element to handle business.
[0101] Specifically, the output result of S205 step is the only prerequisite, that is, it will only be triggered when the backup access condition is met. Once triggered, the system intercepts the user's retransmission request message, but no longer sends it to the main special session management function network element which has been determined to have problems, queries the routing table or service discovery mechanism configured internally, finds the address of the currently available backup special session management function network element, and then forwards the original access request message directly to the backup network element. The advantage of this is to simplify the recovery process and avoid the need for complex and slow operations such as signaling the terminal to change the access point.
[0102] In some embodiments, after the previous steps, when the system determines that it needs to switch to a backup path but finds that all backup network elements are in an extremely congested situation of high load, a pre-emptive access mechanism based on service priority can be further introduced to ensure the access success rate of high-priority users, thereby realizing quality of service guarantee for critical services in extreme conditions.
[0103] Specifically, when the system tries to find a usable backup special session management function network element in S206, it finds that all backup options are unavailable, which triggers the pre-emptive access process. First, the system does not immediately reject the user's access request, but obtains the status list of all backup special session management function network elements in the special area. This is to confirm whether the current situation is an extreme state of saturation of backup resources in the entire network. When the system confirms that the load status of all backup special session management function network elements in the list is higher than the preset load threshold, the system evaluates the value and importance of the service. Query the user subscription database (such as the Unified Data Management function UDR in the 5G core network) to obtain the service priority of the user. This priority is a level pre-defined in the user profile, used to distinguish different importance of services such as public ordinary services, enterprise VIP services or emergency calls. In order to perform fair resource pre-emption, the system understands the priority of the current resource occupant, so it will initiate a query to all high-load backup network elements to obtain the service priority list of all users currently accessing them.
[0104] After the priority information of the requestor and all the occupiers are obtained, the system compares the priority of the new accessing user with the lowest priority in the acquired priority list. Only when the service priority of the user is higher than the lowest priority in the service priority list, i.e. only the more important service can interrupt the relatively less important service. Once the condition is met, the system locks the lowest priority user and the low priority backup special session management function network element which the user is accessing, and sends a session release instruction to the network element to forcibly terminate the session of the low priority user to release the network resources occupied by the user. The value of the process is that it dynamically reallocates the limited resources to the higher value services, ensuring that the critical communication is guaranteed when the resources are severely insufficient.
[0105] Finally, the system waits and detects the confirmation signal of the execution completion of the session release instruction to ensure that the resources have been released indeed. After the resources are successfully recovered, the system forwards the access request message of the high priority user which has been suspended before to the low priority backup special session management function network element (i.e. the network element which has just released the resources), thereby successfully establishing the connection for the user.
[0106] The above technical steps can create service conditions for the access request of the high priority user by introducing the resource preemption mechanism in the scenario of completely saturated backup resources, avoiding the direct access failure due to insufficient resources. This process converts a certain authorization failure result into a successful authorization, improving the effective authorization processing capacity of the system under extreme pressure. By reducing the number of denial of service of critical services, the overall resource allocation of the system is more intelligent, improving the efficiency of the special network resource authorization control.
[0107] S207, after receiving the access response of the backup special session management function network element, sending an authorization special network resource instruction to the authorization module.
[0108] The access response is a confirmation message returned by the backup special session management function network element to the system after successfully processing the access request, which indicates that an effective session context has been successfully established on the backup network element.
[0109] Specifically, when the system forwards the request to the backup network element, it waits for an access response from the backup network element. Once the successful response is received, it indicates that the backup path has been opened and the user's service access problem has been solved. At this time, the system performs the last key operation: sending a special network resource authorization instruction to the authorization module. The core function of the instruction is to inform the authorization module that the special network resource previously reserved or to be allocated for the user should now be formally bound to the newly established session on the backup network element, and update the user session information to indicate that the service network element has changed to the backup network element. This step ensures the consistency of the state of the entire network, ensures that subsequent business functions such as charging, policy control, and lawful interception can accurately find the correct service node where the user is currently located, thereby completing the entire process from fault detection to successful recovery.
[0110] S208, when the system detects that the user location information moves from the special area to the non-special area, a second internal trigger signaling is generated and sent to the authorization module.
[0111] S209, the system sends a second reconnection instruction to the ordinary session management function network element.
[0112] S210, after the system receives the access request message, an ordinary network resource authorization instruction is sent to the authorization module.
[0113] Steps S208-S210 are similar to steps S104-S106 in the embodiment shown in Figure 1 The descriptions in steps S104-S106 can be referred to, and will not be repeated here.
[0114] In the above embodiment, by using the above technical solution, the system can actively identify the unusable state of the access path by sensing the state of the primary network element, thereby avoiding the waste of resources and the access delay caused by sending invalid requests to the fault node. Further, through the intelligent decision mechanism, the request is redirected to the backup path, and the priority preemption strategy is introduced when the backup resource is congested, which can actively clear the resources for high-priority users, and convert the authorization failure caused by resource shortage or node failure into a successful authorization, reducing invalid signaling interaction and retries, thereby improving the efficiency of special network resource authorization control.
[0115] The following describes an exemplary system 300 for authorizing special network resources provided by an embodiment of the present application. Figure 3 is an exemplary hardware structure schematic diagram of the system 300 for authorizing special network resources provided by an embodiment of the present application.
[0116] In some embodiments, the system 300 for authorizing special network resources is a computer device or includes a computer device in the system 300 for authorizing special network resources. The computer device includes a processor, a memory and a network interface connected through a system bus. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The database of the computer device is configured to store data. The network interface of the computer device is configured to communicate with other terminals or servers outside through a network connection. In some embodiments, the network interface can be a wired network interface, and in some embodiments, the network interface can also be a wireless network interface. The computer program is executed by the processor to implement the method in the embodiments of the present application.
[0117] Those skilled in the art can understand that, Figure 3 The structure shown in the above-mentioned embodiments is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0118] The above-described embodiments are only used to illustrate the technical scheme of the present application, but not to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical scheme recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical scheme deviate from the scope of the technical scheme of the embodiments of the present application.
[0119] In the above-described embodiments, according to the context, the term "when" can be interpreted as "if" or "after" or "in response to determining" or "in response to detecting". Similarly, according to the context, the phrase "upon determining" or "if detecting (the stated condition or event)" can be interpreted as "if determining" or "in response to determining" or "upon detecting (the stated condition or event)" or "in response to detecting (the stated condition or event)".
[0120] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk) and the like.
[0121] Those of ordinary skill in the art understand that all or part of the processes in the above embodiments can be implemented by a computer program to instruct the relevant hardware, which can be stored in a computer readable storage medium. The program can include the processes of the above method embodiments when executed. The aforementioned storage medium includes ROM or random access memory (RAM), magnetic disk or optical disk, and various media that can store program codes.
Claims
1. A method of authorizing special network resources, characterized by, The method is applied to a system for authorizing special network resources comprising a billing module, an authorization module and an authentication module, and the method comprises: The system calls a billing message, and when detecting that user location information in the billing message moves from a preset non-special area to a preset special area, records the number of area switching of the user within a preset time window; the billing message is continuously parsed by the billing module to obtain; When the system determines that the number of area switching exceeds a preset switching number threshold, the real-time service type currently being processed by the user is obtained; If the system determines that the real-time service type is a preset key service type, a first internal trigger signaling is generated and sent to the authorization module until the key service processing is completed; If the system determines that the user has been in the same area for a fixed duration that exceeds a preset fixed duration threshold during the delay period for processing the key service processing, a first internal trigger signaling is generated and sent to the authorization module; the system calls and sends a first reconnection instruction to a special session management function network element to trigger the user terminal to disconnect the current network and initiate reconnection; the first reconnection instruction is generated after the authorization module responds to the first internal trigger signaling; After the system receives an access request message and a special network authorization judgment result, an authorization special network resource instruction is sent to the authorization module; the special network authorization judgment result is that the user type is confirmed as a special user by the authentication module and the user location information is the special area by the authorization module; after the authorization special network resource instruction is received by the authorization module, the user is authorized to access special network resources; When the system detects that the user location information moves from the special area to the non-special area, a second internal trigger signaling is generated and sent to the authorization module; The system calls and sends a second reconnection instruction to a general session management function network element; the second reconnection instruction is generated after the authorization module responds to the second internal trigger signaling; After the system receives the access request message, an authorization general network resource instruction is sent to the authorization module; after the authorization general network resource instruction is received by the authorization module, the user is authorized to access general network resources.
2. The method of claim 1, wherein, The real-time service type currently being processed by the user is obtained, specifically comprising: The system obtains a list of all concurrent services currently being processed by the user; The system identifies the type of each service in the concurrent service list; When the system determines that there are multiple key services corresponding to preset key service types in the concurrent service list, the predicted remaining processing duration of each key service is obtained; The system takes the longest predicted remaining processing duration as the delay waiting duration; Within the delay waiting duration, the system periodically detects changes in the concurrent service list according to a preset delay detection period: In the case where the system detects that there is a new service in the concurrent service list and the new service type of the new service belongs to the key service type, the delay waiting duration is updated.
3. The method of claim 1, wherein, The system sends an authorization special network resource instruction to the authorization module after receiving the access request message and the special network authorization judgment result, and specifically includes: In the case where the system receives the access request message, the special network authorization judgment result, and detects that the access request message is a retransmission request, the historical reconnection success rate of the user, the network signal strength of the current location, and the load state of the special session management function network element are obtained; The system determines whether the backup access condition is met according to the historical reconnection success rate, the network signal strength, and the load state; The backup access condition is that at least two of the three conditions that the historical reconnection success rate is lower than the preset reconnection success rate threshold, the network signal strength is lower than the preset signal strength threshold, and the load state is higher than the preset load threshold are met; When the backup access condition is met, the system forwards the access request message to the preset backup special session management function network element; After receiving the access response of the backup special session management function network element, the system sends an authorization special network resource instruction to the authorization module.
4. The method of claim 3, wherein, The system forwards the access request message to the preset backup special session management function network element, specifically including: The system obtains a state list of all backup special session management function network elements in the special area; When the load state of all backup special session management function network elements in the state list is higher than the preset load threshold, the system obtains the service priority of the user; The system obtains a service priority list of all users currently accessing the backup special session management function network element; When the service priority of the user is higher than the lowest priority in the service priority list, the system sends a session release instruction to the low-priority backup special session management function network element currently accessed by the low-priority user corresponding to the lowest priority; After detecting that the session release instruction is executed, the system forwards the access request message to the low-priority backup special session management function network element.
5. The method of claim 1, wherein, Before the system calls the accounting message, when detecting that the user location information in the accounting message moves from the preset non-special area to the preset special area, generating a first internal trigger signaling and sending it to the authorization module, it further includes: The system calls the accounting message, and obtains the location change trend and moving speed of the user through the user location information in the accounting message; When the location change trend points to the special area, and according to the moving speed, it is judged that the user will arrive in the special area within a first time, the system calculates the number of special users entering the special area within the first time; The system determines the reservation quota of special network resources according to the number of special users; The system sends a resource reservation instruction to the special session management function network element; The resource reservation instruction includes the reservation quota; When the user enters the special area, the system allocates special network resources from the reservation quota; When the first time ends, the system releases the unused reservation quota.
6. The method of claim 1, wherein, Before the system generates the second internal trigger signaling and sends it to the authorization module when the system detects that the user location information moves from the special area to the non-special area, it further includes: The system records the number of area switching times of the user within a preset time window; When the number of area switching times exceeds a preset threshold of switching area times, the system respectively acquires the residence duration of the user in the special area and the non-special area within the time window; The system calculates the cumulative residence duration proportion of the user in the special area; When the cumulative residence duration proportion is higher than a preset proportion threshold, the system marks the user as a boundary user; The system keeps the access state of the current special network resource or the ordinary network resource for the boundary user; Every preset detection time, the system recalculates the cumulative residence duration proportion, and when it is detected that the cumulative residence duration proportion is not higher than the preset proportion threshold, the boundary user mark is cancelled.
7. A system for authorizing special network resources, characterized in that The system for authorizing special network resources includes an authentication module, an authorization module, an accounting module, and one or more processors and memories; the memory is coupled with the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors invoke the computer instructions to make the system for authorizing special network resources execute the method in any one of claims 1-6.
8. A computer program product comprising instructions, characterized in that, When the computer program product runs on the system for authorizing special network resources, it makes the system for authorizing special network resources execute the method in any one of claims 1-6.
9. A computer-readable storage medium comprising instructions, characterized in that, When the instructions run on the system for authorizing special network resources, it makes the system for authorizing special network resources execute the method in any one of claims 1-6.
Citation Information
Patent Citations
Network flexible management and control method and device
CN115996380A
Dynamic signing method, device and equipment for roaming place under 5G network and medium
CN119402852A