Access control method, satellite-ground convergence network and computer equipment
By dynamically adjusting access permissions in the satellite-ground fusion network, disabling high-cost access and switching to low-cost access, the problems of low resource utilization and unreasonable charges under traditional access control methods are solved, and user access continuity and resource optimization are achieved.
Patent Information
- Application Number
- CN202510901259.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-10-10
AI Technical Summary
Traditional access control methods cannot differentiate control by access type, resulting in low network resource utilization and poor user experience. They are also unable to distinguish between high-cost access and low-cost access, leading to resource waste and unreasonable charges.
When the balance is insufficient, the policy control function network element of the satellite-ground converged network generates an access restriction policy, disables high-cost access types and switches to low-cost access types. Combined with the real-time monitoring and negotiation of the billing system, access rights are dynamically adjusted to ensure user access continuity.
It improves network resource utilization, reduces the risk of operator arrears, ensures user access continuity, and improves user experience.
Smart Images

Figure CN120769232A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to an access control method, a satellite-ground fusion network, and a computer device. Background Art
[0002] In a satellite-ground converged network, operators can provide multiple access types, including fixed, mobile, and satellite networks. Universal user equipment (UE) supports multiple access methods. However, different network operators have different billing methods. Traditional access control methods cut off all access when the balance is insufficient. This lack of differentiated control based on access type results in low network resource utilization and a negative user experience.
[0003] On the other hand, there are significant differences in the unit (single bit or single terminal) service costs of fixed networks, mobile networks, and satellite networks provided by operators. In particular, the cost of providing services through satellite networks currently far exceeds that of the other two access methods. Traditional access control methods cannot distinguish between high-cost access (such as satellite) and low-cost access (such as Wi-Fi, or Wireless Fidelity), making it impossible for operators to implement accurate billing control, resulting in waste of resources. Summary of the Invention
[0004] Based on this, it is necessary to provide an access control method, a satellite-ground integrated network and computer equipment to address the above technical problems, which can downgrade when the balance is insufficient to retain basic access capabilities and ensure user access continuity.
[0005] In a first aspect, the present application provides an access control method, which is applied to a policy control function network element of a satellite-ground converged network, and the method includes:
[0006] receiving a policy update request sent by a converged billing function network element; when the balance of a current access type is lower than a balance threshold of the current access type, the converged billing function network element sends a policy update request;
[0007] Generate access restriction policy according to policy update request;
[0008] The access restriction policy is sent to the network access control function network element to instruct the network access control function network element to disable the current access type according to the access restriction policy and switch to the target access type; the cost of the target access type is lower than the current access type.
[0009] In one embodiment, after sending the access restriction policy to the network access control function element, the method further includes:
[0010] receiving a restriction lifting instruction sent by the converged billing function network element; the converged billing function network element receives a balance change notification from the billing system, and issues a restriction lifting instruction when determining that the balance of the current access type is not less than the balance threshold of the current access type;
[0011] According to the restriction removal instruction, a notification of restoring the original access policy is sent to the network access control function element to instruct the network access control function element to determine whether to switch to the current access type based on the network status or user needs based on the notification of restoring the original access policy.
[0012] In one embodiment, the method further comprises:
[0013] receiving a first policy request sent by a session management function network element; after obtaining the current access type of the multi-access user equipment, the session management function network element sends the first policy request;
[0014] Negotiate with the converged charging function network element according to the first policy request. When it is determined that the balance is sufficient according to the negotiation result, send the charging policy of the current access type to the session management function network element according to the predefined charging policies of multiple access types, so as to instruct the session management function network element to notify the user plane function network element to collect traffic data of the current access type based on the charging policy of the current access type.
[0015] In one of the embodiments, after receiving the charging policy of the current access type, the session management function network element selects a user plane function network element according to the charging policy of the current access type, converts the charging policy of the current access type into a charging rule carrying an access type identifier, and sends the charging rule carrying the access type identifier to the selected user plane function network element to instruct the user plane function network element to count the traffic data of the current access type according to the access type identifier.
[0016] In one embodiment, after sending the access restriction policy to the network access control function element, the method further includes:
[0017] receiving a second policy request sent by the session management function network element; after receiving notification of the target access type from the network access control function network element, the session management function network element issues a second policy request; after receiving the access restriction policy, the network access control function network element notifies the session management function network element of the target access type and updates the session path;
[0018] According to the predefined charging policies for multiple access types, the charging policy of the target access type is sent to the session management function network element to instruct the session management function network element to issue new charging rules to the user plane function network element based on the charging policy of the target access type, so as to switch to the network corresponding to the target access type.
[0019] In a second aspect, the present application further provides an access control method, which is applied to a converged billing function network element of a satellite-ground converged network, and the method includes:
[0020] Monitor the balances of multiple access types in real time. When it is determined that the balance of the current access type is lower than the balance threshold of the current access type, send a policy update request to the policy control function network element to instruct the policy control function network element to generate an access restriction policy based on the policy update request and send the access restriction policy to the network access control function network element; the network access control function network element disables the current access type according to the access restriction policy and switches to the target access type; the cost of the target access type is lower than the current access type.
[0021] In one embodiment, after sending the policy update request to the policy control function network element, the method further includes:
[0022] Receive a balance change notification from the billing system, and when it is determined that the balance of the current access type is not less than the balance threshold of the current access type, send a restriction release instruction to the policy control function network element to instruct the policy control function network element to send a restoration of the original access policy notification to the network access control function network element based on the restriction release instruction; the network access control function network element determines whether to switch to the current access type based on the restoration of the original access policy notification and according to the network status or user needs.
[0023] In one embodiment, the balances of multiple access types are monitored in real time, including:
[0024] Receive traffic reports for each access type;
[0025] Generate billing records based on traffic reports for each access type;
[0026] Send the billing call record to the billing system to instruct the billing system to process the call record according to the billing call record;
[0027] Real-time monitoring of the balance of each access type in the billing system.
[0028] In a third aspect, the present application further provides a satellite-ground converged network, which includes at least a converged billing function network element, a policy control function network element, and a network access control function network element; wherein:
[0029] The converged charging function network element is configured to send a policy update request to the policy control function network element when determining that the balance of the current access type is lower than the balance threshold of the current access type;
[0030] The policy control function network element is used to generate an access restriction policy according to the policy update request and send the access restriction policy to the network access control function network element;
[0031] The network access control function network element is configured to disable the current access type and switch to a target access type according to the access restriction policy, and the cost of the target access type is lower than that of the current access type.
[0032] In a fourth aspect, the present application further provides a computer device including a memory and a processor, the memory stores a computer program, and the processor implements the steps of the method according to the first aspect or the second aspect when executing the computer program.
[0033] The access control method, the satellite-ground integrated network and the computer device, the policy control function network element of the satellite-ground integrated network receives a policy update request sent by the integrated charging function network element; the integrated charging function network element sends the policy update request in a case where the balance of the current access type is lower than a balance threshold of the current access type; generates an access restriction policy according to the policy update request; and sends the access restriction policy to the network access control function network element to instruct the network access control function network element to disable the current access type and switch to a target access type according to the access restriction policy, and the cost of the target access type is lower than that of the current access type. In this way, different access types are distinguished, and a balance threshold is set for each access type. The access permission is dynamically controlled according to the balance, the basic access capability is retained when the balance is insufficient, service interruption is avoided, user access continuity is ensured, network resource utilization is improved, and user experience is improved. BRIEF DESCRIPTION OF DRAWINGS
[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the description of the embodiments of the present application or the related art will be briefly introduced. Obviously, the drawings in the following description only some embodiments of the present application, and for those skilled in the art, other related drawings can be obtained without creative labor on the basis of these drawings.
[0035] Figure 1 The flowchart of the access control method in one embodiment is shown in the figure;
[0036] Figure 2 The flowchart of the access control method in another embodiment is shown in the figure;
[0037] Figure 3 The access restriction flowchart in one embodiment is shown in the figure;
[0038] Figure 4 The access restriction release flowchart in one embodiment is shown in the figure;
[0039] Figure 5 The flowchart of the access control method in another embodiment is shown in the figure;
[0040] Figure 6 Fig. 1 is a flow chart of a charging bill generation process in an embodiment;
[0041] Figure 7 Fig. 2 is a block diagram of an internal structure of a computer device in an embodiment. DETAILED DESCRIPTION
[0042] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.
[0043] It should be noted that the terms "first", "second", etc. used in the present application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "include" and "have" and any variations thereof used in the present application are intended to cover non-exclusive inclusion. The term "multiple" used in the present application refers to two and more than two. The term "and / or" used in the present application refers to one of the options or any combination of multiple options.
[0044] Before introducing the specific embodiments of the present application, the professional terms involved in the present application are explained:
[0045] MUE (Multi-connection User Equipment, multi-connection user equipment): refers to a user equipment supporting multiple access modes in a communication network.
[0046] NACF (Network Access Control Function, network access control function): manages and controls the access permission of a user equipment (UE) to a satellite-ground integrated network resource.
[0047] PCF (Policy Control Function, policy control function): responsible for dynamically formulating and managing network policies (such as QoS, charging, access control, etc.), ensuring that services are allocated resources as needed and comply with operator rules. QoS refers to Quality of Service, i.e. service quality.
[0048] CHF (Converged Charging Function, converged charging function): supports real-time charging (online) and offline charging, and realizes unified charging control of services and resources.
[0049] UPF (User Plane Function): Responsible for the routing, processing, and transmission of user data. It is the key node connecting the terminal and the external network.
[0050] SMF (Session Management Function): Responsible for session establishment, modification, and release, and manages UPF selection, IP (Internet Protocol) address allocation, and QoS policy enforcement.
[0051] In an exemplary embodiment, Figure 1 As shown, an access control method is provided, which is applied to a policy control function network element of a satellite-ground fusion network, and the method includes:
[0052] Step 102: Receive a policy update request sent by the converged charging function network element; the converged charging function network element sends a policy update request when the balance of the current access type is lower than the balance threshold of the current access type.
[0053] Among them, the satellite-ground fusion network refers to the deep coordination of satellite communications (space-based networks) and ground communication networks (such as cellular networks, Wi-Fi, etc.) through a unified network architecture, protocol and terminal design. It is based on dynamic spectrum sharing and intelligent routing management to ensure that users can switch seamlessly between satellite and ground networks, forming a multi-dimensional and three-dimensional communication system, and also supports multiple business scenarios such as voice, data, and the Internet of Things.
[0054] The current access type refers to the access type currently used by a user device accessing the satellite-ground converged network. When the CHF network element detects that the balance of the current access type is lower than the balance threshold of the current access type, the CHF network element sends a policy update request to the PCF network element. The policy update request includes a restricted access type. Optionally, the restricted access type includes at least one access type with a cost not lower than that of the current access type. Optionally, the restricted access type is the current access type.
[0055] The CHF network element sets a corresponding balance threshold based on the cost of each access type. Based on the balance threshold of each access type, the CHF network element can monitor the balance of each access type in real time. Optionally, the higher the cost of the access type, the higher the balance threshold is set.
[0056] Step 104: Generate an access restriction policy according to the policy update request.
[0057] A new access policy module is added to the PCF network element. This module receives policy update requests from the CHF network element, generates an access restriction policy, and sends it to the NACF network element. It is understood that the access restriction policy is used to restrict the current access type and recommend switching to a lower-cost access type.
[0058] Step 106: Send the access restriction policy to the network access control function element to instruct the network access control function element to disable the current access type and switch to the target access type according to the access restriction policy; the cost of the target access type is lower than the current access type.
[0059] The NACF network element receives the access restriction policy, disables the access type specified in the access restriction policy, allows access mode switching, and switches to a target access type with a lower cost. In this embodiment of the present application, the cost refers to the service cost. The cost level of each access type can be configured in the network in advance. Based on this cost level, the NACF network element can determine the target access type to be switched. Optionally, the PCF network element negotiates with the CHF network element to determine the recommended target access type to be switched. The CHF network element manages a balance status field for each access type. Based on this balance status field, the PCF network element can determine a target access type with sufficient balance and a lower cost than the current access type.
[0060] In the above access control method, the policy control function network element of the satellite-ground converged network receives a policy update request sent by the converged billing function network element; the converged billing function network element issues a policy update request when the balance of the current access type is lower than the balance threshold of the current access type; an access restriction policy is generated based on the policy update request; the access restriction policy is sent to the network access control function network element to instruct the network access control function network element to disable the current access type and switch to the target access type according to the access restriction policy; the cost of the target access type is lower than the current access type. Through the above method, different access types are distinguished and a balance threshold is set for each access type. Access rights are dynamically controlled based on the balance situation, and downgraded when the balance is insufficient to retain basic access capabilities, avoid service interruption, ensure user access continuity, improve network resource utilization, and thus improve user experience.
[0061] In an exemplary embodiment, Figure 2 As shown, after step 106, the method further includes:
[0062] Step 202: Receive a restriction removal instruction sent by the converged billing function network element; the converged billing function network element receives a balance change notification from the billing system, and issues a restriction removal instruction when determining that the balance of the current access type is not less than the balance threshold of the current access type.
[0063] Wherein, after the user completes the recharge, the charging system sends a balance change notification to the CHF network element. The CHF network element checks the balance and updates the balance state field in the bill. The CHF network element manages the balance state field of each access type, and different values of an access type under the balance state field represent different balance states of the access type. For example, a first value represents that the balance of the corresponding access type is lower than the balance threshold of the access type, i.e., the balance of the access type is insufficient; and a second value represents that the balance of the corresponding access type is not lower than the balance threshold of the access type, i.e., the balance of the access type is sufficient. The CHF network element sends a release restriction instruction to the PCF network element in the case of determining that the balance of the current access type is sufficient.
[0064] Step 204, according to the release restriction instruction, a recovery original access strategy notification is sent to the network access control function network element, to instruct the network access control function network element to determine whether to switch to the current access type according to the network state or user demand based on the recovery original access strategy notification.
[0065] Wherein, the PCF network element receives the release restriction instruction of the CHF network element, and sends a recovery original access strategy notification to the NACF network element. Optionally, the recovery original access strategy notification carries the identification of the original access type (i.e., the aforementioned current access type). The NACF network element releases the access type restriction of the MUE, evaluates the original access strategy, and decides whether to switch to a higher-cost access type according to the network state or user demand, i.e., whether to switch from the target access type to the current access type.
[0066] In this embodiment, the PCF network element and the CHF network element negotiate to dynamically control the access right according to the balance, limit the corresponding access type when the balance is lower than the threshold, switch to a low-cost access type, and guarantee the user access continuity. After the balance is sufficient, the access restriction is released, and intelligent decision is made in combination with the current actual situation to optimize the resource utilization.
[0067] In an exemplary embodiment, the method further comprises: receiving a first policy request sent by a session management function network element; the session management function network element sends the first policy request after obtaining the current access type of the multi-access user equipment; negotiating with the converged charging function network element according to the first policy request; in the case of determining that the balance is sufficient according to the negotiation result, sending a charging policy of the current access type to the session management function network element according to the pre-defined charging policies of multiple access types, to instruct the session management function network element to notify the user plane function network element to count the traffic data of the current access type based on the charging policy of the current access type.
[0068] The SMF network element obtains the current access type of the MUE and sends a first policy request to the PCF network element. The PCF network element pre-defines billing policies for various access types, such as fixed-line, mobile, and satellite network billing policies. The PCF network element negotiates with the CHF network element to generate an access policy and sends it to the SMF network element. The SMF network element notifies the UPF network element to collect traffic data for the current access type, providing data support for subsequent call record generation by the CHF network element and call record processing by the billing system.
[0069] In an exemplary embodiment, after receiving the charging policy of the current access type, the session management function network element selects a user plane function network element according to the charging policy of the current access type, converts the charging policy of the current access type into a charging rule carrying an access type identifier, and sends the charging rule carrying the access type identifier to the selected user plane function network element to instruct the user plane function network element to count the traffic data of the current access type according to the access type identifier.
[0070] The SMF network element selects the UPF network element based on the billing policy returned by the PCF network element, converts the billing policy into billing rules executable by the UPF network element and carries the access type identifier, and then sends the billing rules carrying the access type identifier to the selected UPF network element. The UPF network element classifies and counts traffic from different access methods in real time based on the access type identifier and periodically reports this to the SMF network element. The SMF network element generates a traffic report based on the traffic data and sends it to the CHF network element. The CHF network element generates differentiated billing call records based on the traffic report, which contain a balance threshold field corresponding to each access type. The CHF network element sends the call records for different access types to the billing system, which verifies and processes the call records.
[0071] In an exemplary embodiment, after step 106, the method further includes: receiving a second policy request sent by a session management function network element; after receiving a notification of the target access type from the network access control function network element, the session management function network element issues a second policy request; after receiving the access restriction policy, the network access control function network element notifies the session management function network element of the target access type and updates the session path; based on predefined charging policies for multiple access types, the charging policy for the target access type is sent to the session management function network element to instruct the session management function network element to issue new charging rules to the user plane function network element based on the charging policy for the target access type, thereby switching to a network corresponding to the target access type.
[0072] The NACF network element notifies the SMF network element of the new access type and updates the session path. Based on the user equipment access type, the SMF network element requests the PCF network element to obtain the charging policy for the target access type. Based on the charging policy obtained from the PCF network element, the new rules are issued to the UPF network element. The UPF network element redirects traffic of the restricted access type to the new network.
[0073] In an exemplary embodiment, referring to Figure 3 , the access restriction process includes the following steps:
[0074] 1. The CHF network element sets a corresponding balance threshold according to the cost of each access type, and monitors the balance of different access types in real time based on the balance threshold.
[0075] 2. When it is determined that the balance of the current access type is lower than the corresponding balance threshold, a policy update request including the restricted access type is sent to the PCF network element.
[0076] 3. The access policy module of the PCF network element receives the policy update request from the CHF network element, generates an access restriction policy, restricts the corresponding access type and recommends switching to a low-cost access type.
[0077] 4. The PCF network element sends the access restriction policy to the NACF network element.
[0078] 5. The NACF network element receives the access restriction policy, disables the specified access type, and allows switching of access modes.
[0079] 6. The NACF network element notifies the SMF of the new access type and updates the session path.
[0080] 7. The SMF network element obtains the billing policy of the signal from the PCF network element.
[0081] 8. The SMF network element sends new billing rules to the UPF network element.
[0082] 9. The UPF network element redirects the restricted access type traffic to the new network.
[0083] In an exemplary embodiment, referring to Figure 4 The access restriction removal process includes the following steps:
[0084] 1. After the user completes the recharge, the billing system updates the relevant data.
[0085] 2. The billing system sends a balance change notification to the CHF network element.
[0086] 3. The CHF network element verifies the balance, monitors the balance changes, and updates the balance status field in the call record.
[0087] 4. When the CHF network element detects that the balance of the original access type is updated from less than the threshold to not less than the threshold, it sends a restriction removal instruction to the PCF network element.
[0088] 5. The PCF network element receives the restriction removal instruction from the CHF network element and sends a notification to the NACF network element to restore the original access policy.
[0089] 6. The NACF network element removes restrictions on the corresponding access type of the MUE, evaluates the original access policy, and decides whether to switch to a high-cost access type based on network status or user needs.
[0090] In an exemplary embodiment, Figure 5 As shown, an access control method is provided, which is applied to a converged billing function network element of a satellite-ground converged network, and the method includes:
[0091] Step 502 monitors the balances of multiple access types in real time. When it is determined that the balance of the current access type is lower than the balance threshold of the current access type, a policy update request is sent to the policy control function network element to instruct the policy control function network element to generate an access restriction policy based on the policy update request and send the access restriction policy to the network access control function network element; the network access control function network element disables the current access type based on the access restriction policy and switches to the target access type; the cost of the target access type is lower than the current access type.
[0092] The access control method described above distinguishes between different access types and sets a balance threshold for each. Access permissions are dynamically controlled based on the balance, and when the balance is insufficient, the system downgrades to maintain basic access capabilities, avoiding service interruptions and ensuring user access continuity. This improves network resource utilization and, in turn, enhances the user experience.
[0093] In an exemplary embodiment, after sending a policy update request to the policy control function network element, the method further includes: receiving a balance change notification from the billing system, and when determining that the balance of the current access type is not lower than the balance threshold of the current access type, sending a restriction release instruction to the policy control function network element to instruct the policy control function network element to send a restoration original access policy notification to the network access control function network element based on the restriction release instruction; the network access control function network element determines whether to switch to the current access type based on the restoration original access policy notification and according to the network status or user needs.
[0094] In an exemplary embodiment, the balances of multiple access types are monitored in real time, including: receiving traffic reports for each access type; generating billing records based on the traffic reports for each access type; sending the billing records to a billing system to instruct the billing system to process the records based on the billing records; and monitoring the balances of each access type in the billing system in real time.
[0095] In an optional implementation, referring to Figure 6 The billing call record generation process includes the following steps:
[0096] 1. MUE completes registration through a certain access method.
[0097] 2. MUE sends the access type to the SMF network element.
[0098] 3. The SMF network element obtains the access type of the MUE and sends a policy request to the PCF network element.
[0099] 4. The PCF network element negotiates with the CHF network element to generate a charging policy and predefines the charging policies for different MUE access modes (fixed network / mobile / satellite network).
[0100] 5. The PCF network element sends the charging policy to the SMF network element.
[0101] 6. The SMF network element selects the UPF network element based on the billing policy returned by the PCF network element, converts the policy into billing rules that can be executed by the UPF network element and carries the access type identifier.
[0102] 7. The SMF network element sends the billing rules to the UPF network element.
[0103] 8. The UPF network element performs real-time classification and statistics on traffic of different access methods according to the access type identifier.
[0104] 9. Periodically report the traffic statistics to the SMF network element.
[0105] 10. The SMF network element generates a traffic report based on the traffic data and sends it to the CHF network element.
[0106] 11. The CHF network element generates a differentiated billing call record based on the traffic report. The call record contains the balance threshold field corresponding to the access type.
[0107] 12. The CHF network element sends the call record to the billing system.
[0108] 13. Verify and process the billing system dialogue form.
[0109] In an exemplary embodiment, for a satellite-ground converged network, to address issues such as the inability of the billing system to distinguish access types, resulting in unreasonable charges, low network resource utilization, and poor user experience, this embodiment of the application adds an access policy module to the PCF network element and enhances the functions of the NACF network element, SMF network element, UPF network element, and CHF network element. Specifically, this includes the following:
[0110] 1. New access policy module: supports negotiation with CHF network elements and adjusts the generated policy based on the balance information: when the balance is sufficient, a billing policy is generated and sent to the SMF network element, including billing policies for different MUE access methods (fixed network / mobile / satellite network). When the balance is insufficient, it receives the policy update request from the CHF network element, generates an access restriction policy for the NACF network element, restricts the corresponding access type and recommends switching to a low-cost access type. After the balance is recharged, it receives the CHF network element's restriction release instruction, notifies the NACF network element to restore the original access policy, and updates the balance status field in the call record. In this way, the access policy can be dynamically adjusted according to the balance, and high-cost access types can be restricted or lifted, reducing the risk of network arrears. When the balance is insufficient, the basic access capability can be downgraded to avoid service interruption.
[0111] 2. Enhanced SMF network element functions: Based on the user equipment access type, the system initiates a policy request to the PCF network element, converts the policy returned by the PCF network element into a rule executable by the UPF network element, and sends it to the selected UPF network element with the access type identifier. The system receives statistical traffic data periodically reported by the UPF network element, generates a traffic report, and sends it to the CHF network element. In this way, carrying the access type identifier in the sent information helps the PCF network element generate corresponding policies based on the access type, and also helps the UPF network element classify and count traffic of different access types.
[0112] 3. Enhanced UPF network element functions: The system receives the calculation rules of the user equipment access type identifier carried by the SMF network element, classifies and counts the traffic of user equipment through different access methods in real time, and periodically reports it to the SMF network element. This method can classify and count traffic of different access types, which helps the CHF network element generate differentiated billing records.
[0113] 4. Enhanced CHF network element functions: Support negotiation with PCF network elements, receive traffic reports from SMF network elements to generate differentiated call bills, and send call bills of different access types to corresponding operators for chargeback processing. Monitor the accumulated balance of call bills in real time, set the corresponding balance threshold according to the access type cost, trigger the PCF network element to restrict the corresponding access type when the balance is lower than the threshold, and send the corresponding access restriction release notification to the PCF network element when the balance is sufficiently recharged and higher than the threshold. In this way, the CHF network element generates differentiated billing call bills based on the classified traffic counted by the UPF network element, which facilitates accurate billing by operators. At the same time, based on the balance, it provides real-time feedback to the PCF network element on whether to restrict the access type, so that the PCF network element can dynamically adjust the strategy.
[0114] 5. Enhanced NACF network element functionality: Receives access restriction policies from PCF network elements and disables specified access types. Receives the original access policy from the PCF network element, removes restrictions on specified access types, evaluates the original access policy, and decides whether to switch to a higher-cost access type based on network conditions or user needs. This approach dynamically controls access permissions based on PCF network element policies, improving user resource utilization and ensuring service continuity.
[0115] In a satellite-ground converged network, the transmission cost of satellite links is much higher than that of terrestrial networks. The embodiments of the present application achieve differentiated billing call record generation by identifying the access type of user equipment, and dynamically control access permissions based on the real-time call record balance, forming a closed-loop management of billing and access control. This enables refined management and control of network resources in prepaid scenarios, meets the needs of differentiated access control and user service assurance, helps reduce the risk of operator arrears and improves user resource utilization. At the same time, when the user balance is insufficient, the basic access capability is downgraded to avoid service interruption, effectively solving problems such as unreasonable charges, low network resource utilization, and poor user experience caused by the billing system's inability to distinguish access types.
[0116] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of the steps or stages in other steps or other steps. It is understandable that the various steps in different embodiments can be freely combined as needed, and the various non-contradictory schemes formed by the combination all fall within the scope of protection of this application.
[0117] In an exemplary embodiment, a satellite-ground converged network is provided, which includes at least a converged charging function network element, a policy control function network element, and a network access control function network element; wherein:
[0118] The converged charging function network element is configured to send a policy update request to the policy control function network element when determining that the balance of the current access type is lower than the balance threshold of the current access type.
[0119] The policy control function network element is used to generate an access restriction policy according to a policy update request and send the access restriction policy to the network access control function network element.
[0120] The network access control function network element is used to disable the current access type and switch to the target access type according to the access restriction policy; the cost of the target access type is lower than the current access type.
[0121] In an exemplary embodiment, the satellite-ground converged network further includes a billing system; the converged billing function network element is further configured to receive a balance change notification from the billing system, and send a restriction removal instruction to the policy control function network element when determining that the balance of the current access type is not less than a balance threshold of the current access type;
[0122] The policy control function network element is further configured to send a notification of restoring the original access policy to the network access control function network element according to the restriction removal instruction;
[0123] The network access control function network element is also used to determine whether to switch to the current access type based on the notification of restoring the original access policy and according to the network status or user needs.
[0124] In an exemplary embodiment, the satellite-ground fusion network further includes a session management function network element and a user plane function network element;
[0125] The session management function network element is configured to send a first policy request to the policy control function network element after obtaining the current access type of the multi-access user equipment;
[0126] The policy control function network element is further configured to negotiate with the converged charging function network element according to the first policy request, and when it is determined according to the negotiation result that the balance is sufficient, send the charging policy of the current access type to the session management function network element according to the predefined charging policies for multiple access types;
[0127] The session management function network element is also used to notify the user plane function network element to calculate the traffic data of the current access type based on the charging policy of the current access type.
[0128] In an exemplary embodiment, the session management function network element is further used to, after receiving the billing policy of the current access type, select a user plane function network element according to the billing policy of the current access type, convert the billing policy of the current access type into a billing rule carrying an access type identifier, and send the billing rule carrying the access type identifier to the selected user plane function network element; the user plane function network element is used to count the traffic data of the current access type according to the access type identifier.
[0129] In an exemplary embodiment, the network access control function network element is further configured to, after receiving the access restriction policy, notify the session management function network element of the target access type and update the session path;
[0130] The session management function network element is further configured to send a second policy request to the policy control function network element after receiving a notification of the target access type from the network access control function network element;
[0131] The policy control function network element is further configured to send a charging policy of a target access type to the session management function network element according to predefined charging policies of multiple access types;
[0132] The session management function network element is also used to issue new charging rules to the user plane function network element based on the charging policy of the target access type, so as to switch to the network corresponding to the target access type.
[0133] In an exemplary embodiment, the converged charging function network element is also used to monitor the balances of multiple access types in real time.
[0134] In an exemplary embodiment, the converged billing function network element is also used to receive traffic reports of each access type; generate billing bills based on the traffic reports of each access type; send the billing bills to the billing system to instruct the billing system to process the bills based on the billing bills; and monitor the balances of each access type in the billing system in real time.
[0135] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 7 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an access control method is implemented.
[0136] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0137] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the following steps when executing the computer program: receiving a policy update request sent by a converged billing function network element; the converged billing function network element issues a policy update request when the balance of the current access type is lower than the balance threshold of the current access type; generating an access restriction policy based on the policy update request; sending the access restriction policy to a network access control function network element to instruct the network access control function network element to disable the current access type and switch to a target access type based on the access restriction policy; the cost of the target access type is lower than the current access type.
[0138] In one embodiment, when the processor executes the computer program, it also implements the following steps: receiving a restriction release instruction sent by the converged billing function network element; the converged billing function network element receives a balance change notification from the billing system, and issues a restriction release instruction when it determines that the balance of the current access type is not lower than the balance threshold of the current access type; based on the restriction release instruction, sending a restoration original access policy notification to the network access control function network element to instruct the network access control function network element to determine whether to switch to the current access type based on the restoration original access policy notification and according to the network status or user needs.
[0139] In one embodiment, when the processor executes the computer program, the processor further implements the following steps: receiving a first policy request sent by a session management function network element; after obtaining the current access type of the multi-access user equipment, the session management function network element issues the first policy request; negotiating with the converged charging function network element based on the first policy request, and when it is determined that the balance is sufficient according to the negotiation result, sending the charging policy of the current access type to the session management function network element based on predefined charging policies for multiple access types, so as to instruct the session management function network element to notify the user plane function network element to collect traffic data of the current access type based on the charging policy of the current access type.
[0140] In one embodiment, when the processor executes the computer program, the processor further implements the following steps: receiving a second policy request sent by a session management function network element; after receiving a notification of the target access type from the network access control function network element, the session management function network element issues the second policy request; after receiving the access restriction policy, the network access control function network element notifies the session management function network element of the target access type and updates the session path; and according to predefined charging policies for multiple access types, sends a charging policy for the target access type to the session management function network element, instructing the session management function network element to issue new charging rules to the user plane function network element based on the charging policy for the target access type, thereby switching to a network corresponding to the target access type.
[0141] In one embodiment, when the processor executes the computer program, it also implements the following steps: monitoring the balances of multiple access types in real time, and when it is determined that the balance of the current access type is lower than the balance threshold of the current access type, sending a policy update request to the policy control function network element to instruct the policy control function network element to generate an access restriction policy based on the policy update request and send the access restriction policy to the network access control function network element; the network access control function network element disables the current access type based on the access restriction policy and switches to the target access type; the cost of the target access type is lower than the current access type.
[0142] In one embodiment, when the processor executes the computer program, it also implements the following steps: receiving a balance change notification from the billing system, and when determining that the balance of the current access type is not lower than the balance threshold of the current access type, sending a restriction release instruction to the policy control function network element to instruct the policy control function network element to send a restoration original access policy notification to the network access control function network element based on the restriction release instruction; the network access control function network element determines whether to switch to the current access type based on the restoration original access policy notification and according to the network status or user needs.
[0143] In one embodiment, when the processor executes the computer program, it further implements the following steps: receiving traffic reports for each access type; generating billing records based on the traffic reports for each access type; sending the billing records to the billing system to instruct the billing system to process the bills based on the billing records; and monitoring the balances of each access type in the billing system in real time.
[0144] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0145] The technical features of the above embodiments can be combined in any manner. To make the description concise, not all possible combinations of the technical features in the above embodiments are described, but as long as the combinations of the technical features do not exist contradictions, they should be considered as the scope of the present application.
[0146] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. An access control method, characterized in that: The method is applied to a policy control function network element of a satellite-ground fusion network, and the method includes: receiving a policy update request sent by a converged billing function network element; the converged billing function network element issuing the policy update request when the balance of the current access type is lower than the balance threshold of the current access type; generating an access restriction policy according to the policy update request; The access restriction policy is sent to a network access control function element to instruct the network access control function element to disable the current access type and switch to a target access type according to the access restriction policy; the cost of the target access type is lower than that of the current access type.
2. The method according to claim 1, characterized in that After sending the access restriction policy to the network access control function element, the method further includes: receiving a restriction lifting instruction sent by the converged billing function network element; the converged billing function network element receives a balance change notification from the billing system, and issues the restriction lifting instruction when determining that the balance of the current access type is not less than the balance threshold of the current access type; According to the restriction removal instruction, a notification of restoring the original access policy is sent to the network access control function network element to instruct the network access control function network element to determine whether to switch to the current access type based on the network status or user needs based on the notification of restoring the original access policy.
3. The method according to claim 1, characterized in that The method further comprises: receiving a first policy request sent by a session management function network element; the session management function network element issuing the first policy request after acquiring the current access type of the multi-access user equipment; Request negotiation with the converged charging function network element according to the first policy. When it is determined that the balance is sufficient according to the negotiation result, send the charging policy of the current access type to the session management function network element according to predefined charging policies for multiple access types, so as to instruct the session management function network element to notify the user plane function network element to collect traffic data of the current access type based on the charging policy of the current access type.
4. The method according to claim 3, characterized in that After receiving the charging policy of the current access type, the session management function network element selects a user plane function network element according to the charging policy of the current access type, converts the charging policy of the current access type into a charging rule carrying the access type identifier, and sends the charging rule carrying the access type identifier to the selected user plane function network element to instruct the user plane function network element to count the traffic data of the current access type according to the access type identifier.
5. The method according to claim 1, wherein After sending the access restriction policy to the network access control function element, the method further includes: receiving a second policy request sent by a session management function network element; after receiving the notification of the target access type from the network access control function network element, the session management function network element issues the second policy request; after receiving the access restriction policy, the network access control function network element notifies the session management function network element of the target access type and updates the session path; According to the predefined charging policies for multiple access types, the charging policy of the target access type is sent to the session management function network element to instruct the session management function network element to issue new charging rules to the user plane function network element based on the charging policy of the target access type, thereby switching to the network corresponding to the target access type.
6. An access control method, characterized in that: The method is applied to a converged billing function network element of a satellite-ground converged network, and the method includes: Monitor the balances of multiple access types in real time, and when it is determined that the balance of the current access type is lower than the balance threshold of the current access type, send a policy update request to the policy control function network element to instruct the policy control function network element to generate an access restriction policy according to the policy update request, and send the access restriction policy to the network access control function network element; the network access control function network element disables the current access type according to the access restriction policy and switches to the target access type; the cost of the target access type is lower than the current access type.
7. The method according to claim 6, characterized in that After sending the policy update request to the policy control function network element, the method further includes: Receive a balance change notification from the billing system, and when determining that the balance of the current access type is not less than the balance threshold of the current access type, send a restriction removal instruction to the policy control function network element to instruct the policy control function network element to send a restoration original access policy notification to the network access control function network element based on the restriction removal instruction; the network access control function network element determines whether to switch to the current access type based on the restoration original access policy notification and according to the network status or user needs.
8. The method according to claim 6, characterized in that The real-time monitoring of balances of various access types includes: Receive traffic reports for each access type; Generate billing records based on traffic reports for each access type; Sending the billing record to the billing system to instruct the billing system to process the bill according to the billing record; The balance of each access type in the billing system is monitored in real time.
9. A satellite-ground fusion network, characterized in that: The satellite-ground fusion network at least includes a fusion charging function network element, a policy control function network element and a network access control function network element; wherein: The converged charging function network element is configured to send a policy update request to the policy control function network element when determining that the balance of the current access type is lower than the balance threshold of the current access type; The policy control function network element is configured to generate an access restriction policy according to the policy update request, and send the access restriction policy to the network access control function network element; The network access control function network element is used to disable the current access type and switch to a target access type according to the access restriction policy; the cost of the target access type is lower than that of the current access type.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.