Communication method and communication apparatus

By receiving and responding to rule information in 5G LANs, a whitelist is established to achieve fine-grained access control, thus addressing the security risks of enterprise networks in 5G LANs and improving network security and controllability.

CN121126352BActive Publication Date: 2026-02-10XIAN RUIXIN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511670891.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-13
Publication Date
2026-02-10
Estimated Expiration
2045-11-13

AI Technical Summary

Technical Problem

5G LANs pose security risks in enterprise networks due to their open communication mode, especially in scenarios where strict control of communication between branch devices is required, and existing protocols lack effective solutions.

Method used

A flexible intra-group access control method is provided, which receives rule information through user plane function network elements or session management network elements, controls the communication between different devices in the device group based on the rule information, including receiving and responding to the destination address of data, establishing whitelist information, and realizing fine-grained access control.

Benefits of technology

It enhances network security and controllability, meets the security needs of different enterprises, restricts communication between non-managed devices, ensures efficient connection between managed devices and terminal devices, and simplifies mutual access control in cross-user plane network entity scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121126352B_ABST
    Figure CN121126352B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a communication method and a communication device. The communication method comprises: receiving rule information, the rule information indicating at least one of a first rule or a second rule for a device group, wherein the device group comprises a management device located at a first network side or a second network side and a plurality of terminal devices located at the second network side, the first rule being associated with the management device located at the first network side, and the second rule being associated with the management device located at the second network side; and controlling communication between different devices in the device group based on the rule information. In this way, the management devices at the first network side and the second network side communicate with different rules, realizing differentiated inter-visit within the group, improving the security and controllability of the network, and being able to meet the security requirements of different enterprises.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this application mainly relate to the field of communications, and more specifically, to a communication method and a communication device. Background Technology

[0002] The 3rd Generation Partnership Project (3GPP) defines a 5G local area network (LAN) solution for providing 5G LAN services in enterprise scenarios. The core idea of ​​5G LAN is to leverage the 5G public network infrastructure to create a logical Layer 2 network, similar to a traditional Ethernet LAN, for terminals distributed over a wide area. In enterprise networks, after deploying 5G LAN, devices and servers join the same 5G LAN group, allowing unrestricted communication between devices and between devices and data network (DN) servers, expanding the service range and improving management convenience.

[0003] However, this open access model also brings security risks, especially in enterprise environments where strict control over communication between branch devices is required. Summary of the Invention

[0004] This application provides a communication solution that offers a flexible intra-group access control method to enhance network security and controllability, meeting the security needs of different enterprises.

[0005] In a first aspect of this application, a communication method is provided. Optionally, the entity executing this method may be a user plane function network element in the core network. The user plane function network element may be a network component in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). The aforementioned user plane function network element may be divided into one or more services; furthermore, services existing independently of network functions may also exist. Instances of the aforementioned user plane function network element, instances of services included in the aforementioned user plane function network element, or instances of services existing independently of network functions may all be referred to as service instances. Furthermore, the above naming is defined only for the convenience of distinguishing different functions and should not constitute any limitation. It should be understood that in current or future communication systems, the user plane function network element may also be implemented as other units or modules, which is not limited in this application. The communication method includes: receiving rule information, which indicates at least one of a first rule or a second rule for a device group, wherein the device group includes a management device located on a first network side or a second network side and multiple terminal devices located on the second network side, the first rule being associated with the management device on the first network side and the second rule being associated with the management device on the second network side; and controlling communication between different devices in the device group based on the rule information. In this way, the management devices on the first network side and the second network side communicate using different rules, achieving differentiated inter-device access within the group, improving network security and controllability, and meeting the security needs of different enterprises.

[0006] In some embodiments, the rule information indicates a first rule that prohibits communication between different terminal devices on the second network side. In this way, communication between unmanaged devices within the group can be restricted, improving network security.

[0007] In some embodiments, controlling communication between different devices in a device group based on rule information includes: receiving first information from a first terminal device among a plurality of terminal devices, the first information including first data and a first destination address of the first data; and, in response to the first destination address being located on a second network side, discarding the first data based on a first rule; or, in response to the first destination address being on a first network side, forwarding the first data to the first destination address based on the first rule. In this manner, when controlling communication between different devices in a device group based on the first rule, mutual access between terminal devices on the second network side is prohibited, while access to devices on the first network side is allowed by terminal devices on the second network side, thereby achieving finer-grained access control and improving security.

[0008] In some embodiments, the rule information indicates a second rule that permits communication between the management device on the second network side and the terminal device on the second network side. This ensures that the management device can communicate with the terminal device on the second network side regardless of whether it is located on the first or second network side.

[0009] In some embodiments, the rule information further includes whitelist information, which is used to identify management devices on the second network side. In this way, the whitelist information is used to identify management devices located on the second network side within the device group, thereby enabling the identification of management devices through the whitelist information.

[0010] In some embodiments, a whitelist user database is established based on whitelist information. This allows for centralized management of whitelist information, improving management flexibility and efficiency.

[0011] In some embodiments, the whitelist information includes the address information of the management device located on the second network side. In this way, the management device can be identified directly through the address information in the whitelist information, thereby achieving efficient connection between the terminal device and the management device.

[0012] In some embodiments, controlling communication between different devices in a device group based on rule information includes: receiving second information, the second information including second data and a second destination address of the second data; and discarding the second data in response to the second data's source address and destination address being located on the second network side and neither being in a whitelist. In this way, mutual access between terminal devices on the second network side is prohibited, while allowing terminal devices on the second network side to access devices on the first network side, thereby achieving finer-grained access control and improving security.

[0013] In some embodiments, in response to the source address or the second destination address being in the whitelist, the second data is forwarded to the second destination address. In this way, communication can be controlled by whether the source and destination addresses on the second network side are in the whitelist, thus improving security.

[0014] In some embodiments, forwarding the second data to the second destination address includes: in response to the source address belonging to whitelist information, sending the second data marked with whitelist attributes to the user plane network entity associated with the second destination address. This simplifies access control in cross-user plane network entity scenarios.

[0015] In some embodiments, the second information comes from a second terminal device among a plurality of terminal devices; or, the second information comes from a user plane network entity associated with the second terminal device.

[0016] In some embodiments, the second information comes from the management device; or, the second information comes from a user plane network entity associated with the management device.

[0017] In this way, the management device can be ensured to communicate with other devices, regardless of whether it is across user plane network entities.

[0018] In a second aspect of this application, a communication method is provided. Optionally, the execution entity of this method may be a session management network element in the core network. The session management network element may be a network component in a hardware device, a software function running on dedicated hardware, or a virtualization function instantiated on a platform (e.g., a cloud platform). The session management network element may be divided into one or more services, and further, services that exist independently of network functions may also exist. Instances of the aforementioned session management network element, instances of services included in the aforementioned session management network element, or instances of services that exist independently of network functions may all be referred to as service instances. In addition, the above naming is defined only for the convenience of distinguishing different functions and should not constitute any limitation. It should be understood that in current or future communication systems, the session management network element may also be implemented as other units or modules, which is not limited in this application. The communication method includes: sending rule information, the rule information indicating at least one of a first rule or a second rule for a device group, wherein the device group includes a management device located on a first network side or a second network side and multiple terminal devices located on the second network side, the first rule being associated with the management device located on the first network side, and the second rule being associated with the management device located on the second network side.

[0019] In some embodiments, the rule information indicates a first rule, which instructs to prohibit communication between different terminal devices on the second network side.

[0020] In some embodiments, the rule information indicates a second rule that allows communication between the management device on the second network side and the terminal device on the second network side.

[0021] In some embodiments, the rule information also includes whitelist information, which is used to identify the management device on the second network side.

[0022] In some embodiments, the whitelist information includes the address information of the management device located on the second network side.

[0023] In some embodiments, the method further includes: receiving contract information from a unified data management network entity, wherein rule information is determined based on the contract information.

[0024] In some embodiments, the subscription information or rule information is pre-stored in the session management network element. For example, the rule information may be predefined.

[0025] In a third aspect, a communication apparatus is provided. The apparatus includes: a receiving module configured to receive rule information, the rule information indicating at least one of a first rule or a second rule for a device group, wherein the device group includes a management device located on a first network side or a second network side and a plurality of terminal devices located on the second network side, the first rule being associated with the management device on the first network side, and the second rule being associated with the management device on the second network side. The apparatus further includes: a processing module configured to control communication between different devices in the device group based on the rule information. Optionally, the apparatus further includes a sending module.

[0026] In some implementations, the communication device may be configured to implement the method described in the first aspect or any implementation thereof.

[0027] In a fourth aspect, a communication apparatus is provided. The apparatus includes: a transmitting module configured to transmit rule information, the rule information indicating at least one of a first rule or a second rule for a device group, wherein the device group includes a management device located on a first network side or a second network side and a plurality of terminal devices located on the second network side, the first rule being associated with the management device on the first network side, and the second rule being associated with the management device on the second network side. Optionally, the apparatus further includes a receiving module.

[0028] In some implementations, the communication device may be configured to implement the method described in the second aspect or any of its implementations.

[0029] In a fifth aspect, a communication device is provided. The device includes one or more processors configured, together with a transceiver, to perform the methods described in the first or second aspect or any implementation thereof.

[0030] In some implementations, the communication device may further include one or more memories for storing computer instructions that are executed by one or more processors. When the computer instructions are executed by one or more processors, they cause the communication device to perform the method described in the first aspect, the second aspect, or any implementation thereof.

[0031] In a sixth aspect, a communication system is provided. The communication system includes: a communication device configured to implement the first aspect or any implementation thereof, and a communication device configured to implement the second aspect or any implementation thereof.

[0032] In a seventh aspect, a computer-readable storage medium is provided that stores computer-executable instructions that, when executed by a processor, implement the methods described in the first aspect, the second aspect, or any implementation thereof.

[0033] In an eighth aspect, a chip or chip system is provided. The chip or chip system includes processing circuitry configured to perform the methods described in the first or second aspect or any implementation thereof.

[0034] In a ninth aspect, a computer program or computer program product is provided. The computer program or computer program product is tangibly stored on a computer-readable medium and includes computer-executable instructions that, when executed, implement the methods described in the first or second aspect or any implementation thereof.

[0035] It should be understood that the technical effects in the first aspect and its various implementations also apply to each of the second to ninth aspects, therefore the technical effects of the second to ninth aspects will not be described again in this paper.

[0036] It should be understood that the description in the Summary Section is not intended to limit the key or essential features of the embodiments of this application, nor is it intended to restrict the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0037] Figure 1A A schematic diagram of a 5G network architecture in which some embodiments of this application may be implemented is shown;

[0038] Figure 1B A schematic diagram of the application service architecture of the 5G network provided in an embodiment of this application is shown;

[0039] Figure 2 A schematic diagram of a network deployment where the management device is located on the first network side according to an embodiment of this application is shown;

[0040] Figure 3 A schematic diagram of a network deployment where the management device is located on the second network side according to an embodiment of this application is shown;

[0041] Figure 4 A schematic diagram of the interaction flow of the communication process according to an embodiment of this application is shown;

[0042] Figure 5 A schematic diagram of the interaction flow of the communication process of the management device located on the first network side according to an embodiment of this application is shown;

[0043] Figure 6 A schematic diagram of the interaction flow of the communication process of the management device located on the second network side according to an embodiment of this application is shown;

[0044] Figure 7 A schematic block diagram of a communication apparatus according to some embodiments of this application is shown;

[0045] Figure 8 A schematic block diagram of a communication apparatus according to some embodiments of this application is shown; and

[0046] Figure 9 A schematic block diagram of an example device that can be used to implement embodiments of this application is shown.

[0047] Throughout all the accompanying drawings, the same or similar reference numerals are used to denote the same or similar components. Detailed Implementation

[0048] Embodiments of this application will now be described in more detail with reference to the accompanying drawings. While some embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this application. It should be understood that the drawings and embodiments of this application are for illustrative purposes only and are not intended to limit the scope of protection of this application.

[0049] In the description of embodiments of this application, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below.

[0050] In embodiments of this application, unless otherwise expressly stated otherwise, "a plurality of" means at least two, that is, two or more.

[0051] Embodiments of this application may be implemented according to any suitable communication protocol, including but not limited to cellular communication protocols such as third-generation (3G), fourth-generation (4G), fifth-generation (5G) and future communication protocols (e.g., sixth-generation (6G)), wireless local area network communication protocols such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocol currently known or to be developed in the future.

[0052] The technical solutions of the embodiments of this application are applicable to communication systems that follow any appropriate communication protocol, such as: General Packet Radio Service (GPRS), Global System for Mobile Communications (GSM), Enhanced Data Rate for GSM Evolution (EDGE), Universal Mobile Telecommunications Service (UMTS), Long Term Evolution (LTE) system, Wideband Code Division Multiple Access (WCDMA), Code Division Multiple Access 2000 (CDMA2000), Time Division-Synchronization Code Division Multiple Access (TD-SCDMA), Frequency Division Duplex (FDD) system, Time Division Duplex (TDD), 5G system (e.g., New Radio (NR)), and future communication systems (e.g., 6G system), etc.

[0053] For illustrative purposes, embodiments of this application are described below using a 5G communication system as an example within the 3GPP framework. However, it should be understood that embodiments of this application are not limited to this communication system, but can be applied to any communication system with similar problems, such as wireless local area networks (WLANs), wired communication systems, or other communication systems developed in the future.

[0054] As used in this application, the term "terminal" or "terminal device" refers to any terminal device capable of wired or wireless communication with network devices or with each other. A terminal device may sometimes be referred to as a user equipment (UE). A terminal device can be any type of mobile terminal, fixed terminal, or portable terminal. A terminal device can be any wireless communication device with wireless communication capabilities. With the rise of the Internet of Things (IoT) technology, an increasing number of devices that previously lacked communication capabilities, such as but not limited to home appliances, vehicles, tools, service equipment, and service facilities, are beginning to acquire wireless communication capabilities by configuring wireless communication units, thereby enabling them to access wireless communication networks and receive remote control. These devices, due to their configuration with wireless communication units, possess wireless communication capabilities and therefore also fall under the category of wireless communication devices. As an example, a terminal device may include a mobile cellular phone, cordless phone, mobile terminal (MT), mobile station, mobile device, wireless terminal, handheld device, client, subscription station, portable subscription station, internet node, communicator, desktop computer, laptop computer, notebook computer, tablet computer, personal communication system device, personal navigation device, personal digital assistant (PDA), wireless data card, wireless modem, positioning device, radio receiver, e-book device, gaming device, IoT device, in-vehicle device, aircraft, virtual reality (VR) device, augmented reality (AR) device, wearable device (e.g., smartwatch), terminal device in a 5G network or any terminal device in an evolved public land mobile network (PLMN), other devices that can be used for communication, or any combination of the above.

[0055] As used in this application, the terms "network node" or "network device" refer to an entity or node that can be used to communicate with a terminal device, such as an access network device. An access network device can be a means deployed in a radio access network to provide wireless communication functions for a mobile terminal, such as a radio access network (RAN) device. Access network devices can include various types of base stations. Base stations are used to provide radio access services to terminal devices. Specifically, each base station corresponds to a service coverage area, and terminal devices entering this area can communicate with the base station via wireless signals to receive the radio access services provided by the base station. The service coverage areas of base stations may overlap, and terminal devices in overlapping areas can receive wireless signals from multiple base stations, thus allowing multiple base stations to provide services to the terminal device simultaneously. Depending on the size of the provided service coverage area, access network devices can include macro base stations providing macro cells, micro base stations providing pico cells, pico base stations providing pico cells, and femto base stations providing femto cells. In addition, access network equipment can also include various forms of relay stations, access points, remote radio units (RRUs), radioheads (RHs), remote radio heads (RRHs), and so on. The names of access network equipment may differ in systems employing different radio access technologies. For example, in long-term evolution (LTE) networks, it is called an evolved Node B (eNB or eNodeB); in 3G networks, it is called a node B (NB); and in 5G networks, it can be called a g node B (gNB) or NR node B (NR NB), and so on.

[0056] In the past, the vast majority of connections on enterprise intranets were wired Ethernet connections. 5G, targeting businesses (toB), is gradually entering various industries, shifting connections from wired to wireless, bringing advantages such as rapid deployment, mobile adaptability, no wear and tear, and low cost in long-distance scenarios. Ordinary 5G IP sessions are similar to wide area network (WAN) dial-up internet access, which is very mature and convenient for consumers (toC) mobile phones to access the public internet, but has many inconveniences for toB intranet scenarios.

[0057] The 5G LAN solution defined by the 3GPP protocol is used to provide 5G local area network (LAN) services in enterprise scenarios. 5G LAN services provide users with instant LAN service anytime, anywhere via cellular networks, replacing wired LAN and WLAN. 5G LAN services enable terminal group management, provide L2 / L3 (data link layer / network layer) data exchange and multiple communication methods, reduce local latency, expand service range, reduce deployment costs, and improve management convenience.

[0058] 5G LAN technology, based on 5G terminal connectivity and basic 5G network services, provides private mobile LAN services, allowing limited groups of terminals to conduct peer-to-peer communication via Ethernet within the switching environment. Currently, members of a 5G LAN group include N3-side devices (e.g., devices connected to the 5G access network interface, typically 5G terminal devices) and DN-side devices (e.g., devices connected to the data network, typically enterprise servers and other network resources). Once a member joins the 5G LAN group, all members can communicate with each other. This design presents security vulnerabilities in enterprise scenarios, particularly for those requiring restrictions on device communication (e.g., branch office devices) to specific devices (e.g., headquarters devices). Current protocol specifications lack effective solutions for this.

[0059] In enterprise networks, deploying 5G LAN features allows devices and servers to join the same 5G LAN group, enabling unrestricted communication between devices and between devices and DN servers. While this open communication model offers flexibility, it also introduces security risks, such as the risk of insider attacks and data breaches, especially in enterprise environments where strict control over communication between branch devices is required.

[0060] In view of this, embodiments of this application provide a communication scheme, which is a fine-grained access control mechanism capable of flexibly controlling the mutual access permissions of members within a 5G LAN group, thereby improving network security and controllability. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings.

[0061] It should be understood that the communication scheme disclosed in this application can be applied to various scenarios. For example, the application scenarios of the communication include, but are not limited to, LTE systems, 5G systems, or new radio (NR) systems, as well as future communication systems such as sixth-generation mobile communication systems. The embodiments of this application do not limit this, and it should be understood that the communication scheme of this application can follow any appropriate communication technology and corresponding communication standards. The following description uses the application of the communication scheme to a 5G network architecture as an example.

[0062] Figure 1AA schematic diagram of a 5G network architecture 100A in which some embodiments of this application may be implemented is shown. The 5G network architecture 100A may include multiple network elements, as described below.

[0063] 1. Access and mobility management function (AMF) network element.

[0064] The Access Management Function (AMF) primarily performs mobility management and access authentication / authorization functions. In addition, the AMF is responsible for transmitting user policies between terminal devices and policy control function (PCF) network elements. Furthermore, the AMF can receive non-access stratum (NAS) signaling from terminal devices (including mobility management (MM) and session management (SM) signaling) and related signaling from access network devices (e.g., next-generation (NG) 2 interface signaling at the base station granularity that interacts with the AMF), completing user registration procedures, forwarding SM signaling, and managing mobility.

[0065] 2. Session management function (SMF).

[0066] SMF is primarily used for session management, allocation and management of Internet Protocol (IP) addresses for terminal devices, selection of endpoints for manageable user plane functions, policy control and charging function interfaces, and downlink data notification. SMF can also be used to complete processes related to the establishment, release, and update of Protocol Data Unit (PDU) sessions.

[0067] 3. Policy control function (PCF).

[0068] The PCF can be responsible for user policy management, including both mobility-related policies and PDU session-related policies, such as QoS policies and charging policies. In this architecture, the PCFs connected to the AMF and SMF correspond to the AM PCF (PCF for Access and Mobility Control) and SM PCF (PCF for Session Management), respectively, but may not be the same PCF entity in actual deployment scenarios.

[0069] 4. Network slice selection function (NSSF).

[0070] The NSSF mainly includes the following functions: selecting a set of network slice instances for the UE, determining the allowed network slice selection assistance information (NSSAI), and determining the AMF set that can serve the UE.

[0071] 5. Authentication server function (AUSF).

[0072] AUSF mainly includes the following functions: authentication server function, which interacts with the unified data management network element (UDM) to obtain terminal device information and performs authentication-related functions, such as generating intermediate keys.

[0073] 6. Unified data management (UDM).

[0074] UDM mainly includes the following functions: unified data management, support for authentication trust letter processing in 3GPP authentication and key negotiation mechanisms, user identity processing, access authorization, registration and mobility management, subscription management and SMS management, etc.

[0075] 7. Unified data repository (UDR).

[0076] It is mainly responsible for the storage and retrieval functions of data types such as contract data, strategy data, and application data.

[0077] 8. Network element function (NEF).

[0078] The NEF mainly includes the following functions: secure open 3GPP network functions providing services and capabilities, such as internal openness or openness to third parties; transforming or translating information interacting with AF and information interacting with internal network functions, such as AF service identifiers and internal 5G core network information such as data network name (DNN) and single network slice selection assistance information (S-NSSAI).

[0079] 9. Network function repository function (NRF).

[0080] NRF primarily includes the following functions: service discovery, maintaining the NF text of available network function (NF) instances and the services they support.

[0081] 10. Application function (AF).

[0082] The Application Function (AF) primarily conveys application-side requests to the network side, such as QoS requirements or user state event subscriptions. AFs can be third-party functional entities or application services deployed by operators, such as IMS voice call services. For third-party application functional entities, authorization processing can also be handled through the Network Provider Function (NEF) when interacting with the core network. For example, a third-party application function might directly send a request message to the NEF. The NEF determines whether the AF is authorized to send the request message; if the verification is successful, it forwards the request message to the corresponding PCF or UDM.

[0083] 11. User plane function (UPF).

[0084] UPF acts as the interface with the data network, performing functions such as user plane data forwarding, session / flow-based billing and statistics, and bandwidth limiting. This includes packet routing and forwarding, as well as QoS processing for user plane data.

[0085] 12. (Radio) access network (R)AN).

[0086] (R)AN can manage radio resources, provide access services for terminal devices, and forward terminal device data between the terminal device and the core network. For details on (R)AN, please refer to the previous description.

[0087] 13. Data network (DN).

[0088] DN is used to provide services such as carrier services, Internet access, or third-party services, including servers, where video source encoding and rendering are implemented.

[0089] In the above description, the network element can be a network component in a hardware device, a software function running on dedicated hardware, or a virtualization function instantiated on a platform (e.g., a cloud platform). The aforementioned functional network element can be divided into one or more services; furthermore, services that exist independently of network functions may also exist. Instances of the aforementioned functional network element, instances of services included in the aforementioned functional network element, or service instances that exist independently of network functions can all be referred to as service instances.

[0090] Depend on Figure 1A As can be seen, the UE accesses the 5G core network (5GC) through (R)AN. The UE communicates with the AMF through the NG1 interface (N1), the (R)AN communicates with the AMF through the NG2 interface (N2), the (R)AN communicates with the UPF through the NG3 interface (N3), and the UPF communicates with the DN through the NG6 interface (N6). The AMF communicates with the SMF through the NG11 interface (N11), the AMF communicates with the UDM through the NG8 interface (N8), the AMF communicates with the AUSF through the NG12 interface (N12), and the AMF communicates with the PCF through the NG15 interface (N15). The SMF communicates with the PCF through the NG7 interface (N7), the SMF communicates with the UPF through the NG4 interface (N4), the NEF communicates with the SMF through the NG29 interface (N29), and the UPF accesses the DN through the NG6 interface (N6), etc. Some interface functions are described below.

[0091] 1. N7: The interface between PCF and SMF, used to issue protocol data unit (PDU) session granularity and service data flow granularity control policies. The PDU session is the session service that enables PDU connectivity between the UE and the data network (DN), identified by the PDU Session ID.

[0092] 2. N15: The interface between PCF and AMF, used to issue UE policies and access control related policies.

[0093] 3. N5: The interface between AF and PCF, used for issuing application service requests and reporting network events.

[0094] 4. N4: The interface between SMF and UPF, used to transmit information between the control plane and the user plane, including the distribution of forwarding rules, QoS control rules, traffic statistics rules, etc. from the control plane to the user plane, as well as the reporting of information from the user plane.

[0095] 5. N11: The interface between SMF and AMF, used to transmit PDU session tunnel information between RAN and UPF, transmit control messages sent to UE, and transmit radio resource control information sent to RAN, etc.

[0096] 6. N2: The interface between AMF and RAN, used to transmit radio bearer control information from the core network side to the RAN.

[0097] 7. N1: The interface between AMF and UE, access-independent, used to transmit QoS control rules to UE, etc.

[0098] 8. N8: The interface between AMF and UDM, used by AMF to obtain access and mobility management related subscription data and authentication data from UDM, as well as by AMF to register UE's current mobility management information with UDM.

[0099] 9. N10: The interface between SMF and UDM, used by SMF to obtain session management-related subscription data from UDM, and by SMF to register UE current session-related information with UDM.

[0100] 10. N35: The interface between UDM and UDR, used by UDM to obtain user subscription data information from UDR.

[0101] 11. N36: The interface between PCF and UDR, used by PCF to obtain policy-related contract data and application data related information from UDR.

[0102] 12. N52: The interface between UDM and NEF, used by NEF to open network capabilities to third-party application functions, such as third-party application functions subscribing to reachability events of all users in a specific group through NEF to UDM.

[0103] In addition, NEF has direct interfaces with AMF and SMF, corresponding to the N29 interface and N51 interface respectively (not shown in the diagram for simplification). These interfaces are used to open up operator network capabilities to third-party application function entities. The former can be used by NEF to directly subscribe to corresponding network events and update user configuration information from AMF, while the latter can be used to update application configuration data on SMF / UPF, such as packet flow description (PFD) information corresponding to the application ID.

[0104] Figure 1A The interfaces between the various control plane network elements are point-to-point interfaces. In actual implementation, the interfaces between the various control plane network elements can also be service-oriented interfaces.

[0105] Figure 1BA schematic diagram of the application service architecture 100B of the 5G network provided in an embodiment of this application is shown. Figure 1B Npcf, Nudr, Nudm, Naf, Namf, and Nsmf are the service interfaces provided by PCF, UDR, UDM, AF, AMF, and SMF, respectively, and are used to call the corresponding service operations.

[0106] The term "network element" in this document can also be referred to as a network function instance, NF, device, apparatus, or module, etc., and this application does not specifically limit its usage. Furthermore, the above naming conventions are defined solely for the purpose of distinguishing different functions and should not constitute any limitation. This application does not preclude the possibility of using other naming conventions in 5G networks and other future networks. For example, in 6G networks, some or all of the aforementioned network terminology may be retained from 5G, or other names may be used. The interface names between the aforementioned network elements are merely examples; in specific implementations, the interface names may differ, and no specific limitation is made. Moreover, the names of the messages (or signaling) transmitted between the aforementioned network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.

[0107] The following text combines Figures 2 to 5 The interaction process for intra-group access control in 5G LAN is further described.

[0108] Figure 2 A schematic diagram of a network deployment 200 according to an embodiment of this application, in which the management device is located on the first network side, is shown. The schematic diagram of network deployment 200 is used to illustrate the inter-device access control mechanism within a 5G LAN group when the management device is located on the first network side, according to an embodiment of this application.

[0109] In 200, the management device 270 located on the first network side and the terminal devices UE 210, UE 220, and UE 230 are networked via a 5G LAN. It is necessary to restrict lateral communication between the terminal devices to improve security, such as preventing the leakage of sensitive data. Exemplarily, the first network side is the DN side, and the second network side is the terminal side. The term "DN side" can also be referred to as the N6 side, and "terminal side" can also be referred to as the N3 side or the access network side; "management device" can also be referred to as headquarters equipment, control center, equipment controller, etc., depending on the specific scenario, and "terminal device" can also be referred to as branch equipment, branch office terminal, etc., and this application does not limit this.

[0110] Specifically, the terminal device connects to the 5G base station (e.g., gNodeB) through customer premise equipment (CPE), and then connects to the session anchor (PSA) UPF through the N3 interface. The PSA UPF connects to the virtual extensible local area network switch (VXLAN SW) of the management device through the N6 interface. The CPE is used to convert 5G cellular signals into local network signals, providing efficient connectivity for scenarios requiring flexible networking. Optionally, in mobility scenarios, when an intermediate UPF (I-UPF) is inserted between the UE and the session anchor UPF (PSA UPF) for traffic forwarding, the I-UPF and the PSA UPF transmit user plane packets through the N9 interface using the GPRS Tunneling Protocol User Plane (GTP-U). Its function is to ensure that user data traffic can flow correctly and efficiently between multiple UPFs.

[0111] In 5G LAN cross-UPF communication scenarios, two UPFs (such as PSA UPFs) are connected via the N19 interface. When using 5G LAN services, the N19 interface is used to route traffic directly between different PDU sessions without going through the N6 interface that connects to the external data network, thereby enabling direct communication between terminals within the 5G network.

[0112] Optionally, the SMF 280 obtains subscription information from the UDM 290 via the N10 interface. This subscription information includes a first rule, which is associated with the management device 270 on the N6 side. Optionally, the first rule can also instruct communication between different terminal devices on the N3 side to be prohibited. Further, the SMF 280 transmits the first rule to the UPF 240 via the N4 interface, and the UPF controls traffic forwarding according to the first rule. Optionally, the first rule can also be configured locally on the SMF 280, thereby improving the flexibility of first rule configuration and reducing latency.

[0113] For example, UE 210 accesses UPF 240 sequentially via CPE 211, gNodeB 212, and I-UPF 213 (optional); UE 220 accesses UPF 240 sequentially via CPE 221, gNodeB 222, and I-UPF 223 (optional); UE 230 accesses UPF 250 sequentially via CPE 231 and gNodeB 232. I-UPF 213 and I-UPF 223 are intermediate UPFs, and UPF 240 and UPF 250 are PSAUPFs. Optionally, UPF 240 may also be referred to as UPF 1, the first UPF, or others. Optionally, UPF 250 may also be referred to as UPF 2, the second UPF, or others.

[0114] For example, if the enterprise headquarters server is deployed on the N3 side, direct communication between branch office terminals needs to be restricted for communication and data security. For instance, bank branch terminals can only access the head office data center, prohibiting horizontal communication between branches. For example, in 200, direct communication between UE 210, UE 220, and UE 230 is prohibited, but all three can communicate with the management device 270.

[0115] Figure 3 A schematic diagram of a network deployment 300 according to an embodiment of this application, in which the management device is located on the second network side, is shown. The schematic diagram of network deployment 300 is used to illustrate the inter-device access control mechanism within a 5G LAN group when the management device is located on the second network side, according to an embodiment of this application.

[0116] and Figure 2 The difference is that the management device is located on the second network side; for example, it will... Figure 2 Replace UE 220 with Figure 3 The management device 370 in the middle, and an additional branch is added on the second network side, namely the branch where UE 233 is located, in which UE 233 accesses UPF 250 through CPE 234 and gNodeB 235 in sequence.

[0117] Optionally, the SMF 280 can obtain subscription information from the UDM 290 via the N10 interface. This subscription information may further include a second rule associated with the management device 270 on the N3 side, which indicates permission for communication between the management device 370 on the N3 side and the terminal devices on the N3 side. Further, the SMF 280 transmits the second rule to the UPF 240 via the N4 interface, and the UPF controls traffic forwarding according to the second rule. Optionally, the second rule can also be configured locally on the SMF 280, thereby improving the flexibility of second rule configuration. Figure 3 The branches containing UE 210, UE 230, etc. Figure 2The corresponding parts are the same or similar, and for the sake of brevity, they will not be repeated here.

[0118] For example, in 300, the management device 370 located on the N3 side can communicate with any one of the terminal devices UE 210, UE 230 and UE 233 located on the N3 side, while direct communication between UE 210, UE 230 and UE 233 is prohibited.

[0119] In this way, the embodiments of this application provide a flexible intra-group access control method that can meet the security needs of different enterprises.

[0120] It should be noted that, in Figure 2 and Figure 3 The scenarios illustrated are merely for the convenience of describing embodiments of this application. These scenarios may include more or fewer devices, and the connection relationships between different entities can vary. Other scenarios are also applicable. For example, SMF 280 can be connected to UPF 250. For example, the interface names between entities may change in future communication systems.

[0121] Figure 4 A schematic diagram of the interaction flow of a communication process 400 according to an embodiment of this application is shown. Process 400 involves UPF 401 and SMF 402. It should be understood that although process 400 is described in conjunction with UPF 401 and SMF 402, in practical scenarios, UPF 401 and / or SMF 402 can be replaced by network elements, entities, functions, or devices with similar functions, etc., and this application is not limited in this regard. Figure 2 or Figure 3 UPF 401 can be implemented as Figure 2 and Figure 3 The UPF 240 or UPF 250 in the model name; SMF402 can be implemented as Figure 2 and Figure 3 SMF 280 in the middle.

[0122] At 410, SMF 402 sends rule information to UPF 401. Correspondingly, at 420, UPF 401 receives the rule information. The rule information indicates at least one of a first rule or a second rule for a device group, wherein the device group includes a management device located on a first network side or a second network side and multiple terminal devices located on the second network side. The first rule is associated with the management device located on the first network side, and the second rule is associated with the management device located on the second network side. In embodiments of this application, the device group can be a collection of devices belonging to the same enterprise but located in different geographical locations.

[0123] Optionally, SMF 402 can be based on from Figure 2 or Figure 3 The rule information is determined from the contract information of UDM 290 in the system. SMF 402 can also read the rule information from its local pre-configured rule information, thereby reducing latency.

[0124] For example, the first network side is the DN side (or N6 side), and the second network side is the terminal side (or access network side or N3 side). The management device may be located on the N6 side or the N3 side, and the terminal devices are non-managed devices located on the N3 side; there may be multiple terminal devices. When the management device is located on the N6 side, communication between the management device and the terminal devices is based on a first rule; when the management device is located on the N3 side, communication between the management device and the terminal devices is based on a second rule.

[0125] In some embodiments, the rule information indicates a first rule, which instructs that communication between different terminal devices on the second network side be prohibited. (See also...) Figure 2 The management device 270 is located on the N6 side, and UEs 210, UE 220 and UE 230 are located on the N3 side. At this time, the management device 270 and the terminal devices UEs 210, UE 220 and UE 230 can communicate based on the first rule, wherein the first rule indicates that communication between the terminal devices UEs 210, UE 220 and UE 230 is prohibited.

[0126] This method restricts communication between unmanaged devices within the group, thus improving network security.

[0127] In some embodiments, the rule information indicates a second rule that allows communication between the management device on the second network side and the terminal device on the second network side.

[0128] Reference Figure 3 Assuming that management device 370 and terminal devices UE 210, UE 230 and UE 233 are all located on the N3 side, the second rule indicates that communication between management device 370 and UE 210, UE 230 and UE 233 is permitted.

[0129] In this way, it is ensured that the management device can communicate with the terminal device on the second network side, regardless of whether it is located on the first network side or the second network side.

[0130] In some embodiments, the rule information also includes whitelist information, which is used to identify management devices on the second network side. For example, the International Mobile Subscriber Identity (IMSI) and Mobile Station International Subscriber Directory Number (MSISDN) of the management devices are added to the whitelist to identify which devices in the device group are management devices. It should be understood that other identifiers that can distinguish different devices or users can also be used to identify management devices, such as MAC addresses, and this application is not limited to this.

[0131] Reference Figure 3 The management device 370 is located on the N3 side. To identify management devices on the N3 side, whitelist information can be used to identify the management device 370 on the N3 side. For example, a whitelist tag can be added to the IMSI of management device users to distinguish between management devices and terminal devices, avoiding confusion between management devices and terminal devices located on the second network side. Optionally, the mode that allows communication between management devices with whitelist information and other non-managed devices can also be called whitelist mode.

[0132] In this way, the whitelist information is used to identify the management devices located on the second network side in the device group, so that the management devices can be identified through the whitelist information.

[0133] In some embodiments, a whitelist user database can also be established based on whitelist information. For example, the IMSIs of all managed devices within a group can be used as whitelist identifiers, and a whitelist user database can be established to store these IMSIs. Administrators can perform centralized operations such as adding, deleting, modifying, and querying the whitelist. In this way, whitelist information can be centrally managed, improving management flexibility and efficiency.

[0134] In some embodiments, the whitelist information includes the address information of the management device located on the second network side. For example, the address information of the management device includes a media access control (MAC) address. In this way, the management device can be identified directly through the address information in the whitelist, thereby enabling efficient connection between the terminal device and the management device.

[0135] In 430, UPF 401 controls communication between different devices in a device group based on rule information. Specifically, UPF 401 controls communication between multiple devices in a device group based on a first rule or a second rule.

[0136] Optionally, the communication control mode based on the first rule of UPF 401 can be N6 forwarding mode or N6 priority forwarding mode. Optionally, the communication control mode based on the second rule of UPF 401 can be called whitelist mutual access mode or N3 whitelist mode. This application does not limit the name of the mode.

[0137] In some embodiments, rule information indicates a first rule. Controlling communication between different devices in a device group based on rule information includes: receiving first information from a first terminal device among a plurality of terminal devices, the first information including first data and a first destination address of the first data; and discarding the first data based on the first rule in response to the first destination address being located on a second network side; or, forwarding the first data to the first destination address based on the first rule in response to the first destination address being on a first network side.

[0138] Reference Figure 2 UPF 401 can be implemented as Figure 2 The UPF 240 in the UE 210 can receive second information from the UE 210.

[0139] As an example, suppose UPF 240 receives the first message from UE 210 (such as...) Figure 2 (L21 in the solid line), where the first information includes the first data and the first destination address of the first data. For example, the first destination address is the MAC address corresponding to UE 220. Since the MAC address corresponding to UE 220 is located on the N3 side, UPF 240 discards the first data based on the first rule (e.g. Figure 2 The dashed line L22 in the image indicates that UPF 240 no longer forwards the first data.

[0140] As an example, suppose UPF 240 receives the first message from UE 220 (such as...). Figure 2 (L25 in the solid line), where the first information includes the first data and the first destination address of the first data, for example, the first destination address is the MAC address of UE 230. Since the MAC address corresponding to UE 230 is located on the N3 side, UPF 240 discards the first data based on the first rule (e.g. Figure 2 (The dashed line L26 in the image indicates that UPF 240 no longer forwards the first data to UPF 250 and UE 230.)

[0141] As an example, suppose UPF 240 receives the first message from UE 210 (such as...) Figure 2(Solid line L23 in the text), where the first information includes the first data and the first destination address of the first data. For example, the first destination address is the MAC address corresponding to the management device 270. Since the MAC address corresponding to the management device 270 is located on the N6 side, the UPF 240 forwards the first data to the MAC address corresponding to the management device 270 based on the first rule (e.g., Figure 2 (Solid line L23 in the diagram). Similarly, UPF 240 can send data from UE 220 to the MAC address corresponding to the management device 270 based on the first rule (e.g., ...). Figure 2 (The solid line L24 in the middle).

[0142] In this way, based on the first rule, communication between terminal devices on the second network side is prohibited, while terminal devices on the second network side are allowed to access devices on the first network side, thereby achieving finer-grained access control and improving security.

[0143] It should be understood that prohibiting mutual access between terminal devices on the second network side in the embodiments of this application means prohibiting direct communication between terminal devices located on the N3 side. The embodiments of this application do not restrict terminal devices on the N3 side from communicating indirectly through the management device on the N6 side.

[0144] For example, refer to Figure 2 Although UE 210 cannot communicate directly with UE 230 on the N3 side, the management device 270 on the N6 side receives data from UE 210 (such as...). Figure 2 (L23 in the solid line) The management device 270 can decide to forward the data to the UE 230 (e.g., the solid line L23 in ... Figure 2 (The solid line L27 in the diagram) thus enables indirect communication between UE 210 and UE 230.

[0145] In some embodiments, rule information indicates a first rule. Controlling communication between different devices in a device group based on rule information includes: receiving information from a management device located on a second network side, the information including data and the destination address of the data; and forwarding the data to the corresponding destination address based on the first rule.

[0146] As an example, suppose UPF 240 receives information from management device 270, which includes data and the destination address of the data, such as UE 210. UPF 240 then forwards the data to UE 210 (not shown in the figure) based on the first rule.

[0147] In some embodiments, rule information indicates a second rule. Controlling communication between different devices in a device group based on rule information includes: receiving second information, the second information including second data and a second destination address of the second data; and discarding the second data in response to information that the source address and the second destination address of the second data are located on a second network side and neither belongs to a whitelist. In some embodiments, in response to information that either the source address or the second destination address belongs to a whitelist, the second data is forwarded to the second destination address.

[0148] In some examples, the second information comes from a second terminal device among multiple terminal devices; or, the second information comes from a management device located on the second network side.

[0149] Reference Figure 3 UPF 401 can be implemented as Figure 3 The UPF 240 in the middle can receive second information from the UE 210 or from the management device 370 located on the N3 side.

[0150] As an example, suppose UPF 240 receives a second message from UE 210 (such as...). Figure 3 (Solid line L35 in the text), where the second information includes the second data and the second destination address of the second data. For example, the second destination address is the MAC address corresponding to the management device 370. Since the second destination address (i.e., the MAC address corresponding to the management device 370) belongs to the whitelist information, the UPF 240 forwards the second data to the management device 370 (e.g., Figure 3 (The solid line L33 in the middle).

[0151] As an example, suppose UPF 240 receives second information (not shown in the figure) from management device 370, where the second information includes second data and the second destination address of the second data, for example, the second destination address is the MAC address corresponding to UE 210. Since the source address (i.e. the MAC address corresponding to management device 370) belongs to the whitelist information, UPF 240 forwards the second data to UE 210 (not shown in the figure).

[0152] Reference Figure 3 UPF 401 can also be implemented as Figure 3 The UPF 250 in the UE 230 can receive second information from the UE 230.

[0153] As an example, suppose UPF 250 receives a second message from UE 230 (such as...). Figure 3The solid line L31 in the diagram shows that the second information includes the second data and the second destination address of the second data. For example, the second destination address is the MAC address corresponding to UE 233. Since neither the source address (i.e., the MAC address corresponding to UE 230) nor the second destination address (i.e., the MAC address corresponding to UE 233) belongs to the whitelist information, UPF 250 discards the second data (e.g., ...). Figure 3 (The dashed line L32 in the middle).

[0154] In some examples, the second information comes from a user plane network entity associated with the second terminal device, or from a user plane network entity associated with the management device.

[0155] Combination Figure 3 Optionally, UPF 240 can send rule information to UPF 250, or UPF 250 can receive rule information from SMF 280, and UPF 250 can perform data forwarding control. For example, UPF 240 can receive second information from UE 210 or management device 370, the second information including second data. If the second destination address of the second data is associated with UPF 250, then UPF 240 forwards the second information to UPF 250, and UPF 250 subsequently determines whether to forward it to the second destination address based on the rule information.

[0156] Reference Figure 3 UPF 401 can be implemented as Figure 3 The UPF 250 in the example can receive second information from the UPF 240. In one instance, the UPF 240 receives second information from the management device 370. Since the source address of the second data (i.e., the MAC address of the management device 370) is whitelisted, the UPF 240 adds a VXLAN extension header to the second information on the N19 interface to mark it as whitelisted, and then sends the whitelisted second information to the UPF 250. The UPF 250 parses the whitelist identifier, removes the extension header, and forwards the second data to the second destination address, such as the MAC address corresponding to the UE 230 (e.g., ...). Figure 3 (The solid line L34 in the middle).

[0157] As another example, UPF 240 receives second data (such as...) from a source address (e.g., the MAC address corresponding to UE 210). Figure 3 (In the solid line L35), the second data carries a second destination address (e.g., the MAC address corresponding to UE 230). In one example, UPF 240 identifies that neither the source address nor the destination address belongs to the whitelist information, and UPF 240 discards the second data based on the second rule (e.g., Figure 3(Dash line L36 in the diagram). In another example, UPF 240 sends the second information and second rule information to UPF 250 (not shown in the diagram) via the N19 interface. UPF 250 checks the second destination address. If the second destination address (e.g., the MAC address corresponding to UE 230) is not in the whitelist, UPF 250 discards the second data and does not forward the data to the second destination address. If UPF 250 finds that the second destination address is in the whitelist, UPF 250 forwards the data to the second destination address (not shown in the diagram). Optionally, the second rule information can also be pre-configured locally in UPF 250, eliminating the need for UPF 240 to send the second rule to UPF 250, thus saving channel resources.

[0158] In this way, communication can be controlled by checking whether the source or destination address on the second network side is part of a whitelist, thus improving security.

[0159] In some embodiments, forwarding the second data to the second destination address includes: in response to the source address belonging to whitelist information, sending the second data marked with whitelist attributes to the user plane network entity associated with the second destination address.

[0160] For example, refer to Figure 3 UPF 240 receives second data from management device 370 and then sends the second data to UPF 250, where the source address (e.g., MAC address) of management device 370 is whitelist information, and UPF 250 is the user plane network entity associated with the second destination address (e.g., the MAC address corresponding to UE 230).

[0161] In some embodiments, the second information comes from a user plane network entity associated with the second terminal device; or, the second information comes from a user plane network entity associated with a management device.

[0162] For example, refer to Figure 3 The second information comes from UPF 240 associated with UE 210; or, the second information comes from UPF 240 associated with management device 370. It should be understood that the user plane network entity associated with the second terminal device and the user plane network entity associated with the management device can be different username network entities.

[0163] In this way, the management device can be ensured to communicate with other devices, regardless of whether it is across user plane network entities.

[0164] It should be understood that the content format of rule information and destination address (such as MAC address, whitelist information) in the embodiments of this application are merely examples and not restrictive. For example, rule information may also include a combination of first and second rules, and the first rule and / or the second rule may be indicated by indication information (such as index, identifier or mapping relationship, etc.) in the rule information. This application does not limit this.

[0165] Figure 5 A schematic diagram of the interaction flow of a communication process 500 of a management device located on the first network side according to an embodiment of this application is shown. Process 500 involves UE 501, SMF 502, UDM 503, UPF 504, and DN 505. It should be understood that although process 500 is described in conjunction with SMF 502, UDM 503, UPF 504, and DN 505, in actual scenarios, SMF 502, UDM 503, UPF 504, and / or DN can be replaced with network elements, entities, functions, or devices with similar functions, etc., and this application does not limit this. Figure 2 UPF 504 can be implemented as Figure 2 The UPF 240 or UPF 250; SMF 502 can be implemented as Figure 2 SMF 280 in the middle.

[0166] At step 510, UE 501 initiates a session establishment request. Specifically, UE 501 sends a PDU session establishment request to the access network (R)AN (not shown in the figure). Through this request, UE 501 expresses its desire to establish a connection with the data network DN 505. This request carries initial parameters related to the session, such as the requested PDU session type and the data network name (DNN). The AMF (not shown in the figure) selects a suitable SMF 502 based on the information provided by UE 501 (such as the DNN, network slice selection assistance information (S-NSSAI), etc.). The AMF then sends a create SM context request to the selected SMF 502.

[0167] At 515, SMF 502 sends a request to UDM 503 to obtain contract information.

[0168] At 520, UDM 503 returns subscription information to SMF 502. For example, the subscription information includes 5G LAN group information and N6 access mode, such as the identification information and address information of all devices in the group, and the N6 access mode indicates that terminal devices on the N3 side are allowed to access DN 505.

[0169] At 525, SMF 502 sends an N4 session request to UPF 504. The N4 interface is the interface between SMF and UPF. This request carries information such as the first rule for user plane forwarding of the PDU session. UPF receives this information to configure user plane forwarding behavior and prepare for subsequent data transmission.

[0170] Optionally, in rule 530, UPF 504 can establish an N6 priority forwarding policy based on the first rule. For example, refer to... Figure 2 UPF 504 can be implemented as Figure 2 If UPF 240 receives an uplink message from UE 210, and the destination address of the message exists on both the N6 and N19 interfaces, where the N19 interface is the interface between two UPFs (e.g., UPF 240 to UPF 250) in a cross-UPF communication scenario, UPF 240 will prioritize forwarding the message to the N6 side.

[0171] At 535, UE 501 sends an uplink message to UPF 504. For example, refer to... Figure 2 UE 210 sends an uplink message to UPF 240.

[0172] In configuration 540, if the destination address of an uplink message received by UPF 504 from UE 501 is a unicast address, and the unicast address coexists on both N6 and N19, then UPF 504 will only forward the message to the headquarters (i.e., the N6 side). If the uplink message received by UPF 504 from UE 501 is a broadcast or multicast message, then UPF 504 will only unipointly copy the message to the N6 side.

[0173] At 545, DN 505 sends a downlink response message to UPF 504. Exemplarily, the response message includes a message indicating whether message reception was successful or failed.

[0174] At 550, UPF 504 forwards a downlink response message to UE 501. For example, UPF 504 informs UE 501 whether it successfully received the message.

[0175] In this way, when the management device is located on the first network side, communication between the management device and the UE is allowed, while direct communication between UEs within the UPF and across UPFs is prohibited, thereby improving the security and controllability of the network.

[0176] Figure 6A schematic diagram of the interaction flow of a communication process 600 of a management device located on the second network side according to an embodiment of this application is shown. Process 600 involves UE_A 601, UE_B 602, SMF 603, UDM 604, UPF1 605, UPF2 606, and UE_C 607. It should be understood that although process 600 is described in conjunction with SMF 603, UDM 604, UPF1 605, and UPF2 606, in actual scenarios, SMF 603, UDM 604, UPF1 605, and / or UPF2 606 can be replaced with network elements, entities, functions, or devices with the same type of function, etc., and this application does not limit this. Figure 3 UE_A 601 can be implemented as Figure 3 The management device 370 in the UE_B 602 can be implemented as Figure 3 UE 210; SMF 603 can be implemented as Figure 3 The SMF280 and UDM 604 in the model can be implemented as... Figure 3 The UDM 290 and UPF1 605 in the model can be implemented as... Figure 3 UPF 240; UPF2606 can be implemented as Figure 3 UPF 250; UE_C 607 can be implemented as Figure 3 UE 230 or UE 233.

[0177] At step 610, UE_A 601 initiates a session establishment request. The difference from step 510 is that this request also carries whitelist user information, which identifies UE_A 601 as a whitelisted user, such as a regional manager. For parts similar to or the same as step 510, please refer to the corresponding process in the aforementioned method embodiments; it will not be repeated here.

[0178] At 615, SMF 603 sends a request to UDM 604 to obtain contract information.

[0179] At 620, UDM 604 returns subscription information to SMF 603. Optionally, the subscription information includes whitelist information. For example, the IMSI of the management user located on the second network side (i.e., N3) can be whitelisted in the subscription information in UDM 604, and a second rule can be configured in the subscription information.

[0180] Optionally, step 615 can also be replaced by configuring a second rule locally on the SMF 603, thereby improving the flexibility of configuring the second rule information.

[0181] At 625, SMF 603 sends an N4 session request to UPF1 605. This request also carries information such as whitelist attributes. UPF1 605 uses this information to configure user plane forwarding behavior, preparing for subsequent data transmission.

[0182] At 640, UPF1 605 forwards a downlink response message to UE_A 601. For example, it informs UE_A 601 that the data has been successfully sent to the destination address.

[0183] Specifically, at 650, if UPF1 605 identifies UE_A 601 as a whitelisted user through the whitelist information in the subscription information, then it allows the forwarding of packets from the whitelisted user UE_A 601 to the cross-UPF (e.g., UPF2 606) and the destination address UE_C 607.

[0184] For example, when the sending end UE_A 601 is a whitelisted user and does not communicate across UPFs (e.g., from UPF1 605 to UPF2 606), UPF1 605 unconditionally allows forwarding of messages from UE_A 601 to the destination address UE_C 607.

[0185] In 655, when the sending UE_A 601 is a whitelisted user and communicates across UPFs (e.g., from UPF1 605 to UPF2606), UPF1 605 adds a VXLAN extension header to the N19 interface message to mark the whitelist flag.

[0186] At 660, UPF2 606 parses messages from UPF1 605 and extracts the whitelist identifier.

[0187] In step 665, when UPF2 606 identifies the sender UE_A 601 as a whitelisted user, it removes the VXLAN extension header and forwards the packet to the destination address UE_C 607.

[0188] In this way, when the sending end UE_A 601 is a whitelisted user, the message can be forwarded to the destination address UE_C 607 regardless of whether there is cross-UPF communication.

[0189] At step 630, non-whitelisted user UE_B 602 sends a message to UPF1 605. UE_B 602 initiates a session establishment request in the same or similar manner as step 510, and the corresponding process in the aforementioned method embodiments can be referred to, and will not be repeated here.

[0190] At 635, UPF1 605 checks the whitelist status of the destination address (e.g., destination MAC) of packets from UE_B 602.

[0191] In step 645, if the UPF1 605 detects that the destination MAC address does not belong to a whitelisted user, the packet can be dropped directly.

[0192] In a communication scenario where the sender is a non-whitelisted user (UE_B 602) and the communication is across UPFs, packet forwarding is allowed if the destination address belongs to a whitelisted user. The steps are similar to those in 655-665, the difference being that when UPF1 605 adds a VXLAN extension header to the N19 interface packet to mark the whitelist, the whitelist information is the whitelist information corresponding to the destination address. Similarities can be referenced or borrowed from each other; for the sake of indirectness, they will not be elaborated further here.

[0193] In this way, when the management device is located on the second network side, communication between the management device and the UE is allowed, while direct communication between UEs within the UPF and across UPFs is prohibited, thereby improving the security and controllability of the network.

[0194] It should be noted that the above combination Figures 4 to 6 The embodiments of this application are provided. Those skilled in the art can make modifications or adjustments based on them, which still fall within the protection scope of this application.

[0195] It should be understood that the methods, situations, categories, and classifications of embodiments in this application are for the convenience of description only and should not constitute a special limitation. Various methods, categories, situations, and features in embodiments can be combined with each other if they are logically consistent.

[0196] It should also be understood that the above content is only to help those skilled in the art better understand the embodiments of this application, and is not intended to limit the scope of the embodiments of this application. Those skilled in the art can make various modifications, variations, or combinations based on the above content. Such modified, varied, or combined solutions are also within the scope of the embodiments of this application.

[0197] It should also be understood that the above description focuses on highlighting the differences between the various embodiments. Similarities or commonalities can be referenced or learned from each other, and for the sake of brevity, they will not be repeated here.

[0198] This application further provides an apparatus embodiment for implementing the scheme in the above method embodiments, wherein the corresponding apparatus includes units or modules for implementing the above scheme. Examples are given below.

[0199] Figure 7 A schematic block diagram of a communication apparatus 700 according to some embodiments of this application is shown. The apparatus 700 can be implemented as user plane function network elements such as the aforementioned UPF 240, UPF 250, UPF 401, UPF 504, UPF1 605, and UPF2 606. Figure 7As shown, the device 700 includes a receiving module 710 and a processing module 720. Optionally, the device 700 also includes a transmitting module 730.

[0200] The receiving module 710 is configured to receive rule information, which indicates at least one of a first rule or a second rule for a device group, wherein the device group includes a management device located on a first network side or a second network side and multiple terminal devices located on the second network side, the first rule being associated with the management device on the first network side and the second rule being associated with the management device on the second network side. The processing module 720 is configured to control communication between different devices in the device group based on the rule information.

[0201] In some embodiments, the rule information indicates a first rule, which instructs to prohibit communication between different terminal devices on the second network side.

[0202] In some embodiments, the receiving module 710 may be configured to: receive first information from a first terminal device among a plurality of terminal devices, the first information including first data and a first destination address of the first data. The processing module may be configured to: discard the first data based on a first rule in response to the first destination address being located on a second network side. The sending module 730 may be configured to: forward the first data to the first destination address based on a first rule in response to the first destination address being on a first network side.

[0203] In some embodiments, the rule information indicates a second rule that allows communication between the management device on the second network side and the terminal device on the second network side.

[0204] In some embodiments, the rule information also includes whitelist information, which is used to identify the management device on the second network side.

[0205] In some embodiments, the processing module 720 may also be configured to: establish a whitelist user database based on whitelist information.

[0206] In some embodiments, the whitelist information includes the address information of the management device located on the second network side.

[0207] In some embodiments, the receiving module 710 may further be configured to receive second information, the second information including second data and a second destination address of the second data. The processing module 720 may further be configured to discard the second data in response to the second data's source address and destination address being located on a second network side and neither being part of the whitelist.

[0208] In some embodiments, the sending module 730 may be configured to forward the second data to the second destination address in response to information that the source address or the second destination address belongs to the whitelist.

[0209] Figure 7 The device 700 in the middle can be used to achieve the above-mentioned combination. Figures 2 to 6 For the sake of brevity, the various processes performed by UPF will not be described in detail here.

[0210] Figure 8 A schematic block diagram of a communication apparatus 800 according to some embodiments of this application is shown. The apparatus 800 can be implemented as a session management network element such as the aforementioned SMF 280, SMF 402, SMF 502, and SMF 603. Figure 8 As shown, the device 800 includes a transmitting module 810. Optionally, the device 800 also includes a receiving module 820.

[0211] The sending module 810 can be configured to send rule information, the rule information indicating at least one of a first rule or a second rule for a device group, wherein the device group includes a management device located on a first network side or a second network side and multiple terminal devices located on the second network side, the first rule is associated with the management device located on the first network side, and the second rule is associated with the management device located on the second network side.

[0212] In some embodiments, the rule information indicates a first rule, which instructs to prohibit communication between different terminal devices on the second network side.

[0213] In some embodiments, the rule information indicates a second rule that allows communication between the management device on the second network side and the terminal device on the second network side.

[0214] In some embodiments, the rule information also includes whitelist information, which is used to identify the management device on the second network side.

[0215] In some embodiments, the whitelist information includes the address information of the management device located on the second network side.

[0216] Optionally, the device 800 may further include a receiving module 820 configured to receive subscription information from a unified data management network entity, wherein rule information is determined based on the subscription information.

[0217] Figure 8 The device 800 in the middle can be used to achieve the above-mentioned combination. Figures 2 to 6 For the sake of brevity, the various processes executed by SMF will not be described in detail here.

[0218] Figure 7 or Figure 8 The receiving module involved can be implemented as a receiver or transceiver, the transmitting module can be implemented as a transmitter or transceiver, and the processing module can be implemented as a processor or control circuit.

[0219] It is understood that the division of modules or units in the embodiments of this application is illustrative and only represents a logical functional division. In actual implementation, there may be other division methods. Furthermore, the functional units in the embodiments of the application may be integrated into one unit, exist as separate physical entities, or two or more units may be integrated into one unit. The integrated unit described above can be implemented in hardware or as a software functional unit.

[0220] It should be understood that the above description is only intended to help those skilled in the art better understand the embodiments of this application, and is not intended to limit the scope of the embodiments of this application. Those skilled in the art can make various modifications, variations, or combinations based on the above description. Such modifications, variations, or combinations are also within the scope of the embodiments of this application.

[0221] Figure 9 A schematic block diagram of an example device 900 that can be used to implement embodiments of this application is shown. Device 900 may be implemented as or included in... Figures 2-6 In UPF or SMF. For example Figure 9 As shown, the device 900 includes one or more processors 910, one or more memories 920 coupled to the processors 910, and a communication module 940 coupled to the processors 910.

[0222] The communication module 940 can be used for bidirectional communication. The communication module 940 may have at least one communication interface for communication. The communication interface may include any interface necessary for communication with other devices.

[0223] Processor 910 can be any type suitable for a local technology network and can include, but is not limited to, one or more of the following: a general-purpose computer, a special-purpose computer, a microcontroller, a digital signal processor (DSP), or a controller-based multi-core controller architecture. Device 900 can have multiple processors, such as application-specific integrated circuit chips, which are time-dependent on a clock synchronized with the main processor.

[0224] Memory 920 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, at least one of the following: read-only memory (ROM) 924, erasable programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital versatile disc (DVD), or other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to, at least one of the following: random access memory (RAM) 922, or other volatile memories that do not persist during the duration of a power outage.

[0225] Computer program 930 includes computer-executable instructions that are executed by associated processor 910. Program 930 may be stored in ROM 924. Processor 910 may perform any suitable actions and processes by loading program 930 into RAM 922.

[0226] The embodiments of this application can be implemented by means of program 930, so that device 900 can perform as described in the reference. Figures 2 to 6 Any process discussed. Embodiments of this application may also be implemented by hardware or by a combination of software and hardware.

[0227] Program 930 may be tangibly contained in a computer-readable medium, which may be included in device 900 (such as in memory 920) or other storage device accessible by device 900. Program 930 may be loaded from the computer-readable medium into RAM 922 for execution. The computer-readable medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc.

[0228] In some embodiments, the communication module 940 in the device 900 can be implemented as a transmitter and receiver (or transceiver), which can be configured to transmit / receive data such as first data, at least one parameter, and compressed time-domain data. Additionally, the device 900 may further include one or more of a scheduler, a controller, and a radio frequency / antenna, which will not be described in detail here.

[0229] For example, Figure 9 The device 900 can be implemented as an electronic device, or as a chip or chip system in an electronic device, and the embodiments of this application are not limited thereto.

[0230] Embodiments of this application also provide a chip, which may include an input interface, an output interface, and a processing circuit. In embodiments of this application, the input interface and output interface can be used to complete the interaction of signaling or data, and the processing circuit can be used to generate and process the signaling or data information.

[0231] Embodiments of this application also provide a chip system including a processor for supporting a communication device to implement the functions involved in any of the above embodiments. In one possible design, the chip system may further include a memory for storing necessary program instructions and data, which, when executed by the processor, cause a device on which the chip system is installed to implement the methods involved in any of the above embodiments. Exemplarily, the chip system may consist of one or more chips, or may include chips and other discrete devices.

[0232] Embodiments of this application also provide a processor for coupling with a memory storing instructions that, when executed by the processor, cause the processor to perform the methods and functions involved in any of the above embodiments.

[0233] Embodiments of this application also provide a computer program or computer program product containing instructions, which, when run on a computer, causes the computer to perform the methods and functions involved in any of the embodiments described above.

[0234] Embodiments of this application also provide a computer-readable storage medium having computer instructions stored thereon, which, when executed by a processor, cause the processor to perform the methods and functions involved in any of the above embodiments.

[0235] Generally, the various embodiments of this application can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, while others can be implemented in firmware or software, which can be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of this application are shown and described as block diagrams, flowcharts, or represented using some other illustrations, it should be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented as, as non-limiting examples, in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0236] The processor or processing module in this application embodiment has signal processing capabilities and can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), graphics processing units (GPUs), neural network processing units (NPUs), artificial intelligence processors, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor, any conventional processor, or one or more integrated circuits used to control the execution of a program for controlling the method provided in any of the above embodiments. Some or all steps of the communication method in this application embodiment can be implemented by a GPU, NPU, or AI processor, or by a GPU, NPU, or AI processor in conjunction with other processors.

[0237] This application also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, which execute in a device on a target real or virtual processor to perform the processes / methods as described above with reference to the accompanying drawings. Typically, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., that perform specific tasks or implement specific abstract data types. In various embodiments, the functionality of program modules can be combined or divided among program modules as needed. The machine-executable instructions for the program modules can execute within a local or distributed device. In a distributed device, the program modules can reside in both local and remote storage media.

[0238] The computer program code used to implement the methods of this application may be written in one or more programming languages. This computer program code may be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the computer or other programmable data processing device, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a computer, partially on a computer, as a stand-alone software package, partially on a computer and partially on a remote computer, or entirely on a remote computer or server.

[0239] In the context of this application, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, and so on. Examples of signals may include electrical, optical, radio, sound, or other forms of propagation signals, such as carrier waves, infrared signals, etc.

[0240] A computer-readable medium can be any tangible medium that contains or stores a program for or relating to an instruction execution system, apparatus, or device. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. More detailed examples of computer-readable storage media include electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination thereof. The computer-readable storage medium as used herein is not to be construed as a transient signal itself, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.

[0241] Furthermore, although the operation of the method of this application is described in a specific order in the accompanying drawings, this does not require or imply that the operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart can be performed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps. It should also be noted that the features and functions of two or more devices according to this application can be embodied in one device. Conversely, the features and functions of one device described above can be further divided and embodied by multiple devices.

[0242] The various implementations of this application have been described above. The foregoing description is exemplary and not exhaustive, nor is it limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the described implementations. The terminology used herein is chosen to well explain the principles, practical applications, or improvements to technology in the market, or to enable others skilled in the art to understand the various implementations disclosed herein.

Claims

1. A communication method, characterized in that, include: The system receives rule information indicating at least one of a first rule or a second rule for a device group. This rule information controls communication between different devices in the device group, which includes a management device located on a first network side or a second network side, and multiple terminal devices located on the second network side. The first rule is associated with the management device located on the first network side, and the first rule indicates that communication between the management device and the terminal device is allowed and communication between different terminal devices on the second network side is prohibited. The second rule is associated with the management device located on the second network side, and the second rule indicates that communication between the management device on the second network side and the terminal devices on the second network side is allowed. as well as The communication between different devices in the device group is controlled based on the rule information.

2. The method according to claim 1, characterized in that, The method of controlling communication between different devices in the device group based on the rule information includes: Receive first information from a first terminal device among the plurality of terminal devices, the first information including first data and a first destination address of the first data; and In response to the first destination address being located on the second network side, the first data is discarded based on the first rule; or, in response to the first destination address being on the first network side, the first data is forwarded to the first destination address based on the first rule.

3. The method according to any one of claims 1-2, characterized in that, The rule information also includes whitelist information, which is used to identify the management device on the second network side.

4. The method according to claim 3, characterized in that, The whitelist information includes the address information of the management device located on the second network side.

5. The method according to claim 4, characterized in that, The method of controlling communication between different devices in the device group based on the rule information includes: Receive second information, the second information including second data and a second destination address of the second data; and In response to the fact that the source address and the destination address of the second data are located on the second network side and neither of them belongs to the whitelist information, the second data is discarded.

6. The method according to claim 5, characterized in that, Also includes: In response to the source address or the second destination address belonging to the whitelist information, the second data is forwarded to the second destination address.

7. The method according to claim 6, characterized in that, Forwarding the second data to the second destination address includes: In response to the source address belonging to the whitelist information, the second data marked with whitelist attributes is sent to the user plane network entity associated with the second destination address.

8. The method according to claim 5 or 6, characterized in that, The second information comes from the second terminal device among the plurality of terminal devices; or, the second information comes from a user plane network entity associated with the second terminal device.

9. The method according to any one of claims 5-7, characterized in that, The second information comes from the management device; or, the second information comes from a user plane network entity associated with the management device.

10. A communication method, characterized in that, include: Send rule information, the rule information indicating at least one of a first rule or a second rule for a device group, the rule information being used to control communication between different devices in the device group, the device group including a management device located on a first network side or a second network side and a plurality of terminal devices located on the second network side, wherein the first rule is associated with the management device located on the first network side, the first rule indicating that communication between the management device and the terminal devices is allowed and communication between different terminal devices on the second network side is prohibited, and wherein the second rule is associated with the management device located on the second network side, the second rule indicating that communication between the management device on the second network side and the terminal devices on the second network side is allowed.

11. The method according to claim 10, characterized in that, The rule information also includes whitelist information, which is used to identify the management device on the second network side.

12. The method according to claim 11, characterized in that, The whitelist information includes the address information of the management device located on the second network side.

13. The method according to claim 10, characterized in that, Also includes: Receive contract information from a unified data management network entity, wherein the rule information is determined based on the contract information.

14. A communication device, characterized in that, include: A module or unit for performing the method as described in any one of claims 1-9 or 10-13.

15. A communication device, characterized in that, include: A processor for executing a program that causes the communication device to perform the method as described in any one of claims 1-9 or 10-13.

16. A computer-readable storage medium comprising instructions, characterized in that, When the instructions are executed on a computer, the computer performs the method as described in any one of claims 1-9 or 10-13.

17. A computer program product containing instructions, characterized in that, When the instructions are executed on a computer, the computer performs the method as described in any one of claims 1-9 or 10-13.

18. A chip, characterized in that, It includes processing circuitry configured to perform the method as described in any one of claims 1-9 or 10-13.

Citation Information

Patent Citations

  • Service flow routing method and device

    CN117641320A