Communication method, RAN, terminal, network element, communication system and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2024-08-15
- Publication Date
- 2026-04-17
AI Technical Summary
In communication systems, how can we improve the security of data plane connections to balance the needs of data sharing and data transmission security?
The Radio Access Network (RAN) receives requests from terminals, determines whether to establish a data plane connection, and controls the establishment of the connection through authorization mechanisms and list management, including receiving and sending subscription information and authorization results to ensure security.
This improves the security of data plane connections, thereby enhancing the security of data sharing and preventing attacks from malicious terminals and data leaks.
Smart Images

Figure CN121890122A_ABST
Abstract
Description
Communication method, RAN, terminal, network element, communication system and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, a RAN, a terminal, a network element, a communication system and a storage medium. BACKGROUND
[0002] In a communication system, most of the data stored or transmitted in the network comes from network communication operations and subscriptions. As new generation communication functions and services expand from communication to fields such as sensing, computing and artificial intelligence, the range and types of data in the network will increase. As an abstract function between data providers and data consumers, data services can separate data consumers and data providers. Data services need to balance the security of data sharing and data transmission in the data plane.
[0003] SUMMARY
[0004] How to improve the security of establishing a data plane connection is a problem to be solved.
[0005] Embodiments of the present disclosure provide a communication method, a RAN, a terminal, a network element, a communication system and a storage medium.
[0006] According to a first aspect of embodiments of the present disclosure, a communication method is provided, the method comprising: receiving, by a radio access network device RAN, a first request sent by a terminal, the first request being used to request establishment of a first data plane connection; determining, by the RAN, whether to establish the first data plane connection.
[0007] According to a second aspect of embodiments of the present disclosure, a communication method is provided, the method comprising: sending, by a terminal, a first request to a radio access network device RAN, the first request being used to request establishment of a first data plane connection.
[0008] According to a third aspect of embodiments of the present disclosure, a communication method is provided, the method comprising: establishing, between a third network element and a radio access network device RAN, a second data plane connection, the second data plane connection and the first data plane connection having an association relationship; at least one of the following is associated with the second data plane connection: a first list; a second list.
[0009] According to a fourth aspect of embodiments of the present disclosure, a communication method is provided, the method comprising: receiving, by a fourth network element, a terminal state notification sent by a radio access network device RAN, the terminal state notification being used to notify the fourth network element of an update of a state of a terminal.
[0010] According to a fifth aspect of the embodiments of the present disclosure, a communication method is provided. The method comprises: receiving, by a first network element, a second request or a third request sent by a radio access network device, the second request being used to request subscription information of a terminal, the second request comprising a terminal identifier; the third request being used to request an authorization result, the third request comprising a terminal identifier and a service identifier; and sending, by the first network element, the subscription information or the authorization result to the radio access network device, the subscription information being used to determine whether the terminal is authorized to establish a first data plane connection.
[0011] According to a sixth aspect of the embodiments of the present disclosure, a communication method is provided. The method comprises: providing, by a second network element, a first list to a radio access network device, the first list comprising candidate terminal identifiers; the first list being associated with a second data plane connection, and there being an association relationship between the second data plane connection and a first data plane connection.
[0012] According to a seventh aspect of the embodiments of the present disclosure, a radio access network device is provided. The device comprises: a transceiver configured to receive a first request sent by a terminal, the first request being used to request establishment of a first data plane connection; and a processor configured to authorize the terminal.
[0013] According to an eighth aspect of the embodiments of the present disclosure, a terminal is provided. The terminal comprises: a transceiver configured to send a first request to a radio access network device, the first request being used to request establishment of a first data plane connection.
[0014] According to a ninth aspect of the embodiments of the present disclosure, a third network element is provided. The third network element comprises: a transceiver configured to establish a second data plane connection with a radio access network device, there being an association relationship between the second data plane connection and a first data plane connection; and at least one of the following being associated with the second data plane connection: a first list; and a second list.
[0015] According to a tenth aspect of the embodiments of the present disclosure, a fourth network element is provided. The fourth network element comprises: a transceiver configured to receive a terminal state notification sent by a radio access network device, the terminal state notification being used to notify the fourth network element of a state update of a terminal.
[0016] According to an eleventh aspect of the embodiments of the present disclosure, a first network element is provided. The first network element comprises: a transceiver configured to receive a second request or a third request sent by a radio access network device, the second request being used to request subscription information of a terminal, the second request comprising a terminal identifier; the third request being used to request an authorization result, the third request comprising a terminal identifier and a service identifier; and a processor configured to send the subscription information or the authorization result to the radio access network device, the subscription information being used to determine whether the terminal is authorized to establish a first data plane connection.
[0017] According to a twelfth aspect of the embodiments of the present disclosure, a second network element is provided, comprising: a transceiver configured to provide a first list to a radio access network device (RAN), the first list comprising candidate terminal identifiers; the first list being associated with a second data plane connection, and there being an association relationship between the second data plane connection and a first data plane connection.
[0018] According to a thirteenth aspect of the embodiments of the present disclosure, a RAN is provided, comprising: one or more processors; and wherein the RAN is configured to perform the communication method of the first aspect.
[0019] According to a fourteenth aspect of the embodiments of the present disclosure, a terminal is provided, comprising: one or more processors; and wherein the terminal is configured to perform the communication method of the second aspect.
[0020] According to a fifteenth aspect of the embodiments of the present disclosure, a third network element is provided, comprising: one or more processors; and wherein the third network element is configured to perform the communication method of the third aspect.
[0021] According to a sixteenth aspect of the embodiments of the present disclosure, a fourth network element is provided, comprising: one or more processors; and wherein the fourth network element is configured to perform the communication method of the fourth aspect.
[0022] According to a seventeenth aspect of the embodiments of the present disclosure, a first network element is provided, comprising: one or more processors; and wherein the first network element is configured to perform the communication method of the fifth aspect.
[0023] According to an eighteenth aspect of the embodiments of the present disclosure, a second network element is provided, comprising: one or more processors; and wherein the second network element is configured to perform the communication method of the sixth aspect.
[0024] According to a nineteenth aspect of the embodiments of the present disclosure, a communication system is provided, comprising a RAN, a terminal, a third network element, a first network element, and a second network element, wherein the RAN is configured to implement the communication method of the first aspect, the terminal is configured to implement the communication method of the second aspect, the third network element is configured to implement the communication method of the third aspect, the first network element is configured to implement the communication method of the fifth aspect, and the second network element is configured to implement the communication method of the sixth aspect.
[0025] According to a twentieth aspect of the embodiments of the present disclosure, a storage medium is provided, the storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method of any one of the aspects.
[0026] According to a twenty-first aspect of the embodiments of the present disclosure, a computer program is provided, the computer program, when executed on a communication device, causing the communication device to perform the communication method of any one of the aspects.
[0027] By the embodiments of the present disclosure, the RAN receives the first request for requesting to establish the first data plane connection sent by the terminal, and determines whether to establish the first data plane connection, which can improve the security of establishing the data plane connection, thereby improving the security of data sharing. BRIEF DESCRIPTION OF DRAWINGS
[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, which do not specifically limit the protection scope of the present disclosure.
[0029] FIG. 1A is a schematic architecture diagram of a communication system according to an embodiment of the present disclosure.
[0030] FIG. 1B is a schematic diagram of data plane establishment according to an embodiment of the present disclosure.
[0031] FIG. 1C is a schematic diagram of interaction between a UE and a RAN according to an embodiment of the present disclosure.
[0032] FIG. 1D is a schematic diagram of interaction between a UE and a RAN according to an embodiment of the present disclosure.
[0033] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0034] FIG. 2B is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0035] FIG. 3A is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0036] FIG. 3B is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0037] FIG. 4 is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0038] FIG. 5A is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0039] FIG. 5B is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0040] FIG. 6A is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0041] FIG. 6B is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0042] FIG. 7 is a flow schematic diagram of a communication method according to an embodiment of the present disclosure.
[0043] FIG. 8 is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0044] FIG. 9A is a schematic diagram of a network architecture, according to an embodiment of the present disclosure.
[0045] FIG. 9B is an interaction diagram of a communication method, according to an embodiment of the present disclosure.
[0046] FIG. 9C is a schematic diagram of another network architecture, according to an embodiment of the present disclosure.
[0047] FIG. 9D is an interaction diagram of a communication method, according to an embodiment of the present disclosure.
[0048] FIG. 10A is a schematic diagram of a structure of a RAN, according to an embodiment of the present disclosure.
[0049] FIG. 10B is a schematic diagram of a structure of a terminal, according to an embodiment of the present disclosure.
[0050] FIG. 10C is a schematic diagram of a structure of a third network element, according to an embodiment of the present disclosure.
[0051] FIG. 10D is a schematic diagram of a structure of a fourth network element, according to an embodiment of the present disclosure.
[0052] FIG. 10E is a schematic diagram of a structure of a first network element, according to an embodiment of the present disclosure.
[0053] FIG. 10F is a schematic diagram of a structure of a second network element, according to an embodiment of the present disclosure.
[0054] FIG. 11A is a schematic diagram of a structure of a communication device, according to an embodiment of the present disclosure.
[0055] FIG. 11B is a schematic diagram of a structure of a chip, according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0056] Embodiments of the present disclosure provide a communication method, a RAN, a terminal, a network element, a communication system, and a storage medium.
[0057] In a first aspect, some embodiments of the present disclosure provide a communication method, which includes: receiving, by a radio access network device (RAN), a first request sent by a terminal, the first request being used to request to establish a first data plane connection; and determining, by the RAN, whether to establish the first data plane connection.
[0058] In the above embodiments, the RAN receives the first request sent by the terminal and used to request to establish the first data plane connection, and determines whether to establish the first data plane connection, which can improve the security of establishing the data plane connection, thereby improving the security of data sharing.
[0059] In some embodiments, the first request includes at least one of a service identifier and a terminal identifier.
[0060] In some embodiments combined with the first aspect, in some embodiments, the determining whether to establish the first data plane connection comprises: in response to the terminal identifier and an identifier in the first list having a mapping relationship, determining to establish the first data plane connection; the first list comprises candidate terminal identifiers.
[0061] In some embodiments combined with the first aspect, in some embodiments, the determining whether to establish the first data plane connection comprises: the RAN sending a second request to a first network element, the second request being used to request subscription information of the terminal, the second request comprising the terminal identifier; the RAN receiving subscription information sent by the first network element, the subscription information being used to determine whether the terminal is authorized to establish the first data plane connection.
[0062] In some embodiments combined with the first aspect, in some embodiments, the RAN authorizing the terminal comprises: the RAN sending a third request to a first network element, the third request being used to request an authorization result, the third request comprising the terminal identifier and a service identifier; the RAN receiving the authorization result sent by the first network element.
[0063] In some embodiments combined with the first aspect, in some embodiments, the method further comprises: in response to the terminal being authorized to establish the first data plane connection, establishing the first data plane connection; in response to the terminal not being authorized to establish the first data plane connection, refusing to establish the first data plane connection.
[0064] In some embodiments combined with the first aspect, in some embodiments, the method further comprises: in response to the service identifier not belonging to a second list, refusing to establish the first data plane connection; the second list comprises service identifiers.
[0065] In some embodiments combined with the first aspect, in some embodiments, the method further comprises: the RAN acquiring a first list provided by a second network element; the second network element being one of a network function (NF), an application function (AF), a unified data repository (UDR), and a data plane data management (DPDM).
[0066] In some embodiments combined with the first aspect, in some embodiments, the method further comprises: the RAN establishing a second data plane connection with a third network element, at least one of the following being associated with the second data plane connection: the first list; the second list.
[0067] In some embodiments combined with the first aspect, in some embodiments, the first data plane connection and the second data plane connection have an association relationship.
[0068] In some embodiments of the first aspect, in some embodiments, the method further comprises: sending, by the RAN, a terminal status notification to a fourth network element, the terminal status notification being used to notify the fourth network element of an update of a status of the terminal.
[0069] In some embodiments of the first aspect, in some embodiments, the sending, by the RAN, of the terminal status notification to the fourth network element comprises at least one of: sending, by the RAN, the terminal status notification to the fourth network element in response to a change in the status of the terminal; sending, by the RAN, the terminal status notification to the fourth network element in response to the first data plane connection being successfully established; and periodically sending, by the RAN, the terminal status notification to the fourth network element.
[0070] In a second aspect, the embodiments of the present disclosure provide a communication method, comprising: sending, by a terminal, a first request to a radio access network device (RAN), the first request being used to request establishment of a first data plane connection.
[0071] In some embodiments of the second aspect, in some embodiments, the first request comprises at least one of a service identifier and a terminal identifier.
[0072] In a third aspect, the embodiments of the present disclosure provide a communication method, comprising: establishing, by a third network element, a second data plane connection with a radio access network device (RAN), the second data plane connection and the first data plane connection having an association relationship; and at least one of the following being associated with the second data plane connection: a first list; and a second list.
[0073] In some embodiments of the third aspect, in some embodiments, the method further comprises: receiving, by a fourth network element, a terminal status notification sent by the RAN, the terminal status notification being used to notify the third network element of an update of a status of the terminal.
[0074] In some embodiments of the third aspect, in some embodiments, the receiving, by the fourth network element, of the terminal status notification sent by the RAN comprises at least one of: receiving, by the fourth network element, the terminal status notification sent by the RAN in response to a change in the status of the terminal; receiving, by the fourth network element, the terminal status notification sent by the RAN in response to the first data plane connection being successfully established; and periodically receiving, by the third network element, the terminal status notification sent by the RAN.
[0075] In a fourth aspect, the embodiments of the present disclosure provide a communication method, which includes: receiving, by a first network element, a second request or a third request sent by a radio access network device (RAN), the second request being used to request subscription information of a terminal, the second request comprising a terminal identifier; the third request being used to request an authorization result, the third request comprising a terminal identifier and a service identifier; and sending, by the first network element, the subscription information or the authorization result to the RAN, the subscription information being used to determine whether the terminal is authorized to establish a first data plane connection.
[0076] In a fifth aspect, the embodiments of the present disclosure provide a communication method, which includes: providing, by a second network element, a first list to a radio access network device (RAN), the first list comprising candidate terminal identifiers; the first list being associated with a second data plane connection, and there being an association relationship between the second data plane connection and a first data plane connection.
[0077] In combination with some embodiments of the fifth aspect, in some embodiments, the first list is provided by a network function (NF) or an application function (AF).
[0078] In combination with some embodiments of the fifth aspect, in some embodiments, the first list is maintained and managed by a unified data repository (UDR) or a data plane data management (DPDM).
[0079] In a sixth aspect, the embodiments of the present disclosure provide a RAN, which includes: a transceiver module, configured to receive a first request sent by a terminal, the first request being used to request establishment of a first data plane connection; and a processing module, configured to authorize the terminal.
[0080] In a seventh aspect, the embodiments of the present disclosure provide a terminal, which includes: a transceiver module, configured to send a first request to a radio access network device (RAN), the first request being used to request establishment of a first data plane connection.
[0081] In an eighth aspect, the embodiments of the present disclosure provide a third network element, which includes: a transceiver module, configured to establish a second data plane connection with a radio access network device (RAN), there being an association relationship between the second data plane connection and a first data plane connection; and at least one of the following being associated with the second data plane connection: a first list; and a second list.
[0082] In a ninth aspect, the embodiments of the present disclosure provide a first network element, which includes: a transceiver module, configured to receive a second request or a third request sent by a radio access network device (RAN), the second request being used to request subscription information of a terminal, the second request comprising a terminal identifier; the third request being used to request an authorization result, the third request comprising a terminal identifier and a service identifier; and sending, by the first network element, the subscription information or the authorization result to the RAN, the subscription information being used to determine whether the terminal is authorized to establish a first data plane connection.
[0083] In a tenth aspect, embodiments of this disclosure propose a second network element, including: a transceiver module, configured to provide a first list to a radio access network (RAN) device, the first list including candidate terminal identifiers; the first list being associated with a second data plane connection, and an association relationship existing between the second data plane connection and the first data plane connection.
[0084] Eleventhly, embodiments of this disclosure provide an RAN, comprising: one or more processors; wherein the RAN is used to perform the communication method of the first aspect.
[0085] In a twelfth aspect, embodiments of this disclosure provide a terminal comprising: one or more processors; wherein the terminal is configured to execute the communication method of the second aspect.
[0086] In a thirteenth aspect, embodiments of this disclosure provide a third network element, comprising: one or more processors; wherein the third network element is used to execute the communication method of the third aspect.
[0087] In a fourteenth aspect, embodiments of this disclosure provide a first network element, comprising: one or more processors; wherein the first network element is used to execute the communication method of the fourth aspect.
[0088] In a fifteenth aspect, embodiments of this disclosure provide a second network element, comprising: one or more processors; wherein the second network element is used to perform the communication method of the fifth aspect.
[0089] In a sixteenth aspect, embodiments of this disclosure provide a communication system including an RAN, a terminal, a third network element, a first network element, and a second network element, wherein the RAN is configured to implement the communication method of the first aspect, the terminal is configured to implement the communication method of the second aspect, the third network element is configured to implement the communication method of the third aspect, the first network element is configured to implement the communication method of the fourth aspect, and the second network element is configured to implement the communication method of the fifth aspect.
[0090] In a seventeenth aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the methods described above.
[0091] In an eighteenth aspect, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in the optional implementation of the first or second aspect.
[0092] In a nineteenth aspect, embodiments of this disclosure provide a computer program that, when executed by a communication device, causes the communication device to perform any of the communication methods described above.
[0093] In a twentieth aspect, a chip or chip system is provided. The chip or chip system includes processing circuitry configured to perform the method described in any of the optional implementation manners of any of the aspects above.
[0094] It can be understood that the network function, the terminal, the communication system, the storage medium, the program product, the computer program, the chip or the chip system are used to execute the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described here.
[0095] The embodiments of the present disclosure propose a communication method, a terminal, a network device, a communication system and a storage medium. In some embodiments, the communication method and the information sending method, information receiving method and other terms can be replaced with each other.
[0096] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, some or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.
[0097] In each embodiment of the present disclosure, the terms and / or descriptions between the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0098] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.
[0099] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "said", "preceding", "this" and the like, can represent "one and only one", or "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, or as plural expression.
[0100] In the embodiments of the present disclosure, "a plurality of" means two or more.
[0101] In some embodiments, the terms "at least one of," "one or more of," "a plurality of," "multiple," and the like can be used interchangeably.
[0102] In some embodiments, the recitations "at least one of A, B," "A and / or B," "in one case A, in another case B," "in response to a case A, in response to a case B," and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments A and B are selected from A and B (A and B are selectively executed); in some embodiments A and B (A and B are both executed). When there are more branches such as A, B, C, and the like, the above is similar.
[0103] In some embodiments, the recitations "A or B" and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments A and B are selected from A and B (A and B are selectively executed). When there are more branches such as A, B, C, and the like, the above is similar.
[0104] The prefix words "first", "second", and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an additional limitation because of the use of the prefix words. For example, the description objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "devices", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description objects are "information", and "first information" and "second information" can be the same information or different information, and the content thereof can be the same or different.
[0105] In some embodiments, "comprising", "including", "to indicate", "carrying", can be interpreted as directly carrying A, or indirectly indicating A.
[0106] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.
[0107] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", "above" and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.
[0108] In some embodiments, the device and the like can be interpreted as physical or virtual, and the name is not limited to the name described in the embodiments. The terms "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.
[0109] In some embodiments, "network" can be interpreted as a device (for example, access network device, core network device, etc.) contained in the network.
[0110] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “serving cell,” “carrier,” “component carrier,” “bandwidth part (BWP),” and the like can be used interchangeably.
[0111] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.
[0112] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.
[0113] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.
[0114] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.
[0115] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.
[0116] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0117] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0118] As shown in FIG. 1A, the communication system 100 includes a terminal 101, a radio access network device 102, a third network element 103, a first network element 104, and a second network element 105.
[0119] In some embodiments, the terminal 101 can be a user equipment (UE), and the terminal 101, for example, includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, but is not limited thereto.
[0120] In some embodiments, the wireless access network device 102, for example, is a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved node B (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0121] In some embodiments, the technical solutions of the present disclosure can be applicable to an Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.
[0122] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit (control unit), and the CU-DU structure can split the protocol layers of the access network device, and part of the functions of the protocol layers are controlled by the CU, and the remaining part or all of the functions of the protocol layers are distributed in the DU and controlled by the CU, but the present disclosure is not limited thereto.
[0123] In some embodiments, the third network element 103 can be all or part of a core network element, and the third network element can include one or more network elements, and can also be a plurality of devices or device groups. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0124] For example, the third network element 103 can be any one of a 6G core (6GC) network function (NF), a user plane function (UPF), a data plane function (DPF).
[0125] In some embodiments, the third network element can include a fourth network element, which can be, for example, an NF.
[0126] In some embodiments, the first network element 104 is a network element responsible for storing and managing data. The first network element can be, for example, a unified data manager (UDM).
[0127] In some embodiments, the third network element can include the first network element.
[0128] In some embodiments, the second network element 105 is a network element that provides the first list. The second network can be, for example, one of an NF, an application function (AF), a unified data repository (UDR), and a data plane data management (DPDM).
[0129] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new business scenarios appear, the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems.
[0130] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subject, but are not limited thereto. The subjects shown in FIG. 1A are examples, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than those in FIG. 1A. The number and form of each subject is arbitrary, each subject can be real or virtual, the connection relationship between each subject is an example, each subject can not be connected or can be connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0131] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).
[0132] In 5G networks, most of the data stored or transmitted in the network comes from network communication operations and subscriptions. With the functions and services of 6G expanding from communication to perception, computing and Artificial Intelligence (AI), the data within the network will grow in both scope and type. As an abstract function between data providers and data consumers, data services can separate data consumers and data providers. When there are multiple data providers or consumers, data services can help maintain data integrity and improve efficiency through reusability. Data services provide data as a service product using a data distribution / publication framework to meet customers' real-time cross-system data needs, while reusing and complying with enterprise / industry regulations. Ultimately, data services need to strike a balance between data sharing and data transmission security in the data plane. 6G data services aim to efficiently support data collection, transmission, storage and sharing.
[0133] In 6G data services, 6G wireless access network (RAN) nodes can have more capabilities and functions, such as establishing data plane (DP) connections, data collection, data processing, data consumption, etc.
[0134] FIG. IB is a schematic diagram of data plane establishment according to an embodiment of the present disclosure.
[0135] As shown in FIG. IB, the 6G RAN node has established a data plane connection with the 6G user plane function (UPF) or data plane function (DPF) for transmitting shared data and obtaining the parameters required to establish the DP connection. Then, the UE sends a DP connection establishment request, and the RAN node decides whether to establish a DP connection for the UE.
[0136] In some embodiments, the 6G RAN node determines whether to establish a data plane connection with or without the involvement of 6G core (6GC) network functions (NFs).
[0137] In some embodiments, the 6G RAN node has the function of DP connection management. While having the function of DP connection management, if the 6G RAN node is unauthorized to accept the DP connection and establishes the DP connection with the unauthorized terminal, a malicious UE can inject irrelevant or disruptive data, distort the data service result, or even obtain the sensitive data of other UEs in the case of sharing data, which will lead to a Denial of Service (DoS) attack or privacy violation. Therefore, it is necessary to enable the 6G RAN node to establish the DP connection with the authorized terminal.
[0138] FIG. 1C is a schematic diagram of interaction between a UE and a RAN according to an embodiment of the present disclosure.
[0139] As shown in FIG. 1C, the UE and the 6G RAN node have established a DP connection, and the 6G RAN node and the 6G UPF / DPF have established a DP connection. The UE collects shared data and transmits through the DP connection. After receiving the shared data, the 6G RAN node can process and analyze it.
[0140] In some embodiments, the 6G RAN node has the function of data processing and data consumption.
[0141] FIG. 1D is a schematic diagram of interaction between a UE and a RAN according to an embodiment of the present disclosure.
[0142] As shown in FIG. 1D, the UE and the 6G RAN node have established a DP connection, and the 6G RAN node and the 6G UPF / DPF have established a DP connection. The 6G RAN node collects shared data and transmits to the UE through the DP connection. After receiving the shared data, the UE can process and analyze it.
[0143] In some embodiments, the 6G RAN node has the function of data collection.
[0144] FIG. 2A is a schematic diagram of interaction of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2A, the embodiment of the present disclosure relates to a communication method, and the above method comprises:
[0145] In step S2101, a second data plane connection is established between the RAN and a third network element.
[0146] In some embodiments, the third network element can be all or part of the core network element, and the third network element can also be any one of the core network element. For example, the third network element 103 can be at least one of the 6GC NF, the UPF, the DPF, and the UDM, but is not limited thereto.
[0147] In some embodiments, the third network element can include at least one of the fourth network element and the first network element.
[0148] In some embodiments, a data plane connection can be established between the terminal and the third network element, which can include a first data plane connection between the terminal and the RAN, and a second data plane connection between the RAN and the third network element. That is, the first data plane connection and the second data plane connection have an association relationship. It can be understood that the first data plane connection and the second data plane connection can be data plane connections for the same data service.
[0149] In some embodiments, a second data plane connection can be established between the RAN and the third network element, and the third network element can associate at least one of the following with the second data plane connection: the first list; the second list.
[0150] In some embodiments, the first list includes candidate terminal identifiers, for example, the first list is a candidate terminal list.
[0151] In some embodiments, the second data plane connection can be dedicated to a terminal corresponding to a candidate terminal identifier included in the first list. The terminal can include a terminal in a connected state and a terminal in an idle state, for a terminal in a connected state, the candidate terminal identifier included in the first list can be an access and mobility management function (AMF)-UE-Next Generation Application Protocol (NGAP)-ID or a RAN-UE-NGAP-ID; for a terminal in an idle state, the UE identifier included in the list can be a subscription concealed identifier (SUCI) / generic public subscription identifier (GPSI) / application layer identifier (ID).
[0152] In some embodiments, the AMF-UE-NGAP-ID is assigned by the AMF when the terminal is in a connected state. The RAN-UE-NGAP-ID is assigned by the RAN node when the terminal is in a connected state.
[0153] In some embodiments, the RAN stores the relationship between the RNTI and the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID. The AMF stores the relationship between the AMF-UE-NGAP-ID and the RAN-UE-NGAP-ID.
[0154] In some embodiments, the ID mapping details after receiving the message are shown in Table 1.
[0155] Table 1
[0156] In some embodiments, the second list includes service identities or task identities, for example, the second list is a service identity list or a task identity list.
[0157] In some embodiments, the second data plane connection can be dedicated to a service or a task corresponding to the service identity or the task identity included in the second list.
[0158] In some embodiments, the third network element can also associate security policies (including a Confidentiality Protection policy and an Integrity Protection policy) with the second data plane connection.
[0159] In step S2102, the RAN acquires the first list provided by the second network element.
[0160] In some embodiments, the first list can be provided by the second network element.
[0161] In some embodiments, the RAN acquires the first list provided by the second network element.
[0162] In some embodiments, the RAN receives the first list sent by the second network element.
[0163] In an example, the second network element can directly send the first list to the RAN, and the RAN directly receives the first list sent by the second network element. In another example, the second network element can send the first list to the RAN through other network elements, and the RAN can receive the first list sent by the second network element through the other network elements.
[0164] In some embodiments, the second network element is one of an NF, an AF, a UDR, and a DPDM.
[0165] In an example, the first list is provided by the NF or the AF.
[0166] For example, the NF or the AF can send the first list to an AMF or a Session Management Function (SMF), and the AMF or the SMF sends the first list to the RAN.
[0167] For another example, the NF or the AF can send the first list to a UDM, the UDM sends the first list to an AMF or an SMF, and the AMF or the SMF sends the first list to the RAN.
[0168] In another example, the first list is maintained and managed by the UDR or DPDM.
[0169] In some embodiments, the NF or AF provides the first list to the UDR or DPDM. The first list is associated with one or more service identities. For a terminal authorized to provide / use data related to the service identity, its terminal identity is included in the first list. The AF or NF can update the first list stored in the UDR or DPDM periodically or according to the change of terminal subscription information.
[0170] In some embodiments, the UDR or DPDM can provide the first list to the RAN after or during the establishment of the second data plane connection.
[0171] For example, the NF or AF sends a request to trigger the AMF or SMF to establish a data plane connection, the AMF or SMF sends a request to the UDR or DPDM to obtain the first list associated with the data plane connection, and the first list is maintained and managed by the UDR or DPDM. The AMF or SMF can obtain the first list from the UDR or DPDM and send it to the RAN.
[0172] In some embodiments, the network element providing the first list and the data flow direction of the data plane connection establishment process can be as shown in Table 2.
[0173] Table 2
[0174] In some embodiments, when the first list is sent, the second network element sends the updated first list to the RAN.
[0175] Step S2103, the terminal sends a first request to the RAN.
[0176] In some embodiments, the RAN receives the first request sent by the terminal.
[0177] In some embodiments, the first request is used to request the establishment of a first data plane connection. Wherein, the first data plane connection is a data plane connection between the terminal and the RAN.
[0178] In some embodiments, the first request is, for example, a first data plane establishment request.
[0179] In some embodiments, the first request can be sent to the RAN at the Access Stratum (AS) layer.
[0180] In some embodiments, the first request includes at least one of a service identity and a terminal identity.
[0181] In some embodiments, the terminal identity included in the first request can be one of RNTI, SUCI / GPSI / application layer ID, for example.
[0182] In some embodiments, the terminal identity (e.g. SUCI / GPSI / application layer ID) in the first request sent by the terminal to the RAN can be protected by the AS layer key. For example, the terminal encrypts the whole first request based on the AS layer key, or the terminal encrypts the terminal identity in the first request based on the AS layer key. The terminal sends the encrypted first request to the RAN. For another example, the terminal protects the integrity of the whole first request based on the AS layer key, or the terminal protects the integrity of the terminal identity in the first request based on the AS layer key. The terminal sends the integrity-protected first request to the RAN.
[0183] In the embodiments of the present disclosure, the RAN can process the terminal identity such as SUCI, GPSI, application layer ID, and the like, and therefore the terminal can send such terminal identity to the RAN for subsequent processing.
[0184] In step S2104, the RAN determines whether to establish the first data plane connection.
[0185] In some embodiments, the RAN can determine whether the terminal is an authorized terminal.
[0186] In some embodiments, the RAN can determine whether to establish the first data plane connection based on whether the terminal is an authorized terminal. For example, the RAN determines that the terminal is an authorized terminal, and determines to establish the first data plane connection; the RAN determines that the terminal is an unauthorized terminal, and determines not to establish the first data plane connection.
[0187] In some embodiments, the RAN can authorize the terminal.
[0188] In some embodiments, the RAN can determine whether to establish the first data plane connection based on the authorization result. For example, the RAN determines that the terminal is authorized, and determines to establish the first data plane connection; the RAN determines that the terminal is not authorized, and determines not to establish the first data plane connection.
[0189] In some embodiments, the RAN can determine whether to establish the first data plane connection based on the first request sent by the terminal.
[0190] In some embodiments, the RAN can determine whether the terminal is an authorized terminal based on the first request sent by the terminal.
[0191] In some embodiments, in response to the RAN passing the authorization of the terminal, or, in response to the RAN determining that the terminal is an authorized terminal, or, in response to the RAN determining to establish the first data plane connection, the RAN establishes the first data plane connection between the terminal and the RAN, i.e., step S2107 is performed.
[0192] In some other embodiments, in response to the RAN failing the authorization of the terminal, or, in response to the RAN determining that the terminal is an unauthorized terminal, or, in response to the RAN determining not to establish the first data plane connection, the RAN rejects to establish the first data plane connection, in which case, the RAN can send a message to the terminal indicating the rejection to establish the first data plane connection.
[0193] In some embodiments, the RAN can determine whether there is a mapping relationship between the terminal identity included in the first request and the identities in the first list, for example, the RAN determines whether the terminal identity included in the first request belongs to the first list.
[0194] For example, the terminal identities included in the first list are SUCI 1, SUCI 2, SUCI 3, and the terminal identity included in the first request is SUCI 1, then it is determined that the terminal identity included in the first request belongs to the first list.
[0195] For another example, the terminal identities included in the first list are SUCI 1, SUCI 2, SUCI 3, and the terminal identity included in the first request is SUCI 4, then it is determined that the terminal identity included in the first request does not belong to the first list.
[0196] For example, the terminal identities included in the first list are RAN-UE-NGAP-ID 1, RAN-UE-NGAP-ID 2, and the terminal identity included in the first request is RNTI1, wherein there is a mapping relationship between RAN-UE-NGAP-ID 1 and RNTI 1, then it is determined that there is a mapping relationship between the terminal identity included in the first request and the identities in the first list.
[0197] For another example, the terminal identities included in the first list are RAN-UE-NGAP-ID 1, RAN-UE-NGAP-ID 2, and the terminal identity included in the first request is RNTI3, wherein there is a mapping relationship between RAN-UE-NGAP-ID 1 and RNTI 1, then it is determined that there is no mapping relationship between the terminal identity included in the first request and the identities in the first list.
[0198] For example, the terminal identities included in the first list are SUCI 1, SUCI 2, and the terminal identity included in the first request is RNTI1, wherein there is a mapping relationship between SUCI 1 and RNTI 1, then it is determined that there is a mapping relationship between the terminal identity included in the first request and the identities in the first list.
[0199] For example, the terminal identity included in the first list is SUCI 1, the terminal identity included in the first request is RNTI 3, and there is a mapping relationship between SUCI 1 and RNTI 1, and it is determined that there is no mapping relationship between the terminal identity included in the first request and the identity in the first list.
[0200] In some embodiments, in response to the terminal identity and the identity in the first list having a mapping relationship, the terminal authorization is passed, or it is determined that the terminal is an authorized terminal, or it is determined to connect the first data plane connection. In this case, steps S2105-S2106 can be skipped, and step S2107 can be performed.
[0201] In some embodiments, the RAN can determine whether the service identity included in the first request belongs to the second list.
[0202] In some embodiments, in response to the service identity not belonging to the second list, the RAN rejects the establishment of the first data plane connection.
[0203] In other embodiments, in response to the terminal identity and the identity in the first list not having a mapping relationship, but the service identity belonging to the second list, the RAN can further determine whether to establish the first data plane connection by sending a second request to the first network element to obtain the subscription information of the terminal (steps S2105-S2106), or the RAN can further determine whether to establish the first data plane connection by sending a third request to the first network element to obtain the authorization result of the terminal.
[0204] In step S2105, the RAN sends a second request to the first network element.
[0205] In some embodiments, the first network element receives the second request sent by the RAN.
[0206] In some embodiments, the first network element is a network element responsible for storing and managing data, and the first network element can be, for example, a UDM.
[0207] In some embodiments, the RAN can directly interact with the first network element, or can interact with the first network element through the AMF.
[0208] In some embodiments, the second request is used to request the subscription information of the terminal.
[0209] In some embodiments, the second request includes the terminal identity.
[0210] In some embodiments, the first network element retrieves the subscription information of the terminal according to the terminal identity in the second request and returns the RAN.
[0211] Step S2106, the first network element sends the subscription information to the RAN.
[0212] In some embodiments, the RAN receives the subscription information sent by the first network element.
[0213] In some embodiments, the subscription information is used to determine whether the terminal is authorized to establish the first data plane connection.
[0214] In some embodiments, the RAN determines whether the terminal is authorized to establish the first data plane connection based on the subscription information of the terminal.
[0215] In some embodiments, the subscription information includes services to which the terminal has subscribed, and the RAN can determine whether the service corresponding to the service identifier included in the first request is a service to which the terminal has subscribed. If the service corresponding to the service identifier included in the first request is a service to which the terminal has subscribed, the RAN determines that the terminal is authorized to establish the first data plane connection; if the service corresponding to the service identifier included in the first request is not a service to which the terminal has subscribed, the RAN determines that the terminal is not authorized to establish the first data plane connection.
[0216] In some embodiments, in response to the terminal being authorized to establish the first data plane connection, the first data plane connection is established (step S2107 is performed).
[0217] In some other embodiments, in response to the terminal not being authorized to establish the first data plane connection, the establishment of the first data plane connection is rejected.
[0218] It can be understood that steps S2105-S2106 are optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0219] In some embodiments, step S2104 is optional, i.e., step S2104 can not be performed, and steps S2105 and S2106 can be performed directly.
[0220] Step S2107, the RAN establishes the first data plane connection.
[0221] In some embodiments, in response to the RAN authorizing the terminal, or in response to the RAN determining that the terminal is an authorized terminal, or in response to the RAN determining to establish the first data plane connection, the RAN establishes the first data plane connection between the terminal and the RAN.
[0222] In some embodiments, after the first data plane connection is established, the terminal can send uplink data to the RAN based on the first data plane connection, and the RAN sends the uplink data to the third network element based on the second data plane connection. The third network element can send downlink data to the RAN based on the second data plane connection, and the RAN sends the downlink data to the terminal based on the first data plane connection.
[0223] Step S2108, the RAN sends a terminal state notification to the fourth network element.
[0224] In some embodiments, the third network element can be all or part of a core network element, and the fourth network element can be any core network element. The third network element can include the fourth network element, and the fourth network element can be, for example, an NF.
[0225] In some embodiments, the fourth network element receives the terminal state notification sent by the RAN.
[0226] In some embodiments, the terminal state notification is used to notify the fourth network element of the state update of the terminal.
[0227] In some embodiments, the RAN sends the terminal state notification to the fourth network element, including at least one of the following: the RAN sends the terminal state notification to the fourth network element in response to a change in the state of the terminal; the RAN sends the terminal state notification to the fourth network element in response to the successful establishment of the first data plane connection; and the RAN periodically sends the terminal state notification to the fourth network element.
[0228] For example, the RAN sends the terminal state notification to the fourth network element when the state of the terminal changes.
[0229] For another example, the RAN sends the terminal state notification to the fourth network element when the first data plane connection is successfully established.
[0230] For another example, the RAN sends the terminal state notification to the fourth network element based on a preset period, notifying the fourth network element of the terminal whose state changes within the preset period.
[0231] The communication method provided by the embodiments of the present disclosure can improve the security of establishing a data plane connection, thereby improving the security of data sharing.
[0232] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101-S2108. For example, step S2103 can be implemented as an independent embodiment, and steps S2103 and S2104 can be implemented as an independent embodiment, but are not limited thereto.
[0233] In some embodiments, steps S2105 and S2106 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0234] In some embodiments, step S2107 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0235] In some embodiments, step S2108 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0236] In some embodiments, other optional implementations can be found in the description before or after the description of FIG. 2A.
[0237] FIG. 2B is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2B, the embodiment of the present disclosure relates to a communication method, and the method comprises:
[0238] Step S2201: A second data plane connection is established between the RAN and the third network element.
[0239] Optional implementations of step S2201 can be found in the optional implementations of step S2101 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0240] Step S2202: The RAN acquires the first list provided by the second network element.
[0241] Optional implementations of step S2202 can be found in the optional implementations of step S2102 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0242] Step S2203: The terminal sends a first request to the RAN.
[0243] Optional implementations of step S2203 can be found in the optional implementations of step S2103 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0244] Step S2204: The RAN determines whether to establish a first data plane connection.
[0245] Optional implementations of step S2204 can be found in the optional implementations of step S2104 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0246] In some embodiments, in response to the RAN granting the terminal, or in response to the RAN determining that the terminal is an authorized terminal, or in response to the RAN determining to establish the first data plane connection, the RAN establishes the first data plane connection between the terminal and the RAN, i.e., step S2207 is performed.
[0247] In some embodiments, the RAN can determine whether the terminal identifier included in the first request and the identifier in the first list have a mapping relationship.
[0248] In some embodiments, the RAN can determine whether the terminal identifier included in the first request and the identifier in the first list have a mapping relationship.
[0249] In some embodiments, in response to the terminal identifier and the identifier in the first list having a mapping relationship, the terminal authorization passes, or the terminal is determined to be an authorized terminal, or the first data plane connection is determined to be connected. In this case, steps S2205-S2206 below can be skipped, and step S2207 can be performed.
[0250] In some embodiments, the RAN can determine whether the service identifier included in the first request belongs to the second list.
[0251] In some embodiments, in response to the service identifier not belonging to the second list, the RAN refuses to establish the first data plane connection.
[0252] In some embodiments, in response to the terminal identifier and the identifier in the first list not having a mapping relationship, but the service identifier belonging to the second list, the RAN can further determine whether to establish the first data plane connection by sending a second request to the first network element to obtain the subscription information of the terminal (steps S2205-S2206), or the RAN can further determine whether to establish the first data plane connection by sending a third request to the first network element to obtain the authorization result of the terminal.
[0253] In step S2205, the RAN sends a third request to the first network element.
[0254] In some embodiments, the first network element receives the third request sent by the RAN.
[0255] In some embodiments, the RAN can directly interact with the first network element, or can interact with the first network element through the AMF.
[0256] In some embodiments, the third request is used to request the authorization result.
[0257] In some embodiments, the third request includes the terminal identifier and the service identifier.
[0258] In some embodiments, the first network element determines whether the terminal corresponding to the terminal identifier is authorized to use the service corresponding to the service identifier according to the terminal identifier and the service identifier in the third request, and returns the authorization result to the RAN.
[0259] In some embodiments, the first network element can retrieve services to which the terminal is subscribed according to the terminal identifier in the third request, and determine whether the service corresponding to the service identifier included in the third request is a service to which the terminal is subscribed. If the service corresponding to the service identifier included in the third request is a service to which the terminal is subscribed, the first network element determines that the authorization result returned to the RAN is that the terminal is authorized; if the service corresponding to the service identifier included in the third request is not a service to which the terminal is subscribed, the first network element determines that the authorization result returned to the RAN is that the terminal is not authorized.
[0260] In step S2206, the first network element sends the authorization result to the RAN.
[0261] In some embodiments, the RAN receives the authorization result sent by the first network element. The authorization result can include one of that the terminal is authorized and that the terminal is not authorized.
[0262] In some embodiments, the RAN determines whether the terminal is authorized to establish the first data plane connection based on the authorization result sent by the first network element. If the authorization result is that the terminal is authorized, the RAN determines that the terminal is authorized to establish the first data plane connection; if the authorization result is that the terminal is not authorized, the RAN determines that the terminal is not authorized to establish the first data plane connection.
[0263] In some embodiments, in response to the terminal being authorized to establish the first data plane connection, the first data plane connection is established (step S2207 is performed).
[0264] In some other embodiments, in response to the terminal not being authorized to establish the first data plane connection, the establishment of the first data plane connection is rejected.
[0265] It can be understood that steps S2205-S2206 are optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0266] In some embodiments, step S2204 is optional, i.e., step S2204 can not be performed, and steps S2205 and S2206 are directly performed.
[0267] In step S2207, the RAN establishes the first data plane connection.
[0268] The optional implementation of step S2207 can refer to the optional implementation of step S2107 of FIG. 2A and other associated parts in the embodiments involved by FIG. 2A, which will not be described here.
[0269] In step S2208, the RAN sends a terminal state notification to the fourth network element.
[0270] The optional implementation of step S2208 can refer to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0271] The communication method provided by the embodiments of the present disclosure can improve the security of establishing the data plane connection, thereby improving the security of data sharing.
[0272] The communication method related to the embodiments of the present disclosure can include at least one of steps S2201-S2208. For example, step S2203 can be implemented as an independent embodiment, and steps S2203 and S2204 can be implemented as an independent embodiment, but are not limited thereto.
[0273] In some embodiments, steps S2205 and S2206 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0274] In some embodiments, step S2207 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0275] In some embodiments, step S2208 is optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0276] In some embodiments, other optional implementations can be described before or after the corresponding description of FIG. 2B.
[0277] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and the terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "code point", "bit", "data", "program", "chip", and the like can be replaced with each other.
[0278] In some embodiments, the terms "moment", "time point", "time", "time position" and the like can be replaced with each other, and the terms "duration", "time period", "time window", "window", "time" and the like can be replaced with each other.
[0279] In some embodiments, the terms "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" and the like can be replaced with each other, which can be interpreted as receiving from other subjects, acquiring from protocols, obtaining from higher layers, obtaining by self-processing, autonomously implementing and the like.
[0280] In some embodiments, the terms "send", "transmit", "report", "issue", "transmit", "bidirectional transmission", "send and / or receive" and the like can be replaced with each other.
[0281] In some embodiments, the terms "certain", "preset", "preset", "set", "indicated", "certain", "arbitrary", "first" and the like can be replaced with each other, and "certain A", "preset A", "preset A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in protocols and the like, or can be interpreted as A obtained by setting, configuring or indicating, or can be interpreted as certain A, certain A, arbitrary A or first A, but not limited thereto.
[0282] In some embodiments, determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but not limited thereto.
[0283] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or can be interpreted as not performing subsequent processing on the data and the like after receiving the data and the like; "not expecting to send" can be interpreted as not sending, or can be interpreted as sending but not expecting the receiving party to respond to the content of the sending.
[0284] FIG. 3A is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiment of the present disclosure relates to a communication method, which is performed by the RAN, and the above method comprises:
[0285] Step S3101, establishing a second data plane connection.
[0286] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in FIG. 2A, step S2201 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0287] In some embodiments, the RAN establishes the second data plane connection with the third network element.
[0288] Step S3102: Obtain the first list.
[0289] The optional implementation of step S3102 can refer to the optional implementation of step S2102 in FIG. 2A, step S2202 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0290] In some embodiments, the RAN obtains the first list provided by the second network element.
[0291] In some embodiments, the NF or the AF provides the first list to the RAN.
[0292] In some embodiments, the UDR or the DPDM maintains and manages the first list, and the UDR or the DPDM provides the first list to the RAN.
[0293] Step S3103: Obtain the first request.
[0294] The optional implementation of step S3103 can refer to the optional implementation of step S2103 in FIG. 2A, step S2203 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0295] In some embodiments, the RAN receives the first request sent by the terminal.
[0296] Step S3104: Determine whether to establish the first data plane connection.
[0297] The optional implementation of step S3104 can refer to the optional implementation of step S2104 in FIG. 2A, step S2204 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0298] In some embodiments, the RAN determines whether to establish the first data plane connection.
[0299] In some embodiments, the RAN authorizes the terminal, and determines whether to establish the first data plane connection based on the authorization result.
[0300] In some embodiments, the RAN determines whether the terminal is an authorized terminal, and determines whether to establish the first data plane connection.
[0301] In some embodiments, in response to the RAN determining to connect the first data plane connection, or in response to the RAN determining that the terminal is an authorized terminal, or in response to the RAN passing the authorization of the terminal, the RAN establishes the first data plane connection between the terminal and the RAN.
[0302] In some other embodiments, in response to the RAN determining not to connect the first data plane connection, or in response to the RAN determining that the terminal is an unauthorized terminal, or in response to the RAN failing the authorization of the terminal, the RAN refuses to establish the first data plane connection.
[0303] In some embodiments, in response to the terminal identity and the identity in the first list having a mapping relationship, the terminal passes the authorization. In response to the service identity not belonging to the second list, the RAN refuses to establish the first data plane connection. In response to the terminal identity and the identity in the first list not having a mapping relationship, but the service identity belonging to the second list, the RAN can further determine whether to establish the first data plane connection by sending a second request to the first network element to obtain the subscription information of the terminal, or the RAN can further determine whether to establish the first data plane connection by sending a third request to the first network element to obtain the authorization result of the terminal. In response to the terminal being authorized to establish the first data plane connection, the first data plane connection is established. In response to the terminal not being authorized to establish the first data plane connection, the first data plane connection is refused to be established.
[0304] Step S3105, the first data plane connection is established.
[0305] The optional implementation of step S3105 can be referred to the optional implementation of step S2107 in FIG. 2A, step S2207 in FIG. 2B, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2B, which will not be described here.
[0306] In some embodiments, the RAN establishes the first data plane connection between the terminal and the RAN.
[0307] Step S3106, the terminal state notification is sent.
[0308] The optional implementation of step S3106 can be referred to the optional implementation of step S2108 in FIG. 2A, step S2208 in FIG. 2B, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2B, which will not be described here.
[0309] In some embodiments, the RAN sends the terminal state notification to the fourth network element.
[0310] The communication method related to the embodiments of the present disclosure can include at least one of steps S3101-S3106. For example, step S3103 can be implemented as an independent embodiment, steps S3103+S3104 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.
[0311] In some embodiments, step S3102 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0312] In some embodiments, step S3105 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0313] In some embodiments, step S3106 is optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0314] FIG. 3B is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to a communication method performed by a RAN, and the above method includes:
[0315] Step S3201, obtaining a first request.
[0316] The optional implementation of step S3201 can refer to the optional implementation of step S2103 in FIG. 2A, step S2203 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0317] In some embodiments, the RAN receives the first request sent by the terminal.
[0318] Step S3202, determining whether to establish a first data plane connection.
[0319] The optional implementation of step S3202 can refer to the optional implementation of step S2104 in FIG. 2A, step S2204 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0320] In some embodiments, the RAN determines whether to establish the first data plane connection.
[0321] The communication method related to the embodiments of the present disclosure can include at least one of steps S3201-S3202. For example, step S3201 can be implemented as an independent embodiment, step S3202 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.
[0322] FIG. 4 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4, the embodiment of the present disclosure relates to a communication method, which is performed by a terminal, and the method comprises the following steps.
[0323] In step S4101, a first request is sent.
[0324] The optional implementation of step S4101 can refer to the optional implementation of step S2103 in FIG. 2A, step S2203 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0325] In some embodiments, the terminal sends the first request to the RAN.
[0326] FIG. 5A is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 5A, the embodiment of the present disclosure relates to a communication method, which is performed by a third network element, and the method comprises the following steps.
[0327] In step S5101, a second data plane connection is established.
[0328] The optional implementation of step S5101 can refer to the optional implementation of step S2101 in FIG. 2A, step S2201 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0329] In some embodiments, the second data plane connection is established between the third network element and the RAN.
[0330] FIG. 5B is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 5B, the embodiment of the present disclosure relates to a communication method, which is performed by a fourth network element, and the method comprises the following steps.
[0331] In step S5201, a terminal state notification is acquired.
[0332] The optional implementation of step S5201 can refer to the optional implementation of step S2108 in FIG. 2A, step S2208 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0333] In some embodiments, the fourth network element receives the terminal state notification sent by the RAN.
[0334] FIG. 6A is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 6A, the embodiment of the present disclosure relates to a communication method, which is performed by a first network element, and the method comprises the following steps.
[0335] In step S6101, a second request is acquired.
[0336] The optional implementation of step S6101 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0337] In some embodiments, the first network element receives the second request sent by the RAN.
[0338] Step S6102: sending the subscription information.
[0339] The optional implementation of step S6102 can refer to the optional implementation of step S2106 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0340] In some embodiments, the first network element sends the subscription information to the RAN.
[0341] FIG. 6B is a flow diagram of a communication method according to some embodiments of the present disclosure. As shown in FIG. 6B, the embodiments of the present disclosure relate to a communication method, which is performed by a first network element, and the above method comprises the following steps:
[0342] Step S6201: obtaining a third request.
[0343] The optional implementation of step S6201 can refer to the optional implementation of step S2205 in FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.
[0344] In some embodiments, the first network element receives the third request sent by the RAN.
[0345] Step S6202: sending an authorization result.
[0346] The optional implementation of step S6202 can refer to the optional implementation of step S2206 in FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.
[0347] In some embodiments, the first network element sends the authorization result to the RAN.
[0348] FIG. 7 is a flow diagram of a communication method according to some embodiments of the present disclosure. As shown in FIG. 7, the embodiments of the present disclosure relate to a communication method, which is performed by a second network element, and the above method comprises the following steps:
[0349] Step S7101: providing a first list.
[0350] The optional implementation of step S7101 can refer to the optional implementation of step S2102 in FIG. 2A, the optional implementation of step S2202 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0351] In some embodiments, the second network element provides the first list to the RAN.
[0352] FIG. 8 is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 8, the embodiment of the present disclosure relates to a communication method, and the method comprises:
[0353] In step S8101, the terminal sends a first request to the RAN.
[0354] The optional implementation of step S8101 can refer to the optional implementation of step S2103 in FIG. 2A, step S2203 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0355] In step S8102, the RAN determines whether to establish a first data plane connection.
[0356] The optional implementation of step S8102 can refer to the optional implementation of step S2104 in FIG. 2A, step S2204 in FIG. 2B, and other associated parts in the embodiments related to FIG. 2A and FIG. 2B, which will not be repeated here.
[0357] In some embodiments, the above method can include the method of the above embodiments of the communication system side, the terminal side, the RAN side, the network element side, etc., which will not be repeated here.
[0358] The embodiment of the present disclosure proposes a communication method to ensure that the 6G RAN node can detect the terminal authorization in the process of establishing the DP connection. The 6G RAN node is provided with the necessary information related to the request for the DP connection, so as to establish the DP connection in a network in a secure manner.
[0359] In some embodiments, unlike the 5G architecture, the 6G architecture can include three independent planes, which respectively handle different types of traffic, namely the control plane, the user plane, and the data plane.
[0360] In some embodiments, the control plane carries signaling traffic. The control plane is used to handle tasks such as identity verification, authorization, and mobility management.
[0361] In some embodiments, the user plane carries the service data traffic of each UE.
[0362] In some embodiments, the data plane is responsible for the collection and management of shared data. The data of the data plane can be a group of UEs of one owner, or a group of UEs of one network task / service task, rather than one UE.
[0363] FIG. 9A is a schematic diagram of a network architecture according to an embodiment of the present disclosure.
[0364] As shown in FIG. 9A, the network architecture includes a network exposure function (Network Exposure Function, NEF), a network storage function (NF Repository Function, NRF), a policy control function (Policy Control Function, PCF), a unified data management network element (Unified Data Manager, UDM), an application function (Application Function, AF), an authentication server function (Authentication Server Function, AUSF), an access and mobility management function (Access and Mobility Management Function, AMF), a session management function (Session Management Function, SMF), a network data analysis function (Network Data Analytics Function, NWDAF), a UE, a radio access network (Radio Access Net, RAN), a user plane function (User Plane Function, UPF), a data network (Data network, DN), and a data plane function (Data Plane function, DPF).
[0365] In FIG. 9A, N1, N2, N3, N4, N6 and N9 are interfaces between corresponding network elements; Namf, Nsmf, Nausf, Nudm, Nnef, Npcf, Naf, Nnssf, Nnrf and Nnwadf are service interfaces exposed by AMF, SMF, AUSF, UDM, NEF, PCF, AF, NSSF, NRF and NWDAF respectively.
[0366] In the embodiments of the present disclosure, the NF can be a network function in the AMF, SMF, AUSF, UDM, NEF, PCF or AF. The above network elements can be network elements implemented on dedicated hardware, software instances running on dedicated hardware, or instances of virtualized functions on appropriate platforms.
[0367] In some embodiments, the functions of 6G NFs can include the following functions.
[0368] In some embodiments, the 6G data plane function (Data Plane function, DPF) has at least one of the following functions:
[0369] Forwarding and routing shared data to target NFs, e.g. 6G NWDAF or 6G DPMF;
[0370] Anchor function for the data plane;
[0371] Interconnect point for the UE with the 6GC control plane / user plane / data plane.
[0372] In some embodiments, the 6G RAN has at least one of the following functions:
[0373] The RAN node under the 6G network can authorize the UE in the process of establishing a DP connection between the UE and the RAN node;
[0374] The RAN node in the 6G network can interpret higher layer information above the Radio Resource Control (RRC) layer, such as the UE's Subscription Concealed Identifier (SUCI) / generic public subscription identifier (GPSI) / application layer identifier (ID), candidate UE list, service / task identifier, service / task identifier list, etc.
[0375] FIG. 9B is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 9B, the embodiment of the present disclosure relates to a communication method, and the method comprises:
[0376] Step S9101: DP connection establishment between the RAN, the 6GC NF, the UPF / DPF, and the 6G UDM.
[0377] In some embodiments, the 6G RAN node performs a data plane connection establishment procedure. In this procedure, the 6GC NF associates the following parameters with this connection:
[0378] Service / task identifier list: this DP connection is dedicated to these services / tasks;
[0379] Candidate UE list: This DP connection is dedicated to this group of terminals. For the UE in the CONNECTED state, the UE identity included in the list can be AMF-UE-Next Generation Application Protocol (NGAP)-ID or RAN-UE-NGAP-ID; for the terminal in the IDLE state, the UE identity included in the list can be SUCI / GPSI / application layer ID;
[0380] Security policy (including Confidentiality Protection policy and Integrity Protection policy).
[0381] In some embodiments, the candidate UE list can be provided by the AF or 6GC NF. The AF or 6GC NF can interact with the 6G AMF to retrieve the corresponding AMF-UE-NGAP-ID or RAN-UE-NGAP-ID. The AF or 6GC NF can send the message including the UE identity to the 6G AMF, such as SUCI / GPSI / application layer ID; the 6G AMF performs ID mapping for use in the RAN node.
[0382] In some embodiments, the AMF-UE-NGAP-ID is assigned by the AMF only when the terminal is in the CM-CONNECTED state. The RAN-UE-NGAP-ID is assigned by the RAN node only when the terminal is in the CM-CONNECTED state.
[0383] In some embodiments, different UE identities are used in different messages, and the entity receiving the message performs ID mapping.
[0384] In some embodiments, the 6G RAN stores the relationship between the RNTI and the RAN-UE-NGAP-ID, the RAN-UE-NGAP-ID and the AMF-UE-NGAP-ID. The AMF stores the relationship between the AMF-UE-NGAP-ID and the RAN-UE-NGAP-ID.
[0385] In some embodiments, the ID mapping details after receiving the message are shown in Table 1.
[0386] Step S9102, the DP connection between the RAN and the UPF / DPF has been established.
[0387] In some embodiments, the data plane connection between the 6G RAN node and the 6G UPF / 6G DPF has been established.
[0388] Step S9103, the UE sends a DP connection setup request to the RAN.
[0389] In some embodiments, the UE sends a DP connection setup request to the 6G RAN node, which is an RRC message. The DP connection setup request can include a service / task identity, a UE identity (e.g. RNTI or SUCI / GPSI / application layer ID).
[0390] Step S9104, the RAN sends an authorization request to the 6G UDM.
[0391] Step S9105, the 6G UDM sends an authorization response to the RAN.
[0392] In some embodiments, if the UE identity (e.g. RNTI or SUCI / GPSI / application layer ID) can be mapped to an identity in the candidate UE list, steps S9104 and S9105 are skipped.
[0393] In some embodiments, if the service / task identity provided by the UE is not in the service / task identity list, steps S9104 and S9105 are skipped.
[0394] In some embodiments, if the UE identity (e.g. RNTI or SUCI / GPSI / application layer ID) cannot be mapped to an identity included in the candidate UE list, but the service / task identity provided by the UE is included in the service / task identity list, the 6G RAN interacts with the 6G CN (e.g. 6G UDM) through the 6G AMF for UE authorization. The authorization request includes the UE identity (e.g. SUCI / GPSI) and the service / task identity.
[0395] In some embodiments, if the 6G RAN node is a service-based RAN node, the 6G RAN node can directly interact with the 6G UDM. If the 6G RAN node is not a service-based RAN node, the 6G RAN node can indirectly interact with the 6G UDM, i.e. through the 6G AMF forwarding.
[0396] In some embodiments, the 6G UDM retrieves UE subscription information according to the received UE identity and returns to the 6G RAN node.
[0397] Optionally, the 6G UDM returns the authorization result to the 6G RAN node according to the received UE identity and service / task identity.
[0398] Step S9106, the RAN determines whether the connection can be established.
[0399] In some embodiments, the 6G RAN node decides whether the DP connection can be established.
[0400] In some embodiments, if the service / task identity provided by the UE is not in the service / task identity list, the 6G RAN node rejects the DP connection establishment request, regardless of whether the UE identity can be mapped to the identity in the candidate UE list.
[0401] In some embodiments, if the service / task identity provided by the UE is in the service / task identity list, it is further determined whether the UE identity can be mapped to the candidate UE list.
[0402] In some embodiments, if the UE identity can be mapped to the candidate UE list, the DP connection can be established.
[0403] In some embodiments, if the UE identity is not in the candidate UE list, but the UE is authorized to use the service / task of the identity, the DP connection can be established.
[0404] In some embodiments, the 6G RAN determines the UE authorization status by at least one of the following ways:
[0405] The 6G RAN node compares the subscription information of the UE and the service / task identity provided by the UE to determine whether the UE is authorized.
[0406] The authorization result returned by the 6G UDM indicates that the UE has been authorized.
[0407] Step S9107, the UE and the RAN perform access network (AN) resource setup.
[0408] In some embodiments, according to the obtained parameters (such as the above-mentioned security policy), the 6G RAN node can interact with the UE through AN specific signaling. For example, the RAN can perform RRC connection reconfiguration with the UE to activate DP security.
[0409] Step S9108, the RAN sends a UE state notification to the 6GC NF.
[0410] In some embodiments, the RAN sends a UE state notification to the 6GC NF.
[0411] In some embodiments, the 6G RAN node can update the UE context maintained by the 6GC, for example, update the UE CM state, the UE RRC state, and the like. This step can be triggered by the change of the UE state or triggered periodically by the service / task.
[0412] At step S9109, the UE sends the first uplink data to the RAN through the data plane, and the RAN sends the first uplink data to the UPF / DPF through the data plane.
[0413] In some embodiments, the UE can send the uplink data through the data plane.
[0414] At step S9110, the UPF / DPF sends the first downlink data to the RAN through the data plane, and the RAN sends the first downlink data to the UE through the data plane.
[0415] In some embodiments, the 6G UPF / 6G DPF or the 6G RAN node can send the downlink data through the data plane.
[0416] FIG. 9C is a schematic diagram of another network architecture according to an embodiment of the present disclosure.
[0417] As shown in FIG. 9C, the network architecture includes NEF, NRF, PCF, UDM, AF, AUSF, AMF, SMF, NWDAF, UE, (R)AN, UPF, DN, DPF, and Data Plane Data Management (DPDM).
[0418] In FIG. 6C, N1, N2, N3, N4, N6, and N9 are interfaces between corresponding network elements; Namf, Nsmf, Nausf, Nudm, Nnef, Npcf, Naf, Nnssf, Nnrf, Nnwadf, and Ndpdm are service interfaces exposed by AMF, SMF, AUSF, UDM, NEF, PCF, AF, NSSF, NRF, NWDAF, and DPDM, respectively.
[0419] In some embodiments, the DPDM is used for storage and management of data plane service data, such as maintaining an authorized UE list of data services.
[0420] FIG. 9D is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0421] The difference between the communication method shown in FIG. 9D and the communication method shown in FIG. 9B is that, in the communication method shown in FIG. 9D, the candidate UE list provided to the 6G RAN is maintained by the 6G Unified Data Management (UDM) / DPDM. In this way, the 6G RAN can determine whether the DP connection can be established without interacting with the UDM.
[0422] As shown in FIG. 9D, the embodiments of the present disclosure relate to a communication method, and the method comprises:
[0423] Step S9201, service information management is performed between the AF / 6GC NF and the 6G UDR / DPDM.
[0424] In some embodiments, the AF / 6GC NF provides a candidate UE list to the 6G UDR / DPDM. The candidate UE list is associated with one or more service identities. For the UE authorized to provide / use data related to the service identity, the UE identity thereof is contained in the candidate terminal list.
[0425] In some embodiments, the AF / 6GC NF can update the candidate UE list stored in the 6G UDR / DPDM periodically or according to the change of the UE subscription.
[0426] Step S9202, DP connection establishment is performed between the RAN, the AF / 6GC NF, the UPF / DPF, and the 6G UDR / DPDM.
[0427] In some embodiments, the AF / 6GC NF triggers the DP connection establishment procedure, and establishes the DP connection between the 6G RAN and the 6G DPF / UPF. In this procedure, the 6G UDR / DPDM is required to provide the relevant candidate UE list to the 6G RAN.
[0428] In some embodiments, the network element providing the candidate UE list and the service flow of the DP connection establishment procedure can be as shown in Table 2.
[0429] In some embodiments, in response to the candidate UE list update, the 6G UDR / DPDM will send a notification message to the 6G RAN to update the stored candidate UE list.
[0430] Step S9203, the DP connection between the RAN and the 6G UDR / DPDM has been established.
[0431] Step S9204, the UE sends a DP connection establishment request to the RAN.
[0432] Step S9205, the RAN determines whether the connection can be established.
[0433] Step S9206, AN resource setting between the UE and the RAN is performed.
[0434] Step S9207, UE state notification is sent between the RAN and the AF / 6GC NF.
[0435] Step S9208, the UE sends first uplink data to the RAN through the data plane, and the RAN sends the first uplink data to the UPF / DPF through the data plane.
[0436] Step S9209, the UPF / DPF sends first downlink data to the RAN through the data plane, and the RAN sends the first downlink data to the UE through the data plane.
[0437] In some embodiments, the 6G RAN node can receive a DP connection establishment request in an access stratum (AS).
[0438] In some embodiments, the 6G RAN node can obtain parameters from the 6GC NF in the process of establishing the DP connection.
[0439] In some embodiments, the 6G RAN node can determine whether the DP connection can be established.
[0440] In some embodiments, the 6G RAN node can interact with the UDM to obtain UE authorization information.
[0441] In some embodiments, the 6G UDR / DPDM can provide parameters to the 6GC RAN node in the process of establishing the DP connection.
[0442] In some embodiments, the 6G UDM can provide terminal subscription information or authorization results to the 6G RAN node.
[0443] In some embodiments, the UE can send a DP connection establishment request through an AS layer.
[0444] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners in other embodiments.
[0445] The embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device including units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another device is proposed, including units or modules for implementing each step performed by a network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0446] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize the functions of any of the above methods or the units or modules of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship between the elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be all implemented in the form of processor calling software, or all implemented in the form of hardware circuit, or part implemented in the form of processor calling software and the remaining part implemented in the form of hardware circuit.
[0447] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0448] FIG. 10A is a schematic diagram of a structure of a RAN according to an embodiment of the present disclosure. As shown in FIG. 10A, the RAN 10100 can include a transceiver module 10101 and a processing module 10102. In some embodiments, the transceiver module 10101 is configured to receive a first request sent by a terminal. In some embodiments, the processing module 10102 is configured to authorize the terminal.
[0449] In some embodiments, the first request includes at least one of a service identifier and a terminal identifier.
[0450] In some embodiments, the processing module is configured to: in response to the terminal identifier and an identifier in a first list having a mapping relationship, the terminal is authorized to pass; and the first list includes candidate terminal identifiers.
[0451] In some embodiments, the transceiver module is configured to: send, to the first network element, a second request for subscription information of the terminal, the second request comprising the terminal identifier; and receive the subscription information sent by the first network element, the subscription information being used to determine whether the terminal is authorized to establish the first data plane connection.
[0452] In some embodiments, the transceiver module is configured to: send, to the first network element, a third request for an authorization result, the third request comprising the terminal identifier and a service identifier; and receive the authorization result sent by the first network element.
[0453] In some embodiments, the processing module is configured to: in response to the terminal being authorized to establish the first data plane connection, establish the first data plane connection; and in response to the terminal not being authorized to establish the first data plane connection, reject establishment of the first data plane connection.
[0454] In some embodiments, the processing module is configured to: in response to the service identifier not belonging to a second list, reject establishment of the first data plane connection; and the second list comprising service identifiers.
[0455] In some embodiments, the transceiver module is configured to: obtain a first list provided by a second network element; and the second network element being one of a network function (NF), an application function (AF), a unified data repository (UDR), and a data plane data management (DPDM).
[0456] In some embodiments, the processing module is configured to: establish a second data plane connection between the RAN and a third network element, and at least one of the following is associated with the second data plane connection: the first list; and a second list.
[0457] In some embodiments, there is an association relationship between the first data plane connection and the second data plane connection.
[0458] In some embodiments, the transceiver module is configured to: send, by the third network element, a terminal state notification for notifying the third network element of an update of a state of the terminal.
[0459] In some embodiments, the transceiver module is configured to at least one of the following: send, to the third network element, the terminal state notification in response to a change in the state of the terminal; send, to the third network element, the terminal state notification in response to successful establishment of the first data plane connection; and periodically send, to the third network element, the terminal state notification.
[0460] FIG. 10B is a structural schematic diagram of a terminal according to an embodiment of the present disclosure. As shown in FIG. 10B, the terminal 10200 can comprise a transceiver module 10201. In some embodiments, the transceiver module 10201 described above is configured to send, to the RAN, a first request.
[0461] In some embodiments, the terminal can further include a processing module.
[0462] In some embodiments, the first request includes at least one of a service identity and a terminal identity.
[0463] FIG. 10C is a structural schematic diagram of a third network element according to an embodiment of the present disclosure. As shown in FIG. 10C, the third network element 10300 can include a processing module 10301. In some embodiments, the processing module 10301 is configured to connect with a second data plane of a RAN.
[0464] In some embodiments, the third network element can further include a transceiver module.
[0465] FIG. 10D is a structural schematic diagram of a fourth network element according to an embodiment of the present disclosure. As shown in FIG. 10D, the fourth network element 10400 can include a transceiver module 10401. In some embodiments, the transceiver module 10401 is configured to receive a terminal state notification sent by the RAN.
[0466] In some embodiments, the fourth network element can further include a processing module.
[0467] In some embodiments, the transceiver module is configured to at least one of: receive the terminal state notification sent by the RAN in response to a terminal state change; receive the terminal state notification sent by the RAN in response to a successful establishment of the first data plane connection; and periodically receive the terminal state notification sent by the RAN.
[0468] FIG. 10E is a structural schematic diagram of a first network element according to an embodiment of the present disclosure. As shown in FIG. 10E, the first network element 10500 can include a transceiver module 10501. In some embodiments, the transceiver module 10501 is configured to send a second request or a third request.
[0469] In some embodiments, the first network element can further include a processing module.
[0470] FIG. 10F is a structural schematic diagram of a second network element according to an embodiment of the present disclosure. As shown in FIG. 10F, the second network element 10600 can include a transceiver module 10601. In some embodiments, the transceiver module 10601 is configured to provide a first list.
[0471] In some embodiments, the second network element can further include a processing module.
[0472] In some embodiments, the first list is provided by a network function (NF) or an application function (AF).
[0473] In some embodiments, the first list is maintained and managed by a unified data repository (UDR) or a data plane data management (DPDM).
[0474] In some embodiments, the processing module can be one module or include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module. Optionally, the processing module can be mutually replaced with the processor.
[0475] FIG. 11A is a structural schematic diagram of a communication device 11100 according to the embodiments of the present disclosure. The communication device 11100 can be a network device (such as an access network device, a core network device, etc.), a terminal (such as a user equipment, etc.), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 11100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.
[0476] As shown in FIG. 11A, the communication device 11100 includes one or more processors 11101. The processor 11101 can be a general-purpose processor or a special-purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 11100 is configured to perform any of the above methods. Optionally, the one or more processors 11101 are configured to invoke instructions to cause the communication device 11100 to perform any of the above methods.
[0477] In some embodiments, the communication device 11100 further includes one or more transceivers 11102. When the communication device 11100 includes the one or more transceivers 11102, the transceiver 11102 performs at least one of the communication steps (such as step S2103, but not limited to this) in the above method, and the processor 11101 performs at least one of the other steps (such as step S2104, but not limited to this). In an optional embodiment, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms of transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be mutually replaced, and the terms of transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be mutually replaced, and the terms of receiver, receiving unit, receiver, receiving circuit, etc. can be mutually replaced.
[0478] In some embodiments, the communication device 11100 also includes one or more memories 11103 for storing data. Optionally, all or a portion of the memory 11103 can also reside in the communication device 11100. In some embodiments, the communication device 11100 can include one or more interface circuits 11104. Optionally, the interface circuit 11104 can be used to receive data from the memory 11103 or from another device or system, or to send data to the memory 11103 or to another device or system. For example, the interface circuit 11104 can receive data in packets, each packet having a header and a payload.
[0479] The communication device 11100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 11100 described in the present disclosure is not limited thereto, and the structure of the communication device 11100 can not be limited by FIG. 11A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include a storage component for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) other devices, etc.
[0480] FIG. 11B is a structural diagram of a chip 11200 according to an embodiment of the present disclosure. For the case where the communication device 11100 is a chip or a chip system, the structural diagram of the chip 11200 shown in FIG. 11B can be referred to, but is not limited thereto.
[0481] The chip 11200 includes one or more processors 11201. The chip 11200 is configured to perform any of the above methods.
[0482] In some embodiments, the chip 11200 further includes one or more interface circuits 11202. Optionally, the terms interface circuit, interface, transceiver pin, etc. can be replaced by each other. In some embodiments, the chip 11200 further includes one or more memories 11203 for storing data. Optionally, all or part of the memory 11203 can be outside the chip 11200. Optionally, the interface circuit 11202 is connected with the memory 11203, the interface circuit 11202 can be used to receive data from the memory 11203 or other devices, the interface circuit 11202 can be used to send data to the memory 11203 or other devices. For example, the interface circuit 11202 can read the data stored in the memory 11203 and send the data to the processor 11201.
[0483] In some embodiments, the interface circuit 11202 performs at least one of the communication steps (for example, step S2103, but not limited to) of sending and / or receiving in the above method. The interface circuit 11202 performing the communication steps such as sending and / or receiving in the above method means that the interface circuit 11202 performs data interaction between the processor 11201, the chip 11200, the memory 11203 or the transceiver device. In some embodiments, the processor 11201 performs at least one of the other steps (for example, step S2104, but not limited to).
[0484] The modules and / or devices described in each embodiment of the virtual device, the physical device, the chip, etc. can be combined or separated as appropriate. Optionally, part or all of the steps can also be performed by multiple modules and / or devices, which are not limited here.
[0485] The disclosure also proposes a storage medium, and the above storage medium stores instructions, when the above instructions run on the communication device 11100, the communication device 11100 executes any of the above methods. Optionally, the above storage medium is an electronic storage medium. Optionally, the above storage medium is a computer readable storage medium, but not limited to this, it can also be a storage medium readable by other devices. Optionally, the above storage medium can be a non-transitory storage medium, but not limited to this, it can also be a transitory storage medium.
[0486] The disclosure also proposes a program product, and the above program product is executed by the communication device 11100, so that the communication device 11100 executes any of the above methods. Optionally, the above program product is a computer program product.
[0487] The disclosure also proposes a computer program, when it runs on a computer, so that the computer executes any of the above methods.
Claims
1. A communication method characterized by comprising: The method comprises: A radio access network device RAN receives a first request sent by a terminal, the first request being used for requesting to establish a first data plane connection; The RAN determines whether to establish the first data plane connection.
2. The method of claim 1, wherein, The first request comprises at least one of a service identity and a terminal identity.
3. The method according to claim 1 or 2, characterized in that, The determination of whether to establish the first data plane connection comprises: In response to the terminal identity and an identity in a first list having a mapping relationship, it is determined to establish the first data plane connection; the first list comprises candidate terminal identities.
4. The method according to claim 1 or 2, characterized in that, The determination of whether to establish the first data plane connection comprises: The RAN sends a second request to a first network element, the second request being used for requesting subscription information of the terminal, the second request comprising the terminal identity; The RAN receives subscription information sent by the first network element, the subscription information being used for determining whether the terminal is authorized to establish the first data plane connection.
5. The method according to claim 1 or 2, characterized in that, The determination of whether to establish the first data plane connection comprises: The RAN sends a third request to a first network element, the third request being used for requesting an authorization result, the third request comprising the terminal identity and a service identity; The RAN receives an authorization result sent by the first network element, the authorization result being used for determining whether the terminal is authorized to establish the first data plane connection.
6. The method according to claim 4 or 5, characterized in that, The method further comprises: In response to the terminal being authorized to establish the first data plane connection, the first data plane connection is established; In response to the terminal not being authorized to establish the first data plane connection, the establishment of the first data plane connection is rejected.
7. The method according to any one of claims 2 to 6, characterized in that, The method further comprises: In response to the service identity not belonging to a second list, the establishment of the first data plane connection is rejected; the second list comprises service identities.
8. The method according to any one of claims 1 to 7, characterized in that, The method further comprises: The RAN acquires a first list provided by a second network element; The second network element is one of a network function NF, an application function AF, a unified data repository UDR, and a data plane data management DPDM.
9. The method according to any one of claims 1 to 8, characterized in that, The method further comprises: The RAN establishes a second data plane connection with a third network element, and at least one of the following is associated with the second data plane connection: The first list; The second list.
10. The method of claim 9, wherein, An association relationship exists between the first data plane connection and the second data plane connection.
11. The method according to any one of claims 1 to 10, characterized in that, The method further comprises: The RAN sends a terminal state notification to a fourth network element, the terminal state notification being used for notifying the fourth network element of state update of the terminal.
12. The method of claim 11, wherein, The RAN sending the terminal state notification to the fourth network element comprises at least one of the following: In response to terminal state change, the RAN sends the terminal state notification to the fourth network element; In response to the first data plane connection being successfully established, the RAN sends the terminal state notification to the fourth network element; The RAN periodically sends the terminal state notification to the fourth network element.
13. A method of communication, comprising: The method comprises: A terminal sends a first request to a radio access network device RAN, the first request being used for requesting to establish a first data plane connection.
14. The method of claim 13, wherein, The first request comprises at least one of a service identity and a terminal identity.
15. A method of communication, comprising: The method comprises: A third network element establishes a second data plane connection with a radio access network device RAN, the second data plane connection and a first data plane There is an association relationship between the connections; At least one of the following is associated with the second data plane connection: A first list; A second list.
16. A method of communication, comprising: The method comprises: The fourth network element receives a terminal state notification sent by a radio access network device RAN, and the terminal state notification is used to notify the fourth network element of a state update of a terminal.
17. The method of claim 16, wherein, The fourth network element receives a terminal state notification sent by the RAN, including at least one of the following: In response to a terminal state change, the fourth network element receives a terminal state notification sent by the RAN; In response to successful establishment of a first data plane connection, the fourth network element receives a terminal state notification sent by the RAN; The fourth network element periodically receives a terminal state notification sent by the RAN.
18. A method of communication, comprising: The method comprises: The first network element receives a second request or a third request sent by a radio access network device RAN, the second request is used to request subscription information of a terminal, and the second request includes a terminal identifier; the third request is used to request an authorization result, and the third request includes a terminal identifier and a service identifier; The first network element sends subscription information or an authorization result to the RAN, and the subscription information is used to determine whether the terminal is authorized to establish a first data plane connection.
19. A method of communication, comprising: The method comprises: The second network element provides a first list to a radio access network device RAN, and the first list includes candidate terminal identifiers; the first list is associated with a second data plane connection, and there is an association relationship between the second data plane connection and a first data plane connection.
20. The method of claim 19, wherein, The first list is provided by a network function NF or an application function AF.
21. The method of claim 19, wherein, The first list is maintained and managed by a unified data repository UDR or a data plane data management DPDM.
22. A radio access network device (RAN), the RAN comprising: Comprise: The transceiver module is used for receiving a first request sent by a terminal, and the first request is used to request establishment of a first data plane connection; The processing module is used for determining whether to establish the first data plane connection.
23. A terminal, characterized by Comprise: The transceiver module is used for sending a first request to a radio access network device RAN, and the first request is used to request establishment of a first data plane connection.
24. A third network element, characterized by Comprise: The processing module is used for a second data plane connection between a radio access network device RAN, and there is an association relationship between the second data plane connection and a first data plane connection; at least one of the following is associated with the second data plane connection: a first list; a second list.
25. A fourth network element, characterized by Comprise: The transceiver module is used for receiving a terminal state notification sent by a radio access network device RAN, and the terminal state notification is used to notify the fourth network element of a state update of a terminal.
26. A first network element, characterized by, Comprise: The transceiver module is used for receiving a second request or a third request sent by a radio access network device RAN, and the second request is used to request subscription information of a terminal, and the second request includes a terminal identifier; The third request is used to request an authorization result, and the third request includes a terminal identifier and a service identifier; Send subscription information or an authorization result to the RAN, and the subscription information is used to determine whether the terminal is authorized to establish a first data plane connection.
27. A second network element, characterized by, Comprise: The transceiver module is used for providing a first list to a radio access network device RAN, and the first list includes candidate terminal identifiers; The first list is associated with a second data plane connection, and there is an association relationship between the second data plane connection and the first data plane connection.
28. A radio access network device (RAN) comprising: Comprising: One or more processors; The RAN is configured to implement the method of any one of claims 1-12.
29. A terminal, characterized by Comprising: One or more processors; The terminal is configured to implement the method of any one of claims 13-14.
30. A third network element, characterized by Comprising: One or more processors; The third network element is configured to implement the method of claim 15.
31. A fourth network element, characterized by Comprising: One or more processors; The fourth network element is configured to implement the method of any one of claims 16-17.
32. A first network element, characterized by, Comprising: One or more processors; The first network element is configured to implement the method of claim 18.
33. A second network element, characterized by, Comprising: One or more processors; The second network element is configured to implement the method of any one of claims 19-21.
34. A communication system, characterized by The RAN, the terminal, the first network element, the second network element, the third network element, and the fourth network element are at least one of the following: the RAN is configured to implement the method of any one of claims 1-12, the terminal is configured to implement the method of any one of claims 13-14, the third network element is configured to implement the method of claim 15, the fourth network element is configured to implement the method of any one of claims 16-17, the first network element is configured to implement the method of claim 18, and the second network element is configured to implement the method of any one of claims 19-21.
35. A storage medium, the storage medium storing instructions, wherein, When the instructions are run on a communication device, the communication device is caused to perform the method of any one of claims 1-21.
36. A program product, characterized by Comprising: A computer program, which, when executed by a communication device, causes the communication device to perform the method of any one of claims 1-21.