Access control method and device
By obtaining the access level and identifier of non-3GPP devices, differentiated access control is implemented, which solves the problem that terminal devices cannot provide differentiated services for non-3GPP devices, improves access efficiency, and saves power consumption and resources.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-11-21
- Publication Date
- 2026-05-22
AI Technical Summary
In existing technologies, terminal devices cannot provide differentiated access services for non-3GPP devices, resulting in the inability to distinguish access control based on device type, leading to resource waste and increased power consumption.
By acquiring the access class and identifier of non-3GPP devices, differentiated access control can be implemented, including creating QoS flows and user plane resources, and optimizing the access inspection process to reduce unnecessary judgments.
It enables differentiated access services for non-3GPP devices, improves access efficiency, reduces unnecessary access checks, and saves power consumption and resources.
Smart Images

Figure CN122073716A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of mobile communications, and more particularly to an access control method and apparatus. Background Technology
[0002] Currently, before a terminal device can access a 3GPP network, it must perform a unified access barring (UAC) check based on its access category (AC) and access identity (AI). Only if the UAC check result indicates that access is permitted can the terminal device access the 3GPP network.
[0003] With the continuous development of communication networks, more and more non-3GPP devices are being mounted on terminal devices, which then connect to the 3GPP network. Data traffic generated by non-3GPP devices can be transmitted through the terminal devices' sessions.
[0004] When non-3GPP devices generate data traffic, it may trigger the terminal device to perform a UAC check. In this case, the terminal device can only perform the UAC check based on its own AI and AC, resulting in the inability to provide differentiated access services for non-3GPP devices. Summary of the Invention
[0005] This application provides an access control method and apparatus that can provide differentiated access services for non-3GPP equipment.
[0006] Firstly, an access control method is provided. This method can be executed by a first device, or by a chip or module within the first device. The first device can be a 3GPP device. Taking the method executed by the first device as an example: the first device obtains the access level of a second device; the first device determines whether to allow the second device to access the network based on the access level. The second device can be a 3GPP device or a non-3GPP device mounted under the first device, without restriction.
[0007] In this embodiment, the second device connected to the first device has a separate access level. Therefore, the first device can determine whether to allow the second device to access the network based on the access level of the second device, thereby providing the second device with a differentiated access service from the first device. This achieves the technical effect of providing differentiated access services for non-3GPP devices.
[0008] In one possible design, the first device receives a first message, which includes the access level of the second device.
[0009] Obtaining the access level of the second device based on the first message is simple and reliable.
[0010] In one possible design, the first message also includes the identifier of the second device.
[0011] Thus, the access level in the first message can be clearly identified as the access level of the second device based on the identifier of the second device in the first message.
[0012] In one possible design, the identifier of the second device includes the device identifier of the second device, such as the medium access control (MAC) address of the second device; or, the identifier of the second device includes the subscription permanent identity (SUPI) of the second device.
[0013] Of course, the above two are just examples, and the actual situation is not limited to these.
[0014] In one possible design, before the first device determines whether to allow the second device to access the network based on the access level, the first device performs an access check on the access attempt triggered by the second device.
[0015] In this design, the first device determines whether to allow the second device to access the network based on the access level only after the second device triggers an access attempt. On the one hand, it can provide access check services to the second device in a timely manner when the second device has data transmission needs. On the other hand, it can avoid the problem of power waste caused by frequently determining whether to allow the second device to access the network.
[0016] In one possible design, if the first device determines, based on the access level, that the second device is allowed to access the network, then: the first device sends a session modification request message, which includes a session identifier and the identifier of the second device. The session modification request message is used to request the creation of a quality of service (QoS) flow for the second device in the session indicated by the session identifier. The QoS flow is used to transmit data sent by the second device to the network and / or data sent by the network to the second device.
[0017] In this design, after determining that the second device is allowed to access the network, a QoS flow is created for the second device so that subsequent data sent from the second device to the network and / or data sent from the network to the second device can be transmitted based on the QoS flow, thereby improving the reliability of the solution.
[0018] In one possible design, if the first device determines, based on the access level, that the second device is allowed to access the network, then: the first device sends a session establishment request message, which includes the identifier of the second device, and the session establishment request message is used to request the creation of a session for the second device.
[0019] In this design, after the second device is allowed to access the network, a session is created for the second device so that data sent from the second device to the network and / or data sent from the network to the second device can be transmitted based on the session.
[0020] In one possible design, if the first device determines, based on the access level, that the second device is allowed to access the network, then: the first device sends a non-access stratum (NAS) message, which includes a session identifier and is used to indicate the user plane resources of the session indicated by the session identifier.
[0021] In this design, after the second device is allowed to access the network, user plane resources are activated for the second device so that data sent from the second device to the network and / or data sent from the network to the second device can be transmitted based on these user plane resources.
[0022] In one possible design, the NAS message is used to indicate that only the QoS flow of the second device in the session is activated. The NAS message includes the QoS flow identifier (QFI) of the second device's QoS flow.
[0023] In this design, QoS flows of only the second device are activated, which can save air interface resources.
[0024] In one possible design, before the first device receives the first message, the first device also sends a second message, which includes the identifier of the second device. The first message is a response message to the second message. For example, the first message can be any one of a registration acceptance message, a session establishment acceptance message, or a session modification command message.
[0025] In this design, the network issues access level to the second device based on the request of the first device, realizing on-demand issuance and balancing the utilization rate and issuance efficiency of access level.
[0026] Secondly, an access control method is provided. This method can be executed by a first network element, or by a chip or module within the first network element. The first network element is, for example, an access and mobility management function (AMF) network element, a session management function (SMF) network element, etc. Taking the method being executed by the first network element as an example: the first network element obtains the access level of the second device; the first network element sends a first message to the first device, the first message including the access level of the second device.
[0027] In one possible design, the first message also includes the identifier of the second device.
[0028] In one possible design, the identifier of the second device includes the device identifier of the second device; or, the identifier of the second device includes the SUPI of the second device.
[0029] In one possible design, the first network element also receives a session modification request message from the first device. The session modification request message includes a session identifier and an identifier of the second device. The session modification request message is used to request the creation of a QoS flow for the second device in the session indicated by the session identifier. The QoS flow is used to transmit data sent by the second device to the network and / or data sent by the network to the second device. The first network element creates a QoS flow for the second device in the session according to the session modification request message.
[0030] In one possible design, the first network element also receives a session establishment request message from the first device. The session establishment request message includes the identifier of the second device and is used to request the creation of a session for the second device. The first network element creates a session for the second device based on the session establishment request message.
[0031] In one possible design, the first network element also receives a NAS message from the first device. The NAS message includes a session identifier and is used to indicate the user plane resources of the session indicated by the session identifier. The first network element activates the user plane resources of the session according to the NAS message.
[0032] In one possible design, the NAS message is used to instruct that only the QoS flow of the second device in the session be activated. The NAS message includes the QFI of the QoS flow of the second device. Accordingly, the first network element activates only the QoS flow of the second device in the session based on the NAS message.
[0033] In one possible design, before the first network element sends the first message to the first device, the first network element also receives a second message from the first device. The second message includes the identifier of the second device, and the first message is a response message to the second message.
[0034] In one possible design, the first message is one of the following: registration acceptance message, session establishment acceptance message, or session modification command message.
[0035] In one possible design, the first network element obtains the access level of the second device from the second network element.
[0036] In one possible design, the first network element can send a third message to the second network element based on the second message. The third message includes the identifier of the second device and is used to request the access level of the second device. The first network element receives a fourth message from the second network element, which includes the access level of the second device.
[0037] Thirdly, an access control method is provided. This method can be executed by a second network element, or by a chip or module within the second network element. The second network element can be, for example, a unified data management (UDM) network element or a unified data repository (UDR) network element. Taking the method executed by the second network element as an example: the second network element obtains the access level of the second device; the second network element sends a fourth message to the first network element, the fourth message including the access level of the second device.
[0038] In one possible design, the fourth message also includes the identifier of the second device.
[0039] In one possible design, the identifier of the second device includes the device identifier of the second device; or, the identifier of the second device includes the SUPI of the second device.
[0040] In one possible design, the second network element receives a third message from the first network element, the third message including the identifier of the second device. The third message is used to request the access level of the second device. The second network element then sends a fourth message to the first network element, which includes: the second network element sending the fourth message to the first network element based on the third message.
[0041] Fourthly, a communication device is provided, the device comprising modules, units, or technical means for implementing the method described in the first aspect or any possible design of the first aspect.
[0042] For example, the device includes:
[0043] The transceiver module is used to obtain the access level of the second device;
[0044] The processing module is used to determine whether to allow a second device to access the network based on the access level.
[0045] In one possible design, the transceiver module is used to receive a first message, which includes the second device access level.
[0046] In one possible design, the first message also includes the identifier of the second device.
[0047] In one possible design, the identifier of the second device includes the device identifier of the second device, such as the MAC address of the second device; or, the identifier of the second device includes the SUPI of the second device. Of course, the above two are just examples, and the actual design is not limited to these.
[0048] In one possible design, the processing module is also used to perform an access check on the access attempt triggered by the second device before determining whether the second device is allowed to access the network based on the access level.
[0049] In one possible design, if the processing module determines that the second device is allowed to access the network based on the access level, the transceiver module is further configured to: send a session modification request message, which includes a session identifier and an identifier of the second device. The session modification request message is used to request the creation of a QoS flow for the second device in the session indicated by the session identifier. The QoS flow is used to transmit data sent by the second device to the network and / or data sent by the network to the second device.
[0050] In one possible design, if the processing module determines, based on the access level, that the second device is allowed to access the network, the transceiver module is further configured to: send a session establishment request message, which includes the identifier of the second device, and the session establishment request message is used to request the creation of a session for the second device.
[0051] In one possible design, if the processing module determines, based on the access level, that the second device is allowed to access the network, the transceiver module is further configured to: send a NAS message, the NAS message including a session identifier, the NAS message being used to indicate the user plane resources of the session indicated by the session identifier.
[0052] In one possible design, the NAS message is used to indicate that only the QoS flow of the second device in the session is activated, and the NAS message includes the QFI of the QoS flow of the second device.
[0053] In one possible design, the transceiver module is further configured to: send a second message before receiving the first message, the second message including the identifier of the second device, and the first message being a response message to the second message. For example, the first message could be any one of a registration acceptance message, a session establishment acceptance message, or a session modification command message.
[0054] Fifthly, a communication device is provided, the device comprising modules, units, or technical means for implementing the method described in the second aspect or any possible design of the second aspect.
[0055] For example, the device includes:
[0056] The transceiver module is used to obtain the access level of the second device and send a first message to the first device, the first message including the access level of the second device.
[0057] In one possible design, the first message also includes the identifier of the second device.
[0058] In one possible design, the identifier of the second device includes the device identifier of the second device; or, the identifier of the second device includes the SUPI of the second device.
[0059] In one possible design, the transceiver module is further configured to: receive a session modification request message from a first device, the session modification request message including a session identifier and an identifier of a second device, the session modification request message being used to request the creation of a QoS flow for the second device in the session indicated by the session identifier, the QoS flow being used to transmit data sent by the second device to the network and / or data sent by the network to the second device; the processing module is further configured to: create a QoS flow for the second device in the session according to the session modification request message.
[0060] In one possible design, the transceiver module is further configured to: receive a session establishment request message from a first device, the session establishment request message including the identifier of a second device, the session establishment request message being used to request the creation of a session for the second device; the processing module is further configured to: create a session for the second device based on the session establishment request message.
[0061] In one possible design, the transceiver module is further configured to: receive a NAS message from a first device, the NAS message including a session identifier, the NAS message being used to indicate the user plane resources of the session indicated by the session identifier; the processing module is further configured to: activate the user plane resources of the session according to the NAS message.
[0062] In one possible design, the NAS message is used to instruct that only the QoS flow of the second device in the session be activated, and the NAS message includes the QFI of the QoS flow of the second device. Accordingly, the processing module is also used to: activate only the QoS flow of the second device in the session according to the NAS message.
[0063] In one possible design, the transceiver module is further configured to: receive a second message from the first device before sending the first message to the first device, the second message including the identifier of the second device, and the first message being a response message to the second message.
[0064] In one possible design, the first message is one of the following: registration acceptance message, session establishment acceptance message, or session modification command message.
[0065] In one possible design, the processing module is further configured to: control the transceiver module to send a third message to the second network element according to the second message, the third message including the identifier of the second device, the third message being used to request the access level of the second device; the transceiver module is further configured to: receive a fourth message from the second network element, the fourth message including the access level of the second device.
[0066] In a sixth aspect, a communication device is provided, the device comprising modules, units, or technical means for implementing the method described in the third aspect or any possible design of the third aspect.
[0067] For example, the device includes:
[0068] The transceiver module is used to obtain the access level of the second device and send a fourth message to the first network element, the fourth message including the access level of the second device.
[0069] In one possible design, the fourth message also includes the identifier of the second device.
[0070] In one possible design, the identifier of the second device includes the device identifier of the second device; or, the identifier of the second device includes the SUPI of the second device.
[0071] In one possible design, the transceiver module is further configured to receive a third message from the first network element, the third message including the identifier of the second device. The third message is used to request the access level of the second device. When the transceiver module sends a fourth message to the first network element, it is specifically configured to send the fourth message to the first network element based on the third message.
[0072] A seventh aspect provides a communication device, including at least one processor; and a communication interface communicatively connected to the at least one processor; wherein the at least one processor executes instructions stored in a memory to cause the method described in the first aspect or any possible design of the first aspect to be executed, or to cause the method described in the second aspect or any possible design of the second aspect to be executed, or to cause the method described in the third aspect or any possible design of the third aspect to be executed.
[0073] Eighthly, a computer-readable storage medium is provided, the storage medium storing a computer program or instructions that, when executed by a communication device, implement the method as described in the first aspect or any possible design of the first aspect, or implement the method as described in the second aspect or any possible design of the second aspect, or implement the method as described in the third aspect or any possible design of the third aspect.
[0074] Ninth aspect, a computer program product is provided, the computer program product storing instructions that, when run on a computer, cause the computer to perform the method as described in the first aspect or any possible design of the first aspect, or cause the computer to perform the method as described in the second aspect or any possible design of the second aspect, or cause the computer to perform the method as described in the third aspect or any possible design of the third aspect.
[0075] Tenthly, a communication system is provided, comprising:
[0076] A first device for performing the method as described in the first aspect or any possible design of the first aspect;
[0077] The first network element is used to perform the method described in the second aspect or any possible design of the second aspect;
[0078] The second network element is used to perform the methods described in the third aspect or any possible design of the third aspect.
[0079] The technical effects of the second to tenth aspects mentioned above are described in the first aspect and will not be repeated here. Attached Figure Description
[0080] Figure 1 A flowchart illustrating the UAC (User Acquisition Control) process;
[0081] Figure 2 This is a schematic diagram of a non-3GPP device being mounted onto a 3GPP device.
[0082] Figure 3 This is a network architecture diagram of a communication system applicable to embodiments of this application;
[0083] Figure 4 This is a schematic diagram of the communication chip in a terminal device.
[0084] Figure 5 This is a network architecture diagram of another communication system to which the embodiments of this application are applicable;
[0085] Figure 6 A flowchart illustrating an access control method provided in an embodiment of this application;
[0086] Figure 7 A flowchart illustrating the process of obtaining the access level of the second device for the first device;
[0087] Figure 8 A flowchart illustrating another access control method provided in this application embodiment;
[0088] Figure 9 A flowchart illustrating another access control method provided in this application embodiment;
[0089] Figure 10 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0090] Figure 11 This is a schematic diagram of another communication device provided in an embodiment of this application;
[0091] Figure 12 This is a schematic diagram of the structure of a chip provided in an embodiment of this application. Detailed Implementation
[0092] The following explanations of some terms used in the embodiments of this application are provided to facilitate understanding by those skilled in the art. It should be noted that these explanations are intended to make the embodiments of this application easier to understand and should not be construed as limiting the scope of protection claimed in this application.
[0093] 1. Non-access stratum (NAS) layer and access stratum (AS) layer:
[0094] The protocol layers for communication between terminal devices and network devices can be divided into multiple layers from top to bottom, such as the application layer, radio resource control (RRC) layer, service data adaptation protocol (SDAP) layer, packet data convergence protocol (PDCP) layer, radio link control (RLC) layer, and medium access control (MAC) layer. The application layer primarily provides various services to application software, such as file servers, database services, email, and other network software services. The RRC layer's functions include establishing, maintaining, and releasing RRC connections, and allocating or reconfiguring radio resources for RRC connections. One function of the SDAP layer is to map Quality of Service (QoS) streams to data radio bearers (DRBs). The PDCP layer is responsible for compressing and decompressing IP headers, maintaining PDCP sequence numbers, and performing encryption and decryption. The RLC layer primarily provides radio link control functions, offering services such as segmentation, retransmission control, and on-demand transmission to upper layers. The MAC layer's functions include mapping between logical channels and transport channels, and selecting appropriate transmission formats for each transport channel. It should be noted that the network layer division for terminal devices and network devices in this embodiment is not limited; the above is merely an example and not a limitation.
[0095] For terminal equipment, the functional layer between it and access network equipment (such as next-generation NodeB (gNB)) is called the AS layer. For example, the RRC layer and the protocol layer below it can be called the AS layer. The functional layer between it and core network equipment (such as access and mobility management function (AMF) network elements) is called the NAS layer.
[0096] 2. Unified Access Barring (UAC) Mechanism:
[0097] Before transmitting NAS messages, the terminal device needs to request an RRC connection with the access network device. The NAS layer of the terminal device needs to provide information related to the RRC connection establishment to the lower layer. The access network device processes connections according to priority during or after the RRC connection establishment process. Under heavy network load, the network can use the User-Agent Control (UAC) mechanism to prevent some terminal devices from initiating access, thereby limiting network load. Depending on the network configuration, the network may decide whether to allow or block specific access attempts based on classification criteria. Therefore, when a terminal device needs to access the network, a UAC check needs to be performed on the access attempt (e.g., NAS signaling).
[0098] like Figure 1 As shown, the UAC check process includes: 1. The NAS layer of the terminal device generates NAS signaling and maps the NAS signaling to the access category (AC) of the terminal device; 2. The NAS layer of the terminal device sends the AI and AC of the terminal device together to the access stratum (AS) layer of the terminal device; 3. The AS layer of the terminal device determines whether the terminal device is allowed to access the network based on the AI and AC provided by the NAS layer and the UAC parameter set broadcast by the access network device (such as the allowed access AI and AC broadcast by the base station).
[0099] An example of the AS layer inspection method is as follows:
[0100] 1) If the AC provided by the NAS layer is indicated by the access network device to allow access, then NAS signaling can be sent;
[0101] 2) If the AC provided by the NAS layer is not allowed to access by the access network device, check whether the AI provided by the NAS layer is allowed to access by the access network device. If it is allowed to access, the NAS signaling can be sent.
[0102] 3) Other situations: Generate a random value, and determine whether access is ultimately allowed based on the random value.
[0103] In summary, terminal devices need to incorporate AI to determine their network access eligibility. High-priority users (such as MPS and MCS) may be able to access the network even under network congestion conditions, regardless of their service activity. Table 1 provides examples of AI types.
[0104] Table 1
[0105]
[0106] It should be understood that Table 1 is for illustrative purposes only and not as a limitation.
[0107] 3. 3rd Generation Partnership Project (3GPP) equipment and non-3GPP equipment:
[0108] 3GPP equipment refers to equipment with 3GPP communication capabilities, while non-3GPP equipment refers to equipment without 3GPP communication capabilities. 3GPP communication capability refers to the ability to communicate directly with 3GPP networks (such as 5G networks or future communication networks). For example, the terminal device in this article can establish an air interface connection and communicate with access network equipment in a 3GPP network.
[0109] 4. In the embodiments of this application, "transmission" includes "sending" and / or "receiving". "Sending" and "receiving" indicate the direction of signal transmission. For example, "sending information to XX" can be understood as the destination of the information being XX, which can include direct transmission via the air interface or indirect transmission by other units or modules via the air interface. "Receiving information from YY" can be understood as the source of the information being YY, which can include direct reception from YY via the air interface or indirect reception from YY by other units or modules via the air interface. "Sending" can also be understood as the "output" of the chip interface, and "receiving" can also be understood as the "input" of the chip interface. In other words, sending and receiving can occur between devices, such as between access network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.
[0110] In this application embodiment, the number of nouns, unless otherwise specified, refers to "singular nouns or plural nouns," that is, "one or more." "At least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A / B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. For example, A / B means: A or B. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and / or c means the following combinations: a exists alone, b exists alone, c exists alone, a and b exist simultaneously, a and c exist simultaneously, b and c exist simultaneously, or a, b, and c exist simultaneously, where a, b, and c can be single or multiple.
[0111] In the embodiments of this application, "when," "if," and "if" all refer to the device taking corresponding actions under certain objective circumstances, and are not time-limited, nor do they require the device to perform a judgment action, nor do they imply any other limitations. Unless otherwise specified, "if" and "if" can be substituted, and "when" and "in the case of" can be substituted. "When" and "if" / "if" can be substituted.
[0112] In this application, the ordinal numbers such as "first" and "second" are used to distinguish multiple objects, and are not used to limit the size, content, order, timing, priority, or importance of the multiple objects. For example, "first identifier" and "second identifier" refer to two different identifiers, and do not indicate a difference in priority or importance between the two identifiers.
[0113] In the embodiments of this application, the solutions in each embodiment can be used in a reasonable combination, and the explanations or descriptions of various terms, similar operations, or steps appearing in the embodiments can be referenced or explained to each other in the embodiments, without limitation.
[0114] The technical solutions of the embodiments of this application are described in detail below with reference to the accompanying drawings.
[0115] With the continuous development of communication networks, more and more non-3GPP devices are being integrated with 3GPP devices, such as terminal devices, to connect to the 3GPP network and enjoy 3GPP network services. Figure 2 As shown.
[0116] Non-3GPP devices lack 3GPP communication capabilities but can possess short-range communication capabilities such as Wi-Fi, Bluetooth, Near Field Communication (NFC), and Ultra Wide Bandwidth (UWB), enabling them to connect to terminal devices. Data traffic generated by non-3GPP devices is transmitted through sessions established by the terminal device (such as Protocol Data Unit (PDU) sessions). When such devices generate data traffic, it may trigger the terminal device to generate NAS signaling (e.g., service request messages, registration request messages, PDU session establishment / modification request messages, etc.), causing the terminal device's NAS layer to provide AI and AC to the AS layer for UAC checks.
[0117] However, the network only configures AI for 3GPP devices, which means that terminal devices can only map these NAS signaling to their own AI, and cannot distinguish whether the access is initiated for 3GPP devices or non-3GPP devices, thus failing to provide differentiated access services for non-3GPP devices.
[0118] Therefore, the technical solution provided in this application embodiment can achieve more granular control over device access to the network and can provide differentiated access services for non-3GPP devices.
[0119] The technical solutions of the embodiments of this application can be applied to various communication systems, such as: 5th Generation (5G) communication systems, future communication systems, or other wireless communication systems that adopt wireless access technologies, etc., and the technical solutions of the embodiments of this application can be adopted.
[0120] See Figure 3 The diagram illustrates a network architecture of a communication system applicable to embodiments of this application, which is a 5G network architecture based on a service-oriented architecture. Figure 1 The document illustrates the interaction relationships between network functions and entities, as well as their corresponding interfaces. For example, terminal devices (such as user equipment (UE)) and the AMF can interact through the N1 interface, and the interaction messages are called N1 messages. Figure 1Some interfaces in the system are implemented using service-oriented interfaces. The network functions and entities included in the system mainly include: terminal equipment, radio access network (RAN) network elements, user plane function (UPF) network elements, data network (DN), access and mobility management function (AMF) network elements, session management function (SMF) network elements, policy control function (PCF) network elements, application function (AF) network elements, unified data management (UDM) network elements, network exposure function (NEF) network elements, network repository function (NRF) network elements, unified data repository (UDR) network elements, etc.
[0121] 1. Terminal Equipment: Any device capable of data communication with RAN equipment can be considered a terminal equipment. Terminal equipment is also called a terminal, terminal device, UE, user device, mobile station, or mobile terminal, etc. Terminal equipment can be widely used in various scenarios. For example, terminal equipment can be: mobile phones, computers, mobile internet devices (MID), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, stations (STA), robotic arms, cameras, robots, vehicles, drones, helicopters, airplanes, ships, or smart home devices (such as televisions, air conditioners, robot vacuums, speakers, set-top boxes), relays, customer premises equipment (CPE), etc.
[0122] Furthermore, in this embodiment, the terminal device can also be a terminal device in an IoT system, such as a water meter or electricity meter. IoT is an important component of future information technology development. Its main technical characteristic is connecting objects to networks through communication technology, thereby realizing an intelligent network that enables human-machine interconnection and object-to-object interconnection.
[0123] When the terminal device is applied to V2X, it can also be called a V2X device, such as a smart car, an unmanned car, a driverless car, a pilotless car, or an automobile, or a roadside unit (RSU). All the terminal devices described above, if located on a vehicle (e.g., placed / installed inside the vehicle), can be considered in-vehicle terminal devices. In-vehicle terminal devices can be built into a vehicle's on-board module, on-board unit, on-board component, on-board chip, or on-board unit as one or more components or units. The vehicle can implement the methods of this application through the built-in on-board module, on-board unit, on-board component, on-board chip, or on-board unit. In-vehicle terminal devices can be vehicle equipment, on-board modules, vehicles, on-board units (OBU), RSUs, in-vehicle infotainment systems (or on-board transmitting units) (telematics boxes, T-boxes), chips, or SoCs, etc., and the aforementioned chips or SoCs can be installed in the vehicle, OBU, RSU, or T-box.
[0124] Terminal devices can establish connections with the operator's network through interfaces provided by the operator's network (such as N1), and use data and / or voice services provided by the operator's network. Terminal devices can also access the DN (Network Provider) through the operator's network, and use operator services deployed on the DN, and / or services provided by third parties. These third parties can be service providers outside of the operator's network and terminal devices, and can provide other data and / or voice services to the terminal devices. The specific form of these third parties can be determined based on the actual application scenario and is not limited here.
[0125] See Figure 4 This is a schematic diagram of the communication chip structure of a terminal device, mainly composed of a baseband subsystem, a radio frequency subsystem, a power management subsystem, and peripherals (such as storage and external interfaces). The functions of each part are as follows:
[0126] Baseband subsystem: responsible for application layer processing, external interfaces, and L3 / L2 / L1 communication protocol processing;
[0127] Radio frequency (RF) subsystem: The RF front-end and antenna realize the conversion of spatial electromagnetic waves into electrical signals, as well as the required amplification, filtering and other functions to achieve excellent coverage; it connects with the baseband to complete the frequency conversion and nonlinear distortion correction of analog signals;
[0128] Power Management Subsystem: Provides power management functions for communication baseband chips.
[0129] 2. (R)AN Network Element: Also known as access network equipment, radio access network equipment, access network, etc. Specific implementations can include base stations, evolved NodeBs (eNodeBs), Transmission Reception Points (TRPs), next-generation NodeBs (gNBs) in fifth-generation mobile communication systems, base stations in future mobile communication systems, or access nodes in WiFi systems; it can also be a module or unit that performs some of the functions of a base station, for example, a Central Unit (CU) or a Distributed Unit (DU). Here, the CU performs the functions of the radio resource control protocol and the Packet Data Convergence Protocol (PDCP) of the base station, and can also perform the functions of the Service Data Adaptation Protocol (SDAP); the DU performs the functions of the radio link control layer and the medium access control (MAC) layer of the base station, and can also perform some or all of the physical layer functions. For specific descriptions of the above protocol layers, please refer to the relevant 3GPP technical specifications. Wireless access network equipment can be macro base stations, micro base stations, indoor stations, relay nodes, or donor nodes, etc. The embodiments of this application do not limit the specific technologies or equipment forms used in the wireless access network equipment.
[0130] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an ORAN system, CU can also be called O-CU (open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples.
[0131] The CU and DU can be configured according to the protocol layer functions of the wireless network they implement: for example, the CU can be configured to implement the functions of the Packet Data Convergence Protocol (PDCP) layer and above (such as the Radio Resource Control (RRC) layer and / or the Service Data Adaptation Protocol (SDAP) layer); the DU can be configured to implement the functions of the protocol layers below the PDCP layer (such as the Radio Link Control (RLC) layer, the Media Access Control (MAC) layer, and / or the Physical (PHY) layer). For specific descriptions of the above protocol layers, please refer to the relevant 3GPP technical specifications or the technical specifications of other applicable communication protocols.
[0132] The above division of the processing functions of CU and DU according to protocol layers is merely an example; other division methods are also possible, and this application does not limit this. For example, in one design, CU or DU can be further divided into processing functions with protocol layers. In one design, some functions of the RLC layer and the functions of the protocol layer above the RLC layer are located in the CU, while the remaining functions of the RLC layer and the functions of the protocol layer below the RLC layer are located in the DU.
[0133] In another possible design, the DU and RU collaborate to implement the PHY layer functionality, or, more specifically, a portion of the PHY layer functionality of the DU can be moved to the RU. A DU can be connected to one or more RUs. The functions of the DU and RU can be configured in various ways depending on the design. For example, the DU may be configured to implement baseband functions, and the RU may be configured to implement mid-RF functions. Alternatively, the DU may be configured to implement higher-level functions in the PHY layer, and the RU may be configured to implement lower-level functions in the PHY layer, or both lower-level and RF functions. Higher-level functions in the physical layer may include a portion of the physical layer's functionality closer to the MAC layer, and lower-level functions may include another portion of the physical layer's functionality closer to the mid-RF side. This application does not limit the specific functions of the DU and RU. The interface between the DU and RU can be called a fronthaul interface. In one design, the CU may not have a PDCP layer; for example, the CU may only include an RRC layer. The CU-CP may not have PDCP-C. The CU-UP may not have PDCP-U, or may not have a CU-UP. In one design, the DU may not have an RLC layer; for example, the DU may only have a MAC and a higher PHY layer.
[0134] When the RAN is O-RAN, it can also have artificial intelligence (AI) capabilities. For example, O-RAN includes an intelligent controller. The intelligent controller can be a non-real-time RAN intelligent controller (RIC / non-RT RIC / NRTRIC) or a near-real-time RAN intelligent controller (RIC / nRT RIC / nRT RIC). A non-real-time RIC can be used to implement non-real-time intelligent management of RAN functions, enabling workflows including model training and updates, and guiding applications / functions in the nRT RIC based on policies. A near-real-time RIC can be used to implement near-real-time intelligent management of the RAN. Through data collection and related operations on the E2 interface, near-real-time control and optimization of O-RAN modules and resources are achieved.
[0135] 3. SMF network element: Primarily used for session management, IP address allocation and management of terminal equipment, selection of manageable user equipment plane functions, policy control, or terminal points for charging function interfaces, and downlink data notification, etc. It is understood that in future communication systems, the network element responsible for the above functions may still be an SMF network element, or may have other names; this application does not impose any limitations.
[0136] 4. AMF Network Element: Primarily used for mobility management and access management, such as the Mobility Management Entity (MME) function in a 4G communication network or the AMF network element in a 5G network. It is understood that in future communication systems, the network element responsible for the above functions may still be an AMF network element, or have other names; this application does not impose any limitations.
[0137] 5. PCF Network Element: A unified policy framework used to guide network behavior, providing policy rule information to control plane functional network elements (such as AMF, SMF, etc.). It is understood that in future communication systems, the network element responsible for providing policy rule information may still be a PCF network element, or may have other names; this application does not limit this.
[0138] 6. UDM network element: Used to handle user identification, subscription, access authentication, registration, or mobility management, etc. It is understood that in future communication systems, the network element responsible for the above functions may still be a UDM network element, or may have other names; this application does not limit this.
[0139] 7. AF (Active Front-End) Network Element: Used for data routing affected by applications, accessing network open functions, or interacting with the policy framework for policy control, etc. It is understood that in future communication systems, the network element responsible for the above functions may still be an AF network element, or may have other names; this application does not limit this.
[0140] 8. UPF network element: Used for packet routing and forwarding, or quality of service (QoS) processing of user plane data, etc. It is understood that in future communication systems, the network element responsible for the above functions may still be a UPF network element, or may have other names; this application does not limit this.
[0141] 9. NEF Network Element: Used to securely expose services and capabilities provided by 3GPP network functions to the outside world. It is understood that in future communication systems, the network element responsible for the above functions may still be an NEF network element, or may have other names; this application does not limit this.
[0142] 10. NRF Network Element: Used to store network functional entities and their service descriptions, and to support service discovery, network element entity discovery, and other functions. It is understood that in future communication systems, the network element responsible for the above functions may still be an NRF network element, or may have other names; this application does not impose any limitations.
[0143] 11. UDR Network Element: Used to provide storage capacity for subscription data, policy data, and capability openness-related data. It is understood that in future communication systems, the network element responsible for the above functions may still be a UDR network element, or may have other names; this application does not limit this.
[0144] 12. DN, also known as Packet Data Network (PDN), is a data network that provides business services to users. Typically, the client is located on the terminal device, and the server is located on the data network. The data network can be a private network, such as a local area network (LAN), an external network not controlled by the operator, such as the Internet, or a dedicated network jointly deployed by operators, such as a network providing Internet Protocol (IP) Multimedia Core Network Subsystem (IMS) services.
[0145] It is understood that in practical applications, the above network architecture may also include other network elements, and this application does not limit this.
[0146] It should be noted that the names of the network elements in this application are merely examples, and this application does not preclude the possibility of using other names for the network elements in the future, or the merging of functions between the network elements. With the evolution of technology, any device or network element capable of implementing the functions of the aforementioned network elements is within the scope of protection of this application. Figure 1 The interface names between the various network elements are merely examples; in actual implementations, the interface names may differ, and this application does not impose any specific limitations on them. Furthermore, the names of the messages (or signaling) transmitted between the aforementioned network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.
[0147] For ease of description, each network element will be referred to by its corresponding English abbreviation in the following text, such as "SMF" for the session management function network element, etc.
[0148] See Figure 5 The diagram illustrates a network architecture diagram of another communication system to which embodiments of this application are applicable, which is a RAN-based service architecture. Figure 5 Only some NFs are listed, such as UDM, UDR, SMF, AMF, UPF, etc. Figure 2 The dashed line indicates that the connection is not yet complete.
[0149] from Figure 5 As can be seen, in a RAN-based service-oriented architecture, UEs can communicate directly with NFs via the RAN without using the AMF as an anchor point. This reduces AMF congestion. Furthermore, since the AMF doesn't need to be an anchor point, data from the UE to other NFs doesn't pass through the AMF, achieving data isolation and simplifying the process. For the RAN, the N2 interface can also be based on a service-oriented interface protocol, eliminating the need for the AMF as an anchor point. Therefore, the RAN only needs to maintain one set of protocols for each NF. Compared to using the AMF as an anchor point, where operators need to maintain one set of protocols between the access network equipment and the AMF, and another set between the AMF and other NFs, the operator only needs to maintain one set of protocols between the access network equipment and the NFs, resulting in fewer protocols and lower complexity.
[0150] Furthermore, during the process of establishing an AMF connection by sending messages (such as SR) to the terminal device, the security of the access stratum (AS) can be activated to ensure connection security. Additionally, RRC connections and N2 interface connections can be established to ensure reliable message transmission after the connection is established.
[0151] For ease of description, the embodiments of this application are applied to Figure 3 or Figure 5The network architecture shown is an example. The system described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems. It should be noted that the above... Figure 3 , Figure 5 The network elements, functions, or services mentioned can be network components in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). Optionally, the aforementioned network elements, functions, or services can be implemented by a single device, multiple devices working together, or a functional module within a single device; this application does not specifically limit this. Furthermore, some English abbreviations used in this document to describe embodiments of this application using the current 5G network as an example may change as the network evolves; specific evolution can be found in the descriptions in the relevant standards.
[0152] See Figure 6 The flowchart below illustrates an access control method provided in this application embodiment, which includes the following steps:
[0153] S601, The first device obtains the access level of the second device;
[0154] The first device can be a 3GPP device, meaning it has the ability to access 3GPP networks, for example... Figure 3 or Figure 5 The terminal device shown is not limited to either a 3GPP device or a non-3GPP device. The second device can be attached to the first device, for example, the second device can communicate with the first device. The communication connection methods between the second device and the first device include, but are not limited to, Wi-Fi, Bluetooth, UWB, or NFC, etc.
[0155] S602. The first device determines whether to allow the second device to access the network based on the access level of the second device.
[0156] The specific implementation method by which the first device determines whether to allow the second device to access the network based on the access level of the second device can refer to the checking method in the UAC mechanism.
[0157] For example, the first device determines whether the access level of the second device belongs to the allowed access level broadcast by the access network device. If so, the second device is allowed to access the network.
[0158] Of course, the above are just some possible examples. In practice, there may be other methods to determine whether to allow a second device to access the network. This application does not limit these methods.
[0159] In the above scheme, the second device connected to the first device has a separate access level. Therefore, the first device can determine whether to allow the second device to access the network based on the access level of the second device (i.e., perform UAC check), so as to provide the second device with a differentiated access service from the first device. This can achieve the technical effect of providing differentiated access services for non-3GPP devices.
[0160] In one possible design, before the first device determines whether to allow the second device to access the network based on its access level, the first device also performs an access check on the access attempt triggered by the second device. Alternatively, the first device's determination of whether to allow the second device to access the network based on its access level is performed during the process of the first device performing an access check on the access attempt triggered by the second device.
[0161] The second device triggers an access attempt. For example, when the second device has a data transmission requirement, it sends a message to the first device. This message includes the identifier of the second device and is used to indicate that the second device needs to transmit data. Optionally, the message also carries the data to be transmitted by the second device. After receiving the message sent by the second device, the first device generates an access attempt. For example, the NAS layer of the first device generates NAS signaling, and the NAS layer of the first device passes the access level of the second device to the AS layer of the first device. The AS layer of the first device performs an access check on the NAS signaling, for example, determining whether to allow the second device to access the network based on the access level of the second device in the NAS signaling.
[0162] In this design, the first device determines whether to allow the second device to access the network based on the access level only after the second device triggers an access attempt. On the one hand, it can provide access check services to the second device in a timely manner when the second device has data transmission needs. On the other hand, it can avoid the problem of power waste caused by frequently determining whether to allow the second device to access the network.
[0163] In one possible design, the first device obtains the access level of the second device, including: the first device receiving a first message, the first message including the access level of the second device. Optionally, the first message may also include an identifier of the second device. The identifier of the second device in the first message is used to indicate that the access level in the first message is the access level of the second device.
[0164] In a specific implementation, the first device may receive the first message from the network. For example, the first device may receive the first message sent by a first network element in the network. Further, optionally, the first network element may obtain the access level of the second device from other network elements (such as a second network element) and then send the first message to the first device.
[0165] Optionally, the network can issue an access level for the second device based on a request from the first device. For example, before the first device receives the first message, the first device first sends a second message, which includes the identifier of the second device, and the first message is a response message to the second message.
[0166] In practice, the first device can send the second message and receive the first message during processes such as registration, session establishment, or session modification. Of course, the first device can also initiate a separate process to obtain the access level of the second device. This application does not impose any restrictions.
[0167] See one possible example. Figure 7 The process by which the first device obtains the access level of the second device may include the following steps:
[0168] S701, the first device sends the second message; correspondingly, the first network element in the network receives the second message.
[0169] Optionally, the second message includes an identifier for the second device, used to request the access level of the second device. For example, the second message may be a registration request message, a session establishment request message, a session modification request message, or a message specifically for requesting an access level, etc.
[0170] The first network element can be a network element responsible for access control, such as an AMF; or, the first network element can be a network element responsible for session management, such as an SMF, etc., without restriction. This application does not restrict the specific implementation method of the first network element.
[0171] In practice, the second message sent by the first device can be forwarded to the first network element via other network elements, such as via the RAN.
[0172] S702, the first network element sends a third message to the second network element according to the second message; correspondingly, the second network element receives the third message;
[0173] Optionally, the third message may include the identifier of the second device, and the third message may be used to request the access level of the second device.
[0174] The second network element can be a network element responsible for functions such as processing, subscription, access authentication, registration, or mobility management. For example, the second network element can be a UDM (User Device Manager). The second network element can also be a network element responsible for providing data storage capabilities, such as a UDR (User Data Controller). This application does not restrict the specific implementation method of the second network element.
[0175] In practice, the third message sent by the first network element can be sent directly to the second network element, or it can be forwarded to the second network element through other network elements, without any restrictions.
[0176] S703, the second network element sends a fourth message to the first network element based on the third message; correspondingly, the first network element receives the fourth message;
[0177] The fourth message is a response to the third message, and it includes the access level of the second device.
[0178] For example, the third message is a request message to obtain contract data, and the fourth message is a response message to the request message to obtain contract data; or, the third message is a UDM registration request message, and the fourth message is a response message to the UDM registration request message, and so on.
[0179] The fourth message sent by the second network element can be sent directly to the first network element, or it can be forwarded to the first network element via other network elements, without any restrictions.
[0180] S704, the first network element sends the first message to the first device according to the fourth message; correspondingly, the first device receives the first message.
[0181] The first message is a response to the second message. For example, the second message is a registration request message, and the first message is a registration acceptance message; or, the second message is a session establishment request message, and the first message is a session establishment acceptance message; or, the second message is a session modification request message, and the first message is a session modification command message, and so on.
[0182] In practice, the first message sent by the first network element can be forwarded to the first device via other network elements, such as via the RAN.
[0183] In the above design, the first device can obtain the access level of the second device from other devices or network elements, which improves the reliability of the solution.
[0184] In this embodiment of the application, the identifier of the second device can be implemented in multiple ways. Two possible examples are listed below:
[0185] Example 1: The identifier of the second device includes the device identifier of the second device.
[0186] For example, consider a second device used in a fixed location or a private location. For instance, the second device is a home appliance (such as a TV, robot vacuum cleaner, speaker, etc.). The second device may be connected to multiple different 3GPP devices at the same time, or it may be connected to different 3GPP devices one after another. The transmission requirements of the second device are different under different 3GPP devices. In this scenario, the device identifier of the second device can be associated with the identifier of the first device, such as the subscription permanent identity (SUPI) of the first device. The network can store the correspondence between the device identifier of the second device and the identifier of the first device.
[0187] For example, a user purchases services for a second device from a network operator (e.g., through the operator's website or at their counter). This service includes configuring an access class (or differentiated access class) for the user's second device (which can be one or more). After configuring the access class for the second device, the network operator can store the access class in the network (e.g., on network elements like UDM or UDR). For example, the network operator can associate and store the device identifier of the second device, the SUPI of the first device, and the access class of the second device in the network.
[0188] In one possible example, the first device assigns a device identifier to the second device based on the device identifier of the second device. For instance, a user purchases at least one identifier (ID) and the access class corresponding to each ID from an operator, wherein the number of purchased IDs is greater than or equal to the maximum number of devices supported by the first device (i.e., the maximum number of devices that can simultaneously access the network through the first device). The first device stores the at least one ID and the access class corresponding to each ID, and can also configure the QoS, device characteristics, etc., corresponding to each ID. When any device under the first device (such as the second device) goes online, the first device can assign a suitable ID as the identifier of the online device based on the access class, QoS, and device characteristics (specifically, including but not limited to physical characteristics) corresponding to each ID. The first device maintains the correspondence between each device and ID attached to the first device.
[0189] In another possible example, the device identifier of the second device is its factory identifier, such as its media access control (MAC) address. For instance, a user purchases an access class from an operator for at least one device corresponding to a MAC address. When any device under the first device (such as the second device) comes online, the first device can determine the access class of that device based on its MAC address.
[0190] Example 2: The identifier of the second device includes the network identifier of the second device. For example, the identifier of the second device's SIM card, specifically, a subscription permanent identity (SUPI). For instance, consider a scenario where the second device is used in a public place, such as for a smart wearable device (e.g., smart glasses, smart headphones), where the 3GPP equipment connected to the second device changes frequently. In this scenario, a network identifier can be configured for the second device as its access identifier, eliminating the need to associate the second device's identifier with the first device's identifier.
[0191] For example, a user purchases services for a second device from a network operator (e.g., through the operator's website or at their counter). This service includes configuring a separate access class (or differentiated access class) for the second device. After configuring the access class for the second device, the network operator can store the access class in the network (e.g., on network elements such as UDM or UDR). For example, the network operator can associate and store the device identifier of the second device, the SUPI of the first device, and the access class of the second device in the network.
[0192] When the second device connects to the first device, the first device can obtain the second device's SUPI and report the second device's SUPI to the network. After the network authenticates the second device connected to the first device, it issues the access level of the second device. The issuance format is, for example: SUPI of the second device + access level.
[0193] Example 3: The identifier of the second device includes the attribute identifier of the second device. For example, the personal IoT network (PIN) ID or connectivity ID of the second device.
[0194] Of course, the above are just some examples of the identification of the second device, and are not limited to these.
[0195] In one possible design, after the first device determines whether the second device is allowed to access the network based on the access level, it can also create a QoS flow for the second device. The created QoS flow is used to transmit data sent by the second device to the network and / or data sent by the network to the second device.
[0196] Specifically, if the first device determines that the second device is allowed to access the network based on the access level, the first device sends a session modification request message. This message includes a session identifier and the identifier of the second device. The session modification request message requests the creation of a QoS flow for the second device within the session indicated by the session identifier. This QoS flow is used to transmit data sent by the second device to the network and / or data sent by the network to the second device. Correspondingly, the first network element receives the session modification request message from the first device and creates a QoS flow for the second device within the session according to the message. Optionally, after creating the QoS flow for the second device, the first network element also sends a session modification response message to the first device. This response message includes the QoS flow identifier (QFI) of the created QoS flow, indicating that the QoS flow creation is complete (or successful).
[0197] In one possible example, the QoS flow of the second device can reuse the QoS flow of the first device. That is, the QoS flow of the first device can be used not only to transmit data sent from the first device to the network and / or data sent from the network to the first device, but also to transmit data sent from the second device to the network and / or data sent from the network to the second device. This can improve resource utilization.
[0198] In another possible example, the QoS flow of the second device differs from that of the first device. Specifically, the QoS flow of the second device is used to transmit data sent from the second device to the network and / or data sent from the network to the second device, while the QoS flow of the first device is used to transmit data sent from the first device to the network and / or data sent from the network to the first device. This allows for better differentiation of QoS services for the second and first devices.
[0199] In this design approach, after determining that the second device is allowed to access the network, a QoS flow is created for the second device to facilitate the subsequent transmission of data sent from the second device to the network and / or data sent from the network to the second device based on the QoS flow, thereby improving the reliability of the solution.
[0200] In one possible design, after the first device determines whether the second device is allowed to access the network based on the access level, it can also create a session for the second device. Optionally, this session is specifically a PDU session.
[0201] Specifically, if the first device determines that the second device is allowed to access the network based on the access level, the first device sends a session establishment request message. This message includes the identifier of the second device and is used to request the creation of a session for the second device. Correspondingly, the first network element receives the session establishment request message from the first device and creates a session for the second device accordingly. Optionally, after creating a session for the second device, the first network element may also send a session creation response message to the first device. This response message includes the session identifier of the created session and is used to indicate that the session creation is complete (or successful).
[0202] In one possible example, the second device's session can reuse the first device's session. That is, the first device's session can be used not only to transmit data from the first device to the network and / or data from the network to the first device, but also to transmit data from the second device to the network and / or data from the network to the second device. This can improve resource utilization.
[0203] In another possible example, the second device's session differs from the first device's session. Specifically, the second device's session is used to transmit data sent from the second device to the network and / or data sent from the network to the second device, while the first device's session is used to transmit data sent from the first device to the network and / or data sent from the network to the first device. This allows for differentiated session transmission services for the second and first devices.
[0204] In this design, after the second device is allowed to access the network, a session is created for the second device so that data sent from the second device to the network and / or data sent from the network to the second device can be transmitted based on the session.
[0205] In one possible design, after the first device determines whether the second device is allowed to access the network based on the access level, it can also activate user plane resources for the second device. These user plane resources include, but are not limited to, QoS flows, data radio bearers (DRBs), and General Packet Radio Service Tunnel Protocol (GTP-U) tunnels, without restriction.
[0206] Specifically, if the first device determines, based on the access level, that the second device is allowed to access the network, the first device sends a NAS message. The NAS message includes a session identifier and is used to indicate the user plane resources for activating the session indicated by the session identifier. Correspondingly, the first network element receives the NAS message from the first device and activates the user plane resources for that session according to the NAS message. This NAS message can be sent during a registration process or a service request process, etc., and this application does not impose any restrictions.
[0207] In one possible implementation, the first network element can activate all user plane resources of the session indicated by the session identifier, such as activating all QoS flows within the session. For example, when the first device also has data transmission requirements, its user plane resources can be activated simultaneously. This simplifies the activation process.
[0208] In another possible implementation, the first network element can activate only the user plane resources associated with the second device in the session. For example, a NAS message is used to indicate that only the QoS flows of the second device in the session should be activated, and the NAS message includes the QFI of the QoS flows of the second device; accordingly, the first network element activates only the QoS flows of the second device in the session according to the NAS message.
[0209] The specific implementation methods for the first network element to activate only the QoS flow of the second device in the session based on the NAS message are as follows: 1) The PDU session QoS profile sent by the first network element to the RAN only includes the QFI of the QoS flow of the second device; 2) The PDU session QoS profile sent by the first network element to the RAN includes the QFI of all QoS flows in the session and indicates that the QoS flow of the second device is active. Of course, the above are only two possible examples of indication methods, and are not limited to these in practice.
[0210] It is understandable that for activated guaranteed bit rate (GBR) QoS flows, the RAN needs to reserve air interface resources for them. Therefore, for QoS flows that do not need to be activated (such as the QoS flow of the first device), activation is not performed, which can save air interface resources.
[0211] In one possible scenario, after the data transmission of the first device is complete (including the completion of data transmission between the first and second devices), it can return to the RRC idle state. The user plane resources of both the first and second devices are deactivated. In this case, to transmit data from the second device, its user plane resources must first be activated. In another possible scenario, there are no user plane resources for the second device in the session. In this case, to transmit data from the second device, its user plane resources must first be established and activated. Of course, these are just some possible scenario examples, and the actual scenario is not limited to these.
[0212] In this design, after allowing the second device to access the network, user plane resources are activated for the second device to facilitate subsequent transmission of data sent from the second device to the network and / or data sent from the network to the second device based on these user plane resources. Furthermore, only the QoS flow of the second device within the session can be activated, saving air interface resources.
[0213] It is understandable that the above design methods can be implemented individually or in combination. Two possible examples of combinations are given below:
[0214] Example 1, see Figure 8 As shown, it includes the following steps:
[0215] S801, The first network element obtains the access level of the second device from the second network element;
[0216] S802. The first network element sends the access level of the second device to the first device in the registration acceptance message or session establishment response message (equivalent to the first message mentioned above). Correspondingly, the first device receives the registration acceptance message or session establishment response message and obtains the access level of the second device.
[0217] S803. The first device initiates a PDU session establishment process to the first network element, creates a PDU session for the first device, and establishes a QoS flow;
[0218] S804. After the second device comes online, the first device detects that the second device has a traffic transmission requirement and performs a UAC check according to the access level of the second device.
[0219] S805. If the UAC check result is passed, the first device provides data transmission services to the second device based on the QoS flow in the PDU session;
[0220] S806. After the first device completes data transmission, it returns to the RRC idle state, and the QoS flow in the PDU session is deactivated.
[0221] S807. When the first device detects that the second device has a traffic transmission requirement in the RRC idle state, it performs a UAC check again according to the access level of the second device.
[0222] S808. If the UAC check result is passed, a NAS message is sent to the first network element, carrying the identifier of the PDU session, indicating the activation of the QoS flow in the PDU session; the first network element receives the NAS message.
[0223] S809. The first network element sends QoS configuration to the RAN, carrying the QFI of all QoS flows in the PDU session, in order to activate all QoS flows in the PDU session;
[0224] S810 provides data transmission services to the second device based on the activated QoS flow.
[0225] Based on Example 1, the access level of the second device can be provided to the first device in messages such as registration acceptance messages or session establishment response messages. When the second device comes online, it can be connected to the network according to the access level of the second device, and data transmission services can be provided to the second device based on the PDU session.
[0226] Example 2, see Figure 9 As shown, it includes the following steps:
[0227] S901, The first network element obtains the access level of the second device from the second network element;
[0228] S902, the first network element sends the access level of the second device to the first device in the registration acceptance message or session establishment response message (equivalent to the first message mentioned above). Correspondingly, the first device receives the registration acceptance message or session establishment response message and obtains the access level of the second device.
[0229] S903. The first device initiates a PDU session establishment process to the first network element to create a PDU session for the first device;
[0230] S904. After the second device comes online, the first device detects that the second device has a traffic transmission requirement and performs a UAC check according to the access level of the second device.
[0231] S905. If the UAC check result is passed, the first device interacts with the first network element to create a QoS flow for the second device and provides data transmission services to the second device based on the QoS flow of the second device.
[0232] S906. After the first device completes data transmission, it returns to the RRC idle state, and all QoS flows in the PDU session are deactivated.
[0233] S907. When the first device detects that the second device has a traffic transmission requirement in the RRC idle state, it performs a UAC check again according to the access level of the second device.
[0234] S908. If the UAC check result is passed, a NAS message is sent to the first network element, carrying the identifier of the PDU session and the QFI of the QoS flow of the second device, indicating that only the QoS flow of the second device in the PDU session is activated; the first network element receives the NAS message.
[0235] S909, the first network element sends QoS configuration to the RAN, carrying the QFI of the QoS flow of the second device in the PDU session, so as to activate only the QoS flow of the second device;
[0236] S910 provides data transmission services to the second device based on the activated QoS flow.
[0237] Based on this example 2, the access level of the second device can be provided to the first device in messages such as registration acceptance messages or session establishment response messages. When the second device comes online, it can be connected to the network according to its corresponding access level, and data transmission services can be provided to the second device based on the PDU session. Furthermore, when activating the user plane resources of the PDU session, only the QoS flow of the second device can be activated, which can save air interface resources.
[0238] The methods provided by the embodiments of this application have been described above with reference to the accompanying drawings. The apparatus provided by the embodiments of this application will be described below with reference to the accompanying drawings.
[0239] Based on the same technical concept, embodiments of this application provide a communication device, which includes a module / unit / means for performing the methods executed by the transmitting device and / or receiving device in the above-described method embodiments. This module / unit / means can be implemented in software, or in hardware, or implemented in hardware executing corresponding software.
[0240] For example, see Figure 10 The device may include a transceiver module 1001 and a processing module 1002.
[0241] For example, when the device is the first device or when the device is located on the first device:
[0242] Transceiver module 1001 is used to obtain the access level of the second device;
[0243] The processing module 1002 is used to determine whether to allow the second device to access the network based on the access level.
[0244] In one possible design, the transceiver module 1001 is used to receive a first message, which includes a second device access level.
[0245] In one possible design, the first message also includes the identifier of the second device.
[0246] In one possible design, the identifier of the second device includes the device identifier of the second device, such as the MAC address of the second device; or, the identifier of the second device includes the SUPI of the second device. Of course, the above two are just examples, and the actual design is not limited to these.
[0247] In one possible design, the processing module 1002 is further configured to: perform an access check on the access attempt triggered by the second device before determining whether the second device is allowed to access the network based on the access level.
[0248] In one possible design, if the processing module 1002 determines, based on the access level, that the second device is allowed to access the network, the transceiver module 1001 is further configured to: send a session modification request message, the session modification request message including a session identifier and an identifier of the second device, the session modification request message being used to request the creation of a QoS flow for the second device in the session indicated by the session identifier, the QoS flow being used to transmit data sent by the second device to the network and / or data sent by the network to the second device.
[0249] In one possible design, if the processing module 1002 determines, based on the access level, that the second device is allowed to access the network, the transceiver module 1001 is further configured to: send a session establishment request message, the session establishment request message including the identifier of the second device, the session establishment request message being used to request the creation of a session for the second device.
[0250] In one possible design, if the processing module 1002 determines, based on the access level, that the second device is allowed to access the network, the transceiver module 1001 is further configured to: send a NAS message, the NAS message including a session identifier, the NAS message being used to indicate the user plane resources of the session indicated by the session identifier.
[0251] In one possible design, the NAS message is used to indicate that only the QoS flow of the second device in the session is activated, and the NAS message includes the QFI of the QoS flow of the second device.
[0252] In one possible design, the transceiver module 1001 is further configured to: send a second message before receiving the first message, the second message including the identifier of the second device, and the first message being a response message to the second message. For example, the first message may be any one of a registration acceptance message, a session establishment acceptance message, or a session modification command message.
[0253] For example, when the device is the first network element or when the device is located on the first network element:
[0254] The transceiver module 1001 is used to obtain the access level of the second device and send a first message to the first device, the first message including the access level of the second device.
[0255] In one possible design, the first message also includes the identifier of the second device.
[0256] In one possible design, the identifier of the second device includes the device identifier of the second device; or, the identifier of the second device includes the SUPI of the second device.
[0257] In one possible design, the transceiver module 1001 is further configured to: receive a session modification request message from a first device, the session modification request message including a session identifier and an identifier of a second device, the session modification request message being used to request the creation of a QoS flow for the second device in the session indicated by the session identifier, the QoS flow being used to transmit data sent by the second device to the network and / or data sent by the network to the second device; the processing module 1002 is further configured to: create a QoS flow for the second device in the session according to the session modification request message.
[0258] In one possible design, the transceiver module 1001 is further configured to: receive a session establishment request message from a first device, the session establishment request message including the identifier of a second device, the session establishment request message being used to request the creation of a session for the second device; the processing module 1002 is further configured to: create a session for the second device according to the session establishment request message.
[0259] In one possible design, the transceiver module 1001 is further configured to: receive a NAS message from a first device, the NAS message including a session identifier, the NAS message being used to indicate the user plane resources of the session indicated by the session identifier; the processing module 1002 is further configured to: activate the user plane resources of the session according to the NAS message.
[0260] In one possible design, the NAS message is used to instruct that only the QoS flow of the second device in the session be activated, and the NAS message includes the QFI of the QoS flow of the second device. Accordingly, the processing module 1002 is also configured to: activate only the QoS flow of the second device in the session according to the NAS message.
[0261] In one possible design, the transceiver module 1001 is further configured to: receive a second message from the first device before sending the first message to the first device, the second message including the identifier of the second device, and the first message being a response message to the second message.
[0262] In one possible design, the first message is one of the following: registration acceptance message, session establishment acceptance message, or session modification command message.
[0263] In one possible design, the processing module 1002 is further configured to: control the transceiver module 1001 to send a third message to the second network element according to the second message, the third message including the identifier of the second device, the third message being used to request the access level of the second device; the transceiver module 1001 is further configured to: receive a fourth message from the second network element, the fourth message including the access level of the second device.
[0264] For example, when the device is a second network element or when the device is located on a second network element:
[0265] The transceiver module 1001 is used to obtain the access level of the second device and send a fourth message to the first network element, the fourth message including the access level of the second device.
[0266] In one possible design, the fourth message also includes the identifier of the second device.
[0267] In one possible design, the identifier of the second device includes the device identifier of the second device; or, the identifier of the second device includes the SUPI of the second device.
[0268] In one possible design, the transceiver module 1001 is further configured to receive a third message from the first network element, the third message including the identifier of the second device. The third message is used to request the access level of the second device. When the transceiver module 1001 sends a fourth message to the first network element, it is specifically configured to send the fourth message to the first network element based on the third message.
[0269] It should be understood that all relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0270] In practical implementation, the above-mentioned device can take many product forms. Several possible product forms are introduced below.
[0271] like Figure 11As shown in the illustration, this application also provides a communication device, including:
[0272] At least one processor 1101; and a communication interface 1103 communicatively connected to the at least one processor 1101; the at least one processor 1101 causes the device to perform the method steps in the above method embodiments through the communication interface 1103 by executing instructions stored in the memory 1102.
[0273] Optionally, the memory 1102 is located outside the device.
[0274] Optionally, the device includes the memory 1102, which is connected to the at least one processor 1101, and stores instructions executable by the at least one processor 1101. (See attached image) Figure 11 The dashed line indicates that memory 1102 is optional for the device.
[0275] The processor 1101 and the memory 1102 can be coupled through an interface circuit or integrated together; no restriction is imposed here.
[0276] This application embodiment does not limit the specific connection medium between the processor 1101, memory 1102, and communication interface 1103. This application embodiment... Figure 11 The processor 1101, memory 1102, and communication interface 1103 are connected via a bus 1104. Figure 11 The connections between other components are shown in bold and are for illustrative purposes only, not as limiting information. The bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, Figure 11 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0277] Based on the same technical concept, this application also provides a chip, see [link to relevant documentation]. Figure 12 The chip may include logic circuitry and input / output interfaces. Optionally, it may also include a memory. The input / output interfaces can be used to receive code instructions (stored in the memory, which can be read directly from the memory or via other devices) and transmit them to the logic circuitry; the logic circuitry can be used to execute the code instructions to perform the methods described in the above method embodiments.
[0278] It should be understood that the processor mentioned in the embodiments of this application can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor, implemented by reading software code stored in memory.
[0279] For example, the processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0280] It should be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0281] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.
[0282] It should be noted that the memories described herein are intended to include, but are not limited to, these and any other suitable types of memories.
[0283] Based on the same technical concept, this application also provides a computer-readable storage medium storing a computer program or instructions, which, when executed by a communication device, implements the method steps described in the above method embodiments.
[0284] Based on the same technical concept, this application also provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are run by a communication device, the method steps in the above method embodiments are executed.
[0285] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0286] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0287] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1The function specified in one or more boxes.
[0288] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
Claims
1. An access control method, characterized in that, The method includes: The first device obtains the access level of the second device; The first device determines whether to allow the second device to access the network based on the access level.
2. The method as described in claim 1, characterized in that, The first device obtains the access level of the second device, including: The first device receives a first message, which includes the access level.
3. The method as described in claim 2, characterized in that, The first message also includes the identifier of the second device.
4. The method as described in claim 3, characterized in that, The identifier of the second device includes the device identifier of the second device; or, the identifier of the second device includes the subscription persistent identifier SUPI of the second device.
5. The method according to any one of claims 1-4, characterized in that, Before the first device determines whether to allow the second device to access the network based on the access level, the method further includes: The first device performs an access check on the access attempt triggered by the second device.
6. The method according to any one of claims 1-5, characterized in that, The method further includes: If the first device determines, based on the access level, that the second device is allowed to access the network, then: The first device sends a session modification request message, which includes a session identifier and an identifier of the second device. The session modification request message is used to request the creation of a Quality of Service (QoS) flow for the second device in the session indicated by the session identifier. The QoS flow is used to transmit data sent by the second device to the network and / or data sent by the network to the second device.
7. The method according to any one of claims 1-5, characterized in that, The method further includes: If the first device determines, based on the access level, that the second device is allowed to access the network, then: The first device sends a session establishment request message, which includes the identifier of the second device, and is used to request the creation of a session for the second device.
8. The method according to any one of claims 1-5, characterized in that, The method further includes: If the first device determines, based on the access level, that the second device is allowed to access the network, then: The first device sends a Non-Access Stratum (NAS) message, which includes a session identifier and is used to indicate user plane resources for activating the session indicated by the session identifier.
9. The method as described in claim 8, characterized in that, The NAS message is used to indicate that only the QoS flow of the second device in the session is activated, and the NAS message includes the Quality of Service Flow Identifier (QFI) of the QoS flow of the second device.
10. The method according to any one of claims 1-9, characterized in that, Before the first device receives the first message, the method further includes: The first device sends a second message, the second message including the identifier of the second device, and the first message is a response message to the second message.
11. The method according to any one of claims 1-10, characterized in that, The first message is one of the following: registration acceptance message, session establishment acceptance message, or session modification command message.
12. An access control method, characterized in that, include: The first network element obtains the access level of the second device; The first network element sends the first message to the first device, and the first message includes the access level of the second device.
13. The method as described in claim 12, characterized in that, The first message also includes the identifier of the second device.
14. The method as described in claim 13, characterized in that, The identifier of the second device includes the device identifier of the second device; or, the identifier of the second device includes the SUPI of the second device.
15. The method according to any one of claims 12-14, characterized in that, The method further includes: The first network element receives a session modification request message from the first device. The session modification request message includes a session identifier and an identifier of the second device. The session modification request message is used to request the creation of a Quality of Service (QoS) flow for the second device in the session indicated by the session identifier. The QoS flow is used to transmit data sent by the second device to the network and / or data sent by the network to the second device. The first network element creates the QoS flow for the second device in the session according to the session modification request message.
16. The method according to any one of claims 12-14, characterized in that, The method further includes: The first network element receives a session establishment request message from the first device, the session establishment request message including the identifier of the second device, the session establishment request message being used to request the creation of a session for the second device; The first network element creates the session for the second device based on the session establishment request message.
17. The method according to any one of claims 12-14, characterized in that, The method further includes: The first network element receives a non-access stratum (NAS) message from the first device. The NAS message includes a session identifier and is used to indicate user plane resources that activate the session indicated by the session identifier. The first network element activates the user plane resources of the session according to the NAS message.
18. The method as described in claim 17, characterized in that, The NAS message is used to indicate that only the QoS flow of the second device in the session is activated, and the NAS message includes the Quality of Service Flow Identifier (QFI) of the QoS flow of the second device; The first network element activates the user plane resources of the session according to the NAS message, including: The first network element activates only the QoS flow of the second device in the session according to the NAS message.
19. The method according to any one of claims 12-18, characterized in that, Before the first network element sends the first message to the first device, the method further includes: The first network element receives a second message from the first device, the second message including the identifier of the second device, and the first message being a response message to the second message.
20. The method as described in claim 19, characterized in that, The first message is one of the following: registration acceptance message, session establishment acceptance message, or session modification command message.
21. The method as described in claim 19 or 20, characterized in that, The first network element obtains the access level of the second device, including: The first network element sends a third message to the second network element based on the second message. The third message includes the identifier of the second device and is used to request the access level of the second device. The first network element receives a fourth message from the second network element, the fourth message including the access level of the second device.
22. A communication device, characterized in that, It includes a module for performing the method as described in any one of claims 1-11, or includes a module for performing the method as described in any one of claims 12-21.
23. A communication device, characterized in that, It includes at least one processor; and a communication interface communicatively connected to the at least one processor; the at least one processor executes instructions stored in memory to cause the method as described in any one of claims 1-11 to be executed, or to cause the method as described in any one of claims 12-21 to be executed.
24. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions that, when executed, enable the method described in any one of claims 1-11, or the method described in any one of claims 12-21.
25. A computer program product, characterized in that, Includes instructions that, when executed on a computer, cause the method as described in any one of claims 1-11 to be implemented, or cause the method as described in any one of claims 12-21 to be implemented.