Communication method and communication device
By allowing storage function network elements to control data access based on network permissions and domain verification, the method addresses data leakage risks in non-public networks, enhancing location service security.
Patent Information
- Application Number
- JP2025539642
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-01-04
- Filing Date
- 2023-12-04
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2043-12-04
AI Technical Summary
The leakage of user data in location services based on non-public networks due to direct data acquisition from public networks by gateway mobile location centers (GMLCs) poses a security risk.
Implementing a communication method where a storage function network element determines, based on network permissions and domain verification, whether to transmit terminal device data to a GMLC, thereby controlling data access and enhancing security.
This method prevents unauthorized data leakage by ensuring that only permitted networks can access terminal device data, thus improving location service security in non-public networks.
Smart Images

Figure 2026504003000001_ABST
Abstract
Description
[Technical Field]
[0001] This application claims priority to Chinese Patent Application No. 202310007285.0, entitled "Communication Method and Communication Apparatus," filed with the State Intellectual Property Office of China on January 4, 2023, the entire contents of which are incorporated herein by reference.
[0002] Technical Field TECHNICAL FIELD Embodiments of the present application relate to the field of communications, and more particularly to a communication method and a communication device. [Background technology]
[0003] Currently, fifth-generation (5G) communication systems provide location services in non-public networks (PNINPN), sometimes called local location. PNINPN stands for Public Network Integrated Non-Public Network.
[0004] In a location method for a location service based on a non-public network, after receiving a location service request, a Gateway Mobile Location Center (GMLC) may obtain privacy data of a terminal device from a Unified Data Management (UDM) network element. The GMLC belongs to the non-public network, and the UDM belongs to the public network. The non-public network and the public network belong to different security domains. In this location method, the non-public network can actively obtain user data in the public network through an existing interface. This may cause the leakage of user data stored in the public network.
[0005] Therefore, how to improve the location security of location services based on non-public networks becomes an urgent problem to be solved. Summary of the Invention [Problem to be solved by the invention]
[0006] SUMMARY OF THE INVENTION The present application provides a communication method for improving location security for location services based on non-public networks. [Means for solving the problem]
[0007] According to a first aspect, there is provided a communication method, including: a gateway mobile location center (GMLC) in a first network sends a first request message to a storage function network element in a second network, the first request message including an identifier of a terminal device, the first request message being used to request retrieval of data of the terminal device; the storage function network element determines, in response to the first request message, whether the first network is a network allowed to retrieve data of the terminal device, and the storage function network element decides, based on the determination result, whether to transmit data of the terminal device to the GMLC.
[0008] According to a second aspect, a communication method is provided. The method may be performed by a storage function network element in a second network, or may be performed by a component (e.g., a chip or circuit) of the storage function network element. This is not limited herein. For ease of explanation, the following uses an example in which the method is performed by a storage function network element for explanation.
[0009] The communication method includes: a storage function network element in a second network receives a first request message from a gateway mobile location center (GMLC) in a first network, the first request message including an identifier of a terminal device, the first request message being used to request obtaining data of the terminal device; the storage function network element determines, in response to the first request message, whether the first network is a network allowed to obtain data of the terminal device; and the storage function network element determines, based on the determination result, whether to transmit data of the terminal device to the GMLC.
[0010] Based on the aforementioned technical solution, after a storage function network element in a second network receives a request message sent by a GMLC in a first network to request acquisition of terminal device data, the storage function network element first determines whether the first network is a network that is permitted to acquire terminal device data, and then determines whether to transmit the terminal device data to the GMLC based on the determination result, thereby avoiding the leakage of user data in the second network caused when the GMLC in the first network directly and actively acquires the terminal device data from the storage function network element in the second network through an existing interface, thus improving data security.
[0011] For example, when the aforementioned technical solution is applied to a local location scenario, after receiving a request message for obtaining data of a terminal device sent by a GMLC in a non-public network, a storage function network element in a public network determines whether the non-public network is a network that is allowed to obtain data of the terminal device, and then decides whether to send the data of the terminal device to the GMLC, thereby improving the location security of a location service based on a non-public network.
[0012] With reference to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, before the storage function network element determines whether the first network is a network that is allowed to obtain data of the terminal device, the method further includes: the storage function network element determines that the GMLC and the storage function network element belong to different network domains.
[0013] Based on the above technical solution, before determining whether the first network is a network that is allowed to acquire data of the terminal device, the storage function network element in the second network first determines that the GMLC that sends a request message to request acquisition of data of the terminal device and the storage function network element belong to different network domains. Specifically, when determining that the GMLC and the storage function network element belong to different network domains, the storage function network element determines whether the first network is a network that is allowed to acquire data of the terminal device, thereby avoiding a case where the GMLC and the storage function network element belong to the same network domain and the storage function network element still determines whether the first network is a network that is allowed to acquire data of the terminal device. This avoids unnecessary resource overhead.
[0014] With reference to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the storage function network element determining that the GMLC and the storage function network element belong to different network domains includes any one of the following: the storage function network element determines that the GMLC and the storage function network element belong to different network domains based on an identifier of the first network included in the first request message; the storage function network element determines the identifier of the first network based on an Internet Protocol IP address of the GMLC and determines that the GMLC and the storage function network element belong to different network domains based on the identifier of the first network; or the storage function network element determines the identifier of the first network based on a certificate of the GMLC and determines that the GMLC and the storage function network element belong to different network domains based on the identifier of the first network.
[0015] Based on the above technical solution, the storage function network element in the second network may determine in a different manner that the GMLC and the storage function network element belong to different network domains, improving the flexibility of the solution.
[0016] With reference to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the storage function network element determining whether the first network is a network that is allowed to obtain data of the terminal device includes: the storage function network element determining whether the first network is a network that is allowed to obtain data of the terminal device based on local configuration information, the configuration information including a list of identifiers of networks that are allowed to obtain data of the terminal device.
[0017] According to the above technical solution, the storage function network element in the second network can determine whether the first network is a network that is allowed to acquire data of the terminal device based on local configuration information, without obtaining information required for determining whether the first network is a network that is allowed to acquire data of the terminal device from another network element, thereby simplifying the procedure of the solution.
[0018] With reference to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the storage function network element determining, based on the local configuration information, whether the first network is a network that is allowed to obtain data of the terminal device includes: if the identifier of the first network belongs to a list of identifiers of networks that are allowed to obtain data of the terminal device, the storage function network element determines that the first network is a network that is allowed to obtain data of the terminal device; or if the identifier of the first network does not belong to the list of identifiers of networks that are allowed to obtain data of the terminal device, the storage function network element determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0019] With reference to the first or second aspect, in some implementations of the first or second aspect, the storage function network element determining whether the first network is an allowed network from which to obtain data of the terminal device includes: the storage function network element determining whether the first network is an allowed network from which to obtain data of the terminal device based on a correspondence between a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network. Specifically, the mobility management network element corresponding to the first network may be determined based on second configuration information. The second configuration information includes a correspondence between an identifier of at least one network and an identifier of at least one mobility management network element in the second network.
[0020] With reference to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the determining by the storage function network element whether the first network is an allowed network from which to obtain data of the terminal device based on the correspondence between the mobility management network element serving the terminal device and the mobility management network element corresponding to the first network includes: if the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, the storage function network element determines that the first network is an allowed network from which to obtain data of the terminal device; or if the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, the storage function network element determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0021] With reference to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the storage function network element determining whether to transmit data of the terminal device to the GMLC based on the determination result includes: when the determination result is that the first network is a network that is not allowed to obtain data of the terminal device, the storage function network element refuses to transmit the data of the terminal device to the GMLC.
[0022] With reference to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the storage function network element determining whether to transmit data of the terminal device to the GMLC based on the determination result includes: when the determination result is that the first network is a network that is not allowed to obtain data of the terminal device, the storage function network element transmits a public subscription identifier GPSI or a pseudonym of the terminal device to the GMLC.
[0023] With reference to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the storage function network element determining whether to transmit data of the terminal device to the GMLC based on the determination result includes: when the determination result is that the first network is a network that is allowed to obtain data of the terminal device, the storage function network element transmits the data of the terminal device to the GMLC.
[0024] In relation to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the data of the terminal device includes at least one of a subscription permanent identifier (SUPI) of the terminal device, a privacy setting of the terminal device, or an address of a mobility management network element serving the terminal device.
[0025] Referring to the first aspect or the second aspect, in some implementations of the first aspect or the second aspect, the second network is a public network and the first network is a local network.
[0026] According to a third aspect, there is provided a communications device configured to implement the method set forth in the second aspect, the device including: a transceiver module configured to receive a first request message from a gateway mobile location center (GMLC) in a first network, the first request message including an identifier of a terminal device, the first request message being used to request acquisition of data of the terminal device; and a processing module configured to determine, in response to the first request message, whether the first network is an authorized network for acquiring data of the terminal device, the processing module further configured to determine, based on a result of the determination, whether to transmit the data of the terminal device to the GMLC.
[0027] With reference to the third aspect, in some implementations of the third aspect, before the processing module determines whether the first network is a network that is allowed to obtain the data of the terminal device, the processing module is further configured to determine that the GMLC and the communication device belong to different network domains.
[0028] In relation to the third aspect, in some implementations of the third aspect, the processing module determining that the GMLC and the communication device belong to different network domains includes any one of the following: the processing module determines that the GMLC and the communication device belong to different network domains based on a first network identifier included in the first request message; the processing module determines the first network identifier based on an Internet Protocol IP address of the GMLC and determines that the GMLC and the communication device belong to different network domains based on the first network identifier; or the processing module determines the first network identifier based on a certificate of the GMLC and determines that the GMLC and the communication device belong to different network domains based on the first network identifier.
[0029] With reference to the third aspect, in some implementations of the third aspect, the processing module determining whether the first network is a network that is allowed to obtain data of the terminal device includes: the processing module determining whether the first network is a network that is allowed to obtain data of the terminal device based on local configuration information, the configuration information including a list of identifiers of networks that are allowed to obtain data of the terminal device.
[0030] With reference to the third aspect, in some implementations of the third aspect, the processing module determining, based on the local configuration information, whether the first network is a network that is allowed to obtain data of the terminal device includes: if the identifier of the first network belongs to a list of identifiers of networks that are allowed to obtain data of the terminal device, the processing module determines that the first network is a network that is allowed to obtain data of the terminal device; or if the identifier of the first network does not belong to the list of identifiers of networks that are allowed to obtain data of the terminal device, the processing module determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0031] With reference to the third aspect, in some implementations of the third aspect, the processing module determining whether the first network is an allowed network from which to obtain data of the terminal device includes: the processing module determining whether the first network is an allowed network from which to obtain data of the terminal device based on a correspondence between a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network.
[0032] With reference to the third aspect, in some implementations of the third aspect, the processing module determining whether the first network is an allowed network from which to obtain data of the terminal device based on the correspondence between the mobility management network element serving the terminal device and the mobility management network element corresponding to the first network includes: if the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, the processing module determines that the first network is an allowed network from which to obtain data of the terminal device; or if the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, the processing module determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0033] With reference to the third aspect, in some implementations of the third aspect, the processing module determining whether to transmit data of the terminal device to the GMLC based on the determination result includes: when the determination result is that the first network is a network that is not allowed to obtain data of the terminal device, the processing module refuses to transmit the data of the terminal device to the GMLC.
[0034] With reference to the third aspect, in some implementations of the third aspect, the processing module determining whether to transmit data of the terminal device to the GMLC based on the determination result includes: when the determination result is that the first network is not a network that is permitted to obtain data of the terminal device, the transceiver module is further configured to transmit a public subscription identifier (GPSI) or a pseudonym of the terminal device to the GMLC.
[0035] With reference to the third aspect, in some implementations of the third aspect, the processing module determining whether to transmit data of the terminal device to the GMLC based on the determination result includes: when the determination result is that the first network is a network that is allowed to obtain the data of the terminal device, the transceiver module is further configured to transmit the data of the terminal device to the GMLC.
[0036] With reference to the third aspect, in some implementations of the third aspect, the data for the terminal device includes at least one of a subscription permanent identifier (SUPI) of the terminal device, a privacy setting of the terminal device, or an address of a mobility management network element serving the terminal device.
[0037] With reference to the third aspect, in some implementations of the third aspect, the second network is a public network and the first network is a local network.
[0038] According to a fourth aspect, a communication method is provided. The method may be performed by a first network element in a second network, or may be performed by a component (e.g., a chip or circuit) of the first network element. This is not limited herein. For ease of explanation, the following uses an example in which the method is performed by the first network element for explanation.
[0039] The communication method includes: a first network element in the second network receives a first request message from a second network element in the first network, the first request message including an identifier of a terminal device, the first request message being used to request obtaining data of the terminal device; the first network element sends a first response message to the second network element in response to the first request message, the information included in the first response message being determined based on a verification result, the verification result indicating whether the first network is an allowed network for obtaining data of the terminal device.
[0040] Based on the aforementioned technical solution, after a first network element in a second network receives a request message sent by a second network element in a first network to request acquisition of terminal device data, the information included in a first response message sent by the first network element to the second network element is determined based on a verification result, which indicates whether the first network is an authorized network for acquiring terminal device data, thereby avoiding the leakage of user data in the second network caused when the second network element in the first network directly and actively acquires terminal device data through an existing interface, thereby improving data security.
[0041] With reference to the fourth aspect, in some implementations of the fourth aspect, when the first network is a network that is allowed to obtain data of the terminal device, the first response message includes some or all of the data of the terminal device.
[0042] With reference to the fourth aspect, in some implementations of the fourth aspect, when the first network is a network that is not permitted to obtain data of the terminal device, the first response message is used to refuse to provide data of the terminal device.
[0043] With reference to the fourth aspect, in some implementations of the fourth aspect, when the first network is a network that is not allowed to obtain data of the terminal device, the first response message includes a public subscription identifier (GPSI) or a pseudonym of the terminal device.
[0044] With reference to the fourth aspect, in some implementations of the fourth aspect, before the first network element sends the first response message to the second network element, the method further includes: the first network element determines the verification result, or the first network element receives the verification result from a storage function network element in the second network.
[0045] With reference to the fourth aspect, in some implementations of the fourth aspect, the first network element determining the verification result includes: the first network element determining the verification result based on first information, the first information including subscription data of the terminal device and / or a list of identifiers of the terminal device that allow the first network to obtain data, the subscription data of the terminal device including a correspondence between the identifier of the terminal device and an identifier of at least one network, and the at least one network being a network that is allowed to obtain data of the terminal device.
[0046] With reference to the fourth aspect, in some implementations of the fourth aspect, before the first network element determines the verification result, the method further includes: the first network element sending a second request message to a storage function network element in the second network, the second request message including an identifier of the terminal device and / or an identifier of the second network, the second request message being used to request obtaining the first information; and the first network element receiving the first information from the storage function network element.
[0047] With reference to the fourth aspect, in some implementations of the fourth aspect, the first network element determining a verification result based on subscription data of the terminal device includes: if the identifier of the first network is one of the identifiers of the at least one network, the first network element determines that the first network is a network that is allowed to obtain data of the terminal device; if the identifier of the first network is not one of the identifiers of the at least one network, the first network element determines that the first network is a network that is not allowed to obtain data of the terminal device; if the identifier of the terminal device is one of a list of identifiers of terminal devices that the first network allows to obtain data of, the first network element determines that the first network is a network that is allowed to obtain data of the terminal device; or if the identifier of the terminal device is not one of the list of identifiers of terminal devices that the first network allows to obtain data of, the first network element determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0048] With reference to the fourth aspect, in some implementations of the fourth aspect, the first network element determining the verification result includes: the first network element determining the verification result based on a coverage of data of the terminal device and a coverage of a first network, the subscription data of the terminal device including information related to the coverage of data of the terminal device, the coverage of the first network being determined based on first configuration information, and the first configuration information including information related to the coverage of at least one network.
[0049] With reference to the fourth aspect, in some implementations of the fourth aspect, before the first network element determines a verification result, the method further includes: the first network element sending a third request message to a storage function network element in the second network, the third request message including an identifier of the terminal device, the third request message being used to request obtaining subscription data of the terminal device, and the first network element receiving the subscription data of the terminal device from the storage function network element.
[0050] With reference to the fourth aspect, in some implementations of the fourth aspect, before the first network element determines the verification result, the method further includes: the first network element sending a fourth request message to a storage function network element in the second network, the fourth request message including an identifier of the first network, the fourth request message being used to request obtaining information about the coverage area of the first network; and the first network element receiving the information about the coverage area of the first network from the storage function network element.
[0051] With reference to the fourth aspect, in some implementations of the fourth aspect, the data of the terminal device includes first data and second data, the coverage of the first data is a first range, and the coverage of the second data is a second range, and determining a verification result based on the coverage of the data of the terminal device and the coverage of the first network element includes: If an intersection set exists between the coverage range of the first network and the first range, the first network element determines that the first network is a network that is allowed to obtain the first data, and the first response message includes the first data; if an intersection set exists between the coverage range of the first network and the second range, the first network element determines that the first network is a network that is allowed to obtain the second data, and the first response message includes the second data; if an intersection set exists between the coverage range of the first network and each of the first range and the second range, the first network element determines that the first network is a network that is allowed to obtain the first data and the second data, and the first response message includes the first data and the second data; or if no intersection set exists between the coverage range of the first network and the coverage range of the data of the terminal device, the first network element determines that the first network is a network that is not allowed to obtain the data of the terminal device.
[0052] With reference to the fourth aspect, in some implementations of the fourth aspect, the first network element determining the verification result includes: the first network element determining the verification result based on a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network, the mobility management network element corresponding to the first network being determined based on second configuration information, the second configuration information including a correspondence between an identifier of the at least one network and an identifier of the at least one mobility management network element in the second network.
[0053] With reference to the fourth aspect, in some implementations of the fourth aspect, before the first network element determines the verification result, the method further includes: the first network element sending a fifth request message to a storage function network element in the second network, the fifth request message including an identifier of the first network, the fifth request message being used to request obtaining an identifier of a mobility management network element corresponding to the first network; and the first network element receiving the identifier of the mobility management network element corresponding to the first network from the storage function network element.
[0054] With reference to the fourth aspect, in some implementations of the fourth aspect, the first network element determining a verification result based on a relationship between a mobility management network element corresponding to the first network and a mobility management network element serving the terminal device includes: if the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, the first network element determines that the first network is a network that is allowed to obtain data of the terminal device; or if the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, the first network element determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0055] In relation to the fourth aspect, in some implementations of the fourth aspect, before the first network element receives the verification result from the storage function network element in the first network, the method further includes: the first network element sending a sixth request message to the storage function network element, the sixth request message including an identifier of the first network and / or an identifier of the target terminal device, the sixth request message being used to request obtaining the verification result.
[0056] In relation to the fourth aspect, in some implementations of the fourth aspect, the data of the terminal device includes at least one of a subscription permanent identifier (SUPI) of the terminal device, a privacy setting of the terminal device, or a mobility management network element serving the terminal device.
[0057] With reference to the fourth aspect, in some implementations of the fourth aspect, the second network is a public network and the first network is a local network.
[0058] With reference to the fourth aspect, in some implementations of the fourth aspect, the first network element is a unified data management function network element UDM, an authentication server function network element AUSF, or a network data analysis function network element NWDAF; and the second network element is a gateway mobile location center GMLC, a mobility management function network element AMF, or a session management function network element SMF.
[0059] According to a fifth aspect, there is provided a communication method, including: a gateway mobile location center (GMLC) in a first network sending a first request message to a storage function network element in a second network, the first request message including an identifier of a terminal device, the first request message being used to request retrieval of data of the terminal device; the storage function network element determining information to be included in a first response message sent to the GMLC based on a coverage of the data of the terminal device and a coverage of the first network, the subscription data of the terminal device including information regarding the coverage of the data of the terminal device, the coverage of the first network being determined based on first configuration information, the first configuration information including information regarding the coverage of at least one network.
[0060] With reference to the fifth aspect, in some implementations of the fifth aspect, the data of the terminal device includes first data and second data, the coverage of the first data is a first range, and the coverage of the second data is a second range, and the memory function network element determining, based on the coverage of the data of the terminal device and the coverage of the first network, information to be included in the first response message to be sent to the GMLC includes: If an intersection set exists between the coverage area of the first network and the first range, the storage function network element determines that the first response message includes first data; if an intersection set exists between the coverage area of the first network and the second range, the storage function network element determines that the first response message includes second data; if an intersection set exists between the coverage area of the first network and each of the first range and the second range, the storage function network element determines that the first response message includes first data and second data; or if there is no intersection set exists between the coverage area of the first network and the coverage area of the data of the terminal device, the storage function network element determines that the first response message includes information regarding a refusal to provide data for the terminal device.
[0061] According to a sixth aspect, there is provided a communication method, including: a gateway mobile location center (GMLC) in a first network sending a first request message to a storage function network element in a second network, the first request message including an identifier of a terminal device, the first request message being used to request retrieval of data of the terminal device; the storage function network element determining whether to allow transmission of data of the terminal device to the first network based on a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network, the mobility management network element corresponding to the first network being determined based on second configuration information, the second configuration information including a correspondence between an identifier of at least one network and an identifier of at least one mobility management network element in the second network.
[0062] With reference to the sixth aspect, in some implementations of the sixth aspect, determining whether to allow data of the terminal device to be transmitted to the first network by the storage function network element based on a relationship between a mobility management network element corresponding to the first network and a mobility management network element serving the terminal device includes: if the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, the storage function network element determines to allow data of the terminal device to be transmitted to the first network; or if the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, the storage function network element determines not to allow data of the terminal device to be transmitted to the first network.
[0063] With reference to the sixth aspect, in some implementations of the sixth aspect, when the storage function network element determines to allow data of the terminal device to be transmitted to the first network, the method further includes: the storage function network element transmits a first response message to the GMLC in response to the first request message, where the first response message includes the data of the terminal device.
[0064] With reference to the sixth aspect, in some implementations of the sixth aspect, when the storage function network element determines not to allow data of the terminal device to be transmitted to the first network, the method further includes: the storage function network element transmits a first response message to the GMLC in response to the first request message, where the first response message is used to refuse to provide the data of the terminal device.
[0065] With reference to the sixth aspect, in some implementations of the sixth aspect, when the storage function network element determines not to allow data of the terminal device to be transmitted to the first network, the method further includes: the storage function network element sends a first response message to the GMLC in response to the first request message, where the first response message includes a public subscription identifier GPSI or a pseudonym of the terminal device.
[0066] According to a seventh aspect, there is provided a communication method, including: The gateway mobile location center GMLC in the first network sends a first request message to a first network element in the second network, the first request message including an identifier of the terminal device, the first request message being used to request obtaining data of the terminal device; the first network element sends a second request message to a storage function network element in the second network, the second request message including an identifier of the terminal device and / or an identifier of the second network, the second request message being used to request obtaining first information, the first information including subscription data of the terminal device and / or a list of identifiers of terminal devices from which the first network allows the first network to obtain data; the storage function network element sends the first information to the first network element; the first network element determines a verification result based on the first information, the verification result indicating whether the first network is a network that is allowed to obtain data of the terminal device; the first network element sends a first response message to the second network element in response to the first request message, the information included in the first response message being determined based on the verification result.
[0067] With reference to the seventh aspect, in some implementations of the seventh aspect, the method further includes: the storage function network element determines, based on the subscription data of the at least one terminal device and the identifier of the second network, a list of identifiers of terminal devices that allow the second network to obtain data.
[0068] With reference to the seventh aspect, in some implementations of the seventh aspect, when the first network is a network that is allowed to obtain data of the terminal device, the first response message includes data of the terminal device.
[0069] With reference to the seventh aspect, in some implementations of the seventh aspect, when the first network is a network that is not permitted to obtain data of the terminal device, the first response message is used to refuse to provide data of the terminal device.
[0070] With reference to the seventh aspect, in some implementations of the seventh aspect, when the first network is a network that is not allowed to obtain data of the terminal device, the first response message includes a public subscription identifier (GPSI) or a pseudonym of the terminal device.
[0071] According to an eighth aspect, there is provided a communication method, including: a gateway mobile location center (GMLC) in a first network sending a first request message to a storage function network element in a second network, the first request message including an identifier of a terminal device, the first request message being used to request obtaining data of the terminal device; the first network element sending a third request message to a storage function network element in the second network, the third request message including an identifier of the terminal device, the third request message being used to request obtaining subscription data of the terminal device; the storage function network element sending the subscription data of the terminal device to the first network element; the first network element sending a fourth request message to the storage function network element; a fourth request message to the network element, the fourth request message including an identifier of the second network, the fourth request message being used to request obtaining information regarding the coverage of the first network; the storage function network element sending information regarding the coverage of the first network to the first network element; the first network element determining information to be included in a first response message to be sent to the GMLC based on the coverage of the data of the terminal device and the coverage of the first network, the subscription data of the terminal device including information regarding the coverage of the data of the terminal device, the coverage of the first network being determined based on first configuration information, the first configuration information including information regarding the coverage of at least one network.
[0072] With reference to the eighth aspect, in some implementations of the eighth aspect, the method further includes: the storage function network element determines a coverage area of the first network based on the first configuration information and an identifier of the first network.
[0073] With reference to the eighth aspect, in some implementations of the eighth aspect, the data of the terminal device includes first data and second data, the coverage of the first data is a first range, and the coverage of the second data is a second range, and the first network element determining, based on the coverage of the data of the terminal device and the coverage of the first network element, information to be included in the first response message to be sent to the GMLC includes: If an intersection set exists between the coverage range of the first network and the first range, the first network element determines that the first response message includes first data; if an intersection set exists between the coverage range of the first network and the second range, the first network element determines that the first response message includes second data; if an intersection set exists between the coverage range of the first network and each of the first range and the second range, the first network element determines that the first response message includes the first data and the second data; or if an intersection set does not exist between the coverage range of the first network and the coverage range of the data of the terminal device, the first network element determines that the first response message includes information regarding a refusal to provide data for the terminal device.
[0074] According to a ninth aspect, there is provided a communication method, including: a gateway mobile location center (GMLC) in a first network sending a first request message to a storage function network element in a second network, the first request message including an identifier of a terminal device, the first request message being used to request obtaining data of the terminal device; the first network element sending a fifth request message to the storage function network element in the second network, the fifth request message including an identifier of the second network, the fifth request message being used to request obtaining an identifier of a mobility management network element corresponding to the first network; the storage function network element sending the identifier of the mobility management network element corresponding to the first network to the first network element; and the first network element deciding whether to allow data of the terminal device to be transmitted to the first network based on the mobility management network element serving the terminal device and the mobility management network element corresponding to the first network.
[0075] With reference to the ninth aspect, in some implementations of the ninth aspect, determining by the first network element whether to allow data of the terminal device to be transmitted to the first network based on a relationship between a mobility management network element corresponding to the first network and a mobility management network element serving the terminal device includes: if the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, the first network element determines to allow data of the terminal device to be transmitted to the first network; or if the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, the first network element determines not to allow data of the terminal device to be transmitted to the first network.
[0076] With reference to the ninth aspect, in some implementations of the ninth aspect, when the first network element determines to allow data of the terminal device to be transmitted to the first network, the method further includes: the first network element transmitting a first response message to the GMLC in response to the first request message, where the first response message includes the data of the terminal device.
[0077] With reference to the ninth aspect, in some implementations of the ninth aspect, when the first network element determines not to allow data of the terminal device to be transmitted to the first network, the method further includes: the first network element sending a first response message to the GMLC in response to the first request message, where the first response message is used to refuse to provide the data of the terminal device.
[0078] With reference to the ninth aspect, in some implementations of the ninth aspect, when the first network element determines not to allow data of the terminal device to be transmitted to the first network, the method further includes: the first network element sends a first response message to the GMLC in response to the first request message, where the first response message includes a public subscription identifier (GPSI) or a pseudonym of the terminal device.
[0079] According to a tenth aspect, there is provided a communication device configured to perform the method provided in the second or fourth aspect. Specifically, the communication device may include units and / or modules, such as a processing unit and an acquisition unit, configured to perform the method according to any one of the implementations of the second or fourth aspect.
[0080] In some implementations, the transceiver unit may be a transceiver or an input / output interface, and the processing unit may be at least one processor. Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.
[0081] In another implementation, the transceiver unit may be an input / output interface, interface circuit, output circuit, input circuit, pin, associated circuitry, etc. on a chip, chip system, or circuit; the processing unit may be at least one processor, processing circuit, logic circuit, etc.
[0082] According to an eleventh aspect, the present application provides a processor configured to perform the methods provided in the previous aspects. In the processes of performing these methods, the processes of transmitting information and acquiring / receiving information in the previous methods can be understood as processes of outputting information by the processor and receiving input information by the processor. When outputting information, the processor outputs the information to the transceiver, which then transmits the information. After the information is output by the processor, other processing may need to be performed on the information before it arrives at the transceiver. Similarly, when the processor receives input information, the transceiver acquires / receives the information and inputs the information to the processor. Furthermore, after the transceiver receives information, other processing may need to be performed on the information before it is input to the processor.
[0083] Based on the above principles, for example, receiving a request message in the above method may be understood as receiving input information by the processor.
[0084] Unless otherwise specified, or where operations such as transmitting, sending, and acquiring / receiving related to a processor do not contradict the actual function or internal logic of the operations in the associated description, all operations may be more generally understood as operations such as output, receiving, and input of a processor, rather than operations of transmitting, sending, and receiving performed directly by radio frequency circuits and antennas.
[0085] In the implementation process, the processor may be a processor specially configured to execute these methods, or a processor that executes computer instructions in memory to execute these methods, such as a general-purpose processor. The memory may be a non-transitory memory, such as a read-only memory (ROM). The memory and the processor may be integrated on the same chip or separately located on different chips. The type of memory and the manner in which the memory and the processor are located are not limited in the embodiments of the present application.
[0086] According to a twelfth aspect, there is provided a computer-readable storage medium storing program code for execution by a device, the program code being used to perform any of the methods provided in the second or fourth aspects.
[0087] According to a thirteenth aspect, there is provided a computer program product comprising instructions which, when executed on a computer, enable the computer to carry out any of the methods provided in the second or fourth aspect.
[0088] According to a fourteenth aspect, there is provided a chip including a processor and a communication interface, wherein the processor reads instructions stored in a memory via the communication interface to perform any of the methods provided in the second or fourth aspects.
[0089] Optionally, in some implementations, the chip may further include a memory, the memory storing instructions, and the processor configured to execute the instructions stored in the memory, which, when executed, configures the processor to perform any of the methods provided in the second or fourth aspects.
[0090] According to a fifteenth aspect, there is provided a communication system including a Gateway Mobile Location Centre GMLC in a first network and a storage function network element in a second network, the storage function network element performing any method provided in the second or fourth aspect.
[0091] Specifically, the GMLC is configured to send a first request message to a storage function network element, the first request message including an identifier of the terminal device, the first request message being used to request retrieval of data of the terminal device, and the storage function network element is configured to determine, in response to the first request message, whether the first network is a network that is allowed to retrieve data of the terminal device; the storage function network element is further configured to decide, based on the determination result, whether to transmit data of the terminal device to the GMLC.
[0092] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, before the storage function network element determines whether the first network is a network that is allowed to obtain data of the terminal device, the storage function network element is further configured to determine that the GMLC and the storage function network element belong to different network domains.
[0093] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, the storage function network element determining that the GMLC and the storage function network element belong to different network domains includes any one of the following: the storage function network element determines that the GMLC and the storage function network element belong to different network domains based on an identifier of the first network included in the first request message; the storage function network element determines the identifier of the first network based on an Internet Protocol IP address of the GMLC and determines that the GMLC and the storage function network element belong to different network domains based on the identifier of the first network; or the storage function network element determines the identifier of the first network based on a certificate of the GMLC and determines that the GMLC and the storage function network element belong to different network domains based on the identifier of the first network.
[0094] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, the storage function network element determining whether the first network is a network that is allowed to obtain data of the terminal device includes: the storage function network element determining whether the first network is a network that is allowed to obtain data of the terminal device based on local configuration information, the configuration information including a list of identifiers of networks that are allowed to obtain data of the terminal device.
[0095] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, the storage function network element determining, based on the local configuration information, whether the first network is a network that is allowed to obtain data of the terminal device includes: if the identifier of the first network belongs to a list of identifiers of networks that are allowed to obtain data of the terminal device, the storage function network element determines that the first network is a network that is allowed to obtain data of the terminal device; or if the identifier of the first network does not belong to the list of identifiers of networks that are allowed to obtain data of the terminal device, the storage function network element determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0096] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, the storage function network element determining whether the first network is an allowed network from which to obtain data of the terminal device includes: the storage function network element determining whether the first network is an allowed network from which to obtain data of the terminal device based on a correspondence between a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network.
[0097] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, the determining by the storage function network element whether the first network is an allowed network from which to obtain data of the terminal device based on the correspondence between the mobility management network element serving the terminal device and the mobility management network element corresponding to the first network includes: if the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, the storage function network element determines that the first network is an allowed network from which to obtain data of the terminal device, or if the mobility management network element serving the terminal device is not the subset of the mobility management network elements corresponding to the first network, the storage function network element determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0098] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, determining whether to transmit data of the terminal device to the GMLC by the storage function network element based on the determination result includes: when the determination result is that the first network is a network that is not allowed to obtain data of the terminal device, the storage function network element refuses to transmit the data of the terminal device to the GMLC.
[0099] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, determining whether to transmit data of the terminal device to the GMLC by the storage function network element based on the determination result includes: if the determination result is that the first network is a network that is not allowed to obtain data of the terminal device, the storage function network element is used to transmit a public subscription identifier GPSI or a pseudonym of the terminal device to the GMLC.
[0100] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, determining whether to transmit data of the terminal device to the GMLC by the storage function network element based on the determination result includes: when the determination result is that the first network is a network that is allowed to obtain data of the terminal device, the storage function network element is used to transmit data of the terminal device to the GMLC.
[0101] In relation to the fifteenth aspect, in some implementations of the fifteenth aspect, the data for the terminal device includes at least one of a subscription permanent identifier (SUPI) of the terminal device, a privacy setting of the terminal device, or an address of a mobility management network element serving the terminal device.
[0102] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, the second network is a public network and the first network is a local network.
[0103] With reference to the fifteenth aspect, in some implementations of the fifteenth aspect, the communication system further includes a mobile location service client, wherein the mobile location service client is configured to send a location service request to the GMLC, and the location service request includes an identifier of the terminal device. [Brief explanation of the drawings]
[0104] [Figure 1] 1 is a diagram of an architecture of a communication system applicable to certain embodiments of the present application;
[0105] [Figure 2] FIG. 1 is a diagram of a location service architecture in a PNINPN scenario according to an embodiment of the present application.
[0106] [Figure 3] 1 is a schematic flow chart of a location determination method.
[0107] [Figure 4] 1 is a schematic flow chart of a communication method according to the present application;
[0108] [Figure 5] 4 is a schematic flow chart of another communication method according to the present application.
[0109] [Figure 6] 1 is a block diagram of a communication device according to an embodiment of the present application;
[0110] [Figure 7] 1 is a block diagram of a communication device according to another embodiment of the present application;
[0111] [Figure 8] FIG. 10 is a block diagram of a communication device according to yet another embodiment of the present application. DETAILED DESCRIPTION OF THE INVENTION
[0112] The following describes the technical solution of the present application with reference to the accompanying drawings.
[0113] The technical solutions provided in this application may be applied to various communication systems, such as new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, and LTE time division duplex (TDD) systems.
[0114] In a communication system, a network operated by an operator may be called a public land mobile network (PLMN), which may also be called an operator network. A PLMN is a network established and operated by a government or an operator authorized by the government to provide land mobile communication services to the public, and is primarily a public network over which a mobile network operator (MNO) provides mobile broadband access services for users. The PLMN described in the embodiments of the present application may specifically be a network that meets certain requirements of the 3GPP standard and is referred to as a 3GPP network for short. 3GPP networks typically include, but are not limited to, 5G networks, fourth-generation (4G) mobile communication networks, and other future communication systems, such as sixth-generation (6G) networks.
[0115] For ease of explanation, a PLMN or a 5G network is used as an illustrative example in the embodiments of the present application.
[0116] FIG. 1 is a diagram of a network architecture 100 according to the present application. A 5G network architecture based on the Service-Based Architecture (SBA) in a non-roaming scenario defined in the 3GPP standardization process is used as an example. As shown in the figure, the network architecture may include three parts: a terminal device part, a data network (DN) part, and an operator network (PLMN) part. The following briefly describes the functions of the network elements in each part.
[0117] The terminal device portion may include a terminal device 110, which may also be referred to as user equipment (UE). The terminal device 110 herein is a device having radio transmission and reception capabilities and may communicate with one or more core network (CN) devices via access network devices (also referred to as access devices) in a radio access network (RAN) 120. The terminal device 110 may also be referred to as an access terminal, terminal, subscriber unit, subscriber station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, user equipment, etc. The terminal device 110 may be an indoor or outdoor device, or a handheld or vehicle-mounted device, located on land; on water (e.g., a ship); or in the air (e.g., an airplane, a balloon, or a satellite). The terminal device 110 may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smartphone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), etc. Alternatively, the terminal device 110 may be a handheld device with wireless communication capabilities, a computing device, another device connected to a wireless modem, an in-vehicle device, a wearable device, an unmanned aerial device, a terminal in an Internet of Things or Internet of Vehicles, any form of terminal in a 5G network or future network, relay user equipment, a terminal in a future evolved 6G network, etc. The relay user equipment may be, for example, a 5G residential gateway (RG).For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. The terminal device here is a 3GPP terminal. The type, category, etc. of the terminal device are not limited in the embodiments of the present application. For ease of description, an example in which a UE represents a terminal device is used in the following description in this application.
[0118] The operator network PLMN portion may include, but is not limited to, a (radio) access network ((R)AN) 120 and a core network (CN) portion.
[0119] The (R)AN 120 may be considered a subnetwork of an operator network and is an implementation system between a service node in the operator network and the terminal device 110. To access the operator network, the terminal device 111 may first pass through the (R)AN 120 and then connect to a service node in the operator network through the (R)AN 120. An access network device (RAN device) in the embodiment of the present application is a device that provides wireless communication functions for the terminal device 110 and may also be referred to as a network device. RAN devices include, but are not limited to, next generation node base stations (gNBs) in 5G systems, evolved NodeBs (eNBs) in long term evolution (LTE), radio network controllers (RNCs), NodeBs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved NodeBs or home NodeBs, HNBs), baseband units (BBUs), transmitting and receiving points (TRPs), transmitting points (TPs), small cell base station devices (pico), mobile switching centers, network devices in future networks, etc. In systems using different radio access technologies, devices having the functionality of access network devices may have different names. For ease of description, in all embodiments of the present application, the above-mentioned devices that provide wireless communication functions for the terminal device 110 are collectively referred to as access network devices, or abbreviated as RAN or AN. It should be understood that the specific type of access network device is not limited herein.
[0120] The CN portion may include, but is not limited to, the following NFs: user plane function (UPF) 130, network exposure function (NEF) 131, network function repository function (NRF) 132, policy control function (PCF) 133, unified data management (UDM) function 134, unified data repository (UDR) function 135, network data analytics function (NWDAF) 136, authentication server function (AUSF) 137, access and mobility management function (AMF) 138, and session management function (SMF) 139.
[0121] The data network DN 140, sometimes referred to as a packet data network (PDN), is typically a network located outside the operator network, e.g., a third-party network. Of course, in some implementations, the DN may alternatively be deployed by the operator, i.e., the DN is part of a PLMN. Whether a DN belongs to a PLMN is not a limitation of this application. The operator network PLMN can access multiple data network DNs 140. Multiple services may be deployed on the data network DN 140, and the data network DN 140 may provide data services, voice services, etc. for the terminal device 110. For example, the data network DN 140 may be a private network of a smart factory, and sensors installed in a workshop of the smart factory may be the terminal devices 110. A control server for the sensors may be deployed on the data network DN 140, and the control server may provide services for the sensors. The sensors may communicate with the control server to obtain instructions from the control server and, based on the instructions, transmit collected sensor data to the control server. In another example, data network DN 140 may be a company's internal office network, and the company's employee's mobile phone or computer may be the terminal device 110, which may access information, data resources, etc. within the company's internal office network. The terminal device 110 may establish a connection to the operator network through an interface (e.g., N1) provided by the operator network and use data services, voice services, etc. provided by the operator network. The terminal device 110 may further access the data network DN 140 through the operator network and use operator services deployed on the data network DN 140 and / or services provided by third parties.
[0122] Below we briefly explain the NF functions included in the CN.
[0123] 1. The UPF 130 is a gateway provided by an operator for communication between the operator network and the data network DN 140. The UPF network function 130 includes user plane related functions such as data packet routing and transmission, data packet detection, traffic usage reporting, quality of service (QoS) handling, lawful listening, uplink data packet detection, and downlink data packet storage.
[0124] 2. NEF 131 is a control plane function provided by the operator, mainly used to enable third parties to use services provided by the network, to support the network in unlocking network capabilities, event and data analysis, to translate security configuration information from external applications to the PLMN, to exchange information inside and outside the PLMN, to provide API interfaces opened by the operator network to the outside, to provide interaction between external servers and the internal operator network, etc.
[0125] 3. NRF 132 is a control plane function provided by an operator and may be configured to maintain real-time information of network functions and services within the network. For example, NRF 132 supports network service discovery, maintains services supported by NF configuration data (NF profiles) for NF instances, supports service discovery for service communication proxies (SCPs), maintains SCP configuration data (SCP profiles) for SCP instances, sends notifications about newly registered, deregistered, and updated NFs and SCPs, maintains the health status of NFs and SCPs, etc.
[0126] 4. The PCF 133 is a control plane function provided by the operator that supports a unified policy framework to govern network behavior and provide policy rules and subscription information related to policy decisions for other control functions.
[0127] 5. The UDM 134 is a control plane function provided by an operator and is responsible for storing a subscriber's subscription permanent identifier (SUPI), subscriber's generic public subscription identifier (GPSI), credentials, and other information in the operator network. The SUPI is first encrypted in the transmission process, and the encrypted SUPI is called a subscription concealed identifier (SUCI). The information stored in the UDM network function 134 can be used for authentication and authorization for accessing the operator network by the terminal device 110. A subscriber of the operator network may specifically be a user who uses a service provided by the operator network, for example, a user who uses a China Telecom subscriber identity module (SIM) card or a user who uses a China Mobile SIM card. The subscriber's credentials may be a long-term key stored on the SIM card or a small file stored therein, for example, information related to SIM card encryption, and are used for authentication and / or authorization. It should be noted that persistent identifiers, credentials, security contexts, authentication data (cookies), and tokens are equivalent to information related to verification / authentication and authorization, and are not limited or distinguished from one another for ease of explanation in embodiments of this application.
[0128] 6. UDR 135 is a control plane function provided by the operator, and provides functions to store and retrieve subscription data for UDM, store and retrieve policy data for PCF, and store and retrieve user NF group ID (group ID) information.
[0129] 7. NWDAF 136 is a control plane function provided by the operator. The main function of NWDAF 136 is to collect data from NFs, external application functions (AFs), operation, administration, and maintenance (OAM) systems, etc., and provide NWDAF service registration, data publication, data analysis, etc. to NFs and AFs.
[0130] 8. The AUSF 137 is a control plane function provided by an operator and is typically used for primary authentication, i.e., authentication between the terminal device 110 (subscriber) and the operator network. After receiving an authentication request initiated by a subscriber, the AUSF network function 137 may perform authentication and / or authorization for the subscriber by using authentication and / or authorization information stored in the UDM network function 134, or may generate authentication and / or authorization information for the subscriber through the UDM network function 134. The AUSF network function 137 may feed back the authentication and / or authorization information to the subscriber.
[0131] 9. AMF 138 is a control plane network function provided by the operator network that is responsible for access control and mobility management for access to the operator network by terminal devices 110, including functions such as mobility status management, allocation of temporary user identities, and user authentication and authorization.
[0132] The AMF 138 is configured to perform a Non-Access Stratum (NAS) connection to the UE and has the same 5G NAS security context as the UE. The 5G NAS security context includes the KAMF, the NAS stratum key, key identities identical to the NAS stratum key, UE security capabilities, and uplink and downlink NAS COUNT values. The NAS stratum key includes the NAS encryption key and the NAS integrity protection key used for NAS message confidentiality protection and NAS message integrity protection, respectively.
[0133] 10. The SMF 139 is a control plane network function provided by the operator network and is responsible for managing PDU sessions of the terminal device 110. A PDU session is a channel for the transmission of PDUs, and the terminal device and the data network DN 140 need to transmit PDUs to each other through the PDU session. The SMF network function 139 is responsible for establishing, maintaining, deleting, etc. the PDU session. The SMF network function 139 includes session-related functions such as session management (e.g., session establishment, modification, and release, including tunnel maintenance between the user plane function UPF 130 and the (R)AN 120), selection and control of the UPF network function 130, service and session continuity (SSC) mode selection, and roaming.
[0134] 11. The AF 141 is a control plane network function provided by the operator network and configured to provide application layer information. The AF 141 can interact with the policy framework through the network elements of the network exposure function or directly interact with the policy framework to make policy decision requests, etc. The AF 141 can be located inside or outside the operator network.
[0135] It may be understood that the aforementioned network elements or functions may be physical entities within a hardware device, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). In short, an NF may be realized by hardware or software.
[0136] In FIG. 1, Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nausf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface sequence numbers. For example, the meanings of interface sequence numbers may be referred to as those defined in the 3GPP standard protocol. The meanings of interface sequence numbers are not limited by this application. Note that the names of interfaces between network functions in the figure are merely examples. In specific implementations, the names of interfaces in the system architecture may alternatively be different names. This is not limited by this application. In addition, the names of messages (or signaling) whose transmissions are performed between the aforementioned network elements are merely examples and do not constitute any limitations on the functions of the messages.
[0137] For ease of explanation, in the embodiments of the present application, network functions (e.g., NEF 131, ..., and SMF 139) are collectively / simply referred to as NFs. In other words, the NFs described below in the embodiments of the present application may be replaced with any network functions. Also, FIG. 1 illustrates only some network functions as examples, and the NFs described below are not limited to the network functions illustrated in FIG. 1.
[0138] It should be understood that the above-described network architectures applicable to the embodiments of the present application are merely network architectures described from the perspective of a service-based architecture, and that the network architecture applicable to the embodiments of the present application is not limited thereto. Any network architecture capable of implementing the functionality of the above-described network elements is applicable to the embodiments of the present application.
[0139] It should be further understood that the AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown in the figure may be understood as network elements configured to implement different functions in the core network and may be combined as needed to form a network slice, for example. These core network elements may be independent devices or may be integrated into the same device to implement different functions. The specific form of the aforementioned network elements is not limited in this application.
[0140] It should be further understood that the above names are defined simply to facilitate distinguishing different functions and should not constitute any limitation to the present application. The present application does not exclude the possibility that other names will be used in 5G networks and other future networks. For example, in a 6G network, some or all of the above network elements may still use the 5G terminology or may use other names.
[0141] In particular, this application primarily relates to a non-public network location service (PNINPN location service) (sometimes referred to as local location) in a 5G system architecture, which is hereinafter referred to as PNINPN service for short. For ease of understanding, the following briefly describes the location service architecture in a PNINPN scenario with reference to FIG. 2. FIG. 2 is a diagram of the location service architecture in a PNINPN scenario according to an embodiment of the present application. It should be understood that the 5G system described herein is merely an example and should not constitute any limitation on the present application. The two networks described herein, a public network and a local network, are merely an example and should not constitute any limitation on the present application. For example, the two networks may alternatively be a first public network and a second public network.
[0142] As shown in Figure 2, the location service architecture in the PNINPN scenario may include, but is not limited to, the following parts:
[0143] UE, radio access networks (RANs) (e.g., NG-RAN#1, NG-RAN#2, and NG-RAN#3 shown in FIG. 2), and core network elements. User equipment includes devices to be located, and access networks may be configured to implement radio access-related functions. Core network elements may include, but are not limited to, a serving access and mobility management function (serving AMF) network element, a local access and mobility management function (local AMF) network element, a location management function (LMF) network element, a Gateway Mobile Location Center (GMLC), a unified data management (UDM), and a Mobile Location Service Client (Location Service, LCS client).
[0144] Note that the network elements shown in Figure 2 belong to two different networks (e.g., the public network and the local network shown in Figure 2). Specifically, the serving AMF and UDM are network elements in the public network, and the UE, RANs (NG-RAN#1, NG-RAN#2, and NG-RAN#3 shown in Figure 2), local AMF, LMF, GMLC, and LCS client belong to the local network.
[0145] It should be understood that the public network and the local network may include further network elements in addition to the network elements mentioned above. For example, the public network may further include an NEF, a UDR, an NWDAF, an AUSF, etc., and the local network may further include an AMF, an SMF, etc. Details will not be described again in this specification.
[0146] It should be further appreciated that a local network is a type of non-public network and may also be referred to as a campus network, non-public network, etc.
[0147] The following is a brief description of the network elements shown in FIG.
[0148] 1. For the UE, please refer to the description of the terminal device in Figure 1. The details will not be described again here. The UE may be a terminal device to be located (or ranged).
[0149] 2. For RAN devices, please refer to the description of (R)AN 120 in Figure 1. The details will not be described again here.
[0150] 3. The access and mobility management function includes the serving AMF and local AMF shown in Figure 2. Please refer to the description of AMF 138 in Figure 1.
[0151] In the location service, the AMF is configured to receive a location service request, select a gateway mobile location center network element, etc. In the PNINPN scenario, a local AMF is additionally deployed and configured to send location-related messages sent by the base station to the location management network element.
[0152] 4. The LMF is configured to receive a location request, determine a location method based on the UE and network capabilities, Quality of Service (QoS) requirements, and client type, exchange location-related information with the UE, base station, etc., calculate the location result, and perform verification on the location result. In the PNINPN scenario, the LMF is deployed on the local network, and location-related information is not exposed to the public network.
[0153] 5. The GMLC is the first network element through which an external location application accesses the core network and requests UE routing and privacy settings information from the UDM. In a PNINPN scenario, the GMLC is deployed on the local network.
[0154] 6. The LCS client is a third-party client (external client) that requests to obtain the user location. Alternatively, the external client may be replaced by an AF. The AF accesses the GMLC through the NEF interface. In the PNINPN scenario, the location service client is a location service client within the local network.
[0155] It may be understood that the aforementioned network elements or functions may be network elements within a hardware device, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform).
[0156] It should be noted that the names of the network elements and the names of the communication interfaces between the network elements in FIG. 2 are simply explained by using examples specified in current protocols. However, the embodiments of the present application are not limited to being applicable only to currently known communication systems. Therefore, the standard names used when current protocols are used as illustrative examples are all functional descriptions. The specific names of the network elements, interfaces, signaling, etc. are not limited in the present application and merely represent the functions of the network elements, interfaces, or signaling, and may be extended to accommodate other systems, for example, future communication systems.
[0157] In order to facilitate understanding of the technical solutions in the embodiments of the present application, the following briefly describes a location method for a non-public network-based location service based on FIG. 2 with reference to FIG.
[0158] 3 is a schematic flow chart of a location method, which includes the following steps:
[0159] S310: A location client (or application function network element) initiates a location service request to the GMLC.
[0160] Specifically, the location service request (LCS service request) carries the identity of the target UE, which may be a Generic Public Subscription Identifier (GPSI) or a Subscription Permanent Identifier (SUPI).
[0161] For example, a location client or application function network element may send a location service request directly to the GMLC, or may send a location request message to the GMLC through the NEF.
[0162] S320: The GMLC requests the privacy setting of the target UE from the UDM, and the UDM returns the privacy setting of the target UE to the GMLC.
[0163] For example, privacy settings include: (1) location is not permitted; (2) location determination is permissible and does not require notification to the user; (3) location determination must be permitted and users must be notified; (4) Location determination must be notified to and confirmed by the user, and location determination is permitted with the user's authorization or in the absence of a response; or (5) Location determination must be notified to and confirmed by the user, and location determination is permitted with the user's authorization.
[0164] The privacy settings may further include an effective time and effective geographic scope of the privacy settings.
[0165] S330: GMLC sends request message #1 to UDM.
[0166] The request message #1 carries the identification information of the target UE and is used to request obtaining the context management service of the UE. Specifically, the request message #1 is a Nudm_UEcontextmanagement_Get request message.
[0167] S340: UDM sends response message #1 to GMLC.
[0168] The response message #1 carries the network address of the serving AMF of the target UE. If the target UE's identity in step S330 is a GPSI, the response message #1 further includes the target UE's SUPI.
[0169] S350: The GMLC sends a location service request to the serving AMF.
[0170] Specifically, the GMLC sends a location service request to the serving AMF based on the network address of the serving AMF. The location service request carries the target UE's identity (SUPI) and location attribute information such as client type.
[0171] Based on the privacy setting of the target UE, the location service request may further include indication information #1.
[0172] For example, the indication information #1 may indicate one of the following: (1) Location determination is permissible and does not require notification to the user; (2) location determination must be permitted and users must be notified; (3) The location determination must be notified to and confirmed by the user, and if there is no response, the location determination is acceptable; or (4) The location determination must be notified to the user and confirmed by the user, and if there is no response, the location determination is not accepted.
[0173] S360: AMF triggers the paging procedure.
[0174] Optionally, when the target UE is in idle mode, the AMF initiates a network-triggered service request procedure to establish a connection between the network and the UE, i.e., the AMF triggers a paging procedure.
[0175] For example, when paging is successful, the AMF determines whether to notify the user and whether user confirmation is required based on indication information #1. When only notification is required, the AMF sends a NAS message to the target UE, and the message carries the identification information of the location client. When notification to the user is required and user confirmation is required, the message must further carry indication information #2 indicating that user confirmation is required.
[0176] The AMF receives the response message #2 of the target UE, and the response message #2 carries a location privacy indication, and the location privacy indication is (1) location is permitted, or (2) Location identification is not permitted It could be something like this.
[0177] Optionally, the response message #2 carries the applicable times of the location privacy directives, for example, the start time and end time.
[0178] S370:AMF selects LMF.
[0179] In the PNINPN scenario, the AMF selects an LMF in the local network based on configuration information.
[0180] S380: The AMF sends a location request message to the LMF.
[0181] The location request message (Nlmf_Location_DetermimeLocation Request) carries the identification information of the target UE, where the identifier is an identifier associated with location determination.
[0182] S390: The LMF sends a location response message to the AMF.
[0183] Specifically, after receiving the location request message sent by the AMF, the LMF may optionally trigger a location procedure. The LMF sends a location response message (LCS response) to the AMF based on the configuration information.
[0184] S391: The LMF sends a response message #3 (LCS service response) to the GMLC.
[0185] S392: The GMLC sends a response message #4 (LCS service response) to the location client or application function network element.
[0186] S393:LMF triggers location procedure.
[0187] In the PNINPN scenario, the location procedure is a network-assisted location method. The LMF selects an AMF in the public network to send UE-related NRPPa signaling messages. The LMF selects a local AMF to send non-UE-related NRPPa signaling messages. The local base station reports location-related parameters such as measurement reports to the local LMF through the local AMF, and the local LMF calculates the location of the target UE.
[0188] S394: The LMF sends a response message #5 (Nlmf_Location_EventNotify) to the GMLC.
[0189] Response message #5 carries the location of the target UE.
[0190] S395: The GMLC sends the measurement result (LCS service report) to the location client or application function network element to provide the location of the target UE.
[0191] In addition, the following several explanations are provided to facilitate understanding of the embodiments of the present application.
[0192] First, in this application, "indicate" can include "directly indicate" and "indirectly indicate." When a reference is described as indicating A, the reference may directly indicate A or indirectly indicate A, but does not necessarily mean that the reference includes A.
[0193] The information indicated by the indication information is called information to be indicated. In a specific implementation process, there are multiple ways to indicate the information to be indicated. The information to be indicated may be transmitted as a whole, or may be divided into multiple sub-information for separate transmission. Furthermore, the transmission periods and / or transmission opportunities of these sub-information may be the same or different. The specific transmission method is not limited in this application.
[0194] Second, in this application, "at least one" means one or more, and "multiple" means two or more. In addition, in the embodiments of this application, "first," "second," and various numbers (e.g., "#1" and "#2") are used merely for distinction purposes to facilitate description and are not intended to limit the scope of the embodiments of this application. Sequence numbers in the following processes do not indicate an execution sequence. The execution sequence of the processes should be determined based on the functions and internal logic of the processes and should not constitute any limitations on the implementation process of the embodiments of this application. It should be understood that the objects described in this manner may be interchangeable where appropriate, so that solutions other than the embodiments of this application may be described. In addition, in the embodiments of this application, words such as "310" and "320" are merely identifiers to facilitate description and do not limit the sequence in which steps are executed.
[0195] Third, terms such as "example" or "for example" are used herein to denote providing an example, illustration, or explanation. Any embodiment or design scheme described herein as an "example" or "for example" should not be described as being preferred or having more advantages over another embodiment or design scheme. Rather, the use of terms such as "example" or "for example" is intended to present relative concepts in a particular way.
[0196] Fourth, "stored" in the embodiments of the present application may refer to being stored in one or more memories. The one or more memories may be located separately or integrated into the encoder or decoder, processor, or communication device. Alternatively, a portion of the one or more memories may be located separately, and a portion of the one or more memories may be integrated into the decoder, processor, or communication device. The type of memory may be any form of storage medium. This is not limited in the present application.
[0197] Fifth, the term "and / or" in this specification is merely an associative relationship for describing related objects, and indicates that three relationships may exist. For example, A and / or B may indicate the following three cases: only A exists, both A and B exist, and only B exists. Furthermore, the symbol " / " in this specification generally indicates an "or" relationship between associated objects.
[0198] The above briefly describes scenarios in which the communication method provided in the embodiments of the present application can be applied with reference to FIG. 1 and FIG. 2, and describes the location method with reference to FIG.
[0199] From the location procedure shown in Figure 3, we can see that after receiving a location service request, the GMLC can obtain the privacy data of the terminal device from the UDM network element. The GMLC belongs to a non-public network, and the UDM belongs to a public network. The non-public network and the public network belong to different security domains (or network domains). In this location method, the non-public network can actively obtain user data in the public network through existing interfaces. This may cause the leakage of user data stored in the public network.
[0200] For example, the GMLC in the local network actively sends the UE's identity to the UDM in the public network, and the UDM returns the corresponding privacy setting to the UE. In addition, when the UE's identity is GPSI, the GMLC can also obtain the UE's SUPI, which can cause the leakage of user data stored in the public network.
[0201] In another example, the local network serves only UE 1 and UE 2, but a malicious GMLC network element may construct or obtain the identities of UEs other than UE 1 and UE 2 (e.g., UE 3 and UE 4) and further obtain the UE's privacy settings and / or SUPI, which may result in the leakage of user data stored in the public network.
[0202] It should be understood that if a GMLC network element in the local network is a malicious network element (e.g., the GMLC network element is captured), the attack mode is independent of the registration state of the UE and the attack is an independent procedure initiated by the network side.
[0203] In order to avoid leakage of user data stored in the public network, which may be caused by the aforementioned location procedure, the present application provides a communication method for ensuring that user data stored in the public network is not leaked.
[0204] It should be understood that the communication method provided in the embodiments of the present application may be applied to a location communication system for a location service based on a non-public network, for example, the communication architecture shown in FIG. 2 , or another location communication architecture for a location service based on a non-public network, or another communication architecture in which a network element in a local network obtains data of a terminal device from a public network in a hybrid networking scenario (e.g., a GMLC in a visited network actively obtains privacy settings of a terminal device from a GMLC in a home network). The application scenario is not limited in the present application, and any communication system including the functional network elements in the following embodiments may be used.
[0205] It should be further understood that the specific structure of the executing entity of the method provided in the embodiment of the present application is not particularly limited in the following embodiments, as long as a program in which the code of the method provided in the embodiment of the present application is recorded can be executed to perform communication according to the method provided in the embodiment of the present application. For example, the executing entity of the method provided in the embodiment of the present application may be a device, or a functional module that can call and execute a program in the device.
[0206] In the following, interactions between network elements are used as an example to describe in detail the communication method provided in the embodiments of the present application.
[0207] 4 is a schematic flowchart of a communication method according to the present application. The method is applied to hybrid networking including a first network and a second network. For example, the second network is a public network and the first network is a non-public network (e.g., a local network, a private network, or a campus network). In another example, the first network and the second network are different public networks (e.g., the first network is a home network and the second network is a visited network).
[0208] It should be understood that the public network, the non-public network, etc. are merely examples and do not constitute any limitation on the scope of protection of the present application. In this embodiment, the specific forms of the second network and the first network are not limited, and the second network and the first network may be different networks.
[0209] The communication method includes the following steps.
[0210] S410: The first network element receives a first request message from the second network element; in other words, the second network element sends the first request message to the first network element.
[0211] The first network element is a network element having a communication interface with the second network element, for example, a UDM, UDR, AUSF, or NWDAF in the second network.
[0212] The second network element is a network element that needs to obtain data of the terminal device, for example, a GMLC, an AMF, or an SMF in the first network.
[0213] For example, the first network element is a UDM in the second network and the second network element is a GMLC in the first network; the first network element is a UDR in the second network and the second network element is a GMLC in the first network; the first network element is an AUSF or NWDAF in the second network and the second network element is a GMLC in the first network; the first network element is a UDM in the second network and the second network element is an AMF in the first network; or the first network element is a UDM in the second network and the second network element is an SMF in the first network.
[0214] Specifically, the first request message includes an identifier of the terminal device, and the first request message is used to request acquisition of data of the terminal device. The identifier of the terminal device includes, but is not limited to, a GPSI or SUPI of the terminal device. The data of the terminal device includes, but is not limited to, a SUPI of the terminal device, a privacy setting of the terminal device, an address of an AMF serving the terminal device, etc.
[0215] In this embodiment, after receiving the first request message, the first network element does not directly provide the data of the terminal device to the second network element, but determines whether to send part or all of the data of the terminal device to the second network element based on a verification result, which indicates whether the first network is an authorized network for obtaining the data of the terminal device.
[0216] For example, in this embodiment, there are the following three aspects for determining the verification result.
[0217] Aspect 1: The first network element is a storage-capable network element in the second network that locally stores the subscription data of the terminal device and / or other configuration information required to determine the verification result (e.g., the first configuration information, the second configuration information, etc. described below). The storage-capable network element is a network element in the second network that provides the functionality to store and retrieve subscription data, including, but not limited to, a UDM, a UDR, etc. in the second network.
[0218] In this implementation, the first network element may determine a verification result indicating whether the first network is an authorized network for obtaining data of the terminal device based on the locally stored information. The method procedure shown in FIG. 4 further includes the following steps:
[0219] S411: The first network element determines a verification result based on locally stored information.
[0220] For example, the first network element determining the verification result based on the locally stored information in aspect 1 includes the following possibilities 1 to 3.
[0221] Possibility 1: The locally stored information includes subscription data of at least one terminal device, which includes a correspondence (for ease of explanation, hereinafter referred to as a first correspondence for short) between an identifier of the terminal device and an identifier of at least one network, which may be understood as a network from which the terminal device is (or is not) allowed to obtain data of the terminal device, or as a network from which the terminal device is (or is not) allowed to process data of the terminal device, or as a network to which the terminal device may (or may not) have access.
[0222] The identifier of the terminal device is a UE ID. The identifier of the network may be at network granularity, for example, a network identifier or a network name; or the identifier of the network may be at slice granularity, for example, a slice identifier. In this embodiment, the specific form of the identifier of the network is not limited as long as the identifier can identify the network.
[0223] Optionally, in the case shown in possibility 1, the primary key of the subscription data of the terminal device may be the UE ID. For example, a list of identifiers of networks allowed by the UE is stored, whereby the identifiers of the allowed networks can be obtained based on an index of the UE ID.
[0224] Optionally, in the case shown in possibility 1, the primary key of the list of identifiers of terminal devices that the network allows to obtain data may be the identifier of the network. For example, a list of IDs of UEs served by each network is stored, so that the UEs that the network allows to obtain data can be obtained based on the index of the identifier of the network.
[0225] As described above, in the case shown in Possibility 1, in addition to the conventional data of the terminal device (e.g., privacy information and SUPI), the subscription data of the terminal device stored in the first network element further includes a first correspondence, where the first correspondence indicates a network from which the data of the terminal device can be obtained. Thus, after receiving a request message to obtain the data of the terminal device, the first network element determines whether to provide the data of the terminal device based on the network to which the network element requesting to obtain the data belongs and the first correspondence.
[0226] In the case shown in Possibility 1, the first network element determining the verification result based on the locally stored information includes:
[0227] The first network element determines a verification result based on first information, the first information including subscription data of the terminal device and / or a list of identifiers of terminal devices that allow the first network to obtain data.
[0228] Optionally, when the first information is subscription data of the terminal device, and the subscription data of the terminal device includes a first correspondence, the first network element determining a verification result based on the first correspondence includes:
[0229] If the identifier of at least one network in the first correspondence is an identifier of a network that is allowed to obtain data of the terminal device, if the identifier of the first network is one of the identifiers of the at least one network, the first network element determines that the first network is a network that is allowed to obtain data of the terminal device; or if the identifier of the first network is not one of the identifiers of the at least one network, the first network element determines that the first network is a network that is not allowed to obtain data of the terminal device. For example, if the identifier of the first network is network #1 and the subscription data of the terminal device locally stored in the first network element includes a first correspondence between a UE ID and network #1 and network #2, the first network element determines that the first network is a network that is allowed to obtain data of the terminal device.
[0230] If the identifier of the at least one network in the first correspondence is an identifier of a network that is not allowed to obtain data of the terminal device, if the identifier of the first network is one of the identifiers of the at least one network, the first network element determines that the first network is a network that is not allowed to obtain data of the terminal device; or if the identifier of the first network is not one of the identifiers of the at least one network, the first network element determines that the first network is a network that is allowed to obtain data of the terminal device. For example, if the identifier of the first network is network #1 and the subscription data of the terminal device locally stored in the first network element includes a first correspondence between a UE ID and network #1 and network #2, the first network element determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0231] It should be understood that in this embodiment, the identifier of the first network may be determined in the following manner.
[0232] (1) The first request message carries an identifier of a first network to which the second network element belongs, and the first network element may determine information about the network to which the second network element belongs based on the first request message.
[0233] For example, the first request message carries a network identifier or a network name of the first network.
[0234] (2) The first network element determines an IP address of the second network element, and determines information about the network to which the second network element belongs based on the IP address of the second network element.
[0235] (3) The first network element determines information about the network to which the second network element belongs based on the certificate information of the second network element.
[0236] For example, the certificate of the second network element carries a network identifier. In the process of establishing a secure connection between the second network element and the first network element, the second NF obtains the certificate of the second network element, stores the associated network identifier, and determines information about the network to which the second network element belongs based on the network identifier in the certificate.
[0237] (4) The first network element determines information about the network to which the second network element belongs based on information sent by another network element (e.g., a gateway).
[0238] For example, a second network element is connected to a first network element through another network, and the other network element has the ability to sense information about the network to which the second network element belongs and reports the information about the network to which the second network element belongs to the first network element.
[0239] It should be understood that (1) to (4) are merely examples for explaining how the first network element obtains information about the network to which the second network element belongs, and do not constitute any limitation on the scope of protection of the present application. In this embodiment, the first network element may alternatively obtain information about the network to which the second network element belongs in another manner. For example, the first network element infers information about the network to which the second network element belongs based on historical communication data. Details will not be described again in this specification.
[0240] It should be further understood that in this implementation, before determining that verification needs to be performed, the first network element determines that the second network element and the first network element belong to different network or security domains. Specifically, if the second network element and the first network element belong to the same network domain (or security domain), the first network element may provide the terminal device data for the second network element in response to the first request message; or if the second network element and the first network element belong to different network domains (or security domains), the first network element needs to perform verification to determine whether to provide the terminal device data for the second network element.
[0241] For example, after determining the identifier of the first network, the first network element may determine that the second network element and the first network element belong to different network domains or security domains based on the identifier of the first network.
[0242] Optionally, when the first information is a list of identifiers of terminal devices that the first network allows to obtain data, the first network element determining a verification result based on the first information includes:
[0243] The first network element determines, based on the first correspondence in the subscription data of the at least one terminal device, a list of identifiers of terminal devices that the first network allows to obtain data from, and if the identifier of the terminal device is one of the list of identifiers of terminal devices that the first network allows to obtain data from, the first network element determines that the first network is a network that is allowed to obtain data from the terminal device; or if the identifier of the terminal device is not one of the list of identifiers of terminal devices that the first network allows to obtain data from, the first network element determines that the first network is a network that is not allowed to obtain data from the terminal device.
[0244] For example, the first network element locally stores subscription data for UE#1, UE#2, and UE#3. The subscription data for UE#1 includes a first correspondence between the UE#1 ID and network#1 and network#2, the subscription data for UE#2 includes a first correspondence between the UE#2 ID and network#2 and network#3, and the subscription data for UE#3 includes a first correspondence between the UE#3 ID and network#1 and network#2. If the identifier of the first network is network#1, the first network element determines, based on the first correspondence in the subscription data of the at least one terminal device, that the list of identifiers of terminal devices from which the first network is allowed to acquire data includes the UE#1 ID and the UE#3 ID. If the identifier of the terminal device is the UE#1 ID or the UE#3 ID, the first network element determines that the first network is a network from which the terminal device is allowed to acquire data.
[0245] Possibility 2: The locally stored information includes first configuration information and subscription data of at least one terminal device, the subscription data of the terminal device including information regarding the coverage of the data of the terminal device, and the first configuration information including information regarding the coverage of at least one network.
[0246] The coverage of the data of the terminal device may be understood as a service range to which the data of the terminal device is applicable, a coverage range to which the data of the terminal device is applicable, or another name. This is not limited in the embodiment. The coverage of the network may be understood as a service range provided by the network. The service range may be a network identifier such as a tracking area identifier or a cell identifier, or may be an identifier of a physical service area, for example, longitude and latitude.
[0247] As described above, in the case shown in Possibility 2, in addition to the conventional data of the terminal device (e.g., privacy information and SUPI), the subscription data of the terminal device stored in the first network element further includes information indicating the applicability of the data of the terminal device. Therefore, after receiving the request message for obtaining the data of the terminal device, the first network element determines whether to provide the data of the terminal device based on the applicability of the network to which the network element requesting to obtain the data belongs and the applicability of the data of the terminal device.
[0248] In the case shown in Possibility 2, the first network element determining the verification result based on locally stored information includes:
[0249] The first network element determines the coverage of the first network based on the first configuration information and the identifier of the first network, and determines a verification result based on the coverage of the data of the terminal device and the coverage of the first network.
[0250] For example, the data of the terminal device includes first data and second data, the application scope of the first data is a first range, and the application scope of the second data is a second range.
[0251] If an intersection set exists between the coverage area of the first network and the first range, the first network element determines that the first network is a network that is allowed to obtain the first data.
[0252] If an intersection set exists between the coverage area of the first network and the coverage area of the second network, the first network element determines that the first network is a network that is allowed to obtain the second data.
[0253] If there is an intersection set between the coverage area of the first network and each of the first range and the second range, the first network element determines that the first network is a network that is allowed to obtain the first data and the second data.
[0254] If there is no intersection set between the coverage of the first network and the coverage of the data of the terminal device, the first network element determines that the first network is a network that is not allowed to obtain data of the terminal device, or that the first network is allowed to obtain data of the default terminal device.
[0255] For example, first configuration information stored locally in a first network element indicates that the coverage of network #1 is range #1, the coverage of network #2 is range #2, and the coverage of network #3 is range #3. The subscription data of the terminal device indicates that the coverage of data #1 is range #11 and the coverage of data #2 is range #22. There is an intersection set between range #1 and range #11, and there is an intersection set between range #2 and range #22. If the identifier of the first network is network #1, the first network is a network that is allowed to obtain data #1.
[0256] Note that in the case shown in Possibility 2, the concept of a verification result does not need to be introduced. The locally stored information of the first network element includes first configuration information and subscription data of the at least one terminal device. The subscription data of the terminal device includes information about the coverage of the data of the terminal device. The first configuration information includes information about the coverage of the at least one network. After receiving the first request message, the first network element may directly determine the content of the data of the terminal device to be returned to the second network element based on the locally stored information. In this case, step S411 may be understood as determining, by the first network element, information to be transmitted to the second network element.
[0257] For example, first configuration information stored locally in a first network element indicates that the coverage of network #1 is range #1, the coverage of network #2 is range #2, and the coverage of network #3 is range #3. The subscription data of the terminal device indicates that the coverage of data #1 is range #11 and the coverage of data #2 is range #22. There is an intersection set between range #1 and range #11, and there is an intersection set between range #2 and range #22. If the identifier of the first network is network #1, the first network element decides to transmit data #1 to the second network element.
[0258] In another example, first configuration information stored locally in a first network element indicates that the coverage of Network #1 is Range #1, the coverage of Network #2 is Range #2, and the coverage of Network #3 is Range #3. The subscription data of the terminal device indicates that the coverage of Data #1 is Range #11 and the coverage of Data #2 is Range #22. There is an intersection set between Range #1 and Range #11, and there is an intersection set between Range #2 and Range #22. If the identifier of the first network is Network #3, the first network element determines, based on the preconfigured information, not to transmit data of the terminal device to the second network element or to transmit data of a default terminal device to the second network element.
[0259] Possibility 3: The locally stored information includes second configuration information, and the second configuration information includes a correspondence between an identifier of at least one network and an identifier of at least one mobility management network element in the second network (for ease of explanation, hereinafter referred to as a second correspondence for short). The mobility management network element in the embodiments of the present application is a network element that can implement access control and mobility management control functions for terminal devices to access an operator network, and may be, for example, the aforementioned AMF or another network element that can implement AMF functions.
[0260] In the case shown in Possibility 3, in addition to the conventional data of the terminal device (e.g., privacy information and SUPI), the subscription data of the terminal device stored in the first network element further includes a second correspondence, and the second correspondence indicates a mobility management network element that can acquire the data of the terminal device. Thus, after receiving the request message to acquire the data of the terminal device, the first network element determines whether to provide the data of the terminal device based on the mobility management network element corresponding to the network to which the network element requesting to acquire the data belongs and the second correspondence.
[0261] In the case shown in Possibility 3, the first network element determining the verification result based on locally stored information includes:
[0262] The first network element determines a mobility management network element corresponding to the first network based on the second configuration information and the identifier of the first network, and determines a verification result based on the mobility management network element serving the terminal device and the mobility management network element corresponding to the first network.
[0263] If the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, the first network element determines that the first network is a network that is allowed to obtain data of the terminal device; or if the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, the first network element determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0264] For example, the first configuration information stored locally in the first network element indicates that network #1 corresponds to AMF#1 and AMF#2 in the first network (i.e., there is an interface between network #1 and each of AMF#1 and AMF#2 in the first network, and there is no interface between network #1 and an AMF in another network), network #2 corresponds to AMF#2 in the first network, and network #3 corresponds to AMF#1 in the first network. If the mobility management network element serving the terminal device is AMF#1 and the identifier of the first network is network #1, the first network element determines that the first network is a network that is allowed to obtain data of the terminal device.
[0265] Note that in the case shown in Possibility 3, the concept of a verification result does not need to be introduced. After receiving the first request message, the first network element may determine whether to allow data of the terminal device to be transmitted to the first network based on locally stored information. In this case, step S411 may be understood as the first network element determining whether to allow data of the terminal device to be transmitted to the first network.
[0266] For example, if the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, the first network element determines to allow data of the terminal device to be transmitted to the first network.
[0267] In another example, if the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, the first network element determines not to allow data of the terminal device to be transmitted to the first network.
[0268] Aspect 2: The first network element is not a storage-capable network element in the first network (the first network element is a network element different from the UDM, for example, an AUSF or an NWDAF). The storage-capable network element locally stores information necessary for determining the verification result (e.g., the subscription data, first configuration information, and second configuration information of the terminal device shown in Aspect 1 above). The first network element obtains the information necessary for determining the verification result from the storage-capable network element via a request message, and then determines the verification result based on the obtained information.
[0269] For example, the first network element determining the verification result in aspect 2 includes the following possibilities 1 to 3.
[0270] Possibility 1: Corresponding to Possibility 1 of Aspect 1 above, the first network element obtains first information necessary for determining the verification result from the storage function network element via a request message, where the first information includes subscription data of the terminal device and / or a list of identifiers of terminal devices that allow the first network to obtain data. In the case shown in Possibility 1 of Aspect 2, the method procedure shown in Figure 4 further includes the following steps:
[0271] S421: The first network element sends a second request message to the storage function network element; in other words, the storage function network element receives the second request message from the first network element.
[0272] The second request message includes an identifier of the terminal device and / or an identifier of the first network, and the second request message is used to request to obtain the first information.
[0273] S422: The storage function network element determines first information.
[0274] Optionally, the second request message includes an identifier of the terminal device, and the storage function network element determines the subscription data of the terminal device based on the locally stored subscription data of the at least one terminal device and the identifier of the terminal device.
[0275] Optionally, the second request message includes an identifier of the first network, and the storage function network element determines a list of identifiers of terminal devices that allow the first network to obtain data based on the locally stored subscription data of the at least one terminal device and the identifier of the first network.
[0276] S423: The storage function network element sends the first information to the first network element; in other words, the first network element receives the first information from the storage function network element.
[0277] S424: The first network element determines a verification result based on the first information.
[0278] Specifically, for a description of determining the verification result by the first network element in the case shown in Possibility 1 of Aspect 2, please refer to the above description of Possibility 1 of Aspect 1. The details will not be described again herein.
[0279] Possibility 2: Corresponding to Possibility 2 of Aspect 1 above, the first network element obtains, from the storage function network element via a request message, subscription data of the terminal device necessary for determining the verification result and information regarding the coverage of the first network, where the coverage of the first network is determined by the storage function network element based on first configuration information, where the first configuration information includes information regarding the coverage of at least one network. In the case shown in Possibility 2 of Aspect 2, the method procedure shown in FIG. 4 further includes the following steps:
[0280] S431: The first network element sends a third request message and / or a fourth request message to the storage function network element; in other words, the storage function network element receives the third request message and / or the fourth request message from the first network element.
[0281] The third request message includes an identifier of the terminal device and is used to request obtaining subscription data of the terminal device. The fourth request message includes an identifier of the first network and is used to request obtaining information about coverage of the first network.
[0282] The third request message and the fourth request message may be the same or different request messages, and may be sent simultaneously or sequentially.
[0283] It should be understood that the coverage of the first network may be configured locally by the first network element, such that the first network element may not need to request to obtain information regarding the coverage of the first network via the fourth request message.
[0284] S432: The storage function network element determines subscription data of the terminal device and coverage of the first network.
[0285] The storage function network element determines subscription data of the terminal device based on the identifier of the terminal device included in the third request message, the locally stored subscription data of the at least one terminal device, and the identifier of the terminal device, in other words, determines information regarding the applicability of the data of the terminal device contained in the subscription data of the terminal device.
[0286] In addition, the storage function network element determines the coverage of the first network based on the identifier of the first network included in the fourth request message, the locally stored first configuration information, and the identifier of the first network.
[0287] S433: The storage function network element transmits the subscription data of the terminal device and information regarding the coverage of the first network to the first network element; in other words, the first network element receives the subscription data of the terminal device and information regarding the coverage of the first network from the storage function network element.
[0288] S434: The first network element determines a verification result based on the coverage of the data of the terminal device and the coverage of the first network.
[0289] Specifically, for a description of determining the verification result by the first network element in the case shown in Possibility 2 of Aspect 2, please refer to the above description of Possibility 2 of Aspect 1. The details will not be described again herein.
[0290] Possibility 3: Corresponding to Possibility 3 in Aspect 1 above, the first network element obtains, from the storage function network element via a request message, an identifier of a mobility management network element corresponding to the first network that is required to determine the verification result, and the mobility management network element corresponding to the first network is determined by the storage function network element based on second configuration information, and the second configuration information includes a correspondence between an identifier of the at least one network and an identifier of at least one mobility management network element in the second network. In the case shown in Possibility 3 of Aspect 2, the method procedure shown in FIG. 4 further includes the following steps.
[0291] S441: The first network element sends a fifth request message to the storage function network element; in other words, the storage function network element receives the fifth request message from the first network element.
[0292] The fifth request message includes an identifier of the first network, and the fifth request message is used to request to obtain an identifier of a mobility management network element corresponding to the first network.
[0293] S442: The storage function network element determines a mobility management network element corresponding to the first network.
[0294] The storage function network element determines a mobility management network element corresponding to the first network based on the locally stored second configuration information and the identifier of the first network.
[0295] S443: The storage function network element sends an identifier of the mobility management network element corresponding to the first network to the first network element; in other words, the first network element receives the identifier of the mobility management network element corresponding to the first network from the storage function network element.
[0296] S444: The first network element determines a verification result based on the mobility management network element serving the terminal device and the mobility management network element corresponding to the first network.
[0297] Specifically, for a description of determining the verification result by the first network element in the case shown in Possibility 3 of Aspect 2, please refer to the above description of Possibility 3 of Aspect 1. The details will not be described again herein.
[0298] Aspect 3: The first network element is not a storage-function network element in the first network, and the storage-function network element locally stores information necessary for determining the verification result (e.g., the subscription data, first configuration information, and second configuration information of the terminal device shown in Aspect 1 above). The first network element requests to obtain the verification result via a request message. This can be understood as the storage-function network element determining the verification result and providing the verification result for the first network element in Aspect 3. In this case, the method procedure shown in FIG. 4 further includes the following steps:
[0299] S451: The first network element sends a sixth request message to the storage function network element; in other words, the storage function network element receives the sixth request message from the first network element.
[0300] The sixth request message includes an identifier of the first network and / or an identifier of the target terminal device, and the sixth request message is used to request to obtain a verification result.
[0301] S452: The storage function network element determines the verification result.
[0302] Specifically, for how the storage function network element determines the verification result, please refer to the above description of Possibilities 1 to 3 of Aspect 1. The details will not be described again here.
[0303] S453: The storage function network element sends the verification result to the first network element; in other words, the first network element receives the verification result from the storage function network element.
[0304] In one possible implementation, after determining the verification result in aspects 1 to 3, the first network element may determine whether to provide some or all of the data of the terminal device to the second network element based on the verification result.
[0305] For example, if the verification result indicates that the first network is a network that is allowed to obtain data of the terminal device, the first network element decides to provide the data of the terminal device for the second network element based on the verification result.
[0306] In another example, if the verification result indicates that the first network is a network that is allowed to obtain the first data in the data of the terminal device, the first network element decides to provide the first data for the second network element based on the verification result.
[0307] In another possible implementation, in aspect 3, the storage function network element sends an instruction to the first network element indicating whether to provide some or all of the data of the terminal device for the second network element. In other words, in this implementation, after determining the verification result in aspect 3, the storage function network element may further determine whether to provide some or all of the data of the terminal device to the second network element based on the verification result, and notify the first network element through instruction information, so that the first network element sends a response to the second network element based on the instruction.
[0308] The method procedure shown in FIG. 4 further includes the following steps:
[0309] S420: The first network element sends a first response message to the second network element; in other words, the second network element receives the first response message from the first network element.
[0310] Specifically, the information carried in the first response message is determined based on the verification result.
[0311] In one possible implementation, when the first network is a network that is allowed to obtain data of the terminal device, the first response message includes some or all of the data of the terminal device.
[0312] For example, if the verification result indicates that the first network is a network that is allowed to obtain the first data in the data of the terminal device, the first response message includes the first data.
[0313] In another possible implementation, when the first network is not allowed to acquire data of the terminal device, the first response message is used to refuse to provide data of the terminal device. In this implementation, the first response message may be understood as a refusal message, and the refusal message may include information indicating the cause of the refusal.
[0314] In yet another possible implementation, when the first network is not allowed to acquire data of the terminal device, the first response message includes the GPSI or pseudonym of the terminal device, where the pseudonym is generated by the first network element or the storage function network element, and the first network element or the storage function network element stores the correspondence between the SUPI / GPSI and the pseudonym.
[0315] The embodiment shown in Figure 4 may be applied to the location scenario shown in Figure 2. For example, the second network is a public network, the first network is a local network, the first network element is a UDM in the second network, and the second network element is a GMLC in the first network. In the following, with reference to a specific example, we will explain how to perform location in the location scenario while ensuring that user data stored in the public network is not leaked.
[0316] Example 1: Figure 5 is a diagram of a communication method applied to a location scenario according to an embodiment of the present application. The method includes the following steps:
[0317] S510: A location client (or application function network element) initiates a location service request to the GMLC.
[0318] Specifically, the location service request (LCS service request) carries the identification information of the target UE, which may be the GPSI or SUPI of the target UE.
[0319] For example, a location client or application function network element may send a location service request directly to the GMLC, or may send a location request message to the GMLC through the NEF.
[0320] S520: The GMLC sends a first request message to the UDM; in other words, the UDM receives the first request message from the GMLC.
[0321] Specifically, the first request message is used to request data of the target UE. The data of the target UE includes, but is not limited to, one or more of the following: the SUPI of the target UE, the privacy setting of the target UE, or the address of the AMF serving the target UE. For a description of the first request message, please refer to the description of the first request message in step S410 of the communication method in FIG. 4. Details will not be described again in this specification.
[0322] For example, the first request message is a Nudm_SDM_Get or Nudm_UECM_Get request message.
[0323] S530: The UDM determines whether to provide data for the target UE based on locally stored information.
[0324] For example, in this embodiment, assuming that the first network to which the GMLC belongs and the second network to which the UDM belongs are determined to be in different network domains or security domains, the UDM further determines whether to provide data for the target UE.
[0325] For example, before the UDM determines whether to provide data to the target UE, the UDM determines that the GMLC and the UDM belong to different network or security domains. A GMLC and a UDM belonging to different network domains can be understood as the identifier of the network to which the GMLC belongs being different from the identifier of the network to which the UDM belongs. Security domains are an effective way to divide the entire system from a security perspective and implement security level protection for large, complex information systems. A GMLC and a UDM belonging to different security domains can be understood as the GMLC and the UDM belonging to different security levels.
[0326] Optionally, when the GMLC and the UDM belong to different network domains, the GMLC and the UDM belong to different security domains; or when the GMLC and the UDM belong to the same network domain but have different security levels, the GMLC and the UDM belong to different security domains. When the UDM and the GMLC belong to different network domains (security domains), if the GMLC directly obtains the target UE's data from the UDM through the interface between the GMLC and the UDM and the UDM directly provides the target UE's data, the target UE's data may be leaked and security cannot be guaranteed. Therefore, in this embodiment, when the UDM determines that the UDM and the GMLC belong to different security domains, the UDM must further determine whether to provide the target UE's data.
[0327] For example, in this embodiment, the UDM may determine that the UDM and the GMLC belong to different network domains in some implementations below.
[0328] In one possible implementation, the UDM determines that the GMLC and the UDM belong to different network domains based on the first network identifier included in the first request message.
[0329] In another possible implementation, the UDM first determines an identifier of the first network based on the IP address of the GMLC, and then determines that the GMLC and the UDM belong to different network domains based on the identifier of the first network.
[0330] In yet another possible implementation, the UDM first determines an identifier of the first network based on the GMLC's certificate, and then determines that the GMLC and the UDM belong to different network domains based on the identifier of the first network.
[0331] For example, the GMLC's certificate carries an identifier of the first network. In the process of establishing a secure connection between the UDM and the GMLC, the UDM obtains the GMLC's certificate, stores the identifier of the first network, and determines information about the first network to which the GMLC belongs based on the identifier of the first network in the certificate.
[0332] In yet another possible implementation, the UDM determines information about the network to which the GMLC belongs based on information sent by another network element (eg, a gateway).
[0333] For example, the GMLC is connected to the UDM through another network element that has the ability to sense information about the network to which the GMLC belongs and reports information about the first network to which the GMLC belongs to the UDM.
[0334] Corresponding to the embodiment shown in FIG. 4, in this embodiment, the UDM's determination of whether to provide data for the target UE based on locally stored information includes the following three possibilities:
[0335] Possibility 1: The UDM determines whether the first network is a network that is allowed to obtain data for the terminal device based on local configuration information, where the configuration information includes a list of identifiers of networks that are allowed to obtain data for the terminal device.
[0336] Specifically, in the case shown in Possibility 1, in response to the first request message, the UDM determines whether the first network is an allowed network to obtain the data of the target UE, and obtains a determination result, where the determination result indicates whether the first network is an allowed network to obtain the data of the target UE. Furthermore, after obtaining the determination result, the first network element determines whether to transmit the data of the target UE to the GMLC based on the determination result.
[0337] If the identifier of the first network belongs to the list of identifiers of networks that are allowed to obtain data of the terminal device, the UDM determines that the first network is a network that is allowed to obtain data of the terminal device; or If the identifier of the first network does not belong to the list of identifiers of networks that are allowed to obtain data of the terminal device, the UDM determines that the first network is a network that is not allowed to obtain data of the terminal device.
[0338] Optionally, the local configuration information further comprises a list of identifiers of terminal devices that the network allows to obtain data from.
[0339] If the identifier of the target terminal device belongs to the list of identifiers of terminal devices that the first network allows to obtain data from, the UDM determines that the first network is a network that is allowed to obtain data of the terminal device; or If the identifier of the target terminal device does not belong to the list of identifiers of terminal devices that the first network allows to obtain data from, the UDM determines that the first network is a network that is not allowed to obtain data from the terminal device.
[0340] For ease of understanding, the following will use a specific example to explain how the UDM determines whether to provide data of the target terminal device for GMLC in the case shown in Possibility 1.
[0341] For example, the local network may be a corporate campus network that provides services only for the company's employees and devices. The company may provide an association between the local network identifier and the UE (e.g., UE#2 and UE#3) identifiers of the company's employees and devices, and the association is stored in the UDM in the public network. If a UE (e.g., UE#1) is not a user of the local network, there is no association or affiliation between the UE#1 identifier and the local network identifier. When the GMLC requests data for UE#1 via the first request message, the UDM determines, based on the subscription data, that there is no association / affiliation between UE#1 and the local network and refuses to send the UE data for UE#1 to the GMLC. When the GMLC requests data for UE#3 via the first request message, the UDM determines, based on the subscription data, that there is an association / affiliation between UE#3 and the local network and sends the UE data for UE#3 to the GMLC.
[0342] Possibility 2: The UDM determines the information to be included in the first response message sent to the GMLC based on the data coverage of the terminal device and the coverage of the first network.
[0343] For example, the data of the target terminal device includes data #1 and data #2, the coverage of data #1 is range #1, the coverage of data #2 is range #2, and the coverage of the first network is range #3.
[0344] If there is an intersection between Range #3 and Range #1, the UDM determines that the first response message contains Data #1.
[0345] If there is an intersection between Range #3 and Range #2, the UDM determines that the first response message contains Data #2.
[0346] If there is an intersection between Range #3 and each of Range #1 and Range #2, the UDM determines that the first response message includes Data #1 and Data #2.
[0347] If there is no intersection set between Range #3 and each of Range #1 and Range #2, the UDM determines that the first response message contains information regarding a refusal to provide data for the target terminal device.
[0348] For ease of understanding, the following will use a specific example to explain how the UDM determines whether to provide data of the target terminal device for GMLC in the case shown in Possibility 2.
[0349] For example, the local network is a corporate campus network, and the network coverage area is Range #1. The corporate network can provide a binding relationship between the local network identifier and Range #1, and the binding relationship is stored in the UDM in the public network. In addition, the UDM in the public network further stores a binding relationship between the identifier of at least one UE and the coverage area of the data of the UE. When the local network requests to obtain data of a UE (e.g., UE #1), the UDM determines the coverage area of the data of UE #1 based on the binding relationship between the identifier of UE #1 and the coverage area of the data of the UE (e.g., the coverage area of UE #1's data #1 is Range #1, and the coverage area of UE #1's data #2 is Range #2). Based on the local network identifier and the UE#1 identifier, the UDM determines that there is an intersection between the coverage of the local network and the coverage of data #1 of UE#1, and decides to provide data #1 of UE#1 for GMLC; based on the local network identifier and the UE#1 identifier, the UDM determines that there is an intersection between the coverage of the local network and the coverage of data #2 of UE#1, and decides to provide data #2 of UE#1 for GMLC; or, based on the local network identifier and the UE#1 identifier, the UDM determines that there is no intersection between the coverage of the local network and each of the coverage of data #1 of UE#1 and the coverage of data #2 of UE#1, and decides not to provide data of UE#1 for GMLC.
[0350] Possibility 3: The UDM determines whether to allow data of the target terminal device to be transmitted to the first network based on an AMF serving the target terminal device and an AMF corresponding to the first network, where the AMF corresponding to the first network is determined based on second configuration information, and the second configuration information includes a correspondence between an identifier of the at least one network and an identifier of at least one mobility management network element in the second network.
[0351] If the AMF serving the target terminal device is a subset of the AMF corresponding to the first network, the UDM determines to allow data of the target terminal device to be transmitted to the first network; or
[0352] If the AMF serving the target terminal device is not a subset of the AMF corresponding to the first network, the UDM determines not to allow data of the target terminal device to be transmitted to the first network.
[0353] For ease of understanding, the following will use a specific example to explain how the UDM determines whether to provide data of the target terminal device for GMLC in the case shown in Possibility 3.
[0354] For example, the local network is a campus network of an enterprise, and the enterprise can provide an association relationship between the local network identifier and AMF#1 in the public network, and the association relationship is stored in the UDM in the public network. When the local network requests to obtain data of a UE (e.g., UE#1), the UDM determines that the AMF serving UE#1 is AMF#2 and refuses to send the UE data of UE#1 to the GMLC because there is no intersection set between AMF#1 and AMF#2; or the UDM determines that the AMF serving UE#1 is AMF#1 and sends the UE data of UE#1 to the GMLC because there is no intersection set between AMF#1 and AMF#1.
[0355] S540: The UDM sends a first response message to the GMLC; in other words, the GMLC receives the first response message from the UDM.
[0356] For example, the first response message is a Nudm_SDM_Get or Nudm_UECM_Get response message. If the first response message contains the data of the target UE, please refer to the description of the current prior art for the subsequent location procedure, which is not limited in this application.
[0357] If the first response message does not include the data of the target UE, or if the first response message is a rejection message or carries a rejection indication, the location is terminated.
[0358] In the location procedure shown in FIG. 5, before providing the data for the GMLC, the UDM needs to perform verification based on locally stored information (e.g., the subscription data of the terminal device, the first configuration information, or the second configuration information), and provides the data for the GMLC only when the GMLC can obtain the data of the terminal device, thereby allowing the GMLC to obtain only a portion of the UE's data and avoiding data leakage. Note that the example shown in FIG. 5 is merely for ease of understanding and does not constitute any limitation on scenarios to which the communication method provided herein can be applied. The communication method provided herein can also be used in another scenario requiring a second network element in a first network to obtain user data in a second network. Details are not described herein.
[0359] It should be understood that the sequence numbers of the above processes do not mean the execution sequence, and the execution sequence of the processes should be determined based on the functions and internal logic of those processes, and should not be construed as any limitation on the implementation process of the embodiments of the present application.
[0360] It should be further understood that in the embodiments of the present application, unless otherwise specified or there is no logical contradiction, the terms and / or descriptions in different embodiments are consistent and may be cross-referenced, and the technical features in different embodiments may be combined based on their internal logical relationships to form new embodiments.
[0361] It should be further understood that in some of the above-described embodiments, devices in existing network architectures (e.g., GMLC or UDM) are primarily used as examples for explanation. It should be understood that the specific form of the device is not limited to the embodiments of the present application. For example, all devices that can implement the same functions in the future are applicable to the embodiments of the present application.
[0362] In the above method embodiments, it may be understood that the methods and operations performed by the UDM may be performed by components that may be used for the UDM, and the methods and operations performed by the GMLC may be performed by components that may be used for the GMLC.
[0363] The above describes in detail the communication method provided in the embodiment of the present application with reference to Figures 4 and 5. The above communication method is mainly described in terms of interactions between terminal devices. It can be understood that to implement the above functions, the terminal device includes corresponding hardware structures and / or software modules for performing the functions.
[0364] Those skilled in the art should be able to recognize that the present application can be implemented by hardware or a combination of hardware and computer software, in combination with the example units and algorithm steps described in the embodiments disclosed herein. Whether the functions are performed by hardware or by hardware driven by computer software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for specific applications, but such implementation should not be considered to go beyond the scope of the present application.
[0365] The following describes in detail the communication device provided in the embodiments of the present application with reference to Figures 6 to 8. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for the content not described in detail, please refer to the above-mentioned method embodiment. For the sake of brevity, some of the content will not be described again.
[0366] In the embodiments of the present application, the functional modules of the transmitter device or the receiver device may be obtained through division based on the above-mentioned method examples. For example, each functional module may be obtained through division based on each function, or two or more functions may be integrated into one processing module. The integrated module may be implemented in the form of hardware or in the form of a software functional module. It should be noted that in the embodiments of the present application, the module division is an example and is merely a logical functional division. In actual implementation, other division methods may be used. In the following, an explanation is provided by using an example in which each functional module is obtained through division based on each corresponding function.
[0367] 6 is a block diagram of a communication device 10 according to an embodiment of the present application. The device 10 includes a transceiver module 11 and a processing module 12. The transceiver module 11 can implement corresponding communication functions. The processing module 12 is configured to perform data processing. In other words, the transceiver module 11 is configured to perform operations related to reception and transmission, and the processing module 12 is configured to perform operations other than reception and transmission. The transceiver module 11 may also be referred to as a communication interface or a communication unit.
[0368] Optionally, the apparatus 10 may further include a storage module 13. The storage module 13 may be configured to store instructions and / or data. The processing module 12 may read the instructions and / or data in the storage module to enable the apparatus to perform the device or network element operations in the method embodiments described above.
[0369] In a first design, device 10 may correspond to or be a component (eg, a chip) of a GMLC in the method embodiments described above.
[0370] The device 10 may implement corresponding steps or procedures performed by the GMLC in the aforementioned method embodiments. The transceiver module 11 may be configured to perform the reception and transmission-related operations of the GMLC in the aforementioned method embodiments. The processing module 12 may be configured to perform the processing-related operations of the GMLC in the aforementioned method embodiments.
[0371] In one possible implementation, the transceiver module 11 is configured to send a first request message to a storage function network element in the second network, the first request message including an identifier of the terminal device, the first request message being used to request retrieval of data of the terminal device; the transceiver module 11 is further configured to receive a first response message from the storage function network element in the second network, the information included in the first response message including data of the terminal device, denial information, or a publicly available subscription identifier (GPSI) or pseudonym of the terminal device.
[0372] When the device 10 is configured to perform the method of FIG. 4, the transceiver module 11 may be configured to perform the information transmitting steps of the method, e.g., steps S410 and S420, and the processing module 12 may be configured to perform the processing steps of the method.
[0373] When device 10 is configured to perform the method of FIG. 5, transceiver module 11 may be configured to perform the information transmitting steps of the method, e.g., steps S510, S520, and S540, and processing module 12 may be configured to perform the processing steps of the method.
[0374] It should be understood that the specific processes by which the units perform the aforementioned corresponding steps have been described in detail in the aforementioned method embodiments, and for the sake of brevity, the details will not be described again herein.
[0375] In a second design, apparatus 10 may correspond to or be a component (eg, a chip) of a UDM in the method embodiments described above.
[0376] The device 10 may implement corresponding steps or procedures performed by the UDM in the aforementioned method embodiments. The transceiver module 11 may be configured to perform reception- and transmission-related operations of the UDM in the aforementioned method embodiments. The processing module 12 may be configured to perform processing-related operations of the UDM in the aforementioned method embodiments.
[0377] In one possible implementation, the transceiver module 11 is configured to receive a first request message from a gateway mobile location center GMLC in a first network, the first request message including an identifier of a terminal device, the first request message being used to request retrieval of data of the terminal device; the processing module 12 is configured to determine, in response to the first request message, whether the first network is a network that is allowed to retrieve data of the terminal device; the processing module 12 is further configured to determine, based on the determination result, whether to transmit data of the terminal device to the GMLC.
[0378] When apparatus 10 is configured to perform the method of FIG. 4, transceiver module 11 may be configured to perform the information receiving and transmitting steps of the method, e.g., steps S410, S421, S423, S431, S433, S441, S443, S451, S453, and S420, and processing module 12 may be configured to perform the processing steps of the method, e.g., steps S411, S422, S424, S432, S434, S442, S444, and S452.
[0379] When device 10 is configured to perform the method of FIG. 5, transceiver module 11 may be configured to perform the information receiving and transmitting steps of the method, e.g., steps S520 and S540, and processing module 12 may be configured to perform the processing steps of the method, e.g., step S530.
[0380] It should be understood that the specific processes by which the units perform the aforementioned corresponding steps have been described in detail in the aforementioned method embodiments, and for the sake of brevity, the details will not be described again herein.
[0381] It should be further understood that the apparatus 10 herein is embodied in the form of a functional module. The term "module" herein may refer to an application-specific integrated circuit (ASIC), an electronic circuit, a processor (e.g., a shared processor, a dedicated processor, or a group processor) configured to execute one or more software or firmware programs, a memory, a merge logic circuit, and / or another suitable component supporting the described functionality. In an optional example, those skilled in the art will understand that the apparatus 10 may specifically be a mobility management network element in the aforementioned embodiments and may be configured to perform procedures and / or steps corresponding to the mobility management network element in the aforementioned method embodiments. Alternatively, the apparatus 10 may specifically be a terminal device in the aforementioned embodiments and may be configured to perform procedures and / or steps corresponding to the terminal device in the aforementioned method embodiments. To avoid repetition, details will not be described again here.
[0382] The device 10 in the above solution has a function of performing corresponding steps performed by a network element (e.g., a first network element or a second network element) in the above method. The function may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above function. For example, a transceiver module may be replaced with a transceiver (e.g., a transmitting unit in a transceiver module may be replaced with a transmitter, and a receiving unit in a transceiver module may be replaced with a receiver), and another unit such as a processing module may be replaced with a processor to perform receiving and transmitting operations and processing-related operations in the method embodiments, respectively.
[0383] Additionally, the transceiver module 11 may alternatively be a transceiver circuit (eg, may include a receiving circuit and a transmitting circuit), and the processing module may be a processing circuit.
[0384] 7 is a diagram of another communication device 20 according to an embodiment of the present application. The device 20 includes a processor 21. The processor 21 is configured to execute computer programs or instructions stored in a memory 22 or to read data / signaling stored in the memory 22 to perform the method in the above-described method embodiments. Optionally, there may be one or more processors 21.
[0385] Optionally, as shown in Figure 7, the device 20 further includes a memory 22 configured to store computer programs or instructions and / or data. The memory 22 and the processor 21 may be integrated or may be located separately. Optionally, there are one or more memories 22.
[0386] Optionally, as shown in Figure 7, the device 20 further includes a transceiver 23. The transceiver 23 is configured to receive and / or transmit signals. For example, the processor 21 is configured to control the transceiver 23 to receive and / or transmit signals.
[0387] In one solution, the device 20 is configured to implement the operations performed by the GMLC in the above-described method embodiments.
[0388] In another solution, the device 20 is configured to implement the operations performed by the UDM in the above-described method embodiments.
[0389] It is understood that the processor in embodiments of the present application may be a central processing unit (CPU), or may be another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.
[0390] It should be further understood that the memory in the embodiments of the present application may be volatile and / or non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM). For example, RAM may be used as an external cache. By way of example and not limitation, RAM includes multiple forms such as static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchlink dynamic random access memory (synchlink DRAM, SLDRAM), and direct rambus random access memory (direct rambus RAM, DR RAM).
[0391] It should be noted that when the processor is a general-purpose processor, a DSP, an ASIC, an FPGA or another programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, the memory (storage module) may be integrated into the processor.
[0392] It should be further noted that memory as described herein is intended to include, without being limited to, these and any other suitable types of memory.
[0393] 8 is a diagram of a chip system 30 according to an embodiment of the present application. The chip system 30 (which may also be referred to as a processing system) includes a logic circuit 31 and an input / output interface 32.
[0394] The logic circuit 31 may be a processing circuit within the chip system 30. The logic circuit 31 is coupled to a storage unit and can call instructions in the storage unit, so that the chip system 30 can implement the methods and functions in the embodiments of the present application. The input / output interface 32 may be an input / output circuit within the chip system 30, which outputs information processed by the chip system 30 or inputs data or signaling information to be processed into the chip system 30 for processing.
[0395] In one solution, the chip system 30 is configured to implement the operations performed by the GMLC in the method embodiments described above.
[0396] For example, the logic circuitry 31 is configured to implement the processing-related operations performed by the GMLC in the aforementioned method embodiments, and the input / output interface 32 is configured to implement the transmission and / or reception-related operations performed by the GMLC in the aforementioned method embodiments.
[0397] In another solution, the chip system 30 is configured to implement the operations performed by the UDM in the method embodiments described above.
[0398] For example, logic circuitry 31 is configured to implement processing-related operations performed by the UDM in the aforementioned method embodiments, and input / output interface 32 is configured to implement transmission and / or reception-related operations performed by the UDM in the aforementioned method embodiments.
[0399] An embodiment of the present application further provides a computer-readable storage medium, which stores computer instructions for implementing the method performed by the network element in the aforementioned method embodiment.
[0400] For example, when the computer program is executed by a computer, it enables the computer to perform the methods performed by GMLC or UDM in the above-described method embodiments.
[0401] Certain embodiments of the present application further provide a computer program product including instructions that, when executed by a computer, implement the method performed by a device (e.g., a GMLC or a UDM) in the aforementioned method embodiments.
[0402] An embodiment of the present application further provides a communication system including the aforementioned GMLC and UDM.
[0403] For the description of the relevant contents and beneficial effects of any one of the above-provided devices, please refer to the corresponding method embodiments provided above, and the details will not be described again in this specification.
[0404] In some embodiments provided herein, it should be understood that the disclosed devices and methods may be implemented in other ways. For example, the device embodiments described are merely examples. For example, the division into units is merely a logical division of function, and other divisions may be used in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not implemented. In addition, the shown or described mutual couplings or direct couplings or communication connections may be implemented through some interfaces. Indirect couplings or communication connections between devices or units may be implemented in electronic, mechanical, or other forms.
[0405] All or part of the above-described embodiments may be implemented using software, hardware, firmware, or any combination thereof. When software is used to implement an embodiment, all or part of the embodiment may be implemented in the form of a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the procedures or functions described in the embodiments herein are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or another programmable device. For example, the computer may be a personal computer, a server, a network device, etc. The computer instructions may be stored in a computer-readable storage medium or transmitted from a computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optics, or digital subscriber line (DSL)) or wireless (e.g., infrared, radio waves, microwaves, etc.) methods. The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device that integrates one or more available media, such as a server or a data center. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a DVD), a semiconductor medium (e.g., a solid-state disk (SSD)), etc. For example, the available medium may include, but is not limited to, any medium that can store program code, such as a USB flash drive, a removable hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0406] The above description is merely a specific implementation of the present application and is not intended to limit the scope of protection of the present application. Any modifications or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in the present application shall fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the scope of protection of the claims.
Claims
1. 1. A method of communication comprising: sending, by a gateway mobile location center in a first network, a first request message to a storage function network element in a second network, the first request message including an identifier of a terminal device, the first request message being used to request obtaining data of the terminal device; determining, by the storage function network element, in response to the first request message, whether the first network is an authorized network for obtaining the data of the terminal device; determining, by the storage function network element, whether to transmit the data of the terminal device to the gateway mobile location center based on the determination result; A method comprising:
2. Before determining, by the storage function network element, whether the first network is a network that is allowed to obtain the data of the terminal device, the method includes: determining, by the storage function network element, that the gateway mobile location center and the storage function network element belong to different network domains; The method of claim 1.
3. Determining, by the storage function network element, that the gateway mobile location center and the storage function network element belong to different network domains includes: determining, by the storage function network element, based on the identifier of the first network included in the first request message, that the gateway mobile location center and the storage function network element belong to different network domains; determining, by the storage function network element, an identifier of the first network based on an Internet Protocol address of the gateway mobile location center, and determining, based on the first network identifier, that the gateway mobile location center and the storage function network element belong to different network domains; or determining, by the storage function network element, an identifier of the first network based on a certificate of the gateway mobile location center; and determining, based on the identifier of the first network, that the gateway mobile location center and the storage function network element belong to different network domains; including one of the following: The method of claim 2.
4. Determining, by the storage function network element, whether the first network is an allowed network for obtaining the data of the terminal device: determining, by the storage function network element, whether the first network is a network that is permitted to obtain the data of the terminal device based on local configuration information, the configuration information including a list of identifiers of networks that are permitted to obtain the data of the terminal device; 4. The method according to any one of claims 1 to 3.
5. determining, by the storage function network element, based on the local configuration information, whether the first network is an allowed network from which to obtain the data of the terminal device; determining, by the storage function network element, that the first network is a network that is allowed to obtain the data of the terminal device if the identifier of the first network belongs to the list of identifiers of networks that are allowed to obtain the data of the terminal device; or If the identifier of the first network does not belong to the list of identifiers of networks that are allowed to obtain the data of the terminal device, determining by the storage function network element that the first network is a network that is not allowed to obtain the data of the terminal device; The method of claim 4.
6. Determining, by the storage function network element, whether the first network is an allowed network for obtaining the data of the terminal device: determining, by the storage function network element, whether the first network is a network that is allowed to acquire the data of the terminal device based on a correspondence between a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network; 4. The method according to any one of claims 1 to 3.
7. determining, by the storage function network element, whether the first network is a network allowed to obtain the data of the terminal device based on a correspondence between a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network; If the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, determining by the storage function network element that the first network is an allowed network from which the data of the terminal device is obtained; or When the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, determining by the storage function network element that the first network is an unauthorized network for obtaining the data of the terminal device; The method of claim 6.
8. determining, by the storage function network element, based on the determination result, whether to transmit the data of the terminal device to the gateway mobile location center: and refusing, by the storage function network element, to transmit the data of the terminal device to the gateway mobile location center when the determination result is that the first network is not permitted to acquire the data of the terminal device.
8. The method according to any one of claims 1 to 7.
9. determining, by the storage function network element, based on the determination result, whether to transmit the data of the terminal device to the gateway mobile location center: When the determination result is that the first network is not permitted to acquire the data of the terminal device, transmitting, by the storage function network element, a publicly accessible subscription identifier (GPSI) or a pseudonym of the terminal device to the gateway mobile location center; 8. The method according to any one of claims 1 to 7.
10. determining, by the storage function network element, based on the determination result, whether to transmit the data of the terminal device to the gateway mobile location center: When the determination result is that the first network is a network that is allowed to obtain the data of the terminal device, transmitting the data of the terminal device to the gateway mobile location center by the storage function network element; 8. The method according to any one of claims 1 to 7.
11. The data of the terminal device is: a subscription permanent identifier of the terminal device, a privacy setting of the terminal device, or an address of a mobility management network element serving the terminal device 11. The method according to claim 1, further comprising at least one of:
12. 12. The method according to any one of claims 1 to 11, wherein the second network is a public network and the first network is a local network.
13. The method of claim 1 , wherein the first request message includes an identifier of the first network.
14. Before sending the first request message by the gateway mobile location center to the storage function network element, the method includes: receiving, by the gateway mobile location center, a location service request from a mobile location service client, the location service request including an identifier of the terminal device; 14. The method according to any one of claims 1 to 13.
15. 1. A method of communication comprising: receiving, by a storage function network element in a second network, a first request message from a gateway mobile location center in a first network, the first request message including an identifier of a terminal device, the first request message being used to request obtaining data of the terminal device; determining, by the storage function network element, in response to the first request message, whether the first network is an authorized network for obtaining the data of the terminal device; determining, by the storage function network element, whether to transmit the data of the terminal device to the gateway mobile location center based on the determination result; A method comprising:
16. Before determining, by the storage function network element, whether the first network is a network that is allowed to obtain the data of the terminal device, the method includes: determining, by the storage function network element, that the gateway mobile location center and the storage function network element belong to different network domains; 16. The method of claim 15.
17. Determining, by the storage function network element, that the gateway mobile location center and the storage function network element belong to different network domains includes: determining, by the storage function network element, based on the identifier of the first network included in the first request message, that the gateway mobile location center and the storage function network element belong to different network domains; determining, by the storage function network element, an identifier of the first network based on an Internet Protocol address of the gateway mobile location center, and determining, based on the first network identifier, that the gateway mobile location center and the storage function network element belong to different network domains; or determining, by the storage function network element, an identifier of the first network based on a certificate of the gateway mobile location center; and determining, based on the identifier of the first network, that the gateway mobile location center and the storage function network element belong to different network domains; including one of the following:
17. The method of claim 16.
18. Determining, by the storage function network element, whether the first network is an allowed network for obtaining the data of the terminal device: determining, by the storage function network element, whether the first network is a network that is permitted to obtain the data of the terminal device based on local configuration information, the configuration information including a list of identifiers of networks that are permitted to obtain the data of the terminal device; 18. The method according to any one of claims 15 to 17.
19. determining, by the storage function network element, based on the local configuration information, whether the first network is an allowed network from which to obtain the data of the terminal device; determining, by the storage function network element, if the identifier of the first network belongs to the list of identifiers of networks that are allowed to obtain the data of the terminal device, that the first network is an allowed network from which the data of the terminal device is obtained; or If the identifier of the first network does not belong to the list of identifiers of networks that are allowed to obtain the data of the terminal device, determining by the storage function network element that the first network is a network that is not allowed to obtain the data of the terminal device; 20. The method of claim 18.
20. Determining, by the storage function network element, whether the first network is an allowed network for obtaining the data of the terminal device: determining, by the storage function network element, whether the first network is a network that is allowed to acquire the data of the terminal device based on a correspondence between a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network; 18. The method according to any one of claims 15 to 17.
21. determining, by the storage function network element, whether the first network is a network allowed to obtain the data of the terminal device based on a correspondence between a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network; If the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, determining by the storage function network element that the first network is an allowed network from which the data of the terminal device is obtained; or When the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network, determining by the storage function network element that the first network is an unauthorized network for obtaining the data of the terminal device; 21. The method of claim 20.
22. determining, by the storage function network element, based on the determination result, whether to transmit the data of the terminal device to the gateway mobile location center: and refusing, by the storage function network element, to transmit the data of the terminal device to the gateway mobile location center when the determination result is that the first network is not permitted to acquire the data of the terminal device.
22. The method of any one of claims 15 to 21.
23. determining, by the storage function network element, based on the determination result, whether to transmit the data of the terminal device to the gateway mobile location center: When the determination result is that the first network is not authorized to acquire the data of the terminal device, transmitting, by the storage function network element, a public subscription identifier or a pseudonym of the terminal device to the gateway mobile location center; 22. The method of any one of claims 15 to 21.
24. determining, by the storage function network element, based on the determination result, whether to transmit the data of the terminal device to the gateway mobile location center: When the determination result is that the first network is a network that is allowed to obtain the data of the terminal device, transmitting the data of the terminal device to the gateway mobile location center by the storage function network element; 22. The method of any one of claims 15 to 21.
25. The data of the terminal device is: a subscription permanent identifier of the terminal device, a privacy setting of the terminal device, or an address of a mobility management network element serving the terminal device 25. The method of any one of claims 15 to 24, comprising at least one of:
26. 25. The method of any one of claims 15 to 24, wherein the second network is a public network and the first network is a local network.
27. 26. The method of claim 15, wherein the first request message includes an identifier of the first network.
28. 1. A method of communication comprising: receiving, by a first network element in a second network, a first request message from a second network element in the first network, the first request message including an identifier of a terminal device, the first request message being used to request obtaining data of the terminal device; sending, by the first network element, a first response message to the second network element in response to the first request message, wherein information included in the first response message is determined based on a verification result, the verification result indicating whether the first network is an authorized network for obtaining the data of the terminal device; A method comprising:
29. 29. The method of claim 28, wherein when the first network is a network that is not allowed to obtain the data of the terminal device, the first response message is used to refuse to provide the data of the terminal device.
30. 30. The method of claim 28 or 29, wherein when the first network is a network that is not authorized to obtain the data of the terminal device, the first response message includes a public public subscription identifier (GPSI) or a pseudonym of the terminal device.
31. 31. The method of claim 28, wherein before sending the first response message to the second network element by the first network element, the method further comprises: determining, by the first network element, the verification result; or receiving, by the first network element, the verification result from a storage function network element in the second network.
32. Determining the verification result by the first network element includes: determining, by the first network element, the verification result based on first information, the first information comprising subscription data of the terminal device and / or a list of identifiers of terminal devices from which the first network allows data to be obtained, the subscription data of the terminal device comprising a correspondence between the identifier of the terminal device and an identifier of at least one network, the at least one network being a network from which the terminal device is allowed to obtain the data; 32. The method of claim 31 .
33. Before determining the verification result by the first network element, the method further comprises: sending, by the first network element, a second request message to the storage function network element in the second network, the second request message including an identifier of the terminal device and / or an identifier of the second network, the second request message being used to request obtaining the first information; and receiving, by the first network element, the first information from the storage function network element.
33. The method of claim 32, comprising:
34. Determining the verification result based on the subscription data of the terminal device by the first network element includes: If the identifier of the first network is one of the identifiers of the at least one network, determining by the first network element that the first network is an allowed network from which the terminal device can obtain the data; If the identifier of the first network is not one of the identifiers of the at least one network, determining by the first network element that the first network is an unauthorized network through which the terminal device obtains the data; determining, by the first network element, that the first network is an allowed network from which the terminal device obtains the data if the identifier of the terminal device is one of a list of identifiers of terminal devices from which the first network allows the terminal device to obtain data; or determining, by the first network element, if the identifier of the terminal device is not one of a list of identifiers of terminal devices that the first network allows to obtain data from, that the first network is not allowed to obtain the data of the terminal device; 34. The method of claim 32 or 33.
35. Determining the verification result by the first network element includes: determining, by the first network element, the verification result based on a coverage of the data of the terminal device and a coverage of the first network, wherein the subscription data of the terminal device includes information on a coverage of the data of the terminal device, and the coverage of the first network is determined based on first configuration information, wherein the first configuration information includes information on a coverage of at least one network; 35. The method of claim 34.
36. Before determining the verification result by the first network element, the method further comprises: sending, by the first network element, a third request message to the storage function network element in the second network, the third request message including an identifier of the terminal device, the third request message being used to request obtaining the subscription data of the terminal device; receiving, by the first network element, the subscription data of the terminal device from the storage function network element; 36. The method of claim 35, comprising:
37. Before determining the verification result by the first network element, the method further comprises: sending, by the first network element, a fourth request message to the storage function network element in the second network, the fourth request message including an identifier of the first network, the fourth request message being used to request obtaining information about coverage of the first network; receiving, by the first network element, the information regarding coverage of the first network from the storage function network element; 37. The method of claim 36, comprising:
38. The data of the terminal device includes first data and second data, an application scope of the first data is a first range, and an application scope of the second data is a second range, and determining, by the first network element, the verification result based on the application scope of the data of the terminal device and the application scope of the first network element includes: If an intersection exists between the coverage range of the first network and the first range, determining by the first network element that the first network is an allowed network for obtaining the first data, and the first response message includes the first data; If an intersection exists between the coverage area of the first network and the second coverage area, determining by the first network element that the first network is an allowed network for obtaining the second data, and the first response message includes the second data; If there is an intersection set between the coverage range of the first network and each of the first range and the second range, the first network element determines that the first network is an allowed network for obtaining the first data and the second data, and the first response message includes the first data and the second data; or If there is no intersection set between the coverage of the first network and the coverage of the data of the terminal device, determining by the first network element that the first network is a network that is not allowed to obtain the data of the terminal device.
38. The method of any one of claims 35 to 37, comprising:
39. Determining, by the first network element, the verification result includes: determining, by the first network element, the verification result based on a mobility management network element serving the terminal device and a mobility management network element corresponding to the first network, wherein the mobility management network element corresponding to the first network is determined based on second configuration information, and the second configuration information includes a correspondence between an identifier of at least one network and an identifier of at least one mobility management network element in the second network; 39. The method of claim 38.
40. Before determining the verification result by the first network element, the method further comprises: sending, by the first network element, a fifth request message to the storage function network element in the second network, the fifth request message including an identifier of the first network, the fifth request message being used to request obtaining an identifier of a mobility management network element corresponding to the first network; receiving, by the first network element, from the storage function network element, an identifier of a mobility management network element corresponding to the first network; 40. The method of claim 39, comprising:
41. Determining, by the first network element, the verification result based on a relationship between a mobility management network element corresponding to the first network and a mobility management network element serving the terminal device includes: If the mobility management network element serving the terminal device is a subset of the mobility management network elements corresponding to the first network, determining by the first network element that the first network is an allowed network from which the data of the terminal device is obtained; or determining, by the first network element, that the first network is not an authorized network for obtaining the data of the terminal device, if the mobility management network element serving the terminal device is not a subset of the mobility management network elements corresponding to the first network; 41. The method of claim 39 or 40.
42. Before receiving the verification result from a storage function network element in the first network by the first network element, the method further comprises: sending a sixth request message to the storage function network element by the first network element, wherein the sixth request message includes an identifier of the first network and / or an identifier of the target terminal device, and the sixth request message is used to request obtaining the verification result; 42. The method of any one of claims 39 to 41.
43. The data of the terminal device is: a subscription permanent identifier SUPI of the terminal device, a privacy setting of the terminal device, or a mobility management network element serving the terminal device 43. The method of any one of claims 28 to 42, comprising at least one of:
44. 44. The method of any one of claims 28 to 43, wherein the second network is a public network and the first network is a local network.
45. 45. The method of claim 28, wherein the first network element is a unified data management function network element, an authentication server function network element, or a network data analysis function network element; and the second network element is a gateway mobile location center, a mobility management function network element, or a session management function network element.
46. 46. A communications device configured to perform the steps performed by the storage function network element in the method of any one of claims 1 to 45.
47. 1. A communications device comprising: a memory configured to store a computer program; and a processor configured to execute the computer program stored in the memory to enable the communication device to perform the steps performed by the storage function network element in the method of any one of claims 1 to 45, Communication equipment.
48. 46. A computer-readable storage medium having stored thereon computer instructions which, when executed on a computer, cause the steps performed by the storage function network element in the method of any one of claims 1 to 45 to be performed.
49. 46. A computer program product comprising instructions used to carry out the steps performed by said storage function network element in the method of any one of claims 1 to 45.
Citation Information
Patent Citations
Positioning system
JP2009124756A
Privacy Control for User Equipment and Associated Devices - Patent application
JP2022522742A
Method and apparatus for improvements in and relating to localisation in mobile communication system
WO2022173255A1