Information processing method, device and communication device

By controlling data passage using PDR and FAR, the method addresses DNS query failures over restricted channels, ensuring successful remote configuration by allowing essential data to pass while discarding irrelevant data, thus preventing service disruptions.

JP7769004B2Active Publication Date: 2025-11-12VIVO MOBILE COMM CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023559815
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-04-06
Filing Date
2022-04-06
Publication Date
2025-11-12
Estimated Expiration
2042-04-06

AI Technical Summary

Technical Problem

Existing systems fail to efficiently handle DNS query data over restricted data channels, leading to query data being discarded, which results in service failures during remote configuration processes.

Method used

Implementing a method and apparatus that control data passage by determining and transmitting policy information to allow or discard data related to domain name server address and configuration server address, and data related to a domain name server address, and data related to a configuration server address, while discarding data not related to these addresses, using Packet Detection Rules (PDR) and Forwarding Action Rules (FAR) to manage data flow through User Plane Function (UPF).

Benefits of technology

Ensures successful passage of DNS and configuration server data, preventing query failures and ensuring seamless remote configuration processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007769004000001
    Figure 0007769004000001
  • Figure 0007769004000002
    Figure 0007769004000002
  • Figure 0007769004000003
    Figure 0007769004000003
Patent Text Reader

Abstract

The present application provides an information processing method, an apparatus and a communication device, belonging to the field of communication technology, the information processing method including: obtaining first information including at least one of domain name server address information and configuration server address information; and performing a first operation based on the first information, the first operation including determining first policy information and / or sending the first policy information for determining the first information or a first rule of data processing, the first rule of data processing being used to perform data passage-related control on the first data and / or second data, the first data being related to the domain name server address and / or the configuration server address, and the second data being not related to the domain name server address and / or the configuration server address, and / or not the first data.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority from Chinese Patent Application No. 202110369534.1 filed in China on April 6, 2021, the entire contents of which are incorporated herein by reference.

[0002] The present application belongs to the field of communication technology, and specifically relates to an information processing method, apparatus and communication device. [Background technology]

[0003] If a User Equipment (UE) only establishes a restricted data channel, when the UE needs to query DNS domain name information from a Domain Name Server (DNS), the DNS query data sent by the UE to the DNS server will be discarded. Summary of the Invention [Problem to be solved by the invention]

[0004] The embodiments of the present application provide an information processing method, an apparatus, and a communication device that can solve the problem existing in the related art that DNS query data is discarded. [Means for solving the problem]

[0005] According to a first aspect, there is provided an information processing method for use in a first communication device, the information processing method comprising: obtaining first information including at least one of domain name server address information and configuration server address information; and performing a first operation based on the first information, wherein the first operation comprises: determining first policy information; transmitting the first information or the first policy information; wherein the first policy information is used to determine a first rule of data processing, and the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; The first data includes at least one of data related to a domain name server address and data related to a configuration server address, and the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data.

[0006] According to a second aspect, there is provided a first communications device, the first communications device comprising: a first obtaining module for obtaining first information including at least one of domain name server address information and configuration server address information; a first execution module for executing a first operation based on the first information, wherein the first operation includes: determining first policy information; transmitting the first information or the first policy information; wherein the first policy information is used to determine a first rule of data processing, and the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; The second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data.

[0007] According to a third aspect, there is provided an information processing method for use in a second communication device, the information processing method comprising: obtaining second information including at least one of the first information and first policy information; and performing a second operation based on the second information, wherein the second operation comprises: determining the first rules for data processing; transmitting the first information or the first rule of data processing; wherein the first rule of data processing is used to perform data passing-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0008] According to a fourth aspect, there is provided a second communications device, the second communications device comprising: a second acquiring module for acquiring second information including at least one of the first information and the first policy information; a second execution module for executing a second operation based on the second information, wherein the second operation comprises: determining the first rules for data processing; transmitting the first information or the first rule of data processing; wherein the first rule of data processing is used to perform data passing-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0009] According to a fifth aspect, there is provided an information processing method for use in a third communication device, the information processing method comprising: obtaining third information including at least one of the first information and a first rule of data processing; and performing a third operation based on the third information, wherein the third operation comprises: determining a first rule for the data processing based on the first information; and performing a data passing-related control on the first data and / or the second data based on the received or determined first rule of data processing; wherein the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0010] According to a sixth aspect, there is provided a third communications device, the third communications device comprising: a third acquiring module for acquiring third information including at least one of the first information and the first rule of data processing; and a third execution module for performing a third operation based on the third information, wherein the third operation includes: determining a first rule for the data processing based on the first information; and performing a data passing-related control on the first data and / or the second data based on the received or determined first rule of data processing; wherein the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0011] According to a seventh aspect, there is provided an information processing method for use in the fourth communication device, the information processing method comprising: transmitting first information; Here, the first information includes at least one of domain name server address information and configuration server address information.

[0012] According to an eighth aspect, there is provided a fourth communication device, the fourth communication device comprising: a fourth transmitting module for transmitting the first information; Here, the first information includes at least one of domain name server address information and configuration server address information.

[0013] According to a ninth aspect, there is provided a network side device, the network side device including a processor, a memory, and a program or instructions stored in the memory and operable to run on the processor, the program or instructions, when executed by the processor, implementing the steps of the method according to the first aspect, or the program or instructions, when executed by the processor, implementing the steps of the method according to the third aspect, or the program or instructions, when executed by the processor, implementing the steps of the method according to the fifth aspect.

[0014] According to a tenth aspect, there is provided a network side device, the network side device including a processor and a communication interface; the communication interface is used to obtain first information including at least one of domain name server address information and configuration server address information; The processor is adapted to perform a first operation based on the first information, wherein the first operation comprises: determining first policy information; and controlling the communication interface to transmit the first information or the first policy information; wherein the first policy information is used to determine a first rule of data processing, and the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address, and the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; or the communication interface is used to obtain second information including at least one of first information and first policy information; The processor is adapted to perform a second operation based on the second information, wherein the second operation comprises: determining the first rules for data processing; and controlling the communication interface to transmit the first information or the first rule of the data processing; wherein the first rule of data processing is used to perform data passing-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; the first information includes at least one of domain name server address information and configuration server address information; or the communication interface is used to acquire third information including at least one of first information and a first rule of data processing; The processor is adapted to perform a third operation based on the third information, wherein the third operation comprises: determining a first rule for the data processing based on the first information; and performing a data passing-related control on the first data and / or the second data based on the received or determined first rule of data processing; wherein the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0015] According to an eleventh aspect, there is provided a terminal including a processor, a memory, and a program or instructions stored in the memory and operable to run on the processor, the program or instructions, when executed by the processor, implementing the steps of the method of the seventh aspect.

[0016] According to a twelfth aspect, there is provided a terminal, the terminal including a processor and a communication interface; the communication interface is used to transmit first information; Here, the first information includes at least one of domain name server address information and configuration server address information.

[0017] According to a thirteenth aspect, there is provided a configuration method, the configuration method comprising: The method includes a session management function entity (SMF) sending a data processing rule or a rule parameter for forming the data processing rule, the data processing rule being used to perform a data passage control operation on data related to a domain name query in at least a remote configuration process and / or related to the remote configuration.

[0018] According to a fourteenth aspect, there is provided a configuration method, the configuration method comprising: The method includes a Policy Control Function (PCF) sending rule parameters for forming a data processing rule or a policy carrying the rule parameters, the data processing rule being used to perform a data passage control operation on data related to at least a domain name query in a remote configuration process and / or related to the remote configuration.

[0019] According to a fifteenth aspect, there is provided a data control method, the data control method comprising: The method includes a User Plane Function (UPF) performing a data passage control operation on at least data related to a domain name query in a remote configuration process and / or data related to remote configuration based on a data processing rule.

[0020] According to a sixteenth aspect, there is provided a readable storage medium having a program or instructions stored on the readable storage medium, which, when executed by a processor, performs the steps of the method according to the first aspect, or performs the steps of the method according to the third aspect, or performs the steps of the method according to the fifth aspect, or performs the steps of the method according to the seventh aspect, or performs the steps of the method according to the thirteenth aspect, or performs the steps of the method according to the fourteenth aspect, or performs the steps of the method according to the fifteenth aspect.

[0021] According to a seventeenth aspect, there is provided a chip, the chip including a processor and a communication interface, the communication interface coupled to the processor, the processor running a program or instructions and used to implement the method of the first aspect, or to implement the method of the third aspect, or to implement the method of the fifth aspect, or to implement the method of the seventh aspect, or to implement the method of the thirteenth aspect, or to implement the method of the fourteenth aspect, or to implement the method of the fifteenth aspect.

[0022] According to an eighteenth aspect, there is provided a computer program / program product, the computer program / program product being stored in a non-volatile storage medium, the program / program product being executed by at least one processor to implement the steps of the information processing method described in the first aspect, or to implement the steps of the information processing method described in the third aspect, or to implement the steps of the information processing method described in the fifth aspect, or to implement the steps of the information processing method described in the seventh aspect, or to implement the steps of the configuration method described in the thirteenth aspect, or to implement the steps of the configuration method described in the fourteenth aspect, or to implement the steps of the data control method described in the fifteenth aspect. [Effects of the Invention]

[0023] In an embodiment of the present application, a first communication device includes: obtaining first information including at least one of domain name server address information and configuration server address information; and performing a first operation based on the first information, wherein the first operation includes at least one of determining first policy information and transmitting the first information or the first policy information, wherein the first policy information is used to determine a first rule of data processing, and the first rule of data processing is used to perform data passing-related control on first data and / or second data, wherein the first data includes at least one of data related to a domain name server address and data related to a configuration server address, and the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data. The embodiment of the present application can pass data related to a domain name query and / or related to a configuration server. [Brief explanation of the drawings]

[0024] [Figure 1] 1 is a block diagram of a wireless communication system to which an embodiment of the present application can be applied. [Figure 2]1 is a flowchart of an information processing method according to an embodiment of the present application. [Figure 3] 4 is a flowchart of another information processing method according to an embodiment of the present application. [Figure 4] 4 is a flowchart of another information processing method according to an embodiment of the present application. [Figure 5] 4 is a flowchart of another information processing method according to an embodiment of the present application. [Figure 6a] This is a schematic diagram of data interactions in SMF application scenario 1. [Figure 6b] This is a schematic diagram of data interactions in SMF application scenario 2. [Figure 7] FIG. 2 is a structural diagram of a first communication device according to an embodiment of the present application; [Figure 8] FIG. 2 is a structural diagram of a second communication device according to an embodiment of the present application; [Figure 9] FIG. 10 is a structural diagram of a third communication device according to an embodiment of the present application; [Figure 10] FIG. 10 is a structural diagram of a fourth communication device according to an embodiment of the present application; [Figure 11] 1 is a structural diagram of a communication device according to an embodiment of the present application; [Figure 12] FIG. 2 is a structural diagram of a terminal according to an embodiment of the present application; [Figure 13] FIG. 2 is a structural diagram of a network-side device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0025] The following clearly describes the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application, and it is obvious that the described embodiments are only some of the embodiments of the present application, and not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present application fall within the scope of protection of the present application.

[0026] The terms "first," "second," etc. in the specification and claims of this application are intended to distinguish between similar objects and are not intended to describe a particular order or sequence. It should be understood that terms used in this manner are interchangeable where appropriate, so that embodiments of this application may be performed in orders other than those illustrated or described herein, and that objects distinguished by "first" and "second" are generally of the same type and do not limit the number of objects; for example, a first object may be one or more. Furthermore, "and / or" in the specification and claims indicates at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the related objects.

[0027] It should be noted that the techniques described in the embodiments of the present application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be applied to other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), and other systems. The terms "system" and "network" in the embodiments of the present application are always used interchangeably, and the described techniques may be used in the above-mentioned systems and radio technologies as well as other systems and radio technologies. Although the following description describes New Radio (NR) systems for illustrative purposes and uses NR terminology in most of the following description, these technologies may also be used in applications other than NR system applications, such as sixth generation (6G) systems.th This may be applied to 6G (6th Generation) communication systems.

[0028] In order to better understand the embodiments of the present application, the following technical points will be introduced first.

[0029] The terminal accesses a network (Onboarding network) by a first access method (e.g., Onboarding), and the first access method (e.g., Onboarding) includes at least one of an access method of accessing the first network to download a certificate for accessing a second network, an access method of accessing the first network without having a certificate for accessing the first network, an access method in which only restricted services can be used, and an access method in which the certificate for the terminal to access the first network is a default certificate.

[0030] The first network and the second network may be the same network or different networks.

[0031] Remote provisioning (also called remote configuration) refers to the process by which a terminal accesses a current network (onboarding network) to obtain information such as certificates or subscriptions for a target stand-alone non-public network (SNPN) or a public network integrated non-public network (Public Network Integrated Non-Public Network).

[0032] Currently, after completing the first access method, the terminal may perform remote provisioning using a user plane scheme, i.e., it is dedicated to establishing a restricted data channel and remotely provisioning subscription information for the UE, and the subscription information is not only used for primary authentication, but also for secondary authentication and network slice-specific authentication and authorization (NSSAA), etc.

[0033] After the establishment of the restricted data channel is completed, the UE may still not have a remote configuration server address, so the UE needs to use a Fully Qualified Domain Name (FQDN) to discover the remote configuration server address. When the UE uses an FQDN to discover the remote configuration server address, it needs to send a DNS query request to the DNS server to obtain the remote configuration server address.

[0034] The problem of how to allow DNS query data to pass through a restricted data channel must be solved.

[0035] As can be seen from the above, when the UE performs remote configuration, if the UE does not obtain the remote configuration server address after establishing a restricted Protocol Data Unit (PDU) session, the UE needs to use the FQDN to discover the remote configuration server address, which means that the UE needs to perform a DNS query, and because the UE only establishes a restricted PDU session, the DNS query data sent from the UE will be discarded, resulting in a DNS query failure.

[0036] The examples of the present application can solve the above technical problems by the following embodiments.

[0037] In one embodiment, the UE sends first information to the SMF, where the first information includes a DNS and / or a remote configuration server (Provisioning Server, PVS) address; the SMF generates policy information (e.g., a Packet Detection Rule (PDR) and / or a Forwarding Action Rule (FAR) corresponding to the PDR) based on the first information, and sends the policy information to the UPF; In another embodiment, the SMF locally configures the first information, and the SMF generates a first rule for data processing (such as a PDR and / or a FAR corresponding to the PDR) based on the first information and sends it to the UPF; In another embodiment, the SMF receives first policy information from the PCF; the SMF generates first rules for data processing (e.g., a PDR and / or a FAR corresponding to the PDR) based on the first policy information, and sends them to the UPF; In another embodiment, the SMF sends the first information to the UPF.

[0038] According to the above embodiment, the UPF performs an operation to restrict the passage of data, and the operation to restrict the passage of data includes at least one of allowing only the first data to pass and not allowing or discarding data other than the first data (second data). The target or source of the first data includes at least one of a DNS server and a configuration server.

[0039] the configuration server includes a server for configuring certificates and / or subscription information for terminals; The credentials and / or subscription information may be at least one of a credentials and / or subscription information for a primary authentication and / or authorization credential and / or subscription to access a first subject, and a non-primary authentication and / or authorization credential and / or subscription information; The non-primary authentication and / or authorization includes at least one of a secondary authentication and / or authorization and a secondary authentication and / or authorization associated with a slice; The first object includes a slice of the network, a Domain Name (DN), and a network.

[0040] The network type includes at least one of an SNPN, a public network integrated NPN (PNI-NPN), and a public land mobile network (PLMN).

[0041] The target address or source address of the first data includes at least one of DNS server address information and configuration server address information.

[0042] The second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data.

[0043] It should be explained that performing a permissive operation on the first data and / or performing a non-permissive operation on the second data may include: allowing only data related to the domain name query and data related to a remote configuration query to pass; and not allowing any other data to pass through other than data related to said domain name query and data related to said remote configuration query. and discarding data other than data related to the domain name query and data related to the remote configuration query.

[0044] In one embodiment, data related to a domain name server address means data in which the source address or the target address is a domain name server address; In one embodiment, data related to a configuration server address means data in which the source address or the target address is a configuration server address; In one embodiment, the data not related to a domain name server address includes data where the source address or target address is not a domain name server; In one embodiment, data not associated with a configuration server address means data whose source address or target address is not a configuration server address; In one embodiment, the configuration server includes at least one of a PVS and a Subscription Owner; In one embodiment, the first policy information includes a Policy Control and Charging (PCC) rule, and the gateway state corresponding to the corresponding domain name server address or / and configuration server address in the PCC rule is on or off.

[0045] In one embodiment, the data detection rules include PDRs; In one embodiment, the data transfer rule includes a FAR, for example, two addresses in the FAR are set to pass, and a PDR is not required for the second data, making it easy to understand that data that does not correspond to a PDR is discarded. Therefore, the second data is discarded based on the rule.

[0046] In one embodiment, the access method of obtaining a certificate and / or a subscription to access the network includes an access method of obtaining a certificate and / or a subscription remotely to access the network.

[0047] In one embodiment, the restricted data channel includes at least one of a data channel that allows passage of a first data and a data channel that does not allow passage of a second data.

[0048] In one embodiment, the data channel comprises a PDU session.

[0049] In one embodiment, the first access method includes onboarding.

[0050] The first access method (e.g., Onboarding) includes at least one of an access method of accessing the first network to download a certificate for accessing the second network, an access method of accessing the first network without a certificate for accessing the first network, an access method in which only limited services can be used, and an access method in which the certificate for the terminal to access the first network is a default certificate. The first network and the second network may be the same network or different networks.

[0051] The first rule of the data processing relates to at least address information of a domain name query server.

[0052] The first rule of data processing also relates to address information of a remote configuration server and is used to perform a data passing operation on data associated with a remote configuration query.

[0053] In one embodiment, the second communication device (eg, SMF) receives the first information from the first communication device (eg, PCF) or obtains the first information from a local configuration.

[0054] the configuration server includes a server for configuring certificates and / or subscription information for terminals; The credentials and / or subscription information may be at least one of credentials and / or subscription information for a primary authentication and / or authorization credential and / or subscription to access a first subject, and non-primary authentication and / or authorization credential and / or subscription information.

[0055] The non-primary authentication and / or authorization includes at least one of a secondary authentication and / or authorization and a secondary authentication and / or authorization associated with a slice; the first object includes a slice of a network, a DN, and a network; The network type includes at least one of an SNPN, a PNI-NPN, and a PLMN.

[0056] The method, apparatus and communication device according to the embodiments of the present application can be used in a network system including a terminal, a Radio Access Network (RAN) network element and a Core Network (CN) network element.

[0057] In one embodiment of the present application, the communication equipment may include at least one of a communication network element equipment and a terminal.

[0058] In one embodiment of the present application, the communication network element may include at least one of a core network element and a radio access network element.

[0059] In an embodiment of the present application, the core network elements include a core network device, a core network node, a core network function, a core network element, a Mobility Management Entity (MME), an Access Management Function (AMF), a Session Management Function (SMF), a User Plane Function (UPF), a Serving Gateway (SGW), a PDN Gateway (PDN Gateway), a Policy Control Function (PCF), a Policy and Charging Rules Function (PCRF), a General Packet Radio Service (GPRS) Serving GPRS Support Node (SGSN), a Gateway GPRS Support Node (GGSN), a Unified Data Management (UDM), a Unified Data Repository (UDR), and a Home Subscriber Server (HSS). The network functions may include, but are not limited to, at least one of a Network Server (HSS), an Application Function (AF), and a Centralized network configuration (CNC).

[0060] In an embodiment of the present application, the radio access network element may include, but is not limited to, at least one of a radio access network device, a radio access network node, a radio access network function, a radio access network unit, a Third Generation Partnership Project (3GPP) radio access network, a non-3GPP radio access network, a Centralized Unit (CU), a Distributed Unit (DU), a base station, an evolved base station (evolved Node B (eNB), a 5G base station (gNB), a Radio Network Controller (RNC), a base station (NodeB), a Non-3GPP Inter Working Function (N3IWF), an Access Controller (AC) node, an Access Point (AP) device or a Wireless Local Area Networks (WLAN) node, and an N3IWF.

[0061] The base station may be a base transceiver station (BTS) in a Global System for Mobile Communications (GSM) or a Code Division Multiple Access (CDMA), a base station (NodeB) in a Wideband Code Division Multiple Access (WCDMA), an evolved base station in LTE (e.g., eNB or e-NodeB, evolutionary Node B) and a 5G base station (gNB), and is not limited to these in the embodiments of the present application.

[0062] In the embodiments of the present application, a terminal (e.g., a UE) may include a relay supporting a terminal function and / or a terminal supporting a relay function. The terminal may also be referred to as a terminal device or a user equipment (UE), and the terminal may be a terminal-side device such as a mobile phone, a tablet personal computer, a laptop computer, a personal digital assistant (PDA), a mobile internet device (MID), a wearable device, or an in-vehicle device. It should be noted that the embodiments of the present application do not limit the specific type of the terminal.

[0063] In one optional embodiment of the present application, obtaining or acquiring may be understood as obtaining from a configuration, receiving, receiving after receiving a request, obtaining by self-learning, deriving and obtaining based on unreceived information, or obtaining after processing based on received information, and may be determined according to specific actual needs, and the embodiments of the present application are not limited thereto.

[0064] In one alternative embodiment of the present application, the transmission may include a broadcast, a broadcast in a system message, a return after responding to a request, a dedicated signaling transmission, or the like.

[0065] The following clearly and completely describes the technical solutions in the embodiments of the present application, in conjunction with the drawings in the embodiments of the present application, and it is obvious that the described embodiments are only some of the embodiments of the present application, and not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without any creative efforts fall within the scope of protection of the present application.

[0066] 1 shows a block diagram of a wireless communication system to which the embodiments of the present application can be applied. The wireless communication system includes a terminal 11 and a network side device 12. Here, the terminal 11 may be referred to as a terminal device or user equipment (UE), and may be a terminal side device such as a mobile phone, a tablet personal computer (PDA), a laptop computer (also called a notebook computer), a personal digital assistant (PDA), a palmtop computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), a wearable device, a vehicle-mounted equipment (VUE), a pedestrian-mounted equipment (PUE), etc., and wearable devices include a smart watch, a bracelet, an earphone, glasses, etc. It should be noted that the embodiments of the present application do not limit the specific type of the terminal 11. The network side equipment 12 may be a base station or a core network, where the base station may be called a Node B, an evolved Node B, an access point, a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a B node, an evolved B node (eNB), a home B node, a home evolved B node, a WLAN access point, a WiFi node, a transmitting receiving point (TRP), or any other suitable term in the art, as long as the same technical effect is achieved. The base station is not limited to a specific technical term. For illustrative purposes, the embodiments of this application only take base stations in an NR system as examples, but do not limit the specific type of base station.

[0067] The following describes in detail the configuration method, data control method, device and network side equipment according to the embodiments of the present application through several embodiments and their application scenarios in conjunction with the drawings.

[0068] Referring to FIG. 2, this is a flowchart of an information processing method according to an embodiment of the present application, where the execution body of this method is a first communication device, which may be a PCF. As shown in FIG. 2, this method may include the following steps:

[0069] In step 201, first information including at least one of domain name server address information and configuration server address information is obtained.

[0070] In step 202, a first operation is performed based on the first information, where the first operation includes: determining first policy information; transmitting the first information or the first policy information; wherein the first policy information is used to determine a first rule of data processing, and the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; The second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data.

[0071] In one embodiment, the first access method includes onboarding access.

[0072] In one embodiment, data related to a domain name server address means data in which the source address or the target address is a domain name server address; In one embodiment, data related to a configuration server address means data in which the source address or the target address is a configuration server address; In one embodiment, the data not related to a domain name server address includes data where the source address or target address is not a domain name server; In one embodiment, data not associated with a configuration server address means data whose source address or target address is not a configuration server address; In a specific implementation, the first communication device may be a Policy Control Function (PCF), the first information may be a rule parameter for forming a first rule of data processing, and the first policy information may be a policy carrying the rule parameter.

[0073] In addition, the non-first data may be understood as data other than the first data. In a specific implementation, the data passing-related control refers to an operation of controlling whether data passes.

[0074] In one alternative embodiment, the first policy information includes two addresses: gate status=open, close, corresponding to a Policy Control and Charging (PCC) rule.

[0075] In implementation, the PCF may send the first information and / or the first policy information to a Session Management Function (SMF), and the first policy information may be any policy that can be transmitted to the SMF as long as there are sufficient fields to store the rule parameters.

[0076] In a specific implementation, for example, the first data includes data related to a domain name server address. The SMF is used to send a first rule for data processing or a rule parameter for forming the first rule for data processing to the UPF. Based on this, the UPF performs a data pass control operation on the data related to the domain name query in the remote configuration process, so that the UE can obtain correct DNS information from the domain name query server. If only a restricted PDU session is established, the DNS information is used to realize PVS discovery based on a fully qualified domain name (FQDN).

[0077] It should be understood that the present application can be applied to any scenario in which DNS query data is specifically discarded in the UPF, for example, when the UE only establishes a restricted PDU session, and can achieve correct processing of the DNS query data.

[0078] Specifically, during the remote configuration process, if the UE only establishes a restricted PDU session and does not obtain a remote configuration server (Provisioning Server, PVS) address, the UE needs to perform a PVS query based on the FQDN to obtain the PVS address. Considering that the FQDN must have both a hostname and a domain name, the UE needs to obtain the corresponding DNS information to use the FQDN based on the DNS information and the hostname. However, during the process of the UE obtaining the DNS information, if the UE only establishes a restricted PDU session, the DNS query data sent from the UE will be discarded, resulting in a DNS query failure. In other words, in the above case, the UE cannot query the DNS information, and therefore cannot perform a PVS query based on the FQDN, ultimately resulting in a service failure.

[0079] In an embodiment of the present application, by sending a first rule for data processing or rule parameters for forming the first rule for data processing to the UPF, the UPF allows data related to the domain name query and / or data related to the configuration server query to pass through (i.e., not discard) and returns the query result to the UE, thereby being able to independently control the DNS query function and the PVS query function.

[0080] Compared to the related art, the embodiments of the present application individually and independently control data related to domain name queries and / or data related to configuration server queries, thereby enabling the data related to domain name queries and / or data related to configuration server queries to be allowed to pass, thereby avoiding business failures caused by discarding data related to domain name queries and / or data related to configuration server queries in the related art.

[0081] Of course, the UPF may further perform a data pass control operation solely on data related to a configuration query (including a PVS query, and for convenience of explanation, only a PVS query will be described as an example in the following embodiments) based on the first data processing rule or rule parameters for forming the first data processing rule, which will not be specifically described here.

[0082] In addition, in order for the UPF to determine whether the received data is data related to a domain name query, the first rule for data processing may be constructed based on at least address information related to a domain name query server.

[0083] In a specific implementation, the data related to the domain name server address may include at least one of domain name query data and domain name query response data, and the data related to the configuration server address may include at least one of configuration query data and configuration query response data.

[0084] In a specific implementation, to determine whether the data is a data packet related to the domain name query or data related to a configuration query, the determination can be made based on whether the target address or source address of the data is a domain name query server or a configuration server.

[0085] Specifically, the data related to the domain name query includes data of the target address or source address being the address of the domain name query server, or data of the destination or source being the domain name query server; The data associated with the remote configuration query includes data where the target address or source address is the address of a remote configuration server, or data where the destination or source is a remote configuration server.

[0086] Here, the data whose target address is the address of the domain name query server is DNS query request data, and the data whose source address is the address of the domain name query server is DNS query response data.

[0087] Correspondingly, the data whose target address is the address of the remote configuration server is PVS query request data, and the data whose source address is the address of the remote configuration server is PVS query response data.

[0088] Of course, in addition to determining whether the data is data related to the domain name query or remote configuration query based on the address of the data packet, it is also possible to determine whether the data is data received or sent from the domain name query server or remote configuration server by determining the name, device identifier, etc. of the device sending or receiving the data, and if it is determined that the data is data received or sent from the domain name query server or remote configuration server, it is determined that the data is data related to the domain name query or remote configuration query.

[0089] In this embodiment, a single first rule of data processing can realize passage control for both data related to PVS queries and data related to DNS queries.

[0090] Of course, the rule parameters for forming the first rule of the data processing may include DNS address information, a device identifier of a DNS server (ie, a domain name query server), or identifier information of a DNS server, etc.

[0091] Optionally, the first rules for data processing include Forwarding Action Rules (FAR) or Packet Detection Rules (PDR).

[0092] The PDR contains various information and is used to classify data arriving at the UPF, and each PDR is used to detect data in a specific transmission direction, for example, the uplink direction and the downlink direction.

[0093] The FAR is used to define how data is buffered, discarded, or forwarded, including data packaging / unpackaging and forwarding destination.

[0094] In a specific implementation, the FAR or PDR may be generated based on DNS and / or PVS address information locally configured by the SMF, or the SMF may receive DNS and / or PVS address information sent by other network devices (e.g., PCF, Application Function (AF), Local DNS Resolver (LDNSR), Default Credential Server (DCS), Subscription Owner, etc.) or UE before generating the FAR or PDR, and then the SMF generates the FAR or PDR based on the received DNS and / or PVS address information.

[0095] For example, data related to a DNS address and a PVS address in the FAR may be set to pass, and a PDR may not be set for the second data, and the second data will be discarded based on the first rule for data processing.

[0096] In the above embodiment, the conventional FAR or PDR is used to realize storing the processing rules of DNS query data, and the implementation complexity can be reduced.

[0097] In practical applications, the above FAR or PDR may be the same rules as those used by a configuration server in related art (for convenience of explanation, the configuration server in the following embodiments is described as PVS, and no specific limitations are made here).

[0098] Here, the configuration server may be used to configure the terminal with network credentials (e.g., Standalone NPN (SNPN) type networks) and / or subscription data. This subscription information may be data for primary authentication, secondary authentication, Network Slice-Specific Authentication and Authorization (NSSAA), etc.

[0099] It should be noted that the above solution can be applied to a public network integrated NPN (PNI-NPN) network in addition to the SNPN network, and is not specifically limited thereto.

[0100] When the FAR or PDR carries both a data passing rule related to a DNS query and a data passing rule related to a configuration server query, the first rule of data processing may relate to address information of a remote configuration server and is used to perform data passing control operations on data related to the remote configuration query.

[0101] Similar to the address information of the domain name query server, in a specific implementation, the address information of the remote configuration server may be the locally configured PVS address information of the SMF, or the PVS address information sent by other network devices (e.g., PCF, AF, LDNSR, DCS, Subscription Owner, etc.) or UE, and is not specifically limited here.

[0102] Optionally, the first policy information is: associated policy information requiring an operation to be performed on the first data to allow it to pass; and associated policy information requiring a control operation to be performed on the second data, either not allowing it to pass or discarding the second data.

[0103] It should be noted that associated policy information that requests the execution of a control operation on the second data that does not allow it to pass or that discards the second data implicitly includes the meaning of associated policy information that requests the execution of an operation on the first data that allows it to pass.

[0104] Optionally, the first rule of data processing is: performing an allow-pass operation on the first data; and performing an operation on the second data to not allow it to pass or to discard the second data.

[0105] It should be noted that the relevant policy information that performs a control operation on the second data that does not allow it to pass or discards the second data implicitly includes the meaning of the relevant policy information that performs an operation on the first data that allows it to pass.

[0106] Optionally, the first policy information includes the first information; and / or The first rule for data processing includes the first information.

[0107] Optionally, performing a first operation based on the first information includes: When it is determined that the terminal accesses the first network through a first access method, performing a first operation based on the first information; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0108] In a specific implementation, the access method of obtaining the certificate and / or subscription to access the network may include an access method of obtaining the certificate and / or subscription remotely to access the network.

[0109] The restricted data channel may include at least one of a data channel that allows the first data to pass and a data channel that does not allow the second data to pass, and the data channel may include a PDU session.

[0110] Of course, the first access method may further include onboarding.

[0111] In an embodiment of the present application, a first communication device acquires first information including at least one of domain name server address information and configuration server address information, and performs a first operation based on the first information, where the first operation includes at least one of determining first policy information and transmitting the first information or the first policy information, where the first policy information is used to determine a first rule of data processing, and the first rule of data processing is used to perform data passage-related control on first data and / or second data, where the first data includes at least one of data related to a domain name server address and data related to a configuration server address, and the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data. In this manner, data passage-related control may be performed solely on data related to DNS queries and / or configuration server queries, for example, allowing data related to DNS queries and / or configuration server queries to pass through, or not allowing data not related to DNS queries and / or configuration server queries to pass through.

[0112] Referring to FIG. 3, it is a flowchart of an information processing method according to an embodiment of the present application, which is used in a second communication device, and the second communication device may be an SMF. As shown in FIG. 3, the method may include the following steps:

[0113] In step 301, second information including at least one of first information and first policy information is obtained.

[0114] In step 302, a second operation is performed based on the second information, where the second operation comprises: determining the first rules for data processing; transmitting the first information or the first rule of data processing; wherein the first rule of data processing is used to perform data passing-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0115] In a specific implementation, the above-mentioned sending of the first information or the first rule for data processing may be the SMF sending the first information or the first rule for data processing to the UPF.

[0116] The above first information, first policy information, and first rule of data processing have the same meaning and function as the first information, first policy information, and first rule of data processing in the embodiment of the method shown in Figure 2, respectively, and will not be further described here.

[0117] Optionally, the step of determining a first rule for processing data comprises: setting a data detection rule for the first data; setting a data transfer rule for the first data and allowing the first data to pass; setting a data transfer rule for the second data, and not allowing the second data to pass or discarding the second data; and not setting a data detection rule and / or a data transfer rule for the second data.

[0118] In a specific implementation, the data detection rule may include a PDR, and the data forwarding rule may include a FAR. For example, the data related to the DNS address and the PVS address in the FAR may be set to pass, and no PDR may be set for the second data. Data that does not correspond to the PDR will be discarded, that is, it is easy to understand that the second data will be discarded according to the first rule of data processing.

[0119] Optionally, the first rule of data processing relates to at least address information of a domain name query server.

[0120] In a specific implementation, the above-mentioned first rule of data processing is related to at least the address information of the domain name query server, which may be understood as meaning that the first rule of data processing may be established based on at least the address information of the domain name query server so that the UPF can determine whether the received data is data related to a domain name query.

[0121] Correspondingly, the first rule of data processing may further relate to address information of a remote configuration server, which is used to perform a data passing operation on data related to a remote configuration query.

[0122] Optionally, obtaining the second information includes: obtaining the first information from a terminal; receiving second information from the first communication device; obtaining second information from the local configuration; receiving address information of the configuration server from a fifth communication device; receiving data related to a domain name query from a domain name query server; and obtaining address information of the configuration server based on the data related to the domain name query; Here, the fifth communication device is used to verify address information of the configuration server based on data related to the domain name query result.

[0123] In one embodiment, the first communication device may be a first communication device applying the method embodiment shown in FIG.

[0124] For example, the SMF may receive a policy carrying rule parameters from the PCF, and the SMF may parse the policy to obtain the rule parameters for generating a first rule for processing the data.

[0125] Furthermore, the policy carrying the rule parameters sent from the PCF may be a policy for restricting data passage, and this policy for restricting data passage may include at least one of a data channel policy for configuring a certificate in the user plane, a data channel policy for a first access method (e.g., Onboarding), a policy for determining whether to allow data passage (e.g., a policy for determining whether to allow a data passage gateway (e.g., UPF)), etc.

[0126] In one embodiment, the first access method includes onboarding access.

[0127] In one embodiment, the data detection rules include PDRs.

[0128] In one embodiment, the data transfer rule includes FAR, for example, two addresses of FAR are set to pass, and PDR is not set for the second data, which is discarded based on the rule.

[0129] The data processing rules relate to at least address information of a domain name query server.

[0130] The data processing rules also relate to address information of a remote configuration server and are used to perform data passing operations on data associated with a remote configuration query.

[0131] The second information is received from a second communication device (eg, a PCF) or obtained from a local configuration.

[0132] Performing an allowable operation on the first data and / or performing a non-allowable operation on the second data may include: allowing only data related to the domain name query and data related to a remote configuration query to pass; and not allowing any other data to pass through other than data related to said domain name query and data related to said remote configuration query. and discarding data other than data related to the domain name query and data related to the remote configuration query.

[0133] In another embodiment, the second communication device may obtain the second information, eg, a local policy, based on a local configuration.

[0134] Of course, the second information may also be obtained from the terminal or received from a fifth communication device, where the fifth communication device may be an Edge Application Server Detection Function (EASDF) unit.

[0135] For example, the reporting rule retrieves the configuration server address, which is specifically: Setting reporting rules based on DNS addresses; Sending the reporting rule to a target end (e.g., an LDNSR); receiving address information sent by the target end; and wherein the address information sent by the target end is the address of a configuration server.

[0136] In this embodiment, the second communication device can obtain the rule parameters in various ways, thereby increasing the flexibility of the information processing method.

[0137] Optionally, the first rule of data processing is: performing an allow-pass operation on the first data; and performing an operation on the second data to not allow it to pass or to discard the second data.

[0138] Optionally, the first rule for processing data includes the first information.

[0139] Optionally, performing a second operation based on the second information includes: performing a second operation based on second information when it is determined that the terminal accesses the first network through the first access method; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0140] In this embodiment, the first access method etc. have the same meaning and effect as the first access method etc. in the embodiment of the method shown in FIG. 2, and will not be further described here.

[0141] In the embodiment of the present application, the information processing method used in the second communication device corresponds to the embodiment of the method used in the first communication device shown in Figure 2, and can achieve the same beneficial effects as the embodiment of the method shown in Figure 2, and will not be further described here.

[0142] Referring to Figure 4, this is a flowchart of an information processing method according to an embodiment of the present application, which is used in a third communication device, and the third communication device may be a UPF. As shown in Figure 4, this method may include the following steps:

[0143] In step 401, third information including at least one of the first information and the first rule of data processing is obtained.

[0144] In step 402, a third operation is performed based on the third information, where the third operation includes: determining a first rule for the data processing based on the first information; and performing a data passing-related control on the first data and / or the second data based on the received or determined first rule of data processing; wherein the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0145] In a specific implementation, the above-mentioned data passage-related control on the first data and / or second data may include allowing data related to domain name queries to pass through a restricted PDU session in a remote configuration process, thereby realizing the execution of a DNS query function on the restricted PDU session by not discarding the DNS query request data when obtaining DNS request data sent by the UE and returning corresponding DNS query response data to the UE.

[0146] Of course, the above-mentioned data passage-related control on the first data and / or second data may further include allowing the passage of data related to the configuration query carried on the restricted PDU session in the configuration query process, so that when obtaining PVS request data sent by the UE, the PVS query request data is not discarded and the corresponding PVS query response data is returned to the UE, thereby realizing the execution of the PVS query function on the restricted PDU session.

[0147] Compared to the related art, the embodiments of the present application individually and independently control data related to domain name server addresses and / or data related to configuration server addresses, thereby enabling the data related to the domain name server addresses and / or data related to configuration server addresses to pass through, thereby avoiding business failures caused by the discarding of data related to domain name server addresses and / or data related to configuration server addresses in the related art.

[0148] In a specific implementation, the above-mentioned first data processing rule may be a first data processing rule received from an SMF, or a first data processing rule generated based on rule parameters received from an SMF, and this first data processing rule has the same meaning and effect as the first data processing rule in the method embodiment shown in Figure 2 or Figure 3, and will not be further described here.

[0149] Optionally, the step of acquiring the third information includes: receiving the third information from a first communication device; obtaining the first information from a local configuration; receiving address information of the configuration server from a fifth communication device; receiving data associated with a domain name query; and obtaining address information of the configuration server based on the data associated with the domain name query; Here, the fifth communication device is used to verify address information of the configuration server based on data related to the domain name query result.

[0150] The above-mentioned first communication device is the first communication device applying the method embodiment shown in Figure 2, and the above-mentioned fifth communication device has the same meaning as the fifth communication device in the method embodiment shown in Figure 2 or Figure 3, and will not be further described here.

[0151] Optionally, the first rule of data processing is: performing an allow-pass operation on the first data; and performing an operation on the second data to not allow it to pass or to discard the second data.

[0152] Optionally, the step of acquiring the third information includes acquiring the third information when it is confirmed that the terminal accesses the first network through the first access method; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0153] In one embodiment, the first access method includes onboarding access.

[0154] In one embodiment, the data detection rules include PDRs.

[0155] In one embodiment, the data transfer rule includes FAR, for example, two addresses of FAR are set to pass, and PDR is not set for the second data, which is discarded based on the rule.

[0156] The data processing rules relate to at least address information of a domain name query server.

[0157] The data processing rules also relate to address information of a remote configuration server and are used to perform data passing operations on data associated with a remote configuration query.

[0158] The second information is received from a second communication device (eg, a PCF) or obtained from a local configuration.

[0159] Performing an allowable operation on the first data and / or performing a non-allowable operation on the second data may include: allowing only data related to the domain name query and data related to a remote configuration query to pass; and not allowing any other data to pass through other than data related to said domain name query and data related to said remote configuration query. and discarding data other than data related to the domain name query and data related to the remote configuration query.

[0160] The above first data, second data, and first access method have the same meanings as the first data, second data, and first access method in the method embodiment shown in Figure 2 or Figure 3, respectively, and will not be further described here. The information processing method according to the embodiment of the present application corresponds to the method embodiment shown in Figure 2 or Figure 3, and can achieve the same beneficial effects as the method embodiment shown in Figure 2 or Figure 3, and will not be further described here.

[0161] Referring to Figure 5, this is a flowchart of another information processing method according to an embodiment of the present application, which is used in a fourth communication device, and the fourth communication device may be a UE. As shown in Figure 5, this method may include the following steps:

[0162] In step 501, first information is sent, where the first information includes at least one of domain name server address information and configuration server address information.

[0163] In a specific implementation, the UE (i.e., terminal) can transmit the first information to a first communication device that applies the method embodiment shown in Figure 2, and / or transmit the first information to a second communication device that applies the method embodiment shown in Figure 3.

[0164] Optionally, the transmitting of the first information includes transmitting the first information when it is confirmed that the terminal accesses the first network by the first access method; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0165] In one embodiment, the first access method includes onboarding access.

[0166] In specific implementation, the above first access method has the same meaning as the first access method in the method embodiment shown in FIG. 2 or FIG. 3, and will not be further described here.

[0167] In the embodiment of the present application, the information processing method for a fourth communication device corresponds to the embodiment of the method shown in FIG. 2 and / or FIG. 3 and has the same beneficial effects, and will not be further described here.

[0168] An embodiment of the present application further provides a flowchart of a configuration method, which may include the following steps:

[0169] The SMF transmits a data processing rule or a rule parameter for forming the data processing rule, and the data processing rule is used to perform a data passage control operation on data related to at least a domain name query in a remote configuration process and / or data related to a remote configuration query.

[0170] In a specific implementation, the data processing rule may correspond to the first rule of data processing in any one of the method embodiments in Figures 2 to 5, and the rule parameter may correspond to the first information in any one of the method embodiments in Figures 2 to 5. The SMF is used to send the data processing rule or the first information (i.e., the rule parameter) for forming the data processing rule to the UPF, and the UPF then performs a data pass control operation on the data related to the domain name query in the remote configuration process and / or the data related to the remote configuration query, so that the UE can obtain correct DNS information and / or PVS address from the domain name query server. If only a restricted PDU session is established, the DNS information is used to realize PVS discovery based on a fully qualified domain name (FQDN).

[0171] It should be understood that the present application is particularly applicable to any scenario in which DNS query data and / or data related to remote configuration queries are discarded in the UPF, for example, when the UE only establishes restricted PDU sessions, and allows for correct processing of the business.

[0172] Specifically, taking DNS query as an example, during the remote configuration process, if the UE only establishes a restricted PDU session and does not obtain a remote configuration server (PVS) address, the UE needs to perform a PVS query based on the FQDN to obtain the PVS address. Considering that the FQDN must have both a hostname and a domain name, the UE needs to obtain the corresponding DNS information to use the FQDN based on the DNS information and the hostname. However, during the process of the UE obtaining the DNS information, if the UE only establishes a restricted PDU session, the DNS query data packet sent from the UE will be discarded, resulting in a DNS query failure. In other words, in the above case, the UE cannot query the DNS information, and therefore cannot perform a PVS query based on the FQDN, ultimately resulting in a service failure.

[0173] In an embodiment of the present application, by sending a data processing rule or a rule parameter for forming the data processing rule to the UPF, the UPF allows data related to the domain name query and / or data related to the remote configuration query to pass through (i.e., is not discarded) and returns the query result to the UE, thereby realizing the DNS query function and remote configuration.

[0174] Compared to the related art, the embodiments of the present application individually and independently control data related to domain name queries and / or data related to remote configuration queries, thereby enabling the data related to domain name queries and / or data related to remote configuration queries to be allowed to pass, thereby avoiding business failures caused by discarding data related to domain name queries and / or data related to remote configuration queries in the related art.

[0175] In a specific implementation, the data related to the domain name query may include at least one of domain name query data and domain name query response data.

[0176] In order for the UPF to determine whether the received data packet is a data packet related to a domain name query, the data processing rule may be established based on at least address information of a domain name query server.

[0177] In a specific implementation, the address information of the domain name query server may be locally configured address information of the SMF, or may be address information sent by other network devices (e.g., PCF, AF, LDNSR, DCS, Subscription Owner, etc.), or may be address information sent by the UE, and is not specifically limited here.

[0178] In practical application, the UPF may determine whether the data is a data packet related to a domain name query based on the association between the data processing rule and the DNS address information. For example, the UPF may determine whether the data is related to a domain name query based on whether the target address or source address of the received data is a DNS.

[0179] Of course, other than associating the data processing rules with DNS address information, whether data is related to a domain name query can also be determined based on the association between the data processing rules and the type or name of the data. For example, a data processing rule can be established based on data type information carried in the data, and the UPF can determine whether the data is related to a domain name query based on the type of the received data and then decide whether to pass the data. Alternatively, for example, a data processing rule can be established based on the device identifier of the receiving device or sending device carried in the data, and the UPF can determine whether the data is related to a domain name query based on the device identifier of the receiving device or sending device in the received data and then decide whether to pass the data.

[0180] Correspondingly, the rule parameters for forming the data processing rule may include DNS address information, a device identifier of a DNS server (ie, a domain name query server), or identifier information of a DNS server, and so on.

[0181] Optionally, the data processing rules sent by the SMF are Forwarding Action Rules (FAR) or Packet Detection Rules (PDR).

[0182] The PDR contains various information and is used to classify data arriving at the UPF, and each PDR is used to detect data in a specific transmission direction, for example, the uplink direction and the downlink direction.

[0183] The FAR is used to define how data is buffered, discarded, or forwarded, including data packaging / unpackaging and forwarding destination.

[0184] In a specific implementation, the FAR or PDR may be generated based on DNS and / or PVS address information locally configured by the SMF, or the SMF receives DNS and / or PVS address information sent by other network devices (e.g., PCF, AF, LDNSR, DCS, Subscription Owner, etc.) or UE before generating the FAR or PDR, and then the SMF generates the FAR or PDR based on the received DNS and / or PVS address information.

[0185] In the above embodiment, the conventional FAR or PDR is used to realize storing the processing rules of DNS query data, and the implementation complexity can be reduced.

[0186] In practical applications, the above FAR or PDR may be the same rules as those used by a configuration server in related art (for convenience of explanation, the following embodiment only exemplifies that the configuration server is a PVS, and no specific limitations are made here).

[0187] Here, the configuration server may be used to configure the terminal with network (e.g., Standalone NPN (SNPN) type network) credentials and / or subscription data. This subscription information may be data for primary authentication, secondary authentication, NSSAA, etc.

[0188] It should be noted that the above solution can be applied to an SNPN network, and can also be applied to a public network integrated NPN (PNI-NPN) network, and is not specifically limited herein.

[0189] When the FAR or PDR carries both data passing rules related to DNS queries and data passing rules related to configuration server queries, the data processing rules may also be related to address information of a remote configuration server and are used to perform data passing control operations on data related to remote configuration queries.

[0190] Similar to the address information of the domain name query server, in a specific implementation, the address information of the remote configuration server may be the locally configured PVS address information of the SMF, or the PVS address information sent by other network devices (e.g., PCF, AF, LDNSR, DCS, Subscription Owner, etc.) or UE, and is not specifically limited here.

[0191] In practical application, whether data is related to a remote configuration query may be determined based on the association between the data processing rule and the PVS address information. For example, the UPF may determine whether the data is related to a remote configuration query based on whether the target address or source address of a received data packet is a PVS.

[0192] Of course, other than associating the data processing rule with the PVS address information, whether data is related to a remote configuration query can also be determined by the association relationship between the data processing rule and the type or name of the data. For example, a data processing rule can be established based on the data type information carried in the data type, and the UPF can determine whether the data is related to a remote configuration query based on the type of the received data and then decide whether to pass the data. For example, a data processing rule can be established based on the device identifier of the receiving device or sending device carried in the data, and the UPF can determine whether the data is related to a remote configuration query based on the device identifier of the receiving device or sending device in the received data and then decide whether to pass the data.

[0193] In this embodiment, a single data processing rule can be used to realize pass control for both data related to PVS queries and data related to DNS queries.

[0194] Optionally, after the SMF sends a data processing rule or a rule parameter for forming the data processing rule in the above step to obtain the PVS address information, the configuration method according to the present application includes: The method further includes the SMF receiving data related to a domain name query sent by a domain name query server, the data carrying address information of the remote configuration server.

[0195] In a specific implementation, after configuring the passing rules for data packets related to DNS queries, the SMF can send DNS query data packets and then receive DNS response data returned by the DNS server, and the DNS response data can carry the address information of the remote configuration server, thereby simplifying the process of obtaining the address information of the remote configuration server. That is, when the address of the configuration server is not available, the configuration server address can be obtained based on the DNS query result of the terminal.

[0196] Of course, in a specific implementation, the configuration server address may be received from a network-side device such as a terminal or an AF.

[0197] Optionally, the data passing control operation comprises: allowing only data related to the domain name query and data related to a remote configuration query to pass; and not allowing any other data to pass through other than data related to said domain name query and data related to said remote configuration query. and discarding data other than data related to the domain name query and data related to the remote configuration query.

[0198] It should be noted that the above-mentioned "not allowing other data other than the data related to the domain name query and the data related to the remote configuration query to pass" implicitly includes the meaning of allowing the data related to the domain name query and the data related to the remote configuration query to pass, and the above-mentioned "discarding other data other than the data related to the domain name query and the data related to the remote configuration query" implicitly includes the meaning of not discarding the data related to the domain name query and the data related to the remote configuration query.

[0199] In a specific implementation, to determine whether the data is a data packet related to the domain name query or a remote configuration query, the determination may be made based on whether the target address or source address of the data packet is a domain name query server or a remote configuration server.

[0200] Specifically, the data related to the domain name query includes data of the target address or source address being the address of the domain name query server, or data of the destination or source being the domain name query server; The data associated with the remote configuration query includes data where the target address or source address is the address of a remote configuration server, or data where the destination or source is a remote configuration server.

[0201] Here, the data whose target address is the address of the domain name query server is DNS query request data, and the data whose source address is the address of the domain name query server is DNS query response data.

[0202] Correspondingly, the data whose target address is the address of the remote configuration server is PVS query request data, and the data whose source address is the address of the remote configuration server is PVS query response data.

[0203] Of course, other than determining whether the data packet is data related to the domain name query or data related to the remote configuration query based on the address of the data, it is also possible to determine whether the data is data received or sent by the domain name query server or the remote configuration server by determining the name, device identifier, etc. of the device sending or receiving the data, and if it is determined that the data is data received or sent by the domain name query server or the remote configuration server, it is determined that the data is data related to the domain name query or data related to the remote configuration query.

[0204] In practical application, the data processing rule may be generated based on rule parameters such as DNS and / or PVS addresses locally configured by the SMF. Of course, if rule parameters such as DNS and / or PVS addresses are not locally configured in the SMF, the SMF must receive rule parameters such as DNS and / or PVS address information sent by other devices, and generate the data processing rule based on the received rule parameters.

[0205] That is, in the above step, before the SMF transmits the data processing rule or the rule parameters for forming the data processing rule, the configuration method according to the present application includes: The SMF receiving the rule parameters from a terminal or a network device; or the SMF using the rule parameters stored locally in the SMF; or The method may further include the step of the SMF receiving a policy carrying the rule parameters from a PCF.

[0206] In specific implementation, the network side devices may include PCF, AF, LDNSR, DCS, Subscription Owner, etc.

[0207] For example, the reporting rule retrieves the configuration server address, which is specifically: Setting reporting rules based on DNS addresses; Sending the reporting rule to a target end (e.g., an LDNSR); receiving address information sent by the target end; and wherein the address information sent by the target end is the address of a configuration server.

[0208] Furthermore, when the SMF receives a policy carrying the rule parameter from the PCF, the SMF may parse the policy to obtain the rule parameter. Furthermore, the policy carrying the rule parameter transmitted from the PCF may be a policy for restricting data passage, and the policy for restricting data passage may include at least one of a data channel policy for configuring a certificate in a user plane, a data channel policy for a first access method (onboarding), and a policy for determining whether to allow data passage (e.g., a policy for determining whether to allow a data passage gateway (e.g., UPF)).

[0209] In this embodiment, the SMF can obtain the rule parameters in various ways to increase the flexibility of the configuration method.

[0210] In an embodiment of the present application, the SMF sends a data processing rule or a rule parameter for forming the data processing rule, and the data processing rule is used to perform a data pass control operation on at least the data related to the domain name query in the remote configuration process and / or the data related to the remote configuration query, and the UPF performs a data pass control operation on at least the data related to the domain name query in the remote configuration process and / or the data related to the remote configuration query based on the data processing rule, so that the data of the DNS query and / or the data related to the remote configuration query is not discarded.

[0211] An embodiment of the present application further provides a flowchart of another configuration method, which includes: The method may include a step in which the PCF sends rule parameters for forming a data processing rule or a policy carrying the rule parameters, and the data processing rule is used to perform a data passage control operation on data related to at least a domain name query in a remote configuration process and / or data related to a remote configuration query.

[0212] Here, the policy carrying the rule parameters may be any policy that can be transmitted to the SMF as long as there are sufficient fields to store the rule parameters.

[0213] In a specific implementation, the PCF may send rule parameters for forming the above data processing rules or policies carrying the rule parameters to the SMF.

[0214] Furthermore, the above data processing rules have the same meaning and effect as the data processing rules used in the embodiment of the SMF configuration method, and will not be further explained here.

[0215] Optionally, the data processing rules relate to at least address information of a domain name query server.

[0216] Optionally, the data processing rules also relate to address information of a remote configuration server and are used to perform data passage control operations on data associated with a remote configuration query.

[0217] In the embodiment of the present application, the configuration method used in the PCF has the same meaning and can obtain the same beneficial effects as the embodiment of the rule parameters for forming data processing rules or the policies carrying said rule parameters received by the SMF from the PCF in the embodiment used in the configuration method of the SMF, and will not be further described here.

[0218] The embodiment of the present application further provides a flowchart of a data control method, which includes: The method may include a step in which the UPF performs a data pass control operation on at least data related to the domain name query and / or data related to the remote configuration query in the remote configuration process based on the data processing rule.

[0219] Here, the above-mentioned performing a data passage control operation on data related to domain name queries and / or data related to remote configuration queries in at least the remote configuration process may be understood as allowing data related to domain name queries and / or data related to remote configuration queries to pass through the restricted PDU session in the remote configuration process, thereby realizing the execution of DNS query functions and PVS query functions on the restricted PDU session by not discarding the DNS query request data and / or PVS request data when obtaining DNS request data and / or PVS request data sent by the UE and returning corresponding DNS query response data and / or PVS query response data to the UE.

[0220] Compared to the related art, the embodiments of the present application individually and independently control data related to domain name queries and / or data related to remote configuration queries, thereby enabling the data related to domain name queries and / or data related to remote configuration queries to be allowed to pass, thereby avoiding business failures caused by discarding data related to domain name queries and / or data related to remote configuration queries in the related art.

[0221] In a specific implementation, the above data processing rule may be a data processing rule received from an SMF or a data processing rule generated based on rule parameters received from an SMF, and this data processing rule has the same meaning and effect as the data processing rule in the embodiment used in the SMF configuration method, and will not be further described here.

[0222] Optionally, the data processing rules relate to at least address information of a domain name query server.

[0223] Optionally, the data processing rules also relate to address information of a remote configuration server and are used to perform data passage control operations on data associated with a remote configuration query.

[0224] Optionally, the data passing control operation comprises: allowing only data related to the domain name query and data related to a remote configuration query to pass; and not allowing any other data to pass through other than data related to said domain name query and data related to said remote configuration query. and discarding data other than data related to the domain name query and data related to the remote configuration query.

[0225] Optionally, the data related to the domain name query includes data of a target address or a source address being an address of a domain name query server, or data of a destination or a source being a domain name query server; The data associated with the remote configuration query includes data where the target address or source address is the address of a remote configuration server, or data where the destination or source is a remote configuration server.

[0226] Optionally, before performing a data passage control operation on data related to at least a domain name query in the remote configuration process based on the data processing rule, The UPF receives the data processing rules from an SMF; or The UPF receives rule parameters for forming the data processing rules from an SMF; or The UPF further includes receiving, from an SMF, a policy carrying the rule parameters sent from the PCF.

[0227] Optionally, the data processing rule received from the SMF is a FAR or a PDR.

[0228] In the embodiment of the present application, the data control method used in the UPF performs a specific data control process based on the data processing rules obtained by the configuration method used in the SMF or the rule parameters for forming the data processing rules, which has the same beneficial effects as the embodiment of the configuration method used in the SMF, and will not be further described here to avoid repetition.

[0229] For ease of understanding, the configuration method and data control method according to the embodiment of the present application will be exemplarily described by the embodiment shown in FIG. 6a and FIG. 6b.

[0230] In application scenarios where no PCC is deployed on the network side, data processing rules can be generated by locally configured rule parameters in the SMF.

[0231] FIG. 6a is a flowchart of an information processing method according to another embodiment of the present application, which includes the following steps:

[0232] In step 601a, the SMF obtains the rule parameters.

[0233] In implementation, the SMF will: A method in which the terminal sends the first information, which may include DNS and / or PVS address information, to the SMF; A method for configuring the first information locally in the SMF; The first information is obtained by one of the following methods: the SMF receives a first configuration policy from the PCF, and the SMF parses the first configuration policy to obtain the first information.

[0234] In step 602a, the SMF generates a FAR based on the first information.

[0235] In this step, the SMF may generate a first rule for data processing based on the first information, and this first rule for data processing may be a FAR or a PDR.

[0236] In step 603a, the SMF sends a first rule for data processing to the UPF.

[0237] Here, the UPF performs a data pass control operation on data related to a domain name query and / or data related to a remote configuration query in a remote configuration process based on the data processing rules.

[0238] In step 604a, in the process in which the UE initiates a DNS query, the SMF indirectly obtains the PVS information.

[0239] In this step, during the process in which the UE initiates a DNS query, the SMF obtains the DNS domain name information returned by the DNS server, and then uses the DNS domain name information and the hostname to construct an FQDN, and then performs a PVS query based on the FQDN to obtain a PVS address.

[0240] Of course, in the process of the UE initiating a PVS query, the data related to this PVS query will not be discarded by the gateway, so that the SMF can obtain the PVS address information returned by the PVS server.

[0241] In addition, in an application scenario where a PCC is deployed on the network side, by receiving rule parameters sent by a terminal or a network side device, second policy information can be generated based on the rule parameters.

[0242] FIG. 6b is a flowchart of an information processing method according to another embodiment of the present application, which includes the following steps:

[0243] In step 601b, the SMF obtains the first information.

[0244] In implementation, the SMF will: A method in which the terminal sends the first information, which may include DNS and / or PVS address information, to the SMF; The first information can be obtained by one of the following methods: a method in which the first information is configured locally in the SMF;

[0245] In step 602b, the SMF sends the first information to the UPF.

[0246] Here, after receiving the first information, the UPF can generate a first rule for data processing based on the first information, and perform a data pass control operation on data related to the domain name query in the remote configuration process and / or data related to the remote configuration query based on the first rule for data processing. Similarly, in the process of a UE initiating a DNS query, the SMF can obtain DNS domain name information returned by the DNS server, and can further use the DNS domain name information and a hostname to construct an FQDN, and perform a PVS query based on the FQDN to obtain a PVS address. In addition, in the process of a UE initiating a PVS query, data related to the PVS query is not discarded by the gateway, so that the SMF can obtain the PVS address information returned by the PVS server.

[0247] It should be noted that the execution bodies of the configuration method and data control method according to the embodiments of the present application may be a configuration device and a data control device, respectively, or control modules for executing the configuration method and the data control method in the configuration device and the data control device, respectively. In the embodiments of the present application, the configuration device and the data control device according to the embodiments of the present application will be described taking the configuration device and the data control device respectively executing the configuration method and the data control method as an example.

[0248] Referring to FIG. 7, it is a structural diagram of a first communication device according to an embodiment of the present application. As shown in FIG. 7, the first communication device 700 includes: a first obtaining module 701 for obtaining first information including at least one of domain name server address information and configuration server address information; a first execution module 702 for executing a first operation based on the first information, wherein the first operation includes: determining first policy information; transmitting the first information or the first policy information; wherein the first policy information is used to determine a first rule of data processing, and the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; The second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data.

[0249] Optionally, the first policy information is: associated policy information requiring an operation to be performed on the first data to allow it to pass; and associated policy information requiring a control operation to be performed on the second data, either not allowing it to pass or discarding the second data.

[0250] Optionally, the first rule of data processing is: performing an allow-pass operation on the first data; and performing an operation on the second data to not allow it to pass or to discard the second data.

[0251] Optionally, the first policy information includes the first information; and / or The first rule for data processing includes the first information.

[0252] Optionally, the first execution module 702 specifically: When it is determined that the terminal accesses the first network through a first access method, the first operation is performed based on the first information; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0253] The first communication device 700 according to the embodiment of the present application can perform each process performed by the first communication device in the embodiment of the information processing method shown in FIG. 2 and can obtain the same beneficial effects, and will not be further described here to avoid repetition of the description.

[0254] Referring to FIG. 8, it is a structural diagram of a second communication device according to an embodiment of the present application. As shown in FIG. 8, the second communication device 800 includes: a second acquiring module 801 for acquiring second information including at least one of the first information and the first policy information; and a second execution module 802 for executing a second operation based on the second information, wherein the second operation comprises: determining the first rules for data processing; transmitting the first information or the first rule of data processing; wherein the first rule of data processing is used to perform data passing-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0255] Optionally, the operation of determining a first rule of data processing, performed by the second execution module 802, comprises: setting a data detection rule for the first data; setting a data transfer rule for the first data and allowing the first data to pass; setting a data transfer rule for the second data, and not allowing the second data to pass or discarding the second data; and not setting a data detection rule and / or a data transfer rule for the second data.

[0256] Optionally, the first rule of data processing relates to at least address information of a domain name query server.

[0257] Optionally, the first rule of data processing also relates to address information of a remote configuration server and is used to perform a data passing operation on data associated with a remote configuration query.

[0258] Optionally, the second acquisition module 801 specifically: obtaining the first information from a terminal; receiving second information from the first communication device; obtaining second information from the local configuration; receiving address information of the configuration server from a fifth communication device; receiving data related to a domain name query from a domain name query server; and obtaining address information of the configuration server based on the data related to the domain name query; Here, the fifth communication device is used to verify address information of the configuration server based on data related to the domain name query result.

[0259] Optionally, the first rule of data processing is: performing an allow-pass operation on the first data; and performing an operation on the second data to not allow it to pass or to discard the second data.

[0260] Optionally, the first rule for processing data includes the first information.

[0261] Optionally, the second execution module 802 specifically: and performing a second operation based on second information when it is determined that the terminal accesses the first network through the first access method; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0262] The second communication device 800 according to the embodiment of the present application can perform each process performed by the second communication device in the embodiment of the information processing method shown in FIG. 3 and can obtain the same beneficial effects, and will not be further described here to avoid repetition of the description.

[0263] Referring to FIG. 9, it is a structural diagram of a third communication device according to an embodiment of the present application. As shown in FIG. 9, the third communication device 900 includes: a third acquiring module 901 for acquiring third information including at least one of the first information and the first rule of data processing; and a third execution module 902 for performing a third operation based on the third information, wherein the third operation includes: determining a first rule for the data processing based on the first information; and performing a data passing-related control on the first data and / or the second data based on the received or determined first rule of data processing; wherein the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0264] Optionally, the third acquisition module 901 specifically: receiving the third information from a first communication device; obtaining the first information from a local configuration; receiving address information of the configuration server from a fifth communication device; receiving data associated with a domain name query; and obtaining address information of the configuration server based on the data associated with the domain name query; Here, the fifth communication device is used to verify address information of the configuration server based on data related to the domain name query result.

[0265] Optionally, the first rule of data processing is: performing an allow-pass operation on the first data; and performing an operation on the second data to not allow it to pass or to discard the second data.

[0266] Optionally, the third acquisition module 901 specifically: when it is confirmed that the terminal accesses the first network through the first access method, to obtain third information; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0267] The third communication device 900 according to the embodiment of the present application can perform each process performed by the third communication device in the embodiment of the information processing method shown in FIG. 4 and can obtain the same beneficial effects, and will not be further described here to avoid repetition of the description.

[0268] Referring to FIG. 10, it is a structural diagram of a fourth communication device according to an embodiment of the present application. As shown in FIG. 10, the fourth communication device 1000 includes: a fourth transmitting module 1001 for transmitting first information; Here, the first information includes at least one of domain name server address information and configuration server address information.

[0269] Optionally, the fourth sending module 1001 specifically includes: used to transmit first information when it is confirmed that the terminal accesses the first network through the first access method; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0270] The fourth communication device 1000 according to the embodiment of the present application can execute each process performed by the fourth communication device in the embodiment of the information processing method shown in FIG. 5 and can obtain the same beneficial effects, and will not be further described here to avoid repetition of the description.

[0271] In the embodiments of the present application, the configuration device and the data control device may each be a device, an operating system, or an electronic device, a component in a terminal, an integrated circuit, or a chip. The device or electronic device may be a mobile terminal or a non-mobile terminal. Exemplarily, the mobile terminal may include, but is not limited to, the types of terminals 11 listed above. The non-mobile terminal may be, for example, a server, a network-attached storage (NAS), a personal computer (PC), a television (Television), a teller machine, a self-service machine, etc., and the embodiments of the present application are not specifically limited thereto.

[0272] Optionally, as shown in Figure 11, an embodiment of the present application further provides a communication device 1100, which includes a processor 1101, a memory 1102, and a program or instruction stored in the memory 1102 and operable on the processor 1101. For example, if the communication device 1100 is a terminal, when the program or instruction is executed by the processor 1101, it can realize each process of the embodiment of the information processing method shown in Figure 5 and achieve the same technical effect. If the communication device 1100 is a network-side device, when the program or instruction is executed by the processor 1101, it can realize each process of the embodiment of the information processing method shown in Figure 2, Figure 3 or Figure 4 and achieve the same technical effect. In order to avoid repetition, no further description will be given here.

[0273] An embodiment of the present application further provides a terminal including a processor and a communication interface, wherein the communication interface is used to transmit first information, where the first information includes at least one of domain name server address information and configuration server address information.

[0274] This terminal embodiment corresponds to the fourth communication device-side method embodiment, and the implementation processes and realization modes of the above method embodiments can be applied to this terminal embodiment, and the same technical effects can be achieved. Specifically, Figure 12 is a schematic diagram of the hardware structure realizing the terminal of the embodiment of this application.

[0275] The terminal 1200 includes at least some components such as, but not limited to, a radio frequency unit 1201, a network module 1202, an audio output unit 1203, an input unit 1204, a sensor 1205, a display unit 1206, a user input unit 1207, an interface unit 1208, a memory 1209, and a processor 1210.

[0276] As will be understood by those skilled in the art, terminal 1200 may further include a power source (e.g., a battery) for powering each component, and the power source may be logically connected to processor 1210 by a power management system, thereby enabling the power management system to realize functions such as charge / discharge management and power consumption management. The terminal structure shown in FIG. 12 does not constitute a limitation on the terminal, and the terminal may include more or fewer components than those shown, or a combination of some components, or a different configuration of components, which will not be further described here.

[0277] It should be understood that in the embodiment of the present application, the input unit 1204 may include a graphics processing unit (GPU) 12041 and a microphone 12042, and the graphics processor 12041 processes image data of still or video images captured by an image capture device (e.g., a camera) in a video capture mode or an image capture mode. The display unit 1206 may include a display panel 12061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1207 includes a touch panel 12071 and other input devices 12072. The touch panel 12071 is also called a touch screen. The touch panel 12071 may include two parts: a touch detection device and a touch controller. The other input devices 12072 may include, but are not limited to, a physical keyboard, function keys (e.g., volume control buttons, switch buttons, etc.), a trackball, a mouse, and a control lever, which will not be further described herein.

[0278] In the embodiment of the present application, the radio frequency unit 1201 receives downlink data from the network side device, then processes the data in the processor 1210, and transmits uplink data to the network side device. Generally, the radio frequency unit 1201 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, etc.

[0279] The memory 1209 may be used to store software programs or instructions and various data. The memory 1209 may primarily include a program or instruction storage area and a data storage area, where the program or instruction storage area can store an operating system, an application program or instructions required for at least one function (e.g., audio playback function, image playback function, etc.), etc. The memory 1209 may include high-speed random access memory or nonvolatile memory, where the nonvolatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. For example, the memory 1209 may be at least one magnetic disk memory device, flash memory device, or other nonvolatile solid-state memory device.

[0280] Processor 1210 may include one or more processing units. Optionally, processor 1210 may integrate an application processor and a modem processor. Here, the application processor mainly processes an operating system, a user interface, and application programs or instructions, and the modem processor mainly processes wireless communications, such as a baseband processor. It can be understood that the modem processor does not have to be integrated into processor 1210.

[0281] Here, the radio frequency unit 1201 is used to transmit first information, where the first information includes at least one of domain name server address information and configuration server address information.

[0282] Optionally, the transmitting of the first information performed by the radio frequency unit 1201 includes transmitting the first information when it is confirmed that the terminal accesses the first network by a first access method; Here, the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

[0283] The terminal 1200 according to the embodiment of the present application can perform each process in the embodiment of the method shown in FIG. 5 and obtain the same beneficial effects, and will not be further described here to avoid repetition of the description.

[0284] An embodiment of the present application further provides a network side device, which includes a processor and a communication interface.

[0285] In an embodiment in which the network-side device is a first communication device, the communication interface is used to obtain first information including at least one of domain name server address information and configuration server address information; The processor is adapted to perform a first operation based on the first information, wherein the first operation comprises: determining first policy information; and controlling the communication interface to transmit the first information or the first policy information; wherein the first policy information is used to determine a first rule of data processing, and the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address, and the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; This first communication device embodiment corresponds to the method embodiment shown in Figure 2, and the implementation processes and realization methods of the above method embodiment can all be applied to this first communication device embodiment and can achieve the same technical effects.

[0286] In an embodiment in which the network-side device is a second communication device, the communication interface is used to acquire second information including at least one of first information and first policy information; The processor is adapted to perform a second operation based on the second information, wherein the second operation comprises: determining the first rules for data processing; and controlling the communication interface to transmit the first information or the first rule of the data processing; wherein the first rule of data processing is used to perform data passing-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0287] This second communication device embodiment corresponds to the method embodiment shown in Figure 3, and the implementation processes and realization methods of the above method embodiments can all be applied to this second communication device embodiment and can achieve the same technical effects.

[0288] In an embodiment in which the network-side device is a third communication device, the communication interface is used to acquire third information including at least one of first information and a first rule of data processing; The processor is adapted to perform a third operation based on the third information, wherein the third operation comprises: determining a first rule for the data processing based on the first information; and performing a data passing-related control on the first data and / or the second data based on the received or determined first rule of data processing; wherein the first rule of data processing is used to perform data passage-related control on the first data and / or the second data; the first data includes at least one of data related to a domain name server address and data related to a configuration server address; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The first information includes at least one of domain name server address information and configuration server address information.

[0289] This third embodiment of the communication device corresponds to the method embodiment shown in Figure 4, and the implementation processes and realization methods of the above method embodiments can all be applied to this third embodiment of the communication device, and the same technical effects can be achieved.

[0290] Specifically, an embodiment of the present application further provides a network side device. As shown in Fig. 13, the network side device 1300 includes an antenna 1301, a radio frequency device 1302, and a baseband device 1303. The antenna 1301 and the radio frequency device 1302 are connected to each other. In the uplink direction, the radio frequency device 1302 receives information through the antenna 1301 and transmits the received information to the baseband device 1303 for processing. In the downlink direction, the baseband device 1303 processes the information to be transmitted and transmits it to the radio frequency device 1302, and the radio frequency device 1302 processes the received information and then transmits it through the antenna 1301.

[0291] The above frequency band domain processing device may be located in a baseband device 1303, and the method performed by the network side equipment in the above embodiments may be implemented in the baseband device 1303, which includes a processor 1304 and a memory 1305.

[0292] The baseband device 1303 may include, for example, at least one baseband board, on which multiple chips are installed, and as shown in FIG. 13, one of the chips is, for example, a processor 1304, which is connected to a memory 1305, and calls the program in the memory 1305 to perform the network equipment operations shown in the above method embodiments.

[0293] The baseband device 1303 may further include a network interface 1306, which is used to exchange information with the radio frequency device 1302, and this interface may be, for example, a Common Public Radio Interface (CPRI).

[0294] Specifically, the network side device of the embodiment of the present application further includes instructions or programs stored in memory 1305 and capable of running on processor 1304, and processor 1304 can call the instructions or programs in memory 1305 to execute the methods performed by each module shown in Figure 7, Figure 8 or Figure 9, and achieve the same technical effects, which will not be further described here to avoid repetition.

[0295] The embodiments of the present application further provide a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the respective processes of the embodiments of the information processing method, configuration method or data control method can be realized and the same technical effects can be achieved. In order to avoid repetition, no further description will be given here.

[0296] The processor may be the processor in the terminal described in the above embodiment. The readable storage medium may include a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0297] The embodiments of the present application further provide a chip, the chip including a processor and a communication interface, the communication interface is coupled to the processor, the processor runs a program or instruction, and is used to realize each process of the embodiments of the information processing method, configuration method or data control method, and can achieve the same technical effect. In order to avoid repetition, no further description will be given here.

[0298] It should be understood that the chips referred to in the embodiments of this application may be referred to as system level chips, system chips, chip systems, or system-on-chips.

[0299] It should be noted that, in this specification, the terms "comprise," "include," "includes," or any other variant thereof are intended to cover the non-exclusive "comprise," whereby a process, method, article, or apparatus comprising a set of elements not only includes those elements but also other elements not expressly listed or inherent in such process, method, article, or apparatus. Absent further limitations, an element defined by the phrase "comprises one of" does not preclude the presence of other identical elements in the process, method, article, or apparatus comprising that element. It should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may include performing functions in an essentially simultaneous manner or in the reverse order based on the functions involved. For example, the described method may be performed in a different order than described, and various steps may be added, omitted, or combined. Furthermore, features described with reference to some examples may be combined in other examples.

[0300] As will be apparent to those skilled in the art from the above description of the embodiments, the methods of the above embodiments can be realized in the form of software and a necessary general-purpose hardware platform. Of course, they can also be realized in hardware, but in many cases the former is a more preferred embodiment. Based on this understanding, the technical proposal of the present application, in substance or in part contributing to the prior art, may be embodied in the form of a computer software product, which is stored in a storage medium (e.g., ROM / RAM, magnetic disk, optical disk) and includes some instructions for causing a terminal (which may be a mobile phone, computer, server, air conditioner, network device, etc.) to execute the methods described in each embodiment of the present application.

[0301] Although the embodiments of the present application have been described above in conjunction with the drawings, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not limiting. Those skilled in the art can take the teachings of the present application into account and implement many forms without departing from the spirit and scope of the claims, all of which fall within the scope of protection of the present application.

Claims

1. An information processing method used in a first communication device that is a PCF (Policy Control Function), comprising: Obtaining first information, wherein the first information includes domain name server address information, or the first information includes domain name server address information and configuration server address information; and performing a first operation based on the first information, wherein the first operation comprises: determining first policy information; and transmitting the first policy information to a second communication device that is a Session Management Function (SMF); wherein the first policy information includes associated policy information that requests performing an operation on the first data to allow it to pass; An information processing method, wherein the first data includes data related to a domain name server address in a restricted data channel, or the first data includes data related to a domain name server address in a restricted data channel and data related to a configuration server address in a restricted data channel.

2. The first policy information further includes: associated policy information requiring a control operation to be performed on the second data, either not allowing it to pass or discarding said second data; the first information, 2. The information processing method of claim 1, wherein the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data.

3. The first policy information is used to determine a first rule of data processing, and the first rule of data processing comprises: a rule that performs an allow-pass operation on the first data; The information processing method according to claim 1 , further comprising at least one of the following:

4. The information processing method according to claim 1 , further comprising transmitting the first information.

5. performing a first operation based on the first information, When it is determined that the terminal accesses the first network through a first access method, performing a first operation based on the first information; 2. The information processing method of claim 1, wherein the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

6. The information processing method according to claim 1 , wherein the domain name server address information includes a domain name server address, and the configuration server address information includes a configuration server (Provisioning Server, PVS) address.

7. The information processing method described in claim 1, wherein the restricted data channel is for remote provisioning of subscription information for a terminal.

8. An information processing method used in a second communication device that is an SMF, comprising: obtaining first policy information from a first communication device that is a PCF, the first policy information including associated policy information requesting that an operation be performed on first data to allow it to pass; and performing a second operation based on the first policy information, wherein the second operation includes: determining the first rules for data processing; transmitting the first rule of data processing to a third communication device that is a UPF (User Plane Function); wherein the first rule for data processing includes a rule to execute an operation on the first data to allow it to pass; An information processing method, wherein the first data includes data related to a domain name server address in a restricted data channel, or the first data includes data related to a domain name server address in a restricted data channel and data related to a configuration server address in a restricted data channel.

9. The operation of determining the first rule of data processing is: setting a data detection rule for the first data; setting a data transfer rule for the first data and allowing the first data to pass; setting a data transfer rule for the second data, and not allowing the second data to pass or discarding the second data; and at least one of not setting a data detection rule and / or a data transfer rule for the second data, 9. The information processing method of claim 8, wherein the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data.

10. The information processing method according to claim 8 , wherein the first rule of data processing relates to at least address information of a domain name query server.

11. 11. The information processing method of claim 10, wherein the first rule of data processing also relates to address information of a remote configuration server and is used to perform a data passing operation on data related to a remote configuration query.

12. further comprising receiving first information from the first communication device; 9. The information processing method according to claim 8, wherein the first information includes at least one of domain name server address information and configuration server address information.

13. The first rule of data processing further comprises: a rule for performing an operation on the second data that does not allow the second data to pass or discards the second data; wherein the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; Or, the first rule of data processing includes first information; 9. The information processing method according to claim 8, wherein the first information includes at least one of domain name server address information and configuration server address information.

14. The information processing method according to claim 12 , wherein the domain name server address information includes a domain name server address, and the configuration server address information includes a configuration server (Provisioning Server, PVS) address.

15. performing the second operation based on the first policy information; performing a second operation based on the first policy information when it is determined that the terminal accesses the first network through a first access method; 9. The information processing method of claim 8, wherein the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method that can only establish a restricted data channel, and an access method that cannot establish an unrestricted data channel.

16. An information processing method used in a third communication device that is a UPF, comprising: Obtaining a first rule of data processing from a second communication device that is an SMF; and performing a third operation based on the first rule of processing the data; wherein the first rule for data processing includes a rule to perform an operation on the first data to allow it to pass; The third operation is performing an operation on the first data to allow it to pass based on a first rule of the data processing; An information processing method, wherein the first data includes data related to a domain name server address in a restricted data channel, or the first data includes data related to a domain name server address in a restricted data channel and data related to a configuration server address in a restricted data channel.

17. obtaining the first rule of data processing includes obtaining the first rule of data processing when it is confirmed that the terminal accesses the first network by a first access method; 17. The information processing method of claim 16, wherein the first access method includes at least one of an access method for accessing the network to obtain a certificate and / or a subscription, an access method for restricted access to the network, an access method for accessing the network using a default certificate, an access method in which only a restricted data channel can be established, and an access method in which an unrestricted data channel cannot be established.

18. The first rule of data processing further comprises: performing an operation on the second data to not allow it to pass or to discard the second data; the second data includes at least one of data not related to a domain name server address, data not related to a configuration server address, and data that is not the first data; The information processing method according to claim 16 , wherein the domain name server address information includes a domain name server address, and the configuration server address information includes a configuration server (Provisioning Server, PVS) address.

19. A network side device comprising a processor, a memory, and a program or instructions stored in the memory and operable on the processor, the network side device realizing the steps of the information processing method according to any one of claims 1 to 7 when the program or instructions are executed by the processor.

20. A network-side device comprising a processor, a memory, and a program or instruction stored in the memory and capable of running on the processor, wherein when the program or instruction is executed by the processor, the network-side device realizes a step in an information processing method described in any one of claims 8 to 15.

21. A network-side device comprising a processor, a memory, and a program or instruction stored in the memory and capable of running on the processor, wherein when the program or instruction is executed by the processor, the network-side device realizes a step in an information processing method described in any one of claims 16 to 18.

Citation Information

Patent Citations

  • Control device, border router, control method and control program

    WO2016080446A1