Licensing method and device

The authorization method for UE connection services, incorporating location and time ranges, addresses the inflexibility in existing networks, preventing interference and ensuring reliable service provision.

JP7778960B2Active Publication Date: 2025-12-02HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024556235
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-03-21
Filing Date
2023-03-13
Publication Date
2025-12-02
Estimated Expiration
2043-03-13

AI Technical Summary

Technical Problem

Existing communication networks lack flexibility in controlling and managing when user equipment (UE) provides connection services, leading to potential interference by allowing services outside authorized locations or time ranges.

Method used

An authorization method that considers operation permission instruction information along with location and time ranges to dynamically control UE connection services, ensuring services are provided only within permitted boundaries.

Benefits of technology

This approach enhances network control and avoids interference by preventing UE services outside authorized areas or times, ensuring service continuity and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007778960000001
    Figure 0007778960000001
  • Figure 0007778960000002
    Figure 0007778960000002
  • Figure 0007778960000003
    Figure 0007778960000003
Patent Text Reader

Abstract

An authorization method and apparatus are provided. The method includes: an access management network element obtains operation permission indication information and authorization conditions. The operation permission indication information indicates that a terminal device is allowed to provide a connection service, and the authorization conditions include an authorized location range of the connection service and / or an authorized time range of the connection service. The access management network element sends an authorization result to an access network element accessed by the terminal device based on the authorized location range and / or the authorized time range. The authorization result indicates that the terminal device is not allowed to provide a connection service or that the terminal device is allowed to provide a connection service. Even if the operation permission indication information indicates that the terminal device is allowed to provide a connection service, the access management network element may determine that the terminal device is not allowed to provide a connection service based on the authorization conditions. This may avoid the terminal device from providing a connection service outside the authorized location range and / or the authorized time range.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Technical Field

[0002] The present application relates to the field of communication technologies, and in particular to a licensing method and apparatus. [Background technology]

[0003] During the user equipment (UE) registration process, the unified data management (UDM) provides the UE's subscription data for the access and mobility management function (AMF). The UE's subscription data includes operation allowance indication information. The operation allowance indication information indicates whether the UE is authorized to provide connectivity services or whether the UE is not authorized to provide connectivity services. The AMF sends a UE authorization indication or a UE non-authorization indication to the RAN based solely on the operation allowance indication information, so that the RAN controls the UE's connectivity services.

[0004] The network controls and manages the connection service of the UE based only on the operation allowance instruction information. For example, when the operation allowance instruction information indicates that the UE is authorized to provide the connection service, the UE can provide the connection service at any location at any time. This leads to poor flexibility in the network in controlling and managing when the UE provides the connection service. Summary of the Invention [Problem to be solved by the invention]

[0005] The embodiments of the present application provide an authorization method and apparatus for flexibly and dynamically controlling and managing when a UE provides connection services. [Means for solving the problem]

[0006] According to a first aspect, an authorization method is provided, including the following steps: an access management network element obtains operation permission instruction information and authorization conditions; the operation permission instruction information indicates that a terminal device is authorized to provide a connection service, and the authorization conditions include an authorized location range and / or an authorized time range for the connection service; the access management network element transmits an authorization result to an access network element accessed by the terminal device based on the authorization conditions; the authorization result indicates that the terminal device is not authorized to provide the connection service or that the terminal device is authorized to provide the connection service.

[0007] In response, the access network element receives the authorization result and then controls the connection service of the terminal device based on the authorization result. The terminal device may perform a corresponding operation based on the control of the access network element. For example, the terminal device may release resources for providing the connection service or may provide the connection service.

[0008] In the related art, an access management network element allows a terminal device to provide a connection service at any location and at any time based only on operation allowance indication information. This may cause poor flexibility in the network to control and manage when a UE provides a connection service, and may also cause interference with existing communications when the terminal device is outside the permitted location range or permitted time range. However, in the above solution, in addition to the operation allowance indication information, the access management network element may also obtain permission conditions. In this way, even if the operation allowance indication information indicates that the terminal device is allowed to provide a connection service, the access management network element can determine that the terminal device is not allowed to provide a connection service based on the permission conditions. This can flexibly and dynamically control and manage when a UE provides a connection service, preventing the terminal device from providing a service outside the permitted location range and / or permitted time range.

[0009] For example, the access management network element may transmit an authorization result to the access network element based on an authorized location range and / or an authorized time range. More specifically, the access management network element may transmit an authorization result to the access network element based on the location of the terminal device and the authorized location range of the connection service, and / or the current time and the authorized time range of the connection service.

[0010] In one possible implementation, the access management network element can further send the authorization result to the terminal device.

[0011] Correspondingly, the terminal device may receive the authorization result and then perform a corresponding operation based on the authorization result. For example, the authorization result may indicate that the terminal device is not allowed to provide the connection service, in which case the terminal device may release resources for providing the connection service. The authorization result may indicate that the terminal device is allowed to provide the connection service, in which case the terminal device may provide the connection service.

[0012] Optionally, the terminal device may perform corresponding actions based on the control and / or authorization results of the access network element.

[0013] In one possible implementation, when transmitting an authorization result to an access network element accessed by a terminal device based on the authorization conditions, the access management network element may determine the authorization result based on the authorization conditions (e.g., authorized location range and / or authorized time range) and transmit the authorization result to the access network element.

[0014] For example, the access management network element can determine the authorization result based on the location of the terminal device and the authorized location range of the connection service. In another example, the access management network element can determine the authorization result based on the current time and the authorized location range of the connection service.

[0015] In one possible implementation, the license conditions include a licensed time range for the connection service. When the access management network element determines the authorization result based on the authorized time range, and the current time is outside the authorized time range, the access management network element may determine that the authorization result indicates that the terminal device is not allowed to provide the connection service. When the access management network element determines the authorization result based on the authorized time range, and the current time is within the authorized time range, the access management network element may determine that the authorization result indicates that the terminal device is allowed to provide the connection service. In this implementation, this can avoid interference with existing communications caused by providing a service by the terminal device outside the authorized time range.

[0016] In one possible implementation, the license conditions include the licensed location range of the connectivity service.

[0017] When the access management network element determines an authorization result based on an authorized location range, and the terminal device is outside the authorized location range, the access management network element may determine that the authorization result indicates that the terminal device is not allowed to provide connectivity services. When the access management network element determines an authorization result based on an authorized location range, and the terminal device is within the authorized location range, the access management network element may determine that the authorization result indicates that the terminal device is allowed to provide connectivity services. In this implementation, this can avoid interference with existing communications caused by providing services by a terminal device outside the authorized location range.

[0018] For example, the terminal device may obtain the terminal device's location from a location management network element and determine whether the terminal device is outside the permitted location range or within the permitted location range based on the terminal device's location and the permitted location range.

[0019] In one possible implementation, the license conditions include the licensed location range of the connectivity service.

[0020] The access management network element determines the authorization result based on the authorized location range, and when the terminal device is outside the authorized location range, the access management network element receives notification information sent by the location management network element. The notification information is used to notify that the terminal device is outside the authorized location range or within the authorized location range. When the notification information is used to notify that the terminal device is outside the authorized location range, the access management network element determines that the authorization result indicates that the terminal device is not allowed to provide connection service. When the notification information is used to notify that the terminal device is within the authorized location range, the access management network element determines that the authorization result indicates that the terminal device is allowed to provide connection service. In this implementation, this can avoid interference with existing communications caused by providing service by a terminal device outside the authorized location range.

[0021] For example, a terminal device may send a request message to a location management network element. The request message is used to request whether the terminal device is outside or within an authorized location range. The request message may include information about the authorized location range.

[0022] In one possible implementation, the license conditions include the licensed location range of the connectivity service.

[0023] The access management network element determines an authorization result based on an authorized location range, and when the terminal device is outside the authorized location range and the tracking area in which the terminal device is located is outside the tracking area range corresponding to the authorized location range, the access management network element determines that the authorization result indicates that the terminal device is not allowed to provide connectivity service. When the access management network element determines an authorization result based on an authorized location range and the terminal device is outside the authorized location range and the tracking area in which the terminal device is located is within the tracking area range corresponding to the authorized location range, the access management network element determines that the authorization result indicates that the terminal device is allowed to provide connectivity service. In this implementation, this can avoid interference with existing communications caused by providing services by a terminal device outside the authorized location range.

[0024] For example, the access management network element may obtain a tracking area range corresponding to the authorized location range from a network exposure network element.

[0025] In one possible implementation, the connectivity service includes an integrated access and backhaul IAB service, and the terminal device is an IAB terminal device. Alternatively, the connectivity service includes an in-vehicle relay VMR service, and the terminal device is a VMR device. Alternatively, the connectivity service includes a relay service, and the terminal device is a relay terminal device. Alternatively, the VMR may be a mobile base station relay.

[0026] In one possible implementation, the permitted location range includes one or more of a permitted route for the connectivity service, a permitted area for the connectivity service, an area in which the connectivity service is permitted to be provided, or an area in which the connectivity service is not permitted to be provided.

[0027] For example, in an IAB scenario, the permitted location range includes the permitted route of the connectivity service and the permitted area of ​​the connectivity service. As another example, in an L2 relay scenario, the permitted location range includes the area where the connectivity service is allowed to be provided and the area where the connectivity service is not allowed to be provided.

[0028] According to a second aspect, there is provided an authorization method, which includes the following processes: a data management network element obtains operation permission instruction information and authorization conditions; the operation permission instruction information indicates that a terminal device is authorized to provide a connection service, and the authorization conditions include an authorized location range of the connection service and / or an authorized time range of the connection service; the data management network element sends an authorization result to an access management network element based on the authorization conditions; the authorization result indicates that the terminal device is not authorized to provide the connection service or that the terminal device is authorized to provide the connection service.

[0029] In one possible implementation, when sending a permission result based on the permission conditions to the access management network element, the data management network element can determine the permission result based on the permission conditions (e.g., the permitted location range and / or the permitted time range) and send the permission result to the access management network element.

[0030] For example, the data management network element may determine the authorization result based on the location of the terminal device and the authorized location range of the connection service. In another example, the data management network element may determine the authorization result based on the current time and the authorized location range of the connection service.

[0031] In one possible implementation, the license conditions include a licensed time range for the connection service.

[0032] The data management network element may determine the authorization result based on the authorized time range, and when the current time is outside the authorized time range, the data management network element may determine that the authorization result indicates that the terminal device is not allowed to provide the connection service. The data management network element may determine the authorization result based on the authorized time range, and when the current time is within the authorized time range, the data management network element may determine that the authorization result indicates that the terminal device is allowed to provide the connection service. In this implementation, this can avoid interference with existing communications caused by providing services by the terminal device outside the authorized time range.

[0033] In one possible implementation, the license conditions include the licensed location range of the connectivity service.

[0034] The data management network element may determine an authorization result based on an authorized location range, and when the terminal device is outside the authorized location range, the data management network element may determine that the authorization result indicates that the terminal device is not allowed to provide connectivity services. The data management network element may determine an authorization result based on an authorized location range, and when the terminal device is within the authorized location range, the data management network element may determine that the authorization result indicates that the terminal device is allowed to provide connectivity services. In this implementation, this can avoid interference with existing communications caused by providing services by terminal devices outside the authorized location range.

[0035] For example, the terminal device may obtain the terminal device's location from a gateway mobile location center and, based on the terminal device's location and the authorized location range, determine whether the terminal device is outside or within the authorized location range.

[0036] In one possible implementation, the license conditions include the licensed location range of the connectivity service.

[0037] When the data management network element determines the authorization result based on the authorized location range, the data management network element receives notification information sent by the gateway mobile location center. The notification information is used to notify that the terminal device is outside the authorized location range or is within the authorized location range. When the notification information is used to notify that the terminal device is outside the authorized location range, the data management network element determines that the authorization result indicates that the terminal device is not allowed to provide connection service. When the notification information is used to notify that the terminal device is within the authorized location range, the data management network element determines that the authorization result indicates that the terminal device is allowed to provide connection service. In this implementation, this can avoid interference with existing communications caused by providing service by a terminal device outside the authorized location range.

[0038] For example, the terminal device may send a request message to the gateway mobile location center to request whether the terminal device is outside or within an authorized location range. The request message may include information about the authorized location range.

[0039] In one possible implementation, the connectivity service includes an integrated access and backhaul IAB service, and the terminal device is an IAB terminal device. Alternatively, the connectivity service includes an in-vehicle relay VMR service, and the terminal device is a VMR device or a mobile base station relay device. Alternatively, the connectivity service includes a relay service, and the terminal device is a relay terminal device.

[0040] In one possible implementation, the allowed location range includes one or more of an allowed route for the connectivity service, an allowed area for the connectivity service, an area in which the connectivity service is allowed to be provided, or an area in which the connectivity service is not allowed to be provided.

[0041] For example, in an IAB scenario, the permitted location range includes the permitted route of the connectivity service and the permitted area of ​​the connectivity service. As another example, in an L2 relay scenario, the permitted location range includes the area where the connectivity service is allowed to be provided and the area where the connectivity service is not allowed to be provided.

[0042] According to a third aspect, there is provided an authorization method, which includes the following steps: a terminal device receives a first authorization result sent by an access management network element; the first authorization result indicates that the terminal device is not allowed to provide a connection service; and the terminal device releases resources for providing the connection service based on the first authorization result.

[0043] In the above solution, the access management network element may send an authorization result to the terminal device to indicate that the terminal device is not allowed to provide connection service, which avoids interference with existing communications caused by providing service by the terminal device outside the authorized location range and / or authorized time range.

[0044] In one possible implementation, when releasing resources for providing connection services, the terminal device releases the F1 interface, which is used for transmitting information between the terminal device and the access network element.

[0045] In one possible implementation, the terminal device may further receive a second authorization result sent by the access management network element. The second authorization result indicates that the terminal device is allowed to provide the connection service. The terminal device may provide the connection service based on the second authorization result. In this implementation, the access management network element can indicate to the terminal device that the terminal device is allowed to provide the connection service to ensure service continuity and reliability.

[0046] According to a fourth aspect, there is provided an authorization method, the method comprising the steps of: a terminal device receiving a connection control message sent by an access network element accessed by the terminal device, the connection control message being used to control the terminal device not to provide a connection service, and the terminal device releasing resources for providing the connection service based on the connection control message.

[0047] In the aforementioned solution, the terminal device, under the control of the access network element, can release resources for providing connectivity services to avoid interference with existing communications caused by the provision of services by the terminal device outside the authorized location range and / or authorized time range.

[0048] In one possible implementation, when releasing resources for providing connection services, the terminal device releases the F1 interface, which is used for transmitting information between the terminal device and the access network element.

[0049] In one possible implementation, the connection control message may be further used to control a terminal device to provide a connection service. The terminal device may further provide the connection service based on the connection control message. In this implementation, the terminal device can provide the connection service under the control of an access network element to ensure service continuity and reliability.

[0050] According to a fifth aspect, there is provided a communications device. The communications device may be an access management network element, a data management network element, or a terminal device, or may be a chip disposed in the access management network element, the data management network element, or the terminal device. The communications device may implement a method provided in any one of the preceding aspects.

[0051] The communication device includes corresponding modules, units, or means for performing the aforementioned methods. The modules, units, or means may be implemented by using hardware or software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned functions.

[0052] According to a sixth aspect, there is provided a communication device, the communication device including a transceiver unit. Optionally, the communication device further includes a processing unit. The communication device may implement the method provided in any one of the above aspects or implementations of the aspects.

[0053] According to a seventh aspect, a communication device is provided, the communication device including a processor. The processor may be configured to perform a method provided in any one of the aforementioned aspects or implementations of the aspects. Optionally, the device further includes a memory. The processor is coupled to the memory. The memory is configured to store computer programs or instructions. The processor may execute the programs or instructions in the memory, thereby causing the device to perform a method provided in any one of the aforementioned aspects or implementations of the aspects.

[0054] According to an eighth aspect, there is provided a communications device. The device includes an interface circuit and a logic circuit. The logic circuit is coupled to the interface circuit. The interface circuit may be a code / data read / write interface circuit. The interface circuit is configured to receive computer-executable instructions (the computer-executable instructions may be stored in a memory and read directly from the memory or read via another component) and transmit the computer-executable instructions to the logic circuit, which executes the computer-executable instructions to perform a method provided in any one of the aforementioned aspects or implementations of the aspects.

[0055] In some possible designs, the communication device may be a chip or a chip system.

[0056] According to a ninth aspect, there is provided a communication device, the communication device including a processor coupled to a memory, the processor configured to read instructions stored in the memory, receive signals via the receiver, and transmit signals via the transmitter to perform a method provided in any one of the preceding aspects or implementations of the aspects.

[0057] Optionally, there may be one or more processors and one or more memories. Optionally, the memory may be integrated with the processor, or the memory and processor may be located separately.

[0058] In a specific implementation process, the memory may be a non-transitory memory, such as a read-only memory (ROM). The memory and the processor may be integrated on the same chip or may be separately located on different chips. The type of memory and the manner in which the memory and the processor are located are not limited by this application.

[0059] The communication device may be a chip, and the processor may be implemented using hardware or software. When the processor is implemented using hardware, it may be a logic circuit, an integrated circuit, etc. When the processor is implemented using software, it may be a general-purpose processor and is implemented by reading software code stored in memory. The memory may be integrated into the processor or may exist independently and be located outside the processor.

[0060] According to a tenth aspect, a processor is provided, including an input circuit, an output circuit, and a processing circuit configured to receive signals through the input circuit and transmit signals through the output circuit, whereby the processor performs a method provided in any one of the preceding aspects or implementations of the aspects.

[0061] In a specific implementation process, the processor may be a chip, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, various logic circuits, etc. The input signal received by the input circuit may be, for example, but not limited to, received and input by a receiver, and the signal output by the output circuit may be, for example, but not limited to, output to a transmitter and transmitted by the transmitter. Also, the input circuit and the output circuit may be the same circuit. This circuit separately acts as an input circuit and an output circuit at different moments. The specific implementation of the processor and various circuits is not limited in this application.

[0062] According to an eleventh aspect, there is provided a communications device, including a logic circuit and an input / output interface. The input / output interface is configured to communicate with a module other than the communications device. The logic circuit is configured to execute a computer program or instructions to perform a method provided in any one of the designs of the preceding aspects. The communications device may be a device including the first access network element, the second access network element, or the access management network element, the access management network element, the data management network element, or the terminal device of any one of the preceding aspects, or a device, such as a chip, included in the access management network element, the data management network element, or the terminal device.

[0063] Alternatively, the input / output interface may be a code / data read / write interface circuit or a communication interface configured to receive computer programs or instructions (which may be stored in a memory and read directly from the memory or read through another component) and transmit the computer programs or instructions to the input / output interface, which then executes the computer programs or instructions to perform the method of any one of the aforementioned aspects.

[0064] Optionally, the communication device may be a chip.

[0065] According to a twelfth aspect, there is provided a computer program product, which includes a computer program (which may also be referred to as code or instructions), which, when executed, causes a computer to perform a method provided in any one of the preceding aspects or implementations of the aspects.

[0066] According to a thirteenth aspect, a computer-readable medium is provided. The computer-readable medium stores a computer program (also called code or instructions). When the computer program is executed on a computer, the computer performs a method provided in any one of the preceding aspects or implementations of the aspects.

[0067] According to a fourteenth aspect, there is provided a chip system. The chip system includes a processor and an interface and is configured to support a communication device in implementing the functionality provided in any one of the aforementioned aspects or implementations of the aspects. In one possible design, the chip system further includes a memory configured to store necessary information and data of the communication device. The chip system may include a chip, or may include a chip and other discrete components.

[0068] According to a fifteenth aspect, there is provided a chip device. The chip device includes an input interface and / or an output interface. The input interface may implement a receiving function provided in any one of the aforementioned aspects or implementations of the aspects. The output interface may implement a transmitting function provided in any one of the aforementioned aspects or implementations of the aspects.

[0069] According to a sixteenth aspect, there is provided a functional entity configured to implement a method as provided in any one of the preceding aspects or implementations of the aspects.

[0070] According to a seventeenth aspect, there is provided a communications system, comprising an access management network element and an access network element configured to perform the method of the first aspect.

[0071] Optionally, the communication system may further include a terminal device configured to perform the method of the third and / or fourth aspect.

[0072] According to an eighteenth aspect, there is provided a communications system, comprising a data management network element and an access management network element configured to perform the method of the second aspect.

[0073] Optionally, the communication system may further comprise a terminal device and an access network element configured to perform the method of the third aspect and / or the fourth aspect.

[0074] For the technical effects provided by any one of the implementations of the fifth to eighteenth aspects, please refer to the technical effects provided by the first to fourth aspects, and the details will not be described again in this specification. [Brief explanation of the drawings]

[0075] [Figure 1A] A diagram of the architecture of a 5G communication system. [Figure 1B] A diagram of the IAB architecture. [Figure 2] Diagram of the mobile IAB architecture. [Figure 3] 1 is a schematic flowchart of network access for an IAB node. [Figure 4] FIG. 1 is a diagram of the L2 relay architecture. [Figure 5] 1 is a schematic flowchart of a connection setup for a remote UE; [Figure 6] 10 is a schematic flowchart of the start of UE positioning. [Figure 7] 10 is a schematic flowchart of the end of UE positioning. [Figure 8A] FIG. 1 is a diagram of a permission process according to an embodiment of the present application. [Figure 8B] FIG. 10 is a diagram of another authorization process according to an embodiment of the present application. [Figure 9] 1 is a schematic flowchart of authorization in an IAB scenario according to an embodiment of the present application; [Figure 10] 1 is a schematic flowchart of authorization in an L2 relay scenario according to an embodiment of the present application; [Figure 11] FIG. 1 is a diagram of a permission process according to an embodiment of the present application. [Figure 12] 1 is a schematic flowchart of authorization in an IAB scenario according to an embodiment of the present application; [Figure 13] 1 illustrates a structure of a communication device according to an embodiment of the present application; [Figure 14] 1 illustrates a structure of a communication device according to an embodiment of the present application; [Figure 15] 1 illustrates a structure of a communication device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0076] Hereinafter, embodiments of the present application will be described in detail with reference to the accompanying drawings of this specification.

[0077] The technical solutions in the embodiments of the present application may be applied to a mobile communication system, for example, a 4th generation (4G) communication system (e.g., a long term evolution (LTE) system), a 5th generation (5G) mobile communication system (e.g., a new radio (NR) system), or a future mobile communication system such as 6G.

[0078] The 3GPP standardization group is developing the next-generation mobile communication network architecture (next-generation system). This next-generation mobile communication network architecture is called the 5G network architecture. Figure 1A shows the 5G network architecture, including the terminal device part, the network device part, and the data network (DN) part.

[0079] The terminal device portion typically includes user equipment (UE). In a wireless network, a UE is a device with wireless transceiver functionality that can communicate with one or more core network (CN) elements through access network elements in a radio access network (RAN).

[0080] For example, user equipment may also be referred to as an access terminal, terminal, subscriber unit, subscriber station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, or user equipment. User equipment may be terrestrially based and may include indoor user equipment, outdoor user equipment, handheld user equipment, or vehicle-mounted user equipment, may be deployed on water (e.g., on a ship), or may be airborne (e.g., on an airplane, balloon, or satellite). User equipment may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smartphone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), etc. Alternatively, the user equipment may be a handheld or computing device with wireless communication capabilities, another device connected to a wireless modem, a vehicle-mounted device, a wearable device, an unmanned aerial vehicle device, a terminal in the Internet of Things (also called an Internet of Things device), a terminal in the Internet of Vehicles, a terminal in a 5G network, any form of terminal in a future network, a relay user equipment, a mobile termination (MT), a terminal in a future evolved public land mobile network (PLMN), etc. A relay user equipment may be, for example, a 5G residential gateway (RG).For example, the user equipment may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, or a wireless terminal in smart home. The types, categories, etc. of the terminal devices are not limited in this embodiment of the present application.

[0081] The network device portion includes a network exposure function (NEF), a network repository function (NRF), a policy control function (PCF), a UDM, an authentication server function (AUSF), an AMF, a session management function (SMF), a user plane function (UPF), an access network (AN), a network slice selection function (NSSF), etc. In a network device, the portion other than the access network portion may be called a core network portion.

[0082] The core network part includes a user plane function and a control plane function. The user plane function is mainly responsible for forwarding data packets, controlling quality of service (QoS), collecting statistics on billing information, etc. The control plane function is mainly responsible for service procedure interaction and delivering data packet forwarding policies, QoS control policies, etc. to the user plane function.

[0083] The data network DN, sometimes called a packet data network (PDN), may typically be deployed outside the operator network, e.g., a third-party network. For example, the operator network may access multiple DNs, and multiple services may be deployed on the DNs to provide services such as data services and / or voice services for the UE. The third party may be a service party other than the operator network and the UE, and may provide services such as other data services and / or other voice services for the UE. The specific expression of the third party may be specifically determined based on the actual application scenario, and is not limited herein.

[0084] An application function (AF) may or may not belong to the operator network. However, typically, the AF belongs to a third party rather than the operator network, but has a protocol relationship with the operator network. The AF is a functional network element configured to provide various services, support functions that affect data routing by using applications, access the network exposure function NEF, interact with the policy framework for policy control, etc.

[0085] For example, the following is a brief description of network functions in an operator network.

[0086] The RAN is a subnetwork of an operator network and is an implementation system between a service node (or network function) in the operator network and a UE. To access the operator network, the UE first passes through the RAN and then connects to a service node in the operator network via the RAN. In other words, the RAN exists between the UE and the core network part and provides a communication connection between the UE and the core network part. The RAN in this embodiment of the present application may refer to the access network itself or an access network element. This distinction is not made in this specification. The access network element is a device that provides wireless communication functions for the UE and may also be called an access network device, AN device, etc. Access network elements include, but are not limited to, next-generation base stations or next-generation NodeBs (gNBs) in 5G systems, evolved NodeBs (eNBs) in LTE systems, radio network controllers (RNCs), NodeBs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (HNBs), building baseband processing units (BBUs), transmitting and receiving points (TRPs), transmission points (TPs), small cell devices (picos), mobile switching centers, and network devices in future networks. It should be understood that the specific type of access network device is not limited herein. In systems using different radio access technologies, devices having the functionality of an access network device may have different names.

[0087] Optionally, in some deployments of the access device, the access device may include a central unit (CU), a distributed unit (DU), and the like.

[0088] The NEF is a control plane function provided by an operator. It provides a framework, authentication, and interfaces related to network capability disclosure and transfers information between network functions and other network functions within a 5G system. The NEF exposes the external bidirectional interface of the network capabilities to third parties in a secure manner. When another network function (e.g., an AF) needs to communicate with a third-party network, the NEF can act as an intermediary for communication with the third-party network entity. Alternatively, the NEF may act as a translator of subscribed user identities and third-party network function identities. For example, when transmitting a subscribed user's subscription permanent identifier (SUPI) from the PLMN to a third party, the NEF may translate the SUPI into an external generic public subscription identifier (GPSI) corresponding to the SUPI. In response, the NEF forwards external information to the PLMN network, avoiding another network function within the PLMN from directly contacting the external entity.

[0089] The NRF is a control plane function provided by an operator and may be configured to maintain real-time information of all network function services within the network.

[0090] The PCF is a control plane function provided by the operator and configured to create and manage user, session, and QoS flow handling policies. The PCF supports a unified policy framework to manage network behavior and provide policy rules for other control functions, subscription information relevant to policy decisions, etc.

[0091] The UDM is a control plane function provided by an operator and is responsible for storing information such as security context and subscription data of subscribed users within a PLMN. A subscribed user within an operator network may specifically be a user who uses services provided by the operator network, such as a user who uses a terminal device SIM card of China Telecom or a user who uses a terminal device SIM card of China Mobile. For example, the security context may be a cookie or token stored on a local terminal device (e.g., a mobile phone). The subscription data of a subscribed user may be the supporting services of the terminal device SIM card, such as the traffic package of the mobile phone SIM card.

[0092] The AUSF is a control plane function provided by an operator, typically for primary authentication, i.e., network authentication between a UE (subscribed user) and the operator network.

[0093] The AMF is a control plane network function provided by the operator network, and is responsible for access control and mobility management for UEs to access the operator network, such as registration management, connection management, reachability management, and mobility management, allocation of temporary user identifiers, and user authentication and authorization.

[0094] The SMF is a control plane network function provided by the operator network and is responsible for managing protocol data unit (PDU) sessions for UEs. A PDU session is a channel for transmitting PDUs, and a terminal device must transmit data with a DN through the PDU session. The SMF is responsible for setting up, maintaining, and deleting PDU sessions. The SMF performs session-related functions, such as session management (e.g., session setup, modification, and release, including tunnel maintenance between the UPF and the AN), UPF selection and control, service and session continuity (SSC) mode selection, and roaming.

[0095] The UPF is a gateway provided by an operator for communication between the operator network and the DN. The UPF includes functions related to the user plane, such as data packet routing and transmission, packet detection, service usage reporting, QoS processing, lawful interception, uplink packet detection, and downlink data packet storage.

[0096] The NSSF is a control plane network function provided by the operator network and is responsible for determining the network slice instance, selecting the AMF, etc.

[0097] In some scenarios, the core network portion may further include a location management function (LMF) for acquiring location information of the UE by using a particular positioning technique, including but not limited to a downlink observed time difference of arrival (OTDOA) positioning technique, an uplink time difference of arrival (UTDOA) positioning technique, a timing advance (TA) positioning technique, an angle of arrival (AoA) positioning technique, or another positioning technique.

[0098] In some scenarios, the core network portion may further include a gateway mobile location center (GMLC), which is primarily responsible for opening location services to external location service (LCS) clients or AFs.

[0099] In FIG. 1A, Nnef, Nausf, Nnrf, Npcf, Nudm, Naf, Namf, Nsmf, Nnssf, N1, N2, N3, N4, and N6 are interface sequence numbers. For the meanings of interface sequence numbers, see the definitions in the 3GPP standard protocol. The meanings of interface sequence numbers are not limited in this application. Note that the names of network functions and interfaces between network functions in FIG. 1A are merely examples. In a specific implementation, the interface names of the system architecture may alternatively be other names. This is not a limitation of this application.

[0100] The embodiments of the present application may be applied to an IAB scenario and a Layer-2 (L2) relay scenario.

[0101] Scenario 1: IAB Scenario An IAB base station has been proposed in 5G NR research. It is also called an IAB node. The IAB node integrates a radio access link and a radio backhaul link. The radio access link is the communication link between the UE and the IAB node. The radio backhaul link is the communication link between the IAB nodes and is primarily for data backhaul. The IAB node does not require a wired transmission network for data backhaul. Therefore, the IAB node has lower deployment requirements for a wired transmission network and can be deployed in scenarios where a wired transmission network is difficult to deploy, such as outdoor or indoor scenarios. The IAB node includes MT functionality and gNB-DU functionality. After the IAB node is initiated, the MT function of the IAB node accesses the network through cell selection. Therefore, to perform the IAB node functions, it is necessary to ensure that the IAB node can access the IAB network. Figure 1B shows the IAB architecture. The next-generation (NG) RAN communicates with the 5G core (5G core, 5GC) network through the NG interface. The NR RAN includes gNBs, IAB nodes, and IAB donor gNBs. The IAB donor gNB (abbreviated as IAB donor) includes gNB-CU and gNB-DU functions. The gNB-CU mainly handles non-real-time radio upper layer protocol stack functions, such as radio resource control (RRC) functions or packet data convergence protocol (PDCP) functions. The gNB-DU function mainly handles physical layer functions and Layer 2 functions with high real-time requirements, such as physical layer (PHY) functions, media access control (MAC) functions, or radio link control (RLC) functions.The gNB-DU in an IAB node can serve as the Uu interface termination point for the backhaul link between the IAB node and an IAB donor, or between the IAB node and another IAB node.

[0102] Figure 2 is a diagram of a mobile IAB architecture. A vehicle-mounted relay (VMR) or mobile base station relay, a relay installed in a vehicle (which moves with the vehicle), supports wireless relay-related functions and supports access and backhaul by using NR. In other words, it supports wireless backhaul when performing service access and provides wireless access for UEs. Compared to the IAB architecture shown in Figure 1B, the VMR has mobility, and the IAB node in Figure 1B is a fixed terrestrial relay. Therefore, the VMR may alternatively be understood as a mobile IAB node. The terrestrial donor RAN is a RAN node responsible for providing a core network interface for UEs and wireless backhaul functions for the VMR. Generally, the donor RAN is terrestrial and not mobile.

[0103] Figure 3 shows the network access diagram for an IAB node MT (abbreviated as IAB-MT). The following steps are included:

[0104] S301: The IAB-MT sends an RRC connection setup message to the IAB donor. The RRC connection setup message includes an IAB indication.

[0105] At S301, the IAB node initiates an RRC connection setup procedure to access the 5G system. Specifically, the IAB-MT sends an RRC connection setup message to the donor CU of the IAB donor.

[0106] S302: The IAB donor sends an N2 message to the AMF. The N2 message includes an IAB instruction.

[0107] S303: IAB-MT completes the registration procedure.

[0108] Specifically, the UDM provides an IAB operation allowed indication to the AMF. The IAB operation allowed indication serves as part of the access and mobility subscription data. The AMF sends an IAB node authorized indication to the RAN. The IAB node authorized indication can indicate "authorized" or "not authorized." The RAN stores the IAB node authorized indication. After the registration procedure is completed, the IAB node remains in a connected state.

[0109] S304: The IAB-MT sets up a protocol data unit (PDU) session, obtains an internet protocol (IP) address, and interacts with operation administration and maintenance (OAM).

[0110] At S304, the IAB-MT PDU session provides an IP transport connection between the IAB node and the OAM through the 5G network.

[0111] S305: The IAB-MT obtains the configuration information from the OAM. The configuration information includes a cell global identifier (CGI), a physical cell identifier (PCI), a tracking area code (TAC), and the like.

[0112] S306: The IAB-DU (in other words, the DU of the IAB node) sends an F1 Setup Request message to the RAN. The F1 setup request message is used to request to set up an F1 interface, and includes CGI, PCI, TAC, etc.

[0113] S307: The donor CU and AMF of the IAB donor complete the parameter configuration update procedure.

[0114] For example, the donor CU and AMF complete the update of the tracking area (TA) list.

[0115] S308: The donor CU of the IAB donor sends an F1 setup response message to the IAB-DU to complete the setup of the F1 interface.

[0116] The donor CU decides whether to accept the setup of the F1 interface based on the IAB node authorization instruction received from the AMF. If the IAB node authorization instruction indicates authorization, the donor CU accepts the setup of the F1 interface. If the IAB node authorization instruction indicates non-authorization, the donor CU does not accept the setup of the F1 interface.

[0117] Scenario 2: L2 Relay Scenario When a UE is located outside the network coverage or the communication signal between the UE and the RAN is weak, the UE acting as a remote UE may access the network with the assistance of a relay UE to implement communication between the remote UE and the network. Figure 4 shows an L2 relay architecture diagram. In the 5G system, indirect communication is supported as an L2 relay communication mode. Indirect communication is a communication mode in which a remote UE accesses the network through a relay UE. The relay UE forwards the uplink and downlink data of the remote UE based on the access stratum layer (AS layer) configuration so that the remote UE can access the RAN and communicate with the 5G network. The L2 relay can also be called a Layer 2 terminal-to-network relay (L2 UE-to-network relay, L2 U2N relay).

[0118] Figure 5 shows the connection setup procedure for a remote UE in an L2 relay scenario, including the following steps:

[0119] S501: A remote UE and a relay UE are initially registered in a network.

[0120] If the remote UE is not directly connected to the network, the remote UE may not be registered and needs to be registered in the subsequent S509.

[0121] During the initial registration process of the relay UE, the AMF obtains 5G proximity services (ProSe) subscription data from the UDM. The 5G ProSe subscription data includes that the UE is authorized to act as an L2 relay. The AMF sends an indication to the RAN that the UE is authorized to act as an L2 relay.

[0122] S502: The remote UE obtains permission information from the PCF corresponding to the remote UE, and the relay UE obtains permission information from the PCF corresponding to the relay UE.

[0123] The PCF serving the UE may be understood as the PCF responsible for providing UE policies during the registration of the UE.

[0124] The authorization information obtained by the remote UE includes that the UE is authorized to perform indirect communication, in other words, to act as a remote UE.

[0125] The authorization information obtained by the relay UE includes that the UE is authorized to perform indirect communication, in other words, to act as a relay UE.

[0126] If not registered with the network, the remote UE may use pre-configured authorization information.

[0127] S503: The relay UE completes the discovery and selection procedure.

[0128] S504: The remote UE sends an indirect communication request message to the relay UE to instruct the relay UE to set up an indirect communication.

[0129] S505: The relay UE initiates a Service Request message.

[0130] S505 is an optional step. If not in a connected (RRC connected) state, the relay UE initiates a service request message, which allows the relay UE to enter a connected state.

[0131] S506: The relay UE returns an indirect communication response message to the remote UE.

[0132] After S504 to S506, the remote UE sets up a PC5 connection to the relay UE, and the relay UE is in a connected state.

[0133] S507: The remote UE sends an RRC Setup Request message to the RAN via the relay UE.

[0134] S508: The RAN sends an RRC setup message to the remote UE via the relay UE.

[0135] The relay UE may forward uplink and downlink signaling of the remote UE based on the AS layer configuration, so that the remote UE can access the RAN and complete the setup of the RRC connection between the remote UE and the RAN. If the relay UE is not authorized to act as an L2 relay UE, the RAN may deny the remote UE access via the relay UE.

[0136] S509: The remote UE sends a non-access stratum (NAS) request message to the AMF via the RAN.

[0137] In S501, if the remote UE is not registered, the NAS message is an initial registration message. In S501, if the remote UE is registered, the NAS message is a service request message. In the service request message, the remote UE may choose to activate a PDU session.

[0138] The AMF corresponding to a UE may be understood as an AMF responsible for mobility management of the UE during registration of the UE. Specifically, the AMF corresponding to a remote UE is an AMF responsible for mobility management of the remote UE during registration of the remote UE, and the AMF corresponding to a relay UE is an AMF responsible for mobility management of the relay UE during registration of the relay UE.

[0139] S510: The remote UE initiates a PDU session setup procedure.

[0140] S511: The remote UE performs uplink and downlink data transmission using the UPF corresponding to the remote UE via the relay UE and the RAN.

[0141] The relay UE forwards uplink and downlink data of the remote UE based on the configuration of the AS layer. The protocol stack between the relay UE and the RAN supports an adaptation layer, which is used by the relay UE and the RAN to distinguish between data from different remote UEs.

[0142] During the process of a relay UE registering with the network, the AMF obtains 5G ProSe subscription data from the UDM. The 5G ProSe subscription data includes information indicating that the UE is authorized to act as an L2 relay. The AMF sends an indication to the RAN that the UE is authorized to act as an L2 relay. After learning that the UE is authorized to act as an L2 relay, the AMF does not actively trigger a connection release procedure. The connection release is controlled by the RAN because only the RAN knows whether the UE is currently providing L2 relay service. If the L2 relay service is provided, the relay UE's connection should not be terminated.

[0143] In this scenario, the L2 relay UE has two functional roles: one is to perform the service data transmission of the relay UE, and the other is to provide relay services to the remote UE to perform the service data transmission of the remote UE.

[0144] Service area restrictions are defined based on subscription data, such as access and mobility subscription data or 5G ProSe subscription data. In other words, they define areas where a UE is or is not allowed to initiate communication with the network. In an allowed area, the UE can communicate normally with the network. In a non-allowed area, the UE cannot initiate service request procedures or general session management related signaling interactions with the network. When in a non-allowed area, the UE must respond to paging initiated by the core network, NAS notification procedures, and paging initiated by RAN nodes.

[0145] The service area restriction may include one or more complete TAs or all TAs within a public land mobile network (PLMN). The service area restriction is included in the UE's subscription data stored in the UDM and may be represented by a TA identifier and / or other geographic information (e.g., latitude and longitude, or postal code). If geographic location information is used, the AMF first maps the geographic location information to a TA before sending the service area restriction information to the PCF, RAN, and UE. If the AMF does not store the UE's service area restriction context during the registration process, it may obtain the information from the UDM and further adjust the information via the PCF. The network can update the service area restriction by using the general UE configuration update procedure.

[0146] When the size of the service area restriction assigned to the UE by the AMF is limited (e.g., it includes only one or more complete TAs), the allowed areas included in the service area restriction and provided to the UE by the AMF may be pre-configured or dynamically assigned by the AMF (e.g., dynamic TA control is performed as the UE location changes). The AMF provides the service area restriction in the form of a TA. The service area restriction may be part of a complete list stored in the UE subscription data or may be provided for the UE by the PCF in the registration procedure. When the UE is in a non-allowed area, the AMF does not allow the UE to perform service request procedures or general session management related signaling interactions with the network. That is, the terminal cannot perform service-related procedures and only other mobility-related signaling procedures are allowed.

[0147] When providing service area restrictions, the network shall not simultaneously provide allowed and non-allowed areas for the UE. If the network provides a non-allowed area for the UE, any TA within the PLMN that is not on the list shall be considered to belong to the allowed area.

[0148] The UE location estimation result is determined by using a procedure to initiate positioning and a procedure to terminate positioning, and it can be further determined that the UE is in an allowed area or a non-allowed area.

[0149] Figure 6 shows the procedure for initiating UE positioning, which includes the following steps:

[0150] S601: A UE in an idle state initiates a service request procedure to complete a signaling connection between the UE and the AMF.

[0151] S602: The UE sends a mobile originated location request (MO-LR) message.

[0152] The MO-LR message may be carried in an uplink NAS transport (UL NAS TRANSPORT) message.

[0153] The UE can request different location service types: (A) UE location estimation, (B) transmission of the UE location estimate to an LCS client or AF, and (C) location assistance information. For types (A) and (B), the UL NAS TRANSPORT message may further include LCS quality of service (QoS) information such as positioning accuracy, response time, and LCS QoS class. The LCS QoS class may include a Best Effort Class and an Assured Class. For (B), the UL NAS TRANSPORT message may further include an LCS client identifier or AF identifier and a GMLC address allocated by the AMF.

[0154] S603: The AMF selects an appropriate LMF.

[0155] S604: The AMF sends a location determination request (Nlmf_Location_DetermineLocation Request) message to the LMF.

[0156] The message includes an identifier of the cell serving the UE (serving cell identifier) ​​and an indication or location assistance data for requesting UE location information.

[0157] S605: The LMF initiates a procedure for positioning the UE.

[0158] Specifically, the LMF obtains positioning data by interacting with the RAN and the UE, and obtains a location estimation result for the UE through calculation.

[0159] In S605, the positioning technology used by the LMF includes, but is not limited to, an OTDOA positioning technology, a UTDOA positioning technology, a TA positioning technology, an AoA positioning technology, or another positioning technology.

[0160] S606: When the location estimation result satisfies the requested LCS QoS information, the LMF returns the UE location estimation result to the AMF.

[0161] S607: The AMF sends a location update request (Ngmlc_Location_LocationUpdate Request) message to the GMLC. This message contains the location estimation result, the UE's identifier, and the LCS QoS information requested by the UE.

[0162] S608: The GMLC sends a location update request message to the LCS client or AF. The location update request message includes the location estimation result of the UE.

[0163] S609: The LCS client or the AF returns a location update response (Ngmlc_Location_LocationUpdate Response) message.

[0164] If the UE roams, the GMLC includes two entities: visited GMLC (VGLMC) and home GMLC (HGLMC). If the UE does not roam, the VGLMC and HGLMC are the same entity.

[0165] S608 and S609 are optional steps, for example, if the UE does not require location service type (B), S608 and S609 are skipped.

[0166] S610: GMLC sends a location update response message to AMF.

[0167] S611: The AMF sends an MO-LR response message to the UE.

[0168] The MO-LR response message may be carried in a downlink NAS transport (DL NAS TRANSPORT) message, which may further include the location estimation result and whether the location estimation result meets the required positioning accuracy.

[0169] Figure 7 shows the procedure for terminating UE positioning, which includes the following steps:

[0170] S701: The LCS client sends an LCS service request message to the GMLC, where the LCS service request message is used to request to obtain the location of the UE.

[0171] The LCS service request message includes the UE's identifier and the required QoS, which may be a generic public subscription identifier (GPSI) or a subscription permanent identifier (SUPI).

[0172] S702: The GLMC obtains the address of the AMF currently serving the UE from the UDM.

[0173] S703: The GLMC sends a location information providing request (Namf_Location_ProvidePositioningInfo Request) message to the AMF, and the location information providing request message is used to request obtaining the location of the UE.

[0174] The GLMC retrieves the LCS privacy profile from the UDM and determines that the LCS client is authorized to retrieve the UE's location based on the LCS privacy profile. The GLMC requests the AMF to retrieve the UE's location.

[0175] S704: If the UE is in an idle state, the AMF initiates a service request procedure to complete a signaling connection between the UE and the AMF. S704 is an optional step.

[0176] S705: AMF selects LMF.

[0177] S706: The AMF sends an Nlmf_Location_DetermineLocation Request message to the LMF, and the Nlmf_Location_DetermineLocation Request message is used to request the current location of the UE. The Nlmf_Location_DetermineLocation Request message may further include a cell identifier of the UE.

[0178] S707: The LMF initiates a procedure for positioning the UE.

[0179] The LMF obtains positioning data by interacting with the UE via the RAN, and obtains the location estimation result for the UE through calculation.

[0180] In S707, the positioning technology used by the LMF includes, but is not limited to, an OTDOA positioning technology, a UTDOA positioning technology, a TA positioning technology, an AoA positioning technology, or another positioning technology.

[0181] S708: The LMF sends an Nlmf_Location_DetermineLocation Response message to the AMF, and the Nlmf_Location_DetermineLocation Response message includes the current location of the UE and the implemented accuracy.

[0182] S709: The AMF sends a Namf_Location_ProvidePositioningInfo Response message to the GMLC, where the Namf_Location_ProvidePositioningInfo Response message includes the current location of the UE and the implemented accuracy.

[0183] S710: The GMLC sends an LCS service response message to the LCS client, where the LCS service response message includes the UE's current location and the implemented accuracy.

[0184] In conclusion, in the above-mentioned Scenario 1 and Scenario 2, the network controls and manages the connection service of the UE based only on the operation allowance instruction information (e.g., the IAB node authorization instruction in Scenario 1 or the 5G ProSe subscription data in Scenario 2). For example, when the operation allowance instruction information indicates that the UE is authorized to provide the service, the UE may provide the connection service at any location and at any time. This leads to poor flexibility in the network to control and manage when the UE provides the connection service.

[0185] In consideration of this, an embodiment of the present application provides a license method, which is applicable to the above-mentioned Scenario 1 and Scenario 2. Figure 8A is a diagram of the license method according to an embodiment of the present application. The method includes the following steps:

[0186] S801: An access management network element obtains operation permission instruction information and permission conditions.

[0187] The operation permission indication information indicates that the terminal device is allowed to provide a connection service.

[0188] The permission conditions are used to determine whether the terminal device is allowed to provide the connection service, for example, the permission conditions include the permitted location range of the connection service and / or the permitted time range of the connection service.

[0189] S802: The access management network element sends an authorization result to the access network element accessed by the terminal device according to the authorization conditions. In response, the access network element receives the authorization result.

[0190] The authorization result indicates that the terminal device is not allowed to provide the connection service, or indicates that the terminal device is allowed to provide the connection service.

[0191] According to the aforementioned solution, the access management network element can determine whether the location and / or current time of the terminal device meets the authorization conditions based on the obtained authorization conditions, and transmit the corresponding authorization result to the access network element accessed by the terminal device. Even if the operation allowance instruction information allows the terminal device to provide a connection service, if the authorization conditions are not met, the access management network element will not allow the terminal device to provide the connection service. This allows for flexible and dynamic control and management of when the terminal device provides the connection service. According to the aforementioned solution, this can prevent the service from being provided outside the authorized location range and / or authorized time range, thereby avoiding interference with existing communications to a certain extent.

[0192] In one implementation, the access management network element may obtain operation allowance instructions and permission conditions from a data management network element (e.g., UDM) or a policy control network element (e.g., PCF). For example, a terminal device initiates a registration procedure to access a network through the access management network element. The access management network element can obtain subscription data from the data management network element. The subscription data includes operation allowance instructions and permission conditions. For the registration procedure of the terminal device, see S301 to S303 in FIG. 3. The subscription data may be access and mobility subscription data (e.g., in an IAB scenario) or 5G ProSe subscription data (e.g., in an L2 relay scenario). For example, when the PCF network element sends an access management policy to the access management network element, the access management policy includes operation allowance instructions and permission conditions.

[0193] In some cases, the operation permission indication information indicates that the terminal device is not allowed to provide the connection service. The subscription data may not include the permission conditions. The access management network element determines that the terminal device is not allowed to provide the service based on the operation permission indication information.

[0194] Alternatively, in some cases, the access management network element may not obtain the operation allowance indication information and by default will not allow the terminal device to provide the service.

[0195] The connection service includes, but is not limited to, an IAB service, a VMR service, a relay service, etc. An IAB terminal device may provide the IAB service. That is, the terminal device may be an IAB-UE / IAB-MT. Specifically, the IAB terminal device is an IAB-MT. A VMR device or a mobile base station relay device may provide the VMR service. In other words, the terminal device may be a VMR device or a mobile base station relay. The VMR device functions as a relay between the terminal device and a network (e.g., a 5G network), for example, providing an access link for the UE and wirelessly connecting to the network via an IAB donor. When installed in a moving vehicle, the mobile base station relay may serve UEs located inside (or entering) the vehicle or outside (or leaving) the vehicle. A relay terminal device may provide a relay service. That is, the terminal device may be a relay terminal device.

[0196] In S802, the access management network element may determine an authorization result based on the authorization conditions, and then send the authorization conditions to the access network element.

[0197] In one possible case (hereinafter referred to as Case 1), the authorization conditions include an authorized time range for the connection service, and the access management network element can determine whether the current time is outside or within the authorized time range to determine the authorization result.

[0198] When the current time is outside the permitted time range, the access management network element determines that the authorization result indicates that the terminal device is not allowed to provide the service.When the current time is within the permitted time range, the access management network element determines that the authorization result indicates that the terminal device is allowed to provide the service.

[0199] In another possible case (hereinafter referred to as case 2), the authorization conditions include an authorized location range of the connection service, and the access management network element can determine whether the terminal device is outside or within the authorized location range to determine the authorization result.

[0200] When the terminal device is outside the authorized location range, the access management network element determines that the authorization result indicates that the terminal device is not allowed to provide connection services.When the terminal device is within the authorized location range, the access management network element determines that the authorization result indicates that the terminal device is allowed to provide connection services.

[0201] If the terminal device has mobility, for example, if the terminal device is a VMR, when the terminal device moves outside the permitted location range, the terminal device is outside the permitted location range, or when the terminal device moves within the permitted location range, the terminal device is within the permitted location range.

[0202] The authorized location range includes one or more of the authorized route of the connectivity service, the authorized area of ​​the connectivity service, the area where the connectivity service is allowed to be provided, or the area where the connectivity service is not allowed to be provided. The authorized area of ​​the connectivity service may include one or more complete TAs. If the authorized area of ​​the connectivity service is geographical location information, the AMF maps the geographical location information to the TA. The authorized area of ​​the connectivity service may further include one or more cells. For example, the identifier of each cell may be a cell global identifier (CGI).

[0203] In yet another possible case (hereinafter referred to as case 3), the authorization conditions include an authorized location range of the connection service and an authorized time range of the connection service. The access management network element can determine whether the current time is outside the authorized time range (or within the authorized time range) and whether the terminal device is outside the authorized location range (or within the authorized location range) to determine the authorization result.

[0204] When the current time is outside the permitted time range and / or the terminal device is outside the permitted location range, the access management network element determines that the authorization result indicates that the terminal device is not allowed to provide connection service.When the current time is within the permitted time range and the terminal device is within the permitted location range, the access management network element determines that the authorization result indicates that the terminal device is allowed to provide connection service.

[0205] Below, we will mainly explain some implementations in case 2.

[0206] In one implementation, the access management network element can determine whether the terminal device is outside or within the permitted location range based on the location of the terminal device and the permitted location range.

[0207] In this implementation, the location of the terminal device may be a real-time location obtained through estimation by a location management network element (e.g., LMF). The access management network element may obtain the location of the terminal device from the location management network element. For example, see S604 to S606 in FIG. 6 and S706 to S708 in FIG. 7. Optionally, the location of the terminal device may be a location within an allowed time range. For example, the access management network element sends a location determination request message to the location management network element. The location determination request message is used to request the location of the terminal device. The location determination request message may carry an allowed time range, and the location management network element may obtain the location of the terminal device within the allowed time range.

[0208] For example, in an IAB scenario, the authorized location range includes an authorized path for the connectivity service and an authorized area for the connectivity service. In an L2 relay scenario, the authorized location range includes an area where the connectivity service is permitted to be provided (allowed area) and an area where the connectivity service is not permitted to be provided (non-allowed area).

[0209] In another implementation, the location management network element determines whether the terminal device is outside or within the authorized location range, and then notifies the access management network element of the determination result.

[0210] Specifically, the access management network element may send a request message to the location management network element (for example, see S604 in FIG. 6 or S706 in FIG. 7). The request message includes information about the authorized location range and is used to request whether the terminal device is outside the authorized location range or within the authorized location range. The location management network element sends notification information to the access management network element (for example, see S606 in FIG. 6 or S708 in FIG. 7). The notification information is used to notify that the terminal device is outside the authorized location range or that the terminal device is within the authorized location range.

[0211] Optionally, the request message may include a granted time range.

[0212] In yet another implementation, the access management network element determines whether the terminal device is outside or within an authorized location range based on the tracking area in which the terminal device is located.

[0213] Specifically, the access management network element can receive a tracking area range corresponding to the authorized location range (e.g., the authorized location range is a tracking area range, or the network-exposing network element converts the authorized location range into a tracking area range), and the access management network element already knows the tracking area in which the terminal device is located. If the tracking area in which the terminal device is located is outside the tracking area range corresponding to the authorized location range (in other words, the tracking area range corresponding to the authorized location range does not include the tracking area in which the terminal device is located), it represents that the terminal device is outside the authorized location range. If the tracking area in which the terminal device is located is within the tracking area range corresponding to the authorized location range (in other words, the tracking area range corresponding to the authorized location range includes the tracking area in which the terminal device is located), it represents that the terminal device is within the authorized location range. In this implementation, the access management network element can request the network-exposing network element to map the authorized location range to a tracking area range.

[0214] In another example, when allocating a Registration Area to a terminal device, the access management network element may consider the tracking area range corresponding to the authorized location range. If the terminal device is within the authorized location range, the registration area includes a group of TAs that belong to the tracking area range corresponding to the authorized location range. If the terminal device is outside the authorized location range, the registration area includes a group of TAs that do not belong to the tracking area range corresponding to the authorized location range. Furthermore, the access management network element can know whether the terminal device is within or outside the authorized location range by using a Mobility Registration Update mechanism.

[0215] In yet another implementation, the access management network element determines whether the terminal device is outside or within a licensed location range based on the cell in which the terminal device is located.

[0216] Specifically, the access management network element may receive a cell list corresponding to the authorized location range (e.g., the authorized location range is a cell list, or the network exposure network element converts the authorized location range into a cell list), and the access management network element already knows the cell in which the terminal device is located. If the cell in which the terminal device is located is outside the cell list corresponding to the authorized location range (in other words, the cell list corresponding to the authorized location range does not include the cell in which the terminal device is located), it indicates that the terminal device is outside the authorized location range. If the cell in which the terminal device is located is within the cell list corresponding to the authorized location range (in other words, the cell list corresponding to the authorized location range includes the cell in which the terminal device is located), it indicates that the terminal device is within the authorized location range.

[0217] At S802, the access network element may control the connection service of the terminal device based on the received authorization result.

[0218] Optionally, the access management network element may further send the authorization result to the terminal device.

[0219] For a terminal device, the terminal device may perform a corresponding operation based only on the authorization result sent by the access management network element. For example, the terminal device receives a first authorization result sent by the access management network element. The first authorization result indicates that the terminal device is not allowed to provide a connection service. The terminal device releases resources for providing the connection service based on the first authorization result. In another example, the terminal device receives a second authorization result sent by the access management network element. The second authorization result indicates that the terminal device is allowed to provide a connection service. The terminal device provides the connection service based on the second authorization result.

[0220] Alternatively, the terminal device may perform the corresponding operation solely based on the control of the access network element. For example, the terminal device receives a connection control message sent by the access network element. The connection control message is used to control the terminal device not to provide the connection service. The terminal device releases resources for providing the connection service based on the connection control message. In another example, the connection control message is alternatively used to provide the connection service. The terminal device provides the connection service based on the connection control message.

[0221] Alternatively, the terminal device may perform corresponding operations based on the control of the access network element and the authorization result sent by the access management network element. Generally, the control of the access network element is consistent with the authorization result from the access management network element. That is, the terminal device performs the same operation. Indeed, to avoid the control of the access network element being inconsistent with the authorization result of the access management network element, the priority of the control result of the access network element and the priority of the authorization result of the access management network element can be set. For example, the priority of the control result of the access network element is higher than the priority of the authorization result sent by the access management network element.

[0222] For example, when releasing resources for providing connectivity services, the terminal device may release the F1 interface. The F1 interface is for transmitting information between the terminal device and the access network element. "Information" in this specification includes data and / or signaling.

[0223] Optionally, when the authorization result indicates that the terminal device is not allowed to provide the connection service, the access management network element sends a deregistration request message to the terminal device. For example, the deregistration request message may include indication information that the terminal device is not allowed to provide the connection service. After receiving the deregistration request message, the terminal device releases resources for providing the connection service.

[0224] In another implementation, the access management network element can obtain a location range (or prohibited area) that is not authorized for the connection service. When the terminal is in the location range (or prohibited area) that is not authorized, the terminal device is not allowed to provide the connection service, and the cases in which the terminal device provides the connection service are flexibly and dynamically controlled and managed. Figure 8B is a diagram of another authorization method according to an embodiment of the present application. This method includes the following steps:

[0225] S811: The access management network element obtains operation allowance instruction information and a location range that is not permitted for the connection service.

[0226] The operation permission indication information indicates that the terminal device is allowed to provide a connection service.

[0227] A location range where connectivity services are not permitted is a Forbidden Area, for example, included in access and mobility subscription data.

[0228] The access management network element can obtain operation allowance instruction information and unauthorised location ranges of the connection service from the data management network element or the policy control network element.

[0229] S812: The access management network element determines that the terminal device is within an unauthorized location range (or a prohibited area) and sends an authorization result to the access network element accessed by the terminal device, where the authorization result indicates that the terminal device is not allowed to provide connection services, or sends an N2 UE Context Release Request message to the access network element accessed by the terminal device. For example, the N2 UE Context Release Request message may include indication information that the terminal device is not allowed to provide connection services. In response, the access network element receives the authorization result or the N2 UE Context Release Request message.

[0230] In this example, the access management network element may further transmit an authorization result to the terminal device. Alternatively, when the authorization result indicates that the terminal device is not allowed to provide a connection service, the access management network element transmits a deregistration request message to the terminal device. For example, the deregistration request message may include indication information that the terminal device is not allowed to provide a connection service. After receiving the deregistration request message, the terminal device releases resources for providing the connection service.

[0231] The process in S812 in which the access management network element determines that the terminal device is in a prohibited area is similar to the process in S802 in which the access management network element determines that the terminal device is outside or within an authorized location range. Repetitive content will not be described. The differences are as follows: When the terminal device is in a prohibited area, the access management network element determines that the terminal device is not allowed to provide connection service; When the terminal device is outside the prohibited area, the access management network element determines that the terminal device is allowed to provide connection service.

[0232] The authorization procedure shown in FIG. 8A will now be described with reference to an example.

[0233] Figure 9 is a schematic flowchart of the authorization in the IAB scenario, which includes the following steps:

[0234] S901: The IAB-UE initiates the registration procedure.

[0235] S902: The UDM sends access and mobility subscription data to the AMF, and the access and mobility subscription data includes an IAB operation allowance indication and an allowed route / area.

[0236] The IAB operation permission instruction is an example of the aforementioned operation permission instruction information, and the permitted route / area is an example of the aforementioned permitted location range.

[0237] Optionally, the access and mobility subscription data further includes a validity period, which is an example of the allowed time range mentioned above.

[0238] S903: The AMF obtains the location of the IAB-UE from the LMF.

[0239] For example, see S604 to S606 in FIG. 6, or S706 to S708 in FIG.

[0240] S904: The AMF determines whether the IAB-UE is within an authorized route / area to determine the authorization result.

[0241] When the IAB-UE is outside the authorized route / area, the authorization result is determined to be unauthorised indication information. The unauthorised indication information indicates that the IAB-UE is not authorized, in other words, the IAB-UE is not allowed to provide connectivity services. In this example, the case where the IAB-UE is outside the authorized route / area is mainly described.

[0242] When the IAB-UE is within the authorized route / area, the authorization result is determined to be authorization indication information, which indicates that the IAB-UE is authorized, in other words, that the IAB-UE is allowed to provide connection service.

[0243] S903 and S904 are possible implementation 1.

[0244] S905: The AMF subscribes to whether the IAB-UE is within an authorized route / area from the LMF.

[0245] The LMF determines that the IAB-UE is outside the licensed route / area. Alternatively, the LMF determines that the IAB-UE is within the licensed route / area.

[0246] S906: The LMF sends an event notification message to the AMF, and the event notification message includes indication information to notify the AMF that the IAB-UE is outside the allowed route / area.

[0247] If the LMF determines that the IAB-UE is in an authorized route / area, the event notification message includes indication information to notify that the IAB-UE is in an authorized route / area.

[0248] S905 and S906 are possible implementation 2.

[0249] S907: The AMF determines whether the TA / cell where the IAB-UE is located is located within the TA / cell set corresponding to the licensed area.

[0250] When the TA where the IAB-UE is located is outside the TA range corresponding to the licensed area, the AMF determines that the IAB-UE is outside the licensed area.

[0251] When the cell in which the IAB-UE is located is outside the cell list corresponding to the licensed area, the AMF determines that the IAB-UE is outside the licensed area.

[0252] When the TA where the IAB-UE is located is within the TA range corresponding to the licensed area, the AMF determines that the IAB-UE is within the licensed area.

[0253] When the cell in which the IAB-UE is located is in the cell list corresponding to the licensed area, the AMF determines that the IAB-UE is in the licensed area.

[0254] S908: When the IAB-UE is outside the authorized area, the AMF determines that the authorization result is unauthorised indication information.

[0255] S907 and S908 are possible implementation 3. The permission granularity of S907 and S908 is the permission area.

[0256] S909: The AMF sends an N2 message to the RAN. When the IAB-UE is outside the authorized route / area, the N2 message includes unauthorization indication information.

[0257] When the IAB-UE is within a licensed route / area, the N2 message contains license indication information.

[0258] Optionally, when the IAB-UE is outside the permitted route / area, the AMF may initiate a registration procedure for the IAB-UE or release the NAS connection.

[0259] It can be understood that when the IAB operation allowance indication indicates that the IAB-UE is authorized, the AMF sends unauthorised indication information to the RAN when it determines that the IAB-UE is outside the authorized route / area. If the RAN does not obtain whether the IAB-UE is authorized or unauthorised, the RAN defaults to assuming that the IAB-UE is unauthorised.

[0260] S910: The RAN controls the service of the IAB-UE based on the N2 message.

[0261] If the N2 message contains unauthorised instruction information, the RAN may not allow the IAB-UE to act as an IAB node providing IAB services, may release resources used by the IAB-UE to provide IAB services, may release the IAB-UE from acting as the DU's F1 interface, or may not allow the IAB-UE to act as a DU to request the setup of an F1 interface.

[0262] In this example, when the IAB-UE is outside a specific route / area, the AMF may not authorize the IAB-UE to provide IAB service and dynamically update the IAB-UE authorization indication. The RAN controls the IAB service of the IAB-UE based on the updated non-authorization indication to avoid interference with existing communications caused by the IAB-UE providing IAB service in an unlicensed area (or at an unlicensed time).

[0263] Figure 10 is a schematic flowchart of authorization in an L2 relay scenario, which includes the following steps:

[0264] S1001: The UE initiates a registration procedure.

[0265] S1002: The UDM sends 5G ProSe subscription data to the AMF. The 5G ProSe subscription data includes an L2 UE-to-network (U2N) relay permission and an allowed area (or an unallowed area).

[0266] "L2 U2N Relay Authorized" indicates that the UE is allowed to provide L2 U2N relay service.

[0267] S1003: The AMF determines that the UE is authorized to act as an L2 U2N relay based on whether the UE is in an allowed area, or determines that the UE is not authorized to act as an L2 U2N relay based on whether the UE is in a non-allowed area.

[0268] For the implementation of S1003, refer to the implementation of Case 2. Repetitive content will not be described.

[0269] S1004: The AMF sends an N2 message to the RAN. When the AMF determines that the UE is not authorized to act as an L2 U2N relay, the N2 message includes unauthorization indication information.

[0270] When the AMF determines that the UE is authorized to act as an L2 U2N relay, the N2 message includes authorization indication information.

[0271] When it determines that the UE is not allowed to act as an L2 U2N relay, the AMF may further initiate a NAS connection release procedure or may actively initiate an N2 connection release procedure, triggering the UE to enter an idle state.

[0272] S1005: The RAN controls the L2 U2N relay service of the UE based on the N2 message.

[0273] When the N2 message includes unauthorised indication information, the RAN may not allow the UE to use the L2 U2N relay service, and may further release the RRC connection between the RAN and the UE.

[0274] When the N2 message includes the authorization indication information, the RAN may allow the L2 U2N relay service of the UE.

[0275] In this example, the AMF may refer to whether the UE is in an allowed area or a non-allowed area to determine whether the UE is allowed to act as an L2 U2N relay and update the UE's authorization instruction. The RAN controls the UE's L2 U2N relay service based on the updated non-authorization instruction to avoid interference with existing communications caused by the UE providing the L2 U2N relay service in the non-allowed area.

[0276] An embodiment of the present application further provides a licensing method, which is applicable to the above-mentioned Scenario 1 and Scenario 2. Figure 11 is a diagram of the licensing method according to an embodiment of the present application. The method includes the following steps:

[0277] S1101: A data management network element obtains operation permission instruction information and permission conditions.

[0278] The operation permission indication information indicates that the terminal device is allowed to provide a connection service.

[0279] The permission conditions are used to determine whether the terminal device is allowed to provide the connection service, for example, the permission conditions include the permitted location range of the connection service and / or the permitted time range of the connection service.

[0280] S1102: The data management network element sends a permission result to the access management network element based on the permission conditions. In response, the access management network element receives the permission result.

[0281] The authorization result indicates that the terminal device is not allowed to provide the connection service, or indicates that the terminal device is allowed to provide the connection service.

[0282] According to the above solution, the data management network element can determine whether the location and / or current time of the terminal device meets the authorization conditions based on the obtained authorization conditions, and send the corresponding authorization result to the access management network element. Even if the operation permission instruction information allows the terminal device to provide a connection service, if the authorization conditions are not met, the data management network element will not allow the terminal device to provide the connection service. This makes it possible to flexibly and dynamically control and manage when the terminal device provides the connection service. According to the above solution, this can prevent the service from being provided outside the authorized location range and / or authorized time range, thereby avoiding interference with existing communications to a certain extent.

[0283] In one implementation, the data management network element stores subscription data, which includes operational permission instructions and authorization conditions. Similarities between the authorization process of the data management network element and the authorization process of the access management network element are not described herein.

[0284] In another implementation, the data management network element retrieves subscription data from a universal data repository (UDR), which provides a unified data repository service. The subscription data includes operational instructions and license terms.

[0285] In S1102, the data management network element may determine the authorization result based on the authorization conditions, and then send the authorization result to the access management network element.

[0286] Optionally, when the authorization result indicates that the terminal device is not allowed to provide connection service, the data management network element may not send the authorization result to the access management network element. When the authorization result is not obtained, the access management network element knows that the terminal device is not allowed to provide connection service.

[0287] Optionally, when determining that the terminal device is not allowed to provide the connection service, the access management network element sends a deregistration request message to the terminal device. For example, the deregistration request message may include indication information that the terminal device is not allowed to provide the connection service. After receiving the deregistration request message, the terminal device releases resources for providing the connection service.

[0288] In one possible case (hereinafter referred to as Case 1), the authorization conditions include an authorized time range for the connection service, and the data management network element can determine whether the current time is outside or within the authorized time range to determine the authorization result.

[0289] When the current time is outside the permitted time range, the data management network element determines that the authorization result indicates that the terminal device is not allowed to provide the service.When the current time is within the permitted time range, the data management network element determines that the authorization result indicates that the terminal device is allowed to provide the service.

[0290] In another possible case (hereinafter referred to as case 2), the authorization conditions include an authorized location range of the connection service, and the data management network element may determine whether the terminal device is outside or within the authorized location range to determine the authorization result.

[0291] When the terminal device is outside the authorized location range, the data management network element determines that the authorization result indicates that the terminal device is not allowed to provide connection service.When the terminal device is within the authorized location range, the data management network element determines that the authorization result indicates that the terminal device is allowed to provide connection service.

[0292] If the terminal device has mobility, for example, if the terminal device is a VMR, when the terminal device moves outside the permitted location range, the terminal device is outside the permitted location range, or when the terminal device moves within the permitted location range, the terminal device is within the permitted location range.

[0293] In yet another possible case (hereinafter referred to as case 3), the authorization conditions include an authorized location range of the connection service and an authorized time range of the connection service. The data management network element can determine whether the current time is outside the authorized time range (or within the authorized time range) and whether the terminal device is outside the authorized location range (or within the authorized location range) to determine the authorization result.

[0294] When the current time is outside the permitted time range and / or the terminal device is outside the permitted location range, the data management network element determines that the authorization result indicates that the terminal device is not allowed to provide connection service.When the current time is within the permitted time range and the terminal device is within the permitted location range, the data management network element determines that the authorization result indicates that the terminal device is allowed to provide connection service.

[0295] Below, we will mainly explain some implementations in case 2.

[0296] In one implementation, the data management network element can determine whether the terminal device is outside or within the permitted location range based on the location of the terminal device and the permitted location range.

[0297] In this implementation, the location of the terminal device may be a real-time location obtained through estimation by a network mobile position center (e.g., GMLC). The data management network element may obtain the location of the terminal device from the network mobile position center. Optionally, the location of the terminal device may be a location within an allowed time range. For example, the data management network element sends a location request message to the network mobile position center. The location request message is used to request the location of the terminal device. The location request message may carry an allowed time range, and the network mobile position center may obtain the location of the terminal device within the allowed time range.

[0298] For example, in an IAB scenario, the permitted location range includes an authorized path for the connectivity service and an authorized area for the connectivity service, while in an L2 relay scenario, the permitted location range includes an area where the connectivity service is permitted to be provided (allowed area) and an area where the connectivity service is not permitted to be provided (non-allowed area).

[0299] In another implementation, the data management network element determines whether the terminal device is outside or within the authorized location range, and then notifies the access management network element of the determination result.

[0300] Specifically, the data management network element may send a request message to the network mobile location center. The request message includes information about the authorized location range. The request message is used to request whether the terminal device is outside the authorized location range or within the authorized location range. The network mobile location center sends notification information to the data management network element. The notification information is used to notify that the terminal device is outside the authorized location range or that the terminal device is within the authorized location range.

[0301] Optionally, the request message may include an allowed time range.

[0302] In another implementation, in S1101, the data management network element can obtain an unlicensed location range (or prohibited area) for the connection service. When the terminal is in the unlicensed location range (or prohibited area), the data management network element does not allow the terminal device to provide the connection service, and the cases in which the terminal device provides the connection service are flexibly and dynamically controlled and managed.

[0303] The process by which the data management network element determines that the terminal device is in a prohibited area is similar to the process by which the data management network element determines that the terminal device is outside or within an authorized location range in S1102. Repetitive content will not be described. The differences are as follows: When the terminal device is in a prohibited area, the data management network element determines that the terminal device is not allowed to provide connection service; When the terminal device is outside the prohibited area, the data management network element determines that the terminal device is allowed to provide connection service.

[0304] The permission procedure shown in FIG. 11 will now be described with an example.

[0305] Figure 12 is a schematic flowchart of the authorization in the IAB scenario, which includes the following steps:

[0306] S1201: The IAB-UE initiates the registration procedure.

[0307] S1202: The UDM stores access and mobility subscription data, which includes IAB operation permission instructions and permitted routes / areas.

[0308] The IAB operation permission instruction is an example of the aforementioned operation permission instruction information, and the permitted route / area is an example of the aforementioned permitted location range.

[0309] Optionally, the access and mobility subscription data further includes a validity period, which is an example of the permitted time range mentioned above.

[0310] S1203: UDM obtains the location of IAB-UE from GMLC.

[0311] S1204: The DUM determines whether the IAB-UE is within an authorized route / area to determine the authorization result.

[0312] When the IAB-UE is outside the authorized route / area, the authorization result is determined to be unauthorised indication information. Unauthorised indication information indicates that the IAB-UE is not authorized, in other words, the IAB-UE is not allowed to provide connectivity services. In this example, the case where the IAB-UE is outside the authorized route / area is mainly described.

[0313] When the IAB-UE is within the authorized route / area, the authorization result is determined to be authorization indication information, which indicates that the IAB-UE is authorized, in other words, that the IAB-UE is allowed to provide connection service.

[0314] S1203 and S1204 are possible implementations 1.

[0315] S1205: UDM subscribes from GMLC whether IAB-UE is within a licensed route / area.

[0316] The GMLC determines that the IAB-UE is outside the licensed route / area. Alternatively, the GMLC determines that the IAB-UE is within the licensed route / area.

[0317] S1206: The GMLC sends an event notification message to the UDM, and the event notification message includes indication information to notify that the IAB-UE is outside the allowed route / area.

[0318] If the GMLC determines that the IAB-UE is within the authorized route / area, the event notification message includes indication information to notify that the IAB-UE is within the authorized route / area.

[0319] S1205 and S1206 are possible implementation 2.

[0320] S1207: The UDM sends access and mobility subscription data to the AMF. The access and mobility subscription data includes IAB operation permission indication and non-permission indication information.

[0321] S1208: The AMF sends an N2 message to the RAN. When the IAB-UE is outside the authorized route / area, the N2 message includes unauthorised indication information.

[0322] When the IAB-UE is within a licensed route / area, the N2 message contains license indication information.

[0323] S1209: The RAN controls the service of the IAB-UE based on the N2 message.

[0324] In this example, the UDM may not authorize the IAB-UE to provide IAB service when the IAB-UE is outside a specific route / area and dynamically update the IAB-UE authorization instruction. The RAN controls the IAB service of the IAB-UE based on the updated non-authorization instruction to avoid interference with existing communications caused by the IAB-UE providing IAB service in an unauthorised area (or at an unauthorised time).

[0325] Based on the same technical concept as the above-mentioned authorization method, an embodiment of the present application further provides a communication device. As shown in FIG. 13, the communication device 1300 includes a receiving unit 1301 and a transmitting unit 1302. Optionally, the functions implemented by the receiving unit 1301 and the transmitting unit 1302 may be implemented by a communication interface. The receiving unit and the transmitting unit may be integrated into a transceiver unit. The communication device 1300 may be an access management network element, a data management network element, or a terminal device, or may be located within the access management network element, the data management network element, or the terminal device. The communication device 1300 may be configured to implement the method described in the above-mentioned method embodiment. For example, the communication device 1300 may perform the steps performed by the access management network element, the data management network element, or the terminal device in the methods of FIGS. 8A to 12.

[0326] In one possible embodiment, the communication device 1300 is used in an access management network element.

[0327] For example, the receiving unit 1301 is configured to receive operation permission indication information and permission conditions. The operation permission indication information indicates that the terminal device is allowed to provide a connection service, and the permission conditions include a permitted location range and / or a permitted time range of the connection service. The sending unit 1302 is configured to send an authorization result to an access network element accessed by the terminal device based on the permission conditions. The authorization result indicates that the terminal device is not allowed to provide the connection service or that the terminal device is allowed to provide the connection service.

[0328] In one implementation, the sending unit 1302 is specifically configured to send a permission result to an access network element based on the permitted location range and / or the permitted time range.

[0329] In an implementation, the sending unit 1302 is further configured to send the authorization result to the terminal device.

[0330] In some implementations, the communication device 1300 further includes a processing unit 1303 configured to determine an authorization result based on the authorization conditions.

[0331] In some implementations, the processing unit is specifically configured to determine the authorization result based on the authorized location range and / or the authorized time range.

[0332] In one implementation, the processing unit 1303 is specifically configured to determine that the authorization result indicates that the terminal device is not allowed to provide the connection service when the current time is outside the authorized time range, or to determine that the authorization result indicates that the terminal device is allowed to provide the connection service when the current time is within the authorized time range.

[0333] In one implementation, the processing unit 1303 is specifically configured to determine that the authorization result indicates that the terminal device is not allowed to provide connection services when the terminal device is outside the authorized location range, or to determine that the authorization result indicates that the terminal device is allowed to provide connection services when the terminal device is within the authorized location range.

[0334] In one implementation, the receiving unit 1301 is further configured to receive notification information sent by a location management network element, and the notification information is used to notify that the terminal device is outside an authorized location range or is within an authorized location range.

[0335] The processing unit 1303 is specifically configured to determine that when the notification information is used to notify that the terminal device is outside the authorized location range, the authorization result indicates that the terminal device is not allowed to provide the connection service, or when the notification information is used to notify that the terminal device is within the authorized location range, the authorization result indicates that the terminal device is allowed to provide the connection service.

[0336] In an implementation, the processing unit 1303 is specifically configured to determine that the authorization result indicates that the terminal device is not allowed to provide connection services when the tracking area in which the terminal device is located is outside a tracking area range corresponding to the authorized location range, or determine that the authorization result indicates that the terminal device is allowed to provide connection services when the tracking area in which the terminal device is located is within a tracking area range corresponding to the authorized location range.

[0337] In one implementation, the connectivity service includes an integrated access and backhaul IAB service, and the terminal device is an IAB terminal device.

[0338] Alternatively, the connection service includes an in-vehicle relay VMR service, and the terminal device is a VMR device.

[0339] Alternatively, the connection service includes a relay service, and the terminal device is a relay terminal device.

[0340] In some implementations, the permitted location range includes one or more of a permitted route for the connectivity service, a permitted area for the connectivity service, an area in which the connectivity service is allowed to be provided, or an area in which the connectivity service is not allowed to be provided.

[0341] In another possible implementation, the communications apparatus 1300 is used in a terminal device.

[0342] For example, the receiving unit 1301 is configured to receive a first authorization result sent by an access management network element, where the first authorization result indicates that the terminal device is not allowed to provide connection service.

[0343] The processing unit 1303 is configured to release resources for providing the connection service according to the first authorization result.

[0344] In one implementation, the processing unit 1303 is specifically configured to open an F1 interface for transmitting information between a terminal device and an access network element accessed by the terminal device.

[0345] In one implementation, the receiving unit 1301 is further configured to receive a second authorization result sent by the access management network element, where the second authorization result indicates that the terminal device is allowed to provide a connection service.

[0346] The processing unit 1303 is further configured to provide a connection service based on the second authorization result.

[0347] It should be noted that the division into modules in the embodiments of the present application is merely an example and is merely a logical division of functions. During actual implementation, other division schemes may exist. Additionally, the functional units in the embodiments of the present application may be integrated into one processing unit, or may exist physically alone, or two or more units may be integrated into one unit. The integrated units may be implemented in the form of hardware or software functional units. For example, a transceiver unit may include a receiving unit and / or a transmitting unit.

[0348] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, the integrated unit may be stored in a computer-readable storage medium. Based on this understanding, the integrated unit may be stored in a storage medium as a computer software product, and includes several instructions for instructing a computer device (which may be a personal computer, a server, or a network device) or a processor to perform all or part of the steps of the method in the embodiments of the present application.

[0349] As shown in Figure 14, an embodiment of the present application further provides a structural diagram of a communication device 1400. The communication device 1400 may be configured to implement the methods described in the foregoing method embodiments. Please refer to the descriptions in the foregoing method embodiments. For example, the communication device 1400 may perform steps performed by an access management network element, a data management network element, or a terminal device in the methods of Figures 8A to 12.

[0350] The device 1400 includes one or more processors 1401. The processor 1401 may be a general-purpose processor, a special-purpose processor, etc. For example, the processor 1401 may be a baseband processor or a central processing unit. The baseband processor may be configured to process communication protocols and communication data. The central processing unit may be configured to control a communication device (e.g., a base station, a terminal, or a chip), execute software programs, and process data of the software programs. The communication device may include a transceiver unit configured to input (receive) and output (transmit) signals. For example, the transceiver unit may be a transceiver or a radio frequency chip.

[0351] The device 1400 includes one or more processors 1401, which can implement the methods described in the above embodiments. Optionally, the processor 1401 may further implement other functions in addition to the methods described in the above embodiments.

[0352] In one design, processor 1401 may execute instructions, causing device 1400 to perform the methods described in the preceding method embodiments. All or a portion of the instructions may be stored in processor 1401. For example, all or a portion of instructions 1403 may be stored in processor 1401, or instructions 1403 may be stored in processor 1401 and instructions 1404 may be stored in memory 1402 coupled to the processor. Processor 1401 may execute instructions 1403 and 1404 synchronously, causing device 1400 to perform the methods described in the preceding method embodiments. Instructions 1403 and 1404 are also referred to as a computer program.

[0353] In another possible design, the communications device 1400 may further include circuitry that may implement the functionality in the method embodiments described above.

[0354] In yet another possible design, the communications device 1400 may include one or more memories 1402 that store instructions 1404. The instructions may be executed on the processor 1401 such that the communications device 1400 performs the methods described in the foregoing method embodiments. Optionally, the memory 1402 may further store data. Optionally, the processor 1401 may also store instructions and / or data. For example, the one or more memories 1402 may store the correspondence relationships described in the foregoing embodiments, or related parameters, related tables, etc. in the foregoing embodiments. The processor and memory may be located separately or integrated with each other.

[0355] In yet another possible design, the apparatus 1400 may further include a transceiver 1405 and an antenna 1406. The processor 1401 may also be referred to as a processing unit and controls the apparatus (terminal or base station). The transceiver 1405 may also be referred to as a transceiver machine, transceiver circuit, transceiver unit, etc. and is configured to perform transceiver functions of the apparatus by using the antenna 1406.

[0356] The processor may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), one or more integrated circuits configured to control program execution of the solutions of the present application, a general-purpose processor, a digital signal processor (DSP), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The processor may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor, any conventional processor, etc. The steps of the methods disclosed with reference to the embodiments of the present application may be performed and completed directly by a hardware decoding processor, or may be performed and completed by using a combination of hardware and software modules in the decoding processor. The software modules may be in a storage medium, and the storage medium is located in a memory.

[0357] The memory may be volatile or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) acting as an external cache. By way of example and not limitation, many forms of RAM may be used. Examples include static random access memory (Static RAM, SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (Synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct Rambus random access memory (Direct Rambus RAM, DR RAM). It should be noted that the memory in the systems and methods described herein includes, but is not limited to, these memories and any other suitable type of memory. The memory may exist independently or may be connected to the processor through a communication line. Alternatively, the memory may be integrated with the processor.

[0358] An embodiment of the present application further provides a computer-readable medium storing a computer program product, which, when executed by a computer, performs the communication method of any one of the aforementioned method embodiments.

[0359] An embodiment of the present application further provides a computer program product including a computer program that, when executed by a computer, performs the communication method according to any one of the aforementioned method embodiments.

[0360] An embodiment of the present application further provides a communication system including an access management network element and an access network element, wherein the access management network element and the access network element are capable of implementing the communication method in any one of the embodiments of the method described above.

[0361] Optionally, the communication system further includes one or more of a terminal device and a data management network element, wherein the terminal device and the data management network element are capable of implementing the communication method in any one of the aforementioned method embodiments.

[0362] All or part of the above-described embodiments may be implemented using software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded into a computer and executed, the procedures or functions according to the embodiments of the present application are generated in whole or in part. The computer may be the above-described communication device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. The computer-readable storage medium may be the above-described storage medium or the above-described memory.

[0363] In one possible design, when the communication device is a chip, for example, a chip in a network device or a chip in a terminal device, the processing unit or processor 1401 may be one or more logic circuits, and the transmitting unit, receiving unit, or transceiver 1405 may be an input / output interface or may be referred to as a communication interface, interface circuit, interface, etc. Alternatively, the transceiver 1405 may be a transmitting unit and a receiving unit. The transmitting unit may be an output interface, and the receiving unit may be an input interface. The transmitting unit and the receiving unit are integrated into one unit, for example, an input / output interface. As shown in FIG. 15, the communication device 1500 shown in FIG. 15 includes a logic circuit 1501 and an interface circuit 1502. In other words, the determining unit or processor 1401 may be implemented using the logic circuit 1501, and the transmitting unit, receiving unit, or transceiver 1405 may be implemented through the interface circuit 1502. The logic circuit 1501 may be a chip, a processing circuit, an integrated circuit, a system on chip (SoC), etc. The interface circuit 1502 may be a communication interface, an input / output interface, etc. In this embodiment of the present application, the logic circuit and the interface circuit may be further coupled to each other. The specific connection manner of the logic circuit and the interface circuit is not limited in this embodiment of the present application.

[0364] In some embodiments of the present application, logic circuitry 1501 and interface circuitry 1502 may be configured to perform functions, operations, etc. performed by the aforementioned network functions or the aforementioned control plane functions. Interface circuitry 1502 may be configured to receive signals from a communication device other than communication device 1500 and transmit the signals to logic circuitry 1501, or to transmit signals from logic circuitry 1501 to a communication device other than communication device 1500. Logic circuitry 1501 may be configured to implement any one of the aforementioned method embodiments by executing code instructions.

[0365] For example, the interface circuit 1502 is configured to receive operation permission instruction information and permission conditions. For the functions or operations performed by the communication device, please refer to the above-mentioned method embodiments. The details will not be described again in this specification.

[0366] Those skilled in the art will recognize that the units and algorithm steps in combination with the examples described in the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination thereof. In order to clearly describe the interchangeability between hardware and software, the above generally describes the configurations and steps of each example based on functions. Whether these functions are performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but this implementation should not be considered to go beyond the scope of the present application.

[0367] For convenience of description, the detailed operation processes of the above-mentioned systems, devices, and units can be clearly understood by those skilled in the art by referring to the corresponding processes in the above-mentioned method embodiments, and the details will not be described again here.

[0368] In some embodiments provided herein, it should be understood that the disclosed systems, devices, and methods may be implemented in other manners. For example, the device embodiments described above are merely examples. For example, the division into units is merely a logical division of function. During actual implementation, other division schemes may exist. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not implemented. In addition, the shown or discussed mutual couplings or direct couplings or communication connections may be implemented through some interfaces. Indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms of connection.

[0369] The units described as separate parts may or may not be physically separate, and the parts shown as units may or may not be physical units, in other words, they may be located in one place or distributed over multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solutions of the embodiments of the present application.

[0370] In addition, the functional units in the embodiments of the present application may be integrated into one processing unit, and each unit may exist physically alone, or two or more units may be integrated into one unit. The integrated units may be implemented in the form of hardware or software functional units.

[0371] From the above description of implementation, those skilled in the art can clearly understand that the present application can be implemented by hardware, firmware, or a combination thereof. When the present application is implemented by software, the above functions can be stored on a computer-readable medium or transmitted as one or more instructions or code in a computer-readable medium. Computer-readable media include computer storage media and communication media, and communication media include any medium that facilitates the transmission of a computer program from one place to another. Storage media can be any available medium that can be accessed by a computer.

[0372] In conclusion, the above description is only an embodiment of the technical solution of the present application, and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, or improvement made within the principle of the present application shall fall within the protection scope of the present application.

Claims

1. A licensing method comprising: obtaining, by an access management network element, operation permission indication information and permission conditions, the operation permission indication information indicating that the terminal device is permitted to provide a connection service, and the permission conditions including a permitted location range of the connection service and / or a permitted time range of the connection service; sending, by the access management network element, an authorization result based on the authorized location range and / or the authorized time range to an access network element accessed by the terminal device, wherein the authorization result indicates that the terminal device is not authorized to provide the connection service or that the terminal device is authorized to provide the connection service; the connection service includes a mobile base station relay service, and the terminal device is a mobile base station relay device; sending, by the access management network element, an authorization result based on the authorized location range and / or the authorized time range to an access network element accessed by the terminal device: determining, by the access management network element, the authorization result based on the authorized location range and / or the authorized time range, and sending the authorization result to the access network element; method.

2. After the transmitting step, a PDU session setup procedure is initiated by the terminal device. The method of claim 1.

3. determining, by the access management network element, the authorization result based on the authorized time range: When the current time is outside the authorized time range, determining by the access management network element that the authorization result indicates that the terminal device is not allowed to provide the connection service; or determining, by the access management network element, when a current time is within the authorized time range, that the authorization result indicates that the terminal device is allowed to provide the connection service; The method of claim 1.

4. determining, by the access management network element, the authorization result based on the authorized location range: determining, by the access management network element, when the terminal device is outside the authorized location range, that the authorization result indicates that the terminal device is not allowed to provide the connection service; or determining, by the access management network element, when the terminal device is within the authorized location range, that the authorization result indicates that the terminal device is allowed to provide the connection service; The method of claim 1.

5. determining, by the access management network element, the authorization result based on the authorized location range: receiving, by the access management network element, notification information from a location management network element, the notification information being used to notify that the terminal device is outside the authorized location range or is within the authorized location range; When the notification information is used to notify that the terminal device is outside the authorized location range, determining, by the access management network element, that the authorization result indicates that the terminal device is not allowed to provide the connection service; or When the notification information is used to notify that the terminal device is within the authorized location range, determining, by the access management network element, that the authorization result indicates that the terminal device is allowed to provide the connection service. The method of claim 1.

6. determining, by the access management network element, the authorization result based on the authorized location range: When the tracking area in which the terminal device is located is outside the tracking area range corresponding to the authorized location range, determining by the access management network element that the authorization result indicates that the terminal device is not allowed to provide the connection service; or determining, by the access management network element, when a tracking area in which the terminal device is located is within a tracking area range corresponding to the authorized location range, that the authorization result indicates that the terminal device is allowed to provide the connection service; The method of claim 1.

7. and further comprising: transmitting, by the access management network element, the authorization result to the terminal device. The method of claim 1.

8. 2. The method of claim 1, wherein the permitted location range includes one or more of a permitted route of the connectivity service, a permitted area of ​​the connectivity service, an area in which the connectivity service is allowed to be provided, or an area in which the connectivity service is not allowed to be provided.

9. 1. A communications device, the device comprising: a receiving unit configured to obtain operation permission instruction information and permission conditions, the operation permission instruction information indicating that a terminal device is permitted to provide a connection service, and the permission conditions including a permitted location range of the connection service and / or a permitted time range of the connection service; a processing unit configured to determine an authorization result based on the authorized location range and / or the authorized time range; a transmitting unit configured to transmit the authorization result to an access network element accessed by the terminal device, the authorization result indicating that the terminal device is not authorized to provide the connection service or that the terminal device is authorized to provide the connection service; It has The connection service includes a mobile base station relay service, and the terminal device is a mobile base station relay device. Device.

10. 10. The apparatus of claim 9, wherein the processing unit is configured to: determine, when the current time is outside the allowed time range, that the authorization result indicates that the terminal device is not allowed to provide the connection service; or, when the current time is within the allowed time range, that the authorization result indicates that the terminal device is allowed to provide the connection service.

11. 10. The apparatus of claim 9, wherein the processing unit is configured to: determine, when the terminal device is outside the authorized location range, that the authorization result indicates that the terminal device is not allowed to provide the connection service; or, when the terminal device is within the authorized location range, that the authorization result indicates that the terminal device is allowed to provide the connection service.

12. The receiving unit is further configured to receive notification information from a location management network element, the notification information being used to notify that the terminal device is outside the authorized location range or within the authorized location range; the processing unit is configured to determine, when the notification information is used to notify that the terminal device is outside the authorized location range, that the authorization result indicates that the terminal device is not allowed to provide the connection service, or, when the notification information is used to notify that the terminal device is within the authorized location range, that the authorization result indicates that the terminal device is allowed to provide the connection service.

10. The apparatus of claim 9.

13. 10. The apparatus of claim 9, wherein the processing unit is configured to: determine, when a tracking area in which the terminal device is located is outside a tracking area range corresponding to the authorized location range, that the authorization result indicates that the terminal device is not allowed to provide the connectivity service; or, when a tracking area in which the terminal device is located is within a tracking area range corresponding to the authorized location range, that the authorization result indicates that the terminal device is allowed to provide the connectivity service.

14. the sending unit is further configured to send the authorization result to the terminal device; 10. The apparatus of claim 9.

15. 10. The device of claim 9, wherein the authorized location range includes one or more of an authorized route for the connectivity service, an authorized area for the connectivity service, an area in which the connectivity service is allowed to be provided, or an area in which the connectivity service is not allowed to be provided.

16. 1. A communications device comprising: a processor coupled to a memory; A communications device, wherein the processor is configured to execute computer programs or instructions stored in the memory, enabling the device to perform the method of any one of claims 1 to 8.

17. A communications system having an access management network element configured to perform a method according to any one of claims 1 to 8, comprising: The communication system further comprises a first core network element, the first core network element comprising: configured to transmit the operation permission indication information and the permission conditions to the access management network element; Communication system.

18. The communication system described in claim 17, further comprising a terminal device configured to receive the authorization result from the access management network element.

19. The communication system of claim 17, further comprising an access network element configured to receive the authorization result from the access management network element.

20. A computer readable storage medium containing a computer program or instructions, which, when run on a computer, performs the method of any one of claims 1 to 8.

21. A computer program which, when run on a computer, performs a method according to any one of claims 1 to 8.

22. A chip system A chip system comprising a processor and a memory, the processor coupled to the memory, the memory configured to store a program or instructions, and wherein, when the program or the instructions are executed by the processor, the method of any one of claims 1 to 8 is performed.

Citation Information

Patent Citations

  • Method, mobile management unit and gateway for restricting MTC device to access and communicate

    US20120315874A1

  • Method and apparatus for session configuration of terminal according to time or service area in wireless communication system

    US20200351391A1

  • Service authorization method, terminal device and network device

    WO2020147044A1

  • Service processing method, device and system

    WO2021068162A1