Network access control method and apparatus, related device, and readable storage medium

By paging passive devices in the 5GC system and combining contract data and service information, the problem of passive devices being unable to actively register is solved, access control of passive devices is realized, and management efficiency and performance of network systems are improved.

WO2025145918A1PCT designated stage expired Publication Date: 2025-07-10CHINA MOBILE COMM LTD RES INST +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/141367
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-02
Filing Date
2024-12-23
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

5GC is difficult to perform access control for passive devices, mainly because the passive devices are not configured with SIM cards and cannot actively initiate the registration process, which makes it difficult for the network system to distinguish operators and manage access to a large number of passive devices.

Method used

The first network element sends a request to the target object, paging the passive device or device group, and receives a response, combining the contract data and service information to determine whether access is allowed, so as to realize access control of the passive device.

Benefits of technology

Effectively manage the access to passive devices, avoid abuse, reduce access costs, and improve the performance and efficiency of network systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024141367_10072025_PF_FP_ABST
    Figure CN2024141367_10072025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of passive Internet of Things. Provided are a network access control method and apparatus, a related device, and a readable storage medium. The method applied to a first network element comprises: sending to a target object a first request, wherein the first request is used for requesting the target object to page a target passive device or a target passive device group, such that the target passive device or the target passive device group accesses a network, and the target object is at least one of base stations and terminals managed by the first network element; and receiving a first response which is corresponding to the first request and sent by the target object.
Need to check novelty before this filing date? Find Prior Art

Description

Network access control method, device, related equipment and readable storage medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese patent application No. 202410009186.0 filed in China on January 2, 2024, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present disclosure relates to the technical field of passive Internet of Things, and in particular to a network access control method, apparatus, related equipment, and readable storage medium. Background Art

[0004] Passive Internet of Things (Passive IoT) technology is a representative technology of the Internet of Things, which enables passive devices to access the network. After the passive device is powered on, it first selects the Public Land Mobile Network (PLMN) and access network and sends a registration request to the network. By authenticating and authorizing the identity of the passive device, the fifth-generation core network (5G) th The 5GC (5th Generation Core Network) decides whether to allow passive devices to access the network. Currently, when passive devices access the 5GC, they generally lack a Subscriber Identity Module (SIM) and therefore have difficulty in initiating the registration process. This makes it difficult for the 5GC to control access to passive devices. Summary of the Invention

[0005] The embodiments of the present disclosure provide a network access control method, apparatus, related equipment, and readable storage medium to solve the technical problem in related technologies that 5GC has difficulty in performing access control on passive devices.

[0006] To solve the above technical problems, the present disclosure is implemented as follows:

[0007] In a first aspect, an embodiment of the present disclosure provides a network access control method, applied to a first network element, the method comprising:

[0008] Sending a first request to a target object, where the first request is used to request the target object to page a target passive device or a target passive device group so that the target passive device or the target passive device group accesses the network, wherein the target object is at least one of a base station and a terminal managed by the first network element;

[0009] A first response corresponding to the first request is received, sent by the target object.

[0010] Optionally, the method further includes any one of the following:

[0011] performing access of the target passive device or the target passive device group based on the first response;

[0012] Accessing the target passive device or the target passive device group is performed based on contract data, wherein the contract data is stored in a unified data management (UDM), the contract data includes device information associated with the target passive device for executing a pending service, and the pending service is a service sent by a server to be processed by the target passive device or the target passive device group;

[0013] Accessing the target passive device or the target passive device group is performed based on the first response and the subscription data.

[0014] Optionally, before sending the first request to the target object, the method further includes:

[0015] receiving a second request sent by the server, where the second request is associated with the pending service, and the second request carries at least service information of the pending service;

[0016] Acquiring the contract data based on the service information, or reading the pre-stored contract data based on the service information;

[0017] The target object is determined based on the device information and the service information.

[0018] Optionally, the service information includes at least one of the following: identification information of the service to be processed, identification information and location information of the target passive device or the target passive device group for executing the service to be processed;

[0019] The identification information of the service to be processed includes at least one of type information and identifier information of the service to be processed.

[0020] Optionally, when the device information includes identification information of the target passive device, acquiring the subscription data based on the service information includes:

[0021] In a case where the service information does not include the identification information of the target passive device, configuring a correspondence between the service identification of the to-be-processed service and the identification information of the target passive device that executes the to-be-processed service;

[0022] Based on the corresponding relationship, the subscription data associated with the target passive device corresponding to the identification information stored in the UDM is obtained.

[0023] Optionally, the first request carries the service information or the device information;

[0024] The first request is further used to request the target object to send a third request to the target passive device or the target passive device group, and the third request is used to instruct the target passive device or the target passive device group to access a network.

[0025] Optionally, the performing access to the target passive device or the target passive device group based on the first response includes:

[0026] When the time limit for receiving the first response is less than or equal to the first preset receiving time limit, receiving a first response corresponding to the first request sent by the target object;

[0027] In a case where the time limit for receiving the first response is greater than a second preset receiving time limit, instructing the target object to end paging the target passive device;

[0028] Accessing the target passive device or the target passive device group is performed based on the first response.

[0029] Optionally, the performing access to the target passive device or the target passive device group based on the first response includes:

[0030] If the time for the target object to receive the first response is less than or equal to a third preset receiving time limit, receiving a first response corresponding to the first request sent by the target object;

[0031] In a case where the time for the target object to receive the first response is greater than the third preset receiving time limit, instructing the target object to end paging the target passive device;

[0032] performing access of the target passive device or the target passive device group based on a first response, wherein the first response corresponds to the first request;

[0033] Among them, the third preset receiving time limit is obtained by the target object based on the first request.

[0034] Optionally, the device information includes at least one of the following:

[0035] The identification information of the target passive device, the identification information of the executed service, the type of service allowed to be executed, the type of service prohibited to be executed, the location information of the service allowed to be executed, the location information of the service prohibited to be executed, the time period when the service is allowed to be executed, the time period when the service is prohibited to be executed, the preset PLMN, and the application function AF allowed to access the target passive device.

[0036] Optionally, the first response carries at least one of the following:

[0037] The identification information of the target passive device, the current usage time, the current location, the cell identifier NGCI, the associated base station identifier gNB ID, and the accessed public land mobile network PLMN.

[0038] Optionally, the determining, according to the first response, whether to allow the target passive device to access includes at least one of the following:

[0039] If the current usage time of the target passive device exceeds the time period in which the service is allowed to be executed, determine to deny access to the target passive device;

[0040] If the PLMN corresponding to the target passive device does not correspond to the preset PLMN, determining to deny access to the target passive device;

[0041] In a case where the current location of the target passive device is within the location information where execution of services is prohibited, it is determined to deny access to the target passive device.

[0042] In a second aspect, an embodiment of the present disclosure provides a network access control device, applied to a first network element, the device including:

[0043] a sending module, configured to send a first request to a target object, wherein the first request is used to request the target object to page a target passive device or a target passive device group so that the target passive device or the target passive device group accesses the network, wherein the target object is at least one of a base station and a terminal managed by the first network element;

[0044] A first response corresponding to the first request is received, sent by the target object.

[0045] In a third aspect, an embodiment of the present disclosure further provides a network access control device, applied to a first network element, comprising: a processor and a transceiver,

[0046] The transceiver is configured to send a first request to a target object, wherein the first request is used to request the target object to page a target passive device or a target passive device group so that the target passive device or the target passive device group accesses the network, wherein the target object is at least one of a base station and a terminal managed by the first network element;

[0047] A first response corresponding to the first request is received, sent by the target object.

[0048] In a fourth aspect, an embodiment of the present disclosure further provides a network element device, comprising: a processor, a memory, and a program stored on the memory and runnable on the processor, wherein when the program is executed by the processor, the steps of the network access control method as described in any one of the first aspects are implemented.

[0049] In a fifth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the network access control method as described in any one of the first aspects are implemented.

[0050] In the disclosed embodiment, the first request enables the target object to page the target passive device or target passive device group. After being paged by the target object, the target object initiates a network access request to the target object, thereby enabling the target passive device or target passive device group to access the network system. In this way, the first network element can achieve access to the target passive device through screening. Through the paging of the target passive device or target passive device group by the first network element and the target object, access control operations for the passive device in the network system are implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the description of the embodiments of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0052] FIG1 is a flow chart of a network access control method according to an embodiment of the present disclosure;

[0053] FIG2 is a second flowchart of a network access control method provided by an embodiment of the present disclosure;

[0054] FIG3 is a third flowchart of a network access control method provided by an embodiment of the present disclosure;

[0055] FIG4 is a schematic structural diagram of a network access control device provided by an embodiment of the present disclosure;

[0056] FIG5 is a schematic structural diagram of a network element device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0057] The following will clearly and completely describe the technical solutions in the embodiments of the present disclosure in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present disclosure without making any creative efforts shall fall within the scope of protection of the present disclosure.

[0058] For ease of understanding, some contents involved in the embodiments of the present disclosure are described below:

[0059] IoT technologies within 5G (5th Generation Mobile Communication Technology) systems, such as massive machine-type communications (mMTC), narrowband Internet of Things (NB-IoT), and reduced capability (RedCap), are developing rapidly. In some special scenarios, such as those operating under extreme environmental conditions like high voltage, high temperature, low temperature, or humidity, IoT devices require extremely low complexity, extremely small size, and a long lifecycle, making traditional IoT devices no longer suitable. Consequently, IoT technology has expanded into passive IoT and ambient IoT (Ambient IoT). Ambient IoT pursues extreme low power consumption in terminals, drawing power from the surrounding environment (e.g., radio waves, solar energy, wind, vibration, heat, etc.), eliminating the need for batteries or limited storage. Ambient IoT devices can be passive or semi-passive, effectively addressing the energy supply dependency of related IoT technologies. They are widely applicable in automated warehousing, medical equipment storage and management, smart grids, automotive manufacturing, smart homes, and other fields.

[0060] Since most Ambient IoT devices are passive or semi-passive, they are generally not equipped with SIM cards. Furthermore, most passive devices, such as tags, cannot actively request access by initiating a registration process with the network system. This results in the core network elements of the network system being unable to access the passive devices. Furthermore, if multiple passive devices belonging to the same region or the same customer belong to multiple operators, the network system also has difficulty distinguishing the operator to which each passive device belongs. Furthermore, if a single terminal accesses the network system, the access and mobility management function (AMF) in the network system must interact with the unified data management (UDM). The AMF can obtain the customer's subscription data pre-stored in the UDM. If a large number of passive devices need to access the network system, a large number of tags will be required to operate simultaneously, which consumes a large amount of storage space in the core network elements of the network system and generates a large amount of signaling, seriously affecting the performance of the core network elements and increasing interaction costs.

[0061] Therefore, the present disclosure provides a network access control method, apparatus, related equipment and readable storage medium, which can perform access control management on passive devices that need to access the network system, avoid abuse of passive devices, and reduce access costs.

[0062] Referring to FIG. 1 , FIG. 1 is a flowchart of a network access control method provided by an embodiment of the present disclosure, which is applied to a first network element. As shown in FIG. 1 , the method includes the following steps:

[0063] Step 101: Send a first request to a target object, where the first request is used to request the target object to page a target passive device or a target passive device group so that the target passive device or the target passive device group can access a network, wherein the target object is at least one of a base station and a terminal managed by the first network element;

[0064] It should be noted that the above-mentioned first network element can be any network element in the network system that can be used for data management, tag management, access management, mobility management, etc., specifically it can be an AMF, or it can be a newly added network element, or it can be a network element dedicated to tag management added to the core network element, for example, the Tag Management Function (TMF).

[0065] In addition, the terms "system" and "network" in the embodiments of the present disclosure are often used interchangeably, and the described technology can be used for existing systems (such as 5th Generation (5G) communication systems) and radio technologies, as well as other systems (such as 6th Generation (6G) communication systems) and radio technologies.

[0066] In the present disclosure, the network to which the target passive device or the target passive device group accesses may be a network system, and the network system may include core network equipment. The core network equipment may include but is not limited to at least one of the following: a core network node, a core network function, a mobility management entity (MME), an AMF, a session management function (SMF), a user plane function (UPF), a policy control function (PCF), a policy and charging rules function unit (PCRF), an edge application server discovery function (EASDF), a UDM, a unified data repository (UDR), a home subscriber server (HSS), a centralized network configuration (CNC), a network repository function (NRF), a network exposure function (NEF), a local NEF (L-NEF), and a binding support function (BSF). Function, BSF), application function (Application Function, AF), etc.

[0067] It is understandable that a target passive device group is introduced in the embodiments of the present disclosure, but the target passive device mentioned above or any passive device in the target passive device group can be an Ambient IoT device in Ambient IoT, mainly a passive device. The present disclosure does not impose specific restrictions on the scenarios in which the target passive device can be applied, the types of services that can be applied, the functional uses, etc., and the specific categories, functions, and applied services of the target passive device can be determined according to the requirements of accessing the network system in different application scenarios. Each passive device in the above-mentioned target passive device or the target passive device group is a passive device that can be accessed to the network system and can perform business processing. Due to the increase in the use scenarios and frequency of the passive Internet of Things, the passive devices can be connected to the network system in a group manner for management and identification. A target passive device group can include multiple passive devices. Specifically, the target passive device or the passive device in the target passive device group in the embodiments of the present disclosure is described by taking the Ambient IoT device in Ambient IoT as an example.

[0068] It is worth mentioning that the above-mentioned target object can be determined by the decision of the first network element, and the specific decision basis can be information related to the target passive device or the target passive device group, such as the device information of the target passive device or the target passive device group that has signed a contract with the customer pre-stored in the UDM, the information about the target passive device or the target passive device group in the service information carried in the service request sent by the third-party server or the third-party AF, or the target object can be determined based on the device information of the contracted target passive device or the target passive device group and the information about the target passive device or the target passive device group in the service information. In addition, the above-mentioned target object can be at least one of the base stations and terminals managed by the first network element. For example, if the target object is a 5G wireless access network (Next Generation Radio Access Network, NG-RAN), the NG-RAN needs to be able to send service requests or transmit information to the target passive device or the target passive device group. For another example, if the target object is a base station managed by a first network element, the base station should be a base station that can cover the target passive device or the target passive device group and affect the target passive device.

[0069] In a specific implementation of the present disclosure, the first request may be sent by a first network element (e.g., AMF) to a target object, or by another core network element, e.g., TMF, to a target object. The first request is used to request the target object to page a target passive device or a target passive device group, so that the target passive device or the target passive device group can initiate a network access request to the first network element (e.g., AMF).

[0070] Specifically, after the first network element completes the decision to determine the target object, it can send a first request to the target object. The first request can include service information of the pending service to be executed or device information of the target passive device. The first request can also instruct the target object to page the target passive device and send the service information or device information to the target passive device after paging the target passive device. If the service information or device information does not include location information, the first network element can send a service request to all target objects it manages, so that all target objects can send service information or device information to the passive device, helping the target passive device to access the network system.

[0071] Step 102: Receive a first response corresponding to the first request sent by the target object.

[0072] In a specific embodiment of the present disclosure, the above-mentioned first response is a response made by the target passive device or the target passive device group after receiving the paging of the target device. The target passive device or the target passive device group performs random access to the network system and first accesses the target object. For example, after the target passive device or the target passive device group receives the paging of the target object (such as NG-RAN), it performs random access to the NG-RAN and sends a first response to the NG-RAN. The NG-RAN transmits the first response to the first network element. In addition, the above-mentioned first response may carry associated information of the target passive device or the target passive device group, for example, specific device information related to the target passive device or the target passive device group. The present disclosure does not make specific restrictions here. For details, please refer to the explanation of device information in the following specific embodiments.

[0073] Optionally, the method further includes any one of the following:

[0074] performing access of the target passive device or the target passive device group based on the first response;

[0075] Accessing the target passive device or the target passive device group is performed based on contract data, wherein the contract data is stored in a unified data management (UDM), the contract data includes device information associated with the target passive device for executing a pending service, and the pending service is a service sent by a server to be processed by the target passive device or the target passive device group;

[0076] Accessing the target passive device or the target passive device group is performed based on the first response and the subscription data.

[0077] In a specific embodiment of the present disclosure, determining whether the first network element executes access to the target passive device or the target passive device group can be achieved in three ways. Among them, the first way can be to determine whether the first network element executes access to the target passive device or the target passive device group only by the specific content of the first response. For example, if the first response information includes the service type of the target passive device or the target passive device group, which is consistent with the service type required in the server request sent by the current first network element, then the access of the target passive device or the target passive device group can be allowed. The second way is to determine whether the first network element can execute access to the target passive device or the target passive device group through the contract information. For example, after the first network element receives the first response, the contract data shows that it is not currently in a time period where the execution of the service is prohibited, then the access of the target passive device or the target passive device group can be allowed.

[0078] Furthermore, the third type may be determined together with the first response and the contract data. Specifically, since the first response of the target passive device or the target passive device group may carry the associated information of the target passive device, the first network element can compare the specific information content in the first response with the corresponding content in the contract data to determine whether the first network element allows the target passive device or the target passive device group to access the network system. For example, the first response may include the usage period of the target passive device or the target passive device group. If the usage period has exceeded the usage period, it means that the target passive device or the target passive device group should be disabled at this time, so it is necessary to prohibit the target passive device or the target passive device group from accessing the network system. For another example, the first response includes the operator to which it belongs. If the operator to which the target passive device or the target passive device group actually belongs is inconsistent with the operator corresponding to the target passive device stored in the network system, the first network element needs to prohibit the target passive device or the target passive device group from accessing the network system. Through the above embodiments, it is possible to screen the target passive device or target passive device group when accessing the network system, and determine whether the target passive device or target passive device group can access the network system based on actual business needs, access restrictions, etc., thereby improving the effectiveness of the equipment accessing the network system and avoiding the impact of access restrictions on the target passive device or target passive device group on the performance of the core network network elements.

[0079] It is understandable that after the AMF determines the target object, the target object receives the first request sent by the AMF, and the target object then sends a service request message to the target passive device based on the information in the first request to page the target passive device or the target passive device group. The service request message may include the information on which the aforementioned AMF decision to determine the target object is based, for example, specific information related to the service in the service request, or the device information of the target passive device or the target passive device group that has signed a contract with the customer. In this way, it is possible to find a target passive device or a target passive device group that can solve the corresponding service request or is consistent with the device information used for decision-making, and then the target object pages the target passive device or the target passive device group, so that the target passive device or the target passive device group can perform random access to the network system after receiving the paging of the target object.

[0080] In a specific implementation, the first network element may receive a service request sent by a server or other network element. The service request may be sent by the server or a third network element, such as a third-party AF. The service request may be forwarded by the third network element to the first network element via the NEF. The service request is used to request the first network element to control and manage pending services. The pending services may be services related to the server or the third network element and need to be processed by a passive device. Therefore, based on whether there is contract data corresponding to the pending services, it can be determined whether the target passive device or target passive device group corresponding to the contract data can access the network system.

[0081] In this way, when the target passive device or target passive device group accesses the network system, it responds to the first request and sends a first response back to the target object, so that the target object can pass the first response to the first network element, and the first network element then makes a decision on whether to allow the target passive device to access based on the first response. In the embodiment of the present disclosure, the first network element can also distinguish the target passive device or target passive device group and complete access authentication for the target passive device or target passive device group.

[0082] Optionally, before sending the first request to the target object, the method further includes:

[0083] receiving a second request sent by the server, where the second request is associated with the pending service, and the second request carries at least service information of the pending service;

[0084] Acquiring the contract data based on the service information, or reading the pre-stored contract data based on the service information;

[0085] The target object is determined based on the device information and the service information.

[0086] In an embodiment of the present disclosure, the second request may be a service request initiated by a server or a third-party AF, and the service request may correspond to one or more services to be processed. The service request may specifically include service information, and the service information may specifically include identification information of the service to be processed (for example, identification of services such as inventory or positioning), identification information corresponding to the target passive device required to process the service to be processed, etc. The service identification may include type information, identifier information, etc. of the service. In addition, the service request obtained by the first network element in the present disclosure may be obtained directly by the third-party AF or after being forwarded by the NEF.

[0087] In another embodiment of the present disclosure, if the service information does not include the identification information of the target passive device or does not include the group identification of the passive device, the correspondence between the service identification of the service to be processed and the identification information of the target passive device that executes the service to be processed can be configured in the first network element, or the correspondence between the service identification and the group identification of the passive device group can be configured, so that the first network element can match the target passive device that needs to execute the service to be processed in the service request with the target passive device in the contract data.

[0088] Optionally, the service information includes at least one of the following: identification information of the service to be processed, identification information and location information of the target passive device or the target passive device group for executing the service to be processed;

[0089] The identification information of the service to be processed includes at least one of type information and identifier information of the service to be processed.

[0090] It is worth mentioning that the subscription data may include the service type identifier of the pending service that can be executed by the above-mentioned target passive device or one or more passive devices in the target passive device group, the identification information corresponding to the specific passive device that executes the pending service, location information, restricted area, the validity period of the target passive device or one or more passive devices in the target passive device group, the number of passive devices allowed to access, the access rights of the target passive device or one or more passive devices in the target passive device group, etc. Among them, the restricted area may be an area where access to the target passive device or one or more passive devices in the target passive device group is allowed or prohibited, and may include the specific geographical location information of the tracking area (TA), base station identifier (gNB ID), and next generation core network service indicator (NGCI) area. The above-mentioned access rights may be the AF and / or executable operations that are allowed to access the target passive device or one or more passive devices in the target passive device group, such as only allowing read operations, and the present disclosure does not impose specific restrictions on this.

[0091] In another specific embodiment of the present disclosure, the contract data may be the contract data of a single or multiple target passive devices stored in the UDM, or the contract data of one or more passive device groups may be stored together in the UDM. The contract data of a passive device group may include the contract data of multiple target passive devices, or the contract data of other passive devices in the target passive device group. Therefore, the first network element may also directly obtain the contract data of a passive device group from the UDM. Similarly, the service information carried in the service request sent by the server or the third-party AF to the first network element may be of a single or multiple target passive devices, or of one or more passive device groups. The present disclosure does not impose any specific restrictions, and a single or multiple target passive devices, or one or more passive device groups may be set according to the actual application situation.

[0092] It should be noted that the subsequent embodiments of the present disclosure are described using a target passive device as an example, but are also applicable to a target passive device group, which is specifically explained here.

[0093] Optionally, when the device information includes identification information of the target passive device, acquiring the subscription data based on the service information includes:

[0094] In a case where the service information does not include the identification information of the target passive device, configuring a correspondence between the service identification of the to-be-processed service and the identification information of the target passive device that executes the to-be-processed service;

[0095] Based on the corresponding relationship, the subscription data associated with the target passive device corresponding to the identification information stored in the UDM is obtained.

[0096] Specifically, the first network element may send a second request to the target object, requesting the target object to page the target passive device or target passive device group. The second request may carry information related to the pending service in the service request, such as the service type of the pending service, information about the target passive device capable of processing the pending service, or information about the target passive device group capable of processing the pending service. Upon receiving the paging call from the target object, multiple passive devices in the target passive device or target passive device group may execute the pending service and related operations, such as inventory, reading, and writing, and may initiate a network access request through the target object and return response information to the target object.

[0097] In this way, when a target passive device or multiple passive devices in a target passive device group access the network system, the first network element can review their access qualifications to determine whether they are eligible for access. For example, if the response information returned by the target passive device includes its actual PLMN, and the PLMN corresponding to the target passive device in the first context stored by the first network element is inconsistent with its actual PLMN, the first network element may not allow the target passive device to access the network system, thereby facilitating the management of the target passive device.

[0098] Optionally, the first request carries the service information or the device information;

[0099] The first request is further used to request the target object to send a third request to the target passive device or the target passive device group, and the third request is used to instruct the target passive device or the target passive device group to access a network.

[0100] It is understood that the first request can also be used to request the target object to send a third request to the target passive device or target passive device group to instruct the target passive device or target passive device group to access the network system, so that the target passive device or target passive device group can initiate an access request. Through the first network element and the target object paging the target passive device or target passive device group, access control operations for the passive device in the network system are implemented.

[0101] Optionally, the performing access to the target passive device or the target passive device group based on the first response includes:

[0102] When the time limit for receiving the first response is less than or equal to the first preset receiving time limit, receiving a first response corresponding to the first request sent by the target object;

[0103] In a case where the time limit for receiving the first response is greater than a second preset receiving time limit, instructing the target object to end paging the target passive device;

[0104] Accessing the target passive device or the target passive device group is performed based on the first response.

[0105] Optionally, the performing access to the target passive device or the target passive device group based on the first response includes:

[0106] If the time for the target object to receive the first response is less than or equal to a third preset receiving time limit, receiving a first response corresponding to the first request sent by the target object;

[0107] In a case where the time for the target object to receive the first response is greater than the third preset receiving time limit, instructing the target object to end paging the target passive device;

[0108] performing access of the target passive device or the target passive device group based on a first response, wherein the first response corresponds to the first request;

[0109] Among them, the third preset receiving time limit is obtained by the target object based on the first request.

[0110] In another specific embodiment of the present disclosure, a preset reception time limit can be set. The preset reception time limit can be one of the relevant device information of the target passive device subscribed by the customer and can be stored in the subscription data in the UDM. When the first network element obtains the subscription data stored in the UDM, the preset reception time limit is also obtained. The time limit for the first network element to receive the first response can be the time limit for the target object to send the first response to the first network element, or it can be the time it takes for the target passive device to first send the first response to the target object, and then for the target object to send it to the first network element. Therefore, the target passive devices can be screened by comparing the time limit for the first network element to receive the first response with the preset reception time limit. The preset reception time limit can be expressed as the maximum delay for the first network element to receive the first response. If the first network element does not receive the first response returned by the target object (such as NG-RAN) within the time limit, it instructs the NG-RAN to end the paging. At this time, a response message indicating the end of the paging can be returned to the third-party AF or server.

[0111] In another embodiment, the preset receiving time limit can also be carried in the service request message and can be sent to the target object (such as NG-RAN or other terminal). The target object can determine whether to end the paging of the target passive device based on the time limit for the target passive device to return the first response and the preset receiving time limit based on the comparison result.

[0112] Optionally, the device information includes at least one of the following:

[0113] The identification information of the target passive device, the identification information of the executed service, the type of service allowed to be executed, the type of service prohibited to be executed, the location information of the service allowed to be executed, the location information of the service prohibited to be executed, the time period when the service is allowed to be executed, the time period when the service is prohibited to be executed, the preset PLMN, and the application function AF allowed to access the target passive device.

[0114] It should be understood that the device information in the present disclosure may include identification information of passive devices, and the identification information may specifically be one or more identification codes such as a subscriber permanent identifier (SUPI), a subscriber concealed identifier (SUCI), an electronic product code (EPC), and a tag identifier (TID), and the present disclosure is not limited thereto.

[0115] Specifically, each piece of information contained in the device information can be used as a criterion for the subsequent first network element to determine whether the target passive device actually needs to access the network system. For example, based on the service type actually performed by the target passive device, the types of permitted services and prohibited services carried in the contract data (specifically, in the device information) are compared. If the type of service falls within the range of permitted services, the target passive device is allowed to access the network system; if the type of service falls within the range of prohibited services, the target passive device is prohibited from accessing the network system, thus completing the screening of the target passive device's access to the network system.

[0116] Optionally, the first response carries at least one of the following:

[0117] The identification information of the target passive device, the current usage time, the current location, the cell identifier NGCI, the associated base station identifier gNB ID, and the accessed public land mobile network PLMN.

[0118] As an optional embodiment, if the first response returns either an EPC code or a TID code, or both, the target passive device must pre-write its PLMN and include it in the first response. The target object then sends the first response carrying the PLMN to the first network element. If the first response does not include the PLMN, it will be difficult for the first network element to determine the EPC code or TID code of the target passive device based on the EPC code or TID code. However, if the target passive device carries a SUPI, the first network element can determine its PLMN based on this. This allows the first network element to determine whether the target passive device is eligible to access the network system based on the PLMN to which it actually belongs, thereby conserving network system resources.

[0119] It is worth mentioning that the preset PLMN in the present disclosure may be included in the first identification information of the target passive device or the second identification information of the target passive device group, or may be independently presented in the first response message.

[0120] Optionally, the determining, according to the first response, whether to allow the target passive device to access includes at least one of the following:

[0121] If the current usage time of the target passive device exceeds the time period in which the service is allowed to be executed, determine to deny access to the target passive device;

[0122] If the PLMN corresponding to the target passive device does not correspond to the preset PLMN, determining to deny access to the target passive device;

[0123] In a case where the current location of the target passive device is within the location information where execution of services is prohibited, it is determined to deny access to the target passive device.

[0124] It should be noted that after the first network element determines to deny access to the target passive device, it may return a response message to the third-party AF or server. The response message may include device information of the passive device or device information of the entire target passive device group, or an operation structure for denying access to the target passive device. The response message may be sent by the first network element to the NEF, and then sent to the third-party AF via the NEF. Furthermore, the present disclosure does not elaborate on the specific comparison process. Reference may be made to the description of the first network element comparing the information in the first response with the corresponding information in the contract data in the aforementioned embodiment to determine whether the target passive device can access the network system.

[0125] In this way, when a target passive device or multiple passive devices in a target passive device group access the network system, the first network element can review their access qualifications to determine whether they are eligible for access. For example, if the response information returned by the target passive device includes its actual PLMN, and the PLMN corresponding to the target passive device in the first context stored by the first network element is inconsistent with its actual PLMN, the first network element may not allow the target passive device to access the network system, thereby facilitating the management of the target passive device.

[0126] Referring to FIG2 , a network access control method according to an embodiment of the present disclosure specifically includes the following steps:

[0127] Step 201: The UDM stores the subscription data associated with the target passive device or the target passive device group.

[0128] Step 202: The server or the third-party AF sends a second request to the first network element, where the second request is associated with the pending service and carries at least service information of the pending service.

[0129] Step 203: The first network element obtains subscription data from the UDM.

[0130] Step 204: Determine the target object based on the contract data and the service request;

[0131] Step 205: The first network element sends a first request to the target object, where the first request is used to request the target object to page a target passive device or a target passive device group, so that the target passive device initiates a network access request;

[0132] Step 206: The target object pages the target passive device or the target passive device group based on the first request;

[0133] Step 207: The target passive device or the target passive device group initiates a network access request to the target object and sends a first response to the target object within a receiving time limit, wherein the receiving time limit is a preset receiving time limit;

[0134] Step 208: Send a first response to the first network element within the receiving time limit;

[0135] Step 209: The first network element determines whether to allow the target passive device or the target passive device group to access based on the first response;

[0136] Step 210: If it is determined that the target passive device or the target passive device group is denied access, send a second response to the target passive device or the target passive device group;

[0137] Step 211: If it is determined that the target passive device or the target passive device group is denied access, a third response is sent to the server or the third-party AF.

[0138] It should be noted that the network access control method provided by the embodiment of the present disclosure as described in Figure 2 can implement the various processes implemented in the aforementioned method embodiment and can achieve the same beneficial effects. Its specific implementation method can refer to the relevant description of the embodiment shown in Figure 1. In order to avoid repetition, this embodiment will not be repeated.

[0139] As shown in FIG3 , the present disclosure also provides a network access control method, which specifically includes the following steps:

[0140] Step 301: The UDM stores the subscription data associated with the target passive device or the target passive device group.

[0141] Step 302: The server or the third-party AF sends a second request to the first network element, where the second request is associated with the pending service and carries at least service information of the pending service.

[0142] Step 303: The first network element obtains subscription data from the UDM.

[0143] Step 304: Determine the target object based on the contract data and the service request;

[0144] Step 305: The first network element sends a first request to the target object, where the first request is used to request the target object to page the target passive device or the target passive device group, so that the target passive device or the target passive device group initiates a network access request;

[0145] Step 306: The target object pages the target passive device or the target passive device group based on the first request;

[0146] Step 307: The target passive device or target passive device group initiates a network access request to the target object, but fails to send a first response to the target object within a receiving time limit, where the receiving time limit is a preset receiving time limit.

[0147] Step 308: The target object does not send a first response to the first network element within the receiving time limit;

[0148] Step 309: If the first network element does not receive the first response within the receiving time limit, the first network element sends a third request to the target object, where the third request is used to instruct the target object to end paging the target passive device or the target passive device group.

[0149] Step 310: The target object ends paging the target passive device or the target passive device group based on the third request.

[0150] It should be noted that the network access control method provided by the embodiment of the present disclosure as described in Figure 3 can implement the various processes implemented in the aforementioned method embodiment and can achieve the same beneficial effects. Its specific implementation method can refer to the relevant description of the embodiment shown in Figure 1. In order to avoid repetition, this embodiment will not be repeated.

[0151] Referring to FIG. 4 , an embodiment of the present disclosure provides a network access control device 400, which is applied to a first network element. The device includes:

[0152] A sending module 401 is configured to send a first request to a target object, where the first request is used to request the target object to page a target passive device or a target passive device group so that the target passive device or the target passive device group can access the network, wherein the target object is at least one of a base station and a terminal managed by the first network element;

[0153] A first response corresponding to the first request is received, sent by the target object.

[0154] Optionally, the sending module further includes any one of the following:

[0155] A first execution module, configured to execute access to the target passive device or the target passive device group based on the first response;

[0156] a second execution module, configured to execute access of the target passive device or the target passive device group based on contract data, wherein the contract data is stored in a unified data management (UDM), the contract data includes device information associated with the target passive device for executing a pending service, and the pending service is a service sent by a server to be processed by the target passive device or the target passive device group;

[0157] A third execution module is configured to execute access to the target passive device or the target passive device group based on the first response and the subscription data.

[0158] Optionally, the sending module 401 further includes:

[0159] A first receiving submodule is configured to receive a second request sent by the server, where the second request is associated with the pending service and carries at least service information of the pending service;

[0160] A first acquisition submodule, configured to acquire the contract data based on the service information, or read the pre-stored contract data based on the service information;

[0161] The first determination submodule is configured to determine the target object based on the device information and the service information.

[0162] Optionally, the service information includes at least one of the following: identification information of the service to be processed, identification information and location information of the target passive device or the target passive device group for executing the service to be processed;

[0163] The identification information of the service to be processed includes at least one of type information and identifier information of the service to be processed.

[0164] Optionally, when the device information includes identification information of the target passive device, the first acquiring submodule includes:

[0165] a configuration unit, configured to configure a correspondence between the service identifier of the service to be processed and the identification information of the target passive device that executes the service to be processed, if the service information does not include the identification information of the target passive device;

[0166] An acquiring unit is configured to acquire, based on the corresponding relationship, the subscription data associated with the target passive device corresponding to the identification information stored in the UDM.

[0167] Optionally, the first request carries the service information or the device information;

[0168] The first request is further used to request the target object to send a third request to the target passive device or the target passive device group, and the third request is used to instruct the target passive device or the target passive device group to access a network.

[0169] Optionally, the first execution module includes:

[0170] The first receiving submodule is configured to receive a first response corresponding to the first request sent by the target object when a time limit for receiving the first response is less than or equal to a first preset receiving time limit.

[0171] a second receiving submodule, configured to instruct the target object to end paging the target passive device when the time limit for receiving the first response is greater than a second preset receiving time limit;

[0172] The first access submodule is configured to access the target passive device or the target passive device group based on the first response.

[0173] Optionally, the first execution module includes:

[0174] a third receiving submodule, configured to receive, if the time taken by the target object to receive the first response is less than or equal to a third preset receiving time limit, a first response corresponding to the first request sent by the target object;

[0175] an instructing submodule, configured to instruct the target object to end paging the target passive device if the time for the target object to receive the first response is greater than the third preset receiving time limit;

[0176] a second access submodule, configured to perform access of the target passive device or the target passive device group based on a first response, wherein the first response corresponds to the first request;

[0177] Among them, the third preset receiving time limit is obtained by the target object based on the first request.

[0178] Optionally, the device information includes at least one of the following:

[0179] The identification information of the target passive device, the identification information of the executed service, the type of service allowed to be executed, the type of service prohibited to be executed, the location information of the service allowed to be executed, the location information of the service prohibited to be executed, the time period when the service is allowed to be executed, the time period when the service is prohibited to be executed, the preset PLMN, and the application function AF allowed to access the target passive device.

[0180] Optionally, the first response carries at least one of the following:

[0181] The identification information of the target passive device, the current usage time, the current location, the cell identifier NGCI, the associated base station identifier gNB ID, and the accessed public land mobile network PLMN.

[0182] Optionally, the execution module 402 includes at least one of the following:

[0183] A first determining submodule is configured to determine to deny access to the target passive device if the current usage time of the target passive device exceeds the time period in which the service is allowed to be executed;

[0184] A second determining submodule is configured to determine to deny access to the target passive device if the PLMN corresponding to the target passive device does not correspond to the preset PLMN;

[0185] The third determining submodule is configured to determine to deny access to the target passive device if the current location of the target passive device is within the location information where execution of services is prohibited.

[0186] It should be noted that the network access control device 400 provided in the embodiment of the present disclosure is applied to the first network element. The network access control device 400 is a device capable of executing the above-mentioned network access control method. Therefore, all implementation methods in the above-mentioned embodiments are applicable to the network access control device 400. For details, please refer to the corresponding embodiments of Figures 1 and 2, and all of them can achieve the same or similar beneficial effects. To avoid repetition, this embodiment will not be described in detail.

[0187] Specifically, as shown in FIG5 , an embodiment of the present disclosure further provides a network element device, which is applied to a first network element and includes a bus architecture (represented by bus 501). Bus 501 may include any number of interconnected buses and bridges. Bus 501 links various circuits, including one or more processors represented by processor 505 and memory represented by memory 506. Bus 501 may also link various other circuits, such as peripheral devices, voltage regulators, and power management circuits. These are all well known in the art and, therefore, are not further described herein. Bus interface 504 provides an interface between bus 501 and transceiver 502. Transceiver 502 may be a single component or multiple components, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 505 is transmitted over a wireless medium via antenna 503. Antenna 503 also receives data and transmits it to processor 505.

[0188] The processor 505 is responsible for managing the bus 501 and general processing, and may also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. The memory 506 may be used to store data used by the processor 505 when performing operations. The processor 505 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD).

[0189] The transceiver 502 is configured to:

[0190] Sending a first request to a target object, where the first request is used to request the target object to page a target passive device or a target passive device group so that the target passive device or the target passive device group accesses the network, wherein the target object is at least one of a base station and a terminal managed by the first network element;

[0191] A first response corresponding to the first request is received, sent by the target object.

[0192] Optionally, the processor 505 is further configured to:

[0193] performing access of the target passive device or the target passive device group based on the first response;

[0194] Access to the target passive device or the target passive device group is performed based on the contract data, wherein the contract data is stored in the unified data management UDM, and the contract data includes device information associated with the target passive device for executing the pending service, and the pending service is the service sent by the server to be processed by the target passive device or the target passive device group.

[0195] Accessing the target passive device or the target passive device group is performed based on the first response and the subscription data.

[0196] Optionally, the transceiver 502 is further configured to:

[0197] receiving a second request sent by the server, where the second request is associated with the pending service, and the second request carries at least service information of the pending service;

[0198] The processor 505 is further configured to:

[0199] Acquiring the contract data based on the service information, or reading the pre-stored contract data based on the service information;

[0200] The target object is determined based on the device information and the service information.

[0201] Optionally, the service information includes at least one of the following: identification information of the service to be processed, identification information and location information of the target passive device or the target passive device group for executing the service to be processed;

[0202] The identification information of the service to be processed includes at least one of type information and identifier information of the service to be processed.

[0203] Optionally, when the device information includes identification information of the target passive device, the processor 505 is further configured to:

[0204] In a case where the service information does not include the identification information of the target passive device, configuring a correspondence between the service identification of the to-be-processed service and the identification information of the target passive device that executes the to-be-processed service;

[0205] Based on the corresponding relationship, the subscription data associated with the target passive device corresponding to the identification information stored in the UDM is obtained.

[0206] Optionally, the first request carries the service information or the device information;

[0207] The first request is further used to request the target object to send a third request to the target passive device or the target passive device group, and the third request is used to instruct the target passive device or the target passive device group to access a network.

[0208] Optionally, the transceiver 502 is configured to:

[0209] When the time limit for receiving the first response is less than or equal to the first preset receiving time limit, a first response corresponding to the first request and sent by the target object is received.

[0210] The processor 505 is configured to:

[0211] In a case where the time limit for receiving the first response is greater than a second preset receiving time limit, instructing the target object to end paging the target passive device;

[0212] Accessing the target passive device or the target passive device group is performed based on the first response.

[0213] Optionally, the transceiver 502 is configured to:

[0214] If the time for the target object to receive the first response is less than or equal to a third preset receiving time limit, receiving a first response corresponding to the first request sent by the target object;

[0215] The processor 505 is configured to:

[0216] In a case where the time for the target object to receive the first response is greater than the third preset receiving time limit, instructing the target object to end paging the target passive device;

[0217] performing access of the target passive device or the target passive device group based on a first response, wherein the first response corresponds to the first request;

[0218] Among them, the third preset receiving time limit is obtained by the target object based on the first request.

[0219] Optionally, the device information includes at least one of the following:

[0220] The identification information of the target passive device, the identification information of the executed service, the type of service allowed to be executed, the type of service prohibited to be executed, the location information of the service allowed to be executed, the location information of the service prohibited to be executed, the time period when the service is allowed to be executed, the time period when the service is prohibited to be executed, the preset PLMN, and the application function AF allowed to access the target passive device.

[0221] Optionally, the first response carries at least one of the following:

[0222] The identification information of the target passive device, the current usage time, the current location, the cell identifier NGCI, the associated base station identifier gNB ID, and the accessed public land mobile network PLMN.

[0223] Optionally, the processor 505 is configured to perform at least one of the following:

[0224] If the current usage time of the target passive device exceeds the time period in which the service is allowed to be executed, determine to deny access to the target passive device;

[0225] If the PLMN corresponding to the target passive device does not correspond to the preset PLMN, determining to deny access to the target passive device;

[0226] In a case where the current location of the target passive device is within the location information where execution of services is prohibited, it is determined to deny access to the target passive device.

[0227] The network element device provided in the embodiment of the present disclosure can implement each process of the network access control method embodiment in Figures 1 and 2 above, and can achieve the same technical effect. To avoid repetition, it will not be described here.

[0228] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon. When executed by a processor, the computer program implements the various processes of the aforementioned network access control method embodiment and achieves the same technical effects. To avoid repetition, the details are omitted here. The computer-readable storage medium may be, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0229] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0230] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present disclosure.

[0231] The embodiments of the present disclosure are described above in conjunction with the accompanying drawings, but the present disclosure is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present disclosure, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present disclosure and the claims, all of which are protected by the present disclosure.

Claims

1. A network access control method, applied to a first network element, the method comprising: Sending a first request to a target object, the first request being used to request the target object to page a target passive device or a target passive device group, so that the target passive device or the target passive device group accesses the network, wherein the target object is at least one of a base station and a terminal managed by the first network element; Receiving a first response corresponding to the first request sent by the target object.

2. The method according to claim 1, further comprising any one of the following: Performing access of the target passive device or the target passive device group based on the first response; Perform access to the target passive device or the target passive device group based on the signed data, where The subscription data is stored in a unified data management UDM, and the subscription data includes device information associated with the target passive device for performing a to-be-processed service, and the to-be-processed service is a service sent by a server for the target passive device or the target passive device group to process; Performing access of the target passive device or the target passive device group based on the first response and the subscription data.

3. The method according to claim 2, wherein Before sending the first request to the target object, the method further comprises: Receiving a second request sent by a server, the second request being associated with the to-be-processed service, and at least carrying service information of the to-be-processed service; Obtaining the subscription data based on the service information, or reading the pre-stored subscription data based on the service information; Determining the target object based on the device information and the service information.

4. The method according to claim 3, wherein, The service information includes at least one of the following: identification information of the to-be-processed service, identification information of the target passive device or the target passive device group for performing the to-be-processed service, location information; Wherein, the identification information of the to-be-processed service includes at least one of type information and identifier information of the to-be-processed service.

5. The method according to claim 4, wherein, When the device information includes identification information of the target passive device, the obtaining the subscription data based on the service information includes: When the service information does not include identification information of the target passive device, configuring a correspondence relationship between a service identifier of the to-be-processed service and the identification information of the target passive device for performing the to-be-processed service; Obtaining the subscription data associated with the target passive device corresponding to the identification information stored in the UDM based on the correspondence relationship.

6. The method according to claim 3, wherein The first request carries the service information or the device information; Wherein, the first request is further used to request the target object to send a third request to the target passive device or the target passive device group, and the third request is used to instruct the target passive device or the target passive device group to access the network.

7. The method according to claim 2, wherein The performing access of the target passive device or the target passive device group based on the first response includes: When the time limit for receiving the first response is less than or equal to a first preset receiving time limit, receiving the first response corresponding to the first request sent by the target object; In the case where the time limit for receiving the first response is greater than the second preset reception time limit, instruct the target object to end the paging of the target passive device; Perform access to the target passive device or the target passive device group based on the first response.

8. The method according to claim 2, wherein The performing access to the target passive device or the target passive device group based on the first response includes: In the case where the time when the target object receives the first response is less than or equal to the third preset reception time limit, receive the first response sent by the target object corresponding to the first request; In the case where the time when the target object receives the first response is greater than the third preset reception time limit, instruct the target object to end the paging of the target passive device; Perform access to the target passive device or the target passive device group based on the first response, where the first response corresponds to the first request; Wherein, the third preset reception time limit is obtained by the target object based on the first request.

9. The method according to claim 3, wherein The device information includes at least one of the following: The identification information of the target passive device, the identification information of the service being executed, the type of service allowed to be executed, the type of service prohibited from being executed, the location information where the service is allowed to be executed, the location information where the service is prohibited from being executed, the time period when the service is allowed to be executed, the time period when the service is prohibited from being executed, the preset public land mobile network PLMN, the application function AF allowed to access the target passive device.

10. The method according to claim 9, wherein The first response carries at least one of the following: The identification information of the target passive device, the current time in use, the current location, the cell identification NGCI, the associated base station identifier gNB ID, the public land mobile network PLMN accessed.

11. The method according to claim 10, wherein, Determining whether to allow the target passive device to access according to the first response includes at least one of the following: In the case where the current time in use of the target passive device exceeds the time period when the service is allowed to be executed, determine to reject the access of the target passive device; In the case where the corresponding PLMN of the target passive device does not correspond to the preset PLMN, determine to reject the access of the target passive device; In the case where the current location of the target passive device is within the location information where the service is prohibited from being executed, determine to reject the access of the target passive device.

12. A network access control device, applied to a first network element, the device includes: A sending module, configured to send a first request to a target object, where the first request is used to request the target object to page a target passive device or a target passive device group, so that the target passive device or the target passive device group accesses the network, where the target object is at least one of a base station and a terminal managed by the first network element; Receive the first response sent by the target object corresponding to the first request.

13. A network access control device, applied to a first network element, comprising: A processor and a transceiver, The transceiver is used to send a first request to a target object, where the first request is used to request the target object to page a target passive device or a target passive device group, so that the target passive device or the target passive device group can access the network. Among them, the target object is at least one of the base stations and terminals managed by the first network element; Receive a first response corresponding to the first request sent by the target object.

14. A network element device, comprising: A processor, a memory, and a program stored on the memory and executable on the processor. When the program is executed by the processor, it implements the steps of the network access control method according to any one of claims 1 to 11.

15. A computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the network access control method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Network access control method and device, related equipment and readable storage medium

    CN118828998A

  • Paging method and communication apparatus

    WO2022170575A1

  • Controlling paging of a terminal device

    WO2023027614A1

  • Paging method and device

    WO2023071979A1