Access management method and network element
By using CAF or PCF to obtain the CAG list in 5G system, the problem that micro base station owners frequently change the UE authorization status and affect the network where UE access is visited is solved, and more efficient CAG list acquisition and management are achieved.
Patent Information
- Application Number
- PCT/CN2024/115236
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-07
- Filing Date
- 2024-08-28
- Publication Date
- 2025-08-14
AI Technical Summary
In 5G systems, micro base station owners frequently change the UE authorization status, affecting the problem of the UE access network.
The registration request initiated by the terminal is obtained through the base station, and the local closed access group authorization management function CAF or the policy control function PCF obtains the closed access group CAG list that is allowed to be accessed by the current public land mobile network PLMN for access management.
Local acquisition or dynamic acquisition of terminal authorization information is realized, and the UE authorization status is frequently changed in the micro base station scenario, which improves the efficiency and timeliness of the acquisition of CAG lists, and solves the problem that the micro base station owner frequently changes the UE authorization status and affects the network where the UE access is visited.
Smart Images

Figure CN2024115236_14082025_PF_FP_ABST
Abstract
Description
Access management method and network element
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This disclosure is based on Chinese patent application CN202410175169.4 filed on February 7, 2024, entitled “An access management method and a network element”, and claims the priority of the patent application, and all the disclosed contents are incorporated into this disclosure by reference. Technical Field
[0003] The present disclosure relates to the field of communications, and in particular to an access management method and a network element. Background Art
[0004] In 3G / 4G systems, home base stations, also known as micro or small base stations, were introduced to enhance coverage or provide specialized services to homes and small businesses. However, the coverage range of base stations in 5G systems is slightly smaller than that of 3G and 4G base stations, so micro (or small) base stations were not supported when 5G was first introduced. With the continuous development of 5G networks and the increasing number of 5G applications, the 3rd Generation Partnership Project (3GPP) introduced the concept of Premises Radio Access Stations (PRAS), also known as micro base stations, in the Personal IoT Networks (PIN) and Customer Premises Networks (CPN) projects during Release 19. Micro base stations use higher frequencies, improving 5G indoor coverage and offloading some traffic that was previously routed to macro base stations. Therefore, micro base stations can provide better voice call quality and better support mobility within enterprises, thereby improving the user experience for average customers and increasing the willingness of industry customers to use 5G networks. Related technologies draw on the management of micro base stations in 4G and the management of non-public network base stations by the Closed Access Group (CAG) in the non-public network (NPN) in 5G to design the 5G micro base station access architecture.
[0005] Micro base stations support user premises networks (CPNs) and can offload some traffic routed to macro base stations. However, this traffic offloading requires authorization from the micro base station owner. Since a micro base station may belong to a home or enterprise user, authorization can change relatively frequently. The CAG data acquisition method used in related technologies is not suitable for scenarios where CAG authorization frequently changes, potentially hindering UE access to the visited network.
[0006] In summary, there is no good solution to the problem in related technologies that the micro base station owner frequently changes the UE authorization status, thereby affecting the UE's access to the visited network.
[0007] Summary of the Invention
[0008] The embodiments of the present disclosure provide an access management method and a network element to at least solve the problem in related technologies that a micro base station owner frequently changes the UE authorization status, thereby affecting the UE's access to a visited network.
[0009] According to one embodiment of the present disclosure, an access management method is provided, the method comprising: obtaining, through a base station, a registration request initiated by a terminal, wherein the registration request carries a terminal identifier; obtaining, through a local closed access group authorization function CAF or policy control function PCF, a list of closed access groups (CAGs) to which access is permitted in the current public land mobile network (PLMN); and performing access management on the terminal according to the CAG list.
[0010] According to another embodiment of the present disclosure, a network element is provided for performing access management according to the steps in any of the above method embodiments.
[0011] According to another embodiment of the present disclosure, a computer-readable storage medium is provided, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above method embodiments are executed.
[0012] According to another embodiment of the present disclosure, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0013] According to another embodiment of the present disclosure, a computer program product is provided, including a computer program, which performs the steps of any of the above method embodiments when executed by a processor.
[0014] Through the embodiments of the present disclosure, local or dynamic acquisition of terminal authorization information (CAG list) can be achieved. Compared with the technical solution of obtaining authorization information from the UDM network element of the terminal's home location in the related technology, it can be better applied to micro base station scenarios, thereby solving the problem in the related technology that the micro base station owner frequently changes the UE authorization status, thereby affecting the UE's access to the visited network. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] FIG1 is a structural diagram of a 5G system according to an embodiment of the present disclosure;
[0016] FIG2 is a flow chart of an access management method according to an embodiment of the present disclosure;
[0017] FIG3 is a schematic diagram of managing CAG authorization information of a visited location through CAF in one embodiment of the present disclosure;
[0018] FIG4 is a schematic diagram of CAG authorization information update in one embodiment of the present disclosure;
[0019] FIG5 is a schematic diagram of updating CAG information through AF in one embodiment of the present disclosure;
[0020] FIG6 is a schematic diagram of an access process for obtaining authorization information through a PCF in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0021] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.
[0022] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0023] The method embodiments provided in the embodiments of the present disclosure may be applied to a 5G system. FIG1 is a structural diagram of a 5G system according to an embodiment of the present disclosure. As shown in FIG1 , the 5G system includes the following functional entities:
[0024] A terminal (User Equipment, UE for short) can access the operator's network or the customer premises network through a wireless base station.
[0025] Radio Access Network (RAN): A base station in a radio access network can be a macro base station or a micro base station.
[0026] The Access and Mobility Management Function (AMF) manages UE mobility, reachability, connection, and registration. The AMF terminates the N2 interface to the RAN and the N1 NAS interface to the UE. The AMF transparently passes messages related to session management on the N1 and N2 interfaces to the SMF.
[0027] Session Management Function (SMF) manages sessions established by users, including the establishment, modification, and deletion of sessions, as well as the establishment of the user plane on the network side.
[0028] Unified Data Management (UDM), this network function manages the UE's subscription data, application data, etc., which can be stored in a unified data repository (UDR). In the network, UDM and UDR can usually be combined. The subscription data includes access and mobility management subscription data and session management subscription data. AMF and SMF can obtain these subscription data from UDM respectively.
[0029] The Policy Control Function (PCF) can be divided into UE-PCF, AM-PCF and SM-PCF according to different policies. AMF and SMF interact with these PCFs to obtain UE policies, access management policies and session management policies respectively.
[0030] User Plane Function (UPF): The SMF formulates data detection, forwarding, and monitoring rules based on session management contracts, session management policies, and other related information and sends them to the UPF. As a user plane data transmission node, the UPF executes the relevant rules formulated by the SMF. Before sending the UE's session management rules to the UPF, the SMF must first establish a node-level association connection with the UPF to exchange information such as the ports and addresses available to the UPF. Node-level association establishment can be initiated by either the SMF or the UPF.
[0031] The Network Repository Function (NRF) serves as a functional network element for storing and querying NF profiles. It can store the configuration files of other network functions (NFs) in the network. When another NF needs to use a specific NF but doesn't know its information, it can query the NRF by entering key parameters.
[0032] In the disclosed embodiments, since the micro base station supports the user premises network, it can offload some of the traffic routed to the macro base station. However, this traffic offloading requires authorization from the micro base station owner. Since the micro base station may belong to a home user or an enterprise user, this authorization change may be relatively frequent. Therefore, in the disclosed embodiments, an access management method is designed to provide micro base station users with a localized and more flexible authorization method, thereby resolving the problem in related technologies where the micro base station owner frequently changes the UE authorization status, thereby affecting the UE's access to the visited network.
[0033] In one embodiment of the present disclosure, an access management method is provided, which can be applied to an AMF network element. FIG2 is a flow chart of the access management method according to an embodiment of the present disclosure. As shown in FIG2 , the process includes the following steps:
[0034] Step S202: obtaining a registration request initiated by the terminal through the base station, wherein the registration request carries a terminal identifier;
[0035] Step S204: Obtain a list of closed access groups (CAGs) that are allowed to be accessed by the current public land mobile network (PLMN) through the local closed access group authorization function (CAF) or policy control function (PCF);
[0036] Step S206: Perform access management on the terminal according to the CAG list.
[0037] The base station in the embodiments of the present disclosure may be a micro base station, but the present disclosure is not limited thereto. Through the above steps S202 to S206, local or dynamic acquisition of the CAG list can be achieved. Compared with other CAG list acquisition methods, this method is more suitable for micro base station scenarios to address the problem of frequent changes in UE authorization status.
[0038] In some embodiments, after step S202, the method further includes: step S203, obtaining the access management contract data of the terminal from a unified data management function UDM, wherein the access management contract data carries an indication of supporting a local acquisition function or an indication of supporting a dynamic acquisition function, the local acquisition function is to obtain the CAG list through the CAF, and the dynamic acquisition function is to obtain the CAG list through the PCF.
[0039] In some embodiments, the AMF network element or CAF network element may also notify the UDM whether it supports the local acquisition function, or the AMF network element or PCF network element may also notify the UDM whether it supports the dynamic acquisition function. Further, the UDM network element may negotiate with the AMF, PCF, or CAF through the supported features in the message.
[0040] In this embodiment, a CAG authorization management function (CAF) network element is designed to manage CAG information of the visited location.
[0041] In this embodiment, step S204 includes two methods for obtaining UE authorization information (i.e., CAG list). Acquiring the CAG list of the current public land mobile network PLMN that is allowed to access through the local closed access group authorization function CAF, i.e., local acquisition of the CAG list, may include the following steps:
[0042] Step S2041: Send a CAG authorization information request carrying the terminal identifier to the CAF;
[0043] Step S2042: Receive a CAG authorization information response returned by the CAF, wherein the CAG authorization information response includes the CAG list.
[0044] In some embodiments, the CAG authorization information request also carries at least one of the following information: an identifier of the access and mobility management function AMF, PLMN information of the AMF, PLMN information currently selected by the terminal, location information currently accessed by the terminal, and registration area information of the terminal.
[0045] Furthermore, CAF can include the current PLMN allowed CAG list in the response message based on the terminal's identifier. If CAF supports multiple PLMN scenarios, CAF can also return the allowed CAG list under the current PLMN based on the AMF's PLMN information or the PLMN information selected by the UE. In order to reduce the size of the CAG list sent, CAF can also include only the allowed CAG list information that is valid in the current area in the response message based on the UE's location information, the UE's registration area information, and the AMF's identifier. Optionally, for each allowed CAG information, a valid time can also be set to indicate that the terminal is allowed to access the CAG within a specific time period.
[0046] In some embodiments, after step S2042, the method further includes: step S2043, subscribing to the CAF for CAG list change notifications of the terminal.
[0047] In some embodiments, after step S2043, the method further includes: when the CAG list corresponding to the terminal changes, receiving the CAG list change notification from the CAF, and determining an updated CAG list based on the CAG list change notification; and sending the updated CAG list to the terminal.
[0048] Furthermore, sending the updated CAG list to the terminal can be divided into the following two cases:
[0049] When the CAG list corresponding to the terminal changes and the terminal is performing registration, sending the updated CAG list to the terminal through a registration accept message;
[0050] When the CAG list corresponding to the terminal changes and the terminal has completed registration, the updated CAG list is sent to the terminal through a terminal configuration update request.
[0051] In some embodiments, after step S2042, the method further includes: determining whether the terminal is allowed to access the current PLMN based on the updated CAG list; if the judgment result is yes and the base station has established a user context, notifying the base station to update the CAG list; if the judgment result is no, notifying the terminal to release the connection with the network, and there is no need to notify the base station at this time.
[0052] In this embodiment, step S204 includes two methods for obtaining UE authorization information (i.e., CAG list). Acquiring the CAG list of the closed access group allowed to access the current public land mobile network PLMN through the policy control function PCF, i.e., dynamic acquisition of the CAG list, may include the following steps:
[0053] Step S2046: Send a policy control creation message carrying the terminal identifier to the PCF, wherein the PCF is configured to subscribe to application data of the terminal from a unified data store (UDR) according to the terminal identifier, wherein the application data includes at least the CAG list and the terminal identifier;
[0054] Step S2047: Receive a policy control creation response carrying the application data returned by the PCF, and determine the CAG list of the terminal from the application data.
[0055] In some embodiments, before obtaining the CAG list from the UDR, the method further includes: storing the application data in the UDR through an application function AF and a network exposure function (NEF).
[0056] In this embodiment, the AF is used to create, update or delete application data in the UDR through the NEF.
[0057] Furthermore, the AF sends a create / update / delete message of application data (including UE identity and CAG information) to the NEF, and the NEF then sends this message to the UDR.
[0058] In this embodiment, the externally authorized AF will be able to use the terminal information of CAG and send it to the 3GPP core network. Among them, the UE ID can be an external ID visible to the application. NEF can appropriately map the UE external ID in the information sent by AF, and then send the information of the terminal allowed to use CAG to UDM. If UDM and UDR are jointly established network elements, UDM saves these application layer information. If UDM and UDR are separately established, UDM sends a query request to UDR so that UDM can verify whether the above information can be saved in UDR. If so, UDM needs to map the terminal identifier in the above information to the corresponding SUPI, and send an update request to UDR to send the above received information to UDR for storage.
[0059] Usually, CAG information is not included in application data. The present disclosure dynamically creates, updates, and deletes CAG information in the form of application data, which can improve the update speed of CAG information and ensure that UE can obtain the latest CAG information in a timely manner.
[0060] In some embodiments, the method further includes: when the application data corresponding to the terminal changes and the terminal has completed registration, the PCF obtains the updated application data of the UDR.
[0061] Furthermore, the UDR can proactively report updated application data to the PCF, which then sends the updated application data to the AMF via a policy control create response. Alternatively, the PCF can proactively obtain updated application data from the UDR. The application data here primarily consists of CAG information.
[0062] In some embodiments, the method also includes: AMF subscribes to the CAG list to the PCF through the policy control creation message or subscription message, wherein the policy control creation message also carries a CAG list subscription indication, and the CAG list subscription indication or the subscription message is used to instruct the PCF to send all or specified CAG lists to the access and mobility management function AMF when the CAG list changes.
[0063] In some embodiments, step S206 performs access management on the terminal according to the CAG list, which may include the following steps:
[0064] Step S2061: determining whether the terminal is allowed to access the current PLMN according to the CAG list;
[0065] Step S2062: If the judgment result is yes, a registration acceptance message is returned to the terminal through the base station;
[0066] Step S2063: If the judgment result is no, a registration rejection message is sent to the terminal.
[0067] Through the embodiments of the present disclosure, dynamic or local acquisition of terminal authorization information (CAG list) can be achieved. Compared with the technical solution of obtaining authorization information from the UDM network element of the terminal's home location in the related technology, it can be better applied to micro base station scenarios, thereby solving the problem in the related technology that the micro base station owner frequently changes the UE authorization status, thereby affecting the UE's access to the visited network.
[0068] The access management method in the above embodiment will be described below based on the interaction between various network elements in the 5G system.
[0069] In one embodiment of the present disclosure, a technical solution is provided for a UE to obtain a CAG list from a local (visited) location. The UE can obtain the CAG list directly from the visited location, thereby reducing information exchange with the home location UDM and improving CAG list acquisition efficiency. This solution also accommodates situations where micro base station owners frequently change UE authorization status, and the CAG list obtained locally is more timely.
[0070] FIG3 is a schematic diagram of managing CAG authorization information of a visited location through CAF in one embodiment of the present disclosure. As shown in FIG3 , the process includes the following steps:
[0071] Step S301: The UE initiates a registration request from the current cell, and the micro eNodeB forwards the registration request to the AMF.
[0072] Step S302: AMF obtains access management subscription data from UDM (Nudm_SubscriberDataManagement_Get);
[0073] Step S303: AMF determines whether the local acquisition function is supported.
[0074] Step S304: AMF obtains CAG authorization information from CAF (Ncaf_CAGAuthrization_Get);
[0075] Step S305: AMF subscribes to CAF for CAG authorization information changes (Ncaf_CAGAuthrization_subscribe);
[0076] Step S306: The AMF performs access check on the UE based on the CAG authorization information.
[0077] Step S307: The AMF returns an initial context setup message, i.e., a registration acceptance message, to the micro base station.
[0078] Step S308: The micro base station returns a registration accept message (Registration Accept) to the UE;
[0079] In step S309, the UE replies a registration complete message (Registration Complete) to the micro base station.
[0080] The Next Generation Radio Access Network (NG-RAN) in Figure 3 is the basic network architecture of the 5G network, which can be a micro base station, but the present disclosure is not limited to this.
[0081] In this embodiment, a CAG authorization function (CAF) network element is designed to manage CAG information of a visited location.
[0082] In this embodiment, before step S301, the terminal monitors the CAG information of the current cell through broadcast. If the UE does not save the CAG list of the current public land mobile network (PLMN) allowed to be accessed, or the CAG identifier broadcast by the current cell is included in the CAG list locally stored in the UE, the UE initiates the access process and starts executing step S301.
[0083] In this embodiment, when the micro base station forwards the registration request to the AMF in step S301, the message sent by the micro base station to the AMF may also include all CAG identifiers supported by the current cell.
[0084] In this embodiment, step S302 may include: the AMF sends a request to the UDM to obtain the access management subscription data of the terminal, and receives the access management subscription data returned by the UDM, wherein the access management subscription data includes an indication of whether the AMF is allowed to obtain the CAG list of the visited location from the local CAF (ie, whether the local acquisition function is supported).
[0085] In other embodiments, if the access management subscription data indicates that the local acquisition function is not supported, the AMF may directly obtain the allowed CAG list of the current PLMN from the UDM, and subsequently perform the CAG processing in the existing registration process, skipping steps S303 to S305, and directly proceeding to step S306 to perform access check based on the authorization information. If the access management subscription data indicates that the local acquisition function is supported, the access management subscription data obtained by the AMF from the UDM does not include the CAG list of the current PLMN, but only includes the above indication.
[0086] In some embodiments, the AMF network element or the CAF network element may also notify the UDM whether it supports the dynamic acquisition function. Further, the UDM network element may negotiate with the AMF or CAF through the supported features in the message.
[0087] In this embodiment, step S304 may include: the AMF queries the address of the CAF from the network storage function (Network Repository Function, referred to as NRF), or directly configures the address of the CAF locally; the AMF sends a CAG authorization information request carrying the UE identifier to the CAF, and the CAF determines the corresponding CAG list according to the terminal identifier, and returns a CAG authorization information response carrying the current PLMN allowed CAG list to the AMF.
[0088] In an exemplary embodiment, in addition to the UE identifier, the CAG authorization information request may also include any one or more of the following information: AMF identifier, AMF PLMN information (if the AMF supports multiple PLMNs, all may be included), UE currently selected PLMN information, UE currently accessed location information, and UE registration area information.
[0089] Furthermore, if CAF supports multiple PLMN scenarios, CAF can return the allowed CAG list under the current PLMN based on the PLMN information of AMF or the PLMN information currently selected by UE.
[0090] Furthermore, in order to reduce the size of the CAG list sent, CAF can also filter out the allowed CAG list information valid in the current area based on the UE location information, the UE registration area information, and the AMF identifier. At this time, the CAG authorization information response only contains the allowed CAG list information valid in the current area.
[0091] In an exemplary embodiment, for each allowed CAG information, a valid time may be set to indicate that the terminal is allowed to access the CAG within a specific time period.
[0092] In this embodiment, step S305 may include: the AMF sending a subscription request for CAG authorization information to the CAF, so that when the CAG list corresponding to the UE changes, the CAF notifies the AMF of the updated CAG list. By signing the authorization information, it is possible to adapt to the scenario where the owner of the micro base station may frequently change the authorization status of a specific UE, avoiding frequent acquisition of authorization information from the UDM.
[0093] In this embodiment, step S306 may include the AMF performing authorization verification on whether to allow the UE to access based on the allowed CAG list obtained from the CAF. If the authorization verification result is that the UE is allowed to access, step S307 is executed.
[0094] In this embodiment, steps S307 to S308 may include: when the AMF determines that the UE is allowed to access, the AMF returns a registration accept message to the terminal. The registration accept message includes a list of allowed CAGs for the current PLMN or current registration area. The registration accept message needs to be forwarded to the terminal via the micro base station. Furthermore, the AMF also includes the list of allowed CAGs for the current PLMN in the N2 message sent to the micro base station. The terminal saves the list of allowed CAGs for the current PLMN received from the AMF.
[0095] In other embodiments, if the authorization verification result in step S306 is that the UE is not allowed to access, the AMF returns a registration reject message to the terminal, indicating that the terminal is not allowed to access from the current cell due to CAG restrictions. Furthermore, the registration reject message may also include a list of allowed CAGs for the current PLMN or current registration area. The terminal updates and saves the allowed CAG list of the current PLMN received from the AMF.
[0096] In this embodiment, step S309 includes: after the UE updates the allowed CAG list, if the UE is allowed to access the CAG list, the UE replies with a registration completion message to the micro base station.
[0097] In this embodiment, the UDM is typically located at the UE's home location, while other network elements such as the AMF, base station, and CAF are located at the UE's visited location. For UEs accessing from a non-home location, local retrieval of the CAG list is implemented, avoiding the issue of remotely obtaining the CAG list from the home location UDM and the inability to respond to information acquisition and updates in a timely manner. This allows for more efficient and timely retrieval of the CAG list, especially when micro base stations may frequently change the UE's authorization status.
[0098] FIG4 is a schematic diagram of updating CAG authorization information in an embodiment of the present disclosure. As shown in FIG4 , the process includes the following steps:
[0099] Step S401: CAF notifies AMF that CAG authorization information has changed.
[0100] Step S402: The AMF sends a UE configuration update request to the UE.
[0101] Step S403: The UE returns a UE configuration update response to the AMF.
[0102] In this embodiment, before step S401, the AMF needs to first sign a CAG authorization information change contract with the CAF in step S305. After signing the contract, if the CAG authorization information changes, the CAF will proactively send a CAG authorization information change notification to the AMF.
[0103] In this embodiment, the CAG authorization information may be a CAG list that the terminal is allowed to access, and the UE configuration update request in step S402 carries the updated CAG list.
[0104] In this embodiment, if the UE is in the registration process, such as any process between steps S301 to S308 above, the AMF can directly execute step S307 above and send the updated CAG list to the UE through the registration accept message. If the UE is not in the registration process, the updated CAG list can be sent to the UE through steps S402 and S403.
[0105] In some embodiments, after step S403, if the micro eNB has established a user context, the micro eNB needs to be notified of the updated CAG list. If the UE is not allowed to access the current cell according to the updated CAG list, the AMF needs to release the Network Attached Storage (NAS) connection after notifying the UE. In this case, the micro eNB does not need to be notified.
[0106] In one embodiment of the present disclosure, a technical solution is provided for a UE to dynamically obtain a CAG list from a UDR. While related technologies obtain CAG authorization information by acquiring access management subscription data, this solution addresses the situation where micro base station owners frequently change UE authorization status. By acquiring CAG information by acquiring application data, this solution ensures CAG information updates and reduces access pressure on UDM network elements.
[0107] FIG5 is a schematic diagram of updating CAG information through AF in one embodiment of the present disclosure. As shown in FIG5 , the process includes the following steps:
[0108] Step S501: The AF sends a create / update / delete message of application data (including UE identity and CAG information) to the NEF.
[0109] Step S502: NEF sends a create / update / delete message of application data to UDM.
[0110] Step S503: UDM / UDR saves CAG information.
[0111] In this embodiment, step S501 may include: an externally authorized application function (AF) sending terminal information and a UE identifier that can use CAG to a 3GPP core network, such as a network exposure function (NEF) element. The UE identifier may be an external identifier visible to the application.
[0112] In this embodiment, step S502 may include: after the NEF properly maps the UE external ID in the information sent by the AF, it sends the information of the terminal allowed to use the CAG to the UDM.
[0113] In this embodiment, if the UDM and UDR are co-located network elements, the UDM stores the application data. If the UDM and UDR are separate network elements, step S503 may further include: the UDM sending a query request to the UDR to verify whether the above information can be stored in the UDR; if so, the UDM maps the UE identifier in the above information to the corresponding Subscription Permanent Identifier (SUPI), and sends an update request to the UDR to send the received information to the UDR for storage.
[0114] In some embodiments, if the users allowed to access from a specific CAG by the AF change, the updated CAG information may be updated to the UDM / UDR by means of this fact (ie, steps S501 to S503).
[0115] Through the embodiments of the present disclosure, the CAG information stored in the UDR can be dynamically updated, ensuring the timeliness of the CAG information update in the scenario where the micro base station owner frequently changes the UE authorization status.
[0116] FIG6 is a schematic diagram of an access process for obtaining authorization information through a PCF in an embodiment of the present disclosure. As shown in FIG6 , the process includes the following steps:
[0117] Step S601: The UE initiates a registration request from the current cell, and the micro eNodeB forwards the registration request to the AMF.
[0118] Step S602: AMF obtains access management subscription data from UDM (Nudm_SubscriberDataManagement_Get);
[0119] Step S603: AMF determines whether the dynamic acquisition function is supported;
[0120] Step S604: AMF sends a policy control creation message (Npcf_AMPolicyControl_Create) to PCF.
[0121] Step S605: PCF sends an application data subscription message (Nudr_DM_Subcribe) to UDR;
[0122] Step S606: The UDR returns an application data notification message (Nudr_DM_Notify) to the PCF.
[0123] Step S607: The PCF sends a policy control creation response (Npcf_AMPolicyControl_Create response) to the AMF, which carries the authorization information.
[0124] Step S608: The AMF performs access check on the UE based on the CAG authorization information.
[0125] Step S609: The AMF returns an initial context setup message (i.e., a registration acceptance message) to the micro base station.
[0126] Step S610: The micro base station returns a registration accept message (Registration Accept) to the UE;
[0127] In step S611, the UE replies a registration complete message (Registration Complete) to the micro base station.
[0128] The Next Generation Radio Access Network (NG-RAN) in Figure 6 is the basic network architecture of the 5G network, which can be a micro base station, but the present disclosure is not limited to this.
[0129] This embodiment, based on the above-described embodiment, implements dynamic storage of CAG information as application data through the AF. For scenarios where authorization information frequently changes, CAG information stored in the UDR can be created / updated / deleted in real time. If the UE is not online when the CAG information is created / updated / deleted, the method of steps S601 to S611 of this embodiment can be executed when the UE comes online. During the terminal access network process, the PCF can be used to directly obtain CAG information from the UDR, thereby avoiding frequent access to the UDM network element.
[0130] In another embodiment, if the UE is online and the policy control has been created, steps S606 to S611 can be directly executed, and the UDR returns the CAG authorization information in the application data to the PCF, or the PCF obtains the CAG authorization information from the UDR.
[0131] In this embodiment, before step S601, the terminal monitors the CAG information of the current cell through broadcast. If the UE does not save the CAG list of the current PLMN allowed to access, or the CAG identifier broadcast by the current cell is included in the CAG list stored locally by the UE, the UE initiates a registration request from the current cell. In step S601, the message sent by the micro eNB to the AMF also includes all CAG identifiers supported by the current cell.
[0132] In this embodiment, through steps S602 to S603, the AMF can obtain the access management subscription data of the terminal from the UDM, which includes an indication of whether the AMF is allowed to dynamically obtain the allowed CAG list, that is, whether the dynamic acquisition function is supported. If the subscription data does not allow it, the AMF will obtain the allowed CAG list of the current PLMN from the UDM and subsequently perform the CAG processing in the existing registration process, skipping the other steps of the present invention. Otherwise, the subscription data obtained by the AMF from the UDM may include the CAG list of the current PLMN, or only include the above-mentioned indication.
[0133] In some embodiments, the AMF network element or PCF network element may also notify the UDM whether it supports the dynamic acquisition function. Further, the UDM network element may negotiate with the AMF and PCF through the supported features in the message.
[0134] In other embodiments, regardless of whether the AMF supports dynamic acquisition, the terminal's CAG list can be included in the access management subscription data. When performing access checks based on the authorization information, the authorization information obtained from the UDM can be compared with the authorization information obtained from the UDR via the PCF, or the intersection of the two can be used for authorization verification. Furthermore, the authorization information obtained via the PCF has better real-time performance and higher priority.
[0135] In some embodiments, step S604 may include: subscribing to the CAG list from the PCF via a policy control create message carrying a CAG list subscription indication, or subscribing to the CAG list from the PCF via a subscription message. The CAG list subscription indication or the subscription message is used to instruct the PCF to send all or a specified CAG list to the access and mobility management function (AMF) when the CAG list changes.
[0136] Furthermore, the policy control creation message or subscription message carries a terminal identifier, and the PCF subscribes to the application layer information of the terminal from the UDR according to the terminal identifier.
[0137] In some embodiments, steps S605 to S606 include: the PCF subscribes to the terminal's data information from the UDR. If the UDR already stores the UE's application layer data, the UDR sends the application side data to the PCF via a notification message, including the CAG information written by the AF.
[0138] In some embodiments, if the UDR does not store the UE's application data, an access check can be performed based on the CAG authorization information obtained from the access management subscription data. When the CAG authorization information obtained by the two methods exists at the same time, the CAG authorization information obtained from the PCF has a higher priority.
[0139] In some embodiments, step S607 may also include: the PCF generates a CAG list allowing the specified UE to access based on the information obtained from the UDR (the information here may be the entire CAG list or the CAG list of the specified terminal), and returns it to the AMF.
[0140] In this embodiment, step S608 may include: if the AMF obtains the allowed CAG list of the current PLMN from the PCF, determining whether the UE is allowed to access according to the allowed CAG list obtained from the PCF, or performing authorization verification on whether the UE is allowed to access according to the intersection of the CAG list obtained in step S602 and the CAG list obtained in step S607. If the authorization verification result is that the UE is allowed to access, step S307 is executed to determine whether the UE is allowed to access.
[0141] Furthermore, it may be decided in subsequent steps S609 to S611 to send the CAG list or the intersection of the CAG lists obtained from the PCF to the terminal and the micro base station.
[0142] In this embodiment, steps S609 to S610 may include: when the AMF determines that the UE is allowed to access, the AMF returns a registration accept message to the terminal. The registration accept message includes a list of allowed CAGs for the current PLMN or current registration area. The registration accept message needs to be forwarded to the terminal via the micro base station. Furthermore, the AMF also includes the list of allowed CAGs for the current PLMN in the N2 message sent to the micro base station. The terminal saves the list of allowed CAGs for the current PLMN received from the AMF.
[0143] In other embodiments, if the authorization verification result in step S608 is that the UE is not allowed to access, the AMF returns a registration reject message to the terminal, indicating that the terminal is not allowed to access from the current cell due to CAG restrictions. Furthermore, the registration reject message may also include a list of allowed CAGs for the current PLMN or current registration area. The terminal updates and saves the allowed CAG list of the current PLMN received from the AMF.
[0144] In this embodiment, step S611 includes: after the UE updates the allowed CAG list, if the UE is allowed to access the CAG list, the UE replies with a registration completion message to the micro base station.
[0145] In other embodiments, if the UDR data is updated from the AF, the PCF may directly initiate a UE policy association update to the AMF (ie, step S607) to update the CAG list previously obtained by the AMF.
[0146] Furthermore, the AMF can update the CAG lists of the UE and the micro base station through the registration process or the configuration update process. Specifically, it can be divided into the following two situations: when the terminal is performing registration, the updated CAG list is sent to the terminal through the registration acceptance message (that is, executing the above steps S609 to S611); when the CAG list corresponding to the terminal changes and the terminal has completed registration, the updated CAG list is sent to the terminal through the terminal configuration update request (refer to the above steps 401 to S403).
[0147] The embodiments of the present disclosure further provide a network element for performing access management according to the steps in any of the above method embodiments. The network element may be an access and mobility management function (AMF) network element.
[0148] An embodiment of the present disclosure further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above method embodiments are executed.
[0149] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.
[0150] An embodiment of the present disclosure further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.
[0151] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0152] An embodiment of the present disclosure further provides a computer program product, including a computer program, wherein the computer program executes the steps of any of the above method embodiments when executed by a processor.
[0153] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail here.
[0154] Obviously, those skilled in the art should understand that the modules or steps of the present disclosure described above can be implemented using a general-purpose computing device, they can be concentrated on a single computing device, or distributed across a network composed of multiple computing devices, they can be implemented using program code executable by the computing device, and thus, they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be performed in a different order than herein, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present disclosure is not limited to any particular combination of hardware and software.
[0155] The foregoing is merely an exemplary embodiment of the present disclosure and is not intended to limit the present disclosure. Those skilled in the art will readily appreciate that the present disclosure is susceptible to various modifications and variations. Any modifications, equivalent substitutions, improvements, and the like made within the principles of the present disclosure shall be included within the scope of protection of the present disclosure.
Claims
1. An access management method, the method comprising: Obtaining, through a base station, a registration request initiated by a terminal, wherein the registration request carries a terminal identifier; Obtain the CAG list of the current public land mobile network PLMN that is allowed to access through the local closed access group authorization function CAF or policy control function PCF; Access management is performed on the terminal according to the CAG list.
2. The method according to claim 1, wherein The method further comprises: The access management contract data of the terminal is obtained from the unified data management function UDM, wherein the access management contract data carries an indication of supporting a local acquisition function or an indication of supporting a dynamic acquisition function, the local acquisition function is to obtain the CAG list through the CAF, and the dynamic acquisition function is to obtain the CAG list through the PCF.
3. The method according to claim 1, wherein The local closed access group authorization function (CAF) obtains the list of closed access groups (CAGs) allowed to access the current public land mobile network (PLMN), including: Sending a CAG authorization information request carrying the terminal identifier to the CAF; Receive a CAG authorization information response returned by the CAF, where the CAG authorization information response includes the CAG list.
4. The method according to claim 3, wherein: The CAG authorization information request also carries at least one of the following information: The identifier of the access and mobility management function AMF, the PLMN information of the AMF, the PLMN information currently selected by the terminal, the location information currently accessed by the terminal, and the registration area information of the terminal.
5. The method according to claim 3, wherein The method further comprises: Subscribe to the CAF for CAG list change notifications of the terminal.
6. The method according to claim 5, wherein: The method further comprises: When the CAG list corresponding to the terminal changes, receiving the CAG list change notification from the CAF, and determining an updated CAG list according to the CAG list change notification; Send the updated CAG list to the terminal.
7. The method according to claim 6, wherein: Sending the updated CAG list to the terminal includes: When the CAG list corresponding to the terminal changes and the terminal is performing registration, sending the updated CAG list to the terminal through a registration accept message; When the CAG list corresponding to the terminal changes and the terminal has completed registration, the updated CAG list is sent to the terminal through a terminal configuration update request.
8. The method according to claim 7, wherein: The method further comprises: Determining whether the terminal is allowed to access the current PLMN according to the updated CAG list; If the judgment result is yes and the base station has established a user context, notifying the base station to update the CAG list; If the judgment result is no, the terminal is notified to release the connection with the network.
9. The method according to claim 1, wherein Obtain the CAG list of the current public land mobile network (PLMN) that is allowed to access through the policy control function (PCF), including: Sending a policy control creation message carrying the terminal identifier to the PCF, wherein the PCF is configured to subscribe application data of the terminal to a unified data store (UDR) according to the terminal identifier, wherein the application data includes at least the CAG list and the terminal identifier; Receive a policy control creation response carrying the application data returned by the PCF, and determine the CAG list of the terminal from the application data.
10. The method according to claim 9, wherein: The method further comprises: The application data is stored in the UDR through the application function AF and the network exposure function NEF.
11. The method according to claim 10, wherein: The AF is used to create, update or delete application data in the UDR through the NEF.
12. The method according to claim 9, wherein The method further comprises: When the application data corresponding to the terminal changes and the terminal has completed registration, the PCF obtains the updated application data of the UDR.
13. The method according to claim 9, wherein: The method further comprises: The CAG list is subscribed to the PCF through the policy control creation message or the subscription message, wherein the policy control creation message also carries a CAG list subscription indication, and the CAG list subscription indication or the subscription message is used to instruct the PCF to send all or specified CAG lists to the access and mobility management function AMF when the CAG list changes.
14. The method according to claim 1, wherein Performing access management on the terminal according to the CAG list includes: Determining whether the terminal is allowed to access the current PLMN according to the CAG list; If the judgment result is yes, returning a registration acceptance message to the terminal through the base station; If the judgment result is no, a registration rejection message is sent to the terminal.
15. A network element, configured to perform access management according to the method according to any one of claims 1 to 14.
16. A computer-readable storage medium, wherein: The storage medium stores a computer program, wherein the computer program is executed by a processor to execute the method according to any one of claims 1 to 14.
17. An electronic device comprising a memory and a processor, wherein: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 14.
18. A computer program product comprising a computer program, wherein When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 14 are implemented.
Citation Information
Patent Citations
Information configuration method and device
CN111918271A
Data processing method and device, network equipment and terminal
CN113709729A
Method for access and mobility policy decision
WO2023077391A1