Control method, device, and system

By generating device identification for terminal devices and using network configuration files to verify operations, the problem of low management efficiency of devices without USIM is solved, and efficient device management in networks and roaming networks is achieved.

WO2025209147A1PCT designated stage Publication Date: 2025-10-09HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/082434
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-03
Filing Date
2025-03-13
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

In the existing technology, it is impossible to effectively manage terminal devices without USIM, resulting in low device management efficiency.

Method used

By generating a device ID for each device and managing the devices in the network based on the device ID, and using the network configuration file to verify the legitimacy of the operation request and response messages, management efficiency is improved.

Benefits of technology

This enables efficient management of devices in networks and roaming networks, preventing erroneous operations on devices by devices or application units that do not have operating permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025082434_09102025_PF_FP_ABST
    Figure CN2025082434_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a control method, a device, and a system. An AF generates identifier information of a first device; a first network element receives a first operation request, determines a network configuration file of the first device from a second network element by using an AF identifier, a routing identifier, and an operation parameter in the first operation request, verifies the validity of the first operation request and the validity of a first response message on the basis of the network configuration file, and sends a second response message to the first AF when the verification is passed, so as to manage the first device by means of the identifier information generated by the AF. Because the identifier information of the first device is generated by the AF, during execution of the first operation request, the addressing mode and the verification mode are more unified, thereby improving the management efficiency during management of the first device.
Need to check novelty before this filing date? Find Prior Art

Description

A control method, device and system

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on April 3, 2024, with application number 202410409195.9 and application name “A control method, device and system”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a control method, device, and system. Background Art

[0003] Currently, mobile communication networks use the operator-issued Universal Subscriber Identity Module (USIM) to identify devices during terminal device management. The USIM contains a Subscription Permanent Identifier (SUPI) and a Routing Indicator (RI). In some cases, the SUPI is the International Mobile Subscriber Identification Number (IMSI). However, not all devices have a USIM, and managing some devices that cannot be identified by a USIM is inefficient. Summary of the Invention

[0004] The present application provides a control method, device and system, which improves the efficiency of managing the device when the device is in its own network or roaming in a network by generating a device identifier for each device and managing the devices in the network based on the device identifier.

[0005] To achieve the above objectives, this application adopts the following technical solutions:

[0006] In a first aspect, the present application provides a control method, applied to a first network element, the method comprising: receiving a first operation request from a first application unit AF, the first operation request including at least one of the following: an AF identifier, a routing identifier, and an operation parameter; sending a second operation request to a first device, the second operation request including the operation parameter; receiving a first response message from the first device, determining a network configuration file from the second network element based on the first operation request and the first response message; verifying the first response message using the network configuration file, and sending a second response message to the first AF when the verification passes. Based on this, the first network element receives the first operation request from the first AF, sends the operation parameter carried in the first operation request as a second operation request to the first device, and cooperates with the first device to execute the second operation request, wherein the first AF is a network element connected to the network to which the first device belongs. In some examples, the first operation request may be a first inventory request.

[0007] In the solution provided by the first aspect above, the first network element determines the network profile of the first device based on the AF identifier and routing identifier in the received first operation request, verifies the legitimacy of the first operation request and the first response message based on the network profile, and sends a second operation request to the first device through the operation parameters carried by the first operation request, thereby realizing management of the first device and improving the efficiency of managing the first device when the first device is in the network to which it belongs.

[0008] As a possible implementation, the first operation request includes a routing identifier, the first response message includes a device identifier of the first device, and determining the network configuration file from the second network element based on the first operation request and the first response message may include: determining the second network element based on the routing identifier carried in the first operation request, sending the device identifier carried in the first response message to the second network element; and receiving operation permission information in the network configuration file determined by the second network element based on the device identifier. Based on this, the first network element determines the second network element for storing the network configuration file of the first device through the routing identifier in the first operation request, and sends the device identifier carried in the first response message to the second network element. The second network element determines the network configuration file of the first device based on the device identifier, and sends part or all of the network configuration file to the first network element for the first network element to verify the network permissions.

[0009] As a possible implementation, the first response message includes a device identifier of the first device; verifying the first response message using a network configuration file and sending a second response message to the first AF if the verification passes may include: the first network element using the device identifier information in the network configuration file to verify the device identifier carried in the first response message, and verifying the first response message using the operation permission information in the network configuration file, and sending a second response message to the first AF if the verification passes, wherein the second response includes the device identifier of the first device. Based on this, when the first network element verifies the first response message, if the device identifier in the network configuration file does not match the device identifier carried in the first response message, the first network element refuses to respond to the first response message; if the device identifier in the network configuration file matches the device identifier carried in the first response message, the first network element verifies the legitimacy of the first response message based on the operation permission information in the network configuration file; if the first response message passes the verification of the operation permission information, the second response message is sent to the first AF; if the first response message does not pass the verification of the operation permission information, the first network element may refuse to respond to the first response message, thereby preventing a device without operation permission from responding to the first operation request.

[0010] As a possible implementation method, the first operation request carries the current network PLMN, the network profile includes the network HPLMN and the roaming network VPLMN of the first device, and the operation authority information in the network profile is used to verify the first response message, including: the PLMN is the same as the HPLMN, and the first response message passes the verification; or, the PLMN is different from the HPLMN and the same as any VPLMN, and the first response message passes the verification; or the PLMN is different from the HPLMN, and the VPLMN list is empty, and the first response message passes the verification; or, the PLMN is different from the HPLMN, the MCC in any VPLMN is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty, and the first response message passes the verification. Based on this, when the first network element verifies the first response message, it obtains the current network PLMN carried in the first operation request, and uses the network HPLMN and the network list VPLMN that can be roamed included in the network configuration file. The network HPLMN and the network list VPLMN that can be roamed are a kind of operation authority information. The HPLMN and VPLMN are used to verify the PLMN, and when the verification passes, a second response message is sent to the first AF.

[0011] As a possible implementation, the first operation request includes a routing identifier, and the first network element determines a network configuration file from a second network element based on the first operation request. This may include: determining the second network element based on the routing identifier, sending the device identifier in the operation parameters to the second network element; and receiving operation permission information from the network configuration file determined by the second network element based on the device identifier. Based on this, the first network element determines the second network element for storing the network configuration file of the first device based on the routing identifier, and sends the device identifier to the second network element. The second network element determines the network configuration file of the first device based on the device identifier, and sends part or all of the network configuration file to the first network element for the first network element to verify network permissions.

[0012] As a possible implementation, sending the second operation request to the first device may include: the first network element verifying the first operation request using the operation permission information in the network configuration file, and sending the second operation request to the first device if the verification is successful. Based on this, the first network element verifies the legitimacy of the first operation request based on the operation permission information in the determined network configuration file of the first device, and sends the second operation request to the first device if the first operation request passes the verification of the operation permission information. If the first operation request fails to pass the verification of the operation permission information, the first network element may refuse to respond to the first operation request, thereby preventing a network element without operation permission from managing the first device through the first operation request.

[0013] As a possible implementation method, using a network configuration file to verify the first operation request, and sending a second operation request to the first device when the verification is successful, can include: the first network element uses the list of AF identifiers allowed to operate in the network configuration file to verify the AF identifier carried in the first operation request, and sends the second operation request to the first device when the verification is successful. Based on this, the first network element verifies the AF identifier carried in the first operation request through the operation permission information in the network configuration file. The first network element first obtains the list of AF identifiers allowed to operate in the operation permission information from the second network element. If the AF identifier is in the list of AF identifiers allowed to operate, the second operation request is sent to the first device. If the AF identifier is not in the list of AF identifiers allowed to operate, the response to the first operation request can be refused, thereby preventing the AF that does not have the operation permission from managing the first device through the first operation request.

[0014] As a possible implementation, the method may further include: a first network element receiving a first activation request from a network opening element (NEF), the first activation request including a device configuration file and activation parameters; sending a first inventory request and a second activation request to the first device, the first inventory request including the inventory parameters, and the second activation request including the device configuration file and activation parameters, the device configuration file and activation parameters being used to activate the first device; receiving a first response message and a first activation response from the first device, and sending the first activation response to the NEF. Based on this, when the first network element receives the first activation request, the first activation request carries the device configuration file and activation parameters for activating the first device; based on the device configuration file and activation parameters, the first inventory request and the second activation request are sent to the first device, wherein the first inventory request is used to perform an inventory on the first device. The first inventory request and the second activation request may be sent to the first device simultaneously or sequentially. When the first device responds to the first inventory request, the first device may respond to the second activation request. The device configuration file and activation parameters in the second activation request may be sent via the same or different signaling.

[0015] As a possible implementation, the first activation request includes at least one of the following: a device identifier and a routing identifier. The method may further include: the first network element determining the second network element based on the routing identifier and sending the device identifier to the second network element; and receiving operation permission information from a network configuration file determined by the second network element based on the device identifier. Based on this, the first network element determines the second network element for storing the network configuration file of the first device based on the routing identifier and the device identifier, and sends the device identifier to the second network element. The second network element determines the network configuration file of the first device based on the device identifier and sends part or all of the network configuration file to the first network element for the first network element to verify network permissions.

[0016] As a possible implementation, sending a first inventory request and a second activation request to the first device may include: verifying the first activation request using the operation permission information in the network configuration file, and sending the first inventory request and the second activation request to the first device when the verification passes. Based on this, the first network element verifies the legitimacy of the first activation request based on the operation permission information in the determined network configuration file of the first device, and sends the first inventory request and the second activation request to the first device when the first operation request passes the verification of the operation permission information. The first inventory request and the second activation request may be sent to the first device simultaneously or successively. When the first activation request fails to pass the verification of the operation permission information, the first activation request may be refused to be responded to, thereby preventing a network element that does not have operation permission from activating the first device through the first activation request.

[0017] As a possible implementation method, the second activation request includes an AF identifier, the operation permission information in the network configuration file is used to verify the first activation request, and the first inventory request and the second activation request are sent to the first device when the verification is successful. This can include: using the list of AF identifiers allowed to operate in the network configuration file to verify the AF identifier carried in the first activation request, and sending the first inventory request and the second activation request to the first device when the verification is successful. Based on this, the first network element verifies the AF identifier carried in the first activation request through the operation permission information in the network configuration file. The first network element first obtains the list of AF identifiers allowed to operate in the operation permission information from the second network element. If the AF identifier is in the list of AF identifiers allowed to operate, the first inventory request and the second activation request are sent to the first device. If the AF identifier is not in the list of AF identifiers allowed to operate, the response to the first activation request can be refused, thereby preventing the AF that does not have the operation permission from activating the first device through the first activation request.

[0018] As a possible implementation, the method may further include: receiving a third operation request from the first AF, the third operation request including an AF identifier, a second routing identifier, a second device identifier, and operation parameters, the second routing identifier and the second device identifier being obtained by the first AF from the second AF; sending a fourth operation request to the second device, the fourth operation request including the operation parameters; determining a network profile of the second device from a second network element of the second device's home network based on the second routing identifier and the second device identifier; receiving a third response message from the second device; verifying the third response message using the network profile, and sending a fourth response message to the first AF if the verification succeeds. Based on this, the first network element receives the third operation request, the second routing identifier, the second device identifier, and the operation parameters included in the third operation request, and sends the operation parameters as the fourth operation request to the second device, the second device being a device roaming to the network of the first AF; the first AF obtains the second routing identifier and the second device identifier from the second AF, the second AF being a network element of the second device's home network, and the second AF storing the second routing identifier and the second device identifier corresponding to the second device. The second routing identifier includes HPLMN and a routing code, wherein the HPLMN indicates the network to which the second device belongs, and the routing code indicates the second network element used to store the network configuration file of the second device. The first network element obtains the network configuration file of the second device from the second network element of the network to which the second device belongs based on the second routing identifier and the second device identifier. In some embodiments, the first network element verifies the operation authority of the third operation request and the third response message based on the network configuration information. The verification process is the same as the verification method for verifying the first operation request and the first response message in the aforementioned embodiment, and will not be repeated here.

[0019] In the second aspect, the present application provides a control method applied to NEF, the method comprising: NEF receiving a first configuration request from a first AF, the first configuration request including an AF identifier, a device identifier, first auxiliary information, and second auxiliary information, the first auxiliary information being used to select a matching second network element, and the second auxiliary information being used by the second network element to generate a network configuration file and a device configuration file; determining the corresponding second network element based on the first auxiliary information, and sending a second configuration request to the second network element, the second configuration request including an AF identifier, a device identifier, and the second auxiliary information; receiving a first configuration response from the second network element, the first configuration response including a network configuration file, a device configuration file, and a routing identifier. Based on this, NEF receives the first configuration request, the first auxiliary information in the first configuration can be used to determine the second network element for storing the network configuration file, and sends the AF identifier, the device identifier, and the second auxiliary information to the second network element, and the second auxiliary information is used to generate a network configuration file and a device configuration file corresponding to the first device.

[0020] In the solution provided by the second aspect above, the NEF determines the second network element based on the first auxiliary information in the received first configuration request, and sends a second configuration request to the second network element, so that the second network element cooperates to generate a network configuration file, a device configuration file and a routing identifier, and sends the received configuration result to the first AF, completing the configuration process on the network side, so that each device identifier has a corresponding second network element for storing the network configuration file. During use, the corresponding network configuration file can be determined according to the routing identifier and the device identifier, thereby improving the efficiency of subsequent determination of the network configuration file.

[0021] As a possible implementation, the first configuration request also includes an activation indication and activation parameters, and the method further includes: the NEF sends a first activation request to the first network element based on the activation indication, and the first activation request includes an AF identifier, a device identifier, a device configuration file, a routing identifier, and activation parameters. Based on this, the first configuration request carries an activation indication and activation parameters for activating the first device. Based on the activation indication from the first AF, the NEF sends the first activation request to the first network element. In the first activation request, the device configuration file and activation parameters can be used to activate the first device. The AF identifier, the device identifier, and the routing identifier are used to verify the legitimacy of the first activation request. The verification process is the same as the method for verifying the legitimacy of the first operation request in the aforementioned embodiment, and will not be repeated here.

[0022] As a possible implementation, the method may further include: after receiving the first configuration response from the second network element, sending a network configuration file and a routing identifier to the first AF. Based on this, upon receiving the first configuration response from the second network element, the first configuration response may include a network configuration file, a device configuration file, and a routing identifier, and the network configuration file and routing identifier are sent to the first AF, so that the first AF provides the network configuration file and routing identifier to the AF in another network when the first device roams to the other network.

[0023] As a possible implementation, the method further includes: the NEF generating a corresponding network configuration file and device configuration file based on the device identifier and the second auxiliary information, wherein the network configuration file and the device configuration file have a corresponding relationship. Based on this, when the second network element does not generate the network configuration file and the device configuration file, the NEF can generate the network configuration file and the device configuration file based on the device identifier and the second auxiliary information.

[0024] As a possible implementation, the method may further include: the NEF receives a third configuration request from the first AF, the third configuration request including an AF identifier, a second device identifier, a second network configuration file, third auxiliary information, and fourth auxiliary information, the third configuration request being used to configure the second device, the second device identifier and the second network configuration file being obtained by the first AF from the second AF, and the second AF being connected to the network to which the second device belongs; determining the corresponding second network element based on the third auxiliary information, and sending a fourth configuration request to the second network element, the second configuration request including the AF identifier, the second device identifier, the second network configuration file, and the fourth auxiliary information. Based on this, the NEF receives the third configuration request, the second device roams to the network to which the first AF is connected, the third configuration request is used to configure the second device, the second device identifier and the second network configuration file corresponding to the second device are obtained by the first AF from the second AF, and the second AF is connected to the network to which the second device belongs, the third auxiliary information is used by the NEF to determine the second network element, the fourth auxiliary information is used to update the second network configuration file, and the updated second network configuration file and routing identifier from the second network element are accepted.

[0025] In a third aspect, the present application provides a control method, which is applied to a second network element, the method comprising: the second network element receives a second configuration request from an NEF, the second configuration request including an AF identifier, a device identifier, and second auxiliary information; generates a corresponding network configuration file and a device configuration file based on the device identifier and the second auxiliary information, the network configuration file and the device configuration file having a corresponding relationship; saves the network configuration file and allocates a routing identifier corresponding to the network configuration file, the routing identifier being used to obtain the network configuration file in the second network element; sends a first configuration response to the NEF, the first configuration response including the network configuration file, the device configuration file, and the routing identifier. Based on this, the second network element receives the second configuration request, generates a corresponding network configuration file and a device configuration file based on the device identifier and the second auxiliary information in the second configuration request, the network configuration file is stored in the second network element, the device configuration file is stored in the first device, the network configuration file and the device configuration file both include the same device identifier, the second network element allocates a routing identifier for determining the network configuration file, and sends the network configuration file, the device configuration file, and the routing identifier to the NEF as the first configuration response.

[0026] In the solution provided by the third aspect, the second network element generates a corresponding network configuration file, device configuration file, and routing identifier using the device identifier and second auxiliary information in the second configuration request, stores the network configuration file in the second network element, and synchronizes the network configuration file and routing identifier to the first AF through the NEF. This allows the first device corresponding to the device identifier to roam to other networks, and the first AF can provide the network configuration file and routing identifier to the AF in the other network. This improves the efficiency of managing devices in the network and when roaming on the network.

[0027] As a possible implementation, the network configuration file and the device configuration file can be the same or different, and the network configuration file and the device configuration file include device identification, security parameters, and device capabilities. Based on this, the network configuration file and the device configuration file both include matching device identifications. At the same time, the network configuration file may also include information related to device security parameters and / or network device capability information, and the device configuration file may also include information related to device security parameters and / or device capability information.

[0028] As a possible implementation, the network configuration file includes network control permissions, and the device configuration file includes device control permissions. Based on this, the network configuration file including network control permissions can be used to verify permissions for network requests, and the device configuration file including device control permissions can be used to verify permissions for device requests.

[0029] As a possible implementation, the method further includes: receiving a fourth configuration request from the NEF, the fourth configuration request including an AF identifier, a second device identifier, a second network configuration file, and fourth auxiliary information; updating and saving the second network configuration file based on the second device identifier and the fourth auxiliary information, and allocating a routing identifier corresponding to the second network configuration file, the routing identifier being used to obtain the network configuration file in the second network element; and sending a second configuration response to the NEF, the second configuration response including the updated network configuration file and the routing identifier. Based on this, the second network element receives the fourth configuration request, the fourth configuration request being used to configure the second device identifier and the second network configuration file corresponding to the second device, and the second network element updates the second network configuration file based on the second device identifier and the fourth auxiliary information in the fourth configuration request and saves the new second network device file in the second network element, then allocates a routing identifier corresponding to the second network device file, and sends the updated second network configuration file and routing identifier to the NEF.

[0030] As a possible implementation, the first configuration request includes a roaming policy, and the method further includes: the second network element sending a second configuration response to the NEF, where the second configuration response includes a device configuration file and a routing identifier. Based on this, since the first configuration information received by the second network element includes the roaming policy, the second network element does not need to carry the network configuration file when sending the configuration response to the NEF. That is, the second configuration response is sent to the NEF, where the second configuration response includes the device configuration file and the routing identifier, thereby reducing transmission overhead between the second network element and the NEF.

[0031] As a possible implementation, the second auxiliary information includes the HPLMN and the VPLMN to which the first device belongs, and generating the corresponding network profile and device profile based on the device identifier and the second auxiliary information includes: generating the corresponding network profile and device profile based on the device identifier and the HPLMN and VPLMN. Based on this, the second auxiliary information is used to generate the network profile and device profile. When the second auxiliary information includes the HPLMN and VPLMN, a network profile and device profile for restricting roaming permissions can be generated.

[0032] As a possible implementation, the second network element includes a unified data management unit (UDM) or an authentication, authorization, and accounting unit (AAA). Based on this, the second network element generates network configuration files and device configuration files and stores the network configuration files. In some examples, the second network element can be a UDM or AAA. AAA is used for authentication, authorization, and accounting and can be set outside the core network as an external storage unit. AAA in this application plays the same role as UDM.

[0033] In a fourth aspect, the present application provides a control method, which is applied to a first AF, and the method further includes: generating a device identifier for the first device; sending a first configuration request to the NEF, the first configuration request including the AF identifier, the device identifier, the first auxiliary information, the second auxiliary information, the activation indication and the activation parameters, the AF identifier, the device identifier, the first auxiliary information, the second auxiliary information are used by the NEF to configure the corresponding network configuration file, the device configuration file and the routing identifier for the device identifier, and the activation indication and the activation parameters are used to instruct the NEF to activate the first device. Based on this, the first AF generates a corresponding device identifier for the first device, the network to which the first AF accesses is the network to which the first device belongs, and then the first AF sends a first configuration request to the NEF, the first auxiliary information is used by the NEF to determine the second network element, the device identifier and the second auxiliary information are used by the second network element to generate the network configuration file, the device configuration file and the routing identifier, and send them to the first AF for storage, and the activation indication and the activation parameters in the first configuration request are used by the NEF to send a first activation request to the first network element to activate the first device.

[0034] In the solution provided by the fourth aspect, the first AF configures the first network element, the second network element, and the first device by sending a first configuration request, thereby managing the device in the network using the generated device identifier. The first AF saves the configured network configuration file, device configuration file, and routing identifier, so that when the first device roams to another network, the network configuration file and routing identifier are provided to the AF of the roaming network, thereby improving the management efficiency of the first device.

[0035] As a possible implementation, the method further includes: the first AF receiving a first activation response from the NEF, the first activation response including a network configuration file and a routing identifier; and storing the device identifier, the network configuration file, and the routing identifier. Based on this, the first AF receives the first activation response from the NEF, the first activation response carrying the network configuration file and the routing identifier, and stores the network configuration file and the routing identifier along with the device identifier of the first device. When the first device roams to another network, the network configuration file and the routing identifier are provided to the AF of the roaming network, thereby improving management efficiency of the first device.

[0036] As a possible implementation, the method further includes: obtaining a second device identifier and a second device configuration file corresponding to the second device from the second AF, and the second AF accessing the network to which the second device belongs; sending a third configuration request to the NEF, the third configuration request including the AF identifier, the second device identifier, the second network configuration file, the third auxiliary information, and the fourth auxiliary information, the third configuration request being used to configure the second device, the third auxiliary information being used to select a matching second network element, and the fourth auxiliary information being used by the second network element to generate a network configuration file and a device configuration file. Based on this, when the second device roams to the network accessed by the first AF, the first AF obtains the second device identifier and the second device configuration file corresponding to the second device from the second AF of the network to which the second device belongs, and sends the third configuration request to the NEF based on the second device identifier and the second device configuration file, for the first network element or the second network element to update the network configuration file according to the second device identifier and the fourth auxiliary file, so that the second device can be managed through the network accessed by the first AF.

[0037] As a possible implementation, the method further includes: obtaining a second device identifier and a second routing identifier corresponding to the second device from a second AF, the second routing identifier being used to indicate determining a network configuration file of the second device in a second network element of the second device's home network; and sending a third operation request, the third operation request including an AF identifier, a second routing identifier, and inventory parameters. Based on this, when the second device roams to a network accessed by the first AF, the first AF obtains the second device identifier and the second routing identifier corresponding to the second device from the second AF of the second device's home network, and sends a third operation request to the NEF, the third operation request including an AF identifier, a second routing identifier, and inventory parameters. The second routing identifier can be used to determine the network configuration file corresponding to the second device from the second network element of the second device's home network, and can be used by the second network element to verify the legitimacy of the third operation request.

[0038] As a possible implementation, the method further includes: the first AF sending a first operation request to the NEF, the first operation request including an AF identifier, a routing identifier, and operation parameters, the AF identifier, routing identifier, and inventory parameters being used to obtain a network configuration file from the second network element; and receiving a second response message from the NEF, the second response message including the first device identifier. Based on this, the first AF sends the first operation request for managing the first device, and upon receiving the second response message from the NEF, the operation request for the first device is successfully responded to by the first device. In some examples, the first operation request may be a first inventory operation.

[0039] As a possible implementation, the method further includes: the first AF generating a corresponding network configuration file and device configuration file based on the device identifier and the second auxiliary information, where the network configuration file and the device configuration file have a corresponding relationship. Based on this, the first AF may also generate the network configuration file and the device configuration file based on the device identifier and the second auxiliary information, and send the network configuration file to the second network element, which will store the network configuration file. The device configuration information may be carried to the first device via an activation request and stored by the first device.

[0040] As a possible implementation, the method further includes: the first AF receiving a device configuration file from the NEF; and sending a third activation request, where the third activation request includes an AF identifier, a device identifier, a device configuration file, a routing identifier, and activation parameters. Based on this, upon receiving the device configuration file, the first AF directly sends the third activation request to the first network element, not through the NEF, to activate the first device.

[0041] As a possible implementation, the first configuration request includes a roaming policy, and the roaming policy instructs the second network element in the network to which the second device belongs to obtain a network configuration file. Based on this, the first AF carries the roaming policy when sending the first configuration request to the NEF. The roaming policy can instruct the second network element to send a second configuration response when returning the configuration response, without carrying the network configuration file and the device configuration file, and only carrying the routing identifier.

[0042] As a possible implementation, the method further includes: the first AF receiving a second activation response from the NEF, the second activation response including a routing identifier; and storing the device identifier and the routing identifier. Based on this, the first AF receives the second activation response and stores the device identifier and the routing identifier, so that when the first device roams to another network, the first AF provides the device identifier and the routing identifier of the first device, thereby improving management efficiency of the first device.

[0043] In a fifth aspect, the present application provides a control method, applied to a first device, comprising: the first device receiving a second operation request from a first network element, the second operation request including an operation parameter for the first device to determine whether to respond to the second operation request; if the operation parameter satisfies a first preset condition, sending a first response message to the first network element, the first response message including a device identifier of the first device. Based on this, the first device receives the second operation request from the first network element, and when the inventory parameter satisfies the first preset condition, responds to the second operation request and sends a first response message including the device identifier of the first device, thereby enabling management of the first device through the device identifier of the first device.

[0044] As a possible implementation, the method further includes: the first device receiving a first inventory request and a second activation request from a first network element, the first inventory request including inventory parameters, the inventory parameters being used to indicate characteristic information of the first inventory request and used by the first device to determine whether to respond to the first inventory request; the second activation request including a device configuration file and activation parameters, the device activation file and activation parameters being used to activate the first device; if the operating parameters meet a first preset condition, activating the first device based on the activation parameters, saving the device configuration file, and sending a first response message and a first activation response to the first network element, the first response message including a device identifier of the first device. Based on this, upon receiving the first inventory request, the first device determines whether to respond to the first inventory request based on the inventory parameters carried in the first inventory request. If the first device responds to the first inventory request, the first device sends the first inventory response to the first network element. The first device activates itself based on the activation parameters and device configuration file received in the second activation request, saves the device configuration file in the first device, and finally sends the first activation response to the first network element.

[0045] As a possible implementation, the operating parameters include the current network PLMN, and the operating parameters satisfy a first preset condition, including: the PLMN successfully matches the HPLMN and VPLMN included in the device configuration file. Based on this, the first device may verify the PLMN in the operating parameters based on the HPLMN and VPLMN included in the device configuration file. If the PLMN verification passes, it indicates that the PLMN successfully matches the HPLMN and VPLMN included in the device configuration file, and the first device may respond to the second operation request.

[0046] As a possible implementation, the PLMN successfully matches the HPLMN and VPLMN included in the device configuration file, which may include: the PLMN is the same as the HPLMN; or the PLMN is different from the HPLMN and the same as any VPLMN; or the PLMN is different from the HPLMN and the VPLMN list is empty; or the PLMN is different from the HPLMN, the MCC in any VPLMN is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty. When the first device verifies the operation parameter PLMN in the second operation request, it obtains the current network PLMN carried in the second operation request, and uses the network HPLMN and the roaming network list VPLMN included in the network configuration file. The network HPLMN and the roaming network list VPLMN are a type of operation permission information. The HPLMN and VPLMN are used to verify the PLMN, and when the verification is successful, the PLMN successfully matches the HPLMN and VPLMN included in the device configuration file.

[0047] In the sixth aspect, the present application provides a core network network element, which includes: a transceiver for sending and receiving signals; a memory for storing computer program instructions; and a processor for executing the computer program instructions to support the network device to implement a method as described in any one of the first aspect, the second aspect, the third aspect, and the fourth aspect.

[0048] In the seventh aspect, the present application provides a user device, which includes: a transceiver for sending and receiving signals; a memory for storing computer program instructions; and a processor for executing the computer program instructions to support the terminal device to implement a method as described in any one of the fifth aspects.

[0049] In an eighth aspect, the present application provides a communication system, which includes a terminal device and a network device, wherein the terminal device and the network device are communicatively connected, and the communication system is used to implement a method as described in any one of the first aspect, the second aspect, the third aspect, the fourth aspect, and the fifth aspect.

[0050] In the ninth aspect, the present application provides a computer-readable storage medium having computer program instructions stored thereon, and when the computer program instructions are executed by a processing circuit, the method as described in any one of the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect is implemented.

[0051] In a tenth aspect, the present application provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute a method as described in any one of the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.

[0052] In the eleventh aspect, the present application provides a chip system, which includes a processing circuit and a storage medium, in which computer program instructions are stored; when the computer program instructions are executed by the processing circuit, they implement the method as described in any one of the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] FIG1 is a schematic diagram of a system architecture provided by an embodiment of the present application;

[0054] FIG2 is a schematic diagram of a detailed flow chart of a control method provided in an embodiment of the present application;

[0055] FIG3 is a flow chart of a control method provided in an embodiment of the present application;

[0056] FIG4 is a flow chart of a control method in a roaming scenario provided by an embodiment of the present application;

[0057] FIG5 is a flow chart of another control method provided in an embodiment of the present application;

[0058] FIG6 is a flow chart of another control method in a roaming scenario provided by an embodiment of the present application;

[0059] FIG7 is a flow chart of another control method provided in an embodiment of the present application;

[0060] FIG8 is a flow chart of a method for controlling roaming network permissions according to an embodiment of the present application;

[0061] FIG9 is a schematic diagram of the composition structure of a network element device provided in an embodiment of the present application;

[0062] FIG10 is a schematic diagram of the hardware structure of a network element device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0063] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships can exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.

[0064] Hereinafter, the terms "first," "second," and so on are used solely to distinguish different descriptive objects and have no limiting effect on the position, order, priority, quantity, or content of the described objects. For example, if the described object is a "field," the ordinal number preceding the "field" in "first field" and "second field" does not define the position or order of the "fields." "First" and "second" do not define whether the modified "fields" are in the same message, nor do they restrict the order of the "first field" and "second field." For another example, if the described object is a "level," the ordinal number preceding the "level" in "first level" and "second level" does not define the priority of the "levels." For another example, the number of described objects is not limited by the ordinal number and can be one or more. For example, in the case of "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the described object is a "device," the "first device" and "second device" can be the same type of device or different types of devices. For another example, if the described object is "information," the "first information" and "second information" can be information of the same content or different contents. In short, the use of prefixes such as ordinal numbers to distinguish the described objects in the embodiments of the present application does not constitute a restriction on the described objects. For the statement of the described objects, please refer to the description in the context of the claims or embodiments, and no unnecessary restrictions should be constituted due to the use of such prefixes.

[0065] In addition, in the embodiments of the present application, "connection" can be a direct connection or an indirect connection; in addition, it can refer to an electrical connection or a communication connection; for example, the connection between two electrical components A and B can refer to a direct connection between A and B, or it can refer to an indirect connection between A and B through other electrical components or connection media, or it can refer to an indirect connection between A and B through other network element devices or communication media, as long as communication between A and B can be carried out.

[0066] Currently, Ambient IoT technology is being applied in logistics and warehousing, including inventory and tracking, and monitoring the transport environment and status of high-value goods (such as vaccines). It is also being used in industrial manufacturing, including resource management within industrial parks and factories, production process management, and environmental and equipment status monitoring. With technological advancements and environmental protection requirements, the application of Ambient IoT is expected to expand, with projections of covering hundreds of billions of devices in the future. By leveraging existing 5G wireless access network resources and integrating new air interface wireless technologies with readers within RAN base stations, communication capabilities between readers and Ambient IoT devices (including inventory and access operations for tags, labels, and devices) can be integrated into the base station. Ambient IoT devices can be activated and then inventoryed using air interface wireless technology, enabling reader functionality on the base station. This increases the communication distance between passive terminals and readers, while also enabling unified management of operator base stations. In some embodiments, the reader / writer for communicating with the Ambient IoT terminal device may also be integrated into the UE, and the inventory and access operations on the device are implemented by communicating with the terminal device through the UE reader / writer controlled by the network.

[0067] In some embodiments, the terminal user management method of the 5G network is that the operator issues a USIM card, which contains built-in user contract information, including a user permanent identifier (SUPI), a routing indicator (RI), etc. When the SUPI type is IMSI, the IMSI also contains a Mobile Country Code (MCC), a Mobile Network Code (MNC), and an MSIN. This information is set by the operator and stored in both the USIM and the UDM. When the user accesses the 5G network, the AMF addresses the UDM based on the SUPI and RI reported by the UE. Since the user identifier is allocated by the operator, it usually contains network internal routing information, such as addressing the UDM based on the IMSI number segment, or addressing the UDM based on the RI, or using different number segments for different IMSIs for mobile phones, the Internet of Things, the Internet of Vehicles, etc. for easy management. However, in the Ambient IoT scenario, the terminal identifier may be similar to the barcode of an item. The information needed to identify the item to which the terminal is attached has its own encoding method and may not be suitable for routing addressing within the network. If the terminal carries the RI for routing addressing within the network, more information needs to be transmitted on the basis of the device identification, which affects the efficiency of device inventory.

[0068] In some embodiments, when the UE roams between different operators, the visited network AMF needs to perform signaling interaction with the UDM and AUSF of the home network to complete the UE registration and security authentication processes. Different operators are required to sign an inter-network roaming agreement, and the core networks of the two operators need to be interconnected. When the UE roams between different operators, the UE decides whether to initiate the registration process in the roaming area and to which roaming network to initiate the registration process based on the VPLMN and priority level stored in the USIM and the PLMN broadcast by the visited base station. It is only suitable for terminal management and communication of existing terminals in roaming situations, and is not suitable for terminal management and inventory access operations of Ambient IoT terminal devices when they move between different networks. In particular, roaming between different operators will bring complexity to the management of Ambient IoT terminal devices, thereby affecting the efficiency of device inventory and increasing network management costs.

[0069] Therefore, for the management of Ambient IoT terminal devices, a solution is needed that does not rely on the device identity SUPI or RI reported by the terminal to address the UDM, as well as a solution that simplifies terminal management and UDM routing addressing when the device roams between different networks.

[0070] Based on this, the present application discloses a control method, device and system, in which identification information of a first device is generated by AF, a first network element receives a first operation request, and uses the AF identifier, routing identifier and operation parameters in the first operation request to determine the network configuration file of the first device from a second network element, and verifies the legitimacy of the first operation request and the first response message according to the network configuration file; and sends a second response message to the first AF when the verification is passed, so as to realize the management of the first device through the identification information generated by AF. Since the identification information of the first device can be generated by AF, the device identifier can be used completely to identify the item information without carrying and transmitting the routing information used for network addressing, thereby improving the communication efficiency when operating the first device.

[0071] The core of this embodiment is that the device does not need to store or transmit routing information. That is, the device identifier does not need to include network routing information, nor does the device need to provide a RI. Therefore, whether the device identifier is generated by the AF is not crucial. In other words, the fact that the device identifier can be generated by the AF to identify item information (rather than generated by the network) is a significant benefit of this innovative solution.

[0072] In some embodiments, during device management, the enterprise generates and manages the Ambient IoT Device (environmental IoT device) identifier, and the Ambient IoT (passive IoT) network is open to the AF (application function) through the Provisioning (configuration) interface. The Device contract information is registered to the network during Device configuration and roaming. The NEF (network exposure function) determines the UDM where the terminal data is stored, and the UDM generates contract information for terminal and network storage, and generates a routing identifier for addressing the UDM. The AF carries the routing identifier when calling the API to support addressing the UDM; the contract information can be stored in an external AAA (authentication, authorization and accounting), and the AF carries the AAA indication when calling the API to implement network addressing of the AAA; the contract information includes the use and matching logic of HPLMN (home network) and VPLMN (visited network) in the device and UDM / AAA, which can flexibly manage network permissions.

[0073] Refer to Figure 1, which shows a schematic diagram of a system architecture provided by an embodiment of the present application. As shown in Figure 1, an architecture supported by the present invention adds a tag management function (TMF) to the network. The TMF can be independent as shown in the figure, or it can be integrated with the AMF, or there can be no AMF but the TMF directly interfaces with the RAN. The network elements involved in the present invention include Device, RAN Reader, UE Reader, AMF, TMF, UDM, AAA, AF, and CHF. Since the embodiments provided in this application do not require UE Reader, AMF, and CHF to perform special processing, they will not be explained in subsequent embodiments.

[0074] The network element devices involved in the embodiments of the present application are applied to the core network architecture. The core network may include network devices that process and forward user signaling and data. For example, it includes access and mobility management function (AMF), session management function (SMF), user plane gateway, positioning management equipment and other core network devices. Among them, the user plane gateway can be a server with functions such as mobility management, routing, and forwarding of user plane data, generally located on the network side, such as serving gateway (SGW) or packet data network gateway (PGW) or user plane network element function entity (UPF). AMF and SMF are equivalent to the mobility management entity (MME) in the long term evolution (LTE) system. AMF is mainly responsible for access, and SMF is mainly responsible for session management. Of course, the core network can also include other network elements, which are not listed here one by one.

[0075] The network devices involved in the embodiments of the present application are, for example, radio access network (RAN) devices. The radio access network devices may be base stations, evolved NodeBs (eNodeBs), transmission reception points (TRPs), transmission nodes (TPs), next-generation NodeBs (gNBs) in fifth-generation (5G) mobile communication systems, next-generation base stations in sixth-generation (6G) mobile communication systems, base stations in future mobile communication systems, or access nodes in WiFi systems. They may also be modules or units that perform some of the functions of a base station, for example, a centralized unit (CU), a distributed unit (DU), or a radio unit (RU). The CU here implements the functions of the radio resource control protocol and packet data convergence protocol (PDCP) of the base station, and can also implement the functions of the service data adaptation protocol (SDAP); the DU implements the functions of the radio link control layer and medium access control (MAC) layer of the base station, and can also implement some or all of the physical layer functions. For detailed descriptions of the above-mentioned protocol layers, please refer to the relevant technical specifications of the 3rd Generation Partnership Project (3GPP). The CU and DU can be set separately, or they can be included in the same network element, such as the baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). In different systems, CU, DU, or RU may have different names, but those skilled in the art will understand their meanings. For example, in the ORAN system, CU may also be called open CU (open-CU, O-CU), DU may also be called open DU (open-DU, O-DU), and RU may also be called open RU (open-RU, O-RU).Any of the CU (or CU control plane (CU control plane, CU-CP), CU user plane (CU user plane, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0076] The wireless access network device can be a macro base station, a micro base station, an indoor station, a relay node, a donor node, etc. The embodiments of this application do not limit the specific technology and device form used by the wireless access network device. For ease of description, a base station is used as an example of a wireless access network device.

[0077] Electronic devices may also be referred to as terminal devices, user equipment (UE), mobile stations, mobile terminal devices, etc. Terminal devices can be widely used in various scenarios, for example, device-to-device (D2D), vehicle to everything (V2X) communication, machine-type communication (MTC), Internet of Things (IOT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, etc. Terminal devices may be mobile phones, tablet computers, computers with wireless transceiver functions, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, road side units (RSU), sensors, etc. The embodiments of the present application do not limit the specific technology and specific device form adopted by the terminal devices.

[0078] The above-mentioned terminal device can establish a connection with the operator network through the interface provided by the operator network (such as N1, etc.) and use the data and / or voice services provided by the operator network. The terminal device can also access the domain name system (DNS) through the operator network, use the operator services deployed on the DNS, and / or services provided by a third party. Among them, the above-mentioned third party may be a service provider other than the operator network and the terminal device, and can provide other data and / or voice services to the terminal device. Among them, the specific form of the above-mentioned third party can be determined according to the actual application scenario and is not limited here.

[0079] The control method provided in the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0080] Referring to FIG. 2 , which shows a detailed flow diagram of a control method provided in an embodiment of the present application, as shown in FIG. 2 , the method is applied to a first network including a first device, a RAN, a first network element, a second network element, an NEF, and a first AF. The method may include:

[0081] S101: A first AF generates a device identifier for a first device.

[0082] It should be noted that the device identifier generated by the first AF for the first device enables unique identification of the first device within the scope of use of the first device. In some examples, the first device is one or more user devices or terminal devices in a first network, and the first network is the network to which the first device belongs.

[0083] S102: The first AF sends a first configuration request to the NEF. Correspondingly, the NEF receives the first configuration request.

[0084] In some embodiments, the first configuration request carries an AF identifier, a device identifier, first auxiliary information, second auxiliary information, an activation indication, and activation parameters. The AF identifier, device identifier, first auxiliary information, and second auxiliary information are used by the NEF to configure a network configuration file, a device configuration file, and a routing identifier corresponding to the device identifier. The activation indication and the activation parameters are used to instruct the NEF to activate the first device.

[0085] It should be noted that the first AF generates a corresponding device identifier for the first device, the network accessed by the first AF is the network to which the first device belongs, and then the first AF sends a first configuration request to the NEF. The first auxiliary information is used by the NEF to determine the second network element. The device identifier and the second auxiliary information are used by the second network element to generate a network configuration file, a device configuration file, and a routing identifier, and send them to the first AF for storage. The activation indication and activation parameters in the first configuration request are used by the NEF to send a first activation request to the first network element to activate the first device.

[0086] In some embodiments, the AF identifier, device identifier, first auxiliary information, and second auxiliary information in the first configuration request are used by the NEF to configure the corresponding network configuration file, device configuration file, and routing identifier for the device identifier, and the activation indication and activation parameters are used to instruct the NEF to activate the first device.

[0087] In some embodiments, the NEF receives a first configuration request from a first AF, the first configuration request includes an AF identifier, a device identifier, first auxiliary information and second auxiliary information, the first auxiliary information is used to select a matching second network element, and the second auxiliary information is used for the second network element to generate a network configuration file and a device configuration file; determines the corresponding second network element based on the first auxiliary information, and sends a second configuration request to the second network element, the second configuration request includes the AF identifier, the device identifier, and the second auxiliary information; receives a first configuration response from the second network element, the first configuration response includes a network configuration file, a device configuration file and a routing identifier.

[0088] In some embodiments, the NEF receives a first configuration request, and the first auxiliary information in the first configuration can be used to determine a second network element for storing the network configuration file, and the AF identifier, device identifier, and second auxiliary information are sent to the second network element, and the second auxiliary information is used to generate a network configuration file and device configuration file corresponding to the first device.

[0089] It should be noted that the first AF generates a corresponding device identifier for the first device, the network accessed by the first AF is the network to which the first device belongs, and then the first AF sends a first configuration request to the NEF. The first auxiliary information is used by the NEF to determine the second network element. The device identifier and the second auxiliary information are used by the second network element to generate a network configuration file, a device configuration file and a routing identifier, and send them to the first AF for storage. The activation indication and activation parameters in the first configuration request are used by the NEF to send a first activation request to the first network element to activate the first device.

[0090] In some examples, the first auxiliary information is used to assist in selecting the UDM that stores the device contract information, such as the company name, the area where the terminal is used, the prefix of the device identification, etc.; in some examples, the second auxiliary information is used to assist in generating contract information, such as the device's home network HPLMN, the visited network VPLMN allowed to access, the security parameters used by the device (such as whether authentication is supported, one-way authentication or two-way authentication, whether message encryption and integrity protection are supported, support for security algorithms, etc.), permissions for network control (such as which AFs are allowed or prohibited to perform inventory or command requests on this device), permissions for device control, device capability information, manufacturer-defined information, etc.; the activation indication is used to indicate whether to execute the activation command to write the device configuration file to the device, and the activation parameters are used to assist in executing the activation process.

[0091] S103: The NEF selects a second network element.

[0092] In some embodiments, NEF selects a second network element based on the first auxiliary information in the first configuration request. The first auxiliary information is used to assist in selecting the UDM for saving the network configuration file, such as the company name, the area used by the terminal, the prefix of the device identification, etc. Different first auxiliary information can correspond to the same or different second network elements, which are used to store the network configuration file corresponding to the first device.

[0093] In some examples, the NEF may select a second network element for storing the subscription information based on the AF identifier. The same second network element may be selected for the same AF identifier, and the same or different second network elements may be selected for different AF identifiers.

[0094] In some embodiments, the NEF may also select the second network element according to the device identifier, for example, selecting the second network element according to the prefix of the identifier. The same second network element may be selected for the same prefix, and the same or different second network elements may be selected for different prefixes.

[0095] In some embodiments, the NEF may select the second network element based on different combinations of the above-mentioned multiple information.

[0096] In some embodiments, the NEF may select a second network element for storing the subscription information based on different combinations of the above-mentioned multiple information. In some examples, the NEF or the first AF may also optionally determine a corresponding routing identifier based on the second network element selected above. Once the second network element is determined, the routing identifier corresponding to the second network element can also be determined.

[0097] S104: The NEF sends a second configuration request to the second network element. Correspondingly, the second network element receives the second configuration request.

[0098] In some embodiments, the NEF sends a second configuration request to the selected second network element, where the second configuration request carries the AF identifier, the device identifier, and the second auxiliary information.

[0099] In some examples, the second auxiliary information and the device identifier are used by the second network element to generate a network configuration file and a device configuration file; the second configuration request includes the AF identifier, the device identifier, and the second auxiliary information.

[0100] S105: The second network element generates a device configuration file, generates and saves a network configuration file, and allocates a routing identifier.

[0101] In some embodiments, the UDM generates a network configuration file stored in the UDM and a device configuration file stored in the device based on the device identification and the second auxiliary information. The network configuration file and the device configuration file share some information for subsequent device inventory and access operations to verify the legitimacy of the device (such as device identification, security parameters, device capabilities, HPLMN and VPLMN for restricting access to the network, etc.).

[0102] In some examples, the network configuration file includes network configuration information used by the network (such as permissions for network control), and the device configuration file includes device configuration files used by the device (such as permissions for device control, manufacturer-defined information);

[0103] In some embodiments, the UDM allocates a routing identifier, the routing identifier including a PLMN and a routing code, and the UDM can be addressed according to the routing identifier;

[0104] When the second configuration request carries the AF identifier, the UDM can also save the AF identifier as part of the network configuration file;

[0105] In some embodiments, the network configuration file and the device configuration file may be generated by the NEF based on the second auxiliary information and the device identification;

[0106] In some embodiments, the network configuration file and the device configuration file may be generated by the AF based on the second auxiliary information and the device identification;

[0107] In some examples, the second configuration request includes an AF identifier, a device identifier, and second auxiliary information; the second network element generates a corresponding network configuration file and a device configuration file based on the device identifier and the second auxiliary information, and the network configuration file and the device configuration file have a corresponding relationship; the network configuration file is saved, and the second network element can find the corresponding network configuration file based on the device identifier; and the routing identifier corresponding to the second network element is allocated, and the routing identifier is used to address the second network element that saves the network configuration file.

[0108] S106: The second network element sends a first configuration response to the NEF, and the NEF correspondingly receives the first configuration response from the second network element.

[0109] In some embodiments, the second network element sends a first configuration response to the NEF, the first configuration response including a network configuration file, a device configuration file, and a routing identifier. The first configuration response includes the device configuration file, the network configuration file, and the routing identifier.

[0110] In some embodiments, as shown in FIG2 , the method further includes:

[0111] S201: The NEF sends a first activation request to a first network element. Correspondingly, the first network element receives the first activation request.

[0112] In some embodiments, the NEF sends a first activation request to the first network element based on the activation indication in the first configuration request to trigger the activation process; if the activation indication requires initiation of the activation process, the NEF sends an activation request to the first network element, carrying the AF identifier, device identifier, device configuration file, routing identifier, and activation parameters.

[0113] In some embodiments, the NEF may directly send a first activation request to the first network element based on the activation request initiated by the AF to the NEF;

[0114] S202: The first network element addresses the second network element

[0115] S2021: The first network element obtains the contract information from the second network element.

[0116] The first network element determines the second network element according to the routing identifier, and sends a request for obtaining subscription information to the second network element, carrying the AF identifier and the terminal identifier;

[0117] In some embodiments, the request may also carry a subscription information indication for instructing the second network element to return the subscription information of the network configuration file for operation authority check.

[0118] S2022: The second network element searches for the corresponding network configuration file according to the terminal identifier, and returns the subscription information specified in the network configuration file according to the subscription information indication.

[0119] In some examples, the second network element searches for a network configuration file corresponding to the device identifier based on the device identifier and the AF identifier.

[0120] S2023: The first network element checks whether the activation operation is allowed based on the above contract information.

[0121] In some embodiments, the content of the check may be whether the terminal allows the designated AF to access.

[0122] In some embodiments, the content of the check may be whether the terminal allows the designated AF to perform the activation operation.

[0123] In some embodiments, the content of the check may be whether the activation operation is allowed to be performed under the current PLMN network.

[0124] In some embodiments, it can be a combination of the above.

[0125] S203: The first network element sends a first inventory request to the first device through the RAN.

[0126] The TMF sends an inventory request to the device. This request can carry inventory parameters, such as indicating that this is an activation inventory to distinguish it from a normal inventory, so that the device can decide whether to respond to the inventory request. The inventory parameters can also specify a default device ID, so that devices with the default device ID will respond to the request, while devices with non-default device IDs will not respond to the request.

[0127] S204: The first device sends a first inventory response to the first network element through the RAN.

[0128] The device responds to the inventory request with the original device ID. The device ID may be the default one when the device is manufactured, or it may have been activated before, but the device allows reactivation.

[0129] S205: The first network element sends a second activation request to the first device via the RAN, and the first device correspondingly receives the second activation request from the first network element via the RAN.

[0130] Carries device configuration files and activation parameters. The activation parameters can contain user-defined content, such as a string of customized content specifically used to activate the device.

[0131] In some embodiments, the first inventory request includes the inventory parameters, the second activation request includes a device profile and activation parameters, and the device profile and activation parameters are used to activate the first device; a first response message and a first activation response are received from the first device, and the first activation response is sent to the NEF.

[0132] In some examples, when the first network element receives a first activation request, the first activation request carries a device configuration file and activation parameters for activating the first device, and a first inventory request and a second activation request are sent to the first device based on the device configuration file and the activation parameters, wherein the first inventory request is used to perform an inventory on the first device, and the first inventory request and the second activation request can be sent to the first device simultaneously or successively, and when the first device responds to the first inventory request, the first device can respond to the second activation request, and the device configuration file and activation parameters in the second activation request can be sent through the same or different signaling.

[0133] S206: The first device saves the device configuration file.

[0134] In some embodiments, after receiving the second activation request, the first device executes the activation instruction and saves the device configuration file.

[0135] In some embodiments, the content of the activation parameters may be verified before executing the activation instruction, such as verifying whether the activation parameters match the information stored in the device itself, to enhance security.

[0136] S207: The first device sends a first activation response to the first network element through the RAN.

[0137] A first activation response is received from the first device, and the first activation response is sent to the NEF. The first activation response includes whether the activation request is successfully executed.

[0138] S208: The first network element sends a first activation response to the NEF, including whether the activation request is successfully executed.

[0139] S209: The NEF sends a first activation response to the first AF, indicating whether the activation request is successfully executed, as well as a device configuration file and a routing identifier.

[0140] S210: The first AF saves the device identifier, the network configuration file, and the routing identifier.

[0141] In some embodiments, the AF saves the device identification, device configuration file, and routing identification to facilitate subsequent operation requests to the device and data sharing between different AFs.

[0142] In some embodiments, referring to FIG2 , the method includes:

[0143] S301: A first AF sends a first operation request to an NEF.

[0144] The first network element receives a first operation request from a first application unit AF, where the first operation request includes at least one of the following: an AF identifier, a routing identifier, and an operation parameter; and sends a second operation request to the first device, where the second operation request includes the operation parameter.

[0145] It should be noted that the operation parameters can be divided into two parts, one part is used for network processing and will not be sent to the terminal; the other part is sent to the terminal; so the part sent to the terminal is part of the operation parameters; the part used for the network can also be used to derive the routing identifier, so that the operation request of the first AF does not need to carry the routing identifier.

[0146] In some examples, the AF identifier can determine the routing identifier, or information in the inventory parameters (such as the association of regional information in the inventory parameters with regional information in the first auxiliary information) can also be used to determine the routing identifier. In some examples, the AF can send the first operation request without carrying the routing identifier, simplifying the parameters required for the inventory. The process of obtaining the routing identifier based on the AF identifier can be performed by the TMF or the NEF. The process of obtaining the routing identifier as part of the operation parameters can be performed by the TMF or the NEF.

[0147] S302: The NEF sends a first operation request to the first network element, and the first network element correspondingly receives the first operation request sent by the NEF.

[0148] In some embodiments, the first network element receives a first operation request from a first application unit AF, where the first operation request includes at least one of the following: an AF identifier, a routing identifier, and an operation parameter.

[0149] S303: The first network element addresses the second network element.

[0150] S3031: The first network element obtains subscription information from the second network element.

[0151] The first network element determines the second network element according to the routing identifier, and sends a request for obtaining subscription information to the second network element, carrying the AF identifier and the terminal identifier;

[0152] In some embodiments, the request may also carry a subscription information indication for instructing the second network element to return the subscription information of the network configuration file for operation authority check.

[0153] S3032: The second network element searches for the corresponding network configuration file according to the terminal identifier, and returns the subscription information specified in the network configuration file according to the subscription information indication.

[0154] In some examples, the second network element searches for a network configuration file corresponding to the device identifier based on the device identifier and the AF identifier.

[0155] S3033: The first network element checks whether the activation operation is allowed based on the above contract information.

[0156] In some embodiments, the content of the check may be whether the terminal allows the designated AF to access.

[0157] In some embodiments, the content of the check may be whether the terminal allows the designated AF to perform the activation operation.

[0158] In some embodiments, the content of the check may be whether the activation operation is allowed to be performed under the current PLMN network.

[0159] In some embodiments, it can be a combination of the above.

[0160] In some embodiments, the first operation request carries a routing identifier. In this case, the first network element can address the second network element based on the routing identifier, supporting interaction between the first network element and the second network element before the inventory is performed, such as checking permissions before performing the inventory operation. In some examples, the first network element is a TMF and the second network element is a UDM.

[0161] In some embodiments, the first operation request does not carry a routing identifier. In this case, the first network element may generate a routing identifier based on the AF identifier and / or inventory parameters carried in the first operation request, and then address the second network element based on the routing identifier.

[0162] In some embodiments, the first network element can determine the second network element based on the routing identifier, such as determining the second network element for storing the network configuration file of the first device based on the routing identifier, and then sending the device identifier in the operation parameters to the second network element; and then receiving the operation permission information in the network configuration file determined by the second network element based on the device identifier. In some embodiments, the second network element can also determine the network configuration file of the first device based on the device identifier, and send part or all of the network configuration file to the first network element for the first network element to verify the network permissions. In some embodiments, sending the first inventory request and the second activation request to the first device may include: using the operation permission information in the network configuration file to verify the first activation request, and sending the first inventory request and the second activation request to the first device when the verification is successful.

[0163] It should be noted that the first network element verifies the legitimacy of the first activation request based on the operation permission information in the determined network configuration file of the first device. When the first operation request passes the verification of the operation permission information, the first inventory request and the second activation request are sent to the first device. The first inventory request and the second activation request can be sent to the first device simultaneously or successively. When the first activation request does not pass the verification of the operation permission information, the response to the first activation request can be refused, thereby avoiding the network element that does not have the operation permission from activating the first device through the first activation request.

[0164] In some embodiments, the second activation request includes an AF identifier, the operation permission information in the network configuration file is used to verify the first activation request, and the first inventory request and the second activation request are sent to the first device when the verification is successful. This may include: using the AF identifier list allowed to operate in the network configuration file to verify the AF identifier carried in the first activation request, and sending the first inventory request and the second activation request to the first device when the verification is successful.

[0165] It should be noted that the first network element verifies the AF identifier carried in the first activation request through the operation permission information in the network configuration file. The first network element first obtains the list of AF identifiers allowed to operate in the operation permission information from the second network element. If the AF identifier is in the list of AF identifiers allowed to operate, the first inventory request and the second activation request are sent to the first device. If the AF identifier is not in the list of AF identifiers allowed to operate, the response to the first activation request can be refused, thereby avoiding the AF that does not have operation permission from activating the first device through the first activation request.

[0166] In some embodiments, the operation permission information in the network configuration file may include a list of AFIDs for which operations are permitted, or may be more specific, specifying operation requests that are permitted and / or prohibited for each AF ID, such as inventory, read, write, activate, disable, and custom commands. The first network element obtains the above information from the second network element by locating the second network element based on the routing identifier. The second network element locates the network configuration file corresponding to the device based on the device identifier and sends the operation permission information therein to the first network element. The first network element compares the operation request and the AF ID carried with the permission / prohibition information in the network configuration file to determine whether it has permission to perform the operation.

[0167] In some embodiments, the operation permission information may also include a reader / writer identifier that allows and / or prohibits the AF identifier from accessing; using the same method as above, the first network element may use the area information in the request parameter to convert it into a corresponding reader / writer identifier, and then compare it with the information in the network configuration file to determine whether it has permission; since permission control is not the focus of the present invention, the above examples are sufficient; each network configuration file and device configuration file corresponds to a first device.

[0168] In some embodiments, when the first operation request does not carry a device identifier, S304 may be directly executed after S302 is executed. That is, the first network element may temporarily not perform permission verification on the first operation request and directly send the second operation request to the first device.

[0169] S304: The first network element sends a second operation request to the first device through the RAN.

[0170] In some embodiments, the first network element may verify the first operation request using the operation permission information in the network configuration file, and send the second operation request to the first device when the verification passes.

[0171] In some examples, the first network element can verify the legitimacy of the first operation request based on the operation permission information in the determined network configuration file of the first device, and send a second operation request to the first device when the first operation request passes the verification of the operation permission information. When the first operation request does not pass the verification of the operation permission information, it can refuse to respond to the first operation request. Based on this, it can prevent the network element that does not have the operation permission from managing the first device through the first operation request.

[0172] For example, the first network element can use the AF identifier list of allowed operations in the network configuration file to verify the AF identifier carried in the first operation request, and send a second operation request to the first device when the verification is passed, that is, the AF identifier carried in the first operation request is included in the AF identifier list, or refuse to respond to the first operation request when the AF identifier carried in the first operation request is not included in the AF identifier list.

[0173] In some embodiments, before the first network element sends the second operation request to the first device through the RAN, it needs to first send an inventory request to the first device. After receiving the inventory response from the first device, execute S306, verify the authority of the inventory request and the inventory response, and then send the second operation request to the first device.

[0174] S305: The first device sends a first response message to the first network element through the RAN.

[0175] In some embodiments, the second operation request includes an operation parameter used by the first device to determine whether to respond to the second operation request. Based on this, if the operation parameter satisfies a first preset condition, the first device sends a first response message to the first network element, and the first response message includes a device identifier of the first device. Based on this, management of the first device can be achieved using the device identifier of the first device.

[0176] S306: The first network element addresses the second network element.

[0177] S3061: The first network element obtains the subscription information from the second network element.

[0178] The first network element determines the second network element according to the routing identifier, and sends a request for obtaining subscription information to the second network element, carrying the AF identifier and the terminal identifier;

[0179] In some embodiments, the request may also carry a subscription information indication for instructing the second network element to return the subscription information of the network configuration file for operation authority check.

[0180] S3062: The second network element searches for the corresponding network configuration file according to the terminal identifier, and returns the subscription information specified in the network configuration file according to the subscription information indication.

[0181] In some examples, the second network element searches for a network configuration file corresponding to the device identifier based on the device identifier and the AF identifier.

[0182] S3063: The first network element checks whether the activation operation is allowed based on the above contract information.

[0183] In some embodiments, the content of the check may be whether the terminal allows the designated AF to access.

[0184] In some embodiments, the content of the check may be whether the terminal allows the designated AF to perform the activation operation.

[0185] In some embodiments, the content of the check may be whether the activation operation is allowed to be performed under the current PLMN network.

[0186] In some embodiments, it can be a combination of the above.

[0187] In some embodiments, the first network element may determine the second network element based on the routing identifier carried in the previously received first operation request, and then send the device identifier carried in the first response message to the second network element, so that the second network element can determine the network configuration file of the first device based on the device identifier, and receive the operation permission information in the network configuration file determined by the second network element based on the device identifier. In some embodiments, the second network element may also determine the network configuration file of the first device based on the device identifier, and send part or all of the network configuration file to the first network element for the first network element to verify the network permission.

[0188] In some embodiments, the first network element addresses the second network element according to the routing identifier, performs device legitimacy verification through interaction between the first network element and the second network element, and triggers subsequent security processes according to the network configuration file.

[0189] In some embodiments, a first network element determines a network configuration file from a second network element based on a first operation request, determines the second network element based on a routing identifier, sends a device identifier in the operation parameters to the second network element, and receives operation permission information from the network configuration file determined by the second network element based on the device identifier. The first network element determines a second network element for storing the network configuration file of the first device based on the routing identifier, and sends the device identifier to the second network element. The second network element determines the network configuration file of the first device based on the device identifier, and sends part or all of the network configuration file to the first network element for the first network element to verify network permissions.

[0190] In some embodiments, the first network element uses the device identifier in the network configuration file to verify the device identifier carried in the first response message, and uses the operation permission information in the network configuration file to verify the first response message, and sends a second response message to the first AF when the verification is passed, and the second operation response includes the device identifier of the first device. When the first network element verifies the first response message, if the device identifier in the network configuration file does not match the device identifier carried in the first response message, the first network element refuses to respond to the first response message. If the device identifier in the network configuration file matches the device identifier carried in the first response message, the legitimacy of the first response message is verified according to the operation permission information in the network configuration file. When the first response message passes the verification of the operation permission information, the second response message is sent to the first AF. When the first response message does not pass the verification of the operation permission information, the first response message can be refused to respond, thereby avoiding the response of the first operation request by a device that does not have the operation permission.

[0191] In some embodiments, if the second network element cannot obtain the network profile information, it also means that the verification fails. When the second network element does not have a network profile corresponding to the device identifier, it cannot be obtained; in some examples, the verification method may include going through an authentication process, and the authentication process will have another network element AUSF use the security parameters in the Network Profile (but will not transmit the security parameters in the Profile). The specific method and process are not reflected in the present invention. The verification process is controlled by TMF, and TMF / AUSF / UDM / Device completes the security authentication process together, and finally TMF knows the verification result; that is, do not limit the specific verification method in the rights.

[0192] S307: The first network element sends a second response message to the NEF.

[0193] In some embodiments, the first response message includes a device identifier of the first device; using a network configuration file to verify the first response message, and sending a second response message to the first AF when the verification passes, may include: the first network element uses the device identification information in the network configuration file to verify the device identifier carried in the first response message, and uses the operation permission information in the network configuration file to verify the first response message, and sending a second response message to the first AF when the verification passes, and the second response includes the device identifier of the first device.

[0194] It should be noted that when the first network element verifies the first response message, if the device identifier in the network configuration file does not match the device identifier carried in the first response message, the first network element refuses to respond to the first response message. If the device identifier in the network configuration file matches the device identifier carried in the first response message, the legitimacy of the first response message is verified according to the operation authority information in the network configuration file. When the first response message passes the verification of the operation authority information, the second response message is sent to the first AF. When the first response message does not pass the verification of the operation authority information, the response to the first response message can be refused, thereby avoiding the response of the device that does not have the operation authority to the first operation request.

[0195] In some embodiments, the first response message is authenticated using a device profile.

[0196] In some embodiments, the first operation request carries the current network PLMN, the network profile includes the HPLMN and the roaming network VPLMN of the first device, and the operation permission information in the network profile is used to verify the first response message, including: the PLMN is the same as the HPLMN, and the first response message passes the verification; or, the PLMN is different from the HPLMN and the same as any VPLMN, and the first response message passes the verification; or the PLMN is different from the HPLMN, and the VPLMN list is empty, and the first response message passes the verification; or, the PLMN is different from the HPLMN, the MCC in any VPLMN is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty, and the first response message passes the verification.

[0197] It should be noted that when the first network element verifies the first response message, it obtains the current network PLMN carried in the first operation request, and uses the network HPLMN and the network list VPLMN that can roam included in the network configuration file. The network HPLMN and the network list VPLMN that can roam are a kind of operation authority information. The HPLMN and VPLMN are used to verify the PLMN, and when the verification is successful, a second response message is sent to the first AF.

[0198] S308: The NEF sends a second response message to the first AF, and correspondingly, the first AF receives the second response message.

[0199] The second response message includes the first device identifier. The first operation request sent by the first AF in S301 is used to manage the first device. When the first AF receives the second response message from the NEF, the operation request for the first device is successfully responded to by the first device. In some examples, the first operation request may be a first inventory operation.

[0200] In some embodiments, the interaction between the NEF and the second network element may also be relayed through a BOSS system, wherein the network configuration file and the device configuration file may be generated by the BOSS system, and the routing identifier may be allocated by the BOSS system.

[0201] In some embodiments, the activation process may not be implemented through the above process, but the AF writes the device configuration file into the device through other means, such as the device provides a serial port, and the AF writes it through the serial port; it is necessary to obtain the device configuration file. In some examples, the NEF sends the device configuration file to the AF;

[0202] In some embodiments, the activation process can be independently initiated by AF through NET after completing the configuration process. Before initiating the activation process, it is necessary to obtain the device configuration file. In some examples, NEF sends the device configuration file to AF.

[0203] In some embodiments, the device configuration file and the network configuration file may be the same, containing complete information of both profiles. The second network element only saves the portion that needs to be saved by the network, and the device only saves the portion that needs to be saved by the device.

[0204] Based on the same inventive concept as the aforementioned embodiment, refer to FIG3 , which shows a flow chart of a control method provided in an embodiment of the present application. As shown in FIG3 , taking the first network element being TMF, the second network element being UDM, the operation request being an inventory request, and the response message being an inventory response as an example, the method includes S1-S8, wherein S1-S8 are the same principles as S301-S308 in FIG2 in the aforementioned embodiment, and are not repeated here.

[0205] In some embodiments, referring to FIG. 4 , which illustrates a flow chart of a control method in a roaming scenario provided by an embodiment of the present application, as shown in FIG. 4 , taking the example of a first device roaming from a first network to a second network, the second network includes a second AF, a second NEF, and a second UDM. The method further includes S101-S106, S201-S210, and S401-S408, wherein S101-S106 and S201-S210 are the same as those described for S101-S106 and S201-S210 in FIG. 2 in the aforementioned embodiment, and are not further described here. In addition, the method further includes:

[0206] S401: The second AF obtains the device identification and network configuration file from the first AF;

[0207] In some embodiments, the second AF may obtain the device identification and the network configuration file online by establishing a communication connection with the first AF; or obtain the device identification and the network configuration file from the first AF via email, USB flash drive, or the like.

[0208] S402: The second AF sends a third configuration request to the NEF;

[0209] In some embodiments, the third configuration request includes an AF identifier, a second device identifier, a second network configuration file, third auxiliary information, and fourth auxiliary information. The third configuration request is used to configure the second device, the third auxiliary information is used to select a matching second network element, and the fourth auxiliary information is used for the second network element to generate a network configuration file and a device configuration file.

[0210] It should be noted that when the second device roams to the network accessed by the first AF, the first AF obtains the second device identifier and second device configuration file corresponding to the second device from the second AF of the network to which the second device belongs, and sends a third configuration request to the NEF based on the second device identifier and the second device configuration file, so that the first network element or the second network element updates the network configuration file according to the second device identifier and the fourth auxiliary file, so that the second device can be managed through the network accessed by the first AF.

[0211] In some embodiments, the second AF sends a Provisioning request to the NEF to register the device with the network, carrying necessary parameters, including: AFID, device identifier, Network Profile, auxiliary information 1, and auxiliary information 2;

[0212] Exemplarily, auxiliary information 1 is used to assist in selecting the UDM for storing device contract information, such as the company name, the region where the terminal is used, the prefix of the device identification, etc.; auxiliary information 2 is used to assist in generating contract information. Generally speaking, if the Network Profile does not need to be refreshed, auxiliary information 2 is not required; this embodiment is different from embodiment 1 in that the Device Profile is not modified, so if the Network Profile is to be refreshed, it can only carry the part used to refresh the Network Profile that is different from the Device Profile, such as the permissions used for network control (such as which AFIDs are allowed or prohibited to take inventory or issue commands to this device).

[0213] In some embodiments, the third configuration request includes an AF identifier, a second device identifier, a second network configuration file, third auxiliary information, and fourth auxiliary information. The third configuration request is used to configure the second device. The second device identifier and the second network configuration file are obtained by the first AF from the second AF, and the second AF is connected to the network to which the second device belongs; the corresponding second network element is determined based on the third auxiliary information, and a fourth configuration request is sent to the second network element. The second configuration request includes the AF identifier, the second device identifier, the second network configuration file and the fourth auxiliary information.

[0214] It should be noted that when the first device roams to the network accessed by the first AF, the third configuration request is used to configure the second network accessed by the second AF. The second device identifier and second network configuration file corresponding to the second device are obtained by the first AF from the second AF. The second AF accesses the network to which the second device belongs. The third auxiliary information is used by the NEF to determine the second network element. The fourth auxiliary information is used to update the second network configuration file and accept the updated second network configuration file and routing identifier from the second network element.

[0215] S403: NEF selects UDM;

[0216] In some embodiments, the NEF determines the corresponding second network element based on the third auxiliary information and sends a fourth configuration request to the second network element, where the second configuration request includes an AF identifier, a second device identifier, a second network configuration file, and the fourth auxiliary information.

[0217] It should be noted that the NEF receives the third configuration request, the second device roams to the network accessed by the first AF, the third configuration request is used to configure the second device, the second device identifier and the second network configuration file corresponding to the second device are obtained by the first AF from the second AF, and the second AF accesses the network to which the second device belongs. The third auxiliary information is used by the NEF to determine the second network element, and the fourth auxiliary information is used to update the second network configuration file and accept the updated second network configuration file and routing identifier from the second network element.

[0218] S404: NEF sends a fourth configuration request to UDM

[0219] In some embodiments, the fourth configuration request includes an AF identifier, a second device identifier, a second network configuration file, and fourth auxiliary information. The NEF can update and save the second network configuration file based on the second device identifier and the fourth auxiliary information, and allocate a routing identifier corresponding to the second network configuration file. The routing identifier is used to obtain the network configuration file in the second network element so that the UDM sends a second configuration response to the NEF. The second configuration response includes the updated network configuration file and the routing identifier. Based on this, the second network element receives the fourth configuration request, and the fourth configuration request is used to configure the second device identifier and the second network configuration file corresponding to the second device. The second network element updates the second network configuration file based on the second device identifier and the fourth auxiliary information in the fourth configuration request and saves the new second network device file in the second network element, then allocates the routing identifier corresponding to the second network device file, and sends the updated second network configuration file and the routing identifier to the NEF.

[0220] S405: UDM refreshes and saves the network configuration file and assigns a routing identifier;

[0221] In some embodiments, the second network configuration file is updated and saved according to the second device identifier and the fourth auxiliary information, and a routing identifier corresponding to the second network configuration file is allocated, where the routing identifier is used to obtain the network configuration file in the second network element;

[0222] It should be noted that the fourth configuration request is used to configure the second device identifier and second network configuration file corresponding to the second device. The second network element updates the second network configuration file according to the second device identifier and fourth auxiliary information in the fourth configuration request and saves the new second network device file in the second network element, and then allocates the routing identifier corresponding to the second network device file, and sends the updated second network configuration file and routing identifier to the NEF.

[0223] In some embodiments, the UDM refreshes the portion of the Network Profile that is not shared with the Device Profile based on the device identifier and auxiliary information 2; at the same time, the UDM assigns a routing identifier, which may include a PLMN and a routing code, and the UDM may be addressed based on the routing identifier; the UDM may also save the AFID.

[0224] S406: UDM sends a first configuration response to NEF;

[0225] In some embodiments, the UDM sends a second configuration response to the NEF, where the second configuration response includes an updated network configuration file and a routing identifier.

[0226] S407: The NEF sends a first configuration response to the second AF;

[0227] In some embodiments, the first configuration response includes a network configuration file and a routing identifier.

[0228] S408: The second AF saves the device identifier, the updated network configuration file, and the routing identifier.

[0229] In some embodiments, the second AF saves the refreshed network configuration information and routing identifier corresponding to the device identifier to facilitate subsequent inventory, access, and data sharing of the device.

[0230] In some embodiments, referring to FIG5 , which shows a flow chart of another control method provided by an embodiment of the present application, as shown in FIG5 , the method includes S501-S506, S201-S210, and S301-S308, wherein S201-S210 and S301-S308 are the same as the description of S201-S210 and S301-S308 in FIG2 in the aforementioned embodiment, and are not further described here. In addition, the method further includes:

[0231] S501: A first AF generates a device identifier for a first device.

[0232] It should be noted that the device identifier generated by the first AF for the first device enables unique identification of the first device within the scope of use of the first device. In some examples, the first device is one or more user devices or terminal devices in a first network, and the first network is the network to which the first device belongs.

[0233] S502: The first AF sends a first configuration request to the NEF. Correspondingly, the NEF receives the first configuration request.

[0234] In some embodiments, the first configuration request carries an AF identifier, a device identifier, first auxiliary information, second auxiliary information, an activation indication, activation parameters, and a roaming policy.

[0235] In some embodiments, the AF identifier, device identifier, first auxiliary information, and second auxiliary information in the first configuration request are used by the NEF to configure the corresponding network configuration file, device configuration file, and routing identifier for the device identifier, and the activation indication and activation parameters are used to instruct the NEF to activate the first device.

[0236] It should be noted that the first AF can generate a corresponding device identifier for the first device. The network to which the first AF connects is the network to which the first device belongs. The first AF then sends a first configuration request to the NEF. The first auxiliary information is used by the NEF to identify the second network element. The device identifier and second auxiliary information are used by the second network element to generate a network configuration file, a device configuration file, and a routing identifier, and send them to the first AF for storage. The activation indication and activation parameters in the first configuration request are used by the NEF to send a first activation request to the first network element to activate the first device.

[0237] In some embodiments, the first configuration request includes a roaming policy, and the second network element sends a second configuration response to the NEF, where the second configuration response includes a device profile and a routing identifier. Based on this, since the first configuration information received by the second network element includes the roaming policy, the second network element does not need to carry the network profile when sending the configuration response to the NEF. That is, the second configuration response is sent to the NEF, where the second configuration response includes the device profile and the routing identifier, thereby reducing transmission overhead between the second network element and the NEF.

[0238] In some examples, the first auxiliary information is used to assist in selecting the UDM that stores the device contract information, such as the company name, the region where the terminal is used, the prefix of the device identification, etc.; in some examples, the second auxiliary information is used to assist in generating contract information, such as the security parameters used by the device (such as whether authentication is supported, one-way authentication or two-way authentication, whether message encryption and integrity protection are supported, security algorithms are supported, etc.), permissions for network control (such as which AF identifications are allowed or prohibited to take inventory or issue commands to this device), permissions for device control, device capability information, manufacturer-defined information, etc.; the activation indication is used to indicate whether to execute the activation command to write the device configuration file to the device, and the activation parameters are used to assist in executing the activation process.

[0239] S503: The NEF selects a second network element.

[0240] Some NEFs select a UDM storing the subscription information (ie, the network configuration file) according to the AF identifier and the first auxiliary information.

[0241] In some embodiments, NEF selects a second network element based on the first auxiliary information in the first configuration request. The first auxiliary information is used to assist in selecting the UDM for saving the network configuration file, such as the company name, the area used by the terminal, the prefix of the device identification, etc. Different first auxiliary information corresponds to their own second network element, which is used to store the network configuration file corresponding to the first device.

[0242] In some examples, optionally, the NEF or the first AF may also allocate a routing identifier according to the AF identifier and the first auxiliary information.

[0243] S504: The NEF sends a second configuration request to the second network element. Correspondingly, the second network element receives the second configuration request.

[0244] In some embodiments, the second configuration request carries an AF identifier, a device identifier, second auxiliary information, and a roaming policy.

[0245] S505: The second network element generates a device configuration file, generates and saves a network configuration file, and allocates a routing identifier.

[0246] In some embodiments, the second network element generates a device configuration file, generates and saves a network configuration file, and allocates a routing identifier according to the second configuration request.

[0247] In some embodiments, the second network element generates and saves a network configuration file and a device configuration file (i.e., a device sub-protocol) saved in the device based on the device identification and the second auxiliary information. The network configuration file and the device configuration file share a portion of information for subsequent support of device inventory and device legitimacy verification during access (e.g., device identification, security parameters, device capabilities, etc.).

[0248] In some examples, the network configuration file includes a network configuration file used by the network (such as permissions for network control), and the device configuration file includes a device configuration file used by the device (such as permissions for device control, manufacturer-defined information);

[0249] In some embodiments, the routing identifier allocated by the second network element may include a PLMN and a routing code, and the routing identifier may be used to address the corresponding second network element. The UDM may also store the AF identifier.

[0250] In some embodiments, the network configuration file and the device configuration file may be generated by the NEF according to the second auxiliary information and the device identification.

[0251] In some embodiments, the network configuration file and the device configuration file may be generated by the AF according to the second auxiliary information and the device identification.

[0252] In some examples, the second configuration request includes an AF identifier, a device identifier, and second auxiliary information; the second network element generates a corresponding network configuration file and a device configuration file based on the device identifier and the second auxiliary information, and the network configuration file and the device configuration file have a corresponding relationship; the network configuration file is saved, and a routing identifier corresponding to the network configuration file is allocated, and the routing identifier is used to obtain the network configuration file in the second network element.

[0253] In some embodiments, the second network element can generate a corresponding network configuration file and device configuration file based on the device identifier and the second auxiliary information in the second configuration request, store the network configuration file in the second network element, and store the device configuration file in the first device, wherein the network configuration file and the device configuration file both include the same device identifier. The second network element can also allocate a routing identifier for determining the network configuration file, and send the network configuration file, device configuration file and routing identifier as a first configuration response to the NEF.

[0254] S506: The second network element sends a second configuration response to the NEF. Correspondingly, the NEF receives the second configuration response.

[0255] In some embodiments, the second configuration response includes a device configuration file and a routing identifier.

[0256] In some embodiments, as shown in FIG2 , the method further includes:

[0257] In some embodiments, referring to FIG6 , which illustrates a flow chart of another control method in a roaming scenario provided by an embodiment of the present application, as shown in FIG6 , taking the example of a first device roaming from a first network to a second network, the method includes: S501-S506, S201-S210, and S601-S608; wherein S501-S506 and S201-S210 are the same as the description of S501-S506 and S201-S210 in FIG5 in the aforementioned embodiment, and are not further described here. In addition, the method further includes:

[0258] S601: The second AF obtains the routing identifier and the device identifier from the first AF;

[0259] The first network accessed by the first AF is the network to which the first device belongs, and the second AF is the second network to which the first device roams.

[0260] S602: The second AF sends a third operation request to the TMF through the NEF, and the TMF correspondingly receives the third operation request sent by the NEF.

[0261] S603: The first network element addresses the second network element from the network to which the second device belongs.

[0262] In some embodiments, a first network element in a second network receives a third operation request from a second AF, the third operation request including an AF identifier, a second routing identifier, a second device identifier and an operation parameter, the second routing identifier and the second device identifier being obtained by the second AF from the first AF; sends a fourth operation request to the second device, the fourth operation request including the operation parameter; determines a network profile of the second device from a second network element in the home network of the second device based on the second routing identifier and the second device identifier; receives a third response message from the second device; verifies the third response message using the network profile, and sends a fourth response message to the second AF when the verification is successful.

[0263] It should be noted that the first network element receives a third operation request, including a second routing identifier, a second device identifier, and operation parameters. The first network element sends the operation parameters as a fourth operation request to the second device. The second device is a device roaming to the network of the first AF. The second AF obtains the second routing identifier and the second device identifier from the first AF. The first AF is a network element of the network to which the second device belongs. The first AF stores the second routing identifier and the second device identifier corresponding to the second device. The second routing identifier includes an HPLMN and a routing code, wherein the HPLMN indicates the network to which the second device belongs, and the routing code indicates a second network element for storing a network configuration file for the second device. The first network element obtains the network configuration file of the second device from the second network element of the network to which the second device belongs based on the second routing identifier and the second device identifier. In some embodiments, the first network element verifies the operation authority of the third operation request and the third response message based on the network configuration information. The verification process is the same as the verification method for verifying the first operation request and the first response message in the aforementioned embodiment, and is not further described here.

[0264] It's important to note that the roaming policy instructs the home network on how to generate and transmit the network configuration file. The logic for returning to the home UDM remains the same: the home UDM is found based on the routing identifier, and the network configuration file is found based on the device identifier. Because the routing identifier contains the PLMN and routing code, in roaming scenarios, the PLMN in the routing identifier differs from the PLMN of the visited network. Therefore, the TMF of the visited network can use this routing identifier to locate the UDM of the roaming destination.

[0265] S604: The first network element sends a fourth operation request to the second device through the RAN.

[0266] S605: The first device sends a third response message to the first network element through the RAN.

[0267] S606: The first network element addresses the second network element from the network to which the second device belongs.

[0268] S607: The first network element sends a fourth response message to the NEF.

[0269] S608: The NEF sends a fourth response message to the first AF.

[0270] A second response message is received from the NEF, the second response message including the device identifier of the first device. Based on this, the first AF sends a first operation request for managing the first device. Upon receiving the second response message from the NEF, the operation request for the first device is successfully responded to by the first device. In some examples, the first operation request may be a first inventory operation.

[0271] Based on the same inventive concept as the aforementioned embodiment, refer to Figure 7, which shows a flow chart of another control method provided in an embodiment of the present application. As shown in Figure 7, taking the second network element being AAA as an example, the method has the same principle as described in Figure 2 in the aforementioned embodiment, and will not be repeated here.

[0272] In some embodiments, referring to FIG8 , which shows a flow chart of a roaming network authority control method provided by an embodiment of the present application, as shown in FIG8 , taking an inventory request when an operation request is made and an inventory response when a response message is made, the first network element is TMF, and the second network element is UDM or AAA as an example, the method includes S801-S808, wherein

[0273] S801: AF sends an inventory request to NEF;

[0274] S802: NEF sends inventory request to TMF

[0275] S803: TMF sends an inventory request to Device via RAN;

[0276] S804: The first device determines whether to respond to the inventory request based on the matching rules of the HPLMN and VPLMN with the PLMN;

[0277] In some embodiments, the operating parameter includes a current network PLMN, and the operating parameter satisfies a first preset condition, including: the PLMN successfully matches the HPLMN and the VPLMN included in the device configuration file.

[0278] It should be noted that the first device can verify the PLMN in the operation parameters according to the HPLMN and VPLMN included in the device configuration file. If the PLMN verification is successful, it means that the PLMN successfully matches the HPLMN and VPLMN included in the device configuration file and can respond to the second operation request.

[0279] In some embodiments, a successful match between the PLMN and the HPLMN and VPLMN included in the device configuration file may include: the PLMN is the same as the HPLMN; or the PLMN is different from the HPLMN and is the same as any VPLMN; or the PLMN is different from the HPLMN and the VPLMN list is empty; or the PLMN is different from the HPLMN, the MCC in any VPLMN is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty. When the first device verifies the operation parameter PLMN in the second operation request, it obtains the current network PLMN carried in the second operation request and uses the network HPLMN and the roaming network list VPLMN included in the network configuration file. The network HPLMN and the roaming network list VPLMN are a type of operation permission information. The HPLMN and VPLMN are used to verify the PLMN. When the verification is successful, the PLMN successfully matches the HPLMN and VPLMN included in the device configuration file.

[0280] S805: The first device sends an inventory response to the TMF via the RAN;

[0281] S806: TMF verifies the legitimacy of the device based on the HPLMN and VPLMN in the network configuration file;

[0282] In some embodiments, the roaming network VPLMN uses the operation authority information in the network configuration file to verify the first response message, including: the PLMN is the same as the HPLMN, and the first response message passes the verification; or, the PLMN is different from the HPLMN and the same as any VPLMN, and the first response message passes the verification; or the PLMN is different from the HPLMN and the VPLMN list is empty, and the first response message passes the verification; or, the PLMN is different from the HPLMN, the MCC in any VPLMN is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty, and the first response message passes the verification.

[0283] It should be noted that when the first network element verifies the first response message, it obtains the current network PLMN carried in the first operation request, and uses the network HPLMN and the network list VPLMN that can roam included in the network configuration file. The network HPLMN and the network list VPLMN that can roam are a kind of operation authority information. The HPLMN and VPLMN are used to verify the PLMN, and when the verification is successful, a second response message is sent to the first AF.

[0284] S807: TMF sends an inventory response to NEF;

[0285] S808: NEF sends an inventory response to AF.

[0286] In some embodiments, when a device is signed up and activated, the networks it is allowed to roam on can be set, thereby implementing a passive ambient terminal roaming policy. PLMN information does not need to be sent from the terminal to the network during inventory responses, thereby reducing information transmission and improving inventory efficiency. The device identifier can be independent of the Ambient IoT network and does not need to carry network attributes. The network does not rely on the device identifier or routing information sent by the device to address the UDM, thereby enabling the enterprise to independently assign device identifiers based on needs. The first device does not need to send a routing identifier; the routing identifier can be determined based on the AF identifier or operational parameters, which reduces the length of information sent by the device and improves inventory efficiency. The device identifier does not need to include routing information (existing IMSI and MSISDN can allocate and address UDMs based on number segments). The device does not need to send routing information for addressing the UDM (existing SUCI sent by the UE includes PLMN and RI routing indicators), thereby reducing the length of the device identifier. The AF carries routing information when calling the API, and the UDM opens a configuration interface to the AF.

[0287] Based on the same inventive concept as the aforementioned embodiment, see Figure 9, which shows a schematic diagram of the composition structure of a network element device provided in an embodiment of the present application. In one example, the network element device can be used to implement the functions implemented by the network element device in the core network of any of the control methods in the aforementioned embodiments. Specifically, the network element device may include:

[0288] The receiving unit 901 is configured to receive a first operation request from a first application unit AF, where the first operation request includes at least one of the following: an AF identifier, a routing identifier, and an operation parameter;

[0289] The sending unit 902 is configured to send a second operation request to the first device, where the second operation request includes an operation parameter;

[0290] The processing unit 903 is configured to determine a network profile from the second network element according to the first operation request; receive a first response message from the first device, verify the first response message using the network profile, and send a second response message to the first AF when the verification is successful.

[0291] In some embodiments, the first operation request includes a routing identifier, and the processing unit 903 is specifically configured to determine the second network element based on the routing identifier, send the device identifier in the operation parameters to the second network element; and receive the operation permission information in the network configuration file determined by the second network element based on the device identifier.

[0292] In some embodiments, the sending unit 902 is specifically configured to verify the first operation request using the operation permission information in the network configuration file, and send the second operation request to the first device when the verification is successful.

[0293] In some embodiments, the sending unit 902 is specifically configured to verify the AF identifier carried in the first operation request using the AF identifier list of allowed operations in the network configuration file, and send the second operation request to the first device when the verification is successful.

[0294] In some embodiments, the first response message includes a device identifier of the first device; the processing unit 903 is specifically configured to use the device identifier information in the network configuration file to verify the device identifier carried by the first response message, and use the operation permission information in the network configuration file to verify the first response message, and send a second response message to the first AF when the verification is successful, and the second response includes the device identifier of the first device.

[0295] In some embodiments, the first operation request carries the current network PLMN, and the network profile includes the network HPLMN and the roaming network VPLMN of the first device. In some embodiments, the processing unit 903 is specifically configured so that the PLMN is the same as the HPLMN and the first response message passes the verification; or, the PLMN is different from the HPLMN and the same as any VPLMN, and the first response message passes the verification; or the PLMN is different from the HPLMN and the VPLMN list is empty, and the first response message passes the verification; or, the PLMN is different from the HPLMN, the MCC in any VPLMN is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty, and the first response message passes the verification.

[0296] In some embodiments, the processing unit 903 is further configured to receive a first activation request from the network open unit NEF, the first activation request including a device profile and activation parameters, and send a first inventory request and a second activation request to the first device, the first inventory request including the inventory parameters, the second activation request including the device profile and activation parameters, the device profile and activation parameters being used to activate the first device; and receive a first response message and a first activation response from the first device, and send the first activation response to the NEF.

[0297] In some embodiments, the first activation request includes at least one of the following: a device identifier, a routing identifier, and the processing unit 903 is further configured to determine the second network element based on the routing identifier, send the device identifier to the second network element; and receive operation permission information in the network configuration file determined by the second network element based on the device identifier.

[0298] In some embodiments, the sending unit 902 is specifically configured to verify the first activation request using the operation permission information in the network configuration file, and send the first inventory request and the second activation request to the first device when the verification is successful.

[0299] In some embodiments, the second activation request includes an AF identifier, and the sending unit 902 is specifically configured to verify the AF identifier carried in the first activation request using the list of AF identifiers allowed to operate in the network configuration file, and send the first inventory request and the second activation request to the first device when the verification is successful.

[0300] In some embodiments, the receiving unit 901 is specifically configured to receive a third operation request from the first AF, the third operation request including an AF identifier, a second routing identifier, a second device identifier and an operation parameter, and the second routing identifier and the second device identifier are obtained by the first AF from the second AF; the sending unit 902 is specifically configured to send a fourth operation request to the second device, the fourth operation request including the operation parameter; determine the network profile of the second device from the second network element of the home network of the second device according to the second routing identifier and the second device identifier; receive a third response message from the second device; verify the third response message using the network profile, and send a fourth response message to the first AF when the verification is successful.

[0301] In some embodiments, the receiving unit 901 is specifically configured to receive a first configuration request from a first AF, the first configuration request including an AF identifier, a device identifier, first auxiliary information and second auxiliary information, the first auxiliary information being used to select a matching second network element, and the second auxiliary information being used for the second network element to generate a network configuration file and a device configuration file; and determine the corresponding second network element based on the first auxiliary information, and send a second configuration request to the second network element, the second configuration request including an AF identifier, a device identifier, and the second auxiliary information; and receive a first configuration response from the second network element, the first configuration response including a network configuration file, a device configuration file and a routing identifier.

[0302] In some embodiments, the sending unit 902 is specifically configured to send a first activation request to the first network element based on the activation indication, where the first activation request includes an AF identifier, a device identifier, a device configuration file, a routing identifier, and activation parameters.

[0303] In some embodiments, the receiving unit 901 is further configured to send the network configuration file and the routing identifier to the first AF after receiving the first configuration response from the second network element.

[0304] In some embodiments, the processing unit 903 is specifically configured to generate a corresponding network configuration file and a device configuration file according to the device identification and the second auxiliary information, and the network configuration file and the device configuration file have a corresponding relationship.

[0305] In some embodiments, the receiving unit 901 is specifically configured to receive a third configuration request from the first AF, the third configuration request including an AF identifier, a second device identifier, a second network configuration file, third auxiliary information, and fourth auxiliary information, the third configuration request is used to configure the second device, the second device identifier and the second network configuration file are obtained by the first AF from the second AF, and the second AF is connected to the network to which the second device belongs; and determine the corresponding second network element based on the third auxiliary information, and send a fourth configuration request to the second network element, the second configuration request including the AF identifier, the second device identifier, the second network configuration file and the fourth auxiliary information.

[0306] In some embodiments, the receiving unit 901 is specifically configured to receive a second configuration request from the NEF, the second configuration request including an AF identifier, a device identifier and second auxiliary information; and generate a corresponding network configuration file and a device configuration file based on the device identifier and the second auxiliary information, the network configuration file and the device configuration file having a corresponding relationship; and save the network configuration file and assign a routing identifier corresponding to the network configuration file, the routing identifier is used to obtain the network configuration file in the second network element; and send a first configuration response to the NEF, the first configuration response including the network configuration file, the device configuration file and the routing identifier.

[0307] In some embodiments, the network configuration file and the device configuration file may be the same or different, and the network configuration file and the device configuration file include device identification, security parameters, and device capabilities.

[0308] In some embodiments, the network configuration file includes network control permissions, and the device configuration file includes device control permissions.

[0309] In some embodiments, the receiving unit 901 is specifically configured to receive a fourth configuration request from the NEF, the fourth configuration request including an AF identifier, a second device identifier, a second network configuration file and fourth auxiliary information; and update and save the second network configuration file according to the second device identifier and the fourth auxiliary information, and allocate a routing identifier corresponding to the second network configuration file, the routing identifier is used to obtain the network configuration file in the second network element; and the sending unit 902 is specifically configured to send a second configuration response to the NEF, the second configuration response including the updated network configuration file and the routing identifier.

[0310] In some embodiments, the sending unit 902 is further configured to send a second configuration response to the NEF, where the second configuration response includes a device configuration file and a routing identifier.

[0311] In some embodiments, the second auxiliary information includes the home network HPLMN and the roaming network VPLMN of the first device. The processing unit 903 is specifically configured to generate corresponding network configuration files and device configuration files according to the device identifier and the HPLMN and VPLMN.

[0312] In some embodiments, the second network element includes: a unified data management unit UDM or an authentication, authorization and accounting unit AAA.

[0313] In some embodiments, the sending unit 902 is specifically configured to generate a device identifier for the first device; and send a first configuration request to the NEF, the first configuration request including an AF identifier, a device identifier, first auxiliary information, second auxiliary information, an activation indication and activation parameters, the AF identifier, the device identifier, the first auxiliary information and the second auxiliary information are used by the NEF to configure the corresponding network configuration file, device configuration file and routing identifier for the device identifier, and the activation indication and activation parameters are used to instruct the NEF to activate the first device.

[0314] In some embodiments, the receiving unit 901 is specifically configured to receive a first activation response from the NEF, the first activation response including the network configuration file and the routing identifier; and save the device identifier, the network configuration file, and the routing identifier.

[0315] In some embodiments, the receiving unit 901 is specifically configured to obtain a second device identifier and a second device configuration file corresponding to the second device from the second AF, and the second AF accesses the network to which the second device belongs; and send a third configuration request to the NEF, the third configuration request including the AF identifier, the second device identifier, the second network configuration file, the third auxiliary information, and the fourth auxiliary information. The third configuration request is used to configure the second device, the third auxiliary information is used to select a matching second network element, and the fourth auxiliary information is used for the second network element to generate a network configuration file and a device configuration file.

[0316] In some embodiments, the receiving unit 901 is specifically configured to obtain a second device identifier and a second routing identifier corresponding to the second device from the second AF, where the second routing identifier is used to indicate that a network profile of the second device is determined in a second network element of the home network of the second device; the sending unit 902 is specifically configured to send a third operation request, where the third operation request includes the AF identifier, the second routing identifier, and the inventory parameters.

[0317] In some embodiments, the sending unit 902 is specifically configured to send a first operation request to the NEF, the first operation request including an AF identifier, a routing identifier, and inventory parameters, the AF identifier, routing identifier, and inventory parameters being used to obtain a network configuration file from the second network element; and receive a first response message from the NEF, the first response message including a first device identifier.

[0318] In some embodiments, the processing unit 903 is specifically configured to generate a corresponding network configuration file and a device configuration file according to the device identification and the second auxiliary information, and the network configuration file and the device configuration file have a corresponding relationship.

[0319] In some embodiments, the receiving unit 901 is specifically configured to receive a device configuration file from an NEF; and send a third activation request, where the third activation request includes an AF identifier, a device identifier, a device configuration file, a routing identifier, and activation parameters.

[0320] In some embodiments, the first configuration request includes a roaming policy, and the roaming policy indicates obtaining a network configuration file based on a second network element in a network to which the second device belongs.

[0321] In some embodiments, the receiving unit 901 is specifically configured to receive a second activation response from the NEF, where the second activation response includes a routing identifier; and save the device identifier and the routing identifier.

[0322] In some embodiments, the receiving unit 901 is specifically configured to receive a second operation request from the first network element, where the second operation request includes an operation parameter for the first device to determine whether to respond to the second operation request; and if the operation parameter meets a first preset condition, send a first response message to the first network element, where the first response message includes a device identifier of the first device.

[0323] In some embodiments, the receiving unit 901 is specifically configured to receive a first inventory request and a second activation request from a first network element, the first inventory request including inventory parameters, the inventory parameters being used to indicate characteristic information of the first inventory request, and being used by the first device to determine whether to respond to the first inventory request, the second activation request including a device configuration file and activation parameters, the device activation file and activation parameters being used to activate the first device; and if the operating parameters meet a first preset condition, activating the first device based on the activation parameters, saving the device configuration file, and sending a first response message and a first activation response to the first network element, the first response message including a device identifier of the first device.

[0324] In some embodiments, the processing unit 903 is specifically configured to successfully match the PLMN with the HPLMN and VPLMN included in the device configuration file.

[0325] In some embodiments, the PLMN successfully matches the HPLMN and VPLMN included in the device profile, and the processing unit 903 is specifically configured to: the PLMN is the same as the HPLMN; or the PLMN is different from the HPLMN and is the same as any VPLMN; or the PLMN is different from the HPLMN and the VPLMN list is empty; or the PLMN is different from the HPLMN, the MCC in any VPLMN is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty.

[0326] It is understood that in this embodiment, a "unit" can be a portion of a circuit, a portion of a processor, a portion of a program or software, etc., and can also be a module or a non-modular system. Furthermore, the various components in this embodiment can be integrated into a single processing unit, or each unit can exist physically separately, or two or more units can be integrated into a single unit. The aforementioned integrated units can be implemented in the form of hardware or software functional modules.

[0327] If the integrated unit is implemented as a software functional module and is not sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this embodiment, or the portion that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the method provided in this embodiment. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0328] Therefore, this embodiment provides a computer storage medium storing a paging program. When the paging program is executed by at least one processor, the steps of any one of the methods in the above embodiments are implemented.

[0329] Based on the composition of the above-mentioned network element device and the computer storage medium, refer to Figure 10, which shows a schematic diagram of the composition structure of a network element device provided in an embodiment of the present application. As shown in Figure 10, it may include: a processor 1001. Optionally, the network element device may also include a memory 1002 and / or a communication interface 1003. The various components are coupled together through a communication line 1004. It can be understood that the communication line 1004 is used to achieve connection and communication between these components. In addition to the data bus, the communication line 1004 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, various buses are marked as communication lines 1004 in Figure 10.

[0330] The processor 1001 is configured to execute the steps of any one of the methods described in the foregoing embodiments when running the computer program.

[0331] The memory 1002 is used to store computer programs that can be run on the processor 1001 .

[0332] The communication interface 1003 is used to receive and send signals when sending and receiving information with other external network elements.

[0333] It is understood that the memory 1002 in the embodiment of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDRSDRAM), enhanced synchronous DRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus random access memory (DRRAM). The memory 1002 of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0334] The processor 1001 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor 1001 or by software instructions. The above-mentioned processor 1001 may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of this application can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in conjunction with the embodiments of this application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, registers, etc. The storage medium is located in the memory 1002 , and the processor 1001 reads the information in the memory 1002 and completes the steps of the above method in combination with its hardware.

[0335] It is understood that the embodiments described herein may be implemented using hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit may be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions described herein, or a combination thereof.

[0336] For software implementation, the techniques described herein can be implemented by modules (e.g., procedures, functions, etc.) that perform the functions described herein. The software code can be stored in a memory and executed by a processor. The memory can be implemented in the processor or external to the processor.

[0337] Optionally, as another embodiment, the processor 1001 is further configured to execute the steps of the method in any one of the aforementioned embodiments when running the computer program.

[0338] In some embodiments, based on the composition of the above-mentioned network element device, an embodiment of the present application provides another network element device, which may include the network element device described in any one of the above-mentioned embodiments.

[0339] Optionally, the computer-executable instructions in this application may also be referred to as application code, which is not specifically limited in this application.

[0340] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as CPU0 and CPU1 in FIG10 .

[0341] It should be noted that Figure 10 is only an example of a network element device and does not limit the specific structure of the network element device. For example, the terminal device or network device may also include other functional modules.

[0342] An embodiment of the present application provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute any one of the methods provided in the aforementioned embodiments.

[0343] An embodiment of the present application provides a chip system, which may include a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the method provided in any one of the aforementioned embodiments is implemented.

[0344] It should be noted that, in this application, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0345] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments. The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments. The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments. The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A control method, characterized in that: Applied to a first network element, the method includes: receiving a first operation request from a first application unit AF, wherein the first operation request includes at least one of the following: an AF identifier, a routing identifier, and an operation parameter; Sending a second operation request to the first device, where the second operation request includes the operation parameter; receiving a first response message from the first device, and determining a network configuration file from a second network element according to the first operation request and the first response message; The first response message is verified using the network profile, and a second response message is sent to the first AF when the verification succeeds.

2. The method according to claim 1, characterized in that The first operation request includes the routing identifier, the first response message includes the device identifier of the first device, and determining the network configuration file from the second network element according to the first operation request and the first response message includes: Determine the second network element according to the routing identifier carried in the first operation request, and send the device identifier carried in the first response message to the second network element; Receive the operation authority information in the network configuration file determined by the second network element according to the device identifier.

3. The method according to claim 1 or 2, characterized in that The verifying the first response message by using the network configuration file, and sending a second response message to the first AF when the verification passes, includes: Use the device identification information in the network configuration file to verify the device identification carried by the first response message, and use the operation permission information in the network configuration file to verify the first response message, and send a second response message to the first AF when the verification is successful, where the second response includes the device identification of the first device.

4. The method according to claim 3, characterized in that The first operation request carries the current network PLMN, the network profile includes the HPLMN and the roaming network VPLMN of the first device, and the verifying the first response message using the operation permission information in the network profile includes: The PLMN is the same as the HPLMN, and the first response message passes verification; or, The PLMN is different from the HPLMN and is the same as any one of the VPLMNs, and the first response message passes verification; or The PLMN is different from the HPLMN, and the VPLMN list is empty, and the first response message passes the verification; or, The PLMN is different from the HPLMN, the MCC in any one of the VPLMNs is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty, and the first response message passes the verification.

5. The method according to any one of claims 1 to 3, characterized in that The determining a network configuration file from the second network element according to the first operation request includes: Determine the second network element according to the routing identifier, and send the device identifier in the operation parameter to the second network element; Receive the operation authority information in the network configuration file determined by the second network element according to the device identifier.

6. The method according to claim 5, characterized in that The sending the second operation request to the first device includes: The first operation request is verified using the operation permission information in the network configuration file, and the second operation request is sent to the first device when the verification passes.

7. The method according to claim 6, characterized in that The verifying the first operation request by using the network configuration file, and sending the second operation request to the first device when the verification passes, includes: The AF identifier carried in the first operation request is verified using the AF identifier list of allowed operations in the network configuration file, and the second operation request is sent to the first device when the verification is successful.

8. The method according to any one of claims 1 to 7, characterized in that The method further comprises: receiving a first activation request from a network opening element NEF, wherein the first activation request includes a device configuration file and activation parameters; Sending a first inventory request and a second activation request to a first device, where the second activation request includes a device configuration file and activation parameters, where the device configuration file and activation parameters are used to activate the first device; A first response message and a first activation response are received from the first device, and the first activation response is sent to the NEF.

9. The method according to claim 8, characterized in that The first activation request includes at least one of the following: a device identifier and a routing identifier. The method further includes: determining the second network element according to the routing identifier, and sending the device identifier to the second network element; Receive the operation authority information in the network configuration file determined by the second network element according to the device identifier.

10. The method according to claim 9, characterized in that The sending the first inventory request and the second activation request to the first device includes: The first activation request is verified using the operation permission information in the network configuration file, and a first inventory request and a second activation request are sent to the first device when the verification passes.

11. The method according to claim 10, characterized in that The second activation request includes an AF identifier, and the using the operation permission information in the network configuration file to verify the first activation request and sending the first inventory request and the second activation request to the first device when the verification is successful includes: The AF identifier carried in the first activation request is verified using the list of AF identifiers allowed to operate in the network configuration file, and the first inventory request and the second activation request are sent to the first device when the verification passes.

12. The method according to any one of claims 1 to 10, characterized in that The method further comprises: receiving a third operation request from the first AF, where the third operation request includes an AF identifier, a second routing identifier, a second device identifier, and an operation parameter, where the second routing identifier and the second device identifier are obtained by the first AF from the second AF; Sending a fourth operation request to the second device, where the fourth operation request includes the operation parameter; determining a network configuration file of the second device from a second network element of a home network of the second device according to the second routing identifier and the second device identifier; receiving a third response message from the second device; The third response message is verified using the network profile, and a fourth response message is sent to the first AF when the verification passes.

13. A control method, characterized in that: Applied to NEF, the method comprises: receiving a first configuration request from a first AF, where the first configuration request includes an AF identifier, a device identifier, first auxiliary information, and second auxiliary information, where the first auxiliary information is used to select a matching second network element, and the second auxiliary information is used by the second network element to generate a network configuration file and a device configuration file; Determine a corresponding second network element according to the first auxiliary information, and send a second configuration request to the second network element, where the second configuration request includes an AF identifier, a device identifier, and second auxiliary information; A first configuration response is received from the second network element, where the first configuration response includes the network configuration file, the device configuration file, and the routing identifier.

14. The method according to claim 13, characterized in that The first configuration request further includes an activation indication and activation parameters, and the method further includes: A first activation request is sent to the first network element based on the activation indication, where the first activation request includes an AF identifier, a device identifier, a device configuration file, a routing identifier, and activation parameters.

15. The method according to claim 13 or 14, characterized in that The method further comprises: After receiving the first configuration response from the second network element, the network configuration file and the routing identifier are sent to the first AF.

16. The method according to claim 13 or 15, characterized in that The method further comprises: A corresponding network configuration file and device configuration file are generated according to the device identification and the second auxiliary information, and the network configuration file and the device configuration file have a corresponding relationship.

17. The method according to any one of claims 13 to 16, characterized in that: The method further comprises: receiving a third configuration request from the first AF, where the third configuration request includes an AF identifier, a second device identifier, a second network configuration file, third auxiliary information, and fourth auxiliary information, where the third configuration request is used to configure the second device, where the second device identifier and the second network configuration file are obtained by the first AF from the second AF, and the second AF accesses a network to which the second device belongs; Determine the corresponding second network element according to the third auxiliary information, and send a fourth configuration request to the second network element, where the second configuration request includes an AF identifier, a second device identifier, a second network configuration file, and fourth auxiliary information.

18. A control method, characterized in that: Applied to a second network element, the method includes: receiving a second configuration request from the NEF, where the second configuration request includes an AF identifier, a device identifier, and second auxiliary information; Generate a corresponding network configuration file and a device configuration file according to the device identifier and the second auxiliary information, wherein the network configuration file and the device configuration file have a corresponding relationship; saving the network configuration file and allocating a routing identifier corresponding to the network configuration file, wherein the routing identifier is used to obtain the network configuration file in the second network element; A first configuration response is sent to the NEF, where the first configuration response includes the network configuration file, the device configuration file, and the routing identifier.

19. The method according to claim 18, characterized in that The network configuration file and the device configuration file may be the same or different, and the network configuration file and the device configuration file include device identification, security parameters, and device capabilities.

20. The method according to claim 18 or 19, characterized in that The network configuration file includes network control permissions, and the device configuration file includes device control permissions.

21. The method according to any one of claims 18 to 20, characterized in that The method further comprises: receiving a fourth configuration request from the NEF, the fourth configuration request including an AF identifier, a second device identifier, a second network configuration file, and fourth auxiliary information; updating and saving the second network configuration file according to the second device identifier and the fourth auxiliary information, and allocating a routing identifier corresponding to the second network configuration file, where the routing identifier is used to obtain the network configuration file in the second network element; A second configuration response is sent to the NEF, where the second configuration response includes the updated network configuration document and the routing identifier.

22. The method according to any one of claims 18 to 21, characterized in that The first configuration request includes a roaming policy, and the method further includes: A second configuration response is sent to the NEF, where the second configuration response includes the device configuration file and the routing identifier.

23. The method according to any one of claims 18 to 22, characterized in that The second auxiliary information includes the HPLMN and VPLMN of the first device, and generating the corresponding network configuration file and device configuration file according to the device identifier and the second auxiliary information includes: Generate corresponding network configuration files and device configuration files according to the device identifier, the HPLMN, and the VPLMN.

24. The method according to claim 18 or 23, characterized in that The second network element includes: a unified data management unit UDM or an authentication, authorization and accounting unit AAA.

25. A control method, characterized in that: Applied to the first AF, the method further includes: generating a device identifier for the first device; A first configuration request is sent to the NEF, where the first configuration request includes an AF identifier, a device identifier, first auxiliary information, second auxiliary information, an activation indication, and activation parameters. The AF identifier, device identifier, first auxiliary information, and second auxiliary information are used by the NEF to configure a corresponding network profile, device profile, and routing identifier for the device identifier. The activation indication and the activation parameters are used to instruct the NEF to activate the first device.

26. The method according to claim 25, characterized in that The method further comprises: receiving a first activation response from the NEF, where the first activation response includes the network configuration file and the routing identifier; The device identifier, the network configuration file, and the routing identifier are saved.

27. The method according to claim 25 or 26, characterized in that The method further comprises: Obtaining a second device identifier and a second device configuration file corresponding to the second device from the second AF, and the second AF accessing a network to which the second device belongs; A third configuration request is sent to the NEF, where the third configuration request includes an AF identifier, a second device identifier, a second network configuration file, third auxiliary information, and fourth auxiliary information. The third configuration request is used to configure the second device, and the third auxiliary information is used to select a matching second network element. The fourth auxiliary information is used for the second network element to generate a network configuration file and a device configuration file.

28. The method according to any one of claims 25 to 27, characterized in that The method further comprises: acquiring, from the second AF, a second device identifier and a second routing identifier corresponding to the second device, where the second routing identifier is used to indicate determining a network profile of the second device in a second network element of a home network of the second device; Send a third operation request, where the third operation request includes the AF identifier, the second routing identifier, and inventory parameters.

29. The method according to any one of claims 25 to 28, characterized in that The method further comprises: Sending a first operation request to the NEF, where the first operation request includes an AF identifier, a routing identifier, and inventory parameters, where the AF identifier, routing identifier, and inventory parameters are used to obtain a network configuration file from the second network element; A first response message is received from the NEF, where the first response message includes the device identifier of the first device.

30. The method according to any one of claims 25 to 29, characterized in that The method further comprises: A corresponding network configuration file and device configuration file are generated according to the device identification and the second auxiliary information, and the network configuration file and the device configuration file have a corresponding relationship.

31. The method according to any one of claims 25 to 30, characterized in that The method further comprises: receiving a device configuration file from the NEF; Send a third activation request, where the third activation request includes an AF identifier, a device identifier, a device configuration file, a routing identifier, and activation parameters.

32. The method according to any one of claims 25 to 31, characterized in that The first configuration request includes a roaming policy, where the roaming policy indicates obtaining a network configuration file based on a second network element in a network to which the second device belongs.

33. The method according to claim 32, characterized in that The method further comprises: receiving a second activation response from the NEF, where the second activation response includes the routing identifier; The device identifier and the routing identifier are saved.

34. A control method, characterized in that: Applied to a first device, the method includes: receiving a second operation request from the first network element, where the second operation request includes an operation parameter, for the first device to determine whether to respond to the second operation request; If the operating parameter meets the first preset condition, a first response message is sent to the first network element, where the first response message includes a device identifier of the first device.

35. The method according to claim 34, wherein The method further comprises: receiving a first inventory request and a second activation request from a first network element, where the first inventory request includes inventory parameters, where the inventory parameters are used to indicate characteristic information of the first inventory request and are used by the first device to determine whether to respond to the first inventory request; and the second activation request includes a device configuration file and activation parameters, where the device activation file and the activation parameters are used to activate the first device; If the operating parameters meet the first preset conditions, the first device is activated based on the activation parameters, the device configuration file is saved, and a first response message and a first activation response are sent to the first network element, where the first response message includes a device identifier of the first device.

36. The method according to claim 34 or 35, characterized in that The operating parameters include the current network PLMN, and the operating parameters meet the first preset condition, including: The PLMN successfully matches the HPLMN and VPLMN included in the device configuration file.

37. The method according to claim 36, wherein The PLMN successfully matches the HPLMN and VPLMN included in the device configuration file, including: The PLMN is the same as the HPLMN; or The PLMN is different from the HPLMN and is the same as any one of the VPLMNs; or The PLMN is different from the HPLMN, and the VPLMN list is empty; or, The PLMN is different from the HPLMN, the MCC in any one of the VPLMNs is the same as the MCC in the PLMN, and the MNC of the VPLMN is empty.

38. A core network element, characterized in that: The core network elements include: Transceiver, used for sending and receiving signals; a memory for storing computer program instructions; A processor, configured to execute the computer program instructions to support the network device in implementing the method according to any one of claims 1-12 or 13-17 or 18-24 or 25-33.

39. A user equipment, characterized in that The terminal device includes: Transceiver, used for sending and receiving signals; a memory for storing computer program instructions; A processor, configured to execute the computer program instructions to support the terminal device in implementing the method as described in any one of claims 34-37.

40. A communication system, characterized in that: The communication system includes a terminal device and a network device, the terminal device and the network device are communicatively connected, and the communication system is used to implement the method as described in any one of claims 1-12 or 13-17 or 18-24 or 25-33 or 34-37.

41. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when executed by a processing circuit, implement the method according to any one of claims 1 to 12, 13 to 17, 18 to 24, 25 to 33, or 34 to 37.

42. A computer program product comprising instructions, characterized in that When the computer program product is run on a computer, the computer is caused to perform the method according to any one of claims 1 to 12, 13 to 17, 18 to 24, 25 to 33, or 34 to 37.

43. A chip system, characterized in that: The chip system includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the method as described in any one of claims 1-12 or 13-17 or 18-24 or 25-33 or 34-37 is implemented.

Citation Information

Patent Citations

  • Communication method, device and system

    CN116528216A

  • Communication method and device

    CN117528476A

  • Mobility management method for terminal, apparatus, and device

    WO2023143168A1