Communication method, device, and storage medium
By introducing an information interaction mechanism between the first and second network elements into environmental IoT devices, service requests are ensured to be made under authorized conditions, thus solving the communication security problem of battery-free devices and improving the security and reliability of the system.
Patent Information
- Application Number
- PCT/CN2024/092471
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-10
- Publication Date
- 2025-11-13
AI Technical Summary
Environmental IoT devices, lacking batteries or with limited energy storage, face challenges in effectively managing the security of their communication with base stations using existing technologies. Vulnerabilities exist, particularly in the authorization of intermediate nodes, leading to potential attack risks.
After receiving a request through the first network element, information on whether the terminal is authorized to provide services is obtained, ensuring that service requests are made only when authorized. By utilizing the information exchange between the first and second network elements, the authorization status of the terminal is determined, thereby improving system security.
It improves the security of environmental IoT device systems, prevents unauthorized terminals from providing services, and enhances the reliability and security of communication.
Smart Images

Figure CN2024092471_13112025_PF_FP_ABST
Abstract
Description
Communication methods, devices and storage media Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a communication method, device and storage medium. Background Technology
[0002] An ambient power-enabled IoT device is an IoT device that has no battery or only limited energy storage capacity (i.e., uses capacitors). The ambient IoT device communicates bidirectionally with an intermediate node located between the ambient IoT device and the base station, with the intermediate node transmitting information between the base station and the ambient IoT device.
[0003] Summary of the Invention
[0004] This disclosure provides a communication method, device, and storage medium.
[0005] According to a first aspect of the embodiments of this disclosure, a communication method is provided, executed by a first network element, the method comprising:
[0006] Receive a first request, the first request being used to request the terminal to provide a first service;
[0007] The first information is obtained according to the first request, and the first information is used to indicate whether the terminal is authorized to provide the first service.
[0008] According to a second aspect of the embodiments of this disclosure, a communication method is provided, executed by a second network element, the method comprising:
[0009] Send first information to the first network element, the first information being used to indicate whether the terminal is authorized to provide the first service.
[0010] According to a third aspect of the embodiments of this disclosure, a first network element is proposed, comprising:
[0011] The transceiver module is configured to receive a first request, which is used to request the terminal to provide a first service;
[0012] The transceiver module is further configured to obtain first information based on the first request, wherein the first information is used to indicate whether the terminal is authorized to provide the first service.
[0013] According to a fourth aspect of the embodiments of this disclosure, a second network element is proposed, comprising:
[0014] The transceiver module is configured to send first information to the first network element, the first information being used to indicate whether the terminal is authorized to provide the first service.
[0015] According to a fifth aspect of the present disclosure, a core network device is provided, including a first network element and a second network element, wherein the first network element is configured to implement the communication method described in the first aspect; and the second network element is configured to implement the communication method described in the second aspect.
[0016] According to a sixth aspect of the present disclosure, a storage medium is provided that stores instructions that, when executed on a core network device, cause the core network device to perform the method as described in an optional implementation of the first or second aspect.
[0017] The technical solution provided in this disclosure can produce the following beneficial effects: receiving a first request, the first request being used to request a terminal to provide a first service; obtaining first information according to the first request, the first information being used to indicate whether the terminal is authorized to provide the first service. That is, when the first network element receives the first request to request the terminal to provide the first service, it first determines whether the terminal is authorized to provide the first service, and if the terminal is authorized, requests the terminal to provide the first service. This can improve the security of the system.
[0018] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.
[0020] Figure 1A is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
[0021] Figure 1B is a schematic diagram of a topology according to an embodiment of the present disclosure.
[0022] Figure 2A is one of the interactive schematic diagrams of a communication method according to an embodiment of the present disclosure.
[0023] Figure 2B is a second interactive schematic diagram of a communication method according to an embodiment of the present disclosure.
[0024] Figure 3A is a schematic flowchart illustrating one of the communication methods according to an embodiment of the present disclosure.
[0025] Figure 3B is a second schematic flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0026] Figure 3C is a third schematic flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0027] Figure 3D is a fourth schematic flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0028] Figure 3E is a fifth schematic flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0029] Figure 3F is a schematic flowchart of a communication method according to an embodiment of the present disclosure.
[0030] Figure 4A is a schematic flowchart of a communication method according to an embodiment of the present disclosure.
[0031] Figure 4B is a schematic flowchart of a communication method according to an embodiment of the present disclosure.
[0032] Figure 4C is a schematic flowchart of a communication method according to an embodiment of the present disclosure.
[0033] Figure 4D is a schematic flowchart of a communication method according to an embodiment of the present disclosure.
[0034] Figure 4E is an eleventh schematic flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0035] Figure 5 is a third interactive schematic diagram of a communication method according to an embodiment of the present disclosure.
[0036] Figure 6A is a fourth interactive schematic diagram of a communication method according to an embodiment of the present disclosure.
[0037] Figure 6B is a fifth interactive schematic diagram of a communication method according to an embodiment of the present disclosure.
[0038] Figure 7A is a schematic diagram of the structure of a first network element proposed in an embodiment of this disclosure.
[0039] Figure 7B is a schematic diagram of the structure of a second network element proposed in an embodiment of this disclosure.
[0040] Figure 8A is a schematic diagram of the structure of the communication device proposed in an embodiment of this disclosure.
[0041] Figure 8B is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. Detailed Implementation
[0042] This disclosure provides a communication method, device, and storage medium.
[0043] In a first aspect, embodiments of this disclosure propose a communication method executed by a first network element, the method comprising:
[0044] Receive a first request, the first request being used to request the terminal to provide a first service;
[0045] The first information is obtained according to the first request, and the first information is used to indicate whether the terminal is authorized to provide the first service.
[0046] In the above embodiments, when the first network element receives a first request for the terminal to provide a first service, it first determines whether the terminal is authorized to provide the first service. If the terminal is authorized, it requests the terminal to provide the first service. This can improve the security of the system.
[0047] In conjunction with some embodiments of the first aspect, in some embodiments, the first request includes at least one of the following:
[0048] Service identifier;
[0049] The first identifier is the identifier of the terminal;
[0050] The second identifier is the identifier for environmental IoT devices;
[0051] First area.
[0052] In the above embodiments, the first request may include at least one of a service identifier, a first identifier, a second identifier, and a first region, making the way to request the first service more flexible.
[0053] In conjunction with some embodiments of the first aspect, in some embodiments, the first information includes at least one of the following:
[0054] Authorization information, wherein the authorization information is used to determine whether the terminal is authorized to provide the first service;
[0055] The authorization result includes whether the terminal is authorized to provide the first service or whether the terminal is not authorized to provide the first service;
[0056] The location information of the terminal;
[0057] The mapping result includes the user permanent identifier SUPI corresponding to the first identifier.
[0058] In the above embodiments, the first network element can obtain at least one of the following: authorization information, authorization result, terminal location information, and mapping result, to determine whether the terminal is authorized to provide the first service, making the method of judging the authorization status of the terminal more flexible.
[0059] In conjunction with some embodiments of the first aspect, in some embodiments, obtaining the first information according to the first request includes:
[0060] A second request is sent to the second network element according to the first request. The second request is used to obtain second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0061] Receive the second information sent by the second network element.
[0062] In the above embodiments, the first network element obtains second information by sending a second request to the second network element, which is used to determine whether the terminal is authorized to provide the first service.
[0063] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0064] The authorization result is determined based on the second information.
[0065] In the above embodiments, the first network element can determine the authorization result of the terminal based on the authorization information and / or the location information of the terminal.
[0066] In conjunction with some embodiments of the first aspect, in some embodiments, the authorization information includes at least one of the following:
[0067] Service information, including the IoT services authorized for the terminal in the environment;
[0068] Regional information, including the IoT service area authorized for the terminal;
[0069] Device information, which includes the IoT service device authorized by the terminal.
[0070] In the above embodiments, the authorization information may include at least one of service information, region information, and device information, thereby making the determination of the authorization result more flexible.
[0071] In conjunction with some embodiments of the first aspect, in some embodiments, determining the authorization result based on the second information includes at least one of the following:
[0072] The service information includes the service corresponding to the service identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0073] The region information includes the first region, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0074] The area information includes the first area, and the terminal is located within the first area, so the authorization result is determined to be that the terminal is authorized to provide the first service;
[0075] The device information includes the environmental IoT device corresponding to the second identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service.
[0076] In the above embodiments, the accuracy of the authorization result is improved by comparing the first request and the authorization information to determine the authorization result.
[0077] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0078] The location information is used to determine whether the terminal is located within the first area.
[0079] In conjunction with some embodiments of the first aspect, in some embodiments, obtaining the first information according to the first request includes:
[0080] A third request is sent to the second network element according to the first request, the third request being used to obtain the authorization result;
[0081] The authorization result sent by the second network element is received. The authorization result is determined by the second network element based on the second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0082] In the above embodiments, the first network element obtains the authorization result by sending a third request to the second network element, which is used to determine whether the terminal is authorized to provide the first service.
[0083] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0084] The terminal is authorized to provide the first service and sends a fourth request to the second network element, the fourth request being used to request the second network element to perform identifier mapping;
[0085] Receive the mapping result sent by the second network element.
[0086] In the above embodiment, the first network element obtains the mapping result by sending a fourth request to the second network element.
[0087] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0088] Based on the first information, it is determined that the terminal is authorized to provide the first service;
[0089] A fifth request is sent to the terminal, the fifth request being used to request the terminal to provide the first service.
[0090] In the above embodiments, after determining that the terminal is authorized to provide the first service, the first network element requests the first service from the terminal.
[0091] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0092] Based on the first information, it is determined that the terminal is not authorized to provide the first service;
[0093] Send a first message, which indicates that the terminal is not authorized to provide the first service.
[0094] In the above embodiments, after determining that the terminal is not authorized to provide the first service, the first network element sends a first message to inform that it cannot request the first service.
[0095] In conjunction with some embodiments of the first aspect, in some embodiments, the second network element includes at least one of the following: Unified Data Management (UDM) and Unified Data Storage (UDR).
[0096] In conjunction with some embodiments of the first aspect, in some embodiments, the first network element includes at least one of the following: an environmental Internet of Things function (AIoTF) and an access and mobility management function (AMF).
[0097] Secondly, this disclosure provides a communication method executed by a second network element, the method comprising:
[0098] Send first information to the first network element, the first information being used to indicate whether the terminal is authorized to provide the first service.
[0099] In conjunction with some embodiments of the second aspect, in some embodiments, the first information includes at least one of the following:
[0100] Authorization information, wherein the authorization information is used to determine whether the terminal is authorized to provide the first service;
[0101] The authorization result includes whether the terminal is authorized to provide the first service or whether the terminal is not authorized to provide the first service;
[0102] The location information of the terminal;
[0103] The mapping result includes a user permanent identifier (SUPI) corresponding to a first identifier, where the first identifier is the identifier of the terminal.
[0104] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0105] The system receives a second request sent by the first network element based on a first request. The first request is used to request the terminal to provide the first service, and the second request is used to obtain second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0106] In conjunction with some embodiments of the second aspect, in some embodiments, the authorization information includes at least one of the following:
[0107] Service information, including the IoT services authorized for the terminal in the environment;
[0108] Regional information, including the IoT service area authorized for the terminal;
[0109] Device information, which includes the IoT service device authorized by the terminal.
[0110] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0111] A sixth request is sent to a third network element, the sixth request being used to obtain the location information of the terminal;
[0112] Receive the location information of the terminal sent by the third network element.
[0113] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0114] The system receives a third request sent by the first network element in accordance with the first request. The first request is used to request the terminal to provide the first service, and the third request is used to obtain the authorization result.
[0115] In conjunction with some embodiments of the second aspect, in some embodiments, the first request includes at least one of the following:
[0116] Service identifier;
[0117] The first identifier;
[0118] The second identifier is the identifier for environmental IoT devices;
[0119] First area.
[0120] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0121] The authorization result is determined based on the second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0122] In conjunction with some embodiments of the second aspect, in some embodiments, determining the authorization result based on the second information includes at least one of the following:
[0123] The service information includes the service corresponding to the service identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0124] The region information includes the first region, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0125] The area information includes the first area, and the terminal is located within the first area, so the authorization result is determined to be that the terminal is authorized to provide the first service;
[0126] The device information includes the environmental IoT device corresponding to the second identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service.
[0127] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0128] The location information is used to determine whether the terminal is located within the first area.
[0129] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0130] Receive the fourth request sent by the first network element;
[0131] Perform identifier mapping according to the fourth request;
[0132] The mapping result is sent to the first network element.
[0133] In conjunction with some embodiments of the second aspect, in some embodiments, the first network element includes at least one of the following: an environmental Internet of Things function (AIoTF) and an access and mobility management function (AMF).
[0134] In conjunction with some embodiments of the second aspect, in some embodiments, the second network element includes at least one of the following: Unified Data Management (UDM) and Unified Data Storage (UDR).
[0135] Thirdly, embodiments of this disclosure propose a first network element, which may include at least one of a transceiver module and a processing module; wherein the first network element may be used to execute the optional implementation of the first aspect.
[0136] Fourthly, embodiments of this disclosure propose a second network element, which may include at least one of a transceiver module and a processing module; wherein the second network element may be used to execute the optional implementation of the second aspect.
[0137] Fifthly, embodiments of this disclosure provide a core network device, which may include: a first network element and a second network element; wherein the first network element is configured to perform the method described in the optional implementation of the first aspect, and the second network element is configured to perform the method described in the optional implementation of the second aspect.
[0138] In a sixth aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a core network device, cause the core network device to perform the method described in an optional implementation of the first or second aspect.
[0139] In a seventh aspect, embodiments of this disclosure provide a program product that, when executed by a core network device, causes the core network device to perform the method as described in an optional implementation of the first or second aspect.
[0140] Eighthly, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in an optional implementation of the first or second aspect.
[0141] In a ninth aspect, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described in optional implementations of the first or second aspect.
[0142] It is understood that the aforementioned first network element, second network element, core network equipment, storage medium, program product, computer program, chip, or chip system can all be used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0143] This disclosure provides a communication method, device, and storage medium. In some embodiments, the terms "information transmission method" and "information processing method," "communication method," etc., can be used interchangeably; the terms "information transmission device" and "information processing device," "communication device," "communication equipment," etc., can be used interchangeably; and the terms "information processing system," "communication system," etc., can be used interchangeably.
[0144] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0145] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0146] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0147] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0148] In some embodiments, "multiple" can refer to two or more.
[0149] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0150] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0151] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0152] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0153] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0154] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.
[0155] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0156] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “node,” “function,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.
[0157] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).
[0158] In some embodiments, the terms "Access Network Device (AN Device)," "Radio Access Network Device (RAN Device)," "Base Station (BS)," "Radio Base Station," "Fixed Station," "Node," "Access Point," "Transmission Point (TP)," "Reception Point (RP)," "Transmission / Reception Point (TRP)," "Panel," "Antenna Panel," "Antenna Array," "Cell," "Macro Cell," "Small Cell," "Femto Cell," "Pico Cell," "Sector," "Cell Group," "Serving Cell," "Carrier," "Component Carrier," and "Bandwidth Part (BWP)" can be used interchangeably.
[0159] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.
[0160] In some embodiments, access network devices, core network devices, or network devices can be replaced with terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced with communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel or direct channel, and uplink link, downlink, etc., can be replaced with sidelink link or direct link.
[0161] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
[0162] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0163] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0164] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0165] Figure 1A is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure. As shown in Figure 1A, the communication system 100 may include a terminal 101, a core network device 102, and an Internet of Things (IoT) device 103.
[0166] In some embodiments, terminal 101 may include at least one of the following: mobile phone, wearable device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home, but is not limited thereto.
[0167] In some embodiments, the access network device may be a node or device that connects a terminal device to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.
[0168] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0169] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some protocol layer functions are centrally controlled by the CU, while the remaining part or all protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0170] In some embodiments, the core network device 102 may be a single device, including a first network element 1021, a second network element 1022, a third network element 1023, a Network Exposure Function (NEF), an Application Function (AF), etc., or it may be multiple devices or a group of devices, each including all or part of the first network element 1021, the second network element 1022, the third network element 1023, NEF, AF, etc. Network elements may be virtual or physical. The core network may include, for example, at least one of the Evolved Packet Core (EPC), 5G Core Network (5GCN), 6G Core Network (6GCN), and Next Generation Core (NGC).
[0171] In some embodiments, the terms “network element”, “function”, “unit”, “entity”, “device”, “apparatus”, “element”, and “node” can be used interchangeably.
[0172] In some embodiments, the first network element 1021 is a network element with the function of managing environmental IoT services, such as an Ambient IoT Function (AIoTF), or a network element with the function of managing access and mobility, such as an Access and Mobility Management Function (AMF). The name is not limited to these, and it may also be other network elements that implement similar functions.
[0173] In some embodiments, the second network element 1022 may be, for example, a unified data management (UDM) or a unified data repository (UDR), but the name is not limited to these, and it may also be other network elements that implement similar functions.
[0174] In some embodiments, the third network element 1023 is, for example, an AMF, but the name is not limited thereto; it may also be other network elements that implement similar functions.
[0175] The IoT device 103 can be an environmental IoT device or any other IoT device.
[0176] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.
[0177] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1A, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1A are examples. The communication system may include all or some of the main bodies in FIG1A, or it may include other main bodies outside of FIG1A. The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is an example. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0178] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0179] In some embodiments of this disclosure, an ambient power-enabled IoT device is an IoT device that either has no battery or has limited energy storage capacity (i.e., uses capacitors), and the energy is provided by harvesting radio waves, light, motion, heat, or through any other available power source. Applications of ambient IoT include making supply chains more efficient and sustainable, preventing counterfeiting, and providing the data needed for advanced transportation and smart cities.
[0180] According to the study of TR 38.848[1], the topology connection of the environmental IoT network and devices can be topology 2. Figure 1B is a schematic diagram of a topology according to an embodiment of the present disclosure. As shown in Figure 1B, in topology 2, the environmental IoT device communicates bidirectionally with an intermediate node located between the device and the base station. In this topology, the intermediate node can be a repeater with environmental IoT functionality, an Integrated Access and Backhaul (IAB) node, a UE, a repeater, etc. The intermediate node transmits information between the base station and the environmental IoT device.
[0181] In some embodiments, according to the above topology, the Ambient Internet of Things (AIoT) device can transmit sensed data and report it to the core network (CN) or application server. Before transmitting the collected data, the UE, acting as an intermediary node, should be authorized. If authorization of the intermediary node is not supported, an attacker UE can act as an intermediary node and arbitrarily deny AIoT services.
[0182] Figure 2A is one of the interactive schematic diagrams of a communication method according to an embodiment of the present disclosure. The method can be executed by the aforementioned communication system. As shown in Figure 2A, the method may include:
[0183] Step S2101: AF sends a first request to the first network element.
[0184] In some embodiments, the first network element may receive a first request. For example, the first network element may receive a first request. As another example, the first network element may also receive a first request sent by another entity.
[0185] In some embodiments, the first request may be used to request the terminal to provide a first service.
[0186] In some embodiments, the first request may be an inventory request or a command request, and this disclosure does not limit the scope of the request.
[0187] In some embodiments, the first request may include at least one of the following:
[0188] Service identifier;
[0189] The first identifier is the identifier of the terminal;
[0190] The second identifier is the identifier for environmental IoT devices;
[0191] First area.
[0192] In some embodiments, a service identifier (service ID) can be used to indicate the service provided by the AF requesting terminal, and different service identifiers can correspond to different services.
[0193] In some embodiments, the first identifier may be a Generic Public Subscription Identifier (GPSI) or an application layer identifier, and this disclosure does not limit this.
[0194] In some embodiments, the first identifier may also be referred to as a "terminal identifier" or a "UE ID," and this disclosure does not limit this.
[0195] In some embodiments, the second identifier may be used to indicate the identifier of the IoT device in the environment for which the AF requests data or performs command actions.
[0196] In some embodiments, the first region may be used to indicate the region where the AF requests the terminal to provide services.
[0197] In some embodiments, the name of the first request is not limited, and may be, for example, "service request", "service instruction information", "information reporting instruction information", etc.
[0198] In some embodiments, the first service may be a service determined according to the first request. For example, the first service may be a service indicated by the service identifier, or a service corresponding to the first identifier, or a service corresponding to the second identifier, or a service corresponding to the first region.
[0199] In some embodiments, the first service may be a service in the Internet of Things (IoT) environment; for example, the first service may be a service that requests inventory. Alternatively, the first service may be a service that executes commands.
[0200] In some embodiments, the first network element may include at least one of the following: AIoTF, AMF.
[0201] In some embodiments, the AF may send the first request to the AIoTF.
[0202] In some embodiments, the AF may send the first request to the AMF.
[0203] In some embodiments, the AF can send a first request to the first network element through the NEF. For example, the AF can send a first request to the NEF, and after receiving the first request, the NEF will send the first request to the first network element.
[0204] In some embodiments, after receiving the first request from the AF, the NEF can determine whether the AF is authorized to request the first service based on the first request. If the NEF determines that the AF is authorized to request the first service, it sends the first request to the first network element; if the NEF determines that the AF is not authorized to request the first service, it does not send the first request to the first network element.
[0205] In some embodiments, if the NEF determines that the AF is not authorized to request the first service, it may send a second message to the AF indicating that the AF is not authorized to request the first service.
[0206] Step S2102: The first network element sends a second request to the second network element according to the first request.
[0207] In some embodiments, the second network element can receive a second request. For example, the second network element can receive a second request sent by the first network element. As another example, the second network element can also receive a second request sent by other entities.
[0208] In some embodiments, the second request may be used to obtain second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0209] In some embodiments, the location information of the terminal may be stored in the AMF or obtained and provided by the AMF.
[0210] In some embodiments, if the first network element is an AIoTF, the second information may include the authorization information and the location information of the terminal.
[0211] In some embodiments, if the first network element is an AMF, the second information may include authorization information, meaning that the AMF does not need to obtain the terminal's location information through the second network element.
[0212] In some embodiments, the authorization information may include at least one of the following:
[0213] Service information, which may include the IoT services authorized for the terminal in the environment;
[0214] Regional information, which may include the IoT service area authorized for the terminal;
[0215] Device information, which may include the IoT service device authorized by the terminal.
[0216] In some embodiments, the term "environmental IoT service device authorized by the terminal" can be understood as "an environmental IoT device for which the terminal has the authority to obtain data, or an environmental IoT device for which the terminal has the authority to manage, or an environmental IoT device for which the terminal has the authority to provide services".
[0217] In some embodiments, the authorization information of different terminals may be different. For example, the service information of different terminals may be different, the regional information of different terminals may be different, and the device information of different terminals may be different.
[0218] In some embodiments, the authorization information may be included in the terminal's subscription data.
[0219] In some embodiments, the authorization information may be stored in a second network element.
[0220] In some embodiments, the second request may be the same as or different from the first request. For example, the second request may also include first indication information for instructing the acquisition of the second information.
[0221] In some embodiments, the name of the second request is not limited, and may be, for example, "authorization information request", "authorization information reporting request", "information reporting instruction information", etc.
[0222] In some embodiments, the second network element may include at least one of the following: UDM, UDR.
[0223] In some embodiments, after receiving a first request from an AF, a first network element may send the second request to a second network element.
[0224] Step S2103: The second network element sends the second information to the first network element.
[0225] In some embodiments, the first network element can receive the second information. For example, the first network element can receive the second information sent by the second network element. As another example, the first network element can also receive the second information sent by other entities.
[0226] In some embodiments, if the first network element is an AMF (Application Function), meaning the second information includes the terminal's location information, then after receiving the second request, the second network element can obtain the terminal's location information based on the first identifier. The first network element can obtain the terminal's location information by extracting locally stored terminal location information, such as cell information, or by interacting with the terminal to obtain its accurate location, for example, by executing a positioning process.
[0227] In some embodiments, the second network element may send a sixth request to the third network element, the sixth request being used to obtain the location information of the terminal; and receive the location information of the terminal sent by the third network element. The third network element may obtain the terminal's location information by extracting locally stored terminal location information, such as cell information, or by interacting with the terminal to obtain the terminal's accurate location, for example, by executing a positioning process.
[0228] In some embodiments, the third network element may be an AMF.
[0229] In some embodiments, the sixth request may include the first identifier, or identifier information of other terminals.
[0230] In some embodiments, after receiving a sixth request from the second network element, the AMF can send the terminal's location information to the second network element according to the sixth request. The AMF can obtain the terminal's location information by extracting locally stored terminal location information, such as cell information, or by interacting with the terminal to obtain the terminal's accurate location, for example, by executing a positioning process.
[0231] In some embodiments, after receiving the terminal location information sent by the AMF, the second network element can send the location information and the authorization information of the terminal corresponding to the first identifier to the first network element.
[0232] Step S2104: The first network element determines the authorization result based on the second information.
[0233] In some embodiments, the first network element may determine the authorization result by at least one of the following:
[0234] The service information includes the service corresponding to the service identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0235] The region information includes the first region, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0236] The area information includes the first area, and the terminal is located within the first area, so the authorization result is determined to be that the terminal is authorized to provide the first service;
[0237] The device information includes the environmental IoT device corresponding to the second identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service.
[0238] In some embodiments, the first network element can determine the authorization result based on service information and service identifier. For example, if the service information contains the service corresponding to the service identifier, the authorization result is determined to be that the terminal is authorized to provide the first service; if the service information does not contain the service corresponding to the service identifier, the authorization result is determined to be that the terminal is not authorized to provide the first service.
[0239] In some embodiments, the first network element can determine the authorization result based on the area information and the first area. For example, if the area information includes the first area, the authorization result is determined to be that the terminal is authorized to provide the first service; if the area information does not include the first area, the authorization result is determined to be that the terminal is not authorized to provide the first service.
[0240] In some embodiments, determining that a terminal is authorized to provide a first service based on regional information and a first region can be understood as the terminal being authorized to provide services within the first region; determining that a terminal is not authorized to provide a first service based on regional information and a first region can be understood as the terminal not being authorized to provide services within the first region.
[0241] In some embodiments, the first network element may determine the authorization result based on the area information, the first area, and the terminal's location information. For example, if the area information includes the first area and the terminal is located within the first area, the authorization result is determined to be that the terminal is authorized to provide the first service; if the area information does not include the first area, or the terminal is not located within the first area, the authorization result is determined to be that the terminal is not authorized to provide the first service.
[0242] In some embodiments, the first network element may determine whether the terminal is located within the first area based on the location information.
[0243] In some embodiments, the first network element can determine the authorization result based on device information and a second identifier. For example, if the device information contains an environmental IoT device corresponding to the second identifier, the authorization result is determined to be that the terminal is authorized to provide the first service; if the device information does not contain an environmental IoT device corresponding to the second identifier, the authorization result is determined to be that the terminal is not authorized to provide the first service. The first network element can perform a mapping between device information and the second identifier. For example, if the device information corresponds to a set of identifier information for environmental IoT devices, the first network element can determine whether the device information contains an environmental IoT device corresponding to the second identifier by mapping the second identifier.
[0244] In some embodiments, the first network element may determine whether the terminal is authorized to provide the first service based on service information, area information, and device information.
[0245] Step S2105: The first network element determines that the terminal is authorized to provide the first service and sends a fourth request to the second network element.
[0246] In some embodiments, the second network element can receive a fourth request. For example, the second network element can receive a fourth request sent by the first network element. As another example, the second network element can also receive a fourth request sent by other entities.
[0247] In some embodiments, the fourth request can be used to request the second network element to perform an identifier mapping.
[0248] In some embodiments, the name of the fourth request is not limited, and may be, for example, "mapping result request", "identification mapping request", "identification mapping indication information", etc.
[0249] Step S2106: The second network element performs identifier mapping according to the fourth request.
[0250] In some embodiments, after receiving the fourth request sent by the first network element, the second network element may perform an identifier mapping to obtain a mapping result.
[0251] Step S2107: The second network element sends the mapping result to the first network element.
[0252] In some embodiments, the first network element can receive the mapping result. For example, the first network element can receive the mapping result sent by the second network element. As another example, the first network element can also receive the mapping result sent by other entities.
[0253] In some embodiments, the mapping result may include a Subscription Permanent Identifier (SUPI) corresponding to a first identifier, where the first identifier is the identifier of the terminal and the SUPI is a unique identifier of the terminal at the application layer.
[0254] In some embodiments, steps S2105 to S2107 can be omitted, and the second network element can send the mapping result while sending the second information to the first network element.
[0255] Step S2108: The first network element determines that the authorization result is that the terminal is authorized to provide the first service, and sends the fifth request to the terminal.
[0256] In some embodiments, the terminal may receive a fifth request. For example, the terminal may receive a fifth request sent by a first network element. As another example, the terminal may also receive a fifth request sent by other entities.
[0257] In some embodiments, the fifth request may be used to request the terminal to provide the first service.
[0258] In some embodiments, the fifth request may be an inventory request or a command request, and this disclosure does not limit the scope of the request.
[0259] In some embodiments, the fifth request may be the same as or different from the first request. For example, the fifth request may be a request determined based on the first request.
[0260] In some embodiments, if the first network element is an AIoTF, the first network element can send the fifth request to the terminal through the AMF. For example, the first network element can send the fifth request to the AMF, and after receiving the fifth request sent by the first network element, the AMF will send the fifth request to the terminal.
[0261] In some embodiments, if the first network element is an AMF, the first network element can directly send the fifth request to the terminal.
[0262] In some embodiments, after receiving a fifth request sent by a first network element, the terminal may provide a first service to the AF according to the fifth request.
[0263] In some embodiments, the implementation of the terminal providing the first service can refer to existing protocols, and will not be elaborated here.
[0264] In some embodiments, if the first network element determines that the authorization result is that the terminal is not authorized to provide the first service, then step S2108 can be omitted.
[0265] Step S2109: The first network element determines that the authorization result is that the terminal is not authorized to provide the first service, and sends the first message to the AF.
[0266] In some embodiments, the AF can receive a first message. For example, the AF can receive a first message sent by a first network element. As another example, the AF can also receive a first message sent by other entities.
[0267] In some embodiments, the name of the first message is not limited, and may be, for example, "authorization failure message", "service request failure message", "request response message", etc.
[0268] In some embodiments, after the first network element determines that the terminal is not authorized to provide the first service, it may send a first message to the AF to inform the AF that the terminal cannot provide the first service.
[0269] Using the above method, when the first network element receives a first request to request the terminal to provide the first service, it first obtains the second information, determines whether the terminal is authorized to provide the first service based on the second information, and requests the terminal to provide the first service if the terminal is authorized. This can improve the security of the system.
[0270] The methods involved in the embodiments of this disclosure may include at least one of the steps S2101 to S2109 described above. For example, step S2101 can be implemented as an independent embodiment, step S2103 can be implemented as an independent embodiment, step S2105 can be implemented as an independent embodiment, step S2107 can be implemented as an independent embodiment, step S2108 can be implemented as an independent embodiment, step S2109 can be implemented as an independent embodiment, step S2101 + step S2102 can be implemented as an independent embodiment, step S2103 + step S2104 can be implemented as an independent embodiment, and step S2105 + step S2106 + step S2107 can be implemented as an independent embodiment.
[0271] In some embodiments, the order of any two steps in steps S2101 to S2109 can be interchanged or they can be performed simultaneously.
[0272] In some embodiments, steps S2105 to S2107 are optional, and one or more of these steps may be omitted or substituted in different embodiments.
[0273] In some embodiments, other alternative implementations may be described before or after the specification corresponding to FIG2A.
[0274] Figure 2B is a second interactive schematic diagram of a communication method according to an embodiment of the present disclosure. This method can be executed by the aforementioned communication system. As shown in Figure 2B, the method may include:
[0275] Step S2201: AF sends a first request to the first network element.
[0276] The optional implementation of step S2201 can be found in the optional implementation of step S2101 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0277] Step S2202: The first network element sends a third request to the second network element according to the first request.
[0278] In some embodiments, the second network element can receive a third request. For example, the second network element can receive a third request sent by the first network element. As another example, the second network element can also receive a third request sent by other entities.
[0279] In some embodiments, the third request can be used to obtain an authorization result.
[0280] In some embodiments, the authorization result may include whether the terminal is authorized to provide the first service or whether the terminal is not authorized to provide the first service.
[0281] In some embodiments, the third request may be the same as or different from the first request. For example, the third request may also include second instruction information for instructing the acquisition of the authorization result.
[0282] In some embodiments, if the first network element is an AMF, the third request may include the location information of the terminal.
[0283] In some embodiments, the name of the third request is not limited, and may be, for example, "authorization result request", "authorization result reporting request", "information reporting instruction information", etc.
[0284] In some embodiments, after receiving the first request sent by the AF, the first network element may send the third request to the second network element.
[0285] Step S2203: The second network element determines the authorization result based on the second information.
[0286] In some embodiments, after receiving a third request from a first network element, the second network element can determine the authorization result based on the second information.
[0287] In some embodiments, the second network element determines the authorization result based on the second information, including at least one of the following:
[0288] The service information includes the service corresponding to the service identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0289] The region information includes the first region, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0290] The area information includes the first area, and the terminal is located within the first area, so the authorization result is determined to be that the terminal is authorized to provide the first service;
[0291] The device information includes the environmental IoT device corresponding to the second identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service.
[0292] In some embodiments, the second network element can determine whether the terminal is located in the first area based on the terminal's location information.
[0293] In some embodiments, if the first network element is an AMF, the second network element can determine the authorization result based on the authorization information and the terminal location information in the third request sent by the AMF.
[0294] In some embodiments, if the first network element is an AIoTF, the second network element can obtain the terminal's location information from the AMF and determine the authorization result based on the terminal's location information and authorization information.
[0295] It should be noted that the implementation method of determining the authorization result of the second network element can refer to step S2104, and will not be repeated here.
[0296] Step S2204: The second network element sends the authorization result to the first network element.
[0297] In some embodiments, the first network element can receive the authorization result. For example, the first network element can receive the authorization result sent by the second network element. As another example, the first network element can also receive the authorization result sent by other entities.
[0298] In some embodiments, after determining the authorization result of the terminal, the second network element can send the authorization result to the first network element.
[0299] Step S2205: The first network element determines that the terminal is authorized to provide the first service and sends a fourth request to the second network element.
[0300] The optional implementation of step S2205 can be found in the optional implementation of step S2105 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0301] Step S2206: The second network element performs identifier mapping according to the fourth request.
[0302] The optional implementation of step S2206 can be found in the optional implementation of step S2106 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0303] Step S2207: The second network element sends the mapping result to the first network element.
[0304] The optional implementation of step S2207 can be found in the optional implementation of step S2107 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0305] Step S2208: The first network element determines that the authorization result is that the terminal is authorized to provide the first service, and sends the fifth request to the terminal.
[0306] The optional implementation of step S2208 can be found in the optional implementation of step S2108 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0307] Step S2209: The first network element determines that the authorization result is that the terminal is not authorized to provide the first service, and sends the first message to the AF.
[0308] The optional implementation of step S2209 can be found in the optional implementation of step S2109 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0309] Using the above method, when the first network element receives a first request to request the terminal to provide the first service, it first obtains the authorization result of the terminal, determines whether the terminal is authorized to provide the first service based on the authorization result, and requests the terminal to provide the first service if the terminal is authorized. This can improve the security of the system.
[0310] The methods involved in the embodiments of this disclosure may include at least one of the steps S2201 to S2209 described above. For example, step S2201 can be implemented as an independent embodiment, step S2203 can be implemented as an independent embodiment, step S2204 can be implemented as an independent embodiment, step S2207 can be implemented as an independent embodiment, step S2208 can be implemented as an independent embodiment, step S2209 can be implemented as an independent embodiment, step S2201 + step S2202 can be implemented as an independent embodiment, step S2203 + step S2204 can be implemented as an independent embodiment, and step S2205 + step S2206 + step S2207 can be implemented as an independent embodiment.
[0311] In some embodiments, the order of any two steps in steps S2201 to S2209 can be interchanged or they can be performed simultaneously.
[0312] In some embodiments, steps S2205 to S2207 are optional, and one or more of these steps may be omitted or substituted in different embodiments.
[0313] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.
[0314] In some embodiments, “get,” “obtain,” “receive,” “transmit,” “bidirectional transmission,” and “send and / or receive” can be used interchangeably and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining through self-processing, or autonomous implementation, among other meanings.
[0315] In some embodiments, terms such as “send,” “transmit,” “report,” “distribute,” “transfer,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.
[0316] In some embodiments, terms such as "certain," "preset," "default," "set," "indicated," "a certain," "any," and "first" can be used interchangeably. "Certain A," "preset A," "default A," "set A," "indicated A," "a certain A," "any A," and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.
[0317] Figure 3A is a schematic flowchart illustrating one embodiment of a communication method according to this disclosure. As shown in Figure 3A, this disclosure relates to a communication method that can be executed by a first network element. The method may include:
[0318] Step S3101: Receive the first request.
[0319] The optional implementation of step S3101 can be found in the optional implementation of step S2101 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0320] In some embodiments, the first network element may receive a first request sent by the AF, but is not limited thereto; the first network element may also receive a first request sent by other entities.
[0321] Step S3102: Send the second request according to the first request.
[0322] The optional implementation of step S3102 can be found in the optional implementation of step S2102 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0323] In some embodiments, the first network element may send the second request to the second network element, but is not limited thereto; the first network element may also send the second request to other entities.
[0324] Step S3103: Receive the second information.
[0325] The optional implementation of step S3103 can be found in the optional implementation of step S2103 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0326] In some embodiments, the first network element may receive second information sent by the second network element, but is not limited thereto; the first network element may also receive second information sent by other entities.
[0327] Step S3104: Determine the authorization result based on the second information.
[0328] The optional implementation of step S3104 can be found in the optional implementation of step S2104 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0329] Step S3105: Determine that the terminal is authorized to provide the first service, and send the fourth request.
[0330] The optional implementation of step S3105 can be found in the optional implementation of step S2105 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0331] In some embodiments, the first network element may send the fourth request to the terminal, but is not limited thereto; the first network element may also send the fourth request to other entities.
[0332] Step S3106: Receive the mapping result.
[0333] The optional implementation of step S3106 can be found in the optional implementation of step S2107 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0334] In some embodiments, the first network element may receive the mapping result sent by the second network element, but is not limited thereto; the first network element may also receive the mapping result sent by other entities.
[0335] Step S3107: Determine that the authorization result is that the terminal is authorized to provide the first service, and send the fifth request.
[0336] The optional implementation of step S3107 can be found in the optional implementation of step S2108 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0337] In some embodiments, the first network element may send the fifth request to the terminal, but is not limited thereto; the first network element may also send the fifth request to other entities.
[0338] Step S3108: Determine that the authorization result is that the terminal is not authorized to provide the first service, and send the first message.
[0339] The optional implementation of step S3108 can be found in the optional implementation of step S2109 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0340] In some embodiments, the first network element may send the first message to the AF, but it is not limited thereto; the first network element may also send the first message to other entities.
[0341] The methods involved in the embodiments of this disclosure may include at least one of the steps S3101 to S3108 described above. For example, step S3101 can be implemented as an independent embodiment, step S3103 can be implemented as an independent embodiment, step S3105 can be implemented as an independent embodiment, step S3107 can be implemented as an independent embodiment, step S3108 can be implemented as an independent embodiment, step S3101 + step S3102 can be implemented as an independent embodiment, step S3103 + step S3104 can be implemented as an independent embodiment, and step S3105 + step S3106 can be implemented as an independent embodiment.
[0342] In some embodiments, the order of any two steps in steps S3101 to S3108 can be interchanged or they can be performed simultaneously.
[0343] In some embodiments, steps S3105 to S3106 are optional, and one or more of these steps may be omitted or substituted in different embodiments.
[0344] Figure 3B is a second schematic flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3B, this embodiment of the present disclosure relates to a communication method, which can be executed by a first network element. The method may include:
[0345] Step S3201: Receive the first request.
[0346] The optional implementation of step S3201 can be found in the optional implementation of step S2201 in Figure 2B, and other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0347] Step S3202: Send the third request according to the first request.
[0348] The optional implementation of step S3202 can be found in the optional implementation of step S2202 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0349] Step S3203: Receive the authorization result.
[0350] The optional implementation of step S3203 can be found in the optional implementation of step S2204 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0351] Step S3204: Determine that the terminal is authorized to provide the first service, and send the fourth request.
[0352] The optional implementation of step S3204 can be found in the optional implementation of step S2205 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0353] Step S3205: Receive the mapping result.
[0354] The optional implementation of step S3205 can be found in the optional implementation of step S2207 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0355] Step S3206: Determine the authorization result as the terminal is authorized to provide the first service, and send the fifth request.
[0356] The optional implementation of step S3206 can be found in the optional implementation of step S2208 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0357] Step S3207: Determine that the authorization result is that the terminal is not authorized to provide the first service, and send the first message.
[0358] The optional implementation of step S3207 can be found in the optional implementation of step S2209 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0359] The methods involved in the embodiments of this disclosure may include at least one of the steps S3201 to S3207 described above. For example, step S3201 can be implemented as an independent embodiment, step S3203 can be implemented as an independent embodiment, step S3204 can be implemented as an independent embodiment, step S3206 can be implemented as an independent embodiment, step S3207 can be implemented as an independent embodiment, step S3201 + step S3202 can be implemented as an independent embodiment, and step S3204 + step S3205 can be implemented as an independent embodiment.
[0360] In some embodiments, the order of any two steps in steps S3201 to S3207 can be interchanged or they can be performed simultaneously.
[0361] In some embodiments, steps S3204 to S3205 are optional, and one or more of these steps may be omitted or substituted in different embodiments.
[0362] Figure 3C is a third schematic flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3C, this embodiment of the present disclosure relates to a communication method, which can be executed by a first network element. The method may include:
[0363] Step S3301: Receive the first request.
[0364] The optional implementation of step S3301 can be found in step S2101 of Figure 2A, the optional implementation of step S3101 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0365] Step S3302: Send the second request according to the first request.
[0366] The optional implementation of step S3302 can be found in step S2102 of Figure 2A, the optional implementation of step S3102 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0367] Step S3303: Receive the second information.
[0368] The optional implementation of step S3303 can be found in step S2103 of Figure 2A, the optional implementation of step S3103 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0369] Step S3304: Determine the authorization result based on the second information.
[0370] The optional implementation of step S3304 can be found in step S2104 of Figure 2A, the optional implementation of step S3104 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0371] Step S3305: Determine the authorization result as the terminal is authorized to provide the first service, and send the fifth request.
[0372] The optional implementation of step S3305 can be found in the optional implementation of step S2108 in Figure 2A, step S3107 in Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0373] Step S3306: Determine that the authorization result is that the terminal is not authorized to provide the first service, and send the first message.
[0374] The optional implementation of step S3306 can be found in the optional implementation of step S2109 in Figure 2A, the optional implementation of step S3108 in Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0375] The methods involved in the embodiments of this disclosure may include at least one of the steps S3301 to S3306 described above. For example, step S3301 may be implemented as an independent embodiment, step S3305 may be implemented as an independent embodiment, step S3306 may be implemented as an independent embodiment, step S3301 + step S3302 may be implemented as an independent embodiment, and step S3303 + step S3304 may be implemented as an independent embodiment.
[0376] In some embodiments, the order of any two steps in steps S3301 to S3306 can be interchanged or they can be performed simultaneously.
[0377] In some embodiments, the above steps are all optional.
[0378] Figure 3D is a fourth schematic flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3D, this disclosure relates to a communication method that can be executed by a first network element. The method may include:
[0379] Step S3401: Receive the first request.
[0380] The optional implementation of step S3401 can be found in step S2201 of Figure 2B, the optional implementation of step S3201 of Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0381] Step S3402: Send the third request according to the first request.
[0382] The optional implementation of step S3402 can be found in step S2202 of Figure 2B, the optional implementation of step S3202 of Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0383] Step S3403: Receive authorization result.
[0384] The optional implementation of step S3403 can be found in step S2204 of Figure 2B, the optional implementation of step S3203 of Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0385] Step S3404: Determine the authorization result as the terminal is authorized to provide the first service, and send the fifth request.
[0386] The optional implementation of step S3404 can be found in the optional implementation of step S2208 in Figure 2B, step S3206 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0387] Step S3405: Determine that the authorization result is that the terminal is not authorized to provide the first service, and send the first message.
[0388] The optional implementation of step S3405 can be found in the optional implementation of step S2209 in Figure 2B, step S3207 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0389] The methods involved in the embodiments of this disclosure may include at least one of the steps S3401 to S3405 described above. For example, step S3401 may be implemented as a standalone embodiment, step S3404 may be implemented as a standalone embodiment, step S3405 may be implemented as a standalone embodiment, step S3401 + step S3402 may be implemented as a standalone embodiment, and step S3401 + step S3402 + step S3403 may be implemented as a standalone embodiment.
[0390] In some embodiments, the order of any two steps in steps S3401 to S3405 can be interchanged or they can be performed simultaneously.
[0391] In some embodiments, the above steps are all optional.
[0392] Figure 3E is a fifth schematic flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3E, this disclosure relates to a communication method that can be executed by a first network element. The method may include:
[0393] Step S3501: Receive the first request.
[0394] The optional implementation of step S3501 can be found in the optional implementation of step S2101 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0395] Step S3502: Obtain first information according to the first request.
[0396] The optional implementation of step S3502 can be found in the optional implementations of steps S2102 to S2103 in Figure 2A, steps S2202 to S2204 in Figure 2B, and other related parts in the embodiments involved in Figures 2A and 2B, which will not be repeated here.
[0397] In some embodiments, the first network element may send the first request to the second network element, but is not limited thereto; the first network element may also send the first request to other entities.
[0398] In some embodiments, the first network element may receive first information sent by the second network element, but is not limited thereto; the first network element may also receive first information sent by other entities.
[0399] In some embodiments, the first information may include at least one of the following:
[0400] Authorization information, wherein the authorization information is used to determine whether the terminal is authorized to provide the first service;
[0401] The authorization result includes whether the terminal is authorized to provide the first service or whether the terminal is not authorized to provide the first service;
[0402] The location information of the terminal;
[0403] The mapping result includes a user permanent identifier (SUPI) corresponding to a first identifier, where the first identifier is the identifier of the terminal.
[0404] In some embodiments, the first network element may send the first request to the second network element, and after receiving the first request, the second network element may send the first information to the first network element.
[0405] In some embodiments, the second network element may send the first information in accordance with the first request. For example, if the first request includes first indication information, the second network element may send authorization information and the location information of the terminal to the first network element. As another example, if the first request includes second indication information, the second network element may send an authorization result to the first network element.
[0406] In some embodiments, the second network element may send mapping results while sending authorization information and location information to the first network element.
[0407] In some embodiments, the second network element may send authorization information and location information, or authorization information, location information and mapping results, or authorization results to the first network element in accordance with the protocol or instructions from higher layers.
[0408] In some embodiments, if the first network element is an AIoTF, the second network element can send authorization information and location information to the first network element; if the first network element is an AMF, the second network element can send authorization information to the first network element, that is, it does not send location information.
[0409] In some embodiments, if the first information includes authorization information and location information, the first network element can determine the authorization result based on the authorization information and the location information.
[0410] Step S3503: Based on the first information, determine that the authorization result is that the terminal is authorized to provide the first service, and send the fifth request.
[0411] The optional implementation of step S3503 can be found in the optional implementation of step S2108 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0412] Step S3504: Based on the first information, determine that the authorization result is that the terminal is not authorized to provide the first service, and send the first message.
[0413] The optional implementation of step S3504 can be found in the optional implementation of step S2109 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0414] The methods involved in the embodiments of this disclosure may include at least one of the steps S3501 to S3504 described above. For example, step S3501 may be implemented as a separate embodiment, step S3503 may be implemented as a separate embodiment, step S3504 may be implemented as a separate embodiment, and step S3501 + step S3502 may be implemented as a separate embodiment.
[0415] In some embodiments, the order of any two steps in steps S3501 to S3504 can be interchanged or they can be performed simultaneously.
[0416] In some embodiments, the above steps are all optional.
[0417] Figure 3F is a sixth schematic flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3F, this disclosure relates to a communication method that can be executed by a first network element. The method may include:
[0418] Step S3601: Receive the first request.
[0419] The optional implementation of step S3601 can be found in the optional implementation of step S2101 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0420] Step S3602: Obtain first information according to the first request.
[0421] The optional implementation of step S3602 can be found in the optional implementations of steps S2102 to S2103 in Figure 2A, steps S2202 to S2204 in Figure 2B, and other related parts in the embodiments involved in Figures 2A and 2B, which will not be repeated here.
[0422] In some embodiments, the first request includes at least one of the following:
[0423] Service identifier;
[0424] The first identifier;
[0425] The second identifier is the identifier for environmental IoT devices;
[0426] First area.
[0427] In some embodiments, the first information includes at least one of the following:
[0428] Authorization information, wherein the authorization information is used to determine whether the terminal is authorized to provide the first service;
[0429] The authorization result includes whether the terminal is authorized to provide the first service or whether the terminal is not authorized to provide the first service;
[0430] The location information of the terminal;
[0431] The mapping result includes a user permanent identifier (SUPI) corresponding to a first identifier, where the first identifier is the identifier of the terminal.
[0432] In some embodiments, obtaining the first information according to the first request includes:
[0433] A second request is sent to the second network element according to the first request. The second request is used to obtain second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0434] Receive the second information sent by the second network element.
[0435] In some embodiments, the method further includes:
[0436] The authorization result is determined based on the second information.
[0437] In some embodiments, the authorization information includes at least one of the following:
[0438] Service information, including the IoT services authorized for the terminal in the environment;
[0439] Regional information, including the IoT service area authorized for the terminal;
[0440] Device information, which includes the IoT service device authorized by the terminal.
[0441] In some embodiments, determining the authorization result based on the second information includes at least one of the following:
[0442] The service information includes the service corresponding to the service identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0443] The region information includes the first region, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0444] The area information includes the first area, and the terminal is located within the first area, so the authorization result is determined to be that the terminal is authorized to provide the first service;
[0445] The device information includes the environmental IoT device corresponding to the second identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service.
[0446] In some embodiments, the method further includes:
[0447] The location information is used to determine whether the terminal is located within the first area.
[0448] In some embodiments, obtaining the first information according to the first request includes:
[0449] A third request is sent to the second network element according to the first request, the third request being used to obtain the authorization result;
[0450] The authorization result sent by the second network element is received. The authorization result is determined by the second network element based on the second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0451] In some embodiments, the method further includes:
[0452] The terminal is authorized to provide the first service and sends a fourth request to the second network element, the fourth request being used to request the second network element to perform identifier mapping;
[0453] Receive the mapping result sent by the second network element.
[0454] In some embodiments, the method further includes:
[0455] Based on the first information, it is determined that the terminal is authorized to provide the first service;
[0456] A fifth request is sent to the terminal, the fifth request being used to request the terminal to provide the first service.
[0457] In some embodiments, the method further includes:
[0458] Based on the first information, it is determined that the terminal is not authorized to provide the first service;
[0459] Send a first message, which indicates that the terminal is not authorized to provide the first service.
[0460] In some embodiments, the second network element includes at least one of the following: Unified Data Management (UDM) and Unified Data Storage (UDR).
[0461] In some embodiments, the first network element includes at least one of the following: Environmental Internet of Things Function (AIoTF) and Access and Mobility Management Function (AMF).
[0462] Figure 4A is a seventh schematic flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4A, this embodiment of the present disclosure relates to a communication method, which can be executed by a second network element. The method may include:
[0463] Step S4101: Receive the second request.
[0464] The optional implementation of step S4101 can be found in the optional implementation of step S2102 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0465] In some embodiments, the second network element may receive a second request sent by the first network element, but is not limited thereto; the second network element may also receive a second request sent by other entities.
[0466] Step S4102: Send the second message.
[0467] The optional implementation of step S4102 can be found in the optional implementation of step S2103 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0468] In some embodiments, the second network element may send the second information to the first network element, but is not limited thereto; the second network element may also send the second information to other entities.
[0469] Step S4103: Receive the fourth request.
[0470] The optional implementation of step S4103 can be found in the optional implementation of step S2105 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0471] Step S4104: Perform identifier mapping according to the fourth request.
[0472] The optional implementation of step S4104 can be found in the optional implementation of step S2106 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0473] Step S4105: Send the mapping result.
[0474] The optional implementation of step S4105 can be found in the optional implementation of step S2107 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0475] In some embodiments, the second network element may send the mapping result to the first network element, but is not limited thereto; the second network element may also send the mapping result to other entities.
[0476] The methods involved in the embodiments of this disclosure may include at least one of the steps S4101 to S4105 described above. For example, step S4101 may be implemented as a standalone embodiment, step S4102 may be implemented as a standalone embodiment, step S4101 + step S4102 may be implemented as a standalone embodiment, and step S4103 + step S4104 + step S4105 may be implemented as a standalone embodiment.
[0477] In some embodiments, the order of any two steps in steps S4101 to S4105 can be interchanged or they can be performed simultaneously.
[0478] In some embodiments, steps S4103 to S4105 are optional, and one or more of these steps may be omitted or substituted in different embodiments.
[0479] Figure 4B is a schematic flowchart of a communication method according to an embodiment of the present disclosure. As shown in Figure 4B, the present disclosure relates to a communication method that can be executed by a second network element. The method may include:
[0480] Step S4201: Receive the third request.
[0481] The optional implementation of step S4201 can be found in the optional implementation of step S2202 in Figure 2B, and other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0482] Step S4202: Determine the authorization result based on the second information.
[0483] The optional implementation of step S4202 can be found in the optional implementation of step S2203 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0484] Step S4203: Send the authorization result.
[0485] The optional implementation of step S4203 can be found in the optional implementation of step S2204 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0486] Step S4204: Receive the fourth request.
[0487] The optional implementation of step S4204 can be found in the optional implementation of step S2105 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0488] Step S4205: Perform identifier mapping according to the fourth request.
[0489] The optional implementation of step S4205 can be found in the optional implementation of step S2106 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0490] Step S4206: Send the mapping result.
[0491] The optional implementation of step S4206 can be found in the optional implementation of step S2107 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0492] The methods involved in the embodiments of this disclosure may include at least one of the steps S4201 to S4206 described above. For example, step S4201 may be implemented as a standalone embodiment, step S4202 may be implemented as a standalone embodiment, step S4201 + step S4202 + step S4203 may be implemented as a standalone embodiment, and step S4204 + step S4205 + step S4206 may be implemented as a standalone embodiment.
[0493] In some embodiments, the order of any two steps in steps S4201 to S4206 can be interchanged or they can be performed simultaneously.
[0494] In some embodiments, steps S4204 to S4206 are optional, and one or more of these steps may be omitted or substituted in different embodiments.
[0495] Figure 4C is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4C, this disclosure relates to a communication method that can be executed by a second network element. The method may include:
[0496] Step S4301: Receive the second request.
[0497] The optional implementation of step S4301 can be found in the optional implementation of step S2102 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0498] Step S4302: Send the second message.
[0499] The optional implementation of step S4302 can be found in the optional implementation of step S2103 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0500] In some embodiments, the above steps are all optional.
[0501] Figure 4D is a schematic flowchart of a communication method according to an embodiment of the present disclosure. As shown in Figure 4D, the present disclosure relates to a communication method that can be executed by a second network element. The method may include:
[0502] Step S4401: Receive the third request.
[0503] The optional implementation of step S4401 can be found in the optional implementation of step S2202 in Figure 2B, and other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0504] Step S4402: Determine the authorization result based on the second information.
[0505] The optional implementation of step S4402 can be found in the optional implementation of step S2203 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0506] Step S4403: Send the authorization result.
[0507] The optional implementation of step S4403 can be found in the optional implementation of step S2204 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.
[0508] In some embodiments, the above steps are all optional.
[0509] Figure 4E is an eleventh schematic flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4E, this disclosure relates to a communication method that can be executed by a second network element. The method may include:
[0510] Step S4501: Send the first message.
[0511] The optional implementation of step S4501 can be found in the optional implementation of step S2103 in Figure 2A, steps S2203 to S2204 in Figure 2B, and other related parts in the embodiments involved in Figures 2A and 2B, which will not be repeated here.
[0512] In some embodiments, the first information includes at least one of the following:
[0513] Authorization information, wherein the authorization information is used to determine whether the terminal is authorized to provide the first service;
[0514] The authorization result includes whether the terminal is authorized to provide the first service or whether the terminal is not authorized to provide the first service;
[0515] The location information of the terminal;
[0516] The mapping result includes a user permanent identifier (SUPI) corresponding to a first identifier, where the first identifier is the identifier of the terminal.
[0517] In some embodiments, the method further includes:
[0518] The system receives a second request sent by the first network element based on a first request. The first request is used to request the terminal to provide the first service, and the second request is used to obtain second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0519] In some embodiments, the authorization information includes at least one of the following:
[0520] Service information, including the IoT services authorized for the terminal in the environment;
[0521] Regional information, including the IoT service area authorized for the terminal;
[0522] Device information, which includes the IoT service device authorized by the terminal.
[0523] In some embodiments, the method further includes:
[0524] A sixth request is sent to a third network element, the sixth request being used to obtain the location information of the terminal;
[0525] Receive the location information of the terminal sent by the third network element.
[0526] In some embodiments, the method further includes:
[0527] The system receives a third request sent by the first network element in accordance with the first request. The first request is used to request the terminal to provide the first service, and the third request is used to obtain the authorization result.
[0528] In some embodiments, the first request includes at least one of the following:
[0529] Service identifier;
[0530] The first identifier;
[0531] The second identifier is the identifier for environmental IoT devices;
[0532] First area.
[0533] In some embodiments, the method further includes:
[0534] The authorization result is determined based on the second information, which includes at least one of the following: the authorization information and the location information of the terminal.
[0535] In some embodiments, determining the authorization result based on the second information includes at least one of the following:
[0536] The service information includes the service corresponding to the service identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0537] The region information includes the first region, and the authorization result is determined to be that the terminal is authorized to provide the first service;
[0538] The area information includes the first area, and the terminal is located within the first area, so the authorization result is determined to be that the terminal is authorized to provide the first service;
[0539] The device information includes the environmental IoT device corresponding to the second identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service.
[0540] In some embodiments, the method further includes:
[0541] The location information is used to determine whether the terminal is located within the first area.
[0542] In some embodiments, the method further includes:
[0543] Receive the fourth request sent by the first network element;
[0544] Perform identifier mapping according to the fourth request;
[0545] The mapping result is sent to the first network element.
[0546] In some embodiments, the first network element includes at least one of the following: Environmental Internet of Things Function (AIoTF) and Access and Mobility Management Function (AMF).
[0547] In some embodiments, the second network element includes at least one of the following: Unified Data Management (UDM) and Unified Data Storage (UDR).
[0548] Figure 5 is a third interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 5, the embodiments of the present disclosure relate to a communication method, which can be executed by a communication system. The method may include:
[0549] Step S5101: AF sends a first request to the first network element.
[0550] The optional implementation of step S5101 can be found in the optional implementation of step S2101 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0551] Step S5102: The second network element obtains the first information according to the first request.
[0552] The optional implementation of step S5102 can be found in the optional implementations of steps S2102 to S2103 in Figure 2A, steps S2202 to S2204 in Figure 2B, and other related parts in the embodiments involved in Figures 2A and 2B, which will not be repeated here.
[0553] In some embodiments, the above method may include the method described in the embodiments of the communication system, the first network element, the second network element, etc., which will not be repeated here.
[0554] In some embodiments, FIG6A is a fourth interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG6A, the embodiments of the present disclosure relate to a communication method that can be executed by a communication system. The method may include:
[0555] In step S6101, the AF sends a disk entry / command request to the NEF. The disk entry / command request may include the UE ID (e.g., GPSI, application layer identifier, etc.), environmental IoT device ID, service ID, area information, etc.
[0556] Step S6102: After NEF receives the inventory / command request, it checks whether AF is authorized to request environmental IoT services.
[0557] Step S6103: NEF sends the inventory / command request to AIoTF.
[0558] Step S6104: AIoTF interacts with UDM using UE authorization information to check the UE's authorization status. UE authorization information is contained in the UE's subscription data, including the UE's authorized environmental IoT services, the UE's authorized environmental IoT service area, and the UE's authorized environmental IoT service devices.
[0559] In some embodiments, checking the UE authorization status may include the following two methods:
[0560] Method 1: UDM returns the UE's authorization information to AIoTF, and AIoTF determines whether the UE is authorized to execute IoT service requests in this environment.
[0561] Method 2: UDM determines whether the UE is authorized to execute IoT service requests in this environment and returns the UE's authorization result to AIoTF.
[0562] In some embodiments, the implementation of UE authorization checks may include at least one of the following:
[0563] To determine whether a UE is authorized to provide this specific environmental IoT service, UDM / AIoTF checks whether the service ID is included in the environmental IoT services authorized by the UE. If it is included, then the authorization for the environmental IoT service is granted.
[0564] To determine whether a UE is authorized to provide environmental IoT services in a specific area, the UDM / AIoTF checks whether the area information is included in the environmental IoT service area authorized by the UE. If it is included, the authorization is granted through the environmental IoT service area.
[0565] To determine whether the UE is authorized to provide environmental IoT services in a specific area and to determine whether the UE is located in that specific area, the UDM further interacts with the AMF to obtain the UE's last known location. The UDM / AIoTF checks whether the area information is included in the environmental IoT service area authorized by the UE and whether the UE's last known location is within the area information. If it is included, then the authorization of the environmental IoT service area is granted.
[0566] To determine whether a UE is authorized to provide services to a specific environmental IoT device, UDM / AIoTF checks whether the device ID is included in the list of environmental IoT service devices authorized by the UE. If it is, then the authorization of the environmental IoT device is granted.
[0567] In some embodiments, if any of the above authorization checks fail, the UE's authorization check fails. In this case, step S6105 is skipped. The AIoTF returns a response message to the AF, indicating that the UE is not authorized to perform this service request.
[0568] It should be noted that step S6104 includes steps S6104-a to S6104-c in Figure 6A.
[0569] Step S6105: For an authorized UE, AIoTF sends a disk storage / command request to the UE through AMF.
[0570] It should be noted that step S6105 includes steps S6105-a and S6105-b in Figure 6A.
[0571] In some embodiments, FIG6B is a fifth interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG6B, the embodiments of the present disclosure relate to a communication method that can be executed by a communication system. The method may include:
[0572] In step S6201, the AF sends a disk entry / command request to the NEF. The disk entry / command request may include the UE ID (e.g., GPSI, application layer identifier, etc.), environmental IoT device ID, service ID, area information, etc.
[0573] Step S6202: After NEF receives the inventory / command request, it checks whether AF is authorized to request the environmental IoT service.
[0574] Step S6203: NEF sends the inventory / command request to AMF.
[0575] Step S6204: The AMF interacts with the UDM using the UE authorization information to check the UE's authorization status. The UE authorization information is contained in the UE's subscription data, including the UE's authorized environmental IoT services, the UE's authorized environmental IoT service area, and the UE's authorized environmental IoT service devices.
[0576] In some embodiments, checking the UE authorization status may include the following two methods:
[0577] Method 1: UDM returns the UE's authorization information to AMF, and AMF determines whether the UE is authorized to execute IoT service requests in this environment.
[0578] Method 2: UDM determines whether the UE is authorized to execute IoT service requests in this environment and returns the UE's authorization result to AMF.
[0579] In some embodiments, the implementation of UE authorization checks may include at least one of the following:
[0580] To determine whether a UE is authorized to provide a specific environmental IoT service, the UDM / AMF checks whether the service ID is included in the environmental IoT service authorized by the UE. If it is included, the authorization for the environmental IoT service is granted.
[0581] To determine whether a UE is authorized to provide environmental IoT services in a specific area, the UDM / AMF checks whether the area information is included in the UE's authorized environmental IoT service area. If it is included, the authorization for the environmental IoT service area is approved.
[0582] To determine whether the UE is authorized to provide environmental IoT services in a specific area and to determine whether the UE is located in that specific area, the UDM further interacts with the AMF to obtain the UE's last known location. The UDM / AMF checks whether the area information is included in the environmental IoT service area authorized by the UE and whether the UE's last known location is within the area information. If it is included, then the authorization of the environmental IoT service area is granted.
[0583] To determine whether a UE is authorized to provide services to a specific environmental IoT device, the UDM / AMF checks whether the device ID is included in the list of environmental IoT service devices authorized by the UE. If it is, the authorization is granted by the environmental IoT device.
[0584] In some embodiments, if any of the above authorization checks fail, the UE's authorization check fails. In this case, step S6205 is skipped. The AMF returns a response message to the AF, indicating that the UE is not authorized to perform this service request.
[0585] Step S6205: For an authorized UE, the AMF sends a disk storage / command request to the UE.
[0586] In some embodiments, the AMF / AIoTF should be able to obtain the UE's authorization information from the UDM / UDR.
[0587] In some embodiments, the AMF / AIoTF should be able to check the UE's authorization status based on the UE's authorization information.
[0588] In some embodiments, if the UE is authorized, the AMF / AIoTF should be able to send inventory / command requests to the UE.
[0589] In some embodiments, if the UE is not authorized, the AMF / AIoTF should be able to send a rejection message.
[0590] In some embodiments, the UDR / UDM should be able to return the UE's authorization information to the AMF / AIoTF.
[0591] In some embodiments, UDM / UDR should be able to return the authorization result of the UE to AMF / AIoTF.
[0592] In some embodiments of this disclosure, a communication system is provided, which may include a terminal, a core network device, and an Internet of Things (IoT) device, wherein the core network device can execute the communication method performed by the first network element and the second network element in the foregoing embodiments of this disclosure.
[0593] This disclosure also provides an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the first network element in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by the second network element in any of the above methods.
[0594] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an Application-Specific Integrated Circuit (ASIC), and the functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a Programmable Logic Device (PLD), such as a Field Programmable Gate Array (FPGA), which can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0595] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a Graphics Processing Unit (GPU) (which can be understood as a microprocessor), or a Digital Signal Processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an Application-Specific Integrated Circuit (ASIC) or a Programmable Logic Device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be hardware circuits designed for artificial intelligence, which can be understood as ASICs, such as Neural Network Processing Units (NPUs), Tensor Processing Units (TPUs), and Deep Learning Processing Units (DPUs).
[0596] Figure 7A is a schematic diagram of the structure of a first network element according to an embodiment of this disclosure. As shown in Figure 7A, the first network element 1021 may include at least one of a transceiver module 7101, a processing module 7102, etc. In some embodiments, the transceiver module 7101 is configured to receive a first request, the first request being used to request a terminal to provide a first service; the transceiver module 7101 is also configured to obtain first information according to the first request, the first information being used to indicate whether the terminal is authorized to provide the first service. Optionally, the transceiver module 7101 may be used to perform at least one of the communication steps (e.g., steps S2101, S2102, S2103, but not limited thereto) performed by the first network element 1021 in any of the above methods, which will not be described in detail here. Optionally, the processing module 7102 may be used to perform at least one of the other steps (e.g., step S2104, but not limited thereto) performed by the first network element 1021 in any of the above methods, which will not be described in detail here.
[0597] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, which may be separate or integrated. Optionally, the transceiver module may be interchangeable with a transceiver.
[0598] Figure 7B is a schematic diagram of the structure of a second network element according to an embodiment of this disclosure. As shown in Figure 7B, the second network element 1022 may include at least one of a transceiver module 7201, a processing module 7202, etc. In some embodiments, the transceiver module 7201 is configured to send first information to a first network element, wherein the first information is used to indicate whether the terminal is authorized to provide a first service. Optionally, the transceiver module 7201 may be used to perform at least one of the communication steps (e.g., steps S2101, S2102, but not limited thereto) performed by the second network element 1022 in any of the above methods, which will not be described in detail here. Optionally, the processing module 7202 may be used to perform at least one of the other steps performed by the second network element 1022 in any of the above methods, which will not be described in detail here.
[0599] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, which may be separate or integrated. Optionally, the transceiver module may be interchangeable with a transceiver.
[0600] Figure 8A is a schematic diagram of the structure of the communication device 8100 proposed in an embodiment of this disclosure. The communication device 8100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the first device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 8100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0601] As shown in Figure 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, IoT devices, IoT device chips, DUs or CUs, etc.), execute programs, and process program data. The communication device 8100 is used to execute any of the above methods.
[0602] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may also be located outside the communication device 8100.
[0603] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceivers 8103 perform at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2102, but not limited thereto), and the processor 8101 performs at least one of other steps (e.g., step S2104, but not limited thereto).
[0604] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.
[0605] In some embodiments, the communication device 8100 may include one or more interface circuits. Optionally, the interface circuit is connected to the memory 8102, and the interface circuit can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0606] The communication device 8100 described in the above embodiments may be a first device or an Internet of Things (IoT) device, but the scope of the communication device 8100 described in this disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG8A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, IoT device, smart IoT device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, first device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0607] Figure 8B is a schematic diagram of the structure of chip 8200 according to an embodiment of this disclosure. For cases where the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of chip 8200 shown in Figure 8B, but it is not limited thereto.
[0608] Chip 8200 includes one or more processors 8201, which are used to perform any of the above methods.
[0609] In some embodiments, chip 8200 further includes one or more interface circuits 8203. Optionally, the interface circuit 8203 is connected to memory 8202, and the interface circuit 8203 can be used to receive signals from memory 8202 or other devices, and the interface circuit 8203 can be used to send signals to memory 8202 or other devices. For example, the interface circuit 8203 can read instructions stored in memory 8202 and send the instructions to processor 8201.
[0610] In some embodiments, the interface circuit 8203 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2102, but not limited thereto), and the processor 8201 performs at least one of the other steps (e.g., step S2104, but not limited thereto).
[0611] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.
[0612] In some embodiments, chip 8200 further includes one or more memories 8202 for storing instructions. Optionally, all or part of the memories 8202 may be located outside of chip 8200.
[0613] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device 8100, cause the communication device 8100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0614] This disclosure also provides a program product that, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above methods. Optionally, the program product may be a computer program product.
[0615] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
Claims
1. A communication method, characterized in that, The method, executed by the first network element, includes: Receive a first request, the first request being used to request the terminal to provide a first service; The first information is obtained according to the first request, and the first information is used to indicate whether the terminal is authorized to provide the first service.
2. The method according to claim 1, characterized in that, The first request includes at least one of the following: Service identifier; The first identifier is the identifier of the terminal; The second identifier is the identifier for environmental IoT devices; First area.
3. The method according to claim 1 or 2, characterized in that, The first information includes at least one of the following: Authorization information, wherein the authorization information is used to determine whether the terminal is authorized to provide the first service; The authorization result includes whether the terminal is authorized to provide the first service or whether the terminal is not authorized to provide the first service; The location information of the terminal; The mapping result includes the user permanent identifier SUPI corresponding to the first identifier.
4. The method according to claim 3, characterized in that, The step of obtaining the first information according to the first request includes: A second request is sent to the second network element according to the first request. The second request is used to obtain second information, which includes at least one of the following: the authorization information and the location information of the terminal. Receive the second information sent by the second network element.
5. The method according to claim 4, characterized in that, The method further includes: The authorization result is determined based on the second information.
6. The method according to any one of claims 3-5, characterized in that, The authorization information includes at least one of the following: Service information, including the IoT services authorized for the terminal in the environment; Regional information, including the IoT service area authorized for the terminal; Device information, which includes the IoT service device authorized by the terminal.
7. The method according to claim 6, characterized in that, Determining the authorization result based on the second information includes at least one of the following: The service information includes the service corresponding to the service identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service; The region information includes the first region, and the authorization result is determined to be that the terminal is authorized to provide the first service; The area information includes the first area, and the terminal is located within the first area, so the authorization result is determined to be that the terminal is authorized to provide the first service; The device information includes the environmental IoT device corresponding to the second identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service.
8. The method according to claim 7, characterized in that, The method further includes: The location information is used to determine whether the terminal is located within the first area.
9. The method according to claim 3, characterized in that, The step of obtaining the first information according to the first request includes: A third request is sent to the second network element according to the first request, the third request being used to obtain the authorization result; The authorization result sent by the second network element is received. The authorization result is determined by the second network element based on second information, which includes at least one of the following: the authorization information and the location information of the terminal.
10. The method according to any one of claims 3-9, characterized in that, The method further includes: The terminal is authorized to provide the first service and sends a fourth request to the second network element, the fourth request being used to request the second network element to perform identifier mapping; Receive the mapping result sent by the second network element.
11. The method according to any one of claims 1-10, characterized in that, The method further includes: Based on the first information, it is determined that the terminal is authorized to provide the first service; A fifth request is sent to the terminal, the fifth request being used to request the terminal to provide the first service.
12. The method according to any one of claims 1-11, characterized in that, The method further includes: Based on the first information, it is determined that the terminal is not authorized to provide the first service; Send a first message, which indicates that the terminal is not authorized to provide the first service.
13. The method according to any one of claims 4-12, characterized in that, The second network element includes at least one of the following: Unified Data Management (UDM) and Unified Data Storage (UDR).
14. The method according to any one of claims 1-13, characterized in that, The first network element includes at least one of the following: Environmental Internet of Things Function (AIoTF) and Access and Mobility Management Function (AMF).
15. A communication method, characterized in that, The method, executed by the second network element, includes: Send first information to the first network element, the first information being used to indicate whether the terminal is authorized to provide the first service.
16. The method according to claim 15, characterized in that, The first information includes at least one of the following: Authorization information, wherein the authorization information is used to determine whether the terminal is authorized to provide the first service; The authorization result includes whether the terminal is authorized to provide the first service or whether the terminal is not authorized to provide the first service; The location information of the terminal; The mapping result includes a user permanent identifier (SUPI) corresponding to a first identifier, where the first identifier is the identifier of the terminal.
17. The method according to claim 16, characterized in that, The method further includes: The system receives a second request sent by the first network element based on a first request. The first request is used to request the terminal to provide the first service, and the second request is used to obtain second information, which includes at least one of the following: the authorization information and the location information of the terminal.
18. The method according to claim 16 or 17, characterized in that, The authorization information includes at least one of the following: Service information, including the IoT services authorized for the terminal in the environment; Regional information, including the IoT service area authorized for the terminal; Device information, which includes the IoT service device authorized by the terminal.
19. The method according to claim 17 or 18, characterized in that, The method further includes: A sixth request is sent to a third network element, the sixth request being used to obtain the location information of the terminal; Receive the location information of the terminal sent by the third network element.
20. The method according to claim 16, characterized in that, The method further includes: The system receives a third request sent by the first network element in accordance with the first request. The first request is used to request the terminal to provide the first service, and the third request is used to obtain the authorization result.
21. The method according to claim 20, characterized in that, The first request includes at least one of the following: Service identifier; The first identifier; The second identifier is the identifier for environmental IoT devices; First area.
22. The method according to claim 21, characterized in that, The method further includes: The authorization result is determined based on the second information, which includes at least one of the following: the authorization information and the location information of the terminal.
23. The method according to claim 22, characterized in that, Determining the authorization result based on the second information includes at least one of the following: The service information includes the service corresponding to the service identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service; The region information includes the first region, and the authorization result is determined to be that the terminal is authorized to provide the first service; The area information includes the first area, and the terminal is located within the first area, so the authorization result is determined to be that the terminal is authorized to provide the first service; The device information includes the environmental IoT device corresponding to the second identifier, and the authorization result is determined to be that the terminal is authorized to provide the first service.
24. The method according to claim 23, characterized in that, The method further includes: The location information is used to determine whether the terminal is located within the first area.
25. The method according to any one of claims 16-24, characterized in that, The method further includes: Receive the fourth request sent by the first network element; Perform identifier mapping according to the fourth request; The mapping result is sent to the first network element.
26. The method according to any one of claims 15-25, characterized in that, The first network element includes at least one of the following: Environmental Internet of Things Function (AIoTF) and Access and Mobility Management Function (AMF).
27. The method according to any one of claims 15-26, characterized in that, The second network element includes at least one of the following: Unified Data Management (UDM) and Unified Data Storage (UDR).
28. A first network element, characterized in that, include: The transceiver module is configured to receive a first request, which is used to request the terminal to provide a first service; The transceiver module is further configured to obtain first information based on the first request, wherein the first information is used to indicate whether the terminal is authorized to provide the first service.
29. A second network element, characterized in that, include: The transceiver module is configured to send first information to the first network element, the first information being used to indicate whether the terminal is authorized to provide the first service.
30. A core network device, characterized in that, It includes a first network element and a second network element, wherein the first network element is configured to implement the communication method of any one of claims 1-14; and the second network element is configured to implement the communication method of any one of claims 15-27.
31. A storage medium storing instructions, characterized in that, When the instruction is executed on the core network device, the core network device performs the communication method as described in any one of claims 1-14 or 15-27.
Citation Information
Patent Citations
Wireless communication method and device, and storage medium
CN116602051A
Information processing method, system and device, communication equipment and storage medium
CN116724569A
Authorization method and device
CN116828563A
Method for processing prose service authorization change, first network element and second network element
US20170230381A1
Authorization method and communication apparatus
WO2024016954A1