Access control method and apparatus, transmission control method and apparatus, terminal, and network side device

By coordinating the control of terminal and network-side equipment, the access control problem of different services in the next-generation mobile communication system is solved, and the distinction and priority processing of signaling and data transmitted in the user plane channel are realized, thereby improving the flexibility and management efficiency of access control.

WO2026158445A1PCT designated stage Publication Date: 2026-07-30VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
VIVO MOBILE COMM CO LTD
Filing Date
2026-01-22
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

In next-generation mobile communication systems, how to support access control for different services, especially the access control requirements of new services such as computing power, sensing, and data plane that have not been effectively handled in 5G systems.

Method used

The terminal performs access control or determines to skip access control based on at least one of the first, second, and third information; the RAN sends the third information to the terminal to indicate that control is prohibited; the NF performs transmission control or skips transmission control based on the fourth information.

Benefits of technology

It enables flexible access control for different services and network functions, enhances the terminal's access control management capabilities, and supports the differentiation and priority processing of signaling and data transmitted in the user plane channel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2026074180_30072026_PF_FP_ABST
    Figure CN2026074180_30072026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and discloses an access control method and apparatus, a transmission control method and apparatus, a terminal, and a network side device. The access control method in embodiments of the present application comprises: on the basis of at least one of first information, second information, and third information, a terminal performs access control or determines to skip access control, wherein the first information is used for indicating at least one of the following: the terminal being configured with a target service, and the terminal being configured to perform transmission by means of a user plane channel; the second information is used for indicating at least one of the following: a target service, a target network function (NF), user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted by means of the user plane channel, and data transmitted by means of the user plane channel; and the third information is used for indicating that control is prohibited.
Need to check novelty before this filing date? Find Prior Art

Description

Access control methods, transmission control methods, devices, terminals and network-side equipment

[0001] Cross-referencing

[0002] This disclosure claims priority to Chinese patent application No. 202510110530.X, filed on January 23, 2025, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application belongs to the field of communication technology, specifically relating to an access control method, a transmission control method, an apparatus, a terminal, and network-side equipment. Background Technology

[0004] In related technologies, when a terminal needs to access a 5G system (5GS), it must first perform an access control check to determine whether access is permitted. In next-generation mobile communication systems, such as 6G, many services not supported by 5G may be supported, such as computing power, sensing, and data plane. These services may have different access control requirements; therefore, how to support access control for different services is a problem that needs to be solved. Summary of the Invention

[0005] This application provides an access control method, a transmission control method, an apparatus, a terminal, and a network-side device, which can solve the problem of how to support access control for different services.

[0006] Firstly, an access control method is provided, executed by a terminal, the method comprising:

[0007] The terminal performs access control or determines to skip access control based on at least one of the first, second, and third information.

[0008] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0009] The second information is used to indicate at least one of the following: target service, target network function (NF), user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel;

[0010] The third piece of information is used to indicate that control is prohibited.

[0011] Secondly, an access control method is provided, executed by the RAN, the method comprising:

[0012] The RAN sends a third message to the terminal, which is used to indicate that control is prohibited.

[0013] Thirdly, a transmission control method is provided, executed by an NF, the method comprising:

[0014] NF performs transmission control or determines to skip transmission control based on at least one of the fourth information and information used to indicate restrictions on terminal access;

[0015] The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0016] Fourthly, an access control device is provided for use in a terminal, the device comprising:

[0017] The first processing module is configured to perform access control or determine to skip access control based on at least one of the first information, the second information, and the third information.

[0018] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0019] The second information is used to indicate at least one of the following: target service, target NF, user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel;

[0020] The third piece of information is used to indicate that control is prohibited.

[0021] Fifthly, an access control device is provided for use in a RAN, the device comprising:

[0022] The sending module is used to send third information to the terminal, the third information being used to indicate that control is prohibited.

[0023] Sixthly, a transmission control device is provided for use in NF, the device comprising:

[0024] The second processing module is configured to perform transmission control or determine to skip transmission control based on at least one of the fourth information and information indicating restriction of terminal access.

[0025] The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0026] In a seventh aspect, an access control device is provided, the device being configured to perform the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect.

[0027] Eighthly, a transmission control device is provided, the device being configured to perform the steps of the method described in the third aspect.

[0028] In a ninth aspect, a terminal is provided, the terminal including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the first aspect.

[0029] In a tenth aspect, a terminal is provided, including a processor and a communication interface, wherein the processor is configured to perform access control or determine to skip access control based on at least one of first information, second information and third information;

[0030] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0031] The second information is used to indicate at least one of the following: target service, target network function (NF), user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel;

[0032] The third piece of information is used to indicate that control is prohibited.

[0033] Eleventhly, a network-side device is provided, the network-side device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the second or third aspect.

[0034] In a twelfth aspect, a network-side device is provided, including a processor and a communication interface, wherein the communication interface is used to send third information to a terminal, the third information being used to indicate that control is prohibited; or...

[0035] The processor is configured to perform transmission control or determine to skip transmission control based on at least one of fourth information and information indicating restriction of terminal access.

[0036] The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0037] In a thirteenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect.

[0038] In a fourteenth aspect, a wireless communication system is provided, comprising: a terminal, a RAN, and an NF, wherein the terminal is configured to perform the steps of the method described in the first aspect, the RAN is configured to perform the steps of the method described in the second aspect, and the NF is configured to perform the steps of the method described in the third aspect.

[0039] In a fifteenth aspect, a chip is provided, the chip including a processor and a communication interface coupled to the processor, the processor being configured to run a program or instructions to implement the steps of the method as described in the first aspect, or the steps of the method as described in the second aspect, or the steps of the method as described in the third aspect.

[0040] In a sixteenth aspect, a computer program / program product is provided, the computer program / program product being stored in a storage medium, the computer program / program product being executed by at least one processor to implement the steps of the method as described in the first aspect, or the steps of the method as described in the second aspect, or the steps of the method as described in the third aspect.

[0041] In this embodiment, the terminal can perform access control or determine to skip access control based on at least one of the first information, the second information, and the third information. Therefore, the terminal can perform access control for different services, different network functions, and data and / or signaling transmitted through the user plane channel, thereby supporting access control for different services and / or different network functions and / or user plane channel transmissions, and helping to improve the terminal's flexible management of access control. Attached Figure Description

[0042] Figure 1 is a block diagram of a wireless communication system applicable to an embodiment of this application;

[0043] Figure 2 is a flowchart of one of the access control methods provided in an embodiment of this application;

[0044] Figure 3 is a second flowchart of an access control method provided in an embodiment of this application;

[0045] Figure 4 is a flowchart of a transmission control method provided in an embodiment of this application;

[0046] Figure 5 is a flowchart of an access control method provided in an embodiment of this application;

[0047] Figure 6 is a structural diagram of an access control device provided in an embodiment of this application;

[0048] Figure 7 is a second structural diagram of an access control device provided in an embodiment of this application;

[0049] Figure 8 is a structural diagram of a transmission control device provided in an embodiment of this application;

[0050] Figure 9 is a structural diagram of a communication device provided in an embodiment of this application;

[0051] Figure 10 is a structural diagram of a terminal provided in an embodiment of this application;

[0052] Figure 11 is a structural diagram of a network-side device provided in an embodiment of this application;

[0053] Figure 12 is a structural diagram of another network-side device provided in an embodiment of this application. Detailed Implementation

[0054] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0055] The terms "first," "second," etc., used in this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, the first object can be one or more. Furthermore, "or" in this application indicates at least one of the connected objects. For example, the scope of protection for "A or B" covers at least three scenarios: Scenario 1: including A but not B; Scenario 2: including B but not A; Scenario 3: including both A and B. In addition, the terms "A and / or B," "at least one of A and B," and "at least one of A or B" also cover at least the above three scenarios. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0056] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as the sender explicitly informing the receiver of specific information, the required operation, or the requested result in the instruction sent. An indirect instruction can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the required operation or requested result based on the judgment result.

[0057] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. The following description describes New Radio (NR) systems for illustrative purposes, and the term NR is used in most of the following description; however, these technologies can also be applied to systems other than NR systems, such as 6th generation (6G) radio systems. th Generation 6G communication system.

[0058] Figure 1 shows a block diagram of a wireless communication system applicable to an embodiment of this application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 can also be referred to as User Equipment (UE), and can be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipboard equipment, pedestrian user equipment (PUE), smart home (home devices with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, or self-service machine, etc. Wearable devices include: smartwatches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart chains, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among these, in-vehicle devices can also be referred to as in-vehicle terminals, in-vehicle controllers, in-vehicle modules, in-vehicle components, in-vehicle chips, or in-vehicle units, etc. It should be noted that the specific type of terminal 11 is not limited in this application embodiment. Network-side equipment 12 may include access network equipment or core network equipment, wherein access network equipment may also be referred to as Radio Access Network (RAN) equipment, radio access network function, or radio access network unit. Access network equipment may include base stations, Wireless Local Area Network (WLAN) access points (APs), or Wireless Fidelity (WiFi) nodes, etc.Among them, base stations can be referred to as Node B (NB), Evolved Node B (eNB), Next Generation Node B (gNB), New Radio Node B (NR Node B), Access Point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), Radio Base Station, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B, Transmit / Receive Point (TRP), Non-Terrestrial Network (NTN) equipment (such as satellite or high altitude platform stations). The term "base station" can be any suitable term in the field, such as "station" or any other appropriate term in the relevant field, as long as the same technical effect is achieved. The term "base station" is not limited to specific technical terms. It should be noted that the embodiments of this application only use the base station in the NR system as an example for introduction, and do not limit the specific type of base station.

[0059] Core network equipment, also known as core network nodes, core network functions, or core network elements, includes, but is not limited to, at least one of the following: Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), and Binding Support. Functions include BSF, Application Function (AF), Location Management Function (LMF), Gateway Mobile Location Centre (GMLC), Network Data Analytics Function (NWDAF), and Non-Terrestrial Network (NTN) equipment (such as satellite or high altitude platform station).It should be noted that the embodiments of this application only use the core network equipment in the NR system as an example for introduction, and do not limit the specific type of core network equipment. If the name of the core network equipment mentioned in the embodiments of this application changes in subsequent protocol versions (e.g., 6G), it is also within the scope of protection of this application.

[0060] Optionally, the core network equipment can be implemented by one or more functional modules in a single device, or by multiple devices working together; this application does not specifically limit this. It is understood that the aforementioned functional modules can be network elements in hardware devices, software functional modules running on dedicated hardware, or virtualized functional modules instantiated on a platform (e.g., a cloud platform).

[0061] When a UE needs to access 5GS, it first performs access control checks to determine whether access is permitted. These checks should be performed according to the access attempt defined by the following events:

[0062] a) The UE is in 5G Mobility Management (5GMM) idle mode (IDLE) or 5GMM connected mode with a pause indication displayed on 3GPP access, and an event occurs that requires transition to 5GMM-IDLE;

[0063] b) The UE is in 5GMM connected mode while in 3GPP access or in RRC inactive mode and one of the following events has occurred:

[0064] 1) The 5GMM receives an MO-IMS-registration-related-signalling-started indication, an MO-MMTEL-voice-call-started indication, an MO-MMTEL-video-call-started indication, or an MO-SMSoIP-attempt-started indication from upper layers.

[0065] 2) 5GMM receives a request from upper layers to send a mobile-originated SMS over NAS unless the request triggers a service request procedure to transition the UE from 5GMM-IDLE mode or 5GMM-IDLE mode with suspend indication to 5GMM-CONNECTED mode.

[0066] 3) 5GMM receives a request from upper layers to send an UL NAS TRANSPORT message to establish a Protocol Data Unit (PDU) session, unless the request triggers a service request procedure to transition the UE from 5GMM-IDLE mode or 5GMM-IDLE mode with suspend indication to 5GMM-CONNECTED mode.

[0067] 4) 5GMM receives a request from upper layers to send an UL NAS TRANSPORT message to execute the UE-requested PDU session modification procedure, unless the request triggers a service request procedure to transition the UE from 5GMM-IDLE mode or 5GMM-IDLE mode with suspend indication to 5GMM-CONNECTED mode.

[0068] 5) 5GMM receives a request to re-establish the user-plane resources for an existing PDU session;

[0069] 6) 5GMM is notified that an uplink user data packet is to be sent for a PDU session with suspended user-plane resources;

[0070] 7) 5GMM receives a request from upper layers to send a mobile originated location request unless the request triggers a service request procedure to transition the UE from 5GMM-IDLE mode or 5GMM-IDLE mode with suspend indication to 5GMM-CONNECTED mode.

[0071] 8) When 5GMM receives a request from upper layers, it sends a mobile origination signaling transaction to the PCF by sending an UL NAS TRANSPORT message containing a UE policy container (see 3GPP TS24.587[19B] and 3GPP TS24.554[19E]), unless the request triggers a service request procedure to transition the UE from 5GMM-IDLE mode to 5GMM-CONNECTED mode.

[0072] 9) The 5GMM receives an indication from lower layers of the RAN timing synchronization status change and decides to transition the UE from 5GMM-CONNECTED mode with RRC inactive indication to 5GMM-CONNECTED mode as specified in subclause 5.3.1.4.

[0073] When the Non-access stratum (NAS) detects one of the above events, the NAS needs to perform an access prohibition check on the request by mapping the request type to one or more access identifiers and an access class. The lower layer will then perform an access prohibition check on the request based on the determined access identifier and access class.

[0074] To determine the requested access identifier and access category, the NAS detects the access reason, the requested service category, and the UE profile including the UE configuration, based on a set of access identifiers and access categories defined in the relevant protocols.

[0075] In order to enable access prohibition checks for access attempts identified by a lower layer with an RRC inactivity indication in 5GMM-CONNECTED mode, the UE provides the applicable access identifier to the lower layer.

[0076] In addition, in related technologies:

[0077] If the UE is in IDLE state and the access attempt is allowed, the UE initiates an initial NAS message;

[0078] If the UE is in IDLE state and access attempts are prohibited, the UE will not initiate an initial NAS message; in particular, for IMS services, the UE may attempt to select an Evolved Universal Terrestrial Radio Access (E-UTRA) cell to access the Evolved Packet Core Network (EPC).

[0079] If the UE is in the CONNECTED state and the access attempt is allowed, the UE initiates the corresponding procedure, such as establishing / modifying a PDU session, requesting a policy, etc.

[0080] If the UE is in the CONNECTED state, the UE will not initiate the corresponding procedure until the barring ends.

[0081] When a UE needs to access 5GS, it first executes Unified Access Control (UAC) to determine whether access to 5GS is permitted. In next-generation mobile communication systems, such as 6G, many services not supported by 5G may be supported, such as computing power, sensing, and data plane. These services may have different access control requirements, so how to support access control for different services is an urgent problem to be solved.

[0082] In 5G, some signaling messages (such as user plane positioning signaling messages) can be transmitted through user plane channels (such as PDU sessions). However, the network does not control or distinguish these signaling messages transmitted through the user plane. But control plane messages and communication data may have different priorities (such as access control priority), so identifying and distinguishing these signaling messages transmitted through the user plane channel is a problem that urgently needs to be solved.

[0083] It should be noted that, in the embodiments of this application, the user plane channel refers to the association between the UE and the data network providing PDU connection services, or the channel between the UE and the N6 endpoint (e.g., the PDU Session Anchor (PSA) UPF). Sometimes, it may also be referred to as user plane bearer, user plane connection, user plane association, data channel, data bearer, data connection, or data association, all expressing the same meaning. In some implementations, the user plane channel can be a PDU session, a Quality of Service (QoS) stream, a Packet Data Network (PDN) connection, an Evolved Packet System (EPS) bearer, etc.

[0084] The access control method, transmission control method, apparatus, terminal, and network-side equipment provided in this application will be described in detail below with reference to the accompanying drawings and through some embodiments and application scenarios.

[0085] Please refer to Figure 2, which is a flowchart of one of the access control methods provided in an embodiment of this application. The method is executed by a terminal. As shown in Figure 2, the method includes the following steps:

[0086] Step 201: The terminal performs access control or determines to skip access control based on at least one of the first information, the second information, and the third information.

[0087] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0088] The second information is used to indicate at least one of the following: target service, target network function (NF), user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel;

[0089] The third piece of information is used to indicate that control is prohibited.

[0090] It should be noted that the terminal being configured for user plane channel transmission can be understood as the terminal needing or being required to transmit at least one of the signaling and data of the target service through the user plane channel. When the first information includes the terminal being configured to transmit through the user plane channel, the terminal can perform access control or determine to skip access control based on the first information. The terminal determining to skip access control can be understood as the terminal not performing access control.

[0091] Optionally, the target service includes at least one of the following:

[0092] Services supported by terminals or mobile communication systems (such as 6G mobile communication systems (6GS) and their subsequent evolution);

[0093] The business that initiates an access attempt.

[0094] For example, the target service is the service that initiates an access attempt. This can be understood as the target service needing to initiate an access attempt when the terminal needs to execute the target service. In some implementations, the target service may include at least one of the following: mobility management service, session management service, service management service, connection management service, computing management service, data management service, algorithm management service, signaling management service, policy management service, data management service, PDU service, short message service, policy service, location service, computing service, sensing service, artificial intelligence (AI) service, data service, multimedia service, immersive service, security service, task service, Ambient Internet of Things (AIoT) service, energy-saving service, Non-Terrestrial Network (NTN) service, slicing service, Vehicle-to-Everything (V2X) service, and PC5 service.

[0095] For example, the first information is used to indicate that the terminal is configured with a target service. In some implementations, the terminal can perform access control based on the first information. For instance, the target service includes a sensing service, and the first information indicates that the terminal is configured with a sensing service. When the terminal needs to perform a sensing service, the terminal can perform access control based on the first information. It is understood that the target service can also be at least one of the other services listed above, which will not be elaborated here.

[0096] It should be noted that some services do not require the terminal to perform access control. For example, when a terminal responds to a paging request from a network-side device to perform a sensing service, access control is not required. In this case, the terminal can determine to skip access control based on the second information indicating the sensing service.

[0097] In some implementations, the terminal performing access control can be understood as performing access control before transmitting messages (e.g., signaling or data). For example, when the terminal needs to perform a sensing service or send a sensing message, it performs access control and determines whether to perform the sensing service or send the sensing message based on the access control.

[0098] In this embodiment of the application, the second information is further used to indicate the target NF. Optionally, the target NF includes at least one of the following:

[0099] The terminal executes the NF corresponding to the target service;

[0100] The NF that receives the signaling sent by the terminal.

[0101] For example, if the target service is AIoT, the target NF is an AIoT network function (e.g., AIoTF); or, if the target service is a session management service, the target NF can be a session management function (e.g., SMF). Of course, the target service can also be at least one of the other services listed above, and the target NF can be the NF corresponding to the target service, which will not be listed in detail in this application.

[0102] In some implementations, the UE needs to send signaling to the relevant NF before sending signaling to the network function (NF) corresponding to the target service. For example, if the UE needs to send signaling messages to the sensing function through the user plane channel, the UE needs to establish the user plane channel before sending the signaling messages to the sensing function through the user plane channel. Therefore, when the UE needs to send signaling messages to the sensing function through the user plane channel, the target NF can indicate either the session management function or the sensing function; this is not limited in this scheme. For example, if the target NF indicates the session management function, the access attempt can be understood as establishing a user plane channel; if the target NF indicates the sensing function, the access attempt can be understood as an access attempt for the sensing service.

[0103] In this embodiment, the second information may further indicate at least one of the following: signaling and / or data related to the target service, signaling and / or data related to the target NF, and signaling and / or data transmitted through the user plane channel. The terminal can then perform access control or determine to skip access control based on the second information. For example, if the second information indicates signaling related to a sensing service (i.e., the target service), the terminal performs access control based on the second information. As another example, if the second information indicates signaling related to an AIoT network function (i.e., the target NF), the terminal performs access control based on the second information when it needs to perform an AIoT task. As yet another example, if the second information indicates session management data transmitted through the user plane channel, the terminal determines to perform access control based on the second information. It is understood that the content indicated by the second information can also be other possible cases, and this embodiment does not specifically limit it.

[0104] Optionally, the terminal performs access control, including:

[0105] The terminal may allow access attempts or disallow access attempts.

[0106] For example, when the terminal determines to perform access control based on the first information, the terminal may allow or disallow the access attempt. For instance, if the first information indicates that the terminal is configured with a target service, such as a sensing service, and the terminal needs to perform a sensing task or send a sensing message, then the terminal may allow the access attempt and further determine whether to perform the sensing task or send the sensing message. Of course, in some cases, such as when communication quality is poor, the terminal may also disallow the access attempt.

[0107] In this embodiment of the application, the terminal performs access control, which can be understood as the terminal allowing or disallowing access attempts, thereby enabling the terminal to better control access to different services.

[0108] Optionally, the first information is an access identity.

[0109] Optionally, the second information is the access category.

[0110] Optionally, the third information is barring control information.

[0111] Understandably, the first information allows the terminal to determine that the access attempt is for at least one of the target service and user plane channel transmission, thereby correctly performing access control. For example, if the access attempt is for at least one of the signaling and data of the target service that the terminal needs or is required to transmit through the user plane channel, the first information indicates that the terminal is configured for user plane channel transmission.

[0112] Understandably, through the second information, the terminal can determine that the access attempt is for at least one of the following: signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel, thereby correctly performing access control. For example, if the access attempt is for signaling related to the target service, the second information indicates that it is for signaling related to the target service.

[0113] Understandably, through the third information, the terminal can correctly obtain the information used for prohibition control. For example, if the third information indicates that signaling for a target service transmitted through the user plane channel does not require access control, and the second information indicates that the signaling is transmitted through the user plane channel, then the terminal can determine to skip access control. As another example, if the third information indicates that signaling for a target NF requires access control, and the second information indicates signaling related to the target NF, then the terminal determines to execute access control.

[0114] In this embodiment, the terminal can perform access control or determine to skip access control based on at least one of the first information, the second information, and the third information. Therefore, the terminal can perform access control for different services, different network functions, and data and / or signaling transmitted through the user plane channel, thereby supporting access control for different services and / or different network functions and / or user plane channel transmissions, and helping to improve the terminal's flexible management of access control.

[0115] Optionally, in this embodiment of the application, the third information satisfies at least one of the following:

[0116] The third information is associated with at least one of the following: the first information, the second information, and the Public Land Mobile Network (PLMN);

[0117] The third information includes at least one of the following: information for indicating prohibition of control, information for indicating that prohibition of control is not performed, information indicating that the third information is used for all PLMNs, and information indicating that the third information is used for a specific PLMN.

[0118] In some implementations, the third information is associated with the second information, which can be understood as meaning that the third information applies only to the associated second information. For example, the third information indicates information 1 and information 2, where information 1 is associated with information 3 and information 2 is associated with information 4. In this case, if the second information indicates information 3, then only information 1 in the third information associated with information 3 will be used to perform access control.

[0119] In some implementations, the third information is associated with the first information. For example, if the first information indicates that the terminal is configured with a target service, and the third information indicates information 1 and information 2, where information 1 is associated with the target service, then information 1 associated with the target service in the third information will be used to perform access control.

[0120] In some implementations, the third information is associated with a PLMN. Optionally, the PLMN information can be a PLMN identifier. For example, a RAN can belong to multiple PLMNs. If the third information indicates information 1 and information 2, where information 1 is associated with PLMN1 and information 2 is associated with PLMN2, then if the RAN sending the third information is broadcasting information for PLMN1, the RAN will only broadcast information 1 and not information 2.

[0121] In this embodiment of the application, the third information is associated with at least one of the first information, the second information, and the PLMN, so that the terminal can more clearly determine whether to perform access control based on the association between the third information and at least one of the first information, the second information, and the PLMN, which helps the terminal manage access control.

[0122] Optionally, the terminal performs access control or determines to skip access control based on third information, including at least one of the following:

[0123] If the third information includes information indicating that control is prohibited, the terminal performs access control;

[0124] If the third information does not include information indicating prohibition of control or includes information indicating that prohibition of control should not be performed, the terminal determines to skip access control;

[0125] If the third information does not include information indicating prohibition of control or includes information indicating not to enforce prohibition of control, the terminal performs access control, wherein the execution of access control indicates that the access attempt is permitted.

[0126] In some implementations, the third information includes information indicating that access control is prohibited. For example, the third information includes information indicating that signaling for the target NF requires access control; if the terminal needs to transmit signaling for the target NF, then the terminal determines to perform access control.

[0127] In some implementations, the third information includes information indicating that access control should not be performed. For example, the third information includes information indicating that signaling for transmitting the target service on the user plane channel does not require access control. If the terminal needs to transmit the signaling for the target service, the terminal can determine to skip access control.

[0128] In some implementations, the third information does not include information for indicating prohibition control, and the terminal can perform access control based on the third information, such as allowing the access attempt.

[0129] In this embodiment of the application, the terminal can perform access control or determine to skip access control based on the information content included in the third information, which helps the terminal to better manage access control.

[0130] Optionally, in embodiments of this application, the method further includes:

[0131] The terminal acquires at least one of the first information, the second information, and the third information.

[0132] Understandably, when the terminal obtains the first information, the terminal can perform access control or determine to skip access control based on the first information.

[0133] When the terminal obtains the second information, the terminal can perform access control or determine to skip access control based on the second information.

[0134] When the terminal obtains the third information, the terminal can perform access control or determine to skip access control based on the third information.

[0135] In this embodiment of the application, the terminal can effectively perform access control or determine to skip access control by obtaining at least one of the first information, the second information and the third information, which helps the terminal to manage access control.

[0136] Optionally, the terminal acquires at least one of the first information, the second information, and the third information, including:

[0137] The terminal acquires at least one of the first information, the second information, and the third information through a targeted method, wherein the targeted method includes at least one of the following:

[0138] Pre-configured;

[0139] Access attempt;

[0140] Target business;

[0141] Broadcast message;

[0142] NAS signaling.

[0143] In some implementations, the terminal obtains the first information based on pre-configuration, wherein the first information may be pre-configured within the terminal. For example, the first information may be pre-configured in a modem, ME, or Subscriber Identity Module (SIM) card. Understandably, if the first information is pre-configured within the terminal, no air interface signaling is required for transmission, which helps save terminal power consumption. When initiating an access attempt, the terminal can use the pre-configured or stored information to determine the first information, thereby performing access control or determining to skip access control based on the first information.

[0144] In some implementations, the second information or the third information may also be pre-configured, and the terminal may also obtain the second information or the third information based on the pre-configuration, which will not be elaborated here.

[0145] In some implementations, the terminal acquiring the second information may include: the terminal acquiring the second information based on at least one of an access attempt and a target service. For example, if the access attempt is used to transmit signaling related to the target service, the terminal can determine that the second information is signaling related to the target service, and then acquire the second information based on the access attempt. As another example, if the terminal needs to transmit data related to the target service, the terminal can determine that the second information is data related to the target service, and then acquire the second information based on the target service. Other types of second information are similar and will not be listed individually. It is understood that the second information is determined based on the access attempt and does not require transmission via air interface signaling. The terminal can determine the second information based on the access attempt when initiating it, which helps save terminal power consumption.

[0146] In some implementations, the terminal acquiring the third information may include: the terminal acquiring the third information via a broadcast message from the RAN, the broadcast message carrying the third information. Understandably, the third information needs to be transmitted over the air interface. This allows network-side devices to dynamically adjust access control based on network configuration or policies. For example, network-side devices can control one or more target services to perform access control at any time, while other target services do not need to perform access control or can skip access control, thus achieving more flexible access control.

[0147] In some implementations, the terminal can also obtain third information via NAS signaling. Understandably, in this case, the third information needs to be transmitted over the air interface, allowing network-side devices to dynamically adjust access control via NAS signaling.

[0148] Optionally, in embodiments of this application, the method further includes:

[0149] The terminal determines a first cause value based on at least one of the first information and the second information.

[0150] The first cause value can be used to indicate at least one of the reasons for Radio Resource Control (RRC) establishment and the reasons for RRC recovery. For example, the terminal determines the RRC establishment cause value and / or the RRC recovery cause value based on the first information and / or the second information, thereby enabling the terminal to know the reasons for RRC establishment and / or the reasons for RRC recovery.

[0151] Optionally, the first cause value satisfies at least one of the following:

[0152] The first cause value includes at least one of the RRC establishment cause value and the RRC recovery cause value;

[0153] The first cause value indicates at least one of the following: terminal-initiated signaling, terminal-initiated data, terminal-initiated target NF signaling, terminal-initiated target NF data, terminal-initiated target service signaling, terminal-initiated target service data, terminal-initiated user plane channel signaling, and terminal-initiated user plane channel data.

[0154] For example, based on the content indicated by the first reason value, the terminal can ascertain the reason for RRC establishment and / or RRC recovery. For instance, the first reason value indicates that the terminal initiates target NF signaling and / or data. The terminal can perform access control based on the target NF signaling and / or data. When the terminal establishes or recovers RRC based on the access control, it can ascertain that the reason for RRC establishment or recovery is due to the terminal initiating target NF signaling and / or data. It is understood that the first reason value can also indicate other content mentioned above, which are not specifically listed here.

[0155] It should be noted that, in the content indicated by the first cause value, terminal-initiated can also be referred to as mobile-initiated (MO). For example, the first cause value can be understood as indicating at least one of the following: mobile-initiated signaling, mobile-initiated data, mobile-initiated target NF signaling, mobile-initiated target NF data, mobile-initiated target service signaling, mobile-initiated target service data, mobile-initiated user plane channel signaling, and mobile-initiated user plane channel data.

[0156] In this embodiment of the application, the terminal can determine the RRC establishment cause value and / or RRC recovery cause value based on the content indicated by the first cause value, which is helpful for the terminal's wireless communication.

[0157] It is understood that access control (or Unified Access Control (UAC)) can be performed by different layers within the UE. In some implementations, UAC is performed by the Mobile Management (MM) layer (e.g., 6GMM). For example, when a sense service message is sent to the network side as part of an MM message (e.g., contained in an MM container), UAC can be performed by the MM layer. It is understood that since the sense service message is part of an MM message, from the perspective of both the terminal and the network side, access control is performed on the MM message; that is, UAC can be performed by the MM layer. In some implementations, UAC can be performed by the service layer corresponding to the service. Here, the service layer corresponding to the service refers to the layer in the terminal that processes a specific service message; for example, the layer processing sense messages corresponds to the sense layer, and the layer processing session messages corresponds to the session layer. For example, the terminal can send a sense message to the network side, which is sent directly to the sense function after passing through the RAN, rather than being routed through other network functions. In this case, UAC can be performed by the service layer corresponding to the service. It is understandable that, since the messages of the sensing service are sent directly to the sensing function, from the perspective of the terminal and the network side, access control is performed on the sensing messages, that is, UAC can be executed by the sensing layer corresponding to the sensing function.

[0158] This application also provides an access control method performed by the RAN. Referring to Figure 3, the access control method includes the following steps:

[0159] Step 301: RAN sends third information to the terminal.

[0160] The third piece of information is used to indicate that control is prohibited.

[0161] Optionally, the third information satisfies at least one of the following:

[0162] The third information is associated with at least one of the following: first information, second information, or PLMN;

[0163] The third information includes at least one of the following: information for indicating prohibition of control, information for indicating that prohibition of control is not performed, information indicating that the third information is used for all PLMNs, and information indicating that the third information is used for a specific PLMN;

[0164] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0165] The second information is used to indicate at least one of the following: target service, target NF, user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0166] It should be noted that the relevant descriptions of the first, second, and third information can be specifically referred to the explanations in the method embodiment of Figure 2 above, and will not be repeated in this embodiment.

[0167] Understandably, if the third information contains information indicating prohibition of control, the terminal performs access control; if the third information does not contain information indicating prohibition of control, or if the third information contains information indicating not to perform prohibition of control, the terminal determines to skip access control.

[0168] Optionally, the RAN sends third information to the terminal, including:

[0169] The RAN sends third information to the terminal via broadcast messages.

[0170] For example, the broadcast message carries the third information, so that the RAN can send the third information to the terminal through the broadcast message. The RAN does not need to send the third information through additional signaling or messages, which helps to save the RAN's energy consumption.

[0171] Optionally, the method further includes:

[0172] The RAN acquires the third information.

[0173] Understandably, before sending the third information to the terminal, the RAN first obtains the third information, for example, the RAN obtains the third information sent by the core network equipment, so that the RAN can broadcast the third information to the terminal, so that the terminal can perform access control or determine to skip access control based on the third information.

[0174] Optionally, the RAN acquires the third information, including at least one of the following:

[0175] The RAN acquires the third information from the core network equipment;

[0176] The RAN obtains the third information based on information from the core network equipment.

[0177] For example, when network load is high, network-side devices can restrict access attempts from terminals to avoid overload. In this case, the RAN can obtain third information from core network devices (e.g., heavily loaded NFs or AMFs). For instance, the core network devices may send third information to the RAN, or the RAN may determine the third information based on information from the core network devices. For example, when the sensing function is under high load, it can provide the RAN with information requiring terminal access restriction, or the sensing function can provide the RAN with information requiring terminal access restriction through other NFs (e.g., AMFs) (e.g., indicating that the NF is under high load, indicating terminal access restriction, etc.). The RAN then determines the third information, meaning that the information from the core network devices is the information for restricting terminal access (e.g., indicating that the NF is under high load, indicating UE access restriction, etc.). As another example, when the sensing function is under high load, it can also directly provide the third information to the RAN.

[0178] Optionally, the information from the core network device indicates at least one of the following:

[0179] Information used to indicate NF load;

[0180] Information used to indicate NF energy consumption;

[0181] Information used to indicate restrictions on terminal access.

[0182] For example, when the information used to indicate NF load indicates that the NF load is high, the RAN obtains the third information based on the information used to indicate the NF load, wherein the third information indicates prohibition control related to the NF; the terminal can perform access control based on the third information.

[0183] When the information used to indicate NF power consumption indicates that NF power consumption is high, the RAN obtains the third information based on the information used to indicate NF power consumption, wherein the third information indicates prohibition control related to NF, and the terminal can perform access control based on the third information.

[0184] When the information used to indicate restricted terminal access indicates restricted terminal access, the RAN obtains the third information based on the information used to indicate restricted terminal access, wherein the third information indicates restricted terminal access, and the terminal performs access control based on the third information.

[0185] In this embodiment, the RAN obtains the third information and sends the third information to the terminal, so that the terminal can perform access control or determine to skip access control according to the third information, which helps to optimize wireless communication between the terminal and the network side.

[0186] It should be noted that the embodiments of this application are RAN-side method embodiments corresponding to the terminal-side method embodiments in Figure 2 above. The relevant concepts and specific implementation processes can be referred to the descriptions in the terminal-side method embodiments above, and will not be repeated in this embodiment.

[0187] This application also provides a transmission control method executed by NF. Referring to Figure 4, the transmission control method includes the following steps:

[0188] Step 401: NF performs transmission control or determines to skip transmission control based on at least one of the fourth information and information used to indicate restrictions on terminal access;

[0189] The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0190] It should be noted that the target service may refer to a service supported by the terminal or mobile communication system (e.g., a 6G mobile communication system (6GS) and its subsequent evolutions), or a service that initiates an access attempt. In some implementations, the target service is the service that initiates an access attempt, which can be understood as the target service needing to initiate an access attempt when the NF needs to execute the target service.

[0191] In some implementations, the target service may include at least one of the following: mobility management service, session management service, service management service, connection management service, computing management service, data management service, algorithm management service, signaling management service, policy management service, data management service, PDU service, short message service, policy service, location service, computing service, sensing service, AI service, data service, multimedia service, immersive service, security service, task service, AIoT service, energy saving service, NTN service, slicing service, V2X service, and PC5 service.

[0192] In this embodiment, the NF performs transmission control or determines to skip transmission control based on the fourth information. In some implementations, some services do not require terminal access control. For example, sensing services do not require terminal access control; in this case, the NF can indicate the sensing service (i.e., the target service) based on the fourth information and determine to skip transmission control. In some implementations, some services require terminal access control; for example, some data transmitted through the user plane channel requires terminal access control. In this case, the NF can indicate the data to be transmitted through the user plane channel based on the fourth information and perform transmission control. Thus, the NF can perform transmission control or determine to skip transmission control based on the fourth information, thereby allowing or disallowing terminal access to the NF, which helps to effectively manage communication between the terminal and the network.

[0193] Optionally, the NF performs transmission control or determines to skip transmission control based on information used to indicate restrictions on terminal access, including:

[0194] When the information indicating that terminal access needs to be restricted indicates that terminal access needs to be restricted, the NF performs transmission control;

[0195] If the information indicating that terminal access restriction is not required indicates that terminal access restriction is not required, the NF determines to skip transmission control;

[0196] When the information indicating that terminal access restriction is not required indicates that terminal access restriction is not required, the NF performs transmission control, wherein the execution of transmission control indicates that a transmission attempt is permitted.

[0197] For example, when the information indicating restricted terminal access indicates that terminal access needs to be restricted, the NF determines to perform transmission control. When the information indicating restricted terminal access indicates that terminal access does not need to be restricted, the NF determines to skip transmission control, or the NF performs transmission control, that is, determines to allow the transmission attempt. Thus, the NF can allow or disallow a terminal to access the NF based on the information indicating restricted terminal access, which helps to effectively manage communication between the terminal and the network.

[0198] Optionally, the information used to indicate restricted terminal access includes at least one of the following:

[0199] Information used to indicate NF load;

[0200] Information used to indicate NF energy consumption.

[0201] For example, when the information used to indicate NF load indicates that the NF load is high, the NF performs transmission control based on the information used to indicate the NF load. At this time, terminal access can be restricted to avoid further increasing the NF load.

[0202] When the information indicating NF power consumption indicates that NF power consumption is high, NF performs transmission control based on the information indicating NF power consumption. At this time, terminal access can be restricted to avoid further increasing NF power consumption.

[0203] Optionally, the NF performs transmission control, including at least one of the following:

[0204] The NF determines whether a transmission attempt is allowed or not.

[0205] The NF performs transmission control in the event of congestion.

[0206] In some implementations, the NF allowing transmission attempts can be understood as the NF having downlink (DL) data or DL ​​signaling that needs to be sent to the terminal and attempting to send it to the terminal. The NF disallowing transmission attempts can be understood as the NF disallowing transmission, or the NF not sending DL data or DL ​​signaling to the terminal.

[0207] In some implementations, when the NF is congested, the NF determines whether to allow or disallow transmission attempts in order to better manage the transmission of the NF and avoid further exacerbating the congestion situation.

[0208] To better understand, the technical solutions provided in this application will be explained in detail below through some embodiments.

[0209] Please refer to Figure 5, which is a flowchart of an access method provided in an embodiment of this application. As shown in Figure 5, the method includes the following steps:

[0210] Step 501: The NF sends the fourth information or information indicating the need to restrict UE access to the RAN;

[0211] The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0212] Step 502: The RAN broadcasts third information to the UE; the third information is used to indicate control prohibition.

[0213] Step 503: The UE initiates an access attempt and performs access control or determines to skip access control based on at least one of the first information, the second information, and the third information.

[0214] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0215] The second information is used to indicate at least one of the following: target service, target network function (NF), user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0216] Optionally, the first information may be access identities, indicating that the UE is configured with the target service. For example, please refer to Table 1 below:

[0217] Table 1. Access identities

[0218] It is understandable that when the first information also indicates at least two services in the target service, the same or different Access Identity (AI) values ​​can be used. For example, when the first information indicates target service 1 and target service 2, different AI values ​​can also be used to distinguish them, that is, the AI ​​value is 4 when the UE is configured with target service 1, and the AI ​​value is 5 when the UE is configured with target service 2, as shown in Table 2 below:

[0219] Table 2. Access identities

[0220] Understandably, using existing AI values ​​can reduce the implementation complexity of the UE.

[0221] Understandably, using the new AI value allows the UE to distinguish between existing services and target services. For example, the AI ​​value for an existing MPS service is 1, while if the mobile terminal (e.g., a terminal) uses the new AI value (e.g., 4) when initiating a target service, the different priorities of existing and target services can be differentiated. For instance, the network side can set different third-party information for prohibition control for AI=1 and AI=4, such as performing access control on signaling related to the target service but not on the MPS service.

[0222] Understandably, if both Service 1 and Service 2 use the new AI value, different access controls can be applied to Service 1 and Service 2. For example, the network side can set different third-party information for prohibition control for AI=4 ​​and AI=5, such as applying access control to target Service 1 (AI=4) and not applying access control to target Service 2 (AI=5).

[0223] The second piece of information can be the access category (AC), indicating at least one of the following: the target service, the signaling related to the target service, and the data related to the target service.

[0224] As an optional implementation, when the access attempt type indicates that the access attempt is for a target service, or the access attempt is for signaling of a target service, or the conditions to be met indicate that the access attempt is for signaling of a target service initiated by the mobile terminal, the access type is determined to be an existing AC value, such as 3 (representing signaling initiated by the mobile terminal (MO_sig)), or a new AC value, such as 11 (representing signaling related to the target service initiated by the mobile terminal).

[0225] Understandably, using existing AC values ​​can reduce the implementation complexity of the UE.

[0226] Understandably, using the new AC value allows the UE to distinguish between existing signaling and signaling related to the target service. For example, an AC value of 3 for existing mobility management signaling indicates signaling initiated by the mobile terminal (MO_sig). However, if a new AC value (e.g., 11) is used for signaling related to the target service initiated by the mobile terminal, the different priorities of existing signaling and signaling related to the target service can be distinguished. For instance, the network side can set different third-party information for prohibition control for AC=3 and AC=11, such as performing access control for signaling related to the target service and not performing access control for mobility management signaling.

[0227] As an optional implementation, when the access attempt type indicates that the access attempt is for target service data, or when the conditions to be met indicate that the access attempt is for target service data initiated by the mobile terminal, the access type is determined to be an existing AC value, such as 7 (representing data initiated by the mobile terminal (MO_data)), or a new AC value, such as 12 (representing data related to the target service initiated by the mobile terminal). It is understood that using a new AC value allows the UE to distinguish between existing data and data related to the target service. For example, the existing uplink data has an AC value of 7 (=MO_data), while if the target service-related data initiated by the mobile terminal uses a new AC value (e.g., 12), the different priorities of existing data and target service-related data can be distinguished. For example, the network side can set different third information for prohibition control for AC=7 and AC=12, such as performing access control for data related to the target service and not performing access control for other data.

[0228] It is worth noting that the above method includes four possible implementations. For example, if the access attempt type indicates that the access attempt is for the target service, or the access attempt is for the signaling of the target service, or the conditions to be met indicate that the access attempt is for the signaling of the target service initiated by the mobile terminal, the access type is determined to be an existing AC value, such as 3 (= MO_sig); if the access attempt type indicates that the access attempt is for the target service data, or the conditions to be met indicate that the access attempt is for the data of the target service initiated by the mobile terminal, the access type is determined to be a new AC value, such as 12 (= data related to the target service initiated by the mobile terminal). Other combinations are not listed here.

[0229] Table 3 below shows one possible implementation method when the second information is AC:

[0230] Table 3. Mapping table for access categories

[0231] Optionally, the method further includes: the UE determining a first cause value based on at least one of the first information and the second information.

[0232] Optionally, the first reason value can be an RRC establishment reason value or an RRC recovery reason value.

[0233] It is understood that the UE determines the first cause value based on at least one of the first information and the second information. The first information can be an existing value or a new value, the second information can also be an existing value or a new value, and the first cause value can also be an existing value or a new value. The following are just a few examples of these cases:

[0234] As an optional implementation, when the UE is configured with a new AI value (e.g., AI=4) indicating that the UE is configured for the target service, the first cause value indicates the target service initiated by the mobile terminal when an access attempt is made for the target service. It is understood that this implementation does not distinguish whether the first cause value is signaling for the target service or data for the target service. One implementation is shown in Table 4 below:

[0235] Table 4. Mapping table of access identifier / access category and RRC establishment reason when establishing N1 NAS signaling connection via NR to 5GCN

[0236] As an optional implementation, when the UE is configured with a new AI value (e.g., AI=4) indicating that the UE is configured for the target service, the first cause value is set according to the AC when an access attempt is made for the target service. When the AC indicates signaling related to the target service or signaling related to the target service initiated by the mobile terminal, the first cause value is determined to be an existing cause value, such as signaling initiated by the mobile terminal (mo-Signalling), or a new cause value, such as signaling related to the target service initiated by the mobile terminal.

[0237] It is understandable that by using existing cause values, the implementation complexity of the UE can be reduced.

[0238] Understandably, using new existing cause values ​​allows the UE and RAN to distinguish between existing signaling and target service-related signaling, or between existing data and target service-related data. For example, the existing mobility management signaling uses the RRC establishment cause value *mo-Signalling*. If the target service-related signaling initiated by the mobile terminal uses a new RRC establishment cause value (e.g., target service-related signaling initiated by the mobile terminal), it can differentiate the different priorities of existing mobility management signaling and target service-related signaling. For instance, the network side can set different transmission priorities for different RRC establishment causes. For example, the RAN can prioritize transmission resources for RRC establishment cause values ​​of target service-related signaling initiated by the mobile terminal.

[0239] As an optional implementation, when the UE is configured with a new AI value (e.g., AI=4) to indicate that the UE is configured for the target service, the first reason value is set according to the AC when an access attempt is made for the target service. The AC can use an existing value. One implementation is shown in Table 5 below:

[0240] Table 5. Mapping table of access identifier / access category and RRC establishment reason when establishing an N1 NAS signaling connection via NR to 5GCN

[0241] As an optional implementation, when the UE is configured with a new AI value (e.g., AI=4) to indicate that the UE is configured for the target service, the first reason value is set according to the AC when an access attempt is made for the target service. The AC can use the new AC value. One implementation is shown in Table 6 below:

[0242] Table 6. Mapping table of access identifier / access category and RRC establishment reason when establishing N1 NAS signaling connection via NR to 5GCN

[0243] As an optional implementation, an existing AI value (e.g., AI = 0) can be used. When an access attempt is made for a target service, the first cause value is set according to the AC. When the AC is a new AC value, such as indicating signaling related to the target service or signaling related to the target service initiated by the mobile terminal, the first cause value is determined to be either an existing cause value, such as signaling initiated by the mobile terminal (mo-Signalling), or a new cause value, such as signaling related to the target service initiated by the mobile terminal. One implementation is shown in Table 7 below:

[0244] Table 7. Mapping table of access identifier / access category and RRC establishment reason when establishing N1 NAS signaling connection via NR to 5GCN

[0245] It is understandable that the table above contains 8 optional implementation methods. For example, when AC=11, the RRC establishment reason value indicates an existing reason value (e.g., mo-Signalling); when AC=12, the RRC establishment reason value indicates a new reason value (e.g., data related to the target service initiated by the mobile terminal). For another example, if the signaling related to the target service uses an existing AC value, such as 3 (=MO_sig), then the RRC establishment reason value indicates an existing reason value, such as mo-Signalling; while the data related to the target service uses a new AC value, such as AC=12 for data related to the target service, then the RRC establishment reason value can indicate an existing reason value, such as mo-Data, or a new reason value, such as data related to the target service initiated by the mobile terminal, as shown in Table 8 below. Other combinations are not listed here.

[0246] Table 8. Mapping table of access identifier / access category and RRC establishment reason when establishing N1 NAS signaling connection via NR to 5GCN

[0247] The above embodiments indicate that the first information can be an access identifier, indicating that the UE is configured with a target service, and is a service-level indication. In some embodiments, for example, the UE can communicate directly with the NF, in which case the first information can be an NF-level indication.

[0248] The “target service” in the above implementation can be replaced with “target NF”. Table 9 below shows an optional implementation when the second information is AC. Other combinations are similar and will not be listed one by one.

[0249] Table 9. Access Type Mapping Table

[0250] Understandably, by using NF-level indications, the UE can correctly determine the AC and RRC establishment reason values. For example, if the UE can communicate with a target NF, then when the AC value indicates the target NF, it can distinguish the signaling / data of the target NF from that of other NFs. For instance, if the AC value indicates the target NF when communicating with it, but an existing AC value (e.g., AC=3) is used when transmitting mobility management signaling, the network can allocate different scheduling resources, transmission priorities, or different access controls, which helps improve the communication quality between the terminal and the network.

[0251] In some implementations, the first information may be access identities (AI), indicating that the UE is configured for user plane channel transmission. Please refer to Table 10 below:

[0252] Table 10. Access Identifier

[0253] Understandably, using existing AI values ​​(Access Identity numbers) can reduce the implementation complexity of the UE.

[0254] Understandably, using the new AI value allows the UE to distinguish between existing services and user plane channel transmissions. For example, the AI ​​value for existing MPS services is 1, while if the mobile terminal uses a new AI value (e.g., 4) when initiating user plane channel transmissions, it can differentiate the different priorities of existing services (e.g., MPS) and user plane channel transmissions. For instance, the network side can set different third-party information for prohibition control for AI=1 and AI=4, such as performing access control for user plane channel transmissions but not performing access control for MPS services.

[0255] The second piece of information can be access categories, indicating at least one of user plane channel signaling and user plane channel data.

[0256] As an optional implementation, if the access attempt type indicates that the access attempt is for user plane channel signaling, or if the conditions to be met indicate that the access attempt is for user plane channel signaling initiated by the mobile terminal, the access type is determined to be a new AC value, such as 11 (representing user plane channel signaling initiated by the mobile terminal).

[0257] Understandably, in related technologies, if user plane channel signaling is transmitted through the user plane channel, an AC indicator needs to be set to indicate data initiated by the mobile terminal. Therefore, the RAN cannot distinguish whether the UE is transmitting data or signaling transmitted through the user plane channel. Using a new AC value allows the UE and RAN to distinguish between existing signaling and user plane channel signaling, and also allows them to distinguish between existing data and signaling transmitted through the user plane channel. An optional implementation is shown in Table 11 below:

[0258] Table 11. Access Identifier

[0259] Optionally, the method further includes: the UE determining a first cause value based on at least one of the first information and the second information.

[0260] Optionally, the first reason value can be an RRC establishment reason value or an RRC recovery reason value.

[0261] It is understood that the UE determines the first cause value based on at least one of the first information and the second information. The first information can use an existing value or a new value, and the second information can also use an existing value or a new value; examples of a few such cases are given below.

[0262] As an optional implementation, when the UE is configured with a new AI value (e.g., AI=4) to indicate that the UE is configured to transmit signaling via the user plane channel, when an access attempt is made for transmitting signaling via the user plane channel, the first cause value indicates the user plane channel transmission signaling, as shown in Table 12 below:

[0263] Table 12. Mapping table of access identifier / access category and RRC establishment reason when establishing N1 NAS signaling connection via NR to 5GCN

[0264] As an optional implementation, when the UE is configured with a new AI value (e.g., AI=4) to indicate that the UE is configured with a target service, the first cause value is set according to the AC when access attempts to transmit signaling on the user plane channel. The AC can use an existing value. One implementation is shown in Table 13 below:

[0265] Table 13. Mapping table of access identifier / access category and RRC establishment reason when establishing N1 NAS signaling connection via NR to 5GCN

[0266] As an optional implementation, when the UE is configured with a new AI value (e.g., AI=4) to indicate that the UE is configured to transmit signaling via the user plane channel, the first cause value is set according to the AC when an access attempt is made for transmitting signaling via the user plane channel. The AC can use a new AC value. One implementation is shown in Table 14 below:

[0267] Table 14. Mapping table of access identifier / access category and RRC establishment reason when establishing N1 NAS signaling connection via NR to 5GCN

[0268] As an optional implementation, an existing AI value (e.g., AI = 0) can be used. When access attempts to be used for user plane channel transmission, the first cause value is set according to the AC. When the AC is a new AC value, such as indicating user plane channel transmission signaling or user plane channel transmission signaling initiated by the mobile terminal, the target cause value is determined to be either an existing cause value, such as mobile-initiated signaling (mo-Signalling), or a new cause value, such as mobile-initiated user plane channel transmission signaling. One implementation is shown in Table 15 below:

[0269] Table 15. Mapping table of access identifier / access category and RRC establishment reason when establishing N1 NAS signaling connection via NR to 5GCN

[0270] It is understood that the table above contains four optional implementation methods. For example, when AC=11, the RRC establishment cause value indicates an existing cause value (e.g., mo-Signalling), and when AC=12, the RRC establishment cause value indicates a new cause value (e.g., user plane channel data transmission initiated by the mobile terminal). Other combinations are not listed here.

[0271] The access control method provided in this application can be executed by an access control device. This application uses an access control device executing the access control method as an example to illustrate the access control device provided in this application.

[0272] This application provides an access control device. As an example, the access control device may be a communication device or a component within a communication device, such as a chip. The communication device may be a terminal, a network-side device, or a server, etc. Exemplarily, the terminal may include, but is not limited to, the type of terminal 11 listed above, and the network-side device may include, but is not limited to, the type of network-side device 12 listed above. This application does not impose specific limitations.

[0273] The access control device includes a receiving module, a transmitting module, and a processing module. These modules can be implemented in software or hardware. When implemented in hardware, the processing module can be implemented by a processor. For example, the processor can include general-purpose processors, special-purpose processors, etc., such as central processing units (CPUs), microprocessors, digital signal processors (DSPs), artificial intelligence (AI) processors, graphics processing units (GPUs), application-specific integrated circuits (ASICs), network processors (NPs), field-programmable gate arrays (FPGAs), or other programmable logic devices, gate circuits, transistors, discrete hardware components, etc. The receiving and transmitting modules can be implemented by a communication interface, which can include one or more of the following: transceivers, pins, circuits, buses, radio frequency units, etc.

[0274] Specifically, referring to Figure 6, when the access control device is a terminal or a component within a terminal, the access control device 600 includes:

[0275] The first processing module 601 is configured to perform access control or determine to skip access control based on at least one of the first information, the second information, and the third information.

[0276] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0277] The second information is used to indicate at least one of the following: target service, target NF, user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel;

[0278] The third piece of information is used to indicate that control is prohibited.

[0279] Optionally, the first processing module 601 is further configured to:

[0280] Allow access attempts or disallow access attempts.

[0281] Optionally, the third information satisfies at least one of the following:

[0282] The third information is associated with at least one of the following: the first information, the second information, and the Public Land Mobile Network (PLMN);

[0283] The third information includes at least one of the following: information for indicating prohibition of control, information for indicating that prohibition of control is not performed, information indicating that the third information is used for all PLMNs, and information indicating that the third information is used for a specific PLMN.

[0284] Optionally, the first processing module 601 is further configured to perform at least one of the following:

[0285] If the third information includes information indicating that control is prohibited, access control is performed.

[0286] If the third information does not include information indicating prohibition of control or includes information indicating that prohibition of control is not to be performed, it is determined that access control should be skipped.

[0287] If the third information does not include information indicating prohibition of control or includes information indicating not to enforce prohibition of control, access control is performed, wherein the execution of access control indicates that the access attempt is permitted.

[0288] Optionally, the device further includes:

[0289] The first acquisition module is used to acquire at least one of the first information, the second information, and the third information.

[0290] Optionally, the acquisition module is further configured to:

[0291] At least one of the first information, the second information, and the third information is obtained through a targeted method, wherein the targeted method includes at least one of the following:

[0292] Pre-configured;

[0293] Access attempt;

[0294] The target business

[0295] Broadcast message;

[0296] NAS signaling.

[0297] Optionally, the first processing module 601 is further configured to:

[0298] The first cause value is determined based on at least one of the first information and the second information.

[0299] Optionally, the first cause value satisfies at least one of the following:

[0300] The first cause value includes at least one of the Radio Resource Control (RRC) establishment cause value and the RRC recovery cause value;

[0301] The first cause value indicates at least one of the following: terminal-initiated signaling, terminal-initiated data, terminal-initiated target NF signaling, terminal-initiated target NF data, terminal-initiated target service signaling, terminal-initiated target service data, terminal-initiated user plane channel signaling, and terminal-initiated user plane channel data.

[0302] Optionally, the target service includes at least one of the following:

[0303] Services supported by the terminal or mobile communication system;

[0304] The business that initiates an access attempt.

[0305] Optionally, the target NF includes at least one of the following:

[0306] The terminal executes the NF corresponding to the target service;

[0307] The NF that receives the signaling sent by the terminal.

[0308] The access control device 600 provided in this application embodiment can implement the various processes implemented by the terminal in the method embodiment of FIG2 or FIG5 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0309] Referring to Figure 7, when the access control device is a network-side device or a component within a network-side device, the access control device 700 includes:

[0310] The sending module 701 is used to send third information to the terminal, the third information being used to indicate that control is prohibited.

[0311] Optionally, the sending module 701 is further configured to:

[0312] The RAN sends third information to the terminal via broadcast messages.

[0313] Optionally, the device further includes a second acquisition module, used for:

[0314] Obtain the third information.

[0315] Optionally, the second acquisition module is further configured to perform at least one of the following:

[0316] Obtain the third information from the core network device;

[0317] The third information is obtained based on information from the core network equipment.

[0318] Optionally, the information from the core network device indicates at least one of the following:

[0319] Information used to indicate NF load;

[0320] Information used to indicate NF energy consumption;

[0321] Information used to indicate restrictions on terminal access.

[0322] Optionally, the third information satisfies at least one of the following:

[0323] The third information is associated with at least one of the following: first information, second information, or PLMN;

[0324] The third information includes at least one of the following: information for indicating prohibition of control, information for indicating that prohibition of control is not performed, information indicating that the third information is used for all PLMNs, and information indicating that the third information is used for a specific PLMN;

[0325] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0326] The second information is used to indicate at least one of the following: target service, target NF, user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0327] The access control device 700 provided in this application embodiment can implement the various processes implemented by the RAN in the method embodiment of FIG3 or FIG5 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0328] The transmission control method provided in this application can be executed by a transmission control device. This application uses the example of a transmission control device executing the transmission control method to illustrate the transmission control device provided in this application.

[0329] Referring to Figure 8, this application embodiment also provides a transmission control device 800, which is applied to an NF (Network Functions). The transmission control device 800 includes:

[0330] The second processing module 801 is configured to perform transmission control or determine to skip transmission control based on at least one of the fourth information and information indicating restriction of terminal access.

[0331] The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0332] Optionally, the second processing module 801 is further configured to perform at least one of the following:

[0333] Determine whether to allow or disallow the transmission attempt;

[0334] In the event of NF congestion, transmission control is performed.

[0335] Optionally, the information used to indicate restricted terminal access includes at least one of the following:

[0336] Information used to indicate NF load;

[0337] Information used to indicate NF energy consumption.

[0338] Optionally, the second processing module 801 is further configured to perform at least one of the following:

[0339] When the information indicating that terminal access needs to be restricted indicates that terminal access needs to be restricted, transmission control is performed;

[0340] If the information indicating that terminal access restriction is not required indicates that transmission control should be skipped;

[0341] If the information indicating that terminal access restriction is not required is used to indicate that terminal access restriction is not required, transmission control is performed, wherein the transmission control instruction determines that a transmission attempt is permitted.

[0342] The transmission control device 800 provided in this application embodiment can implement the various processes implemented by NF in the method embodiment of FIG4 or FIG5 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0343] As shown in Figure 9, this application embodiment also provides a communication device 900, including a processor 901 and a memory 902. The memory 902 stores programs or instructions that can run on the processor 901. For example, when the communication device 900 is a terminal, the program or instructions executed by the processor 901 implement the various steps of the above-described access control method embodiment and achieve the same technical effect. When the communication device 900 is a RAN, the program or instructions executed by the processor 901 implement the various steps of the above-described access control method embodiment and achieve the same technical effect. When the communication device 900 is an NF, the program or instructions executed by the processor 901 implement the various steps of the above-described transmission control method embodiment and achieve the same technical effect. To avoid repetition, further details are omitted here.

[0344] This application also provides a terminal, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps in the method embodiment shown in FIG2. This terminal embodiment corresponds to the above-described terminal-side method embodiment, and all implementation processes and methods of the above-described method embodiments can be applied to this terminal embodiment and can achieve the same technical effect. The terminal may be the access control device shown in FIG6. Specifically, FIG10 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of this application.

[0345] The terminal 1000 includes, but is not limited to, at least some of the following components: radio frequency unit 1001, network module 1002, audio output unit 1003, input unit 1004, sensor 1005, display unit 1006, user input unit 1007, interface unit 1008, memory 1009, and processor 1010.

[0346] Those skilled in the art will understand that the terminal 1000 may also include a power supply (such as a battery) for powering various components. The power supply can be logically connected to the processor 1010 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The terminal structure shown in Figure 10 does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0347] It should be understood that, in this embodiment, the input unit 1004 may include a graphics processor 10041 and a microphone 10042. The graphics processor 10041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 1006 may include a display panel 10061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1007 includes a touch panel 10071 and at least one of other input devices 10072. The touch panel 10071 is also called a touch screen. The touch panel 10071 may include a touch detection device and a touch controller. Other input devices 10072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.

[0348] In this embodiment, after receiving downlink data from the network-side device, the radio frequency unit 1001 can transmit it to the processor 1010 for processing; in addition, the radio frequency unit 1001 can send uplink data to the network-side device. Typically, the radio frequency unit 1001 includes, but is not limited to, antennas, amplifiers, transceivers, couplers, low-noise amplifiers, duplexers, etc.

[0349] The memory 1009 can be used to store software programs or instructions, as well as various data. The memory 1009 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 1009 may include volatile memory or non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 1009 in this embodiment includes, but is not limited to, these and any other suitable types of memory.

[0350] The processor 1010 may include one or more processing units; optionally, the processor 1010 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into the processor 1010.

[0351] The processor 1010 is configured to perform access control or determine to skip access control based on at least one of the first information, the second information, and the third information.

[0352] Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel;

[0353] The second information is used to indicate at least one of the following: target service, target network function (NF), user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel;

[0354] The third piece of information is used to indicate that control is prohibited.

[0355] It is understood that the terminal provided in this embodiment can implement all the technical processes of the method embodiment in Figure 2. The implementation process of each implementation method mentioned in this embodiment can refer to the relevant description in the method embodiment in Figure 2 and achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.

[0356] This application also provides a network-side device, including a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method embodiment shown in FIG3 or FIG4. This network-side device embodiment corresponds to the above-described network-side device method embodiment. All implementation processes and methods of the above-described method embodiments can be applied to this network-side device embodiment and can achieve the same technical effect.

[0357] Specifically, this application embodiment also provides a network-side device, which may be the access control device shown in FIG7. As shown in FIG11, the network-side device 1100 includes: an antenna 111, a radio frequency device 112, a baseband device 113, a processor 114, and a memory 115. The antenna 111 is connected to the radio frequency device 112. In the uplink direction, the radio frequency device 112 receives information through the antenna 111 and sends the received information to the baseband device 113 for processing. In the downlink direction, the baseband device 113 processes the information to be transmitted and sends it to the radio frequency device 112. The radio frequency device 112 processes the received information and transmits it through the antenna 111.

[0358] The method executed by the network-side device in the above embodiments can be implemented in the baseband device 113, which includes a baseband processor.

[0359] The baseband device 113 may include at least one baseband board, on which multiple chips are disposed, as shown in FIG11. One of the chips is, for example, a baseband processor, which is connected to the memory 115 via a bus interface to call the program or instructions in the memory 115 to execute the network-side device operation shown in the above method embodiment.

[0360] The network-side device may also include a network interface 116, such as a Common Public Radio Interface (CPRI).

[0361] The radio frequency device 112 is used to send third information to the terminal, and the third information is used to indicate that control is prohibited.

[0362] In addition, the network-side device 1100 of this application embodiment also includes: a program or instructions stored in the memory 115 and executable on the processor 114. The processor 114 calls the program or instructions in the memory 115 to execute the methods executed by each module shown in FIG7 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.

[0363] Specifically, this application embodiment also provides a network-side device. As shown in FIG12, the network-side device 1200 includes: a processor 1201, a network interface 1202, and a memory 1203. The network-side device may be the transmission control device shown in FIG8. The network interface 1202 is, for example, a Common Public Radio Interface (CPRI).

[0364] The processor 1201 is used to perform transmission control or determine to skip transmission control based on at least one of the fourth information and information for indicating restriction of terminal access;

[0365] The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

[0366] In addition, the network-side device 1200 of this application embodiment also includes: a program or instructions stored in the memory 1203 and executable on the processor 1201. The processor 1201 calls the program or instructions in the memory 1203 to execute the methods executed by each module shown in FIG8 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.

[0367] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the method embodiments described in FIG2, FIG3, or FIG4 above and achieve the same technical effect. To avoid repetition, they will not be described again here.

[0368] The processor mentioned above is either the processor in the terminal described in the above embodiments or the processor in the network-side device. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk. In some examples, the readable storage medium may be a non-transient readable storage medium.

[0369] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the method embodiments described in FIG2, FIG3 or FIG4 above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0370] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0371] This application also provides a computer program / program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the method embodiments described in FIG2, FIG3, or FIG4 above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0372] This application also provides a wireless communication system, including a terminal, a RAN, and an NF. The terminal can be used to execute various processes of the method embodiment shown in FIG2, the RAN can be used to execute various processes of the method embodiment shown in FIG3, and the NF can be used to execute various processes of the method embodiment shown in FIG4.

[0373] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0374] From the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of computer software products plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.), and the computer software product includes several instructions to cause the terminal or network-side device to execute the methods described in the various embodiments of this application.

[0375] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other implementations under the guidance of this application without departing from the spirit and scope of the claims. All of these implementations are within the protection scope of this application.

Claims

1. An access control method, comprising: The terminal performs access control or determines to skip access control based on at least one of the first, second, and third information. Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel; The second information is used to indicate at least one of the following: target service, target network function (NF), user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel; The third piece of information is used to indicate that control is prohibited.

2. The method of claim 1, wherein, The terminal performs access control, including: The terminal may allow access attempts or disallow access attempts.

3. The method of claim 1 or 2, wherein, The third information satisfies at least one of the following: The third information is associated with at least one of the following: the first information, the second information, and the Public Land Mobile Network (PLMN); The third information includes at least one of the following: information for indicating prohibition of control, information for indicating that prohibition of control is not performed, information indicating that the third information is used for all PLMNs, and information indicating that the third information is used for a specific PLMN.

4. The method of any one of claims 1-3, wherein, The terminal performs access control or determines to skip access control based on third information, including at least one of the following: If the third information includes information indicating that control is prohibited, the terminal performs access control; If the third information does not include information indicating prohibition of control or includes information indicating that prohibition of control should not be performed, the terminal determines to skip access control; If the third information does not include information indicating prohibition of control or includes information indicating not to enforce prohibition of control, the terminal performs access control, wherein the execution of access control indicates that the access attempt is permitted.

5. The method of any one of claims 1-4, wherein, The method further includes: The terminal acquires at least one of the first information, the second information, and the third information.

6. The method of claim 5, wherein, The terminal acquires at least one of the first information, the second information, and the third information, including: The terminal acquires at least one of the first information, the second information, and the third information through a targeted method, wherein the targeted method includes at least one of the following: Pre-configured; Access attempt; The target service; Broadcast message; NAS signaling.

7. The method of claim 1, wherein, The method further includes: The terminal determines a first cause value based on at least one of the first information and the second information.

8. The method of claim 7, wherein, The first cause value satisfies at least one of the following: The first cause value includes at least one of the Radio Resource Control (RRC) establishment cause value and the RRC recovery cause value; The first cause value indicates at least one of the following: terminal-initiated signaling, terminal-initiated data, terminal-initiated target NF signaling, terminal-initiated target NF data, terminal-initiated target service signaling, terminal-initiated target service data, terminal-initiated user plane channel signaling, and terminal-initiated user plane channel data.

9. The method of claim 1, wherein, The target business includes at least one of the following: Services supported by the terminal or mobile communication system; The business that initiates an access attempt.

10. The method of claim 1, wherein, The target NF includes at least one of the following: The terminal executes the NF corresponding to the target service; The NF that receives the signaling sent by the terminal.

11. An access control method, comprising: The RAN sends a third message to the terminal, which is used to indicate that control is prohibited.

12. The method of claim 11, wherein, The RAN sends third information to the terminal, including: The RAN sends third information to the terminal via broadcast messages.

13. The method of claim 11 or 12, wherein, The method further includes: The RAN acquires the third information.

14. The method of claim 13, wherein, The RAN acquires the third information, including at least one of the following: The RAN acquires the third information from the core network equipment; The RAN obtains the third information based on information from the core network equipment.

15. The method of claim 14, wherein, The information from the core network equipment indicates at least one of the following: Information used to indicate NF load; Information used to indicate NF energy consumption; Information used to indicate restrictions on terminal access.

16. The method according to any one of claims 11-15, wherein, The third information satisfies at least one of the following: The third information is associated with at least one of the following: first information, second information, or PLMN; The third information includes at least one of the following: information for indicating prohibition of control, information for indicating that prohibition of control is not performed, information indicating that the third information is used for all PLMNs, and information indicating that the third information is used for a specific PLMN; Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel; The second information is used to indicate at least one of the following: target service, target NF, user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

17. A transmission control method, comprising: NF performs transmission control or determines to skip transmission control based on at least one of the fourth information and information used to indicate restrictions on terminal access; The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

18. The method according to claim 17, wherein, The NF performs transmission control, including at least one of the following: The NF determines whether a transmission attempt is allowed or not. The NF performs transmission control in the event of congestion.

19. The method according to claim 17 or 18, wherein, The information used to indicate restrictions on terminal access includes at least one of the following: Information used to indicate NF load; Information used to indicate NF energy consumption.

20. The method according to any one of claims 17-19, wherein, The NF performs transmission control or determines to skip transmission control based on information used to indicate restrictions on terminal access, including at least one of the following: When the information indicating that terminal access needs to be restricted indicates that terminal access needs to be restricted, the NF performs transmission control; If the information indicating that terminal access restriction is not required indicates that terminal access restriction is not required, the NF determines to skip transmission control; When the information indicating that terminal access restriction is not required indicates that terminal access restriction is not required, the NF performs transmission control, wherein the execution of transmission control indicates that a transmission attempt is permitted.

21. An access control device, applied to a terminal, wherein, The device includes: The first processing module is configured to perform access control or determine to skip access control based on at least one of the first information, the second information, and the third information. Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel; The second information is used to indicate at least one of the following: target service, target NF, user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel; The third piece of information is used to indicate that control is prohibited.

22. The apparatus according to claim 21, wherein, The first processing module is also used for: Allow access attempts or disallow access attempts.

23. The apparatus according to claim 21 or 22, wherein, The first processing module is also used for at least one of the following: If the third information includes information indicating that control is prohibited, access control is performed. If the third information does not include information indicating prohibition of control or includes information indicating that prohibition of control is not to be performed, it is determined that access control should be skipped. If the third information does not include information indicating prohibition of control or includes information indicating not to enforce prohibition of control, access control is performed, wherein the execution of access control indicates that the access attempt is permitted.

24. The apparatus according to any one of claims 21-23, wherein, The device further includes: The first acquisition module is used to acquire at least one of the first information, the second information, and the third information.

25. The apparatus according to claim 24, wherein, The acquisition module is also used for: At least one of the first information, the second information, and the third information is obtained through a targeted method, wherein the targeted method includes at least one of the following: Pre-configured; Access attempt; The target business Broadcast message; NAS signaling.

26. An access control device, applied to a RAN, wherein, The device includes: The sending module is used to send third information to the terminal, the third information being used to indicate that control is prohibited.

27. The apparatus according to claim 26, wherein, The sending module is also used for: The RAN sends third information to the terminal via broadcast messages.

28. The apparatus according to claim 26 or 27, wherein, The device further includes a second acquisition module, used for at least one of the following: Obtain the third information from the core network device; The third information is obtained based on information from the core network equipment.

29. The apparatus according to claim 26 or 27, wherein, The third information satisfies at least one of the following: The third information is associated with at least one of the following: first information, second information, or PLMN; The third information includes at least one of the following: information for indicating prohibition of control, information for indicating that prohibition of control is not performed, information indicating that the third information is used for all PLMNs, and information indicating that the third information is used for a specific PLMN; Wherein, the first information is used to indicate at least one of the following: the terminal is configured with a target service, or the terminal is configured to transmit through a user plane channel; The second information is used to indicate at least one of the following: target service, target NF, user plane channel transmission, signaling related to the target service, data related to the target service, signaling related to the target NF, data related to the target NF, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

30. A transmission control device, applied to NF, wherein, The device includes: The second processing module is configured to perform transmission control or determine to skip transmission control based on at least one of the fourth information and information indicating restriction of terminal access. The fourth information is used to indicate at least one of the following: target service, user plane channel transmission, signaling related to the target service, data related to the target service, signaling transmitted through the user plane channel, and data transmitted through the user plane channel.

31. The apparatus according to claim 30, wherein, The second processing module is also used for at least one of the following: Determine whether to allow or disallow the transmission attempt; In the event of NF congestion, transmission control is performed.

32. The apparatus according to claim 30 or 31, wherein, The second processing module is also used for at least one of the following: When the information indicating that terminal access needs to be restricted indicates that terminal access needs to be restricted, transmission control is performed; If the information indicating that terminal access restriction is not required indicates that transmission control should be skipped; If the information indicating that terminal access restriction is not required is used to indicate that terminal access restriction is not required, transmission control is performed, wherein the transmission control instruction determines that a transmission attempt is permitted.

33. A terminal, comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the access control method as described in any one of claims 1-10.

34. A network-side device, comprising a processor and a memory, the memory storing a program or instructions executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the access control method as described in any one of claims 11-16, or implement the steps of the transmission control method as described in any one of claims 17-20.

35. A readable storage medium, wherein, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the access control method as described in any one of claims 1-10, or the steps of the access control method as described in any one of claims 11-16, or the steps of the transmission control method as described in any one of claims 17-20.

36. A computer program product, wherein, The computer program product is stored in a storage medium and is executed by at least one processor to implement the steps of the access control method as claimed in any one of claims 1-10, or the steps of the access control method as claimed in any one of claims 11-16, or the steps of the transmission control method as claimed in any one of claims 17-20.