Network access method, apparatus, network device and terminal device
Patent Information
- Application Number
- PCT/CN2026/086152
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-28
- Filing Date
- 2026-03-26
- Publication Date
- 2026-10-01
Smart Images

Figure CN2026086152_01102026_PF_FP_ABST
Abstract
Description
Network access methods and devices, network equipment and terminal equipment
[0001] This application claims priority to Chinese patent application CN202510382581.8, filed on March 28, 2025. The entire contents of the aforementioned Chinese patent application are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communication technology, and in particular to a network access method and apparatus, network equipment and terminal equipment. Background Technology
[0003] Satellite-based direct-connection technology refers to a mobile phone connecting to a terrestrial mobile network via satellite to enjoy mobile services. The satellite performs relay functions or some of the functions of a terrestrial base station, forwarding or transmitting signals from the mobile phone to the base station, or vice versa. The mobile phone, satellite, terrestrial gateway, base station, and core network constitute the direct-connection satellite communication network, as shown in Figure 1. The coverage area of the direct-connection satellite network supplements the coverage of the terrestrial mobile network, including areas where the terrestrial mobile network cannot reach or has weak coverage, such as sea areas, mountains, forests, deserts, and areas affected by natural disasters.
[0004] As shown in Figure 2, when a satellite is in operation, it will scan neighboring countries or adjacent regions. Unauthorized terrestrial mobile users in those countries or regions, such as mobile phone A and mobile phone B, will be unable to access the satellite and enjoy satellite communication services. This is because the current process in terrestrial mobile network systems requires successful user authentication and authorization before users can enjoy mobile network services; unauthorized terminal devices cannot enjoy mobile communication services.
[0005] The registration process for UE (User Equipment) in the prior art is shown in Figure 3, and specifically includes:
[0006] Step 1: The UE initiates a registration request, which includes at least one UE identifier, such as SUCI (Subscriber Concealed Identifier), 5G-GUTI (5G Globally Unique Temporary UE Identity), IMEI (International Mobile Equipment Identity), IMEISV (International Mobile Equipment Identity Software Version), 5G-S-TMSI (5G-S-Temporary Mobile Subscriber Identity), MAC Address (Media Access Control Address), EUI-64 (Extended Unique Identifier), etc.
[0007] Step 2: The gNB (base station in the 5G network) forwards the UE's registration request to the AMF (Authentication Management Function), which includes information such as PLMN (Public Land Mobile Network), UE location information, and cell ID. If the AMF changes, the new AMF will send a request to the old AMF, requesting parameters such as UE context.
[0008] Step 3: If the UE registration request message received by the AMF does not contain SUCI, send a message to the UE requesting it to report SUCI;
[0009] Step 4: The UE sends a SUCI to the AMF;
[0010] Step 5: AMF selects AUSF (Authentication Server Function) based on SUCI and sends an authentication request message to AUSF;
[0011] Step 6: The process of exchanging UE subscription information between AUSF and UDM (Unified Data Management); when there is no authorized subscription at the location of the UE, it is found that the UE does not have a roaming subscription, and UDM directly sends an authentication failure to AUSF and executes step 8a; otherwise, execute steps 7-9.
[0012] Step 7: AUSF generates authentication key parameters and performs authentication and security encryption processes;
[0013] Step 8: After the authentication and security process is completed, the AMF sends a registration acceptance message to the UE;
[0014] Step 9: The UE sends a registration completion message to the AMF to end the process;
[0015] Step 8a: The AMF sends a registration rejection message to the UE, ending the process.
[0016] As can be seen from the UE registration process, only UEs with a contract can complete the authentication process. Only after successful authentication and authorization will the network provide services to the UE. Network services cannot be provided to UEs without authorization.
[0017] The UE attachment process in the prior art is shown in Figure 4, which specifically includes:
[0018] Step 1: The UE sends an RLOS (Restricted Local Operator Services) attach request, which includes the IMEI or other UE identifiers;
[0019] Step 2: The eNB (base station in the 4G LTE network) forwards the RLOS attach request to the MME (Mobility Management Entity);
[0020] Step 3: The MME sends a message to the UE to report the IMSI / IMEI;
[0021] Step 4: UE reports IMSI / IMEI;
[0022] Step 5: If the MME supports RLOS functionality, the MME decides not to perform the authentication process.
[0023] Step 6: Configure the default bearer in the MME. The MME and SGW (Serving Gateway) / PGW (PDN Gateway) mark the IMSI / IMEI as an unauthenticated UE.
[0024] Step 7: The SGW / PGW sends a message to the PCRF (Policy and Charging Rules Function) to update the bearer and mark the IMSI / IMEI as an unauthenticated UE.
[0025] Step 8: The SGW / PGW notifies the MME of the bearer establishment completion information;
[0026] Step 9: The MME notifies the UE that the RLOS attach request has been accepted;
[0027] Step 10: UE feedback attachment process completed.
[0028] It should be noted that steps 3 and 4 above are optional.
[0029] The UE attachment process reveals that it requires the UE to be limited to RLOS features and directly authorized to provide RLOS services without undergoing a subscription authentication process. This process cannot provide network service to unauthorized UEs in satellite communication scenarios. Summary of the Invention
[0030] The technical problem to be solved by this application is to overcome the shortcomings of the prior art in providing network service to UEs without authentication in satellite communication scenarios, and to provide a network access method and apparatus, network equipment and terminal equipment.
[0031] This application solves the above-mentioned technical problems through the following technical solution:
[0032] The first aspect of this application provides a network access method applied to a network device. The network access method includes the following steps: configuring a policy for a corresponding node in the network, the policy being whether to provide all or part of the service to an unauthorized terminal device; receiving an access request initiated by a terminal device; and, in response to determining that the terminal device is located in a satellite communication cell, determining whether to provide the corresponding service to the terminal device according to the configured policy.
[0033] A second aspect of this application provides a network access method applied to a terminal device. The network access method includes the following steps: initiating an access request to a network device; wherein the access request includes indication information, the indication information being used to instruct an unauthorized terminal device located within a satellite communication cell to request the network to provide service.
[0034] A third aspect of this application provides a network access device applied to a network equipment. The network access device includes: a receiving module for receiving an access request initiated by a terminal device; and a control module for providing corresponding service to the terminal device according to a configured policy in response to determining that the terminal device is located in a satellite communication cell; wherein the policy is whether to provide all or part of the service to an unauthorized terminal device.
[0035] A fourth aspect of this application provides a network access device applied to a terminal device. The network access device includes: an initiation module for initiating an access request to a network device; wherein the access request includes indication information, the indication information being used to indicate an unauthorized terminal device located within a satellite communication cell to request the network to provide service.
[0036] The fifth aspect of this application provides a network device including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method described in the first aspect.
[0037] A sixth aspect of this application provides a terminal device including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method described in the second aspect.
[0038] A seventh aspect of this application provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the method described in the first or second aspect.
[0039] The eighth aspect of this application provides a computer program product, including a computer program, characterized in that, when executed by a processor, the computer program implements the steps of the method described in the first or second aspect.
[0040] Based on common knowledge in the field, the above optional conditions can be combined arbitrarily to obtain the preferred embodiments of this application.
[0041] The positive advancements of this application are as follows: In response to an access request initiated by a terminal device, the network device determines, based on a configured policy, whether to provide corresponding service to an unauthorized terminal device located within the satellite communication cell. Different configured policies result in different service provision to unauthorized terminal devices within the satellite communication cell; specifically, it may provide all service, some service, or refuse to provide any service. By configuring policies, corresponding service can be provided to unauthorized terminal devices in satellite communication scenarios, allowing unauthorized mobile users to potentially enjoy some or all satellite communication services in certain situations, essentially a "post-contract authorization," thus improving the user experience.
[0042] Furthermore, during the access process, the network device marks unauthorized terminal devices within the satellite communication cell with indication information according to the configured policy. Subsequently, billing for service can be performed based on the indication information, thereby managing resources more accurately and improving operational efficiency. Attached Figure Description
[0043] Figure 1 is a schematic diagram of the application of a mobile phone direct connection to a satellite communication system.
[0044] Figure 2 is a schematic diagram of a satellite-mobile phone communication scenario.
[0045] Figure 3 is a schematic diagram of the UE registration process in the prior art.
[0046] Figure 4 is a schematic diagram of the UE attachment process in the prior art.
[0047] Figure 5 is a flowchart of a network access method provided in Embodiment 1 of this application.
[0048] Figure 6 is a flowchart of a specific network access method provided in Embodiment 1 of this application.
[0049] Figure 7 is a flowchart of a UE registration process provided in Embodiment 1 of this application.
[0050] Figure 8 is a registration flowchart of another UE provided in Embodiment 1 of this application.
[0051] Figure 9 is a flowchart of the attachment process of a UE provided in Embodiment 1 of this application.
[0052] Figure 10 is a flowchart of another UE attachment process provided in Embodiment 1 of this application.
[0053] Figure 11 is a structural block diagram of a network access device provided in Embodiment 1 of this application. Detailed Implementation
[0054] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These embodiments should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0055] It should be noted that the terms "first," "second," etc., used in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0056] The terminal equipment in this application embodiment can refer to various forms of user equipment, access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, wireless communication equipment, user agent, or user device. Terminal devices can also be cellular phones, cordless phones, Session Initiation Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistants (PDAs), handheld devices with wireless communication capabilities, computers with wireless transceiver capabilities, Virtual Reality (VR) terminal devices, Augmented Reality (AR) terminal devices, wireless terminals in industrial control, wireless terminals in self-driving vehicles, wireless terminals in remote surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, computing devices or other processing devices connected to a wireless modem, in-vehicle devices, wearable devices, terminal devices in 5G networks, or terminal devices in future evolved PLMNs, etc. This application does not limit these possibilities.
[0057] The network device in this application embodiment is a device deployed in a Radio Access Network (RAN) to provide wireless communication functions, including a base station and a core network.
[0058] A base station can also be called a base station device. For example, in a 4G network, devices that provide base station functionality include eNB (evolved Node B), and in 5G NR, devices that provide base station functionality include gNB (5G Node B). 4G base stations connect to the 4G core network, meaning the eNB connects to the EPC (Evolved Packet Core), while 5G base stations connect to the 5G core network, meaning the gNB connects to the 5GC (5G Core Network).
[0059] The core network (CN) is a crucial component of a mobile communication system, responsible for handling functions such as communication between the user equipment (UE) and external networks, data transmission, user management, and security. The composition of the core network varies depending on the network technology used (e.g., 4G LTE or 5G).
[0060] The 4G core network mainly consists of the following functional entities: MME, S-GW, P-GW, HSS (Home Subscriber Server), and PCRF.
[0061] The 5G core network mainly consists of the following functional entities: AMF, SMF (Session Management Function), UPF (User Plane Function), UDM, AUSF, NEF (Network Exposure Function), and PCF (Policy and Charging Function).
[0062] Example 1
[0063] Figure 5 is a flowchart illustrating a network access method provided in this embodiment. This network access method can be executed by a network access device, which can be implemented through software and / or hardware. The network access device can be part or all of a network device. The network access method provided in this embodiment is described below with the network device as the executing entity.
[0064] As shown in Figure 5, the network access method provided in this embodiment includes the following steps S10-S12:
[0065] Step S10: Configure policies for the corresponding nodes in the network. The policies specify whether to provide all or part of the service to unauthorized terminal devices. Nodes can be base stations or the core network. It should be noted that in practical applications, step S10 can be executed when configuring the policy for the first time or when a policy change is required.
[0066] In practice, corresponding policies can be configured for nodes in the network through OAM (Operations Administration Maintenance), policies can be passed between network nodes through message passing, and policies can be further passed to nodes in the network based on the roaming interface between different regions.
[0067] Step S11: Receive an access request initiated by the terminal device. The access request may be a registration request, an attachment request, or other types of requests.
[0068] Step S12: In response to determining that the terminal device is within a satellite communication cell, determine whether to provide corresponding service to the terminal device according to the configured policy. The service corresponding to the configured policy may be providing all network service, some network service, or refusing to provide any network service.
[0069] In this embodiment, the configured strategy can enable the provision of corresponding network services to unauthorized terminal devices in satellite communication scenarios.
[0070] In one optional implementation, the access request initiated by the terminal device includes indication information indicating that an unauthorized terminal device is located within a satellite communication cell and requesting the network to provide it with service. In one specific example, the terminal device adds the indication information to its access request to the network device after receiving a broadcast message. The broadcast message may indicate that the network device supports providing services to unauthorized terminal devices located within a satellite communication cell, and may also indicate that the cell type of the terminal device is a satellite communication cell. In another specific example, the terminal device adds the indication information to its access request to the network device after receiving a denial message from the network device. In practical applications, the terminal device may add the indication information to its access request to the network device after receiving multiple denial messages consecutively.
[0071] In an alternative embodiment, the network access method further includes the following steps S13-S14:
[0072] Step S13: The base station determines whether to mark the terminal device with indication information based on the location information of the terminal device, the cell type in which the terminal device is located, and the policy. The indication information is used to instruct unauthorized terminal devices located within a satellite communication cell to request network service.
[0073] In one specific example, the base station determines that the terminal device is within a satellite communication cell based on its location information and the cell type it is in. The specific policy is to provide service to unauthorized terminal devices, in which case the base station can label the terminal device with the indication information. In another specific example, the base station determines that the terminal device is within a satellite communication cell based on its location information and the cell type it is in. The specific policy is to refuse to provide service to unauthorized terminal devices, in which case the base station may not label the terminal device with the indication information. In yet another specific example, the base station determines that the terminal device is not within a satellite communication cell based on its location information and the cell type it is in. In this case, the base station may not label the terminal device with the indication information.
[0074] In specific implementations, the location information may include latitude and longitude information, cell ID, tracking area, location area, paging area, and the interface through which the terminal device transmits data between the satellite and the base station.
[0075] Step S14: The base station forwards the access request to the core network control unit. The access request may or may not include the indication information.
[0076] In this embodiment, the base station in the network device determines whether to label the terminal device with indication information.
[0077] In one optional implementation, the network access method further includes step S15: the core network control unit determines whether to label the terminal device with the indication information based on the location information of the terminal device, the cell type in which the terminal device is located, and the policy. Further, the core network control unit may also add the indication information to the access request. In this implementation, if the access request forwarded by the base station to the core network control unit does not carry the indication information, the core network control unit in the network device can determine whether to label the terminal device with the indication information. The specific principle by which the core network control unit determines whether to label the terminal device with the indication information is similar to the specific principle by which the base station determines whether to label the terminal device with the indication information.
[0078] In the following two scenarios, the network device provides corresponding service to the terminal device according to different strategies: Scenario 1: The access request received by the core network control unit includes the indication information; Scenario 2: The access request received by the core network control unit does not include the indication information, but the core network control unit determines that the terminal device is marked with the indication information.
[0079] The following details the solutions of this embodiment for different strategies:
[0080] In one optional implementation, the strategy specifically involves providing all or part of the service to unauthorized terminal devices located within the satellite communication cell, and directly authorizing them without performing an authentication process. The network access method further includes steps S16-S17:
[0081] Step S16: The core network control unit sends a session establishment request message or a bearer establishment request message to the core network data unit. The session establishment request message or the bearer establishment request message may or may not include the indication information.
[0082] Step S17: The core network data unit and the policy control unit exchange information. The indication information can also be added to the session or bearer message to establish a session or bearer, or to use a reserved session or default bearer.
[0083] In one optional implementation, the strategy specifically involves providing all or part of the service to unauthorized terminal devices located within the satellite communication cell, and performing authentication; the network access method further includes steps S18-S19:
[0084] Step S18: The core network control unit sends an authentication request message to the corresponding policy control unit. The authentication request message may or may not include the indication information.
[0085] Step S19: The policy control unit and the user information unit perform authentication and authorization, and the instruction information can be added to the authentication interaction message.
[0086] In one optional implementation, the strategy specifically involves refusing to provide service to unauthorized terminal devices located within a satellite communication cell; the network access method further includes step S20: in response to the received access request including the indication information, the core network sends a denial-of-access message to the terminal device; wherein the denial-of-access message carries a reason for the denial of access, the reason being that the core network refuses to provide service to unauthorized terminal devices located within a satellite communication cell.
[0087] In practice, the policy control unit can charge based on the indication information in the session or bearer message, or it can charge based on the indication information in the authentication interaction message.
[0088] For the sake of simplicity, the indication information is referred to as PSI (Partial Services Indicator), which means that an unauthorized UE in a satellite communication cell requests the network to provide service.
[0089] Figure 6 illustrates a flowchart of a specific network access method. As shown in Figure 6, the network access method specifically includes:
[0090] Step 0: Configure policies for the corresponding nodes in the network. These nodes include BS (Base Station), CNC (Core Network Control Unit), CND (Core Network Data Unit), PCU (Policy Control Unit), and HUU (User Information Unit). The BS performs access network functions, including but not limited to eNB and gNB. The CNC performs access and mobility management functions, including but not limited to AMF and MME. The CND performs user plane data transmission and session management functions, including but not limited to SGW, PGW, and SMF. The PCU performs authentication and policy management functions, including but not limited to AUSF, PCF, and PCRF. The HUU manages user subscription information, including but not limited to HSS and UDM.
[0091] OAM can be used to configure corresponding policies for nodes in the network. Alternatively, after configuring one network node, other nodes can configure policies through node message passing. Furthermore, corresponding policies can be passed to nodes in the network based on the roaming interface between different regions.
[0092] Step 1: The UE initiates an access request. Optionally, the access request includes a PSI (Power Scheme Indicator). Optionally, the UE adds the PSI to the access request after receiving the broadcast message. The broadcast message includes information indicating that the network device supports providing services to unauthorized UEs located in a satellite communication cell, and may also indicate that the cell type where the UE is located is a satellite communication cell.
[0093] Optionally, the UE may add the PSI to the access request after receiving an access denial message from the network device.
[0094] Step 2: If the access request received by the BS does not include PSI, then determine whether to label the UE with PSI based on the UE's location information, the cell type where the UE is located, and the policy.
[0095] Step 3: The BS forwards the access request to the CNC. If step 2 determines that the UE has a PSI, the access request including that PSI can be forwarded.
[0096] Step 4: If the access request received by the CNC does not include the PSI, then determine whether to label the PSI for the UE based on the UE's location information, the cell type where the UE is located, and the policy.
[0097] Step 5: The CNC sends a session establishment request message or a bearer establishment request message to the CND. The session establishment request message or the bearer establishment request message may contain a PSI. The CND and PCU exchange information to establish a session or bearer. The PSI can be added to the session or bearer message to provide information for the subsequent billing process.
[0098] Step 6: The CNC sends an authentication request message to the PCU. The PCU and HUU perform authentication. The PSI can be added to the authentication interaction message to provide information for the subsequent billing process.
[0099] CND provides CNC with an authentication completion message.
[0100] Alternatively, in step 6a, the CNC may decide not to proceed with the authentication process.
[0101] Step 7: The CNC sends an access success message to the UE.
[0102] Figure 7 illustrates a UE registration flowchart. As shown in Figure 7, the network access method specifically includes: a configured policy used to instruct authentication to be performed.
[0103] Step 0: Configure policies for the corresponding nodes in the network. These policies determine whether to provide all or part of the service to unauthorized UEs. Nodes can be base stations or the core network. Policies can be configured for nodes in the network through OAM or through message passing between network nodes. Furthermore, policies can be passed to nodes in the network based on the roaming interface between different areas. Figure 7 shows the configuration of policies for AMF, PCF, AUSF, and UDM.
[0104] Step 1: The UE initiates a registration request. The registration request may include PSI, UE identifiers such as 5G-GUTI, SUCI, IMEI, PLMN list, etc., and location information such as cell ID, TAC / LAC, TAC / LAC list, latitude and longitude information, etc.
[0105] Optionally, the UE adds the PSI to the registration request after receiving the broadcast information. The broadcast message contains instructions that the network device supports providing services to unauthorized UEs located in a satellite communication cell, and may also indicate that the cell type where the UE is located is a satellite communication cell.
[0106] Optionally, the UE may add the PSI to the registration request after receiving an access denial message from the network device.
[0107] Step 2: gNB forwards the registration request to AMF.
[0108] Optionally, if the registration request received by the gNB does not include a PSI, the gNB determines whether to label the UE with a PSI based on the UE's location information, the cell type of the UE, and the policy. If the gNB determines to label the UE with a PSI, it forwards a registration request that may include a PSI to the AMF.
[0109] Step 3: The AMF determines whether to provide service to unauthorized UEs located within the satellite communication cell based on the configured policy. If service is denied, proceed to step 4a. If partial or full service can be provided and authentication is performed, proceed to step 4.
[0110] Optionally, if the registration request received by the AMF does not include the PSI, then it is determined whether to label the PSI for the UE based on the UE's location information, the cell type in which the UE is located, and the policy.
[0111] Step 4a: Send a registration rejection message to the UE. The registration rejection message carries the reason for the rejection, specifically that the network device refuses to provide services to an unauthorized UE located within the satellite communication cell. Skip the following steps and terminate directly.
[0112] Step 4: The AMF selects the AUSF based on the UE identifier and sends an authentication request message to the AUSF to request the authentication process. This authentication request message may contain a PSI.
[0113] Step 5: The AUSF and UDM exchange UE subscription information. If the UDM returns interaction information indicating that the UE has not subscribed, the UDM directly sends an authentication failure message to the AUSF and jumps to step 7a.
[0114] Step 6: AUSF generates authentication key parameters and performs authentication and security encryption processes.
[0115] Step 7: After the authentication and security process is completed, the AMF sends a registration acceptance message to the UE.
[0116] Step 7a: The AMF sends a registration rejection message to the UE, ending the process.
[0117] Step 8: The UE sends a registration completion message to the AMF to end the process.
[0118] Figure 8 illustrates a different UE registration flowchart. As shown in Figure 8, the network access method specifically includes: a configured policy used to indicate that authentication is not performed.
[0119] Step 0: Configure policies for the corresponding nodes in the network. These policies determine whether to provide all or part of the service to unauthorized UEs. Nodes can be base stations or the core network. Policies can be configured for nodes in the network through OAM, through message passing between network nodes, or further by transmitting policies to nodes in the network based on the roaming interface between different regions. Figure 8 shows the configuration of policies for AMF, SMF, UPF, and PCF.
[0120] Step 1: The UE initiates a registration request. The registration request may include indication information, as well as UE identifiers such as 5G-GUTI, SUCI, IMEI, PLMN list, etc., and location information such as cell ID, TAC / LAC, TAC / LAC list, latitude and longitude information, etc.
[0121] Optionally, the UE adds the PSI to the registration request after receiving the broadcast information. The broadcast message contains an indication that the network device supports providing services to unauthorized UEs located in a satellite communication cell, and may also indicate that the cell type where the UE is located is a satellite communication cell.
[0122] Optionally, the UE may add the PSI to the registration request after receiving an access denial message from the network device.
[0123] Step 2: gNB forwards the registration request to AMF.
[0124] Optionally, if the registration request received by the gNB does not include a PSI, the gNB determines whether to label the UE with a PSI based on the UE's location information, the cell type of the UE, and the policy. If the gNB determines to label the UE with a PSI, it forwards a registration request that may include a PSI to the AMF.
[0125] Step 3: The AMF determines whether to provide service to unauthorized UEs located within the satellite communication cell based on the configured policy. If service is denied, proceed to step 4a. If partial or full service can be provided without authentication, proceed to step 4.
[0126] Optionally, if the registration request received by the AMF does not include the PSI, then it is determined whether to label the PSI for the UE based on the UE's location information, the cell type in which the UE is located, and the policy.
[0127] Step 4a: Send a registration rejection message to the UE. The registration rejection message carries the reason for the registration rejection, specifically that the network device refuses to provide services to an unauthorized UE located in the satellite communication cell. Skip the following steps and end directly.
[0128] Step 4: The AMF selects the SMF based on the UE identifier and sends a Session Establishment Request Message or Bearer Establishment Request Message, which includes indication information, to the SMF to request session or bearer establishment.
[0129] Step 5: SMF and UPF establish a session or bearer, and the PSI can be added to the session or bearer message.
[0130] Step 6: UPF and PCF establish and modify sessions or bearers, and can add the indicated information to the session or bearer messages.
[0131] Step 7: SMF notifies AMF that the session bearer establishment is complete.
[0132] Step 8: The AMF sends a registration completion message to the UE.
[0133] Figure 9 illustrates a UE attachment flowchart. As shown in Figure 9, the network access method specifically includes: a configured policy to instruct that the access request be directly authorized without performing an authentication process.
[0134] Step 0: Configure policies for the corresponding nodes in the network. These policies determine whether to provide all or part of the service to unauthorized UEs. Nodes can be base stations or the core network. Policies can be configured for network nodes through OAM, or through message passing between network nodes. Alternatively, policies can be further transmitted to nodes in network devices based on roaming interfaces between different regions.
[0135] Step 1: The UE sends an attach request to the eNB. The attach request includes user identification information such as MSI / MEI / PEI information, and may also include location information such as cell ID, TAC / LAC, TAC / LAC list, latitude and longitude information, etc.
[0136] Optionally, the UE adds the PSI to the attach request after receiving the broadcast message. The broadcast message includes instructions that the network device supports providing services to unauthorized UEs located in a satellite communication cell, and may also indicate that the cell type where the UE is located is a satellite communication cell.
[0137] Optionally, the UE adds the PSI to the attach request after receiving an access denial message from the network device.
[0138] Step 2: If the attach request received by the eNB does not include a PSI, then determine whether to label the UE with a PSI based on the UE's location information, the cell type in which the UE is located, and the policy.
[0139] Step 3: The eNB forwards the attach request to the MME. If step 2 determines that the UE has labeled the PSI, the forwarding may include the attach request for the PSI.
[0140] Step 4: The MME determines whether to provide service to unauthorized UEs located within the satellite communication cell based on the configured policy. If service is denied, proceed to step 5a. If partial or full service can be provided without authentication, proceed to step 5.
[0141] Step 5a: Send an attach rejection message to the UE. The attach rejection message carries the reason for the attachment rejection, specifically that the network device refuses to provide service to an unauthorized UE located within the satellite communication cell. Skip the following steps and terminate directly.
[0142] Step 5: If the MME does not have IMSI / MEI / PEI information, the MME sends a message to the UE to report the IMSI. If the MME has IMSI / MEI / PEI information, proceed to step 7.
[0143] Step 6: The UE reports IMSI / IMEI / PEI.
[0144] Step 7: Configure the default bearer for the MME, and label the PSI for the UE with the MME and SGW / PGW.
[0145] Step 8: The SGW / PGW sends a message to the PCRF to perform a bearer update and assign a PSI to the UE.
[0146] Step 9: The SGW / PGW sends a bearer establishment completion message to the MME.
[0147] Step 10: The MME notifies the UE that the attach request has been accepted.
[0148] Step 11: The UE sends feedback to the MME that the attachment process is complete.
[0149] Figure 10 illustrates a different UE attachment flowchart. As shown in Figure 10, the network access method specifically includes: performing an authentication process for unauthorized UEs.
[0150] Step 0: Configure policies for the corresponding nodes in the network. These policies determine whether to provide all or part of the service to unauthorized UEs. Nodes can be base stations or the core network. Policies can be configured for nodes in the network through OAM, through message passing between network nodes, or further, by transmitting the corresponding policies to nodes in the network based on the roaming interface between different regions.
[0151] Step 1: The UE sends an attach request to the eNB. The attach request includes user identification information such as MSI / MEI / PEI information, and may also include location information such as cell ID, TAC / LAC, TAC / LAC list, latitude and longitude information, etc.
[0152] Optionally, the UE adds the PSI to the attach request after receiving the broadcast message. The broadcast message includes instructions that the network device supports providing services to unauthorized UEs located in a satellite communication cell, and may also indicate that the cell type where the UE is located is a satellite communication cell.
[0153] Optionally, the UE adds the PSI to the attach request after receiving an access denial message from the network device.
[0154] Step 2: If the attach request received by the eNB does not include a PSI, then determine whether to label the UE with a PSI based on the UE's location information, the cell type in which the UE is located, and the policy.
[0155] Step 3: The eNB forwards the attach request to the MME. If step 2 determines that the UE has labeled the PSI, the forwarding may include the attach request for the PSI.
[0156] Step 4: The MME determines whether to provide service to an unauthorized UE located within the satellite communication cell based on the configured policy. If service is refused, proceed to step 5a. If partial or full service can be provided without authentication, proceed to step 5.
[0157] Step 5a: Send an attach rejection message to the UE. The attach rejection message carries the reason for the attachment rejection, specifically that the network device refuses to provide service to the UE located in an unauthorized satellite communication cell. Skip the following steps and terminate directly.
[0158] Step 5: If the MME does not have IMSI / MEI / PEI information, the MME sends a message to the UE to report the IMSI. If the MME has IMSI / MEI / PEI information, proceed to step 7.
[0159] Step 6: The UE reports IMSI / IMEI / PEI.
[0160] Step 7: The MME and HSS complete the authentication key generation process. Specifically, the MME notifies the HSS to assign a PSI to the UE.
[0161] Step 8: The MME notifies the SGW / PGW to establish a bearer, and the MME and SGW / PGW mark the PSI for the UE.
[0162] Step 9: The SGW / PGW sends a message to the PCRF to perform a bearer update and assign a PSI to the UE.
[0163] Step 10: The SGW / PGW sends a bearer establishment completion message to the MME.
[0164] Step 11: The MME notifies the UE that the attach request has been accepted.
[0165] Step 12: The UE sends feedback to the MME that the attachment process is complete.
[0166] This embodiment also provides a network access device applied to network equipment, as shown in Figure 11. The network access device includes a receiving module 31 and a control module 32. First, policies need to be configured for the corresponding nodes in the network. These policies determine whether to provide all or part of the service to unauthorized terminal devices. The nodes can be base stations or the core network.
[0167] The receiving module is used to receive access requests initiated by terminal devices. These access requests can be registration requests, attachment requests, or other types of requests.
[0168] The control module is used to provide corresponding service to the terminal device according to a configured policy upon determining that the terminal device is within a satellite communication cell. The service corresponding to the configured policy may be providing all network service, some network service, or denying any network service.
[0169] In this embodiment, the configured strategy can enable the provision of corresponding network services to unauthorized terminal devices in satellite communication scenarios.
[0170] In one optional implementation, the receiving module is specifically configured to receive the policy configured via OAM, or to receive the policy via message passing between network nodes, or may further receive the policy transmitted according to the roaming interface between different regions.
[0171] In one optional implementation, the access request includes indication information, which instructs an unauthorized terminal device located within a satellite communication cell to request the network to provide service. In one specific example, after receiving a broadcast message, the terminal device adds the indication information to its access request to the network device. The broadcast message may indicate that the network device supports providing services to unauthorized terminal devices within the satellite communication cell, and may also indicate that the cell type of the terminal device is a satellite communication cell. In another specific example, the terminal device adds the indication information to its access request to the network device after receiving a denial message from the network device. In practical applications, the terminal device may add the indication information to its access request to the network device after receiving multiple denial messages consecutively.
[0172] In one optional implementation, the base station is configured to determine whether to label the terminal device with the indication information based on the location information of the terminal device, the cell type in which the terminal device is located, and the policy; wherein, the indication information is used to instruct an unauthorized terminal device located in a satellite communication cell to request the network to provide service. The base station is also configured to forward the access request to the core network control unit, the access request may or may not include the indication information. In this embodiment, the determination of whether to label the terminal device with the indication information is made by the base station in the network device.
[0173] In one specific example, the base station determines that the terminal device is within a satellite communication cell based on its location information and the cell type it is in. The specific policy is to provide service to unauthorized terminal devices, in which case the base station can label the terminal device with the indication information. In another specific example, the base station determines that the terminal device is within a satellite communication cell based on its location information and the cell type it is in. The specific policy is to refuse to provide service to unauthorized terminal devices, in which case the base station may not label the terminal device with the indication information. In yet another specific example, the base station determines that the terminal device is not within a satellite communication cell based on its location information and the cell type it is in, in which case the base station may not label the terminal device with the indication information.
[0174] In specific implementations, the location information may include latitude and longitude information, cell ID, tracking area, location area, paging area, and the interface through which the terminal device transmits data between the satellite and the base station.
[0175] In one optional implementation, the core network control unit (CNCU) determines whether to label the terminal device with the indication information based on the location information of the terminal device, the cell type in which the terminal device is located, and the policy. Further, the CNCU can also add the indication information to the access request. In this implementation, if the access request forwarded by the base station to the CNCU does not carry the indication information, the CNCU in the network device can determine whether to label the terminal device with the indication information. The specific principle by which the CNCU determines whether to label the terminal device with the indication information is similar to the principle by which the base station determines whether to label the terminal device with the indication information.
[0176] In the following two scenarios, the network device provides corresponding service to the terminal device according to different strategies: Scenario 1: The access request received by the core network control unit includes the indication information; Scenario 2: The access request received by the core network control unit does not include the indication information, but the core network control unit determines that the terminal device is marked with the indication information.
[0177] The following details the solutions of this embodiment for different strategies:
[0178] In one optional implementation, the policy specifically involves providing all or part of the service to unauthorized terminal devices located within the satellite communication cell without authentication. The core network control unit sends a session establishment request message or a bearer establishment request message to the core network data unit; the session establishment request message or bearer establishment request message may or may not include the indication information. The core network data unit interacts with the policy control unit, and may also add the indication information to the session or bearer message to establish a session or bearer, or use a reserved session or a default bearer.
[0179] In one optional implementation, the policy specifically involves providing all or part of the service to unauthorized terminal devices located within the satellite communication cell, and performing authentication with the indicated information. The core network control unit sends an authentication request message to the corresponding policy control unit; this authentication request message may or may not include the indicated information. The policy control unit performs authentication with the user information unit and may add the indicated information to the authentication interaction message.
[0180] In one optional implementation, the strategy specifically involves refusing to provide service to unauthorized terminal devices located within the satellite communication cell. The core network sends an access denial message to the terminal device; wherein the access denial message carries a reason for the access denial, the reason being that the core network refuses to provide service to unauthorized terminal devices located within the satellite communication cell.
[0181] In one optional implementation, the policy control unit is used to perform billing based on the indication information in the session or bearer message, or based on the indication information in the authentication interaction message.
[0182] It should be noted that the network access device in this embodiment can be a separate chip, chip module, or network device, or it can be a chip or chip module integrated into a network device.
[0183] Regarding the various modules / units included in the network access device described in this embodiment, they can be software modules / units, hardware modules / units, or a combination of both. For example, for various devices or products applied to or integrated into a chip, all of their modules / units can be implemented using hardware methods such as circuits, or at least some modules / units can be implemented using software programs running on a processor integrated within the chip, while the remaining modules / units can be implemented using hardware methods such as circuits. For various devices or products applied to or integrated into a chip module, all of their modules / units can be implemented using hardware methods such as circuits. Different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or different components of the chip module, or at least some modules / units... It can be implemented using software programs that run on the processor integrated within the chip module, while the remaining modules / units can be implemented using hardware methods such as circuits. For various devices and products applied to or integrated into network equipment, each of its modules / units can be implemented using hardware methods such as circuits. Different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or different components within the network equipment. Alternatively, at least some modules / units can be implemented using software programs that run on the processor integrated within the network equipment, while the remaining modules / units can be implemented using hardware methods such as circuits.
[0184] This embodiment also provides a network device, including at least one processor and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, which enables the at least one processor to perform the steps of the network access method described above.
[0185] Example 2
[0186] This embodiment provides a network access method, which can be executed by a network access device. The network access device can be implemented through software and / or hardware, and can be part or all of a terminal device. The network access method provided in this embodiment is described below with the terminal device as the executing entity.
[0187] The network access method provided in this embodiment includes the following step S21:
[0188] Step S21: Initiate an access request to the network device; wherein the access request includes indication information, which is used to indicate to an unauthorized terminal device located in the satellite communication cell that it requests the network to provide service.
[0189] It should be noted that the network device mentioned can be the network device in Embodiment 1.
[0190] In one optional implementation, the method further includes receiving a broadcast message before step S21. The broadcast message includes information indicating that the network device supports providing service to unauthorized terminal devices located within a satellite communication cell, and may also indicate that the cell type of the terminal device is a satellite communication cell. In this implementation, after receiving the broadcast information, the terminal device adds the indication information to the access request initiated to the network device.
[0191] In an alternative embodiment, the step S21 is preceded by receiving an access denial message from the network device. In this embodiment, after receiving the access denial message from the network device, the terminal device adds the indication information to the access request initiated to the network device. In practical applications, the terminal device can add the indication information to the access request initiated to the network device after receiving multiple access denial messages consecutively.
[0192] In one optional implementation, the above step S22 is followed by: receiving an access denial message sent by the network device, wherein the access denial message carries a reason for the access denial, the reason being that the network device refuses to provide service to unauthorized terminal devices located in the satellite communication cell.
[0193] This embodiment also provides a network access device applied to a terminal device. The network access device includes an initiation module for initiating an access request to the network device. The access request includes indication information, which is used to indicate to an unauthorized terminal device located in a satellite communication cell that it requests the network to provide service.
[0194] In one optional implementation, the network access device further includes a first receiving module, configured to receive a broadcast message before initiating an access request to the network device; wherein the broadcast message includes an indication that the network device supports providing service to unauthorized terminal devices located in a satellite communication cell; or, the broadcast message is used to indicate that the cell type of the terminal device is a satellite communication cell.
[0195] In one optional embodiment, the network access device further includes a second receiving module, configured to receive an access rejection message sent by the network device before initiating an access request to the network device.
[0196] In one optional embodiment, the network access device further includes a third receiving module, configured to receive a rejection message sent by the network device after initiating an access request to the network device, wherein the rejection message carries a reason for the rejection, the reason being that the network device refuses to provide service to unauthorized terminal devices located within the satellite communication cell.
[0197] It should be noted that the network access device in this embodiment can be a separate chip, chip module, or terminal device, or it can be a chip or chip module integrated into a terminal device.
[0198] Regarding the various modules / units included in the network access device described in this embodiment, they can be software modules / units, hardware modules / units, or a combination of both. For example, for various devices or products applied to or integrated into a chip, all of their modules / units can be implemented using hardware methods such as circuits, or at least some modules / units can be implemented using software programs running on a processor integrated within the chip, while the remaining modules / units can be implemented using hardware methods such as circuits. For various devices or products applied to or integrated into a chip module, all of their modules / units can be implemented using hardware methods such as circuits. Different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or different components of the chip module, or at least some modules / units... It can be implemented using software programs that run on the processor integrated within the chip module, while the remaining modules / units can be implemented using hardware methods such as circuits. For various devices and products applied to or integrated into terminal devices, each of their modules / units can be implemented using hardware methods such as circuits. Different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or different components within the terminal device. Alternatively, at least some modules / units can be implemented using software programs that run on the processor integrated within the terminal device, while the remaining modules / units can be implemented using hardware methods such as circuits.
[0199] This embodiment provides a terminal device, including at least one processor and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, which enables the at least one processor to perform the steps of the network access method described above.
[0200] Example 3
[0201] This embodiment provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the network access method in embodiment 1 or 2.
[0202] The readable storage medium may be more specifically adopted, including but not limited to: portable disk, hard disk, random access memory, read-only memory, erasable programmable read-only memory, optical storage device, magnetic storage device, or any suitable combination thereof.
[0203] In a possible implementation, this embodiment can also be implemented as a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the network access method in embodiment 1 or 2.
[0204] The computer program for executing this application can be written in any combination of one or more programming languages. The computer program can be executed entirely on an electronic device, partially on an electronic device, as a standalone software package, partially on an electronic device and partially on a remote device, or entirely on a remote device.
[0205] This embodiment also provides a computer program that, when executed by one or more processors, can implement the steps of the network access method in embodiment 1 or 2.
[0206] While specific embodiments of this application have been described above, those skilled in the art should understand that these are merely illustrative examples, and the scope of protection of this application is defined by the appended claims. Those skilled in the art can make various changes or modifications to these embodiments without departing from the principles and essence of this application, but all such changes and modifications fall within the scope of protection of this application.
Claims
1. A network access method, characterized in that, Applied to network devices, the network access method includes the following steps: Receive access requests initiated by terminal devices; In response to determining that the terminal device is within a satellite communication cell, a policy is configured to determine whether to provide corresponding service to the terminal device; wherein, the policy is whether to provide all or part of the service to unauthorized terminal devices.
2. The network access method as described in claim 1, characterized in that, The network access method further includes: Receive the policy configured via OAM; Alternatively, the strategy can be received via message passing between network nodes; Alternatively, receive the policy transmitted based on the roaming interface between different regions.
3. The network access method as described in claim 1, characterized in that, The access request includes indication information, which is used to instruct unauthorized terminal devices located within the satellite communication cell to request the network to provide service.
4. The network access method as described in claim 3, characterized in that, The network access method further includes: The base station determines whether to mark the terminal device with indication information based on the location information of the terminal device, the cell type in which the terminal device is located, and the policy; wherein, the indication information is used to instruct unauthorized terminal devices located in the satellite communication cell to request the network to provide service. The base station forwards the access request to the core network control unit, and the access request may or may not contain the indication information.
5. The network access method as described in claim 3 or 4, characterized in that, The network access method further includes: The core network control unit determines whether to label the terminal device with the indication information based on the location information of the terminal device, the cell type in which the terminal device is located, and the policy. The access request may or may not contain the indication information.
6. The network access method as described in any one of claims 3-5, characterized in that, The strategy specifically involves providing all or part of the service to unauthorized terminal devices located within a satellite communication cell without performing authentication.
7. The network access method as described in any one of claims 3-5, characterized in that, The strategy specifically involves providing all or part of the service to unauthorized terminal devices located within a satellite communication cell, and performing authentication with the indicated information.
8. The network access method as described in claim 6 or 7, characterized in that, The network access method further includes: The core network control unit sends a session establishment request message or a bearer establishment request message to the core network data unit; the session establishment request message or the bearer establishment request message may or may not contain the indication information. The core network data unit and the policy control unit exchange information to establish a session or bearer, or use a reserved session or default bearer. The session or bearer message may or may not contain the indication information.
9. The network access method as described in claim 7, characterized in that, The network access method further includes: The core network control unit sends an authentication request message to the corresponding policy control unit, and the authentication request message may or may not contain the indication information. The policy control unit and the user information unit perform authentication between each other, and the authentication interaction message may or may not contain the instruction information.
10. The network access method as described in any one of claims 3-5, characterized in that, The strategy specifically involves refusing to provide service to unauthorized terminal devices located within the satellite communication cell; the network access method further includes: The core network sends an access denial message to the terminal device; wherein the access denial message carries the reason for the access denial, that is, the core network refuses to provide service to unauthorized terminal devices located in the satellite communication cell.
11. The network access method as described in claim 4 or 5, characterized in that, The location information includes at least one of the following: latitude and longitude information, cell ID, tracking area, location area, paging area, and the interface through which the terminal device transmits data between the satellite and the base station.
12. The network access method as described in claim 8 or 9, characterized in that, The network access method further includes: The policy control unit performs billing based on the instruction information.
13. A network access method, characterized in that, Applied to terminal devices, the network access method includes the following steps: An access request is initiated to a network device; wherein the access request includes indication information, the indication information being used to instruct an unauthorized terminal device located within a satellite communication cell to request the network to provide service.
14. The network access method as described in claim 13, characterized in that, The steps preceding the initiation of an access request to the network device also include: Receive a broadcast message, the broadcast message containing instructions to the network device to support providing services to unauthorized terminal devices located in a satellite communication cell; or, the broadcast message indicating that the cell type of the terminal device is a satellite communication cell; Alternatively, it may receive an access denial message sent by the network device.
15. A network access device, characterized in that, Applied to network devices, the network access device includes: The receiving module is used to receive access requests initiated by terminal devices; The control module is configured to provide corresponding service to the terminal device according to a configured policy in response to determining that the terminal device is within a satellite communication cell, wherein the policy is whether to provide all or part of the service to unauthorized terminal devices.
16. A network access device, characterized in that, The network access device, applied to terminal equipment, includes: The initiation module is used to initiate an access request to a network device; wherein the access request includes indication information, which is used to instruct an unauthorized terminal device located in the satellite communication cell to request the network to provide service.
17. A network device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1-12.
18. A terminal device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 13-14.
19. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-14.
20. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-14.
21. A chip used in electronic devices, characterized in that, The chip is used to perform the steps of the method according to any one of claims 1-14.
22. A chip module, used in electronic devices, characterized in that, Includes a chip for performing the steps of the method according to any one of claims 1-14.