User Equipment Access Control via Application-Specific Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network resources are strained because applications not allowed by the operator cannot be prevented from accessing the network, leading to unauthorized use of network resources.

Innovation Solution

The user equipment (UE) receives access control information from the network device, which includes a correspondence between application information and access control indications, and determines whether to send non-access stratum signaling based on this information to control access to the network, ensuring that only authorized applications can access the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the UE sends RRC connection establishment request to the network device when in idle mode, then the UE can access the network for allowed applications, but unauthorized applications can also access the network and occupy network resources

Engineering Contradiction:
Improveapplication access controlVSAvoidnetwork resource occupation by unauthorized applications
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The network device pre-configures access control information including application identifiers and access control indications before the UE needs to access the network. When the UE is in idle mode and an application needs to access the network, the UE checks the pre-configured access control information to determine whether to send the RRC connection establishment request. This preliminary configuration prevents unauthorized applications from accessing the network in both idle and connected modes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network device sends access control information to the UE, and the UE provides feedback by checking whether the current application is allowed to access the network based on the received access control information. The UE determines whether to send the RRC connection establishment request or non-access stratum signaling based on the access control indication corresponding to the application identifier, creating a feedback loop that prevents unauthorized access.

Inventive Principle:
Principle #23Feedback

2Reliability

If the UE checks access control information for every application, then unauthorized applications are prevented from accessing the network, but the complexity of the access control mechanism increases

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control mechanism is segmented into distinct components: application identifiers, access control indications, and determination logic. The access control information is segmented into multiple access control indications, each corresponding to a specific application identifier. This segmentation allows the UE to efficiently check only the relevant access control indication for the current application without processing all access control information, reducing complexity while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10674363B2Access control method, user equipment, and network device
Publication Date: 2020.06.02 HONOR DEVICE CO LTD
  • US10674363B2 patent drawing
  • US10674363B2 patent drawing
  • US10674363B2 patent drawing

AI summary

The present disclosure provides an access control method, user equipment, and a network device. The UE is connected to the network device, and the method includes: receiving, by the UE, access control information sent by the network device; and determining, according to obtained first application information in a service establishment request and the access control information, whether to send non-access stratum signaling to the network device, so as to determine whether a first application corresponding to the first application information is allowed to access a network. In this way, network resources are reduced.