WO2023011069A1 - 一种通信方法及装置 - Google Patents

一种通信方法及装置 Download PDF

Info

Publication number
WO2023011069A1
WO2023011069A1 PCT/CN2022/103024 CN2022103024W WO2023011069A1 WO 2023011069 A1 WO2023011069 A1 WO 2023011069A1 CN 2022103024 W CN2022103024 W CN 2022103024W WO 2023011069 A1 WO2023011069 A1 WO 2023011069A1
Authority
WO
WIPO (PCT)
Prior art keywords
session
network
terminal device
identifier
network function
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2022/103024
Other languages
English (en)
French (fr)
Inventor
雷中定
王海光
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to EP22851784.3A priority Critical patent/EP4376487A4/en
Publication of WO2023011069A1 publication Critical patent/WO2023011069A1/zh
Priority to US18/434,782 priority patent/US20240179614A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W48/00—Access restriction; Network selection; Access point selection
    • H04W48/02—Access restriction performed under specific conditions
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W24/00—Supervisory, monitoring or testing arrangements
    • H04W24/02—Arrangements for optimising operational condition
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/20—Services signaling; Auxiliary data signalling, i.e. transmitting data via a non-traffic channel
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W48/00—Access restriction; Network selection; Access point selection
    • H04W48/16—Discovering, processing access restriction or access information
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • H04W60/04—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration using triggered events
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • H04W60/06—De-registration or detaching
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W76/00—Connection management
    • H04W76/10—Connection setup
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W76/00—Connection management
    • H04W76/30—Connection release
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W8/00—Network data management
    • H04W8/02—Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/08—Mobility data transfer
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W76/00—Connection management
    • H04W76/10—Connection setup
    • H04W76/11—Allocation or use of connection identifiers
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W76/00—Connection management
    • H04W76/10—Connection setup
    • H04W76/12—Setup of transport tunnels
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04W—WIRELESS COMMUNICATION NETWORKS
    • H04W76/00—Connection management
    • H04W76/30—Connection release
    • H04W76/32—Release of transport tunnels

Definitions

  • the present application relates to the technical field of wireless communication, and in particular to a communication method and device.
  • the access and mobility management function can send an availability query and terminal quantity update (availability check and update, ACU) request to the network slice admission control function (Network Slice Admission Control Function, NSACF), According to the request of the ACU, the NSACF updates the number of terminal devices registered in the network slice identified as single network slice selection assistance information (S-NSSAI). When the admission quota of the number of terminals in the network slice is full, the NSACF notifies the AMF accordingly, and the AMF may therefore reject the access request of the terminal device.
  • S-NSSAI single network slice selection assistance information
  • the session management function can send an ACU request to the NSACF, and the NSACF updates the number of protocol data unit (PDU) sessions established in the network slice identified as S-NSSAI according to the ACU request.
  • PDU protocol data unit
  • the NSACF notifies the SMF accordingly, and the SMF can therefore reject the session establishment request of the terminal device.
  • the NF may send a false ACU request to NSACF, causing NSACF to incorrectly update the number of registered terminal devices or established PDU sessions in the network slice, causing other terminal devices to fail to connect normally. Incoming or terminal devices cannot normally establish a new PDU session, and the network slicing service is degraded or unable to provide services normally.
  • the present application provides a communication method and device, which are used to reduce wrong updates of network slice configurations caused by false news, and improve the stability of services provided by network slices.
  • a communication method including the following process: an admission control network function receives a first message, and the first message includes first parameter information for updating the number of terminal devices or sessions in the first network slice; The ingress control network function verifies the authenticity of the first parameter information, and if the first parameter information is true, updates the number of terminal devices or sessions in the first network slice.
  • the first parameter information may include one or more of the following information: terminal device identifier, first network slice identifier, access management network function identifier, first indication information requesting registration or de-registration, requesting session establishment or release session.
  • the second indication information the access type of the terminal device, the session identifier, the data network identifier, the session management network function identifier, and the status of the session.
  • the first parameter information may include one or more of the following information: terminal device identifier, first network slice identifier, access management The network function identifier, the first indication information requesting registration or de-registration, and the access type of the terminal device.
  • the first parameter information may include one or more of the following information: terminal device identifier, identifier of the first network slice, request to establish The second indication information of the session or the released session, the session ID, the data network ID, the session management network function ID, and the state of the session.
  • the admission control network function may be NSACF.
  • the admission control network function may verify the authenticity of the first parameter information by itself, or the admission control network function may request other network functions to verify the authenticity of the first parameter information. The authenticity of the first parameter information is verified.
  • the admission control network function receives the first parameter information, and the first parameter information is used to update the number of terminal devices or sessions in the first network slice, and the admission control network function may check the true value of the first parameter information Fake verification, when the first parameter information is true, the number of terminal devices or sessions in the first network slice may be updated, and when the first parameter information is false, it indicates that the first parameter information is forged and wrong information, The number of terminal devices or sessions in the first network slice is not updated, thereby reducing incorrect updates of network slice configurations caused by false messages, ensuring that terminal devices can normally access network slices or establish PDU sessions normally, and improve network security. Slicing provides service stability.
  • the admission control network function verifies the authenticity of the first parameter information
  • one or more of the following methods may be adopted:
  • the admission control network function checks whether the terminal device corresponding to the terminal device identifier has signed up for the service of the network to which the first network slice belongs or has signed up for the service of the home network corresponding to the first network slice;
  • the admission control network function checks whether the terminal device has subscribed to the service of the first network slice or the service of the network slice of the home network corresponding to the first network slice;
  • the admission control network function checks whether the terminal device is registered with the network to which the first network slice belongs;
  • the admission control network function checks whether the terminal device is connected to the first network slice
  • the access control network function verifies whether the terminal device has registered with the network through the access management network function corresponding to the access management network function identifier;
  • the admission control network function verifies whether the terminal device has accessed the first network slice through the access management network function
  • the access control network function verifies whether the terminal device has connected to the network through the access type
  • the admission control network function checks whether the registration or de-registration request indicated by the first indication information matches the saved registration status of the terminal device;
  • the admission control network function checks whether the request for establishing a session or releasing a session indicated by the second indication information matches the saved session state of the terminal device;
  • the admission control network function checks whether the session identifier or the session corresponding to the session identifier exists
  • the admission control network function checks whether the session identifier or the session corresponding to the session identifier belongs to the terminal device;
  • the admission control network function checks whether the session identifier or the session corresponding to the session identifier belongs to the first network slice;
  • the admission control network function checks whether the session corresponding to the session identifier belongs to the session management network function management corresponding to the session management network function identifier;
  • the admission control network function checks whether the state of the session is consistent with the current state of the session
  • the admission control network function checks whether the first network slice matches the data network corresponding to the data network identifier.
  • the admission control network function may itself verify the authenticity of the first parameter information.
  • the second parameter information used to verify the authenticity of the first parameter information may be pre-stored in the admission control network function, or may be obtained by the admission control network function from other network functions.
  • the admission control network function may send a fifth message to the data management network function, where the fifth message is used to request the second parameter information, and the first The second parameter information is used to verify the authenticity of the first parameter information; and receive a sixth message from the data management network function, where the sixth message includes the second parameter information.
  • the admission control network function may not store real second parameter information.
  • the admission control network function when it verifies the authenticity of the first parameter information, it may send a second message to the data management network function, and the second message is used to request verification of the first parameter information. and receiving a third message, where the third message includes a verification result of the first parameter information, and the verification result is used to indicate whether the first parameter information is true or false.
  • the admission control network function may request other network functions (such as the data management network function) to verify the authenticity of the first parameter information.
  • the second message includes one or more of the following information: terminal device identifier, instruction information for verifying the subscription status of the terminal device, and instruction information for verifying the access status of the terminal device , the identifier of the first network slice, the slice identifier of the home network corresponding to the first network slice, the identifier of the access management network function, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, The terminal device's access type, session ID, data network ID, session management network function ID, and session status.
  • the admission control network function may further determine that the first condition is satisfied. Satisfying the first condition includes one or more of the following: the duration of the timer reaches the first duration, the number of times the first message is received reaches the first threshold, and the number of connected terminal devices or sessions reaches the first threshold 1. Receive the indication information triggering the verification.
  • trigger verification is determined when the first condition is met, which can avoid verification of a large number of first parameter information received at the same time or in a short period of time, and increase access control
  • the processing burden of the network function reduces the processing efficiency of the admission control network function.
  • the first message is sent when the admission control mode performed first is in an inactive state, and the number of terminal devices requesting to access the first network slice reaches a second number threshold.
  • the access management network function can first authorize the terminal device to access the first network slice, and then execute the ACU process.
  • the second number threshold it is possible to avoid the risk that the access management network function authorizes a large number of terminal devices to access at the same time or within a short period of time, resulting in the number of terminal devices exceeding the configuration of the first network slice, thereby Further improve the stability of services provided by network slicing.
  • a communication method including the following process: the data management network function receives a second message, the second message is used to request verification of the first parameter information, and the first parameter information is used to update the first network slice The number of end devices or sessions.
  • the data management network function may verify the first parameter information according to the acquired second parameter information of the terminal device or session.
  • the data management network function sends a third message to the admission control network function, the third message includes a verification result of the first parameter information, and the verification result includes whether the first parameter information is true or false.
  • the data management network function may be unified data management (UDM) and/or unified data storage (UDR).
  • UDM unified data management
  • UDR unified data storage
  • the data management network function can verify the authenticity of the first parameter information received by the admission control network function, thereby reducing the error update of the network slice configuration caused by false information and improving the service efficiency of the network slice. stability.
  • the second message includes one or more of the following information: terminal device identifier, instruction information for verifying the subscription status of the terminal device, and instruction information for verifying the access status of the terminal device , the identifier of the first network slice, the slice identifier of the home network corresponding to the first network slice, the identifier of the access management network function, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, The terminal device's access type, session ID, data network ID, session management network function ID, and session status.
  • the data management network function verifies the first parameter information according to the obtained second parameter information of the terminal device or session, and may adopt one or more of the following methods:
  • the data management network function verifies the contract status of the terminal device according to the instruction information for verifying the contract status of the terminal device
  • the data management network function checks whether the terminal device corresponding to the terminal device identifier has signed up for the service of the network to which the first network slice belongs or has signed up for the service of the network of the home network corresponding to the first network slice;
  • the data management network function checks whether the terminal device has subscribed to the service of the first network slice or the service of the network slice of the home network corresponding to the first network slice;
  • the data management network function verifies the access status of the terminal device according to the instruction information for verifying the access status of the terminal device
  • the data management network function checks whether the terminal device is registered with the network to which the first network slice belongs;
  • the data management network function checks whether the terminal device is connected to the first network slice
  • the data management network function verifies whether the terminal device has registered with the network through the access management network function corresponding to the access management network function identifier;
  • the data management network function verifies whether the terminal device has accessed the first network slice through the access management network function
  • the data management network function checks whether the terminal device is connected to the network through the access type
  • the data management network function checks whether the registration or de-registration request indicated by the first indication information matches the saved registration status of the terminal device;
  • the data management network function checks whether the request for establishing a session or releasing a session indicated by the second indication information matches the saved session state of the terminal device;
  • the data management network function checks whether the session identifier or the session corresponding to the session identifier exists
  • the data management network function checks whether the session identifier or the session corresponding to the session identifier belongs to the terminal device;
  • the data management network function checks whether the session identifier or the session corresponding to the session identifier belongs to the first network slice;
  • the data management network function checks whether the session corresponding to the session identifier belongs to the session management network function management corresponding to the session management network function identifier;
  • the data management network function checks whether the state of the session is consistent with the current state of the session
  • the data management network function checks whether the first network slice matches the data network corresponding to the data network identifier.
  • a communication method including the following process: when the admission control mode performed first is in an inactive state, the access management network function determines the number of terminal devices requesting to access the first network slice. If the number of terminal devices requesting access to the first network slice reaches the second number threshold, the access management network function sends a first message to the admission control network function, and the first message includes information for updating terminal devices in the first network slice. quantity.
  • the access management network function can first authorize terminal devices to access the first network slice, and then execute the ACU process, but there may be a large number of terminal devices authorized to access Therefore, by setting the second number threshold, it can be ensured that the number of connected terminal devices is within the range that the first network slice can stably provide services , to improve the stability of services provided by network slicing.
  • the access management network function may be an AMF.
  • the access management network function may also receive a fourth message sent by the admission control network function, where the fourth message is used to modify the pre-executed admission control mode to an inactive state.
  • the access management network function may verify the fourth message, and if the verification is passed, the access management network function determines that the admission control mode is first executed as an inactive state.
  • the access management network function can verify the authenticity of the fourth message.
  • the fourth message can modify the admission control mode to be inactive.
  • the fourth message is false
  • the fourth message may include one or more of the following information: an admission control network function identifier, an identifier of an operator network where the admission control network function is located, and an identifier of the first network slice.
  • the access management network function may check one or more of the access control network function identifier, the identifier of the operator network where the admission control network function is located, and the identifier of the first network slice. check.
  • a communication device which can be the above-mentioned admission control network function or data management network function or access management network function, or be set in the admission control network function or data management network function or access Chips in management network functions or session management network functions.
  • the communication device may implement the method provided by any one of the designs of the first aspect, the second aspect, or the third aspect.
  • the communication device includes a corresponding module, unit, or means (means) for implementing the above method, and the module, unit, or means may be implemented by hardware, software, or by executing corresponding software on hardware.
  • the hardware or software includes one or more modules or units corresponding to the above functions.
  • a communication device including a transceiver unit.
  • the communication device further includes a processing unit.
  • the communication device may implement the method provided by any design in the first aspect, the second aspect, or the third aspect.
  • a communication device including a processor.
  • the processor may be used to execute the method provided by any one of the above-mentioned first aspect, second aspect, or third aspect.
  • the device further includes a memory, the processor is coupled to the memory, and the memory is used to store computer programs or instructions, and the processor can execute the programs or instructions in the memory, so that the device can perform the above-mentioned first aspect or the second aspect. Any one design method provided in the second aspect or the third aspect.
  • a communication device includes an interface circuit and a logic circuit, and the logic circuit is coupled to the interface circuit.
  • the interface circuit may be a code/data read-write interface circuit, or a communication interface, and the interface circuit is used to receive computer-executed instructions (computer-executed instructions are stored in the memory, may be read directly from the memory, or may pass through other devices) and transmit to the logic circuit, so that the logic circuit runs the computer to execute instructions to execute the method provided by any one of the above-mentioned first aspect, second aspect or third aspect.
  • the communication device may be a chip or a chip system.
  • a communication device including a processor and a memory.
  • the processor is used to read instructions stored in the memory, and can receive signals through the receiver, and transmit signals through the transmitter, so as to execute the method provided by any one of the above-mentioned first aspect, second aspect, or third aspect. .
  • processors there may be one or more processors, and one or more memories.
  • the memory can be integrated with the processor, or the memory can be set separately from the processor.
  • the memory can be a non-transitory (non-transitory) memory, such as a read-only memory (read only memory, ROM), which can be integrated with the processor on the same chip, or can be respectively arranged in different On the chip, the application does not limit the type of the memory and the arrangement of the memory and the processor.
  • a non-transitory memory such as a read-only memory (read only memory, ROM)
  • ROM read only memory
  • the communication device can be a chip, and the processor can be implemented by hardware or software.
  • the processor can be a logic circuit, integrated circuit, etc.; when implemented by software, the processing
  • the processor may be a general-purpose processor, and may be implemented by reading software codes stored in a memory.
  • the memory may be integrated in the processor, or it may be located outside the processor and exist independently.
  • a processor including: an input circuit, an output circuit, and a processing circuit.
  • the processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor executes the method provided by any one of the above-mentioned first aspect, second aspect or third aspect.
  • the above-mentioned processor can be a chip
  • the input circuit can be an input pin
  • the output circuit can be an output pin
  • the processing circuit can be a transistor, a gate circuit, a flip-flop, and various logic circuits.
  • the input signal received by the input circuit may be received and input by, for example but not limited to, the receiver
  • the output signal of the output circuit may be, for example but not limited to, output to the transmitter and transmitted by the transmitter
  • the circuit may be the same circuit, which is used as an input circuit and an output circuit respectively at different times.
  • the present application does not limit the specific implementation manners of the processor and various circuits.
  • a communication device including: a logic circuit and an input-output interface, the input-output interface is used to communicate with modules other than the communication device; the logic circuit is used to run computer programs or instructions to perform any of the above-mentioned Aspect any one of the methods provided by Design.
  • the communication device may be the admission control network function or the data management network function or the access management network function or the session management function in the above-mentioned first aspect or the second aspect or the third aspect, or include the above-mentioned admission control network function or data
  • a device for managing network functions or access management network functions or session management functions or a device contained in the above-mentioned admission control network functions or data management network functions or access management network functions or session management functions, such as a chip.
  • the I/O interface may be a code/data read/write interface circuit, or a communication interface, and the I/O interface is used to receive computer programs or instructions (the computer programs or instructions are stored in the memory, may be directly read from the memory, or may through other devices) and transmitted to the input-output interface, so that the input-output interface runs a computer program or instruction to perform the method of any one of the above aspects.
  • the communication device may be a chip.
  • a computer program product includes: a computer program (also referred to as code, or an instruction), when the computer program is executed, the computer executes the above-mentioned first aspect or the second aspect Or the method provided by any one design in the third aspect.
  • a computer program also referred to as code, or an instruction
  • a computer-readable medium stores a computer program (also referred to as code, or instruction) when it is run on a computer, so that the computer executes the above-mentioned first or second aspect.
  • a computer program also referred to as code, or instruction
  • a chip system includes a processor and an interface, configured to support a communication device to realize the functions provided by any one of the designs of the first aspect, the second aspect, or the third aspect.
  • the chip system further includes a memory for storing necessary information and data of the aforementioned communication device.
  • the system-on-a-chip may consist of chips, or may include chips and other discrete devices.
  • a chip device in a fourteenth aspect, includes an input interface and/or an output interface.
  • the input interface can realize the receiving function provided by any design in the first aspect or the second aspect or the third aspect
  • the output interface can realize any design in the first aspect or the second aspect or the third aspect The send function provided.
  • a functional entity is provided, and the functional entity is used to implement the method provided by any one of the above first to third aspects.
  • a sixteenth aspect provides a communication system, including the admission control network function or data management network function or access management network function or session management function of the first aspect or the second aspect or the third aspect.
  • the technical effect brought about by any one of the design methods from the second aspect to the sixteenth aspect can refer to the technical effect brought about by the above-mentioned first aspect, and will not be repeated here.
  • FIG. 1 is a schematic diagram of a possible network architecture applicable to an embodiment of the present application
  • Fig. 2 is a schematic flow chart of an ACU
  • Fig. 3 is a schematic flow chart of an ACU
  • FIG. 4 is a schematic diagram of a communication process applicable to an embodiment of the present application.
  • FIG. 5 is a schematic diagram of a communication process applicable to an embodiment of the present application.
  • FIG. 6 is a schematic diagram of a first-execution admission control process
  • FIG. 7 is a schematic diagram of a first-execution admission control process
  • FIG. 8 is a schematic diagram of a communication process applicable to an embodiment of the present application.
  • FIG. 9 is a schematic diagram of a communication device applicable to an embodiment of the present application.
  • FIG. 10 is a schematic diagram of a communication device applicable to an embodiment of the present application.
  • FIG. 11 is a schematic diagram of a communication device applicable to an embodiment of the present application.
  • the present application presents various aspects, embodiments or features in terms of a system that can include a number of devices, components, modules and the like. It is to be understood and appreciated that the various systems may include additional devices, components, modules, etc. and/or may not include all of the devices, components, modules etc. discussed in connection with the figures. In addition, combinations of these schemes can also be used.
  • the network architecture and business scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute limitations on the technical solutions provided by the embodiments of the present application.
  • the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
  • UE User equipment
  • terminal equipment is a device with wireless transceiver function, which can communicate with one or more Core network (core network, CN) devices communicate.
  • Core network Core network
  • User equipment may also be called an access terminal, terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, or user device, among others.
  • User equipment can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; it can also be deployed on water (such as ships, etc.); it can also be deployed in the air (such as on aircraft, balloons, and satellites, etc.).
  • the user equipment can be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smart phone, a mobile phone, a wireless local loop (WLL) Station, personal digital assistant (PDA), etc.
  • SIP session initiation protocol
  • WLL wireless local loop
  • PDA personal digital assistant
  • the user equipment can also be a handheld device with wireless communication function, a computing device or other devices connected to a wireless modem, a vehicle device, a wearable device, a drone device or a terminal in the Internet of Things, the Internet of Vehicles, the fifth generation Mobile communication (5th-generation, 5G) network and any form of terminal in the future network, relay user equipment or terminal in the future evolution of the public mobile land network (public land mobile network, PLMN), etc.
  • the relay user equipment may be, for example, a 5G residential gateway (residential gateway, RG).
  • the user equipment can be a virtual reality (virtual reality, VR) terminal, an augmented reality (augmented reality, AR) terminal, a wireless terminal in industrial control (industrial control), a wireless terminal in self driving (self driving), telemedicine Wireless terminals in remote medical, wireless terminals in smart grid, wireless terminals in transportation safety, wireless terminals in smart city, and smart home wireless terminals, etc.
  • the embodiment of the present application does not limit the type or category of the terminal device.
  • a network device refers to a device that can provide a wireless access function for a terminal.
  • the network device may support at least one wireless communication technology, such as long term evolution (long term evolution, LTE), new radio (new radio, NR) and the like.
  • network equipment may include access network equipment.
  • the network equipment includes but is not limited to: a next-generation base station or a next-generation node B (generation nodeB, gNB), an evolved node B (evolved node B, eNB) in a 5G network, and a radio network controller (radio network controller, RNC), node B (node B, NB), base station controller (base station controller, BSC), base transceiver station (base transceiver station, BTS), home base station (for example, home evolved node B, or home node B, HNB ), baseband unit (baseband unit, BBU), transceiver point (transmitting and receiving point, TRP), transmitting point (transmitting point, TP), mobile switching center, small station, micro station, etc.
  • RNC radio network controller
  • node B node B
  • base station controller base station controller
  • BTS base transceiver station
  • home base station for example, home evolved node B, or home node B, H
  • the network device may also be a wireless controller, a centralized unit (centralized unit, CU), and/or a distributed unit (distributed unit, DU) in a cloud radio access network (cloud radio access network, CRAN) scenario, or the network device may It is a relay station, an access point, a vehicle-mounted device, a terminal, a wearable device, a network device in future mobile communications or a network device in a future evolved PLMN, etc.
  • the network device may include a core network (CN) device, such as an AMF, an SMF, and the like.
  • CN core network
  • At least one refers to one or more, and multiple refers to two or more.
  • PLMN a part operated by an operator
  • PLMN is a network established and operated by the government or its approved operators for the purpose of providing land mobile communication services to the public. It is mainly a public network where mobile network operators (MNO) provide mobile broadband access services for users. network.
  • MNO mobile network operators
  • the PLMN described in the embodiments of the present application may specifically be a network conforming to the requirements of the third generation partnership project (3rd generation partnership project, 3GPP) standard, referred to as a 3GPP network.
  • 3GPP network generally includes but is not limited to 5G, a fourth-generation mobile communication (4th-generation, 4G) network, and other future communication systems such as 6G.
  • the 5G network has also adjusted its network architecture compared to the 4G network. For example, the 5G network splits the mobility management entity (MME) in the 4G network into multiple network functions including AMF and SMF.
  • MME mobility management entity
  • FIG. 1 is a schematic diagram of a 5G network architecture, which may include: a user equipment 110 part, a PLMN part and a data network (data network, DN) 150 part.
  • PLMN may include: network exposure function (network exposure function, NEF) 131, network storage function (network function repository function, NRF) 132, policy control function (policy control function, PCF) 133, unified data management (unified data management, UDM) ) 134, unified data storage (unified data repository, UDR) 135, network data analysis function (network data analytics function, NWDAF) 136, network slice selection function (network slice selection function, NSSF) 137, authentication server function (authentication server function) , AUSF) 138, AMF 139, session management function (session management function, SMF) 140, network slice authentication and authorization function (Network Slice Specific Authentication and Authorization Function, NSSAAF) 141, network slice admission control function (NSACF) 142, user plane Function (user plane function, UPF) 130, access network (access network, AN) 120, etc.
  • the part other than the access network 120 part may be called the core network part.
  • the data network DN 150 may also be called a packet data network (packet data network, PDN), and may be deployed within the PLMN or outside the PLMN (such as a third-party network).
  • PDN packet data network
  • AN 120 also called wireless (Radio) AN, is a sub-network of PLMN, and is an implementation system between service nodes (or network functions) in PLMN and UE110.
  • the UE 110 To access the PLMN, the UE 110 first passes through the AN 120, and then connects to the service node in the PLMN through the AN 120.
  • the AN 120 in the embodiment of the present application may refer to the access network itself, or refer to the access network equipment, which is not distinguished here.
  • the access network device is a device that provides a wireless communication function for the UE 110 , and may also be called an access device, (R)AN device, or network device. It can be understood that the present application does not limit the specific type of the access network device. In systems using different wireless access technologies, the names of devices that function as access network devices may be different.
  • the access device may include a CU, a DU, and so on.
  • the CU can also be divided into CU-control plane (control plane, CP) and CU-user plane (user plan, UP).
  • the access device can also be an open radio access network (open radio access network, O-RAN or Open RAN) architecture, etc. This application does not limit the specific deployment method of the access device .
  • a network opening function NEF (also called a network opening function entity) 131 is a control plane function provided by an operator, and is used to enable a third party to use services provided by the network.
  • the network storage function NRF 132 is a control plane function provided by the operator, which can be used to maintain real-time information of all network function services in the network.
  • the policy control function PCF 133 is a control plane function provided by the operator. It supports a unified policy framework to govern network behavior, and provides policy rules and contract information related to policy decisions to other control functions.
  • the unified data management UDM 134 is a control plane function provided by the operator, responsible for storing SUPI, security context (security context), subscription data and other information of the subscriber in the PLMN.
  • the unified data storage UDR135 is a control plane network function provided by the PLMN, which is used to support the storage and extraction of UDM subscription data, PCF policy data, open structured data, application data, etc.
  • the network data analysis function NWDAF136 is a control plane network function provided by PLMN, which is used to support network operation-related network functions (network function, NF), application functions (application function, AF), network management data collection, data openness, analysis, Machine learning model training, etc.
  • network function network function, NF
  • application function application function, AF
  • network management data collection data openness, analysis, Machine learning model training, etc.
  • the network slice selection function NSSF137 is a control plane network function provided by the PLMN, which is responsible for determining a network slice instance, selecting an AMF, and so on.
  • the authentication server function AUSF 138 is a control plane function provided by the operator, and is usually used for the first-level authentication, that is, the network authentication between the UE 110 (subscriber) and the PLMN.
  • Access and mobility management function AMF 139 is a control plane network function provided by the PLMN, which is responsible for the access control and mobility management of the UE 110 accessing the PLMN, for example, including mobility status management, allocation of user temporary identities, authentication and authorization of users, etc. Function.
  • the session management function SMF 140 is a control plane network function provided by the PLMN, and is responsible for managing the PDU session of the UE 110 .
  • the PDU session is a channel for transmitting PDUs, and the terminal device needs to transmit data with DN 150 through the PDU session.
  • the PDU session can be established, maintained and deleted by the SMF 140.
  • SMF 140 includes session management (such as session establishment, modification and release, including tunnel maintenance between UPF 130 and AN 120, etc.), selection and control of UPF 130, service and session continuity (service and session continuity, SSC) mode selection , roaming and other session-related functions.
  • the network slice authentication and authorization function NSSAAF141 is a control plane network function provided by the PLMN, and is used to support slice authentication between the UE110 and the DN.
  • the network slice admission control function NSACF142 is a network function used by the PLMN to monitor and control the number of UEs registered on the network slice. Usually, the maximum number of UEs that can be served in each network slice monitored and controlled by NSACF is configured on the NSACF.
  • the user plane function UPF 130 is a gateway provided by the operator, and is a gateway for communication between the PLMN and the DN 150 .
  • the UPF 130 includes functions related to the user plane such as data packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, lawful interception, uplink packet detection, and downlink data packet storage.
  • QoS quality of service
  • the network functions in the PLMN shown in FIG. 1 may also include other network functions (not shown in the figure), and this embodiment of the present application does not limit other network functions included in the PLMN.
  • Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nnssf, Nausf, Namf, Nsmf, Nnssaaf, Nnsacf, N1, N2, N3, N4, and N6 are interface serial numbers.
  • the meaning of the above interface serial number may refer to the meaning defined in the 3GPP standard protocol, and the present application does not limit the meaning of the above interface serial number.
  • the name of the interface between various network functions in FIG. 1 is only an example. In a specific implementation, the name of the interface of the system architecture may also be another name, which is not limited in this application.
  • the mobility management network function in this application may be the AMF 139 shown in FIG. 1, or other network functions having the above-mentioned access and mobility management function AMF 139 in the future communication system.
  • the mobility management network function in this application may also be a mobility management entity (mobility management entity, MME) in the LTE system. Understandably, other network functions are also applicable.
  • the network architecture diagram shown in FIG. 1 can be understood as a service-based 5G network architecture diagram in a non-roaming scenario.
  • this architecture according to the requirements of specific scenarios, different network functions are combined in an orderly manner as needed, which can realize the customization of network capabilities and services, so as to deploy dedicated networks for different services and realize 5G network slicing.
  • Network slicing technology can enable operators to respond to customer needs more flexibly and quickly, and support flexible allocation of network resources.
  • Slice is network slicing.
  • a simple understanding is to divide the operator's physical network into multiple virtual end-to-end networks. Between each virtual network (including devices in the network, access network, transmission network and core network) ) are logically independent, any failure of one virtual network will not affect other virtual networks.
  • Instances of different service types may be deployed on different network slices, and different instances (instances) of the same service type may also be deployed on different network slices.
  • a slice can consist of a set of network functions (network functions, NFs) and/or sub-networks.
  • the subnetwork (R)AN 120, AMF 139, SMF 140, and UPF 130 in Figure 1 can form a slice. It can be understood that only one of each network function is schematically shown in FIG. 1 , but in actual network deployment, there may be multiple or tens of each network function or sub-network. Many slices can be deployed in the PLMN, and each slice can have different performances to meet the requirements of different applications and vertical industries. Operators can "tailor-made" a slice according to the needs of customers in different vertical industries.
  • the UE may provide or indicate to the core network the slice that the UE wants to access in an uplink message.
  • the uplink message is the message sent by the UE to the network side, such as registration request, service request, periodic registration update, etc. For convenience of description, these uplink messages are described as "request messages" below.
  • the indication information of the desired slice is called a requested (network slice selection assistance information set) (NSSAI).
  • NSSAI network slice selection assistance information set
  • the NSSAI is actually a list or a set, which includes one or more S-NSSAI.
  • An S-NSSAI is used to identify a network slice (it can also be a type of network slice), which can also be understood as S-NSSAI is the identification information of the slice.
  • NSI-ID Network Slice Instance Identifier/Identity
  • S-NSSAI Network Slice Instance Identifier/Identity
  • a slice identified by an S-NSSAI can also be instantiated into one or more slice instances (slice instance) , each NSI-ID corresponds to a slice instance.
  • an NSI-ID can also be called identification information of a slice, and one S-NSSAI can correspond to multiple NSI-IDs.
  • S-NSSAI uses S-NSSAI as an example for description, and does not strictly distinguish or limit S-NSSAI and NSI-ID. The description of S-NSSAI can also be applied to NSI-ID.
  • slice-level authentication is a network control function with limited participation by slice customers, that is, to authenticate and authorize terminal devices accessing slices. This application is referred to as “slice authentication" for short.
  • the terminal device Before the terminal device is allowed to access the network slice, it first needs to perform a "network-level authentication" with the PLMN network, that is, the PLMN needs to perform authentication based on the contract identification information used by the terminal device to sign with the PLMN. This authentication is usually called Primary authentication. Secondly, the PLMN needs to perform authentication based on the subscription identifier used by the terminal device and the DN, that is, "slice authentication".
  • the NSACF mentioned above is a network function used by the PLMN to monitor and control the number of terminal devices (or the number of PDU sessions) registered on the network slice.
  • the PLMN may first configure the maximum number of terminal devices (or PDU sessions) that can be served in each network slice monitored by the NSACF on one or more NSACFs, or Quota.
  • NSACF When the network is ready to authorize a new terminal device to access a certain slice (or allow a new PDU session to be established in a certain slice), NSACF first determines whether the network slice is It is also possible to accept the terminal device's access request (or the terminal device's PDU session establishment request), and store and update the number of admitted terminals (or the number of established PDU sessions) in the slice in real time.
  • the network slicing here refers to the network slicing that requires admission control (or PDU session quantity control). In the following description, unless otherwise specified, all network slices belong to such slices that require admission (or number of PDU sessions)
  • ACU basic process of availability check and update
  • AMF triggers an ACU process.
  • This process will be triggered when AMF performs processes such as registration, de-registration, configuration update (UE Configuration Update, UCU), re-authentication and authorization revocation initiated by the slice authentication server for the terminal device.
  • processes such as registration, de-registration, configuration update (UE Configuration Update, UCU), re-authentication and authorization revocation initiated by the slice authentication server for the terminal device.
  • time involved in the embodiments of the present application may mean before, during, or after the execution of the process, which will be described uniformly here and will not be described in detail below.
  • the AMF When the AMF decides to trigger the ACU process, it will first verify that the slice identified as S-NSSAI is a slice that the PLMN allows the terminal device to access, that is, the AMF verifies that the S-NSSAI is in the (corresponding to the terminal device) "NSSAI list allowed for access" "(Allowed NSSAI). After the verification is successful, the AMF will send an ACU request for the S-NSSAI to the NSACF, that is, execute S202.
  • S202 The AMF sends an ACU request to the NSACF.
  • the NSACF receives the ACU request.
  • the ACU request may include UE identity, S-NSSAI, access type (access type) and update flag (flag).
  • the update identification flag is used to indicate the UE's request for S-NSSAI, which is used to request "number increase” (such as when the UE registers the slice S-NSSAI) or request "number reduction” (such as when the UE registers the slice S-NSSAI) .
  • the S-NSSAI may refer to the S-NSSAI of the network slice provided by the visited network (ie, visited PLMN), or may refer to the UE's affiliation corresponding to the network slice of the visited network.
  • the S-NSSAI of the network (home PLMN), that is, the mapped S-NSSAI (Mapped S-NSSAI), can also include the above two S-NSSAIs at the same time, that is, the S-NSSAI of the visited network and the Mapped S-NSSAI of the home network .
  • S203 The NSACF responds to the ACU request according to the number of currently admitted terminal devices.
  • the NSACF may update the number of terminals registered on the slice identified as S-NSSAI.
  • the NSACF checks whether the UE corresponding to the UE identifier has been included in the admitted UE list. If yes, the admitted UE counter remains unchanged. If not, NSACF continues to check whether the number of currently admitted UEs is less than the admission quota of the slice S-NSSAI. If the quota is sufficient (that is, the number of terminals accessing the slice has not reached the maximum number of admitted terminals in the slice), NSACF will The UE is included in the admitted UE list, and the count value of the admitted UE counter is increased by 1. If the quota is full, the counter remains unchanged, and responds to the AMF that the slice quota is full.
  • the NSACF deletes the UE identification from the admitted UE list, and decreases the count value of the counters of all slice S-NSSAIs admitted to the UE by 1.
  • S204 The NSACF sends an ACU response to the AMF.
  • the NSACF will include the number update information in the ACU response. If it is determined that the quota is full, the NSACF responds to the ACU including the information that the slice quota is full.
  • the AMF can perform corresponding processing according to the received ACU response. For example, when the slice quota is full, the AMF may reject the UE's request to access the slice S-NSSAI, and notify the UE of the rejection reason that the slice quota is full. Optionally, the AMF may also notify the UE to wait for a period of time (and send the waiting time) and then re-request for access.
  • AMFx indicates that the NF has been maliciously controlled, or is controlled by an insider (insider), so as to send a false message, which can cause NSACF to incorrectly update the number of terminal devices or PDU sessions registered in the network slice.
  • NSACF mistakenly believes that the slice quota is full, and when AMF sends an ACU request, because the slice has no quota, NSACF refuses UE access or refuses to establish a PDU session, resulting in the failure of terminal equipment to access or establish a PDU session normally, network slicing The service is degraded or cannot be provided normally.
  • an embodiment of the present application provides a communication method.
  • the admission control network function receives a first message, the first message includes first parameter information used to update the number of terminal devices or sessions in the first network slice, and the admission control network function performs the first parameter information Check the authenticity of the first parameter information, if the first parameter information is true, the admission control network function can update the number of terminal devices or sessions in the first network slice, here by checking the authenticity of the received first parameter The verification can reduce the wrong update of the network slice configuration caused by false news, ensure that the terminal equipment can normally access the network slice or can establish a PDU session normally, improve the stability of the service provided by the network slice, and improve the security of the network.
  • FIG. 4 is a possible communication method, including the following steps:
  • the admission control network function receives a first message.
  • the admission control network function may be NSACF in 5G.
  • the first message includes first parameter information for updating the number of terminal devices or sessions in the first network slice.
  • the first message may be an ACU request message.
  • the first parameter information may include but not limited to one or more of the following information: terminal device identifier, first network slice identifier, access management network function identifier, first indication information requesting registration or de-registration, request to establish a session or Release the second indication information of the session, the access type of the terminal device, the session identifier, the data network identifier, the session management network function identifier, and the status of the session.
  • terminal device identifier terminal device identifier
  • first network slice identifier access management network function identifier
  • first indication information requesting registration or de-registration, request to establish a session or Release the second indication information of the session
  • the access type of the terminal device the session identifier
  • the data network identifier the data network identifier
  • the session management network function identifier the status of the session.
  • the access management network function (such as AMF) sends the first message to the admission control network function, and the first parameter information is used to update the number of terminal devices in the first network slice.
  • the session management network function (such as SMF) sends the first message to the admission control network function, and the first parameter information is used to update the number of sessions in the first network slice.
  • the first message is sent when the admission control mode performed first is in an inactive state, and the number of terminal devices requesting to access the first network slice reaches a second number threshold.
  • the second quantity threshold may be any positive integer, which is not limited here.
  • S402 The admission control network function verifies the authenticity of the first parameter information.
  • the process of verifying the authenticity of the first parameter information may be to match the real parameter information stored in the network (hereinafter referred to as the second parameter information) with the first parameter information, or to check the consistency.
  • the false message may include the following false parameters, so the verification can be performed on the parameter information that may generate false parameters:
  • False parameter 1 Use an unauthorized terminal device identifier.
  • a fake terminal device identifier is used, which may be a terminal device identifier generated in any manner.
  • Another example is the use of the real terminal device identity intercepted by the AMFx, but the real terminal device identity has not subscribed to the first network slice.
  • Another example is to use a terminal device identifier that subscribes to network slicing, but the serving network where the terminal device identifier is located does not match the serving network to which the NF that sent the first message belongs to.
  • the NF that sends the terminal device ID can pass false messages (fake Parameter 1), the number of terminal devices or sessions is falsely reported, so that the admission control network function mistakenly believes that the quota of the network slice is full, and refuses the UE to access the network slice or establish a session from other NFs, causing the terminal device to suffer from denial of service (denial of service, DoS) attack.
  • denial of service denial of service
  • the admission control network function can verify the authenticity of the terminal device identification.
  • the terminal device identifier may be a UE ID, and/or an Internet Protocol (internet protocol, IP) address of the UE.
  • IP Internet Protocol
  • False parameter 2 Use network slices signed by non-terminal devices.
  • the NF sending the first message can attack network slices served by other NFs by sending false parameter two.
  • the admission control network function can verify the authenticity of the network slice identifier.
  • the network slice identifier may be S-NSSAI.
  • the indication information for requesting to increase the number may be indication information for the terminal device to request registration or request to create a session, and the indication information for requesting to decrease the number may be indication information for the terminal device to request de-registration or request to release the session.
  • the NF that sent the first message eavesdropped on the messages sent by other NFs, and directly tampered with the indication information in the messages of other NFs, so that the number of terminal devices or the number of sessions saved by NSACF did not match the real situation, resulting in terminal devices being unable to access network slices or The session cannot be established or the service is terminated due to network overload.
  • the admission control network function can verify the authenticity of the indication information, where the indication information can be the first indication information (such as update identification flag1) requesting registration or de-registration, and/or the indication information can be the request to create a session or Release the second indication information of the session (for example, update flag2).
  • the indication information can be the first indication information (such as update identification flag1) requesting registration or de-registration, and/or the indication information can be the request to create a session or Release the second indication information of the session (for example, update flag2).
  • False parameter four use the wrong access type (access type).
  • a terminal device uses the real terminal device ID and network slice ID, but using the wrong service type, doubles the number of terminal devices or sessions accessing the network slice.
  • a terminal device repeatedly accesses only one quota, but under multiple access types, a terminal device uses different types of repeated access to occupy multiple quotas. For terminal devices, each type of access will occupy a certain amount of quota.
  • the NF that sends the first message directly tampers with the access type in the messages of other NFs by eavesdropping on the messages sent by other NFs, and can falsely report the number of terminal devices. When the quota reaches the maximum number, other legal terminal devices cannot be accessed.
  • the admission control network function can therefore verify the authenticity of the access type.
  • the admission control network function may itself verify the authenticity of the first parameter information.
  • the admission control network function may store real second parameter information.
  • admission control network function verifies the authenticity of the first parameter information
  • one or more of the following methods may be used:
  • the admission control network function checks whether the terminal device corresponding to the terminal device identifier has subscribed to the service of the network to which the first network slice belongs. If the terminal device corresponding to the terminal device identifier subscribes to the service of the network to which the first network slice belongs, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device corresponding to the terminal device identifier does not subscribe to the first network
  • the service of the network to which the slice belongs may determine that the terminal device identifier and/or the identifier of the first network slice is false.
  • the admission control network function checks whether the terminal device corresponding to the terminal device identifier has subscribed to the service of the home network corresponding to the first network slice. This may be for a scenario when the terminal device roams to the visited network and the first network slice is provided by the visited network.
  • the contracted network of the roaming terminal device is the home network, and the identifier of the subscribed network slice is Mapped S-NSSAI, which has a mapping relationship with the identifier S-NSSAI of the first network slice. Therefore, in the roaming scenario, the admission control network function can check whether the terminal device has subscribed to the home network.
  • the terminal device corresponding to the terminal device identifier subscribes to the service of the home network corresponding to the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true;
  • the service of the home network corresponding to a network slice may determine that the terminal device identifier and/or the identifier of the first network slice is false.
  • the admission control network function checks whether the terminal device has subscribed to the service of the first network slice. If the terminal device subscribes to the service of the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device does not subscribe to the service of the first network slice, it can be determined that the terminal device identifier and/or The flag of a network slice is false.
  • the admission control network function checks whether the terminal device has subscribed to the service of the network slice in the home network corresponding to the first network slice. If the terminal device subscribes to the service of the network slice of the home network corresponding to the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device is not subscribed to correspond to the first network slice. The service of the network slice of the home network may determine that the identifier of the terminal device and/or the identifier of the first network slice is false.
  • the admission control network function checks whether the terminal device is registered with the network to which the first network slice belongs. If the terminal device is registered with the network to which the first network slice belongs, it may be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device is not registered with the network to which the first network slice belongs, it may be determined that the terminal device identifier and/or the identifier of the first network slice is true. Or the identification of the first network slice is false.
  • the admission control network function checks whether the terminal device has access to the first network slice. Accessing the first network slice by the terminal device may mean that the terminal device has received authorization information sent by the network to allow access to the first network slice, for example, the identifier S-NSSAI of the first network slice is in the Allowed NSSAI list of the terminal device. If the terminal device accesses the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true, and if the terminal device accesses the first network slice, it can be determined that the terminal device identifier and/or the first network slice Slice's id is false.
  • the admission control network function verifies whether the terminal device has registered with the network through the access management network function corresponding to the access management network function identifier. If the terminal device registers with the network through the access management network function corresponding to the access management network function identifier, it may be determined that the terminal device identifier and/or the access management network function identifier is true. If the terminal device has not registered with the network through the access management network function corresponding to the access management network function identifier, it may be determined that the terminal device identifier and/or the access management network function identifier are false.
  • the admission control network function checks whether the terminal device establishes a session through the session management network function corresponding to the session management network function identifier. If the terminal device establishes a session through the session management network function corresponding to the session management network function identifier, it may be determined that the terminal device identifier and/or the session management network function identifier is true. If the terminal device has not established a session by accessing the session management network function corresponding to the management network function identifier, it may be determined that the terminal device identifier and/or the session management network function identifier are false.
  • the admission control network function verifies whether the terminal device has accessed the first network slice through the access management network function. If the terminal device accesses the first network slice through the access management network function, it may be determined that one or more parameter information among the terminal device identifier, the access management network function identifier, and the identifier of the first network slice is true, and if the terminal device does not Access the first network slice through the access management network function, or if the terminal device does not access the first network slice through the access management network function, determine the identifier of the terminal device, the identifier of the access management network function, and the identifier of the first network slice One or more of the parameter information in is false.
  • the admission control network function checks whether the terminal device has established a session of the first network slice through the session management network function. If the terminal device establishes a session on the first network slice through the session management network function, it may be determined that one or more parameter information among the terminal device identifier, the session management network function identifier, and the identifier of the first network slice is true, and if the terminal device does not By establishing a session in the first network slice through the session management network function, it may be determined that one or more parameter information among the terminal device identifier, the session management network function identifier, and the identifier of the first network slice is false.
  • the admission control network function checks whether the terminal device is connected to the network through the access type. If the terminal device accesses the network through this access type, it can be determined that the terminal device identifier and/or access type is true; if the terminal device does not access the network through this access type, it can be determined that the terminal device identifier and/or access type false.
  • the access type may include access through a 3GPP network, and/or access through a non-3GPP network. Accessing through a non-3GPP network may include accessing through a local area network (such as wireless fidelity (Wi-Fi)), and/or accessing through a fixed network (such as a fiber-optic network (Fiber-Optic network)), and the like.
  • the admission control network function checks whether the registration or de-registration request indicated by the first indication information matches the stored registration status of the terminal device. If they match, it may be determined that the first indication information is true, and if they do not match, it may be determined that the first indication information is false. For example, the first indication information is used to request de-registration, but the actual registration state of the terminal device saved in the network is unregistered, at this time it can be considered that the de-registration request indicated by the first indication information does not match the saved registration state of the terminal device, The first indication information is false. However, the first indication information is used to request registration, but the actual registration status of the terminal device saved in the network is registered.
  • the terminal device Since the current standard allows the terminal device to re-register, the terminal device only occupies a quota of one quantity, and the number of admitted terminal devices The counter remains unchanged. Therefore, in this case, it can be considered that the registration request indicated by the first indication information matches the stored registration status of the terminal device, and the first indication information is true.
  • the first indication information is used to request de-registration, the actual registration status of the terminal device stored in the network is registered, and the first indication information is used to request registration, and the actual registration status of the terminal device stored in the network is unregistered, which can be It is considered that the registration or de-registration request indicated by the first indication information matches the saved registration state of the terminal device, and the first indication information is true.
  • the admission control network function checks whether the second indication information indicates whether the request for establishing a session or releasing a session matches the saved session state of the terminal device. If they match, it may be determined that the second indication information is true, and if they do not match, it may be determined that the second indication information is false. For example, the second indication information is used to request the release of the session, but the actual session state of the terminal device saved in the network is not created. At this time, it can be considered that the release session request indicated by the second indication information does not match the saved actual session state, and the second The indication is false. The second indication information is used to request the establishment of a session, but the actual session status saved in the network is created.
  • the session Since the current standard allows the establishment of multiple sessions, but multiple sessions correspond to the same session ID, the session only occupies a quota of one quantity. , the session counter remains unchanged, so in this case, it can be considered that the second indication information indicates that the session establishment request matches the saved session state, and the second indication information is true.
  • the second indication information is used to request the release of the session, the actual session state saved in the network is created, and the second indication information is used to request the establishment of the session, the actual session state saved in the network is not created, which can be regarded as the second indication The request for establishing a session or releasing a session indicated by the information matches the saved session state, and the second indication information is true.
  • the admission control network function checks whether the session identifier (or the session corresponding to the session identifier) exists. If the session identifier (or the session corresponding to the session identifier) exists, it can be determined that the session identifier is true; if the session identifier (or the session corresponding to the session identifier) does not exist, it can be determined that the session identifier is false.
  • the session ID can be PDU Session ID.
  • the admission control network function checks whether the session identifier (or the session corresponding to the session identifier) belongs to the terminal device. If the session identification (or session) belongs to the terminal equipment, it can be determined that the session identification and/or the terminal equipment identification is true, and if the session identification (or session) does not belong to the terminal equipment, it can be determined that the session identification and/or the terminal equipment identification are false .
  • the admission control network function checks whether the session identifier (or the session corresponding to the session identifier) belongs to the first network slice. If the session identifier or the session belongs to the first network slice, it may be determined that the session identifier and/or the identifier of the first network slice is true, and if the session identifier or the session does not belong to the first network slice, the session identifier and/or the first network slice may be determined flag is false.
  • the admission control network function checks whether the session corresponding to the session identifier is managed by the session management network function corresponding to the session management network function identifier. If the session corresponding to the session identifier belongs to the session management network function management corresponding to the session management network function identifier, it can be determined that the session identifier and/or the session management network function identifier is true; if the session corresponding to the session identifier does not belong to the session management network function identifier corresponding The session management network function management may determine that the session identification and/or the session management network function identification is false.
  • the admission control network function checks whether the state of the session is consistent with the current state of the session. If the state of the session is consistent with the current state of the session, it can be determined that the state of the session is true; if the state of the session is inconsistent with the current state of the session, it can be determined that the state of the session is false.
  • the admission control network function checks whether the first network slice matches the data network corresponding to the data network identifier. If the first network slice matches the data network corresponding to the data network identifier, it can be determined that the identifier of the first network slice and/or the data network identifier is true; if the first network slice does not match the data network corresponding to the data network identifier, it can be determined that The identifier of the first network slice and/or the data network identifier is false.
  • the data network identifier may be a data network name (data network name, DNN) and/or a data network access identifier (data network access identifier, DNAI).
  • the admission control network function may send a second message to the data management network function (such as UDM and/or UDR), and the second message is used to Requesting second parameter information, the second parameter information is used to verify the authenticity of the first parameter information; and receiving a third message, the third message includes verifying the second parameter information.
  • the admission control network function may not store real second parameter information.
  • the admission control network function may request other network functions to verify the authenticity of the first parameter information.
  • other network functions may be data management network functions (such as UDM and/or UDR)
  • the admission control network function may send a second message to the data management network function, and the second message is used to request to verify the first parameter information
  • the data management network function sends a third message to the admission control network function, the third message includes a verification result of the first parameter information, and the verification result includes whether the first parameter information is true or false.
  • the admission control network function may not store real second parameter information.
  • the data management network function verifies the first parameter information according to the acquired second parameter information of the terminal device or session.
  • the second message may include one or more of the following information: terminal device identifier, instruction information for verifying the subscription status of the terminal device, instruction information for verifying the access status of the terminal device, and the identifier of the first network slice , the slice identifier of the home network corresponding to the first network slice, the access management network function identifier, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, the access type of the terminal device, Session ID, data network ID, session management network function ID, session status.
  • the data management network function verifies the first parameter information according to the obtained second parameter information of the terminal device or session.
  • one or more of the following methods may be adopted:
  • the data management network function checks the subscription status of the terminal device according to the instruction information for checking the subscription status of the terminal device.
  • the subscription status of the terminal device may be the status of whether the terminal device has subscribed to the service of the network to which the first network slice belongs, or may be the status of whether the terminal device has subscribed to the service of the home network corresponding to the first network slice, or may be Whether the terminal device has subscribed to the service of the first network slice, or whether the terminal device has subscribed to the service of the network slice of the home network corresponding to the first network slice.
  • the data management network function checks whether the terminal device corresponding to the terminal device identifier has subscribed to the service of the network to which the first network slice belongs. If the terminal device corresponding to the terminal device identifier subscribes to the service of the network to which the first network slice belongs, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device corresponding to the terminal device identifier does not subscribe to the first network
  • the service of the network to which the slice belongs may determine that the terminal device identifier and/or the identifier of the first network slice is false.
  • the data management network function checks whether the terminal device has subscribed to the service of the first network slice. If the terminal device subscribes to the service of the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device does not subscribe to the service of the first network slice, it can be determined that the terminal device identifier and/or The flag of a network slice is false.
  • the data management network function checks whether the terminal device has subscribed to the service of the network slice in the home network corresponding to the first network slice. If the terminal device subscribes to the service of the network slice of the home network corresponding to the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device is not subscribed to correspond to the first network slice.
  • the service of the network slice of the home network may determine that the identifier of the terminal device and/or the identifier of the first network slice is false.
  • the data management network function checks the access status of the terminal equipment according to the instruction information for checking the access status of the terminal equipment.
  • the access status of the terminal device may be whether the terminal device has registered with the network to which the first network slice belongs, or whether the terminal device has accessed the first network slice.
  • the data management network function checks whether the terminal device has registered with the network to which the first network slice belongs. If the terminal device has registered the network to which the first network slice belongs, it may be determined that one or more parameter information among the terminal device identifier, the identifier of the first network slice, and the slice identifier of the home network corresponding to the first network slice is true, if the terminal The device has not registered the network to which the first network slice belongs, and may determine that one or more parameter information among the terminal device identifier, the identifier of the first network slice, and the slice identifier of the home network corresponding to the first network slice is false.
  • the data management network function checks whether the terminal device is connected to the first network slice. If the terminal device accesses the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true, and if the terminal device accesses the first network slice, it can be determined that the terminal device identifier and/or the first network slice Slice's id is false.
  • the data management network function checks whether the terminal device has registered with the network through the access management network function corresponding to the access management network function identifier. If the terminal device registers with the network through the access management network function corresponding to the access management network function identifier, it may be determined that the terminal device identifier and/or the access management network function identifier is true. If the terminal device has not registered with the network through the access management network function corresponding to the access management network function identifier, it may be determined that the terminal device identifier and/or the access management network function identifier are false.
  • the data management network function checks whether the terminal device has established a session through the session management network function corresponding to the session management network function identifier. If the terminal device establishes a session through the session management network function corresponding to the session management network function identifier, it may be determined that the terminal device identifier and/or the session management network function identifier is true. If the terminal device does not establish a session through the session management network function corresponding to the session management network function identifier, it may be determined that the terminal device identifier and/or the session management network function identifier are false.
  • the data management network function checks whether the terminal device has accessed the first network slice through the access management network function. If the terminal device accesses the first network slice through the access management network function, it may be determined that one or more parameter information among the terminal device identifier, the access management network function identifier, and the identifier of the first network slice is true, and if the terminal device does not Access the first network slice through the access management network function, or if the terminal device does not access the first network slice through the access management network function, determine the identifier of the terminal device, the identifier of the access management network function, and the identifier of the first network slice One or more of the parameter information in is false.
  • the data management network function checks whether the terminal device has established a session of the first network slice through the session management network function. If the terminal device establishes a session on the first network slice through the session management network function, it may be determined that one or more parameter information among the terminal device identifier, the session management network function identifier, and the identifier of the first network slice is true, and if the terminal device does not By establishing a session in the first network slice through the session management network function, it may be determined that one or more parameter information among the terminal device identifier, the session management network function identifier, and the identifier of the first network slice is false.
  • the data management network function checks whether the terminal device is connected to the network through the access type. If the terminal device accesses the network through this access type, it can be determined that the terminal device identifier and/or access type is true; if the terminal device does not access the network through this access type, it can be determined that the terminal device identifier and/or access type false.
  • the data management network function checks whether the registration or de-registration request indicated by the first indication information matches the stored registration status of the terminal device. If they match, it may be determined that the first indication information is true, and if they do not match, it may be determined that the first indication information is false.
  • the data management network function checks whether the request for establishing a session or releasing a session indicated by the second indication information matches the saved session state of the terminal device. If they match, it may be determined that the second indication information is true, and if they do not match, it may be determined that the second indication information is false.
  • the data management network function checks whether the session identifier (or the session corresponding to the session identifier) exists. If the session identifier exists, it can be determined that the session identifier is true, and if the session identifier does not exist, it can be determined that the session identifier is false.
  • the data management network function checks whether the session identifier (or the session corresponding to the session identifier) belongs to the terminal device. If the session ID (or the session corresponding to the session ID) belongs to the terminal device, it can be determined that the session ID and/or the terminal device ID is true; if the session ID (or the session corresponding to the session ID) does not belong to the terminal device, the session ID can be determined and/or end device identification is false.
  • the data management network function checks whether the session identifier (or the session corresponding to the session identifier) belongs to the first network slice. If the session identifier (or the session corresponding to the session identifier) belongs to the first network slice, it may be determined that the session identifier and/or the identifier of the first network slice is true; if the session identifier (or the session corresponding to the session identifier) does not belong to the first network slice , it may be determined that the session identifier and/or the identifier of the first network slice is false.
  • the data management network function checks whether the session corresponding to the session identifier is managed by the session management network function corresponding to the session management network function identifier. If the session corresponding to the session identifier belongs to the session management network function management corresponding to the session management network function identifier, it can be determined that the session identifier and/or the session management network function identifier is true; if the session corresponding to the session identifier does not belong to the session management network function identifier corresponding The session management network function management may determine that the session identification and/or the session management network function identification is false.
  • the data management network function checks whether the state of the session is consistent with the current state of the session. If the state of the session is consistent with the current state of the session, it can be determined that the state of the session is true, and if the state of the session is consistent with the current state of the session, it can be determined that the state of the session is false.
  • the data management network function checks whether the first network slice matches the data network corresponding to the data network identifier. If the first network slice matches the data network corresponding to the data network identifier, it can be determined that the identifier of the first network slice and/or the data network identifier is true; if the first network slice does not match the data network corresponding to the data network identifier, it can be determined that The identifier of the first network slice and/or the data network identifier is false.
  • the first parameter information includes one or more types of information, it may be determined that the first parameter information is true when any one type of information is true. If any information is false, it may be determined that the first parameter information is false.
  • S402 is executed to avoid increasing the processing burden of NF due to frequent verification of a large amount of first parameter information received at the same time or within a short period of time, affecting NF processing efficiency.
  • Satisfying the first condition includes one or more of the following: the duration of the timer reaches the first duration, the number of times the first message is received reaches the first threshold, the number of connected terminal devices or sessions reaches the first threshold, Indication information (such as third indication information) triggering verification is received.
  • a timer when triggered by time, can be preset in the admission control network function, and the timer can be triggered to verify the received first parameter information according to the set time interval, that is, the duration of the timer reaches the first duration .
  • a counter can be preset in the admission control network function to count the first message received, and check the first parameter information according to the set number of times interval, that is, the number of times the first message is received The first count threshold is reached.
  • the counter in the admission control network function counts the number of admitted terminal devices or sessions, and for every certain number of admitted terminal devices or sessions, the first parameter information A check is performed, that is, the number of connected terminal devices or sessions reaches a first number threshold.
  • the admission control network function receives indication information triggering verification from other NFs, it verifies the received first parameter information.
  • the other NF may be an NWDAF or an operation administration and management (OAM).
  • the value of the first duration is any positive number, which is not limited here.
  • the first number threshold can be any positive integer, which is not limited here.
  • the first number threshold may be any positive integer, and there is no limitation here.
  • the first number threshold and the second number threshold may be the same or different. It can be understood that the counter involved in this embodiment of the present application may be counting up or counting down, and the timer may be counting up or counting down.
  • the admission control network function updates the number of terminal devices or sessions in the first network slice.
  • the admission control network function performs processing according to insufficient quota of the first network slice.
  • the optional admission control network function can notify the OAM of abnormal events, etc.
  • the following uses the first parameter information to update the number of terminal devices in the first network slice as an example, referring to Figure 5, including the following steps:
  • S501 The AMF sends an ACU request to the NSACF.
  • the ACU request includes terminal equipment identification UE ID, identification S-NSSAI of the first network slice, first indication information flag and access type parameter information such as access type.
  • AMF and NSACF can interact based on a service based interface (service based interface, SBI).
  • the AMF can also include a token (token) in the ACU message for the NSACF to verify the identity of the AMF, and the token can also include the AMF ID.
  • token token
  • the identifier S-NSSAI of the first network slice may be the identifier of the first network slice of the home network of the terminal device, or may be the slice identifier of the network slice of the visited network of the terminal device.
  • the identifier of the first network slice may also include two identifiers of the first network slice, one is the slice identifier S-NSSAI of the visited network, and the other is the corresponding slice identifier of the home network, that is, Mapped S -NSSAI.
  • S502 The NSACF sends a verification request message to the UDM.
  • the NSACF and the UDM may first perform authentication and authorization through the NRF based on the SBI, and the NSACF and the UDM may interact in authentication and authorization.
  • the subscription verification request message is used to request the UDM to verify the authenticity of the first parameter information, and determine whether the first parameter information has parameter falsification.
  • the Subscription Verification Request message may include UE ID.
  • the subscription verification request message may also include one or more of the following: indication information for verifying the subscription state of the UE, indication information for verifying the access state of the UE, one or more S-NSSAI , AMF ID, etc.
  • “one or more S-NSSAIs” in this application may include one or more S-NSSAIs of visited networks, or one or more S-NSSAIs of home networks, or include one or more S-NSSAIs of visited networks S-NSSAI and one or more S-NSSAIs of the home network, or include one or more S-NSSAIs of the visited network and the corresponding Mapped S-NSSAI of the home network.
  • the AMF ID refers to the AMF that sends the ACU request message to the NSACF in step S501.
  • NSACF can obtain it from the token in the ACU request message. It should be noted that this application does not limit how the NSACF obtains the ID of the AMF.
  • the subscription verification request message may also include at least the UE ID.
  • the subscription verification request message may also include one or more S-NSSAIs.
  • the subscription verification request message may also include at least the UE ID.
  • the subscription verification request message may also include one or more of the following: one or more S-NSSAI, AMF ID, and UE access type.
  • the UDM may indicate the verification of one or both states by default, Or the UDM can be pre-specified or configured to perform the verification of one of the states by default.
  • the UDM may also determine the first parameter information to be verified according to the first parameter information included in the subscription verification request message.
  • the subscription verification request message includes the access type and the AMF ID, and the UDM determines that the access type and the status of the terminal access (from which AMF or network to access) need to be verified.
  • the UDM stores the subscription data of the UE but does not store the access state of the UE.
  • the UDM may request the UDR to verify the access state of the UE, and S503 is executed. It can be understood that the UDM may verify the subscription state and/or the access state of the UE, and the UDR may also verify the subscription state and/or the access state of the UE.
  • S503 the UDM sends an access state verification request message to the UDR.
  • the access state verification request message sent by the UDM can be used to obtain the access state in the UDR, and correspondingly, the access state verification result includes the access state stored in the UDR.
  • the access state verification request sent by the UDM may be used to request the UDR to verify the access state, and correspondingly, the access state verification result includes the verification result of the access state determined by the UDR.
  • the UDM can perform the following operations: if the UDM determines to verify the subscription status of the UE, the UDM can obtain the UE ID from the NSACF (such as in the message in step 502), and query the UE's subscription stored in the UDM. data.
  • the subscription data includes UEs that have signed contracts with the network.
  • UDM can determine whether the UE to be queried corresponding to the UE ID is a subscriber, that is, UDM can verify whether the UE ID is a real UE ID, that is, whether the UE ID belongs to A subscribed UE, or a legal UE.
  • the subscription data stored in the UDM may also include slice information subscribed by the UE, for example, the slice information subscribed by the UE may be included in the "Subscribed S-NSSAIs" information element (information element, IE) of the UDM.
  • the UDM will list the S-NSSAI list corresponding to the slice identifiers subscribed by the UE, including S-NSSAI-1 and S-NSSAI-2.
  • UDM can determine that S-NSSAI-1 has passed the verification (UE has subscribed to this slice), S-NSSAI- 3 The verification fails (the UE has not subscribed to the slice).
  • the UDM refers to the UDM in the home network of the UE.
  • the UDM When executing S503 and S504, the UDM does not necessarily store all the state information of the UE. In this case, the UDM can perform the following operations:
  • the UDM can determine the network to which the AMF belongs based on the AMF ID (that is, the PLMN ID to which it belongs), for example, the PLMN ID is PLMN-4.
  • the UDM can determine which PLMN network the S-NSSAI belongs to according to the slice identifier S-NSSAI subscribed by the UE. For example, the S-NSSAI-1 subscribed by the UE belongs to the PLMN-1, and the S-NSSAI-2 subscribed by the UE belongs to the PLMN-2.
  • UDM determines that PLMN-4 is different from PLMN-1 and PLMN-2 respectively, so it can be determined that the slice information signed by AMF and UE is inconsistent, and the verification fails.
  • the UE accesses the serving network before accessing the slice (the serving network refers to the visited network that the UE accesses when roaming, or the UE accesses the The AMF of the home network accessed during non-roaming) performs primary authentication and generates related keys, and the AMF ID will be stored in UDM or UDR. Therefore UDM can compare the stored AMF ID of the UE serving the UE (mainly authenticated by the AMF) with the AMF ID in the subscription verification request message. If they are consistent, the verification is passed, otherwise the verification is not passed.
  • the PLMN ID can also be verified by comparing the current (or primary authenticated) PLMN ID of the UE stored in the UDM with the PLMN ID corresponding to the AMF in the subscription verification request message. It should be noted that, if no relevant information is stored in the UDM, the UDM can be obtained through the UDR, that is, by executing S503, the access state verification request message is sent to the UDR. There are multiple IEs in the UDR that store PLMN ID information.
  • IE “UE Current PLMN” (“UE Current PLMN”) includes the current PLMN ID, and IE “UE Roaming status” (“UE Roaming status”) Including the PLMN ID of the service network to which the UE currently roams, and whether the network is the home network (home PLMN).
  • UE Current PLMN includes the current PLMN ID
  • UE Roaming status (“UE Roaming status”) Including the PLMN ID of the service network to which the UE currently roams, and whether the network is the home network (home PLMN).
  • This embodiment does not limit which IE in the UDR is used to acquire the current PLMN or AMF information.
  • UDR stores the current access type of the UE (3GPP access or non-3GPP access), if the subscription verification request message includes terminal The access type of the device indicates that the access type is required to be verified. UDM can verify the request message to the UDR access status through S503. If the access type stored in the UDR is consistent with the access type in the subscription verification request message, if they are consistent Then it is determined that the verification is passed, otherwise the verification is not passed.
  • UDR stores the current registration status of the UE, which can be used to verify whether the registration status indicated by the flag in the subscription verification request message is true or false. For example, UDR also saves the "registration state" IE ("UE registration state”) about UE access, which shows whether the current state of the UE is “registered” (“Registered”) or “deregistered” (“Deregistered”) ). When the UE is in the "de-registered" state, it means that the UE does not access any slice and does not occupy the admission quota of any slice.
  • the NSACF handles it according to the fact that the network slice does not have an admission quota, or notifies the network management function or the entity OAM, for example, notifies that there is an abnormal event.
  • S507 The NSACF sends an ACU response to the AMF.
  • all or part of the process of verifying parameter information can be implemented by NSACF, or by UDM, or by UDR.
  • the verification process of the parameter information is implemented by the NSACF
  • what the UDM sends to the NSACF in S505 is not the verification result but the second parameter information, which is used to verify the authenticity of the first parameter information.
  • the admission control network function may not store real second parameter information.
  • the verification process of the UE state information is implemented by the UDM
  • what the UDR sends to the UDM in S504 is not the verification result but the second parameter information, which is used to verify the state of the UE.
  • the AMF is used as an example to interact with the NSACF to control the number of UEs in a slice.
  • the same method is also applicable to the ACU process of interaction between SMF and NSACF, which is to control the number of PDUs in the slice.
  • the parameters of the relevant PDU session stored in UDM and UDR can be used for verification, that is, the first parameter information of the above verification needs to be replaced with the first parameter information of the relevant PDU session.
  • the UDM stores the PDU session, PDU session identifier (PDU Session ID), DN name (DNN), and SMF ID (such as SMF IP Address or SMF NF ID) that the UE has established.
  • PDU Session ID PDU session identifier
  • DNN DN name
  • SMF ID such as SMF IP Address or SMF NF ID
  • UDR stores the PDU session established by UE, UE IP address (UE IP Address), PDU session status (PDU Session status), DN access ID (DN access identifier, DNAI), etc., and similar verification can be performed. That is, as the first parameter information in step 502, one-by-one verification is performed, which will not be repeated here.
  • the admission control network function receives a first message, the first message includes first parameter information used to update the number of terminal devices or sessions in the first network slice, and the admission control network function performs the first parameter information Verify the authenticity of the first parameter information. If the first parameter information is true, the admission control network function can update the number of terminal devices or sessions in the first network slice. If the first parameter information is false, it means that the first parameter information For falsified wrong information, the admission control network function does not update the number of terminals or sessions in the first network slice.
  • verifying the authenticity of the received first parameter it is possible to reduce the error update of the slice configuration caused by false messages, ensure that the terminal device can normally access the network slice or establish a PDU session normally, and improve the service provided by the network slice. stability and improve network security.
  • the basic process of executing the early admission control (EAC) mode first is described below.
  • the EAC mode is used to indicate the point in time to execute the ACU procedure.
  • the EAC mode When the EAC mode is activated (active), before the AMF authorizes the UE to access the network slice, it must first execute the ACU process, so as to confirm that the quota of the network slice is not full and allow the UE to access.
  • the EAC mode is not activated (inactive)
  • the AMF can execute the ACU process after authorizing the UE to access the network slice.
  • the network slice has sufficient quota and is not in a hurry to update the terminal devices or sessions accessed by the network slice.
  • other processes of the UE can be executed preferentially. In conjunction with Figure 6, the following steps are included:
  • S601 The NSACF triggers an EAC configuration update process.
  • the NSACF triggers an EAC configuration update process.
  • the NSACF sends an EAC mode update message to the AMF, where the EAC mode update message is used to activate or deactivate the EAC mode of the network slice.
  • the NSACF deactivates the EAC mode of the network slice, and does not need to initiate the ACU process before authorizing the UE.
  • the preset number threshold such as higher than 75% of the quota
  • NSACF activates the EAC mode of the network slice, and needs to initiate the ACU process before authorizing the UE, so as to ensure that the network The slice has enough quota to access the UE.
  • the AMF can also initiate the ACU procedure before or after authorizing the UE according to the configuration.
  • NSACFx indicates that the NF that has been maliciously attacked may be controlled by an insider, thus sending false messages, which may tamper with the EAC mode, such as setting the EAC flag to deactived or inactive, making the above risks more likely to occur.
  • the embodiment of the present application provides another communication method.
  • this method when the previously executed admission control mode is in an inactive state, if the number of terminal devices requesting access to the first network slice reaches a second threshold, the access management network function sends the first A message, used to update the number of terminal devices in the first network slice, so as to reduce the risk of authorizing too many terminal devices to access the network slice when the admission control mode is not activated first, and improve the service provided by the network slice stability.
  • Figure 8 is a possible communication method, including the following steps:
  • the access management network function determines the number of terminal devices requesting to access the first network slice.
  • the AMF is preset with a counter, which can update the count value of the counter when receiving a terminal device request to access the first network slice after initiating the ACU process, such as adding a set value to the count value, and the set value is arbitrary An integer, which is not limited in this embodiment of the application, for example, the set value may be 1.
  • the admission control network function receives the first message.
  • a second number threshold may be set in the terminal device, and the second number threshold may be any integer, which is not limited in this embodiment of the present application.
  • the first number threshold and the second number threshold may be the same, or may be different.
  • the second quantity threshold may be a value preset in the system, or may be a value updated by first performing an admission control configuration update process, or may be a value determined by an access management network function. If the second number threshold is obtained by performing the update of the admission control configuration update process first, the admission control network function may increase the second number threshold in the first-execution admission control mode update message when sending the first-execution admission control mode update message instructions for the .
  • the access management network function may determine the second quantity threshold according to the remaining admission quota of the network slice and/or the quantity of the access management network function. Certainly, other manners of determining the second quantity threshold are not limited in this embodiment of the present application.
  • the second quantity threshold may be an upper limit of the maximum number of terminal devices admitted to the access management network function between two ACU procedures. If the number of terminal devices requesting to access the first network slice reaches the second number threshold, the ACU process needs to be executed first, and the first message is sent to the admission control network function. The first message includes updating the number of terminal devices in the first network slice, or rejecting a terminal device requesting to access the first network slice. It can be understood that an additional condition for triggering the ACU process is added to the access management network function when the admission control mode is inactive.
  • the admission control network function may also send a fourth message, and the access management network function receives the fourth message.
  • the fourth message is verified; if the verification is passed, the access management network function determines that the access control mode is first executed as an inactive state.
  • the access management network function can determine that there is no malicious modification in the first execution of the admission control mode; when the verification of the fourth message fails, the access management network function can determine that the There are malicious modifications in the execution access control mode, and the risk of attack is identified.
  • the fourth message may include but not limited to one or more of the following: an admission control network function identifier, an identifier of an operator network where the admission control network function is located, and an identifier of the first network slice.
  • the access management network function may check the admission control network function identifier (NSACF ID), the identifier of the operator network where the admission control network function is located (PLMN ID), the first One or more of the identifiers of a network slice (S-NSSAI) are verified.
  • NSACF ID admission control network function identifier
  • PLMN ID the identifier of the operator network where the admission control network function is located
  • S-NSSAI the first One or more of the identifiers of a network slice
  • the above identifier in the fourth message is usually included in the Token, such as included in the claim item (Claim) of the Token.
  • the information in the Token is integrity-protected information. If an attacker tampers with the information, the verification will fail.
  • the S-NSSAI in the fourth message can be the S-NSSAI of the serving network (ie, the visited network) PLMN, or the mapped network slice identifier (mapped S -NSSAI), that is, the S-NSSAI in the home network.
  • PLMN ID that is, the ID of the visited network
  • mapped S-NSSAI the S-NSSAI of the home network
  • S-NSSAI mapped S-NSSAI
  • the process of verifying the fourth message may be performed after S602, and if the verification is passed, then S603 is performed.
  • the access management network function when the previously executed admission control mode is in an inactive state, if the number of terminal devices requesting access to the first network slice reaches a second threshold, the access management network function sends the first A message, used to update the number of terminal devices in the first network slice, so as to reduce the risk of authorizing too many terminal devices to access the network slice when the admission control mode is not activated first, and improve the service provided by the network slice stability and improve network security.
  • FIG. 7 and FIG. 8 are also applicable to the control of the number of sessions, where the access control network function AMF needs to be replaced by the session management function SMF.
  • the information in the corresponding token can be correspondingly added or replaced with the information of the relevant session, which will not be repeated here.
  • various embodiments of the present application may also be applicable to the information verification scenario when interacting with other NFs based on the SBI, and other NFs and information to be verified may be different from the NF and first parameter information in the above-mentioned embodiments , the verification process is similar and will not be repeated here.
  • the embodiment of the present application also provides a communication device. As shown in FIG. method described in .
  • the apparatus 900 may be applied to, or located in, an admission control network function, a data management network function, or an access management network function.
  • the functions implemented by the optional transceiver unit 902 can be completed by the communication interface.
  • the transceiver unit 902 is configured to receive a first message, where the first message includes a first message for updating the number of terminal devices or sessions in the first network slice.
  • the processing unit 901 is configured to verify the authenticity of the first parameter information; if the first parameter information is true, update the number of terminal devices or sessions in the first network slice.
  • the first parameter information includes one or more of the following information: a terminal device identifier, an identifier of a first network slice, an access management network function identifier, first indication information requesting registration or de-registration, and first indication information requesting session establishment or release session 2. Indication information, access type of terminal equipment, session identifier, data network identifier, session management network function identifier, and session status.
  • the processing unit 901 is specifically configured to verify the authenticity of the first parameter information in one or more of the following ways: verify whether the terminal device corresponding to the terminal device identifier has subscribed to the first network slice to which the first network slice belongs.
  • the processing unit 901 is specifically configured to use the transceiver unit 902 to send a second message to the data management network function, and the second message is used to request that the first parameter information be verified; to receive the third message, the first The third message includes the verification result of the first parameter information.
  • the second message includes one or more of the following information: terminal device identifier, indication information for verifying the subscription state of the terminal device, indication information for verifying the access state of the terminal device, A network slice identifier, the slice identifier of the home network corresponding to the first network slice, the access management network function identifier, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, terminal device access type, session identifier, data network identifier, session management network function identifier, and session status.
  • the processing unit 901 is further configured to determine that the first condition is met.
  • Satisfying the first condition includes one or more of the following: the duration of the timer reaches the first duration, the number of times the first message is received reaches the first threshold, the number of connected terminal devices or sessions reaches the first threshold, An indication message was received to trigger the verification.
  • the first message is sent when the admission control mode performed first is in an inactive state and the number of terminal devices requesting to access the first network slice reaches a second number threshold.
  • the transceiver unit 902 when the device 900 is a data management network function, the transceiver unit 902 is configured to receive a second message, the second message is used to request verification of the first parameter information, and the first parameter information is used to Update the number of terminal devices or sessions in the first network slice; the processing unit 901 is configured to verify the first parameter information according to the acquired second parameter information of the terminal device or session; the transceiver unit 902 is configured to send The admission control network function sends a third message, where the third message includes a verification result of the first parameter information, and the verification result includes whether the first parameter information is true or false.
  • the second message includes one or more of the following information: terminal device identifier, indication information for verifying the subscription state of the terminal device, indication information for verifying the access state of the terminal device, A network slice identifier, the slice identifier of the home network corresponding to the first network slice, the access management network function identifier, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, terminal device access type, session identifier, data network identifier, session management network function identifier, and session status.
  • the processing unit 901 is specifically configured to verify the first parameter information according to the acquired second parameter information of the terminal device or session in one or more of the following ways: Instructions for verifying the status of the terminal device, verifying the subscription status of the terminal device; verifying whether the terminal device corresponding to the terminal device identifier has signed up for the service of the network to which the first network slice belongs or has signed up for the service corresponding to the first network slice.
  • the service of the network of the home network verify whether the terminal device has subscribed to the service of the first network slice or the service of the network slice of the home network corresponding to the first network slice; check according to the access status of the terminal device Check the access status of the terminal device; check whether the terminal device is registered with the network to which the first network slice belongs; check whether the terminal device has access to the first network slice; check whether the terminal device has passed the access
  • the access management network function corresponding to the access management network function identifier has registered with the network; verify whether the terminal device has accessed the first network slice through the access management network function; verify whether
  • the processing unit 901 is configured to determine the identity of the terminal device requesting to access the first network slice when the admission control mode previously executed is in an inactive state. Quantity; the transceiver unit 902 is configured to send a first message to the admission control network function if the number of terminal devices requesting access to the first network slice reaches a second quantity threshold, and the first message includes information for updating the first network slice. the number of terminal devices.
  • the transceiving unit 902 is further configured to receive a fourth message sent by the admission control network function, where the fourth message is used to modify the pre-executed admission control mode to an inactive state.
  • the processing unit 901 is further configured to verify the fourth message, and if the verification is passed, determine that the admission control mode executed first is in an inactive state.
  • the processing unit 901 is specifically configured to verify one or more of the admission control network function identifier, the identifier of the operator network where the admission control network function is located, and the identifier of the first network slice .
  • each functional unit in each embodiment of the present application It can be integrated in one processing unit, or physically exist separately, or two or more units can be integrated in one unit.
  • the above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
  • the transceiving unit may include a receiving unit and/or a transmitting unit.
  • the integrated unit can be stored in a computer-readable storage medium. Based on this understanding, the integrated unit can be stored in a storage medium as a computer software product, including several instructions to make a computer device (it can be a personal computer, a server, or a network device, etc.) or a processor (processor) Execute all or part of the steps of the methods in the various embodiments of the present application.
  • the embodiment of the present application also provides a schematic structural diagram of a communication device 1000 .
  • the apparatus 1000 may be used to implement the methods described in the foregoing method embodiments, and reference may be made to the descriptions in the foregoing method embodiments.
  • the Apparatus 1000 includes one or more processors 1001 .
  • the processor 1001 may be a general purpose processor or a special purpose processor or the like.
  • it may be a baseband processor or a central processing unit.
  • the baseband processor can be used to process communication protocols and communication data
  • the central processing unit can be used to control communication devices (such as base stations, terminals, or chips, etc.), execute software programs, and process data of software programs.
  • the communication device may include a transceiver unit for inputting (receiving) and outputting (sending) signals.
  • the transceiver unit may be a transceiver, a radio frequency chip, and the like.
  • the device 1000 includes one or more processors 1001, and the one or more processors 1001 can implement the methods in the above-mentioned embodiments.
  • processor 1001 may also implement other functions in addition to implementing the methods in the above-mentioned embodiments.
  • the processor 1001 may execute instructions, so that the apparatus 1000 executes the methods described in the foregoing method embodiments.
  • the instruction can be stored in whole or in part in the processor 1001, such as the instruction 1003 can be stored in whole or in part in the processor 1001, or the instruction 1003 is stored in the processor 1001, and the instruction 1004 is stored in the memory 1002 coupled with the processor,
  • the processor 1001 may execute the instruction 1003 and the instruction 1004 synchronously so that the apparatus 1000 executes the methods described in the foregoing method embodiments.
  • the instructions 1003 and 1004 are also referred to as computer programs.
  • the communication device 1000 may further include a circuit, and the circuit may implement the functions in the foregoing method embodiments.
  • the device 1000 may include one or more memories 1002, on which instructions 1004 are stored, and the instructions may be executed on the processor 1001, so that the device 1000 executes the methods described in the above method embodiments.
  • data may also be stored in the memory.
  • Optional processor 1001 may also store instructions and/or data therein.
  • one or more memories 1002 may store the correspondence described in the above embodiments, or related parameters or tables involved in the above embodiments, and the like. Processor and memory can be set separately or integrated together.
  • the apparatus 1000 may further include a transceiver 1005 and an antenna 1006 .
  • the processor 1001 may be referred to as a processing unit, and controls the device (terminal or base station).
  • the transceiver 1005 may be called a transceiver, a transceiver circuit, or a transceiver unit, etc., and is used to realize the transceiver function of the device through the antenna 1006 .
  • the processor can be a general-purpose central processing unit (central processing unit, CPU), a microprocessor, a specific application integrated circuit (application-specific integrated circuit, ASIC), one or more integrated circuits used to control the execution of the program program of this application , general-purpose processor, digital signal processor (digital signal processor, DSP), off-the-shelf programmable gate array (field programmable gate array, FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
  • DSP digital signal processor
  • FPGA field programmable gate array
  • a general-purpose processor may be a microprocessor, or the processor may be any conventional processor, or the like.
  • the steps of the method disclosed in connection with the embodiments of the present application may be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor.
  • a software module may be stored on a storage medium located in a memory.
  • Memory can be volatile memory or nonvolatile memory, or can include both volatile and nonvolatile memory.
  • the non-volatile memory can be read-only memory (Read-Only Memory, ROM), programmable read-only memory (Programmable ROM, PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electronically programmable Erase Programmable Read-Only Memory (Electrically EPROM, EEPROM) or Flash.
  • the volatile memory can be Random Access Memory (RAM), which acts as external cache memory.
  • RAM Static Random Access Memory
  • SRAM Static Random Access Memory
  • DRAM Dynamic Random Access Memory
  • Synchronous Dynamic Random Access Memory Synchronous Dynamic Random Access Memory
  • SDRAM double data rate synchronous dynamic random access memory
  • Double Data Rate SDRAM, DDR SDRAM enhanced synchronous dynamic random access memory
  • Enhanced SDRAM, ESDRAM synchronous connection dynamic random access memory
  • Synchlink DRAM, SLDRAM Direct Memory Bus Random Access Memory
  • Direct Rambus RAM Direct Rambus RAM
  • the embodiment of the present application also provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a computer, the communication method in any one of the above method embodiments is implemented.
  • An embodiment of the present application further provides a computer program product, including a computer program, and when the computer program is executed by a computer, the communication method in any one of the above method embodiments is implemented.
  • the embodiment of the present application also provides a communication system, including an admission control network function, and may also include an access management network function and/or a session management network function.
  • the communication system may also include a data management network function.
  • Each network function may implement any of the foregoing method embodiments.
  • all or part of them may be implemented by software, hardware, firmware or any combination thereof.
  • software When implemented using software, it may be implemented in whole or in part in the form of a computer program product.
  • a computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on the computer, the processes or functions according to the embodiments of the present application are generated in whole or in part.
  • the computer may be the communication device described above.
  • Computer instructions may be stored in, or transmitted from, one computer-readable storage medium to another computer-readable storage medium.
  • the computer-readable storage medium may be the above-mentioned storage medium or the above-mentioned memory.
  • the determination unit or processor 1001 may be one or more logic circuits, and the sending unit
  • the receiving unit or the transceiver 1005 may be an input-output interface, or called a communication interface, or an interface circuit, or an interface, or the like.
  • the transceiver 1005 may also be a sending unit and a receiving unit, the sending unit may be an output interface, and the receiving unit may be an input interface, and the sending unit and the receiving unit are integrated into one unit, such as an input and output interface.
  • the logic circuit 1101 includes a logic circuit 1101 and an interface circuit 1102 . That is, the above-mentioned determination unit or processor 1001 may be realized by a logic circuit 1101 , and the sending unit or receiving unit or transceiver 1005 may be realized by an interface circuit 1102 .
  • the logic circuit 1101 may be a chip, a processing circuit, an integrated circuit or a system on chip (SoC) chip, etc.
  • the interface circuit 1102 may be a communication interface, an input-output interface, or the like.
  • the logic circuit and the interface circuit may also be coupled to each other. The embodiment of the present application does not limit the specific connection manner of the logic circuit and the interface circuit.
  • the logic circuit 1101 and the interface circuit 1102 may be used to perform functions or operations performed by the above-mentioned terminal device or the policy control network function or the access management network function.
  • the interface circuit may be used to receive signals from other communication devices than the communication device and transmit to or transmit signals from the logic circuit to other communication devices than the communication device.
  • the logic circuit can be used to implement any of the above method embodiments by executing code instructions.
  • the interface circuit 1102 may be used to receive signals from other communication devices other than the communication device 1100 and transmit them to the logic circuit 1101 or send signals from the logic circuit 1101 to other communication devices other than the communication device 1100 .
  • the logic circuit 1101 may be used to implement any of the foregoing method embodiments by executing code instructions.
  • the interface circuit 1102 is configured to receive a first message, where the first message includes first parameter information for updating the number of terminal devices or sessions in the first network slice.
  • the logic circuit 1101 is configured to verify the authenticity of the first parameter information, and if the first parameter information is true, update the number of terminal devices or sessions in the first network slice.
  • the disclosed systems, devices and methods may be implemented in other ways.
  • the device embodiments described above are only illustrative.
  • the division of units is only a logical function division. In actual implementation, there may be other division methods.
  • multiple units or components can be combined or integrated. to another system, or some features may be ignored, or not implemented.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices or units, and may also be electrical, mechanical or other forms of connection.
  • a unit described as a separate component may or may not be physically separated, and a component displayed as a unit may or may not be a physical unit, that is, it may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiment of the present application.
  • each functional unit in each embodiment of the present application may be integrated into one processing unit, each unit may exist separately physically, or two or more units may be integrated into one unit.
  • the above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
  • Computer-readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another.
  • a storage media may be any available media that can be accessed by a computer.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Databases & Information Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请涉及一种通信方法及装置,该方法包括:准入控制网络功能接收第一消息,第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息;准入控制网络功能对第一参数信息的真实性进行校验;若第一参数信息为真,准入控制网络功能对第一网络切片内的终端设备或会话的数量进行更新。第一参数信息为真时,可以对第一网络切片内的终端设备或会话的数量进行更新,第一参数信息为假时,表示第一参数信息为伪造的错误的信息,不对第一网络切片内的终端设备或会话的数量进行更新。通过该方案,可以降低因虚假消息造成的网络切片配置的错误更新,提高网络切片提供服务的稳定性。

Description

一种通信方法及装置
相关申请的交叉引用
本申请要求在2021年08月06日提交中国国家知识产权局、申请号为202110904039.6、申请名称为“一种通信方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及无线通信技术领域,尤其涉及一种通信方法及装置。
背景技术
接入与移动性管理功能(access and mobility management function,AMF)可以向网络切片准入控制功能(Network Slice Admission Control Function,NSACF)发送可用性查询及终端数量更新(availability check and update,ACU)请求,NSACF根据ACU请求,对标识为单网络切片选择辅助信息(single network slice selection assistance information,S-NSSAI)的网络切片中注册的终端设备数量进行更新。在该网络切片中的终端数量的准入配额已满时,NSACF向AMF进行相应的通知,AMF可以因此拒绝终端设备的接入请求。
或者会话管理功能(session management function,SMF)可以向NSACF发送ACU请求,NSACF根据ACU请求,对标识为S-NSSAI的网络切片中建立的协议数据单元(protocol data unit,PDU)会话数量进行更新。在该网络切片中PDU会话数量的准入配额已满时,NSACF向SMF进行相应的通知,SMF可以因此拒绝终端设备的建立会话请求。
但是在网络中在某个NF被攻击后,该NF可能向NSACF发送虚假ACU请求,造成NSACF错误更新网络切片中已经注册的终端设备或已经建立的PDU会话的数量,导致其他终端设备无法正常接入或终端设备无法正常建立新的PDU会话,网络切片服务降级或者无法正常提供服务。
发明内容
本申请提供一种通信方法及装置,用以降低因虚假消息造成的网络切片配置的错误更新,提高网络切片提供服务的稳定性。
第一方面,提供一种通信方法,包括如下过程:准入控制网络功能接收第一消息,第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息;准入控制网络功能对第一参数信息的真实性进行校验,若第一参数信息为真,对第一网络切片内的终端设备或会话的数量进行更新。
其中第一参数信息可以包括以下一种或多种信息:终端设备标识、第一网络切片的标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
示例的,如果第一参数信息用于更新第一网络切片内的终端设备的数量,第一参数信息可以包括以下一种或多种信息:终端设备标识、第一网络切片的标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、终端设备的接入类型。
又一示例的,如果第一参数信息用于更新第一网络切片内的会话的数量,第一参数信息可以包括以下一种或多种信息:终端设备标识、第一网络切片的标识、请求建立会话或释放会话的第二指示信息、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
准入控制网络功能可以为NSACF。
准入控制网络功能在对第一参数信息的真实性进行校验时,准入控制网络功能可以自身对第一参数信息的真实性进行校验,或者准入控制网络功能可以请求其它网络功能对第一参数信息的真实性进行校验。
在该方法中,准入控制网络功能接收到第一参数信息,第一参数信息用于更新第一网络切片内的终端设备或会话的数量,准入控制网络功能可以对第一参数信息的真伪进行校验,第一参数信息为真时,可以对第一网络切片内的终端设备或会话的数量进行更新,第一参数信息为假时,表示第一参数信息为伪造的错误的信息,不对第一网络切片内的终端设备或会话的数量进行更新,从而可以降低因虚假消息造成的网络切片配置的错误更新,保证终端设备可以正常接入网络切片或可以正常建立PDU会话,并且提高网络切片提供服务的稳定性。
在一种可能的实现中,准入控制网络功能对第一参数信息的真实性进行校验时,可以采用以下方式中的一种或多种:
准入控制网络功能校验终端设备标识对应的终端设备是否签约了第一网络切片所属的网络的服务或者签约了与第一网络切片相对应的归属网络的服务;
准入控制网络功能校验终端设备是否签约了第一网络切片的服务或者签约了与第一网络切片相对应的归属网络的网络切片的服务;
准入控制网络功能校验终端设备是否注册了第一网络切片所属的网络;
准入控制网络功能校验终端设备是否接入了第一网络切片;
准入控制网络功能校验终端设备是否通过接入管理网络功能标识对应的接入管理网络功能注册了网络;
准入控制网络功能校验终端设备是否通过接入管理网络功能接入了第一网络切片;
准入控制网络功能校验终端设备是否通过接入类型接入了网络;
准入控制网络功能校验第一指示信息指示的注册或去注册的请求是否与保存的终端设备的注册状态匹配;
准入控制网络功能校验第二指示信息指示的建立会话或释放会话的请求是否与保存的终端设备的会话状态匹配;
准入控制网络功能校验会话标识或该会话标识对应的会话是否存在;
准入控制网络功能校验会话标识或该会话标识对应的会话是否属于终端设备;
准入控制网络功能校验会话标识或该会话标识对应的会话是否属于第一网络切片;
准入控制网络功能校验会话标识对应的会话是否属于会话管理网络功能标识对应的会话管理网络功能管理;
准入控制网络功能校验会话的状态是否与会话当前的状态一致;
准入控制网络功能校验第一网络切片是否匹配数据网络标识对应的数据网络。
在该实现中,准入控制网络功能可以自身对第一参数信息的真实性进行校验。用于对第一参数信息的真实性进行校验的第二参数信息,可以预先保存在准入控制网络功能中,或者可以是准入控制网络功能从其他网络功能中获取到。
在一种可能的实现中,准入控制网络功能对第一参数信息的真实性进行校验之前,可以向数据管理网络功能发送第五消息,第五消息用于请求第二参数信息,该第二参数信息用于对第一参数信息的真实性进行校验;以及接收来自数据管理网络功能的第六消息,第六消息包括第二参数信息。这样,准入控制网络功能对第一参数信息的真实性进行校验时,可以根据第六消息中的第二参数信息,对第一参数信息的真实性进行校验。在该实现中,准入控制网络功能可以未保存有真实的第二参数信息。
在一种可能的实现中,准入控制网络功能对第一参数信息的真实性进行校验时,可以向数据管理网络功能发送第二消息,第二消息用于请求对第一参数信息进行校验;以及接收第三消息,第三消息包括第一参数信息的校验结果,该验证结果用于指示第一参数信息为真或假。在该实现中,准入控制网络功能可以请求其它网络功能(如数据管理网络功能)对第一参数信息的真实性进行校验。
在一种可能的实现中,第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、第一网络切片的标识、第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
在一种可能的实现中,准入控制网络功能对第一参数信息的真实性进行校验之前,还可以确定满足第一条件。其中满足第一条件包括以下一种或多种:计时器的时长达到第一时长、接收到第一消息的次数达到第一次数阈值、接入的终端设备或会话的数量达到第一数量阈值、接收到触发校验的指示信息。在该实现中,通过设置具体的第一条件,在满足第一条件时确定触发校验,这样可以避免对同时或在短时间内接收到的大量第一参数信息进行校验,增加准入控制网络功能的处理负担,降低准入控制网络功能的处理效率。
在一种可能的实现中,第一消息为先执行准入控制模式为未激活状态,且请求接入第一网络切片的终端设备的数量达到第二数量阈值时发送。先执行准入控制模式为未激活状态时,接入管理网络功能可以先授权终端设备接入第一网络切片,然后再执行ACU流程。在该实现中,通过设置第二数量阈值,可以避免接入管理网络功能同时或在短时间内授权大量的终端设备接入,导致的终端设备的数量超过第一网络切片的配置的风险,从而进一步提高网络切片提供服务的稳定性。
第二方面,提供一种通信方法,包括如下过程:数据管理网络功能接收第二消息,第二消息用于请求对第一参数信息进行校验,第一参数信息用于更新第一网络切片内的终端设备或会话的数量。数据管理网络功能可以根据获取到的终端设备或会话的第二参数信息,对第一参数信息进行校验。数据管理网络功能向准入控制网络功能发送第三消息,第三消息包括第一参数信息的校验结果,校验结果包括第一参数信息为真或假。
数据管理网络功能可以为统一数据管理(UDM)和/或统一数据存储(UDR)。
在该方法中,数据管理网络功能可以对准入控制网络功能接收到第一参数信息的真实性进行校验,从而可以降低因虚假消息造成的网络切片配置的错误更新,提高网络切片提 供服务的稳定性。
在一种可能的实现中,第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、第一网络切片的标识、第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识,会话的状态。
在一种可能的实现中,数据管理网络功能根据获取到的终端设备或会话的第二参数信息,对第一参数信息进行校验,可以采用以下方式中一种或多种:
数据管理网络功能根据对终端设备的签约状态进行校验的指示信息,对终端设备的签约状态进行校验;
数据管理网络功能校验终端设备标识对应的终端设备是否签约了第一网络切片所属的网络的服务或者签约了与第一网络切片相对应的归属网络的网络的服务;
数据管理网络功能校验终端设备是否签约了第一网络切片的服务或者签约了与第一网络切片相对应的归属网络的网络切片的服务;
数据管理网络功能根据对终端设备的接入状态进行校验的指示信息,对终端设备的接入状态进行校验;
数据管理网络功能校验终端设备是否注册了第一网络切片所属的网络;
数据管理网络功能校验终端设备是否接入了第一网络切片;
数据管理网络功能校验终端设备是否通过接入管理网络功能标识对应的接入管理网络功能注册了网络;
数据管理网络功能校验终端设备是否通过接入管理网络功能接入了第一网络切片;
数据管理网络功能校验终端设备是否通过接入类型接入了网络;
数据管理网络功能校验第一指示信息指示的注册或去注册的请求是否与保存的终端设备的注册状态匹配;
数据管理网络功能校验第二指示信息指示的建立会话或释放会话的请求是否与保存的终端设备的会话状态匹配;
数据管理网络功能校验会话标识或会话标识对应的会话是否存在;
数据管理网络功能校验会话标识或会话标识对应的会话是否属于终端设备;
数据管理网络功能校验会话标识或会话标识对应的会话是否属于第一网络切片;
数据管理网络功能校验会话标识对应的会话是否属于会话管理网络功能标识对应的会话管理网络功能管理;
数据管理网络功能校验会话的状态是否与会话当前的状态一致;
数据管理网络功能校验第一网络切片是否匹配数据网络标识对应的数据网络。
第三方面,提供一种通信方法,包括如下过程:在先执行准入控制模式为未激活状态时,接入管理网络功能确定请求接入第一网络切片的终端设备的数量。如果请求接入第一网络切片的终端设备的数量达到第二数量阈值,接入管理网络功能向准入控制网络功能发送第一消息,第一消息包括用于更新第一网络切片内的终端设备的数量。
先执行准入控制模式为未激活状态时,接入管理网络功能可以先授权终端设备接入第一网络切片,然后再执行ACU流程,但是可能存在同时或在短时间内授权大量的终端设备接入的风险,导致接入的终端设备的数量超过第一网络切片的配置,因此通过设置第二 数量阈值,可以保证接入的终端设备的数量在第一网络切片可以稳定提供服务的数量范围内,提高网络切片提供服务的稳定性。
其中接入管理网络功能可以为AMF。
在一种可能的实现中,接入管理网络功能还可以接收准入控制网络功能发送的第四消息,第四消息用于将先执行准入控制模式修改为未激活状态。接入管理网络功能可以对第四消息进行校验,若校验通过,接入管理网络功能确定先执行准入控制模式为未激活状态。
在该实现中,接入管理网络功能可以对第四消息的真伪进行校验,当第四消息为真时,可以对先执行准入控制模式修改为未激活状态,当第四消息为假时,表示第四消息为伪造的错误的消息,不对先执行准入控制模式进行修改,从而可以降低先执行准入控制模式被恶意篡改的风险,进一步提高网络切片提供服务的稳定性。
在一种可能的实现中,第四消息可以包括以下一种或多种信息:准入控制网络功能标识、准入控制网络功能所在运营商网络的标识、第一网络切片的标识。
接入管理网络功能对第四消息进行校验时,可以对准入控制网络功能标识、准入控制网络功能所在运营商网络的标识、第一网络切片的标识中的一种或多种,进行校验。
第四方面,提供一种通信装置,该通信装置可以为上述准入控制网络功能或数据管理网络功能或接入管理网络功能,或者为设置在准入控制网络功能或数据管理网络功能或接入管理网络功能或会话管理网络功能中的芯片。该通信装置可以实现上述第一方面或第二方面或第三方面中的任一项设计所提供的方法。
通信装置包括实现上述方法相应的模块、单元、或手段(means),该模块、单元、或means可以通过硬件实现,软件实现,或者通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块或单元。
第五方面,提供一种通信装置,包括收发单元。可选的,该通信装置还包括处理单元。该通信装置可以实现第一方面或第二方面或第三方面中的任一项设计所提供的方法。
第六方面,提供一种通信装置,包括处理器。该处理器可用于执行上述第一方面或第二方面或第三方面中的任一项设计所提供的方法。可选地,该装置还包括存储器,该处理器与存储器耦合,存储器中用于存储计算机程序或指令,处理器可以执行存储器中的程序或指令,以使得该装置可以执行上述第一方面或第二方面或第三方面中的任一项设计所提供的方法。
第七方面,提供一种通信装置,该装置包括接口电路和逻辑电路,逻辑电路与接口电路耦合。该接口电路可以为代码/数据读写接口电路,或通信接口,该接口电路用于接收计算机执行指令(计算机执行指令存储在存储器中,可能直接从存储器读取,或可能经过其他器件)并传输至该逻辑电路,以使该逻辑电路运行计算机执行指令以执行上述第一方面或第二方面或第三方面中的任一项设计所提供的方法。
在一些可能的设计中,该通信装置可以为芯片或芯片系统。
第八方面,提供一种通信装置,包括处理器和存储器。该处理器用于读取存储器中存储的指令,并可通过接收器接收信号,通过发射器发射信号,以执行上述第一方面或第二方面或第三方面中的任一项设计所提供的方法。
可选地,该处理器可以为一个或多个,该存储器也可以为一个或多个。可选地,该存储器可以与该处理器集成在一起,或者该存储器与处理器分离设置。
在具体实现过程中,存储器可以为非瞬时性(non-transitory)存储器,例如只读存储器(read only memory,ROM),其可以与处理器集成在同一块芯片上,也可以分别设置在不同的芯片上,本申请对存储器的类型以及存储器与处理器的设置方式不做限定。
该通信装置可以是一个芯片,该处理器可以通过硬件来实现也可以通过软件来实现,当通过硬件实现时,该处理器可以是逻辑电路、集成电路等;当通过软件来实现时,该处理器可以是一个通用处理器,通过读取存储器中存储的软件代码来实现,该存储器可以集成在处理器中,可以位于该处理器之外,独立存在。
第九方面,提供一种处理器,包括:输入电路、输出电路和处理电路。该处理电路用于通过该输入电路接收信号,并通过该输出电路发射信号,使得该处理器执行上述第一方面或第二方面或第三方面中的任一项设计所提供的方法。
在具体实现过程中,上述处理器可以为芯片,输入电路可以为输入管脚,输出电路可以为输出管脚,处理电路可以为晶体管、门电路、触发器和各种逻辑电路等。输入电路所接收的输入的信号可以是由例如但不限于接收器接收并输入的,输出电路所输出的信号可以是例如但不限于输出给发射器并由发射器发射的,且输入电路和输出电路可以是同一电路,该电路在不同的时刻分别用作输入电路和输出电路。本申请对处理器及各种电路的具体实现方式不做限定。
第十方面,提供一种通信装置,包括:逻辑电路和输入输出接口,该输入输出接口用于与该通信装置之外的模块通信;该逻辑电路用于运行计算机程序或指令以执行上述任一方面的任一项设计所提供的方法。该通信装置可以为上述第一方面或第二方面或第三方面中的准入控制网络功能或数据管理网络功能或接入管理网络功能或会话管理功能,或者包含上述准入控制网络功能或数据管理网络功能或接入管理网络功能或会话管理功能的装置,或者上述准入控制网络功能或数据管理网络功能或接入管理网络功能或会话管理功能中包含的装置,比如芯片。
或者,该输入输出接口可以为代码/数据读写接口电路,或通信接口,该输入输出接口用于接收计算机程序或指令(计算机程序或指令存储在存储器中,可能直接从存储器读取,或可能经过其他器件)并传输至该输入输出接口,以使该输入输出接口运行计算机程序或指令以执行上述任一方面的方法。
可选的,该通信装置可以为芯片。
第十一方面,提供一种计算机程序产品,该计算机程序产品包括:计算机程序(也可以称为代码,或指令),当该计算机程序被运行时,使得计算机执行上述第一方面或第二方面或第三方面中的任一项设计所提供的方法。
第十二方面,提供一种计算机可读介质,该计算机可读介质存储有计算机程序(也可以称为代码,或指令)当其在计算机上运行时,使得计算机执行上述第一方面或第二方面或第三方面中的任一项设计所提供的方法。
第十三方面,提供一种芯片系统,该芯片系统包括处理器和接口,用于支持通信装置实现上述第一方面或第二方面或第三方面中任一项设计所提供的功能。在一种可能的设计中,芯片系统还包括存储器,用于保存前述通信装置的必要的信息和数据。该芯片系统,可以由芯片构成,也可以包括芯片和其他分立器件。
第十四方面,提供一种芯片装置,该芯片装置包括输入接口和/或输出接口。该输入接口可以实现上述第一方面或第二方面或第三方面中任一项设计所提供的接收功能,该输出 接口可以实现上述第一方面或第二方面或第三方面中任一项设计所提供的发送功能。
第十五方面,提供一种功能实体,该功能实体用于实现上述第一方面至第三方面中的任一项设计所提供的方法。
第十六方面,提供一种通信系统,包括上述第一方面或第二方面或第三方面的准入控制网络功能或数据管理网络功能或接入管理网络功能或会话管理功能。
其中,第二方面至第十六方面中任一种设计方式所带来的技术效果可参见上述第一方面所带来的技术效果,此处不再赘述。
附图说明
图1为本申请实施例适用的一种可能的网络架构示意图;
图2为一种ACU流程示意图;
图3为一种ACU流程示意图;
图4为本申请实施例适用的一种通信过程示意图;
图5为本申请实施例适用的一种通信过程示意图;
图6为一种先执行准入控制流程示意图;
图7为一种先执行准入控制流程示意图;
图8为本申请实施例适用的一种通信过程示意图;
图9为本申请实施例适用的一种通信装置示意图;
图10为本申请实施例适用的一种通信装置示意图;
图11为本申请实施例适用的一种通信装置示意图。
具体实施方式
下面将结合附图对本申请作进一步地详细描述。
本申请将围绕可包括多个设备、组件、模块等的系统来呈现各个方面、实施例或特征。应当理解和明白的是,各个系统可以包括另外的设备、组件、模块等,并且/或者可以并不包括结合附图讨论的所有设备、组件、模块等。此外,还可以使用这些方案的组合。
另外,在本申请实施例中,“示例的”一词用于表示作例子、例证或说明。本申请中被描述为“示例的”的任何实施例或设计方案不应被解释为比其他实施例或设计方案更优选或更具优势。确切而言,使用“示例的”一词旨在以具体方式呈现概念。
本申请实施例描述的网络架构以及业务场景是为了更加清楚的说明本申请实施例的技术方案,并不构成对于本申请实施例提供的技术方案的限定,本领域普通技术人员可知,随着网络架构的演变和新业务场景的出现,本申请实施例提供的技术方案对于类似的技术问题,同样适用。
以下对本申请实施例的部分用语进行解释说明,以便于本领域技术人员理解。
1)用户设备(user equipment,UE),也称终端设备,是一种具有无线收发功能的设备,可以经无线接入网(radio access network,RAN)中的接入网设备与一个或多个核心网(core network,CN)设备进行通信。
用户设备也可称为接入终端、终端、用户单元、用户站、移动站、移动台、远方站、远程终端、移动设备、用户终端、用户代理或用户装置等。用户设备可以部署在陆地上, 包括室内或室外、手持或车载;也可以部署在水面上(如轮船等);还可以部署在空中(例如飞机、气球和卫星上等)。用户设备可以是蜂窝电话(cellular phone)、无绳电话、会话启动协议(session initiation protocol,SIP)电话、智能电话(smart phone)、手机(mobile phone)、无线本地环路(wireless local loop,WLL)站、个人数字处理(personal digital assistant,PDA)等。或者,用户设备还可以是具有无线通信功能的手持设备、计算设备或连接到无线调制解调器的其它设备、车载设备、可穿戴设备、无人机设备或物联网、车联网中的终端、第五代移动通信(5th-generation,5G)网络以及未来网络中的任意形态的终端、中继用户设备或者未来演进的公共移动陆地网络(public land mobile network,PLMN)中的终端等。其中,中继用户设备例如可以是5G家庭网关(residential gateway,RG)。例如用户设备可以是虚拟现实(virtual reality,VR)终端、增强现实(augmented reality,AR)终端、工业控制(industrial control)中的无线终端、无人驾驶(self driving)中的无线终端、远程医疗(remote medical)中的无线终端、智能电网(smart grid)中的无线终端、运输安全(transportation safety)中的无线终端、智慧城市(smart city)中的无线终端、智慧家庭(smart home)中的无线终端等。本申请实施例对终端设备的类型或种类等并不限定。
2)网络设备,指可以为终端提供无线接入功能的设备。其中,网络设备可以支持至少一种无线通信技术,例如长期演进(long term evolution,LTE)、新无线(new radio,NR)等。
例如网络设备可以包括接入网设备。示例的,网络设备包括但不限于:5G网络中的下一代基站或下一代节点B(generation nodeB,gNB)、演进型节点B(evolved node B,eNB)、无线网络控制器(radio network controller,RNC)、节点B(node B,NB)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、家庭基站(例如,home evolved node B、或home node B,HNB)、基带单元(baseband unit,BBU)、收发点(transmitting and receiving point,TRP)、发射点(transmitting point,TP)、移动交换中心、小站、微型站等。网络设备还可以是云无线接入网络(cloud radio access network,CRAN)场景下的无线控制器、集中单元(centralized unit,CU)、和/或分布单元(distributed unit,DU),或者网络设备可以为中继站、接入点、车载设备、终端、可穿戴设备以及未来移动通信中的网络设备或者未来演进的PLMN中的网络设备等。
又如,网络设备可以包括核心网(CN)设备,核心网设备例如AMF、SMF等。
本申请中的“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。字符“/”一般表示前后关联对象是一种“或”的关系。
本申请中所涉及的至少一个是指一个或多个,多个是指两个或两个以上。
另外,需要理解的是,在本申请的描述中,“第一”、“第二”等词汇,仅用于区分描述的目的,而不能理解为指示或暗示相对重要性,也不能理解为指示或暗示顺序。
本申请实施例的技术方案可以应用于各种通信系统。一个通信系统中,由运营者运营的部分可称为PLMN(也可以称为运营商网络等)。PLMN是由政府或其所批准的经营者,为公众提供陆地移动通信业务目的而建立和经营的网络,主要是移动网络运营商(mobile network operator,MNO)为用户提供移动宽带接入服务的公共网络。本申请实施例中所描述的PLMN,具体可为符合第三代移动通信伙伴项目(3rd generation partnership project, 3GPP)标准要求的网络,简称3GPP网络。3GPP网络通常包括但不限于5G、第四代移动通信(4th-generation,4G)网络以及未来的其他通信系统如6G等。
随着移动带宽接入服务的扩展,移动网络也会随之发展以便更好地支持多样化的商业模式,满足更加多样化的应用业务以及更多行业的需求。为了给更多的行业提供更好、更完善的服务,5G网络相对于4G网络也做了网络架构调整。例如,5G网络将4G网络中的移动管理实体(mobility management entity,MME)进行拆分,拆分为包括AMF和SMF等多个网络功能。
为了便于理解本申请实施例,以图1所示的5G网络架构为例对本申请使用的应用场景进行说明。图1为一种5G网络架构的示意图,网络架构中可以包括:用户设备110部分、PLMN部分和数据网络(data network,DN)150部分。
PLMN可以包括:网络开放功能(network exposure function,NEF)131、网络存储功能(network function repository function,NRF)132、策略控制功能(policy control function,PCF)133、统一数据管理(unified data management,UDM)134、统一数据存储(unified data repository,UDR)135、网络数据分析功能(network data analytics function,NWDAF)136、网络切片选择功能(network slice selection function,NSSF)137、认证服务器功能(authentication server function,AUSF)138、AMF139、会话管理功能(session management function,SMF)140、网络切片认证授权功能(Network Slice Specific Authentication and Authorization Function,NSSAAF)141、网络切片准入控制功能(NSACF)142、用户面功能(user plane function,UPF)130、接入网(access network,AN)120等。上述PLMN中,除接入网120部分之外的部分可以称为核心网部分。
数据网络DN 150,也可以称为分组数据网络(packet data network,PDN),可以部署在PLMN之内,也可以部署在PLMN之外(例如第三方网络)。
示例性的,下面对PLMN中的网络功能进行简要介绍。
AN 120,也称无线(Radio)AN,是PLMN的子网络,是PLMN中业务节点(或网络功能)与UE110之间的实施系统。UE110要接入PLMN,首先是经过AN 120,进而通过AN 120与PLMN中的业务节点连接。本申请实施例中的AN 120,可以指代接入网本身,也可以指接入网设备,此处不作区分。接入网设备是一种为UE110提供无线通信功能的设备,也可以称为接入设备、(R)AN设备或网络设备等。可理解,本申请对接入网设备的具体类型不作限定。采用不同无线接入技术的系统中,具备接入网设备功能的设备的名称可能会有所不同。
可选的,在接入设备的一些部署中,接入设备可以包括CU和DU等。在接入设备的另一些部署中,CU还可以划分为CU-控制面(control plane,CP)和CU-用户面(user plan,UP)等。在接入设备的又一些部署中,接入设备还可以是开放的无线接入网(open radio access network,O-RAN或Open RAN)架构等,本申请对于接入设备的具体部署方式不作限定。
网络开放功能NEF(也可以称为网络开放功能实体)131是由运营商提供的控制面功能,用于使能第三方使用网络提供的服务。
网络存储功能NRF 132,是由运营商提供的控制面功能,可用于维护网络中所有网络功能服务的实时信息。
策略控制功能PCF 133是由运营商提供的控制面功能,它支持统一的策略框架来治理 网络行为、向其他控制功能提供策略规则、策略决策相关的签约信息等。
统一数据管理UDM 134是由运营商提供的控制面功能,负责存储PLMN中签约用户的SUPI、安全上下文(security context)、签约数据等信息。
统一数据存储UDR135是由PLMN提供的控制面网络功能,用于支持存储和提取UDM的签约数据、PCF的策略数据、用于开放的结构性数据、应用数据等。
网络数据分析功能NWDAF136,是由PLMN提供的控制面网络功能,用于支持网络运营相关的网络功能(network function,NF)、应用功能(application function,AF)、网管数据搜集、数据开放、分析、机器学习模型训练等。
网络切片选择功能NSSF137,是由PLMN提供的控制面网络功能,用于负责确定网络切片实例,选择AMF等。
认证服务器功能AUSF 138是由运营商提供的控制面功能,通常用于一级认证,即UE110(签约用户)与PLMN之间的网络认证。
接入与移动性管理功能AMF 139是由PLMN提供的控制面网络功能,负责UE110接入PLMN的接入控制和移动性管理,例如包括移动状态管理,分配用户临时身份标识,认证和授权用户等功能。
会话管理功能SMF 140是由PLMN提供的控制面网络功能,负责管理UE110的PDU会话。PDU会话是一个用于传输PDU的通道,终端设备需要通过PDU会话与DN 150互相传输数据。PDU会话可以由SMF 140负责建立、维护和删除等。SMF 140包括会话管理(如会话建立、修改和释放,包含UPF 130和AN 120之间的隧道维护等)、UPF 130的选择和控制、业务和会话连续性(service and session continuity,SSC)模式选择、漫游等会话相关的功能。
网络切片认证授权功能NSSAAF141,是由PLMN提供的控制面网络功能,用于支持UE110与DN进行的切片认证。
网络切片准入控制功能NSACF142是PLMN用来监测并控制注册在网络切片上的UE数量的网络功能。通常NSACF上配置了每个受其监测和控制的网络切片中,最多可以服务的UE的数量。
用户面功能UPF 130是由运营商提供的网关,是PLMN与DN 150通信的网关。UPF 130包括数据包路由和传输、包检测、业务用量上报、服务质量(quality of service,QoS)处理、合法监听、上行包检测、下行数据包存储等用户面相关的功能。
图1所示的PLMN中的网络功能还可以包括其他网络功能(图中未示出),本申请实施例对于PLMN中包括的其他网络功能不作限定。
图1中Nnef、Nnrf、Npcf、Nudm、Nudr、Nnwdaf、Nnssf、Nausf、Namf、Nsmf、Nnssaaf、Nnsacf、N1、N2、N3、N4,以及N6为接口序列号。示例性的,上述接口序列号的含义可参见3GPP标准协议中定义的含义,本申请对于上述接口序列号的含义不做限制。需要说明的是,图1中的各个网络功能之间的接口名称也仅仅是一个示例,在具体实现中,该系统架构的接口名称还可能为其他名称,本申请对此不作限定。
本申请中的移动性管理网络功能可以是图1所示的AMF 139,也可以是未来通信系统中的具有上述接入与移动性管理功能AMF 139的其他网络功能。或者,本申请中的移动性管理网络功能还可以是LTE系统中的移动管理实体(mobility management entity,MME)等。可理解,其他网络功能同样适用。
图1中示出的网络架构示意图可以理解为一种非漫游场景下基于服务的5G网络架构示意图。在该架构中,根据特定场景需求,将不同网络功能按需有序组合,可以实现网络的能力与服务的定制化,从而为不同业务部署专用网络,实现5G网络切片(network slicing)。网络切片技术可以使运营商能够更加灵活、快速地响应客户需求,支持网络资源的灵活分配。
首先对网络设备中的切片进行说明。
切片(slice)即网络切片,简单理解就是将运营商的物理网络切割成多个虚拟的端到端的网络,每个虚拟网络之间(包括网络内的设备、接入网、传输网和核心网)是逻辑独立的,任何一个虚拟网络发生故障都不会影响到其它虚拟网络。为了满足多样性需求和切片间的隔离,需要业务间相对独立的管理和运维,并提供量身定做的业务功能和分析能力。不同业务类型的实例可以部署在不同的网络切片上,相同业务类型的不同实例(instance)也可部署在不同的网络切片上。切片可以由一组网络功能(network function,NF)和/或子网络构成。比如,图1中的子网络(R)AN 120、AMF 139、SMF 140、UPF 130可以组成一个切片。可理解,图1中的每种网络功能只示意性地画出了一个,而在实际网络部署中,每种网络功能或子网络可以有多个、数十个。PLMN中可以部署很多切片,每个切片可以有不同的性能来满足不同应用、不同垂直行业的需求。运营商可以根据不同垂直行业客户的需求,“量身定做”一个切片。
当UE需要接入到网络中的某个切片时,UE可以在上行消息中提供或指示核心网UE想要接入的切片。上行消息即UE发给网络侧的消息,如注册请求(registration request),服务请求(service request),周期注册更新(Periodic Registration Update)等。为了描述方便,下面描述这些上行消息为“请求消息”。通常,想要接入的切片的指示信息被称为请求的(requested)“网络切片选择辅助信息集合”(network slice selection assistance information,NSSAI)。该NSSAI实际上是一个列表或集合,其中包括了一个或多个S-NSSAI,一个S-NSSAI用于标识一个网络切片(也可以是一种网络切片类型),也可以理解为,S-NSSAI是切片的标识信息。
另外,在标准中还定义了网络切片实例标识符(Network Slice Instance Identifier/Identity,NSI-ID)的概念,一个S-NSSAI所标识的切片还可以实例化成一个或多个切片实例(slice instance),每个NSI-ID对应一个切片实例。也可以说,NSI-ID也可以称为切片的标识信息,一个S-NSSAI又可以对应于多个NSI-ID。本申请以S-NSSAI为例进行描述,对S-NSSAI和NSI-ID不作严格区分、限定,对S-NSSAI的描述,同样也可以适用于NSI-ID。
运营商在运营商网络(PLMN)中部署切片时,也可以允许一些切片客户享有较大的自主权,参与切片的部分管理、控制功能。其中,切片级的认证就是由切片客户有限参与的一种网络控制功能,即对终端设备接入切片进行认证和授权,即“切片级认证”,也可称为“二级认证”、“二次认证”等,本申请简称为“切片认证”。
终端设备在被允许接入网络切片之前,首先需要与PLMN网络进行一次“网络级认证”,即PLMN要基于终端设备所使用的与PLMN签约的签约识别信息进行认证,这种认证通常被称为一级认证(primary authentication)。其次,PLMN要基于终端设备所使用的与DN的签约标识进行的认证,即“切片认证”。
上文中涉及的NSACF是PLMN用来监测并控制注册在网络切片上的终端设备数量(或PDU会话数量)的网络功能。PLMN可以在一个或多个NSACF上先配置NSACF所监控的每个网络切片中最多可以服务的终端设备(或PDU会话)的数量,或称为配额(Quota)。当网络准备授权新的终端设备接入某个切片时(或者允许新的PDU会话在某个切片中建立时),NSACF先根据该切片的终端(或PDU会话)配额使用状况,确定网络切片是否还可以接纳该终端设备的接入请求(或该终端设备的PDU会话建立请求),并实时存储、更新切片中已经准入的终端数量(或已经建立的PDU会话数量)。需要说明的是,这里的网络切片,是指需要进行准入控制(admission control)(或PDU会话数量控制)的网络切片。在以下的描述中,如无特别说明,所有网络切片均属此类需要进行准入(或PDU会话数量)控制的切片。
下面以AMF发起用于终端设备数量更新(或终端设备接入控制)为例,对网络切片的可用性查询及更新(availability check and update,ACU)的基本流程进行说明,以下简称为ACU流程。需要说明的是,该ACU流程也同样适用于SMF发起的PDU会话数量更新的流程。当ACU流程是由SMF发起并用于PDU会话数量更新时,需要将AMF替换为SMF,并将终端设备的数量/接入控制/接入请求等描述相应地替换为PDU会话的数量/会话建立控制/会话建立请求等。对于需要进行终端设备准入控制的切片,由AMF触发并向NSACF发送ACU请求。结合图2进行说明,包括以下步骤:
S201:AMF触发ACU流程。
AMF在为终端设备进行注册、去注册、配置更新(UE Configuration Update,UCU)、切片认证服务器发起的重认证和授权吊销等流程时,会触发该流程。需要说明的是,本申请实施例中涉及的“时”可以表示执行该流程之前、该流程过程中或该流程之后,在此统一说明,下文不进行赘述。
AMF决定触发ACU流程时,首先会验证标识为S-NSSAI的切片是PLMN允许该终端设备接入的切片,即AMF验证该S-NSSAI在(该终端设备对应的)“允许接入的NSSAI列表”(Allowed NSSAI)之中。验证成功后,AMF会向NSACF发送针对该S-NSSAI的ACU请求,即执行S202。
S202:AMF向NSACF发送ACU请求。
NSACF接收ACU请求。
ACU请求可以包括UE标识、S-NSSAI、接入类型(access type)以及更新标识(flag)。更新标识flag用于指示UE有关S-NSSAI的请求,该请求用于请求“数量增加”(如UE注册切片S-NSSAI时)或者请求“数量减少”(如UE去注册切片S-NSSAI时)。需要说明的是,当UE处于漫游场景时,S-NSSAI可以是指拜访网络(即visited PLMN)所提供的网络切片的S-NSSAI,也可以是指拜访网络的网络切片所对应的UE的归属网络(home PLMN)的S-NSSAI,即映射的S-NSSAI(Mapped S-NSSAI),也可以是同时包括上述两种S-NSSAI,即拜访网络的S-NSSAI和归属网络的Mapped S-NSSAI。
S203:NSACF根据当前已经准入的终端设备的数量,响应ACU请求。
NSACF可以对注册在标识为S-NSSAI的切片上的终端数量进行更新。
如果ACU请求中包括“数量增加”的更新标识flag,NSACF检查UE标识对应的UE是否已经计入了准入的UE列表。如果是,准入的UE计数器保持不变。如果否,NSACF继续检查当前准入的UE数量是否少于切片S-NSSAI的准入配额,如果配额足够(即接入 该切片的终端数量还未达到切片准入终端的最大值),NSACF将该UE计入准入的UE列表,并将准入的UE计数器的计数值增加1。如果配额已满,计数器保持不变,向AMF响应该切片配额已满。
如果ACU请求中包括“数量减少”的更新标识flag,NSACF在准入的UE列表中删除该UE标识,并将准入该UE的所有切片S-NSSAI的计数器的计数值减少1。
S204:NSACF向AMF发送ACU响应。
如果确定UE准入或删除,NSACF在ACU响应包括数量更新的信息。如果确定配额已满,NSACF在ACU响应包括切片配额已满的信息。
AMF可以根据接收到的ACU响应,进行相应的处理。例如,在切片配额已满时,AMF可以拒绝UE接入切片S-NSSAI的请求,并通知UE切片配额已满的拒绝原因。可选的,AMF还可以通知UE等待一段时间(并发送等待时间)后重新请求接入。
上述ACU流程中,即使网络中各NF都经过了认证,属于合法NF,仍然存在遭受攻击的潜在风险。例如可能存在NF发送虚假消息(或错误消息)欺骗NSACF,造成切片无法正常提供服务或者服务降级。以图3为例,AMFx表示已经受到恶意控制的NF,或者被内部人(insider)控制,从而发送虚假消息,该虚假消息可以造成NSACF错误更新网络切片中注册的终端设备或PDU会话的数量。例如NSACF错误认为切片配额已满,造成AMF发送ACU请求时,由于切片没有配额,而被NSACF拒绝UE接入或拒绝建立PDU会话,导致终端设备无法正常接入或无法正常建立PDU会话,网络切片服务降级或者无法正常提供服务。
基于此,本申请实施例提供一种通信方法。在该方法中,准入控制网络功能接收第一消息,第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息,准入控制网络功能对第一参数信息的真实性进行校验,若第一参数信息为真,准入控制网络功能可以对第一网络切片内的终端设备或会话的数量进行更新,这里通过对接收到的第一参数的真实性进行校验,可以降低因虚假消息造成的网络切片配置的错误更新,保证终端设备可以正常接入网络切片或可以正常建立PDU会话,提高网络切片提供服务的稳定性,以及提高网络的安全性。
本申请实施例提供的通信方法可以应用于图1所示的通信系统。图4为一种可能的通信方法,包括以下步骤:
S401:准入控制网络功能接收第一消息。
准入控制网络功能可以为5G中的NSACF。
该第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息。可选的,第一消息可以为ACU请求消息。
第一参数信息可以包括但不限于以下一种或多种信息:终端设备标识、第一网络切片的标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。需要说明的是,在第一消息为虚假消息或错误消息时,第一参数信息中的一种或多种信息可能为虚假的参数信息或错误的参数信息,例如此时第一参数信息中的第一网络切片的标识与网络中真实的第一网络切片的标识不同。
一种可能的场景中,接入管理网络功能(如AMF)向准入控制网络功能发送第一消息, 第一参数信息用于对第一网络切片内的终端设备的数量进行更新。
另一种可能的场景中,会话管理网络功能(如SMF)向准入控制网络功能发送第一消息,第一参数信息用于对第一网络切片内的会话的数量进行更新。
可选的,第一消息为先执行准入控制模式为未激活状态,且请求接入第一网络切片的终端设备的数量达到第二数量阈值时发送。第二数量阈值可以为任意正整数,在此不做限制。
S402:准入控制网络功能对第一参数信息的真实性进行校验。
对第一参数信息的真实性进行验证的过程,可以是将网络中保存的真实参数信息(下文称为第二参数信息)与第一参数信息进行匹配,或者一致性进行校验。
在一些可能的情况下,虚假消息中可能包括以下虚假参数,因此在进行校验时可以针对这些可能产生虚假参数的参数信息进行校验:
虚假参数一:使用非授权的终端设备标识。
例如使用假的终端设备标识,该假的终端设备标识可以是任意方式生成的终端设备标识。
又如使用AMFx窃听到的真实的终端设备标识,但该真实的终端设备标识没有签约第一网络切片。
又如使用签约了网络切片的终端设备标识,但该终端设备标识所在的服务网络(serving network)与发送第一消息的NF所属的服务网络不匹配。
当发送终端设备标识的NF(如受攻击者控制的AMFx或SMFx)和其它NF(如受害者的AMF或SMF)共同服务某个网络切片时,发送终端设备标识的NF可以通过虚假消息(虚假参数一),虚报终端设备或会话的数量,使得准入控制网络功能误认为网络切片的配额已满,拒绝UE从其他NF接入网络切片或建立会话,造成终端设备遭受被拒绝服务(denial of service,DoS)攻击。
因此准入控制网络功能可以对终端设备标识的真实性进行校验。其中终端设备标识可以为UE ID,和/或UE的因特网协议(internet protocol,IP)地址。
虚假参数二:使用非终端设备签约的网络切片。
例如使用发送第一消息的NF不服务的网络切片。
发送第一消息的NF可以通过发送虚假参数二攻击其他NF服务的网络切片。
因此准入控制网络功能可以对网络切片标识的真实性进行校验。其中网络切片标识可以为S-NSSAI。
虚假参数三:使用错误的指示信息。
例如使用真实的终端设备标识和网络切片标识,但使用错误的指示信息,将用于请求增加数量的指示信息篡改为用于请求减少数量的指示信息,或者将用于请求减少数量的指示信息篡改为用于请求增加数量的指示信息。其中用于请求增加数量的指示信息可以是终端设备请求注册的指示信息或请求创建会话的指示信息,用于请求减少数量的指示信息可以是终端设备请求去注册或请求释放会话的指示信息。
发送第一消息的NF通过窃听其他NF发送的消息,直接篡改其它NF的消息中的指示信息,从而使得NSACF保存的终端设备数量或会话数量与真实情况不符,造成终端设备无法接入网络切片或无法建立会话或者造成网络过载中止服务。
因此准入控制网络功能可以对指示信息的真实性进行校验,其中指示信息可以为请求 注册或去注册的第一指示信息(如更新标识flag1),和/或指示信息可以为请求创建会话或释放会话的第二指示信息(如更新标识flag2)。
虚假参数四:使用错误的接入类型(access type)。
例如使用真实的终端设备标识和网络切片标识,但使用错误的服务类型,使接入网络切片的终端设备或会话的数量加倍。在同一个接入类型下,一个终端设备反复接入仅占用一个数量的配额,而在多个接入类型下,终端设备使用不同类型反复接入时会占用多个数量的配额,也就是说对终端设备来说,每种接入类型会占用一个数量的配额。
发送第一消息的NF通过窃听其他NF发送的消息,直接篡改其它NF的消息中的接入类型,可以虚报终端设备数量,当配额达到最大数量时,造成其他合法终端设备无法接入。
因此准入控制网络功能可以接入类型的真实性进行校验。
可以理解,上述几种虚假参数仅为示例,而对实际校验的参数信息不构成限定。
在一个示例中,准入控制网络功能可以自身对第一参数信息的真实性进行校验。在该示例中,准入控制网络功能可以保存有真实的第二参数信息。
可选的,准入控制网络功能对第一参数信息的真实性进行校验时,可以采用以下一种或多种方式:
准入控制网络功能校验终端设备标识对应的终端设备是否签约了第一网络切片所属的网络的服务。如果终端设备标识对应的终端设备签约了第一网络切片所属的网络的服务,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备标识对应的终端设备未签约第一网络切片所属的网络的服务,可以确定终端设备标识和/或第一网络切片的标识为假。
准入控制网络功能校验终端设备标识对应的终端设备是否签约了与第一网络切片相对应的归属网络的服务。这可以是针对终端设备漫游到拜访网络且第一网络切片是拜访网络所提供时的场景。该漫游终端设备的签约网络为归属网络,签约的网络切片的标识为Mapped S-NSSAI,该标识与第一网络切片的标识S-NSSAI有映射关系。所以在该漫游场景,准入控制网络功能可以校验该终端设备是否签约了该归属网络。如果终端设备标识对应的终端设备签约了第一网络切片所对应的归属网络的服务,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备标识对应的终端设备未签约第一网络切片所对应的归属网络的服务,可以确定终端设备标识和/或第一网络切片的标识为假。
准入控制网络功能校验终端设备是否签约了第一网络切片的服务。如果终端设备签约了第一网络切片的服务,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备未签约第一网络切片的服务,可以确定终端设备标识和/或第一网络切片的标识为假。
准入控制网络功能校验终端设备是否签约了与第一网络切片相对应的归属网络中的网络切片的服务。如果终端设备签约了与第一网络切片相对应的归属网络的网络切片的服务,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备未签约与第一网络切片相对应的归属网络的网络切片的服务,可以确定终端设备标识和/或第一网络切片的标识为假。
准入控制网络功能校验终端设备是否注册了第一网络切片所属的网络。如果终端设备注册了第一网络切片所属的网络,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备未注册第一网络切片所属的网络,可以确定终端设备标识和/或第一网络切片的标识为假。
准入控制网络功能校验终端设备是否接入了第一网络切片。终端设备接入第一网络切片可以是指终端设备收到了网络发送的允许接入第一网络切片的授权信息,比如第一网络切片的标识S-NSSAI在终端设备的Allowed NSSAI列表中。如果终端设备接入了第一网络切片,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备接入了第一网络切片,可以确定终端设备标识和/或第一网络切片的标识为假。
准入控制网络功能校验终端设备是否通过接入管理网络功能标识对应的接入管理网络功能注册了网络。如果终端设备通过接入管理网络功能标识对应的接入管理网络功能注册了网络,可以确定终端设备标识和/或接入管理网络功能标识为真。如果终端设备通过接入管理网络功能标识对应的接入管理网络功能未注册网络,可以确定终端设备标识和/或接入管理网络功能标识为假。
准入控制网络功能校验终端设备是否通过会话管理网络功能标识对应的会话管理网络功能建立了会话。如果终端设备通过会话管理网络功能标识对应的会话管理网络功能建立了会话,可以确定终端设备标识和/或会话管理网络功能标识为真。如果终端设备通过接入管理网络功能标识对应的会话管理网络功能未建立会话,可以确定终端设备标识和/或会话管理网络功能标识为假。
准入控制网络功能校验终端设备是否通过接入管理网络功能接入了第一网络切片。如果终端设备通过接入管理网络功能接入第一网络切片,可以确定终端设备标识、接入管理网络功能标识、第一网络切片的标识中的一个或多个参数信息为真,如果终端设备未通过接入管理网络功能接入第一网络切片,或者如果终端设备通过接入管理网络功能未接入第一网络切片,可以确定终端设备标识、接入管理网络功能标识、第一网络切片的标识中的一个或多个参数信息为假。
准入控制网络功能校验终端设备是否通过会话管理网络功能建立了第一网络切片的会话。如果终端设备通过会话管理网络功能在第一网络切片建立了会话,可以确定终端设备标识、会话管理网络功能标识、第一网络切片的标识中的一个或多个参数信息为真,如果终端设备未通过会话管理网络功能在第一网络切片中建立会话,可以确定终端设备标识、会话管理网络功能标识、第一网络切片的标识中的一个或多个参数信息为假。
准入控制网络功能校验终端设备是否通过接入类型接入了网络。如果终端设备通过该接入类型接入了网络,可以确定终端设备标识和/或接入类型为真,如果终端设备未通过该接入类型接入网络,可以确定终端设备标识和/或接类型为假。其中接入类型可以包括通过3GPP网络接入,和/或通过非3GPP网络接入。通过非3GPP网络接入可以包括通过局域网(如无线保真(wireless fidelity,Wi-Fi))接入,和/或通过固定网络(如光纤网络(Fiber-Optic network))接入等等。
准入控制网络功能校验第一指示信息指示的注册或去注册的请求是否与保存的终端设备的注册状态匹配。如果匹配,可以确定第一指示信息为真,如果不匹配,可以确定第一指示信息为假。例如第一指示信息用于请求去注册,但是网络中保存的终端设备的实际注册状态为未注册,此时可以认为第一指示信息指示的去注册请求与保存的终端设备的注册状态不匹配,第一指示信息为假。而对于第一指示信息用于请求注册,但是网络中保存的终端设备的实际注册状态为已注册,由于目前标准中允许终端设备重新注册,终端设备仅占用一个数量的配额,准入终端设备的计数器保持不变,因此这种情况可以认为第一指示信息指示的注册请求与保存的终端设备的注册状态匹配,第一指示信息为真。又如第一 指示信息用于请求去注册,网络中保存的终端设备的实际注册状态为注册,以及第一指示信息用于请求注册,网络中保存的终端设备的实际注册状态为未注册,可以认为第一指示信息指示的注册或去注册的请求与保存的终端设备的注册状态匹配,第一指示信息为真。
准入控制网络功能校验第二指示信息指示建立会话或释放会话的请求是否与保存的终端设备的会话状态匹配。如果匹配,可以确定第二指示信息为真,如果不匹配,可以确定第二指示信息为假。例如第二指示信息用于请求释放会话,但是网络中保存的终端设备的实际会话状态为未创建,此时可以认为第二指示信息指示的释放会话请求与保存的实际会话状态不匹配,第二指示信息为假。而对于第二指示信息用于请求建立会话,但是网络中保存的实际会话状态为已创建,由于目前标准中允许建立多个会话,但是多个会话对应同一会话标识,会话仅占用一个数量的配额,会话的计数器保持不变,因此这种情况可以认为第二指示信息指示建立会话请求与保存的会话状态匹配,第二指示信息为真。又如第二指示信息用于请求释放会话,网络中保存的实际会话状态为已创建,以及第二指示信息用于请求建立会话,网络中保存的实际会话状态为未创建,可以认为第二指示信息指示的建立会话或释放会话的请求与保存的会话状态匹配,第二指示信息为真。
准入控制网络功能校验会话标识(或会话标识对应的会话)是否存在。如果会话标识(或会话标识对应的会话)存在,可以确定会话标识为真,如果会话标识(或会话标识对应的会话)不存在,可以确定会话标识为假。其中会话标识可以为PDU Session ID。
准入控制网络功能校验会话标识(或会话标识对应的会话)是否属于终端设备。如果会话标识(或会话)属于该终端设备,可以确定会话标识和/或终端设备标识为真,如果会话标识(或会话)不属于该终端设备,可以确定会话标识和/或终端设备标识为假。
准入控制网络功能校验会话标识(或会话标识对应的会话)是否属于第一网络切片。如果会话标识或会话属于第一网络切片,可以确定会话标识和/或第一网络切片的标识为真,如果会话标识或会话不属于第一网络切片,可以确定会话标识和/或第一网络切片的标识为假。
准入控制网络功能校验会话标识对应的会话是否属于会话管理网络功能标识对应的会话管理网络功能管理。如果会话标识对应的会话属于会话管理网络功能标识对应的会话管理网络功能管理,可以确定会话标识和/或会话管理网络功能标识为真,如果会话标识对应的会话不属于会话管理网络功能标识对应的会话管理网络功能管理,可以确定会话标识和/或会话管理网络功能标识为假。
准入控制网络功能校验会话的状态是否与会话当前的状态一致。如果会话的状态与会话当前的状态一致,可以确定会话的状态为真,如果会话的状态与会话当前的状态不一致,可以确定会话的状态为假。
准入控制网络功能校验第一网络切片是否匹配数据网络标识对应的数据网络。如果第一网络切片与数据网络标识对应的数据网络匹配,可以确定第一网络切片的标识和/或数据网络标识为真,如果第一网络切片与数据网络标识对应的数据网络不匹配,可以确定第一网络切片的标识和/或数据网络标识为假。其中数据网络标识可以为数据网络名称(data network name,DNN)和/或数据网络接入标识符(data network access identifier,DNAI)。
在一种可能的实现中,准入控制网络功能对第一参数信息的真实性进行校验之前,可以向数据管理网络功能(如UDM和/或UDR)发送第二消息,第二消息用于请求第二参数信息,第二参数信息用于对第一参数信息的真实性进行校验;以及接收第三消息,第三消 息包括校验第二参数信息。在该实现中,准入控制网络功能可以未保存有真实的第二参数信息。
另一个示例中,准入控制网络功能可以请求其它网络功能对第一参数信息的真实性进行校验。例如其它网络功能可以为数据管理网络功能(如UDM和/或UDR),准入控制网络功能可以向数据管理网络功能发送第二消息,第二消息用于请求对第一参数信息进行校验,数据管理网络功能向准入控制网络功能发送第三消息,第三消息包括第一参数信息的校验结果,校验结果包括第一参数信息为真或假。在该示例中,准入控制网络功能可以未保存有真实的第二参数信息。
数据管理网络功能根据获取到的终端设备或会话的第二参数信息,对第一参数信息进行校验。
第二消息可以包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、第一网络切片的标识、第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识,会话的状态。
可选的,数据管理网络功能根据获取到的终端设备或会话的第二参数信息,对第一参数信息进行校验时,可以采用以下一种或多种方式:
数据管理网络功能根据对终端设备的签约状态进行校验的指示信息,对终端设备的签约状态进行校验。其中终端设备的签约状态可以是终端设备是否签约了第一网络切片所属的网络的服务的状态,或者可以是终端设备是否签约了第一网络切片所对应的归属网络的服务的状态,或者可以是终端设备是否签约了第一网络切片的服务,或者可以是终端设备是否签约了第一网络切片对应的归属网络的网络切片的服务。
数据管理网络功能校验终端设备标识对应的终端设备是否签约了第一网络切片所属的网络的服务。如果终端设备标识对应的终端设备签约了第一网络切片所属的网络的服务,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备标识对应的终端设备未签约第一网络切片所属的网络的服务,可以确定终端设备标识和/或第一网络切片的标识为假。
数据管理网络功能校验终端设备是否签约了第一网络切片的服务。如果终端设备签约了第一网络切片的服务,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备未签约第一网络切片的服务,可以确定终端设备标识和/或第一网络切片的标识为假。
数据管理网络功能校验终端设备是否签约了与第一网络切片相对应的归属网络中的网络切片的服务。如果终端设备签约了与第一网络切片相对应的归属网络的网络切片的服务,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备未签约与第一网络切片相对应的归属网络的网络切片的服务,可以确定终端设备标识和/或第一网络切片的标识为假。
数据管理网络功能根据对终端设备的接入状态进行校验的指示信息,对终端设备的接入状态进行校验。其中终端设备的接入状态可以是终端设备是否注册了第一网络切片所属的网络,可以是终端设备是否接入了第一网络切片。
数据管理网络功能校验终端设备是否注册了第一网络切片所属的网络。如果终端设备注册了第一网络切片所属的网络,可以确定终端设备标识、第一网络切片的标识、第一网 络切片对应的归属网络的切片标识中的一个或多个参数信息为真,如果终端设备未注册第一网络切片所属的网络,可以确定终端设备标识、第一网络切片的标识、第一网络切片对应的归属网络的切片标识中的一个或多个参数信息为假。
数据管理网络功能校验终端设备是否接入了第一网络切片。如果终端设备接入了第一网络切片,可以确定终端设备标识和/或第一网络切片的标识为真,如果终端设备接入了第一网络切片,可以确定终端设备标识和/或第一网络切片的标识为假。
数据管理网络功能校验终端设备是否通过接入管理网络功能标识对应的接入管理网络功能注册了网络。如果终端设备通过接入管理网络功能标识对应的接入管理网络功能注册了网络,可以确定终端设备标识和/或接入管理网络功能标识为真。如果终端设备通过接入管理网络功能标识对应的接入管理网络功能未注册网络,可以确定终端设备标识和/或接入管理网络功能标识为假。
数据管理网络功能校验终端设备是否通过会话管理网络功能标识对应的会话管理网络功能建立了会话。如果终端设备通过会话管理网络功能标识对应的会话管理网络功能建立了会话,可以确定终端设备标识和/或会话管理网络功能标识为真。如果终端设备通过会话管理网络功能标识对应的会话管理网络功能未建立会话,可以确定终端设备标识和/或会话管理网络功能标识为假。
数据管理网络功能校验终端设备是否通过接入管理网络功能接入了第一网络切片。如果终端设备通过接入管理网络功能接入第一网络切片,可以确定终端设备标识、接入管理网络功能标识、第一网络切片的标识中的一个或多个参数信息为真,如果终端设备未通过接入管理网络功能接入第一网络切片,或者如果终端设备通过接入管理网络功能未接入第一网络切片,可以确定终端设备标识、接入管理网络功能标识、第一网络切片的标识中的一个或多个参数信息为假。
数据管理网络功能校验终端设备是否通过会话管理网络功能建立了第一网络切片的会话。如果终端设备通过会话管理网络功能在第一网络切片建立了会话,可以确定终端设备标识、会话管理网络功能标识、第一网络切片的标识中的一个或多个参数信息为真,如果终端设备未通过会话管理网络功能在第一网络切片中建立会话,可以确定终端设备标识、会话管理网络功能标识、第一网络切片的标识中的一个或多个参数信息为假。
数据管理网络功能校验终端设备是否通过接入类型接入了网络。如果终端设备通过该接入类型接入了网络,可以确定终端设备标识和/或接入类型为真,如果终端设备未通过该接入类型接入网络,可以确定终端设备标识和/或接类型为假。
数据管理网络功能校验第一指示信息指示的注册或去注册的请求是否与保存的终端设备的注册状态匹配。如果匹配,可以确定第一指示信息为真,如果不匹配,可以确定第一指示信息为假。
数据管理网络功能校验第二指示信息指示的建立会话或释放会话的请求是否与保存的终端设备的会话状态匹配。如果匹配,可以确定第二指示信息为真,如果不匹配,可以确定第二指示信息为假。
数据管理网络功能校验会话标识(或会话标识对应的会话)是否存在。如果会话标识存在,可以确定会话标识为真,如果会话标识不存在,可以确定会话标识为假。
数据管理网络功能校验会话标识(或会话标识对应的会话)是否属于终端设备。如果会话标识(或会话标识对应的会话)属于该终端设备,可以确定会话标识和/或终端设备标 识为真,如果会话标识(或会话标识对应的会话)不属于该终端设备,可以确定会话标识和/或终端设备标识为假。
数据管理网络功能校验会话标识(或会话标识对应的会话)是否属于第一网络切片。如果会话标识(或会话标识对应的会话)属于第一网络切片,可以确定会话标识和/或第一网络切片的标识为真,如果会话标识(或会话标识对应的会话)不属于第一网络切片,可以确定会话标识和/或第一网络切片的标识为假。
数据管理网络功能校验会话标识对应的会话是否属于会话管理网络功能标识对应的会话管理网络功能管理。如果会话标识对应的会话属于会话管理网络功能标识对应的会话管理网络功能管理,可以确定会话标识和/或会话管理网络功能标识为真,如果会话标识对应的会话不属于会话管理网络功能标识对应的会话管理网络功能管理,可以确定会话标识和/或会话管理网络功能标识为假。
数据管理网络功能校验会话的状态是否与会话当前的状态一致。如果会话的状态与会话当前的状态一致,可以确定会话的状态为真,如果会话的状态与会话当前的状态一致,可以确定会话的状态为假。
数据管理网络功能校验第一网络切片是否匹配数据网络标识对应的数据网络。如果第一网络切片与数据网络标识对应的数据网络匹配,可以确定第一网络切片的标识和/或数据网络标识为真,如果第一网络切片与数据网络标识对应的数据网络不匹配,可以确定第一网络切片的标识和/或数据网络标识为假。
如果第一参数信息包括一种或多种信息,则可以在任一种信息为真时,确定第一参数信息为真。如果存在一种信息为假,可以确定第一参数信息为假。
可选的,准入控制网络功能确定满足第一条件时,执行该S402,避免由于对同时或在短时间内接收到的大量第一参数信息频繁进行校验,增大NF的处理负担,影响NF的处理效率。满足第一条件包括以下一种或多种:计时器的时长达到第一时长、接收到第一消息的次数达到第一次数阈值、接入的终端设备或会话的数量达到第一数量阈值、接收到触发校验的指示信息(如第三指示信息)。例如通过时间触发时,准入控制网络功能中可以预先设置有计时器,计时器按照设定的时间间隔触发对接收到的第一参数信息进行校验,即计时器计时的时长达到第一时长。又如通过次数触发,准入控制网络功能中可以预先设置有计数器,对接收到第一消息进行计数,按照设定的次数间隔对第一参数信息进行校验,即接收到第一消息的次数达到第一次数阈值。又如通过准入的终端设备或会话的数量,准入控制网络功能中的计数器对准入的终端设备或会话的数量进行计数,每准入一定数量的终端设备或会话,对第一参数信息进行校验,即接入的终端设备或会话的数量达到第一数量阈值。又如准入控制网络功能接收到来自其他NF的触发校验的指示信息时,对接收到第一参数信息进行校验。该其他NF可以为NWDAF或业务行政管理网络功能(operations administration and management,OAM)。第一时长的取值任意正数,在此不做限制。第一次数阈值可以为任意正整数,在此不做限制。第一数量阈值可以为任意正整数,在此不做限制,第一数量阈值和第二数量阈值可以相同,或者可以不同。可以理解,本申请实施例中所涉及的计数器可以为正计数或者可以为倒计数,计时器可以为正计时或者可以为倒计时。
S403:若第一参数信息为真,准入控制网络功能对第一网络切片内的终端设备或会话的数量进行更新。
若第一参数信息为假,准入控制网络功能按照第一网络切片配额不足进行处理。可选的准入控制网络功能可以通知OAM存在异常事件等。
下面以第一参数信息用于更新第一网络切片内的终端设备的数量为例进行说明,参见图5,包括如下步骤:
S501:AMF向NSACF发送ACU请求。
ACU请求包括终端设备标识UE ID,第一网络切片的标识S-NSSAI,第一指示信息flag和接入类型access type等参数信息。
可选地,AMF和NSACF可以基于服务化接口(service based interface,SBI)进行交互。AMF在ACU消息中还可以包括令牌(token)供NSACF验证AMF身份,该令牌中还可以包括AMF ID。
可选地,第一网络切片的标识S-NSSAI可以是终端设备的归属网络的第一网络切片的标识,也可以是终端设备的拜访网络的网络切片的切片标识。可选地,第一网络切片的标识也可以包括两个第一网络切片的标识,一个是拜访网络的切片标识S-NSSAI,另一个是与之相对应的归属网络的切片标识,即Mapped S-NSSAI。
S502:NSACF向UDM发送验证请求消息。
可选地,NSACF和UDM之间可以先基于SBI通过NRF进行认证和授权,NSACF和UDM认证和授权可以进行交互。
该签约验证请求消息用于请求UDM对第一参数信息的真实性进行校验,判断第一参数信息是否存在参数造假。
签约验证请求消息可以包括UE ID。可选地,签约验证请求消息还可以包括以下一种或多种:对UE的签约状态进行校验的指示信息、对UE的接入状态进行校验的指示信息、一个或多个S-NSSAI、AMF ID等。需要说明的是,本申请中“一个或多个S-NSSAI”可以包括一个或多个拜访网络的S-NSSAI、或者一个或多个归属网络的S-NSSAI、或者包括一个或多个拜访网络的S-NSSAI和一个或多个归属网络的S-NSSAI、或者包括一个或多个拜访网络的S-NSSAI以及对应的归属网络的Mapped S-NSSAI。本申请中对上述情况不作特别限定。在下面的描述中同样适用,不再赘述。
AMF ID是指步骤S501中向NSACF发送ACU请求消息的AMF。可选地,NSACF可以从ACU请求消息中的令牌中获取。需要说明的是,本申请对NSACF如何获取AMF的ID不做限制。
如果签约验证请求消息包括对UE的签约状态进行校验的指示信息,该签约验证请求消息还可以至少包括UE ID。可选地,该签约验证请求消息还可以包括一个或多个S-NSSAI。
如果签约验证请求消息包括对UE的接入状态进行校验的指示信息,该签约验证请求消息还可以至少包括UE ID。可选地,该签约验证请求消息还可以包括以下一种或多种:一个或多个S-NSSAI、AMF ID、UE的接入类型。
如果签约验证请求消息中不包括对UE的签约状态进行校验的指示信息或/和对UE的接入状态进行校验的指示信息,UDM可以默认指示该一种或两种状态的校验,或者UDM可以预先的规定或配置默认执行其中一种状态的校验。
UDM也可以根据签约验证请求消息中包括的第一参数信息,确定需要校验的第一参数信息。例如签约验证请求消息包括接入类型和AMF ID,UDM确定需要对接入类型和终端接入的状态(从哪个AMF或网络接入)进行校验。
一种可能的情况下,UDM中存储有UE的签约数据,未存储UE的接入状态,这时,UDM可以请求UDR对UE的接入状态进行校验,执行S503。可以理解,UDM可以对UE的签约状态和/或接入状态进行校验,UDR也可以对UE的签约状态和/或接入状态进行校验。
可选地S503:UDM向UDR发送接入状态验证请求消息。
可选地S504:UDR向UDM发送接入状态验证结果。
可以理解,UDM发送的接入状态验证请求消息可以用于在UDR获取接入状态,对应的,接入状态验证结果中包括UDR中存储的接入状态。或者UDM发送的接入状态验证请求可以用于请求UDR验证接入状态,对应的,接入状态验证结果中包括UDR确定的接入状态的验证结果。
在不执行S503和S504时,UDM可以执行如下操作:UDM如果确定对UE的签约状态进行校验,UDM可以从NSACF中(如步骤502的消息中)获取UE ID,查询UDM中存储UE的签约数据。该签约数据包括与网络已经签约的UE,根据UE ID,UDM可以确定UE ID对应的待查询UE是否为签约用户,即UDM可以校验UE ID是否为真实的UE ID,即UE ID是否属于已签约的UE,或者属于合法的UE。
可选地UDM中存储的签约数据中还可以包括UE所签约的切片信息,例如UE所签约的切片信息可以包括在UDM的“Subscribed S-NSSAIs”信息元(information element,IE)。示例的,如果UE已经签约了两个切片,UDM中会列出对应UE签约的切片标识S-NSSAI列表,包括S-NSSAI-1和S-NSSAI-2。如果UDM收到的NSACF的签约验证请求消息中包括了S-NSSAI-1和S-NSSAI-3,则UDM可以确定S-NSSAI-1校验通过(UE已签约该切片)、S-NSSAI-3校验不通过(UE未签约该切片)。可选地,在UE漫游到拜访网络时,UDM是指UE的归属网络中的UDM。
在执行S503和S504时,UDM不一定存储UE所有状态信息,这种情况下,UDM可以执行如下操作:
如果需要校验UE接入的服务网络与签约的UE接入的服务网络是否一致:如果NSACF在签约验证请求消息中包括了需要校验的AMF ID,UDM可以根据AMF ID确定该AMF所属的网络(即所属的PLMN ID),例如PLMN ID为PLMN-4。而UDM可以根据UE签约的切片标识S-NSSAI,确定S-NSSAI属于哪个PLMN网络。例如UE签约的S-NSSAI-1属于PLMN-1,以及UE签约的S-NSSAI-2属于PLMN-2。UDM通过比较PLMN ID,确定PLMN-4分别与PLMN-1和PLMN-2不同,由此可以确定AMF与UE签约的切片信息不一致,校验不通过。
如果需要验证签约验证请求消息中的AMF与UE接入的AMF是否一致:UE在接入切片之前通过接入的服务网络(服务网络是指UE在漫游时接入的拜访网络、或者是UE在非漫游时接入的归属网络)的AMF进行主认证并生成相关的密钥,AMF ID会保存在UDM或UDR中。因此UDM可以将存储的服务该UE的(通过该AMF进行主认证的)AMF ID与签约验证请求消息中的AMF ID相比较,如果一致即校验通过,否则校验不通过。类似地,也可以通过比较UDM中存储的该UE当前的(或通过主认证的)PLMN ID与签约验证请求消息中的AMF所对应的PLMN ID是否相同来校验PLMN ID。需要说明的是,如果UDM中未存储相关信息,UDM可以通过UDR来获取,即通过执行S503,向UDR发送接入状态验证请求消息。UDR中有多个IE存储了PLMN ID的信息,例如IE“UE 当前的PLMN”(“UE Current PLMN”)中包括当前PLMN ID,又如IE“UE漫游状态”(“UE Roaming status”)中包括UE当前漫游到的服务网络PLMN ID,该网络是否为归属网络(home PLMN)。本实施例不限制通过UDR中哪一个IE获取当前PLMN或AMF的信息。
如果需要验证签约验证请求消息中的接入类型与签约的UE的接入类型是否一致:UDR中存储UE当前的接入类型(3GPP接入或者是非3GPP接入),如果签约验证请求消息包括终端设备的接入类型,表示要求验证接入类型,UDM可以通过S503,向UDR接入状态验证请求消息,如果UDR中存储的接入类型与签约验证请求消息中的接入类型是否一致,如果一致则确定校验通过,否则校验不通过。
如果需要验证签约验证请求消息中的flag与签约的UE的注册状态是否一致:UDR中存储UE当前的注册状态,可以被用来校验签约验证请求消息中的flag指示的注册状态的真假。例如UDR中还保存了有关UE接入的“注册状态”IE(“UE registration state”),该IE显示UE的当前状态是“已注册”(“Registered”)还是“去注册”(“Deregistered”)。当UE处于“去注册”状态时,意味着UE没有接入任何切片,没有占用任何切片的准入配额。如果此时签约验证请求消息中Flag=“-“(即减少准入配额,与该UE当前的注册状态不符合。因此如果UDM从UDR获取了该UE注册状态后,即可验证签约验证请求消息中的“-”Flag信息验证不通过。
S505:UDM向NSACF发送验证结果。
S506:当所有参数信息验证通过时,NSACF更新存储的网络切片的准入配额。
如果参数信息验证不通过时,可选地,NSACF按照网络切片没有准入配额进行处理,或者通知网络管理功能或实体OAM,例如通知存在异常事件。
S507:NSACF向AMF发送ACU响应。
该S507可以参见上述S204。
值得说明的是,对参数信息验证的全部或部分过程可以由NSACF实现,或者可以由UDM实现,或者可以由UDR实现。例如,当参数信息的验证过程由NSACF实现时,S505中UDM向NSACF发送的不是验证结果,而是第二参数信息,该第二参数信息用于对第一参数信息验证真假。在该实现中,准入控制网络功能可以未保存有真实的第二参数信息。又例如,当UE状态信息的验证过程由UDM实现时,S504中UDR向UDM发送的不是验证结果,而是第二参数信息,该信息用于验证UE的状态。
需要说明的是,上述实施例以AMF为例子与NSACF交互用来控制切片内的UE数量。同样方法也适用于SMF与NSACF交互的ACU流程,该流程是控制切片内PDU的数量。当用来控制PDU数量的时候,UDM、UDR中存储了相关PDU会话的参数可以用来校验,即上述校验的第一参数信息需要替换为相关PDU会话的第一参数信息。例如,UDM中存储了UE已经建立的PDU会话、PDU会话标识(PDU Session ID)、DN名称(DNN)、SMF ID(如SMF IP Address或SMF NF ID)。又例如UDR中存储了UE已经建立的PDU会话、UE IP地址(UE IP Address)、PDU会话状态(PDU Session status)、DN接入ID(DN access identifier,DNAI)等,可以进行类似校验,即作为步骤502中的第一参数信息进行一一校验,这里不再赘述。
在该方法中,准入控制网络功能接收第一消息,第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息,准入控制网络功能对第一参数信息的真实性 进行校验,若第一参数信息为真,准入控制网络功能可以对第一网络切片内的终端设备或会话的数量进行更新,若第一参数信息为假,表示第一参数信息为伪造的错误的信息,准入控制网络功能不对第一网络切片内的终端设备或会话的数量进行更新。这里通过对接收到的第一参数的真实性进行校验,可以降低因虚假消息造成的切片配置的错误更新,保证终端设备可以正常接入网络切片或可以正常建立PDU会话,提高网络切片提供服务的稳定性,以及提高网络安全性。
下面对先执行准入控制(early admission control,EAC)模式的基本流程进行说明。EAC模式用于指示执行ACU流程的时间点。当EAC模式被激活(active)时,AMF在授权UE接入网络切片之前,要先执行ACU流程,以便确认网络切片的配额未满,允许UE接入。当EAC模式没有被激活(inactive)时,AMF可以在授权UE接入网络切片之后,再去执行ACU流程,通常情况下网络切片有充足的配额,不急于更新网络切片接入的终端设备或会话的数量,可以优先执行UE的其他流程。结合图6进行说明,包括以下步骤:
S601:NSACF触发EAC配置更新流程。
例如当网络切片中接入的终端设备的数量达到一定数量(如终端设备的数量高于或低于预设的数量阈值)时,NSACF触发EAC配置更新流程。
S602:NSACF向AMF发送EAC模式更新消息,EAC模式更新消息用于激活或去激活网络切片的EAC模式。
例如当网络切片中接入的终端设备的数量低于预设的数量阈值(如低于50%的配额)时,NSACF去激活网络切片的EAC模式,不必在授权UE之前发起ACU流程。当网络切片中接入的终端设备的数量高于预设的数量阈值(如高于75%的配额)时,NSACF激活网络切片的EAC模式,需要在授权UE之前发起ACU流程,以便于保证网络切片有足够配额接入UE。
S603:AMF更新EAC模式。
AMF还可以根据配置,在授权UE之前或之后发起ACU流程。
即使网络中各NF都经过了认证,属于合法NF,仍然存在遭受攻击的潜在风险。例如在EAC未被激活时,AMF不需要在UE被授权接入网络切片之前发起ACU流程。如果此时允许AMF同时或在短时间内授权大量UE,会造成UE数量突然大量增加,可能导致UE数量超过网络切片配置的风险,在多个AMF服务于同一个网络切片时该风险会更严重。以图7为例,NSACFx表示已经受到恶意攻击的NF或被insider控制,从而发送虚假消息,该虚假消息可能篡改EAC模式,如将EAC flag设置为deactived或inactive,使上述风险更易发生。
基于此,本申请实施例提供另一种通信方法。在该方法中,在先执行准入控制模式为未激活状态时,如果请求接入第一网络切片的终端设备的数量达到第二数量阈值,接入管理网络功能向准入控制网络功能发送第一消息,用于更新第一网络切片内的终端设备的数量,从而可以降低先执行准入控制模式在未激活状态下,授权终端设备接入网络切片过多的风险,可以提高网络切片提供服务的稳定性。
本申请实施例提供的通信方法可以应用于图1所示的通信系统。图8为一种可能的通信方法,包括以下步骤:
S801:在先执行准入控制模式为未激活状态时,接入管理网络功能确定请求接入第一网络切片的终端设备的数量。
AMF预先设置有计数器,可以在发起ACU流程之后,在接收到终端设备请求接入第一网络切片时,对计数器的计数值进行更新,例如对计数值增加设定值,该设定值为任意整数,在本申请实施例中不做限制,例如该设定值可以为1。
S802:如果请求接入第一网络切片的终端设备的数量达到第二数量阈值,接入管理网络功能向准入控制网络功能发送第一消息。
对应的,准入控制网络功能接收第一消息。
终端设备中可以设置有第二数量阈值,该第二数量阈值可以为任意整数,在本申请实施例不做限制,第一数量阈值和第二数量阈值可以相同,或者可以不同。该第二数量阈值可以为系统中预设设置的值,或者可以是通过先执行准入控制配置更新流程更新得到的值,或者可以是由接入管理网络功能确定的值。如果通过先执行准入控制配置更新流程更新得到第二数量阈值,准入控制网络功能在发送先执行准入控制模式更新消息时,可以在先执行准入控制模式更新消息中增加第二数量阈值的指示信息。如果接入管理网络功能确定第二数量阈值,接入管理网络功能可以根据网络切片剩余的准入配额和/或接入管理网络功能的数量,确定第二数量阈值。当然,本申请实施例对第二数量阈值的其他确定方式不做限定。
该第二数量阈值可以为接入管理网络功能在两次ACU流程之间,最多准入的终端设备的数量上限。如果请求接入第一网络切片的终端设备的数量达到第二数量阈值,则需要先执行ACU流程,向准入控制网络功能发送第一消息。该第一消息包括用于更新第一网络切片内的终端设备的数量,或者拒绝请求接入第一网络切片的终端设备。可以理解为在先执行准入控制模式为未激活状态下,接入管理网络功能中额外增加了一个触发ACU流程的条件。
可选地,准入控制网络功能还可以发送第四消息,接入管理网络功能接收第四消息,该第四消息用于将先执行准入控制模式修改为未激活状态,接入管理网络功能对第四消息进行校验;若校验通过,接入管理网络功能确定先执行准入控制模式为未激活状态。通过该验证过程,在第四消息校验通过时,接入管理网络功能可以确定先执行准入控制模式不存在恶意修改,在第四消息校验不通过时,接入管理网络功能可以确定先执行准入控制模式存在恶意修改,识别出攻击风险。
第四消息可以包括但不限于以下一种或多种:准入控制网络功能标识、准入控制网络功能所在运营商网络的标识、第一网络切片的标识。在接入管理网络功能对第四消息进行校验时,接入管理网络功能可以对准入控制网络功能标识(NSACF ID)、准入控制网络功能所在运营商网络的标识(PLMN ID)、第一网络切片的标识(S-NSSAI)中的一种或多种,进行校验。需要说明的是,第四消息中的上述标识,通常是包含在Token中,如包含在Token的声明项(Claim)中。Token中的信息是经过了完整性保护的信息,攻击者如果篡改其中的信息,会造成验证不通过。
需要说明的是,如果在UE漫游时,第四消息中(如Token中)的S-NSSAI可以采用服务网络(即拜访网络)PLMN的S-NSSAI,也可以采用映射的网络切片标识(mapped S-NSSAI),即归属网络中的S-NSSAI。PLMN ID(即拜访网络的ID)和mapped S-NSSAI (归属网络的S-NSSAI)可以更准确的确定准入控制网络功能。由于一个归属网络的S-NSSAI(mapped S-NSSAI)可以被映射到不同的PLMN里的S-NSSAI,因此仅仅包括mapped S-NSSAI信息仍存在被冒用的风险,这样通过对PLMN和网络切片标识(serving S-NSSAI和/或mapped S-NSSAI)进行校验,可以减弱该风险。
可选地,对第四消息进行校验的过程可以在S602之后执行,如果验证通过,再执行S603。
在该方法中,在先执行准入控制模式为未激活状态时,如果请求接入第一网络切片的终端设备的数量达到第二数量阈值,接入管理网络功能向准入控制网络功能发送第一消息,用于更新第一网络切片内的终端设备的数量,从而可以降低先执行准入控制模式在未激活状态下,授权终端设备接入网络切片过多的风险,可以提高网络切片提供服务的稳定性,以及提高网络的安全性。
需要说明的是,图7、图8所述步骤同样适用于对会话的数量的控制,其中接入控制网络功能AMF需要替换为会话管理功能SMF。相应的token中的信息可以相应地增加或者替换为相关会话的信息,这里不再赘述。
在本申请的各个实施例中,如果没有特殊说明以及逻辑冲突,不同的实施例之间的术语和/或描述具有一致性、且可以相互引用,不同的实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
并且,本申请的各个实施例,也可以适用于基于SBI的其它NF之间交互时的信息校验场景,其它NF和待校验的信息可能与上述实施例中的NF和第一参数信息不同,校验过程类似,这里不做赘述。
基于与上述通信方法的同一技术构思,本申请实施例还提供一种通信装置,如图9所示,通信装置900包括处理单元901和收发单元902,通信装置900可以用于实现上述方法实施例中描述的方法。装置900可以应用于准入控制网络功能或数据管理网络功能或接入管理网络功能,或者位于准入控制网络功能或数据管理网络功能或接入管理网络功能中。可选的收发单元902所实现的功能可以由通信接口完成。
在一个可能的实施例中,装置900为准入控制网络功能时,收发单元902,用于接收第一消息,第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息;处理单元901,用于对第一参数信息的真实性进行校验;若第一参数信息为真,对第一网络切片内的终端设备或会话的数量进行更新。
第一参数信息包括以下一种或多种信息:终端设备标识、第一网络切片的标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
在一个实现方式中,处理单元901,具体用于采用以下一种或多种方式对第一参数信息的真实性进行校验:校验终端设备标识对应的终端设备是否签约了第一网络切片所属的网络的服务或者签约了与第一网络切片相对应的归属网络的服务;校验终端设备是否签约了第一网络切片的服务或者签约了与第一网络切片相对应的归属网络的网络切片的服务;校验终端设备是否注册了第一网络切片所属的网络;校验终端设备是否接入了第一网络切片;校验终端设备是否通过接入管理网络功能标识对应的接入管理网络功能注册了网络; 校验终端设备是否通过接入管理网络功能接入了第一网络切片;校验终端设备是否通过接入类型接入了网络;校验第一指示信息指示的注册或去注册的请求是否与保存的终端设备的注册状态匹配;校验第二指示信息指示的建立会话或释放会话的请求是否与保存的终端设备的会话状态匹配;校验会话标识或会话标识对应的会话是否存在;校验会话标识或会话标识对应的会话是否属于终端设备;校验会话标识或会话标识对应的会话是否属于第一网络切片;校验会话标识对应的会话是否属于会话管理网络功能标识对应的会话管理网络功能管理;校验会话的状态是否与会话当前的状态一致;校验第一网络切片是否匹配数据网络标识对应的数据网络。
在一个实现方式中,处理单元901,具体用于通过收发单元902用于向数据管理网络功能发送第二消息,第二消息用于请求对第一参数信息进行校验;接收第三消息,第三消息包括第一参数信息的校验结果。
在一个实现方式中,第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、第一网络切片的标识、第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
在一个实现方式中,处理单元901还用于确定满足第一条件。
满足第一条件包括以下一种或多种:计时器的时长达到第一时长、接收到第一消息的次数达到第一次数阈值、接入的终端设备或会话的数量达到第一数量阈值、接收到触发校验的指示信息。
在一个实现方式中,第一消息为先执行准入控制模式为未激活状态,且请求接入第一网络切片的终端设备的数量达到第二数量阈值时发送。
在另一个可能的实施例中,装置900为数据管理网络功能时,收发单元902,用于接收第二消息,第二消息用于请求对第一参数信息进行校验,第一参数信息用于更新第一网络切片内的终端设备或会话的数量;处理单元901,用于根据获取到的终端设备或会话的第二参数信息,对第一参数信息进行校验;收发单元902,用于向准入控制网络功能发送第三消息,第三消息包括第一参数信息的校验结果,校验结果包括第一参数信息为真或假。
在一个实现方式中,第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、第一网络切片的标识、第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
在一个实现方式中,处理单元901,具体用于采用以下一种或多种方式根据获取到的终端设备或会话的第二参数信息,对第一参数信息进行校验:根据对终端设备的签约状态进行校验的指示信息,对终端设备的签约状态进行校验;校验终端设备标识对应的终端设备是否签约了第一网络切片所属的网络的服务或者签约了与第一网络切片相对应的归属网络的网络的服务;校验终端设备是否签约了第一网络切片的服务或者签约了与第一网络切片相对应的归属网络的网络切片的服务;根据对终端设备的接入状态进行校验的指示信息,对终端设备的接入状态进行校验;校验终端设备是否注册了第一网络切片所属的网络;校验终端设备是否接入了第一网络切片;校验终端设备是否通过接入管理网络功能标识对 应的接入管理网络功能注册了网络;校验终端设备是否通过接入管理网络功能接入了第一网络切片;校验终端设备是否通过接入类型接入了网络;校验第一指示信息指示的注册或去注册的请求是否与保存的终端设备的注册状态匹配;校验第二指示信息指示的建立会话或释放会话的请求是否与保存的终端设备的会话状态匹配;校验会话标识或会话标识对应的会话是否存在;校验会话标识或会话标识对应的会话是否属于终端设备;校验会话标识或会话标识对应的会话是否属于第一网络切片;校验会话标识对应的会话是否属于会话管理网络功能标识对应的会话管理网络功能管理;校验会话的状态是否与会话当前的状态一致;校验第一网络切片是否匹配数据网络标识对应的数据网络。
在又一个可能的实施例中,装置900为接入管理网络功能时,处理单元901,用于在先执行准入控制模式为未激活状态时,确定请求接入第一网络切片的终端设备的数量;收发单元902,用于如果请求接入第一网络切片的终端设备的数量达到第二数量阈值,向准入控制网络功能发送第一消息,第一消息包括用于更新第一网络切片内的终端设备的数量。
在一个实现方式中,收发单元902,还用于接收准入控制网络功能发送的第四消息,第四消息用于将先执行准入控制模式修改为未激活状态。
处理单元901,还用于可以对第四消息进行校验,若校验通过,确定先执行准入控制模式为未激活状态。
在一个实现方式中,处理单元901,具体用于对准入控制网络功能标识、准入控制网络功能所在运营商网络的标识、第一网络切片的标识中的一种或多种,进行校验。
需要说明的是,本申请实施例中对模块的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。例如收发单元可以包括接收单元和/或发送单元。
集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,该集成的单元可以作为计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)或处理器(processor)执行本申请各个实施例方法的全部或部分步骤。
如图10所示,本申请实施例还提供了一种通信装置1000的结构示意图。装置1000可用于实现上述方法实施例中描述的方法,可以参见上述方法实施例中的说明。
装置1000包括一个或多个处理器1001。处理器1001可以是通用处理器或者专用处理器等。例如可以是基带处理器、或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,基站、终端、或芯片等)进行控制,执行软件程序,处理软件程序的数据。通信装置可以包括收发单元,用以实现信号的输入(接收)和输出(发送)。例如,收发单元可以为收发器,射频芯片等。
装置1000包括一个或多个处理器1001,一个或多个处理器1001可实现上述所示的实施例中的方法。
可选的,处理器1001除了实现上述所示的实施例的方法,还可以实现其他功能。
一种设计中,处理器1001可以执行指令,使得装置1000执行上述方法实施例中描述的方法。指令可以全部或部分存储在处理器1001内,如指令1003可以全部或部分存储在 处理器1001中,或者指令1003存储在处理器1001中,以及指令1004存储在与处理器耦合的存储器1002中,处理器1001可以同步执行指令1003和指令1004使得装置1000执行上述方法实施例中描述的方法。指令1003和指令1004也称为计算机程序。
在又一种可能的设计中,通信装置1000还可以包括电路,电路可以实现前述方法实施例中的功能。
在又一种可能的设计中装置1000中可以包括一个或多个存储器1002,其上存有指令1004,指令可在处理器1001上被运行,使得装置1000执行上述方法实施例中描述的方法。可选的,存储器中还可以存储有数据。可选的处理器1001中也可以存储指令和/或数据。例如,一个或多个存储器1002可以存储上述实施例中所描述的对应关系,或者上述实施例中所涉及的相关的参数或表格等。处理器和存储器可以单独设置,也可以集成在一起。
在又一种可能的设计中,装置1000还可以包括收发器1005以及天线1006。处理器1001可以称为处理单元,对装置(终端或者基站)进行控制。收发器1005可以称为收发机、收发电路、或者收发单元等,用于通过天线1006实现装置的收发功能。
处理器可以是一个通用中央处理器(central processing unit,CPU)、微处理器、特定应用集成电路(application-specific integrated circuit,ASIC)、一个或多个用于控制本申请方案程序执行的集成电路、通用处理器、数字信号处理器(digital signal processor,DSP)、现成可编程门阵列(field programmable gate array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本申请实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以存储介质中,该存储介质位于存储器。
存储器可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDR SDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synchlink DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DR RAM)。应注意,本文描述的系统和方法的存储器旨在包括但不限于这些和任意其它适合类型的存储器。存储器可以是独立存在,通过通信线路与处理器相连接。存储器也可以和处理器集成在一起。
本申请实施例还提供了一种计算机可读介质,其上存储有计算机程序,该计算机程序被计算机执行时实现上述任一方法实施例的通信方法。
本申请实施例还提供了一种计算机程序产品,包括计算机程序,该计算机程序被计算机执行时实现上述任一方法实施例的通信方法。
本申请实施例还提供了一种通信系统,包括准入控制网络功能,还可以包括接入管理 网络功能和/或会话管理网络功能。可选的,通信系统还可以包括数据管理网络功能。各网络功能可以实现上述任一方法实施例。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行计算机指令时,全部或部分地产生按照本申请实施例的流程或功能。计算机可以是上述通信装置。计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输。计算机可读存储介质可以是上述存储介质或上述存储器。
在一种可能的设计中,当上述通信装置是芯片,如网络设备中的芯片时,或者,如终端设备中的芯片时,确定单元或者处理器1001可以是一个或多个逻辑电路,发送单元或者接收单元或者收发器1005可以是输入输出接口,又或者称为通信接口,或者接口电路,或接口等等。或者收发器1005还可以是发送单元和接收单元,发送单元可以是输出接口,接收单元可以是输入接口,该发送单元和接收单元集成于一个单元,例如输入输出接口。如图11所示,图11所示的通信装置1100包括逻辑电路1101和接口电路1102。即上述确定单元或者处理器1001可以用逻辑电路1101实现,发送单元或者接收单元或者收发器1005可以用接口电路1102实现。其中,该逻辑电路1101可以为芯片、处理电路、集成电路或片上系统(system on chip,SoC)芯片等,接口电路1102可以为通信接口、输入输出接口等。本申请实施例中,逻辑电路和接口电路还可以相互耦合。对于逻辑电路和接口电路的具体连接方式,本申请实施例不作限定。
在本申请的一些实施例中,该逻辑电路1101和接口电路1102可用于执行上述终端设备或策略控制网络功能或接入管理网络功能执行的功能或操作等。接口电路可以用于接收来自通信装置之外的其它通信装置的信号并传输至逻辑电路或将来自逻辑电路的信号发送给通信装置之外的其它通信装置。逻辑电路可以通过执行代码指令用于实现上述任一方法实施例。接口电路1102可以用于接收来自通信装置1100之外的其它通信装置的信号并传输至逻辑电路1101或将来自逻辑电路1101的信号发送给通信装置1100之外的其它通信装置。逻辑电路1101可以通过执行代码指令用于实现上述任一方法实施例。
示例性地,接口电路1102用于接收第一消息,第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息。逻辑电路1101用于对第一参数信息的真实性进行校验,若第一参数信息为真,对第一网络切片内的终端设备或会话的数量进行更新。网络设备或终端设备执行的功能或操作可以参照前述方法实施例,在此不再赘述。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、计算机软件或者二者的结合来实现,为了清楚地说明硬件和软件的可互换性,在上述说明中已经按照功能一般性地描述了各示例的组成及步骤。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。
所属领域的技术人员可以清楚地了解到,为了描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,单元的划分, 仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另外,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口、装置或单元的间接耦合或通信连接,也可以是电的,机械的或其它的形式连接。
作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本申请实施例方案的目的。
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以是两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
通过以上的实施方式的描述,所属领域的技术人员可以清楚地了解到本申请可以用硬件实现,或固件实现,或它们的组合方式来实现。当使用软件实现时,可以将上述功能存储在计算机可读介质中或作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是计算机能够存取的任何可用介质。
总之,以上仅为本申请技术方案的实施例而已,并非用于限定本申请的保护范围。凡在本申请的原则之内,所作的任何修改、等同替换、改进等,均应包含在本申请的保护范围之内。

Claims (23)

  1. 一种通信方法,其特征在于,包括:
    准入控制网络功能接收第一消息,所述第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息,所述第一参数信息包括以下一种或多种信息:终端设备标识、所述第一网络切片的标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态;
    所述准入控制网络功能对所述第一参数信息的真实性进行校验;
    若所述第一参数信息为真,所述准入控制网络功能对所述第一网络切片内的终端设备或会话的数量进行更新。
  2. 如权利要求1所述的方法,其特征在于,所述准入控制网络功能对所述第一参数信息的真实性进行校验,包括以下一种或多种:
    所述准入控制网络功能校验所述终端设备标识对应的终端设备是否签约了所述第一网络切片所属的网络的服务或者签约了与所述第一网络切片相对应的归属网络的服务;
    所述准入控制网络功能校验所述终端设备是否签约了所述第一网络切片的服务或者签约了与所述第一网络切片相对应的归属网络的网络切片的服务;
    所述准入控制网络功能校验所述终端设备是否注册了所述第一网络切片所属的网络;
    所述准入控制网络功能校验所述终端设备是否接入了所述第一网络切片;
    所述准入控制网络功能校验所述终端设备是否通过所述接入管理网络功能标识对应的接入管理网络功能注册了网络;
    所述准入控制网络功能校验所述终端设备是否通过所述接入管理网络功能接入了所述第一网络切片;
    所述准入控制网络功能校验所述终端设备是否通过所述接入类型接入了网络;
    所述准入控制网络功能校验所述第一指示信息指示的注册或去注册的请求是否与保存的所述终端设备的注册状态匹配;
    所述准入控制网络功能校验所述第二指示信息指示的建立会话或释放会话的请求是否与保存的所述终端设备的会话状态匹配;
    所述准入控制网络功能校验所述会话标识或所述会话标识对应的会话是否存在;
    所述准入控制网络功能校验所述会话标识或所述会话标识对应的会话是否属于所述终端设备;
    所述准入控制网络功能校验所述会话标识或所述会话标识对应的会话是否属于所述第一网络切片;
    所述准入控制网络功能校验所述会话标识对应的会话是否属于所述会话管理网络功能标识对应的会话管理网络功能管理;
    所述准入控制网络功能校验所述会话的状态是否与所述会话当前的状态一致;
    所述准入控制网络功能校验所述第一网络切片是否匹配所述数据网络标识对应的数据网络。
  3. 如权利要求1或2所述的方法,其特征在于,所述准入控制网络功能对所述第一参数信息的真实性进行校验,包括:
    所述准入控制网络功能向数据管理网络功能发送第二消息,所述第二消息用于请求对所述第一参数信息进行校验;
    所述准入控制网络功能接收第三消息,所述第三消息包括所述第一参数信息的校验结果。
  4. 如权利要求3所述的方法,其特征在于,所述第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、所述第一网络切片的标识、所述第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
  5. 如权利要求1-4任一项所述的方法,其特征在于,所述准入控制网络功能对所述第一参数信息的真实性进行校验之前,还包括:
    所述准入控制网络功能确定满足第一条件;
    所述满足第一条件包括以下一种或多种:计时器的时长达到第一时长、接收到第一消息的次数达到第一次数阈值、接入的终端设备或会话的数量达到第一数量阈值、接收到触发校验的指示信息。
  6. 如权利要求1-5任一项所述的方法,其特征在于,所述第一消息为先执行准入控制模式为未激活状态,且请求接入第一网络切片的终端设备的数量达到第二数量阈值时发送。
  7. 一种通信方法,其特征在于,包括:
    数据管理网络功能接收第二消息,第二消息用于请求对第一参数信息进行校验,所述第一参数信息用于更新第一网络切片内的终端设备或会话的数量;
    所述数据管理网络功能根据获取到的终端设备或会话的第二参数信息,对所述第一参数信息进行校验;
    所述数据管理网络功能向准入控制网络功能发送第三消息,所述第三消息包括所述第一参数信息的校验结果,所述校验结果包括所述第一参数信息为真或假。
  8. 如权利要求7所述的方法,其特征在于,所述第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、所述第一网络切片的标识、所述第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
  9. 如权利要求8所述的方法,其特征在于,所述数据管理网络功能根据获取到的终端设备或会话的第二参数信息,对所述第一参数信息进行校验,包括以下一种或多种:
    所述数据管理网络功能根据所述对终端设备的签约状态进行校验的指示信息,对所述终端设备的签约状态进行校验;
    所述数据管理网络功能校验所述终端设备标识对应的终端设备是否签约了所述第一网络切片所属的网络的服务或者签约了与所述第一网络切片相对应的归属网络的网络的服务;
    所述数据管理网络功能校验所述终端设备是否签约了所述第一网络切片的服务或者签约了与所述第一网络切片相对应的归属网络的网络切片的服务;
    所述数据管理网络功能根据所述对终端设备的接入状态进行校验的指示信息,对所述终端设备的接入状态进行校验;
    所述数据管理网络功能校验所述终端设备是否注册了所述第一网络切片所属的网络;
    所述数据管理网络功能校验所述终端设备是否接入了所述第一网络切片;
    所述数据管理网络功能校验所述终端设备是否通过所述接入管理网络功能标识对应的接入管理网络功能注册了网络;
    所述数据管理网络功能校验所述终端设备是否通过所述接入管理网络功能接入了所述第一网络切片;
    所述数据管理网络功能校验所述终端设备是否通过所述接入类型接入了网络;
    所述数据管理网络功能校验所述第一指示信息指示的注册或去注册的请求是否与保存的所述终端设备的注册状态匹配;
    所述数据管理网络功能校验所述第二指示信息指示的建立会话或释放会话的请求是否与保存的所述终端设备的会话状态匹配;
    所述数据管理网络功能校验所述会话标识或所述会话标识对应的会话是否存在;
    所述数据管理网络功能校验所述会话标识或所述会话标识对应的会话是否属于所述终端设备;
    所述数据管理网络功能校验所述会话标识或所述会话标识对应的会话是否属于所述第一网络切片;
    所述数据管理网络功能校验所述会话标识对应的会话是否属于所述会话管理网络功能标识对应的会话管理网络功能管理;
    所述数据管理网络功能校验所述会话的状态是否与所述会话当前的状态一致;
    所述数据管理网络功能校验所述第一网络切片是否匹配所述数据网络标识对应的数据网络。
  10. 一种通信装置,其特征在于,包括:
    收发单元,用于接收第一消息,所述第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息,所述第一参数信息包括以下一种或多种信息:终端设备标识、第一网络切片的标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态;
    处理单元,用于对所述第一参数信息的真实性进行校验;若所述第一参数信息为真,对所述第一网络切片内的终端设备或会话的数量进行更新。
  11. 如权利要求10所述的装置,其特征在于,所述处理单元,具体用于采用以下一种或多种方式对所述第一参数信息的真实性进行校验:
    校验所述终端设备标识对应的终端设备是否签约了所述第一网络切片所属的网络的服务或者签约了与所述第一网络切片相对应的归属网络的服务;
    校验所述终端设备是否签约了所述第一网络切片的服务或者签约了与所述第一网络切片相对应的归属网络的网络切片的服务;
    校验所述终端设备是否注册了所述第一网络切片所属的网络;
    校验所述终端设备是否接入了所述第一网络切片;
    校验所述终端设备是否通过所述接入管理网络功能标识对应的接入管理网络功能注册了网络;
    校验所述终端设备是否通过所述接入管理网络功能接入了所述第一网络切片;
    校验所述终端设备是否通过所述接入类型接入了网络;
    校验所述第一指示信息指示的注册或去注册的请求是否与保存的所述终端设备的注册状态匹配;
    校验所述第二指示信息指示的建立会话或释放会话的请求是否与保存的所述终端设备的会话匹配;
    校验所述会话标识或所述会话标识对应的会话是否存在;
    校验所述会话标识或所述会话标识对应的会话是否属于所述终端设备;
    校验所述会话标识或所述会话标识对应的会话是否属于所述第一网络切片;
    校验所述会话标识对应的会话是否属于所述会话管理网络功能标识对应的会话管理网络功能管理;
    校验所述会话的状态是否与所述会话当前的状态一致;
    校验所述第一网络切片是否匹配所述数据网络标识对应的数据网络。
  12. 如权利要求10或11所述的装置,其特征在于,所述收发单元,具体用于向数据管理网络功能发送第二消息,所述第二消息用于请求对所述第一参数信息进行校验;接收第三消息,所述第三消息包括所述第一参数信息的校验结果。
  13. 如权利要求12所述的装置,其特征在于,所述第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、所述第一网络切片的标识、所述第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
  14. 如权利要求10-13任一项所述的装置,其特征在于,所述处理单元,还用于确定满足第一条件;所述满足第一条件包括以下一种或多种:计时器的时长达到第一时长、接收到第一消息的次数达到第一次数阈值、接入的终端设备或会话的数量达到第一数量阈值、接收到触发校验的指示信息。
  15. 如权利要求10-14任一项所述的装置,其特征在于,所述第一消息为先执行准入控制模式为未激活状态,且请求接入第一网络切片的终端设备的数量达到第二数量阈值时发送。
  16. 一种通信装置,其特征在于,包括:
    收发单元,用于接收第二消息,第二消息用于请求对第一参数信息进行校验,所述第一参数信息用于更新第一网络切片内的终端设备或会话的数量;
    处理单元,用于根据获取到的终端设备或会话的第二参数信息,对所述第一参数信息进行校验;
    所述收发单元,用于向准入控制网络功能发送第三消息,所述第三消息包括所述第一参数信息的校验结果,所述校验结果包括所述第一参数信息为真或假。
  17. 如权利要求16所述的装置,其特征在于,所述第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行 校验的指示信息、所述第一网络切片的标识、所述第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
  18. 如权利要求17所述的装置,其特征在于,所述处理单元,具体用于采用以下一种或多种方式根据获取到的终端设备或会话的第二参数信息,对所述第一参数信息进行校验:
    根据所述对终端设备的签约状态进行校验的指示信息,对所述终端设备的签约状态进行校验;
    校验所述终端设备标识对应的终端设备是否签约了所述第一网络切片所属的网络的服务或者签约了与所述第一网络切片相对应的归属网络的网络的服务;
    校验所述终端设备是否签约了所述第一网络切片的服务或者签约了与所述第一网络切片相对应的归属网络的网络切片的服务;
    根据所述对终端设备的接入状态进行校验的指示信息,对所述终端设备的接入状态进行校验;
    校验所述终端设备是否注册了所述第一网络切片所属的网络;
    校验所述终端设备是否接入了所述第一网络切片;
    校验所述终端设备是否通过所述接入管理网络功能标识对应的接入管理网络功能注册了网络;
    校验所述终端设备是否通过所述接入管理网络功能接入了所述第一网络切片;
    校验所述终端设备是否通过所述接入类型接入了网络;
    校验所述第一指示信息指示的注册或去注册的请求是否与保存的所述终端设备的注册状态匹配;
    校验所述第二指示信息指示的建立会话或释放会话的请求是否与保存的所述终端设备的会话状态匹配;
    校验所述会话标识或所述会话标识对应的会话是否存在;
    校验所述会话标识或所述会话标识对应的会话是否属于所述终端设备;
    校验所述会话标识或所述会话标识对应的会话是否属于所述第一网络切片;
    校验所述会话标识对应的会话是否属于所述会话管理网络功能标识对应的会话管理网络功能管理;
    校验所述会话的状态是否与所述会话当前的状态一致;
    校验所述第一网络切片是否匹配所述数据网络标识对应的数据网络。
  19. 一种通信装置,其特征在于,包括处理器,所述处理器用于执行如权利要求1-9中任一项所述的方法。
  20. 一种通信装置,其特征在于,包括处理器和存储器,所述处理器与所述存储器耦合;
    存储器存储有计算机程序或指令;
    处理器,用于执行所述存储器中的计算机程序或指令,以使得所述装置执行如权利要求1-9中任一项所述的方法。
  21. 一种通信装置,其特征在于,包括逻辑电路和接口电路;
    所述接口电路,用于与所述通信装置之外的模块通信;
    所述逻辑电路用于执行计算机程序或指令,以使所述通信装置执行如权利要求1-9中 任一项所述的方法。
  22. 一种计算机可读存储介质,其特征在于,包括计算机程序或指令,当所述计算机程序或指令在计算机上运行时,使得如权利要求1-9中任一项所述的方法被执行。
  23. 一种计算机程序产品,其特征在于,包括计算机程序或指令,当其在计算机上运行时,使得如权利要求1-9中任一项所述的方法被执行。
PCT/CN2022/103024 2021-08-06 2022-06-30 一种通信方法及装置 Ceased WO2023011069A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP22851784.3A EP4376487A4 (en) 2021-08-06 2022-06-30 COMMUNICATION METHOD AND APPARATUS
US18/434,782 US20240179614A1 (en) 2021-08-06 2024-02-06 Communication method and apparatus

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110904039.6 2021-08-06
CN202110904039.6A CN115706699A (zh) 2021-08-06 2021-08-06 一种通信方法及装置

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US18/434,782 Continuation US20240179614A1 (en) 2021-08-06 2024-02-06 Communication method and apparatus

Publications (1)

Publication Number Publication Date
WO2023011069A1 true WO2023011069A1 (zh) 2023-02-09

Family

ID=85155182

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/103024 Ceased WO2023011069A1 (zh) 2021-08-06 2022-06-30 一种通信方法及装置

Country Status (4)

Country Link
US (1) US20240179614A1 (zh)
EP (1) EP4376487A4 (zh)
CN (1) CN115706699A (zh)
WO (1) WO2023011069A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2025213348A1 (zh) * 2024-04-08 2025-10-16 北京小米移动软件有限公司 通信方法、装置和存储介质

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116367270A (zh) * 2021-12-27 2023-06-30 中国移动通信有限公司研究院 通信方法、装置、相关设备及存储介质
CN116800614A (zh) * 2023-03-31 2023-09-22 广州爱浦路网络技术有限公司 网络切片分配方法及装置、网络切片申请方法、电子设备
CN116830629A (zh) * 2023-04-07 2023-09-29 北京小米移动软件有限公司 基于网络切片的通信方法及装置
CN120614667A (zh) * 2024-03-06 2025-09-09 维沃移动通信有限公司 网络接入的控制方法、装置及通信设备

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109314917A (zh) * 2017-05-09 2019-02-05 华为技术有限公司 网络切片选择策略更新方法、及装置
WO2021070086A1 (en) * 2019-10-07 2021-04-15 Telefonaktiebolaget Lm Ericsson (Publ) Ue controlled pdu sessions on a network slice

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102847659B1 (ko) * 2020-11-06 2025-08-20 레노보 (싱가포르) 피티이. 엘티디. 검증된 디지털 아이덴티티를 사용한 가입 온보딩
CN117158050A (zh) * 2021-04-09 2023-12-01 三星电子株式会社 用于处理ue的网络切片准入控制的方法和系统
CN117178602A (zh) * 2021-05-06 2023-12-05 联想(新加坡)私人有限公司 网络切片准入控制
JP2024125444A (ja) * 2021-08-05 2024-09-19 シャープ株式会社 UE(User Equipment)
EP4381813A1 (en) * 2021-08-06 2024-06-12 Lenovo (Singapore) Pte. Ltd. Registration to a network slice subject to admission control
EP4383857A4 (en) * 2021-08-06 2024-10-02 Beijing Xiaomi Mobile Software Co., Ltd. METHOD AND APPARATUS FOR SELECTING A NETWORK LAYER ACCESS CONTROL FUNCTION

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109314917A (zh) * 2017-05-09 2019-02-05 华为技术有限公司 网络切片选择策略更新方法、及装置
WO2021070086A1 (en) * 2019-10-07 2021-04-15 Telefonaktiebolaget Lm Ericsson (Publ) Ue controlled pdu sessions on a network slice

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
[NEC, APPLE, NOKIA, NOKIA SHANGHAI BELL, ERICSSON, LG ELECTRONICS], HUAWEI, HISILICON: "TS23.502 KI#2 Network Slice Admission Control Function (NSACF) services and procedures", 3GPP DRAFT; S2-2104082, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. e-meeting; 20210517 - 20210528, 10 May 2021 (2021-05-10), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP052004416 *
HUAWEI, HISILICON: "Default Subscribed S-NSSAIs for Network Slice Admission Control", 3GPP DRAFT; S2-2102218, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. e-meeting; 20210412 - 20210416, 6 April 2021 (2021-04-06), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051993604 *
See also references of EP4376487A4 *
ZTE: "Additional NSAC information from NSACF", 3GPP DRAFT; S2-2104469, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. E (e-meeting); 20210517 - 20210528, 10 May 2021 (2021-05-10), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP052004777 *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2025213348A1 (zh) * 2024-04-08 2025-10-16 北京小米移动软件有限公司 通信方法、装置和存储介质

Also Published As

Publication number Publication date
EP4376487A1 (en) 2024-05-29
EP4376487A4 (en) 2024-11-13
US20240179614A1 (en) 2024-05-30
CN115706699A (zh) 2023-02-17

Similar Documents

Publication Publication Date Title
US20230078317A1 (en) Relay Link Establishment Method, Configuration Information Sending Method, Apparatus, and Readable Storage Medium
US12425861B2 (en) Method for determining class information and apparatus
US20240179614A1 (en) Communication method and apparatus
US11871223B2 (en) Authentication method and apparatus and device
US12501305B2 (en) Proximity service communication method, management network element, terminal device, and communication system
CN112584486B (zh) 一种通信方法及装置
RU2759094C1 (ru) Обновление конфигурации сетевых сегментов
CN113630272B (zh) 一种通信方法及装置
CN110881185A (zh) 一种通信的方法及装置
WO2021012736A1 (zh) 一种会话管理网元的选择方法、装置及系统
US20220394596A1 (en) Enforcement of maximum number of admitted terminals per network slice
JP7662571B2 (ja) ネットワークスライスアドミッション制御(nsac)発見及びローミング強化
US20240224098A1 (en) Network verification method and apparatus
CN114450991B (zh) 用于注册程序的无线通信方法
US20250227465A1 (en) Communication method and communication apparatus
US11991781B2 (en) Subscriber data management method and apparatus
CN115568001B (zh) 一种会话建立方法、装置及存储介质
CN116233953A (zh) 数据传输方法、装置、设备及存储介质
US20240314886A1 (en) Method for slice resource release
CN115551122A (zh) 切片准入控制的方法和通信装置
WO2021253859A1 (zh) 切片认证方法及系统
US20250338123A1 (en) Communication method and communication apparatus
US20250260979A1 (en) Communication method and communication apparatus
CN112449377B (zh) 一种网络数据的上报方法及装置
WO2022155913A1 (zh) 一种接入控制的方法、装置和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22851784

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 202447008598

Country of ref document: IN

WWE Wipo information: entry into national phase

Ref document number: 2022851784

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2022851784

Country of ref document: EP

Effective date: 20240222

NENP Non-entry into the national phase

Ref country code: DE