WO2023011069A1 - 一种通信方法及装置 - Google Patents
一种通信方法及装置 Download PDFInfo
- Publication number
- WO2023011069A1 WO2023011069A1 PCT/CN2022/103024 CN2022103024W WO2023011069A1 WO 2023011069 A1 WO2023011069 A1 WO 2023011069A1 CN 2022103024 W CN2022103024 W CN 2022103024W WO 2023011069 A1 WO2023011069 A1 WO 2023011069A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- session
- network
- terminal device
- identifier
- network function
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W48/00—Access restriction; Network selection; Access point selection
- H04W48/02—Access restriction performed under specific conditions
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W24/00—Supervisory, monitoring or testing arrangements
- H04W24/02—Arrangements for optimising operational condition
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/20—Services signaling; Auxiliary data signalling, i.e. transmitting data via a non-traffic channel
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W48/00—Access restriction; Network selection; Access point selection
- H04W48/16—Discovering, processing access restriction or access information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
- H04W60/04—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration using triggered events
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W60/00—Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
- H04W60/06—De-registration or detaching
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/30—Connection release
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/02—Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
- H04W8/08—Mobility data transfer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
- H04W76/11—Allocation or use of connection identifiers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
- H04W76/12—Setup of transport tunnels
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/30—Connection release
- H04W76/32—Release of transport tunnels
Definitions
- the present application relates to the technical field of wireless communication, and in particular to a communication method and device.
- the access and mobility management function can send an availability query and terminal quantity update (availability check and update, ACU) request to the network slice admission control function (Network Slice Admission Control Function, NSACF), According to the request of the ACU, the NSACF updates the number of terminal devices registered in the network slice identified as single network slice selection assistance information (S-NSSAI). When the admission quota of the number of terminals in the network slice is full, the NSACF notifies the AMF accordingly, and the AMF may therefore reject the access request of the terminal device.
- S-NSSAI single network slice selection assistance information
- the session management function can send an ACU request to the NSACF, and the NSACF updates the number of protocol data unit (PDU) sessions established in the network slice identified as S-NSSAI according to the ACU request.
- PDU protocol data unit
- the NSACF notifies the SMF accordingly, and the SMF can therefore reject the session establishment request of the terminal device.
- the NF may send a false ACU request to NSACF, causing NSACF to incorrectly update the number of registered terminal devices or established PDU sessions in the network slice, causing other terminal devices to fail to connect normally. Incoming or terminal devices cannot normally establish a new PDU session, and the network slicing service is degraded or unable to provide services normally.
- the present application provides a communication method and device, which are used to reduce wrong updates of network slice configurations caused by false news, and improve the stability of services provided by network slices.
- a communication method including the following process: an admission control network function receives a first message, and the first message includes first parameter information for updating the number of terminal devices or sessions in the first network slice; The ingress control network function verifies the authenticity of the first parameter information, and if the first parameter information is true, updates the number of terminal devices or sessions in the first network slice.
- the first parameter information may include one or more of the following information: terminal device identifier, first network slice identifier, access management network function identifier, first indication information requesting registration or de-registration, requesting session establishment or release session.
- the second indication information the access type of the terminal device, the session identifier, the data network identifier, the session management network function identifier, and the status of the session.
- the first parameter information may include one or more of the following information: terminal device identifier, first network slice identifier, access management The network function identifier, the first indication information requesting registration or de-registration, and the access type of the terminal device.
- the first parameter information may include one or more of the following information: terminal device identifier, identifier of the first network slice, request to establish The second indication information of the session or the released session, the session ID, the data network ID, the session management network function ID, and the state of the session.
- the admission control network function may be NSACF.
- the admission control network function may verify the authenticity of the first parameter information by itself, or the admission control network function may request other network functions to verify the authenticity of the first parameter information. The authenticity of the first parameter information is verified.
- the admission control network function receives the first parameter information, and the first parameter information is used to update the number of terminal devices or sessions in the first network slice, and the admission control network function may check the true value of the first parameter information Fake verification, when the first parameter information is true, the number of terminal devices or sessions in the first network slice may be updated, and when the first parameter information is false, it indicates that the first parameter information is forged and wrong information, The number of terminal devices or sessions in the first network slice is not updated, thereby reducing incorrect updates of network slice configurations caused by false messages, ensuring that terminal devices can normally access network slices or establish PDU sessions normally, and improve network security. Slicing provides service stability.
- the admission control network function verifies the authenticity of the first parameter information
- one or more of the following methods may be adopted:
- the admission control network function checks whether the terminal device corresponding to the terminal device identifier has signed up for the service of the network to which the first network slice belongs or has signed up for the service of the home network corresponding to the first network slice;
- the admission control network function checks whether the terminal device has subscribed to the service of the first network slice or the service of the network slice of the home network corresponding to the first network slice;
- the admission control network function checks whether the terminal device is registered with the network to which the first network slice belongs;
- the admission control network function checks whether the terminal device is connected to the first network slice
- the access control network function verifies whether the terminal device has registered with the network through the access management network function corresponding to the access management network function identifier;
- the admission control network function verifies whether the terminal device has accessed the first network slice through the access management network function
- the access control network function verifies whether the terminal device has connected to the network through the access type
- the admission control network function checks whether the registration or de-registration request indicated by the first indication information matches the saved registration status of the terminal device;
- the admission control network function checks whether the request for establishing a session or releasing a session indicated by the second indication information matches the saved session state of the terminal device;
- the admission control network function checks whether the session identifier or the session corresponding to the session identifier exists
- the admission control network function checks whether the session identifier or the session corresponding to the session identifier belongs to the terminal device;
- the admission control network function checks whether the session identifier or the session corresponding to the session identifier belongs to the first network slice;
- the admission control network function checks whether the session corresponding to the session identifier belongs to the session management network function management corresponding to the session management network function identifier;
- the admission control network function checks whether the state of the session is consistent with the current state of the session
- the admission control network function checks whether the first network slice matches the data network corresponding to the data network identifier.
- the admission control network function may itself verify the authenticity of the first parameter information.
- the second parameter information used to verify the authenticity of the first parameter information may be pre-stored in the admission control network function, or may be obtained by the admission control network function from other network functions.
- the admission control network function may send a fifth message to the data management network function, where the fifth message is used to request the second parameter information, and the first The second parameter information is used to verify the authenticity of the first parameter information; and receive a sixth message from the data management network function, where the sixth message includes the second parameter information.
- the admission control network function may not store real second parameter information.
- the admission control network function when it verifies the authenticity of the first parameter information, it may send a second message to the data management network function, and the second message is used to request verification of the first parameter information. and receiving a third message, where the third message includes a verification result of the first parameter information, and the verification result is used to indicate whether the first parameter information is true or false.
- the admission control network function may request other network functions (such as the data management network function) to verify the authenticity of the first parameter information.
- the second message includes one or more of the following information: terminal device identifier, instruction information for verifying the subscription status of the terminal device, and instruction information for verifying the access status of the terminal device , the identifier of the first network slice, the slice identifier of the home network corresponding to the first network slice, the identifier of the access management network function, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, The terminal device's access type, session ID, data network ID, session management network function ID, and session status.
- the admission control network function may further determine that the first condition is satisfied. Satisfying the first condition includes one or more of the following: the duration of the timer reaches the first duration, the number of times the first message is received reaches the first threshold, and the number of connected terminal devices or sessions reaches the first threshold 1. Receive the indication information triggering the verification.
- trigger verification is determined when the first condition is met, which can avoid verification of a large number of first parameter information received at the same time or in a short period of time, and increase access control
- the processing burden of the network function reduces the processing efficiency of the admission control network function.
- the first message is sent when the admission control mode performed first is in an inactive state, and the number of terminal devices requesting to access the first network slice reaches a second number threshold.
- the access management network function can first authorize the terminal device to access the first network slice, and then execute the ACU process.
- the second number threshold it is possible to avoid the risk that the access management network function authorizes a large number of terminal devices to access at the same time or within a short period of time, resulting in the number of terminal devices exceeding the configuration of the first network slice, thereby Further improve the stability of services provided by network slicing.
- a communication method including the following process: the data management network function receives a second message, the second message is used to request verification of the first parameter information, and the first parameter information is used to update the first network slice The number of end devices or sessions.
- the data management network function may verify the first parameter information according to the acquired second parameter information of the terminal device or session.
- the data management network function sends a third message to the admission control network function, the third message includes a verification result of the first parameter information, and the verification result includes whether the first parameter information is true or false.
- the data management network function may be unified data management (UDM) and/or unified data storage (UDR).
- UDM unified data management
- UDR unified data storage
- the data management network function can verify the authenticity of the first parameter information received by the admission control network function, thereby reducing the error update of the network slice configuration caused by false information and improving the service efficiency of the network slice. stability.
- the second message includes one or more of the following information: terminal device identifier, instruction information for verifying the subscription status of the terminal device, and instruction information for verifying the access status of the terminal device , the identifier of the first network slice, the slice identifier of the home network corresponding to the first network slice, the identifier of the access management network function, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, The terminal device's access type, session ID, data network ID, session management network function ID, and session status.
- the data management network function verifies the first parameter information according to the obtained second parameter information of the terminal device or session, and may adopt one or more of the following methods:
- the data management network function verifies the contract status of the terminal device according to the instruction information for verifying the contract status of the terminal device
- the data management network function checks whether the terminal device corresponding to the terminal device identifier has signed up for the service of the network to which the first network slice belongs or has signed up for the service of the network of the home network corresponding to the first network slice;
- the data management network function checks whether the terminal device has subscribed to the service of the first network slice or the service of the network slice of the home network corresponding to the first network slice;
- the data management network function verifies the access status of the terminal device according to the instruction information for verifying the access status of the terminal device
- the data management network function checks whether the terminal device is registered with the network to which the first network slice belongs;
- the data management network function checks whether the terminal device is connected to the first network slice
- the data management network function verifies whether the terminal device has registered with the network through the access management network function corresponding to the access management network function identifier;
- the data management network function verifies whether the terminal device has accessed the first network slice through the access management network function
- the data management network function checks whether the terminal device is connected to the network through the access type
- the data management network function checks whether the registration or de-registration request indicated by the first indication information matches the saved registration status of the terminal device;
- the data management network function checks whether the request for establishing a session or releasing a session indicated by the second indication information matches the saved session state of the terminal device;
- the data management network function checks whether the session identifier or the session corresponding to the session identifier exists
- the data management network function checks whether the session identifier or the session corresponding to the session identifier belongs to the terminal device;
- the data management network function checks whether the session identifier or the session corresponding to the session identifier belongs to the first network slice;
- the data management network function checks whether the session corresponding to the session identifier belongs to the session management network function management corresponding to the session management network function identifier;
- the data management network function checks whether the state of the session is consistent with the current state of the session
- the data management network function checks whether the first network slice matches the data network corresponding to the data network identifier.
- a communication method including the following process: when the admission control mode performed first is in an inactive state, the access management network function determines the number of terminal devices requesting to access the first network slice. If the number of terminal devices requesting access to the first network slice reaches the second number threshold, the access management network function sends a first message to the admission control network function, and the first message includes information for updating terminal devices in the first network slice. quantity.
- the access management network function can first authorize terminal devices to access the first network slice, and then execute the ACU process, but there may be a large number of terminal devices authorized to access Therefore, by setting the second number threshold, it can be ensured that the number of connected terminal devices is within the range that the first network slice can stably provide services , to improve the stability of services provided by network slicing.
- the access management network function may be an AMF.
- the access management network function may also receive a fourth message sent by the admission control network function, where the fourth message is used to modify the pre-executed admission control mode to an inactive state.
- the access management network function may verify the fourth message, and if the verification is passed, the access management network function determines that the admission control mode is first executed as an inactive state.
- the access management network function can verify the authenticity of the fourth message.
- the fourth message can modify the admission control mode to be inactive.
- the fourth message is false
- the fourth message may include one or more of the following information: an admission control network function identifier, an identifier of an operator network where the admission control network function is located, and an identifier of the first network slice.
- the access management network function may check one or more of the access control network function identifier, the identifier of the operator network where the admission control network function is located, and the identifier of the first network slice. check.
- a communication device which can be the above-mentioned admission control network function or data management network function or access management network function, or be set in the admission control network function or data management network function or access Chips in management network functions or session management network functions.
- the communication device may implement the method provided by any one of the designs of the first aspect, the second aspect, or the third aspect.
- the communication device includes a corresponding module, unit, or means (means) for implementing the above method, and the module, unit, or means may be implemented by hardware, software, or by executing corresponding software on hardware.
- the hardware or software includes one or more modules or units corresponding to the above functions.
- a communication device including a transceiver unit.
- the communication device further includes a processing unit.
- the communication device may implement the method provided by any design in the first aspect, the second aspect, or the third aspect.
- a communication device including a processor.
- the processor may be used to execute the method provided by any one of the above-mentioned first aspect, second aspect, or third aspect.
- the device further includes a memory, the processor is coupled to the memory, and the memory is used to store computer programs or instructions, and the processor can execute the programs or instructions in the memory, so that the device can perform the above-mentioned first aspect or the second aspect. Any one design method provided in the second aspect or the third aspect.
- a communication device includes an interface circuit and a logic circuit, and the logic circuit is coupled to the interface circuit.
- the interface circuit may be a code/data read-write interface circuit, or a communication interface, and the interface circuit is used to receive computer-executed instructions (computer-executed instructions are stored in the memory, may be read directly from the memory, or may pass through other devices) and transmit to the logic circuit, so that the logic circuit runs the computer to execute instructions to execute the method provided by any one of the above-mentioned first aspect, second aspect or third aspect.
- the communication device may be a chip or a chip system.
- a communication device including a processor and a memory.
- the processor is used to read instructions stored in the memory, and can receive signals through the receiver, and transmit signals through the transmitter, so as to execute the method provided by any one of the above-mentioned first aspect, second aspect, or third aspect. .
- processors there may be one or more processors, and one or more memories.
- the memory can be integrated with the processor, or the memory can be set separately from the processor.
- the memory can be a non-transitory (non-transitory) memory, such as a read-only memory (read only memory, ROM), which can be integrated with the processor on the same chip, or can be respectively arranged in different On the chip, the application does not limit the type of the memory and the arrangement of the memory and the processor.
- a non-transitory memory such as a read-only memory (read only memory, ROM)
- ROM read only memory
- the communication device can be a chip, and the processor can be implemented by hardware or software.
- the processor can be a logic circuit, integrated circuit, etc.; when implemented by software, the processing
- the processor may be a general-purpose processor, and may be implemented by reading software codes stored in a memory.
- the memory may be integrated in the processor, or it may be located outside the processor and exist independently.
- a processor including: an input circuit, an output circuit, and a processing circuit.
- the processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor executes the method provided by any one of the above-mentioned first aspect, second aspect or third aspect.
- the above-mentioned processor can be a chip
- the input circuit can be an input pin
- the output circuit can be an output pin
- the processing circuit can be a transistor, a gate circuit, a flip-flop, and various logic circuits.
- the input signal received by the input circuit may be received and input by, for example but not limited to, the receiver
- the output signal of the output circuit may be, for example but not limited to, output to the transmitter and transmitted by the transmitter
- the circuit may be the same circuit, which is used as an input circuit and an output circuit respectively at different times.
- the present application does not limit the specific implementation manners of the processor and various circuits.
- a communication device including: a logic circuit and an input-output interface, the input-output interface is used to communicate with modules other than the communication device; the logic circuit is used to run computer programs or instructions to perform any of the above-mentioned Aspect any one of the methods provided by Design.
- the communication device may be the admission control network function or the data management network function or the access management network function or the session management function in the above-mentioned first aspect or the second aspect or the third aspect, or include the above-mentioned admission control network function or data
- a device for managing network functions or access management network functions or session management functions or a device contained in the above-mentioned admission control network functions or data management network functions or access management network functions or session management functions, such as a chip.
- the I/O interface may be a code/data read/write interface circuit, or a communication interface, and the I/O interface is used to receive computer programs or instructions (the computer programs or instructions are stored in the memory, may be directly read from the memory, or may through other devices) and transmitted to the input-output interface, so that the input-output interface runs a computer program or instruction to perform the method of any one of the above aspects.
- the communication device may be a chip.
- a computer program product includes: a computer program (also referred to as code, or an instruction), when the computer program is executed, the computer executes the above-mentioned first aspect or the second aspect Or the method provided by any one design in the third aspect.
- a computer program also referred to as code, or an instruction
- a computer-readable medium stores a computer program (also referred to as code, or instruction) when it is run on a computer, so that the computer executes the above-mentioned first or second aspect.
- a computer program also referred to as code, or instruction
- a chip system includes a processor and an interface, configured to support a communication device to realize the functions provided by any one of the designs of the first aspect, the second aspect, or the third aspect.
- the chip system further includes a memory for storing necessary information and data of the aforementioned communication device.
- the system-on-a-chip may consist of chips, or may include chips and other discrete devices.
- a chip device in a fourteenth aspect, includes an input interface and/or an output interface.
- the input interface can realize the receiving function provided by any design in the first aspect or the second aspect or the third aspect
- the output interface can realize any design in the first aspect or the second aspect or the third aspect The send function provided.
- a functional entity is provided, and the functional entity is used to implement the method provided by any one of the above first to third aspects.
- a sixteenth aspect provides a communication system, including the admission control network function or data management network function or access management network function or session management function of the first aspect or the second aspect or the third aspect.
- the technical effect brought about by any one of the design methods from the second aspect to the sixteenth aspect can refer to the technical effect brought about by the above-mentioned first aspect, and will not be repeated here.
- FIG. 1 is a schematic diagram of a possible network architecture applicable to an embodiment of the present application
- Fig. 2 is a schematic flow chart of an ACU
- Fig. 3 is a schematic flow chart of an ACU
- FIG. 4 is a schematic diagram of a communication process applicable to an embodiment of the present application.
- FIG. 5 is a schematic diagram of a communication process applicable to an embodiment of the present application.
- FIG. 6 is a schematic diagram of a first-execution admission control process
- FIG. 7 is a schematic diagram of a first-execution admission control process
- FIG. 8 is a schematic diagram of a communication process applicable to an embodiment of the present application.
- FIG. 9 is a schematic diagram of a communication device applicable to an embodiment of the present application.
- FIG. 10 is a schematic diagram of a communication device applicable to an embodiment of the present application.
- FIG. 11 is a schematic diagram of a communication device applicable to an embodiment of the present application.
- the present application presents various aspects, embodiments or features in terms of a system that can include a number of devices, components, modules and the like. It is to be understood and appreciated that the various systems may include additional devices, components, modules, etc. and/or may not include all of the devices, components, modules etc. discussed in connection with the figures. In addition, combinations of these schemes can also be used.
- the network architecture and business scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute limitations on the technical solutions provided by the embodiments of the present application.
- the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
- UE User equipment
- terminal equipment is a device with wireless transceiver function, which can communicate with one or more Core network (core network, CN) devices communicate.
- Core network Core network
- User equipment may also be called an access terminal, terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, or user device, among others.
- User equipment can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; it can also be deployed on water (such as ships, etc.); it can also be deployed in the air (such as on aircraft, balloons, and satellites, etc.).
- the user equipment can be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smart phone, a mobile phone, a wireless local loop (WLL) Station, personal digital assistant (PDA), etc.
- SIP session initiation protocol
- WLL wireless local loop
- PDA personal digital assistant
- the user equipment can also be a handheld device with wireless communication function, a computing device or other devices connected to a wireless modem, a vehicle device, a wearable device, a drone device or a terminal in the Internet of Things, the Internet of Vehicles, the fifth generation Mobile communication (5th-generation, 5G) network and any form of terminal in the future network, relay user equipment or terminal in the future evolution of the public mobile land network (public land mobile network, PLMN), etc.
- the relay user equipment may be, for example, a 5G residential gateway (residential gateway, RG).
- the user equipment can be a virtual reality (virtual reality, VR) terminal, an augmented reality (augmented reality, AR) terminal, a wireless terminal in industrial control (industrial control), a wireless terminal in self driving (self driving), telemedicine Wireless terminals in remote medical, wireless terminals in smart grid, wireless terminals in transportation safety, wireless terminals in smart city, and smart home wireless terminals, etc.
- the embodiment of the present application does not limit the type or category of the terminal device.
- a network device refers to a device that can provide a wireless access function for a terminal.
- the network device may support at least one wireless communication technology, such as long term evolution (long term evolution, LTE), new radio (new radio, NR) and the like.
- network equipment may include access network equipment.
- the network equipment includes but is not limited to: a next-generation base station or a next-generation node B (generation nodeB, gNB), an evolved node B (evolved node B, eNB) in a 5G network, and a radio network controller (radio network controller, RNC), node B (node B, NB), base station controller (base station controller, BSC), base transceiver station (base transceiver station, BTS), home base station (for example, home evolved node B, or home node B, HNB ), baseband unit (baseband unit, BBU), transceiver point (transmitting and receiving point, TRP), transmitting point (transmitting point, TP), mobile switching center, small station, micro station, etc.
- RNC radio network controller
- node B node B
- base station controller base station controller
- BTS base transceiver station
- home base station for example, home evolved node B, or home node B, H
- the network device may also be a wireless controller, a centralized unit (centralized unit, CU), and/or a distributed unit (distributed unit, DU) in a cloud radio access network (cloud radio access network, CRAN) scenario, or the network device may It is a relay station, an access point, a vehicle-mounted device, a terminal, a wearable device, a network device in future mobile communications or a network device in a future evolved PLMN, etc.
- the network device may include a core network (CN) device, such as an AMF, an SMF, and the like.
- CN core network
- At least one refers to one or more, and multiple refers to two or more.
- PLMN a part operated by an operator
- PLMN is a network established and operated by the government or its approved operators for the purpose of providing land mobile communication services to the public. It is mainly a public network where mobile network operators (MNO) provide mobile broadband access services for users. network.
- MNO mobile network operators
- the PLMN described in the embodiments of the present application may specifically be a network conforming to the requirements of the third generation partnership project (3rd generation partnership project, 3GPP) standard, referred to as a 3GPP network.
- 3GPP network generally includes but is not limited to 5G, a fourth-generation mobile communication (4th-generation, 4G) network, and other future communication systems such as 6G.
- the 5G network has also adjusted its network architecture compared to the 4G network. For example, the 5G network splits the mobility management entity (MME) in the 4G network into multiple network functions including AMF and SMF.
- MME mobility management entity
- FIG. 1 is a schematic diagram of a 5G network architecture, which may include: a user equipment 110 part, a PLMN part and a data network (data network, DN) 150 part.
- PLMN may include: network exposure function (network exposure function, NEF) 131, network storage function (network function repository function, NRF) 132, policy control function (policy control function, PCF) 133, unified data management (unified data management, UDM) ) 134, unified data storage (unified data repository, UDR) 135, network data analysis function (network data analytics function, NWDAF) 136, network slice selection function (network slice selection function, NSSF) 137, authentication server function (authentication server function) , AUSF) 138, AMF 139, session management function (session management function, SMF) 140, network slice authentication and authorization function (Network Slice Specific Authentication and Authorization Function, NSSAAF) 141, network slice admission control function (NSACF) 142, user plane Function (user plane function, UPF) 130, access network (access network, AN) 120, etc.
- the part other than the access network 120 part may be called the core network part.
- the data network DN 150 may also be called a packet data network (packet data network, PDN), and may be deployed within the PLMN or outside the PLMN (such as a third-party network).
- PDN packet data network
- AN 120 also called wireless (Radio) AN, is a sub-network of PLMN, and is an implementation system between service nodes (or network functions) in PLMN and UE110.
- the UE 110 To access the PLMN, the UE 110 first passes through the AN 120, and then connects to the service node in the PLMN through the AN 120.
- the AN 120 in the embodiment of the present application may refer to the access network itself, or refer to the access network equipment, which is not distinguished here.
- the access network device is a device that provides a wireless communication function for the UE 110 , and may also be called an access device, (R)AN device, or network device. It can be understood that the present application does not limit the specific type of the access network device. In systems using different wireless access technologies, the names of devices that function as access network devices may be different.
- the access device may include a CU, a DU, and so on.
- the CU can also be divided into CU-control plane (control plane, CP) and CU-user plane (user plan, UP).
- the access device can also be an open radio access network (open radio access network, O-RAN or Open RAN) architecture, etc. This application does not limit the specific deployment method of the access device .
- a network opening function NEF (also called a network opening function entity) 131 is a control plane function provided by an operator, and is used to enable a third party to use services provided by the network.
- the network storage function NRF 132 is a control plane function provided by the operator, which can be used to maintain real-time information of all network function services in the network.
- the policy control function PCF 133 is a control plane function provided by the operator. It supports a unified policy framework to govern network behavior, and provides policy rules and contract information related to policy decisions to other control functions.
- the unified data management UDM 134 is a control plane function provided by the operator, responsible for storing SUPI, security context (security context), subscription data and other information of the subscriber in the PLMN.
- the unified data storage UDR135 is a control plane network function provided by the PLMN, which is used to support the storage and extraction of UDM subscription data, PCF policy data, open structured data, application data, etc.
- the network data analysis function NWDAF136 is a control plane network function provided by PLMN, which is used to support network operation-related network functions (network function, NF), application functions (application function, AF), network management data collection, data openness, analysis, Machine learning model training, etc.
- network function network function, NF
- application function application function, AF
- network management data collection data openness, analysis, Machine learning model training, etc.
- the network slice selection function NSSF137 is a control plane network function provided by the PLMN, which is responsible for determining a network slice instance, selecting an AMF, and so on.
- the authentication server function AUSF 138 is a control plane function provided by the operator, and is usually used for the first-level authentication, that is, the network authentication between the UE 110 (subscriber) and the PLMN.
- Access and mobility management function AMF 139 is a control plane network function provided by the PLMN, which is responsible for the access control and mobility management of the UE 110 accessing the PLMN, for example, including mobility status management, allocation of user temporary identities, authentication and authorization of users, etc. Function.
- the session management function SMF 140 is a control plane network function provided by the PLMN, and is responsible for managing the PDU session of the UE 110 .
- the PDU session is a channel for transmitting PDUs, and the terminal device needs to transmit data with DN 150 through the PDU session.
- the PDU session can be established, maintained and deleted by the SMF 140.
- SMF 140 includes session management (such as session establishment, modification and release, including tunnel maintenance between UPF 130 and AN 120, etc.), selection and control of UPF 130, service and session continuity (service and session continuity, SSC) mode selection , roaming and other session-related functions.
- the network slice authentication and authorization function NSSAAF141 is a control plane network function provided by the PLMN, and is used to support slice authentication between the UE110 and the DN.
- the network slice admission control function NSACF142 is a network function used by the PLMN to monitor and control the number of UEs registered on the network slice. Usually, the maximum number of UEs that can be served in each network slice monitored and controlled by NSACF is configured on the NSACF.
- the user plane function UPF 130 is a gateway provided by the operator, and is a gateway for communication between the PLMN and the DN 150 .
- the UPF 130 includes functions related to the user plane such as data packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, lawful interception, uplink packet detection, and downlink data packet storage.
- QoS quality of service
- the network functions in the PLMN shown in FIG. 1 may also include other network functions (not shown in the figure), and this embodiment of the present application does not limit other network functions included in the PLMN.
- Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nnssf, Nausf, Namf, Nsmf, Nnssaaf, Nnsacf, N1, N2, N3, N4, and N6 are interface serial numbers.
- the meaning of the above interface serial number may refer to the meaning defined in the 3GPP standard protocol, and the present application does not limit the meaning of the above interface serial number.
- the name of the interface between various network functions in FIG. 1 is only an example. In a specific implementation, the name of the interface of the system architecture may also be another name, which is not limited in this application.
- the mobility management network function in this application may be the AMF 139 shown in FIG. 1, or other network functions having the above-mentioned access and mobility management function AMF 139 in the future communication system.
- the mobility management network function in this application may also be a mobility management entity (mobility management entity, MME) in the LTE system. Understandably, other network functions are also applicable.
- the network architecture diagram shown in FIG. 1 can be understood as a service-based 5G network architecture diagram in a non-roaming scenario.
- this architecture according to the requirements of specific scenarios, different network functions are combined in an orderly manner as needed, which can realize the customization of network capabilities and services, so as to deploy dedicated networks for different services and realize 5G network slicing.
- Network slicing technology can enable operators to respond to customer needs more flexibly and quickly, and support flexible allocation of network resources.
- Slice is network slicing.
- a simple understanding is to divide the operator's physical network into multiple virtual end-to-end networks. Between each virtual network (including devices in the network, access network, transmission network and core network) ) are logically independent, any failure of one virtual network will not affect other virtual networks.
- Instances of different service types may be deployed on different network slices, and different instances (instances) of the same service type may also be deployed on different network slices.
- a slice can consist of a set of network functions (network functions, NFs) and/or sub-networks.
- the subnetwork (R)AN 120, AMF 139, SMF 140, and UPF 130 in Figure 1 can form a slice. It can be understood that only one of each network function is schematically shown in FIG. 1 , but in actual network deployment, there may be multiple or tens of each network function or sub-network. Many slices can be deployed in the PLMN, and each slice can have different performances to meet the requirements of different applications and vertical industries. Operators can "tailor-made" a slice according to the needs of customers in different vertical industries.
- the UE may provide or indicate to the core network the slice that the UE wants to access in an uplink message.
- the uplink message is the message sent by the UE to the network side, such as registration request, service request, periodic registration update, etc. For convenience of description, these uplink messages are described as "request messages" below.
- the indication information of the desired slice is called a requested (network slice selection assistance information set) (NSSAI).
- NSSAI network slice selection assistance information set
- the NSSAI is actually a list or a set, which includes one or more S-NSSAI.
- An S-NSSAI is used to identify a network slice (it can also be a type of network slice), which can also be understood as S-NSSAI is the identification information of the slice.
- NSI-ID Network Slice Instance Identifier/Identity
- S-NSSAI Network Slice Instance Identifier/Identity
- a slice identified by an S-NSSAI can also be instantiated into one or more slice instances (slice instance) , each NSI-ID corresponds to a slice instance.
- an NSI-ID can also be called identification information of a slice, and one S-NSSAI can correspond to multiple NSI-IDs.
- S-NSSAI uses S-NSSAI as an example for description, and does not strictly distinguish or limit S-NSSAI and NSI-ID. The description of S-NSSAI can also be applied to NSI-ID.
- slice-level authentication is a network control function with limited participation by slice customers, that is, to authenticate and authorize terminal devices accessing slices. This application is referred to as “slice authentication" for short.
- the terminal device Before the terminal device is allowed to access the network slice, it first needs to perform a "network-level authentication" with the PLMN network, that is, the PLMN needs to perform authentication based on the contract identification information used by the terminal device to sign with the PLMN. This authentication is usually called Primary authentication. Secondly, the PLMN needs to perform authentication based on the subscription identifier used by the terminal device and the DN, that is, "slice authentication".
- the NSACF mentioned above is a network function used by the PLMN to monitor and control the number of terminal devices (or the number of PDU sessions) registered on the network slice.
- the PLMN may first configure the maximum number of terminal devices (or PDU sessions) that can be served in each network slice monitored by the NSACF on one or more NSACFs, or Quota.
- NSACF When the network is ready to authorize a new terminal device to access a certain slice (or allow a new PDU session to be established in a certain slice), NSACF first determines whether the network slice is It is also possible to accept the terminal device's access request (or the terminal device's PDU session establishment request), and store and update the number of admitted terminals (or the number of established PDU sessions) in the slice in real time.
- the network slicing here refers to the network slicing that requires admission control (or PDU session quantity control). In the following description, unless otherwise specified, all network slices belong to such slices that require admission (or number of PDU sessions)
- ACU basic process of availability check and update
- AMF triggers an ACU process.
- This process will be triggered when AMF performs processes such as registration, de-registration, configuration update (UE Configuration Update, UCU), re-authentication and authorization revocation initiated by the slice authentication server for the terminal device.
- processes such as registration, de-registration, configuration update (UE Configuration Update, UCU), re-authentication and authorization revocation initiated by the slice authentication server for the terminal device.
- time involved in the embodiments of the present application may mean before, during, or after the execution of the process, which will be described uniformly here and will not be described in detail below.
- the AMF When the AMF decides to trigger the ACU process, it will first verify that the slice identified as S-NSSAI is a slice that the PLMN allows the terminal device to access, that is, the AMF verifies that the S-NSSAI is in the (corresponding to the terminal device) "NSSAI list allowed for access" "(Allowed NSSAI). After the verification is successful, the AMF will send an ACU request for the S-NSSAI to the NSACF, that is, execute S202.
- S202 The AMF sends an ACU request to the NSACF.
- the NSACF receives the ACU request.
- the ACU request may include UE identity, S-NSSAI, access type (access type) and update flag (flag).
- the update identification flag is used to indicate the UE's request for S-NSSAI, which is used to request "number increase” (such as when the UE registers the slice S-NSSAI) or request "number reduction” (such as when the UE registers the slice S-NSSAI) .
- the S-NSSAI may refer to the S-NSSAI of the network slice provided by the visited network (ie, visited PLMN), or may refer to the UE's affiliation corresponding to the network slice of the visited network.
- the S-NSSAI of the network (home PLMN), that is, the mapped S-NSSAI (Mapped S-NSSAI), can also include the above two S-NSSAIs at the same time, that is, the S-NSSAI of the visited network and the Mapped S-NSSAI of the home network .
- S203 The NSACF responds to the ACU request according to the number of currently admitted terminal devices.
- the NSACF may update the number of terminals registered on the slice identified as S-NSSAI.
- the NSACF checks whether the UE corresponding to the UE identifier has been included in the admitted UE list. If yes, the admitted UE counter remains unchanged. If not, NSACF continues to check whether the number of currently admitted UEs is less than the admission quota of the slice S-NSSAI. If the quota is sufficient (that is, the number of terminals accessing the slice has not reached the maximum number of admitted terminals in the slice), NSACF will The UE is included in the admitted UE list, and the count value of the admitted UE counter is increased by 1. If the quota is full, the counter remains unchanged, and responds to the AMF that the slice quota is full.
- the NSACF deletes the UE identification from the admitted UE list, and decreases the count value of the counters of all slice S-NSSAIs admitted to the UE by 1.
- S204 The NSACF sends an ACU response to the AMF.
- the NSACF will include the number update information in the ACU response. If it is determined that the quota is full, the NSACF responds to the ACU including the information that the slice quota is full.
- the AMF can perform corresponding processing according to the received ACU response. For example, when the slice quota is full, the AMF may reject the UE's request to access the slice S-NSSAI, and notify the UE of the rejection reason that the slice quota is full. Optionally, the AMF may also notify the UE to wait for a period of time (and send the waiting time) and then re-request for access.
- AMFx indicates that the NF has been maliciously controlled, or is controlled by an insider (insider), so as to send a false message, which can cause NSACF to incorrectly update the number of terminal devices or PDU sessions registered in the network slice.
- NSACF mistakenly believes that the slice quota is full, and when AMF sends an ACU request, because the slice has no quota, NSACF refuses UE access or refuses to establish a PDU session, resulting in the failure of terminal equipment to access or establish a PDU session normally, network slicing The service is degraded or cannot be provided normally.
- an embodiment of the present application provides a communication method.
- the admission control network function receives a first message, the first message includes first parameter information used to update the number of terminal devices or sessions in the first network slice, and the admission control network function performs the first parameter information Check the authenticity of the first parameter information, if the first parameter information is true, the admission control network function can update the number of terminal devices or sessions in the first network slice, here by checking the authenticity of the received first parameter The verification can reduce the wrong update of the network slice configuration caused by false news, ensure that the terminal equipment can normally access the network slice or can establish a PDU session normally, improve the stability of the service provided by the network slice, and improve the security of the network.
- FIG. 4 is a possible communication method, including the following steps:
- the admission control network function receives a first message.
- the admission control network function may be NSACF in 5G.
- the first message includes first parameter information for updating the number of terminal devices or sessions in the first network slice.
- the first message may be an ACU request message.
- the first parameter information may include but not limited to one or more of the following information: terminal device identifier, first network slice identifier, access management network function identifier, first indication information requesting registration or de-registration, request to establish a session or Release the second indication information of the session, the access type of the terminal device, the session identifier, the data network identifier, the session management network function identifier, and the status of the session.
- terminal device identifier terminal device identifier
- first network slice identifier access management network function identifier
- first indication information requesting registration or de-registration, request to establish a session or Release the second indication information of the session
- the access type of the terminal device the session identifier
- the data network identifier the data network identifier
- the session management network function identifier the status of the session.
- the access management network function (such as AMF) sends the first message to the admission control network function, and the first parameter information is used to update the number of terminal devices in the first network slice.
- the session management network function (such as SMF) sends the first message to the admission control network function, and the first parameter information is used to update the number of sessions in the first network slice.
- the first message is sent when the admission control mode performed first is in an inactive state, and the number of terminal devices requesting to access the first network slice reaches a second number threshold.
- the second quantity threshold may be any positive integer, which is not limited here.
- S402 The admission control network function verifies the authenticity of the first parameter information.
- the process of verifying the authenticity of the first parameter information may be to match the real parameter information stored in the network (hereinafter referred to as the second parameter information) with the first parameter information, or to check the consistency.
- the false message may include the following false parameters, so the verification can be performed on the parameter information that may generate false parameters:
- False parameter 1 Use an unauthorized terminal device identifier.
- a fake terminal device identifier is used, which may be a terminal device identifier generated in any manner.
- Another example is the use of the real terminal device identity intercepted by the AMFx, but the real terminal device identity has not subscribed to the first network slice.
- Another example is to use a terminal device identifier that subscribes to network slicing, but the serving network where the terminal device identifier is located does not match the serving network to which the NF that sent the first message belongs to.
- the NF that sends the terminal device ID can pass false messages (fake Parameter 1), the number of terminal devices or sessions is falsely reported, so that the admission control network function mistakenly believes that the quota of the network slice is full, and refuses the UE to access the network slice or establish a session from other NFs, causing the terminal device to suffer from denial of service (denial of service, DoS) attack.
- denial of service denial of service
- the admission control network function can verify the authenticity of the terminal device identification.
- the terminal device identifier may be a UE ID, and/or an Internet Protocol (internet protocol, IP) address of the UE.
- IP Internet Protocol
- False parameter 2 Use network slices signed by non-terminal devices.
- the NF sending the first message can attack network slices served by other NFs by sending false parameter two.
- the admission control network function can verify the authenticity of the network slice identifier.
- the network slice identifier may be S-NSSAI.
- the indication information for requesting to increase the number may be indication information for the terminal device to request registration or request to create a session, and the indication information for requesting to decrease the number may be indication information for the terminal device to request de-registration or request to release the session.
- the NF that sent the first message eavesdropped on the messages sent by other NFs, and directly tampered with the indication information in the messages of other NFs, so that the number of terminal devices or the number of sessions saved by NSACF did not match the real situation, resulting in terminal devices being unable to access network slices or The session cannot be established or the service is terminated due to network overload.
- the admission control network function can verify the authenticity of the indication information, where the indication information can be the first indication information (such as update identification flag1) requesting registration or de-registration, and/or the indication information can be the request to create a session or Release the second indication information of the session (for example, update flag2).
- the indication information can be the first indication information (such as update identification flag1) requesting registration or de-registration, and/or the indication information can be the request to create a session or Release the second indication information of the session (for example, update flag2).
- False parameter four use the wrong access type (access type).
- a terminal device uses the real terminal device ID and network slice ID, but using the wrong service type, doubles the number of terminal devices or sessions accessing the network slice.
- a terminal device repeatedly accesses only one quota, but under multiple access types, a terminal device uses different types of repeated access to occupy multiple quotas. For terminal devices, each type of access will occupy a certain amount of quota.
- the NF that sends the first message directly tampers with the access type in the messages of other NFs by eavesdropping on the messages sent by other NFs, and can falsely report the number of terminal devices. When the quota reaches the maximum number, other legal terminal devices cannot be accessed.
- the admission control network function can therefore verify the authenticity of the access type.
- the admission control network function may itself verify the authenticity of the first parameter information.
- the admission control network function may store real second parameter information.
- admission control network function verifies the authenticity of the first parameter information
- one or more of the following methods may be used:
- the admission control network function checks whether the terminal device corresponding to the terminal device identifier has subscribed to the service of the network to which the first network slice belongs. If the terminal device corresponding to the terminal device identifier subscribes to the service of the network to which the first network slice belongs, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device corresponding to the terminal device identifier does not subscribe to the first network
- the service of the network to which the slice belongs may determine that the terminal device identifier and/or the identifier of the first network slice is false.
- the admission control network function checks whether the terminal device corresponding to the terminal device identifier has subscribed to the service of the home network corresponding to the first network slice. This may be for a scenario when the terminal device roams to the visited network and the first network slice is provided by the visited network.
- the contracted network of the roaming terminal device is the home network, and the identifier of the subscribed network slice is Mapped S-NSSAI, which has a mapping relationship with the identifier S-NSSAI of the first network slice. Therefore, in the roaming scenario, the admission control network function can check whether the terminal device has subscribed to the home network.
- the terminal device corresponding to the terminal device identifier subscribes to the service of the home network corresponding to the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true;
- the service of the home network corresponding to a network slice may determine that the terminal device identifier and/or the identifier of the first network slice is false.
- the admission control network function checks whether the terminal device has subscribed to the service of the first network slice. If the terminal device subscribes to the service of the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device does not subscribe to the service of the first network slice, it can be determined that the terminal device identifier and/or The flag of a network slice is false.
- the admission control network function checks whether the terminal device has subscribed to the service of the network slice in the home network corresponding to the first network slice. If the terminal device subscribes to the service of the network slice of the home network corresponding to the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device is not subscribed to correspond to the first network slice. The service of the network slice of the home network may determine that the identifier of the terminal device and/or the identifier of the first network slice is false.
- the admission control network function checks whether the terminal device is registered with the network to which the first network slice belongs. If the terminal device is registered with the network to which the first network slice belongs, it may be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device is not registered with the network to which the first network slice belongs, it may be determined that the terminal device identifier and/or the identifier of the first network slice is true. Or the identification of the first network slice is false.
- the admission control network function checks whether the terminal device has access to the first network slice. Accessing the first network slice by the terminal device may mean that the terminal device has received authorization information sent by the network to allow access to the first network slice, for example, the identifier S-NSSAI of the first network slice is in the Allowed NSSAI list of the terminal device. If the terminal device accesses the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true, and if the terminal device accesses the first network slice, it can be determined that the terminal device identifier and/or the first network slice Slice's id is false.
- the admission control network function verifies whether the terminal device has registered with the network through the access management network function corresponding to the access management network function identifier. If the terminal device registers with the network through the access management network function corresponding to the access management network function identifier, it may be determined that the terminal device identifier and/or the access management network function identifier is true. If the terminal device has not registered with the network through the access management network function corresponding to the access management network function identifier, it may be determined that the terminal device identifier and/or the access management network function identifier are false.
- the admission control network function checks whether the terminal device establishes a session through the session management network function corresponding to the session management network function identifier. If the terminal device establishes a session through the session management network function corresponding to the session management network function identifier, it may be determined that the terminal device identifier and/or the session management network function identifier is true. If the terminal device has not established a session by accessing the session management network function corresponding to the management network function identifier, it may be determined that the terminal device identifier and/or the session management network function identifier are false.
- the admission control network function verifies whether the terminal device has accessed the first network slice through the access management network function. If the terminal device accesses the first network slice through the access management network function, it may be determined that one or more parameter information among the terminal device identifier, the access management network function identifier, and the identifier of the first network slice is true, and if the terminal device does not Access the first network slice through the access management network function, or if the terminal device does not access the first network slice through the access management network function, determine the identifier of the terminal device, the identifier of the access management network function, and the identifier of the first network slice One or more of the parameter information in is false.
- the admission control network function checks whether the terminal device has established a session of the first network slice through the session management network function. If the terminal device establishes a session on the first network slice through the session management network function, it may be determined that one or more parameter information among the terminal device identifier, the session management network function identifier, and the identifier of the first network slice is true, and if the terminal device does not By establishing a session in the first network slice through the session management network function, it may be determined that one or more parameter information among the terminal device identifier, the session management network function identifier, and the identifier of the first network slice is false.
- the admission control network function checks whether the terminal device is connected to the network through the access type. If the terminal device accesses the network through this access type, it can be determined that the terminal device identifier and/or access type is true; if the terminal device does not access the network through this access type, it can be determined that the terminal device identifier and/or access type false.
- the access type may include access through a 3GPP network, and/or access through a non-3GPP network. Accessing through a non-3GPP network may include accessing through a local area network (such as wireless fidelity (Wi-Fi)), and/or accessing through a fixed network (such as a fiber-optic network (Fiber-Optic network)), and the like.
- the admission control network function checks whether the registration or de-registration request indicated by the first indication information matches the stored registration status of the terminal device. If they match, it may be determined that the first indication information is true, and if they do not match, it may be determined that the first indication information is false. For example, the first indication information is used to request de-registration, but the actual registration state of the terminal device saved in the network is unregistered, at this time it can be considered that the de-registration request indicated by the first indication information does not match the saved registration state of the terminal device, The first indication information is false. However, the first indication information is used to request registration, but the actual registration status of the terminal device saved in the network is registered.
- the terminal device Since the current standard allows the terminal device to re-register, the terminal device only occupies a quota of one quantity, and the number of admitted terminal devices The counter remains unchanged. Therefore, in this case, it can be considered that the registration request indicated by the first indication information matches the stored registration status of the terminal device, and the first indication information is true.
- the first indication information is used to request de-registration, the actual registration status of the terminal device stored in the network is registered, and the first indication information is used to request registration, and the actual registration status of the terminal device stored in the network is unregistered, which can be It is considered that the registration or de-registration request indicated by the first indication information matches the saved registration state of the terminal device, and the first indication information is true.
- the admission control network function checks whether the second indication information indicates whether the request for establishing a session or releasing a session matches the saved session state of the terminal device. If they match, it may be determined that the second indication information is true, and if they do not match, it may be determined that the second indication information is false. For example, the second indication information is used to request the release of the session, but the actual session state of the terminal device saved in the network is not created. At this time, it can be considered that the release session request indicated by the second indication information does not match the saved actual session state, and the second The indication is false. The second indication information is used to request the establishment of a session, but the actual session status saved in the network is created.
- the session Since the current standard allows the establishment of multiple sessions, but multiple sessions correspond to the same session ID, the session only occupies a quota of one quantity. , the session counter remains unchanged, so in this case, it can be considered that the second indication information indicates that the session establishment request matches the saved session state, and the second indication information is true.
- the second indication information is used to request the release of the session, the actual session state saved in the network is created, and the second indication information is used to request the establishment of the session, the actual session state saved in the network is not created, which can be regarded as the second indication The request for establishing a session or releasing a session indicated by the information matches the saved session state, and the second indication information is true.
- the admission control network function checks whether the session identifier (or the session corresponding to the session identifier) exists. If the session identifier (or the session corresponding to the session identifier) exists, it can be determined that the session identifier is true; if the session identifier (or the session corresponding to the session identifier) does not exist, it can be determined that the session identifier is false.
- the session ID can be PDU Session ID.
- the admission control network function checks whether the session identifier (or the session corresponding to the session identifier) belongs to the terminal device. If the session identification (or session) belongs to the terminal equipment, it can be determined that the session identification and/or the terminal equipment identification is true, and if the session identification (or session) does not belong to the terminal equipment, it can be determined that the session identification and/or the terminal equipment identification are false .
- the admission control network function checks whether the session identifier (or the session corresponding to the session identifier) belongs to the first network slice. If the session identifier or the session belongs to the first network slice, it may be determined that the session identifier and/or the identifier of the first network slice is true, and if the session identifier or the session does not belong to the first network slice, the session identifier and/or the first network slice may be determined flag is false.
- the admission control network function checks whether the session corresponding to the session identifier is managed by the session management network function corresponding to the session management network function identifier. If the session corresponding to the session identifier belongs to the session management network function management corresponding to the session management network function identifier, it can be determined that the session identifier and/or the session management network function identifier is true; if the session corresponding to the session identifier does not belong to the session management network function identifier corresponding The session management network function management may determine that the session identification and/or the session management network function identification is false.
- the admission control network function checks whether the state of the session is consistent with the current state of the session. If the state of the session is consistent with the current state of the session, it can be determined that the state of the session is true; if the state of the session is inconsistent with the current state of the session, it can be determined that the state of the session is false.
- the admission control network function checks whether the first network slice matches the data network corresponding to the data network identifier. If the first network slice matches the data network corresponding to the data network identifier, it can be determined that the identifier of the first network slice and/or the data network identifier is true; if the first network slice does not match the data network corresponding to the data network identifier, it can be determined that The identifier of the first network slice and/or the data network identifier is false.
- the data network identifier may be a data network name (data network name, DNN) and/or a data network access identifier (data network access identifier, DNAI).
- the admission control network function may send a second message to the data management network function (such as UDM and/or UDR), and the second message is used to Requesting second parameter information, the second parameter information is used to verify the authenticity of the first parameter information; and receiving a third message, the third message includes verifying the second parameter information.
- the admission control network function may not store real second parameter information.
- the admission control network function may request other network functions to verify the authenticity of the first parameter information.
- other network functions may be data management network functions (such as UDM and/or UDR)
- the admission control network function may send a second message to the data management network function, and the second message is used to request to verify the first parameter information
- the data management network function sends a third message to the admission control network function, the third message includes a verification result of the first parameter information, and the verification result includes whether the first parameter information is true or false.
- the admission control network function may not store real second parameter information.
- the data management network function verifies the first parameter information according to the acquired second parameter information of the terminal device or session.
- the second message may include one or more of the following information: terminal device identifier, instruction information for verifying the subscription status of the terminal device, instruction information for verifying the access status of the terminal device, and the identifier of the first network slice , the slice identifier of the home network corresponding to the first network slice, the access management network function identifier, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, the access type of the terminal device, Session ID, data network ID, session management network function ID, session status.
- the data management network function verifies the first parameter information according to the obtained second parameter information of the terminal device or session.
- one or more of the following methods may be adopted:
- the data management network function checks the subscription status of the terminal device according to the instruction information for checking the subscription status of the terminal device.
- the subscription status of the terminal device may be the status of whether the terminal device has subscribed to the service of the network to which the first network slice belongs, or may be the status of whether the terminal device has subscribed to the service of the home network corresponding to the first network slice, or may be Whether the terminal device has subscribed to the service of the first network slice, or whether the terminal device has subscribed to the service of the network slice of the home network corresponding to the first network slice.
- the data management network function checks whether the terminal device corresponding to the terminal device identifier has subscribed to the service of the network to which the first network slice belongs. If the terminal device corresponding to the terminal device identifier subscribes to the service of the network to which the first network slice belongs, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device corresponding to the terminal device identifier does not subscribe to the first network
- the service of the network to which the slice belongs may determine that the terminal device identifier and/or the identifier of the first network slice is false.
- the data management network function checks whether the terminal device has subscribed to the service of the first network slice. If the terminal device subscribes to the service of the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device does not subscribe to the service of the first network slice, it can be determined that the terminal device identifier and/or The flag of a network slice is false.
- the data management network function checks whether the terminal device has subscribed to the service of the network slice in the home network corresponding to the first network slice. If the terminal device subscribes to the service of the network slice of the home network corresponding to the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true; if the terminal device is not subscribed to correspond to the first network slice.
- the service of the network slice of the home network may determine that the identifier of the terminal device and/or the identifier of the first network slice is false.
- the data management network function checks the access status of the terminal equipment according to the instruction information for checking the access status of the terminal equipment.
- the access status of the terminal device may be whether the terminal device has registered with the network to which the first network slice belongs, or whether the terminal device has accessed the first network slice.
- the data management network function checks whether the terminal device has registered with the network to which the first network slice belongs. If the terminal device has registered the network to which the first network slice belongs, it may be determined that one or more parameter information among the terminal device identifier, the identifier of the first network slice, and the slice identifier of the home network corresponding to the first network slice is true, if the terminal The device has not registered the network to which the first network slice belongs, and may determine that one or more parameter information among the terminal device identifier, the identifier of the first network slice, and the slice identifier of the home network corresponding to the first network slice is false.
- the data management network function checks whether the terminal device is connected to the first network slice. If the terminal device accesses the first network slice, it can be determined that the terminal device identifier and/or the identifier of the first network slice is true, and if the terminal device accesses the first network slice, it can be determined that the terminal device identifier and/or the first network slice Slice's id is false.
- the data management network function checks whether the terminal device has registered with the network through the access management network function corresponding to the access management network function identifier. If the terminal device registers with the network through the access management network function corresponding to the access management network function identifier, it may be determined that the terminal device identifier and/or the access management network function identifier is true. If the terminal device has not registered with the network through the access management network function corresponding to the access management network function identifier, it may be determined that the terminal device identifier and/or the access management network function identifier are false.
- the data management network function checks whether the terminal device has established a session through the session management network function corresponding to the session management network function identifier. If the terminal device establishes a session through the session management network function corresponding to the session management network function identifier, it may be determined that the terminal device identifier and/or the session management network function identifier is true. If the terminal device does not establish a session through the session management network function corresponding to the session management network function identifier, it may be determined that the terminal device identifier and/or the session management network function identifier are false.
- the data management network function checks whether the terminal device has accessed the first network slice through the access management network function. If the terminal device accesses the first network slice through the access management network function, it may be determined that one or more parameter information among the terminal device identifier, the access management network function identifier, and the identifier of the first network slice is true, and if the terminal device does not Access the first network slice through the access management network function, or if the terminal device does not access the first network slice through the access management network function, determine the identifier of the terminal device, the identifier of the access management network function, and the identifier of the first network slice One or more of the parameter information in is false.
- the data management network function checks whether the terminal device has established a session of the first network slice through the session management network function. If the terminal device establishes a session on the first network slice through the session management network function, it may be determined that one or more parameter information among the terminal device identifier, the session management network function identifier, and the identifier of the first network slice is true, and if the terminal device does not By establishing a session in the first network slice through the session management network function, it may be determined that one or more parameter information among the terminal device identifier, the session management network function identifier, and the identifier of the first network slice is false.
- the data management network function checks whether the terminal device is connected to the network through the access type. If the terminal device accesses the network through this access type, it can be determined that the terminal device identifier and/or access type is true; if the terminal device does not access the network through this access type, it can be determined that the terminal device identifier and/or access type false.
- the data management network function checks whether the registration or de-registration request indicated by the first indication information matches the stored registration status of the terminal device. If they match, it may be determined that the first indication information is true, and if they do not match, it may be determined that the first indication information is false.
- the data management network function checks whether the request for establishing a session or releasing a session indicated by the second indication information matches the saved session state of the terminal device. If they match, it may be determined that the second indication information is true, and if they do not match, it may be determined that the second indication information is false.
- the data management network function checks whether the session identifier (or the session corresponding to the session identifier) exists. If the session identifier exists, it can be determined that the session identifier is true, and if the session identifier does not exist, it can be determined that the session identifier is false.
- the data management network function checks whether the session identifier (or the session corresponding to the session identifier) belongs to the terminal device. If the session ID (or the session corresponding to the session ID) belongs to the terminal device, it can be determined that the session ID and/or the terminal device ID is true; if the session ID (or the session corresponding to the session ID) does not belong to the terminal device, the session ID can be determined and/or end device identification is false.
- the data management network function checks whether the session identifier (or the session corresponding to the session identifier) belongs to the first network slice. If the session identifier (or the session corresponding to the session identifier) belongs to the first network slice, it may be determined that the session identifier and/or the identifier of the first network slice is true; if the session identifier (or the session corresponding to the session identifier) does not belong to the first network slice , it may be determined that the session identifier and/or the identifier of the first network slice is false.
- the data management network function checks whether the session corresponding to the session identifier is managed by the session management network function corresponding to the session management network function identifier. If the session corresponding to the session identifier belongs to the session management network function management corresponding to the session management network function identifier, it can be determined that the session identifier and/or the session management network function identifier is true; if the session corresponding to the session identifier does not belong to the session management network function identifier corresponding The session management network function management may determine that the session identification and/or the session management network function identification is false.
- the data management network function checks whether the state of the session is consistent with the current state of the session. If the state of the session is consistent with the current state of the session, it can be determined that the state of the session is true, and if the state of the session is consistent with the current state of the session, it can be determined that the state of the session is false.
- the data management network function checks whether the first network slice matches the data network corresponding to the data network identifier. If the first network slice matches the data network corresponding to the data network identifier, it can be determined that the identifier of the first network slice and/or the data network identifier is true; if the first network slice does not match the data network corresponding to the data network identifier, it can be determined that The identifier of the first network slice and/or the data network identifier is false.
- the first parameter information includes one or more types of information, it may be determined that the first parameter information is true when any one type of information is true. If any information is false, it may be determined that the first parameter information is false.
- S402 is executed to avoid increasing the processing burden of NF due to frequent verification of a large amount of first parameter information received at the same time or within a short period of time, affecting NF processing efficiency.
- Satisfying the first condition includes one or more of the following: the duration of the timer reaches the first duration, the number of times the first message is received reaches the first threshold, the number of connected terminal devices or sessions reaches the first threshold, Indication information (such as third indication information) triggering verification is received.
- a timer when triggered by time, can be preset in the admission control network function, and the timer can be triggered to verify the received first parameter information according to the set time interval, that is, the duration of the timer reaches the first duration .
- a counter can be preset in the admission control network function to count the first message received, and check the first parameter information according to the set number of times interval, that is, the number of times the first message is received The first count threshold is reached.
- the counter in the admission control network function counts the number of admitted terminal devices or sessions, and for every certain number of admitted terminal devices or sessions, the first parameter information A check is performed, that is, the number of connected terminal devices or sessions reaches a first number threshold.
- the admission control network function receives indication information triggering verification from other NFs, it verifies the received first parameter information.
- the other NF may be an NWDAF or an operation administration and management (OAM).
- the value of the first duration is any positive number, which is not limited here.
- the first number threshold can be any positive integer, which is not limited here.
- the first number threshold may be any positive integer, and there is no limitation here.
- the first number threshold and the second number threshold may be the same or different. It can be understood that the counter involved in this embodiment of the present application may be counting up or counting down, and the timer may be counting up or counting down.
- the admission control network function updates the number of terminal devices or sessions in the first network slice.
- the admission control network function performs processing according to insufficient quota of the first network slice.
- the optional admission control network function can notify the OAM of abnormal events, etc.
- the following uses the first parameter information to update the number of terminal devices in the first network slice as an example, referring to Figure 5, including the following steps:
- S501 The AMF sends an ACU request to the NSACF.
- the ACU request includes terminal equipment identification UE ID, identification S-NSSAI of the first network slice, first indication information flag and access type parameter information such as access type.
- AMF and NSACF can interact based on a service based interface (service based interface, SBI).
- the AMF can also include a token (token) in the ACU message for the NSACF to verify the identity of the AMF, and the token can also include the AMF ID.
- token token
- the identifier S-NSSAI of the first network slice may be the identifier of the first network slice of the home network of the terminal device, or may be the slice identifier of the network slice of the visited network of the terminal device.
- the identifier of the first network slice may also include two identifiers of the first network slice, one is the slice identifier S-NSSAI of the visited network, and the other is the corresponding slice identifier of the home network, that is, Mapped S -NSSAI.
- S502 The NSACF sends a verification request message to the UDM.
- the NSACF and the UDM may first perform authentication and authorization through the NRF based on the SBI, and the NSACF and the UDM may interact in authentication and authorization.
- the subscription verification request message is used to request the UDM to verify the authenticity of the first parameter information, and determine whether the first parameter information has parameter falsification.
- the Subscription Verification Request message may include UE ID.
- the subscription verification request message may also include one or more of the following: indication information for verifying the subscription state of the UE, indication information for verifying the access state of the UE, one or more S-NSSAI , AMF ID, etc.
- “one or more S-NSSAIs” in this application may include one or more S-NSSAIs of visited networks, or one or more S-NSSAIs of home networks, or include one or more S-NSSAIs of visited networks S-NSSAI and one or more S-NSSAIs of the home network, or include one or more S-NSSAIs of the visited network and the corresponding Mapped S-NSSAI of the home network.
- the AMF ID refers to the AMF that sends the ACU request message to the NSACF in step S501.
- NSACF can obtain it from the token in the ACU request message. It should be noted that this application does not limit how the NSACF obtains the ID of the AMF.
- the subscription verification request message may also include at least the UE ID.
- the subscription verification request message may also include one or more S-NSSAIs.
- the subscription verification request message may also include at least the UE ID.
- the subscription verification request message may also include one or more of the following: one or more S-NSSAI, AMF ID, and UE access type.
- the UDM may indicate the verification of one or both states by default, Or the UDM can be pre-specified or configured to perform the verification of one of the states by default.
- the UDM may also determine the first parameter information to be verified according to the first parameter information included in the subscription verification request message.
- the subscription verification request message includes the access type and the AMF ID, and the UDM determines that the access type and the status of the terminal access (from which AMF or network to access) need to be verified.
- the UDM stores the subscription data of the UE but does not store the access state of the UE.
- the UDM may request the UDR to verify the access state of the UE, and S503 is executed. It can be understood that the UDM may verify the subscription state and/or the access state of the UE, and the UDR may also verify the subscription state and/or the access state of the UE.
- S503 the UDM sends an access state verification request message to the UDR.
- the access state verification request message sent by the UDM can be used to obtain the access state in the UDR, and correspondingly, the access state verification result includes the access state stored in the UDR.
- the access state verification request sent by the UDM may be used to request the UDR to verify the access state, and correspondingly, the access state verification result includes the verification result of the access state determined by the UDR.
- the UDM can perform the following operations: if the UDM determines to verify the subscription status of the UE, the UDM can obtain the UE ID from the NSACF (such as in the message in step 502), and query the UE's subscription stored in the UDM. data.
- the subscription data includes UEs that have signed contracts with the network.
- UDM can determine whether the UE to be queried corresponding to the UE ID is a subscriber, that is, UDM can verify whether the UE ID is a real UE ID, that is, whether the UE ID belongs to A subscribed UE, or a legal UE.
- the subscription data stored in the UDM may also include slice information subscribed by the UE, for example, the slice information subscribed by the UE may be included in the "Subscribed S-NSSAIs" information element (information element, IE) of the UDM.
- the UDM will list the S-NSSAI list corresponding to the slice identifiers subscribed by the UE, including S-NSSAI-1 and S-NSSAI-2.
- UDM can determine that S-NSSAI-1 has passed the verification (UE has subscribed to this slice), S-NSSAI- 3 The verification fails (the UE has not subscribed to the slice).
- the UDM refers to the UDM in the home network of the UE.
- the UDM When executing S503 and S504, the UDM does not necessarily store all the state information of the UE. In this case, the UDM can perform the following operations:
- the UDM can determine the network to which the AMF belongs based on the AMF ID (that is, the PLMN ID to which it belongs), for example, the PLMN ID is PLMN-4.
- the UDM can determine which PLMN network the S-NSSAI belongs to according to the slice identifier S-NSSAI subscribed by the UE. For example, the S-NSSAI-1 subscribed by the UE belongs to the PLMN-1, and the S-NSSAI-2 subscribed by the UE belongs to the PLMN-2.
- UDM determines that PLMN-4 is different from PLMN-1 and PLMN-2 respectively, so it can be determined that the slice information signed by AMF and UE is inconsistent, and the verification fails.
- the UE accesses the serving network before accessing the slice (the serving network refers to the visited network that the UE accesses when roaming, or the UE accesses the The AMF of the home network accessed during non-roaming) performs primary authentication and generates related keys, and the AMF ID will be stored in UDM or UDR. Therefore UDM can compare the stored AMF ID of the UE serving the UE (mainly authenticated by the AMF) with the AMF ID in the subscription verification request message. If they are consistent, the verification is passed, otherwise the verification is not passed.
- the PLMN ID can also be verified by comparing the current (or primary authenticated) PLMN ID of the UE stored in the UDM with the PLMN ID corresponding to the AMF in the subscription verification request message. It should be noted that, if no relevant information is stored in the UDM, the UDM can be obtained through the UDR, that is, by executing S503, the access state verification request message is sent to the UDR. There are multiple IEs in the UDR that store PLMN ID information.
- IE “UE Current PLMN” (“UE Current PLMN”) includes the current PLMN ID, and IE “UE Roaming status” (“UE Roaming status”) Including the PLMN ID of the service network to which the UE currently roams, and whether the network is the home network (home PLMN).
- UE Current PLMN includes the current PLMN ID
- UE Roaming status (“UE Roaming status”) Including the PLMN ID of the service network to which the UE currently roams, and whether the network is the home network (home PLMN).
- This embodiment does not limit which IE in the UDR is used to acquire the current PLMN or AMF information.
- UDR stores the current access type of the UE (3GPP access or non-3GPP access), if the subscription verification request message includes terminal The access type of the device indicates that the access type is required to be verified. UDM can verify the request message to the UDR access status through S503. If the access type stored in the UDR is consistent with the access type in the subscription verification request message, if they are consistent Then it is determined that the verification is passed, otherwise the verification is not passed.
- UDR stores the current registration status of the UE, which can be used to verify whether the registration status indicated by the flag in the subscription verification request message is true or false. For example, UDR also saves the "registration state" IE ("UE registration state”) about UE access, which shows whether the current state of the UE is “registered” (“Registered”) or “deregistered” (“Deregistered”) ). When the UE is in the "de-registered" state, it means that the UE does not access any slice and does not occupy the admission quota of any slice.
- the NSACF handles it according to the fact that the network slice does not have an admission quota, or notifies the network management function or the entity OAM, for example, notifies that there is an abnormal event.
- S507 The NSACF sends an ACU response to the AMF.
- all or part of the process of verifying parameter information can be implemented by NSACF, or by UDM, or by UDR.
- the verification process of the parameter information is implemented by the NSACF
- what the UDM sends to the NSACF in S505 is not the verification result but the second parameter information, which is used to verify the authenticity of the first parameter information.
- the admission control network function may not store real second parameter information.
- the verification process of the UE state information is implemented by the UDM
- what the UDR sends to the UDM in S504 is not the verification result but the second parameter information, which is used to verify the state of the UE.
- the AMF is used as an example to interact with the NSACF to control the number of UEs in a slice.
- the same method is also applicable to the ACU process of interaction between SMF and NSACF, which is to control the number of PDUs in the slice.
- the parameters of the relevant PDU session stored in UDM and UDR can be used for verification, that is, the first parameter information of the above verification needs to be replaced with the first parameter information of the relevant PDU session.
- the UDM stores the PDU session, PDU session identifier (PDU Session ID), DN name (DNN), and SMF ID (such as SMF IP Address or SMF NF ID) that the UE has established.
- PDU Session ID PDU session identifier
- DNN DN name
- SMF ID such as SMF IP Address or SMF NF ID
- UDR stores the PDU session established by UE, UE IP address (UE IP Address), PDU session status (PDU Session status), DN access ID (DN access identifier, DNAI), etc., and similar verification can be performed. That is, as the first parameter information in step 502, one-by-one verification is performed, which will not be repeated here.
- the admission control network function receives a first message, the first message includes first parameter information used to update the number of terminal devices or sessions in the first network slice, and the admission control network function performs the first parameter information Verify the authenticity of the first parameter information. If the first parameter information is true, the admission control network function can update the number of terminal devices or sessions in the first network slice. If the first parameter information is false, it means that the first parameter information For falsified wrong information, the admission control network function does not update the number of terminals or sessions in the first network slice.
- verifying the authenticity of the received first parameter it is possible to reduce the error update of the slice configuration caused by false messages, ensure that the terminal device can normally access the network slice or establish a PDU session normally, and improve the service provided by the network slice. stability and improve network security.
- the basic process of executing the early admission control (EAC) mode first is described below.
- the EAC mode is used to indicate the point in time to execute the ACU procedure.
- the EAC mode When the EAC mode is activated (active), before the AMF authorizes the UE to access the network slice, it must first execute the ACU process, so as to confirm that the quota of the network slice is not full and allow the UE to access.
- the EAC mode is not activated (inactive)
- the AMF can execute the ACU process after authorizing the UE to access the network slice.
- the network slice has sufficient quota and is not in a hurry to update the terminal devices or sessions accessed by the network slice.
- other processes of the UE can be executed preferentially. In conjunction with Figure 6, the following steps are included:
- S601 The NSACF triggers an EAC configuration update process.
- the NSACF triggers an EAC configuration update process.
- the NSACF sends an EAC mode update message to the AMF, where the EAC mode update message is used to activate or deactivate the EAC mode of the network slice.
- the NSACF deactivates the EAC mode of the network slice, and does not need to initiate the ACU process before authorizing the UE.
- the preset number threshold such as higher than 75% of the quota
- NSACF activates the EAC mode of the network slice, and needs to initiate the ACU process before authorizing the UE, so as to ensure that the network The slice has enough quota to access the UE.
- the AMF can also initiate the ACU procedure before or after authorizing the UE according to the configuration.
- NSACFx indicates that the NF that has been maliciously attacked may be controlled by an insider, thus sending false messages, which may tamper with the EAC mode, such as setting the EAC flag to deactived or inactive, making the above risks more likely to occur.
- the embodiment of the present application provides another communication method.
- this method when the previously executed admission control mode is in an inactive state, if the number of terminal devices requesting access to the first network slice reaches a second threshold, the access management network function sends the first A message, used to update the number of terminal devices in the first network slice, so as to reduce the risk of authorizing too many terminal devices to access the network slice when the admission control mode is not activated first, and improve the service provided by the network slice stability.
- Figure 8 is a possible communication method, including the following steps:
- the access management network function determines the number of terminal devices requesting to access the first network slice.
- the AMF is preset with a counter, which can update the count value of the counter when receiving a terminal device request to access the first network slice after initiating the ACU process, such as adding a set value to the count value, and the set value is arbitrary An integer, which is not limited in this embodiment of the application, for example, the set value may be 1.
- the admission control network function receives the first message.
- a second number threshold may be set in the terminal device, and the second number threshold may be any integer, which is not limited in this embodiment of the present application.
- the first number threshold and the second number threshold may be the same, or may be different.
- the second quantity threshold may be a value preset in the system, or may be a value updated by first performing an admission control configuration update process, or may be a value determined by an access management network function. If the second number threshold is obtained by performing the update of the admission control configuration update process first, the admission control network function may increase the second number threshold in the first-execution admission control mode update message when sending the first-execution admission control mode update message instructions for the .
- the access management network function may determine the second quantity threshold according to the remaining admission quota of the network slice and/or the quantity of the access management network function. Certainly, other manners of determining the second quantity threshold are not limited in this embodiment of the present application.
- the second quantity threshold may be an upper limit of the maximum number of terminal devices admitted to the access management network function between two ACU procedures. If the number of terminal devices requesting to access the first network slice reaches the second number threshold, the ACU process needs to be executed first, and the first message is sent to the admission control network function. The first message includes updating the number of terminal devices in the first network slice, or rejecting a terminal device requesting to access the first network slice. It can be understood that an additional condition for triggering the ACU process is added to the access management network function when the admission control mode is inactive.
- the admission control network function may also send a fourth message, and the access management network function receives the fourth message.
- the fourth message is verified; if the verification is passed, the access management network function determines that the access control mode is first executed as an inactive state.
- the access management network function can determine that there is no malicious modification in the first execution of the admission control mode; when the verification of the fourth message fails, the access management network function can determine that the There are malicious modifications in the execution access control mode, and the risk of attack is identified.
- the fourth message may include but not limited to one or more of the following: an admission control network function identifier, an identifier of an operator network where the admission control network function is located, and an identifier of the first network slice.
- the access management network function may check the admission control network function identifier (NSACF ID), the identifier of the operator network where the admission control network function is located (PLMN ID), the first One or more of the identifiers of a network slice (S-NSSAI) are verified.
- NSACF ID admission control network function identifier
- PLMN ID the identifier of the operator network where the admission control network function is located
- S-NSSAI the first One or more of the identifiers of a network slice
- the above identifier in the fourth message is usually included in the Token, such as included in the claim item (Claim) of the Token.
- the information in the Token is integrity-protected information. If an attacker tampers with the information, the verification will fail.
- the S-NSSAI in the fourth message can be the S-NSSAI of the serving network (ie, the visited network) PLMN, or the mapped network slice identifier (mapped S -NSSAI), that is, the S-NSSAI in the home network.
- PLMN ID that is, the ID of the visited network
- mapped S-NSSAI the S-NSSAI of the home network
- S-NSSAI mapped S-NSSAI
- the process of verifying the fourth message may be performed after S602, and if the verification is passed, then S603 is performed.
- the access management network function when the previously executed admission control mode is in an inactive state, if the number of terminal devices requesting access to the first network slice reaches a second threshold, the access management network function sends the first A message, used to update the number of terminal devices in the first network slice, so as to reduce the risk of authorizing too many terminal devices to access the network slice when the admission control mode is not activated first, and improve the service provided by the network slice stability and improve network security.
- FIG. 7 and FIG. 8 are also applicable to the control of the number of sessions, where the access control network function AMF needs to be replaced by the session management function SMF.
- the information in the corresponding token can be correspondingly added or replaced with the information of the relevant session, which will not be repeated here.
- various embodiments of the present application may also be applicable to the information verification scenario when interacting with other NFs based on the SBI, and other NFs and information to be verified may be different from the NF and first parameter information in the above-mentioned embodiments , the verification process is similar and will not be repeated here.
- the embodiment of the present application also provides a communication device. As shown in FIG. method described in .
- the apparatus 900 may be applied to, or located in, an admission control network function, a data management network function, or an access management network function.
- the functions implemented by the optional transceiver unit 902 can be completed by the communication interface.
- the transceiver unit 902 is configured to receive a first message, where the first message includes a first message for updating the number of terminal devices or sessions in the first network slice.
- the processing unit 901 is configured to verify the authenticity of the first parameter information; if the first parameter information is true, update the number of terminal devices or sessions in the first network slice.
- the first parameter information includes one or more of the following information: a terminal device identifier, an identifier of a first network slice, an access management network function identifier, first indication information requesting registration or de-registration, and first indication information requesting session establishment or release session 2. Indication information, access type of terminal equipment, session identifier, data network identifier, session management network function identifier, and session status.
- the processing unit 901 is specifically configured to verify the authenticity of the first parameter information in one or more of the following ways: verify whether the terminal device corresponding to the terminal device identifier has subscribed to the first network slice to which the first network slice belongs.
- the processing unit 901 is specifically configured to use the transceiver unit 902 to send a second message to the data management network function, and the second message is used to request that the first parameter information be verified; to receive the third message, the first The third message includes the verification result of the first parameter information.
- the second message includes one or more of the following information: terminal device identifier, indication information for verifying the subscription state of the terminal device, indication information for verifying the access state of the terminal device, A network slice identifier, the slice identifier of the home network corresponding to the first network slice, the access management network function identifier, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, terminal device access type, session identifier, data network identifier, session management network function identifier, and session status.
- the processing unit 901 is further configured to determine that the first condition is met.
- Satisfying the first condition includes one or more of the following: the duration of the timer reaches the first duration, the number of times the first message is received reaches the first threshold, the number of connected terminal devices or sessions reaches the first threshold, An indication message was received to trigger the verification.
- the first message is sent when the admission control mode performed first is in an inactive state and the number of terminal devices requesting to access the first network slice reaches a second number threshold.
- the transceiver unit 902 when the device 900 is a data management network function, the transceiver unit 902 is configured to receive a second message, the second message is used to request verification of the first parameter information, and the first parameter information is used to Update the number of terminal devices or sessions in the first network slice; the processing unit 901 is configured to verify the first parameter information according to the acquired second parameter information of the terminal device or session; the transceiver unit 902 is configured to send The admission control network function sends a third message, where the third message includes a verification result of the first parameter information, and the verification result includes whether the first parameter information is true or false.
- the second message includes one or more of the following information: terminal device identifier, indication information for verifying the subscription state of the terminal device, indication information for verifying the access state of the terminal device, A network slice identifier, the slice identifier of the home network corresponding to the first network slice, the access management network function identifier, the first indication information requesting registration or de-registration, the second indication information requesting session establishment or release session, terminal device access type, session identifier, data network identifier, session management network function identifier, and session status.
- the processing unit 901 is specifically configured to verify the first parameter information according to the acquired second parameter information of the terminal device or session in one or more of the following ways: Instructions for verifying the status of the terminal device, verifying the subscription status of the terminal device; verifying whether the terminal device corresponding to the terminal device identifier has signed up for the service of the network to which the first network slice belongs or has signed up for the service corresponding to the first network slice.
- the service of the network of the home network verify whether the terminal device has subscribed to the service of the first network slice or the service of the network slice of the home network corresponding to the first network slice; check according to the access status of the terminal device Check the access status of the terminal device; check whether the terminal device is registered with the network to which the first network slice belongs; check whether the terminal device has access to the first network slice; check whether the terminal device has passed the access
- the access management network function corresponding to the access management network function identifier has registered with the network; verify whether the terminal device has accessed the first network slice through the access management network function; verify whether
- the processing unit 901 is configured to determine the identity of the terminal device requesting to access the first network slice when the admission control mode previously executed is in an inactive state. Quantity; the transceiver unit 902 is configured to send a first message to the admission control network function if the number of terminal devices requesting access to the first network slice reaches a second quantity threshold, and the first message includes information for updating the first network slice. the number of terminal devices.
- the transceiving unit 902 is further configured to receive a fourth message sent by the admission control network function, where the fourth message is used to modify the pre-executed admission control mode to an inactive state.
- the processing unit 901 is further configured to verify the fourth message, and if the verification is passed, determine that the admission control mode executed first is in an inactive state.
- the processing unit 901 is specifically configured to verify one or more of the admission control network function identifier, the identifier of the operator network where the admission control network function is located, and the identifier of the first network slice .
- each functional unit in each embodiment of the present application It can be integrated in one processing unit, or physically exist separately, or two or more units can be integrated in one unit.
- the above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
- the transceiving unit may include a receiving unit and/or a transmitting unit.
- the integrated unit can be stored in a computer-readable storage medium. Based on this understanding, the integrated unit can be stored in a storage medium as a computer software product, including several instructions to make a computer device (it can be a personal computer, a server, or a network device, etc.) or a processor (processor) Execute all or part of the steps of the methods in the various embodiments of the present application.
- the embodiment of the present application also provides a schematic structural diagram of a communication device 1000 .
- the apparatus 1000 may be used to implement the methods described in the foregoing method embodiments, and reference may be made to the descriptions in the foregoing method embodiments.
- the Apparatus 1000 includes one or more processors 1001 .
- the processor 1001 may be a general purpose processor or a special purpose processor or the like.
- it may be a baseband processor or a central processing unit.
- the baseband processor can be used to process communication protocols and communication data
- the central processing unit can be used to control communication devices (such as base stations, terminals, or chips, etc.), execute software programs, and process data of software programs.
- the communication device may include a transceiver unit for inputting (receiving) and outputting (sending) signals.
- the transceiver unit may be a transceiver, a radio frequency chip, and the like.
- the device 1000 includes one or more processors 1001, and the one or more processors 1001 can implement the methods in the above-mentioned embodiments.
- processor 1001 may also implement other functions in addition to implementing the methods in the above-mentioned embodiments.
- the processor 1001 may execute instructions, so that the apparatus 1000 executes the methods described in the foregoing method embodiments.
- the instruction can be stored in whole or in part in the processor 1001, such as the instruction 1003 can be stored in whole or in part in the processor 1001, or the instruction 1003 is stored in the processor 1001, and the instruction 1004 is stored in the memory 1002 coupled with the processor,
- the processor 1001 may execute the instruction 1003 and the instruction 1004 synchronously so that the apparatus 1000 executes the methods described in the foregoing method embodiments.
- the instructions 1003 and 1004 are also referred to as computer programs.
- the communication device 1000 may further include a circuit, and the circuit may implement the functions in the foregoing method embodiments.
- the device 1000 may include one or more memories 1002, on which instructions 1004 are stored, and the instructions may be executed on the processor 1001, so that the device 1000 executes the methods described in the above method embodiments.
- data may also be stored in the memory.
- Optional processor 1001 may also store instructions and/or data therein.
- one or more memories 1002 may store the correspondence described in the above embodiments, or related parameters or tables involved in the above embodiments, and the like. Processor and memory can be set separately or integrated together.
- the apparatus 1000 may further include a transceiver 1005 and an antenna 1006 .
- the processor 1001 may be referred to as a processing unit, and controls the device (terminal or base station).
- the transceiver 1005 may be called a transceiver, a transceiver circuit, or a transceiver unit, etc., and is used to realize the transceiver function of the device through the antenna 1006 .
- the processor can be a general-purpose central processing unit (central processing unit, CPU), a microprocessor, a specific application integrated circuit (application-specific integrated circuit, ASIC), one or more integrated circuits used to control the execution of the program program of this application , general-purpose processor, digital signal processor (digital signal processor, DSP), off-the-shelf programmable gate array (field programmable gate array, FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
- DSP digital signal processor
- FPGA field programmable gate array
- a general-purpose processor may be a microprocessor, or the processor may be any conventional processor, or the like.
- the steps of the method disclosed in connection with the embodiments of the present application may be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor.
- a software module may be stored on a storage medium located in a memory.
- Memory can be volatile memory or nonvolatile memory, or can include both volatile and nonvolatile memory.
- the non-volatile memory can be read-only memory (Read-Only Memory, ROM), programmable read-only memory (Programmable ROM, PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electronically programmable Erase Programmable Read-Only Memory (Electrically EPROM, EEPROM) or Flash.
- the volatile memory can be Random Access Memory (RAM), which acts as external cache memory.
- RAM Static Random Access Memory
- SRAM Static Random Access Memory
- DRAM Dynamic Random Access Memory
- Synchronous Dynamic Random Access Memory Synchronous Dynamic Random Access Memory
- SDRAM double data rate synchronous dynamic random access memory
- Double Data Rate SDRAM, DDR SDRAM enhanced synchronous dynamic random access memory
- Enhanced SDRAM, ESDRAM synchronous connection dynamic random access memory
- Synchlink DRAM, SLDRAM Direct Memory Bus Random Access Memory
- Direct Rambus RAM Direct Rambus RAM
- the embodiment of the present application also provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a computer, the communication method in any one of the above method embodiments is implemented.
- An embodiment of the present application further provides a computer program product, including a computer program, and when the computer program is executed by a computer, the communication method in any one of the above method embodiments is implemented.
- the embodiment of the present application also provides a communication system, including an admission control network function, and may also include an access management network function and/or a session management network function.
- the communication system may also include a data management network function.
- Each network function may implement any of the foregoing method embodiments.
- all or part of them may be implemented by software, hardware, firmware or any combination thereof.
- software When implemented using software, it may be implemented in whole or in part in the form of a computer program product.
- a computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on the computer, the processes or functions according to the embodiments of the present application are generated in whole or in part.
- the computer may be the communication device described above.
- Computer instructions may be stored in, or transmitted from, one computer-readable storage medium to another computer-readable storage medium.
- the computer-readable storage medium may be the above-mentioned storage medium or the above-mentioned memory.
- the determination unit or processor 1001 may be one or more logic circuits, and the sending unit
- the receiving unit or the transceiver 1005 may be an input-output interface, or called a communication interface, or an interface circuit, or an interface, or the like.
- the transceiver 1005 may also be a sending unit and a receiving unit, the sending unit may be an output interface, and the receiving unit may be an input interface, and the sending unit and the receiving unit are integrated into one unit, such as an input and output interface.
- the logic circuit 1101 includes a logic circuit 1101 and an interface circuit 1102 . That is, the above-mentioned determination unit or processor 1001 may be realized by a logic circuit 1101 , and the sending unit or receiving unit or transceiver 1005 may be realized by an interface circuit 1102 .
- the logic circuit 1101 may be a chip, a processing circuit, an integrated circuit or a system on chip (SoC) chip, etc.
- the interface circuit 1102 may be a communication interface, an input-output interface, or the like.
- the logic circuit and the interface circuit may also be coupled to each other. The embodiment of the present application does not limit the specific connection manner of the logic circuit and the interface circuit.
- the logic circuit 1101 and the interface circuit 1102 may be used to perform functions or operations performed by the above-mentioned terminal device or the policy control network function or the access management network function.
- the interface circuit may be used to receive signals from other communication devices than the communication device and transmit to or transmit signals from the logic circuit to other communication devices than the communication device.
- the logic circuit can be used to implement any of the above method embodiments by executing code instructions.
- the interface circuit 1102 may be used to receive signals from other communication devices other than the communication device 1100 and transmit them to the logic circuit 1101 or send signals from the logic circuit 1101 to other communication devices other than the communication device 1100 .
- the logic circuit 1101 may be used to implement any of the foregoing method embodiments by executing code instructions.
- the interface circuit 1102 is configured to receive a first message, where the first message includes first parameter information for updating the number of terminal devices or sessions in the first network slice.
- the logic circuit 1101 is configured to verify the authenticity of the first parameter information, and if the first parameter information is true, update the number of terminal devices or sessions in the first network slice.
- the disclosed systems, devices and methods may be implemented in other ways.
- the device embodiments described above are only illustrative.
- the division of units is only a logical function division. In actual implementation, there may be other division methods.
- multiple units or components can be combined or integrated. to another system, or some features may be ignored, or not implemented.
- the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices or units, and may also be electrical, mechanical or other forms of connection.
- a unit described as a separate component may or may not be physically separated, and a component displayed as a unit may or may not be a physical unit, that is, it may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiment of the present application.
- each functional unit in each embodiment of the present application may be integrated into one processing unit, each unit may exist separately physically, or two or more units may be integrated into one unit.
- the above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
- Computer-readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another.
- a storage media may be any available media that can be accessed by a computer.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Databases & Information Systems (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (23)
- 一种通信方法,其特征在于,包括:准入控制网络功能接收第一消息,所述第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息,所述第一参数信息包括以下一种或多种信息:终端设备标识、所述第一网络切片的标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态;所述准入控制网络功能对所述第一参数信息的真实性进行校验;若所述第一参数信息为真,所述准入控制网络功能对所述第一网络切片内的终端设备或会话的数量进行更新。
- 如权利要求1所述的方法,其特征在于,所述准入控制网络功能对所述第一参数信息的真实性进行校验,包括以下一种或多种:所述准入控制网络功能校验所述终端设备标识对应的终端设备是否签约了所述第一网络切片所属的网络的服务或者签约了与所述第一网络切片相对应的归属网络的服务;所述准入控制网络功能校验所述终端设备是否签约了所述第一网络切片的服务或者签约了与所述第一网络切片相对应的归属网络的网络切片的服务;所述准入控制网络功能校验所述终端设备是否注册了所述第一网络切片所属的网络;所述准入控制网络功能校验所述终端设备是否接入了所述第一网络切片;所述准入控制网络功能校验所述终端设备是否通过所述接入管理网络功能标识对应的接入管理网络功能注册了网络;所述准入控制网络功能校验所述终端设备是否通过所述接入管理网络功能接入了所述第一网络切片;所述准入控制网络功能校验所述终端设备是否通过所述接入类型接入了网络;所述准入控制网络功能校验所述第一指示信息指示的注册或去注册的请求是否与保存的所述终端设备的注册状态匹配;所述准入控制网络功能校验所述第二指示信息指示的建立会话或释放会话的请求是否与保存的所述终端设备的会话状态匹配;所述准入控制网络功能校验所述会话标识或所述会话标识对应的会话是否存在;所述准入控制网络功能校验所述会话标识或所述会话标识对应的会话是否属于所述终端设备;所述准入控制网络功能校验所述会话标识或所述会话标识对应的会话是否属于所述第一网络切片;所述准入控制网络功能校验所述会话标识对应的会话是否属于所述会话管理网络功能标识对应的会话管理网络功能管理;所述准入控制网络功能校验所述会话的状态是否与所述会话当前的状态一致;所述准入控制网络功能校验所述第一网络切片是否匹配所述数据网络标识对应的数据网络。
- 如权利要求1或2所述的方法,其特征在于,所述准入控制网络功能对所述第一参数信息的真实性进行校验,包括:所述准入控制网络功能向数据管理网络功能发送第二消息,所述第二消息用于请求对所述第一参数信息进行校验;所述准入控制网络功能接收第三消息,所述第三消息包括所述第一参数信息的校验结果。
- 如权利要求3所述的方法,其特征在于,所述第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、所述第一网络切片的标识、所述第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
- 如权利要求1-4任一项所述的方法,其特征在于,所述准入控制网络功能对所述第一参数信息的真实性进行校验之前,还包括:所述准入控制网络功能确定满足第一条件;所述满足第一条件包括以下一种或多种:计时器的时长达到第一时长、接收到第一消息的次数达到第一次数阈值、接入的终端设备或会话的数量达到第一数量阈值、接收到触发校验的指示信息。
- 如权利要求1-5任一项所述的方法,其特征在于,所述第一消息为先执行准入控制模式为未激活状态,且请求接入第一网络切片的终端设备的数量达到第二数量阈值时发送。
- 一种通信方法,其特征在于,包括:数据管理网络功能接收第二消息,第二消息用于请求对第一参数信息进行校验,所述第一参数信息用于更新第一网络切片内的终端设备或会话的数量;所述数据管理网络功能根据获取到的终端设备或会话的第二参数信息,对所述第一参数信息进行校验;所述数据管理网络功能向准入控制网络功能发送第三消息,所述第三消息包括所述第一参数信息的校验结果,所述校验结果包括所述第一参数信息为真或假。
- 如权利要求7所述的方法,其特征在于,所述第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、所述第一网络切片的标识、所述第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
- 如权利要求8所述的方法,其特征在于,所述数据管理网络功能根据获取到的终端设备或会话的第二参数信息,对所述第一参数信息进行校验,包括以下一种或多种:所述数据管理网络功能根据所述对终端设备的签约状态进行校验的指示信息,对所述终端设备的签约状态进行校验;所述数据管理网络功能校验所述终端设备标识对应的终端设备是否签约了所述第一网络切片所属的网络的服务或者签约了与所述第一网络切片相对应的归属网络的网络的服务;所述数据管理网络功能校验所述终端设备是否签约了所述第一网络切片的服务或者签约了与所述第一网络切片相对应的归属网络的网络切片的服务;所述数据管理网络功能根据所述对终端设备的接入状态进行校验的指示信息,对所述终端设备的接入状态进行校验;所述数据管理网络功能校验所述终端设备是否注册了所述第一网络切片所属的网络;所述数据管理网络功能校验所述终端设备是否接入了所述第一网络切片;所述数据管理网络功能校验所述终端设备是否通过所述接入管理网络功能标识对应的接入管理网络功能注册了网络;所述数据管理网络功能校验所述终端设备是否通过所述接入管理网络功能接入了所述第一网络切片;所述数据管理网络功能校验所述终端设备是否通过所述接入类型接入了网络;所述数据管理网络功能校验所述第一指示信息指示的注册或去注册的请求是否与保存的所述终端设备的注册状态匹配;所述数据管理网络功能校验所述第二指示信息指示的建立会话或释放会话的请求是否与保存的所述终端设备的会话状态匹配;所述数据管理网络功能校验所述会话标识或所述会话标识对应的会话是否存在;所述数据管理网络功能校验所述会话标识或所述会话标识对应的会话是否属于所述终端设备;所述数据管理网络功能校验所述会话标识或所述会话标识对应的会话是否属于所述第一网络切片;所述数据管理网络功能校验所述会话标识对应的会话是否属于所述会话管理网络功能标识对应的会话管理网络功能管理;所述数据管理网络功能校验所述会话的状态是否与所述会话当前的状态一致;所述数据管理网络功能校验所述第一网络切片是否匹配所述数据网络标识对应的数据网络。
- 一种通信装置,其特征在于,包括:收发单元,用于接收第一消息,所述第一消息包括用于更新第一网络切片内的终端设备或会话的数量的第一参数信息,所述第一参数信息包括以下一种或多种信息:终端设备标识、第一网络切片的标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态;处理单元,用于对所述第一参数信息的真实性进行校验;若所述第一参数信息为真,对所述第一网络切片内的终端设备或会话的数量进行更新。
- 如权利要求10所述的装置,其特征在于,所述处理单元,具体用于采用以下一种或多种方式对所述第一参数信息的真实性进行校验:校验所述终端设备标识对应的终端设备是否签约了所述第一网络切片所属的网络的服务或者签约了与所述第一网络切片相对应的归属网络的服务;校验所述终端设备是否签约了所述第一网络切片的服务或者签约了与所述第一网络切片相对应的归属网络的网络切片的服务;校验所述终端设备是否注册了所述第一网络切片所属的网络;校验所述终端设备是否接入了所述第一网络切片;校验所述终端设备是否通过所述接入管理网络功能标识对应的接入管理网络功能注册了网络;校验所述终端设备是否通过所述接入管理网络功能接入了所述第一网络切片;校验所述终端设备是否通过所述接入类型接入了网络;校验所述第一指示信息指示的注册或去注册的请求是否与保存的所述终端设备的注册状态匹配;校验所述第二指示信息指示的建立会话或释放会话的请求是否与保存的所述终端设备的会话匹配;校验所述会话标识或所述会话标识对应的会话是否存在;校验所述会话标识或所述会话标识对应的会话是否属于所述终端设备;校验所述会话标识或所述会话标识对应的会话是否属于所述第一网络切片;校验所述会话标识对应的会话是否属于所述会话管理网络功能标识对应的会话管理网络功能管理;校验所述会话的状态是否与所述会话当前的状态一致;校验所述第一网络切片是否匹配所述数据网络标识对应的数据网络。
- 如权利要求10或11所述的装置,其特征在于,所述收发单元,具体用于向数据管理网络功能发送第二消息,所述第二消息用于请求对所述第一参数信息进行校验;接收第三消息,所述第三消息包括所述第一参数信息的校验结果。
- 如权利要求12所述的装置,其特征在于,所述第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行校验的指示信息、所述第一网络切片的标识、所述第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
- 如权利要求10-13任一项所述的装置,其特征在于,所述处理单元,还用于确定满足第一条件;所述满足第一条件包括以下一种或多种:计时器的时长达到第一时长、接收到第一消息的次数达到第一次数阈值、接入的终端设备或会话的数量达到第一数量阈值、接收到触发校验的指示信息。
- 如权利要求10-14任一项所述的装置,其特征在于,所述第一消息为先执行准入控制模式为未激活状态,且请求接入第一网络切片的终端设备的数量达到第二数量阈值时发送。
- 一种通信装置,其特征在于,包括:收发单元,用于接收第二消息,第二消息用于请求对第一参数信息进行校验,所述第一参数信息用于更新第一网络切片内的终端设备或会话的数量;处理单元,用于根据获取到的终端设备或会话的第二参数信息,对所述第一参数信息进行校验;所述收发单元,用于向准入控制网络功能发送第三消息,所述第三消息包括所述第一参数信息的校验结果,所述校验结果包括所述第一参数信息为真或假。
- 如权利要求16所述的装置,其特征在于,所述第二消息包括以下一种或多种信息:终端设备标识、对终端设备的签约状态进行校验的指示信息、对终端设备的接入状态进行 校验的指示信息、所述第一网络切片的标识、所述第一网络切片对应的归属网络的切片标识、接入管理网络功能标识、请求注册或去注册的第一指示信息、请求建立会话或释放会话的第二指示信息、终端设备的接入类型、会话标识、数据网络标识、会话管理网络功能标识、会话的状态。
- 如权利要求17所述的装置,其特征在于,所述处理单元,具体用于采用以下一种或多种方式根据获取到的终端设备或会话的第二参数信息,对所述第一参数信息进行校验:根据所述对终端设备的签约状态进行校验的指示信息,对所述终端设备的签约状态进行校验;校验所述终端设备标识对应的终端设备是否签约了所述第一网络切片所属的网络的服务或者签约了与所述第一网络切片相对应的归属网络的网络的服务;校验所述终端设备是否签约了所述第一网络切片的服务或者签约了与所述第一网络切片相对应的归属网络的网络切片的服务;根据所述对终端设备的接入状态进行校验的指示信息,对所述终端设备的接入状态进行校验;校验所述终端设备是否注册了所述第一网络切片所属的网络;校验所述终端设备是否接入了所述第一网络切片;校验所述终端设备是否通过所述接入管理网络功能标识对应的接入管理网络功能注册了网络;校验所述终端设备是否通过所述接入管理网络功能接入了所述第一网络切片;校验所述终端设备是否通过所述接入类型接入了网络;校验所述第一指示信息指示的注册或去注册的请求是否与保存的所述终端设备的注册状态匹配;校验所述第二指示信息指示的建立会话或释放会话的请求是否与保存的所述终端设备的会话状态匹配;校验所述会话标识或所述会话标识对应的会话是否存在;校验所述会话标识或所述会话标识对应的会话是否属于所述终端设备;校验所述会话标识或所述会话标识对应的会话是否属于所述第一网络切片;校验所述会话标识对应的会话是否属于所述会话管理网络功能标识对应的会话管理网络功能管理;校验所述会话的状态是否与所述会话当前的状态一致;校验所述第一网络切片是否匹配所述数据网络标识对应的数据网络。
- 一种通信装置,其特征在于,包括处理器,所述处理器用于执行如权利要求1-9中任一项所述的方法。
- 一种通信装置,其特征在于,包括处理器和存储器,所述处理器与所述存储器耦合;存储器存储有计算机程序或指令;处理器,用于执行所述存储器中的计算机程序或指令,以使得所述装置执行如权利要求1-9中任一项所述的方法。
- 一种通信装置,其特征在于,包括逻辑电路和接口电路;所述接口电路,用于与所述通信装置之外的模块通信;所述逻辑电路用于执行计算机程序或指令,以使所述通信装置执行如权利要求1-9中 任一项所述的方法。
- 一种计算机可读存储介质,其特征在于,包括计算机程序或指令,当所述计算机程序或指令在计算机上运行时,使得如权利要求1-9中任一项所述的方法被执行。
- 一种计算机程序产品,其特征在于,包括计算机程序或指令,当其在计算机上运行时,使得如权利要求1-9中任一项所述的方法被执行。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP22851784.3A EP4376487A4 (en) | 2021-08-06 | 2022-06-30 | COMMUNICATION METHOD AND APPARATUS |
| US18/434,782 US20240179614A1 (en) | 2021-08-06 | 2024-02-06 | Communication method and apparatus |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202110904039.6 | 2021-08-06 | ||
| CN202110904039.6A CN115706699A (zh) | 2021-08-06 | 2021-08-06 | 一种通信方法及装置 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US18/434,782 Continuation US20240179614A1 (en) | 2021-08-06 | 2024-02-06 | Communication method and apparatus |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023011069A1 true WO2023011069A1 (zh) | 2023-02-09 |
Family
ID=85155182
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/103024 Ceased WO2023011069A1 (zh) | 2021-08-06 | 2022-06-30 | 一种通信方法及装置 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20240179614A1 (zh) |
| EP (1) | EP4376487A4 (zh) |
| CN (1) | CN115706699A (zh) |
| WO (1) | WO2023011069A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2025213348A1 (zh) * | 2024-04-08 | 2025-10-16 | 北京小米移动软件有限公司 | 通信方法、装置和存储介质 |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116367270A (zh) * | 2021-12-27 | 2023-06-30 | 中国移动通信有限公司研究院 | 通信方法、装置、相关设备及存储介质 |
| CN116800614A (zh) * | 2023-03-31 | 2023-09-22 | 广州爱浦路网络技术有限公司 | 网络切片分配方法及装置、网络切片申请方法、电子设备 |
| CN116830629A (zh) * | 2023-04-07 | 2023-09-29 | 北京小米移动软件有限公司 | 基于网络切片的通信方法及装置 |
| CN120614667A (zh) * | 2024-03-06 | 2025-09-09 | 维沃移动通信有限公司 | 网络接入的控制方法、装置及通信设备 |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109314917A (zh) * | 2017-05-09 | 2019-02-05 | 华为技术有限公司 | 网络切片选择策略更新方法、及装置 |
| WO2021070086A1 (en) * | 2019-10-07 | 2021-04-15 | Telefonaktiebolaget Lm Ericsson (Publ) | Ue controlled pdu sessions on a network slice |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR102847659B1 (ko) * | 2020-11-06 | 2025-08-20 | 레노보 (싱가포르) 피티이. 엘티디. | 검증된 디지털 아이덴티티를 사용한 가입 온보딩 |
| CN117158050A (zh) * | 2021-04-09 | 2023-12-01 | 三星电子株式会社 | 用于处理ue的网络切片准入控制的方法和系统 |
| CN117178602A (zh) * | 2021-05-06 | 2023-12-05 | 联想(新加坡)私人有限公司 | 网络切片准入控制 |
| JP2024125444A (ja) * | 2021-08-05 | 2024-09-19 | シャープ株式会社 | UE(User Equipment) |
| EP4381813A1 (en) * | 2021-08-06 | 2024-06-12 | Lenovo (Singapore) Pte. Ltd. | Registration to a network slice subject to admission control |
| EP4383857A4 (en) * | 2021-08-06 | 2024-10-02 | Beijing Xiaomi Mobile Software Co., Ltd. | METHOD AND APPARATUS FOR SELECTING A NETWORK LAYER ACCESS CONTROL FUNCTION |
-
2021
- 2021-08-06 CN CN202110904039.6A patent/CN115706699A/zh active Pending
-
2022
- 2022-06-30 EP EP22851784.3A patent/EP4376487A4/en active Pending
- 2022-06-30 WO PCT/CN2022/103024 patent/WO2023011069A1/zh not_active Ceased
-
2024
- 2024-02-06 US US18/434,782 patent/US20240179614A1/en active Pending
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109314917A (zh) * | 2017-05-09 | 2019-02-05 | 华为技术有限公司 | 网络切片选择策略更新方法、及装置 |
| WO2021070086A1 (en) * | 2019-10-07 | 2021-04-15 | Telefonaktiebolaget Lm Ericsson (Publ) | Ue controlled pdu sessions on a network slice |
Non-Patent Citations (4)
| Title |
|---|
| [NEC, APPLE, NOKIA, NOKIA SHANGHAI BELL, ERICSSON, LG ELECTRONICS], HUAWEI, HISILICON: "TS23.502 KI#2 Network Slice Admission Control Function (NSACF) services and procedures", 3GPP DRAFT; S2-2104082, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. e-meeting; 20210517 - 20210528, 10 May 2021 (2021-05-10), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP052004416 * |
| HUAWEI, HISILICON: "Default Subscribed S-NSSAIs for Network Slice Admission Control", 3GPP DRAFT; S2-2102218, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. e-meeting; 20210412 - 20210416, 6 April 2021 (2021-04-06), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051993604 * |
| See also references of EP4376487A4 * |
| ZTE: "Additional NSAC information from NSACF", 3GPP DRAFT; S2-2104469, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. E (e-meeting); 20210517 - 20210528, 10 May 2021 (2021-05-10), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP052004777 * |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2025213348A1 (zh) * | 2024-04-08 | 2025-10-16 | 北京小米移动软件有限公司 | 通信方法、装置和存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| EP4376487A1 (en) | 2024-05-29 |
| EP4376487A4 (en) | 2024-11-13 |
| US20240179614A1 (en) | 2024-05-30 |
| CN115706699A (zh) | 2023-02-17 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20230078317A1 (en) | Relay Link Establishment Method, Configuration Information Sending Method, Apparatus, and Readable Storage Medium | |
| US12425861B2 (en) | Method for determining class information and apparatus | |
| US20240179614A1 (en) | Communication method and apparatus | |
| US11871223B2 (en) | Authentication method and apparatus and device | |
| US12501305B2 (en) | Proximity service communication method, management network element, terminal device, and communication system | |
| CN112584486B (zh) | 一种通信方法及装置 | |
| RU2759094C1 (ru) | Обновление конфигурации сетевых сегментов | |
| CN113630272B (zh) | 一种通信方法及装置 | |
| CN110881185A (zh) | 一种通信的方法及装置 | |
| WO2021012736A1 (zh) | 一种会话管理网元的选择方法、装置及系统 | |
| US20220394596A1 (en) | Enforcement of maximum number of admitted terminals per network slice | |
| JP7662571B2 (ja) | ネットワークスライスアドミッション制御(nsac)発見及びローミング強化 | |
| US20240224098A1 (en) | Network verification method and apparatus | |
| CN114450991B (zh) | 用于注册程序的无线通信方法 | |
| US20250227465A1 (en) | Communication method and communication apparatus | |
| US11991781B2 (en) | Subscriber data management method and apparatus | |
| CN115568001B (zh) | 一种会话建立方法、装置及存储介质 | |
| CN116233953A (zh) | 数据传输方法、装置、设备及存储介质 | |
| US20240314886A1 (en) | Method for slice resource release | |
| CN115551122A (zh) | 切片准入控制的方法和通信装置 | |
| WO2021253859A1 (zh) | 切片认证方法及系统 | |
| US20250338123A1 (en) | Communication method and communication apparatus | |
| US20250260979A1 (en) | Communication method and communication apparatus | |
| CN112449377B (zh) | 一种网络数据的上报方法及装置 | |
| WO2022155913A1 (zh) | 一种接入控制的方法、装置和系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22851784 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202447008598 Country of ref document: IN |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2022851784 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 2022851784 Country of ref document: EP Effective date: 20240222 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |