WO2023061275A1 - Communication authorization method and apparatus, network element and storage medium - Google Patents

Communication authorization method and apparatus, network element and storage medium Download PDF

Info

Publication number
WO2023061275A1
WO2023061275A1 PCT/CN2022/124026 CN2022124026W WO2023061275A1 WO 2023061275 A1 WO2023061275 A1 WO 2023061275A1 CN 2022124026 W CN2022124026 W CN 2022124026W WO 2023061275 A1 WO2023061275 A1 WO 2023061275A1
Authority
WO
WIPO (PCT)
Prior art keywords
pin element
pin
communication
policy
data packet
Prior art date
Application number
PCT/CN2022/124026
Other languages
French (fr)
Chinese (zh)
Inventor
李欢
吴晓波
谢振华
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Publication of WO2023061275A1 publication Critical patent/WO2023061275A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • H04W28/10Flow control between communication endpoints

Abstract

The present application relates to the technical field of communications, and provides a communication authorization method and apparatus, a network element, and a storage medium. The communication authorization method in the embodiments of the present application comprises: a first network element acquiring policy information, the policy information comprising a communication policy of a first PIN element; and the first network element performing authorization control, according to the policy information, on a data packet associated with the first PIN element.

Description

通信授权方法、装置、网元和存储介质Communication authorization method, device, network element and storage medium
相关申请的交叉引用Cross References to Related Applications
本申请主张在2021年10月12日在中国提交的中国专利申请No.202111188003.9的优先权,其全部内容通过引用包含于此。This application claims priority to Chinese Patent Application No. 202111188003.9 filed in China on October 12, 2021, the entire contents of which are hereby incorporated by reference.
技术领域technical field
本申请属于通信技术领域,具体涉及一种通信授权方法、装置、网元和存储介质。The present application belongs to the technical field of communication, and in particular relates to a communication authorization method, device, network element and storage medium.
背景技术Background technique
第三代合作伙伴计划(3 rd Generation Partnership Project,3GPP)当前引入了个人物联网(Personal IoT Network,PIN)的概念。PIN是一个由至少一个PIN元素(PIN element)构成的组,其中,一个PIN元素为一个终端或一个3GPP非设备。同一个PIN中的各PIN元素之间可以通过它们之间的直接连接进行通信,也可以通过通信网络进行间接通信。 The 3rd Generation Partnership Project ( 3rd Generation Partnership Project, 3GPP) currently introduces the concept of Personal IoT Network (PIN). A PIN is a group consisting of at least one PIN element (PIN element), wherein a PIN element is a terminal or a 3GPP non-device. The PIN elements in the same PIN can communicate through direct connection among them, or through indirect communication through communication network.
发明内容Contents of the invention
本申请实施例提供一种通信授权方法、装置、网元和存储介质,以保证设备间的通信的安全。Embodiments of the present application provide a communication authorization method, device, network element, and storage medium, so as to ensure the security of communication between devices.
第一方面,本申请实施例提供一种通信授权方法,包括:In the first aspect, the embodiment of the present application provides a communication authorization method, including:
第一网元获取策略信息,所述策略信息包括:第一PIN元素的通信策略;The first network element acquires policy information, where the policy information includes: a communication policy of the first PIN element;
所述第一网元根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制。The first network element performs authorization control on data packets associated with the first PIN element according to the policy information.
这样根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the data packets associated with the PIN element are authorized and controlled according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication security between devices.
第二方面,本申请实施例提供一种通信授权方法,包括:In the second aspect, the embodiment of the present application provides a communication authorization method, including:
第二网元获取第一个人物联网PIN元素的第一通信策略;The second network element obtains the first communication strategy of the first IoT PIN element;
所述第二网元向第一网元发送策略信息,所述策略信息包括:所述第一 PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。The second network element sends policy information to the first network element, where the policy information includes: a second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is based on the determined by the first communication policy of the first PIN element.
这样第二网元向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the second network element sends policy information to the first network element, so that the first network element can authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication rights and ensuring the communication between devices. communication security.
第三方面,本申请实施例提供一种通信授权装置,包括:In a third aspect, the embodiment of the present application provides a communication authorization device, including:
获取模块,用于获取策略信息,所述策略信息包括:第一个人物联网PIN元素的通信策略;An acquisition module, configured to acquire policy information, where the policy information includes: the communication policy of the first IoT PIN element;
控制模块,用于根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制。A control module, configured to perform authorization control on data packets associated with the first PIN element according to the policy information.
这样根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the data packets associated with the PIN element are authorized and controlled according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication security between devices.
第四方面,本申请实施例提供一种通信授权装置,包括:In a fourth aspect, the embodiment of the present application provides a communication authorization device, including:
获取模块,用于获取第一个人物联网PIN元素的第一通信策略;An acquisition module, configured to acquire the first communication strategy of the first IoT PIN element;
发送模块,用于向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。A sending module, configured to send policy information to a first network element, where the policy information includes: a second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is based on the second communication policy of the first PIN element determined by the first communication policy of a PIN element.
这样通信授权装置向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the communication authorization device sends policy information to the first network element, so that the first network element performs authorization control on the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication between devices. communication security.
第五方面,本申请实施例提供一种网元,所述网元为第一网元,包括:存储器、处理器及存储在所述存储器上并可在所述处理器上运行的程序或者指令,所述程序或者指令被所述处理器执行时实现本申请实施例提供的第一网元侧的通信授权方法中的步骤。In the fifth aspect, the embodiment of the present application provides a network element, the network element is a first network element, including: a memory, a processor, and a program or instruction stored in the memory and operable on the processor When the program or instruction is executed by the processor, the steps in the communication authorization method at the first network element side provided in the embodiment of the present application are implemented.
这样可以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the authorization control of the data packets associated with the PIN element can be implemented according to the policy information, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices.
第六方面,本申请实施例提供一种网元,所述网元为第一网元,包括处理器及通信接口,其中,所述处理器或者通信接口用于:获取策略信息,所述策略信息包括:第一PIN元素的通信策略;根据所述策略信息,对所述第 一PIN元素关联的数据包进行授权控制。In a sixth aspect, an embodiment of the present application provides a network element, the network element is a first network element, and includes a processor and a communication interface, wherein the processor or the communication interface is used to: acquire policy information, and the policy The information includes: a communication policy of the first PIN element; according to the policy information, authorization control is performed on a data packet associated with the first PIN element.
这样可以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the authorization control of the data packets associated with the PIN element can be implemented according to the policy information, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices.
第七方面,本申请实施例提供一种网元,所述网元为第二网元,包括:存储器、处理器及存储在所述存储器上并可在所述处理器上运行的程序或者指令,所述程序或者指令被所述处理器执行时实现本申请实施例提供的第二网元侧的通信授权方法中的步骤。In a seventh aspect, the embodiment of the present application provides a network element, the network element is a second network element, including: a memory, a processor, and a program or instruction stored in the memory and operable on the processor When the program or instruction is executed by the processor, the steps in the communication authorization method at the second network element side provided by the embodiment of the present application are implemented.
这样可以实现向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the policy information can be sent to the first network element, so that the first network element can authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication between devices Safety.
第八方面,本申请实施例提供一种网元,所述网元为第二网元,包括处理器及通信接口,其中,所述处理器或者通信接口用于:获取第一个人物联网PIN元素的第一通信策略;向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。In an eighth aspect, the embodiment of the present application provides a network element, the network element is a second network element, and includes a processor and a communication interface, wherein the processor or the communication interface is used to: obtain the first IoT PIN The first communication policy of the element; sending policy information to the first network element, the policy information includes: the second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is based on the determined by the first communication policy of the first PIN element.
这样可以实现向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the policy information can be sent to the first network element, so that the first network element can authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication permissions and ensuring communication between devices Safety.
第九方面,本申请实施例提供一种可读存储介质,所述可读存储介质上存储有程序或指令,所述程序或指令被处理器执行时实现本申请实施例提供的第一网元侧的通信授权方法中的步骤,或者,所述程序或指令被处理器执行时实现本申请实施例提供的第二网元侧的通信授权方法中的步骤。In the ninth aspect, the embodiments of the present application provide a readable storage medium, the readable storage medium stores programs or instructions, and when the programs or instructions are executed by a processor, the first network element provided in the embodiments of the present application is implemented The steps in the communication authorization method on the second network element side, or, when the program or instruction is executed by the processor, implement the steps in the communication authorization method on the second network element side provided in the embodiment of the present application.
这样可以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。或者可以实现向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the authorization control of the data packets associated with the PIN element can be implemented according to the policy information, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices. Alternatively, policy information can be sent to the first network element, so that the first network element can authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication between devices Safety.
第十方面,提供了一种计算机程序产品,所述计算机程序产品被存储在存储介质中,所述计算机程序产品被至少一个处理器执行以实现本申请实施 例提供的第一网元侧的通信授权方法中的步骤,或者,所述计算机程序产品被至少一个处理器执行以实现本申请实施例提供的第二网元侧的通信授权方法中的步骤。In a tenth aspect, a computer program product is provided, the computer program product is stored in a storage medium, and the computer program product is executed by at least one processor to implement the communication on the first network element side provided by the embodiment of the present application The steps in the authorization method, or the computer program product is executed by at least one processor to implement the steps in the communication authorization method on the second network element side provided by the embodiment of this application.
第十一方面,提供了一种通信设备,被配置为执行以实现本申请实施例提供的第一网元侧的通信授权方法,或者被配置为执行以实现本申请实施例提供的第二网元侧的通信授权方法。In an eleventh aspect, there is provided a communication device configured to implement the communication authorization method on the first network element side provided in the embodiment of the present application, or configured to implement the second network element provided in the embodiment of the present application. Communication authorization method on the element side.
这样可以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。或者可以实现向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this way, the authorization control of the data packets associated with the PIN element can be implemented according to the policy information, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices. Alternatively, policy information can be sent to the first network element, so that the first network element can authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication between devices Safety.
附图说明Description of drawings
图1示出本申请实施例可应用的一种无线通信系统的框图;FIG. 1 shows a block diagram of a wireless communication system to which an embodiment of the present application is applicable;
图2是本申请实施例提供的一种通信授权方法的流程图;FIG. 2 is a flow chart of a communication authorization method provided in an embodiment of the present application;
图3是本申请实施例提供的另一种通信授权方法的流程图;Fig. 3 is a flow chart of another communication authorization method provided by the embodiment of the present application;
图4是本申请实施例提供的一种通信授权的示意图;FIG. 4 is a schematic diagram of a communication authorization provided by an embodiment of the present application;
图5是本申请实施例提供的另一种通信授权的示意图;Fig. 5 is a schematic diagram of another communication authorization provided by the embodiment of the present application;
图6是本申请实施例提供的另一种通信授权的示意图;Fig. 6 is a schematic diagram of another communication authorization provided by the embodiment of the present application;
图7是本申请实施例提供的另一种通信授权的示意图;FIG. 7 is a schematic diagram of another communication authorization provided by the embodiment of the present application;
图8是本申请实施例提供的另一种通信授权的示意图;Fig. 8 is a schematic diagram of another communication authorization provided by the embodiment of the present application;
图9是本申请实施例提供的一种通信授权装置的结构图;FIG. 9 is a structural diagram of a communication authorization device provided in an embodiment of the present application;
图10是本申请实施例提供的另一种通信授权装置的结构图;FIG. 10 is a structural diagram of another communication authorization device provided by an embodiment of the present application;
图11是本申请实施例提供的通信设备的结构图;FIG. 11 is a structural diagram of a communication device provided by an embodiment of the present application;
图12是本申请实施例提供的一种第一网元的结构图;FIG. 12 is a structural diagram of a first network element provided by an embodiment of the present application;
图13是本申请实施例提供的一种第二网元的结构图。FIG. 13 is a structural diagram of a second network element provided by an embodiment of the present application.
具体实施方式Detailed ways
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行 清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。The technical solutions in the embodiments of the application will be clearly described below in conjunction with the accompanying drawings in the embodiments of the application. Obviously, the described embodiments are part of the embodiments of the application, not all of them. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in this application belong to the protection scope of this application.
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。The terms "first", "second" and the like in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific sequence or sequence. It is to be understood that the terms so used are interchangeable under appropriate circumstances such that the embodiments of the application are capable of operation in sequences other than those illustrated or described herein and that "first" and "second" distinguish objects. It is usually one category, and the number of objects is not limited. For example, there may be one or more first objects. In addition, "and/or" in the description and claims means at least one of the connected objects, and the character "/" generally means that the related objects are an "or" relationship.
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括PIN,无线接入网(Radio Access Network,RAN)和核心网。Fig. 1 shows a block diagram of a wireless communication system to which the embodiment of the present application is applicable. The wireless communication system includes a PIN, a radio access network (Radio Access Network, RAN) and a core network.
其中,PIN包括至少一个PIN元素(PIN element),一个PIN元素为一个终端或一个非3GPP设备。非3GPP设备指未使用3GPP定义的凭证的设备,不支持3GPP定义的非接入层(Non-Access-Stratum,NAS)协议的设备,或者不支持3GPP接入技术(如3G/4G/5G空口技术)而只支持非3GPP接入技术(如无线保真(Wireless Fidelity,WiFi),固网,蓝牙等接入技术)的设备。Wherein, the PIN includes at least one PIN element (PIN element), and one PIN element is a terminal or a non-3GPP device. Non-3GPP devices refer to devices that do not use 3GPP-defined credentials, devices that do not support the Non-Access-Stratum (NAS) protocol defined by 3GPP, or devices that do not support 3GPP access technologies (such as 3G/4G/5G air interface technology) but only supports non-3GPP access technologies (such as wireless fidelity (Wireless Fidelity, WiFi), fixed network, Bluetooth and other access technologies).
另外,一个PIN中可以有一个或多个具有网关能力的PIN元素(PIN element with gateway capability)。该PIN中的PIN元素互相之间可以通信,例如:PIN元素之间可以通过它们之间的直接连接进行通信,或者,可以通过通信网络进行间接通信。PIN中的PIN元素也可以和该PIN外的其他设备进行通信。此时,可以通过该具有网关能力的PIN元素进行转发PIN中的PIN元素和该PIN外的其他设备的通信数据。In addition, a PIN can have one or more PIN elements with gateway capability (PIN element with gateway capability). The PIN elements in the PIN can communicate with each other, for example, the PIN elements can communicate through a direct connection between them, or can communicate indirectly through a communication network. The PIN element in the PIN can also communicate with other devices outside the PIN. At this time, the communication data between the PIN element in the PIN and other devices outside the PIN can be forwarded through the PIN element with gateway capability.
其中,终端也可以称作终端设备或者用户终端(User Equipment,UE),终端可以是终端可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personal computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、 增强现实(augmented reality,AR)/虚拟现实(virtual reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、车载设备(Vehicle User Equipment,VUE)、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)等终端侧设备,可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装、游戏机等。需要说明的是,在本申请实施例并不限定终端的具体类型。Wherein, the terminal can also be called terminal equipment or user equipment (User Equipment, UE), and the terminal can be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal computer, or a mobile phone. Digital assistant (Personal Digital Assistant, PDA), handheld computer, netbook, ultra-mobile personal computer (ultra-mobile personal computer, UMPC), mobile internet device (Mobile Internet Device, MID), augmented reality (augmented reality, AR)/virtual Reality (virtual reality, VR) equipment, robot, wearable device (Wearable Device), vehicle equipment (Vehicle User Equipment, VUE), pedestrian terminal (Pedestrian User Equipment, PUE), smart home (home equipment with wireless communication function , such as refrigerators, TVs, washing machines or furniture, etc.), wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, Smart anklets, smart anklets, etc.), smart wristbands, smart clothing, game consoles, etc. It should be noted that, the embodiment of the present application does not limit the specific type of the terminal.
值得指出的是,本申请实施例所描述的无线接入网不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency-Division Multiple Access,SC-FDMA)和其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术,如非3GPP接入系统(例如,无线局域网(Wireless Local Area Network,WLAN),固定接入系统,蓝牙等)。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,这些技术也可应用于NR系统应用以外的应用,如第6代(6th Generation,6G)通信系统。It is worth noting that the wireless access network described in the embodiment of the present application is not limited to the long term evolution (Long Term Evolution, LTE)/LTE evolution (LTE-Advanced, LTE-A) system, and can also be used in other wireless communication systems , such as Code Division Multiple Access (CDMA), Time Division Multiple Access (Time Division Multiple Access, TDMA), Frequency Division Multiple Access (Frequency Division Multiple Access, FDMA), Orthogonal Frequency Division Multiple Access, OFDMA), Single-carrier Frequency-Division Multiple Access (Single-carrier Frequency-Division Multiple Access, SC-FDMA) and other systems. The terms "system" and "network" in the embodiments of this application are often used interchangeably, and the described technology can be used for the above-mentioned system and radio technology, and can also be used for other systems and radio technologies, such as non-3GPP Access systems (eg, Wireless Local Area Network (WLAN), fixed access systems, Bluetooth, etc.). The following description describes the New Radio (New Radio, NR) system for example purposes, and uses NR terms in most of the following descriptions. These technologies can also be applied to applications other than NR system applications, such as the 6th generation (6th Generation, 6G) communication system.
上述核心网可以包括:会话管理功能(Session Management Function,SMF)、接入和移动管理功能(Access and Mobility Management Function,AMF)、用户面功能(User Port Function,UPF)、策略控制功能(Policy Control Function,PCF)和统一数据管理(Unified Data Management,UDM)。在本申请实施例中,核心网还可以包括:访问策略功能(Access Right Function,ARF)。该ARF可以独立存在,也可以与其他核心网网元合设或这由其他核心网网元实现。例如,PCF或UDM支持本申请实施例中ARF的功能。The above-mentioned core network may include: session management function (Session Management Function, SMF), access and mobility management function (Access and Mobility Management Function, AMF), user plane function (User Port Function, UPF), policy control function (Policy Control Function, PCF) and unified data management (Unified Data Management, UDM). In the embodiment of the present application, the core network may further include: an access policy function (Access Right Function, ARF). The ARF can exist independently, or can be set up together with other core network elements or implemented by other core network elements. For example, PCF or UDM supports the function of ARF in this embodiment of the application.
本申请实施例中,PIN元素也可以称作PIN设备。例如,用户的手机,家里的打印机,扫地机器人均为PIN元素,它们组成了一个PIN。手机可以 与打印机通信,指定打印的文件。手机还可以与扫地机器人通信,制定并执行打扫计划。In this embodiment of the application, the PIN element may also be referred to as a PIN device. For example, the user's mobile phone, the printer at home, and the sweeping robot are all PIN elements, and they form a PIN. The phone can communicate with the printer to specify which files to print. The mobile phone can also communicate with the sweeping robot to formulate and execute a cleaning plan.
现有的通信机制可能存在风险,即该PIN之外的其他设备或该PIN中的其他设备可能也向打印机发送打印命令,或者向扫地机器人发送打扫命令。如果使用应用程序来控制通信权限,则当应用程序被攻击时,通信权限可能被破坏,进而造成未经授权的UE访问PIN元素,从而打扰了该PIN中PIN元素之间的正常通信,例如,让打印机或扫地机器人执行了本不该执行的任务。因此,本申请实施例提出一种设备间通信的授权方法,保证设备间的通信在授权的状态下才能进行。There may be risks in the existing communication mechanism, that is, other devices outside the PIN or other devices in the PIN may also send printing commands to the printer, or send cleaning commands to the sweeping robot. If an application is used to control communication permissions, when the application is attacked, the communication permissions may be compromised, causing unauthorized UEs to access PIN elements, thereby disturbing the normal communication between PIN elements in the PIN, for example, Making a printer or robot vacuum perform a task it shouldn't. Therefore, the embodiment of the present application proposes an authorization method for inter-device communication, which ensures that the inter-device communication can only be performed in an authorized state.
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的一种通信授权方法、装置、网元和存储介质进行详细地说明。A communication authorization method, device, network element, and storage medium provided in the embodiments of the present application are described in detail below through some embodiments and application scenarios with reference to the accompanying drawings.
请参见图2,图2是本申请实施例提供的一种通信授权方法的流程图,如图2所示,包括以下步骤:Please refer to FIG. 2. FIG. 2 is a flowchart of a communication authorization method provided in the embodiment of the present application. As shown in FIG. 2, it includes the following steps:
步骤201、第一网元获取策略信息,所述策略信息包括:第一PIN元素的通信策略。 Step 201, the first network element acquires policy information, where the policy information includes: a communication policy of the first PIN element.
本申请实施例中,第一网元可以包括如下一项:In this embodiment of the application, the first network element may include the following items:
UPF、所述第一PIN元素、目标PIN元素;UPF, said first PIN element, target PIN element;
其中,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素。Wherein, the target PIN element is a PIN element with gateway capability among the PINs to which the first PIN element belongs.
上述第一网元获取策略信息可以是,第一网元从第二网元接收策略信息,例如:第一网元从接收AMF或者SMF等接收策略信息。The acquisition of the policy information by the first network element may be that the first network element receives the policy information from the second network element, for example, the first network element receives the policy information from an AMF or an SMF.
上述第一PIN元素可以为PIN中一个或者多个PIN元素。The above-mentioned first PIN element may be one or more PIN elements in the PIN.
上述第一PIN元素的通信策略可以包括第一PIN元素的双向通信策略,和单项通信策略中的至少一种。该双向通信策略包括可以互相通信的PIN元素的描述信息。The above-mentioned communication policy of the first PIN element may include at least one of a bidirectional communication policy of the first PIN element and a single communication policy. The two-way communication policy includes description information of PIN elements that can communicate with each other.
本申请实施例中PIN元素的描述信息可以包括以下至少一项:The description information of the PIN element in this embodiment of the application may include at least one of the following:
PIN元素的互联网协议(Internet Protocol,IP)地址;Internet Protocol (IP) address of the PIN element;
PIN元素的媒体接入控制(Medium Access Control,MAC)地址;The Medium Access Control (MAC) address of the PIN element;
PIN元素的标识;Identification of the PIN element;
PIN元素发送的数据包所使用的虚拟局域网(Virtual Local Area Network,VLAN)标识;The virtual local area network (Virtual Local Area Network, VLAN) identifier used by the data packet sent by the PIN element;
PIN元素发送的数据包所使用的用户数据报协议(User Datagram Protocol,UDP)端口号。The User Datagram Protocol (UDP) port number used by the packet sent by the PIN element.
其中,PIN元素的标识包括但不限于外部标识,例如:通用公共用户标识(Generic Public Subscription Identifier,GPSI),完全合格域名(Fully Qualified Domain Name,FQDN),国际移动用户识别码(International Mobile Subscriber Identification Number,IMSI),用户永久标识(Subscription Permanent Identifier,SUPI),用户隐藏标识(Subscription Concealed Identifier,SUCI),用户临时标识,或在PIN中的唯一标识;Among them, the identification of the PIN element includes but not limited to external identification, such as: Generic Public Subscription Identifier (Generic Public Subscription Identifier, GPSI), Fully Qualified Domain Name (Fully Qualified Domain Name, FQDN), International Mobile Subscriber Identification Code (International Mobile Subscriber Identification Number, IMSI), User Permanent Identifier (Subscription Permanent Identifier, SUPI), User Concealed Identifier (Subscription Concealed Identifier, SUCI), User Temporary Identifier, or unique identifier in PIN;
单向通信策略表示第一PIN元素可以向哪些PIN元素发送数据包,或者,该单向通信策略表示第一PIN元素可以接收哪些PIN元素发送的数据包。具体的,单项通信策略可以包括这些PIN元素的描述信息。The one-way communication policy indicates which PIN elements the first PIN element can send data packets to, or, the one-way communication policy indicates which PIN elements the first PIN element can receive data packets sent by. Specifically, a single communication policy may include description information of these PIN elements.
需要说明的是,本申请实施例中第一PIN元素的通信策略也可以称作第一PIN元素的访问权限或访问策略,即该策略可以控制访问第一PIN元素的PIN元素或其他设备的通信行为。本申请实施例中PIN元素的描述信息也可以称为PIN元素的指示信息,或者PIN元素的标识信息。It should be noted that the communication strategy of the first PIN element in the embodiment of the present application can also be called the access right or access strategy of the first PIN element, that is, the strategy can control the communication of the PIN element or other devices that access the first PIN element Behavior. The description information of the PIN element in this embodiment of the present application may also be referred to as indication information of the PIN element, or identification information of the PIN element.
步骤202、所述第一网元根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制。 Step 202, the first network element performs authorization control on data packets associated with the first PIN element according to the policy information.
上述第一PIN元素关联的数据包可以是目的地址指示为第一PIN元素的数据包。其中,目的地址指示为所述第一PIN元素的数据包可以为:数据包的目的IP地址为第一PIN元素的IP地址,数据包的目的MAC地址为第一PIN元素的MAC地址,或者数据包包头中包括第一PIN元素的标识,以指示本数据包的目的地为第一PIN元素。通过上述步骤可以实现对目的地址指示为第一PIN元素的数据包进行授权控制。上述对所述第一PIN元素关联的数据包进行授权控制可以是,根据第一PIN元素的通信策略发送、接收或者丢弃第一PIN元素关联的数据包。The data packet associated with the above-mentioned first PIN element may be a data packet whose destination address is indicated as the first PIN element. Wherein, the data packet whose destination address indicates the first PIN element can be: the destination IP address of the data packet is the IP address of the first PIN element, the destination MAC address of the data packet is the MAC address of the first PIN element, or the data packet The identifier of the first PIN element is included in the packet header to indicate that the destination of the data packet is the first PIN element. Through the above steps, the authorization control of the data packet whose destination address is indicated as the first PIN element can be realized. The foregoing authorization control of the data packet associated with the first PIN element may be sending, receiving or discarding the data packet associated with the first PIN element according to the communication policy of the first PIN element.
在一些实施方式中,上述第一PIN元素关联的数据包还可以是源地址指示为第一PIN元素的数据包,其中,源地址指示为所述第一PIN元素的数据 包可以为:数据包的源IP地址为第一PIN元素的IP地址,数据包的源MAC地址为第一PIN元素的MAC地址,或者数据包包头中包括第一PIN元素的标识,以指示本数据包的来源为第一PIN元素。通过上述步骤可以实现对源地址指示为第一PIN元素的数据包进行授权控制。上述对所述第一PIN元素关联的数据包进行授权控制可以是,判断第一PIN关联的数据包是否可以发送到数据包的目的地址所指示的设备。例如数据包的目的地址指示为第二PIN元素,如果通信策略允许第一PIN元素与第二PIN元素通信,或者允许第一PIN元素向第二PIN元素发送数据包,则转发该数据包,否则,丢弃该数据包。In some implementations, the data packet associated with the above-mentioned first PIN element may also be a data packet whose source address indicates the first PIN element, wherein the data packet whose source address indicates the first PIN element may be: a data packet The source IP address of the data packet is the IP address of the first PIN element, the source MAC address of the data packet is the MAC address of the first PIN element, or the header of the data packet includes the identifier of the first PIN element to indicate that the source of the data packet is the first PIN element A PIN element. Through the above steps, the authorization control of the data packet whose source address is indicated as the first PIN element can be realized. The foregoing authorization control of the data packet associated with the first PIN element may be to determine whether the data packet associated with the first PIN can be sent to the device indicated by the destination address of the data packet. For example, the destination address of the data packet is indicated as the second PIN element, if the communication strategy allows the first PIN element to communicate with the second PIN element, or allows the first PIN element to send a data packet to the second PIN element, then forward the data packet, otherwise , discarding the packet.
上述对所述第一PIN元素关联的数据包进行授权控制可以是,根据第一PIN元素的通信策略发送、接收或者丢弃第一PIN元素关联的数据包,具体由上述通信策略决定。The authorization control of the data packets associated with the first PIN element may be sending, receiving or discarding the data packets associated with the first PIN element according to the communication policy of the first PIN element, which is specifically determined by the communication policy.
本申请实施例通过上述步骤可以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全,防止PIN元素遭到其他无通信权限设备的攻击。Through the above steps, the embodiment of the present application can realize the authorization control of the data packets associated with the PIN element according to the policy information, thereby avoiding the communication between devices without communication authority, ensuring the communication security between the devices, and preventing the PIN element from being attacked by others. Attacks on devices without communication permissions.
作为一种可能的实施方式,上述对所述第一PIN元素关联的数据包进行授权控制,包括如下至少一项:As a possible implementation manner, the authorization control of the data packet associated with the first PIN element includes at least one of the following:
向所述第一PIN元素发送所述第一PIN元素关联的第一数据包;sending a first data packet associated with the first PIN element to the first PIN element;
丢弃所述第一PIN元素关联的第二数据包;Discarding the second data packet associated with the first PIN element;
接收所述第一PIN元素关联的第三数据包。receiving a third data packet associated with the first PIN element.
上述向所述第一PIN元素发送所述第一PIN元素关联的第一数据包可以是,向所述第一PIN元素转发所述第一PIN元素关联的第一数据包。例如:第一网元为UPF,向第一PIN元素转发第一PIN元素关联的第一数据包。其中,向第一PIN元素转发第一数据包,可以通过第一PIN元素的会话通道进行转发,或者,向第一PIN元素所属PIN进行转发,例如,向第一PIN元素所属PIN中具有网关能力的PIN元素进行转发。The foregoing sending the first data packet associated with the first PIN element to the first PIN element may be forwarding the first data packet associated with the first PIN element to the first PIN element. For example, the first network element is a UPF, and forwards the first data packet associated with the first PIN element to the first PIN element. Wherein, forwarding the first data packet to the first PIN element can be forwarded through the session channel of the first PIN element, or forwarded to the PIN to which the first PIN element belongs, for example, to the PIN to which the first PIN element belongs has gateway capability The PIN element is forwarded.
上述丢弃所述第一PIN元素关联的第二数据包可以是,在接收到上述第二数据包时,丢弃第二数据包,或不向第一PIN元素转发该数据包。The discarding of the second data packet associated with the first PIN element may be, when the second data packet is received, discarding the second data packet, or not forwarding the data packet to the first PIN element.
上述接收所述第一PIN元素关联的第三数据包可以是,第一PIN元素接 收上述通信策略接收第三数据包。The aforementioned receiving of the third data packet associated with the first PIN element may be that the first PIN element receives the communication policy and receives the third data packet.
其中,在向所述第一PIN元素发送所述第一PIN元素关联的第一数据包的情况下,第一网元可以包括UPF或者上述目标PIN元素;Wherein, in the case of sending the first data packet associated with the first PIN element to the first PIN element, the first network element may include a UPF or the above-mentioned target PIN element;
在丢弃所述第一PIN元素关联的第二数据包的情况下,第一网元可以包括UPF、所述第一PIN元素或者目标PIN元素;In the case of discarding the second data packet associated with the first PIN element, the first network element may include a UPF, the first PIN element, or a target PIN element;
在接收所述第一PIN元素关联的第三数据包的情况下,第一网元可以包括UPF、所述第一PIN元素或者目标PIN元素。In the case of receiving the third data packet associated with the first PIN element, the first network element may include a UPF, the first PIN element, or a target PIN element.
该实施方式中,通过上述发送、丢弃或者接收数据包可以提高PIN元素的安全性。In this embodiment, the security of the PIN element can be improved by sending, discarding or receiving the data packet.
可选的,所述向所述第一PIN元素发送所述第一PIN元素关联的第一数据包,包括:Optionally, the sending the first data packet associated with the first PIN element to the first PIN element includes:
在所述第一PIN元素的通信策略包括允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略的情况下,向所述第一PIN元素发送所述第一PIN元素关联的第一数据包,其中,所述第一数据包为所述第二PIN元素向所述第一PIN元素发送的数据包。In the case where the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive a data packet sent by the second PIN element, send the first PIN element associated information to the first PIN element A first data packet, wherein the first data packet is a data packet sent by the second PIN element to the first PIN element.
上述第二PIN元素可以是一个或者多个元素,具体可以根据实际情况配置相应的通信策略。The above-mentioned second PIN element may be one or more elements, and specifically, a corresponding communication strategy may be configured according to an actual situation.
该实施方式中,可以实现只向第一PIN元素发送通信策略允许发送的PIN元素的数据包。In this implementation manner, it can be realized that only the data packets of the PIN elements allowed by the communication policy are sent to the first PIN element.
可选的,所述丢弃所述第一PIN元素关联的第二数据包,包括:Optionally, the discarding the second data packet associated with the first PIN element includes:
在所述第一PIN元素的通信策略包括禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略的情况下,丢弃所述第一PIN元素关联的第二数据包,其中,所述第二数据包为所述第三PIN元素向所述第一PIN元素发送的数据包;或者In the case where the communication strategy of the first PIN element includes a communication strategy that prohibits the first PIN element from receiving a data packet sent by a third PIN element, discarding the second data packet associated with the first PIN element, wherein, The second data packet is a data packet sent by the third PIN element to the first PIN element; or
在所述第一PIN元素的通信策略不包括允许所述第一PIN元素接收第三PIN元素发送的数据包的通信策略的情况下,丢弃所述第一PIN元素关联的第二数据包,其中,所述第二数据包为所述第三PIN元素向所述第一PIN元素发送的数据包。When the communication policy of the first PIN element does not include a communication policy that allows the first PIN element to receive a data packet sent by a third PIN element, discarding the second data packet associated with the first PIN element, wherein , the second data packet is a data packet sent by the third PIN element to the first PIN element.
上述第三PIN可以是一个或者多个PIN元素。The aforementioned third PIN may be one or more PIN elements.
该实施方式中,可以实现禁止向第一PIN元素发送通信策略禁止第一PIN元素接收的PIN元素发送的数据包。In this implementation manner, it may be implemented to prohibit sending to the first PIN element the data packet sent by the PIN element that is prohibited by the communication policy from being received by the first PIN element.
可选的,所述接收所述第一PIN元素关联的第三数据包,包括:Optionally, the receiving the third data packet associated with the first PIN element includes:
在所述第一PIN元素的通信策略包括允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略的情况下,接收所述第二PIN元素发送的所述第一PIN元素关联的第三数据包。In the case where the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive data packets sent by the second PIN element, receiving the first PIN element sent by the second PIN element is associated with of the third packet.
该实施方式中,可以实现第一PIN元素只接收通信策略允许第一PIN元素接收的PIN元素发送的数据包。In this implementation manner, it can be realized that the first PIN element only receives data packets sent by the PIN element that the communication policy allows the first PIN element to receive.
作为一种可能的实施方式,所述第一网元为UPF,所述第一网元获取策略信息,包括:所述第一网元从SMF接收所述策略信息。As a possible implementation manner, the first network element is a UPF, and the acquiring policy information by the first network element includes: receiving the policy information from an SMF by the first network element.
第一网元可以通过UPF与SMF之间的N4接口从SMF接收所述策略信息。该策略信息可以是N4规则,该N4规则为SMF在接收到第一PIN元素的第一通信策略后,根据第一PIN元素的第一通信策略所确定的。该N4规则可以指示UPF可以向第一PIN元素发送的数据包,和/或,该N4规则可以指示UPF不能向第一PIN元素发送的数据包。The first network element may receive the policy information from the SMF through the N4 interface between the UPF and the SMF. The policy information may be an N4 rule, and the N4 rule is determined by the SMF according to the first communication policy of the first PIN element after receiving the first communication policy of the first PIN element. The N4 rule may indicate data packets that the UPF can send to the first PIN element, and/or, the N4 rule may indicate data packets that the UPF cannot send to the first PIN element.
该实施方式,可以实现UPF根据第一PIN元素的通信策略对第一PIN元素关联的数据包授权控制。In this implementation manner, the UPF can implement authorization control of data packets associated with the first PIN element according to the communication policy of the first PIN element.
可选的,所述第一PIN元素的通信策略包括:Optionally, the communication policy of the first PIN element includes:
包检测规则(Packet Detection Rules,PDR)和转发行为规则(Forwarding Action Rules,FAR);Packet Detection Rules (PDR) and Forwarding Action Rules (FAR);
其中,示例性的,所述PDR包括如下至少一项:Wherein, exemplary, the PDR includes at least one of the following:
允许所述第一PIN元素接收的数据包的第一检测信息;Allow the first detection information of the data packet received by the first PIN element;
禁止所述第一PIN元素接收的数据包的第二检测信息;Forbid the second detection information of the data packet received by the first PIN element;
所述FAR用于指示如下至少一项:The FAR is used to indicate at least one of the following:
在接收到符合所述第一检测信息的第一数据包的情况下,向所述第一PIN元素转发所述第一数据包;Forwarding the first data packet to the first PIN element in case a first data packet conforming to the first detection information is received;
在接收到符合所述第二检测信息的第二数据包的情况下,丢弃所述第二数据包。In case of receiving a second data packet conforming to the second detection information, discarding the second data packet.
在上述通信策略允许第一PIN元素接收第二PIN元素的数据包的情况下, 上述第一检测信息可以包括第二PIN元素的描述信息;在上述通信策略禁止第一PIN元素接收第三PIN元素的数据包的情况下,上述第二检测信息可以包括第三PIN元素的描述信息。In the case where the above-mentioned communication policy allows the first PIN element to receive the data packet of the second PIN element, the above-mentioned first detection information may include the description information of the second PIN element; when the above-mentioned communication policy prohibits the first PIN element from receiving the third PIN element In the case of a data packet, the second detection information may include description information of the third PIN element.
上述接收到符合第一检测信息的第一数据包可以是,接收到符合第一检测信息对应的PIN元素发送的数据包,如接收到上述第二PIN元素的数据包。The receiving of the first data packet conforming to the first detection information may be the receiving of a data packet conforming to the PIN element corresponding to the first detection information, such as receiving the data packet of the above-mentioned second PIN element.
上述接收到符合第二检测信息的第二数据包可以是,接收到符合第二检测信息对应的PIN元素发送的数据包,如接收到上述第三PIN元素的数据包。The received second data packet conforming to the second detection information may be a received data packet conforming to the PIN element corresponding to the second detection information, such as the data packet receiving the above-mentioned third PIN element.
例如:第一PIN元素的通信策略中描述了第一PIN元素能够接收来自第二PIN元素的数据包。N4规则中包括的PDR中包括第二PIN元素的数据包的检测信息。该检测信息可以包括第二PIN元素的描述信息。该PDR关联的FAR指示了UPF接收到符合第二PIN元素的数据包的检测信息的数据包时,向第一PIN元素的转发该数据包。例如,FAR的行为(action)指示为转发(forwarding),目标接口(destination interface)指示为接入端(access side)。For example, the communication policy of the first PIN element describes that the first PIN element can receive data packets from the second PIN element. The PDR included in the N4 rule includes the detection information of the data packet of the second PIN element. The detection information may include description information of the second PIN element. The FAR associated with the PDR indicates that when the UPF receives a data packet conforming to the detection information of the data packet of the second PIN element, it forwards the data packet to the first PIN element. For example, the action (action) of the FAR is indicated as forwarding, and the destination interface (destination interface) is indicated as the access side.
另外,PDR还可以包括描述除第二PIN元素的数据包之外的检测信息,如包括第三PIN元素的数据包的检测信息。该检测信息可以包括第三PIN元素的描述信息。该PDR关联的FAR指示了UPF接收到符合第三PIN元素的数据包的检测信息的数据包时,丢弃该数据包。In addition, the PDR may also include detection information describing data packets other than the data packet of the second PIN element, such as detection information of a data packet including the third PIN element. The detection information may include description information of the third PIN element. The FAR associated with the PDR indicates that when the UPF receives a data packet conforming to the detection information of the data packet of the third PIN element, it discards the data packet.
需要说明的是,在通信策略只包括上述PDR的情况下,第一网元可以根据上述第一检测信息发送第一检测信息对应的数据包,或者根据第二检测信息中丢弃第二检测信息对应的数据包。It should be noted that, when the communication strategy only includes the above-mentioned PDR, the first network element can send the data packet corresponding to the first detection information according to the above-mentioned first detection information, or discard the data packet corresponding to the second detection information according to the second detection information. data packets.
在通信策略只包括上述FAR的情况下,该FAR中包括上述第一检测信息和第二检测信息中的至少一项,从而直接根据FAR发送或者丢弃对应的数据包。In the case where the communication strategy only includes the FAR, the FAR includes at least one of the first detection information and the second detection information, so that the corresponding data packet is directly sent or discarded according to the FAR.
该实施方式中,通过上述PDR和FAR可以实现UPF根据第一PIN元素的通信策略对第一PIN元素关联的数据包授权控制。当然,在一些实施方式中,UPF获取的第一PIN元素的通信策略并不限定包括上述PDR和FAR,例如:可以通过其他信息来表示第一PIN元素的通信策略,本申请实施例对此不作限定。In this embodiment, through the above PDR and FAR, the UPF can realize the authorization control of the data packet associated with the first PIN element according to the communication policy of the first PIN element. Of course, in some implementations, the communication strategy of the first PIN element obtained by the UPF is not limited to include the above-mentioned PDR and FAR, for example: the communication strategy of the first PIN element can be represented by other information, and this embodiment of the present application does not make any limited.
作为一种可能的实施方式,所述第一网元为所述第一PIN元素或者所述 目标PIN元素,所述第一网元获取策略信息,包括:所述第一网元从AMF接收所述策略信息。As a possible implementation manner, the first network element is the first PIN element or the target PIN element, and obtaining the policy information by the first network element includes: receiving, by the first network element, the policy information.
该实施方式,可以实现第一PIN元素或者目标PIN元素根据第一PIN元素的通信策略对第一PIN元素关联的数据包进行授权控制。In this implementation manner, the first PIN element or the target PIN element can implement authorization control on data packets associated with the first PIN element according to the communication policy of the first PIN element.
本申请实施例中,第一网元获取策略信息,所述策略信息包括:第一个人物联网PIN元素的通信策略;所述第一网元根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制。这样根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this embodiment of the present application, the first network element obtains policy information, and the policy information includes: the communication policy of the first PIN element of the Internet of Things; Associated packets for authorization control. In this way, the data packets associated with the PIN element are authorized and controlled according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication security between devices.
请参见图3,图3是本申请实施例提供的另一种通信授权方法的流程图,如图3所示,包括以下步骤:Please refer to FIG. 3. FIG. 3 is a flowchart of another communication authorization method provided in the embodiment of the present application. As shown in FIG. 3, it includes the following steps:
步骤301、第二网元获取第一个人物联网PIN元素的第一通信策略; Step 301, the second network element acquires the first communication policy of the first IoT PIN element;
步骤302、所述第二网元向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。 Step 302, the second network element sends policy information to the first network element, the policy information includes: the second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is Determined according to the first communication policy of the first PIN element.
其中,上述第一PIN元素的第二通信策略为图2所示的实施例中的第一PIN元素的通信策略。Wherein, the above-mentioned second communication strategy of the first PIN element is the communication strategy of the first PIN element in the embodiment shown in FIG. 2 .
上述第一PIN元素的第二通信策略可以与第一PIN元素的第一通信策略相同,或者第一PIN元素的第二通信策略为第二网元根据第一PIN元素的第一通信策略生成的通信规则或者与第一通信策略存在形式上和/或内容上区别的通信策略。The second communication strategy of the above-mentioned first PIN element may be the same as the first communication strategy of the first PIN element, or the second communication strategy of the first PIN element is generated by the second network element according to the first communication strategy of the first PIN element A communication rule or a communication strategy that differs in form and/or content from the first communication strategy.
本实施例中,通过向第一网元发送策略信息,从而使得第一网元根据第一PIN元素的第二通信策略对第一PIN元素关联的数据包进行授权控制,以提高PIN元素的安全性。In this embodiment, by sending policy information to the first network element, the first network element performs authorization control on the data packets associated with the first PIN element according to the second communication policy of the first PIN element, so as to improve the security of the PIN element sex.
可选的,所述第一PIN元素的第二通信策略包括如下至少一项:Optionally, the second communication policy of the first PIN element includes at least one of the following:
允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略;A communication policy that allows the first PIN element to receive the data packet sent by the second PIN element;
禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略。A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
其中,上述第一PIN元素的第二通信策略请参见图2所示的实施例的相应说明,此处不作赘述。For the second communication strategy of the above-mentioned first PIN element, please refer to the corresponding description of the embodiment shown in FIG. 2 , which will not be repeated here.
可选的,所述第二网元获取第一PIN元素的第一通信策略,包括:Optionally, the second network element obtaining the first communication policy of the first PIN element includes:
所述第二网元从PIN元素通信策略网元接收第一PIN元素的第一通信策略;或者The second network element receives the first communication policy of the first PIN element from the PIN element communication policy network element; or
所述第二网元从PIN元素通信策略网元接收所述第一PIN元素所属的PIN的通信策略,所述PIN的通信策略包括第一PIN元素的第一通信策略。The second network element receives the communication policy of the PIN to which the first PIN element belongs from the PIN element communication policy network element, and the communication policy of the PIN includes the first communication policy of the first PIN element.
上述PIN元素通信策略网元可以是UDM或者PCF。The aforementioned PIN element communication policy network element may be UDM or PCF.
上述PIN的通信策略可以包括一个或者多个PIN元素的第一通信策略,例如:包括该PIN内一个或多个或所有PIN元素的第一通信策略。The above PIN communication policy may include a first communication policy of one or more PIN elements, for example: a first communication policy including one or more or all PIN elements in the PIN.
该实施方式中,上述从PIN元素通信策略网元接收通信策略可以是,从PIN元素通信策略网元接收PIN元素通信策略网元主动发送的通信策略,或者可以是,向PIN元素通信策略网元请求并获得通信策略。In this embodiment, the above-mentioned reception of the communication strategy from the PIN element communication strategy network element may be to receive the communication strategy actively sent by the PIN element communication strategy network element from the PIN element communication strategy network element, or may be to send the PIN element communication strategy network element Request and obtain a communications policy.
可选的,所述方法还包括:Optionally, the method also includes:
所述第二网元向所述PIN元素通信策略网元发送的通信策略请求,所述通信策略请求包括所述第一PIN元素的描述信息,或者,所述通信策略请求包括所述第一PIN元素所属的PIN的描述信息。A communication policy request sent by the second network element to the PIN element communication policy network element, where the communication policy request includes description information of the first PIN element, or, the communication policy request includes the first PIN Description information of the PIN to which the element belongs.
其中,上述通信策略请求可以为会话管理签约数据请求消息,或者(签约数据管理-获取请求服务(Nudm_SDM_Get请求服务)。上述PIN元素通信策略网元可以通过通信策略响应发送通信策略,该通信策略响应可以为会话管理签约数据响应消息或者Nudm_SDM_Get服务响应。Wherein, the above-mentioned communication strategy request may be a session management subscription data request message, or (subscription data management-acquisition request service (Nudm_SDM_Get request service). The above-mentioned PIN element communication strategy network element may send a communication strategy through a communication strategy response, and the communication strategy response It can be a session management subscription data response message or a Nudm_SDM_Get service response.
或者,上述通信策略请求可以为会话管理策略连接建立请求消息,或者会话管理策略控制创建(Npcf_SMPolicyControl_Create)服务请求;通信策略响应可以为会话管理策略连接建立响应消息,或者会话管理策略控制创建(Npcf_SMPolicyControl_Create)服务响应。Alternatively, the communication policy request may be a session management policy connection establishment request message, or a session management policy control creation (Npcf_SMPolicyControl_Create) service request; the communication policy response may be a session management policy connection establishment response message, or a session management policy control creation (Npcf_SMPolicyControl_Create) Service response.
该实施方式中,通过上述通信策略请求向PIN元素通信策略网元请求通信策略。In this embodiment, the communication policy is requested from the PIN element communication policy network element through the above communication policy request.
可选的,所述第二网元包括如下一项:Optionally, the second network element includes the following item:
服务于所述第一PIN元素的SMF、服务于所述第一PIN元素的AMF、所述第一PIN元素、目标PIN元素;an SMF serving the first PIN element, an AMF serving the first PIN element, the first PIN element, a target PIN element;
其中,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能 力的PIN元素。Wherein, the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs.
该实施方式中,可以实现服务于所述第一PIN元素的SMF、服务于所述第一PIN元素的AMF、所述第一PIN元素、或者目标PIN元素向第一网元发送第一PIN元素的第二通信策略。In this embodiment, the SMF serving the first PIN element, the AMF serving the first PIN element, the first PIN element, or the target PIN element can send the first PIN element to the first network element the second communication strategy.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述第二网元获取第一个PIN元素的第一通信策略包括:所述第二网元在所述第一PIN元素的会话建立过程中获取第一PIN元素的第一通信策略。Optionally, the second network element is an SMF serving the first PIN element, and obtaining the first communication policy of the first PIN element by the second network element includes: the second network element is in the The first communication policy of the first PIN element is acquired during the session establishment process of the first PIN element.
上述在所述第一PIN元素的会话建立过程中获取第一PIN元素的第一通信策略可以是,SMF在接收到第一PIN元素发起的PDU会话建立请求的情况下,从PIN元素通信策略网元获取第一PIN元素的第一通信策略。The above-mentioned first communication strategy for obtaining the first PIN element during the session establishment process of the first PIN element may be that, when the SMF receives the PDU session establishment request initiated by the first PIN element, it sends the PDU from the PIN element communication strategy network Element obtains the first communication policy of the first PIN element.
可选的,所述第二网元为服务于所述第一PIN元素的AMF,所述第二网元获取第一个PIN元素的第一通信策略包括:所述第二网元在所述第一PIN元素的注册过程或者会话建立过程中获取第一PIN元素的第一通信策略。Optionally, the second network element is an AMF serving the first PIN element, and obtaining the first communication policy of the first PIN element by the second network element includes: the second network element is in the The first communication policy of the first PIN element is acquired during the registration process of the first PIN element or the session establishment process.
上述在所述第一PIN元素的注册过程或者会话建立过程中获取第一PIN元素的第一通信策略可以是,AMF在接收到第一PIN元素发起的注册请求或者PDU会话建立请求的情况下,从PIN元素通信策略网元获取第一PIN元素的第一通信策略。可选的,AMF可以通过服务于所述第一PIN元素的SMF从PIN元素通信策略网元获取第一PIN元素的第一通信策略。The above-mentioned first communication strategy for obtaining the first PIN element during the registration process of the first PIN element or the session establishment process may be that, when the AMF receives a registration request initiated by the first PIN element or a PDU session establishment request, Obtain the first communication policy of the first PIN element from the PIN element communication policy network element. Optionally, the AMF may acquire the first communication policy of the first PIN element from the PIN element communication policy network element through the SMF serving the first PIN element.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述第二网元向第一网元发送策略信息,包括:所述第二网元向所述第一网元发送所述策略信息,所述第一网元包括UPF。Optionally, the second network element is an SMF serving the first PIN element, and sending policy information to the first network element by the second network element includes: sending the policy information to the first network element by the second network element A network element sends the policy information, and the first network element includes a UPF.
其中,上述SMF向UPF发送策略信息请参见图2所示的实施例的相应说明,此处不作赘述。For the policy information sent by the SMF to the UPF, please refer to the corresponding description of the embodiment shown in FIG. 2 , which will not be repeated here.
可选的,所述第一PIN元素的第二通信策略包括:Optionally, the second communication policy of the first PIN element includes:
PDR和FAR;PDRs and FARs;
其中,所述PDR包括如下至少一项:Wherein, the PDR includes at least one of the following:
允许所述第一PIN元素接收的数据包的第一检测信息;Allow the first detection information of the data packet received by the first PIN element;
禁止所述第一PIN元素接收的数据包的第二检测信息;Forbid the second detection information of the data packet received by the first PIN element;
所述FAR用于指示如下至少一项:The FAR is used to indicate at least one of the following:
在接收到符合所述第一检测信息的第一数据包的情况下,向所述第一PIN转发所述第一数据包;Forwarding the first data packet to the first PIN in case a first data packet conforming to the first detection information is received;
在接收到符合所述第二检测信息的第二数据包的情况下,丢弃所述第二数据包。In case of receiving a second data packet conforming to the second detection information, discarding the second data packet.
其中,上述PDR和FAR请参见图2所示的实施例的相应说明,此处不作赘述。For the above PDR and FAR, please refer to the corresponding description of the embodiment shown in FIG. 2 , which will not be repeated here.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述第二网元向第一网元发送策略信息,包括:所述第二网元通过AMF向所述第一网元发送所述策略信息;Optionally, the second network element is an SMF serving the first PIN element, and the second network element sends policy information to the first network element, including: the second network element sends the policy information to the sending the policy information by the first network element;
其中,所述第一网元包括目标PIN元素,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素;或者Wherein, the first network element includes a target PIN element, and the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs; or
所述第一网元包括所述第一PIN元素。The first network element includes the first PIN element.
上述第二网元通过AMF向所述第一网元发送所述策略信息可以是,SMF向上述目标PIN元素AMF发送上述策略信息,由该AMF向第一网元发送上述策略信息。例如:SMF向AMF发送消息传输请求消息或者通信传输请求消息(Namf_Communication_N1N2MessageTransfer服务),以发送PIN元素的第二通信策略。可选的,消息传输请求消息或者通信传输请求消息(Namf_Communication_N1N2MessageTransfer服务)中包括会话管理容器(N1SM container)包括第一PIN元素的第二通信策略。The sending of the policy information by the second network element to the first network element through the AMF may be that the SMF sends the policy information to the target PIN element AMF, and the AMF sends the policy information to the first network element. For example: the SMF sends a message transfer request message or a communication transfer request message (Namf_Communication_N1N2MessageTransfer service) to the AMF to send the second communication policy of the PIN element. Optionally, the message transfer request message or the communication transfer request message (Namf_Communication_N1N2MessageTransfer service) includes the second communication policy that the session management container (N1SM container) includes the first PIN element.
可选的,所述第二网元为服务于所述第一PIN元素的AMF,所述第二网元向第一网元发送策略信息,包括:所述第二网元向所述第一网元发送所述策略信息;Optionally, the second network element is an AMF serving the first PIN element, and sending policy information to the first network element by the second network element includes: sending the policy information to the first network element by the second network element The network element sends the policy information;
其中,所述第一网元包括目标PIN元素,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素;或者Wherein, the first network element includes a target PIN element, and the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs; or
所述第一网元包括所述第一PIN元素。The first network element includes the first PIN element.
上述第二网元向所述第一网元发送所述策略信息可以是,AMF从PIN元素通信策略网元或者SMF接收到第一PIN元素的第一通信策略后,向第一网元发送第一PIN元素的第二通信策略。The sending of the policy information by the second network element to the first network element may be that after the AMF receives the first communication policy of the first PIN element from the PIN element communication policy network element or the SMF, it sends the first communication policy to the first network element. A second communication strategy for a PIN element.
需要说明的是,本实施例作为与图2所示的实施例中对应的第二网元的 实施方式,其具体的实施方式可以参见图2所示的实施例的相关说明,以为避免重复说明,本实施例不再赘述。It should be noted that this embodiment is an implementation manner of the second network element corresponding to the embodiment shown in FIG. 2 , and its specific implementation manner can refer to the relevant description of the embodiment shown in FIG. 2 to avoid repeated descriptions. , which will not be described in detail in this embodiment.
本实施例中,通过向第一网元发送策略信息,从而使得第一网元根据第一PIN元素的第二通信策略对第一PIN元素关联的数据包进行授权控制,以提高PIN元素的安全性。In this embodiment, by sending policy information to the first network element, the first network element performs authorization control on the data packets associated with the first PIN element according to the second communication policy of the first PIN element, so as to improve the security of the PIN element sex.
下面以多个实施例对本申请实施例提供的方法进行举例说明:The method provided by the embodiment of the present application is illustrated below with multiple embodiments:
实施例1:Example 1:
该实施例以服务于PIN元素的UPF对PIN元素的数据包进行授权控制进行举例说明,如图4所示,以第一PIN元素的会话为PDU会话为例,该方法实施例包括以下步骤:This embodiment uses the UPF serving the PIN element to perform authorization control on the data packet of the PIN element as an example. As shown in FIG. 4 , taking the session of the first PIN element as a PDU session as an example, the method embodiment includes the following steps:
步骤1、PIN元素访问策略网元(例如可以是UDM或PCF)获取PIN元素的访问策略。Step 1, PIN element access policy The network element (for example, UDM or PCF) obtains the access policy of the PIN element.
其中,PIN元素的访问策略可以包括以下至少一项:Wherein, the access policy of the PIN element may include at least one of the following:
双向通信策略,即可以互相通信的PIN元素/设备的描述信息;Two-way communication strategy, that is, the description information of PIN elements/devices that can communicate with each other;
单向通信策略,即特定PIN元素/设备可以向哪些PIN元素发送数据,或者特定PIN元素可以接收哪些PIN元素/设备发送的数据;One-way communication strategy, that is, to which PIN elements a specific PIN element/device can send data to, or which PIN elements/devices a specific PIN element can receive data from;
PIN元素/设备的描述信息可以包括以下至少一项:The description information of the PIN element/device may include at least one of the following:
该PIN元素/设备的IP地址;the IP address of the PIN element/device;
该PIN元素/设备的MAC地址;MAC address of the PIN element/device;
该PIN元素/设备的标识,包括但不限于外部标识,GPSI,FQDN,IMSI,SUCI或SUPI,临时标识,在PIN中的唯一标识;The identification of the PIN element/device, including but not limited to external identification, GPSI, FQDN, IMSI, SUCI or SUPI, temporary identification, unique identification in the PIN;
该PIN元素/设备发送的数据包所使用的VLAN标识;The VLAN identifier used by the data packet sent by the PIN element/device;
该PIN元素/设备发送的数据包所使用的UPD端口号。The UPD port number used by the packet sent by this PIN element/device.
步骤2、第一PIN元素向AMF发送NAS消息,其中包括PDU会话建立请求。Step 2. The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
可选的,NAS消息中包括PDU会话建立参数,例如数据网络名称(Data Network Name,DNN)和/或网络切片选择辅助信息(network slice selection assistance information,NSSAI)。Optionally, the NAS message includes PDU session establishment parameters, such as data network name (Data Network Name, DNN) and/or network slice selection assistance information (network slice selection assistance information, NSSAI).
步骤3、AMF接收到NAS消息,向SMF转发其中的PDU会话建立请求。Step 3, AMF receives the NAS message, and forwards the PDU session establishment request therein to the SMF.
可选的,AMF可以根据其中的PDU会话建立参数选择SMF,AMF也可以根据配置信息选择SMF。Optionally, the AMF may select the SMF according to the PDU session establishment parameters therein, and the AMF may also select the SMF according to the configuration information.
步骤4、SMF从PIN元素通信策略网元获取PIN元素的通信策略(例如:访问策略)。Step 4. The SMF acquires the communication policy (eg access policy) of the PIN element from the PIN element communication policy network element.
SMF可以获取到PIN元素所属PIN的PIN元素通信策略,也可以获取该PIN元素通信策略中与第一PIN元素相关的通信策略。The SMF may obtain the PIN element communication strategy of the PIN to which the PIN element belongs, and may also obtain the communication strategy related to the first PIN element in the PIN element communication strategy.
一种可能的方式中,SMF是配置为该PIN元素或该PIN元素所属的PIN服务的SMF。PIN元素通信策略网元在步骤1获取PIN元素的通信策略后,即可以向SMF发送PIN元素的通信策略。In a possible manner, the SMF is an SMF configured to serve the PIN element or the PIN to which the PIN element belongs. PIN element communication policy After the network element acquires the communication policy of the PIN element in step 1, it can send the communication policy of the PIN element to the SMF.
另一种可能的方式中,SMF向PIN元素通信策略网元发送PIN元素的通信策略请求消息,该请求消息可以包括第一PIN元素的标识,或第一PIN元素所属的PIN的标识。可选的,还可以包括PIN元素的通信策略请求指示。SMF从PIN元素通信策略网元接收PIN元素的通信策略响应消息,该响应消息包括PIN元素的通信策略。In another possible manner, the SMF sends a PIN element communication policy request message to the PIN element communication policy network element, where the request message may include the identifier of the first PIN element, or the identifier of the PIN to which the first PIN element belongs. Optionally, a communication policy request indication of a PIN element may also be included. The SMF receives a communication policy response message of the PIN element from the PIN element communication policy network element, and the response message includes the communication policy of the PIN element.
示例性的,PIN元素的通信策略请求消息可以为会话管理签约数据请求消息,或者Nudm_SDM_Get请求服务;PIN元素的通信策略响应消息可以为会话管理签约数据响应消息或者Nudm_SDM_Get服务响应。Exemplarily, the communication policy request message of the PIN element may be a session management subscription data request message, or a Nudm_SDM_Get service request message; the communication policy response message of the PIN element may be a session management subscription data response message or a Nudm_SDM_Get service response.
或者,示例性的,PIN元素的通信策略请求消息可以为会话管理策略连接建立请求消息,或者Npcf_SMPolicyControl_Create服务;PIN元素的通信策略响应消息可以为会话管理策略连接建立响应消息,或者Npcf_SMPolicyControl_Create服务响应。Or, for example, the communication policy request message of the PIN element may be a session management policy connection establishment request message, or an Npcf_SMPolicyControl_Create service; the communication policy response message of the PIN element may be a session management policy connection establishment response message, or an Npcf_SMPolicyControl_Create service response.
步骤5、SMF向服务于该PDU会话的UPF发送N4规则,该N4规则指示UPF可以向第一PIN元素发送的数据包,或者,该N4规则指示UPF不能向第一PIN元素发送的数据包。Step 5. The SMF sends the N4 rule to the UPF serving the PDU session, the N4 rule indicates the data packet that the UPF can send to the first PIN element, or the N4 rule indicates the data packet that the UPF cannot send to the first PIN element.
SMF根据PIN元素的通信策略确定N4规则。The SMF determines the N4 rule according to the communication policy of the PIN element.
例如,PIN元素的通信策略中描述了第一PIN元素能够接收来第二PIN元素的数据。N4规则中包括PDR和FAR。PDR中包括第二PIN元素的数据包的检测信息。该检测信息可以包括第二PIN元素的描述信息,第二PIN元素的描述信息可以参考步骤1中PIN元素的描述信息的描述。该PDR关联的 FAR指示了UPF接收到符合第二PIN元素的数据包的检测信息的数据包时,向PIN element1转发该数据包。例如FAR的行为(action)指示为转发(forwarding),目标接口(destination interface)指示为接入端(access side)。For example, the communication policy of the PIN element describes that the first PIN element can receive data from the second PIN element. N4 rules include PDR and FAR. The PDR includes the detection information of the data packet of the second PIN element. The detection information may include description information of the second PIN element, and the description information of the second PIN element may refer to the description of the description information of the PIN element in step 1. The FAR associated with the PDR indicates that when the UPF receives a data packet conforming to the detection information of the data packet of the second PIN element, it forwards the data packet to PIN element1. For example, the action (action) of FAR indicates forwarding (forwarding), and the destination interface (destination interface) indicates access side (access side).
可选的,PDR还可以包括描述除第二PIN元素的数据包之外的检测信息。例如,该检测信息可以包括第三PIN元素的描述信息,第三PIN元素的描述信息可以参考步骤1中PIN元素的描述信息的描述。该PDR关联的FAR指示了UPF接收到符合该除第二PIN元素的数据包的检测信息的数据包时,丢弃该数据包。Optionally, the PDR may also include detection information describing the data packet other than the second PIN element. For example, the detection information may include description information of the third PIN element, and the description information of the third PIN element may refer to the description of the description information of the PIN element in step 1. The FAR associated with the PDR indicates that when the UPF receives a data packet conforming to the detection information of the data packet except the second PIN element, it discards the data packet.
步骤6a、UPF接收到第二PIN元素的数据包,UPF根据N4规则转发该数据包;Step 6a, the UPF receives the data packet of the second PIN element, and the UPF forwards the data packet according to the N4 rule;
步骤6b、UPF接收到第三PIN元素或者其他UE或设备的数据包,UPF根据N4规则丢弃该数据包。In step 6b, the UPF receives the third PIN element or data packets of other UEs or devices, and the UPF discards the data packets according to the N4 rule.
本实施例中,根据通信策略转发第二PIN元素向第一PIN元素发送的数据包,而丢弃第三PIN元素向第一PIN元素发送的数据,以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this embodiment, the data packet sent by the second PIN element to the first PIN element is forwarded according to the communication policy, and the data sent by the third PIN element to the first PIN element is discarded, so as to realize the data packet associated with the PIN element according to the policy information Authorization control is carried out, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices.
实施例2:Example 2:
该实施例以具备网关能力的PIN元素对PIN元素的数据包进行授权控制进行举例说明,如图5所示,以第一PIN元素的会话为PDU会话为例,该方法实施例包括以下步骤:This embodiment uses the PIN element with gateway capability to perform authorization control on the data packet of the PIN element as an example. As shown in FIG. 5, taking the session of the first PIN element as a PDU session as an example, the method embodiment includes the following steps:
步骤1、PIN元素访问策略网元(例如可以是UDM或PCF)获取PIN元素的访问策略。Step 1, PIN element access policy The network element (for example, UDM or PCF) obtains the access policy of the PIN element.
步骤2、第一PIN元素向AMF发送NAS消息,其中包括PDU会话建立请求。Step 2. The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
步骤3、AMF接收到NAS消息,向SMF转发其中的PDU会话建立请求。Step 3, AMF receives the NAS message, and forwards the PDU session establishment request therein to the SMF.
步骤4、SMF从PIN元素通信策略网元获取PIN元素的通信策略(例如:访问策略)。Step 4. The SMF acquires the communication policy (eg access policy) of the PIN element from the PIN element communication policy network element.
其中,步骤1至4参考实施例一的描述,此处不作赘述。Wherein, for steps 1 to 4, refer to the description of Embodiment 1, and details are not repeated here.
步骤5、SMF向UPF下发N4规则,用于建立N4会话。Step 5. The SMF sends the N4 rule to the UPF for establishing the N4 session.
步骤1-5为可选步骤。Steps 1-5 are optional.
步骤6、SMF向服务与具备网关能力的PIN元素(PIN element with GW(gateway)capability)的AMF发送PIN元素的通信策略(例如:访问策略)。Step 6. The SMF sends the communication policy (for example: access policy) of the PIN element to the AMF serving the PIN element with GW (gateway) capability.
示例性的,SMF向AMF发送消息传输请求消息或者Namf_Communication_N1N2MessageTransfer服务,其中包括PIN元素的访问策略。Exemplarily, the SMF sends a message transfer request message or Namf_Communication_N1N2MessageTransfer service to the AMF, which includes the access policy of the PIN element.
可选的,消息传输请求消息或者Namf_Communication_N1N2MessageTransfer服务中包括N1SM container,其中包括PIN元素的访问策略。Optionally, the message transfer request message or the Namf_Communication_N1N2MessageTransfer service includes the N1SM container, which includes the access policy of the PIN element.
步骤7、AMF向具备网关能力的PIN元素发送步骤6中接收到的PIN元素的通信策略。In step 7, the AMF sends the communication policy of the PIN element received in step 6 to the PIN element with gateway capability.
步骤8a、具备网关能力的PIN元素接收到第二PIN元素的数据包,根据PIN元素的访问策略转发该数据包;Step 8a, the PIN element with gateway capability receives the data packet of the second PIN element, and forwards the data packet according to the access policy of the PIN element;
步骤8b、具备网关能力的PIN元素接收到第三PIN元素或者其他UE或设备的数据包,根据PIN元素的访问策略丢弃该数据包。Step 8b, the PIN element with gateway capability receives the third PIN element or the data packet of other UE or device, and discards the data packet according to the access policy of the PIN element.
PIN元素的通信策略的描述和举例可以参考实施例一中的说明。For the description and examples of the communication policy of the PIN element, refer to the description in Embodiment 1.
本实施例中,根据通信策略转发第二PIN元素向第一PIN元素发送的数据包,而丢弃第三PIN元素向第一PIN元素发送的数据,以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this embodiment, the data packet sent by the second PIN element to the first PIN element is forwarded according to the communication policy, and the data sent by the third PIN element to the first PIN element is discarded, so as to realize the data packet associated with the PIN element according to the policy information Authorization control is carried out, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices.
实施例3:Example 3:
该实施例以第一PIN元素对PIN元素的数据包进行授权控制进行举例说明,如图6所示,以第一PIN元素的会话为PDU会话为例,该方法实施例包括以下步骤:This embodiment uses the first PIN element to perform authorization control on the data packet of the PIN element as an example. As shown in FIG. 6, taking the session of the first PIN element as a PDU session as an example, the method embodiment includes the following steps:
步骤1、PIN元素访问策略网元(例如可以是UDM或PCF)获取PIN元素的访问策略。Step 1, PIN element access policy The network element (for example, UDM or PCF) obtains the access policy of the PIN element.
步骤2、第一PIN元素向AMF发送NAS消息,其中包括PDU会话建立请求。Step 2. The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
步骤3、AMF接收到NAS消息,向SMF转发其中的PDU会话建立请求。Step 3, AMF receives the NAS message, and forwards the PDU session establishment request therein to the SMF.
步骤4、SMF从PIN元素通信策略网元获取PIN元素的通信策略(例如:访问策略)。Step 4. The SMF acquires the communication policy (eg access policy) of the PIN element from the PIN element communication policy network element.
步骤5、SMF向UPF下发N4规则,用于建立N4会话。Step 5. The SMF sends the N4 rule to the UPF for establishing the N4 session.
其中,步骤1至5参考实施例二的描述,此处不作赘述。步骤1-5为可选步骤。Wherein, for steps 1 to 5, refer to the description of Embodiment 2, and details are not repeated here. Steps 1-5 are optional.
步骤6、SMF向AMF发送PIN元素的通信策略(例如:访问策略)。该AMF为服务于第一PIN元素的AMF。Step 6. The SMF sends the communication policy (for example: access policy) of the PIN element to the AMF. The AMF is the AMF serving the first PIN element.
示例性的,SMF向AMF发送消息传输请求消息或者Namf_Communication_N1N2MessageTransfer服务,其中包括PIN元素的访问策略。Exemplarily, the SMF sends a message transfer request message or Namf_Communication_N1N2MessageTransfer service to the AMF, which includes the access policy of the PIN element.
可选的,消息传输请求消息或者Namf_Communication_N1N2MessageTransfer服务中包括的N1SM container包括PIN元素的访问策略。Optionally, the N1SM container included in the message transfer request message or the Namf_Communication_N1N2MessageTransfer service includes the access policy of the PIN element.
步骤7、AMF向第一PIN元素发送步骤6中接收到的PIN元素的通信策略。In step 7, the AMF sends the communication policy of the PIN element received in step 6 to the first PIN element.
步骤8a、第一PIN元素接收到第二PIN元素的数据包,根据PIN元素的接收该数据包;Step 8a, the first PIN element receives the data packet of the second PIN element, and receives the data packet according to the PIN element;
步骤8b、第一PIN元素接收到第三PIN元素或者其他UE或设备的数据包,根据PIN元素的通信策略丢弃该数据包。Step 8b, the first PIN element receives the third PIN element or data packets of other UEs or devices, and discards the data packets according to the communication policy of the PIN element.
PIN元素的通信策略的描述和举例可以参考实施例一中的说明。For the description and examples of the communication policy of the PIN element, refer to the description in Embodiment 1.
本实施例中,根据通信策略接收第二PIN元素向第一PIN元素发送的数据包,而丢弃第三PIN元素向第一PIN元素发送的数据,以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this embodiment, the data packet sent by the second PIN element to the first PIN element is received according to the communication policy, and the data sent by the third PIN element to the first PIN element is discarded, so as to realize the data packet associated with the PIN element according to the policy information Authorization control is carried out, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices.
实施例4:Example 4:
该实施例以具备网关能力的PIN元素对PIN元素的数据包进行授权控制进行举例说明,如图7所示,以第一PIN元素的会话为PDU会话为例,该方法实施例包括以下步骤:In this embodiment, the PIN element with gateway capability performs authorization control on the data packet of the PIN element as an example. As shown in FIG. 7, taking the session of the first PIN element as a PDU session as an example, the method embodiment includes the following steps:
步骤1、PIN元素访问策略网元(例如可以是UDM或PCF)获取PIN 元素的访问策略。Step 1, PIN element access policy The network element (for example, UDM or PCF) obtains the access policy of the PIN element.
步骤2、第一PIN元素向AMF发送NAS消息,其中包括PDU会话建立请求。Step 2. The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
步骤3、AMF接收到NAS消息,向SMF转发其中的PDU会话建立请求。Step 3, AMF receives the NAS message, and forwards the PDU session establishment request therein to the SMF.
其中,步骤1至3参考实施例二的描述,此处不作赘述。步骤1-3为可选步骤。Wherein, for steps 1 to 3, refer to the description of Embodiment 2, and details are not repeated here. Steps 1-3 are optional.
步骤4、AMF从PIN元素通信策略网元获取PIN元素的通信策略(例如:访问策略)。Step 4. The AMF obtains the communication policy (for example: access policy) of the PIN element from the PIN element communication policy network element.
该步骤可以参考实施例一步骤4的说明,其中把SMF替换成AMF。会话管理签约数据请求消息替换为签约数据请求消息。移动性管理策略请求消息或UE/PIN元素策略请求消息For this step, reference may be made to the description of Step 4 of Embodiment 1, wherein SMF is replaced with AMF. The session management subscription data request message is replaced by the subscription data request message. Mobility Management Policy Request message or UE/PIN Element Policy Request message
示例性的,PIN元素的通信策略请求消息可以为签约数据请求消息,或者Nudm_SDM_Get请求服务;PIN元素的通信策略响应消息可以为签约数据响应消息或者Nudm_SDM_Get服务响应。Exemplarily, the communication policy request message of the PIN element may be a subscription data request message, or a Nudm_SDM_Get service request message; the communication policy response message of the PIN element may be a subscription data response message or a Nudm_SDM_Get service response.
或者,示例性的,PIN元素的通信策略请求消息可以为移动性管理策略连接建立请求消息,移动性管理策略连接修改请求消息,UE/PIN元素策略控制建立请求消息,UE/PIN元素策略控制修改请求消息,如AM策略控制建立消息(Npcf_AMPolicyControl_Create服务),AM策略控制更新消息(Npcf_AMPolicyControl_Update服务),UE策略控制建立消息(Npcf_UEPolicyControl_Create服务),或者UE策略控制更新消息(Npcf_UEPolicyControl_Update服务);PIN元素的访问策略响应消息可以为移动性管理策略连接建立响应消息,移动性管理策略连接修改响应消息,UE/PIN元素策略控制建立响应消息,UE/PIN元素策略控制修改响应消息,如Npcf_AMPolicyControl_Create服务响应,Npcf_AMPolicyControl_Update服务响应,Npcf_UEPolicyControl_Create服务响应,或者Npcf_UEPolicyControl_Update服务响应。Or, exemplary, the communication policy request message of the PIN element may be a mobility management policy connection establishment request message, a mobility management policy connection modification request message, a UE/PIN element policy control establishment request message, and a UE/PIN element policy control modification request message Request message, such as AM policy control establishment message (Npcf_AMPolicyControl_Create service), AM policy control update message (Npcf_AMPolicyControl_Update service), UE policy control establishment message (Npcf_UEPolicyControl_Create service), or UE policy control update message (Npcf_UEPolicyControl_Update service); access policy of PIN element The response message can be a mobility management policy connection establishment response message, a mobility management policy connection modification response message, a UE/PIN element policy control establishment response message, and a UE/PIN element policy control modification response message, such as Npcf_AMPolicyControl_Create service response, Npcf_AMPolicyControl_Update service response , Npcf_UEPolicyControl_Create service response, or Npcf_UEPolicyControl_Update service response.
该步骤也可以在步骤6后执行,或者在第一PIN元素注册到AMF的时候执行。This step can also be performed after step 6, or when the first PIN element is registered with the AMF.
步骤5、SMF向UPF下发N4规则,用于建立N4会话。Step 5. The SMF sends the N4 rule to the UPF for establishing the N4 session.
步骤6、SMF向AMF发送会话建立响应消息。Step 6. The SMF sends a session establishment response message to the AMF.
步骤7、AMF向具备网关能力的PIN元素发送步骤6中接收到的PIN元素的通信策略。In step 7, the AMF sends the communication policy of the PIN element received in step 6 to the PIN element with gateway capability.
步骤8a、具备网关能力的PIN元素接收到第二PIN元素的数据包,根据PIN元素的访问策略转发该数据包;Step 8a, the PIN element with gateway capability receives the data packet of the second PIN element, and forwards the data packet according to the access policy of the PIN element;
步骤8b、具备网关能力的PIN元素接收到第三PIN元素或者其他UE或设备的数据包,根据PIN元素的访问策略丢弃该数据包。Step 8b, the PIN element with gateway capability receives the third PIN element or the data packet of other UE or device, and discards the data packet according to the access policy of the PIN element.
其中,步骤7至8参考实施例二的描述,此处不作赘述。Wherein, for steps 7 to 8, refer to the description of Embodiment 2, and details are not repeated here.
PIN元素的通信策略的描述和举例可以参考实施例一中的说明。For the description and examples of the communication policy of the PIN element, refer to the description in Embodiment 1.
本实施例中,根据通信策略转发第二PIN元素向第一PIN元素发送的数据包,而丢弃第三PIN元素向第一PIN元素发送的数据,以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this embodiment, the data packet sent by the second PIN element to the first PIN element is forwarded according to the communication policy, and the data sent by the third PIN element to the first PIN element is discarded, so as to realize the data packet associated with the PIN element according to the policy information Authorization control is carried out, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices.
实施例5:Example 5:
该实施例以第一PIN元素对PIN元素的数据包进行授权控制进行举例说明,如图8所示,以第一PIN元素的会话为PDU会话为例,该方法实施例包括以下步骤:This embodiment uses the first PIN element to perform authorization control on the data packet of the PIN element as an example. As shown in FIG. 8 , taking the session of the first PIN element as a PDU session as an example, the method embodiment includes the following steps:
步骤1、PIN元素访问策略网元(例如可以是UDM或PCF)获取PIN元素的访问策略。Step 1, PIN element access policy The network element (for example, UDM or PCF) obtains the access policy of the PIN element.
步骤2、第一PIN元素向AMF发送NAS消息,其中包括PDU会话建立请求。Step 2. The first PIN element sends a NAS message to the AMF, which includes a PDU session establishment request.
步骤3、AMF接收到NAS消息,向SMF转发其中的PDU会话建立请求。Step 3, AMF receives the NAS message, and forwards the PDU session establishment request therein to the SMF.
步骤4、AMF从PIN元素通信策略网元获取PIN元素的通信策略(例如:访问策略)。Step 4. The AMF obtains the communication policy (for example: access policy) of the PIN element from the PIN element communication policy network element.
步骤5、SMF向UPF下发N4规则,用于建立N4会话。Step 5. The SMF sends the N4 rule to the UPF for establishing the N4 session.
步骤6、SMF向AMF发送会话建立响应消息。Step 6. The SMF sends a session establishment response message to the AMF.
其中,步骤1至6参考实施例四的描述,此处不作赘述。Wherein, steps 1 to 6 refer to the description of Embodiment 4, which will not be repeated here.
步骤7、AMF向第一PIN元素发送步骤6中接收到的PIN元素的通信策略。In step 7, the AMF sends the communication policy of the PIN element received in step 6 to the first PIN element.
步骤8a、第一PIN元素接收到第二PIN元素的数据包,根据PIN元素的接收该数据包;Step 8a, the first PIN element receives the data packet of the second PIN element, and receives the data packet according to the PIN element;
步骤8b、第一PIN元素接收到第三PIN元素或者其他UE或设备的数据包,根据PIN元素的通信策略丢弃该数据包。Step 8b, the first PIN element receives the third PIN element or data packets of other UEs or devices, and discards the data packets according to the communication policy of the PIN element.
其中,步骤7至8参考实施例三的描述,此处不作赘述。Wherein, for steps 7 to 8, refer to the description of Embodiment 3, and details are not repeated here.
PIN元素的通信策略的描述和举例可以参考实施例一中的说明。For the description and examples of the communication policy of the PIN element, refer to the description in Embodiment 1.
本实施例中,根据通信策略转发第二PIN元素向第一PIN元素发送的数据包,而丢弃第三PIN元素向第一PIN元素发送的数据,以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this embodiment, the data packet sent by the second PIN element to the first PIN element is forwarded according to the communication policy, and the data sent by the third PIN element to the first PIN element is discarded, so as to realize the data packet associated with the PIN element according to the policy information Authorization control is carried out, thereby avoiding communication between devices without communication authority, and ensuring communication security between devices.
需要说明的是,上述实施例1至5均是以数据包为目的地址指示第一PIN元素为例进行说明,本申请实施例中,对第一PIN元素关联的数据包还可以包括源地址指示第一PIN元素。例如:在第一PIN元素的通信策略包括允许第一PIN元素与第二PIN元素通信,禁止第一PIN元素与第三PIN元素通信的情况下:It should be noted that the above-mentioned embodiments 1 to 5 all take the data packet as an example to indicate the first PIN element as the destination address. In the embodiment of the present application, the data packet associated with the first PIN element may also include a source address indication The first PIN element. For example: in the case where the communication policy of the first PIN element includes allowing the first PIN element to communicate with the second PIN element and prohibiting the communication between the first PIN element and the third PIN element:
示例性的,PIN元素访问策略中描述了第一PIN元素能够向第二PIN元素发送数据。可选的,PIN元素访问策略中描述了禁止第一PIN元素向第三PIN元素发送数据。在上述实施例1中,步骤6a和6b分别如下:Exemplarily, the PIN element access policy describes that the first PIN element can send data to the second PIN element. Optionally, the PIN element access policy describes that the first PIN element is prohibited from sending data to the third PIN element. In above-mentioned embodiment 1, steps 6a and 6b are as follows respectively:
步骤6a、UPF接收到第一PIN元素发送的目的地址指示为第二PIN元素的数据包,UPF根据N4规则向第二PIN元素转发该数据包;Step 6a, the UPF receives the data packet sent by the first PIN element indicating that the destination address is the second PIN element, and the UPF forwards the data packet to the second PIN element according to the N4 rule;
步骤6b、UPF接收到第一PIN元素发送的目的地址指示为第三PIN元素的数据包,UPF根据N4规则丢弃该数据包。In step 6b, the UPF receives the data packet sent by the first PIN element and indicates that the destination address is the third PIN element, and the UPF discards the data packet according to the N4 rule.
在上述实施例2中,步骤8a和8b分别如下:In above-mentioned embodiment 2, steps 8a and 8b are as follows respectively:
步骤8a、具备网关能力的PIN元素接收到第一PIN元素发送的目的地址指示为第二PIN元素的数据包,根据PIN元素的通信策略向第二PIN元素转发该数据包;Step 8a, the PIN element having the gateway capability receives the data packet sent by the first PIN element indicating the destination address as the second PIN element, and forwards the data packet to the second PIN element according to the communication policy of the PIN element;
步骤8b、具备网关能力的PIN元素接收到第一PIN元素发送的目的地址指示为第三PIN元素的数据包,根据PIN元素的访问策略丢弃该数据包。Step 8b: The PIN element with gateway capability receives the data packet sent by the first PIN element indicating that the destination address is the third PIN element, and discards the data packet according to the access policy of the PIN element.
在上述实施例3中,步骤8a和8b分别如下:In above-mentioned embodiment 3, steps 8a and 8b are as follows respectively:
步骤8a、第一PIN元素需要发送目的地址指示为第二PIN元素的数据包时,根据PIN元素的通信策略向第二PIN元素发送数据包;Step 8a, when the first PIN element needs to send a data packet whose destination address is indicated as the second PIN element, send the data packet to the second PIN element according to the communication policy of the PIN element;
步骤8b、第一PIN元素需要发送目的地址指示为第三PIN元素的数据包时,根据PIN元素的通信策略丢弃该数据包,或者不发送目的地址指示为第三PIN元素的数据包。Step 8b: When the first PIN element needs to send the data packet whose destination address is indicated as the third PIN element, the data packet is discarded according to the communication strategy of the PIN element, or the data packet whose destination address is indicated as the third PIN element is not sent.
在上述实施例4中,步骤8a和8b分别如下:In above-mentioned embodiment 4, steps 8a and 8b are as follows respectively:
步骤8a、具备网关能力的PIN元素接收到第一PIN元素发送的目的地址指示为第二PIN元素的数据包,根据PIN元素的通信策略向第二PIN元素转发该数据包;Step 8a, the PIN element having the gateway capability receives the data packet sent by the first PIN element indicating the destination address as the second PIN element, and forwards the data packet to the second PIN element according to the communication policy of the PIN element;
步骤8b、具备网关能力的PIN元素接收到第一PIN元素发送的目的地址指示为第三PIN元素的数据包,根据PIN元素的访问策略丢弃该数据包。Step 8b: The PIN element with gateway capability receives the data packet sent by the first PIN element indicating that the destination address is the third PIN element, and discards the data packet according to the access policy of the PIN element.
在上述实施例5中,步骤8a和8b分别如下:In above-mentioned embodiment 5, steps 8a and 8b are as follows respectively:
步骤8a、第一PIN元素需要发送目的地址指示为第二PIN元素的数据包,根据PIN元素的通信策略向第二PIN元素发送数据包;Step 8a, the first PIN element needs to send the data packet whose destination address is indicated as the second PIN element, and send the data packet to the second PIN element according to the communication strategy of the PIN element;
步骤8b、第一PIN元素需要发送目的地址指示为第三PIN元素的数据包,根据PIN元素的通信策略丢弃该数据包,或者不发送目的地址指示为第三PIN元素的数据包。Step 8b, the first PIN element needs to send the data packet whose destination address is indicated as the third PIN element, and discards the data packet according to the communication policy of the PIN element, or does not send the data packet whose destination address is indicated as the third PIN element.
本实施例中,可以实现根据策略信息对源地址指示为第一PIN元素的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this embodiment, authorization control can be implemented on data packets whose source address is indicated as the first PIN element according to policy information, thereby avoiding communication between devices without communication authority and ensuring communication security between devices.
请参见图9,图9是本申请实施例提供的一种通信授权装置的结构图,如图9所示,通信授权装置900包括:Please refer to FIG. 9. FIG. 9 is a structural diagram of a communication authorization device provided by an embodiment of the present application. As shown in FIG. 9, the communication authorization device 900 includes:
获取模块901,用于获取策略信息,所述策略信息包括:第一个人物联网PIN元素的通信策略;An acquisition module 901, configured to acquire policy information, where the policy information includes: a communication policy of the first IoT PIN element;
控制模块902,用于根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制。The control module 902 is configured to perform authorization control on data packets associated with the first PIN element according to the policy information.
其中,上述通信授权装置包含在第一网元内,或者称作第一网元包括上述通信授权装置,第一网元参见上述方法实施例的相应描述,此处不作赘述。Wherein, the above-mentioned communication authorization device is included in the first network element, or referred to as the first network element including the above-mentioned communication authorization device, and the first network element refers to the corresponding description of the above-mentioned method embodiment, which will not be repeated here.
可选的,所述对所述第一PIN元素关联的数据包进行授权控制,包括如 下至少一项:Optionally, the authorization control of the data packet associated with the first PIN element includes at least one of the following:
向所述第一PIN元素发送所述第一PIN元素关联的第一数据包;sending a first data packet associated with the first PIN element to the first PIN element;
丢弃所述第一PIN元素关联的第二数据包;Discarding the second data packet associated with the first PIN element;
接收所述第一PIN元素关联的第三数据包。receiving a third data packet associated with the first PIN element.
可选的,所述向所述第一PIN元素发送所述第一PIN元素关联的第一数据包,包括:Optionally, the sending the first data packet associated with the first PIN element to the first PIN element includes:
在所述第一PIN元素的通信策略包括允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略的情况下,向所述第一PIN元素发送所述第一PIN元素关联的第一数据包,其中,所述第一数据包为所述第二PIN元素向所述第一PIN元素发送的数据包。In the case where the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive a data packet sent by the second PIN element, send the first PIN element associated information to the first PIN element A first data packet, wherein the first data packet is a data packet sent by the second PIN element to the first PIN element.
可选的,所述丢弃所述第一PIN元素关联的第二数据包,包括:Optionally, the discarding the second data packet associated with the first PIN element includes:
在所述第一PIN元素的通信策略包括禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略的情况下,丢弃所述第一PIN元素关联的第二数据包,其中,所述第二数据包为所述第三PIN元素向所述第一PIN元素发送的数据包;或者In the case where the communication strategy of the first PIN element includes a communication strategy that prohibits the first PIN element from receiving a data packet sent by a third PIN element, discarding the second data packet associated with the first PIN element, wherein, The second data packet is a data packet sent by the third PIN element to the first PIN element; or
在所述第一PIN元素的通信策略不包括允许所述第一PIN元素接收第三PIN元素发送的数据包的通信策略的情况下,丢弃所述第一PIN元素关联的第二数据包,其中,所述第二数据包为所述第三PIN元素向所述第一PIN元素发送的数据包。When the communication policy of the first PIN element does not include a communication policy that allows the first PIN element to receive a data packet sent by a third PIN element, discarding the second data packet associated with the first PIN element, wherein , the second data packet is a data packet sent by the third PIN element to the first PIN element.
可选的,所述接收所述第一PIN元素关联的第三数据包,包括:Optionally, the receiving the third data packet associated with the first PIN element includes:
在所述第一PIN元素的通信策略包括允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略的情况下,接收所述第二PIN元素发送的所述第一PIN元素关联的第三数据包。In the case where the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive data packets sent by the second PIN element, receiving the first PIN element sent by the second PIN element is associated with of the third packet.
可选的,所述第一网元包括如下一项:Optionally, the first network element includes the following item:
用户面功能UPF、所述第一PIN元素、目标PIN元素;User plane function UPF, said first PIN element, target PIN element;
其中,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素。Wherein, the target PIN element is a PIN element with gateway capability among the PINs to which the first PIN element belongs.
可选的,所述第一网元为用户面功能UPF,所述第一网元获取策略信息,包括:所述第一网元从会话管理功能SMF接收所述策略信息。Optionally, the first network element is a user plane function UPF, and the acquiring policy information by the first network element includes: the first network element receiving the policy information from a session management function SMF.
可选的,所述第一网元为所述第一PIN元素或者所述目标PIN元素,所述第一网元获取策略信息,包括:所述第一网元从接入和移动管理功能AMF接收所述策略信息。Optionally, the first network element is the first PIN element or the target PIN element, and the acquisition of policy information by the first network element includes: the first network element obtains the policy information from the access and mobility management function AMF The policy information is received.
可选的,所述第一PIN元素的通信策略包括如下至少一项:Optionally, the communication policy of the first PIN element includes at least one of the following:
包检测规则PDR和转发行为规则FAR;Packet detection rule PDR and forwarding behavior rule FAR;
其中,所述PDR包括如下至少一项:Wherein, the PDR includes at least one of the following:
允许所述第一PIN元素接收的数据包的第一检测信息;Allow the first detection information of the data packet received by the first PIN element;
禁止所述第一PIN元素接收的数据包的第二检测信息;Forbid the second detection information of the data packet received by the first PIN element;
所述FAR用于指示如下至少一项:The FAR is used to indicate at least one of the following:
在接收到符合所述第一检测信息的第一数据包的情况下,向所述第一PIN元素转发所述第一数据包;Forwarding the first data packet to the first PIN element in case a first data packet conforming to the first detection information is received;
在接收到符合所述第二检测信息的第二数据包的情况下,丢弃所述第二数据包。In case of receiving a second data packet conforming to the second detection information, discarding the second data packet.
本申请实施例中的通信授权装置根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。The communication authorization device in the embodiment of the present application performs authorization control on data packets associated with PIN elements according to policy information, thereby avoiding communication between devices without communication authority and ensuring communication security between devices.
本申请实施例中的通信授权装置可以是装置,具有操作系统的装置或电子设备,也可以是第一网元中的部件、集成电路、或芯片。The communication authorization device in this embodiment of the present application may be a device, a device with an operating system or an electronic device, or may be a component, an integrated circuit, or a chip in the first network element.
本申请实施例提供的通信授权装置能够实现图2的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The communication authorization device provided by the embodiment of the present application can realize each process realized by the method embodiment in FIG. 2 and achieve the same technical effect. To avoid repetition, details are not repeated here.
请参见图10,图10是本申请实施例提供的一种通信授权装置的结构图,如图10所示,通信授权装置1000包括:Please refer to FIG. 10, which is a structural diagram of a communication authorization device provided by an embodiment of the present application. As shown in FIG. 10, the communication authorization device 1000 includes:
获取模块1001,用于获取第一个人物联网PIN元素的第一通信策略;An acquisition module 1001, configured to acquire a first communication strategy of the first IoT PIN element;
发送模块1002,用于向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。A sending module 1002, configured to send policy information to a first network element, where the policy information includes: a second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is based on the determined by the first communication policy of the first PIN element.
其中,上述通信授权装置包含在第二网元内,或者称作第二网元包括上述通信授权装置,第一网元参见上述方法实施例的相应描述,此处不作赘述。Wherein, the above-mentioned communication authorization device is included in the second network element, or referred to as the second network element including the above-mentioned communication authorization device, and the first network element refers to the corresponding description of the above-mentioned method embodiment, which will not be repeated here.
可选的,所述第一PIN元素的第二通信策略包括如下至少一项:Optionally, the second communication policy of the first PIN element includes at least one of the following:
允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略;A communication policy that allows the first PIN element to receive the data packet sent by the second PIN element;
禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略。A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
可选的,所述获取第一PIN元素的第一通信策略,包括:Optionally, the acquiring the first communication policy of the first PIN element includes:
从PIN元素通信策略网元接收第一PIN元素的第一通信策略;或者receiving a first communication policy for a first PIN element from a PIN element communication policy network element; or
从PIN元素通信策略网元接收所述第一PIN元素所属的PIN的通信策略,所述PIN的通信策略包括第一PIN元素的第一通信策略。The communication policy of the PIN to which the first PIN element belongs is received from the PIN element communication policy network element, where the communication policy of the PIN includes the first communication policy of the first PIN element.
可选的,所述装置还包括:Optionally, the device also includes:
请求模块,用于向所述PIN元素通信策略网元发送的通信策略请求,所述通信策略请求包括所述第一PIN元素的描述信息,或者,所述通信策略请求包括所述第一PIN元素所属的PIN的描述信息。A request module, configured to send a communication policy request to the PIN element communication policy network element, where the communication policy request includes description information of the first PIN element, or, the communication policy request includes the first PIN element Description information of the PIN to which it belongs.
可选的,所述第二网元包括如下一项:Optionally, the second network element includes the following item:
服务于所述第一PIN元素的会话管理功能SMF、服务于所述第一PIN元素的接入和移动管理功能AMF、所述第一PIN元素、目标PIN元素;a session management function SMF serving said first PIN element, an access and mobility management function AMF serving said first PIN element, said first PIN element, a target PIN element;
其中,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素。Wherein, the target PIN element is a PIN element with gateway capability among the PINs to which the first PIN element belongs.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述获取第一个PIN元素的第一通信策略包括:在所述第一PIN元素的会话建立过程中获取第一PIN元素的第一通信策略;或者Optionally, the second network element is an SMF serving the first PIN element, and the obtaining the first communication policy of the first PIN element includes: obtaining during the session establishment process of the first PIN element a first communication policy for a first PIN element; or
所述第二网元为服务于所述第一PIN元素的AMF,所述获取第一个PIN元素的第一通信策略包括:在所述第一PIN元素的注册过程或者会话建立过程中获取第一PIN元素的第一通信策略。The second network element is an AMF serving the first PIN element, and the acquiring the first communication policy of the first PIN element includes: acquiring the first PIN element during a registration process or a session establishment process of the first PIN element. A first communication strategy for a PIN element.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述向第一网元发送策略信息,包括:向所述第一网元发送所述策略信息,所述第一网元包括用户面功能UPF。Optionally, the second network element is an SMF serving the first PIN element, and the sending the policy information to the first network element includes: sending the policy information to the first network element, the The first network element includes a user plane function UPF.
可选的,所述第一PIN元素的第二通信策略包括如下至少一项:Optionally, the second communication policy of the first PIN element includes at least one of the following:
包检测规则PDR和转发行为规则FAR;Packet detection rule PDR and forwarding behavior rule FAR;
其中,所述PDR包括如下至少一项:Wherein, the PDR includes at least one of the following:
允许所述第一PIN元素接收的数据包的第一检测信息;Allow the first detection information of the data packet received by the first PIN element;
禁止所述第一PIN元素接收的数据包的第二检测信息;Forbid the second detection information of the data packet received by the first PIN element;
所述FAR用于指示如下至少一项:The FAR is used to indicate at least one of the following:
在接收到符合所述第一检测信息的第一数据包的情况下,向所述第一PIN转发所述第一数据包;Forwarding the first data packet to the first PIN in case a first data packet conforming to the first detection information is received;
在接收到符合所述第二检测信息的第二数据包的情况下,丢弃所述第二数据包。In case of receiving a second data packet conforming to the second detection information, discarding the second data packet.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述向第一网元发送策略信息,包括:通过AMF向所述第一网元发送所述策略信息;Optionally, the second network element is an SMF serving the first PIN element, and the sending the policy information to the first network element includes: sending the policy information to the first network element through AMF;
其中,所述第一网元包括目标PIN元素,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素;或者Wherein, the first network element includes a target PIN element, and the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs; or
所述第一网元包括所述第一PIN元素。The first network element includes the first PIN element.
可选的,所述第二网元为服务于所述第一PIN元素的AMF,所述向第一网元发送策略信息,包括:向所述第一网元发送所述策略信息;Optionally, the second network element is an AMF serving the first PIN element, and the sending the policy information to the first network element includes: sending the policy information to the first network element;
其中,所述第一网元包括目标PIN元素,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素;或者Wherein, the first network element includes a target PIN element, and the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs; or
所述第一网元包括所述第一PIN元素。The first network element includes the first PIN element.
本申请实施例中的通信授权装置向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。The communication authorization device in the embodiment of the present application sends policy information to the first network element, so that the first network element performs authorization control on the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication authority, The communication security between devices is guaranteed.
本申请实施例中的通信授权装置可以是装置,具有操作系统的装置或电子设备,也可以是第二网元中的部件、集成电路、或芯片。The communication authorization device in this embodiment of the present application may be a device, a device with an operating system or an electronic device, or may be a component, an integrated circuit, or a chip in the second network element.
本申请实施例提供的通信授权装置能够实现图3的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The communication authorization device provided by the embodiment of the present application can realize each process realized by the method embodiment in FIG. 3 and achieve the same technical effect. To avoid repetition, details are not repeated here.
可选的,如图11所示,本申请实施例还提供一种通信设备1100,包括处理器1101,存储器1102,存储在存储器1102上并可在所述处理器1101上运行的程序或指令,例如,该通信设备1100为第一网元时,该程序或指令被处理器1101执行时实现上述第一网元侧的通信授权方法实施例的各个过程,且能达到相同的技术效果。该通信设备1100为第二网元时,该程序或指令被处理器1101执行时实现上述第二网元侧的通信授权方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。该通信设备为终端或 者网络侧设备。Optionally, as shown in FIG. 11 , this embodiment of the present application further provides a communication device 1100, including a processor 1101, a memory 1102, and programs or instructions stored in the memory 1102 and operable on the processor 1101, For example, when the communication device 1100 is the first network element, when the program or instruction is executed by the processor 1101, each process of the above embodiment of the communication authorization method on the first network element side can be realized, and the same technical effect can be achieved. When the communication device 1100 is the second network element, when the program or the instruction is executed by the processor 1101, each process of the above embodiment of the communication authorization method on the second network element side can be achieved, and the same technical effect can be achieved. In order to avoid repetition, I won't go into details here. The communication device is a terminal or a network side device.
本申请实施例还提供一种通信设备,包括处理器和通信接口,其中,所述处理器或者通信接口用于:获取策略信息,所述策略信息包括:第一PIN元素的通信策略;根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制。The embodiment of the present application also provides a communication device, including a processor and a communication interface, wherein the processor or the communication interface is used to: obtain policy information, and the policy information includes: a communication policy of the first PIN element; according to the The policy information is used to perform authorization control on data packets associated with the first PIN element.
或者,所述通信接口用于:获取第一PIN元素的第一通信策略;向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。Alternatively, the communication interface is configured to: obtain a first communication policy of the first PIN element; send policy information to the first network element, where the policy information includes: a second communication policy of the first PIN element, wherein the The second communication policy of the first PIN element is determined according to the first communication policy of the first PIN element.
本实施例中,这样可以实现根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。或者可以实现向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。In this embodiment, in this way, the data packets associated with the PIN element can be authorized and controlled according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication security between devices. Alternatively, policy information can be sent to the first network element, so that the first network element can authorize and control the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication between devices Safety.
该通信设备实施例是与上述图2和图3所示的方法实施例对应的,上述方法实施例的各个实施过程和实现方式均可适用于该通信设备实施例中,且能达到相同的技术效果。This communication device embodiment corresponds to the method embodiment shown in the above-mentioned Figure 2 and Figure 3, and each implementation process and implementation method of the above-mentioned method embodiment can be applied to this communication device embodiment, and can achieve the same technology Effect.
具体地,图12为实现本申请实施例的一种第一网元的硬件结构示意图。需要说明的是,本实施例中,以第一网元为PIN元素,PIN元素为终端进行举例说明:Specifically, FIG. 12 is a schematic diagram of a hardware structure of a first network element implementing an embodiment of the present application. It should be noted that, in this embodiment, the first network element is used as a PIN element, and the PIN element is used as an example for illustration:
该第一网元1200包括但不限于:射频单元1201、网络模块1202、音频输出单元1203、输入单元1204、传感器1205、显示单元1206、用户输入单元1207、接口单元1208、存储器1209、以及处理器1210等中的至少部分部件。The first network element 1200 includes but not limited to: a radio frequency unit 1201, a network module 1202, an audio output unit 1203, an input unit 1204, a sensor 1205, a display unit 1206, a user input unit 1207, an interface unit 1208, a memory 1209, and a processor 1210 etc. at least some of the components.
本领域技术人员可以理解,第一网元1200还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器1210逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。图12中示出的第一网元结构并不构成对通信设备的限定,第一网元可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。Those skilled in the art can understand that the first network element 1200 may also include a power supply (such as a battery) for supplying power to various components, and the power supply may be logically connected to the processor 1210 through the power management system, so that the management of charging, discharging, and power management functions. The structure of the first network element shown in FIG. 12 does not constitute a limitation on the communication device. The first network element may include more or fewer components than shown in the figure, or combine some components, or arrange different components. This will not be repeated here.
应理解的是,本申请实施例中,输入单元1204可以包括图形处理器(Graphics Processing Unit,GPU)12041和麦克风12042,图形处理器12041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元1206可包括显示面板12061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板12061。用户输入单元1207包括触控面板12071以及其他输入设备12072。触控面板12071,也称为触摸屏。触控面板12071可包括触摸检测装置和触摸控制器两个部分。其他输入设备12072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。It should be understood that, in the embodiment of the present application, the input unit 1204 may include a graphics processor (Graphics Processing Unit, GPU) 12041 and a microphone 12042, and the graphics processor 12041 is used for the image capture device ( Such as the image data of the still picture or video obtained by the camera) for processing. The display unit 1206 may include a display panel 12061, and the display panel 12061 may be configured in the form of a liquid crystal display, an organic light emitting diode, or the like. The user input unit 1207 includes a touch panel 12071 and other input devices 12072 . Touch panel 12071, also called touch screen. The touch panel 12071 may include two parts, a touch detection device and a touch controller. Other input devices 12072 may include, but are not limited to, physical keyboards, function keys (such as volume control keys, switch keys, etc.), trackballs, mice, and joysticks, which will not be repeated here.
本申请实施例中,射频单元1201将来自网络侧设备的下行数据接收后,给处理器1210处理;另外,将上行的数据发送给网络侧设备。通常,射频单元1201包括但不限于天线、至少一个放大器、收发信机、耦合器、低噪声放大器、双工器等。In the embodiment of the present application, the radio frequency unit 1201 receives the downlink data from the network side device, and processes it to the processor 1210; in addition, sends the uplink data to the network side device. Generally, the radio frequency unit 1201 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, and the like.
存储器1209可用于存储软件程序或指令以及各种数据。存储器1209可主要包括存储程序或指令区和存储数据区,其中,存储程序或指令区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器1209可以包括高速随机存取存储器,还可以包括非易失性存储器,其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。例如至少一个磁盘存储器件、闪存器件、或其他非易失性固态存储器件。The memory 1209 can be used to store software programs or instructions as well as various data. The memory 1209 may mainly include a program or instruction storage area and a data storage area, wherein the program or instruction storage area may store an operating system, an application program or instructions required by at least one function (such as a sound playback function, an image playback function, etc.) and the like. In addition, the memory 1209 may include a high-speed random access memory, and may also include a nonvolatile memory, wherein the nonvolatile memory may be a read-only memory (Read-Only Memory, ROM), a programmable read-only memory (Programmable ROM) , PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) or flash memory. For example at least one magnetic disk storage device, flash memory device, or other non-volatile solid-state storage device.
处理器1210可包括一个或多个处理单元;可选的,处理器1210可集成应用处理器和调制解调处理器,其中,应用处理器主要处理操作系统、用户界面和应用程序或指令等,调制解调处理器主要处理无线通信,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器1210中。The processor 1210 may include one or more processing units; optionally, the processor 1210 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface, application programs or instructions, etc., Modem processors mainly handle wireless communications, such as baseband processors. It can be understood that the foregoing modem processor may not be integrated into the processor 1210 .
其中,射频单元1201或者处理器1210,用于获取策略信息,所述策略信息包括:第一个人物联网PIN元素的通信策略;根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制。Wherein, the radio frequency unit 1201 or the processor 1210 is used to acquire policy information, the policy information includes: the communication policy of the first IoT PIN element; according to the policy information, the data packet associated with the first PIN element Perform authorization control.
可选的,所述对所述第一PIN元素关联的数据包进行授权控制,包括如下至少一项:Optionally, the authorization control of the data packet associated with the first PIN element includes at least one of the following:
向所述第一PIN元素发送所述第一PIN元素关联的第一数据包;sending a first data packet associated with the first PIN element to the first PIN element;
丢弃所述第一PIN元素关联的第二数据包;Discarding the second data packet associated with the first PIN element;
接收所述第一PIN元素关联的第三数据包。receiving a third data packet associated with the first PIN element.
可选的,所述向所述第一PIN元素发送所述第一PIN元素关联的第一数据包,包括:Optionally, the sending the first data packet associated with the first PIN element to the first PIN element includes:
在所述第一PIN元素的通信策略包括允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略的情况下,向所述第一PIN元素发送所述第一PIN元素关联的第一数据包,其中,所述第一数据包为所述第二PIN元素向所述第一PIN元素发送的数据包。In the case where the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive a data packet sent by the second PIN element, send the first PIN element associated information to the first PIN element A first data packet, wherein the first data packet is a data packet sent by the second PIN element to the first PIN element.
可选的,所述丢弃所述第一PIN元素关联的第二数据包,包括:Optionally, the discarding the second data packet associated with the first PIN element includes:
在所述第一PIN元素的通信策略包括禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略的情况下,丢弃所述第一PIN元素关联的第二数据包,其中,所述第二数据包为所述第三PIN元素向所述第一PIN元素发送的数据包;或者In the case where the communication strategy of the first PIN element includes a communication strategy that prohibits the first PIN element from receiving a data packet sent by a third PIN element, discarding the second data packet associated with the first PIN element, wherein, The second data packet is a data packet sent by the third PIN element to the first PIN element; or
在所述第一PIN元素的通信策略不包括允许所述第一PIN元素接收第三PIN元素发送的数据包的通信策略的情况下,丢弃所述第一PIN元素关联的第二数据包,其中,所述第二数据包为所述第三PIN元素向所述第一PIN元素发送的数据包。When the communication policy of the first PIN element does not include a communication policy that allows the first PIN element to receive a data packet sent by a third PIN element, discarding the second data packet associated with the first PIN element, wherein , the second data packet is a data packet sent by the third PIN element to the first PIN element.
可选的,所述接收所述第一PIN元素关联的第三数据包,包括:Optionally, the receiving the third data packet associated with the first PIN element includes:
在所述第一PIN元素的通信策略包括允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略的情况下,接收所述第二PIN元素发送的所述第一PIN元素关联的第三数据包。In the case where the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive data packets sent by the second PIN element, receiving the first PIN element sent by the second PIN element is associated with of the third packet.
可选的,所述第一网元包括如下一项:Optionally, the first network element includes the following item:
用户面功能UPF、所述第一PIN元素、目标PIN元素;User plane function UPF, said first PIN element, target PIN element;
其中,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素。Wherein, the target PIN element is a PIN element with gateway capability among the PINs to which the first PIN element belongs.
可选的,所述第一网元为用户面功能UPF,所述获取策略信息,包括: 从会话管理功能SMF接收所述策略信息。Optionally, the first network element is a user plane function UPF, and the acquiring policy information includes: receiving the policy information from a session management function SMF.
可选的,所述第一网元为所述第一PIN元素或者所述目标PIN元素,所述获取策略信息,包括:从接入和移动管理功能AMF接收所述策略信息。Optionally, the first network element is the first PIN element or the target PIN element, and the acquiring policy information includes: receiving the policy information from an access and mobility management function AMF.
可选的,所述第一PIN元素的通信策略包括如下至少一项:Optionally, the communication policy of the first PIN element includes at least one of the following:
包检测规则PDR和转发行为规则FAR;Packet detection rule PDR and forwarding behavior rule FAR;
其中,所述PDR包括如下至少一项:Wherein, the PDR includes at least one of the following:
允许所述第一PIN元素接收的数据包的第一检测信息;Allow the first detection information of the data packet received by the first PIN element;
禁止所述第一PIN元素接收的数据包的第二检测信息;Forbid the second detection information of the data packet received by the first PIN element;
所述FAR用于指示如下至少一项:The FAR is used to indicate at least one of the following:
在接收到符合所述第一检测信息的第一数据包的情况下,向所述第一PIN元素转发所述第一数据包;Forwarding the first data packet to the first PIN element in case a first data packet conforming to the first detection information is received;
在接收到符合所述第二检测信息的第二数据包的情况下,丢弃所述第二数据包。In case of receiving a second data packet conforming to the second detection information, discarding the second data packet.
上述第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。The above-mentioned first network element performs authorization control on the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication authority and ensuring communication security between devices.
具体地,本发明实施例的终端还包括:存储在存储器1209上并可在处理器1210上运行的指令或程序,处理器1210调用存储器1209中的指令或程序执行图9所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。Specifically, the terminal in this embodiment of the present invention also includes: instructions or programs stored in the memory 1209 and operable on the processor 1210, and the processor 1210 calls the instructions or programs in the memory 1209 to execute the functions executed by the modules shown in FIG. method, and achieve the same technical effect, in order to avoid repetition, it is not repeated here.
具体地,本申请实施例还提供了一种第二网元。该实施例中,以第二网元为核心网网元进行举例说明:如图13所示,该第二网元1300包括:收发装置1301。Specifically, the embodiment of the present application also provides a second network element. In this embodiment, the second network element is used as an example for illustration: as shown in FIG. 13 , the second network element 1300 includes: a transceiver device 1301 .
收发装置1301,用于获取第一PIN元素的第一通信策略;向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。Transceiving means 1301, configured to acquire a first communication policy of a first PIN element; send policy information to a first network element, where the policy information includes: a second communication policy of the first PIN element, wherein the first The second communication policy of the PIN element is determined according to the first communication policy of the first PIN element.
可选的,所述第一PIN元素的第二通信策略包括如下至少一项:Optionally, the second communication policy of the first PIN element includes at least one of the following:
允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略;A communication policy that allows the first PIN element to receive the data packet sent by the second PIN element;
禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略。A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
可选的,所述获取第一PIN元素的第一通信策略,包括:Optionally, the acquiring the first communication policy of the first PIN element includes:
从PIN元素通信策略网元接收第一PIN元素的第一通信策略;或者receiving a first communication policy for a first PIN element from a PIN element communication policy network element; or
从PIN元素通信策略网元接收所述第一PIN元素所属的PIN的通信策略,所述PIN的通信策略包括第一PIN元素的第一通信策略。The communication policy of the PIN to which the first PIN element belongs is received from the PIN element communication policy network element, where the communication policy of the PIN includes the first communication policy of the first PIN element.
可选的,收发装置1301还用于:Optionally, the transceiver 1301 is also used for:
向所述PIN元素通信策略网元发送的通信策略请求,所述通信策略请求包括所述第一PIN元素的描述信息,或者,所述通信策略请求包括所述第一PIN元素所属的PIN的描述信息。A communication policy request sent to the PIN element communication policy network element, where the communication policy request includes description information of the first PIN element, or, the communication policy request includes a description of the PIN to which the first PIN element belongs information.
可选的,所述第二网元包括如下一项:Optionally, the second network element includes the following item:
服务于所述第一PIN元素的会话管理功能SMF、服务于所述第一PIN元素的接入和移动管理功能AMF、所述第一PIN元素、目标PIN元素;a session management function SMF serving said first PIN element, an access and mobility management function AMF serving said first PIN element, said first PIN element, a target PIN element;
其中,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素。Wherein, the target PIN element is a PIN element with gateway capability among the PINs to which the first PIN element belongs.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述获取第一个PIN元素的第一通信策略包括:在所述第一PIN元素的会话建立过程中获取第一PIN元素的第一通信策略;或者Optionally, the second network element is an SMF serving the first PIN element, and the obtaining the first communication policy of the first PIN element includes: obtaining during the session establishment process of the first PIN element a first communication policy for a first PIN element; or
所述第二网元为服务于所述第一PIN元素的AMF,所述获取第一个PIN元素的第一通信策略包括:在所述第一PIN元素的注册过程或者会话建立过程中获取第一PIN元素的第一通信策略。The second network element is an AMF serving the first PIN element, and the acquiring the first communication policy of the first PIN element includes: acquiring the first PIN element during a registration process or a session establishment process of the first PIN element. A first communication strategy for a PIN element.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述向第一网元发送策略信息,包括:向所述第一网元发送所述策略信息,所述第一网元包括用户面功能UPF。Optionally, the second network element is an SMF serving the first PIN element, and the sending the policy information to the first network element includes: sending the policy information to the first network element, the The first network element includes a user plane function UPF.
可选的,所述第一PIN元素的第二通信策略包括如下至少一项:Optionally, the second communication policy of the first PIN element includes at least one of the following:
包检测规则PDR和转发行为规则FAR;Packet detection rule PDR and forwarding behavior rule FAR;
其中,所述PDR包括如下至少一项:Wherein, the PDR includes at least one of the following:
允许所述第一PIN元素接收的数据包的第一检测信息;Allow the first detection information of the data packet received by the first PIN element;
禁止所述第一PIN元素接收的数据包的第二检测信息;Forbid the second detection information of the data packet received by the first PIN element;
所述FAR用于指示如下至少一项:The FAR is used to indicate at least one of the following:
在接收到符合所述第一检测信息的第一数据包的情况下,向所述第一 PIN转发所述第一数据包;Forwarding the first data packet to the first PIN in case a first data packet conforming to the first detection information is received;
在接收到符合所述第二检测信息的第二数据包的情况下,丢弃所述第二数据包。In case of receiving a second data packet conforming to the second detection information, discarding the second data packet.
可选的,所述第二网元为服务于所述第一PIN元素的SMF,所述向第一网元发送策略信息,包括:通过AMF向所述第一网元发送所述策略信息;Optionally, the second network element is an SMF serving the first PIN element, and the sending the policy information to the first network element includes: sending the policy information to the first network element through AMF;
其中,所述第一网元包括目标PIN元素,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素;或者Wherein, the first network element includes a target PIN element, and the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs; or
所述第一网元包括所述第一PIN元素。The first network element includes the first PIN element.
可选的,所述第二网元为服务于所述第一PIN元素的AMF,所述向第一网元发送策略信息,包括:向所述第一网元发送所述策略信息;Optionally, the second network element is an AMF serving the first PIN element, and the sending the policy information to the first network element includes: sending the policy information to the first network element;
其中,所述第一网元包括目标PIN元素,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素;或者Wherein, the first network element includes a target PIN element, and the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs; or
所述第一网元包括所述第一PIN元素。The first network element includes the first PIN element.
上述第二网元向第一网元发送策略信息,使得第一网元根据策略信息对PIN元素关联的数据包进行授权控制,从而避免了无通信权限的设备之间的通信,保证了设备间的通信安全。The above-mentioned second network element sends policy information to the first network element, so that the first network element performs authorization control on the data packets associated with the PIN element according to the policy information, thereby avoiding communication between devices without communication authority, and ensuring the communication between devices. communication security.
具体地,本发明实施例的第二网元还包括:存储在存储器1302上并可在处理器1303上运行的指令或程序,处理器1303调用存储器1302中的指令或程序执行图10所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。Specifically, the second network element in the embodiment of the present invention further includes: instructions or programs stored in the memory 1302 and executable on the processor 1303, and the processor 1303 invokes the instructions or programs in the memory 1302 to execute the The method of module execution achieves the same technical effect, so in order to avoid repetition, it is not repeated here.
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,所述程序或指令被处理器执行时实现本申请实施例提供的第一网元侧的通信授权方法中的步骤,或者,所述程序或指令被处理器执行时实现本申请实施例提供的第二网元侧的通信授权方法中的步骤。The embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by the processor, the communication on the first network element side provided by the embodiment of the present application is realized. The steps in the authorization method, or, when the program or instruction is executed by the processor, implement the steps in the communication authorization method on the second network element side provided by the embodiment of the present application.
其中,所述处理器为上述实施例中所述的第一网元或者第二网元中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等。Wherein, the processor is the processor in the first network element or the second network element described in the foregoing embodiments. The readable storage medium includes computer readable storage medium, such as computer read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk, etc.
本申请实施例还提供了一种系统,该系统包括第一网元和第二网元,其 中,第一网元用于:获取策略信息,所述策略信息包括:第一个人物联网PIN元素的通信策略;以及根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制;An embodiment of the present application also provides a system, the system includes a first network element and a second network element, wherein the first network element is used to: obtain policy information, and the policy information includes: the first IoT PIN element communication policy; and according to the policy information, perform authorization control on the data packet associated with the first PIN element;
第二网元,用于获取第一个人物联网PIN元素的第一通信策略;以及向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。The second network element is used to acquire the first communication policy of the first IoT PIN element; and send policy information to the first network element, where the policy information includes: the second communication policy of the first PIN element, wherein , the second communication policy of the first PIN element is determined according to the first communication policy of the first PIN element.
本申请实施例还提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述通信授权方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。The embodiment of the present application also provides a chip, the chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the above communication authorization method embodiment Each process can achieve the same technical effect, so in order to avoid repetition, it will not be repeated here.
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。It should be understood that the chip mentioned in the embodiment of the present application may also be called a system-on-chip, a system-on-chip, a system-on-a-chip, or a system-on-a-chip.
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。It should be noted that, in this document, the term "comprising", "comprising" or any other variation thereof is intended to cover a non-exclusive inclusion such that a process, method, article or apparatus comprising a set of elements includes not only those elements, It also includes other elements not expressly listed, or elements inherent in the process, method, article, or device. Without further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved. Functions are performed, for example, the described methods may be performed in an order different from that described, and various steps may also be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以计算机软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁 碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general-purpose hardware platform, and of course also by hardware, but in many cases the former is better implementation. Based on such an understanding, the technical solution of the present application can be embodied in the form of computer software products, which are stored in a storage medium (such as ROM/RAM, magnetic disk, etc.) , CD-ROM), including several instructions to make a terminal (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) execute the methods described in the various embodiments of the present application.
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。The embodiments of the present application have been described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementations. The above-mentioned specific implementations are only illustrative and not restrictive. Those of ordinary skill in the art will Under the inspiration of this application, without departing from the purpose of this application and the scope of protection of the claims, many forms can also be made, all of which belong to the protection of this application.

Claims (29)

  1. 一种通信授权方法,包括:A communication authorization method, comprising:
    第一网元获取策略信息,所述策略信息包括:第一个人物联网PIN元素的通信策略;The first network element obtains policy information, and the policy information includes: a communication policy of the first IoT PIN element;
    所述第一网元根据所述策略信息,对所述第一PIN元素关联的数据包进行授权控制。The first network element performs authorization control on data packets associated with the first PIN element according to the policy information.
  2. 如权利要求1所述的方法,其中,所述对所述第一PIN元素关联的数据包进行授权控制,包括如下至少一项:The method according to claim 1, wherein the authorization control of the data packet associated with the first PIN element includes at least one of the following:
    向所述第一PIN元素发送所述第一PIN元素关联的第一数据包;sending a first data packet associated with the first PIN element to the first PIN element;
    丢弃所述第一PIN元素关联的第二数据包;Discarding the second data packet associated with the first PIN element;
    接收所述第一PIN元素关联的第三数据包。receiving a third data packet associated with the first PIN element.
  3. 如权利要求2所述的方法,其中,所述向所述第一PIN元素发送所述第一PIN元素关联的第一数据包,包括:The method according to claim 2, wherein the sending the first data packet associated with the first PIN element to the first PIN element comprises:
    在所述第一PIN元素的通信策略包括允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略的情况下,向所述第一PIN元素发送所述第一PIN元素关联的第一数据包,其中,所述第一数据包为所述第二PIN元素向所述第一PIN元素发送的数据包。In the case where the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive a data packet sent by the second PIN element, send the first PIN element associated information to the first PIN element A first data packet, wherein the first data packet is a data packet sent by the second PIN element to the first PIN element.
  4. 如权利要求2所述的方法,其中,所述丢弃所述第一PIN元素关联的第二数据包,包括:The method according to claim 2, wherein the discarding the second data packet associated with the first PIN element comprises:
    在所述第一PIN元素的通信策略包括禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略的情况下,丢弃所述第一PIN元素关联的第二数据包,其中,所述第二数据包为所述第三PIN元素向所述第一PIN元素发送的数据包;或者In the case where the communication strategy of the first PIN element includes a communication strategy that prohibits the first PIN element from receiving a data packet sent by a third PIN element, discarding the second data packet associated with the first PIN element, wherein, The second data packet is a data packet sent by the third PIN element to the first PIN element; or
    在所述第一PIN元素的通信策略不包括允许所述第一PIN元素接收第三PIN元素发送的数据包的通信策略的情况下,丢弃所述第一PIN元素关联的第二数据包,其中,所述第二数据包为所述第三PIN元素向所述第一PIN元素发送的数据包。When the communication policy of the first PIN element does not include a communication policy that allows the first PIN element to receive a data packet sent by a third PIN element, discarding the second data packet associated with the first PIN element, wherein , the second data packet is a data packet sent by the third PIN element to the first PIN element.
  5. 如权利要求2所述的方法,其中,所述接收所述第一PIN元素关联的 第三数据包,包括:The method according to claim 2, wherein said receiving the third data packet associated with said first PIN element comprises:
    在所述第一PIN元素的通信策略包括允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略的情况下,接收所述第二PIN元素发送的所述第一PIN元素关联的第三数据包。In the case where the communication policy of the first PIN element includes a communication policy that allows the first PIN element to receive data packets sent by the second PIN element, receiving the first PIN element sent by the second PIN element is associated with of the third packet.
  6. 如权利要求1所述的方法,其中,所述第一网元包括如下一项:The method according to claim 1, wherein the first network element comprises one of the following:
    用户面功能UPF、所述第一PIN元素、目标PIN元素;User plane function UPF, said first PIN element, target PIN element;
    其中,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素。Wherein, the target PIN element is a PIN element with gateway capability among the PINs to which the first PIN element belongs.
  7. 如权利要求6所述的方法,其中,所述第一网元为用户面功能UPF,所述第一网元获取策略信息,包括:所述第一网元从会话管理功能SMF接收所述策略信息。The method according to claim 6, wherein the first network element is a user plane function (UPF), and obtaining policy information by the first network element comprises: the first network element receives the policy from a session management function (SMF) information.
  8. 如权利要求6所述的方法,其中,所述第一网元为所述第一PIN元素或者所述目标PIN元素,所述第一网元获取策略信息,包括:所述第一网元从接入和移动管理功能AMF接收所述策略信息。The method according to claim 6, wherein the first network element is the first PIN element or the target PIN element, and obtaining policy information by the first network element comprises: the first network element obtains policy information from The Access and Mobility Management Function AMF receives said policy information.
  9. 如权利要求7所述的方法,其中,所述第一PIN元素的通信策略包括如下至少一项:The method of claim 7, wherein the communication policy of the first PIN element includes at least one of the following:
    包检测规则PDR和转发行为规则FAR;Packet detection rule PDR and forwarding behavior rule FAR;
    其中,所述PDR包括如下至少一项:Wherein, the PDR includes at least one of the following:
    允许所述第一PIN元素接收的数据包的第一检测信息;Allow the first detection information of the data packet received by the first PIN element;
    禁止所述第一PIN元素接收的数据包的第二检测信息;Forbid the second detection information of the data packet received by the first PIN element;
    所述FAR用于指示如下至少一项:The FAR is used to indicate at least one of the following:
    在接收到符合所述第一检测信息的第一数据包的情况下,向所述第一PIN元素转发所述第一数据包;Forwarding the first data packet to the first PIN element in case a first data packet conforming to the first detection information is received;
    在接收到符合所述第二检测信息的第二数据包的情况下,丢弃所述第二数据包。In case of receiving a second data packet conforming to the second detection information, discarding the second data packet.
  10. 一种通信授权方法,包括:A communication authorization method, comprising:
    第二网元获取第一个人物联网PIN元素的第一通信策略;The second network element obtains the first communication strategy of the first IoT PIN element;
    所述第二网元向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据 所述第一PIN元素的第一通信策略确定的。The second network element sends policy information to the first network element, where the policy information includes: a second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is based on the determined by the first communication policy of the first PIN element.
  11. 如权利要求10所述的方法,其中,所述第一PIN元素的第二通信策略包括如下至少一项:The method of claim 10, wherein the second communication policy of the first PIN element includes at least one of the following:
    允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略;A communication policy that allows the first PIN element to receive the data packet sent by the second PIN element;
    禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略。A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
  12. 如权利要求10或11所述的方法,其中,所述第二网元获取第一PIN元素的第一通信策略,包括:The method according to claim 10 or 11, wherein said second network element acquiring the first communication policy of the first PIN element comprises:
    所述第二网元从PIN元素通信策略网元接收第一PIN元素的第一通信策略;或者The second network element receives the first communication policy of the first PIN element from the PIN element communication policy network element; or
    所述第二网元从PIN元素通信策略网元接收所述第一PIN元素所属的PIN的通信策略,所述PIN的通信策略包括第一PIN元素的第一通信策略。The second network element receives the communication policy of the PIN to which the first PIN element belongs from the PIN element communication policy network element, and the communication policy of the PIN includes the first communication policy of the first PIN element.
  13. 如权利要求12所述的方法,其中,所述方法还包括:The method of claim 12, wherein the method further comprises:
    所述第二网元向所述PIN元素通信策略网元发送的通信策略请求,所述通信策略请求包括所述第一PIN元素的描述信息,或者,所述通信策略请求包括所述第一PIN元素所属的PIN的描述信息。A communication policy request sent by the second network element to the PIN element communication policy network element, where the communication policy request includes description information of the first PIN element, or, the communication policy request includes the first PIN Description information of the PIN to which the element belongs.
  14. 如权利要求10或11所述的方法,其中,所述第二网元包括如下一项:The method according to claim 10 or 11, wherein the second network element comprises one of the following:
    服务于所述第一PIN元素的会话管理功能SMF、服务于所述第一PIN元素的接入和移动管理功能AMF、所述第一PIN元素、目标PIN元素;a session management function SMF serving said first PIN element, an access and mobility management function AMF serving said first PIN element, said first PIN element, a target PIN element;
    其中,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素。Wherein, the target PIN element is a PIN element with gateway capability among the PINs to which the first PIN element belongs.
  15. 如权利要求14所述的方法,其中,所述第二网元为服务于所述第一PIN元素的SMF,所述第二网元获取第一个PIN元素的第一通信策略包括:所述第二网元在所述第一PIN元素的会话建立过程中获取第一PIN元素的第一通信策略;或者The method according to claim 14, wherein the second network element is an SMF serving the first PIN element, and obtaining the first communication policy of the first PIN element by the second network element comprises: the The second network element obtains the first communication policy of the first PIN element during the session establishment process of the first PIN element; or
    所述第二网元为服务于所述第一PIN元素的AMF,所述第二网元获取第一个PIN元素的第一通信策略包括:所述第二网元在所述第一PIN元素的注册过程或者会话建立过程中获取第一PIN元素的第一通信策略。The second network element is an AMF serving the first PIN element, and the acquisition of the first communication policy of the first PIN element by the second network element includes: the second network element is in the first PIN element Obtain the first communication policy of the first PIN element during the registration process or the session establishment process of .
  16. 如权利要求14所述的方法,其中,所述第二网元为服务于所述第一 PIN元素的SMF,所述第二网元向第一网元发送策略信息,包括:所述第二网元向所述第一网元发送所述策略信息,所述第一网元包括用户面功能UPF。The method according to claim 14, wherein the second network element is an SMF serving the first PIN element, and the second network element sends policy information to the first network element, comprising: the second The network element sends the policy information to the first network element, where the first network element includes a user plane function UPF.
  17. 如权利要求16所述的方法,其中,所述第一PIN元素的第二通信策略包括如下至少一项:The method of claim 16, wherein the second communication policy of the first PIN element includes at least one of the following:
    包检测规则PDR和转发行为规则FAR;Packet detection rule PDR and forwarding behavior rule FAR;
    其中,所述PDR包括如下至少一项:Wherein, the PDR includes at least one of the following:
    允许所述第一PIN元素接收的数据包的第一检测信息;Allow the first detection information of the data packet received by the first PIN element;
    禁止所述第一PIN元素接收的数据包的第二检测信息;Forbid the second detection information of the data packet received by the first PIN element;
    所述FAR用于指示如下至少一项:The FAR is used to indicate at least one of the following:
    在接收到符合所述第一检测信息的第一数据包的情况下,向所述第一PIN转发所述第一数据包;Forwarding the first data packet to the first PIN in case a first data packet conforming to the first detection information is received;
    在接收到符合所述第二检测信息的第二数据包的情况下,丢弃所述第二数据包。In case of receiving a second data packet conforming to the second detection information, discarding the second data packet.
  18. 如权利要求14所述的方法,其中,所述第二网元为服务于所述第一PIN元素的SMF,所述第二网元向第一网元发送策略信息,包括:所述第二网元通过AMF向所述第一网元发送所述策略信息;The method according to claim 14, wherein the second network element is an SMF serving the first PIN element, and the second network element sends policy information to the first network element, comprising: the second The network element sends the policy information to the first network element through the AMF;
    其中,所述第一网元包括目标PIN元素,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素;或者Wherein, the first network element includes a target PIN element, and the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs; or
    所述第一网元包括所述第一PIN元素。The first network element includes the first PIN element.
  19. 如权利要求15所述的方法,其中,所述第二网元为服务于所述第一PIN元素的AMF,所述第二网元向第一网元发送策略信息,包括:所述第二网元向所述第一网元发送所述策略信息;The method according to claim 15, wherein the second network element is an AMF serving the first PIN element, and the second network element sends policy information to the first network element, comprising: the second The network element sends the policy information to the first network element;
    其中,所述第一网元包括目标PIN元素,所述目标PIN元素为所述第一PIN元素所属的PIN中具有网关能力的PIN元素;或者Wherein, the first network element includes a target PIN element, and the target PIN element is a PIN element with gateway capability in the PIN to which the first PIN element belongs; or
    所述第一网元包括所述第一PIN元素。The first network element includes the first PIN element.
  20. 一种通信授权装置,包括:A communication authorization device, comprising:
    获取模块,用于获取策略信息,所述策略信息包括:第一个人物联网PIN元素的通信策略;An acquisition module, configured to acquire policy information, where the policy information includes: the communication policy of the first IoT PIN element;
    控制模块,用于根据所述策略信息,对所述第一PIN元素关联的数据包 进行授权控制。A control module, configured to perform authorization control on data packets associated with the first PIN element according to the policy information.
  21. 如权利要求20所述的装置,其中,所述对所述第一PIN元素关联的数据包进行授权控制,包括如下至少一项:The device according to claim 20, wherein said performing authorization control on the data packet associated with the first PIN element comprises at least one of the following:
    向所述第一PIN元素发送所述第一PIN元素关联的第一数据包;sending a first data packet associated with the first PIN element to the first PIN element;
    丢弃所述第一PIN元素关联的第二数据包;Discarding the second data packet associated with the first PIN element;
    接收所述第一PIN元素关联的第三数据包。receiving a third data packet associated with the first PIN element.
  22. 一种通信授权装置,包括:A communication authorization device, comprising:
    获取模块,用于获取第一个人物联网PIN元素的第一通信策略;An acquisition module, configured to acquire the first communication strategy of the first IoT PIN element;
    发送模块,用于向第一网元发送策略信息,所述策略信息包括:所述第一PIN元素的第二通信策略,其中,所述第一PIN元素的第二通信策略是根据所述第一PIN元素的第一通信策略确定的。A sending module, configured to send policy information to a first network element, where the policy information includes: a second communication policy of the first PIN element, wherein the second communication policy of the first PIN element is based on the second communication policy of the first PIN element determined by the first communication policy of a PIN element.
  23. 如权利要求22所述的装置,其中,所述第一PIN元素的第二通信策略包括如下至少一项:The apparatus of claim 22, wherein the second communication policy of the first PIN element includes at least one of the following:
    允许所述第一PIN元素接收第二PIN元素发送的数据包的通信策略;A communication policy that allows the first PIN element to receive the data packet sent by the second PIN element;
    禁止所述第一PIN元素接收第三PIN元素发送的数据包的通信策略。A communication policy that prohibits the first PIN element from receiving data packets sent by the third PIN element.
  24. 一种网元,所述网元为第一网元,包括:存储器、处理器及存储在所述存储器上并可在所述处理器上运行的程序或者指令,其中,所述程序或者指令被所述处理器执行时实现如权利要求1至9中任一项所述的通信授权方法中的步骤。A network element, where the network element is a first network element, including: a memory, a processor, and a program or instruction stored in the memory and operable on the processor, wherein the program or instruction is The processor implements the steps in the communication authorization method according to any one of claims 1 to 9 when executed.
  25. 一种网元,所述网元为第二网元,包括:存储器、处理器及存储在所述存储器上并可在所述处理器上运行的程序或者指令,其中,所述程序或者指令被所述处理器执行时实现如权利要求10至19中任一项所述的通信授权方法中的步骤。A network element, where the network element is a second network element, including: a memory, a processor, and a program or instruction stored in the memory and operable on the processor, wherein the program or instruction is The processor implements the steps in the communication authorization method according to any one of claims 10 to 19 when executed.
  26. 一种可读存储介质,所述可读存储介质上存储有程序或指令,其中,所述程序或指令被处理器执行时实现如权利要求1至9中任一项所述的通信授权方法中的步骤,或者,所述程序或指令被处理器执行时实现如权利要求10至19中任一项所述的通信授权方法中的步骤。A readable storage medium, on which a program or instruction is stored, wherein, when the program or instruction is executed by a processor, the communication authorization method according to any one of claims 1 to 9 is implemented or, when the program or instructions are executed by the processor, the steps in the communication authorization method according to any one of claims 10 to 19 are realized.
  27. 一种芯片,包括处理器和通信接口,其中,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如权利要求1至9中任一 项所述的通信授权方法中的步骤,或者实现如权利要求10至19中任一项所述的通信授权方法中的步骤。A chip, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the communication authorization as claimed in any one of claims 1 to 9 steps in the method, or implement the steps in the communication authorization method according to any one of claims 10 to 19.
  28. 一种计算机程序产品,其中,所述程序产品被存储在非易失的存储介质中,所述程序产品被至少一个处理器执行以实现如权利要求1至9中任一项所述的通信授权方法中的步骤,或者实现如权利要求10至19中任一项所述的通信授权方法中的步骤。A computer program product, wherein the program product is stored in a non-volatile storage medium, and the program product is executed by at least one processor to implement the communication authorization according to any one of claims 1 to 9 steps in the method, or implement the steps in the communication authorization method according to any one of claims 10 to 19.
  29. 一种通信设备,其中,被配置为执行如权利要求1至9中任一项所述的通信授权方法,或者执行如权利要求10至19中任一项所述的通信授权方法。A communication device, wherein it is configured to execute the communication authorization method according to any one of claims 1 to 9, or to execute the communication authorization method according to any one of claims 10 to 19.
PCT/CN2022/124026 2021-10-12 2022-10-09 Communication authorization method and apparatus, network element and storage medium WO2023061275A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202111188003.9A CN115967942A (en) 2021-10-12 2021-10-12 Communication authorization method, device, network element and storage medium
CN202111188003.9 2021-10-12

Publications (1)

Publication Number Publication Date
WO2023061275A1 true WO2023061275A1 (en) 2023-04-20

Family

ID=85898165

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/124026 WO2023061275A1 (en) 2021-10-12 2022-10-09 Communication authorization method and apparatus, network element and storage medium

Country Status (2)

Country Link
CN (1) CN115967942A (en)
WO (1) WO2023061275A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018205756A1 (en) * 2017-05-09 2018-11-15 中国移动通信有限公司研究院 Data packet flow distribution method, device and computer storage medium
CN109756430A (en) * 2017-11-07 2019-05-14 华为技术有限公司 A kind of processing method and processing device of rule
CN112311691A (en) * 2019-07-26 2021-02-02 华为技术有限公司 Policy control method, device and system
CN112839078A (en) * 2020-12-30 2021-05-25 奇点新源国际技术开发(北京)有限公司 Data forwarding method and device for 5G private network environment and electronic equipment

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018205756A1 (en) * 2017-05-09 2018-11-15 中国移动通信有限公司研究院 Data packet flow distribution method, device and computer storage medium
CN109756430A (en) * 2017-11-07 2019-05-14 华为技术有限公司 A kind of processing method and processing device of rule
CN112311691A (en) * 2019-07-26 2021-02-02 华为技术有限公司 Policy control method, device and system
CN112839078A (en) * 2020-12-30 2021-05-25 奇点新源国际技术开发(北京)有限公司 Data forwarding method and device for 5G private network environment and electronic equipment

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
HUAWEI, HUAWEI DEVICES: "Addition of potential requirements on PIN and PIN Element identity and discovery of PIN Element identity", 3GPP DRAFT; S1-212132, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG1, no. Electronic Meeting; 20210705 - 20210712, 13 July 2021 (2021-07-13), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP052031351 *

Also Published As

Publication number Publication date
CN115967942A (en) 2023-04-14

Similar Documents

Publication Publication Date Title
WO2021159492A1 (en) Access control method and apparatus, communication device, and storage medium
EP3439371B1 (en) Method and apparatus for determining access point service capabilities
US10051607B2 (en) Data processing method, apparatus and system
WO2022095850A1 (en) Method and apparatus for establishing policy association, and terminal and network-side device
WO2023061275A1 (en) Communication authorization method and apparatus, network element and storage medium
CN115699677A (en) Method and apparatus for determining authentication type
WO2022068903A1 (en) Network selection method and apparatus, information transmission method and apparatus, and information acquisition method and apparatus
WO2021168713A1 (en) Communication method and apparatus
RU2760872C1 (en) Local network service control method and communication device
WO2023143423A1 (en) Information acquisition, storage and reporting method and device, terminal, and network function
WO2023143411A1 (en) Device authentication methods, apparatus and communication device
WO2023020465A1 (en) Address conversion control method and apparatus, and terminal and network element
WO2023143412A1 (en) Ip address assignment method, device, and readable storage medium
WO2024022210A1 (en) Pegc registration methods, apparatus, and communication device
WO2023143414A1 (en) Data transmission method and apparatus, configuration method and apparatus, and terminal and network-side device
WO2024022161A1 (en) Pin device registration method and apparatus, and communication device
WO2022033458A1 (en) Network transition method and apparatus, and device
WO2023143450A1 (en) Method for configuring data processing rule, and terminal and network-side device
WO2024027578A1 (en) Traffic routing method and apparatus, and device
WO2023179595A1 (en) Session channel establishment method and apparatus for non-3gpp device, and device
WO2023020466A1 (en) Data processing method and apparatus, terminal, access network device, and core network device
WO2022214064A1 (en) Method for accessing network, network side device, and terminal
WO2023143453A1 (en) Direct-connectivity air interface configuration method, and terminal and network-side device
WO2023280022A1 (en) Multi-path communication method, and device
WO2023143422A1 (en) Disaster roaming control method and apparatus, terminal, and network side device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22880214

Country of ref document: EP

Kind code of ref document: A1