WO2023279776A1 - 多模终端接入控制方法、装置、电子设备及存储介质 - Google Patents

多模终端接入控制方法、装置、电子设备及存储介质 Download PDF

Info

Publication number
WO2023279776A1
WO2023279776A1 PCT/CN2022/082474 CN2022082474W WO2023279776A1 WO 2023279776 A1 WO2023279776 A1 WO 2023279776A1 CN 2022082474 W CN2022082474 W CN 2022082474W WO 2023279776 A1 WO2023279776 A1 WO 2023279776A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
local
access control
n3iwf
control rule
Prior art date
Application number
PCT/CN2022/082474
Other languages
English (en)
French (fr)
Inventor
俞一帆
Original Assignee
深圳艾灵网络有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳艾灵网络有限公司 filed Critical 深圳艾灵网络有限公司
Publication of WO2023279776A1 publication Critical patent/WO2023279776A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/08Access restriction or access information delivery, e.g. discovery data delivery
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/02Terminal devices
    • H04W88/06Terminal devices adapted for operation in multiple networks or having at least two operational modes, e.g. multi-mode terminals

Definitions

  • the present application relates to the field of communication technology, and in particular to a multi-mode terminal access control method, device, electronic equipment and storage medium.
  • the fifth generation mobile communication technology (5th generation mobile networks or 5th generation wireless systems, 5th-Generation, referred to as 5G or 5G technology) is the latest generation of cellular mobile communication technology.
  • the 5G local network developed based on 5G technology is also called a private 5G network, which uses 5G technology to create a private network at the local user site, which has unified connectivity, optimized services, and secure communication methods within a specific area, It also provides features such as high transmission speed, low latency and massive connections supported by 5G technology.
  • Existing, multi-mode terminals refer to mobile terminals that can communicate through networks of different technical standards (such as WIFI, 4G and 5G, etc.), which have multiple modes of transmitting, receiving and processing signal systems, and can support many different How radio signals are processed.
  • networks of different technical standards such as WIFI, 4G and 5G, etc.
  • WIFI wireless fidelity
  • 4G and 5G wireless fidelity
  • 3GPP non-3rd generation partnership project
  • the terminal communicates with the access controller (AC) through the extensible authentication protocol over lan (EAPOL) communication based on the LAN, and the AC communicates with the verification, authorization and accounting (authentication, authorization) , accounting, AAA) server forwards the extensible authentication protocol (extensible authentication protocol, EAP) message through the remote authentication dial in user service (Radius) protocol, and the AAA server uses the mobile application part (mobile application part) , MAP)
  • the MAP protocol obtains the global subscriber identity card (universal subscriber identity module, USIM) authentication subscription information from the home location register (home location register, HLR)/home subscriber server (home subscriber server, HSS), and completes the authentication,
  • the AAA server is the enforcement point of authentication.
  • non-3GPP access networks must be equipped with dedicated equipment or protocol stacks to interact with network elements in 5G networks.
  • wireless local area network wireless local area network, WLAN
  • the implementation of the AAA server interacting with the operator's HLR/HSS system is relatively complicated.
  • the purpose of this application is to provide a multi-mode terminal access control method, device, electronic equipment and storage medium to address the deficiencies in the above-mentioned prior art, which can access the terminal according to the terminal subscription information in the local communication network
  • the process of non-3GPP access network is controlled, which has the characteristics of simple implementation and strong flexibility.
  • the present application provides a multi-mode terminal access control method, including:
  • the local session management function SMF receives the protocol data unit PDU session establishment request sent by the terminal, and the PDU session establishment request includes: terminal identification;
  • the local SMF sends a terminal subscription information query request to the local unified data management UDM according to the terminal identifier in the PDU session establishment request;
  • the local SMF receives the terminal subscription information query result returned by the local UDM according to the terminal identifier
  • the local SMF sends an access control rule creation request to the local N3IWF, and the access control rule
  • the creation request is used to request to create a target access control rule
  • the access control rule creation request includes: the terminal identifier
  • the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF .
  • the present application provides a multi-mode terminal access control method, including:
  • the local non-3GPP interworking function N3IWF receives the access control rule creation request sent by the local session management function SMF after the terminal subscription information query result indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF, and the The access control rule creation request includes: a terminal identifier; wherein, the query result of the terminal subscription information is obtained by the local SMF requesting the local unified data management UDM according to the terminal identifier;
  • the local N3IWF creates a target access control rule according to the access control rule creation request, and the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF;
  • the local N3IWF sends a target access control rule creation complete message to the local SMF.
  • the present application provides a multi-mode terminal access control method, including:
  • the terminal sends a protocol data unit PDU session establishment request to the local session management function SMF, and the PDU session establishment request includes: a terminal identification, and the terminal identification is used to instruct the local SMF to request the local unified data management UDM to obtain terminal subscription information query
  • the terminal subscription information query result is used to indicate whether the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF;
  • the query result of the terminal subscription information indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF
  • the local SMF notifies the N3IWF to create a target access control rule between the terminal and the local target UPF
  • the establishment of the PDU session is completed, and the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local target UPF.
  • the present application provides a multi-mode terminal access control device, including:
  • the first receiving module is used for the local session management function SMF to receive the protocol data unit PDU session establishment request sent by the terminal, and the PDU session establishment request includes: terminal identification;
  • the first sending module is used for the local SMF to send a terminal subscription information query request to the local unified data management UDM according to the terminal identifier in the PDU session establishment request;
  • the second receiving module is used for the local SMF to receive the terminal subscription information query result returned by the local UDM according to the terminal identifier;
  • the second sending module is configured to send an access control rule creation request to the local N3IWF if the terminal subscription information query result indicates that the terminal is allowed to communicate in a non-3GPP access network through a non-3GPP interworking function N3IWF , the access control rule creation request is used to request the creation of a target access control rule, the access control rule creation request includes: the terminal identifier, and the target access control rule is used to indicate that the local N3IWF is allowed to send the terminal The data packets are forwarded to the local UPF.
  • the present application provides a multi-mode terminal access control device, including:
  • the receiving module is used for the local non-3GPP interworking function N3IWF to receive the access control rule sent by the local session management function SMF after the terminal subscription information query result indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF Create a request
  • the access control rule creation request includes: a terminal identifier; wherein, the query result of the terminal subscription information is obtained by the local SMF requesting the local unified data management UDM according to the terminal identifier;
  • the creation module is used for the local N3IWF to create a target access control rule according to the access control rule creation request, and the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF;
  • a sending module configured for the local N3IWF to send a target access control rule creation completion message to the local SMF.
  • the present application provides a multi-mode terminal access control device, which may include:
  • the sending module is used for the terminal to send a protocol data unit PDU session establishment request to the local session management function SMF, and the PDU session establishment request includes: a terminal identifier, and the terminal identifier is used to instruct the local SMF to request the local unified data management UDM Acquiring a terminal subscription information query result, where the terminal subscription information query result is used to indicate whether the terminal is allowed to communicate in a non-3GPP access network through a non-3GPP interworking function N3IWF;
  • Establishing a module configured to: if the terminal subscription information query result indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF, the terminal and the local target UPF notify the N3IWF to create a target interface in the local SMF After the entry control rule is established, the establishment of the PDU session is completed, and the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local target UPF.
  • the present application provides an electronic device, including: a processor, a storage medium, and a bus, the storage medium stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor Communicating with the storage medium through a bus, the processor executes the machine-readable instructions to execute the steps of the multi-mode terminal access control method as described in any one of the foregoing implementation manners.
  • the present application provides a computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is run by a processor, the multi-mode terminal interface described in any one of the preceding implementation modes is executed. into the steps of the control method.
  • the local session management function SMF receives the protocol data unit PDU session establishment request sent by the terminal, and the PDU session establishment request includes: terminal identification; local The SMF sends a terminal subscription information query request to the local unified data management UDM according to the terminal identifier in the PDU session establishment request; the local SMF receives the terminal subscription information query result returned by the local UDM according to the terminal identifier; if the terminal subscription information query result indicates that the terminal is allowed to pass
  • the local SMF sends an access control rule creation request to the local N3IWF.
  • the access control rule creation request is used to request the creation of target access control rules.
  • the access control rule creation request Including: terminal identification, the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF, so that it is no longer necessary to equip a non-3GPP access network with a dedicated protocol stack that interacts with N3IWF network elements,
  • the process of the terminal accessing the non-3GPP access network can be controlled according to the terminal subscription information of the terminal in the local communication network, so that the local communication network can be flexibly adapted to different non-3GPP access networks, and has the advantages of simple implementation and strong flexibility features.
  • FIG. 1 is a schematic diagram of a network architecture applicable to the method provided by the embodiment of the present application
  • FIG. 2 is a schematic flowchart of a multi-mode terminal access control method provided in an embodiment of the present application
  • FIG. 3 is a schematic flowchart of another multi-mode terminal access control method provided in an embodiment of the present application.
  • FIG. 4 is a schematic flowchart of another multi-mode terminal access control method provided in the embodiment of the present application.
  • FIG. 5 is a schematic flowchart of another multi-mode terminal access control method provided in the embodiment of the present application.
  • FIG. 6 is a schematic flowchart of another multi-mode terminal access control method provided by the embodiment of the present application.
  • FIG. 7 is a schematic flowchart of another multi-mode terminal access control method provided by the embodiment of the present application.
  • FIG. 8 is a schematic diagram of an interaction process provided by an embodiment of the present application.
  • FIG. 9 is a schematic diagram of functional modules of a multi-mode terminal access control device provided in an embodiment of the present application.
  • FIG. 10 is a schematic structural diagram of an electronic device provided by an embodiment of the present application.
  • the technical solution of the embodiment of the present application can be applied to various local communication systems, such as: global system for mobile communications (global system for mobile communications, GSM) system, code division multiple access (code division multiple access, CDMA) system, wideband code division multiple access wideband code division multiple access (WCDMA) system, general packet radio service (GPRS), long term evolution (long term evolution, LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (time division duplex, TDD), universal mobile telecommunications system (universal mobile telecommunications system, UMTS), global interconnection microwave access (worldwide interoperability for microwave access, WiMAX) communication system, the fifth generation (5th generation, 5G ) communication system or future new radio access technology (new radio access technology, NR), etc.
  • GSM global system for mobile communications
  • CDMA code division multiple access
  • WCDMA wideband code division multiple access
  • GPRS general packet radio service
  • long term evolution long term evolution
  • LTE long term evolution
  • FDD frequency division
  • FIG. 1 is a schematic diagram of a network architecture applicable to the method provided by the embodiment of the present application.
  • the network architecture may be, for example, a non-roaming (non-roaming) architecture.
  • the network architecture may specifically include the following network elements:
  • Terminal equipment can be called user equipment, terminal, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile equipment, user terminal, wireless communication equipment, User Agent or User Device.
  • the UE can also be a cellular phone, a cordless phone, a session initiation protocol (session initiation protocol, SIP) phone, a wireless local loop (wireless local loop, WLL) station, a personal digital assistant (personal digital assistant, PDA), having a wireless communication function Handheld devices, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, terminal devices in 5G networks or terminal devices in the future evolution of public land mobile network (PLMN) etc.
  • PLMN public land mobile network
  • IoT devices such as sensors, electricity meters, water meters, etc. (Internet of things, IoT) devices.
  • IoT Internet of things
  • Access network Provides network access functions for authorized users in a specific area, and can use transmission tunnels of different qualities according to user levels and business requirements.
  • the access network may be an access network using different access technologies.
  • 3rd generation partnership project (3GPP) access technologies such as those used in 3G, 4G or 5G systems
  • non-3GPP non-third generation partnership Partnership project
  • the 3GPP access technology refers to the access technology that complies with the 3GPP standard specification.
  • the access network adopting the 3GPP access technology is called the radio access network (radio access network, RAN).
  • the access network equipment in the 5G system is called Next generation Node Base station (gNB).
  • gNB Next generation Node Base station
  • a non-3GPP access technology refers to an access technology that does not comply with the 3GPP standard specification, for example, an air interface technology represented by an access point (access point, AP) in WIFI.
  • An access network that implements a network access function based on a wireless communication technology may be referred to as a radio access network (radio access network, RAN).
  • the wireless access network can manage wireless resources, provide access services for terminals, and complete the forwarding of control signals and user data between terminals and the core network.
  • the access network device may include a device in the access network that communicates with the wireless terminal through one or more sectors on the air interface.
  • the access network system may be used to convert received over-the-air frames to and from Internet Protocol (IP) packets and act as a router between the wireless terminal and the rest of the access network, which may include IP network.
  • IP Internet Protocol
  • the radio access network system may also coordinate attribute management for the air interface.
  • the access network equipment includes but not limited to: evolved node B (evolved node B, eNB), radio network controller (radio network controller, RNC), node B (node B, NB), base station controller (base station controller, BSC), base transceiver station (base transceiver station, BTS), home base station (for example, home evolved nodeB, or home node B, HNB), base band unit (base band unit, BBU), wireless fidelity (wireless fidelity , WIFI) system access point (access point, AP), wireless relay node, wireless backhaul node, transmission point (transmission and reception point, TRP or transmission point, TP), etc., can also be 5G, such as, NR, a gNB in the system, or, a transmission point (TRP or TP), one or a group (including multiple antenna panels) antenna panels of a base station in a 5G system, or, it can also be a network node that constitutes a gNB or a transmission
  • RNC
  • a gNB may include a centralized unit (CU) and a DU.
  • the gNB may also include a radio unit (radio unit, RU).
  • CU implements some functions of gNB
  • DU implements some functions of gNB, for example, CU implements radio resource control (radio resource control, RRC), packet data convergence layer protocol (packet data convergence protocol, PDCP) layer functions
  • DU implements wireless link Functions of the radio link control (radio link control, RLC), media access control (media access control, MAC) and physical (physical, PHY) layers.
  • the access network device may be a CU node, or a DU node, or a device including a CU node and a DU node.
  • the CU can be divided into access network devices in the access network (radio access network, RAN), and the CU can also be divided into access network devices in the core network (core network, CN), which is not limited here.
  • Access and mobility management function entity: mainly used for mobility management and access management, etc., and can be used to implement mobility management entity (mobility management entity, MME) function except session Functions other than management, for example, functions such as lawful interception, or access authorization (or authentication). In the embodiment of the present application, it can be used to implement functions of access and mobility management network elements.
  • AMF access and mobility management function
  • MME mobility management entity
  • session Functions other than management for example, functions such as lawful interception, or access authorization (or authentication).
  • it can be used to implement functions of access and mobility management network elements.
  • Session management function session management function, SMF
  • Session management function entity: mainly used for session management, UE's Internet Protocol (Internet Protocol, IP) address allocation and management, selection of manageable user plane functions, policy control, or charging function interfaces Endpoint and downlink data notification, etc.
  • SMF session management function
  • IP Internet Protocol
  • User Plane Function (UPF) entity that is, the data plane gateway. It can be used for packet routing and forwarding, or quality of service (QoS) processing of user plane data, etc.
  • User data can be accessed to a data network (data network, DN) through this network element. In the embodiment of this application, it can be used to realize the function of the user plane gateway.
  • data network data network
  • Policy control function policy control function
  • PCF policy control function
  • Unified data management (UDM) entity used to process user identification, access authentication, registration, or mobility management.
  • N3IWF Non-3GPP InterWorking Function, non-3GPP interworking function: responsible for connecting untrusted non-3GPP access networks (such as Wi-Fi) to the 5G core network.
  • the UE establishes an IPsec tunnel with the N3IWF, and the N3IWF accesses the control plane and the user plane of the 5G core network through the N2 interface and the N3 interface respectively.
  • the N1 interface is the reference point between the terminal and the AMF entity;
  • the N2 interface is the reference point between the AN and the AMF entity, and is used for sending non-access stratum (non-access stratum, NAS) messages, etc.;
  • N3 The interface is the reference point between the (R)AN and UPF entities, used to transmit user plane data, etc.;
  • the N4 interface is the reference point between the SMF entity and the UPF entity, used to transmit tunnel identification information such as N3 connections, data Cache indication information, downlink data notification messages and other information;
  • N6 interface is the reference point between the UPF entity and the DN, and is used to transmit user plane data, etc.
  • the above-mentioned network architecture applied to the embodiment of the present application is only an example of a network architecture described from the perspective of a traditional point-to-point architecture and a service-oriented architecture, and the network architecture applicable to the embodiment of the present application is not limited thereto. Any network architecture capable of implementing the functions of the foregoing network elements is applicable to this embodiment of the present application.
  • AMF entity, SMF entity, UPF entity, PCF entity, and UDM entity shown in FIG. 1 can be understood as network elements used to implement different functions in the core network, for example, they can be combined into network slices as required. These network elements of the core network may be independent devices, or may be integrated into the same device to implement different functions, which is not limited in this application.
  • AMF entity used to implement AMF
  • PCF entity used to implement PCF
  • AMF entity used to implement PCF
  • PCF entity used to implement PCF
  • the name of the interface between network elements in FIG. 1 is just an example, and the name of the interface in a specific implementation may be another name, which is not specifically limited in this application.
  • the name of the message (or signaling) transmitted between the above network elements is only an example, and does not constitute any limitation on the function of the message itself.
  • the 5G local network developed based on 5G technology is also called a private 5G network, which uses 5G technology to create a private network at the local user site, which has unified connectivity, optimized services, and secure communication methods within a specific area, and Provide features such as high transmission speed, low latency and massive connections supported by 5G technology.
  • the 5G local network is built on the basis of 5G equipment, including 5G terminal equipment, 5G wireless base stations and 5G core network equipment. It is exclusive to the network owner, that is, local users, and can be independently managed and easily deployed. 5G local networks can eliminate the need for wired devices such as Ethernet, which are expensive and bulky, and unable to connect large numbers of mobile devices and people.
  • the 5G local network can be configured locally, and the network owner has full control over the network, such as security, network resource usage, etc.
  • the network owner can assign higher priority to key devices to use network resources.
  • 5G local networks can be deployed in almost any campus, enterprise building or public place, especially in specific areas where the deployment of public 5G networks is slow, 5G local networks can be quickly deployed.
  • 5G local networks are widely used in various scenarios, for example, in industrial internet of things (IIoT) scenarios, sensors will be installed in factories to monitor environmental conditions, support quality control and customized manufacturing .
  • IIoT internet of things
  • sensor data can be collected and analyzed, and all aspects of factory operation information can be finely controlled. It can transmit the analysis results to the intelligent robot through the 5G local network to support product manufacturing or transportation of goods in the factory area.
  • workers can wear lightweight augmented reality equipment and complete equipment operations through a virtual environment.
  • the 5G core network supports access through 3GPP access networks (such as gNB, eNB), and also supports non-3GPP network access (such as WIFI).
  • 3GPP access networks such as gNB, eNB
  • non-3GPP network access such as WIFI
  • the Non-3GPP network accesses the 5G network through the non-3GPP interworking function (Non-3GPP Inter Working Function, N3IWF), and the N3IWF accesses the 5G network through the N2 and N3 interfaces.
  • N3IWF Non-3GPP Inter Working Function
  • the terminal UE accesses a 5G core network through 3GPP and non-3GPP at the same time, then there will be two N1 entities for this terminal at the same time, one corresponding to 3GPP access and the other corresponding to non-3GPP access; if N3IWF If the 3GPP access network and the 3GPP access network belong to the same network (the same public land mobile network PLMN), then the two N1 instances should be in the same AMF.
  • the non-3GPP access network eg, WIFI
  • the non-3GPP access network is connected to the 5G core network through a non-3GPP interworking function (N3IWF).
  • N3IWF is connected to 5G core network CP and UP functions through N2 and N3 interfaces respectively.
  • the UE must establish an IPSec tunnel with the N3IWF to connect to the 5G core network through untrusted non-3GPP access.
  • the UE will be authenticated by the 5G core network and attached to the 5G core network.
  • This technology requires that the non-3GPP access network must be equipped with a dedicated protocol stack that interacts with N3IWF network elements.
  • this application provides a multi-mode terminal access control method. It is no longer necessary to equip a non-3GPP access network with a dedicated protocol stack for interaction with N3IWF network elements, and it can be based on the terminal subscription information of the terminal in the local communication network.
  • the process of terminal access to non-3GPP access network is controlled, so that the local communication network can flexibly adapt to different non-3GPP access networks, and has the characteristics of simple implementation and strong flexibility.
  • Fig. 2 is a schematic flow diagram of a multi-mode terminal access control method provided by an embodiment of the present application.
  • the execution body of the method may be a local SMF in a local communication system, wherein a multi-mode terminal refers to a network that can pass through different technical standards (such as WiFi, 4G and 5G, etc.) mobile terminals for communication, which have multiple modes of transmitting, receiving and processing signal systems, and can support a variety of different radio signal processing methods.
  • the establishment of a local communication system based on a local 5G network is taken as an example for illustration, but not limited thereto.
  • the method may include:
  • the local session management function SMF receives a protocol data unit PDU session establishment request sent by a terminal, and the PDU session establishment request includes: a terminal identifier.
  • the terminal may send a PDU session establishment request to the local AMF, and the PDU session establishment request may include a terminal identifier.
  • the terminal identifier may be an international mobile subscriber identity (IMSI) , but not limited to this.
  • IMSI international mobile subscriber identity
  • the local AMF may select the local SMF to perform the PDU session establishment process.
  • the local AMF may select any local SMF among the multiple optional local SMFs according to a preset selection rule to perform PDU session establishment processing.
  • the local AMF may forward the PDU session establishment request sent by the terminal to the local SMF, and the local SMF receives the PDU session establishment request.
  • the local SMF sends a terminal subscription information query request to the local unified data management UDM according to the terminal identifier in the PDU session establishment request.
  • the local SMF receives the terminal subscription information query result returned by the local UDM according to the terminal identifier.
  • the local SMF After the local SMF receives the PDU session establishment request, it can extract the terminal identifier in the PDU session establishment request, and send a terminal subscription information query request to the local unified data management UDM according to the terminal identifier; for the local UDM, the local UDM receives After receiving the terminal subscription information query request, it can query according to the terminal identifier in the terminal subscription information query request, and return the corresponding terminal subscription information query result to the local SMF.
  • the terminal subscription information query result can indicate whether the terminal is allowed to pass through non-
  • the 3GPP interworking function N3IWF communicates in non-3GPP access networks.
  • a terminal when it initiates a network access request to the communication base station for the first time, it can register its relevant terminal subscription information with the local UDM, and the terminal subscription information can indicate whether the terminal is allowed to use the non-3GPP interworking function N3IWF in Communication in non-3GPP access network.
  • the local UDM will associate and store the subscription information with the corresponding terminal ID for subsequent query.
  • the local SMF sends an access control rule creation request to the local N3IWF.
  • the access control rule creation request is used to request to create a target access control rule
  • the access control rule creation request includes: the terminal identifier
  • the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF .
  • the local SMF can further send an access control rule creation request to the local N3IWF; for the local N3IWF, it can according to the The access control rule creation request creates a target access control rule, through which the target access control rule indicates that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF.
  • the data packets sent by the terminal to the local N3IWF will be further forwarded to the local UPF through the local N3IWF, that is, to the inside of the local 5G network, so that the local communication network can flexibly adapt to different Non-3GPP access network, and avoid the need for non-3GPP access network to be equipped with special equipment or protocol stack to interact with network elements in the 5G network, which has the characteristics of simple implementation and strong flexibility.
  • the local session management function SMF receives the protocol data unit PDU session establishment request sent by the terminal, and the PDU session establishment request includes: the terminal identifier; the local SMF establishes the session according to the PDU
  • the terminal identifier in the request sends a terminal subscription information query request to the local unified data management UDM; the local SMF receives the terminal subscription information query result returned by the local UDM according to the terminal identifier; if the terminal subscription information query result indicates that the terminal is allowed to pass the non-3GPP interworking function N3IWF
  • the local SMF sends an access control rule creation request to the local N3IWF.
  • the access control rule creation request is used to request the creation of a target access control rule.
  • the access control rule creation request includes: terminal identification,
  • the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packets sent by the terminal to the local UPF, so that it is no longer necessary to equip the non-3GPP access network with a dedicated
  • the terminal subscription information in the communication network controls the process of the terminal accessing the non-3GPP access network, so that the local communication network can flexibly adapt to different non-3GPP access networks, and has the characteristics of simple implementation and strong flexibility.
  • the source address in the above data packet is the address of the terminal.
  • the source address in the data packet may be the address of the terminal, that is, the forwarding flow of the data packet may be determined according to the address of the terminal in the data packet.
  • the local N3IWF when the source address (for example, IP address) of the data packet from the non-3GPP access network is the address of the terminal, the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF, so that the terminal and the local Data communication between communication networks.
  • the embodiment of the present application introduces a new processing function in the local SMF and the local N3IWF, so that an access control rule can be created in the local N3IWF through the local SMF, that is, an entry allowing data transmission can be created.
  • an access control rule can be created in the local N3IWF through the local SMF, that is, an entry allowing data transmission can be created.
  • data packets that do not have matching entries in the access control rules will be deleted or discarded.
  • FIG. 3 is a schematic flowchart of another multi-mode terminal access control method provided by an embodiment of the present application.
  • the above method further includes:
  • the local SMF sends an access control rule deletion request to the local N3IWF, and the access control rule deletion request is used to request deletion of the local N3IWF
  • the access control rule corresponding to the terminal identifier, and the control rule deletion request includes: the terminal identifier.
  • the terminal subscription information query result indicates that the terminal is allowed to communicate in the non-3GPP access network through the N3IWF within the first preset time period, refer to the relevant description above, and the local N3IWF will create the target access network
  • the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF; and the query result of the terminal subscription information within the second preset time period indicates that the terminal is not allowed to use the N3IWF in non-3GPP
  • the local SMF needs to send an access control rule deletion request to the local N3IWF.
  • the control rule deletion request may include: terminal identification, to request deletion of the terminal identification corresponding to the local N3IWF It is understood that after deletion, the data packets sent by the terminal to the local N3IWF will no longer be forwarded to the local UPF, that is, the terminal will not be able to communicate in the non-3GPP access network through the N3IWF, so that according to In actual application scenarios, the access control rules in the local N3IWF can be updated at any time to improve the applicability of the method of this application.
  • the local N3IWF can store the access control rules corresponding to each terminal identifier in the form of entries, for example, it can be stored through access control lists (Access Control Lists, ACL), but not limited thereto.
  • the entry may include: a mapping relationship between each terminal identifier and each access control rule.
  • the specific storage method is not limited to this, and may be different according to actual application scenarios.
  • Fig. 4 is a schematic flowchart of another multi-mode terminal access control method provided by the embodiment of the present application.
  • the execution subject of the method may be a local N3IWF network element in the local communication system.
  • the method may include :
  • the local non-3GPP interworking function N3IWF receives the access control rule creation request sent by the local session management function SMF after the terminal subscription information query result indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF, and access
  • the control rule creation request includes: terminal identification.
  • the query result of the terminal subscription information is obtained by the local SMF requesting the local unified data management UDM according to the terminal identifier.
  • the terminal can send a PDU session establishment request to the local AMF, and the PDU session establishment request can include a terminal identifier; after the local AMF receives the PDU session establishment request, it can forward the PDU session establishment request to the Local SMF: According to the terminal identifier in the PDU session establishment request, the local SMF can send a terminal subscription information query request to the local unified data management UDM; after receiving the terminal subscription information query request, the local UDM can return the query to the local SMF The terminal subscription information query result corresponding to the terminal identifier.
  • the local SMF can send an access control rule creation request to the local N3IWF, and the access control rule creation request can include: terminal identification .
  • the local N3IWF creates a target access control rule according to the access control rule creation request, and the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF.
  • the local N3IWF sends a target access control rule creation completion message to the local SMF.
  • the local N3IWF After the local N3IWF receives the access control rule creation request, it can create a target access control rule according to the access control rule creation request.
  • the created target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to local UPF.
  • the local N3IWF can send a target access control rule creation completion message to the local SMF, so as to notify the local SMF in time, and the local SMF can send a PDU session confirmation to the local AMF according to the target access control rule creation completion message Create a message to ensure that the PDU session can continue to be created.
  • the application of the embodiment of this application makes it possible for the local N3IWF to forward the data packet to the local UPF, that is, to the local 5G network if the local N3IWF receives the data packet sent by the terminal to which the terminal identification belongs. , realizing the control of the process of the terminal accessing the non-3GPP access network according to the terminal subscription information of the terminal in the local communication network, so that the local communication network can flexibly adapt to different non-3GPP access networks, with simple and flexible implementation Strong features.
  • the source address in the above data packet is the address of the terminal.
  • the source address in the data packet can be the address of the terminal, that is, when the source address (for example, IP address) of the data packet from the non-3GPP access network is the address of the terminal, the local N3IWF is allowed to send the data sent by the terminal.
  • the packet is forwarded to the local UPF to realize the data communication between the terminal and the local communication network.
  • FIG. 5 is a schematic flowchart of another multi-mode terminal access control method provided by an embodiment of the present application.
  • the above method also includes:
  • the local N3IWF receives the access control rule deletion request sent by the local SMF after the terminal subscription information query result indicates that the terminal is not allowed to communicate in the non-3GPP access network through the N3IWF.
  • the access control rule deletion request includes: terminal identification.
  • the local N3IWF deletes the access control rule corresponding to the terminal identifier according to the access control rule deletion request.
  • the terminal subscription information query results may be different in different time periods.
  • the terminal subscription information query results in the first preset time period indicate that the terminal is allowed to use Communication during network access; it is not allowed within the first preset time period, and if not allowed, the local SMF can send an access control rule deletion request to the local N3IWF, and after the local N3IWF receives the access control rule deletion request , the access control rule corresponding to the terminal identifier in the access control rule deletion request can be deleted, so that the access control rule in the local N3IWF can be updated at any time according to the actual application scenario, and the applicability of the method of this application can be improved.
  • FIG. 6 is a schematic flowchart of another multi-mode terminal access control method provided in the embodiment of the present application.
  • the execution subject of the method may be a terminal in a local communication system. As shown in FIG. 6 , the method may include:
  • the terminal sends a protocol data unit PDU session establishment request to a local session management function SMF, where the PDU session establishment request includes: a terminal identifier.
  • the terminal identifier is used to instruct the local SMF to request the local unified data management UDM to obtain the terminal subscription information query result
  • the terminal subscription information query result is used to indicate whether the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF.
  • the terminal can send a PDU session establishment request to the local AMF, and the PDU session establishment request can include a terminal identifier, and the local AMF can further forward the PDU session establishment request sent by the terminal to the local SMF; the local SMF according to the terminal identifier in the PDU session establishment request,
  • the terminal subscription information query request can be sent to the local unified data management UDM to request to obtain the terminal subscription information query result corresponding to the terminal identifier; the local UDM can return the terminal subscription information query result to the local SMF according to the terminal identifier, and the terminal subscription information query result It is used to indicate whether the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF.
  • the terminal subscription information query result indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF
  • the terminal and the local target UPF complete the establishment of the PDU session after the local SMF notifies the N3IWF to create the target access control rule, and the target The access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local target UPF.
  • the local SMF can send an access control rule creation request to the local N3IWF to request the creation of a target access control rule, and the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF;
  • the local N3IWF creates the target access control rule according to the access control rule creation request, it can send the target access control rule creation completion message to the local SMF; for the terminal, at this time, the terminal can complete the establishment of the PDU session with the local target UPF .
  • the application of the embodiment of this application enables the terminal to determine whether the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF according to the terminal identifier in the PDU session establishment request when it initiates a PDU session establishment request. If allowed, the local N3I can create a target access control rule corresponding to the terminal identifier. Through the creation of the target access control rule, the local N3IWF can forward the data packet sent by the terminal to the local UPF, that is, to the local 5G In the network, the data communication between the terminal and the local UPF is realized, and it is no longer necessary to equip the non-3GPP access network with a dedicated protocol stack that interacts with the N3IWF network element. The process of the terminal accessing the non-3GPP access network is controlled, so that the local communication network can flexibly adapt to different non-3GPP access networks, and has the characteristics of simple implementation and strong flexibility.
  • Fig. 7 is a schematic flow diagram of another multi-mode terminal access control method provided in the embodiment of the present application
  • Fig. 8 is a schematic flow diagram of an interaction flow provided in the embodiment of the present application
  • the execution subject of the method may be a local communication system
  • the local communication system may include: a local AMF, a local UPF, a local SMF, a local PCF, a local UDM, and a local N3IWF, as shown in Figures 7 and 8, the method may include:
  • the terminal sends a protocol data unit PDU session establishment request to the local AMF, where the PDU session establishment request includes: a terminal identifier.
  • the terminal may first send a PDU session establishment request to the local RAN, and forward the request to the local AMF through the RAN.
  • the local AMF receives the PDU session establishment request sent by the terminal, and forwards the PDU session establishment request to the local SMF.
  • the local SMF sends a terminal subscription information query request to the local UDM according to the terminal identifier in the PDU session establishment request.
  • the local UDM returns a terminal subscription information query result to the local SMF according to the terminal identifier in the terminal subscription information query request sent by the local SMF.
  • the local SMF sends an access control rule creation request to the local N3IWF, and the access control rule creation request includes: terminal identification .
  • the local N3IWF receives the access control rule creation request sent by the local SMF, and creates a target access control rule according to the access control rule creation request.
  • the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF.
  • the local N3IWF can create an access control list (Access Control Lists, ACL) entry that allows data transmission in the N3IWF according to the access control rule creation request.
  • ACL Access Control Lists
  • the process of establishing a PDU session between the above-mentioned terminal and the local target UPF may refer to the following steps: the local SMF sends a PDU session confirmation establishment message to the local AMF; the local SMF authenticates the PDU session information; the local SMF selects the local PCF, And obtain PCC (policy control and charging) policy information from local PCF, optionally, this PCC policy information can include QOS policy, charging policy etc., do not limit here; Local SMF selects local UPF; Local SMF selects local UPF; Local SMF according to local UPF Update the policy information to the local PCF; the local SMF sends the session information and policy information to the local UPF; the local SMF sends a PDU session establishment acceptance message to the local AMF; the local AMF notifies the local 5G base station to establish a radio bearer; the local 5G base station notifies the terminal to establish a radio bearer The local 5G base station notifies the local AMF to complete the establishment of the radio bearer; the local local S
  • the local SMF generates access control rules in the N3IWF according to the terminal subscription information generated by the terminal during the establishment of the PDU session. For terminals that are allowed to access the network in the terminal subscription information, SMF will create an entry in N3IWF that allows data transmission.
  • the 5G network element controls the terminal to access the non-3GPP access network, which can significantly reduce the threshold for the connection between the non-3GPP network and the 5G network , so that the 5G network can flexibly adapt to different non-3GPP access networks.
  • Fig. 9 is a schematic diagram of functional modules of a multi-mode terminal access control device provided by an embodiment of the present application.
  • the device may be the aforementioned local SMF network element.
  • the basic principles and technical effects of the device are the same as those of the aforementioned corresponding method embodiments Similarly, for brief description, for parts not mentioned in this embodiment, reference may be made to the corresponding content in the method embodiment.
  • the multi-mode terminal access control device 100 may include:
  • the first receiving module 110 is used for the local session management function SMF to receive the protocol data unit PDU session establishment request sent by the terminal, and the PDU session establishment request includes: terminal identification;
  • the first sending module 120 is used for the local SMF to send a terminal subscription information query request to the local unified data management UDM according to the terminal identifier in the PDU session establishment request;
  • the second receiving module 130 is used for the local SMF to receive the terminal subscription information query result returned by the local UDM according to the terminal identifier;
  • the second sending module 140 is configured to: if the query result of the terminal subscription information indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF, the local SMF sends the access control rule creation to the local N3IWF request, the access control rule creation request is used to request the creation of a target access control rule, the access control rule creation request includes: the terminal identifier, and the target access control rule is used to indicate that the local N3IWF is allowed to send the terminal Sent packets are forwarded to the local UPF.
  • the source address in the data packet is the address of the terminal.
  • the second sending module 140 is further configured to send the local SMF to The local N3IWF sends an access control rule deletion request, the access control rule deletion request is used to request deletion of the access control rule corresponding to the terminal identifier in the local N3IWF, and the control rule deletion request includes: the Terminal ID.
  • the embodiment of the present application also provides a multi-mode terminal access control device, which may be the aforementioned local N3IWF network element.
  • the basic principles and technical effects of the device are the same as those of the corresponding method embodiments described above. For a brief description, this For the parts not mentioned in the embodiment, you can refer to the corresponding content in the method embodiment.
  • the multi-mode terminal access control device may include:
  • the receiving module is used for the local non-3GPP interworking function N3IWF to receive the access control rule sent by the local session management function SMF after the terminal subscription information query result indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF Create a request
  • the access control rule creation request includes: a terminal identifier; wherein, the query result of the terminal subscription information is obtained by the local SMF requesting the local unified data management UDM according to the terminal identifier;
  • the creation module is used for the local N3IWF to create a target access control rule according to the access control rule creation request, and the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local UPF;
  • a sending module configured for the local N3IWF to send a target access control rule creation completion message to the local SMF.
  • the source address in the data packet is the address of the terminal.
  • the sending module is also used for the local N3IWF to receive the access control sent by the local SMF after the terminal subscription information query result indicates that the terminal is not allowed to communicate in the non-3GPP access network through the N3IWF.
  • a rule deletion request where the access control rule deletion request includes: the terminal identifier;
  • the local N3IWF deletes the access control rule corresponding to the terminal identifier according to the access control rule deletion request.
  • the embodiment of the present application also provides a multi-mode terminal access control device, which may be the aforementioned terminal.
  • the basic principles and technical effects of the device are the same as those of the corresponding method embodiments described above.
  • the multi-mode terminal access control device may include:
  • the sending module is used for the terminal to send a protocol data unit PDU session establishment request to the local session management function SMF, and the PDU session establishment request includes: a terminal identifier, and the terminal identifier is used to instruct the local SMF to request the local unified data management UDM Acquiring a terminal subscription information query result, where the terminal subscription information query result is used to indicate whether the terminal is allowed to communicate in a non-3GPP access network through a non-3GPP interworking function N3IWF;
  • Establishing a module configured to: if the terminal subscription information query result indicates that the terminal is allowed to communicate in the non-3GPP access network through the non-3GPP interworking function N3IWF, the terminal and the local target UPF notify the N3IWF to create a target interface in the local SMF After the entry control rule is established, the establishment of the PDU session is completed, and the target access control rule is used to indicate that the local N3IWF is allowed to forward the data packet sent by the terminal to the local target UPF.
  • the above modules may be one or more integrated circuits configured to implement the above method, for example: one or more specific integrated circuits (Application Specific Integrated Circuit, referred to as ASIC), or, one or more microprocessors, or, One or more Field Programmable Gate Arrays (Field Programmable Gate Array, FPGA for short), etc.
  • ASIC Application Specific Integrated Circuit
  • microprocessors or, One or more Field Programmable Gate Arrays (Field Programmable Gate Array, FPGA for short)
  • FPGA Field Programmable Gate Array
  • the processing element may be a general-purpose processor, such as a central processing unit (Central Processing Unit, referred to as CPU) or other processors that can call program codes.
  • CPU central processing unit
  • these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC for short).
  • FIG. 10 is a schematic structural diagram of an electronic device provided by an embodiment of the present application.
  • the electronic device may include: a processor 210, a storage medium 220, and a bus 230.
  • the storage medium 220 stores machine-readable instructions executable by the processor 210.
  • the processor 210 communicates with the storage
  • the media 220 communicate through the bus 230 , and the processor 210 executes machine-readable instructions to execute the steps of the foregoing method embodiments.
  • the specific implementation manner and technical effect are similar, and will not be repeated here.
  • the present application further provides a storage medium, on which a computer program is stored, and when the computer program is run by a processor, the steps in the foregoing method embodiments are executed.
  • a storage medium on which a computer program is stored, and when the computer program is run by a processor, the steps in the foregoing method embodiments are executed.
  • the specific implementation manner and technical effect are similar, and will not be repeated here.
  • the disclosed devices and methods may be implemented in other ways.
  • the device embodiments described above are only illustrative.
  • the division of units is only a logical function division. In actual implementation, there may be other division methods.
  • multiple units or components can be combined or integrated. to another system, or some features may be ignored, or not implemented.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of devices or units may be in electrical, mechanical or other forms.
  • a unit described as a separate component may or may not be physically separated, and a component displayed as a unit may or may not be a physical unit, that is, it may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
  • each functional unit in each embodiment of the present application may be integrated into one processing unit, each unit may exist separately physically, or two or more units may be integrated into one unit.
  • the above-mentioned integrated units can be implemented in the form of hardware, or in the form of hardware plus software functional units.
  • the above-mentioned integrated units implemented in the form of software functional units may be stored in a computer-readable storage medium.
  • the above-mentioned software functional units are stored in a storage medium, and include several instructions to enable a computer device (which may be a personal computer, server, or network device, etc.) or a processor (English: processor) to execute the methods of the various embodiments of the present application. partial steps.
  • the aforementioned storage media include: U disk, mobile hard disk, read-only memory (English: Read-Only Memory, abbreviated: ROM), random access memory (English: Random Access Memory, abbreviated: RAM), magnetic disk or optical disc, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请提供一种多模终端接入控制方法、装置、电子设备及存储介质,涉及通信技术领域。其中,本地SMF根据终端发送的PDU会话建立请求中的终端标识,向本地UDM发送终端签约信息查询请求;接收本地UDM返回的终端签约信息查询结果;若终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则本地SMF向本地N3IWF发送接入控制规则创建请求以请求创建目标接入控制规则,目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF,实现了可根据终端在本地通信网络中的终端签约信息对终端接入非3GPP接入网的过程进行控制,具有实现简单、灵活性强的特点。

Description

多模终端接入控制方法、装置、电子设备及存储介质
相关申请的交叉引用
本申请要求于2021年07月05日提交中国国家知识产权局的申请号为202110754644.X、名称为“多模终端接入控制方法、装置、电子设备及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信技术领域,特别涉及一种多模终端接入控制方法、装置、电子设备及存储介质。
背景技术
第五代移动通信技术(5th generation mobile networks或5th generation wireless systems、5th-Generation,简称5G或5G技术)是最新一代蜂窝移动通信技术。而基于5G技术发展的5G本地网络也称为私有5G网络,它使用5G技术在本地用户现场创建一个专用网络,该网络具有统一的连接性,优化的服务以及在特定区域内的安全通信方式,并提供5G技术支持的高传输速度,低延迟及海量连接等特性。
现有的,多模终端指能够通过不同技术标准的网络(如WIFI,4G及5G等)进行通信的移动终端,它具备多种模式的发射、接收和处理信号系统,可支持多种不同的无线电信号处理方式。目前基于蜂窝移动终端的接入控制技术主要有两类:WLANSIM认证技术和基于5G网络的非第三代合作伙伴计划(3rd generation partnership project,3GPP)接入技术。在WLANSIM认证技术中,终端与接入控制器(access controller,AC)之间通过基于局域网的扩展认证协议(extensible authentication protocol over lan,EAPOL)通信,AC和验证、授权和记账(authentication、authorization、accounting,AAA)服务器通过远程用户拨号认证服务(remote authentication dial In user service,Radius)协议转发使用可扩展的身份验证协议(extensible authentication protocol,EAP)消息,AAA服务器使用移动应用部分(mobile application part,MAP)MAP协议从归属位置寄存器(home location register,HLR)/归属签约用户服务器(home subscriber server,HSS)获取全球用户识别卡(universal subscriber identity module,USIM)鉴权签约信息,并完成认证,AAA服务器是认证的执行点。
但基于现有的方案实现时,一般要求非3GPP接入网必须配备专用的设备或者协议栈与5G网络中的网元进行交互,例如,无线局域网(wireless local area network,WLAN)系统必须配备可以与运营商HLR/HSS系统交互的AAA服务器,实现方式比较复杂。
发明内容
本申请的目的在于,针对上述现有技术中的不足,提供一种多模终端接入控制方法、装置、电子设备及存储介质,可根据终端在本地通信网络中的终端签约信息对终端接入非3GPP接入网的过程进行控制,具有实现简单、灵活性强的特点。
为实现上述目的,本申请实施例采用的技术方案如下:
第一方面,本申请提供一种多模终端接入控制方法,包括:
本地会话管理功能SMF接收终端发送的协议数据单元PDU会话建立请求,所述PDU会话建立请求包括:终端标识;
所述本地SMF根据所述PDU会话建立请求中的终端标识,向本地统一数据管理UDM发送终端签约信息查询请求;
所述本地SMF接收所述本地UDM根据所述终端标识返回的终端签约信息查询结果;
若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则所述本地SMF向本地N3IWF发送接入控制规则创建请求,所述接入控制规则创建请求用于请求创建目标接入控制规则,所述接入控制规则创建请求包括:所述终端标识,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF。
第二方面,本申请提供一种多模终端接入控制方法,包括:
本地非3GPP互通功能N3IWF接收本地会话管理功能SMF在所述终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信后,发送的接入控制规则创建请求,所述接入控制规则创建请求包括:终端标识;其中,所述终端签约信息查询结果由本地SMF根据所述终端标识向本地统一数据管理UDM请求获取;
所述本地N3IWF根据所述接入控制规则创建请求创建目标接入控制规则,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF;
所述本地N3IWF向所述本地SMF发送目标接入控制规则创建完成消息。
第三方面,本申请提供一种多模终端接入控制方法,包括:
终端向本地会话管理功能SMF发送协议数据单元PDU会话建立请求,所述PDU会话建立请求包括:终端标识,所述终端标识用于指示所述本地SMF向本地统一数据管理UDM请求获取终端签约信息查询结果,所述终端签约信息查询结果用于指示是否允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信;
若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,所述终端与本地目标UPF在所述本地SMF通知N3IWF创建目标接入控制规则后,完成建立PDU会话,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至所述本地目标UPF。
第四方面,本申请提供一种多模终端接入控制装置,包括:
第一接收模块,用于本地会话管理功能SMF接收终端发送的协议数据单元PDU会话建立请求,所述PDU会话建立请求包括:终端标识;
第一发送模块,用于所述本地SMF根据所述PDU会话建立请求中的终端标识,向本地统一数据管理UDM发送终端签约信息查询请求;
第二接收模块,用于所述本地SMF接收所述本地UDM根据所述终端标识返回的终端签约信息查询结果;
第二发送模块,用于若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则所述本地SMF向本地N3IWF发送接入控制规则创建请求,所述接入控制规则创建请求用于请求创建目标接入控制规则,所述接入控制规则创建请求包括:所述终端标识,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF。
第五方面,本申请提供一种多模终端接入控制装置,包括:
接收模块,用于本地非3GPP互通功能N3IWF接收本地会话管理功能SMF在所述终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信后,发送的接入控制规则创建请求,所述接入控制规则创建请求包括:终端标识;其中,所述终端签约信息查询结果由本地SMF根据所述终端标识向本地统一数据管理UDM请求获取;
创建模块,用于所述本地N3IWF根据所述接入控制规则创建请求创建目标接入控制规则,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF;
发送模块,用于所述本地N3IWF向所述本地SMF发送目标接入控制规则创建完成消息。
第六方面,本申请提供一种多模终端接入控制装置,可以包括:
发送模块,用于终端向本地会话管理功能SMF发送协议数据单元PDU会话建立请求,所述PDU会话建立请求包括:终端标识,所述终端标识用于指示所述本地SMF向本地统一数据管理UDM请求获取终端签约信息查询结果,所述终端签约信息查询结果用于指示是否允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信;
建立模块,用于若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,所述终端与本地目标UPF在所述本地SMF通知N3IWF创建目标接入控制规则后,完成建立PDU会话,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至所述本地目标UPF。
第七方面,本申请提供一种电子设备,包括:处理器、存储介质和总线,所述存储介 质存储有所述处理器可执行的机器可读指令,当电子设备运行时,所述处理器与所述存储介质之间通过总线通信,所述处理器执行所述机器可读指令,以执行如前述实施方式任一所述多模终端接入控制方法的步骤。
第八方面,本申请提供一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器运行时执行如前述实施方式任一所述多模终端接入控制方法的步骤。
本申请的有益效果是:
本申请实施例提供的多模终端接入控制方法、装置、电子设备及存储介质中,本地会话管理功能SMF接收终端发送的协议数据单元PDU会话建立请求,PDU会话建立请求包括:终端标识;本地SMF根据PDU会话建立请求中的终端标识,向本地统一数据管理UDM发送终端签约信息查询请求;本地SMF接收本地UDM根据终端标识返回的终端签约信息查询结果;若终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则本地SMF向本地N3IWF发送接入控制规则创建请求,接入控制规则创建请求用于请求创建目标接入控制规则,接入控制规则创建请求包括:终端标识,目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF,实现了不再需要在非3GPP接入网中配备与N3IWF网元交互的专用协议栈,可根据终端在本地通信网络中的终端签约信息对终端接入非3GPP接入网的过程进行控制,使得本地通信网络可以灵活适应于不同的非3GPP接入网,具有实现简单、灵活性强的特点。
附图说明
为了更清楚地说明本申请实施例的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,应当理解,以下附图仅示出了本申请的某些实施例,因此不应被看作是对范围的限定,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他相关的附图。
图1是适用于本申请实施例提供的方法的网络架构的示意图;
图2为本申请实施例提供的一种多模终端接入控制方法的流程示意图;
图3为本申请实施例提供的另一种多模终端接入控制方法的流程示意图;
图4为本申请实施例提供的又一种多模终端接入控制方法的流程示意图;
图5为本申请实施例提供的另一种多模终端接入控制方法的流程示意图;
图6为本申请实施例提供的又一种多模终端接入控制方法的流程示意图;
图7为本申请实施例提供的另一种多模终端接入控制方法的流程示意图;
图8为本申请实施例提供的一种交互流程示意图;
图9为本申请实施例提供的一种多模终端接入控制装置的功能模块示意图;
图10为本申请实施例提供的一种电子设备结构示意图。
具体实施方式
为使本申请实施例的目的、技术方案和优点更加清楚,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。通常在此处附图中描述和示出的本申请实施例的组件可以以各种不同的配置来布置和设计。
因此,以下对在附图中提供的本申请的实施例的详细描述并非旨在限制要求保护的本申请的范围,而是仅仅表示本申请的选定实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
应注意到:相似的标号和字母在下面的附图中表示类似项,因此,一旦某一项在一个附图中被定义,则在随后的附图中不需要对其进行进一步定义和解释。
本申请实施例的技术方案可以应用于各种本地通信系统,例如:全球移动通讯(global system for mobile communications,GSM)系统、码分多址(code division multiple access,CDMA)系统、宽带码分多址(wideband code division multiple access,WCDMA)系统、通用分组无线业务(general packet radio service,GPRS)、长期演进(long term evolution,LTE)系统、LTE频分双工(frequency division duplex,FDD)系统、LTE时分双工(time division duplex,TDD)、通用移动通信系统(universal mobile telecommunication system,UMTS)、全球互联微波接入(worldwide interoperability for microwave access,WiMAX)通信系统、第五代(5th generation,5G)通信系统或未来的新无线接入技术(new radio access technology,NR)等。
图1是适用于本申请实施例提供的方法的网络架构的示意图。如图1所示,该网络架构例如可以是非漫游(non-roaming)架构。该网络架构具体可以包括下列网元:
1、终端设备(user equipment,UE):可以称用户设备、终端、接入终端、用户单元、用户站、移动站、移动台、远方站、远程终端、移动设备、用户终端、无线通信设备、用户代理或用户装置。UE还可以是蜂窝电话、无绳电话、会话启动协议(session initiation protocol,SIP)电话、无线本地环路(wireless local loop,WLL)站、个人数字助理(personal digital assistant,PDA)、具有无线通信功能的手持设备、计算设备或连接到无线调制解调器的其它处理设备、车载设备、可穿戴设备,5G网络中的终端设备或者未来演进的公用陆地移动通信网络(public land mobile network,PLMN)中的终端设备等,还可以是端设备,逻辑实体,智能设备,如手机,智能终端等终端设备,或者服务器,网关,基站,控制器等通信设备,或者物联网设备,如传感器,电表,水表等物联网(Internet of things,IoT) 设备。本申请实施例对此并不限定。
2、接入网(access network,AN):为特定区域的授权用户提供入网功能,并能够根据用户的级别,业务的需求等使用不同质量的传输隧道。接入网络可以为采用不同接入技术的接入网络。目前的无线接入技术有两种类型:第三代合作伙伴计划(3rd generation partnership project,3GPP)接入技术(例如3G、4G或5G系统中采用的无线接入技术)和非第三代合作伙伴计划(non-3GPP)接入技术。3GPP接入技术是指符合3GPP标准规范的接入技术,采用3GPP接入技术的接入网络称为无线接入网络(radio access network,RAN),其中,5G系统中的接入网设备称为下一代基站节点(next generation Node Base station,gNB)。非3GPP接入技术是指不符合3GPP标准规范的接入技术,例如,以WIFI中的接入点(access point,AP)为代表的空口技术。
基于无线通信技术实现接入网络功能的接入网可以称为无线接入网(radio access network,RAN)。无线接入网能够管理无线资源,为终端提供接入服务,进而完成控制信号和用户数据在终端和核心网之间的转发。
其中,接入网设备可以包括接入网中在空中接口上通过一个或多个扇区与无线终端通信的设备。接入网系统可用于将收到的空中帧与网际协议(internet protocol,IP)分组进行相互转换,作为无线终端与接入网的其余部分之间的路由器,其中接入网的其余部分可包括IP网络。无线接入网系统还可协调对空中接口的属性管理。应理解,接入网设备包括但不限于:演进型节点B(evolved node B,eNB)、无线网络控制器(radio network controller,RNC)、节点B(node B,NB)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、家庭基站(例如,home evolved nodeB,或home node B,HNB)、基带单元(base band unit,BBU),无线保真(wireless fidelity,WIFI)系统中的接入点(access point,AP)、无线中继节点、无线回传节点、传输点(transmission and reception point,TRP或者transmission point,TP)等,还可以为5G,如,NR,系统中的gNB,或,传输点(TRP或TP),5G系统中的基站的一个或一组(包括多个天线面板)天线面板,或者,还可以为构成gNB或传输点的网络节点,如基带单元(BBU)),或,分布式单元(distribute dunit,DU)等。
在一些部署中,gNB可以包括集中式单元(centralized unit,CU)和DU。gNB还可以包括射频单元(radio unit,RU)。CU实现gNB的部分功能,DU实现gNB的部分功能,比如,CU实现无线资源控制(radio resource control,RRC),分组数据汇聚层协议(packet data convergence protocol,PDCP)层的功能,DU实现无线链路控制(radio link control,RLC)、媒体接入控制(media access control,MAC)和物理(physical,PHY)层的功能。由于RRC层的信息最终会变成PHY层的信息,或者,由PHY层的信息转变而来,因而, 在这种架构下,高层信令,如RRC层信令,也可以认为是由DU发送的,或者,由DU+CU发送的。可以理解的是,接入网设备可以为CU节点、或DU节点、或包括CU节点和DU节点的设备。此外,CU可以划分为接入网(radio access network,RAN)中的接入网设备,也可以将CU划分为核心网(core network,CN)中的接入网设备,在此不做限制。
3、接入与移动管理功能(access and mobility management function,AMF)实体:主要用于移动性管理和接入管理等,可以用于实现移动性管理实体(mobility management entity,MME)功能中除会话管理之外的其它功能,例如,合法监听、或接入授权(或鉴权)等功能。在本申请实施例中,可用于实现接入和移动管理网元的功能。
4、会话管理功能(session management function,SMF)实体:主要用于会话管理、UE的网际协议(Internet Protocol,IP)地址分配和管理、选择可管理用户平面功能、策略控制、或收费功能接口的终结点以及下行数据通知等。在本申请实施例中,可用于实现会话管理网元的功能。
5、用户平面功能(User Plane Function,UPF)实体:即,数据面网关。可用于分组路由和转发、或用户面数据的服务质量(quality of service,QoS)处理等。用户数据可通过该网元接入到数据网络(data network,DN)。在本申请实施例中,可用于实现用户面网关的功能。
6、策略控制功能(policy control function,PCF)实体:用于指导网络行为的统一策略框架,为控制平面功能网元(例如AMF,SMF网元等)提供策略规则信息等。
7、统一数据管理(unified data management,UDM)实体:用于处理用户标识、接入鉴权、注册、或移动性管理等。
8、N3IWF(Non-3GPP InterWorking Function,非3GPP互通功能):负责将不可信的非3GPP接入网(如Wi-Fi)接入到5G核心网。UE与N3IWF建立一个IPsec隧道,N3IWF分别通过N2接口和N3接口接入5G核心网的控制面和用户面。
在该网络架构中,N1接口为终端与AMF实体之间的参考点;N2接口为AN和AMF实体的参考点,用于非接入层(non-access stratum,NAS)消息的发送等;N3接口为(R)AN和UPF实体之间的参考点,用于传输用户面的数据等;N4接口为SMF实体和UPF实体之间的参考点,用于传输例如N3连接的隧道标识信息,数据缓存指示信息,以及下行数据通知消息等信息;N6接口为UPF实体和DN之间的参考点,用于传输用户面的数据等。
应理解,上述应用于本申请实施例的网络架构仅是举例说明的从传统点到点的架构和服务化架构的角度描述的网络架构,适用本申请实施例的网络架构并不局限于此,任何能够实现上述各个网元的功能的网络架构都适用于本申请实施例。
还应理解,图1中所示的AMF实体、SMF实体、UPF实体、PCF实体以及UDM实体可以理解为核心网中用于实现不同功能的网元,例如可以按需组合成网络切片。这些核心网网元可以各自独立的设备,也可以集成于同一设备中实现不同的功能,本申请对此不做限定。
下文中,为便于说明,将用于实现AMF的实体记作AMF,将用于实现PCF的实体记作PCF。应理解,上述命名仅为用于区分不同的功能,并不代表这些网元分别为独立的物理设备,本申请对于上述网元的具体形态不作限定,例如,可以集成在同一个物理设备中,也可以分别是不同的物理设备。此外,上述命名仅为便于区分不同的功能,而不应对本申请构成任何限定,本申请并不排除在5G网络以及未来其它的网络中采用其他命名的可能。例如,在6G网络中,上述各个网元中的部分或全部可以沿用5G中的术语,也可能采用其他名称等。在此进行统一说明,以下不再赘述。
还应理解,图1中的各个网元之间的接口名称只是一个示例,具体实现中接口的名称可能为其他的名称,本申请对此不作具体限定。此外,上述各个网元之间的所传输的消息(或信令)的名称也仅仅是一个示例,对消息本身的功能不构成任何限定。
基于5G技术发展的5G本地网络也称为私有5G网络,它使用5G技术在本地用户现场创建一个专用网络,该网络具有统一的连接性,优化的服务以及在特定区域内的安全通信方式,并提供5G技术支持的高传输速度,低延迟及海量连接等特性。5G本地网络基于5G设备构建,包括5G终端设备,5G无线基站及5G核心网设备,它专属于网络所有者,即本地用户,可独立管理且易于部署。5G本地网络可消除对以太网等有线设备的依赖,这些有线设备不仅昂贵且笨重,而且无法连接大量移动设备及人员。
5G本地网络可在本地完成配置,并由网络所有者完全控制网络,例如安全性,网络资源使用等,网络所有者可以为关键设备分配更高的优先级来使用网络资源。几乎任何园区,企业建筑物或公共场所都可部署5G本地网络,尤其是在公共5G网络部署缓慢的特定区域中,5G本地网络可实现快速部署。
现有的,5G本地网络被广泛应用在多种场景下,比如,工业物联网(industrial internet of things,IIoT)场景中,传感器将安装在工厂中,以监视环境状况,支持质量控制和定制制造。通过5G本地网络,可以收集分析传感器数据,对工厂运营各方面信息进行精细化掌控。它可将分析结果通过5G本地网络传输至智能机器人,支持产品制造或厂区物品运输。借助5G本地网络,工人可佩戴轻量化增强现实设备,通过虚拟环境完成设备操作。
目前,5G核心网支持通过3GPP接入网(如gNB、eNB)接入,也支持通过Non 3GPP的网络接入(例如WIFI)。Non 3GPP网络通过非3GPP互通功能(Non-3GPP Inter Working Function,N3IWF)接入5G网络,N3IWF通过N2和N3接口接入5G网络。如果终端UE 同时通过3GPP和non-3GPP方式接入一个5G核心网,那么对这个终端来说会同时存在两个N1实体,一个对应3GPP的接入另一个对应non-3GPP的接入;如果N3IWF和3GPP接入网又是属于同一个网络(相同公共陆地移动网PLMN)的话,那么这两个N1实例应该在同一个AMF内。
目前,在基于5G网络的非3GPP接入技术中,非3GPP接入网(例如,WIFI)通过非3GPP互通功能(N3IWF)连接到5G核心网。N3IWF分别通过N2和N3接口连接5G核心网CP和UP功能。UE必须与N3IWF建立IPSec隧道,以通过不受信任的非3GPP访问连接到5G核心网络。在IPSec隧道建立过程中,UE将由5G核心网进行身份验证并附加到5G核心网。该技术要求非3GPP接入网内部必须配备与N3IWF网元交互的专用协议栈。
有鉴于此,本申请提供一种多模终端接入控制方法,不再需要在非3GPP接入网中配备与N3IWF网元交互的专用协议栈,可根据终端在本地通信网络中的终端签约信息对终端接入非3GPP接入网的过程进行控制,使得本地通信网络可以灵活适应于不同的非3GPP接入网,具有实现简单、灵活性强的特点。
图2为本申请实施例提供的一种多模终端接入控制方法的流程示意图,该方法的执行主体可以是本地通信系统中的本地SMF,其中,多模终端指能够通过不同技术标准的网络(如WiFi,4G及5G等)进行通信的移动终端,它具备多种模式的发射、接收和处理信号系统,可支持多种不同的无线电信号处理方式。为了更好的理解本申请,以本地通信系统基于本地5G网络建立为例进行说明,但不以此为限。如图2所示,该方法可以包括:
S101、本地会话管理功能SMF接收终端发送的协议数据单元PDU会话建立请求,PDU会话建立请求包括:终端标识。
其中,对于终端来说,终端可以向本地AMF发送PDU会话建立请求,该PDU会话建立请求可以包括终端标识,可选地,该终端标识可以是国际移动用户识别码(international mobile subscriber identity,IMSI),但不以此为限。本地AMF收到该PDU会话建立请求后,可以选择本地SMF进行PDU会话建立处理。可选地,本地SMF包括多个时,本地AMF可以根据预设选择规则在该多个可选本地SMF中选择任一本地SMF用于进行PDU会话建立处理。其中,本地SMF确定后,本地AMF可以向本地SMF转发终端发送的PDU会话建立请求,本地SMF则接收该PDU会话建立请求。
S102、本地SMF根据PDU会话建立请求中的终端标识,向本地统一数据管理UDM发送终端签约信息查询请求。
S103、本地SMF接收本地UDM根据终端标识返回的终端签约信息查询结果。
本地SMF接收到该PDU会话建立请求后,可以提取该PDU会话建立请求中的终端标识,根据该终端标识向本地统一数据管理UDM发送终端签约信息查询请求;对于本地UDM 来说,本地UDM在接收到该终端签约信息查询请求后,可以根据该终端签约信息查询请求中的终端标识进行查询,并向本地SMF返回相应地终端签约信息查询结果,该终端签约信息查询结果可以指示是否允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信。
可选地,对于终端来说,其在向通信基站首次发起网络接入请求时,可以向本地UDM注册其相关的终端签约信息,该终端签约信息可以指示是否允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信。本地UDM会将签约信息和对应的终端标识进行关联并存储,以便于后续进行查询。
S104、若终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则本地SMF向本地N3IWF发送接入控制规则创建请求。
其中,接入控制规则创建请求用于请求创建目标接入控制规则,接入控制规则创建请求包括:终端标识,目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF。
若终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则本地SMF可以进一步向本地N3IWF发送接入控制规则创建请求;对于本地N3IWF来说,其可以根据该接入控制规则创建请求创建目标接入控制规则,通过该目标接入控制规则指示允许本地N3IWF将终端发送的数据包转发至本地UPF。基于该说明,可以理解的是,通过该设置,则终端发送给本地N3IWF的数据包将进一步通过本地N3IWF转发至本地UPF,也即转发至本地5G网内部,使得本地通信网络可以灵活适应于不同的非3GPP接入网,而避免非3GPP接入网需要配备专用的设备或者协议栈才与5G网络中的网元进行交互,具有实现简单、灵活性强的特点。
综上,本申请实施例提供的多模终端接入控制方法中,本地会话管理功能SMF接收终端发送的协议数据单元PDU会话建立请求,PDU会话建立请求包括:终端标识;本地SMF根据PDU会话建立请求中的终端标识,向本地统一数据管理UDM发送终端签约信息查询请求;本地SMF接收本地UDM根据终端标识返回的终端签约信息查询结果;若终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则本地SMF向本地N3IWF发送接入控制规则创建请求,接入控制规则创建请求用于请求创建目标接入控制规则,接入控制规则创建请求包括:终端标识,目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF,实现了不再需要在非3GPP接入网中配备与N3IWF网元交互的专用协议栈,可根据终端在本地通信网络中的终端签约信息对终端接入非3GPP接入网的过程进行控制,使得本地通信网络可以灵活适应于不同的非3GPP接入网,具有实现简单、灵活性强的特点。
可选地,上述数据包中的源地址为终端的地址。
其中,数据包中的源地址可以为终端的地址,也即可以根据数据包中终端的地址,确定该数据包的转发流向。对于本地N3IWF来说,当来自非3GPP接入网的数据包的源地址(比如,IP地址)为终端的地址时,允许本地N3IWF将终端发送的该数据包转发至本地UPF,实现终端和本地通信网络之间的数据通信。
本申请实施例在本地SMF、本地N3IWF引入了新的处理功能,以便于可以通过本地SMF在本地N3IWF中创建接入控制规则,也即创建允许数据传输的表项。相应地,接入控制规则中没有匹配表项的数据包会被删除或丢弃。
图3为本申请实施例提供的另一种多模终端接入控制方法的流程示意图。可选地,根据实际的应用场景,如图3所示,上述方法还包括:
S201、若终端签约信息查询结果指示不允许终端通过N3IWF在非3GPP接入网中通信,则本地SMF向本地N3IWF发送接入控制规则删除请求,接入控制规则删除请求用于请求删除本地N3IWF中终端标识对应的接入控制规则,控制规则删除请求包括:终端标识。
可选地,实际的应用场景中,若第一预设时间段内终端签约信息查询结果指示允许终端通过N3IWF在非3GPP接入网中通信,参见前述的相关说明可知,本地N3IWF将创建目标接入控制规则,该目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF;而第二预设时间段内终端签约信息查询结果指示不允许该终端通过N3IWF在非3GPP接入网中通信,则对于本地SMF来说,此时,本地SMF需要向本地N3IWF发送接入控制规则删除请求,该控制规则删除请求可以包括:终端标识,以请求删除本地N3IWF中终端标识对应的接入控制规则,可以理解的是,在删除之后,终端发送至本地N3IWF的数据包将不再被转发至本地UPF,也即终端将不能通过N3IWF在非3GPP接入网中通信,使得根据实际的应用场景,可以随时更新本地N3IWF中的接入控制规则,提高本申请方法的适用性。
在一些实施例中,本地N3IWF中可以以表项的形式存储各终端标识对应的接入控制规则,比如,可以通过访问控制列表(Access Control Lists,ACL)存储但不以此为限。可选地,具体在进行存储时,该表项中可以包括:各终端标识和各接入控制规则之间的映射关系。当然,具体的存储方式并不以此为限,根据实际的应用场景可以有所不同。
图4为本申请实施例提供的又一种多模终端接入控制方法的流程示意图,该方法的执行主体可以是本地通信系统中的本地N3IWF网元,如图4所示,该方法可以包括:
S301、本地非3GPP互通功能N3IWF接收本地会话管理功能SMF在终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信后,发送的接入控制规则创建请求,接入控制规则创建请求包括:终端标识。
其中,终端签约信息查询结果由本地SMF根据终端标识向本地统一数据管理UDM请求获取。
参见前述本地SMF的通信过程可知,终端可以向本地AMF发送PDU会话建立请求,该PDU会话建立请求可以包括终端标识;本地AMF收到该PDU会话建立请求后,可以将该PDU会话建立请求转发给本地SMF;本地SMF根据PDU会话建立请求中的终端标识,可以向本地统一数据管理UDM发送终端签约信息查询请求;本地UDM在接收到该终端签约信息查询请求后,通过查询,可以向本地SMF返回该终端标识对应的终端签约信息查询结果。
若终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,本地SMF可以向本地N3IWF发送接入控制规则创建请求,该接入控制规则创建请求可以包括:终端标识。
S302、本地N3IWF根据接入控制规则创建请求创建目标接入控制规则,目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF。
S303、本地N3IWF向本地SMF发送目标接入控制规则创建完成消息。
本地N3IWF在接收到接入控制规则创建请求后,可以根据该接入控制规则创建请求创建目标接入控制规则,所创建的目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF。可选地,创建完成后,本地N3IWF可以向本地SMF发送目标接入控制规则创建完成消息,以便及时通知本地SMF,本地SMF根据该目标接入控制规则创建完成消息可以向本地AMF发送PDU会话确认建立消息,保证PDU会话可以继续创建。
综上,应用本申请实施例,使得对于本地N3IWF来说,若本地N3IWF接收到该终端标识所属终端发送的数据包时,可以将该数据包转发给本地UPF,也即转发至本地5G网内部,实现了可根据终端在本地通信网络中的终端签约信息对终端接入非3GPP接入网的过程进行控制,使得本地通信网络可以灵活适应于不同的非3GPP接入网,具有实现简单、灵活性强的特点。
可选地,上述数据包中的源地址为终端的地址。
其中,数据包中的源地址可以为终端的地址,也即当来自非3GPP接入网的数据包的源地址(比如,IP地址)为终端的地址时,允许本地N3IWF将终端发送的该数据包转发至本地UPF,实现终端和本地通信网络之间的数据通信。
图5为本申请实施例提供的另一种多模终端接入控制方法的流程示意图。可选地,如图5所示,上述方法还包括:
S401、本地N3IWF接收本地SMF在终端签约信息查询结果指示不允许终端通过N3IWF在非3GPP接入网中通信后,发送的接入控制规则删除请求,接入控制规则删除请 求包括:终端标识。
S402、本地N3IWF根据接入控制规则删除请求删除终端标识对应的接入控制规则。
当然,实际的应用场景中,对于同一终端标识,不同时间段内终端签约信息查询结果可以有所不同,比如,第一预设时间段内终端签约信息查询结果指示允许终端通过N3IWF在非3GPP接入网中通信;而第一预设时间段内则不允许,其中,若不允许时,本地SMF可以向本地N3IWF发送接入控制规则删除请求,本地N3IWF接收到该接入控制规则删除请求后,可以删除接入控制规则删除请求中终端标识对应的接入控制规则,使得根据实际的应用场景,可以随时更新本地N3IWF中的接入控制规则,提高本申请方法的适用性。
图6为本申请实施例提供的又一种多模终端接入控制方法的流程示意图,该方法的执行主体可以是本地通信系统中的终端,如图6所示,该方法可以包括:
S501、终端向本地会话管理功能SMF发送协议数据单元PDU会话建立请求,PDU会话建立请求包括:终端标识。
其中,终端标识用于指示本地SMF向本地统一数据管理UDM请求获取终端签约信息查询结果,终端签约信息查询结果用于指示是否允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信。
终端可以向本地AMF发送PDU会话建立请求,该PDU会话建立请求可以包括终端标识,本地AMF进一步地可以向本地SMF转发终端发送的PDU会话建立请求;本地SMF根据PDU会话建立请求中的终端标识,可以向本地统一数据管理UDM发送终端签约信息查询请求以请求获取该终端标识对应的终端签约信息查询结果;本地UDM根据终端标识可以向本地SMF返回的终端签约信息查询结果,该终端签约信息查询结果用于指示是否允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信。
S502、若终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,终端与本地目标UPF在本地SMF通知N3IWF创建目标接入控制规则后,完成建立PDU会话,目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地目标UPF。
其中,若允许,本地SMF可以向本地N3IWF发送接入控制规则创建请求,以请求创建目标接入控制规则,目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF;本地N3IWF根据接入控制规则创建请求创建目标接入控制规则后,可以向本地SMF发送目标接入控制规则创建完成消息;对于终端来说,此时,终端可以与本地目标UPF完成PDU会话的建立。
综上,应用本申请实施例,使得终端在发起PDU会话建立请求时,可以根据该PDU会话建立请求中的终端标识判断该终端是否允许通过非3GPP互通功能N3IWF在非3GPP 接入网中通信,若允许,本地N3I可以创建该终端标识对应的目标接入控制规则,通过该目标接入控制规则的创建,使得本地N3IWF可以将该终端发送的数据包转发至本地UPF,也即转发至本地5G网内部,实现终端和本地UPF之间的数据通信,实现了不再需要在非3GPP接入网中配备与N3IWF网元交互的专用协议栈,可根据终端在本地通信网络中的终端签约信息对终端接入非3GPP接入网的过程进行控制,使得本地通信网络可以灵活适应于不同的非3GPP接入网,具有实现简单、灵活性强的特点。
图7为本申请实施例提供的另一种多模终端接入控制方法的流程示意图,图8为本申请实施例提供的一种交互流程示意图,该方法的执行主体可以是本地通信系统,该本地通信系统可以包括:本地AMF、本地UPF、本地SMF、本地PCF、本地UDM以及本地N3IWF,如图7和图8所示,该方法可以包括:
S601、终端向本地AMF发送协议数据单元PDU会话建立请求,PDU会话建立请求包括:终端标识。
其中,终端可以先向本地RAN发送PDU会话建立请求,经RAN转发给本地AMF。
S602、本地AMF接收终端发送的PDU会话建立请求,并转发PDU会话建立请求至本地SMF。
S603、本地SMF根据PDU会话建立请求中的终端标识,向本地UDM发送终端签约信息查询请求。
S604、本地UDM根据本地SMF发送的终端签约信息查询请求中的终端标识,向本地SMF返回终端签约信息查询结果。
S605、若终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则本地SMF向本地N3IWF发送接入控制规则创建请求,接入控制规则创建请求包括:终端标识。
S606、本地N3IWF接收本地SMF发送的接入控制规则创建请求,根据接入控制规则创建请求创建目标接入控制规则,目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF。
可选地,本地N3IWF可以根据接入控制规则创建请求在N3IWF中创建允许数据传输的访问控制列表(Access Control Lists,ACL)表项,基于前述说明,可以理解的是,对于N3IWF来说,若ACL中没有与终端标识相匹配的表项,则终端发送至本地N3IWF的数据包将不再被转发至本地UPF,而会被丢弃。
S607、终端与本地目标UPF建立PDU会话完成。
可选地,上述终端与本地目标UPF建立PDU会话完成的过程,可参见如下的步骤:本地SMF向本地AMF发送PDU会话确认建立消息;本地SMF对PDU会话信息进行认证; 本地SMF选择本地PCF,并从本地PCF获取PCC(策略控制和计费)策略信息,可选地,该PCC策略信息可以包括QOS策略、计费策略等,在此不作限定;本地SMF选择本地UPF;本地SMF根据本地UPF向本地PCF更新策略信息;本地SMF将会话信息和策略信息发送至本地UPF;本地SMF发送PDU会话建立接受消息至本地AMF;本地AMF通知本地5G基站建立无线承载;本地5G基站通知终端建立无线承载;本地5G基站通知本地AMF完成无线承载建立;本地AMF通知本地SMF相应隧道信息;本地SMF通知本地UPF下行隧道信息;本地SMF向本地AMF确认隧道建立完成;目标PDU会话建立完成。
综上,本地SMF根据终端在PDU会话建立过程中产生的终端签约信息在N3IWF中生成接入控制规则。对于终端签约信息中允许接入网络的终端,SMF将在N3IWF中创建允许数据传输的表项,对于N3IWF,凡是在ACL中没有匹配表项的数据包都将被丢弃,可以在不修改非3GPP接入网现有设备配置及协议栈的条件下,根据5G本地网内的终端签约信息,由5G网元控制终端接入非3GPP接入网,可以明显降低非3GPP网络与5G网络对接的门槛,使得5G网络能够灵活适应不同的非3GPP接入网。
图9为本申请实施例提供的一种多模终端接入控制装置的功能模块示意图,该装置可以是前述的本地SMF网元,该装置基本原理及产生的技术效果与前述对应的方法实施例相同,为简要描述,本实施例中未提及部分,可参考方法实施例中的相应内容。如图9所示,该多模终端接入控制装置100,可以包括:
第一接收模块110,用于本地会话管理功能SMF接收终端发送的协议数据单元PDU会话建立请求,所述PDU会话建立请求包括:终端标识;
第一发送模块120,用于所述本地SMF根据所述PDU会话建立请求中的终端标识,向本地统一数据管理UDM发送终端签约信息查询请求;
第二接收模块130,用于所述本地SMF接收所述本地UDM根据所述终端标识返回的终端签约信息查询结果;
第二发送模块140,用于若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则所述本地SMF向本地N3IWF发送接入控制规则创建请求,所述接入控制规则创建请求用于请求创建目标接入控制规则,所述接入控制规则创建请求包括:所述终端标识,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF。
在可选的实施方式中,所述数据包中的源地址为所述终端的地址。
在可选的实施方式中,所述第二发送模块140,还用于若所述终端签约信息查询结果指示不允许所述终端通过N3IWF在非3GPP接入网中通信,则所述本地SMF向所述本地N3IWF发送接入控制规则删除请求,所述接入控制规则删除请求用于请求删除所述本地 N3IWF中所述终端标识对应的接入控制规则,所述控制规则删除请求包括:所述终端标识。
本申请实施例还提供一种多模终端接入控制装置,该装置可以是前述的本地N3IWF网元,该装置基本原理及产生的技术效果与前述对应的方法实施例相同,为简要描述,本实施例中未提及部分,可参考方法实施例中的相应内容,该多模终端接入控制装置可以包括:
接收模块,用于本地非3GPP互通功能N3IWF接收本地会话管理功能SMF在所述终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信后,发送的接入控制规则创建请求,所述接入控制规则创建请求包括:终端标识;其中,所述终端签约信息查询结果由本地SMF根据所述终端标识向本地统一数据管理UDM请求获取;
创建模块,用于所述本地N3IWF根据所述接入控制规则创建请求创建目标接入控制规则,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至本地UPF;
发送模块,用于所述本地N3IWF向所述本地SMF发送目标接入控制规则创建完成消息。
在可选的实施方式中,所述数据包中的源地址为所述终端的地址。
在可选的实施方式中,所述发送模块,还用于本地N3IWF接收本地SMF在所述终端签约信息查询结果指示不允许终端通过N3IWF在非3GPP接入网中通信后,发送的接入控制规则删除请求,所述接入控制规则删除请求包括:所述终端标识;
所述本地N3IWF根据所述接入控制规则删除请求删除所述终端标识对应的接入控制规则。
本申请实施例还提供一种多模终端接入控制装置,该装置可以是前述的终端,该装置基本原理及产生的技术效果与前述对应的方法实施例相同,为简要描述,本实施例中未提及部分,可参考方法实施例中的相应内容,该多模终端接入控制装置可以包括:
发送模块,用于终端向本地会话管理功能SMF发送协议数据单元PDU会话建立请求,所述PDU会话建立请求包括:终端标识,所述终端标识用于指示所述本地SMF向本地统一数据管理UDM请求获取终端签约信息查询结果,所述终端签约信息查询结果用于指示是否允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信;
建立模块,用于若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,所述终端与本地目标UPF在所述本地SMF通知N3IWF创建目标接入控制规则后,完成建立PDU会话,所述目标接入控制规则用于指示允许本地N3IWF将终端发送的数据包转发至所述本地目标UPF。
上述装置用于执行前述实施例提供的方法,其实现原理和技术效果类似,在此不再赘述。
以上这些模块可以是被配置成实施以上方法的一个或多个集成电路,例如:一个或多个特定集成电路(Application Specific Integrated Circuit,简称ASIC),或,一个或多个微处理器,或,一个或者多个现场可编程门阵列(Field Programmable Gate Array,简称FPGA)等。再如,当以上某个模块通过处理元件调度程序代码的形式实现时,该处理元件可以是通用处理器,例如中央处理器(Central Processing Unit,简称CPU)或其它可以调用程序代码的处理器。再如,这些模块可以集成在一起,以片上系统(system-on-a-chip,简称SOC)的形式实现。
图10为本申请实施例提供的一种电子设备结构示意图。如图10所示,该电子设备可以包括:处理器210、存储介质220和总线230,存储介质220存储有处理器210可执行的机器可读指令,当电子设备运行时,处理器210与存储介质220之间通过总线230通信,处理器210执行机器可读指令,以执行上述方法实施例的步骤。具体实现方式和技术效果类似,这里不再赘述。
可选地,本申请还提供一种存储介质,存储介质上存储有计算机程序,计算机程序被处理器运行时执行上述方法实施例的步骤。具体实现方式和技术效果类似,这里不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用硬件加软件功能单元的形式实现。
上述以软件功能单元的形式实现的集成的单元,可以存储在一个计算机可读取存储介质中。上述软件功能单元存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)或处理器(英文:processor)执行本申请各个实施例方法的部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(英文:Read-Only Memory,简称:ROM)、随机存取存储器(英文:Random Access Memory,简称:RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
需要说明的是,在本文中,诸如“第一”和“第二”等之类的关系术语仅仅用来将一个实体或者操作与另一个实体或操作区分开来,而不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。而且,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括要素的过程、方法、物品或者设备中还存在另外的相同要素。
以上仅为本申请的优选实施例而已,并不用于限制本申请,对于本领域的技术人员来说,本申请可以有各种更改和变化。凡在本申请的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本申请的保护范围之内。应注意到:相似的标号和字母在下面的附图中表示类似项,因此,一旦某一项在一个附图中被定义,则在随后的附图中不需要对其进行进一步定义和解释。以上仅为本申请的优选实施例而已,并不用于限制本申请,对于本领域的技术人员来说,本申请可以有各种更改和变化。凡在本申请的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本申请的保护范围之内。

Claims (10)

  1. 一种多模终端接入控制方法,其特征在于,包括:
    本地会话管理功能SMF接收终端发送的协议数据单元PDU会话建立请求,所述协议数据单元PDU会话建立请求包括:终端标识;
    所述本地会话管理功能SMF根据所述协议数据单元PDU会话建立请求中的终端标识,向本地统一数据管理UDM发送终端签约信息查询请求;
    所述本地会话管理功能SMF接收所述本地统一数据管理UDM根据所述终端标识返回的终端签约信息查询结果;
    若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则所述本地会话管理功能SMF向本地非3GPP互通功能N3IWF发送接入控制规则创建请求,所述接入控制规则创建请求用于请求创建目标接入控制规则,所述接入控制规则创建请求包括:所述终端标识,所述目标接入控制规则用于指示允许本地非3GPP互通功能N3IWF将终端发送的数据包转发至本地用户平面功能UPF。
  2. 根据权利要求1所述的方法,其特征在于,所述数据包中的源地址为所述终端的地址。
  3. 根据权利要求1所述的方法,其特征在于,所述方法还包括:
    若所述终端签约信息查询结果指示不允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则所述本地会话管理功能SMF向所述本地非3GPP互通功能N3IWF发送接入控制规则删除请求,所述接入控制规则删除请求用于请求删除所述本地非3GPP互通功能N3IWF中所述终端标识对应的接入控制规则,所述控制规则删除请求包括:所述终端标识。
  4. 一种多模终端接入控制方法,其特征在于,包括:
    本地非3GPP互通功能N3IWF接收本地会话管理功能SMF在所述终端签约信息查询结果指示允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信后,发送的接入控制规则创建请求,所述接入控制规则创建请求包括:终端标识;其中,所述终端签约信息查询结果由本地会话管理功能SMF根据所述终端标识向本地统一数据管理UDM请求获取;所述终端标识由所述本地会话管理功能SMF接收的终端发送的协议数据单元PDU会话建立请求携带;
    所述本地非3GPP互通功能N3IWF根据所述接入控制规则创建请求创建目标接入控制规则,所述目标接入控制规则用于指示允许本地非3GPP互通功能N3IWF将终端发送的数据包转发至本地用户平面功能UPF;
    所述本地非3GPP互通功能N3IWF向所述本地会话管理功能SMF发送目标接入控制规则创建完成消息。
  5. 根据权利要求4所述的方法,其特征在于,所述数据包中的源地址为所述终端的地址。
  6. 根据权利要求5所述的方法,其特征在于,所述方法还包括:
    本地非3GPP互通功能N3IWF接收本地会话管理功能SMF在所述终端签约信息查询结果指示不允许终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信后,发送的接入控制规则删除请求,所述接入控制规则删除请求包括:所述终端标识;
    所述本地非3GPP互通功能N3IWF根据所述接入控制规则删除请求删除所述终端标识对应的接入控制规则。
  7. 一种多模终端接入控制方法,其特征在于,包括:
    终端向本地会话管理功能SMF发送协议数据单元PDU会话建立请求,所述协议数据单元PDU会话建立请求包括:终端标识,所述终端标识用于指示所述本地会话管理功能SMF向本地统一数据管理UDM请求获取终端签约信息查询结果,所述终端签约信息查询结果用于指示是否允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信;
    若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,所述终端与本地目标用户平面功能UPF在所述本地会话管理功能SMF通知非3GPP互通功能N3IWF创建目标接入控制规则后,完成建立PDU会话,所述目标接入控制规则用于指示允许本地非3GPP互通功能N3IWF将终端发送的数据包转发至所述本地目标用户平面功能UPF。
  8. 一种多模终端接入控制装置,其特征在于,包括:
    第一接收模块,用于本地会话管理功能SMF接收终端发送的协议数据单元PDU会话建立请求,所述协议数据单元PDU会话建立请求包括:终端标识;
    第一发送模块,用于所述本地会话管理功能SMF根据所述协议数据单元PDU会话建立请求中的终端标识,向本地统一数据管理UDM发送终端签约信息查询请求;
    第二接收模块,用于所述本地会话管理功能SMF接收所述本地统一数据管理UDM根据所述终端标识返回的终端签约信息查询结果;
    第二发送模块,用于若所述终端签约信息查询结果指示允许所述终端通过非3GPP互通功能N3IWF在非3GPP接入网中通信,则所述本地会话管理功能SMF向本地非3GPP互通功能N3IWF发送接入控制规则创建请求,所述接入控制规则创建请求用于请求创建目标接入控制规则,所述接入控制规则创建请求包括:所述终端标识,所述目标接入控制规则用于指示允许本地非3GPP互通功能N3IWF将终端发送的数据包转发至本地用户平面功能UPF。
  9. 一种电子设备,其特征在于,包括:处理器、存储介质和总线,所述存储介质存储有所述处理器可执行的机器可读指令,当电子设备运行时,所述处理器与所述存储介质之间通过总线通信,所述处理器执行所述机器可读指令,以执行如权利要求1-7任一所述多模终端接入控制方法的步骤。
  10. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器运行时执行如权利要求1-7任一所述多模终端接入控制方法的步骤。
PCT/CN2022/082474 2021-07-05 2022-03-23 多模终端接入控制方法、装置、电子设备及存储介质 WO2023279776A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110754644.X 2021-07-05
CN202110754644.XA CN113260016B (zh) 2021-07-05 2021-07-05 多模终端接入控制方法、装置、电子设备及存储介质

Publications (1)

Publication Number Publication Date
WO2023279776A1 true WO2023279776A1 (zh) 2023-01-12

Family

ID=77190628

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/082474 WO2023279776A1 (zh) 2021-07-05 2022-03-23 多模终端接入控制方法、装置、电子设备及存储介质

Country Status (2)

Country Link
CN (1) CN113260016B (zh)
WO (1) WO2023279776A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115879895A (zh) * 2023-02-01 2023-03-31 深圳高灯计算机科技有限公司 协议准入方法、装置、计算机设备和存储介质

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113260016B (zh) * 2021-07-05 2021-10-08 深圳艾灵网络有限公司 多模终端接入控制方法、装置、电子设备及存储介质
CN114363975A (zh) * 2022-01-17 2022-04-15 北京艾灵客科技有限公司 数据通信方法、装置、电子设备及存储介质
CN115119287B (zh) * 2022-06-29 2024-03-26 阿里巴巴(中国)有限公司 通信网络、车联网、终端设备接入方法、设备和存储介质
CN117979373A (zh) * 2022-10-25 2024-05-03 华为技术有限公司 通信方法、系统、存储介质和程序产品

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108377497A (zh) * 2016-11-21 2018-08-07 华为技术有限公司 连接建立方法、设备及系统
CN111034336A (zh) * 2017-08-11 2020-04-17 Idac控股公司 多个接入网络之间的业务引导和切换
WO2020204518A1 (ko) * 2019-03-29 2020-10-08 삼성전자 주식회사 무선 통신 시스템에서 세션 관리를 위한 장치 및 방법
US20200351818A1 (en) * 2019-04-30 2020-11-05 Comcast Cable Communications, Llc Wireless Communications for Network Access Configuration
CN113260016A (zh) * 2021-07-05 2021-08-13 深圳艾灵网络有限公司 多模终端接入控制方法、装置、电子设备及存储介质

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107979860B (zh) * 2016-10-25 2020-07-07 华为技术有限公司 支持non-3GPP接入的用户面功能实体选择方法、设备及系统
US11510058B2 (en) * 2018-03-29 2022-11-22 Telefonaktiebolaget Lm Ericsson (Publ) Methods for support of user plane separation and user plane local offloading for 5G non-3GPP access
CN112399507B (zh) * 2019-08-16 2022-08-19 华为技术有限公司 用于传输数据的方法、终端设备和网络设备
CN112751780B (zh) * 2019-10-29 2023-03-24 中国电信股份有限公司 数据传输方法、装置、系统和计算机可读存储介质

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108377497A (zh) * 2016-11-21 2018-08-07 华为技术有限公司 连接建立方法、设备及系统
CN111034336A (zh) * 2017-08-11 2020-04-17 Idac控股公司 多个接入网络之间的业务引导和切换
WO2020204518A1 (ko) * 2019-03-29 2020-10-08 삼성전자 주식회사 무선 통신 시스템에서 세션 관리를 위한 장치 및 방법
US20200351818A1 (en) * 2019-04-30 2020-11-05 Comcast Cable Communications, Llc Wireless Communications for Network Access Configuration
CN113260016A (zh) * 2021-07-05 2021-08-13 深圳艾灵网络有限公司 多模终端接入控制方法、装置、电子设备及存储介质

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
QUALCOMM INCORPORATED: "23.502: Procedures for roaming support for non-3GPP access support", 3GPP DRAFT; S2-171283-WAS-170740-5G-N3GPP-ROAMING-23.502-REVISED, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG2, no. Dubrovnik, Croatia; 20170213 - 20170217, 18 February 2017 (2017-02-18), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051240575 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115879895A (zh) * 2023-02-01 2023-03-31 深圳高灯计算机科技有限公司 协议准入方法、装置、计算机设备和存储介质
CN115879895B (zh) * 2023-02-01 2023-07-07 安徽有活科技有限公司 协议准入方法、装置、计算机设备和存储介质

Also Published As

Publication number Publication date
CN113260016A (zh) 2021-08-13
CN113260016B (zh) 2021-10-08

Similar Documents

Publication Publication Date Title
WO2023279776A1 (zh) 多模终端接入控制方法、装置、电子设备及存储介质
CN104521287B (zh) 网络切换方法、装置、设备及系统
US11864103B2 (en) Network slicing method and device, and storage medium
WO2018161796A1 (zh) 多接入场景中的连接处理方法和装置
CN113207191B (zh) 基于网络切片的会话建立方法、装置、设备及存储介质
WO2022048394A1 (zh) 网络连接方法、网络去连接方法及通信装置
CN111869261A (zh) Lwa 通信中的发现与安全
JP7383827B2 (ja) 時刻同期方法、電子設備および記憶媒体
WO2023124457A1 (zh) 选择网络的方法和装置
WO2012116623A1 (zh) 一种移动通信系统和组网方法
CN113676904B (zh) 切片认证方法及装置
CN113595911B (zh) 数据转发方法、装置、电子设备及存储介质
WO2021233340A1 (zh) 网络注册的方法和装置
CA3204536A1 (en) Key identifier generation method and related apparatus
WO2023185880A1 (zh) 一种接入网设备的确定方法
CN114980074B (zh) 基于虚拟局域网的数据通信方法、装置、设备及介质
CN114885382B (zh) 一种业务会话管理方法、装置及存储介质
WO2022194262A1 (zh) 安全通信的方法和装置
KR20240060670A (ko) 통신 방법 및 장치
CN114363975A (zh) 数据通信方法、装置、电子设备及存储介质
CN114600487B (zh) 身份认证方法及通信装置
CN116056171B (zh) 终端切换系统、方法、电子设备及存储介质
WO2023160390A1 (zh) 通信方法与装置
WO2023179397A1 (zh) 一种授权方法及装置
WO2023142717A1 (zh) 一种确定用户设备路由选择策略的方法和装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22836535

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE