WO2024093783A1 - Operation execution method and apparatus, terminal and network function - Google Patents

Operation execution method and apparatus, terminal and network function Download PDF

Info

Publication number
WO2024093783A1
WO2024093783A1 PCT/CN2023/126764 CN2023126764W WO2024093783A1 WO 2024093783 A1 WO2024093783 A1 WO 2024093783A1 CN 2023126764 W CN2023126764 W CN 2023126764W WO 2024093783 A1 WO2024093783 A1 WO 2024093783A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
network function
indication information
message
information
Prior art date
Application number
PCT/CN2023/126764
Other languages
French (fr)
Chinese (zh)
Inventor
谢振华
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Publication of WO2024093783A1 publication Critical patent/WO2024093783A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/009Security arrangements; Authentication; Protecting privacy or anonymity specially adapted for networks, e.g. wireless sensor networks, ad-hoc networks, RFID networks or cloud networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security

Definitions

  • the present application belongs to the field of communication technology, and specifically relates to an operation execution method, device, terminal and network function.
  • the Internet of Things is a network covering multiple devices based on the computer Internet, using sensor networks, radio frequency identification technology, wireless data communication and other technologies.
  • devices can communicate with each other. Its essence is to use radio frequency automatic identification (RFID) technology to achieve mutual communication between devices through wireless data links and computer Internet.
  • RFID radio frequency automatic identification
  • the Internet of Things device generally refers to the terminal device used in certain specific scenarios or specific services, such as smart home devices, smart utilities, e-health and smart wearable devices.
  • the embodiments of the present application provide an operation execution method, apparatus, terminal, and network function to implement authentication-related operations on a device in a PIN, thereby improving the security of accessing the PIN.
  • an operation execution method comprising:
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • an operation execution method comprising:
  • the first network function sends fifth indication information to the first terminal
  • the first network function receives a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first network function In response to the first non-access stratum NAS message and/or the first indication information, the first network function performs at least one of the following:
  • the fifth indication information is used to indicate at least one of the following:
  • an operation execution method including:
  • the third network function performs a second operation
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • an operation execution method comprising:
  • the second terminal sends configuration information to the first terminal in the personal Internet of Things PIN.
  • an operation execution method including:
  • the fifth network function sends fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • an operation execution device including:
  • a first sending module configured to send a first non-access stratum NAS message and/or first indication information to a network side, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first receiving module is configured to receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • an operation execution device including:
  • a second sending module used to send fifth indication information to the first terminal
  • a second receiving module configured to receive a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • a first processing module is configured to, in response to the first non-access layer NAS message and/or the first indication information, perform at least one of the following:
  • the fifth indication information is used to indicate at least one of the following:
  • the first operation is allowed or not allowed to be performed through a user plane of the mobile network.
  • an operation execution device including:
  • a second processing module used for performing a second operation
  • the second operation includes at least one of the following:
  • an operation execution device comprising:
  • the third sending module is used to send configuration information to the first terminal in the personal Internet of Things PIN.
  • an operation execution device comprising:
  • a fourth sending module configured to send fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform a second operation
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • a terminal which includes a processor and a memory, wherein the memory stores a program or instruction that can be executed on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the first aspect or the fourth aspect are implemented.
  • a network function including a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the second aspect, the third aspect, or the fifth aspect are implemented.
  • an operation execution system including: a first terminal, a second terminal, a first network function, a second network function, a third network function, a fourth network function, and at least two of a fifth network function, wherein the first terminal can be used to execute the steps of the operation execution method as described in the first aspect above, the second terminal can be used to execute the steps of the operation execution method as described in the fourth aspect above, and the first network function can be used to execute the steps of the operation execution method as described in the fourth aspect above.
  • the third network function can be used to execute the steps of the operation execution method described in the third aspect
  • the fifth network function can be used to execute the steps of the operation execution method described in the fifth aspect
  • the second network function and the fifth network function can be used to cooperate with at least one of the first terminal, the second terminal, the first network function, the third network function and the fifth network function to execute the steps of the operation execution method described in any one of claims 1-46.
  • a readable storage medium on which a program or instruction is stored.
  • the program or instruction is executed by a processor, the steps of the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect are implemented.
  • a chip comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.
  • a computer program/program product is provided, wherein the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement the steps of the method described in the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect.
  • an embodiment of the present application provides an operation execution determination device, which is used to execute the steps of the operation execution method described in the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect.
  • the first terminal can send a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization; and/or the first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • the first terminal can instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, authentication, and authorization operations on the device in the PIN, that is, the present application clarifies the authentication, authentication, and authorization operations in the PIN, thereby improving the security of accessing the PIN.
  • FIG1 is a block diagram of a wireless communication system to which an embodiment of the present application can be applied;
  • FIG2 is a flow chart of an operation execution method in an embodiment of the present application.
  • FIG3 is a flow chart of another operation execution method in an embodiment of the present application.
  • FIG4 is a flow chart of another operation execution method in an embodiment of the present application.
  • FIG5 is a flow chart of another operation execution method in an embodiment of the present application.
  • FIG6 is a flow chart of another operation execution method in an embodiment of the present application.
  • FIG7 is a flowchart of implementation mode 1 of the operation execution method of the embodiment of the present application.
  • FIG8 is a flow chart of implementation mode 2 of the operation execution method of an embodiment of the present application.
  • FIG9 is a flow chart of an operation execution device in an embodiment of the present application.
  • FIG10 is a flow chart of another operation execution device in an embodiment of the present application.
  • FIG11 is a flow chart of another operation execution device in an embodiment of the present application.
  • FIG12 is a flow chart of another operation execution device in an embodiment of the present application.
  • FIG13 is a flow chart of another operation execution device in an embodiment of the present application.
  • FIG14 is a block diagram of a communication device in an embodiment of the present application.
  • FIG15 is a block diagram of a terminal in an embodiment of the present application.
  • FIG16 is a structural block diagram of a network function in an embodiment of the present application.
  • FIG. 17 is a structural block diagram of another network function in an embodiment of the present application.
  • first, second, etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by “first” and “second” are generally of the same type, and the number of objects is not limited.
  • the first object can be one or more.
  • “and/or” in the specification and claims represents at least one of the connected objects, and the character “/" generally represents that the objects associated with each other are in an "or” relationship.
  • LTE Long Term Evolution
  • LTE-A Long Term Evolution
  • CDMA Code Division Multiple Access
  • TDMA Time Division Multiple Access
  • FDMA Frequency Division Multiple Access
  • OFDMA Orthogonal Frequency Division Multiple Access
  • SC-FDMA Single-carrier Frequency Division Multiple Access
  • NR new radio
  • FIG1 shows a block diagram of a wireless communication system applicable to the embodiment of the present application.
  • the wireless communication system includes a terminal 11 and a network function 12.
  • the terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), Laptop Computer (also called notebook computer), Personal Digital Assistant (PDA), PDA, netbook, ultra-mobile personal computer (UMPC), mobile Internet Device (MID), augmented reality (AR)/virtual reality (VR) equipment, robot, wearable device (Wearable Device), vehicle-mounted equipment (VUE), pedestrian terminal (PUE), smart home (home equipment with wireless communication function, such as refrigerator, TV, washing machine or furniture, etc.), game console, personal computer (personal computer, PC), teller machine or self-service machine and other terminal side equipment, wearable device includes: smart watch, smart bracelet, smart headset, smart glasses, smart jewelry (smart bracelet, smart bracelet, smart ring, smart necklace, smart anklet, smart anklet, etc.), smart wristband, smart clothing, etc.
  • PDA Personal Digital Assistant
  • UMPC
  • the network function 12 may include an access network device or a core network device, wherein the access network device 12 may also be referred to as a radio access network device, a radio access network (RAN), a radio access network function or a radio access network unit.
  • the access network device 12 may include a base station, a WLAN access point or a WiFi node, etc.
  • the base station may be referred to as a node B, an evolved node B (eNB), an access point, a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home B node, a home evolved B node, a transmitting and receiving point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to a specific technical vocabulary, it should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
  • the core network equipment may include but is not limited to at least one of the following: core network nodes, core network functions, mobility management entity (Mobility Management Entity, MME), access mobility management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), policy control function (Policy Control Function, PCF), policy and charging rules function unit (Policy and Charging Rules Function, PCRF), edge application service discovery function (Edge Application Server Discovery ...
  • MME mobility management entity
  • AMF Access and Mobility Management Function
  • SMF Session Management Function
  • SMF Session Management Function
  • UPF User Plane Function
  • Policy Control Function Policy Control Function
  • PCRF Policy and Charging Rules Function
  • edge application service discovery function Edge Application Server Discovery ...
  • the method may include the following steps 201 and/or 202:
  • Step 201 A first terminal sends a first non-access stratum NAS message and/or first indication information to a network side.
  • the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function
  • the first terminal can be, for example, a terminal with gateway capability, i.e., a gateway terminal (PIN Element with Gateway Capability, PEGC);
  • the first network function can be, for example, a session management function (Session Management Function, SMF) or an access and mobility management function (Access and Mobility Management Function, AMF).
  • SMF Session Management Function
  • AMF Access and Mobility Management Function
  • the first non-access layer NAS message is used to indicate the first operation
  • the first indication information is used to indicate the first operation.
  • the first terminal can send a first non-access layer NAS message to the network side (such as the above-mentioned first network function) to instruct the network side to perform the first operation (that is, trigger the network side to perform the first operation through a NAS message); or, it can send a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side device to perform the first operation through an indication information); or, it can also send a first NAS message and a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side to perform the first operation through a NAS message and an indication information), here, the first NAS message and the first indication information can be independent, or the first indication information can be carried in the first NAS message.
  • the first operation includes at least one of the following:
  • Step 202 The first terminal receives fifth indication information sent by the network side.
  • the fifth indication information is used to indicate at least one of the following:
  • the method further includes:
  • the first terminal interacts with the network side to establish a PDU session
  • step 202 “the first terminal receives the fifth indication information sent by the network side” includes:
  • the first terminal receives a PDU session establishment/modification confirmation message sent by the network side, and the PDU session establishment/modification confirmation message carries the fifth indication information.
  • the network side may carry the fifth indication information in a PDU session confirmation message and send it to the first terminal.
  • step 202 “the first terminal receives fifth indication information sent by the network side” includes:
  • the first terminal receives the fifth indication information sent by the network side in response to the first non-access layer NAS message and/or the first indication information.
  • the network side can carry the fifth indication information in the PDU session establishment confirmation/modification confirmation message and send it to the first terminal to inform the first terminal whether it allows the first operation; or after receiving the first non-access layer NAS message and/or the first indication information sent by the first terminal, the network side can send the fifth indication information to the first terminal to inform the first terminal whether it allows the first operation.
  • the first terminal can send a first non-access layer NAS message and/or a first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization; and/or, the first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used for at least one of the following:
  • the first terminal can instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, certification, and authorization operations on the device in the PIN, thereby improving the security of accessing the PIN.
  • the first terminal may also meet the following conditions 1 or 2:
  • the first terminal can also have the function of a personal Internet of Things device (PIN Element, PINE) and gateway capabilities, that is, PEGC and PINE can be combined into one device.
  • PINE personal Internet of Things device
  • PEGC and PINE can be combined into one device.
  • the first terminal may not have the PINE capability.
  • the first terminal only has the gateway capability, that is, PEGC and PINE are independently configured.
  • the method further includes:
  • the first terminal interacts with the network side to establish a protocol data unit (PDU) session.
  • PDU protocol data unit
  • the first terminal formed by combining PEGC and PINE can also establish a PDU session with the network side before sending the first non-access layer NAS message and/or the first indication information to the network side.
  • the first terminal before the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, if a PDU session is established, the first terminal can subsequently use the modification process of the subsequent PDU session to send the first non-access layer NAS message to the network side.
  • the first non-access layer NAS message is a PDU session modification request. That is, in the aforementioned situation 1, the first terminal can send the PDU modification request as the first NAS message to the network side to trigger the network side to perform the first operation.
  • the first indication information includes at least one of the following items A-1 to A-3:
  • Item A-1 an instruction for instructing to perform the first operation
  • Item A-2 information of the first terminal
  • Item A-3 Information about a second network function, wherein the second network function is used to perform the first operation.
  • the information of the first terminal may include at least one of an identifier, an IP address, and a MAC address.
  • the above-mentioned item A-1 indicates that the first terminal can display and instruct the network side to perform the first operation
  • the above item A-2 indicates that the first terminal can implicitly instruct the network side to perform the first operation through the information of the first terminal.
  • the network side when the network side receives the first indication information sent by the first terminal including the above-mentioned indication for instructing to perform the first operation, it can determine that the first operation needs to be performed on the first terminal based on the displayed indication content; when the network side receives the first indication information sent by the first terminal including the above-mentioned information of the first terminal, it can also determine that the first operation needs to be performed on the first terminal through the implicit indication content.
  • the second network function may be, for example, an external data network authentication and authorization center (AAA), that is, the first terminal may also inform the network side which network function performs the first operation.
  • AAA external data network authentication and authorization center
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
  • the first terminal When or after a connection is established between the first terminal and the first device, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side.
  • the first device may be a PINE.
  • the first terminal may instruct the network side to perform the first operation.
  • the first terminal when or after the connection is established between the first terminal and the first device, the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, including:
  • the first terminal receives the first message sent by the first device, or receives the sixth message sent by the second terminal;
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side in response to the first message or the sixth message;
  • the first message is used to indicate at least one of the following:
  • the sixth message is used to instruct the first terminal or the first device to communicate with the second network function
  • the second network function is used to perform the first operation.
  • the first message When the first message is used to indicate establishment of a connection between the first device and the first terminal, the first message may be a connection request sent by the first device to the first terminal, or may be a connection request sent by the first terminal to the first device.
  • the first terminal when the first terminal receives the first message sent by the first device, it can trigger the first terminal to send the above-mentioned first non-access layer NAS message and/or first indication information to the network side device, so that the network side performs the first operation on the first device; or, when the first terminal receives the above-mentioned sixth message sent by the second terminal, it can trigger the first terminal to send the above-mentioned first non-access layer NAS message and/or first indication information to the network side device, so that the network side performs the first operation on the first device.
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request. That is, in the aforementioned situation 2, the first terminal can send the PDU modification request or the PDU session establishment request as the first NAS message to the network side to trigger the network side to perform the first operation.
  • the first indication information includes at least one of the following items B-1 to B-4:
  • Item B-1 an instruction for instructing to perform the first operation
  • Item B-2 information about the first device
  • Item B-3 information of the first terminal
  • Item B-4 Information about a second network function, wherein the second network function is used to perform the first operation.
  • the information of the first terminal may include at least one of an identifier, an IP address, and a MAC address; the information of the first device may include at least one of an identifier, an IP address, and a MAC address.
  • the above item B-1 indicates that the first terminal can display and instruct the network side to perform the first operation
  • Item B-2 above indicates that the first terminal may implicitly instruct the network side to perform the first operation through information of the first device;
  • the above item B-3 indicates that the first terminal can implicitly instruct the network side to perform the first operation through the information of the first terminal;.
  • the network side when the network side receives the first indication information sent by the first terminal including the above-mentioned indication for instructing to perform the first operation, it can be determined based on the displayed indication content that the first operation needs to be performed on the device (i.e., the first device) that sends the above-mentioned first message to the first terminal; when the network side receives the first indication information sent by the first terminal including the information of the above-mentioned first device, it can also be determined through the implicit indication content that the first operation needs to be performed on the first device; when the network side receives the first indication information sent by the first terminal including the information of the above-mentioned first terminal, it can also be determined through the implicit indication content that the first operation needs to be performed on the device (i.e., the first device) that sends the above-mentioned first message to the first terminal.
  • the second network function may be, for example, an external data network authentication and authorization center (AAA), that is, the first terminal may also inform the network side which network function performs the first operation.
  • AAA external data network authentication and authorization center
  • the method further includes:
  • the first terminal receives second indication information sent by the network side, wherein the second indication information is used to indicate a result of the first operation:
  • the first terminal performs at least one of the following items C-1 to C-3 according to the second indication information:
  • Item C-1 allowing or rejecting the first message sent by the first device to be received by the first terminal;
  • Item C-2 Allow or deny processing of data of the first device
  • Item C-3 allowing, retaining or releasing the connection between the first terminal and the first device
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the network side After the network side receives the first non-access layer NAS message and/or the first indication information, it performs the first operation on the first device according to the indication of the first non-access layer NAS message and/or the first indication information, thereby returning the result of executing the first operation to the first terminal.
  • the first terminal can execute at least one of the above items C-1 to C-3 according to the result of executing the first operation.
  • the method further comprises:
  • the first terminal executes at least one of the following items G-1 to G- according to the fifth indication information:
  • Item G-1 Execute or stop executing the first operation
  • Item G-2 sending or stopping sending sixth indication information to the second network function, where the sixth indication information is used to instruct the second network function to perform the first operation;
  • Item G-3 sending or stopping sending a fourth message to the second network function, where the fourth message is a message related to performing the first operation;
  • Item G-4 receiving or stopping receiving a fifth message from the second network function, where the fifth message is a message related to performing the first operation;
  • Item G-5 allowing or rejecting the first message sent by the first device and received by the first terminal;
  • Item G-6 Allow or deny processing of data on the first device
  • Item G-7 allowing, retaining or releasing the connection between the first terminal and the first device
  • the first message is used to indicate at least one of the following:
  • Establish a connection between the first device and the first terminal access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
  • the above-mentioned item G-1 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal performs the first operation; when the fifth indication information does not allow the first operation, or does not allow the first operation to be performed through the control plane of the network side, or does not allow the first operation to be performed through the user plane of the network side, the first terminal stops performing the first operation.
  • the above G-2 item indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal sends the sixth indication information to the second network function; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the first terminal stops sending the sixth indication information to the second network function;
  • the above-mentioned item G-3 indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal sends the fourth message to the second network function; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the first terminal stops sending the fourth message to the second network function;
  • the above-mentioned item G-4 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the fifth message from the second network function is received; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the fifth message from the second network function is stopped;
  • the above G-5 item indicates: when the fifth indication information indicates that the first operation is allowed, or the control plane on the network side is allowed When performing the first operation or allowing the first operation to be performed through the user plane of the network side, allowing the first message sent by the first device received by the first terminal; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, rejecting the first message sent by the first device received by the first terminal;
  • the above-mentioned item G-6 indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the processing of the data of the first device is allowed; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the processing of the data of the first device is rejected;
  • the above-mentioned item G-7 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the connection between the first terminal and the first device is allowed or retained; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the connection between the first terminal and the first device is released.
  • the first terminal receiving the second indication information sent by the network side includes:
  • the first terminal receives a second NAS message sent by the network side, wherein the second NAS message carries the second indication information.
  • the network side may carry the second indication information used to indicate the result of executing the first operation in the second NAS message, and send the message to the first terminal.
  • the second indication information satisfies at least one of the following items D-1 to D-2:
  • Item D-1 indicating the result of the first operation by an identifier or a name of the second NAS message
  • Item D-1 Indicate the result of the first operation through a cause value.
  • the above item D-1 represents the identifier or name of different second NAS messages, indicating different results of the first operation.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the second NAS message sent by the network side to the first terminal is a PDU session modification confirmation message or a PDU session establishment confirmation message, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side to the first terminal is a PDU session modification rejection message or a PDU session establishment rejection message, it indicates that the first operation fails.
  • the network side when the network side successfully executes the first operation, it returns a PDU session modification confirmation message or a PDU session establishment confirmation message to the first terminal; when the network side fails to execute the first operation, it returns a PDU session modification rejection message or a PDU session establishment rejection message to the first terminal.
  • the above-mentioned item D-2 indicates that the result of the first operation indicating a difference is displayed by the cause value.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the second NAS message sent by the network side includes a failure cause value and/or a failure indication, it indicates that the first operation has failed; if the second NAS message sent by the network side does not include a failure cause value and/or a failure indication, it indicates that the first operation has been successfully executed.
  • the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side does not include a success reason value and/or a success indication, it indicates that the first operation fails.
  • the second NAS message sent by the network side includes a failure reason value and/or a failure indication, it indicates that the first operation has failed to execute; if the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation has been executed successfully.
  • the method further comprises at least one of the following:
  • the first terminal receives a second message from the network side, and sends the second message to the first device;
  • the first terminal receives a third message from the first device, and sends the third message to the network side;
  • the second message and the third message are messages involved in executing the first operation, that is, the second message and the third message are messages that the first device and the network side need to interact with when executing the first operation.
  • the first terminal can also forward interaction messages for the first device and the network side.
  • the network side may send a second message to the first terminal for requesting the identification information of the first device, so that the first terminal sends the second message to the first device, and the first device returns a third message carrying the identification information of the first device to the first terminal, and the first terminal returns the third message to the network side.
  • the second message is an extensible authentication protocol (EAP) message
  • the third message is an EAP message
  • step 201 can be as described in the following method 1, method 2 or method 3:
  • the method further includes:
  • the first terminal receives the rule information sent by the network side
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information.
  • the first terminal can send the first non-access layer NAS message and/or the first indication information according to the rule information sent by the network side (i.e., the third network function, such as the policy control function entity (Policy Control Function, PCF)).
  • the third network function such as the policy control function entity (Policy Control Function, PCF)
  • rule information is used to indicate at least one of the following items E-1 to E-2:
  • Item E-1 the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • Item E-2 At least one first target device requires the first operation or does not require the first operation.
  • the target PIN is one of the PINs created by the second terminal;
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the above item E-1 indicates that the rule information can indicate whether the first operation needs to be performed for the PIN, that is, whether the first operation needs to be performed is indicated with the PIN as the granularity.
  • the above-mentioned item E-2 indicates that the rule information may also indicate whether the first operation needs to be performed for each PINE, that is, indicating whether the first operation needs to be performed with PINE as the granularity.
  • the second terminal for example, the management terminal (PIN Element with Management Capability, PEMC)
  • the management terminal PIN Element with Management Capability, PEMC
  • the fifth network function for example, the application function (Application Function, AF)
  • the third network function for example, PCF
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information, including at least one of the following:
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side;
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side:
  • Item H-1 the first non-access stratum NAS message and/or the first indication information is related to the target PIN;
  • Item H-2 The connection between the first terminal and the first device is related to the target PIN;
  • Item H-3 the first message sent by the first device and received by the first terminal is related to the target PIN;
  • Item H-4 The first device is associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the first terminal does not send the first non-access layer NAS message and/or the first indication information to the network side;
  • the first terminal When the rule information indicates that the first device does not need the first operation, the first terminal does not send the first non-access stratum NAS message and/or the first indication information to the network side.
  • the method further includes:
  • the first terminal receives configuration information sent by the second terminal;
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the configuration information.
  • the first terminal can send the first non-access stratum NAS message and/or the first indication information according to the configuration information sent by the second terminal (for example, PEMC).
  • the second terminal for example, PEMC
  • the configuration information is used to indicate at least one of the following items F-1 to F-2:
  • Item F-1 the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • Item F-2 At least one second target device requires the first operation or does not require the first operation.
  • the target PIN is one of the PINs created by the second terminal;
  • the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  • the above item F-1 indicates that the configuration information can indicate whether the first operation needs to be performed for the PIN, that is, whether the first operation needs to be performed is indicated with the PIN as the granularity.
  • the above item F-2 indicates that the configuration information may also indicate whether the first operation needs to be performed for each PINE, that is, indicating whether the first operation needs to be performed with PINE as the granularity.
  • the second terminal may indicate to the first terminal whether the first operation needs to be applied to the PIN and/or whether a PIN needs the first operation.
  • the first terminal when the configuration information indicates that the first device requires the first operation, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side;
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side:
  • Item L-1 the first non-access stratum NAS message and/or the first indication information is related to the target PIN;
  • Item L-2 The connection between the first terminal and the first device is related to the target PIN;
  • Item L-3 the first message sent by the first device and received by the first terminal is related to the target PIN;
  • Item L-4 The first device is associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the first terminal does not send the first non-access layer NAS message and/or the first indication information to the network side;
  • the first terminal When the configuration information indicates that the first device does not need the first operation, the first terminal does not send the first non-access stratum NAS message and/or the first indication information to the network side.
  • the method further includes:
  • the first terminal receives the PIN rule information sent by the network side;
  • the first terminal receives configuration information sent by the second terminal;
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information and the configuration information.
  • the first terminal can send the first non-access stratum NAS message and/or the first indication information according to the rule information sent by the network side and the configuration information sent by the second terminal.
  • the content indicated by the rule information can refer to the aforementioned method 1
  • the content indicated by the configuration information can refer to the aforementioned method 2. That is, both the rule information and the configuration information can perform the aforementioned PIN granularity indication and PINE granularity indication.
  • the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side according to the rule information and the configuration information, including:
  • the first non-access layer NAS message and/or the first indication information is sent to the network side.
  • the specific method of sending the first non-access layer NAS message and/or the first indication information to the network side according to the rule information is the same as the aforementioned method one; when the one with a higher priority between the rule information and the configuration information is the configuration information, the specific method of sending the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information is the same as the aforementioned method two and is not repeated here.
  • the method further comprises:
  • the first terminal sends information of the first device to the network side.
  • the first terminal can also send information of the first device to the network side (for example, the first network function).
  • the information of the first device may include address information of the first device (eg, IP address).
  • an embodiment of the present application provides an operation execution method. As shown in FIG. 3 , the method may include the following steps 301 and/or 302 and 303:
  • Step 301 The first network function sends fifth indication information to the first terminal.
  • the fifth indication information is used to indicate at least one of the following:
  • the method further includes:
  • the first network function interacts with the first terminal to establish a PDU session
  • Step 301 “the first network function sends fifth indication information to the first terminal” includes:
  • the first network function sends a PDU session establishment/modification confirmation message to the first terminal, and the PDU session establishment/modification confirmation message carries the fifth indication information.
  • the first network function may carry the fifth indication information in a PDU session establishment/modification confirmation message and send it to the first terminal.
  • Step 302 The first network function receives a first non-access stratum NAS message and/or first indication information sent by the first terminal.
  • the first non-access stratum NAS message is used to indicate the first operation
  • the first indication information is used to indicate the first operation
  • the first operation includes at least one of authentication, certification, and authorization.
  • the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function
  • the first terminal can be, for example, a terminal with gateway capability, i.e., a gateway terminal (PIN Element with Gateway Capability, PEGC);
  • the first network function can be, for example, a session management function (Session Management Function, SMF) or an access and mobility management function (Access and Mobility Management Function, AMF).
  • SMF Session Management Function
  • AMF Access and Mobility Management Function
  • the first terminal can send a first non-access layer NAS message to the network side (such as the above-mentioned first network function) to instruct the network side to perform the first operation (that is, trigger the network side to perform the first operation through a NAS message); or, it can send a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side device to perform the first operation through an indication information); or, it can also send a first NAS message and a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side to perform the first operation through a NAS message and an indication information), where the first NAS message and the first indication information can be independent, or the first indication information can be carried in the first NAS message.
  • the network side such as the above-mentioned first network function
  • the first operation includes at least one of the following:
  • Step 303 The first network function performs at least one of the following in response to the first non-access stratum NAS message and/or the first indication information:
  • the first network function can establish/modify the PDU session after receiving the PDU sent by the first terminal.
  • the fifth indication information is carried in the PDU session establishment/modification confirmation message and sent to the first terminal to inform the first terminal whether it allows the first operation; or after the first network function receives the first non-access layer NAS message and/or the first indication information sent by the first terminal, the fifth indication information is sent to the first terminal to inform the first terminal whether it allows the first operation.
  • the first network function is capable of receiving a first non-access layer NAS message and/or a first indication information sent by the first terminal, thereby responding to the first non-access layer NAS message and/or the first indication information, sending fifth indication information to the first terminal and/or instructing the second network function and the first terminal to perform a first operation; and/or, the first network function sends the fifth indication information to the first terminal; wherein the first non-access layer NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, the first operation includes at least one of authentication, authentication, and authorization, and the fifth indication information is used to indicate at least one of the following:
  • the first terminal can instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, certification, and authorization operations on the device in the PIN, thereby improving the security of accessing the PIN.
  • the method further includes:
  • the first network function receives third indication information sent by the second network function, wherein the third indication information is used to indicate a result of the first operation;
  • the first network function sends second indication information to the first terminal according to the third indication information, where the second indication information is used to indicate a result of the first operation.
  • the second network function is used to perform the first operation. After the second network function performs the first operation, it can return third indication information indicating the result of the first operation to the first network function, and then the first network function returns second indication information indicating the result of the first operation to the first terminal based on the third indication information.
  • the first terminal may also meet the following conditions 1 or 2:
  • the first terminal can also have the function of a personal Internet of Things device (PIN Element, PINE) and gateway capabilities, that is, PEGC and PINE can be combined into one device.
  • PINE personal Internet of Things device
  • PEGC and PINE can be combined into one device.
  • the first terminal may not have the PINE capability.
  • the first terminal only has the gateway capability, that is, PEGC and PINE are independently configured.
  • the method further includes:
  • the first network function interacts with the first terminal to establish a protocol data unit (PDU) session.
  • PDU protocol data unit
  • the first terminal formed by combining PEGC and PINE can also establish a PDU session with the network side before sending the first non-access layer NAS message and/or the first indication information to the network side.
  • the first terminal before the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, if a PDU session is established, the first terminal can subsequently use the modification process of the subsequent PDU session to send the first non-access layer NAS message to the network side.
  • the first non-access layer NAS message is a PDU session modification request. That is, in the aforementioned situation 1, the first terminal can send the PDU modification request as the first NAS message to the network side to trigger the network side to perform the first operation.
  • the first indication information includes at least one of the following items A-1 to A-3:
  • Item A-1 an instruction for instructing to perform the first operation
  • Item A-2 information of the first terminal
  • Item A-3 Information about a second network function, wherein the second network function is used to perform the first operation.
  • the first indication information includes at least one of the following items B-1 to B-4:
  • Item B-1 an instruction for instructing to perform the first operation
  • Item B-2 information about the first device
  • Item B-3 information of the first terminal
  • Item B-4 Information about a second network function, wherein the second network function is used to perform the first operation.
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request. That is, in the aforementioned situation 2, the first terminal can send the PDU modification request or the PDU session establishment request as the first NAS message to the network side to trigger the network side to perform the first operation.
  • the first network function sending second indication information to the first terminal according to the third indication information includes:
  • the first network function sends a second NAS message to the first terminal according to the third indication information, wherein the second NAS message carries the second indication information.
  • the first network function may carry the second indication information used to indicate the result of executing the first operation in the second NAS message, and send the message to the first terminal.
  • the second indication information satisfies at least one of the following items D-1 to D-2:
  • Item D-1 indicating the result of the first operation by an identifier or a name of the second NAS message
  • Item D-1 Indicate the result of the first operation through a cause value.
  • the above item D-1 represents the identifier or name of different second NAS messages, indicating different results of the first operation.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the second NAS message sent by the network side to the first terminal is a PDU session modification confirmation message or a PDU session establishment confirmation message, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side to the first terminal is a PDU session modification rejection message or a PDU session establishment rejection message, it indicates that the first operation fails.
  • the network side when the network side successfully executes the first operation, it returns a PDU session modification confirmation message or a PDU session establishment confirmation message to the first terminal; when the network side fails to execute the first operation, it returns a PDU session modification rejection message or a PDU session establishment rejection message to the first terminal.
  • the above-mentioned item D-2 indicates that the result of the first operation indicating a difference is displayed by the cause value.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the second NAS message sent by the network side includes a failure cause value and/or a failure indication, it indicates that the first operation has failed; if the second NAS message sent by the network side does not include a failure cause value and/or a failure indication, it indicates that the first operation has been successfully executed.
  • the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side does not include a success reason value and/or a success indication, it indicates that the first operation fails.
  • the second NAS message sent by the network side includes a failure reason value and/or a failure indication, it indicates that the first operation has failed to execute; if the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation has been executed successfully.
  • the method further comprises at least one of the following:
  • the first network function receives a second message forwarded by the first terminal for the first device
  • the first network function sends a third message to the first terminal, so that the first terminal forwards the third message to the first device;
  • the second message and the third message are messages involved in executing the first operation, that is, the second message and the third message are messages that the first device and the network side need to interact with when executing the first operation.
  • the first terminal can also forward the interaction message for the first device and the first network function.
  • the first network function may send a second message for requesting the identification information of the first device to the first terminal, so that the first terminal The terminal sends the second message to the first device, so that the first device returns a third message carrying the identification information of the first device to the first terminal, and the first terminal returns the third message to the first network function.
  • the first network function instructs the second network function to perform the first operation, including:
  • the first network function sends identification information of the first device to the second network function to instruct the second network function to perform the first operation.
  • the first network function instructs the second network function and the first terminal to perform the first operation in response to the first non-access layer NAS message, including at least one of the following items V-1 to V-5:
  • Item V-1 the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message;
  • Item V-2 the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message and the first association information between the PDU session related information and the PIN instance or session;
  • Item V-3 the first network function instructs the second network function and the first terminal to perform the first operation based on the PIN instance or session related information in the first non-access layer NAS message;
  • Item V-4 the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information and the PIN service indication information in the first non-access layer NAS message;
  • the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message, and the second association information between the PDU session related information and the PIN service.
  • the above-mentioned V-1 item indicates that if the PDU session related information in the first non-access layer NAS message is specific information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PDU session related information may include at least one of the PDU session identifier, the data network name (Data Network Name, DNN), and the network slice selection auxiliary information (Single Network Slice Selection Assistance Information, S-NSSAI).
  • S-NSSAI Single Network Slice Selection Assistance Information
  • the above-mentioned V-2 item indicates: if there is a PIN instance or session corresponding to the PDU session related information in the first non-access layer NAS message in the first association information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PDU session related information may include at least one of the PDU session identifier, DNN, and S-NSSAI.
  • the first network function instructs the second network function and the first terminal to perform the first operation.
  • the above item V-3 indicates that: if the first non-access layer NAS message includes PIN instance or session related information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PIN instance or session related information may include a PIN instance or a session identifier.
  • the first non-access layer NAS message contains indication information indicating that the PDU session related information is related to the PIN service (that is, it is related to the PIN service, rather than other services such as telephone service and video service), and the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PDU session related information may include at least one of the PDU session identifier, DNN, and S-NSSAI.
  • the above-mentioned item V-5 indicates that: if the second association information indicates that the PDU session-related information in the first non-access layer NAS message is related to the PIN service (referring to the PIN service, not other services such as telephone service and video service), the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PDU session-related information may include at least one of the PDU session identifier, DNN, and S-NSSAI. For example, when there is a PIN service corresponding to the PDU session identifier in the first NAS message in the second association information, the first network function instructs the second network function and the first terminal to perform the first operation.
  • the first network function may also instruct the second network function and the first terminal to perform the first operation according to the information of the sending device of the received first NAS message. For example, when the first NAS message is sent by a device with gateway capabilities (that is, when the first terminal is a terminal with gateway capabilities), the first network function instructs the second network function and the first terminal to perform the first operation; when the first NAS message is not sent by a device with gateway capabilities (that is, when the first terminal is not a terminal with gateway capabilities), the first network function does not instruct the second network function and the first terminal to perform the first operation.
  • the method further comprises:
  • the first network function learns at least one of the following from the third network function:
  • the second associated information The second associated information.
  • the third network function may be PCF or UDM.
  • the method further comprises:
  • the first network function receives information about the first device sent by the first terminal;
  • the first device is a device that needs to access the PIN or the network where the first network function is located through the first terminal.
  • the first terminal can also send information of the first device to the network side (for example, the first network function).
  • the information of the first device may include address information of the first device (eg, IP address).
  • the method further comprises:
  • the first network function uses the message filtering rule to configure a fourth network function.
  • the fourth network function may be, for example, a user plane function (User Port Function, UPF).
  • UPF User Port Function
  • the embodiment of the present application further provides an operation execution method, as shown in FIG4 , the method includes the following step 401:
  • Step 401 The third network function performs a second operation.
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • the third network function may be, for example, PCF or UDM.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the PDU session configuration information includes at least one of the following:
  • the second association information between the PDU session related information and the PIN service is the second association information between the PDU session related information and the PIN service.
  • the first terminal after the first terminal receives the rule information, it can send the first non-access layer NAS message and/or the first indication information to the first network function according to the rule information.
  • the specific sending method can be found in the above description and will not be repeated here.
  • the first network function After the first network function receives the PDU session configuration information, it can instruct the second network function and the first terminal to perform the first operation according to the PDU session configuration information (i.e., the first association information and/or the second association information).
  • the PDU session configuration information i.e., the first association information and/or the second association information.
  • the method further includes:
  • the third network function acquires fourth indication information, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
  • the third network function performs the second operation, including:
  • the third network function performs the second operation according to the fourth indication information.
  • the third network function acquires the fourth indication information, including:
  • the third network function receives the fourth indication information sent by the fifth network function.
  • the fifth network function may be AF.
  • the second terminal for example, the management terminal (PIN Element with Management Capability, PEMC)
  • the management terminal PIN Element with Management Capability, PEMC
  • the fifth network function for example, the application function (Application Function, AF)
  • the fifth network function sends the above-mentioned fourth indication information to the third network function, thereby triggering the third network function to perform the above-mentioned second operation.
  • the present application embodiment further provides an operation execution method, as shown in FIG5 , the method may include The steps 501 are as follows:
  • Step 501 The second terminal sends configuration information to the first terminal in the personal Internet of Things PIN.
  • the second terminal may be, for example, PEMC
  • the first terminal may be, for example, PEGC
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  • the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function according to the configuration information.
  • the specific sending method can be found in the above description and will not be repeated here.
  • the embodiment of the present application further provides an operation execution method, as shown in FIG6 , the method may include the following step 601:
  • Step 601 The fifth network function sends fourth indication information to the third network function.
  • the fifth network function may be AF.
  • the fourth indication information is used to instruct the third network function to perform a second operation
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the PDU session configuration information includes at least one of the following:
  • the second association information between the PDU session related information and the PIN service is the second association information between the PDU session related information and the PIN service.
  • the first terminal after the first terminal receives the rule information, it can send the first non-access layer NAS message and/or the first indication information to the first network function according to the rule information.
  • the specific sending method can be found in the above description and will not be repeated here.
  • the first network function After the first network function receives the PDU session configuration information, it can instruct the second network function and the first terminal to perform the first operation according to the PDU session configuration information (i.e., the first association information and/or the second association information).
  • the PDU session configuration information i.e., the first association information and/or the second association information.
  • Implementation method 1 as shown in FIG. 7 , it includes the following steps 71 to 716 (the first operation mentioned above includes authentication and/or authorization for illustration).
  • Step 71 The PEMC creates a PIN, can notify the AF that a PIN has been created, and can indicate whether access to the PIN requires 5G core network-assisted authentication and/or authorization.
  • PEMC can ask PINE for device information (for example, PEMC asks PINE for device information when PINE accesses PIN) to learn whether PINE has a credential, so that when PINE has a credential, when such PINE is added to a PIN, AF is instructed that the PINE needs authentication and/or authorization assisted by the 5G core network.
  • the credential is the authentication information.
  • Step 72 AF may notify PCF directly or through NEF whether the PIN requires authentication and/or authorization assisted by the 5G core network.
  • Step 73 After the PCF learns whether the PIN requires authentication and/or authorization assisted by the 5G core network, it generates rule information and sends the rule information to each PEGC in the PIN through the AMF.
  • the rule information is used to indicate whether access to the PIN requires authentication and/or authorization assisted by the 5G core network.
  • Step 74 The first PINE connects to the PEGC to access the PIN (eg, the first PINE sends a connection request to the PEGC).
  • Step 75 If the rule information obtained by PEGC indicates that the PIN requires authentication and/or authorization assisted by the 5G core network, configuration information is obtained from PEMC, wherein the configuration information is used to indicate whether at least one PINE requires authentication and/or authorization assisted by the 5G core network.
  • Step 76 If the configuration information indicates that the first PINE requires authentication and/or authorization assisted by the 5G core network, the PEGC sends a first NAS message to the SMF, wherein the first NAS message carries an indication for indicating authentication and/or authorization; if the configuration information indicates that the first PINE does not require authentication and/or authorization assisted by the core network, the PEGC does not send the first NAS message to the SMF.
  • the first NAS message can be a PDU session modification request (PDU Session Modification Request) or a PDU session establishment request (PDU Session Establishment Request).
  • PDU Session Modification Request PDU Session Modification Request
  • PDU Session Establishment Request PDU Session Establishment Request
  • Step 77 If the SMF receives the first NAS message, it determines whether the first PINE needs to be authenticated and/or authorized based on the relevant information of the first NAS message, and then executes the following step 78 when determining whether the first PINE needs to be authenticated and/or authorized;
  • the relevant information of the first NAS message includes at least one of the following:
  • PDU session related information in the first NAS message e.g. PDU session identifier, DNN, S-NASSAI
  • PIN instance or session related information e.g. PIN identifier
  • the PDU session related information and the PIN service indication information in the first NAS message i.e., indicating that the PDU session related information in the first NAS message is related to the PIN service
  • Step 78 SMF sends a first EAP message to PEGC, so that PEGC forwards the first EAP message to PINE, wherein the first EAP message is used to request the ID of PINE; the first EAP message may be an EAP identity in an EAP request (EAP Request);
  • Step 79 PINE sends a second EAP message to PEGC, so that PEGC forwards the first EAP message to SMF, wherein the second EAP message carries the ID of PINE; the second EAP message may be an EAP identity in an EAP response (EAP Response);
  • Step 710 SMF sends a second EAP message to the external data network authentication authority (AAA).
  • AAA external data network authentication authority
  • Step 711 AAA and PINE exchange EAP messages (such as EAP Request, EAP Response) through SMF, UPF, and PEGC to complete the authentication and/or authorization process.
  • EAP messages such as EAP Request, EAP Response
  • Step 712 If the authentication and/or authorization is successful, AAA (eg, through UPF) sends an EAP success (EAP-Success message) to SMF.
  • AAA eg, through UPF
  • EAP success EAP-Success message
  • Step 713 If SMF receives the EAP-Success message, SMF sends a PDU session establishment acknowledgment (PDU Session Establishment Ack) or a PDU session modification acknowledgment (PDU Session Modification Ack) to PEGC, otherwise it sends a PDU session establishment reject (PDU Session Establishment Reject) or a PDU session modification reject (PDU Session Modification Reject).
  • PDU Session Establishment Ack PDU session establishment acknowledgment
  • PDU Session Modification Ack PDU Session Modification Ack
  • PDU Session Establishment Ack or PDU Session Modification Ack may also carry at least one of the indication of successful authentication and/or authorization and the reason value of successful authentication and/or authorization;
  • PDU Session Establishment Reject or PDU Session Modification Reject may also carry at least one of the indication of authentication and/or authorization failure and the reason value of authentication and/or authorization failure.
  • Step 714 If the PEGC receives a PDU Session Establishment Ack or a PDU Session Modification Ack, the PEGC allows the first PINE to connect to access the PIN, otherwise the PEGC rejects the connection of the first PINE.
  • Step 715 If PEGC receives PDU Session Establishment Ack or PDU Session Modification Ack, PEGC can also send the IP address of the first PINE to SMF.
  • Step 716 SMF can authorize the communication configuration of the PIN (including message filtering rules) based on the received IP address of the first PINE, such as accepting the message filtering rules related to the first PINE (i.e., accepting the message filtering rules containing the IP address of the PINE).
  • SMF may be replaced by AMF
  • UPF may be replaced by authentication service function (AUSF); or UPF or AUSF may not be involved in this implementation.
  • AUSF authentication service function
  • Implementation method 2 includes the following steps 81 to 811 .
  • Step 81 PEGC establishes a PDU Session and initiates a PDU session establishment request (PDU Session Establishment Request).
  • Step 82 SMF returns a PDU Session Establishment Ack message, carrying the fifth indication information, and the first operation includes at least one of authentication, certification, and authorization.
  • the fifth indication information is used to indicate at least one of the following:
  • Step 83 The first PINE connects to the PEGC to access the PIN (eg, the first PINE sends a connection request to the PEGC).
  • Step 84 PEMC creates a PIN and can notify AF that a PIN has been created.
  • PEMC can send a Communication Request message to PEGC to indicate that one or more PINEs of PEGC need to perform the first operation.
  • the fifth indication information in the aforementioned step 82 indicates that the first operation is not allowed, or an operation is not allowed to be performed through the control plane of the mobile network where the SMF is located, or the first operation is not allowed to be performed through the user plane of the mobile network where the SMF is located, then the subsequent steps stop executing, otherwise the subsequent steps are executed.
  • Step 85 PEGC sends a PDU Session Modification Request to SMF, which may carry at least one of the first indication information, the first PINE information, the PEGC information, and the AAA information.
  • the first indication information is used to indicate the first operation.
  • Step 86 If the SMF allows the first operation, or allows the AAA in step 85 to perform the first operation, or allows the PEGC or the first PINE in step 85 to perform the first operation, or allows the PEGC or the first PINE in step 85 and the AAA to perform the first operation, it returns a PDU Session Modification Ack message; otherwise, it returns a PDU Session Modification Reject message, which may carry indication information for indicating that the first operation is not allowed.
  • Step 87 If the first operation is allowed, the PEGC may send a first EAP message to the first PINE to request the ID of the first PINE; the first EAP message may be an EAP identity in an EAP request (EAP Request);
  • Step 88 PINE sends a second EAP message to PEGC, carrying the ID of the first PINE; the second EAP message can be the EAP identity (EAP Identity) in the EAP response (EAP Response).
  • EAP Identity EAP identity
  • EAP Response EAP response
  • Step 89 PEGC sends the ID of the first PINE to the external data network authentication authority (AAA) through the user of the 5G system.
  • AAA external data network authentication authority
  • Step 810 AAA and PINE exchange EAP messages (such as EAP Request and EAP Response) through PEGC to perform the first operation.
  • EAP messages such as EAP Request and EAP Response
  • Step 811 If the first operation is successful, AAA sends an EAP-Success message to PEGC, otherwise it sends an EAP failure (send EAP-Failure) message. If PEGC receives EAP-Success, it allows the first PINE to connect to access the PIN, otherwise PEGC rejects the connection of the first PINE.
  • SMF may be replaced by AMF
  • UPF may be replaced by authentication service function (AUSF); or UPF or AUSF may not be involved in this implementation.
  • AUSF authentication service function
  • Implementation Mode 1 and Implementation Mode 2 are only two implementation modes of the embodiment of the present application, that is, the specific implementation mode of the operation execution method of the embodiment of the present application is not limited thereto, and can also be various possible combinations of the aforementioned contents.
  • the operation execution method provided in the embodiment of the present application can be executed by an operation execution device.
  • the operation execution device provided in the embodiment of the present application is described by taking the operation execution method executed by the operation execution device as an example.
  • an embodiment of the present application provides an operation execution device, which is applied to a first terminal.
  • the operation execution device 90 includes the following modules:
  • a first sending module 901 is configured to send a first non-access stratum NAS message and/or first indication information to a network side, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first receiving module 902 is configured to receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • the device further comprises:
  • the first establishing module is used to interact with the network side to establish a protocol data unit PDU session before the first sending module 901 sends the first non-access layer NAS message and/or the first indication information to the network side.
  • the first non-access layer NAS message is a PDU session modification request.
  • the first indication information includes at least one of the following:
  • the first sending module 901 includes:
  • the first sending submodule is used for, when or after the connection between the first terminal and the first device is established, for the first terminal to send the first non-access layer NAS message and/or the first indication information to the network side.
  • the first sending submodule is specifically used for:
  • the first message is used to indicate at least one of the following:
  • the sixth message is used to instruct the first terminal or the first device to communicate with the second network function
  • the second network function is used to perform the first operation.
  • the first indication information includes at least one of the following:
  • the device further comprises:
  • a third receiving module is configured to receive second indication information sent by the network side after the first sending module 901 sends the first non-access layer NAS message and/or the first indication information to the network side, wherein the second indication information is used to indicate a result of the first operation:
  • the third processing module is configured to perform at least one of the following according to the second indication information:
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the device further comprises:
  • the fourth processing module is configured to perform at least one of the following according to the fifth indication information:
  • the first message is used to indicate at least one of the following:
  • Establish a connection between the first device and the first terminal access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
  • the first receiving module 902 is specifically configured to:
  • a second NAS message sent by the network side is received, wherein the second NAS message carries the second indication information.
  • the second indication information satisfies at least one of the following:
  • the result of the first operation is indicated by a cause value.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the device further comprises at least one of the following modules:
  • a first forwarding module configured to receive a second message from the network side, and send the second message to the first device
  • a second forwarding module configured to receive a third message from the first device, and send the third message to the network side;
  • the second message and the third message are respectively messages involved in executing the first operation.
  • the second message is an Extensible Authentication Protocol (EAP) message
  • the third message is an EAP message.
  • EAP Extensible Authentication Protocol
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
  • the device further comprises:
  • a fourth receiving module used to receive the rule information sent by the network side
  • the first sending module includes:
  • the second sending submodule is used to send the first non-access layer NAS message and/or the first indication information to the network side according to the rule information.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation.
  • the second sending submodule is specifically configured to perform at least one of the following:
  • the first non-access stratum NAS message and/or the first indication information are related to the target PIN;
  • connection between the first terminal and the first device is associated with the target PIN
  • the first message sent by the first device and received by the first terminal is related to the target PIN;
  • the first device being associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the device further comprises:
  • a fifth receiving module configured to receive configuration information sent by the second terminal
  • the first sending module 901 includes:
  • the third sending submodule is used for the first terminal to send the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information.
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation.
  • the third sending submodule is specifically configured to perform at least one of the following:
  • the first non-access stratum NAS message and/or the first indication information are related to the target PIN;
  • connection between the first terminal and the first device is associated with the target PIN
  • the first message sent by the first device and received by the first terminal is related to the target PIN;
  • the first device being associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the device further comprises:
  • a fifth sending module is used to send information of the first device to the network side when the second indication information indicates that the first operation is successful.
  • the first terminal is a terminal with gateway capability.
  • the operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a terminal, for example
  • the terminal may include but is not limited to the types of the terminal 11 listed above, and the embodiment of the present application does not make any specific limitation.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 2 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application provides an operation execution device, which is applied to a first network function.
  • the operation execution device 100 includes the following modules:
  • the second sending module 1001 is used to send fifth indication information to the first terminal
  • the second receiving module 1002 is configured to receive a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first processing module 1003 is configured to, in response to the first non-access stratum NAS message and/or the first indication information, perform at least one of the following:
  • the fifth indication information is used to indicate at least one of the following:
  • the first operation is allowed or not allowed to be performed through a user plane of the mobile network.
  • the device further comprises:
  • a sixth receiving module configured to receive third indication information sent by the second network function when the first network function instructs the second network function and the first terminal to perform the first operation, wherein the third indication information is used to indicate a result of the first operation;
  • the sixth sending module is used to send second indication information to the first terminal according to the third indication information, where the second indication information is used to indicate a result of the first operation.
  • the device further comprises:
  • the second establishing module is used to interact with the first terminal to establish a protocol data unit PDU session before the first network function receives the first non-access layer NAS message and/or the first indication information sent by the first terminal.
  • the first non-access layer NAS message is a PDU session modification request.
  • the first indication information includes at least one of the following:
  • the first indication information includes at least one of the following:
  • the first device needs to access the personal IoT PIN through the first terminal or a device in the network where the first network function is located;
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
  • the sixth sending module is specifically configured to:
  • a second NAS message is sent to the first terminal, wherein the second NAS message carries the second indication information.
  • the second indication information satisfies at least one of the following:
  • the result of the first operation is indicated by a cause value.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the first processing module when the first processing module instructs the second network function and the first terminal to perform the first operation in response to the first non-access layer NAS message, the first processing module is specifically configured to perform at least one of the following:
  • the second network function and the first terminal are instructed to perform the first operation.
  • the device further comprises:
  • the fifth processing module is configured to obtain at least one of the following from the third network function:
  • the second associated information The second associated information.
  • the device further comprises:
  • a seventh receiving module configured to receive information about the first device sent by the first terminal when the second indication information indicates that the first operation is successful
  • the first device is a device that needs to access the PIN or the network where the first network function is located through the first terminal.
  • the device further comprises:
  • a configuration module is used for, when the first network function learns a message filtering rule and the message filtering rule is related to the first device, the first network function uses the message filtering rule to configure a fourth network function.
  • the operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a network function.
  • the network function can include but is not limited to the types of network functions 12 listed above, and the embodiment of the present application does not specifically limit this.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 3 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application provides an operation execution device, which is applied to a third network function.
  • the operation execution device 110 includes the following modules:
  • the second processing module 1101 is used to perform a second operation
  • the second operation includes at least one of the following:
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the PDU session configuration information includes at least one of the following:
  • the second association information between the PDU session related information and the PIN service is the second association information between the PDU session related information and the PIN service.
  • the device further comprises:
  • a sixth processing module configured to obtain fourth indication information before the second processing module 1101 performs the second operation, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
  • the second processing module 1101 is specifically used for:
  • the second operation is performed according to the fourth indication information.
  • the sixth processing module is specifically configured to:
  • the third network function receives the fourth indication information sent by the fifth network function.
  • the operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a network function, and illustratively, the network function can include but is not limited to the types of network functions 12 listed above, which are not specifically limited in the embodiment of the present application.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 4 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application provides an operation execution device, which is applied to a second terminal.
  • the operation execution device 120 includes the following modules:
  • the third sending module 1201 is used to send configuration information to the first terminal in the personal Internet of Things PIN.
  • the first terminal in the personal Internet of Things PIN created by the second terminal device sends configuration information.
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  • the operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a terminal, and illustratively, the terminal can include but is not limited to the types of the terminal 11 listed above, and the embodiment of the present application does not specifically limit it.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 5 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application provides an operation execution device, which is applied to the fifth network function.
  • the operation execution device 130 includes the following modules:
  • the fourth sending module 1301 is configured to send fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform a second operation;
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the PDU session configuration information includes at least one of the following:
  • the second association information between the PDU session related information and the PIN service is the second association information between the PDU session related information and the PIN service.
  • the operation execution method in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a network function, and illustratively, the network function can include but is not limited to the types of network functions 12 listed above, which are not specifically limited in the embodiment of the present application.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 6 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the embodiment of the present application further provides a communication device 1400, including a processor 1401 and a memory 1402, the memory 1402 stores a program or instruction that can be run on the processor 1401, for example, when the communication device 1400 is a terminal, the program or instruction is executed by the processor 1401 to implement the various steps of the above-mentioned operation execution method embodiment, and can achieve the same technical effect.
  • the communication device 1400 is a network function
  • the program or instruction is executed by the processor 1401 to implement the various steps of the above-mentioned operation execution method embodiment, and can achieve the same technical effect, to avoid repetition, it will not be repeated here.
  • the embodiment of the present application also provides a terminal, as shown in FIG14 , which is a schematic diagram of the hardware structure of a terminal for implementing the embodiment of the present application.
  • the terminal 1400 includes but is not limited to: a radio frequency unit 1401, a network module 1402, an audio output unit 1403, an input unit 1404, a sensor 1405, a display unit 1406, a user input unit 1407, an interface unit 1408, a memory 1409 and at least some of the components of the processor 1410.
  • the terminal 1400 may also include a power source (such as a battery) for supplying power to each component, and the power source may be logically connected to the processor 1410 through a power management system, so as to implement functions such as charging, discharging, and power consumption management through the power management system.
  • a power source such as a battery
  • the terminal structure shown in FIG14 does not constitute a limitation on the terminal, and the terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange components differently, which will not be described in detail here.
  • the input unit 1404 may include a graphics processing unit (GPU) 14041 and a microphone 14042, and the graphics processor 14041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode.
  • the display unit 1406 may include a display panel 14061, and the display panel 14061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc.
  • the user input unit 1407 includes a touch panel 14071 and at least one of other input devices 14072.
  • the touch panel 14071 is also called a touch screen.
  • the touch panel 14071 may include two parts: a touch detection device and a touch controller.
  • Other input devices 14072 may include, but are not limited to, a physical keyboard, function keys, and the like. (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be repeated here.
  • the RF unit 1401 can transmit the data to the processor 1410 for processing; in addition, the RF unit 1401 can send uplink data to the network function.
  • the RF unit 1401 includes but is not limited to an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.
  • the memory 1409 can be used to store software programs or instructions and various data.
  • the memory 1409 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.), etc.
  • the memory 1409 may include a volatile memory or a non-volatile memory, or the memory 1409 may include both volatile and non-volatile memories.
  • the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
  • the volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM).
  • the memory 1409 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
  • the processor 1410 may include one or more processing units; optionally, the processor 1410 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 1410.
  • the radio frequency unit 1401 is used to send a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization;
  • the radio frequency unit 1401 is further used to: receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • the processor 1410 is used to: interact with the network side to establish a protocol data unit PDU session.
  • the first non-access layer NAS message is a PDU session modification request.
  • the first indication information includes at least one of the following:
  • the radio frequency unit 1401 sends a first non-access layer NAS message and/or first indication information to the network side, specifically used for:
  • the first non-access layer NAS message and/or the first indication information is sent to the network side.
  • the radio frequency unit 1401 when or after the connection is established between the first terminal and the first device, the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side, specifically for:
  • the first message is used to indicate at least one of the following:
  • the sixth message is used to instruct the first terminal or the first device to communicate with the second network function
  • the second network function is used to perform the first operation.
  • the first indication information includes at least one of the following:
  • the radio frequency unit 1401 after the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side, it is further configured to:
  • the processor 1410 is further configured to: perform at least one of the following according to the second indication information:
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • processor 1410 is further configured to:
  • the first message is used to indicate at least one of the following:
  • Establish a connection between the first device and the first terminal access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
  • the radio frequency unit 1401 receives the second indication information sent by the network side, specifically configured to:
  • a second NAS message sent by the network side is received, wherein the second NAS message carries the second indication information.
  • the second indication information satisfies at least one of the following:
  • the result of the first operation is indicated by a cause value.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the radio frequency unit 1401 is further configured to perform at least one of the following:
  • the second message and the third message are respectively messages involved in executing the first operation.
  • the second message is an Extensible Authentication Protocol (EAP) message
  • the third message is an EAP message.
  • EAP Extensible Authentication Protocol
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
  • the radio frequency unit 1401 is further used to: receive rule information sent by the network side;
  • the radio frequency unit 1401 sends a first non-access layer NAS message and/or a first indication information to the network side, specifically used for:
  • the first non-access layer NAS message and/or the first indication information are sent to the network side.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation.
  • the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side according to the rule information, specifically configured to perform at least one of the following:
  • the first non-access stratum NAS message and/or the first indication information are related to the target PIN;
  • connection between the first terminal and the first device is associated with the target PIN
  • the first message sent by the first device and received by the first terminal is related to the target PIN;
  • the first device being associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the radio frequency unit 1401 is further configured to:
  • the first terminal receives configuration information sent by the second terminal;
  • the radio frequency unit 1401 sends a first non-access layer NAS message and/or first indication information to the network side, specifically used for:
  • the first non-access stratum NAS message and/or the first indication information are sent to the network side.
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation.
  • the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information, specifically configured to perform at least one of the following:
  • the first non-access stratum NAS message and/or the first indication information are related to the target PIN;
  • connection between the first terminal and the first device is associated with the target PIN
  • the first message sent by the first device and received by the first terminal is related to the target PIN;
  • the first device being associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the radio frequency unit 1401 is further used to: send information of the first device to the network side when the second indication information indicates that the first operation is successful.
  • the first terminal is a terminal with gateway capability.
  • the radio frequency unit 1401 is used to send configuration information to the first terminal in the personal Internet of Things PIN.
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  • the network function 1500 includes: an antenna 151, a radio frequency device 152, a baseband device 153, a processor 154, and a memory 155.
  • the antenna 151 is connected to the radio frequency device 152.
  • the radio frequency device 152 receives information through the antenna 151 and sends the received information to the baseband device 153 for processing.
  • the baseband device 153 processes the information to be sent and sends it to the radio frequency device 152.
  • the radio frequency device 152 processes the received information and sends it out through the antenna 151.
  • the method for executing the network function in the above embodiment may be implemented in the baseband device 153, which includes a baseband processor.
  • the baseband device 153 may include, for example, at least one baseband board, on which a plurality of chips are arranged, as shown in FIG15 , wherein one of the chips is, for example, a baseband processor, which is connected to the memory 155 through a bus interface to call a program in the memory 155 and execute the network function operations shown in the above method embodiment.
  • the network function may also include a network interface 156, which may be, for example, a common public radio interface (CPRI).
  • a network interface 156 which may be, for example, a common public radio interface (CPRI).
  • CPRI common public radio interface
  • the network function 1500 of the embodiment of the present invention further includes: instructions or programs stored in the memory 155 and executable on the processor 154, and the processor 154 calls the instructions or programs in the memory 155 to execute the method shown in FIG.
  • the same technical effect is achieved by the method, so it will not be described here to avoid repetition.
  • the embodiment of the present application also provides a network function.
  • the network function 1600 includes: a processor 1601, a network interface 1602, and a memory 1603.
  • the network interface 1602 is, for example, a common public radio interface (CPRI).
  • CPRI common public radio interface
  • the network function 1600 of the embodiment of the present invention also includes: instructions or programs stored in the memory 1603 and executable on the processor 1601.
  • the processor 1601 calls the instructions or programs in the memory 1603 to execute the method shown in Figure 3 or Figure 4 or Figure 6, and achieves the same technical effect. To avoid repetition, it will not be repeated here.
  • An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored.
  • a program or instruction is stored.
  • each process of the above-mentioned operation execution method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
  • the processor is the processor in the terminal described in the above embodiment.
  • the readable storage medium may be non-volatile or non-transient.
  • the readable storage medium may include a computer-readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.
  • An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the operation execution method embodiment described in any one of the first to fifth aspects above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
  • An embodiment of the present application further provides a computer program/program product, which is stored in a storage medium.
  • the computer program/program product is executed by at least one processor to implement the various processes of the operation execution method embodiment described in any one of the first to fifth aspects above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • An embodiment of the present application also provides an operation execution system, including: a terminal and a network function, wherein the terminal can be used to execute the steps of the operation execution method described in the first aspect or the fourth aspect above, and the network function can be used to execute the steps of the operation execution method described in the second aspect or the third aspect or the fifth aspect above.
  • the technical solution of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM/RAM, magnetic disk, optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, computer, server, air conditioner, or network function, etc.) to execute the methods described in each embodiment of the present application.
  • a storage medium such as ROM/RAM, magnetic disk, optical disk
  • a terminal which can be a mobile phone, computer, server, air conditioner, or network function, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

The present application belongs to the technical field of communication. Disclosed are an operation execution method and apparatus, a terminal and a network function. The operation execution method in the embodiments of the present application comprises at least one of the following: a first terminal sending a first non-access stratum (NAS) message and/or first indication information to a network side, wherein the first NAS message is used for indicating a first operation, the first indication information is used for indicating the first operation, and the first operation comprises at least one of authentication, certification and authorization; and the first terminal receiving fifth indication information, which is sent by the network side, wherein the fifth indication information is used for indicating at least one of the following: allowing or not allowing the first operation, allowing or not allowing the first operation to be executed by means of a control plane of the network side, and allowing or not allowing the first operation to be executed by means of a user plane of the network side.

Description

操作执行方法、装置、终端及网络功能Operation execution method, device, terminal and network function
相关申请的交叉引用CROSS-REFERENCE TO RELATED APPLICATIONS
本申请要求在2022年11月4日提交中国专利局、申请号为202211395204.0、名称为“操作执行方法、装置、终端及网络功能”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims priority to a Chinese patent application filed with the Chinese Patent Office on November 4, 2022, with application number 202211395204.0 and title “Operation Execution Method, Device, Terminal and Network Function”, the entire contents of which are incorporated by reference in this application.
技术领域Technical Field
本申请属于通信技术领域,具体涉及一种操作执行方法、装置、终端及网络功能。The present application belongs to the field of communication technology, and specifically relates to an operation execution method, device, terminal and network function.
背景技术Background technique
物联网是在计算机互联网的基础上,利用传感器网络、射频识别技术、无线数据通信等技术,构造一个覆盖多种设备的网络。在这个网络中,设备之间可以相互通信。其实质是利用射频自动识别(RFID)技术,通过无线数据链路、计算机互联网实现设备的互相通信。The Internet of Things is a network covering multiple devices based on the computer Internet, using sensor networks, radio frequency identification technology, wireless data communication and other technologies. In this network, devices can communicate with each other. Its essence is to use radio frequency automatic identification (RFID) technology to achieve mutual communication between devices through wireless data links and computer Internet.
其中,随着技术的发展,在物联网的基础上逐渐出现了个人物联网(Personal IoT Network,PIN),即通过以终端为中心构建个域网络,推动终端与运营商网络高度融合,促进终端与物联网设备之间的良好协同,提升用户整体操作体验和使用质量。其中,物联网设备一般指用于某些特定的场景或特定的服务的终端设备,例如,智能家居设备、智能公用设施、电子健康和智能可穿戴设备等。Among them, with the development of technology, the Personal Internet of Things (PIN) has gradually emerged on the basis of the Internet of Things, that is, by building a personal domain network centered on the terminal, promoting the high integration of the terminal and the operator network, promoting the good coordination between the terminal and the Internet of Things devices, and improving the overall user experience and quality of use. Among them, the Internet of Things device generally refers to the terminal device used in certain specific scenarios or specific services, such as smart home devices, smart utilities, e-health and smart wearable devices.
然而,目前对于PIN中的设备还未明确相应的认证相关操作方法,从而降低了这些设备访问PIN的安全性。However, currently there is no clear corresponding authentication-related operation method for the devices in the PIN, which reduces the security of these devices accessing the PIN.
发明内容Summary of the invention
本申请实施例提供一种操作执行方法、装置、终端及网络功能,以实现对PIN中的设备的认证相关操作,从而提升访问PIN的安全性。The embodiments of the present application provide an operation execution method, apparatus, terminal, and network function to implement authentication-related operations on a device in a PIN, thereby improving the security of accessing the PIN.
第一方面,提供了一种操作执行方法,包括:In a first aspect, an operation execution method is provided, comprising:
第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;The first terminal sends a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
所述第一终端接收所述网络侧发送的第五指示信息,其中,所述第五指示信息用于指示以下至少一项:The first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the network side;
允许或不允许通过所述网络侧的用户面执行所述第一操作。Allow or not allow the first operation to be performed through the user plane of the network side.
第二方面,提供了一种操作执行方法,包括:In a second aspect, an operation execution method is provided, comprising:
第一网络功能向第一终端发送第五指示信息;The first network function sends fifth indication information to the first terminal;
和/或, and / or,
所述第一网络功能接收所述第一终端发送的第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示所述第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;The first network function receives a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
所述第一网络功能响应于所述第一非接入层NAS消息和/或所述第一指示信息,执行如下至少一项:In response to the first non-access stratum NAS message and/or the first indication information, the first network function performs at least one of the following:
向所述第一终端发送第五指示信息;Sending fifth indication information to the first terminal;
指示第二网络功能和所述第一终端进行所述第一操作;instructing a second network function and the first terminal to perform the first operation;
其中,所述第五指示信息用于指示以下至少一项:The fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述第一网络功能所在的移动网络的控制面执行所述第一操作;allowing or not allowing execution of the first operation through a control plane of the mobile network where the first network function is located;
允许或不允许通过所述第一网络功能所在的移动网络的用户面执行所述第一操作。Allow or not allow the first operation to be performed through a user plane of a mobile network where the first network function is located.
第三方面,提供了一种操作执行方法,包括:In a third aspect, an operation execution method is provided, including:
第三网络功能执行第二操作;The third network function performs a second operation;
其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
所述第三网络功能向第一终端发送规则信息;The third network function sends rule information to the first terminal;
所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
第四方面,提供了一种操作执行方法,包括:In a fourth aspect, an operation execution method is provided, comprising:
第二终端向个人物联网PIN中的第一终端发送配置信息。The second terminal sends configuration information to the first terminal in the personal Internet of Things PIN.
第五方面,提供了一种操作执行方法,包括:In a fifth aspect, an operation execution method is provided, including:
第五网络功能向第三网络功能发送第四指示信息,其中,所述第四指示信息用于指示所述第三网络功能执行第二操作;The fifth network function sends fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
所述第三网络功能向第一终端发送规则信息;The third network function sends rule information to the first terminal;
所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
第六方面,提供了一种操作执行装置,包括:In a sixth aspect, an operation execution device is provided, including:
第一发送模块,用于向网络侧发送第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;A first sending module, configured to send a first non-access stratum NAS message and/or first indication information to a network side, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
第一接收模块,用于接收所述网络侧发送的第五指示信息,其中,所述第五指示信息用于指示以下至少一项:The first receiving module is configured to receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane on the network side;
允许或不允许通过所述网络侧的用户面执行所述第一操作。Allow or not allow the first operation to be performed through the user plane of the network side.
第七方面,提供了一种操作执行装置,包括:In a seventh aspect, an operation execution device is provided, including:
第二发送模块,用于向第一终端发送第五指示信息; A second sending module, used to send fifth indication information to the first terminal;
和/或,and / or,
第二接收模块,用于接收所述第一终端发送的第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示所述第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;A second receiving module, configured to receive a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
第一处理模块,用于响应于所述第一非接入层NAS消息和/或所述第一指示信息,执行如下至少一项:A first processing module is configured to, in response to the first non-access layer NAS message and/or the first indication information, perform at least one of the following:
向所述第一终端发送第五指示信息;Sending fifth indication information to the first terminal;
指示第二网络功能和所述第一终端进行所述第一操作;instructing a second network function and the first terminal to perform the first operation;
其中,所述第五指示信息用于指示以下至少一项:The fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过移动网络的控制面执行所述第一操作;allowing or not allowing the first operation to be performed through a control plane of the mobile network;
允许或不允许通过移动网络的用户面执行所述第一操作。The first operation is allowed or not allowed to be performed through a user plane of the mobile network.
第八方面,提供了一种操作执行装置,包括:In an eighth aspect, an operation execution device is provided, including:
第二处理模块,用于执行第二操作;A second processing module, used for performing a second operation;
其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
向第一终端发送个人物联网PIN的规则信息;Sending rule information of the personal Internet of Things PIN to the first terminal;
向第一网络功能发送数据协议单元PDU会话配置信息。Send data protocol unit PDU session configuration information to the first network function.
第九方面,提供了一种操作执行装置,包括:In a ninth aspect, an operation execution device is provided, comprising:
第三发送模块,用于向个人物联网PIN中的第一终端发送配置信息。The third sending module is used to send configuration information to the first terminal in the personal Internet of Things PIN.
第十方面,提供了一种操作执行装置,包括:In a tenth aspect, an operation execution device is provided, comprising:
第四发送模块,用于向第三网络功能发送第四指示信息,其中,所述第四指示信息用于指示所述第三网络功能执行第二操作;a fourth sending module, configured to send fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform a second operation;
其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
所述第三网络功能向第一终端发送规则信息;The third network function sends rule information to the first terminal;
所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
第十一方面,提供了一种终端,该终端包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面或第四方面所述的方法的步骤。In the eleventh aspect, a terminal is provided, which includes a processor and a memory, wherein the memory stores a program or instruction that can be executed on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the first aspect or the fourth aspect are implemented.
第十二方面,提供了一种网络功能,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第二方面或第三方面或第五方面所述的方法的步骤。In the twelfth aspect, a network function is provided, including a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the second aspect, the third aspect, or the fifth aspect are implemented.
第十三方面,提供了一种操作执行系统,包括:第一终端、第二终端、第一网络功能、第二网络功能、第三网络功能、第四网络功能和第五网络功能中的至少两者,所述第一终端可用于执行如上述第一方面所述的操作执行方法的步骤,所述第二终端可用于执行如上述第四方面所述的操作执行方法的步骤,所述第一网络功能可用于执行如上述 第二方面所述的操作执行方法的步骤,所述第三网络功能可用于执行如上述第三方面所述的操作执行方法的步骤,所述第五网络功能可用于执行如上述第五方面所述的操作执行方法的步骤,所述第二网络功能和所述第五网络功能可用于配合所述第一终端、第二终端、第一网络功能、第三网络功能和第五网络功能中的至少一者执行如权利要求1-46任一项所述的操作执行方法的步骤。In a thirteenth aspect, an operation execution system is provided, including: a first terminal, a second terminal, a first network function, a second network function, a third network function, a fourth network function, and at least two of a fifth network function, wherein the first terminal can be used to execute the steps of the operation execution method as described in the first aspect above, the second terminal can be used to execute the steps of the operation execution method as described in the fourth aspect above, and the first network function can be used to execute the steps of the operation execution method as described in the fourth aspect above. The steps of the operation execution method described in the second aspect, the third network function can be used to execute the steps of the operation execution method described in the third aspect, the fifth network function can be used to execute the steps of the operation execution method described in the fifth aspect, and the second network function and the fifth network function can be used to cooperate with at least one of the first terminal, the second terminal, the first network function, the third network function and the fifth network function to execute the steps of the operation execution method described in any one of claims 1-46.
第十四方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面或第二方面或第三方面或第四方面或第五方面所述的方法的步骤。In the fourteenth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect are implemented.
第十五方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面或第二方面或第三方面或第四方面或第五方面所述的方法。In the fifteenth aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.
第十六方面,提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现如第一方面或第二方面或第三方面或第四方面或第五方面所述的方法的步骤。In the sixteenth aspect, a computer program/program product is provided, wherein the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement the steps of the method described in the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect.
第十七方面,本申请实施例提供了一种操作执行确定装置,所述装置用于执行如第一方面或第二方面或第三方面或第四方面或第五方面所述的操作执行方法的步骤。In the seventeenth aspect, an embodiment of the present application provides an operation execution determination device, which is used to execute the steps of the operation execution method described in the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect.
在本申请实施例中,第一终端能够向网络侧发送第一非接入层NAS消息和/或第一指示信息,其中,第一非接入层NAS消息用于指示第一操作,第一指示信息用于指示第一操作,第一操作包括鉴权、认证、授权中的至少一项;和/或,第一终端接收网络侧发送的第五指示信息,其中,第五指示信息用于指示以下至少一项:In an embodiment of the present application, the first terminal can send a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization; and/or the first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the network side;
允许或不允许通过所述网络侧的用户面执行所述第一操作。Allow or not allow the first operation to be performed through the user plane of the network side.
由此可见,第一终端可以通过发送第一非接入层NAS消息来指示网络侧执行鉴权、认证、授权中的至少一项操作,或通过发送第一指示信息指示网络侧执行鉴权、认证、授权中的至少一项操作,或者,通过发送第一NAS消息和第一指示信息指示网络侧执行鉴权、认证、授权中的至少一项操作;还可以接收网络侧发送的上述第五指示信息。因此,可以采用本申请实施例的操作执行方法,对PIN中的设备进行鉴权、认证、授权中的至少一项,即本申请明确了PIN中的鉴权、认证、授权的操作,从而提升访问PIN的安全性。It can be seen that the first terminal can instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, authentication, and authorization operations on the device in the PIN, that is, the present application clarifies the authentication, authentication, and authorization operations in the PIN, thereby improving the security of accessing the PIN.
附图说明BRIEF DESCRIPTION OF THE DRAWINGS
图1是本申请实施例可应用的一种无线通信系统的框图;FIG1 is a block diagram of a wireless communication system to which an embodiment of the present application can be applied;
图2是本申请实施例中的一种操作执行方法的流程图;FIG2 is a flow chart of an operation execution method in an embodiment of the present application;
图3是本申请实施例中的另一种操作执行方法的流程图;FIG3 is a flow chart of another operation execution method in an embodiment of the present application;
图4是本申请实施例中的另一种操作执行方法的流程图; FIG4 is a flow chart of another operation execution method in an embodiment of the present application;
图5是本申请实施例中的另一种操作执行方法的流程图;FIG5 is a flow chart of another operation execution method in an embodiment of the present application;
图6是本申请实施例中的另一种操作执行方法的流程图;FIG6 is a flow chart of another operation execution method in an embodiment of the present application;
图7是本申请实施例的操作执行方法的实施方式一的流程图;FIG7 is a flowchart of implementation mode 1 of the operation execution method of the embodiment of the present application;
图8是本申请实施例的操作执行方法的实施方式二的流程图;FIG8 is a flow chart of implementation mode 2 of the operation execution method of an embodiment of the present application;
图9是本申请实施例中的一种操作执行装置的流程图;FIG9 is a flow chart of an operation execution device in an embodiment of the present application;
图10是本申请实施例中的另一种操作执行装置的流程图;FIG10 is a flow chart of another operation execution device in an embodiment of the present application;
图11是本申请实施例中的另一种操作执行装置的流程图;FIG11 is a flow chart of another operation execution device in an embodiment of the present application;
图12是本申请实施例中的另一种操作执行装置的流程图;FIG12 is a flow chart of another operation execution device in an embodiment of the present application;
图13是本申请实施例中的另一种操作执行装置的流程图;FIG13 is a flow chart of another operation execution device in an embodiment of the present application;
图14是本申请实施例中的一种通信设备的结构框图;FIG14 is a block diagram of a communication device in an embodiment of the present application;
图15是本申请实施例中的一种终端的结构框图;FIG15 is a block diagram of a terminal in an embodiment of the present application;
图16是本申请实施例中的一种网络功能的结构框图;FIG16 is a structural block diagram of a network function in an embodiment of the present application;
图17是本申请实施例中的另一种网络功能的结构框图。FIG. 17 is a structural block diagram of another network function in an embodiment of the present application.
具体实施例Specific embodiments
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。The following will be combined with the drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field belong to the scope of protection of this application.
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”一般表示前后关联对象是一种“或”的关系。The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first" and "second" are generally of the same type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and/or" in the specification and claims represents at least one of the connected objects, and the character "/" generally represents that the objects associated with each other are in an "or" relationship.
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency Division Multiple Access,SC-FDMA)和其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统应用以外的应用,如第6代(6th Generation,6G)通信系统。It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE)/LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA) and other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used for the above-mentioned systems and radio technologies as well as other systems and radio technologies. The following description describes a new radio (NR) system for example purposes, and NR terms are used in most of the following descriptions, but these technologies can also be applied to applications other than NR system applications, such as the 6th Generation (6G) communication system.
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络功能12。其中,终端11可以是手机、平板电脑(Tablet Personal Computer)、 膝上型电脑(Laptop Computer)或称为笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(ultra-mobile personal computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(augmented reality,AR)/虚拟现实(virtual reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、车载设备(VUE)、行人终端(PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(personal computer,PC)、柜员机或者自助机等终端侧设备,可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络功能12可以包括接入网设备或核心网设备,其中,接入网设备12也可以称为无线接入网设备、无线接入网(Radio Access Network,RAN)、无线接入网功能或无线接入网单元。接入网设备12可以包括基站、WLAN接入点或WiFi节点等,基站可被称为节点B、演进节点B(eNB)、接入点、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点、家用演进型B节点、发送接收点(Transmitting Receiving Point,TRP)或所述领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。FIG1 shows a block diagram of a wireless communication system applicable to the embodiment of the present application. The wireless communication system includes a terminal 11 and a network function 12. The terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), Laptop Computer (also called notebook computer), Personal Digital Assistant (PDA), PDA, netbook, ultra-mobile personal computer (UMPC), mobile Internet Device (MID), augmented reality (AR)/virtual reality (VR) equipment, robot, wearable device (Wearable Device), vehicle-mounted equipment (VUE), pedestrian terminal (PUE), smart home (home equipment with wireless communication function, such as refrigerator, TV, washing machine or furniture, etc.), game console, personal computer (personal computer, PC), teller machine or self-service machine and other terminal side equipment, wearable device includes: smart watch, smart bracelet, smart headset, smart glasses, smart jewelry (smart bracelet, smart bracelet, smart ring, smart necklace, smart anklet, smart anklet, etc.), smart wristband, smart clothing, etc. It should be noted that the specific type of terminal 11 is not limited in the embodiment of the present application. The network function 12 may include an access network device or a core network device, wherein the access network device 12 may also be referred to as a radio access network device, a radio access network (RAN), a radio access network function or a radio access network unit. The access network device 12 may include a base station, a WLAN access point or a WiFi node, etc. The base station may be referred to as a node B, an evolved node B (eNB), an access point, a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home B node, a home evolved B node, a transmitting and receiving point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to a specific technical vocabulary, it should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
核心网设备可以包含但不限于如下至少一项:核心网节点、核心网功能、移动管理实体(Mobility Management Entity,MME)、接入移动管理功能(Access and Mobility Management Function,AMF)、会话管理功能(Session Management Function,SMF)、用户平面功能(User Plane Function,UPF)、策略控制功能(Policy Control Function,PCF)、策略与计费规则功能单元(Policy and Charging Rules Function,PCRF)、边缘应用服务发现功能(Edge Application Server Discovery Function,EASDF)、统一数据管理(Unified Data Management,UDM),统一数据仓储(Unified Data Repository,UDR)、归属用户服务器(Home Subscriber Server,HSS)、集中式网络配置(Centralized network configuration,CNC)、网络存储功能(Network Repository Function,NRF),网络开放功能(Network Exposure Function,NEF)、本地NEF(Local NEF,或L-NEF)、绑定支持功能(Binding Support Function,BSF)、应用功能(Application Function,AF)等。需要说明的是,在本申请实施例中仅以NR系统中的核心网设备为例进行介绍,并不限定核心网设备的具体类型。The core network equipment may include but is not limited to at least one of the following: core network nodes, core network functions, mobility management entity (Mobility Management Entity, MME), access mobility management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), policy control function (Policy Control Function, PCF), policy and charging rules function unit (Policy and Charging Rules Function, PCRF), edge application service discovery function (Edge Application Server Discovery ... user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user plane function (User Plane Function, UPF), user ion, EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (L-NEF), Binding Support Function (BSF), Application Function (AF), etc. It should be noted that in the embodiments of the present application, only the core network device in the NR system is taken as an example for introduction, and the specific type of the core network device is not limited.
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的操作执行方法进行详细地说明。The following is a detailed description of the operation execution method provided by the embodiments of the present application through some embodiments and their application scenarios in combination with the accompanying drawings.
第一方面,参见图2所示,为本申请实施例所提供的一种操作执行方法的流程图,该方法可以包括以下步骤201和/或步骤202: In the first aspect, referring to FIG. 2 , which is a flowchart of an operation execution method provided in an embodiment of the present application, the method may include the following steps 201 and/or 202:
步骤201:第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息。Step 201: A first terminal sends a first non-access stratum NAS message and/or first indication information to a network side.
这里,第一终端可以向第一网络功能发送第一非接入层NAS消息和/或第一指示信息,其中,第一终端例如可以为具有网关能力的终端,即)网关终端(PIN Element with Gateway Capability,PEGC);第一网络功能例如可以为会话管理功能(Session Management Function,SMF),或接入和移动性管理功能(Access and Mobility Management Function,AMF)。Here, the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function, where the first terminal can be, for example, a terminal with gateway capability, i.e., a gateway terminal (PIN Element with Gateway Capability, PEGC); the first network function can be, for example, a session management function (Session Management Function, SMF) or an access and mobility management function (Access and Mobility Management Function, AMF).
其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作。由此可知,在本申请实施例中,第一终端可以向网络侧(例如上述第一网络功能)发送第一非接入层NAS消息,指示网络侧执行第一操作(即通过一个NAS消息触发网络侧执行第一操作);或者,可以向网络侧发送第一指示信息,指示网络侧执行第一操作(即通过一个指示信息来指示网络侧设备执行第一操作);或者,也可以向网络侧发送第一NAS消息和第一指示信息,指示网络侧执行第一操作(即通过一个NAS消息和一个指示信息来指示网络侧执行第一操作),这里,第一NAS消息和第一指示信息可以是独立的,也可以将第一指示信息携带在第一NAS消息中。Among them, the first non-access layer NAS message is used to indicate the first operation, and the first indication information is used to indicate the first operation. It can be seen that in the embodiment of the present application, the first terminal can send a first non-access layer NAS message to the network side (such as the above-mentioned first network function) to instruct the network side to perform the first operation (that is, trigger the network side to perform the first operation through a NAS message); or, it can send a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side device to perform the first operation through an indication information); or, it can also send a first NAS message and a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side to perform the first operation through a NAS message and an indication information), here, the first NAS message and the first indication information can be independent, or the first indication information can be carried in the first NAS message.
另外,所述第一操作包括以下至少之一:In addition, the first operation includes at least one of the following:
鉴权(authentication)、认证(authentication)、授权(authorization)。Authentication, authentication, and authorization.
步骤202:所述第一终端接收所述网络侧发送的第五指示信息。Step 202: The first terminal receives fifth indication information sent by the network side.
其中,所述第五指示信息用于指示以下至少一项:The fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the network side;
允许或不允许通过所述网络侧的用户面执行所述第一操作。Allow or not allow the first operation to be performed through the user plane of the network side.
可选地,上述步骤201或202之前,所述方法还包括:Optionally, before step 201 or 202, the method further includes:
所述第一终端与所述网络侧交互以建立PDU会话;The first terminal interacts with the network side to establish a PDU session;
上述步骤202“所述第一终端接收网络侧发送的第五指示信息”,包括:The above step 202 “the first terminal receives the fifth indication information sent by the network side” includes:
所述第一终端接收所述网络侧发送的PDU会话建立/修改确认消息,所述PDU会话建立/修改确认消息中携带有所述第五指示信息。The first terminal receives a PDU session establishment/modification confirmation message sent by the network side, and the PDU session establishment/modification confirmation message carries the fifth indication information.
即网络侧可以将上述第五指示信息携带在PDU会话确认消息中,发送给第一终端。That is, the network side may carry the fifth indication information in a PDU session confirmation message and send it to the first terminal.
可选地,上述步骤202“所述第一终端接收网络侧发送的第五指示信息”,包括:Optionally, the above step 202 “the first terminal receives fifth indication information sent by the network side” includes:
所述第一终端接收所述网络侧响应于所述第一非接入层NAS消息和/或所述第一指示信息发送的所述第五指示信息。The first terminal receives the fifth indication information sent by the network side in response to the first non-access layer NAS message and/or the first indication information.
由此可知,网络侧可以在接收到第一终端发送的PDU会话建立/修改请求消息后,将第五指示信息携带在PDU会话建立确认/修改确认消息中发送给第一终端,以告知第一终端其是否允许第一操作;也可以在网络侧接收到第一终端发送的第一非接入层NAS消息和/或第一指示信息之后,发送第五指示信息给第一终端,以告知第一终端其是否允许第一操作。 It can be seen from this that after receiving the PDU session establishment/modification request message sent by the first terminal, the network side can carry the fifth indication information in the PDU session establishment confirmation/modification confirmation message and send it to the first terminal to inform the first terminal whether it allows the first operation; or after receiving the first non-access layer NAS message and/or the first indication information sent by the first terminal, the network side can send the fifth indication information to the first terminal to inform the first terminal whether it allows the first operation.
由上述步骤201至202可知,在本申请实施例中,第一终端能够向网络侧发送第一非接入层NAS消息和/或第一指示信息,其中,第一非接入层NAS消息用于指示第一操作,第一指示信息用于指示第一操作,第一操作包括鉴权、认证、授权中的至少一项;和/或,第一终端接收网络侧发送的第五指示信息,其中,第五指示信息用于以下至少一项:It can be known from the above steps 201 to 202 that in an embodiment of the present application, the first terminal can send a first non-access layer NAS message and/or a first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization; and/or, the first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used for at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the network side;
允许或不允许通过所述网络侧的用户面执行所述第一操作。Allow or not allow the first operation to be performed through the user plane of the network side.
由此可见,第一终端可以通过发送第一非接入层NAS消息来指示网络侧执行鉴权、认证、授权中的至少一项操作,或通过发送第一指示信息指示网络侧执行鉴权、认证、授权中的至少一项操作,或者,通过发送第一NAS消息和第一指示信息指示网络侧执行鉴权、认证、授权中的至少一项操作;还可以接收网络侧发送的上述第五指示信息。因此,可以采用本申请实施例的操作执行方法,对PIN中的设备进行鉴权、认证、授权中的至少一项,从而提升访问PIN的安全性。It can be seen that the first terminal can instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, certification, and authorization operations on the device in the PIN, thereby improving the security of accessing the PIN.
需要说明的是,上述第一终端还可以满足如下的情况一或情况二:It should be noted that the first terminal may also meet the following conditions 1 or 2:
情况一:第一终端还可以具有个人物联网设备(PIN Element,PINE)的功能,以及网关能力,亦即PEGC和PINE可以合并为一个设备。Case 1: The first terminal can also have the function of a personal Internet of Things device (PIN Element, PINE) and gateway capabilities, that is, PEGC and PINE can be combined into one device.
情况二:第一终端也可以不具备PINE的能力,例如第一终端只具备网关能力,亦即PEGC与PINE独立设置。Case 2: The first terminal may not have the PINE capability. For example, the first terminal only has the gateway capability, that is, PEGC and PINE are independently configured.
可选地,在上述情况一中,在上述步骤201“所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息之前”,所述方法还包括:Optionally, in the above situation 1, before the above step 201 "the first terminal sends a first non-access layer NAS message and/or first indication information to the network side", the method further includes:
所述第一终端与所述网络侧交互以建立协议数据单元PDU会话。The first terminal interacts with the network side to establish a protocol data unit (PDU) session.
即PEGC与PINE合并设置而成的第一终端,在向网络侧发送第一非接入层NAS消息和/或第一指示信息之前,还可以与网络侧建立PDU会话。That is, the first terminal formed by combining PEGC and PINE can also establish a PDU session with the network side before sending the first non-access layer NAS message and/or the first indication information to the network side.
其中,第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息之前,若建立PDU会话,则后续第一终端可以利用后续PDU会话的修改流程来向网络侧发送第一非接入层NAS消息。Among them, before the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, if a PDU session is established, the first terminal can subsequently use the modification process of the subsequent PDU session to send the first non-access layer NAS message to the network side.
可选地,所述第一非接入层NAS消息为PDU会话修改请求。即在前述情况一中,第一终端可以将PDU修改请求作为第一NAS消息,发送给网络侧,以触发网络侧执行第一操作。Optionally, the first non-access layer NAS message is a PDU session modification request. That is, in the aforementioned situation 1, the first terminal can send the PDU modification request as the first NAS message to the network side to trigger the network side to perform the first operation.
可选地,所述第一指示信息包括如下A-1项至A-3中至少一项:Optionally, the first indication information includes at least one of the following items A-1 to A-3:
A-1项:用于指示进行所述第一操作的指示;Item A-1: an instruction for instructing to perform the first operation;
A-2项:所述第一终端的信息;Item A-2: information of the first terminal;
A-3项:第二网络功能的信息,其中,所述第二网络功能用于执行所述第一操作。Item A-3: Information about a second network function, wherein the second network function is used to perform the first operation.
其中,第一终端的信息可以包括标识、IP地址、MAC地址中的至少一项。 The information of the first terminal may include at least one of an identifier, an IP address, and a MAC address.
上述A-1项表示第一终端可以显示指示网络侧进行第一操作;The above-mentioned item A-1 indicates that the first terminal can display and instruct the network side to perform the first operation;
上述A-2项,表示第一终端可以通过第一终端的信息隐式指示网络侧进行第一操作。The above item A-2 indicates that the first terminal can implicitly instruct the network side to perform the first operation through the information of the first terminal.
例如,当网络侧接收到第一终端发送的第一指示信息包括上述用于指示进行第一操作的指示时,则可以根据该显示指示内容确定需要对第一终端进行第一操作;当网络侧接收到第一终端发送的第一指示信息包括上述第一终端的信息时,也可以通过该隐式指示内容确定需要对第一终端进行第一操作。For example, when the network side receives the first indication information sent by the first terminal including the above-mentioned indication for instructing to perform the first operation, it can determine that the first operation needs to be performed on the first terminal based on the displayed indication content; when the network side receives the first indication information sent by the first terminal including the above-mentioned information of the first terminal, it can also determine that the first operation needs to be performed on the first terminal through the implicit indication content.
上述A-3项中,第二网络功能例如可以为外部数据网络认证授权中心(AAA),即第一终端还可以告知网络侧由哪个网络功能执行第一操作。In the above item A-3, the second network function may be, for example, an external data network authentication and authorization center (AAA), that is, the first terminal may also inform the network side which network function performs the first operation.
可选地,在前述情况二中,所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,包括:Optionally, in the aforementioned situation 2, the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
在所述第一终端与第一设备之间建立连接之时或之后,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。When or after a connection is established between the first terminal and the first device, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side.
这里,第一设备可以为PINE。Here, the first device may be a PINE.
即可以在第一终端与第一设备之间建立连接之时或之后,由第一终端指示网络侧执行第一操作。That is, when or after the connection is established between the first terminal and the first device, the first terminal may instruct the network side to perform the first operation.
可选地,在所述第一终端与所述第一设备之间建立连接之时或之后,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,包括:Optionally, when or after the connection is established between the first terminal and the first device, the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, including:
所述第一终端接收所述第一设备发送的第一消息,或接收第二终端发送的第六消息;The first terminal receives the first message sent by the first device, or receives the sixth message sent by the second terminal;
所述第一终端响应于所述第一消息或所述第六消息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;The first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side in response to the first message or the sixth message;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的个人物联网PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the personal Internet of Things PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第六消息用于指示所述第一终端或所述第一设备与所述第二网络功能通信;The sixth message is used to instruct the first terminal or the first device to communicate with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
其中,当第一消息用于指示建立第一设备与第一终端之间的连接时,第一消息可以是第一设备发送给第一终端的连接请求,也可以是第一终端给第一设备发送的连接请求。When the first message is used to indicate establishment of a connection between the first device and the first terminal, the first message may be a connection request sent by the first device to the first terminal, or may be a connection request sent by the first terminal to the first device.
由此可知,在第一终端接收到第一设备发送的第一消息时,可以触发第一终端向网络侧设备发送上述第一非接入层NAS消息和/或第一指示信息,以使得网络侧对第一设备执行第一操作;或者,在第一终端接收到第二终端发送的上述第六消息时,可以触发第一终端向网络侧设备发送上述第一非接入层NAS消息和/或第一指示信息,以使得网络侧对第一设备执行第一操作。It can be seen from this that when the first terminal receives the first message sent by the first device, it can trigger the first terminal to send the above-mentioned first non-access layer NAS message and/or first indication information to the network side device, so that the network side performs the first operation on the first device; or, when the first terminal receives the above-mentioned sixth message sent by the second terminal, it can trigger the first terminal to send the above-mentioned first non-access layer NAS message and/or first indication information to the network side device, so that the network side performs the first operation on the first device.
可选地,所述第一非接入层NAS消息为PDU会话修改请求或PDU会话建立请求。即在前述情况二中,第一终端可以将PDU修改请求或PDU会话建立请求作为第一NAS消息,发送给网络侧,以触发网络侧执行第一操作。 Optionally, the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request. That is, in the aforementioned situation 2, the first terminal can send the PDU modification request or the PDU session establishment request as the first NAS message to the network side to trigger the network side to perform the first operation.
可选地,所述第一指示信息包括如下B-1项至B-4项中至少一项:Optionally, the first indication information includes at least one of the following items B-1 to B-4:
B-1项:用于指示进行所述第一操作的指示;Item B-1: an instruction for instructing to perform the first operation;
B-2项:所述第一设备的信息;Item B-2: information about the first device;
B-3项:所述第一终端的信息;Item B-3: information of the first terminal;
B-4项:第二网络功能的信息,其中,所述第二网络功能用于执行所述第一操作。Item B-4: Information about a second network function, wherein the second network function is used to perform the first operation.
其中,第一终端的信息可以包括标识、IP地址、MAC地址中的至少一项;第一设备的信息可以包括标识、IP地址、MAC地址中的至少一项。The information of the first terminal may include at least one of an identifier, an IP address, and a MAC address; the information of the first device may include at least one of an identifier, an IP address, and a MAC address.
上述B-1项表示第一终端可以显示指示网络侧进行第一操作;The above item B-1 indicates that the first terminal can display and instruct the network side to perform the first operation;
上述B-2项,表示第一终端可以通过第一设备的信息隐式指示网络侧进行第一操作;Item B-2 above indicates that the first terminal may implicitly instruct the network side to perform the first operation through information of the first device;
上述B-3项,表示第一终端可以通过第一终端的信息隐式指示网络侧进行第一操作;。The above item B-3 indicates that the first terminal can implicitly instruct the network side to perform the first operation through the information of the first terminal;.
例如,当网络侧接收到第一终端发送的第一指示信息包括上述用于指示进行第一操作的指示时,则可以根据该显示指示内容确定需要对向第一终端发送上述第一消息的设备(即第一设备)进行第一操作;当网络侧接收到第一终端发送的第一指示信息包括上述第一设备的信息时,也可以通过该隐式指示内容确定需要对第一设备进行第一操作;当网络侧接收到第一终端发送的第一指示信息包括上述第一终端的信息时,也可以通过该隐式指示内容确定需要对向第一终端发送上述第一消息的设备(即第一设备)进行第一操作。For example, when the network side receives the first indication information sent by the first terminal including the above-mentioned indication for instructing to perform the first operation, it can be determined based on the displayed indication content that the first operation needs to be performed on the device (i.e., the first device) that sends the above-mentioned first message to the first terminal; when the network side receives the first indication information sent by the first terminal including the information of the above-mentioned first device, it can also be determined through the implicit indication content that the first operation needs to be performed on the first device; when the network side receives the first indication information sent by the first terminal including the information of the above-mentioned first terminal, it can also be determined through the implicit indication content that the first operation needs to be performed on the device (i.e., the first device) that sends the above-mentioned first message to the first terminal.
上述B-4项中,第二网络功能例如可以为外部数据网络认证授权中心(AAA),即第一终端还可以告知网络侧由哪个网络功能执行第一操作。In the above item B-4, the second network function may be, for example, an external data network authentication and authorization center (AAA), that is, the first terminal may also inform the network side which network function performs the first operation.
可选地,在所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息之后,所述方法还包括:Optionally, after the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, the method further includes:
所述第一终端接收所述网络侧发送的第二指示信息,其中,所述第二指示信息用于指示所述第一操作的结果:The first terminal receives second indication information sent by the network side, wherein the second indication information is used to indicate a result of the first operation:
所述第一终端根据所述第二指示信息,执行以下C-1项至C-3项中至少一项:The first terminal performs at least one of the following items C-1 to C-3 according to the second indication information:
C-1项:允许或拒绝所述第一终端接收的第一设备发送的第一消息;Item C-1: allowing or rejecting the first message sent by the first device to be received by the first terminal;
C-2项:允许或拒绝对所述第一设备的数据的处理;Item C-2: Allow or deny processing of data of the first device;
C-3项:允许或保留或释放所述第一终端与所述第一设备的连接;Item C-3: allowing, retaining or releasing the connection between the first terminal and the first device;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
其中,网络侧接收到第一非接入层NAS消息和/或第一指示信息之后,则根据第一非接入层NAS消息和/或第一指示信息的指示,对第一设备执行第一操作,从而向第一终端返回执行第一操作的结果,这样,第一终端则可以根据执行第一操作的结果,执行上述C-1项至C-3项中的至少一项。 Among them, after the network side receives the first non-access layer NAS message and/or the first indication information, it performs the first operation on the first device according to the indication of the first non-access layer NAS message and/or the first indication information, thereby returning the result of executing the first operation to the first terminal. In this way, the first terminal can execute at least one of the above items C-1 to C-3 according to the result of executing the first operation.
可选地,所述方法还包括:Optionally, the method further comprises:
所述第一终端根据所述第五指示信息,执行以下G-1项至G-至少一项:The first terminal executes at least one of the following items G-1 to G- according to the fifth indication information:
G-1项:执行或停止执行所述第一操作;Item G-1: Execute or stop executing the first operation;
G-2项:发送或停止发送第六指示信息给第二网络功能,所述第六指示信息用于指示所述第二网络功能执行所述第一操作;Item G-2: sending or stopping sending sixth indication information to the second network function, where the sixth indication information is used to instruct the second network function to perform the first operation;
G-3项:发送或停止发送第四消息给所述第二网络功能,所述第四消息为执行所述第一操作涉及的消息;Item G-3: sending or stopping sending a fourth message to the second network function, where the fourth message is a message related to performing the first operation;
G-4项:接收或停止接收来自所述第二网络功能的第五消息,所述第五消息为执行所述第一操作涉及的消息;Item G-4: receiving or stopping receiving a fifth message from the second network function, where the fifth message is a message related to performing the first operation;
G-5项:允许或拒绝所述第一终端接收到的第一设备发送的第一消息;Item G-5: allowing or rejecting the first message sent by the first device and received by the first terminal;
G-6项:允许或拒绝对所述第一设备的数据的处理;Item G-6: Allow or deny processing of data on the first device;
G-7项:允许或保留或释放所述第一终端与所述第一设备的连接;Item G-7: allowing, retaining or releasing the connection between the first terminal and the first device;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与所述第二网络功能通信。Establish a connection between the first device and the first terminal, access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
上述G-1项表示:当第五指示信息指示允许第一操作,或允许通过网络侧的控制面执行第一操作,或允许通过网络侧的用户面执行第一操作时,第一终端执行所述第一操作;当第五指示信息不允许第一操作,或不允许通过网络侧的控制面执行第一操作,或不允许通过网络侧的用户面执行第一操作时,第一终端停止执行所述第一操作。The above-mentioned item G-1 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal performs the first operation; when the fifth indication information does not allow the first operation, or does not allow the first operation to be performed through the control plane of the network side, or does not allow the first operation to be performed through the user plane of the network side, the first terminal stops performing the first operation.
上述G-2项表示:当第五指示信息指示允许第一操作或允许通过网络侧的控制面执行第一操作,或允许通过网络侧的用户面执行第一操作时,第一终端发送第六指示信息给第二网络功能;当第五指示信息指示不允许第一操作,或不允许通过网络侧的控制面执行第一操作,或不允许通过网络侧的用户面执行第一操作时,第一终端停止发送第六指示信息给第二网络功能;The above G-2 item indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal sends the sixth indication information to the second network function; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the first terminal stops sending the sixth indication information to the second network function;
上述G-3项表示:当第五指示信息指示允许第一操作,或允许通过网络侧的控制面执行第一操作,或允许通过网络侧的用户面执行第一操作时,第一终端发送第四消息给第二网络功能;当第五指示信息指示不允许第一操作,或不允许通过网络侧的控制面执行第一操作,或不允许通过网络侧的用户面执行第一操作时,第一终端停止发送第四消息给第二网络功能;The above-mentioned item G-3 indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal sends the fourth message to the second network function; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the first terminal stops sending the fourth message to the second network function;
上述G-4项表示:当第五指示信息指示允许第一操作,或允许通过网络侧的控制面执行第一操作,或允许通过网络侧的用户面执行第一操作时,接收来自第二网络功能的第五消息;当第五指示信息指示不允许第一操作,或不允许通过网络侧的控制面执行第一操作,或不允许通过网络侧的用户面执行第一操作时,停止接收来自第二网络功能的第五消息;The above-mentioned item G-4 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the fifth message from the second network function is received; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the fifth message from the second network function is stopped;
上述G-5项表示:当第五指示信息指示允许第一操作,或允许通过网络侧的控制面 执行第一操作,或允许通过网络侧的用户面执行第一操作时,允许第一终端接收到的第一设备发送的第一消息;当第五指示信息指示不允许第一操作,或不允许通过网络侧的控制面执行第一操作,或不允许通过网络侧的用户面执行第一操作时,拒绝第一终端接收到的第一设备发送的第一消息;The above G-5 item indicates: when the fifth indication information indicates that the first operation is allowed, or the control plane on the network side is allowed When performing the first operation or allowing the first operation to be performed through the user plane of the network side, allowing the first message sent by the first device received by the first terminal; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, rejecting the first message sent by the first device received by the first terminal;
上述G-6项表示:当第五指示信息指示允许第一操作,或允许通过网络侧的控制面执行第一操作,或允许通过网络侧的用户面执行第一操作时,允许对第一设备的数据的处理;当第五指示信息指示不允许第一操作,或不允许通过网络侧的控制面执行第一操作,或不允许通过网络侧的用户面执行第一操作时,拒绝对第一设备的数据的处理;The above-mentioned item G-6 indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the processing of the data of the first device is allowed; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the processing of the data of the first device is rejected;
上述G-7项表示:当第五指示信息指示允许第一操作,或允许通过网络侧的控制面执行第一操作,或允许通过网络侧的用户面执行第一操作时,允许或保留第一终端与第一设备的连接;当第五指示信息指示不允许第一操作,或不允许通过网络侧的控制面执行第一操作,或不允许通过网络侧的用户面执行第一操作时,释放第一终端与第一设备的连接。The above-mentioned item G-7 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the connection between the first terminal and the first device is allowed or retained; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the connection between the first terminal and the first device is released.
可选地,所述第一终端接收所述网络侧发送的所述第二指示信息,包括:Optionally, the first terminal receiving the second indication information sent by the network side includes:
所述第一终端接收所述网络侧发送的第二NAS消息,其中,所述第二NAS消息中携带有所述第二指示信息。The first terminal receives a second NAS message sent by the network side, wherein the second NAS message carries the second indication information.
即网络侧可以将用于指示执行第一操作的结果的第二指示信息携带在第二NAS消息中,发送给第一终端。That is, the network side may carry the second indication information used to indicate the result of executing the first operation in the second NAS message, and send the message to the first terminal.
可选地,所述第二指示信息满足以下D-1项至D-2项中至少一项:Optionally, the second indication information satisfies at least one of the following items D-1 to D-2:
D-1项:通过所述第二NAS消息的标识或名称指示所述第一操作的结果;Item D-1: indicating the result of the first operation by an identifier or a name of the second NAS message;
D-1项:通过原因值指示所述第一操作的结果。Item D-1: Indicate the result of the first operation through a cause value.
上述D-1项表示不同的第二NAS消息的标识或名称,指示不同的第一操作的结果。The above item D-1 represents the identifier or name of different second NAS messages, indicating different results of the first operation.
可选地,所述通过所述第二NAS消息的标识或名称指示所述第一操作的结果,包括以下至少一项:Optionally, the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
通过PDU会话修改确认消息或PDU会话建立确认消息指示所述第一操作成功;Indicating that the first operation is successful through a PDU session modification confirmation message or a PDU session establishment confirmation message;
通过PDU会话修改拒绝消息或PDU会话建立拒绝消息指示所述第一操作失败。The failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
即若网络侧发送给第一终端的第二NAS消息是PDU会话修改确认消息或PDU会话建立确认消息,则表示第一操作执行成功;若网络侧发送给第一终端的第二NAS消息是PDU会话修改拒绝消息或PDU会话建立拒绝消息,则表示第一操作执行失败。That is, if the second NAS message sent by the network side to the first terminal is a PDU session modification confirmation message or a PDU session establishment confirmation message, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side to the first terminal is a PDU session modification rejection message or a PDU session establishment rejection message, it indicates that the first operation fails.
即网络侧执行第一操作成功时,向第一终端返回PDU会话修改确认消息或PDU会话建立确认消息;网络侧执行第一操作失败时,向第一终端返回PDU会话修改拒绝消息或PDU会话建立拒绝消息。That is, when the network side successfully executes the first operation, it returns a PDU session modification confirmation message or a PDU session establishment confirmation message to the first terminal; when the network side fails to execute the first operation, it returns a PDU session modification rejection message or a PDU session establishment rejection message to the first terminal.
上述D-2项表示通过原因值显示指示不同的第一操作的结果。The above-mentioned item D-2 indicates that the result of the first operation indicating a difference is displayed by the cause value.
可选地,所述通过原因值指示所述第一操作的结果,包括以下至少一项指示:Optionally, the result of the first operation indicated by the reason value includes at least one of the following indications:
失败原因值和/或失败指示,用于指示所述第一操作失败; a failure reason value and/or a failure indication, used to indicate that the first operation failed;
成功原因值和/或成功指示,用于指示所述第一操作成功;A success reason value and/or a success indication, used to indicate that the first operation is successful;
在所述第二NAS消息中未包括所述失败原因值和/或失败指示的情况下,指示所述第一操作成功;In a case where the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful;
在所述第二NAS消息中未包括所述成功原因值和/或成功指示的情况下,指示所述第一操作失败。In a case where the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
即若网络侧发送的第二NAS消息中包括失败原因值和/或失败指示,则表示第一操作执行失败;若网络侧发送的第二NAS消息中未包括失败原因值和/或失败指示,表示第一操作执行成功。That is, if the second NAS message sent by the network side includes a failure cause value and/or a failure indication, it indicates that the first operation has failed; if the second NAS message sent by the network side does not include a failure cause value and/or a failure indication, it indicates that the first operation has been successfully executed.
或者,若网络侧发送的第二NAS消息中包括成功原因值和/或成功指示,则表示第一操作执行成功;若网络侧发送的第二NAS消息中未包括成功原因值和/或成功指示,表示第一操作执行失败。Alternatively, if the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side does not include a success reason value and/or a success indication, it indicates that the first operation fails.
或者,若网络侧发送的第二NAS消息中包括失败原因值和/或失败指示,则表示第一操作执行失败;若网络侧发送的第二NAS消息中包括成功原因值和/或成功指示,则表示第一操作执行成功。Alternatively, if the second NAS message sent by the network side includes a failure reason value and/or a failure indication, it indicates that the first operation has failed to execute; if the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation has been executed successfully.
可选地,所述方法还包括如下中至少一项:Optionally, the method further comprises at least one of the following:
所述第一终端接收来自所述网络侧的第二消息,将所述第二消息发送给所述第一设备;The first terminal receives a second message from the network side, and sends the second message to the first device;
所述第一终端接收来自所述第一设备的第三消息,将所述第三消息发送给所述网络侧;The first terminal receives a third message from the first device, and sends the third message to the network side;
其中,所述第二消息和所述第三消息分别为执行所述第一操作涉及的消息,即第二消息和第三消息分别为执行第一操作时,第一设备与网络侧需要交互的消息。The second message and the third message are messages involved in executing the first operation, that is, the second message and the third message are messages that the first device and the network side need to interact with when executing the first operation.
由此可知,在网络侧执行第一操作的过程中,第一终端还可以为第一设备和网络侧转发交互消息。It can be seen from this that, during the process of executing the first operation on the network side, the first terminal can also forward interaction messages for the first device and the network side.
例如若在执行第一过程中,网络侧需要请求第一设备的标识信息,则网络侧可以向第一终端发送用于请求第一设备的标识信息的第二消息,从而使得第一终端将第二消息发送给第一设备,进而使得第一设备向第一终端返回携带第一设备的标识信息的第三消息,并由第一终端将该第三消息返回给网络侧。For example, if during the execution of the first process, the network side needs to request the identification information of the first device, the network side may send a second message to the first terminal for requesting the identification information of the first device, so that the first terminal sends the second message to the first device, and the first device returns a third message carrying the identification information of the first device to the first terminal, and the first terminal returns the third message to the network side.
可选地,所述第二消息为可扩展认证协议(Extensible authentication protocol,EAP)消息,所述第三消息为EAP消息。Optionally, the second message is an extensible authentication protocol (EAP) message, and the third message is an EAP message.
此外,上述步骤201的具体实现方式可如下方式一、方式二或方式三所述:In addition, the specific implementation of the above step 201 can be as described in the following method 1, method 2 or method 3:
方式一:可选地,所述方法还包括:Mode 1: Optionally, the method further includes:
所述第一终端接收所述网络侧发送的规则信息;The first terminal receives the rule information sent by the network side;
所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,包括:The first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
所述第一终端根据所述规则信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。 The first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information.
由此可知,第一终端可以根据网络侧(即第三网络功能,例如策略控制功能实体(Policy Control Function,PCF))发送的规则信息,来发送第一非接入层NAS消息和/或第一指示信息。It can be seen from this that the first terminal can send the first non-access layer NAS message and/or the first indication information according to the rule information sent by the network side (i.e., the third network function, such as the policy control function entity (Policy Control Function, PCF)).
可选地,所述规则信息用于指示以下E-1项至E-2项中至少一项:Optionally, the rule information is used to indicate at least one of the following items E-1 to E-2:
E-1项:所述第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;Item E-1: the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
E-2项:至少一个第一目标设备需要所述第一操作或不需要所述第一操作。Item E-2: At least one first target device requires the first operation or does not require the first operation.
其中,目标PIN为第二终端创建的其中一个PIN;所述第一目标设备为需要通过所述第一终端访问个人物联网PIN或所述第三网络功能所在移动网络的设备。Among them, the target PIN is one of the PINs created by the second terminal; the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
上述E-1项表示规则信息可以针对PIN来指示是否需要执行第一操作,即以PIN为粒度指示是否需要执行第一操作。The above item E-1 indicates that the rule information can indicate whether the first operation needs to be performed for the PIN, that is, whether the first operation needs to be performed is indicated with the PIN as the granularity.
上述E-2项表示规则信息也可以针对各个PINE来指示是否需要执行第一操作,即以PINE为粒度指示是否需要执行第一操作。The above-mentioned item E-2 indicates that the rule information may also indicate whether the first operation needs to be performed for each PINE, that is, indicating whether the first operation needs to be performed with PINE as the granularity.
其中,第二终端(例如管理终端(PIN Element with Management Capability,PEMC))创建一个PIN后,可以通知第五网络功能(例如应用功能(Application Function,AF))其创建了一个PIN,并指示第一操作是否需要应用于该PIN和/或指示一个PINE是否需要第一操作,从而由第五网络功能通知第三网络功能(例如PCF)第一操作是否需要应用于该PIN和/或指示一个PINE是否需要第一操作,从而由第三网络功能生成用于指示上述E-1项和/或E-2项的规则信息。Among them, after the second terminal (for example, the management terminal (PIN Element with Management Capability, PEMC)) creates a PIN, it can notify the fifth network function (for example, the application function (Application Function, AF)) that it has created a PIN, and indicate whether the first operation needs to be applied to the PIN and/or indicate whether a PINE needs the first operation, so that the fifth network function notifies the third network function (for example, PCF) whether the first operation needs to be applied to the PIN and/or indicates whether a PINE needs the first operation, so that the third network function generates rule information for indicating the above-mentioned E-1 items and/or E-2 items.
可选地,所述第一终端根据所述规则信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,包括以下至少一项:Optionally, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information, including at least one of the following:
在所述规则信息指示第一设备需要所述第一操作的情况下,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;When the rule information indicates that the first device needs the first operation, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side;
在所述规则信息指示所述第一操作需要应用于所述目标PIN,且满足以下H-1项至H-4项中至少一项条件的情况下,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息:When the rule information indicates that the first operation needs to be applied to the target PIN and at least one of the following conditions H-1 to H-4 is met, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side:
H-1项:所述第一非接入层NAS消息和/或所述第一指示信息与所述目标PIN相关;Item H-1: the first non-access stratum NAS message and/or the first indication information is related to the target PIN;
H-2项:所述第一终端与第一设备之间的连接与所述目标PIN相关;Item H-2: The connection between the first terminal and the first device is related to the target PIN;
H-3项:所述第一终端接收到的所述第一设备发送的第一消息与所述目标PIN相关;Item H-3: the first message sent by the first device and received by the first terminal is related to the target PIN;
H-4项:所述第一设备与所述目标PIN相关;Item H-4: The first device is associated with the target PIN;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可以理解的是,在所述规则信息指示所述第一操作不需要应用于所述目标PIN,或 所不满足上述H-1至H-4的条件的情况下,所述第一终端不向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;It is understood that, when the rule information indicates that the first operation does not need to be applied to the target PIN, or When the above conditions H-1 to H-4 are not met, the first terminal does not send the first non-access layer NAS message and/or the first indication information to the network side;
在所述规则信息指示所述第一设备不需要所述第一操作的情况下,所述第一终端不向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。When the rule information indicates that the first device does not need the first operation, the first terminal does not send the first non-access stratum NAS message and/or the first indication information to the network side.
方式二,可选地,所述方法还包括:Mode 2: Optionally, the method further includes:
所述第一终端接收第二终端发送的配置信息;The first terminal receives configuration information sent by the second terminal;
所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,包括:The first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
所述第一终端根据所述配置信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。The first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the configuration information.
由此可知,第一终端可以根据第二终端(例如PEMC)发送的配置信息,来发送第一非接入层NAS消息和/或第一指示信息。It can be seen from this that the first terminal can send the first non-access stratum NAS message and/or the first indication information according to the configuration information sent by the second terminal (for example, PEMC).
可选地,所述配置信息用于指示以下F-1项至F-2项中至少一项:Optionally, the configuration information is used to indicate at least one of the following items F-1 to F-2:
F-1项:所述第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;Item F-1: the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
F-2项:至少一个第二目标设备需要所述第一操作或不需要所述第一操作。Item F-2: At least one second target device requires the first operation or does not require the first operation.
其中,目标PIN为第二终端创建的其中一个PIN;所述第二目标设备为需要通过所述第一终端访问所述个人物联网PIN或移动网络的设备。Among them, the target PIN is one of the PINs created by the second terminal; the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
上述F-1项表示配置信息可以针对PIN来指示是否需要执行第一操作,即以PIN为粒度指示是否需要执行第一操作。The above item F-1 indicates that the configuration information can indicate whether the first operation needs to be performed for the PIN, that is, whether the first operation needs to be performed is indicated with the PIN as the granularity.
上述F-2项表示配置信息也可以针对各个PINE来指示是否需要执行第一操作,即以PINE为粒度指示是否需要执行第一操作。The above item F-2 indicates that the configuration information may also indicate whether the first operation needs to be performed for each PINE, that is, indicating whether the first operation needs to be performed with PINE as the granularity.
其中,第二终端可以在创建PIN之后,向第一终端指示“第一操作是否需要应用于该PIN和/或指示一个PINE是否需要第一操作”。After creating the PIN, the second terminal may indicate to the first terminal whether the first operation needs to be applied to the PIN and/or whether a PIN needs the first operation.
可选地,在所述配置信息指示第一设备需要所述第一操作的情况下,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;Optionally, when the configuration information indicates that the first device requires the first operation, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side;
在所述配置信息指示所述第一操作需要应用于所述目标PIN,且满足以下L-1项至L-4项中至少一项条件的情况下,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息:When the configuration information indicates that the first operation needs to be applied to the target PIN and at least one of the following conditions L-1 to L-4 is met, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side:
L-1项:所述第一非接入层NAS消息和/或所述第一指示信息与所述目标PIN相关;Item L-1: the first non-access stratum NAS message and/or the first indication information is related to the target PIN;
L-2项:所述第一终端与第一设备之间的连接与所述目标PIN相关;Item L-2: The connection between the first terminal and the first device is related to the target PIN;
L-3项:所述第一终端接收到的所述第一设备发送的第一消息与所述目标PIN相关;Item L-3: the first message sent by the first device and received by the first terminal is related to the target PIN;
L-4项:所述第一设备与所述目标PIN相关;Item L-4: The first device is associated with the target PIN;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信; Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可以理解的是,在所述配置信息指示所述第一操作不需要应用于所述目标PIN,或所不满足上述L-1至L-4的条件的情况下,所述第一终端不向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;It can be understood that, when the configuration information indicates that the first operation does not need to be applied to the target PIN, or the above conditions L-1 to L-4 are not met, the first terminal does not send the first non-access layer NAS message and/or the first indication information to the network side;
在所述配置信息指示所述第一设备不需要所述第一操作的情况下,所述第一终端不向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。When the configuration information indicates that the first device does not need the first operation, the first terminal does not send the first non-access stratum NAS message and/or the first indication information to the network side.
方式三,可选地,所述方法还包括:Mode three, optionally, the method further includes:
所述第一终端接收所述网络侧发送的PIN的规则信息;The first terminal receives the PIN rule information sent by the network side;
所述第一终端接收第二终端发送的配置信息;The first terminal receives configuration information sent by the second terminal;
所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,包括:The first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
所述第一终端根据所述规则信息和所述配置信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。The first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information and the configuration information.
由此可知,第一终端可以根据网络侧发送的规则信息以及第二终端发送的配置信息,来发送第一非接入层NAS消息和/或第一指示信息。It can be seen from this that the first terminal can send the first non-access stratum NAS message and/or the first indication information according to the rule information sent by the network side and the configuration information sent by the second terminal.
这里规则信息用于指示的内容可参见前述方式一,配置信息用于指示的内容可参见前述方式二。即规则信息和配置信息都可以进行前述所述的PIN粒度的指示,以及PINE粒度的指示。Here, the content indicated by the rule information can refer to the aforementioned method 1, and the content indicated by the configuration information can refer to the aforementioned method 2. That is, both the rule information and the configuration information can perform the aforementioned PIN granularity indication and PINE granularity indication.
可选地,所述第一终端根据所述规则信息和所述配置信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,包括:Optionally, the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side according to the rule information and the configuration information, including:
根据预先确定的规则信息和配置信息中优先级较高的一者,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。According to the predetermined rule information and the configuration information, whichever has a higher priority, the first non-access layer NAS message and/or the first indication information is sent to the network side.
这里,当规则信息和配置信息中优先级较高的一者为规则信息时,根据规则信息向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息的具体方式与前述方式一相同;当规则信息和配置信息中优先级较高的一者为配置信息时,根据配置信息向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息的具体方式与前述方式二相同此处不再赘述。Here, when the one with a higher priority between the rule information and the configuration information is the rule information, the specific method of sending the first non-access layer NAS message and/or the first indication information to the network side according to the rule information is the same as the aforementioned method one; when the one with a higher priority between the rule information and the configuration information is the configuration information, the specific method of sending the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information is the same as the aforementioned method two and is not repeated here.
可选地,所述方法还包括:Optionally, the method further comprises:
在所述第二指示信息指示所述第一操作成功的情况下,所述第一终端向所述网络侧发送所述第一设备的信息。When the second indication information indicates that the first operation is successful, the first terminal sends information of the first device to the network side.
由此可知,在网络侧执行第一操作成功的情况下,第一终端还可以向网络侧(例如第一网络功能)发送第一设备的信息。It can be seen from this that when the first operation is successfully executed on the network side, the first terminal can also send information of the first device to the network side (for example, the first network function).
其中,所述第一设备的信息可以包括第一设备的地址信息(例如IP地址)。The information of the first device may include address information of the first device (eg, IP address).
第二方面,本申请实施例提供了一种操作执行方法,如图3所述,该方法可以包括如下步骤301和/或302与303:In a second aspect, an embodiment of the present application provides an operation execution method. As shown in FIG. 3 , the method may include the following steps 301 and/or 302 and 303:
步骤301:第一网络功能向第一终端发送第五指示信息。 Step 301: The first network function sends fifth indication information to the first terminal.
其中,所述第五指示信息用于指示以下至少一项:The fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述第一网络功能所在的移动网络的控制面执行所述第一操作;allowing or not allowing execution of the first operation through a control plane of the mobile network where the first network function is located;
允许或不允许通过所述第一网络功能所在的移动网络的用户面执行所述第一操作。Allow or not allow the first operation to be performed through a user plane of a mobile network where the first network function is located.
可选地,在步骤301之前,所述方法还包括:Optionally, before step 301, the method further includes:
第一网络功能与第一终端交互以建立PDU会话;The first network function interacts with the first terminal to establish a PDU session;
步骤301“第一网络功能向第一终端发送第五指示信息”,包括:Step 301 “the first network function sends fifth indication information to the first terminal” includes:
所述第一网络功能向所述第一终端发送PDU会话建立/修改确认消息,所述PDU会话建立/修改确认消息中携带有所述第五指示信息。The first network function sends a PDU session establishment/modification confirmation message to the first terminal, and the PDU session establishment/modification confirmation message carries the fifth indication information.
即第一网络功能可以将上述第五指示信息携带在PDU会话建立/修改确认消息中,发送给第一终端。That is, the first network function may carry the fifth indication information in a PDU session establishment/modification confirmation message and send it to the first terminal.
步骤302:所述第一网络功能接收所述第一终端发送的第一非接入层NAS消息和/或第一指示信息。Step 302: The first network function receives a first non-access stratum NAS message and/or first indication information sent by the first terminal.
其中,所述第一非接入层NAS消息用于指示所述第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项。The first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization.
这里,第一终端可以向第一网络功能发送第一非接入层NAS消息和/或第一指示信息,其中,第一终端例如可以为具有网关能力的终端,即)网关终端(PIN Element with Gateway Capability,PEGC);第一网络功能例如可以为会话管理功能(Session Management Function,SMF),或接入和移动性管理功能(Access and Mobility Management Function,AMF)。Here, the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function, where the first terminal can be, for example, a terminal with gateway capability, i.e., a gateway terminal (PIN Element with Gateway Capability, PEGC); the first network function can be, for example, a session management function (Session Management Function, SMF) or an access and mobility management function (Access and Mobility Management Function, AMF).
另外,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作。由此可知,在本申请实施例中,第一终端可以向网络侧(例如上述第一网络功能)发送第一非接入层NAS消息,指示网络侧执行第一操作(即通过一个NAS消息触发网络侧执行第一操作);或者,可以向网络侧发送第一指示信息,指示网络侧执行第一操作(即通过一个指示信息来指示网络侧设备执行第一操作);或者,也可以向网络侧发送第一NAS消息和第一指示信息,指示网络侧执行第一操作(即通过一个NAS消息和一个指示信息来指示网络侧执行第一操作),这里,第一NAS消息和第一指示信息可以是独立的,也可以将第一指示信息携带在第一NAS消息中。In addition, the first non-access layer NAS message is used to indicate the first operation, and the first indication information is used to indicate the first operation. It can be seen that in the embodiment of the present application, the first terminal can send a first non-access layer NAS message to the network side (such as the above-mentioned first network function) to instruct the network side to perform the first operation (that is, trigger the network side to perform the first operation through a NAS message); or, it can send a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side device to perform the first operation through an indication information); or, it can also send a first NAS message and a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side to perform the first operation through a NAS message and an indication information), where the first NAS message and the first indication information can be independent, or the first indication information can be carried in the first NAS message.
另外,所述第一操作包括以下至少之一:In addition, the first operation includes at least one of the following:
鉴权(authentication)、认证(attestation/identification)、授权(authorization)。Authentication, attestation/identification, authorization.
步骤303:所述第一网络功能响应于所述第一非接入层NAS消息和/或所述第一指示信息,执行如下至少一项:Step 303: The first network function performs at least one of the following in response to the first non-access stratum NAS message and/or the first indication information:
向所述第一终端发送第五指示信息;Sending fifth indication information to the first terminal;
指示第二网络功能和所述第一终端进行所述第一操作。Instruct a second network function and the first terminal to perform the first operation.
由前述内容可知,第一网络功能可以在接收到第一终端发送的PDU会话建立/修改 请求消息后,将第五指示信息携带在PDU会话建立/修改确认消息中发送给第一终端,以告知第一终端其是否允许第一操作;也可以在第一网络功能接收到第一终端发送的第一非接入层NAS消息和/或第一指示信息之后,发送第五指示信息给第一终端,以告知第一终端其是否允许第一操作。As can be seen from the foregoing, the first network function can establish/modify the PDU session after receiving the PDU sent by the first terminal. After the request message, the fifth indication information is carried in the PDU session establishment/modification confirmation message and sent to the first terminal to inform the first terminal whether it allows the first operation; or after the first network function receives the first non-access layer NAS message and/or the first indication information sent by the first terminal, the fifth indication information is sent to the first terminal to inform the first terminal whether it allows the first operation.
由上述步骤301至302可知,在本申请实施例中,第一网络功能能够接收第一终端发送的第一非接入层NAS消息和/或第一指示信息,从而响应于第一非接入层NAS消息和/或所述第一指示信息,向第一终端发送第五指示信息和/或指示第二网络功能和第一终端进行第一操作;和/或,第一网络功能向第一终端发送第五指示信息;其中,第一非接入层NAS消息用于指示第一操作,第一指示信息用于指示第一操作,第一操作包括鉴权、认证、授权中的至少一项,第五指示信息用于指示以下至少一项:It can be known from the above steps 301 to 302 that in an embodiment of the present application, the first network function is capable of receiving a first non-access layer NAS message and/or a first indication information sent by the first terminal, thereby responding to the first non-access layer NAS message and/or the first indication information, sending fifth indication information to the first terminal and/or instructing the second network function and the first terminal to perform a first operation; and/or, the first network function sends the fifth indication information to the first terminal; wherein the first non-access layer NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, the first operation includes at least one of authentication, authentication, and authorization, and the fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述第一网络功能所在的移动网络的控制面执行所述第一操作;allowing or not allowing execution of the first operation through a control plane of the mobile network where the first network function is located;
允许或不允许通过所述第一网络功能所在的移动网络的用户面执行所述第一操作。Allow or not allow the first operation to be performed through a user plane of a mobile network where the first network function is located.
由此可见,第一终端可以通过发送第一非接入层NAS消息来指示网络侧执行鉴权、认证、授权中的至少一项操作,或通过发送第一指示信息指示网络侧执行鉴权、认证、授权中的至少一项操作,或者,通过发送第一NAS消息和第一指示信息指示网络侧执行鉴权、认证、授权中的至少一项操作;还可以接收网络侧发送的上述第五指示信息。因此,可以采用本申请实施例的操作执行方法,对PIN中的设备进行鉴权、认证、授权中的至少一项,从而提升访问PIN的安全性。It can be seen that the first terminal can instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, certification, and authorization operations on the device in the PIN, thereby improving the security of accessing the PIN.
可选地,在所述第一网络功能指示第二网络功能和所述第一终端进行所述第一操作的情况下,所述方法还包括:Optionally, when the first network function instructs the second network function and the first terminal to perform the first operation, the method further includes:
所述第一网络功能接收所述第二网络功能发送的第三指示信息,其中,所述第三指示信息用于指示所述第一操作的结果;The first network function receives third indication information sent by the second network function, wherein the third indication information is used to indicate a result of the first operation;
所述第一网络功能根据所述第三指示信息,向所述第一终端发送第二指示信息,所述第二指示信息用于指示所述第一操作的结果。The first network function sends second indication information to the first terminal according to the third indication information, where the second indication information is used to indicate a result of the first operation.
这里第二网络功能用于执行第一操作,则第二网络功能执行完第一操作后,可以向第一网络功能返回用于指示第一操作的结果的第三指示信息,进而由第一网络功能根据第三指示信息,向第一终端返回用于指示第一操作的结果的第二指示信息。Here, the second network function is used to perform the first operation. After the second network function performs the first operation, it can return third indication information indicating the result of the first operation to the first network function, and then the first network function returns second indication information indicating the result of the first operation to the first terminal based on the third indication information.
需要说明的是,上述第一终端还可以满足如下的情况一或情况二:It should be noted that the first terminal may also meet the following conditions 1 or 2:
情况一:第一终端还可以具有个人物联网设备(PIN Element,PINE)的功能,以及网关能力,亦即PEGC和PINE可以合并为一个设备。Case 1: The first terminal can also have the function of a personal Internet of Things device (PIN Element, PINE) and gateway capabilities, that is, PEGC and PINE can be combined into one device.
情况二:第一终端也可以不具备PINE的能力,例如第一终端只具备网关能力,亦即PEGC与PINE独立设置。Case 2: The first terminal may not have the PINE capability. For example, the first terminal only has the gateway capability, that is, PEGC and PINE are independently configured.
可选地,在上述情况一中,在上述步骤302所述第一网络功能接收第一终端发送的第一非接入层NAS消息和/或第一指示信息之前,所述方法还包括: Optionally, in the above situation 1, before the first network function receives the first non-access layer NAS message and/or the first indication information sent by the first terminal in the above step 302, the method further includes:
所述第一网络功能与所述第一终端交互以建立协议数据单元PDU会话。The first network function interacts with the first terminal to establish a protocol data unit (PDU) session.
即PEGC与PINE合并设置而成的第一终端,在向网络侧发送第一非接入层NAS消息和/或第一指示信息之前,还可以与网络侧建立PDU会话。That is, the first terminal formed by combining PEGC and PINE can also establish a PDU session with the network side before sending the first non-access layer NAS message and/or the first indication information to the network side.
其中,第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息之前,若建立PDU会话,则后续第一终端可以利用后续PDU会话的修改流程来向网络侧发送第一非接入层NAS消息。Among them, before the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, if a PDU session is established, the first terminal can subsequently use the modification process of the subsequent PDU session to send the first non-access layer NAS message to the network side.
可选地,所述第一非接入层NAS消息为PDU会话修改请求。即在前述情况一中,第一终端可以将PDU修改请求作为第一NAS消息,发送给网络侧,以触发网络侧执行第一操作。Optionally, the first non-access layer NAS message is a PDU session modification request. That is, in the aforementioned situation 1, the first terminal can send the PDU modification request as the first NAS message to the network side to trigger the network side to perform the first operation.
可选地,所述第一指示信息包括如下A-1项至A-3中至少一项:Optionally, the first indication information includes at least one of the following items A-1 to A-3:
A-1项:用于指示进行所述第一操作的指示;Item A-1: an instruction for instructing to perform the first operation;
A-2项:所述第一终端的信息;Item A-2: information of the first terminal;
A-3项:第二网络功能的信息,其中,所述第二网络功能用于执行所述第一操作。Item A-3: Information about a second network function, wherein the second network function is used to perform the first operation.
这里A-1项至A-3项的相关说明可参见前文所述,此处不再赘述。The relevant explanations of items A-1 to A-3 can be found in the previous text and will not be repeated here.
可选地,在上述情况二中,所述第一指示信息包括如下B-1项至B-4项中至少一项:Optionally, in the above situation 2, the first indication information includes at least one of the following items B-1 to B-4:
B-1项:用于指示进行所述第一操作的指示;Item B-1: an instruction for instructing to perform the first operation;
B-2项:所述第一设备的信息;Item B-2: information about the first device;
B-3项:所述第一终端的信息;Item B-3: information of the first terminal;
B-4项:第二网络功能的信息,其中,所述第二网络功能用于执行所述第一操作。Item B-4: Information about a second network function, wherein the second network function is used to perform the first operation.
这里B-1项至B-4项的相关说明可参见前文所述,此处不再赘述。The relevant explanations of Items B-1 to B-4 can be found in the previous text and will not be repeated here.
可选地,所述第一非接入层NAS消息为PDU会话修改请求或PDU会话建立请求。即在前述情况二中,第一终端可以将PDU修改请求或PDU会话建立请求作为第一NAS消息,发送给网络侧,以触发网络侧执行第一操作。Optionally, the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request. That is, in the aforementioned situation 2, the first terminal can send the PDU modification request or the PDU session establishment request as the first NAS message to the network side to trigger the network side to perform the first operation.
可选地,所述第一网络功能根据所述第三指示信息,向所述第一终端发送第二指示信息,包括:Optionally, the first network function sending second indication information to the first terminal according to the third indication information includes:
所述第一网络功能根据所述第三指示信息,向所述第一终端发送第二NAS消息,其中,所述第二NAS消息中携带有所述第二指示信息。The first network function sends a second NAS message to the first terminal according to the third indication information, wherein the second NAS message carries the second indication information.
即第一网络功能可以将用于指示执行第一操作的结果的第二指示信息携带在第二NAS消息中,发送给第一终端。That is, the first network function may carry the second indication information used to indicate the result of executing the first operation in the second NAS message, and send the message to the first terminal.
可选地,所述第二指示信息满足以下D-1项至D-2项中至少一项:Optionally, the second indication information satisfies at least one of the following items D-1 to D-2:
D-1项:通过所述第二NAS消息的标识或名称指示所述第一操作的结果;Item D-1: indicating the result of the first operation by an identifier or a name of the second NAS message;
D-1项:通过原因值指示所述第一操作的结果。Item D-1: Indicate the result of the first operation through a cause value.
上述D-1项表示不同的第二NAS消息的标识或名称,指示不同的第一操作的结果。The above item D-1 represents the identifier or name of different second NAS messages, indicating different results of the first operation.
可选地,所述通过所述第二NAS消息的标识或名称指示所述第一操作的结果,包括以下至少一项: Optionally, the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
通过PDU会话修改确认消息或PDU会话建立确认消息指示所述第一操作成功;Indicating that the first operation is successful through a PDU session modification confirmation message or a PDU session establishment confirmation message;
通过PDU会话修改拒绝消息或PDU会话建立拒绝消息指示所述第一操作失败。The failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
即若网络侧发送给第一终端的第二NAS消息是PDU会话修改确认消息或PDU会话建立确认消息,则表示第一操作执行成功;若网络侧发送给第一终端的第二NAS消息是PDU会话修改拒绝消息或PDU会话建立拒绝消息,则表示第一操作执行失败。That is, if the second NAS message sent by the network side to the first terminal is a PDU session modification confirmation message or a PDU session establishment confirmation message, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side to the first terminal is a PDU session modification rejection message or a PDU session establishment rejection message, it indicates that the first operation fails.
即网络侧执行第一操作成功时,向第一终端返回PDU会话修改确认消息或PDU会话建立确认消息;网络侧执行第一操作失败时,向第一终端返回PDU会话修改拒绝消息或PDU会话建立拒绝消息。That is, when the network side successfully executes the first operation, it returns a PDU session modification confirmation message or a PDU session establishment confirmation message to the first terminal; when the network side fails to execute the first operation, it returns a PDU session modification rejection message or a PDU session establishment rejection message to the first terminal.
上述D-2项表示通过原因值显示指示不同的第一操作的结果。The above-mentioned item D-2 indicates that the result of the first operation indicating a difference is displayed by the cause value.
可选地,所述通过原因值指示所述第一操作的结果,包括以下至少一项指示:Optionally, the result of the first operation indicated by the reason value includes at least one of the following indications:
失败原因值和/或失败指示,用于指示所述第一操作失败;a failure reason value and/or a failure indication, used to indicate that the first operation failed;
成功原因值和/或成功指示,用于指示所述第一操作成功;A success reason value and/or a success indication, used to indicate that the first operation is successful;
在所述第二NAS消息中未包括所述失败原因值和/或失败指示的情况下,指示所述第一操作成功;In a case where the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful;
在所述第二NAS消息中未包括所述成功原因值和/或成功指示的情况下,指示所述第一操作失败。In a case where the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
即若网络侧发送的第二NAS消息中包括失败原因值和/或失败指示,则表示第一操作执行失败;若网络侧发送的第二NAS消息中未包括失败原因值和/或失败指示,表示第一操作执行成功。That is, if the second NAS message sent by the network side includes a failure cause value and/or a failure indication, it indicates that the first operation has failed; if the second NAS message sent by the network side does not include a failure cause value and/or a failure indication, it indicates that the first operation has been successfully executed.
或者,若网络侧发送的第二NAS消息中包括成功原因值和/或成功指示,则表示第一操作执行成功;若网络侧发送的第二NAS消息中未包括成功原因值和/或成功指示,表示第一操作执行失败。Alternatively, if the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side does not include a success reason value and/or a success indication, it indicates that the first operation fails.
或者,若网络侧发送的第二NAS消息中包括失败原因值和/或失败指示,则表示第一操作执行失败;若网络侧发送的第二NAS消息中包括成功原因值和/或成功指示,则表示第一操作执行成功。Alternatively, if the second NAS message sent by the network side includes a failure reason value and/or a failure indication, it indicates that the first operation has failed to execute; if the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation has been executed successfully.
可选地,所述方法还包括如下中至少一项:Optionally, the method further comprises at least one of the following:
第一网络功能接收第一终端为第一设备转发的第二消息;The first network function receives a second message forwarded by the first terminal for the first device;
第一网络功能向第一终端发送第三消息,以使得第一终端将第三消息转发给第一设备;The first network function sends a third message to the first terminal, so that the first terminal forwards the third message to the first device;
其中,所述第二消息和所述第三消息分别为执行所述第一操作涉及的消息,即第二消息和第三消息分别为执行第一操作时,第一设备与网络侧需要交互的消息。The second message and the third message are messages involved in executing the first operation, that is, the second message and the third message are messages that the first device and the network side need to interact with when executing the first operation.
由此可知,在第一网络功能执行第一操作的过程中,第一终端还可以为第一设备和第一网络功能转发交互消息。It can be seen from this that during the process of the first network function performing the first operation, the first terminal can also forward the interaction message for the first device and the first network function.
例如若在执行第一过程中,第一网络功能需要请求第一设备的标识信息,则第一网络功能可以向第一终端发送用于请求第一设备的标识信息的第二消息,从而使得第一终 端将第二消息发送给第一设备,进而使得第一设备向第一终端返回携带第一设备的标识信息的第三消息,并由第一终端将该第三消息返回给第一网络功能。For example, if the first network function needs to request the identification information of the first device during the execution of the first process, the first network function may send a second message for requesting the identification information of the first device to the first terminal, so that the first terminal The terminal sends the second message to the first device, so that the first device returns a third message carrying the identification information of the first device to the first terminal, and the first terminal returns the third message to the first network function.
可选地,在前述步骤303中,第一网络功能指示第二网络功能进行所述第一操作,包括:Optionally, in the aforementioned step 303, the first network function instructs the second network function to perform the first operation, including:
第一网络功能向第二网络功能发送第一设备的标识信息,以指示所述第二网络功能执行所述第一操作。The first network function sends identification information of the first device to the second network function to instruct the second network function to perform the first operation.
可选地,所述第一网络功能响应于所述第一非接入层NAS消息,指示第二网络功能和所述第一终端进行所述第一操作,包括如下V-1项至V-5项中至少一项:Optionally, the first network function instructs the second network function and the first terminal to perform the first operation in response to the first non-access layer NAS message, including at least one of the following items V-1 to V-5:
V-1项:所述第一网络功能基于所述第一非接入层NAS消息中的PDU会话相关信息,指示所述第二网络功能和所述第一终端进行所述第一操作;Item V-1: the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message;
V-2项:所述第一网络功能基于所述第一非接入层NAS消息中的PDU会话相关信息,以及PDU会话相关信息与PIN实例或会话的第一关联信息,指示所述第二网络功能和所述第一终端进行所述第一操作;Item V-2: the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message and the first association information between the PDU session related information and the PIN instance or session;
V-3项:所述第一网络功能基于所述第一非接入层NAS消息中的PIN实例或会话相关信息,指示所述第二网络功能和所述第一终端进行所述第一操作;Item V-3: the first network function instructs the second network function and the first terminal to perform the first operation based on the PIN instance or session related information in the first non-access layer NAS message;
V-4项:所述第一网络功能基于所述第一非接入层NAS消息中的PDU会话相关信息和PIN业务指示信息,指示所述第二网络功能和所述第一终端进行所述第一操作;Item V-4: the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information and the PIN service indication information in the first non-access layer NAS message;
V-5项:所述第一网络功能基于所述第一非接入层NAS消息中的PDU会话相关信息,以及PDU会话相关信息与PIN业务的第二关联信息,指示所述第二网络功能和所述第一终端进行所述第一操作。Item V-5: The first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message, and the second association information between the PDU session related information and the PIN service.
上述V-1项表示,若第一非接入层NAS消息中的PDU会话相关信息为特定信息,则第一网络功能指示第二网络功能和第一终端进行第一操作,否则不指示第二网络功能和第一终端进行第一操作。这里,PDU会话相关信息可以包括PDU会话标识、数据网络名(Data Network Name,DNN)、网络片选择辅助信息(Single Network Slice Selection Assistance Information,S-NSSAI)中至少一项。例如第一NAS消息中的PDU会话标识与特定标识时,第一网络功能指示第二网络功能和第一终端进行第一操作。The above-mentioned V-1 item indicates that if the PDU session related information in the first non-access layer NAS message is specific information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation. Here, the PDU session related information may include at least one of the PDU session identifier, the data network name (Data Network Name, DNN), and the network slice selection auxiliary information (Single Network Slice Selection Assistance Information, S-NSSAI). For example, when the PDU session identifier in the first NAS message is the same as the specific identifier, the first network function instructs the second network function and the first terminal to perform the first operation.
上述V-2项表示:第一关联信息中存在与第一非接入层NAS消息中的PDU会话相关信息对应的PIN实例或会话,则第一网络功能指示第二网络功能和第一终端进行第一操作,否则不指示第二网络功能和第一终端进行第一操作。这里,PDU会话相关信息可以包括PDU会话标识、DNN、S-NSSAI中至少一项。例如第一关联信息中存在与第一NAS消息中的PDU会话标识对应的PIN实例或会话时,第一网络功能指示第二网络功能和第一终端进行第一操作。The above-mentioned V-2 item indicates: if there is a PIN instance or session corresponding to the PDU session related information in the first non-access layer NAS message in the first association information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation. Here, the PDU session related information may include at least one of the PDU session identifier, DNN, and S-NSSAI. For example, when there is a PIN instance or session corresponding to the PDU session identifier in the first NAS message in the first association information, the first network function instructs the second network function and the first terminal to perform the first operation.
上述V-3项表示:第一非接入层NAS消息中包括PIN实例或会话相关信息,则第一网络功能指示第二网络功能和第一终端进行第一操作,否则不指示第二网络功能和第一终端进行第一操作。这里,PIN实例或会话相关信息可以包括PIN实例或会话标识。 The above item V-3 indicates that: if the first non-access layer NAS message includes PIN instance or session related information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation. Here, the PIN instance or session related information may include a PIN instance or a session identifier.
上述V-4项表示:第一非接入层NAS消息中存在指示PDU会话相关信息与PIN业务相关的指示信息(即指与PIN这个业务有关,而不是与,比如电话业务、视频业务,这些其他业务有关),第一网络功能指示第二网络功能和第一终端进行第一操作,否则不指示第二网络功能和第一终端进行第一操作。这里,PDU会话相关信息可以包括PDU会话标识、DNN、S-NSSAI中至少一项。The above-mentioned item V-4 indicates that: the first non-access layer NAS message contains indication information indicating that the PDU session related information is related to the PIN service (that is, it is related to the PIN service, rather than other services such as telephone service and video service), and the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation. Here, the PDU session related information may include at least one of the PDU session identifier, DNN, and S-NSSAI.
上述V-5项表示:第二关联信息中指示第一非接入层NAS消息中的PDU会话相关信息与PIN业务相关(指与PIN这个业务有关,而不是与,比如电话业务、视频业务,这些其他业务有关),则第一网络功能指示第二网络功能和第一终端进行第一操作,否则不指示第二网络功能和第一终端进行第一操作。这里,PDU会话相关信息可以包括PDU会话标识、DNN、S-NSSAI中至少一项。例如第二关联信息中存在与第一NAS消息中的PDU会话标识对应的PIN业务时,第一网络功能指示第二网络功能和第一终端进行第一操作。The above-mentioned item V-5 indicates that: if the second association information indicates that the PDU session-related information in the first non-access layer NAS message is related to the PIN service (referring to the PIN service, not other services such as telephone service and video service), the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation. Here, the PDU session-related information may include at least one of the PDU session identifier, DNN, and S-NSSAI. For example, when there is a PIN service corresponding to the PDU session identifier in the first NAS message in the second association information, the first network function instructs the second network function and the first terminal to perform the first operation.
可以理解的是,第一网络功能还可以根据接收到的第一NAS消息的发送设备的信息,指示所述第二网络功能和所述第一终端进行所述第一操作。例如在第一NAS消息是具有网关能力的设备发送的情况下(即在第一终端为具有网关能力的终端的情况下),第一网络功能指示所述第二网络功能和所述第一终端进行所述第一操作;在第一NAS消息不是具备网关能力的设备发送的情况下(即在第一终端不是具有网关能力的终端的情况下),第一网络功能不指示所述第二网络功能和所述第一终端进行所述第一操作。It is understandable that the first network function may also instruct the second network function and the first terminal to perform the first operation according to the information of the sending device of the received first NAS message. For example, when the first NAS message is sent by a device with gateway capabilities (that is, when the first terminal is a terminal with gateway capabilities), the first network function instructs the second network function and the first terminal to perform the first operation; when the first NAS message is not sent by a device with gateway capabilities (that is, when the first terminal is not a terminal with gateway capabilities), the first network function does not instruct the second network function and the first terminal to perform the first operation.
可选地,所述方法还包括:Optionally, the method further comprises:
所述第一网络功能从第三网络功能获知以下至少之一:The first network function learns at least one of the following from the third network function:
所述第一关联信息;the first associated information;
所述第二关联信息。The second associated information.
这里第三网络功能可以为PCF或UDM。Here, the third network function may be PCF or UDM.
可选地,所述方法还包括:Optionally, the method further comprises:
在所述第二指示信息指示所述第一操作成功的情况下,所述第一网络功能接收所述第一终端发送的第一设备的信息;When the second indication information indicates that the first operation is successful, the first network function receives information about the first device sent by the first terminal;
其中,所述第一设备为需要通过所述第一终端访问PIN或所述第一网络功能所在网络的设备。The first device is a device that needs to access the PIN or the network where the first network function is located through the first terminal.
由此可知,在网络侧执行第一操作成功的情况下,第一终端还可以向网络侧(例如第一网络功能)发送第一设备的信息。It can be seen from this that when the first operation is successfully executed on the network side, the first terminal can also send information of the first device to the network side (for example, the first network function).
其中,所述第一设备的信息可以包括第一设备的地址信息(例如IP地址)。The information of the first device may include address information of the first device (eg, IP address).
可选地,所述方法还包括:Optionally, the method further comprises:
在所述第一网络功能获知报文过滤规则,且所述报文过滤规则与所述第一设备相关的情况下,所述第一网络功能使用所述报文过滤规则配置第四网络功能。When the first network function learns the message filtering rule and the message filtering rule is related to the first device, the first network function uses the message filtering rule to configure a fourth network function.
这里,第四网络功能例如可以为用户面功能(User Port Function,UPF)。 Here, the fourth network function may be, for example, a user plane function (User Port Function, UPF).
第三方面,本申请实施例还提供了一种操作执行方法,如图4所示,该方法包括如下步骤401:In a third aspect, the embodiment of the present application further provides an operation execution method, as shown in FIG4 , the method includes the following step 401:
步骤401:第三网络功能执行第二操作。Step 401: The third network function performs a second operation.
其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
所述第三网络功能向第一终端发送规则信息;The third network function sends rule information to the first terminal;
所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
这里,第三网络功能例如可以为PCF或UDM。Here, the third network function may be, for example, PCF or UDM.
可选地,所述规则信息用于指示以下至少一项:Optionally, the rule information is used to indicate at least one of the following:
第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
至少一个第一目标设备需要所述第一操作或不需要所述第一操作;At least one first target device requires the first operation or does not require the first operation;
其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
所述第一目标设备为需要通过所述第一终端访问个人物联网PIN或所述第三网络功能所在移动网络的设备。The first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
可选地,所述PDU会话配置信息包括以下至少一项:Optionally, the PDU session configuration information includes at least one of the following:
PDU会话相关信息与PIN实例或会话的第一关联信息;First association information between PDU session related information and PIN instance or session;
PDU会话相关信息与PIN业务的第二关联信息。The second association information between the PDU session related information and the PIN service.
其中,第一终端接收到规则信息后,可以根据规则信息向第一网络功能发送第一非接入层NAS消息和/或第一指示信息,其中的具体发送方式可参见前文所述,此处不再赘述。Among them, after the first terminal receives the rule information, it can send the first non-access layer NAS message and/or the first indication information to the first network function according to the rule information. The specific sending method can be found in the above description and will not be repeated here.
第一网络功能接收到PDU会话配置信息后,可以根据该PDU会话配置信息(即第一关联信息和/或第二关联信息),指示第二网络功能和第一终端进行第一操作,具体实现方式可参见前文所述,此处不再赘述。After the first network function receives the PDU session configuration information, it can instruct the second network function and the first terminal to perform the first operation according to the PDU session configuration information (i.e., the first association information and/or the second association information). The specific implementation method can be found in the above description and will not be repeated here.
可选地,在所述第三网络功能执行所述第二操作之前,所述方法还包括:Optionally, before the third network function performs the second operation, the method further includes:
所述第三网络功能获知第四指示信息,其中,所述第四指示信息用于指示所述第三网络功能执行所述第二操作;The third network function acquires fourth indication information, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
所述第三网络功能执行所述第二操作,包括:The third network function performs the second operation, including:
所述第三网络功能根据所述第四指示信息执行所述第二操作。The third network function performs the second operation according to the fourth indication information.
可选地,所述第三网络功能获知第四指示信息,包括:Optionally, the third network function acquires the fourth indication information, including:
所述第三网络功能接收第五网络功能发送的所述第四指示信息。The third network function receives the fourth indication information sent by the fifth network function.
这里第五网络功能可以为AF。Here, the fifth network function may be AF.
其中,第二终端(例如管理终端(PIN Element with Management Capability,PEMC))创建一个PIN后,可以通知第五网络功能(例如应用功能(Application Function,AF))其创建了一个PIN,并指示第一操作需要应用于该PIN,从而由第五网络功能再向第三网络功能发送上述第四指示信息,进而触发第三网络功能执行上述第二操作。Among them, after the second terminal (for example, the management terminal (PIN Element with Management Capability, PEMC)) creates a PIN, it can notify the fifth network function (for example, the application function (Application Function, AF)) that it has created a PIN and indicate that the first operation needs to be applied to the PIN, so that the fifth network function sends the above-mentioned fourth indication information to the third network function, thereby triggering the third network function to perform the above-mentioned second operation.
第四方面,本申请实施例还提供了一种操作执行方法,如图5所示,该方法可以包 括如下步骤501:In a fourth aspect, the present application embodiment further provides an operation execution method, as shown in FIG5 , the method may include The steps 501 are as follows:
步骤501:第二终端向个人物联网PIN中的第一终端发送配置信息。Step 501: The second terminal sends configuration information to the first terminal in the personal Internet of Things PIN.
这里第二终端例如可以为PEMC,第一终端例如可以为PEGC。Here, the second terminal may be, for example, PEMC, and the first terminal may be, for example, PEGC.
可选地,所述配置信息用于指示以下至少一项:Optionally, the configuration information is used to indicate at least one of the following:
第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
至少一个第二目标设备需要所述第一操作或不需要所述第一操作;At least one second target device requires the first operation or does not require the first operation;
其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
所述第二目标设备为需要通过所述第一终端访问所述个人物联网PIN或移动网络的设备。The second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
另外,第一终端接收到配置信息后,可以根据配置信息向第一网络功能发送第一非接入层NAS消息和/或第一指示信息,其中的具体发送方式可参见前文所述,此处不再赘述。In addition, after receiving the configuration information, the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function according to the configuration information. The specific sending method can be found in the above description and will not be repeated here.
第五方面,本申请实施例还提供了一种操作执行方法,如图6所示,该方法可以包括如下步骤601:In a fifth aspect, the embodiment of the present application further provides an operation execution method, as shown in FIG6 , the method may include the following step 601:
步骤601:第五网络功能向第三网络功能发送第四指示信息。Step 601: The fifth network function sends fourth indication information to the third network function.
这里第五网络功能可以为AF。Here, the fifth network function may be AF.
其中,所述第四指示信息用于指示所述第三网络功能执行第二操作;The fourth indication information is used to instruct the third network function to perform a second operation;
其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
所述第三网络功能向第一终端发送规则信息;The third network function sends rule information to the first terminal;
所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
可选地,所述规则信息用于指示以下至少一项:Optionally, the rule information is used to indicate at least one of the following:
第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
至少一个第一目标设备需要所述第一操作或不需要所述第一操作;At least one first target device requires the first operation or does not require the first operation;
其中,所述第一操作包括鉴权、认证、授权中的至少一项;Wherein, the first operation includes at least one of authentication, certification, and authorization;
所述第一目标设备为需要通过所述第一终端访问个人物联网PIN或所述第三网络功能所在移动网络的设备。The first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
可选地,所述PDU会话配置信息包括以下至少一项:Optionally, the PDU session configuration information includes at least one of the following:
PDU会话相关信息与PIN实例或会话的第一关联信息;First association information between PDU session related information and PIN instance or session;
PDU会话相关信息与PIN业务的第二关联信息。The second association information between the PDU session related information and the PIN service.
其中,第一终端接收到规则信息后,可以根据规则信息向第一网络功能发送第一非接入层NAS消息和/或第一指示信息,其中的具体发送方式可参见前文所述,此处不再赘述。Among them, after the first terminal receives the rule information, it can send the first non-access layer NAS message and/or the first indication information to the first network function according to the rule information. The specific sending method can be found in the above description and will not be repeated here.
第一网络功能接收到PDU会话配置信息后,可以根据该PDU会话配置信息(即第一关联信息和/或第二关联信息),指示第二网络功能和第一终端进行第一操作,具体实现方式可参见前文所述,此处不再赘述。 After the first network function receives the PDU session configuration information, it can instruct the second network function and the first terminal to perform the first operation according to the PDU session configuration information (i.e., the first association information and/or the second association information). The specific implementation method can be found in the above description and will not be repeated here.
综上所述,本申请实施例的操作执行方法的具体实施方式可如下实施方式一或实施方式二所述。In summary, the specific implementation of the operation execution method of the embodiment of the present application can be described in the following implementation mode 1 or 2.
实施方式一:如图7所示,包括如下步骤71至716(以前文所述的第一操作包括认证和/或授权为例进行说明)。Implementation method 1: as shown in FIG. 7 , it includes the following steps 71 to 716 (the first operation mentioned above includes authentication and/or authorization for illustration).
步骤71:PEMC创建一个PIN,可以通知AF创建了一个PIN,并可以指示访问该PIN是否需要5G核心网辅助的认证和/或授权。Step 71: The PEMC creates a PIN, can notify the AF that a PIN has been created, and can indicate whether access to the PIN requires 5G core network-assisted authentication and/or authorization.
其中,PEMC可以向PINE询问设备信息(例如在PINE接入PIN时PEMC向PINE询问设备信息),以获知PINE是否具有信任状(credential),从而在PINE具有信任状时,在将这类PINE加入一个PIN时,指示AF该PINE需要5G核心网辅助的认证和/或授权。这里,所述信任状即为鉴权认证信息。Among them, PEMC can ask PINE for device information (for example, PEMC asks PINE for device information when PINE accesses PIN) to learn whether PINE has a credential, so that when PINE has a credential, when such PINE is added to a PIN, AF is instructed that the PINE needs authentication and/or authorization assisted by the 5G core network. Here, the credential is the authentication information.
步骤72:AF可以直接或通过NEF通知PCF:该PIN是否需要5G核心网辅助的认证和/或授权。Step 72: AF may notify PCF directly or through NEF whether the PIN requires authentication and/or authorization assisted by the 5G core network.
步骤73:PCF获知到该PIN是否需要5G核心网辅助的认证和/或授权之后,生成规则信息,从而通过AMF将该规则信息发送给该PIN中的各PEGC。Step 73: After the PCF learns whether the PIN requires authentication and/or authorization assisted by the 5G core network, it generates rule information and sends the rule information to each PEGC in the PIN through the AMF.
其中,规则信息用于指示:访问该PIN是否需要5G核心网辅助的认证和/或授权。The rule information is used to indicate whether access to the PIN requires authentication and/or authorization assisted by the 5G core network.
步骤74:第一PINE连接PEGC以访问该PIN(例如第一PINE给PEGC发送连接请求)。Step 74: The first PINE connects to the PEGC to access the PIN (eg, the first PINE sends a connection request to the PEGC).
步骤75:如果PEGC获得的规则信息指示中该PIN需要5G核心网辅助的认证和/或授权,则从PEMC获取配置信息,其中,该配置信息用于指示:至少一个PINE是否需要5G核心网辅助的认证和/或授权。Step 75: If the rule information obtained by PEGC indicates that the PIN requires authentication and/or authorization assisted by the 5G core network, configuration information is obtained from PEMC, wherein the configuration information is used to indicate whether at least one PINE requires authentication and/or authorization assisted by the 5G core network.
步骤76:如果配置信息指示第一PINE需要5G核心网辅助的认证和/或授权,则PEGC向SMF发送第一NAS消息,其中,该第一NAS消息携带有用于指示进行认证和/或授权的指示;如果配置信息指示第一PINE不需要核心网辅助的认证和/或授权,则PEGC不向SMF发送第一NAS消息。Step 76: If the configuration information indicates that the first PINE requires authentication and/or authorization assisted by the 5G core network, the PEGC sends a first NAS message to the SMF, wherein the first NAS message carries an indication for indicating authentication and/or authorization; if the configuration information indicates that the first PINE does not require authentication and/or authorization assisted by the core network, the PEGC does not send the first NAS message to the SMF.
其中,该第一NAS消息可以为PDU会话修改请求(PDU Session Modification Request)或PDU会话建立请求(PDU Session Establishment Request)。Among them, the first NAS message can be a PDU session modification request (PDU Session Modification Request) or a PDU session establishment request (PDU Session Establishment Request).
步骤77:SMF若接收到第一NAS消息,则根据第一NAS消息的相关信息,判断第一PINE是否需要进行认证和/或授权,从而在判定第一PINE是否需要进行认证和/或授权时,执行如下步骤78;Step 77: If the SMF receives the first NAS message, it determines whether the first PINE needs to be authenticated and/or authorized based on the relevant information of the first NAS message, and then executes the following step 78 when determining whether the first PINE needs to be authenticated and/or authorized;
其中,该第一NAS消息的相关信息包括如下中至少一项:The relevant information of the first NAS message includes at least one of the following:
第一NAS消息中的PDU会话相关信息(例如PDU会话标识、DNN、S-NASSAI);PDU session related information in the first NAS message (e.g. PDU session identifier, DNN, S-NASSAI);
PDU会话相关信息与PIN实例或会话的第一关联信息;First association information between PDU session related information and PIN instance or session;
第一NAS消息中的PIN实例或会话相关信息(例如PIN标识);PIN instance or session related information (e.g. PIN identifier) in the first NAS message;
第一NAS消息中的PDU会话相关信息和PIN业务指示信息(即指示第一NAS消息中的PDU会话相关信息与PIN业务相关); The PDU session related information and the PIN service indication information in the first NAS message (i.e., indicating that the PDU session related information in the first NAS message is related to the PIN service);
PDU会话相关信息与PIN业务的第二关联信息;Second association information between the PDU session related information and the PIN service;
发送第一NAS消息的设备的信息。Information of the device sending the first NAS message.
步骤78:SMF向PEGC发送第一EAP消息,从而由PEGC将第一EAP消息转发给PINE,其中,第一EAP消息用于请求PINE的ID;第一EAP消息可以为EAP请求(EAP Request)中的EAP标识(EAP Identity);Step 78: SMF sends a first EAP message to PEGC, so that PEGC forwards the first EAP message to PINE, wherein the first EAP message is used to request the ID of PINE; the first EAP message may be an EAP identity in an EAP request (EAP Request);
步骤79:PINE向PEGC发送第二EAP消息,从而由PEGC将第一EAP消息转发给SMF,其中,第二EAP消息携带有PINE的ID;第二EAP消息可以为EAP响应(EAP Response)中的EAP标识(EAP Identity);Step 79: PINE sends a second EAP message to PEGC, so that PEGC forwards the first EAP message to SMF, wherein the second EAP message carries the ID of PINE; the second EAP message may be an EAP identity in an EAP response (EAP Response);
步骤710:SMF向外部数据网络认证授权中心(AAA)发送第二EAP消息。Step 710: SMF sends a second EAP message to the external data network authentication authority (AAA).
步骤711:AAA与PINE间通过SMF、UPF、以及PEGC交互EAP消息(例如EAP Request、EAP Response)完成认证和/或授权过程。Step 711: AAA and PINE exchange EAP messages (such as EAP Request, EAP Response) through SMF, UPF, and PEGC to complete the authentication and/or authorization process.
步骤712:如果认证和/或授权成功,AAA(例如通过UPF)向SMF发送EAP成功(EAP-Success消息)。Step 712: If the authentication and/or authorization is successful, AAA (eg, through UPF) sends an EAP success (EAP-Success message) to SMF.
步骤713:如果SMF收到EAP-Success消息,则SMF向PEGC发送PDU会话建立确认(PDU Session Establishment Ack)或PDU会话修改确认(PDU Session Modification Ack),否则发送PDU会话建立拒绝(PDU Session Establishment Reject)或PDU会话修改拒绝(PDU Session Modification Reject)。Step 713: If SMF receives the EAP-Success message, SMF sends a PDU session establishment acknowledgment (PDU Session Establishment Ack) or a PDU session modification acknowledgment (PDU Session Modification Ack) to PEGC, otherwise it sends a PDU session establishment reject (PDU Session Establishment Reject) or a PDU session modification reject (PDU Session Modification Reject).
其中,上述PDU Session Establishment Ack或PDU Session Modification Ack中还可以携带认证和/或授权成功的指示、认证和/或授权成功的原因值中的至少一项;Wherein, the above-mentioned PDU Session Establishment Ack or PDU Session Modification Ack may also carry at least one of the indication of successful authentication and/or authorization and the reason value of successful authentication and/or authorization;
上述PDU Session Establishment Reject或PDU Session Modification Reject中还可以携带认证和/或授权失败的指示、认证和/或授权失败的原因值中的至少一项。The above-mentioned PDU Session Establishment Reject or PDU Session Modification Reject may also carry at least one of the indication of authentication and/or authorization failure and the reason value of authentication and/or authorization failure.
步骤714:如果PEGC收到PDU Session Establishment Ack或PDU Session Modification Ack,则PEGC允许第一PINE连接以访问该PIN,否则PEGC拒绝第一PINE的连接。Step 714: If the PEGC receives a PDU Session Establishment Ack or a PDU Session Modification Ack, the PEGC allows the first PINE to connect to access the PIN, otherwise the PEGC rejects the connection of the first PINE.
步骤715:如果PEGC收到PDU Session Establishment Ack或PDU Session Modification Ack,则PEGC还可以发送第一PINE的IP地址给SMF。Step 715: If PEGC receives PDU Session Establishment Ack or PDU Session Modification Ack, PEGC can also send the IP address of the first PINE to SMF.
步骤716:SMF可以基于收到的第一PINE的IP地址对PIN的通信配置(包含报文过滤规则)进行授权,比如接受与第一PINE相关的报文过滤规则(即接受含该PINE IP地址的报文过滤规则)。Step 716: SMF can authorize the communication configuration of the PIN (including message filtering rules) based on the received IP address of the first PINE, such as accepting the message filtering rules related to the first PINE (i.e., accepting the message filtering rules containing the IP address of the PINE).
其中,在该实施方式中,SMF也可以用AMF代替,UPF也可以用认证服务功能(AUSF)代替;或者改实施方式中也可以不涉及UPF或AUSF。In this implementation, SMF may be replaced by AMF, and UPF may be replaced by authentication service function (AUSF); or UPF or AUSF may not be involved in this implementation.
实施方式二:如图8所示,包括如下步骤81至811。Implementation method 2: as shown in FIG8 , includes the following steps 81 to 811 .
步骤81:PEGC建立PDU Session,发起PDU会话建立请求(PDU Session Establishment Request)。Step 81: PEGC establishes a PDU Session and initiates a PDU session establishment request (PDU Session Establishment Request).
步骤82:SMF返回PDU会话建立确认(PDU Session Establishment Ack)消息,携带第五指示信息,第一操作包括鉴权、认证、授权中的至少一项。 Step 82: SMF returns a PDU Session Establishment Ack message, carrying the fifth indication information, and the first operation includes at least one of authentication, certification, and authorization.
其中,所述第五指示信息用于指示以下至少一项:The fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过SMF所在的移动网络的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the mobile network where the SMF is located;
允许或不允许通过SMF所在的移动网络的用户面执行所述第一操作。Allow or not allow the first operation to be performed through the user plane of the mobile network where the SMF is located.
步骤83:第一PINE连接PEGC以访问该PIN(例如第一PINE给PEGC发送连接请求)。Step 83: The first PINE connects to the PEGC to access the PIN (eg, the first PINE sends a connection request to the PEGC).
步骤84:PEMC创建一个PIN,可以通知AF创建了一个PIN。PEMC可以向PEGC发送通信请求(Communication Request)消息,指示PEGC某个或某些PINE需要进行第一操作。Step 84: PEMC creates a PIN and can notify AF that a PIN has been created. PEMC can send a Communication Request message to PEGC to indicate that one or more PINEs of PEGC need to perform the first operation.
其中,若前述步骤82中的第五指示信息指示不允许第一操作,或不允许通过SMF所在的移动网络的控制面执行一操作,或者不允许通过SMF所在的移动网络的用户面执行第一操作,则后续步骤停止执行,否则执行后续步骤。Among them, if the fifth indication information in the aforementioned step 82 indicates that the first operation is not allowed, or an operation is not allowed to be performed through the control plane of the mobile network where the SMF is located, or the first operation is not allowed to be performed through the user plane of the mobile network where the SMF is located, then the subsequent steps stop executing, otherwise the subsequent steps are executed.
步骤85:PEGC向SMF发送PDU Session Modification Request,可以携带第一指示信息、第一PINE的信息、PEGC的信息、AAA的信息中的至少一项,第一指示信息用于指示进行第一操作。Step 85: PEGC sends a PDU Session Modification Request to SMF, which may carry at least one of the first indication information, the first PINE information, the PEGC information, and the AAA information. The first indication information is used to indicate the first operation.
步骤86:SMF如果允许第一操作,或允许步骤85中的AAA执行第一操作,或允许步骤85中的PEGC或第一PINE执行第一操作,或允许步骤85中的PEGC或第一PINE与AAA执行第一操作,则返回PDU Session Modification Ack消息,否则返回PDU Session Modification Reject消息,可以携带用于指示不允许第一操作的指示信息。Step 86: If the SMF allows the first operation, or allows the AAA in step 85 to perform the first operation, or allows the PEGC or the first PINE in step 85 to perform the first operation, or allows the PEGC or the first PINE in step 85 and the AAA to perform the first operation, it returns a PDU Session Modification Ack message; otherwise, it returns a PDU Session Modification Reject message, which may carry indication information for indicating that the first operation is not allowed.
步骤87:如果第一操作被允许,PEGC可以向第一PINE发送第一EAP消息请求第一PINE的ID;第一EAP消息可以为EAP请求(EAP Request)中的EAP标识(EAP Identity);Step 87: If the first operation is allowed, the PEGC may send a first EAP message to the first PINE to request the ID of the first PINE; the first EAP message may be an EAP identity in an EAP request (EAP Request);
步骤88:PINE发送第二EAP消息给PEGC,携带第一PINE的ID;第二EAP消息可以为EAP响应(EAP Response)中的EAP标识(EAP Identity)。Step 88: PINE sends a second EAP message to PEGC, carrying the ID of the first PINE; the second EAP message can be the EAP identity (EAP Identity) in the EAP response (EAP Response).
步骤89:PEGC通过5G系统的用户面向外部数据网络认证授权中心(AAA)发送第一PINE的ID。Step 89: PEGC sends the ID of the first PINE to the external data network authentication authority (AAA) through the user of the 5G system.
步骤810:AAA与PINE间通过PEGC交互EAP消息(例如EAP Request、EAP Response)执行第一操作。Step 810: AAA and PINE exchange EAP messages (such as EAP Request and EAP Response) through PEGC to perform the first operation.
步骤811:如果第一操作成功,AAA向PEGC发送EAP-Success消息,否则发EAP失败(送EAP-Failure)消息。如果PEGC收到EAP-Success,则允许第一PINE连接以访问该PIN,否则PEGC拒绝第一PINE的连接。Step 811: If the first operation is successful, AAA sends an EAP-Success message to PEGC, otherwise it sends an EAP failure (send EAP-Failure) message. If PEGC receives EAP-Success, it allows the first PINE to connect to access the PIN, otherwise PEGC rejects the connection of the first PINE.
其中,在该实施方式中,SMF也可以用AMF代替,UPF也可以用认证服务功能(AUSF)代替;或者改实施方式中也可以不涉及UPF或AUSF。In this implementation, SMF may be replaced by AMF, and UPF may be replaced by authentication service function (AUSF); or UPF or AUSF may not be involved in this implementation.
需要说明的是,图7和图8中只标出了各个步骤相关的主要内容或相关消息,具体可参见前文中各个步骤的详细说明。 It should be noted that only the main contents or related messages related to each step are marked in FIG. 7 and FIG. 8 . For details, please refer to the detailed description of each step in the previous text.
此外,上述实施方式一和实施方式二只是本申请实施例的两个实现方式,即本申请实施例的操作执行方法的具体实现方式并不局限于此,还可以为前述内容的各种可能组合。In addition, the above-mentioned Implementation Mode 1 and Implementation Mode 2 are only two implementation modes of the embodiment of the present application, that is, the specific implementation mode of the operation execution method of the embodiment of the present application is not limited thereto, and can also be various possible combinations of the aforementioned contents.
本申请实施例提供的操作执行方法,执行主体可以为操作执行装置。本申请实施例中以操作执行装置执行操作执行方法为例,说明本申请实施例提供的操作执行装置。The operation execution method provided in the embodiment of the present application can be executed by an operation execution device. In the embodiment of the present application, the operation execution device provided in the embodiment of the present application is described by taking the operation execution method executed by the operation execution device as an example.
第六方面,本申请实施例提供了一种操作执行装置,应用于第一终端,如图9所示,该操作执行装置90包括以下模块:In a sixth aspect, an embodiment of the present application provides an operation execution device, which is applied to a first terminal. As shown in FIG9 , the operation execution device 90 includes the following modules:
第一发送模块901,用于向网络侧发送第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;A first sending module 901 is configured to send a first non-access stratum NAS message and/or first indication information to a network side, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
第一接收模块902,用于接收所述网络侧发送的第五指示信息,其中,所述第五指示信息用于指示以下至少一项:The first receiving module 902 is configured to receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the network side;
允许或不允许通过所述网络侧的用户面执行所述第一操作。。Allow or not allow the first operation to be performed through the user plane of the network side.
可选地,所述装置还包括:Optionally, the device further comprises:
第一建立模块,用于在所述第一发送模块901向网络侧发送第一非接入层NAS消息和/或第一指示信息之前,与所述网络侧交互以建立协议数据单元PDU会话。The first establishing module is used to interact with the network side to establish a protocol data unit PDU session before the first sending module 901 sends the first non-access layer NAS message and/or the first indication information to the network side.
可选地,所述第一非接入层NAS消息为PDU会话修改请求。Optionally, the first non-access layer NAS message is a PDU session modification request.
可选地,所述第一指示信息包括如下中至少一项:Optionally, the first indication information includes at least one of the following:
用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
所述第一终端的信息;information of the first terminal;
第二网络功能的信息,其中,所述第二网络功能用于执行所述第一操作。Information about a second network function, wherein the second network function is used to perform the first operation.
可选地,所述第一发送模块901包括:Optionally, the first sending module 901 includes:
第一发送子模块,用于在所述第一终端与第一设备之间建立连接之时或之后,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。The first sending submodule is used for, when or after the connection between the first terminal and the first device is established, for the first terminal to send the first non-access layer NAS message and/or the first indication information to the network side.
可选地,所述第一发送子模块具体用于:Optionally, the first sending submodule is specifically used for:
接收所述第一设备发送的第一消息,或接收第二终端发送的第六消息;receiving a first message sent by the first device, or receiving a sixth message sent by the second terminal;
响应于所述第一消息或所述第六消息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;In response to the first message or the sixth message, sending the first non-access stratum NAS message and/or the first indication information to the network side;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的个人物联网PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the personal Internet of Things PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第六消息用于指示所述第一终端或所述第一设备与所述第二网络功能通信;The sixth message is used to instruct the first terminal or the first device to communicate with the second network function;
所述第二网络功能用于执行所述第一操作。 The second network function is used to perform the first operation.
可选地,所述第一指示信息包括如下中至少一项:Optionally, the first indication information includes at least one of the following:
用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
所述第一设备的信息;information of the first device;
所述第一终端的信息;information of the first terminal;
第二网络功能的信息,所述第二网络功能用于执行所述第一操作。information of a second network function, where the second network function is used to perform the first operation.
可选地,所述装置还包括:Optionally, the device further comprises:
第三接收模块,用于在所述第一发送模块901向网络侧发送第一非接入层NAS消息和/或第一指示信息之后,接收所述网络侧发送的第二指示信息,其中,所述第二指示信息用于指示所述第一操作的结果:A third receiving module is configured to receive second indication information sent by the network side after the first sending module 901 sends the first non-access layer NAS message and/or the first indication information to the network side, wherein the second indication information is used to indicate a result of the first operation:
第三处理模块,用于根据所述第二指示信息,执行以下至少一项:The third processing module is configured to perform at least one of the following according to the second indication information:
允许或拒绝所述第一终端接收的第一设备发送的第一消息;Allow or deny the first message sent by the first device to be received by the first terminal;
允许或拒绝对所述第一设备的数据的处理;Allow or deny processing of data of the first device;
允许或保留或释放所述第一终端与所述第一设备的连接;Allow, retain or release the connection between the first terminal and the first device;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可选地,所述装置还包括:Optionally, the device further comprises:
第四处理模块,用于根据所述第五指示信息,执行以下至少一项:The fourth processing module is configured to perform at least one of the following according to the fifth indication information:
执行或停止执行所述第一操作;Execute or stop executing the first operation;
发送或停止发送第六指示信息给第二网络功能,所述第六指示信息用于指示所述第二网络功能执行所述第一操作;Sending or stopping sending sixth indication information to the second network function, where the sixth indication information is used to instruct the second network function to perform the first operation;
发送或停止发送第四消息给所述第二网络功能,所述第四消息为执行所述第一操作涉及的消息;sending or stopping sending a fourth message to the second network function, where the fourth message is a message involved in performing the first operation;
接收或停止接收来自所述第二网络功能的第五消息,所述第五消息为执行所述第一操作涉及的消息;receiving or stopping receiving a fifth message from the second network function, where the fifth message is a message related to performing the first operation;
允许或拒绝所述第一终端接收到的第一设备发送的第一消息;Allow or reject a first message sent by a first device and received by the first terminal;
允许或拒绝对所述第一设备的数据的处理;Allow or deny processing of data of the first device;
允许或保留或释放所述第一终端与所述第一设备的连接;Allow, retain or release the connection between the first terminal and the first device;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与所述第二网络功能通信。Establish a connection between the first device and the first terminal, access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
可选地,所述第一接收模块902具体用于:Optionally, the first receiving module 902 is specifically configured to:
接收所述网络侧发送的第二NAS消息,其中,所述第二NAS消息中携带有所述第二指示信息。 A second NAS message sent by the network side is received, wherein the second NAS message carries the second indication information.
可选地,所述第二指示信息满足以下至少一项:Optionally, the second indication information satisfies at least one of the following:
通过所述第二NAS消息的标识或名称指示所述第一操作的结果;Indicating a result of the first operation by an identifier or a name of the second NAS message;
通过原因值指示所述第一操作的结果。The result of the first operation is indicated by a cause value.
可选地,所述通过所述第二NAS消息的标识或名称指示所述第一操作的结果,包括以下至少一项:Optionally, the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
通过PDU会话修改确认消息或PDU会话建立确认消息指示所述第一操作成功;Indicating that the first operation is successful through a PDU session modification confirmation message or a PDU session establishment confirmation message;
通过PDU会话修改拒绝消息或PDU会话建立拒绝消息指示所述第一操作失败。The failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
可选地,所述通过原因值指示所述第一操作的结果,包括以下至少一项指示:Optionally, the result of the first operation indicated by the reason value includes at least one of the following indications:
失败原因值和/或失败指示,用于指示所述第一操作失败;a failure reason value and/or a failure indication, used to indicate that the first operation failed;
成功原因值和/或成功指示,用于指示所述第一操作成功;A success reason value and/or a success indication, used to indicate that the first operation is successful;
在所述第二NAS消息中未包括所述失败原因值和/或失败指示的情况下,指示所述第一操作成功;In a case where the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful;
在所述第二NAS消息中未包括所述成功原因值和/或成功指示的情况下,指示所述第一操作失败。In a case where the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
可选地,所述装置还包括如下中至少一个模块:Optionally, the device further comprises at least one of the following modules:
第一转发模块,用于接收来自所述网络侧的第二消息,将所述第二消息发送给所述第一设备;A first forwarding module, configured to receive a second message from the network side, and send the second message to the first device;
第二转发模块,用于接收来自所述第一设备的第三消息,将所述第三消息发送给所述网络侧;A second forwarding module, configured to receive a third message from the first device, and send the third message to the network side;
其中,所述第二消息和所述第三消息分别为执行所述第一操作涉及的消息。The second message and the third message are respectively messages involved in executing the first operation.
可选地,所述第二消息为可扩展认证协议EAP消息,所述第三消息为EAP消息。Optionally, the second message is an Extensible Authentication Protocol (EAP) message, and the third message is an EAP message.
可选地,所述第一非接入层NAS消息为PDU会话修改请求或PDU会话建立请求。Optionally, the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
可选地,所述装置还包括:Optionally, the device further comprises:
第四接收模块,用于接收所述网络侧发送的规则信息;A fourth receiving module, used to receive the rule information sent by the network side;
所述第一发送模块包括:The first sending module includes:
第二发送子模块,用于根据所述规则信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。The second sending submodule is used to send the first non-access layer NAS message and/or the first indication information to the network side according to the rule information.
可选地,所述规则信息用于指示以下至少一项:Optionally, the rule information is used to indicate at least one of the following:
所述第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
至少一个第一目标设备需要所述第一操作或不需要所述第一操作。At least one first target device requires the first operation or does not require the first operation.
可选地,所述第二发送子模块具体用于执行以下至少一项:Optionally, the second sending submodule is specifically configured to perform at least one of the following:
在所述规则信息指示第一设备需要所述第一操作的情况下,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;When the rule information indicates that the first device needs the first operation, sending the first non-access stratum NAS message and/or the first indication information to the network side;
在所述规则信息指示所述第一操作需要应用于所述目标PIN,且满足以下至少一项条件的情况下,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息: When the rule information indicates that the first operation needs to be applied to the target PIN and at least one of the following conditions is met, sending the first non-access stratum NAS message and/or the first indication information to the network side:
所述第一非接入层NAS消息和/或所述第一指示信息与所述目标PIN相关;The first non-access stratum NAS message and/or the first indication information are related to the target PIN;
所述第一终端与第一设备之间的连接与所述目标PIN相关;The connection between the first terminal and the first device is associated with the target PIN;
所述第一终端接收到的所述第一设备发送的第一消息与所述目标PIN相关;The first message sent by the first device and received by the first terminal is related to the target PIN;
所述第一设备与所述目标PIN相关;the first device being associated with the target PIN;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可选地,所述装置还包括:Optionally, the device further comprises:
第五接收模块,用于接收第二终端发送的配置信息;A fifth receiving module, configured to receive configuration information sent by the second terminal;
所述第一发送模块901包括:The first sending module 901 includes:
第三发送子模块,用于所述第一终端根据所述配置信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。The third sending submodule is used for the first terminal to send the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information.
可选地,所述配置信息用于指示以下至少一项:Optionally, the configuration information is used to indicate at least one of the following:
所述第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
至少一个第二目标设备需要所述第一操作或不需要所述第一操作。At least one second target device requires the first operation or does not require the first operation.
可选地,所述第三发送子模块具体用于执行以下至少一项:Optionally, the third sending submodule is specifically configured to perform at least one of the following:
在所述配置信息指示第一设备需要所述第一操作的情况下,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;When the configuration information indicates that the first device needs the first operation, sending the first non-access stratum NAS message and/or the first indication information to the network side;
在所述配置信息指示所述第一操作需要应用于所述目标PIN,且满足以下至少一项条件的情况下,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息:When the configuration information indicates that the first operation needs to be applied to the target PIN and at least one of the following conditions is met, sending the first non-access stratum NAS message and/or the first indication information to the network side:
所述第一非接入层NAS消息和/或所述第一指示信息与所述目标PIN相关;The first non-access stratum NAS message and/or the first indication information are related to the target PIN;
所述第一终端与第一设备之间的连接与所述目标PIN相关;The connection between the first terminal and the first device is associated with the target PIN;
所述第一终端接收到的所述第一设备发送的第一消息与所述目标PIN相关;The first message sent by the first device and received by the first terminal is related to the target PIN;
所述第一设备与所述目标PIN相关;the first device being associated with the target PIN;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可选地,所述装置还包括:Optionally, the device further comprises:
第五发送模块,用于在所述第二指示信息指示所述第一操作成功的情况下,向所述网络侧发送所述第一设备的信息。A fifth sending module is used to send information of the first device to the network side when the second indication information indicates that the first operation is successful.
可选地,所述第一终端为具有网关能力的终端。Optionally, the first terminal is a terminal with gateway capability.
本申请实施例中的操作执行装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,示例性的 该,终端可以包括但不限于上述所列举的终端11的类型,本申请实施例不作具体限定。The operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, for example The terminal may include but is not limited to the types of the terminal 11 listed above, and the embodiment of the present application does not make any specific limitation.
本申请实施例提供的操作执行装置能够实现图2的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 2 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
第七方面,本申请实施例提供了一种操作执行装置,应用于第一网络功能,如图10所示,该操作执行装置100包括以下模块:In a seventh aspect, an embodiment of the present application provides an operation execution device, which is applied to a first network function. As shown in FIG10 , the operation execution device 100 includes the following modules:
第二发送模块1001,用于向第一终端发送第五指示信息;The second sending module 1001 is used to send fifth indication information to the first terminal;
和/或,and / or,
第二接收模块1002,用于接收所述第一终端发送的第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示所述第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;The second receiving module 1002 is configured to receive a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
第一处理模块1003,用于响应于所述第一非接入层NAS消息和/或所述第一指示信息,执行如下至少一项:The first processing module 1003 is configured to, in response to the first non-access stratum NAS message and/or the first indication information, perform at least one of the following:
向所述第一终端发送第五指示信息;Sending fifth indication information to the first terminal;
指示第二网络功能和所述第一终端进行所述第一操作;instructing a second network function and the first terminal to perform the first operation;
其中,所述第五指示信息用于指示以下至少一项:The fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过移动网络的控制面执行所述第一操作;allowing or not allowing the first operation to be performed through a control plane of the mobile network;
允许或不允许通过移动网络的用户面执行所述第一操作。The first operation is allowed or not allowed to be performed through a user plane of the mobile network.
可选地,所述装置还包括:Optionally, the device further comprises:
第六接收模块,用于在所述第一网络功能指示第二网络功能和所述第一终端进行所述第一操作的情况下,接收所述第二网络功能发送的第三指示信息,其中,所述第三指示信息用于指示所述第一操作的结果;a sixth receiving module, configured to receive third indication information sent by the second network function when the first network function instructs the second network function and the first terminal to perform the first operation, wherein the third indication information is used to indicate a result of the first operation;
第六发送模块,用于根据所述第三指示信息,向所述第一终端发送第二指示信息,所述第二指示信息用于指示所述第一操作的结果。The sixth sending module is used to send second indication information to the first terminal according to the third indication information, where the second indication information is used to indicate a result of the first operation.
可选地,所述装置还包括:Optionally, the device further comprises:
第二建立模块,用于在所述第一网络功能接收第一终端发送的第一非接入层NAS消息和/或第一指示信息之前,与所述第一终端交互以建立协议数据单元PDU会话。The second establishing module is used to interact with the first terminal to establish a protocol data unit PDU session before the first network function receives the first non-access layer NAS message and/or the first indication information sent by the first terminal.
可选地,所述第一非接入层NAS消息为PDU会话修改请求。Optionally, the first non-access layer NAS message is a PDU session modification request.
可选地,所述第一指示信息包括如下中至少一项:Optionally, the first indication information includes at least one of the following:
用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
所述第一终端的信息;information of the first terminal;
所述第二网络功能的信息。information of the second network function.
可选地,所述第一指示信息包括如下中至少一项:Optionally, the first indication information includes at least one of the following:
用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
第一设备的信息,其中,所述第一设备为需要通过所述第一终端访问个人物联网PIN 或所述第一网络功能所在网络的设备;Information of the first device, wherein the first device needs to access the personal IoT PIN through the first terminal or a device in the network where the first network function is located;
所述第一终端的信息;information of the first terminal;
所述第二网络功能的信息。information of the second network function.
可选地,所述第一非接入层NAS消息为PDU会话修改请求或PDU会话建立请求。Optionally, the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
可选地,所述第六发送模块具体用于:Optionally, the sixth sending module is specifically configured to:
根据所述第三指示信息,向所述第一终端发送第二NAS消息,其中,所述第二NAS消息中携带有所述第二指示信息。According to the third indication information, a second NAS message is sent to the first terminal, wherein the second NAS message carries the second indication information.
可选地,所述第二指示信息满足以下至少一项:Optionally, the second indication information satisfies at least one of the following:
通过所述第二NAS消息的标识或名称指示所述第一操作的结果;indicating a result of the first operation by an identifier or a name of the second NAS message;
通过原因值指示所述第一操作的结果。The result of the first operation is indicated by a cause value.
可选地,所述通过所述第二NAS消息的标识或名称指示所述第一操作的结果,包括以下至少一项:Optionally, the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
通过PDU会话修改确认或PDU会话建立确认指示所述第一操作的结果成功;Indicating a successful result of the first operation through a PDU session modification confirmation or a PDU session establishment confirmation;
通过PDU会话修改拒绝消息或PDU会话建立拒绝指示所述第一操作失败。The failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
可选地,所述通过原因值指示所述第一操作的结果,包括以下至少一项指示:Optionally, the result of the first operation indicated by the reason value includes at least one of the following indications:
失败原因值和/或失败指示,用于指示所述第一操作失败;a failure reason value and/or a failure indication, used to indicate that the first operation failed;
成功原因值和/或成功指示,用于指示所述第一操作成功;A success reason value and/or a success indication, used to indicate that the first operation is successful;
在所述第二NAS消息中未包括所述失败原因值和/或失败指示的情况下,指示所述第一操作成功;In a case where the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful;
在所述第二NAS消息中未包括所述成功原因值和/或成功指示的情况下,指示所述第一操作失败。In a case where the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
可选地,所述第一处理模块响应于所述第一非接入层NAS消息,指示第二网络功能和所述第一终端进行所述第一操作时,具体用于执行如下至少一项:Optionally, when the first processing module instructs the second network function and the first terminal to perform the first operation in response to the first non-access layer NAS message, the first processing module is specifically configured to perform at least one of the following:
基于所述第一非接入层NAS消息中的PDU会话相关信息,指示所述第二网络功能和所述第一终端进行所述第一操作;Instructing the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message;
基于所述第一非接入层NAS消息中的PDU会话相关信息,以及PDU会话相关信息与PIN实例或会话的第一关联信息,指示所述第二网络功能和所述第一终端进行所述第一操作;Instructing the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message and the first association information between the PDU session related information and the PIN instance or session;
基于所述第一非接入层NAS消息中的PIN实例或会话相关信息,指示所述第二网络功能和所述第一终端进行所述第一操作;Instructing the second network function and the first terminal to perform the first operation based on the PIN instance or session related information in the first non-access stratum NAS message;
基于所述第一非接入层NAS消息中的PDU会话相关信息和PIN业务指示信息,指示所述第二网络功能和所述第一终端进行所述第一操作;Instructing the second network function and the first terminal to perform the first operation based on the PDU session related information and the PIN service indication information in the first non-access layer NAS message;
基于所述第一非接入层NAS消息中的PDU会话相关信息,以及PDU会话相关信息与PIN业务的第二关联信息,指示所述第二网络功能和所述第一终端进行所述第一操作。Based on the PDU session related information in the first non-access layer NAS message, and the second association information between the PDU session related information and the PIN service, the second network function and the first terminal are instructed to perform the first operation.
可选地,所述装置还包括: Optionally, the device further comprises:
第五处理模块,用于从第三网络功能获知以下至少之一:The fifth processing module is configured to obtain at least one of the following from the third network function:
所述第一关联信息;the first associated information;
所述第二关联信息。The second associated information.
可选地,所述装置还包括:Optionally, the device further comprises:
第七接收模块,用于在所述第二指示信息指示所述第一操作成功的情况下,接收所述第一终端发送的第一设备的信息;A seventh receiving module, configured to receive information about the first device sent by the first terminal when the second indication information indicates that the first operation is successful;
其中,所述第一设备为需要通过所述第一终端访问PIN或所述第一网络功能所在网络的设备。The first device is a device that needs to access the PIN or the network where the first network function is located through the first terminal.
可选地,所述装置还包括:Optionally, the device further comprises:
配置模块,用于在所述第一网络功能获知报文过滤规则,且所述报文过滤规则与所述第一设备相关的情况下,所述第一网络功能使用所述报文过滤规则配置第四网络功能。A configuration module is used for, when the first network function learns a message filtering rule and the message filtering rule is related to the first device, the first network function uses the message filtering rule to configure a fourth network function.
本申请实施例中的操作执行装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是网络功能。示例性的,该网络功能可以包括但不限于上述所列举的网络功能12的类型,本申请实施例不作具体限定。The operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a network function. Exemplarily, the network function can include but is not limited to the types of network functions 12 listed above, and the embodiment of the present application does not specifically limit this.
本申请实施例提供的操作执行装置能够实现图3的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 3 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
第八方面,本申请实施例提供了一种操作执行装置,应用于第三网络功能,如图11所示,该操作执行装置110包括以下模块:In an eighth aspect, an embodiment of the present application provides an operation execution device, which is applied to a third network function. As shown in FIG11 , the operation execution device 110 includes the following modules:
第二处理模块1101,用于执行第二操作;The second processing module 1101 is used to perform a second operation;
其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
向第一终端发送个人物联网PIN的规则信息;Sending rule information of the personal Internet of Things PIN to the first terminal;
向第一网络功能发送数据协议单元PDU会话配置信息。Send data protocol unit PDU session configuration information to the first network function.
可选地,所述规则信息用于指示以下至少一项:Optionally, the rule information is used to indicate at least one of the following:
第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
至少一个第一目标设备需要所述第一操作或不需要所述第一操作;At least one first target device requires the first operation or does not require the first operation;
其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
所述第一目标设备为需要通过所述第一终端访问个人物联网PIN或所述第三网络功能所在移动网络的设备。The first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
可选地,所述PDU会话配置信息包括以下至少一项:Optionally, the PDU session configuration information includes at least one of the following:
PDU会话相关信息与PIN实例或会话的第一关联信息;First association information between PDU session related information and PIN instance or session;
PDU会话相关信息与PIN业务的第二关联信息。The second association information between the PDU session related information and the PIN service.
可选地,所述装置还包括:Optionally, the device further comprises:
第六处理模块,用于在所述第二处理模块1101执行所述第二操作之前,获知第四指示信息,其中,所述第四指示信息用于指示所述第三网络功能执行所述第二操作; a sixth processing module, configured to obtain fourth indication information before the second processing module 1101 performs the second operation, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
所述第二处理模块1101具体用于:The second processing module 1101 is specifically used for:
根据所述第四指示信息执行所述第二操作。The second operation is performed according to the fourth indication information.
可选地,所述第六处理模块具体用于:Optionally, the sixth processing module is specifically configured to:
所述第三网络功能接收第五网络功能发送的所述第四指示信息。The third network function receives the fourth indication information sent by the fifth network function.
本申请实施例中的操作执行装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是网络功能,示例性的,该网络功能可以包括但不限于上述所列举的网络功能12的类型,本申请实施例不作具体限定。The operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a network function, and illustratively, the network function can include but is not limited to the types of network functions 12 listed above, which are not specifically limited in the embodiment of the present application.
本申请实施例提供的操作执行装置能够实现图4的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 4 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
第九方面,本申请实施例提供了一种操作执行装置,应用于第二终端,如图12所示,该操作执行装置120包括以下模块:In a ninth aspect, an embodiment of the present application provides an operation execution device, which is applied to a second terminal. As shown in FIG12 , the operation execution device 120 includes the following modules:
第三发送模块1201,用于向个人物联网PIN中的第一终端发送配置信息。The third sending module 1201 is used to send configuration information to the first terminal in the personal Internet of Things PIN.
述第二终端设备创建的个人物联网PIN中的第一终端发送配置信息。The first terminal in the personal Internet of Things PIN created by the second terminal device sends configuration information.
可选地,所述配置信息用于指示以下至少一项:Optionally, the configuration information is used to indicate at least one of the following:
第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
至少一个第二目标设备需要所述第一操作或不需要所述第一操作;At least one second target device requires the first operation or does not require the first operation;
其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
所述第二目标设备为需要通过所述第一终端访问所述个人物联网PIN或移动网络的设备。The second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
本申请实施例中的操作执行装置可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,示例性的,该终端可以包括但不限于上述所列举的终端11的类型,本申请实施例不作具体限定。The operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, and illustratively, the terminal can include but is not limited to the types of the terminal 11 listed above, and the embodiment of the present application does not specifically limit it.
本申请实施例提供的操作执行装置能够实现图5的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 5 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
第十方面,本申请实施例提供了一种操作执行装置,应用于第五网络功能,如图13所示,该操作执行装置130包括以下模块:In a tenth aspect, an embodiment of the present application provides an operation execution device, which is applied to the fifth network function. As shown in FIG. 13 , the operation execution device 130 includes the following modules:
第四发送模块1301,用于向第三网络功能发送第四指示信息,其中,所述第四指示信息用于指示所述第三网络功能执行第二操作;The fourth sending module 1301 is configured to send fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform a second operation;
其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
所述第三网络功能向第一终端发送规则信息;The third network function sends rule information to the first terminal;
所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
可选地,所述规则信息用于指示以下至少一项:Optionally, the rule information is used to indicate at least one of the following:
第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
至少一个第一目标设备需要所述第一操作或不需要所述第一操作; At least one first target device requires the first operation or does not require the first operation;
其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
所述第一目标设备为需要通过所述第一终端访问个人物联网PIN或所述第三网络功能所在移动网络的设备。The first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
可选地,所述PDU会话配置信息包括以下至少一项:Optionally, the PDU session configuration information includes at least one of the following:
PDU会话相关信息与PIN实例或会话的第一关联信息;First association information between PDU session related information and PIN instance or session;
PDU会话相关信息与PIN业务的第二关联信息。The second association information between the PDU session related information and the PIN service.
本申请实施例中的操作执行方法可以是电子设备,例如具有操作系统的电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是网络功能,示例性的,该网络功能可以包括但不限于上述所列举的网络功能12的类型,本申请实施例不作具体限定。The operation execution method in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a network function, and illustratively, the network function can include but is not limited to the types of network functions 12 listed above, which are not specifically limited in the embodiment of the present application.
本申请实施例提供的操作执行装置能够实现图6的方法实施例实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。The operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 6 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
可选地,如图14所示,本申请实施例还提供一种通信设备1400,包括处理器1401和存储器1402,存储器1402上存储有可在所述处理器1401上运行的程序或指令,例如,该通信设备1400为终端时,该程序或指令被处理器1401执行时实现上述操作执行方法实施例的各个步骤,且能达到相同的技术效果。该通信设备1400为网络功能时,该程序或指令被处理器1401执行时实现上述操作执行方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。Optionally, as shown in FIG14, the embodiment of the present application further provides a communication device 1400, including a processor 1401 and a memory 1402, the memory 1402 stores a program or instruction that can be run on the processor 1401, for example, when the communication device 1400 is a terminal, the program or instruction is executed by the processor 1401 to implement the various steps of the above-mentioned operation execution method embodiment, and can achieve the same technical effect. When the communication device 1400 is a network function, the program or instruction is executed by the processor 1401 to implement the various steps of the above-mentioned operation execution method embodiment, and can achieve the same technical effect, to avoid repetition, it will not be repeated here.
本申请实施例还提供一种终端,如图14所示,为实现本申请实施例的一种终端的硬件结构示意图。The embodiment of the present application also provides a terminal, as shown in FIG14 , which is a schematic diagram of the hardware structure of a terminal for implementing the embodiment of the present application.
该终端1400包括但不限于:射频单元1401、网络模块1402、音频输出单元1403、输入单元1404、传感器1405、显示单元1406、用户输入单元1407、接口单元1408、存储器1409以及处理器1410等中的至少部分部件。The terminal 1400 includes but is not limited to: a radio frequency unit 1401, a network module 1402, an audio output unit 1403, an input unit 1404, a sensor 1405, a display unit 1406, a user input unit 1407, an interface unit 1408, a memory 1409 and at least some of the components of the processor 1410.
本领域技术人员可以理解,终端1400还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器1410逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。图14中示出的终端结构并不构成对终端的限定,终端可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。Those skilled in the art will appreciate that the terminal 1400 may also include a power source (such as a battery) for supplying power to each component, and the power source may be logically connected to the processor 1410 through a power management system, so as to implement functions such as charging, discharging, and power consumption management through the power management system. The terminal structure shown in FIG14 does not constitute a limitation on the terminal, and the terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange components differently, which will not be described in detail here.
应理解的是,本申请实施例中,输入单元1404可以包括图形处理单元(Graphics Processing Unit,GPU)14041和麦克风14042,图形处理器14041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元1406可包括显示面板14061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板14061。用户输入单元1407包括触控面板14071以及其他输入设备14072中的至少一种。触控面板14 071,也称为触摸屏。触控面板14071可包括触摸检测装置和触摸控制器两个部分。其他输入设备14072可以包括但不限于物理键盘、功能键 (比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。It should be understood that in the embodiment of the present application, the input unit 1404 may include a graphics processing unit (GPU) 14041 and a microphone 14042, and the graphics processor 14041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 1406 may include a display panel 14061, and the display panel 14061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 1407 includes a touch panel 14071 and at least one of other input devices 14072. The touch panel 14071 is also called a touch screen. The touch panel 14071 may include two parts: a touch detection device and a touch controller. Other input devices 14072 may include, but are not limited to, a physical keyboard, function keys, and the like. (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be repeated here.
本申请实施例中,射频单元1401接收来自网络功能的下行数据后,可以传输给处理器1410进行处理;另外,射频单元1401可以向网络功能发送上行数据。通常,射频单元1401包括但不限于天线、放大器、收发信机、耦合器、低噪声放大器、双工器等。In the embodiment of the present application, after receiving downlink data from the network function, the RF unit 1401 can transmit the data to the processor 1410 for processing; in addition, the RF unit 1401 can send uplink data to the network function. Generally, the RF unit 1401 includes but is not limited to an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.
存储器1409可用于存储软件程序或指令以及各种数据。存储器1409可主要包括存储程序或指令的第一存储区和存储数据的第二存储区,其中,第一存储区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器1409可以包括易失性存储器或非易失性存储器,或者,存储器1409可以包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synch link DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本申请实施例中的存储器1409包括但不限于这些和任意其它适合类型的存储器。The memory 1409 can be used to store software programs or instructions and various data. The memory 1409 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.), etc. In addition, the memory 1409 may include a volatile memory or a non-volatile memory, or the memory 1409 may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM). The memory 1409 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
处理器1410可包括一个或多个处理单元;可选地,处理器1410集成应用处理器和调制解调处理器,其中,应用处理器主要处理涉及操作系统、用户界面和应用程序等的操作,调制解调处理器主要处理无线通信信号,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器1410中。The processor 1410 may include one or more processing units; optionally, the processor 1410 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 1410.
第一方面,当终端1400作为第一终端时,射频单元1401用于向网络侧发送第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;In a first aspect, when the terminal 1400 serves as a first terminal, the radio frequency unit 1401 is used to send a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization;
射频单元1401还用于:接收所述网络侧发送的第五指示信息,其中,所述第五指示信息用于指示以下至少一项:The radio frequency unit 1401 is further used to: receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
允许或不允许所述第一操作;allowing or not allowing the first operation;
允许或不允许通过所述网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the network side;
允许或不允许通过所述网络侧的用户面执行所述第一操作。。Allow or not allow the first operation to be performed through the user plane of the network side.
可选地,在射频单元1401向网络侧发送第一非接入层NAS消息和/或第一指示信息之前,处理器1410用于:与所述网络侧交互以建立协议数据单元PDU会话。Optionally, before the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side, the processor 1410 is used to: interact with the network side to establish a protocol data unit PDU session.
可选地,所述第一非接入层NAS消息为PDU会话修改请求。Optionally, the first non-access layer NAS message is a PDU session modification request.
可选地,所述第一指示信息包括如下中至少一项: Optionally, the first indication information includes at least one of the following:
用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
所述第一终端的信息;information of the first terminal;
第二网络功能的信息,其中,所述第二网络功能用于执行所述第一操作。Information about a second network function, wherein the second network function is used to perform the first operation.
可选地,射频单元1401向网络侧发送第一非接入层NAS消息和/或第一指示信息,具体用于:Optionally, the radio frequency unit 1401 sends a first non-access layer NAS message and/or first indication information to the network side, specifically used for:
在所述第一终端与第一设备之间建立连接之时或之后,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。When or after the connection is established between the first terminal and the first device, the first non-access layer NAS message and/or the first indication information is sent to the network side.
可选地,在所述第一终端与所述第一设备之间建立连接之时或之后,射频单元1401向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,具体用于:Optionally, when or after the connection is established between the first terminal and the first device, the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side, specifically for:
接收所述第一设备发送的第一消息,或接收第二终端发送的第六消息;receiving a first message sent by the first device, or receiving a sixth message sent by the second terminal;
响应于所述第一消息或所述第六消息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;In response to the first message or the sixth message, sending the first non-access stratum NAS message and/or the first indication information to the network side;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的个人物联网PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the personal Internet of Things PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第六消息用于指示所述第一终端或所述第一设备与所述第二网络功能通信;The sixth message is used to instruct the first terminal or the first device to communicate with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可选地,所述第一指示信息包括如下中至少一项:Optionally, the first indication information includes at least one of the following:
用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
所述第一设备的信息;information of the first device;
所述第一终端的信息;information of the first terminal;
第二网络功能的信息,所述第二网络功能用于执行所述第一操作。information of a second network function, where the second network function is used to perform the first operation.
可选地,在射频单元1401向网络侧发送第一非接入层NAS消息和/或第一指示信息之后,还用于:Optionally, after the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side, it is further configured to:
接收所述网络侧发送的第二指示信息,其中,所述第二指示信息用于指示所述第一操作的结果:Receiving second indication information sent by the network side, wherein the second indication information is used to indicate a result of the first operation:
处理器1410还用于:根据所述第二指示信息,执行以下至少一项:The processor 1410 is further configured to: perform at least one of the following according to the second indication information:
允许或拒绝所述第一终端接收的第一设备发送的第一消息;Allow or deny the first message sent by the first device to be received by the first terminal;
允许或拒绝对所述第一设备的数据的处理;Allow or deny processing of data of the first device;
允许或保留或释放所述第一终端与所述第一设备的连接;Allow, retain or release the connection between the first terminal and the first device;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可选地,处理器1410还用于: Optionally, the processor 1410 is further configured to:
根据所述第五指示信息,执行以下至少一项:According to the fifth instruction information, perform at least one of the following:
执行或停止执行所述第一操作;Execute or stop executing the first operation;
发送或停止发送第六指示信息给第二网络功能,所述第六指示信息用于指示所述第二网络功能执行所述第一操作;Sending or stopping sending sixth indication information to the second network function, where the sixth indication information is used to instruct the second network function to perform the first operation;
发送或停止发送第四消息给所述第二网络功能,所述第四消息为执行所述第一操作涉及的消息;sending or stopping sending a fourth message to the second network function, where the fourth message is a message involved in performing the first operation;
接收或停止接收来自所述第二网络功能的第五消息,所述第五消息为执行所述第一操作涉及的消息;receiving or stopping receiving a fifth message from the second network function, where the fifth message is a message related to performing the first operation;
允许或拒绝所述第一终端接收到的第一设备发送的第一消息;Allow or reject a first message sent by a first device and received by the first terminal;
允许或拒绝对所述第一设备的数据的处理;Allow or deny processing of data of the first device;
允许或保留或释放所述第一终端与所述第一设备的连接;Allow, retain or release the connection between the first terminal and the first device;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与所述第二网络功能通信。Establish a connection between the first device and the first terminal, access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
可选地,射频单元1401接收所述网络侧发送的所述第二指示信息,具体用于:Optionally, the radio frequency unit 1401 receives the second indication information sent by the network side, specifically configured to:
接收所述网络侧发送的第二NAS消息,其中,所述第二NAS消息中携带有所述第二指示信息。A second NAS message sent by the network side is received, wherein the second NAS message carries the second indication information.
可选地,所述第二指示信息满足以下至少一项:Optionally, the second indication information satisfies at least one of the following:
通过所述第二NAS消息的标识或名称指示所述第一操作的结果;indicating a result of the first operation by an identifier or a name of the second NAS message;
通过原因值指示所述第一操作的结果。The result of the first operation is indicated by a cause value.
可选地,所述通过所述第二NAS消息的标识或名称指示所述第一操作的结果,包括以下至少一项:Optionally, the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
通过PDU会话修改确认消息或PDU会话建立确认消息指示所述第一操作成功;Indicating that the first operation is successful through a PDU session modification confirmation message or a PDU session establishment confirmation message;
通过PDU会话修改拒绝消息或PDU会话建立拒绝消息指示所述第一操作失败。The failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
可选地,所述通过原因值指示所述第一操作的结果,包括以下至少一项指示:Optionally, the result of the first operation indicated by the reason value includes at least one of the following indications:
失败原因值和/或失败指示,用于指示所述第一操作失败;a failure reason value and/or a failure indication, used to indicate that the first operation failed;
成功原因值和/或成功指示,用于指示所述第一操作成功;A success reason value and/or a success indication, used to indicate that the first operation is successful;
在所述第二NAS消息中未包括所述失败原因值和/或失败指示的情况下,指示所述第一操作成功;In a case where the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful;
在所述第二NAS消息中未包括所述成功原因值和/或成功指示的情况下,指示所述第一操作失败。In a case where the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
可选地,射频单元1401还用于执行如下中至少一项:Optionally, the radio frequency unit 1401 is further configured to perform at least one of the following:
接收来自所述网络侧的第二消息,将所述第二消息发送给所述第一设备;receiving a second message from the network side, and sending the second message to the first device;
接收来自所述第一设备的第三消息,将所述第三消息发送给所述网络侧;receiving a third message from the first device, and sending the third message to the network side;
其中,所述第二消息和所述第三消息分别为执行所述第一操作涉及的消息。 The second message and the third message are respectively messages involved in executing the first operation.
可选地,所述第二消息为可扩展认证协议EAP消息,所述第三消息为EAP消息。Optionally, the second message is an Extensible Authentication Protocol (EAP) message, and the third message is an EAP message.
可选地,所述第一非接入层NAS消息为PDU会话修改请求或PDU会话建立请求。Optionally, the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
可选地,所述射频单元1401还用于:接收所述网络侧发送的规则信息;Optionally, the radio frequency unit 1401 is further used to: receive rule information sent by the network side;
射频单元1401向网络侧发送第一非接入层NAS消息和/或第一指示信息,具体用于:The radio frequency unit 1401 sends a first non-access layer NAS message and/or a first indication information to the network side, specifically used for:
根据所述规则信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。According to the rule information, the first non-access layer NAS message and/or the first indication information are sent to the network side.
可选地,所述规则信息用于指示以下至少一项:Optionally, the rule information is used to indicate at least one of the following:
所述第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
至少一个第一目标设备需要所述第一操作或不需要所述第一操作。At least one first target device requires the first operation or does not require the first operation.
可选地,射频单元1401根据所述规则信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,具体用于执行以下至少一项:Optionally, the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side according to the rule information, specifically configured to perform at least one of the following:
在所述规则信息指示第一设备需要所述第一操作的情况下,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;When the rule information indicates that the first device needs the first operation, sending the first non-access stratum NAS message and/or the first indication information to the network side;
在所述规则信息指示所述第一操作需要应用于所述目标PIN,且满足以下至少一项条件的情况下,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息:When the rule information indicates that the first operation needs to be applied to the target PIN and at least one of the following conditions is met, sending the first non-access stratum NAS message and/or the first indication information to the network side:
所述第一非接入层NAS消息和/或所述第一指示信息与所述目标PIN相关;The first non-access stratum NAS message and/or the first indication information are related to the target PIN;
所述第一终端与第一设备之间的连接与所述目标PIN相关;The connection between the first terminal and the first device is associated with the target PIN;
所述第一终端接收到的所述第一设备发送的第一消息与所述目标PIN相关;The first message sent by the first device and received by the first terminal is related to the target PIN;
所述第一设备与所述目标PIN相关;the first device being associated with the target PIN;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可选地,所述射频单元1401还用于:Optionally, the radio frequency unit 1401 is further configured to:
所述第一终端接收第二终端发送的配置信息;The first terminal receives configuration information sent by the second terminal;
射频单元1401向网络侧发送第一非接入层NAS消息和/或第一指示信息,具体用于:The radio frequency unit 1401 sends a first non-access layer NAS message and/or first indication information to the network side, specifically used for:
根据所述配置信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。According to the configuration information, the first non-access stratum NAS message and/or the first indication information are sent to the network side.
可选地,所述配置信息用于指示以下至少一项:Optionally, the configuration information is used to indicate at least one of the following:
所述第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
至少一个第二目标设备需要所述第一操作或不需要所述第一操作。At least one second target device requires the first operation or does not require the first operation.
可选地,射频单元1401根据所述配置信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,具体用于执行以下至少一项:Optionally, the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information, specifically configured to perform at least one of the following:
在所述配置信息指示第一设备需要所述第一操作的情况下,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息; When the configuration information indicates that the first device needs the first operation, sending the first non-access stratum NAS message and/or the first indication information to the network side;
在所述配置信息指示所述第一操作需要应用于所述目标PIN,且满足以下至少一项条件的情况下,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息:When the configuration information indicates that the first operation needs to be applied to the target PIN and at least one of the following conditions is met, sending the first non-access stratum NAS message and/or the first indication information to the network side:
所述第一非接入层NAS消息和/或所述第一指示信息与所述目标PIN相关;The first non-access stratum NAS message and/or the first indication information are related to the target PIN;
所述第一终端与第一设备之间的连接与所述目标PIN相关;The connection between the first terminal and the first device is associated with the target PIN;
所述第一终端接收到的所述第一设备发送的第一消息与所述目标PIN相关;The first message sent by the first device and received by the first terminal is related to the target PIN;
所述第一设备与所述目标PIN相关;the first device being associated with the target PIN;
其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
可选地,射频单元1401还用于:在所述第二指示信息指示所述第一操作成功的情况下,向所述网络侧发送所述第一设备的信息。Optionally, the radio frequency unit 1401 is further used to: send information of the first device to the network side when the second indication information indicates that the first operation is successful.
可选地,所述第一终端为具有网关能力的终端。Optionally, the first terminal is a terminal with gateway capability.
第二方面,当终端1400作为第二终端时,射频单元1401用于向个人物联网PIN中的第一终端发送配置信息。In the second aspect, when the terminal 1400 is used as the second terminal, the radio frequency unit 1401 is used to send configuration information to the first terminal in the personal Internet of Things PIN.
可选地,所述配置信息用于指示以下至少一项:Optionally, the configuration information is used to indicate at least one of the following:
第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
至少一个第二目标设备需要所述第一操作或不需要所述第一操作;At least one second target device requires the first operation or does not require the first operation;
其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
所述第二目标设备为需要通过所述第一终端访问所述个人物联网PIN或移动网络的设备。The second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
本申请实施例还提供一种网络功能,如图15所示,该网络功能1500包括:天线151、射频装置152、基带装置153、处理器154和存储器155。天线151与射频装置152连接。在上行方向上,射频装置152通过天线151接收信息,将接收的信息发送给基带装置153进行处理。在下行方向上,基带装置153对要发送的信息进行处理,并发送给射频装置152,射频装置152对收到的信息进行处理后经过天线151发送出去。The embodiment of the present application also provides a network function. As shown in FIG15 , the network function 1500 includes: an antenna 151, a radio frequency device 152, a baseband device 153, a processor 154, and a memory 155. The antenna 151 is connected to the radio frequency device 152. In the uplink direction, the radio frequency device 152 receives information through the antenna 151 and sends the received information to the baseband device 153 for processing. In the downlink direction, the baseband device 153 processes the information to be sent and sends it to the radio frequency device 152. The radio frequency device 152 processes the received information and sends it out through the antenna 151.
以上实施例中网络功能执行的方法可以在基带装置153中实现,该基带装置153包括基带处理器。The method for executing the network function in the above embodiment may be implemented in the baseband device 153, which includes a baseband processor.
基带装置153例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图15所示,其中一个芯片例如为基带处理器,通过总线接口与存储器155连接,以调用存储器155中的程序,执行以上方法实施例中所示的网络功能操作。The baseband device 153 may include, for example, at least one baseband board, on which a plurality of chips are arranged, as shown in FIG15 , wherein one of the chips is, for example, a baseband processor, which is connected to the memory 155 through a bus interface to call a program in the memory 155 and execute the network function operations shown in the above method embodiment.
该网络功能还可以包括网络接口156,该接口例如为通用公共无线接口(common public radio interface,CPRI)。The network function may also include a network interface 156, which may be, for example, a common public radio interface (CPRI).
具体地,本发明实施例的网络功能1500还包括:存储在存储器155上并可在处理器154上运行的指令或程序,处理器154调用存储器155中的指令或程序执行图6所示的方 法,并达到相同的技术效果,为避免重复,故不在此赘述。Specifically, the network function 1500 of the embodiment of the present invention further includes: instructions or programs stored in the memory 155 and executable on the processor 154, and the processor 154 calls the instructions or programs in the memory 155 to execute the method shown in FIG. The same technical effect is achieved by the method, so it will not be described here to avoid repetition.
本申请实施例还提供了一种网络功能。如图16所示,该网络功能1600包括:处理器1601、网络接口1602和存储器1603。其中,网络接口1602例如为通用公共无线接口(common public radio interface,CPRI)。The embodiment of the present application also provides a network function. As shown in FIG16 , the network function 1600 includes: a processor 1601, a network interface 1602, and a memory 1603. The network interface 1602 is, for example, a common public radio interface (CPRI).
具体地,本发明实施例的网络功能1600还包括:存储在存储器1603上并可在处理器1601上运行的指令或程序,处理器1601调用存储器1603中的指令或程序执行图3或图4或图6所示的方法,并达到相同的技术效果,为避免重复,故不在此赘述。Specifically, the network function 1600 of the embodiment of the present invention also includes: instructions or programs stored in the memory 1603 and executable on the processor 1601. The processor 1601 calls the instructions or programs in the memory 1603 to execute the method shown in Figure 3 or Figure 4 or Figure 6, and achieves the same technical effect. To avoid repetition, it will not be repeated here.
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述操作执行方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the above-mentioned operation execution method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
其中,所述处理器为上述实施例中所述的终端中的处理器。所述可读存储介质,可以是非易失性的,也可以是非瞬态的。可读存储介质,可以包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。The processor is the processor in the terminal described in the above embodiment. The readable storage medium may be non-volatile or non-transient. The readable storage medium may include a computer-readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述第一方面至第五方面中任一方面所述的操作执行方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the operation execution method embodiment described in any one of the first to fifth aspects above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述第一方面至第五方面中任一方面所述的操作执行方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。An embodiment of the present application further provides a computer program/program product, which is stored in a storage medium. The computer program/program product is executed by at least one processor to implement the various processes of the operation execution method embodiment described in any one of the first to fifth aspects above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
本申请实施例还提供了一种操作执行系统,包括:终端及网络功能,所述终端可用于执行如上第一方面或第四方面所述的操作执行方法的步骤,所述网络功能可用于执行如上所述的第二方面或第三方面或第五方面所述的操作执行方法的步骤。An embodiment of the present application also provides an operation execution system, including: a terminal and a network function, wherein the terminal can be used to execute the steps of the operation execution method described in the first aspect or the fourth aspect above, and the network function can be used to execute the steps of the operation execution method described in the second aspect or the third aspect or the fifth aspect above.
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。 It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises one..." does not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be noted that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对相关技术做出贡献的部分可以以计算机软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络功能等)执行本申请各个实施例所述的方法。Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the relevant technology, can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM/RAM, magnetic disk, optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, computer, server, air conditioner, or network function, etc.) to execute the methods described in each embodiment of the present application.
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。 The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.

Claims (60)

  1. 一种操作执行方法,其中,包括如下中至少一项:An operation execution method, comprising at least one of the following:
    第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;The first terminal sends a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
    所述第一终端接收所述网络侧发送的第五指示信息,其中,所述第五指示信息用于指示以下至少一项:The first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
    允许或不允许所述第一操作;allowing or not allowing the first operation;
    允许或不允许通过所述网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the network side;
    允许或不允许通过所述网络侧的用户面执行所述第一操作。Allow or not allow the first operation to be performed through the user plane of the network side.
  2. 根据权利要求1所述的方法,其中,在所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息之前,所述方法还包括:The method according to claim 1, wherein, before the first terminal sends a first non-access stratum NAS message and/or a first indication information to the network side, the method further comprises:
    所述第一终端与所述网络侧交互以建立协议数据单元PDU会话。The first terminal interacts with the network side to establish a protocol data unit (PDU) session.
  3. 根据权利要求2所述的方法,其中,所述第一非接入层NAS消息为PDU会话修改请求。The method according to claim 2, wherein the first non-access layer NAS message is a PDU session modification request.
  4. 根据权利要求1-3中任一项所述的方法,其中,所述第一指示信息包括如下中至少一项:The method according to any one of claims 1 to 3, wherein the first indication information includes at least one of the following:
    用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
    所述第一终端的信息;information of the first terminal;
    第二网络功能的信息,其中,所述第二网络功能用于执行所述第一操作。Information about a second network function, wherein the second network function is used to perform the first operation.
  5. 根据权利要求1或2所述的方法,其中,所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,包括:The method according to claim 1 or 2, wherein the first terminal sends a first non-access stratum NAS message and/or first indication information to the network side, comprising:
    在所述第一终端与第一设备之间建立连接之时或之后,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。When or after a connection is established between the first terminal and the first device, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side.
  6. 根据权利要求5所述的方法,其中,在所述第一终端与所述第一设备之间建立连接之时或之后,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,包括:The method according to claim 5, wherein when or after the connection between the first terminal and the first device is established, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side, comprising:
    所述第一终端接收所述第一设备发送的第一消息,或接收第二终端发送的第六消息;The first terminal receives the first message sent by the first device, or receives the sixth message sent by the second terminal;
    所述第一终端响应于所述第一消息或所述第六消息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;The first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side in response to the first message or the sixth message;
    其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
    建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的个人物联网PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the personal Internet of Things PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
    所述第六消息用于指示所述第一终端或所述第一设备与所述第二网络功能通信;The sixth message is used to instruct the first terminal or the first device to communicate with the second network function;
    所述第二网络功能用于执行所述第一操作。 The second network function is used to perform the first operation.
  7. 根据权利要求5或6所述的方法,其中,所述第一指示信息包括如下中至少一项:The method according to claim 5 or 6, wherein the first indication information includes at least one of the following:
    用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
    所述第一设备的信息;information of the first device;
    所述第一终端的信息;information of the first terminal;
    第二网络功能的信息,所述第二网络功能用于执行所述第一操作。information of a second network function, where the second network function is used to perform the first operation.
  8. 根据权利要求5至7中任一项所述的方法,其中,在所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息之后,所述方法还包括:The method according to any one of claims 5 to 7, wherein after the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, the method further comprises:
    所述第一终端接收所述网络侧发送的第二指示信息,其中,所述第二指示信息用于指示所述第一操作的结果:The first terminal receives second indication information sent by the network side, wherein the second indication information is used to indicate a result of the first operation:
    所述第一终端根据所述第二指示信息,执行以下至少一项:The first terminal performs at least one of the following according to the second indication information:
    允许或拒绝所述第一终端接收的第一设备发送的第一消息;Allow or deny the first message sent by the first device to be received by the first terminal;
    允许或拒绝对所述第一设备的数据的处理;Allow or deny processing of data of the first device;
    允许或保留或释放所述第一终端与所述第一设备的连接;Allow, retain or release the connection between the first terminal and the first device;
    其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
    建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
    所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
  9. 根据权利要求1、5-8中任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1, 5-8, wherein the method further comprises:
    所述第一终端根据所述第五指示信息,执行以下至少一项:The first terminal performs at least one of the following according to the fifth indication information:
    执行或停止执行所述第一操作;Execute or stop executing the first operation;
    发送或停止发送第六指示信息给第二网络功能,所述第六指示信息用于指示所述第二网络功能执行所述第一操作;Sending or stopping sending sixth indication information to the second network function, where the sixth indication information is used to instruct the second network function to perform the first operation;
    发送或停止发送第四消息给所述第二网络功能,所述第四消息为执行所述第一操作涉及的消息;sending or stopping sending a fourth message to the second network function, where the fourth message is a message involved in performing the first operation;
    接收或停止接收来自所述第二网络功能的第五消息,所述第五消息为执行所述第一操作涉及的消息;receiving or stopping receiving a fifth message from the second network function, where the fifth message is a message related to performing the first operation;
    允许或拒绝所述第一终端接收到的第一设备发送的第一消息;Allow or reject a first message sent by a first device and received by the first terminal;
    允许或拒绝对所述第一设备的数据的处理;Allow or deny processing of data of the first device;
    允许或保留或释放所述第一终端与所述第一设备的连接;Allow, retain or release the connection between the first terminal and the first device;
    其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
    建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与所述第二网络功能通信。Establish a connection between the first device and the first terminal, access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
  10. 根据权利要求8所述的方法,其中,所述第一终端接收所述网络侧发送的所述第二指示信息,包括:The method according to claim 8, wherein the first terminal receives the second indication information sent by the network side, comprising:
    所述第一终端接收所述网络侧发送的第二NAS消息,其中,所述第二NAS消息中 携带有所述第二指示信息。The first terminal receives a second NAS message sent by the network side, wherein the second NAS message The second indication information is carried.
  11. 根据权利要求10所述的方法,其中,所述第二指示信息满足以下至少一项:The method according to claim 10, wherein the second indication information satisfies at least one of the following:
    通过所述第二NAS消息的标识或名称指示所述第一操作的结果;indicating a result of the first operation by an identifier or a name of the second NAS message;
    通过原因值指示所述第一操作的结果。The result of the first operation is indicated by a cause value.
  12. 根据权利要求11所述的方法,其中,所述通过所述第二NAS消息的标识或名称指示所述第一操作的结果,包括以下至少一项:The method according to claim 11, wherein the indicating the result of the first operation by the identifier or name of the second NAS message comprises at least one of the following:
    通过PDU会话修改确认消息或PDU会话建立确认消息指示所述第一操作成功;Indicating that the first operation is successful through a PDU session modification confirmation message or a PDU session establishment confirmation message;
    通过PDU会话修改拒绝消息或PDU会话建立拒绝消息指示所述第一操作失败。The failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  13. 根据权利要求11所述的方法,其中,所述通过原因值指示所述第一操作的结果,包括以下至少一项指示:The method according to claim 11, wherein the result of the first operation indicated by the cause value includes at least one of the following indications:
    失败原因值和/或失败指示,用于指示所述第一操作失败;a failure reason value and/or a failure indication, used to indicate that the first operation failed;
    成功原因值和/或成功指示,用于指示所述第一操作成功;A success reason value and/or a success indication, used to indicate that the first operation is successful;
    在所述第二NAS消息中未包括所述失败原因值和/或失败指示的情况下,指示所述第一操作成功;In a case where the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful;
    在所述第二NAS消息中未包括所述成功原因值和/或成功指示的情况下,指示所述第一操作失败。In a case where the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  14. 根据权利要求5-13中任一项所述的方法,其中,所述方法还包括如下中至少一项:The method according to any one of claims 5 to 13, wherein the method further comprises at least one of the following:
    所述第一终端接收来自所述网络侧的第二消息,将所述第二消息发送给所述第一设备;The first terminal receives a second message from the network side, and sends the second message to the first device;
    所述第一终端接收来自所述第一设备的第三消息,将所述第三消息发送给所述网络侧;The first terminal receives a third message from the first device, and sends the third message to the network side;
    其中,所述第二消息和所述第三消息分别为执行所述第一操作涉及的消息。The second message and the third message are respectively messages involved in executing the first operation.
  15. 根据权利要求14所述的方法,其中,所述第二消息为可扩展认证协议EAP消息,所述第三消息为EAP消息。The method according to claim 14, wherein the second message is an Extensible Authentication Protocol (EAP) message, and the third message is an EAP message.
  16. 根据权利要求5-15中任一项所述的方法,其中,所述第一非接入层NAS消息为PDU会话修改请求或PDU会话建立请求。The method according to any one of claims 5 to 15, wherein the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
  17. 根据权利要求1-16中任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1 to 16, wherein the method further comprises:
    所述第一终端接收所述网络侧发送的规则信息;The first terminal receives the rule information sent by the network side;
    所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,包括:The first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
    所述第一终端根据所述规则信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。The first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information.
  18. 根据权利要求17所述的方法,其中,所述规则信息用于指示以下至少一项:The method according to claim 17, wherein the rule information is used to indicate at least one of the following:
    所述第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
    至少一个第一目标设备需要所述第一操作或不需要所述第一操作。At least one first target device requires the first operation or does not require the first operation.
  19. 根据权利要求18所述的方法,其中,所述第一终端根据所述规则信息,向所述网 络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,包括以下至少一项:The method according to claim 18, wherein the first terminal sends a The network side sends the first non-access layer NAS message and/or the first indication information, including at least one of the following:
    在所述规则信息指示第一设备需要所述第一操作的情况下,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;When the rule information indicates that the first device needs the first operation, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side;
    在所述规则信息指示所述第一操作需要应用于所述目标PIN,且满足以下至少一项条件的情况下,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息:When the rule information indicates that the first operation needs to be applied to the target PIN and at least one of the following conditions is met, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side:
    所述第一非接入层NAS消息和/或所述第一指示信息与所述目标PIN相关;The first non-access stratum NAS message and/or the first indication information are related to the target PIN;
    所述第一终端与第一设备之间的连接与所述目标PIN相关;The connection between the first terminal and the first device is associated with the target PIN;
    所述第一终端接收到的所述第一设备发送的第一消息与所述目标PIN相关;The first message sent by the first device and received by the first terminal is related to the target PIN;
    所述第一设备与所述目标PIN相关;the first device being associated with the target PIN;
    其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
    建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the PIN where the first terminal is located, communicating with the network side, and communicating with the second network function;
    所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
  20. 根据权利要求1-19中任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1 to 19, wherein the method further comprises:
    所述第一终端接收第二终端发送的配置信息;The first terminal receives configuration information sent by the second terminal;
    所述第一终端向网络侧发送第一非接入层NAS消息和/或第一指示信息,包括:The first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
    所述第一终端根据所述配置信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息。The first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the configuration information.
  21. 根据权利要求20所述的方法,其中,所述配置信息用于指示以下至少一项:The method according to claim 20, wherein the configuration information is used to indicate at least one of the following:
    所述第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
    至少一个第二目标设备需要所述第一操作或不需要所述第一操作。At least one second target device requires the first operation or does not require the first operation.
  22. 根据权利要求21所述的方法,其中,所述第一终端根据所述配置信息,向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息,包括以下至少一项:The method according to claim 21, wherein the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the configuration information, including at least one of the following:
    在所述配置信息指示第一设备需要所述第一操作的情况下,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息;When the configuration information indicates that the first device needs the first operation, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side;
    在所述配置信息指示所述第一操作需要应用于所述目标PIN,且满足以下至少一项条件的情况下,所述第一终端向所述网络侧发送所述第一非接入层NAS消息和/或所述第一指示信息:When the configuration information indicates that the first operation needs to be applied to the target PIN and at least one of the following conditions is met, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side:
    所述第一非接入层NAS消息和/或所述第一指示信息与所述目标PIN相关;The first non-access stratum NAS message and/or the first indication information are related to the target PIN;
    所述第一终端与第一设备之间的连接与所述目标PIN相关;The connection between the first terminal and the first device is associated with the target PIN;
    所述第一终端接收到的所述第一设备发送的第一消息与所述目标PIN相关;The first message sent by the first device and received by the first terminal is related to the target PIN;
    所述第一设备与所述目标PIN相关;the first device being associated with the target PIN;
    其中,所述第一消息用于指示以下至少一项:The first message is used to indicate at least one of the following:
    建立所述第一设备与所述第一终端之间的连接、访问所述第一终端、接入所述第一 终端所在的PIN、与所述网络侧通信、与第二网络功能通信;Establishing a connection between the first device and the first terminal, accessing the first terminal, accessing the first The PIN where the terminal is located, communicates with the network side, and communicates with the second network function;
    所述第二网络功能用于执行所述第一操作。The second network function is used to perform the first operation.
  23. 根据权利要求8-22中任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 8 to 22, wherein the method further comprises:
    在所述第二指示信息指示所述第一操作成功的情况下,所述第一终端向所述网络侧发送所述第一设备的信息。When the second indication information indicates that the first operation is successful, the first terminal sends information of the first device to the network side.
  24. 根据权利要求1-23中任一项所述的方法,其中,所述第一终端为具有网关能力的终端。The method according to any one of claims 1-23, wherein the first terminal is a terminal with gateway capability.
  25. 一种操作执行方法,其中,包括:An operation execution method, comprising:
    第一网络功能向第一终端发送第五指示信息;The first network function sends fifth indication information to the first terminal;
    和/或,and / or,
    所述第一网络功能接收所述第一终端发送的第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;The first network function receives a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
    所述第一网络功能响应于所述第一非接入层NAS消息和/或所述第一指示信息,执行如下至少一项:In response to the first non-access stratum NAS message and/or the first indication information, the first network function performs at least one of the following:
    向所述第一终端发送所述第五指示信息;Sending the fifth indication information to the first terminal;
    指示第二网络功能和所述第一终端进行所述第一操作;instructing a second network function and the first terminal to perform the first operation;
    其中,所述第五指示信息用于指示以下至少一项:The fifth indication information is used to indicate at least one of the following:
    允许或不允许所述第一操作;allowing or not allowing the first operation;
    允许或不允许通过所述第一网络功能所在的移动网络的控制面执行所述第一操作;allowing or not allowing execution of the first operation through a control plane of the mobile network where the first network function is located;
    允许或不允许通过所述第一网络功能所在的移动网络的用户面执行所述第一操作。Allow or not allow the first operation to be performed through a user plane of a mobile network where the first network function is located.
  26. 根据权利要求25所述的方法,其中,在所述第一网络功能指示第二网络功能和所述第一终端进行所述第一操作的情况下,所述方法还包括:The method according to claim 25, wherein, when the first network function instructs the second network function and the first terminal to perform the first operation, the method further comprises:
    所述第一网络功能接收所述第二网络功能发送的第三指示信息,其中,所述第三指示信息用于指示所述第一操作的结果;The first network function receives third indication information sent by the second network function, wherein the third indication information is used to indicate a result of the first operation;
    所述第一网络功能根据所述第三指示信息,向所述第一终端发送第二指示信息,所述第二指示信息用于指示所述第一操作的结果。The first network function sends second indication information to the first terminal according to the third indication information, where the second indication information is used to indicate a result of the first operation.
  27. 根据权利要求25或26所述的方法,其中,在所述第一网络功能接收第一终端发送的第一非接入层NAS消息和/或第一指示信息之前,所述方法还包括:The method according to claim 25 or 26, wherein, before the first network function receives the first non-access stratum NAS message and/or the first indication information sent by the first terminal, the method further comprises:
    所述第一网络功能与所述第一终端交互以建立协议数据单元PDU会话。The first network function interacts with the first terminal to establish a protocol data unit (PDU) session.
  28. 根据权利要求27所述的方法,其中,所述第一非接入层NAS消息为PDU会话修改请求。The method according to claim 27, wherein the first non-access stratum (NAS) message is a PDU session modification request.
  29. 根据权利要求25-28中任一项所述的方法,其中,所述第一指示信息包括如下中至少一项:The method according to any one of claims 25 to 28, wherein the first indication information includes at least one of the following:
    用于指示进行所述第一操作的指示; an instruction for instructing to perform the first operation;
    所述第一终端的信息;information of the first terminal;
    所述第二网络功能的信息。information of the second network function.
  30. 根据权利要求25或26所述的方法,其中,所述第一指示信息包括如下中至少一项:The method according to claim 25 or 26, wherein the first indication information includes at least one of the following:
    用于指示进行所述第一操作的指示;an instruction for instructing to perform the first operation;
    第一设备的信息,其中,所述第一设备为需要通过所述第一终端访问个人物联网PIN或所述第一网络功能所在网络的设备;Information of a first device, wherein the first device is a device that needs to access a personal Internet of Things PIN or a network where the first network function is located through the first terminal;
    所述第一终端的信息;information of the first terminal;
    所述第二网络功能的信息。information of the second network function.
  31. 根据权利要求25、26、30中任一项所述的方法,其中,所述第一非接入层NAS消息为PDU会话修改请求或PDU会话建立请求。The method according to any one of claims 25, 26, and 30, wherein the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
  32. 根据权利要求26-31中任一项所述的方法,其中,所述第一网络功能根据所述第三指示信息,向所述第一终端发送第二指示信息,包括:The method according to any one of claims 26 to 31, wherein the first network function sends second indication information to the first terminal according to the third indication information, comprising:
    所述第一网络功能根据所述第三指示信息,向所述第一终端发送第二NAS消息,其中,所述第二NAS消息中携带有所述第二指示信息。The first network function sends a second NAS message to the first terminal according to the third indication information, wherein the second NAS message carries the second indication information.
  33. 根据权利要求26或32所述的方法,其中,所述第二指示信息满足以下至少一项:The method according to claim 26 or 32, wherein the second indication information satisfies at least one of the following:
    通过所述第二NAS消息的标识或名称指示所述第一操作的结果;indicating a result of the first operation by an identifier or a name of the second NAS message;
    通过原因值指示所述第一操作的结果。The result of the first operation is indicated by a cause value.
  34. 根据权利要求33所述的方法,其中,所述通过所述第二NAS消息的标识或名称指示所述第一操作的结果,包括以下至少一项:The method of claim 33, wherein the indicating the result of the first operation by the identifier or name of the second NAS message comprises at least one of the following:
    通过PDU会话修改确认或PDU会话建立确认指示所述第一操作的结果成功;Indicating a successful result of the first operation through a PDU session modification confirmation or a PDU session establishment confirmation;
    通过PDU会话修改拒绝消息或PDU会话建立拒绝指示所述第一操作失败。The failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject.
  35. 根据权利要求33所述的方法,其中,所述通过原因值指示所述第一操作的结果,包括以下至少一项指示:The method according to claim 33, wherein the result of the first operation indicated by the cause value includes at least one of the following indications:
    失败原因值和/或失败指示,用于指示所述第一操作失败;a failure reason value and/or a failure indication, used to indicate that the first operation failed;
    成功原因值和/或成功指示,用于指示所述第一操作成功;A success reason value and/or a success indication, used to indicate that the first operation is successful;
    在所述第二NAS消息中未包括所述失败原因值和/或失败指示的情况下,指示所述第一操作成功;In a case where the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful;
    在所述第二NAS消息中未包括所述成功原因值和/或成功指示的情况下,指示所述第一操作失败。In a case where the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  36. 根据权利要求25-35中任一项所述的方法,其中,所述第一网络功能响应于所述第一非接入层NAS消息,指示第二网络功能和所述第一终端进行所述第一操作,包括如下至少一项:The method according to any one of claims 25 to 35, wherein the first network function instructs the second network function and the first terminal to perform the first operation in response to the first non-access stratum NAS message, including at least one of the following:
    所述第一网络功能基于所述第一非接入层NAS消息中的PDU会话相关信息,指示所述第二网络功能和所述第一终端进行所述第一操作; The first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message;
    所述第一网络功能基于所述第一非接入层NAS消息中的PDU会话相关信息,以及PDU会话相关信息与PIN实例或会话的第一关联信息,指示所述第二网络功能和所述第一终端进行所述第一操作;The first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message and the first association information between the PDU session related information and the PIN instance or session;
    所述第一网络功能基于所述第一非接入层NAS消息中的PIN实例或会话相关信息,指示所述第二网络功能和所述第一终端进行所述第一操作;The first network function instructs the second network function and the first terminal to perform the first operation based on the PIN instance or session related information in the first non-access layer NAS message;
    所述第一网络功能基于所述第一非接入层NAS消息中的PDU会话相关信息和PIN业务指示信息,指示所述第二网络功能和所述第一终端进行所述第一操作;The first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information and the PIN service indication information in the first non-access layer NAS message;
    所述第一网络功能基于所述第一非接入层NAS消息中的PDU会话相关信息,以及PDU会话相关信息与PIN业务的第二关联信息,指示所述第二网络功能和所述第一终端进行所述第一操作。The first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message, and the second association information between the PDU session related information and the PIN service.
  37. 根据权利要求36所述的方法,其中,所述方法还包括:The method according to claim 36, wherein the method further comprises:
    所述第一网络功能从第三网络功能获知以下至少之一:The first network function learns at least one of the following from the third network function:
    所述第一关联信息;the first associated information;
    所述第二关联信息。The second associated information.
  38. 根据权利要求25-37中任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 25 to 37, wherein the method further comprises:
    在所述第二指示信息指示所述第一操作成功的情况下,所述第一网络功能接收所述第一终端发送的第一设备的信息;When the second indication information indicates that the first operation is successful, the first network function receives information about the first device sent by the first terminal;
    其中,所述第一设备为需要通过所述第一终端访问PIN或所述第一网络功能所在网络的设备。The first device is a device that needs to access the PIN or the network where the first network function is located through the first terminal.
  39. 根据权利要求38所述的方法,其中,所述方法还包括:The method according to claim 38, wherein the method further comprises:
    在所述第一网络功能获知报文过滤规则,且所述报文过滤规则与所述第一设备相关的情况下,所述第一网络功能使用所述报文过滤规则配置第四网络功能。When the first network function learns the message filtering rule and the message filtering rule is related to the first device, the first network function uses the message filtering rule to configure a fourth network function.
  40. 一种操作执行方法,其中,包括:An operation execution method, comprising:
    第三网络功能执行第二操作;The third network function performs a second operation;
    其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
    所述第三网络功能向第一终端发送规则信息;The third network function sends rule information to the first terminal;
    所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
  41. 根据权利要求40所述的方法,其中,所述规则信息用于指示以下至少一项:The method according to claim 40, wherein the rule information is used to indicate at least one of the following:
    第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
    至少一个第一目标设备需要所述第一操作或不需要所述第一操作;At least one first target device requires the first operation or does not require the first operation;
    其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
    所述第一目标设备为需要通过所述第一终端访问个人物联网PIN或所述第三网络功能所在移动网络的设备。The first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  42. 根据权利要求40或41所述的方法,其中,所述PDU会话配置信息包括以下至少一项: The method according to claim 40 or 41, wherein the PDU session configuration information includes at least one of the following:
    PDU会话相关信息与PIN实例或会话的第一关联信息;First association information between PDU session related information and PIN instance or session;
    PDU会话相关信息与PIN业务的第二关联信息。The second association information between the PDU session related information and the PIN service.
  43. 根据权利要求40-42中任一项所述的方法,其中,在所述第三网络功能执行所述第二操作之前,所述方法还包括:The method according to any one of claims 40 to 42, wherein before the third network function performs the second operation, the method further comprises:
    所述第三网络功能获知第四指示信息,其中,所述第四指示信息用于指示所述第三网络功能执行所述第二操作;The third network function acquires fourth indication information, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
    所述第三网络功能执行所述第二操作,包括:The third network function performs the second operation, including:
    所述第三网络功能根据所述第四指示信息执行所述第二操作。The third network function performs the second operation according to the fourth indication information.
  44. 根据权利要求43所述的方法,其中,所述第三网络功能获知第四指示信息,包括:The method according to claim 43, wherein the third network function obtains the fourth indication information, comprising:
    所述第三网络功能接收第五网络功能发送的所述第四指示信息。The third network function receives the fourth indication information sent by the fifth network function.
  45. 一种操作执行方法,其中,包括:An operation execution method, comprising:
    第二终端向个人物联网PIN中的第一终端发送配置信息。The second terminal sends configuration information to the first terminal in the personal Internet of Things PIN.
  46. 根据权利要求45所述的方法,其中,所述配置信息用于指示以下至少一项:The method according to claim 45, wherein the configuration information is used to indicate at least one of the following:
    第一操作需要应用于目标PIN或所述第一操作不需要应用于所述目标PIN;The first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
    至少一个第二目标设备需要所述第一操作或不需要所述第一操作;At least one second target device requires the first operation or does not require the first operation;
    其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
    所述第二目标设备为需要通过所述第一终端访问所述个人物联网PIN或移动网络的设备。The second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  47. 一种操作执行方法,其中,包括:An operation execution method, comprising:
    第五网络功能向第三网络功能发送第四指示信息,其中,所述第四指示信息用于指示所述第三网络功能执行第二操作;The fifth network function sends fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
    其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
    所述第三网络功能向第一终端发送规则信息;The third network function sends rule information to the first terminal;
    所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
  48. 根据权利要求47所述的方法,其中,所述规则信息用于指示以下至少一项:The method according to claim 47, wherein the rule information is used to indicate at least one of the following:
    第一操作需要应用于目标个人物联网PIN或所述第一操作不需要应用于所述目标个人物联网PIN;The first operation needs to be applied to the target personal IoT PIN or the first operation does not need to be applied to the target personal IoT PIN;
    至少一个第一目标设备需要所述第一操作或不需要所述第一操作;At least one first target device requires the first operation or does not require the first operation;
    其中,所述第一操作包括鉴权、认证、授权中的至少一项;The first operation includes at least one of authentication, certification, and authorization;
    所述第一目标设备为需要通过所述第一终端访问个人物联网PIN或所述第三网络功能所在移动网络的设备。The first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  49. 根据权利要求47或48所述的方法,其中,所述PDU会话配置信息包括以下至少一项:The method according to claim 47 or 48, wherein the PDU session configuration information includes at least one of the following:
    PDU会话相关信息与PIN实例或会话的第一关联信息;First association information between PDU session related information and PIN instance or session;
    PDU会话相关信息与PIN业务的第二关联信息。 The second association information between the PDU session related information and the PIN service.
  50. 一种操作执行装置,其中,包括如下中至少一个模块:An operation execution device, comprising at least one of the following modules:
    第一发送模块,用于向网络侧发送第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;A first sending module, configured to send a first non-access stratum NAS message and/or first indication information to a network side, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
    第一接收模块,用于接收所述网络侧发送的第五指示信息,其中,所述第五指示信息用于指示以下至少一项:The first receiving module is configured to receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
    允许或不允许所述第一操作;allowing or not allowing the first operation;
    允许或不允许通过所述网络侧的控制面执行所述第一操作;Allowing or not allowing the first operation to be performed through the control plane of the network side;
    允许或不允许通过所述网络侧的用户面执行所述第一操作。Allow or not allow the first operation to be performed through the user plane of the network side.
  51. 一种操作执行装置,其中,包括:An operation execution device, comprising:
    第二发送模块,用于向第一终端发送第五指示信息;A second sending module, used to send fifth indication information to the first terminal;
    和/或,and / or,
    第二接收模块,用于接收所述第一终端发送的第一非接入层NAS消息和/或第一指示信息,其中,所述第一非接入层NAS消息用于指示第一操作,所述第一指示信息用于指示所述第一操作,所述第一操作包括鉴权、认证、授权中的至少一项;A second receiving module, configured to receive a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
    第一处理模块,用于响应于所述第一非接入层NAS消息和/或所述第一指示信息,执行如下至少一项:A first processing module is configured to, in response to the first non-access layer NAS message and/or the first indication information, perform at least one of the following:
    向所述第一终端发送所述第五指示信息;Sending the fifth indication information to the first terminal;
    指示第二网络功能和所述第一终端进行所述第一操作;instructing a second network function and the first terminal to perform the first operation;
    其中,所述第五指示信息用于指示以下至少一项:The fifth indication information is used to indicate at least one of the following:
    允许或不允许所述第一操作;allowing or not allowing the first operation;
    允许或不允许通过移动网络的控制面执行所述第一操作;allowing or not allowing the first operation to be performed through a control plane of the mobile network;
    允许或不允许通过移动网络的用户面执行所述第一操作。The first operation is allowed or not allowed to be performed through a user plane of the mobile network.
  52. 一种操作执行装置,其中,包括:An operation execution device, comprising:
    第二处理模块,用于执行第二操作;A second processing module, used for performing a second operation;
    其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
    向第一终端发送个人物联网PIN的规则信息;Sending rule information of the personal Internet of Things PIN to the first terminal;
    向第一网络功能发送数据协议单元PDU会话配置信息。Send data protocol unit PDU session configuration information to the first network function.
  53. 一种操作执行装置,其中,包括:An operation execution device, comprising:
    第三发送模块,用于向个人物联网PIN中的第一终端发送配置信息。The third sending module is used to send configuration information to the first terminal in the personal Internet of Things PIN.
  54. 一种操作执行装置,其中,包括:An operation execution device, comprising:
    第四发送模块,用于向第三网络功能发送第四指示信息,其中,所述第四指示信息用于指示所述第三网络功能执行第二操作;a fourth sending module, configured to send fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform a second operation;
    其中,所述第二操作包括以下至少一项:The second operation includes at least one of the following:
    所述第三网络功能向第一终端发送规则信息; The third network function sends rule information to the first terminal;
    所述第三网络功能向第一网络功能发送数据协议单元PDU会话配置信息。The third network function sends data protocol unit PDU session configuration information to the first network function.
  55. 一种终端,其中,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至24中任一项所述的操作执行方法的步骤,或者实现如权利要求45至46中任一项所述的操作执行方法的步骤。A terminal, comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the operation execution method as described in any one of claims 1 to 24 are implemented, or the steps of the operation execution method as described in any one of claims 45 to 46 are implemented.
  56. 一种网络功能,其中,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求25至39中任一项所述的操作执行方法的步骤,或者实现如权利要求40至44中任一项所述的操作执行方法的步骤,或者,实现如权利要求47至49中任一项所述的操作执行方法的步骤。A network function, comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, it implements the steps of the operation execution method as described in any one of claims 25 to 39, or implements the steps of the operation execution method as described in any one of claims 40 to 44, or implements the steps of the operation execution method as described in any one of claims 47 to 49.
  57. 一种可读存储介质,其中,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至24任一项所述的操作执行方法,或者实现如权利要求25至39中任一项所述的操作执行方法的步骤,或者实现如权利要求40至44中任一项所述的操作执行方法的步骤,或者实现如权利要求45至46中任一项所述的操作执行方法的步骤,或者实现如权利要求47至49中任一项所述的操作执行方法的步骤。A readable storage medium, wherein the readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, it implements the operation execution method as described in any one of claims 1 to 24, or implements the steps of the operation execution method as described in any one of claims 25 to 39, or implements the steps of the operation execution method as described in any one of claims 40 to 44, or implements the steps of the operation execution method as described in any one of claims 45 to 46, or implements the steps of the operation execution method as described in any one of claims 47 to 49.
  58. 一种芯片,其中,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如权利要求1至24任一项所述的操作执行方法,或者实现如权利要求25至39中任一项所述的操作执行方法的步骤,或者实现如权利要求40至44中任一项所述的操作执行方法的步骤,或者实现如权利要求45至46中任一项所述的操作执行方法的步骤,或者实现如权利要求47至49中任一项所述的操作执行方法的步骤。A chip, wherein the chip includes a processor and a communication interface, the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the operation execution method as described in any one of claims 1 to 24, or to implement the steps of the operation execution method as described in any one of claims 25 to 39, or to implement the steps of the operation execution method as described in any one of claims 40 to 44, or to implement the steps of the operation execution method as described in any one of claims 45 to 46, or to implement the steps of the operation execution method as described in any one of claims 47 to 49.
  59. 一种计算机程序产品,其中,所述程序产品被存储在非易失的存储介质中,所述程序产品被至少一个处理器执行,以实现如权利要求1至24任一项所述的操作执行方法,或者实现如权利要求25至39中任一项所述的操作执行方法的步骤,或者实现如权利要求40至44中任一项所述的操作执行方法的步骤,或者实现如权利要求45至46中任一项所述的操作执行方法的步骤,或者实现如权利要求47至49中任一项所述的操作执行方法的步骤。A computer program product, wherein the program product is stored in a non-volatile storage medium, and the program product is executed by at least one processor to implement the operation execution method as described in any one of claims 1 to 24, or implement the steps of the operation execution method as described in any one of claims 25 to 39, or implement the steps of the operation execution method as described in any one of claims 40 to 44, or implement the steps of the operation execution method as described in any one of claims 45 to 46, or implement the steps of the operation execution method as described in any one of claims 47 to 49.
  60. 一种操作执行装置,其中,所述装置用于执行如权利要求1至24任一项所述的操作执行方法,或者执行如权利要求25至39中任一项所述的操作执行方法的步骤,或者执行如权利要求40至44中任一项所述的操作执行方法的步骤,或者执行如权利要求45至46中任一项所述的操作执行方法的步骤,或者执行如权利要求47至49中任一项所述的操作执行方法的步骤。 An operation execution device, wherein the device is used to execute the operation execution method as described in any one of claims 1 to 24, or to execute the steps of the operation execution method as described in any one of claims 25 to 39, or to execute the steps of the operation execution method as described in any one of claims 40 to 44, or to execute the steps of the operation execution method as described in any one of claims 45 to 46, or to execute the steps of the operation execution method as described in any one of claims 47 to 49.
PCT/CN2023/126764 2022-11-04 2023-10-26 Operation execution method and apparatus, terminal and network function WO2024093783A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202211395204.0 2022-11-04
CN202211395204.0A CN118042452A (en) 2022-11-04 2022-11-04 Operation execution method, device, terminal and network function

Publications (1)

Publication Number Publication Date
WO2024093783A1 true WO2024093783A1 (en) 2024-05-10

Family

ID=90929697

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/126764 WO2024093783A1 (en) 2022-11-04 2023-10-26 Operation execution method and apparatus, terminal and network function

Country Status (2)

Country Link
CN (1) CN118042452A (en)
WO (1) WO2024093783A1 (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20210368341A1 (en) * 2020-08-10 2021-11-25 Ching-Yu LIAO Secure access for 5g iot devices and services
WO2022147582A2 (en) * 2021-05-07 2022-07-07 Futurewei Technologies, Inc. Methods and apparatus for provisioning, authentication, authorization, and user equipment (ue) key generation and distribution in an on-demand network
CN115250470A (en) * 2021-04-08 2022-10-28 英特尔公司 Arrangement in a gateway device

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20210368341A1 (en) * 2020-08-10 2021-11-25 Ching-Yu LIAO Secure access for 5g iot devices and services
CN115250470A (en) * 2021-04-08 2022-10-28 英特尔公司 Arrangement in a gateway device
WO2022147582A2 (en) * 2021-05-07 2022-07-07 Futurewei Technologies, Inc. Methods and apparatus for provisioning, authentication, authorization, and user equipment (ue) key generation and distribution in an on-demand network

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on architecture enhancements for Personal IoT Network (PIN) (Release 18)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 23.700-88, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V1.1.0, 21 October 2022 (2022-10-21), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, pages 1 - 165, XP052211639 *
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on personal IoT networks security aspects (Release 18)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 33.882, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V0.3.0, 24 October 2022 (2022-10-24), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, pages 1 - 17, XP052211756 *
ZHENHUA XIE, VIVO: "Consolidated solution.", 3GPP DRAFT; S2-2209009; TYPE PCR; FS_PIN, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. 3GPP SA 2, no. Online; 20221010 - 20221017, 30 September 2022 (2022-09-30), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, XP052208771 *

Also Published As

Publication number Publication date
CN118042452A (en) 2024-05-14

Similar Documents

Publication Publication Date Title
WO2021088990A1 (en) Relay connection establishing method and device
WO2023116786A1 (en) Registration method and apparatus of internet of things device, communication device, core network device, storage medium and system
WO2023143411A1 (en) Device authentication methods, apparatus and communication device
WO2024093783A1 (en) Operation execution method and apparatus, terminal and network function
WO2023143418A1 (en) Device authentication method and apparatus, and terminal and network function
WO2024140570A1 (en) Policy configuration method and apparatus, terminal, network side device, and readable storage medium
WO2024067331A1 (en) Device switching method in personal internet of things network, and communication method and device
WO2024131793A1 (en) Reader-writer management method, terminal, and network side device
WO2023143554A1 (en) Pin establishment method and device
WO2023143453A1 (en) Direct-connectivity air interface configuration method, and terminal and network-side device
WO2024093712A1 (en) Relay communication link processing method, relay communication link configuration method, relay terminal processing method and related device
WO2024017124A1 (en) Device authentication method, certificate allocation method, identifier allocation method, network controlled repeater and network-side device
WO2024022161A1 (en) Pin device registration method and apparatus, and communication device
WO2023143436A1 (en) Data forwarding method and apparatus, and terminal device and network device
WO2024160155A1 (en) Method for updating secondary key, terminal, and network-side device
WO2024017195A1 (en) Pin management method and apparatus, first terminal, and first device
WO2023165481A1 (en) Network fault processing method, terminal, access network device, and core network device
WO2024001954A1 (en) Identifier configuration methods and apparatus, terminal and storage medium
WO2024017181A1 (en) Device authorization method and apparatus, and network-side device
WO2023143423A1 (en) Information acquisition, storage and reporting method and device, terminal, and network function
WO2024022182A1 (en) Information query method and apparatus, terminal, and network side device
WO2023143416A1 (en) Information processing method, terminal, and network function
WO2023179595A1 (en) Session channel establishment method and apparatus for non-3gpp device, and device
WO2023131286A1 (en) Resource control method and apparatus, terminal, network side device, and readable storage medium
US20230328532A1 (en) Communication method and apparatus for trusted or untrusted relay, terminal, and network side device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23884715

Country of ref document: EP

Kind code of ref document: A1