WO2024093783A1 - Procédé et appareil d'exécution d'opération, terminal et fonction de réseau - Google Patents

Procédé et appareil d'exécution d'opération, terminal et fonction de réseau Download PDF

Info

Publication number
WO2024093783A1
WO2024093783A1 PCT/CN2023/126764 CN2023126764W WO2024093783A1 WO 2024093783 A1 WO2024093783 A1 WO 2024093783A1 CN 2023126764 W CN2023126764 W CN 2023126764W WO 2024093783 A1 WO2024093783 A1 WO 2024093783A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
network function
indication information
message
information
Prior art date
Application number
PCT/CN2023/126764
Other languages
English (en)
Chinese (zh)
Inventor
谢振华
Original Assignee
维沃移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 维沃移动通信有限公司 filed Critical 维沃移动通信有限公司
Publication of WO2024093783A1 publication Critical patent/WO2024093783A1/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/009Security arrangements; Authentication; Protecting privacy or anonymity specially adapted for networks, e.g. wireless sensor networks, ad-hoc networks, RFID networks or cloud networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security

Definitions

  • the present application belongs to the field of communication technology, and specifically relates to an operation execution method, device, terminal and network function.
  • the Internet of Things is a network covering multiple devices based on the computer Internet, using sensor networks, radio frequency identification technology, wireless data communication and other technologies.
  • devices can communicate with each other. Its essence is to use radio frequency automatic identification (RFID) technology to achieve mutual communication between devices through wireless data links and computer Internet.
  • RFID radio frequency automatic identification
  • the Internet of Things device generally refers to the terminal device used in certain specific scenarios or specific services, such as smart home devices, smart utilities, e-health and smart wearable devices.
  • the embodiments of the present application provide an operation execution method, apparatus, terminal, and network function to implement authentication-related operations on a device in a PIN, thereby improving the security of accessing the PIN.
  • an operation execution method comprising:
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • an operation execution method comprising:
  • the first network function sends fifth indication information to the first terminal
  • the first network function receives a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first network function In response to the first non-access stratum NAS message and/or the first indication information, the first network function performs at least one of the following:
  • the fifth indication information is used to indicate at least one of the following:
  • an operation execution method including:
  • the third network function performs a second operation
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • an operation execution method comprising:
  • the second terminal sends configuration information to the first terminal in the personal Internet of Things PIN.
  • an operation execution method including:
  • the fifth network function sends fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • an operation execution device including:
  • a first sending module configured to send a first non-access stratum NAS message and/or first indication information to a network side, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first receiving module is configured to receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • an operation execution device including:
  • a second sending module used to send fifth indication information to the first terminal
  • a second receiving module configured to receive a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • a first processing module is configured to, in response to the first non-access layer NAS message and/or the first indication information, perform at least one of the following:
  • the fifth indication information is used to indicate at least one of the following:
  • the first operation is allowed or not allowed to be performed through a user plane of the mobile network.
  • an operation execution device including:
  • a second processing module used for performing a second operation
  • the second operation includes at least one of the following:
  • an operation execution device comprising:
  • the third sending module is used to send configuration information to the first terminal in the personal Internet of Things PIN.
  • an operation execution device comprising:
  • a fourth sending module configured to send fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform a second operation
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • a terminal which includes a processor and a memory, wherein the memory stores a program or instruction that can be executed on the processor, and when the program or instruction is executed by the processor, the steps of the method described in the first aspect or the fourth aspect are implemented.
  • a network function including a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the second aspect, the third aspect, or the fifth aspect are implemented.
  • an operation execution system including: a first terminal, a second terminal, a first network function, a second network function, a third network function, a fourth network function, and at least two of a fifth network function, wherein the first terminal can be used to execute the steps of the operation execution method as described in the first aspect above, the second terminal can be used to execute the steps of the operation execution method as described in the fourth aspect above, and the first network function can be used to execute the steps of the operation execution method as described in the fourth aspect above.
  • the third network function can be used to execute the steps of the operation execution method described in the third aspect
  • the fifth network function can be used to execute the steps of the operation execution method described in the fifth aspect
  • the second network function and the fifth network function can be used to cooperate with at least one of the first terminal, the second terminal, the first network function, the third network function and the fifth network function to execute the steps of the operation execution method described in any one of claims 1-46.
  • a readable storage medium on which a program or instruction is stored.
  • the program or instruction is executed by a processor, the steps of the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect are implemented.
  • a chip comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.
  • a computer program/program product is provided, wherein the computer program/program product is stored in a storage medium, and the computer program/program product is executed by at least one processor to implement the steps of the method described in the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect.
  • an embodiment of the present application provides an operation execution determination device, which is used to execute the steps of the operation execution method described in the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect.
  • the first terminal can send a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization; and/or the first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • the first terminal can instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, authentication, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, authentication, and authorization operations on the device in the PIN, that is, the present application clarifies the authentication, authentication, and authorization operations in the PIN, thereby improving the security of accessing the PIN.
  • FIG1 is a block diagram of a wireless communication system to which an embodiment of the present application can be applied;
  • FIG2 is a flow chart of an operation execution method in an embodiment of the present application.
  • FIG3 is a flow chart of another operation execution method in an embodiment of the present application.
  • FIG4 is a flow chart of another operation execution method in an embodiment of the present application.
  • FIG5 is a flow chart of another operation execution method in an embodiment of the present application.
  • FIG6 is a flow chart of another operation execution method in an embodiment of the present application.
  • FIG7 is a flowchart of implementation mode 1 of the operation execution method of the embodiment of the present application.
  • FIG8 is a flow chart of implementation mode 2 of the operation execution method of an embodiment of the present application.
  • FIG9 is a flow chart of an operation execution device in an embodiment of the present application.
  • FIG10 is a flow chart of another operation execution device in an embodiment of the present application.
  • FIG11 is a flow chart of another operation execution device in an embodiment of the present application.
  • FIG12 is a flow chart of another operation execution device in an embodiment of the present application.
  • FIG13 is a flow chart of another operation execution device in an embodiment of the present application.
  • FIG14 is a block diagram of a communication device in an embodiment of the present application.
  • FIG15 is a block diagram of a terminal in an embodiment of the present application.
  • FIG16 is a structural block diagram of a network function in an embodiment of the present application.
  • FIG. 17 is a structural block diagram of another network function in an embodiment of the present application.
  • first, second, etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by “first” and “second” are generally of the same type, and the number of objects is not limited.
  • the first object can be one or more.
  • “and/or” in the specification and claims represents at least one of the connected objects, and the character “/" generally represents that the objects associated with each other are in an "or” relationship.
  • LTE Long Term Evolution
  • LTE-A Long Term Evolution
  • CDMA Code Division Multiple Access
  • TDMA Time Division Multiple Access
  • FDMA Frequency Division Multiple Access
  • OFDMA Orthogonal Frequency Division Multiple Access
  • SC-FDMA Single-carrier Frequency Division Multiple Access
  • NR new radio
  • FIG1 shows a block diagram of a wireless communication system applicable to the embodiment of the present application.
  • the wireless communication system includes a terminal 11 and a network function 12.
  • the terminal 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), Laptop Computer (also called notebook computer), Personal Digital Assistant (PDA), PDA, netbook, ultra-mobile personal computer (UMPC), mobile Internet Device (MID), augmented reality (AR)/virtual reality (VR) equipment, robot, wearable device (Wearable Device), vehicle-mounted equipment (VUE), pedestrian terminal (PUE), smart home (home equipment with wireless communication function, such as refrigerator, TV, washing machine or furniture, etc.), game console, personal computer (personal computer, PC), teller machine or self-service machine and other terminal side equipment, wearable device includes: smart watch, smart bracelet, smart headset, smart glasses, smart jewelry (smart bracelet, smart bracelet, smart ring, smart necklace, smart anklet, smart anklet, etc.), smart wristband, smart clothing, etc.
  • PDA Personal Digital Assistant
  • UMPC
  • the network function 12 may include an access network device or a core network device, wherein the access network device 12 may also be referred to as a radio access network device, a radio access network (RAN), a radio access network function or a radio access network unit.
  • the access network device 12 may include a base station, a WLAN access point or a WiFi node, etc.
  • the base station may be referred to as a node B, an evolved node B (eNB), an access point, a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home B node, a home evolved B node, a transmitting and receiving point (TRP) or some other suitable term in the field, as long as the same technical effect is achieved, the base station is not limited to a specific technical vocabulary, it should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
  • the core network equipment may include but is not limited to at least one of the following: core network nodes, core network functions, mobility management entity (Mobility Management Entity, MME), access mobility management function (Access and Mobility Management Function, AMF), session management function (Session Management Function, SMF), user plane function (User Plane Function, UPF), policy control function (Policy Control Function, PCF), policy and charging rules function unit (Policy and Charging Rules Function, PCRF), edge application service discovery function (Edge Application Server Discovery ...
  • MME mobility management entity
  • AMF Access and Mobility Management Function
  • SMF Session Management Function
  • SMF Session Management Function
  • UPF User Plane Function
  • Policy Control Function Policy Control Function
  • PCRF Policy and Charging Rules Function
  • edge application service discovery function Edge Application Server Discovery ...
  • the method may include the following steps 201 and/or 202:
  • Step 201 A first terminal sends a first non-access stratum NAS message and/or first indication information to a network side.
  • the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function
  • the first terminal can be, for example, a terminal with gateway capability, i.e., a gateway terminal (PIN Element with Gateway Capability, PEGC);
  • the first network function can be, for example, a session management function (Session Management Function, SMF) or an access and mobility management function (Access and Mobility Management Function, AMF).
  • SMF Session Management Function
  • AMF Access and Mobility Management Function
  • the first non-access layer NAS message is used to indicate the first operation
  • the first indication information is used to indicate the first operation.
  • the first terminal can send a first non-access layer NAS message to the network side (such as the above-mentioned first network function) to instruct the network side to perform the first operation (that is, trigger the network side to perform the first operation through a NAS message); or, it can send a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side device to perform the first operation through an indication information); or, it can also send a first NAS message and a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side to perform the first operation through a NAS message and an indication information), here, the first NAS message and the first indication information can be independent, or the first indication information can be carried in the first NAS message.
  • the first operation includes at least one of the following:
  • Step 202 The first terminal receives fifth indication information sent by the network side.
  • the fifth indication information is used to indicate at least one of the following:
  • the method further includes:
  • the first terminal interacts with the network side to establish a PDU session
  • step 202 “the first terminal receives the fifth indication information sent by the network side” includes:
  • the first terminal receives a PDU session establishment/modification confirmation message sent by the network side, and the PDU session establishment/modification confirmation message carries the fifth indication information.
  • the network side may carry the fifth indication information in a PDU session confirmation message and send it to the first terminal.
  • step 202 “the first terminal receives fifth indication information sent by the network side” includes:
  • the first terminal receives the fifth indication information sent by the network side in response to the first non-access layer NAS message and/or the first indication information.
  • the network side can carry the fifth indication information in the PDU session establishment confirmation/modification confirmation message and send it to the first terminal to inform the first terminal whether it allows the first operation; or after receiving the first non-access layer NAS message and/or the first indication information sent by the first terminal, the network side can send the fifth indication information to the first terminal to inform the first terminal whether it allows the first operation.
  • the first terminal can send a first non-access layer NAS message and/or a first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization; and/or, the first terminal receives fifth indication information sent by the network side, wherein the fifth indication information is used for at least one of the following:
  • the first terminal can instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, certification, and authorization operations on the device in the PIN, thereby improving the security of accessing the PIN.
  • the first terminal may also meet the following conditions 1 or 2:
  • the first terminal can also have the function of a personal Internet of Things device (PIN Element, PINE) and gateway capabilities, that is, PEGC and PINE can be combined into one device.
  • PINE personal Internet of Things device
  • PEGC and PINE can be combined into one device.
  • the first terminal may not have the PINE capability.
  • the first terminal only has the gateway capability, that is, PEGC and PINE are independently configured.
  • the method further includes:
  • the first terminal interacts with the network side to establish a protocol data unit (PDU) session.
  • PDU protocol data unit
  • the first terminal formed by combining PEGC and PINE can also establish a PDU session with the network side before sending the first non-access layer NAS message and/or the first indication information to the network side.
  • the first terminal before the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, if a PDU session is established, the first terminal can subsequently use the modification process of the subsequent PDU session to send the first non-access layer NAS message to the network side.
  • the first non-access layer NAS message is a PDU session modification request. That is, in the aforementioned situation 1, the first terminal can send the PDU modification request as the first NAS message to the network side to trigger the network side to perform the first operation.
  • the first indication information includes at least one of the following items A-1 to A-3:
  • Item A-1 an instruction for instructing to perform the first operation
  • Item A-2 information of the first terminal
  • Item A-3 Information about a second network function, wherein the second network function is used to perform the first operation.
  • the information of the first terminal may include at least one of an identifier, an IP address, and a MAC address.
  • the above-mentioned item A-1 indicates that the first terminal can display and instruct the network side to perform the first operation
  • the above item A-2 indicates that the first terminal can implicitly instruct the network side to perform the first operation through the information of the first terminal.
  • the network side when the network side receives the first indication information sent by the first terminal including the above-mentioned indication for instructing to perform the first operation, it can determine that the first operation needs to be performed on the first terminal based on the displayed indication content; when the network side receives the first indication information sent by the first terminal including the above-mentioned information of the first terminal, it can also determine that the first operation needs to be performed on the first terminal through the implicit indication content.
  • the second network function may be, for example, an external data network authentication and authorization center (AAA), that is, the first terminal may also inform the network side which network function performs the first operation.
  • AAA external data network authentication and authorization center
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
  • the first terminal When or after a connection is established between the first terminal and the first device, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side.
  • the first device may be a PINE.
  • the first terminal may instruct the network side to perform the first operation.
  • the first terminal when or after the connection is established between the first terminal and the first device, the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, including:
  • the first terminal receives the first message sent by the first device, or receives the sixth message sent by the second terminal;
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side in response to the first message or the sixth message;
  • the first message is used to indicate at least one of the following:
  • the sixth message is used to instruct the first terminal or the first device to communicate with the second network function
  • the second network function is used to perform the first operation.
  • the first message When the first message is used to indicate establishment of a connection between the first device and the first terminal, the first message may be a connection request sent by the first device to the first terminal, or may be a connection request sent by the first terminal to the first device.
  • the first terminal when the first terminal receives the first message sent by the first device, it can trigger the first terminal to send the above-mentioned first non-access layer NAS message and/or first indication information to the network side device, so that the network side performs the first operation on the first device; or, when the first terminal receives the above-mentioned sixth message sent by the second terminal, it can trigger the first terminal to send the above-mentioned first non-access layer NAS message and/or first indication information to the network side device, so that the network side performs the first operation on the first device.
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request. That is, in the aforementioned situation 2, the first terminal can send the PDU modification request or the PDU session establishment request as the first NAS message to the network side to trigger the network side to perform the first operation.
  • the first indication information includes at least one of the following items B-1 to B-4:
  • Item B-1 an instruction for instructing to perform the first operation
  • Item B-2 information about the first device
  • Item B-3 information of the first terminal
  • Item B-4 Information about a second network function, wherein the second network function is used to perform the first operation.
  • the information of the first terminal may include at least one of an identifier, an IP address, and a MAC address; the information of the first device may include at least one of an identifier, an IP address, and a MAC address.
  • the above item B-1 indicates that the first terminal can display and instruct the network side to perform the first operation
  • Item B-2 above indicates that the first terminal may implicitly instruct the network side to perform the first operation through information of the first device;
  • the above item B-3 indicates that the first terminal can implicitly instruct the network side to perform the first operation through the information of the first terminal;.
  • the network side when the network side receives the first indication information sent by the first terminal including the above-mentioned indication for instructing to perform the first operation, it can be determined based on the displayed indication content that the first operation needs to be performed on the device (i.e., the first device) that sends the above-mentioned first message to the first terminal; when the network side receives the first indication information sent by the first terminal including the information of the above-mentioned first device, it can also be determined through the implicit indication content that the first operation needs to be performed on the first device; when the network side receives the first indication information sent by the first terminal including the information of the above-mentioned first terminal, it can also be determined through the implicit indication content that the first operation needs to be performed on the device (i.e., the first device) that sends the above-mentioned first message to the first terminal.
  • the second network function may be, for example, an external data network authentication and authorization center (AAA), that is, the first terminal may also inform the network side which network function performs the first operation.
  • AAA external data network authentication and authorization center
  • the method further includes:
  • the first terminal receives second indication information sent by the network side, wherein the second indication information is used to indicate a result of the first operation:
  • the first terminal performs at least one of the following items C-1 to C-3 according to the second indication information:
  • Item C-1 allowing or rejecting the first message sent by the first device to be received by the first terminal;
  • Item C-2 Allow or deny processing of data of the first device
  • Item C-3 allowing, retaining or releasing the connection between the first terminal and the first device
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the network side After the network side receives the first non-access layer NAS message and/or the first indication information, it performs the first operation on the first device according to the indication of the first non-access layer NAS message and/or the first indication information, thereby returning the result of executing the first operation to the first terminal.
  • the first terminal can execute at least one of the above items C-1 to C-3 according to the result of executing the first operation.
  • the method further comprises:
  • the first terminal executes at least one of the following items G-1 to G- according to the fifth indication information:
  • Item G-1 Execute or stop executing the first operation
  • Item G-2 sending or stopping sending sixth indication information to the second network function, where the sixth indication information is used to instruct the second network function to perform the first operation;
  • Item G-3 sending or stopping sending a fourth message to the second network function, where the fourth message is a message related to performing the first operation;
  • Item G-4 receiving or stopping receiving a fifth message from the second network function, where the fifth message is a message related to performing the first operation;
  • Item G-5 allowing or rejecting the first message sent by the first device and received by the first terminal;
  • Item G-6 Allow or deny processing of data on the first device
  • Item G-7 allowing, retaining or releasing the connection between the first terminal and the first device
  • the first message is used to indicate at least one of the following:
  • Establish a connection between the first device and the first terminal access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
  • the above-mentioned item G-1 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal performs the first operation; when the fifth indication information does not allow the first operation, or does not allow the first operation to be performed through the control plane of the network side, or does not allow the first operation to be performed through the user plane of the network side, the first terminal stops performing the first operation.
  • the above G-2 item indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal sends the sixth indication information to the second network function; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the first terminal stops sending the sixth indication information to the second network function;
  • the above-mentioned item G-3 indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the first terminal sends the fourth message to the second network function; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the first terminal stops sending the fourth message to the second network function;
  • the above-mentioned item G-4 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the fifth message from the second network function is received; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the fifth message from the second network function is stopped;
  • the above G-5 item indicates: when the fifth indication information indicates that the first operation is allowed, or the control plane on the network side is allowed When performing the first operation or allowing the first operation to be performed through the user plane of the network side, allowing the first message sent by the first device received by the first terminal; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, rejecting the first message sent by the first device received by the first terminal;
  • the above-mentioned item G-6 indicates that: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the processing of the data of the first device is allowed; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the processing of the data of the first device is rejected;
  • the above-mentioned item G-7 indicates: when the fifth indication information indicates that the first operation is allowed, or the first operation is allowed to be performed through the control plane of the network side, or the first operation is allowed to be performed through the user plane of the network side, the connection between the first terminal and the first device is allowed or retained; when the fifth indication information indicates that the first operation is not allowed, or the first operation is not allowed to be performed through the control plane of the network side, or the first operation is not allowed to be performed through the user plane of the network side, the connection between the first terminal and the first device is released.
  • the first terminal receiving the second indication information sent by the network side includes:
  • the first terminal receives a second NAS message sent by the network side, wherein the second NAS message carries the second indication information.
  • the network side may carry the second indication information used to indicate the result of executing the first operation in the second NAS message, and send the message to the first terminal.
  • the second indication information satisfies at least one of the following items D-1 to D-2:
  • Item D-1 indicating the result of the first operation by an identifier or a name of the second NAS message
  • Item D-1 Indicate the result of the first operation through a cause value.
  • the above item D-1 represents the identifier or name of different second NAS messages, indicating different results of the first operation.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the second NAS message sent by the network side to the first terminal is a PDU session modification confirmation message or a PDU session establishment confirmation message, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side to the first terminal is a PDU session modification rejection message or a PDU session establishment rejection message, it indicates that the first operation fails.
  • the network side when the network side successfully executes the first operation, it returns a PDU session modification confirmation message or a PDU session establishment confirmation message to the first terminal; when the network side fails to execute the first operation, it returns a PDU session modification rejection message or a PDU session establishment rejection message to the first terminal.
  • the above-mentioned item D-2 indicates that the result of the first operation indicating a difference is displayed by the cause value.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the second NAS message sent by the network side includes a failure cause value and/or a failure indication, it indicates that the first operation has failed; if the second NAS message sent by the network side does not include a failure cause value and/or a failure indication, it indicates that the first operation has been successfully executed.
  • the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side does not include a success reason value and/or a success indication, it indicates that the first operation fails.
  • the second NAS message sent by the network side includes a failure reason value and/or a failure indication, it indicates that the first operation has failed to execute; if the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation has been executed successfully.
  • the method further comprises at least one of the following:
  • the first terminal receives a second message from the network side, and sends the second message to the first device;
  • the first terminal receives a third message from the first device, and sends the third message to the network side;
  • the second message and the third message are messages involved in executing the first operation, that is, the second message and the third message are messages that the first device and the network side need to interact with when executing the first operation.
  • the first terminal can also forward interaction messages for the first device and the network side.
  • the network side may send a second message to the first terminal for requesting the identification information of the first device, so that the first terminal sends the second message to the first device, and the first device returns a third message carrying the identification information of the first device to the first terminal, and the first terminal returns the third message to the network side.
  • the second message is an extensible authentication protocol (EAP) message
  • the third message is an EAP message
  • step 201 can be as described in the following method 1, method 2 or method 3:
  • the method further includes:
  • the first terminal receives the rule information sent by the network side
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information.
  • the first terminal can send the first non-access layer NAS message and/or the first indication information according to the rule information sent by the network side (i.e., the third network function, such as the policy control function entity (Policy Control Function, PCF)).
  • the third network function such as the policy control function entity (Policy Control Function, PCF)
  • rule information is used to indicate at least one of the following items E-1 to E-2:
  • Item E-1 the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • Item E-2 At least one first target device requires the first operation or does not require the first operation.
  • the target PIN is one of the PINs created by the second terminal;
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the above item E-1 indicates that the rule information can indicate whether the first operation needs to be performed for the PIN, that is, whether the first operation needs to be performed is indicated with the PIN as the granularity.
  • the above-mentioned item E-2 indicates that the rule information may also indicate whether the first operation needs to be performed for each PINE, that is, indicating whether the first operation needs to be performed with PINE as the granularity.
  • the second terminal for example, the management terminal (PIN Element with Management Capability, PEMC)
  • the management terminal PIN Element with Management Capability, PEMC
  • the fifth network function for example, the application function (Application Function, AF)
  • the third network function for example, PCF
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information, including at least one of the following:
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side;
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side:
  • Item H-1 the first non-access stratum NAS message and/or the first indication information is related to the target PIN;
  • Item H-2 The connection between the first terminal and the first device is related to the target PIN;
  • Item H-3 the first message sent by the first device and received by the first terminal is related to the target PIN;
  • Item H-4 The first device is associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the first terminal does not send the first non-access layer NAS message and/or the first indication information to the network side;
  • the first terminal When the rule information indicates that the first device does not need the first operation, the first terminal does not send the first non-access stratum NAS message and/or the first indication information to the network side.
  • the method further includes:
  • the first terminal receives configuration information sent by the second terminal;
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the configuration information.
  • the first terminal can send the first non-access stratum NAS message and/or the first indication information according to the configuration information sent by the second terminal (for example, PEMC).
  • the second terminal for example, PEMC
  • the configuration information is used to indicate at least one of the following items F-1 to F-2:
  • Item F-1 the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • Item F-2 At least one second target device requires the first operation or does not require the first operation.
  • the target PIN is one of the PINs created by the second terminal;
  • the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  • the above item F-1 indicates that the configuration information can indicate whether the first operation needs to be performed for the PIN, that is, whether the first operation needs to be performed is indicated with the PIN as the granularity.
  • the above item F-2 indicates that the configuration information may also indicate whether the first operation needs to be performed for each PINE, that is, indicating whether the first operation needs to be performed with PINE as the granularity.
  • the second terminal may indicate to the first terminal whether the first operation needs to be applied to the PIN and/or whether a PIN needs the first operation.
  • the first terminal when the configuration information indicates that the first device requires the first operation, the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side;
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side:
  • Item L-1 the first non-access stratum NAS message and/or the first indication information is related to the target PIN;
  • Item L-2 The connection between the first terminal and the first device is related to the target PIN;
  • Item L-3 the first message sent by the first device and received by the first terminal is related to the target PIN;
  • Item L-4 The first device is associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the first terminal does not send the first non-access layer NAS message and/or the first indication information to the network side;
  • the first terminal When the configuration information indicates that the first device does not need the first operation, the first terminal does not send the first non-access stratum NAS message and/or the first indication information to the network side.
  • the method further includes:
  • the first terminal receives the PIN rule information sent by the network side;
  • the first terminal receives configuration information sent by the second terminal;
  • the first terminal sends a first non-access layer NAS message and/or first indication information to the network side, including:
  • the first terminal sends the first non-access stratum NAS message and/or the first indication information to the network side according to the rule information and the configuration information.
  • the first terminal can send the first non-access stratum NAS message and/or the first indication information according to the rule information sent by the network side and the configuration information sent by the second terminal.
  • the content indicated by the rule information can refer to the aforementioned method 1
  • the content indicated by the configuration information can refer to the aforementioned method 2. That is, both the rule information and the configuration information can perform the aforementioned PIN granularity indication and PINE granularity indication.
  • the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side according to the rule information and the configuration information, including:
  • the first non-access layer NAS message and/or the first indication information is sent to the network side.
  • the specific method of sending the first non-access layer NAS message and/or the first indication information to the network side according to the rule information is the same as the aforementioned method one; when the one with a higher priority between the rule information and the configuration information is the configuration information, the specific method of sending the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information is the same as the aforementioned method two and is not repeated here.
  • the method further comprises:
  • the first terminal sends information of the first device to the network side.
  • the first terminal can also send information of the first device to the network side (for example, the first network function).
  • the information of the first device may include address information of the first device (eg, IP address).
  • an embodiment of the present application provides an operation execution method. As shown in FIG. 3 , the method may include the following steps 301 and/or 302 and 303:
  • Step 301 The first network function sends fifth indication information to the first terminal.
  • the fifth indication information is used to indicate at least one of the following:
  • the method further includes:
  • the first network function interacts with the first terminal to establish a PDU session
  • Step 301 “the first network function sends fifth indication information to the first terminal” includes:
  • the first network function sends a PDU session establishment/modification confirmation message to the first terminal, and the PDU session establishment/modification confirmation message carries the fifth indication information.
  • the first network function may carry the fifth indication information in a PDU session establishment/modification confirmation message and send it to the first terminal.
  • Step 302 The first network function receives a first non-access stratum NAS message and/or first indication information sent by the first terminal.
  • the first non-access stratum NAS message is used to indicate the first operation
  • the first indication information is used to indicate the first operation
  • the first operation includes at least one of authentication, certification, and authorization.
  • the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function
  • the first terminal can be, for example, a terminal with gateway capability, i.e., a gateway terminal (PIN Element with Gateway Capability, PEGC);
  • the first network function can be, for example, a session management function (Session Management Function, SMF) or an access and mobility management function (Access and Mobility Management Function, AMF).
  • SMF Session Management Function
  • AMF Access and Mobility Management Function
  • the first terminal can send a first non-access layer NAS message to the network side (such as the above-mentioned first network function) to instruct the network side to perform the first operation (that is, trigger the network side to perform the first operation through a NAS message); or, it can send a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side device to perform the first operation through an indication information); or, it can also send a first NAS message and a first indication information to the network side to instruct the network side to perform the first operation (that is, instruct the network side to perform the first operation through a NAS message and an indication information), where the first NAS message and the first indication information can be independent, or the first indication information can be carried in the first NAS message.
  • the network side such as the above-mentioned first network function
  • the first operation includes at least one of the following:
  • Step 303 The first network function performs at least one of the following in response to the first non-access stratum NAS message and/or the first indication information:
  • the first network function can establish/modify the PDU session after receiving the PDU sent by the first terminal.
  • the fifth indication information is carried in the PDU session establishment/modification confirmation message and sent to the first terminal to inform the first terminal whether it allows the first operation; or after the first network function receives the first non-access layer NAS message and/or the first indication information sent by the first terminal, the fifth indication information is sent to the first terminal to inform the first terminal whether it allows the first operation.
  • the first network function is capable of receiving a first non-access layer NAS message and/or a first indication information sent by the first terminal, thereby responding to the first non-access layer NAS message and/or the first indication information, sending fifth indication information to the first terminal and/or instructing the second network function and the first terminal to perform a first operation; and/or, the first network function sends the fifth indication information to the first terminal; wherein the first non-access layer NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, the first operation includes at least one of authentication, authentication, and authorization, and the fifth indication information is used to indicate at least one of the following:
  • the first terminal can instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first non-access layer NAS message, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first indication information, or instruct the network side to perform at least one of the authentication, certification, and authorization operations by sending a first NAS message and a first indication information; and can also receive the fifth indication information sent by the network side. Therefore, the operation execution method of the embodiment of the present application can be used to perform at least one of the authentication, certification, and authorization operations on the device in the PIN, thereby improving the security of accessing the PIN.
  • the method further includes:
  • the first network function receives third indication information sent by the second network function, wherein the third indication information is used to indicate a result of the first operation;
  • the first network function sends second indication information to the first terminal according to the third indication information, where the second indication information is used to indicate a result of the first operation.
  • the second network function is used to perform the first operation. After the second network function performs the first operation, it can return third indication information indicating the result of the first operation to the first network function, and then the first network function returns second indication information indicating the result of the first operation to the first terminal based on the third indication information.
  • the first terminal may also meet the following conditions 1 or 2:
  • the first terminal can also have the function of a personal Internet of Things device (PIN Element, PINE) and gateway capabilities, that is, PEGC and PINE can be combined into one device.
  • PINE personal Internet of Things device
  • PEGC and PINE can be combined into one device.
  • the first terminal may not have the PINE capability.
  • the first terminal only has the gateway capability, that is, PEGC and PINE are independently configured.
  • the method further includes:
  • the first network function interacts with the first terminal to establish a protocol data unit (PDU) session.
  • PDU protocol data unit
  • the first terminal formed by combining PEGC and PINE can also establish a PDU session with the network side before sending the first non-access layer NAS message and/or the first indication information to the network side.
  • the first terminal before the first terminal sends the first non-access layer NAS message and/or the first indication information to the network side, if a PDU session is established, the first terminal can subsequently use the modification process of the subsequent PDU session to send the first non-access layer NAS message to the network side.
  • the first non-access layer NAS message is a PDU session modification request. That is, in the aforementioned situation 1, the first terminal can send the PDU modification request as the first NAS message to the network side to trigger the network side to perform the first operation.
  • the first indication information includes at least one of the following items A-1 to A-3:
  • Item A-1 an instruction for instructing to perform the first operation
  • Item A-2 information of the first terminal
  • Item A-3 Information about a second network function, wherein the second network function is used to perform the first operation.
  • the first indication information includes at least one of the following items B-1 to B-4:
  • Item B-1 an instruction for instructing to perform the first operation
  • Item B-2 information about the first device
  • Item B-3 information of the first terminal
  • Item B-4 Information about a second network function, wherein the second network function is used to perform the first operation.
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request. That is, in the aforementioned situation 2, the first terminal can send the PDU modification request or the PDU session establishment request as the first NAS message to the network side to trigger the network side to perform the first operation.
  • the first network function sending second indication information to the first terminal according to the third indication information includes:
  • the first network function sends a second NAS message to the first terminal according to the third indication information, wherein the second NAS message carries the second indication information.
  • the first network function may carry the second indication information used to indicate the result of executing the first operation in the second NAS message, and send the message to the first terminal.
  • the second indication information satisfies at least one of the following items D-1 to D-2:
  • Item D-1 indicating the result of the first operation by an identifier or a name of the second NAS message
  • Item D-1 Indicate the result of the first operation through a cause value.
  • the above item D-1 represents the identifier or name of different second NAS messages, indicating different results of the first operation.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the second NAS message sent by the network side to the first terminal is a PDU session modification confirmation message or a PDU session establishment confirmation message, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side to the first terminal is a PDU session modification rejection message or a PDU session establishment rejection message, it indicates that the first operation fails.
  • the network side when the network side successfully executes the first operation, it returns a PDU session modification confirmation message or a PDU session establishment confirmation message to the first terminal; when the network side fails to execute the first operation, it returns a PDU session modification rejection message or a PDU session establishment rejection message to the first terminal.
  • the above-mentioned item D-2 indicates that the result of the first operation indicating a difference is displayed by the cause value.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the second NAS message sent by the network side includes a failure cause value and/or a failure indication, it indicates that the first operation has failed; if the second NAS message sent by the network side does not include a failure cause value and/or a failure indication, it indicates that the first operation has been successfully executed.
  • the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation is executed successfully; if the second NAS message sent by the network side does not include a success reason value and/or a success indication, it indicates that the first operation fails.
  • the second NAS message sent by the network side includes a failure reason value and/or a failure indication, it indicates that the first operation has failed to execute; if the second NAS message sent by the network side includes a success reason value and/or a success indication, it indicates that the first operation has been executed successfully.
  • the method further comprises at least one of the following:
  • the first network function receives a second message forwarded by the first terminal for the first device
  • the first network function sends a third message to the first terminal, so that the first terminal forwards the third message to the first device;
  • the second message and the third message are messages involved in executing the first operation, that is, the second message and the third message are messages that the first device and the network side need to interact with when executing the first operation.
  • the first terminal can also forward the interaction message for the first device and the first network function.
  • the first network function may send a second message for requesting the identification information of the first device to the first terminal, so that the first terminal The terminal sends the second message to the first device, so that the first device returns a third message carrying the identification information of the first device to the first terminal, and the first terminal returns the third message to the first network function.
  • the first network function instructs the second network function to perform the first operation, including:
  • the first network function sends identification information of the first device to the second network function to instruct the second network function to perform the first operation.
  • the first network function instructs the second network function and the first terminal to perform the first operation in response to the first non-access layer NAS message, including at least one of the following items V-1 to V-5:
  • Item V-1 the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message;
  • Item V-2 the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message and the first association information between the PDU session related information and the PIN instance or session;
  • Item V-3 the first network function instructs the second network function and the first terminal to perform the first operation based on the PIN instance or session related information in the first non-access layer NAS message;
  • Item V-4 the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information and the PIN service indication information in the first non-access layer NAS message;
  • the first network function instructs the second network function and the first terminal to perform the first operation based on the PDU session related information in the first non-access layer NAS message, and the second association information between the PDU session related information and the PIN service.
  • the above-mentioned V-1 item indicates that if the PDU session related information in the first non-access layer NAS message is specific information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PDU session related information may include at least one of the PDU session identifier, the data network name (Data Network Name, DNN), and the network slice selection auxiliary information (Single Network Slice Selection Assistance Information, S-NSSAI).
  • S-NSSAI Single Network Slice Selection Assistance Information
  • the above-mentioned V-2 item indicates: if there is a PIN instance or session corresponding to the PDU session related information in the first non-access layer NAS message in the first association information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PDU session related information may include at least one of the PDU session identifier, DNN, and S-NSSAI.
  • the first network function instructs the second network function and the first terminal to perform the first operation.
  • the above item V-3 indicates that: if the first non-access layer NAS message includes PIN instance or session related information, the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PIN instance or session related information may include a PIN instance or a session identifier.
  • the first non-access layer NAS message contains indication information indicating that the PDU session related information is related to the PIN service (that is, it is related to the PIN service, rather than other services such as telephone service and video service), and the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PDU session related information may include at least one of the PDU session identifier, DNN, and S-NSSAI.
  • the above-mentioned item V-5 indicates that: if the second association information indicates that the PDU session-related information in the first non-access layer NAS message is related to the PIN service (referring to the PIN service, not other services such as telephone service and video service), the first network function instructs the second network function and the first terminal to perform the first operation, otherwise the second network function and the first terminal are not instructed to perform the first operation.
  • the PDU session-related information may include at least one of the PDU session identifier, DNN, and S-NSSAI. For example, when there is a PIN service corresponding to the PDU session identifier in the first NAS message in the second association information, the first network function instructs the second network function and the first terminal to perform the first operation.
  • the first network function may also instruct the second network function and the first terminal to perform the first operation according to the information of the sending device of the received first NAS message. For example, when the first NAS message is sent by a device with gateway capabilities (that is, when the first terminal is a terminal with gateway capabilities), the first network function instructs the second network function and the first terminal to perform the first operation; when the first NAS message is not sent by a device with gateway capabilities (that is, when the first terminal is not a terminal with gateway capabilities), the first network function does not instruct the second network function and the first terminal to perform the first operation.
  • the method further comprises:
  • the first network function learns at least one of the following from the third network function:
  • the second associated information The second associated information.
  • the third network function may be PCF or UDM.
  • the method further comprises:
  • the first network function receives information about the first device sent by the first terminal;
  • the first device is a device that needs to access the PIN or the network where the first network function is located through the first terminal.
  • the first terminal can also send information of the first device to the network side (for example, the first network function).
  • the information of the first device may include address information of the first device (eg, IP address).
  • the method further comprises:
  • the first network function uses the message filtering rule to configure a fourth network function.
  • the fourth network function may be, for example, a user plane function (User Port Function, UPF).
  • UPF User Port Function
  • the embodiment of the present application further provides an operation execution method, as shown in FIG4 , the method includes the following step 401:
  • Step 401 The third network function performs a second operation.
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • the third network function may be, for example, PCF or UDM.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the PDU session configuration information includes at least one of the following:
  • the second association information between the PDU session related information and the PIN service is the second association information between the PDU session related information and the PIN service.
  • the first terminal after the first terminal receives the rule information, it can send the first non-access layer NAS message and/or the first indication information to the first network function according to the rule information.
  • the specific sending method can be found in the above description and will not be repeated here.
  • the first network function After the first network function receives the PDU session configuration information, it can instruct the second network function and the first terminal to perform the first operation according to the PDU session configuration information (i.e., the first association information and/or the second association information).
  • the PDU session configuration information i.e., the first association information and/or the second association information.
  • the method further includes:
  • the third network function acquires fourth indication information, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
  • the third network function performs the second operation, including:
  • the third network function performs the second operation according to the fourth indication information.
  • the third network function acquires the fourth indication information, including:
  • the third network function receives the fourth indication information sent by the fifth network function.
  • the fifth network function may be AF.
  • the second terminal for example, the management terminal (PIN Element with Management Capability, PEMC)
  • the management terminal PIN Element with Management Capability, PEMC
  • the fifth network function for example, the application function (Application Function, AF)
  • the fifth network function sends the above-mentioned fourth indication information to the third network function, thereby triggering the third network function to perform the above-mentioned second operation.
  • the present application embodiment further provides an operation execution method, as shown in FIG5 , the method may include The steps 501 are as follows:
  • Step 501 The second terminal sends configuration information to the first terminal in the personal Internet of Things PIN.
  • the second terminal may be, for example, PEMC
  • the first terminal may be, for example, PEGC
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  • the first terminal can send a first non-access layer NAS message and/or a first indication information to the first network function according to the configuration information.
  • the specific sending method can be found in the above description and will not be repeated here.
  • the embodiment of the present application further provides an operation execution method, as shown in FIG6 , the method may include the following step 601:
  • Step 601 The fifth network function sends fourth indication information to the third network function.
  • the fifth network function may be AF.
  • the fourth indication information is used to instruct the third network function to perform a second operation
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the PDU session configuration information includes at least one of the following:
  • the second association information between the PDU session related information and the PIN service is the second association information between the PDU session related information and the PIN service.
  • the first terminal after the first terminal receives the rule information, it can send the first non-access layer NAS message and/or the first indication information to the first network function according to the rule information.
  • the specific sending method can be found in the above description and will not be repeated here.
  • the first network function After the first network function receives the PDU session configuration information, it can instruct the second network function and the first terminal to perform the first operation according to the PDU session configuration information (i.e., the first association information and/or the second association information).
  • the PDU session configuration information i.e., the first association information and/or the second association information.
  • Implementation method 1 as shown in FIG. 7 , it includes the following steps 71 to 716 (the first operation mentioned above includes authentication and/or authorization for illustration).
  • Step 71 The PEMC creates a PIN, can notify the AF that a PIN has been created, and can indicate whether access to the PIN requires 5G core network-assisted authentication and/or authorization.
  • PEMC can ask PINE for device information (for example, PEMC asks PINE for device information when PINE accesses PIN) to learn whether PINE has a credential, so that when PINE has a credential, when such PINE is added to a PIN, AF is instructed that the PINE needs authentication and/or authorization assisted by the 5G core network.
  • the credential is the authentication information.
  • Step 72 AF may notify PCF directly or through NEF whether the PIN requires authentication and/or authorization assisted by the 5G core network.
  • Step 73 After the PCF learns whether the PIN requires authentication and/or authorization assisted by the 5G core network, it generates rule information and sends the rule information to each PEGC in the PIN through the AMF.
  • the rule information is used to indicate whether access to the PIN requires authentication and/or authorization assisted by the 5G core network.
  • Step 74 The first PINE connects to the PEGC to access the PIN (eg, the first PINE sends a connection request to the PEGC).
  • Step 75 If the rule information obtained by PEGC indicates that the PIN requires authentication and/or authorization assisted by the 5G core network, configuration information is obtained from PEMC, wherein the configuration information is used to indicate whether at least one PINE requires authentication and/or authorization assisted by the 5G core network.
  • Step 76 If the configuration information indicates that the first PINE requires authentication and/or authorization assisted by the 5G core network, the PEGC sends a first NAS message to the SMF, wherein the first NAS message carries an indication for indicating authentication and/or authorization; if the configuration information indicates that the first PINE does not require authentication and/or authorization assisted by the core network, the PEGC does not send the first NAS message to the SMF.
  • the first NAS message can be a PDU session modification request (PDU Session Modification Request) or a PDU session establishment request (PDU Session Establishment Request).
  • PDU Session Modification Request PDU Session Modification Request
  • PDU Session Establishment Request PDU Session Establishment Request
  • Step 77 If the SMF receives the first NAS message, it determines whether the first PINE needs to be authenticated and/or authorized based on the relevant information of the first NAS message, and then executes the following step 78 when determining whether the first PINE needs to be authenticated and/or authorized;
  • the relevant information of the first NAS message includes at least one of the following:
  • PDU session related information in the first NAS message e.g. PDU session identifier, DNN, S-NASSAI
  • PIN instance or session related information e.g. PIN identifier
  • the PDU session related information and the PIN service indication information in the first NAS message i.e., indicating that the PDU session related information in the first NAS message is related to the PIN service
  • Step 78 SMF sends a first EAP message to PEGC, so that PEGC forwards the first EAP message to PINE, wherein the first EAP message is used to request the ID of PINE; the first EAP message may be an EAP identity in an EAP request (EAP Request);
  • Step 79 PINE sends a second EAP message to PEGC, so that PEGC forwards the first EAP message to SMF, wherein the second EAP message carries the ID of PINE; the second EAP message may be an EAP identity in an EAP response (EAP Response);
  • Step 710 SMF sends a second EAP message to the external data network authentication authority (AAA).
  • AAA external data network authentication authority
  • Step 711 AAA and PINE exchange EAP messages (such as EAP Request, EAP Response) through SMF, UPF, and PEGC to complete the authentication and/or authorization process.
  • EAP messages such as EAP Request, EAP Response
  • Step 712 If the authentication and/or authorization is successful, AAA (eg, through UPF) sends an EAP success (EAP-Success message) to SMF.
  • AAA eg, through UPF
  • EAP success EAP-Success message
  • Step 713 If SMF receives the EAP-Success message, SMF sends a PDU session establishment acknowledgment (PDU Session Establishment Ack) or a PDU session modification acknowledgment (PDU Session Modification Ack) to PEGC, otherwise it sends a PDU session establishment reject (PDU Session Establishment Reject) or a PDU session modification reject (PDU Session Modification Reject).
  • PDU Session Establishment Ack PDU session establishment acknowledgment
  • PDU Session Modification Ack PDU Session Modification Ack
  • PDU Session Establishment Ack or PDU Session Modification Ack may also carry at least one of the indication of successful authentication and/or authorization and the reason value of successful authentication and/or authorization;
  • PDU Session Establishment Reject or PDU Session Modification Reject may also carry at least one of the indication of authentication and/or authorization failure and the reason value of authentication and/or authorization failure.
  • Step 714 If the PEGC receives a PDU Session Establishment Ack or a PDU Session Modification Ack, the PEGC allows the first PINE to connect to access the PIN, otherwise the PEGC rejects the connection of the first PINE.
  • Step 715 If PEGC receives PDU Session Establishment Ack or PDU Session Modification Ack, PEGC can also send the IP address of the first PINE to SMF.
  • Step 716 SMF can authorize the communication configuration of the PIN (including message filtering rules) based on the received IP address of the first PINE, such as accepting the message filtering rules related to the first PINE (i.e., accepting the message filtering rules containing the IP address of the PINE).
  • SMF may be replaced by AMF
  • UPF may be replaced by authentication service function (AUSF); or UPF or AUSF may not be involved in this implementation.
  • AUSF authentication service function
  • Implementation method 2 includes the following steps 81 to 811 .
  • Step 81 PEGC establishes a PDU Session and initiates a PDU session establishment request (PDU Session Establishment Request).
  • Step 82 SMF returns a PDU Session Establishment Ack message, carrying the fifth indication information, and the first operation includes at least one of authentication, certification, and authorization.
  • the fifth indication information is used to indicate at least one of the following:
  • Step 83 The first PINE connects to the PEGC to access the PIN (eg, the first PINE sends a connection request to the PEGC).
  • Step 84 PEMC creates a PIN and can notify AF that a PIN has been created.
  • PEMC can send a Communication Request message to PEGC to indicate that one or more PINEs of PEGC need to perform the first operation.
  • the fifth indication information in the aforementioned step 82 indicates that the first operation is not allowed, or an operation is not allowed to be performed through the control plane of the mobile network where the SMF is located, or the first operation is not allowed to be performed through the user plane of the mobile network where the SMF is located, then the subsequent steps stop executing, otherwise the subsequent steps are executed.
  • Step 85 PEGC sends a PDU Session Modification Request to SMF, which may carry at least one of the first indication information, the first PINE information, the PEGC information, and the AAA information.
  • the first indication information is used to indicate the first operation.
  • Step 86 If the SMF allows the first operation, or allows the AAA in step 85 to perform the first operation, or allows the PEGC or the first PINE in step 85 to perform the first operation, or allows the PEGC or the first PINE in step 85 and the AAA to perform the first operation, it returns a PDU Session Modification Ack message; otherwise, it returns a PDU Session Modification Reject message, which may carry indication information for indicating that the first operation is not allowed.
  • Step 87 If the first operation is allowed, the PEGC may send a first EAP message to the first PINE to request the ID of the first PINE; the first EAP message may be an EAP identity in an EAP request (EAP Request);
  • Step 88 PINE sends a second EAP message to PEGC, carrying the ID of the first PINE; the second EAP message can be the EAP identity (EAP Identity) in the EAP response (EAP Response).
  • EAP Identity EAP identity
  • EAP Response EAP response
  • Step 89 PEGC sends the ID of the first PINE to the external data network authentication authority (AAA) through the user of the 5G system.
  • AAA external data network authentication authority
  • Step 810 AAA and PINE exchange EAP messages (such as EAP Request and EAP Response) through PEGC to perform the first operation.
  • EAP messages such as EAP Request and EAP Response
  • Step 811 If the first operation is successful, AAA sends an EAP-Success message to PEGC, otherwise it sends an EAP failure (send EAP-Failure) message. If PEGC receives EAP-Success, it allows the first PINE to connect to access the PIN, otherwise PEGC rejects the connection of the first PINE.
  • SMF may be replaced by AMF
  • UPF may be replaced by authentication service function (AUSF); or UPF or AUSF may not be involved in this implementation.
  • AUSF authentication service function
  • Implementation Mode 1 and Implementation Mode 2 are only two implementation modes of the embodiment of the present application, that is, the specific implementation mode of the operation execution method of the embodiment of the present application is not limited thereto, and can also be various possible combinations of the aforementioned contents.
  • the operation execution method provided in the embodiment of the present application can be executed by an operation execution device.
  • the operation execution device provided in the embodiment of the present application is described by taking the operation execution method executed by the operation execution device as an example.
  • an embodiment of the present application provides an operation execution device, which is applied to a first terminal.
  • the operation execution device 90 includes the following modules:
  • a first sending module 901 is configured to send a first non-access stratum NAS message and/or first indication information to a network side, wherein the first non-access stratum NAS message is used to indicate a first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first receiving module 902 is configured to receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • the device further comprises:
  • the first establishing module is used to interact with the network side to establish a protocol data unit PDU session before the first sending module 901 sends the first non-access layer NAS message and/or the first indication information to the network side.
  • the first non-access layer NAS message is a PDU session modification request.
  • the first indication information includes at least one of the following:
  • the first sending module 901 includes:
  • the first sending submodule is used for, when or after the connection between the first terminal and the first device is established, for the first terminal to send the first non-access layer NAS message and/or the first indication information to the network side.
  • the first sending submodule is specifically used for:
  • the first message is used to indicate at least one of the following:
  • the sixth message is used to instruct the first terminal or the first device to communicate with the second network function
  • the second network function is used to perform the first operation.
  • the first indication information includes at least one of the following:
  • the device further comprises:
  • a third receiving module is configured to receive second indication information sent by the network side after the first sending module 901 sends the first non-access layer NAS message and/or the first indication information to the network side, wherein the second indication information is used to indicate a result of the first operation:
  • the third processing module is configured to perform at least one of the following according to the second indication information:
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the device further comprises:
  • the fourth processing module is configured to perform at least one of the following according to the fifth indication information:
  • the first message is used to indicate at least one of the following:
  • Establish a connection between the first device and the first terminal access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
  • the first receiving module 902 is specifically configured to:
  • a second NAS message sent by the network side is received, wherein the second NAS message carries the second indication information.
  • the second indication information satisfies at least one of the following:
  • the result of the first operation is indicated by a cause value.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the device further comprises at least one of the following modules:
  • a first forwarding module configured to receive a second message from the network side, and send the second message to the first device
  • a second forwarding module configured to receive a third message from the first device, and send the third message to the network side;
  • the second message and the third message are respectively messages involved in executing the first operation.
  • the second message is an Extensible Authentication Protocol (EAP) message
  • the third message is an EAP message.
  • EAP Extensible Authentication Protocol
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
  • the device further comprises:
  • a fourth receiving module used to receive the rule information sent by the network side
  • the first sending module includes:
  • the second sending submodule is used to send the first non-access layer NAS message and/or the first indication information to the network side according to the rule information.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation.
  • the second sending submodule is specifically configured to perform at least one of the following:
  • the first non-access stratum NAS message and/or the first indication information are related to the target PIN;
  • connection between the first terminal and the first device is associated with the target PIN
  • the first message sent by the first device and received by the first terminal is related to the target PIN;
  • the first device being associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the device further comprises:
  • a fifth receiving module configured to receive configuration information sent by the second terminal
  • the first sending module 901 includes:
  • the third sending submodule is used for the first terminal to send the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information.
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation.
  • the third sending submodule is specifically configured to perform at least one of the following:
  • the first non-access stratum NAS message and/or the first indication information are related to the target PIN;
  • connection between the first terminal and the first device is associated with the target PIN
  • the first message sent by the first device and received by the first terminal is related to the target PIN;
  • the first device being associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the device further comprises:
  • a fifth sending module is used to send information of the first device to the network side when the second indication information indicates that the first operation is successful.
  • the first terminal is a terminal with gateway capability.
  • the operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in an electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a terminal, for example
  • the terminal may include but is not limited to the types of the terminal 11 listed above, and the embodiment of the present application does not make any specific limitation.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 2 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application provides an operation execution device, which is applied to a first network function.
  • the operation execution device 100 includes the following modules:
  • the second sending module 1001 is used to send fifth indication information to the first terminal
  • the second receiving module 1002 is configured to receive a first non-access stratum NAS message and/or first indication information sent by the first terminal, wherein the first non-access stratum NAS message is used to indicate the first operation, the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, certification, and authorization;
  • the first processing module 1003 is configured to, in response to the first non-access stratum NAS message and/or the first indication information, perform at least one of the following:
  • the fifth indication information is used to indicate at least one of the following:
  • the first operation is allowed or not allowed to be performed through a user plane of the mobile network.
  • the device further comprises:
  • a sixth receiving module configured to receive third indication information sent by the second network function when the first network function instructs the second network function and the first terminal to perform the first operation, wherein the third indication information is used to indicate a result of the first operation;
  • the sixth sending module is used to send second indication information to the first terminal according to the third indication information, where the second indication information is used to indicate a result of the first operation.
  • the device further comprises:
  • the second establishing module is used to interact with the first terminal to establish a protocol data unit PDU session before the first network function receives the first non-access layer NAS message and/or the first indication information sent by the first terminal.
  • the first non-access layer NAS message is a PDU session modification request.
  • the first indication information includes at least one of the following:
  • the first indication information includes at least one of the following:
  • the first device needs to access the personal IoT PIN through the first terminal or a device in the network where the first network function is located;
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
  • the sixth sending module is specifically configured to:
  • a second NAS message is sent to the first terminal, wherein the second NAS message carries the second indication information.
  • the second indication information satisfies at least one of the following:
  • the result of the first operation is indicated by a cause value.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the first processing module when the first processing module instructs the second network function and the first terminal to perform the first operation in response to the first non-access layer NAS message, the first processing module is specifically configured to perform at least one of the following:
  • the second network function and the first terminal are instructed to perform the first operation.
  • the device further comprises:
  • the fifth processing module is configured to obtain at least one of the following from the third network function:
  • the second associated information The second associated information.
  • the device further comprises:
  • a seventh receiving module configured to receive information about the first device sent by the first terminal when the second indication information indicates that the first operation is successful
  • the first device is a device that needs to access the PIN or the network where the first network function is located through the first terminal.
  • the device further comprises:
  • a configuration module is used for, when the first network function learns a message filtering rule and the message filtering rule is related to the first device, the first network function uses the message filtering rule to configure a fourth network function.
  • the operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a network function.
  • the network function can include but is not limited to the types of network functions 12 listed above, and the embodiment of the present application does not specifically limit this.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 3 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application provides an operation execution device, which is applied to a third network function.
  • the operation execution device 110 includes the following modules:
  • the second processing module 1101 is used to perform a second operation
  • the second operation includes at least one of the following:
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the PDU session configuration information includes at least one of the following:
  • the second association information between the PDU session related information and the PIN service is the second association information between the PDU session related information and the PIN service.
  • the device further comprises:
  • a sixth processing module configured to obtain fourth indication information before the second processing module 1101 performs the second operation, wherein the fourth indication information is used to instruct the third network function to perform the second operation;
  • the second processing module 1101 is specifically used for:
  • the second operation is performed according to the fourth indication information.
  • the sixth processing module is specifically configured to:
  • the third network function receives the fourth indication information sent by the fifth network function.
  • the operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a network function, and illustratively, the network function can include but is not limited to the types of network functions 12 listed above, which are not specifically limited in the embodiment of the present application.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 4 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application provides an operation execution device, which is applied to a second terminal.
  • the operation execution device 120 includes the following modules:
  • the third sending module 1201 is used to send configuration information to the first terminal in the personal Internet of Things PIN.
  • the first terminal in the personal Internet of Things PIN created by the second terminal device sends configuration information.
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  • the operation execution device in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a terminal, and illustratively, the terminal can include but is not limited to the types of the terminal 11 listed above, and the embodiment of the present application does not specifically limit it.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 5 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application provides an operation execution device, which is applied to the fifth network function.
  • the operation execution device 130 includes the following modules:
  • the fourth sending module 1301 is configured to send fourth indication information to the third network function, wherein the fourth indication information is used to instruct the third network function to perform a second operation;
  • the second operation includes at least one of the following:
  • the third network function sends rule information to the first terminal
  • the third network function sends data protocol unit PDU session configuration information to the first network function.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the first target device is a device that needs to access the personal Internet of Things PIN or the mobile network where the third network function is located through the first terminal.
  • the PDU session configuration information includes at least one of the following:
  • the second association information between the PDU session related information and the PIN service is the second association information between the PDU session related information and the PIN service.
  • the operation execution method in the embodiment of the present application can be an electronic device, such as an electronic device with an operating system, or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a network function, and illustratively, the network function can include but is not limited to the types of network functions 12 listed above, which are not specifically limited in the embodiment of the present application.
  • the operation execution device provided in the embodiment of the present application can implement each process implemented by the method embodiment of Figure 6 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the embodiment of the present application further provides a communication device 1400, including a processor 1401 and a memory 1402, the memory 1402 stores a program or instruction that can be run on the processor 1401, for example, when the communication device 1400 is a terminal, the program or instruction is executed by the processor 1401 to implement the various steps of the above-mentioned operation execution method embodiment, and can achieve the same technical effect.
  • the communication device 1400 is a network function
  • the program or instruction is executed by the processor 1401 to implement the various steps of the above-mentioned operation execution method embodiment, and can achieve the same technical effect, to avoid repetition, it will not be repeated here.
  • the embodiment of the present application also provides a terminal, as shown in FIG14 , which is a schematic diagram of the hardware structure of a terminal for implementing the embodiment of the present application.
  • the terminal 1400 includes but is not limited to: a radio frequency unit 1401, a network module 1402, an audio output unit 1403, an input unit 1404, a sensor 1405, a display unit 1406, a user input unit 1407, an interface unit 1408, a memory 1409 and at least some of the components of the processor 1410.
  • the terminal 1400 may also include a power source (such as a battery) for supplying power to each component, and the power source may be logically connected to the processor 1410 through a power management system, so as to implement functions such as charging, discharging, and power consumption management through the power management system.
  • a power source such as a battery
  • the terminal structure shown in FIG14 does not constitute a limitation on the terminal, and the terminal may include more or fewer components than shown in the figure, or combine certain components, or arrange components differently, which will not be described in detail here.
  • the input unit 1404 may include a graphics processing unit (GPU) 14041 and a microphone 14042, and the graphics processor 14041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode.
  • the display unit 1406 may include a display panel 14061, and the display panel 14061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc.
  • the user input unit 1407 includes a touch panel 14071 and at least one of other input devices 14072.
  • the touch panel 14071 is also called a touch screen.
  • the touch panel 14071 may include two parts: a touch detection device and a touch controller.
  • Other input devices 14072 may include, but are not limited to, a physical keyboard, function keys, and the like. (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be repeated here.
  • the RF unit 1401 can transmit the data to the processor 1410 for processing; in addition, the RF unit 1401 can send uplink data to the network function.
  • the RF unit 1401 includes but is not limited to an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.
  • the memory 1409 can be used to store software programs or instructions and various data.
  • the memory 1409 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.), etc.
  • the memory 1409 may include a volatile memory or a non-volatile memory, or the memory 1409 may include both volatile and non-volatile memories.
  • the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
  • the volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM).
  • the memory 1409 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
  • the processor 1410 may include one or more processing units; optionally, the processor 1410 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 1410.
  • the radio frequency unit 1401 is used to send a first non-access layer NAS message and/or first indication information to the network side, wherein the first non-access layer NAS message is used to indicate a first operation, and the first indication information is used to indicate the first operation, and the first operation includes at least one of authentication, authentication, and authorization;
  • the radio frequency unit 1401 is further used to: receive fifth indication information sent by the network side, wherein the fifth indication information is used to indicate at least one of the following:
  • the processor 1410 is used to: interact with the network side to establish a protocol data unit PDU session.
  • the first non-access layer NAS message is a PDU session modification request.
  • the first indication information includes at least one of the following:
  • the radio frequency unit 1401 sends a first non-access layer NAS message and/or first indication information to the network side, specifically used for:
  • the first non-access layer NAS message and/or the first indication information is sent to the network side.
  • the radio frequency unit 1401 when or after the connection is established between the first terminal and the first device, the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side, specifically for:
  • the first message is used to indicate at least one of the following:
  • the sixth message is used to instruct the first terminal or the first device to communicate with the second network function
  • the second network function is used to perform the first operation.
  • the first indication information includes at least one of the following:
  • the radio frequency unit 1401 after the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side, it is further configured to:
  • the processor 1410 is further configured to: perform at least one of the following according to the second indication information:
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • processor 1410 is further configured to:
  • the first message is used to indicate at least one of the following:
  • Establish a connection between the first device and the first terminal access the first terminal, access the PIN where the first terminal is located, communicate with the network side, and communicate with the second network function.
  • the radio frequency unit 1401 receives the second indication information sent by the network side, specifically configured to:
  • a second NAS message sent by the network side is received, wherein the second NAS message carries the second indication information.
  • the second indication information satisfies at least one of the following:
  • the result of the first operation is indicated by a cause value.
  • the indicating a result of the first operation by using an identifier or a name of the second NAS message includes at least one of the following:
  • the failure of the first operation is indicated by a PDU session modification reject message or a PDU session establishment reject message.
  • the result of the first operation indicated by the reason value includes at least one of the following indications:
  • failure reason value and/or a failure indication used to indicate that the first operation failed
  • the second NAS message does not include the failure cause value and/or the failure indication, indicating that the first operation is successful
  • the second NAS message does not include the success cause value and/or the success indication, it indicates that the first operation fails.
  • the radio frequency unit 1401 is further configured to perform at least one of the following:
  • the second message and the third message are respectively messages involved in executing the first operation.
  • the second message is an Extensible Authentication Protocol (EAP) message
  • the third message is an EAP message.
  • EAP Extensible Authentication Protocol
  • the first non-access layer NAS message is a PDU session modification request or a PDU session establishment request.
  • the radio frequency unit 1401 is further used to: receive rule information sent by the network side;
  • the radio frequency unit 1401 sends a first non-access layer NAS message and/or a first indication information to the network side, specifically used for:
  • the first non-access layer NAS message and/or the first indication information are sent to the network side.
  • rule information is used to indicate at least one of the following:
  • the first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
  • At least one first target device requires the first operation or does not require the first operation.
  • the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side according to the rule information, specifically configured to perform at least one of the following:
  • the first non-access stratum NAS message and/or the first indication information are related to the target PIN;
  • connection between the first terminal and the first device is associated with the target PIN
  • the first message sent by the first device and received by the first terminal is related to the target PIN;
  • the first device being associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the radio frequency unit 1401 is further configured to:
  • the first terminal receives configuration information sent by the second terminal;
  • the radio frequency unit 1401 sends a first non-access layer NAS message and/or first indication information to the network side, specifically used for:
  • the first non-access stratum NAS message and/or the first indication information are sent to the network side.
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to a target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation.
  • the radio frequency unit 1401 sends the first non-access layer NAS message and/or the first indication information to the network side according to the configuration information, specifically configured to perform at least one of the following:
  • the first non-access stratum NAS message and/or the first indication information are related to the target PIN;
  • connection between the first terminal and the first device is associated with the target PIN
  • the first message sent by the first device and received by the first terminal is related to the target PIN;
  • the first device being associated with the target PIN
  • the first message is used to indicate at least one of the following:
  • the second network function is used to perform the first operation.
  • the radio frequency unit 1401 is further used to: send information of the first device to the network side when the second indication information indicates that the first operation is successful.
  • the first terminal is a terminal with gateway capability.
  • the radio frequency unit 1401 is used to send configuration information to the first terminal in the personal Internet of Things PIN.
  • the configuration information is used to indicate at least one of the following:
  • the first operation needs to be applied to the target PIN or the first operation does not need to be applied to the target PIN;
  • At least one second target device requires the first operation or does not require the first operation
  • the first operation includes at least one of authentication, certification, and authorization
  • the second target device is a device that needs to access the personal Internet of Things PIN or mobile network through the first terminal.
  • the network function 1500 includes: an antenna 151, a radio frequency device 152, a baseband device 153, a processor 154, and a memory 155.
  • the antenna 151 is connected to the radio frequency device 152.
  • the radio frequency device 152 receives information through the antenna 151 and sends the received information to the baseband device 153 for processing.
  • the baseband device 153 processes the information to be sent and sends it to the radio frequency device 152.
  • the radio frequency device 152 processes the received information and sends it out through the antenna 151.
  • the method for executing the network function in the above embodiment may be implemented in the baseband device 153, which includes a baseband processor.
  • the baseband device 153 may include, for example, at least one baseband board, on which a plurality of chips are arranged, as shown in FIG15 , wherein one of the chips is, for example, a baseband processor, which is connected to the memory 155 through a bus interface to call a program in the memory 155 and execute the network function operations shown in the above method embodiment.
  • the network function may also include a network interface 156, which may be, for example, a common public radio interface (CPRI).
  • a network interface 156 which may be, for example, a common public radio interface (CPRI).
  • CPRI common public radio interface
  • the network function 1500 of the embodiment of the present invention further includes: instructions or programs stored in the memory 155 and executable on the processor 154, and the processor 154 calls the instructions or programs in the memory 155 to execute the method shown in FIG.
  • the same technical effect is achieved by the method, so it will not be described here to avoid repetition.
  • the embodiment of the present application also provides a network function.
  • the network function 1600 includes: a processor 1601, a network interface 1602, and a memory 1603.
  • the network interface 1602 is, for example, a common public radio interface (CPRI).
  • CPRI common public radio interface
  • the network function 1600 of the embodiment of the present invention also includes: instructions or programs stored in the memory 1603 and executable on the processor 1601.
  • the processor 1601 calls the instructions or programs in the memory 1603 to execute the method shown in Figure 3 or Figure 4 or Figure 6, and achieves the same technical effect. To avoid repetition, it will not be repeated here.
  • An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored.
  • a program or instruction is stored.
  • each process of the above-mentioned operation execution method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
  • the processor is the processor in the terminal described in the above embodiment.
  • the readable storage medium may be non-volatile or non-transient.
  • the readable storage medium may include a computer-readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.
  • An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the operation execution method embodiment described in any one of the first to fifth aspects above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
  • An embodiment of the present application further provides a computer program/program product, which is stored in a storage medium.
  • the computer program/program product is executed by at least one processor to implement the various processes of the operation execution method embodiment described in any one of the first to fifth aspects above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • An embodiment of the present application also provides an operation execution system, including: a terminal and a network function, wherein the terminal can be used to execute the steps of the operation execution method described in the first aspect or the fourth aspect above, and the network function can be used to execute the steps of the operation execution method described in the second aspect or the third aspect or the fifth aspect above.
  • the technical solution of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM/RAM, magnetic disk, optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, computer, server, air conditioner, or network function, etc.) to execute the methods described in each embodiment of the present application.
  • a storage medium such as ROM/RAM, magnetic disk, optical disk
  • a terminal which can be a mobile phone, computer, server, air conditioner, or network function, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

La présente demande a trait au domaine technique de la communication. Son divulgués un procédé et un appareil d'exécution d'opération, un terminal et une fonction de réseau. Le procédé d'exécution d'opération dans les modes de réalisation de la présente demande comprend au moins l'une des étapes suivantes : un premier terminal envoie un premier message de strate de non-accès (NAS) et/ou des premières informations d'indication à un côté réseau, le premier message NAS étant utilisé pour indiquer une première opération, les premières informations d'indication étant utilisées pour indiquer la première opération, et la première opération comprenant au moins l'une d'une authentification, d'une certification et d'une autorisation ; et le premier terminal reçoit des cinquièmes informations d'indication, qui sont envoyées par le côté réseau, les cinquièmes informations d'indication étant utilisées pour indiquer au moins l'un des éléments suivants : autoriser ou non la première opération, autoriser ou non la première opération à être exécutée au moyen d'un plan de commande du côté réseau, et autoriser ou non la première opération à être exécutée au moyen d'un plan utilisateur du côté réseau.
PCT/CN2023/126764 2022-11-04 2023-10-26 Procédé et appareil d'exécution d'opération, terminal et fonction de réseau WO2024093783A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202211395204.0 2022-11-04
CN202211395204.0A CN118042452A (zh) 2022-11-04 2022-11-04 操作执行方法、装置、终端及网络功能

Publications (1)

Publication Number Publication Date
WO2024093783A1 true WO2024093783A1 (fr) 2024-05-10

Family

ID=90929697

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/126764 WO2024093783A1 (fr) 2022-11-04 2023-10-26 Procédé et appareil d'exécution d'opération, terminal et fonction de réseau

Country Status (2)

Country Link
CN (1) CN118042452A (fr)
WO (1) WO2024093783A1 (fr)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20210368341A1 (en) * 2020-08-10 2021-11-25 Ching-Yu LIAO Secure access for 5g iot devices and services
WO2022147582A2 (fr) * 2021-05-07 2022-07-07 Futurewei Technologies, Inc. Procédés et appareil de fourniture, d'authentification, d'autorisation et génération et distribution de clé d'équipement d'utilisateur (eu) dans un réseau à la demande
CN115250470A (zh) * 2021-04-08 2022-10-28 英特尔公司 用在网关设备中的装置

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20210368341A1 (en) * 2020-08-10 2021-11-25 Ching-Yu LIAO Secure access for 5g iot devices and services
CN115250470A (zh) * 2021-04-08 2022-10-28 英特尔公司 用在网关设备中的装置
WO2022147582A2 (fr) * 2021-05-07 2022-07-07 Futurewei Technologies, Inc. Procédés et appareil de fourniture, d'authentification, d'autorisation et génération et distribution de clé d'équipement d'utilisateur (eu) dans un réseau à la demande

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on architecture enhancements for Personal IoT Network (PIN) (Release 18)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 23.700-88, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V1.1.0, 21 October 2022 (2022-10-21), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, pages 1 - 165, XP052211639 *
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on personal IoT networks security aspects (Release 18)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 33.882, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V0.3.0, 24 October 2022 (2022-10-24), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, pages 1 - 17, XP052211756 *
ZHENHUA XIE, VIVO: "Consolidated solution.", 3GPP DRAFT; S2-2209009; TYPE PCR; FS_PIN, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. 3GPP SA 2, no. Online; 20221010 - 20221017, 30 September 2022 (2022-09-30), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, XP052208771 *

Also Published As

Publication number Publication date
CN118042452A (zh) 2024-05-14

Similar Documents

Publication Publication Date Title
WO2021088990A1 (fr) Procédé et dispositif d'établissement de connexion de relais
WO2023116786A1 (fr) Procédé et appareil d'enregistrement de dispositif de l'internet des objets, dispositif de communication, dispositif de réseau central, support de stockage et système
WO2024001954A1 (fr) Procédés et appareil de configuration d'identifiant, terminal et support de stockage
WO2023143411A1 (fr) Procédés d'authentification de dispositif, appareil et dispositif de communication
WO2024093783A1 (fr) Procédé et appareil d'exécution d'opération, terminal et fonction de réseau
WO2023005898A1 (fr) Procédé de gestion de session conjointe multi-terminal, dispositif côté réseau et terminal
WO2023143418A1 (fr) Procédé et appareil d'authentification de dispositif, ainsi que terminal et fonction de réseau
WO2024199161A1 (fr) Procédé d'authentification, appareil d'authentification, dispositif de communication et support de stockage lisible
WO2024140570A1 (fr) Procédé et appareil de configuration de politique, terminal, dispositif côté réseau, et support de stockage lisible
WO2024067331A1 (fr) Procédé de commutation de dispositif dans un réseau personnel de l'internet des objets, et procédé et dispositif de communication
WO2024131793A1 (fr) Procédé de gestion de dispositif de lecture-écriture, terminal et dispositif côté réseau
WO2024199019A1 (fr) Procédé de commande de communication, procédé de commande de session, ou procédé de configuration ou de mise à jour de règle, et procédé de transmission d'informations
WO2023143554A1 (fr) Procédé et dispositif d'établissement de pin
WO2023143453A1 (fr) Procédé de configuration d'interface radio à connectivité directe, terminal et dispositif côté réseau
WO2024093712A1 (fr) Procédé de traitement de liaison de communication de relais, procédé de configuration de liaison de communication relais, procédé de traitement de terminal relais et dispositif associé
WO2024017124A1 (fr) Procédé d'authentification de dispositif, procédé d'attribution de certificat, procédé d'attribution d'identifiant, répéteur commandé par réseau et dispositif côté réseau
WO2024022161A1 (fr) Procédé et appareil d'enregistrement de dispositif pin, et dispositif de communication
WO2023143436A1 (fr) Procédé et appareil de transfert de données, dispositif terminal et dispositif de réseau
WO2024125358A1 (fr) Procédé de traitement de puissance informatique et dispositif de communication
WO2024160155A1 (fr) Procédé de mise à jour de clé secondaire, terminal et dispositif côté réseau
WO2024017195A1 (fr) Procédé et appareil de gestion de numéro d'identification personnel (pin), premier terminal et premier dispositif
WO2023165481A1 (fr) Procédé de traitement de défaillance de réseau, terminal, dispositif de réseau d'accès, et dispositif de réseau central
WO2024208125A1 (fr) Procédé de configuration de srs, appareil et dispositif associé
WO2024017181A1 (fr) Procédé et appareil d'autorisation de dispositif, et dispositif côté réseau
WO2024022267A1 (fr) Procédé de migration de tâche de capacité de calcul et dispositif de communication

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23884715

Country of ref document: EP

Kind code of ref document: A1