WO2025035325A1 - 通信处理方法、第一实体、第二实体、第三实体 - Google Patents
通信处理方法、第一实体、第二实体、第三实体 Download PDFInfo
- Publication number
- WO2025035325A1 WO2025035325A1 PCT/CN2023/112757 CN2023112757W WO2025035325A1 WO 2025035325 A1 WO2025035325 A1 WO 2025035325A1 CN 2023112757 W CN2023112757 W CN 2023112757W WO 2025035325 A1 WO2025035325 A1 WO 2025035325A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- message
- entity
- identifier
- authorization
- nssai
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/02—Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
- H04W8/08—Mobility data transfer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/20—Transfer of user or subscriber data
Definitions
- the present disclosure relates to the field of communication technology, and in particular to a communication processing method, a first entity, a second entity, and a third entity.
- application functions in a communication network supported by a communication system are configured through functional entities in a core network.
- the disclosed embodiments provide a communication processing method, a first entity, a second entity, and a third entity, thereby improving communication efficiency.
- a communication processing method comprising:
- a fifth message sent by the second entity is received, wherein the fifth message is used to indicate an authorization result, wherein the authorization result includes authorization passed or authorization failed.
- a communication processing method comprising:
- a fifth message is sent to the first entity, wherein the fifth message is used to indicate the authorization result, wherein the authorization result includes authorization passed or authorization failed.
- a communication processing method comprising:
- a communication processing method comprising:
- the first entity sends a first message to the second entity, wherein the first message is used to provide relevant information about a specific private IoT PIN;
- the second entity receives the first message sent by the first entity, generates a second message according to the first message, and sends the second message to the third entity;
- the third entity receives the second message sent by the second entity, and performs authorization based on relevant information in the second message;
- the third entity sends a third message to the second entity, wherein the third message is used to indicate the authorization result;
- the second entity receives the third message sent by the third entity, and sends a fifth message to the first entity, wherein the fifth message is used to indicate the authorization result, wherein the authorization result includes authorization passed or authorization failed;
- the first entity receives a fifth message sent by the second entity.
- a first entity is provided, wherein the device includes:
- a transceiver module configured to send a first message to a second entity, wherein the first message is used to provide relevant information of a specific private IoT PIN;
- the transceiver module is used to receive a fifth message sent by the second entity, wherein the fifth message is used to indicate an authorization result, wherein the authorization result includes authorization passed or authorization failed.
- the device includes:
- a transceiver module configured to receive a first message sent by a first entity, and generate a second message according to the first message
- the transceiver module is used to send a fifth message to the first entity, wherein the fifth message is used to indicate the authorization result, wherein the authorization result includes authorization passed or authorization failed.
- a third entity is provided, wherein the device includes:
- a transceiver module configured to receive a second message or a sixth message sent by a second entity
- a processing module configured to perform authorization based on relevant information in the second message or the sixth message
- the transceiver module is used to send a third message or a seventh message to the second entity, wherein the third message or the seventh message is used to indicate an authorization result.
- a first entity including:
- processors one or more processors
- the first entity is used to execute any one of the methods in the first aspect.
- a second entity including:
- processors one or more processors
- the second entity is used to execute any one of the methods in the second aspect.
- a third entity including:
- processors one or more processors
- the third entity is used to execute any one of the methods in the third aspect.
- a communication system comprising a first entity, a second entity, and a third entity, wherein the first entity is configured to implement the method described in any one of the first aspect, the second entity is configured to implement the method described in any one of the second aspect, and the third entity is configured to implement the method described in any one of the third aspect.
- a storage medium which stores instructions.
- the instructions When the instructions are executed on a communication device, the communication device executes a method as described in any one of the first aspect, the second aspect, or the third aspect.
- FIG1 is an exemplary schematic diagram of the architecture of a communication system provided according to an embodiment of the present disclosure.
- FIG. 2 is an exemplary interaction diagram of a communication processing method provided according to an embodiment of the present disclosure.
- FIG3A is a flow chart of a communication processing method according to an embodiment of the present disclosure.
- FIG4A is a flow chart of a communication processing method according to an embodiment of the present disclosure.
- FIG4B is a flow chart of a communication processing method according to an embodiment of the present disclosure.
- FIG4C is a flow chart of a communication processing method according to an embodiment of the present disclosure.
- FIG4D is a flow chart of a communication processing method according to an embodiment of the present disclosure.
- FIG5A is an interactive schematic diagram of a communication processing method according to an embodiment of the present disclosure.
- FIG. 6 is a schematic diagram of a communication processing method according to an embodiment of the present disclosure.
- FIG. 7A is a schematic diagram of the structure of the first entity proposed in an embodiment of the present disclosure.
- FIG. 7B is a schematic diagram of the structure of the second entity proposed in an embodiment of the present disclosure.
- FIG. 7C is a schematic diagram of the structure of the third entity proposed in the embodiment of the present disclosure.
- FIG8A is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure.
- FIG8B is a schematic diagram of the structure of a chip 8200 according to an embodiment of the present disclosure.
- the embodiments of the present disclosure provide a communication processing method, a first entity, a second entity, a third entity, and a core network device.
- an embodiment of the present disclosure provides a communication processing method, the method comprising:
- a fifth message sent by the second entity is received, wherein the fifth message is used to indicate an authorization result, wherein the authorization result includes authorization passed or authorization failed.
- the relevant information of a specific private IoT PIN is provided and authorized through the first message, so that 5GS limits AF to the granularity of a specific PIN, avoiding that AF can configure information for PIN IDs that are not managed by itself, affecting the user experience, and improving the quality of communication.
- the first message includes at least one of the following:
- an embodiment of the present disclosure provides a communication processing method, the method comprising:
- a fifth message is sent to the first entity, wherein the fifth message is used to indicate an authorization result, wherein the authorization result includes authorization passed or authorization failed.
- the relevant information of a specific private IoT PIN is provided and authorized through the first message, so that 5GS limits AF to the granularity of a specific PIN, avoiding that AF can configure information for PIN IDs that are not managed by itself, affecting the user experience, and improving the quality of communication.
- the first message includes at least one of the following:
- the second message includes at least one of the following specific PIN related information:
- generating the second message according to the first message includes:
- the method further includes:
- a third message sent by a third entity is received, wherein the third message is used to indicate an authorization result.
- the method further includes:
- a fourth message is sent to the fourth network element.
- the method further includes:
- authorizing according to the second message includes:
- mapping relationship table includes a mapping relationship between the S-NSSAI and/or the DNN and the PIN identifier.
- the method further includes at least one of the following:
- the target S-NSSAI and/or target DNN that has a mapping relationship with the PIN identifier in the second message is queried based on the locally stored mapping relationship table.
- the method further includes any one of the following:
- the target PIN identifier is consistent with the PIN identifier in the second message, determining that there is a mapping relationship between the S-NSSAI and/or the DNN in the second message and the PIN identifier in the second message;
- the target S-NSSAI and/or the target DNN are consistent with the S-NSSAI and/or the DNN in the second message, determining that there is a mapping relationship between the S-NSSAI and/or the DNN in the second message and the PIN identifier in the second message;
- the method further includes any one of the following:
- the sixth message includes at least one of the following:
- a communication processing method comprising:
- the third message or the seventh message is sent to the second entity, wherein the third message or the seventh message is used to indicate the authorization result.
- the relevant information of a specific private IoT PIN is provided and authorized through the first message, so that 5GS limits AF to the granularity of a specific PIN, avoiding that AF can configure information for PIN IDs that are not managed by itself, affecting the user experience, and improving the quality of communication.
- the second message includes at least one of the following specific PIN related information:
- the method further includes:
- mapping relationship table includes a mapping relationship between the S-NSSAI and/or DNN and the PIN identifier.
- the method further includes:
- authorization is performed based on relevant information of a specific PIN in the second message, including at least one of the following:
- the target S-NSSAI and/or target DNN that has a mapping relationship with the PIN identifier in the second message is queried based on the locally stored mapping relationship table.
- the method further includes any one of the following:
- the target PIN identifier is consistent with the PIN identifier in the second message, determining that there is a mapping relationship between the S-NSSAI and/or the DNN in the second message and the PIN identifier in the second message;
- the target S-NSSAI and/or the target DNN are consistent with the S-NSSAI and/or the DNN in the second message, determining that there is a mapping relationship between the S-NSSAI and/or the DNN in the second message and the PIN identifier in the second message;
- authorization is performed based on relevant information of a specific PIN in the second message, including:
- the subscription information corresponding to the GPSI or SUPI, where the subscription information includes the target S-NSSAI and/or DNN.
- authorization is performed based on relevant information of a specific PIN in the second message, further comprising:
- the permission information corresponding to the AF identifier wherein the permission information is used to indicate that the AF corresponding to the AF identifier can modify the user routing policy URSP information of the GPSI or SUPI related terminal, or that the AF corresponding to the AF identifier cannot modify the URSP information of the GPSI or SUPI related terminal.
- the method further includes any one of the following:
- the S-NSSAI and/or DNN in the second message has a mapping relationship with the PIN identifier in the second message, and the S-NSSAI and/or DNN in the second message is the target S-NSSAI and/or DNN in the subscription information, and the AF corresponding to the AF identifier can modify the URSP information of the GPSI or SUPI related terminal, then an authorization result of authorization passing is generated;
- the method further includes:
- a seventh message is sent to the second entity, where the seventh message includes an authorization result, wherein the authorization result includes authorization passed or authorization failed.
- the sixth message includes at least one of the following:
- the method further includes:
- Authorization is performed according to the sixth message to generate an authorization result.
- a communication processing method comprising:
- the first entity sends a first message to the second entity, wherein the first message is used to provide relevant information about a specific private IoT PIN;
- the second entity receives the first message sent by the first entity, generates a second message or a sixth message according to the first message, and sends the second message or the sixth message to the third entity;
- the third entity receives the second message or the sixth message sent by the second entity, and performs authorization based on relevant information in the second message or the sixth message;
- the third entity sends a third message or a seventh message to the second entity, wherein the third message or the seventh message is used to indicate the authorization result;
- the second entity receives the third message or the seventh message sent by the third entity, and sends a fifth message to the first entity, wherein the fifth message is used to indicate the authorization result, wherein the authorization result includes authorization passed or authorization failed;
- the first entity receives a fifth message sent by the second entity.
- a first entity is provided, and the device includes:
- a transceiver module configured to send a first message to a second entity, wherein the first message is used to provide relevant information about a specific private IoT PIN;
- the transceiver module is used to receive a fifth message sent by the second entity, wherein the fifth message is used to indicate an authorization result, wherein the authorization result includes authorization passed or authorization failed.
- the device includes:
- a transceiver module configured to receive a first message sent by a first entity, and generate a second message according to the first message
- the transceiver module is used to send a fifth message to the first entity, wherein the fifth message is used to indicate an authorization result, wherein the authorization result includes authorization passed or authorization failed.
- a third entity is proposed, and the device includes:
- a transceiver module configured to receive a second message or a sixth message sent by a second entity
- a processing module configured to perform authorization based on relevant information in the second message or the sixth message
- the transceiver module is used to send the third message or the seventh message to the second entity, wherein the third message or the seventh message is used to indicate the authorization result.
- a first entity including:
- processors one or more processors
- the first entity is used to execute any one of the methods in the first aspect.
- a second entity including:
- processors one or more processors
- the second entity is used to execute any method in the second aspect.
- a third entity including:
- processors one or more processors
- the third entity is used to execute any method in the third aspect.
- a communication system comprising a first entity, a second entity, and a third entity, wherein the first entity is configured to implement any method of the first aspect, the second entity is configured to implement any method of the second aspect, and the third entity is configured to implement any method of the third aspect.
- a storage medium which stores instructions.
- the instructions When the instructions are executed on a communication device, the communication device executes a method as described in any one of the first aspect, the second aspect, or the third aspect.
- an embodiment of the present disclosure proposes a first entity, and the above-mentioned first entity includes at least one of a transceiver module and a processing module; wherein the above-mentioned first entity is used to execute the optional implementation method of the first aspect and the fifth aspect.
- an embodiment of the present disclosure proposes a second entity, and the second entity includes at least one of a transceiver module and a processing module; wherein the second entity is used to execute optional implementation methods of the second and sixth aspects.
- an embodiment of the present disclosure proposes a third entity, and the third entity includes at least one of a transceiver module and a processing module; wherein the third entity is used to execute optional implementation methods of the third aspect and the seventh aspect.
- an embodiment of the present disclosure proposes a core network device, which includes at least one of a transceiver module and a processing module; wherein the core network device is used to execute the optional implementation method of the fourth aspect.
- an embodiment of the present disclosure proposes a first entity, and the above-mentioned first entity includes: one or more processors; wherein the above-mentioned first entity is used to execute optional implementation methods of the first aspect and the fifth aspect.
- an embodiment of the present disclosure proposes a second entity, and the second entity includes: one or more processors; wherein the second entity is used to execute optional implementation methods of the second aspect and the sixth aspect.
- an embodiment of the present disclosure proposes a third entity, including: one or more processors; wherein the above-mentioned third entity is used to execute optional implementation methods of the third aspect and the seventh aspect.
- an embodiment of the present disclosure proposes a core network device, comprising: one or more processors; wherein the above-mentioned core network device is used to execute the optional implementation method of the fourth aspect.
- an embodiment of the present disclosure proposes a communication system, which includes: a first entity, a second entity, and a third entity; wherein the first entity is configured to execute the method described in the optional implementation manners of the first and fifth aspects, the eighth and thirteenth aspects, the second entity is configured to execute the method described in the optional implementation manners of the second and sixth aspects, the ninth and fourteenth aspects, and the third entity is configured to execute the method described in the optional implementation manners of the third and seventh aspects, the tenth and fifteenth aspects.
- an embodiment of the present disclosure proposes a storage medium, which stores instructions.
- the communication device executes the method described in the optional implementation methods of the first and second aspects, the third aspect and the fourth aspect.
- an embodiment of the present disclosure proposes a program product.
- the communication device executes the method described in the optional implementation of the first and second aspects, the third and fourth aspects.
- an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the optional implementations of the first and second aspects, the third and fourth aspects.
- an embodiment of the present disclosure provides a chip or a chip system.
- the chip or chip system includes a processing circuit configured to execute the method described in the optional implementation of the first aspect, the second aspect, the third aspect, and the fourth aspect.
- the embodiments of the present disclosure propose a communication processing method, a first entity, a second entity, a third entity, and a core network device.
- the terms such as communication processing method, information processing method, and communication method can be replaced with each other, the terms such as communication processing device, information processing device, and communication device can be replaced with each other, and the terms such as information processing system and communication system can be replaced with each other.
- each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined.
- a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged.
- the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined, for example, some or all of the steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
- elements expressed in the singular form such as “a”, “an”, “the”, “above”, “”, “the”, “the”, etc., may mean “one and only one", or “one or more”, “at least one”, etc.
- the noun after the article may be understood as a singular expression or a plural expression.
- plurality refers to two or more.
- "at least one of A and B", “A and/or B", “A in one case, B in another case”, “in response to one case A, in response to another case B”, etc. may include the following technical solutions according to the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). When there are more branches such as A, B, C, etc., the above is also similar.
- the recording method of "A or B” may include the following technical solutions according to the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed).
- A A is executed independently of B
- B B is executed independently of A
- execution is selected from A and B (A and B are selectively executed).
- prefixes such as “first” and “second” in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute any restrictions on the position, order, priority, quantity or content of the description objects.
- the description object please refer to the description in the context of the claims or embodiments, and no unnecessary restrictions should be imposed due to the use of prefixes.
- the description object is a "field”
- the ordinal number before the "field” in the "first field” and the "second field” does not limit the position or order between the "fields”.
- “First” and “second” do not limit whether the "fields” they modify are in the same message, nor do they limit the order of the "first field” and the "second field”.
- the description object is a "level”
- the ordinal number before the "level” in the “first level” and the “second level” does not limit the priority between the “levels”.
- the description object The quantity is not limited by ordinal numbers and can be one or more.
- the number of "devices” can be one or more.
- the objects modified by different prefixes can be the same or different.
- the object described is “device”
- first device and “second device” can be the same device or different devices, and their types can be the same or different.
- the object described is “information”
- first information” and “second information” can be the same information or different information, and their contents can be the same or different.
- “including A”, “comprising A”, “used to indicate A”, and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
- terms such as “greater than”, “greater than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, and “above” can be replaced with each other, and terms such as “less than”, “less than or equal to”, “not greater than”, “less than”, “less than or equal to”, “no more than”, “lower than”, “lower than or equal to”, “not higher than”, and “below” can be replaced with each other.
- devices and equipment may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as “equipment”, “device”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, “subject”, etc.
- network can be interpreted as devices included in the network, such as access network equipment, core network equipment, etc.
- access network device may also be referred to as “radio access network device (RAN device)", “base station (BS)”, “radio base station (radio base station)”, “fixed station” and in some embodiments may also be understood as “node”, “access point (access point)”, “transmission point (TP)”, “reception point (RP)”, “transmission and/or reception point (transmission/reception point, TRP)", “panel”, “antenna panel”, “antenna array”, “cell”, “macro cell”, “small cell”, “femto cell”, “pico cell”, “sector”, “cell group”, “serving cell”, “carrier”, “component carrier”, “bandwidth part (bandwidth part, BWP)", etc.
- RAN device radio access network device
- base station base station
- RP radio base station
- TRP transmission and/or reception point
- terminal or “terminal device” may be referred to as "user equipment (UE)", “user terminal (user terminal)”, “mobile station (MS)”, “mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc.
- UE user equipment
- MS mobile station
- MT mobile terminal
- acquisition of data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
- data, information, etc. may be obtained with the user's consent.
- each element, each row, or each column in the table of the embodiments of the present disclosure may be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns may also be implemented as an independent embodiment.
- FIG1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
- a communication system 100 includes a terminal 101, an access network device 102, and a core network device 103.
- the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited to these.
- a mobile phone a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device
- the access network device 102 is, for example, a node or device that accesses a terminal to a wireless network.
- the access network device may include an evolved NodeB (eNB), a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, and a base in a 6G communication system.
- the invention relates to at least one of a base station, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and an access node in a Wi-Fi system, but is not limited thereto.
- the technical solution of the present disclosure may be applicable to the Open RAN architecture.
- the interfaces between access network devices or within access network devices involved in the embodiments of the present disclosure may become internal interfaces of Open RAN, and the processes and information interactions between these internal interfaces may be implemented through software or programs.
- the access network device may be composed of a centralized unit (central unit, CU) and a distributed unit (distributed unit, DU), wherein the CU may also be called a control unit (control unit).
- the CU-DU structure may be used to split the protocol layer of the access network device, with some functions of the protocol layer being centrally controlled by the CU, and the remaining part or all of the functions of the protocol layer being distributed in the DU, and the DU being centrally controlled by the CU, but not limited to this.
- the core network device 103 may be a device including a first entity 1031, a second entity 1032, a third entity 1033, a fourth entity 1034, etc., or may be a plurality of devices or a device group including all or part of the first entity 1031, the second entity 1032, the third entity 1033, the fourth entity 1034, etc.
- the network element may be virtual or physical.
- the core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
- EPC Evolved Packet Core
- 5GCN 5G Core Network
- NGC Next Generation Core
- the first entity 1031 is, for example, an application function (AF) entity.
- AF application function
- the first entity 1031 is used to "provide application services", and the name is not limited thereto.
- the second entity 1032 is, for example, a network exposure function (NEF) entity.
- NEF network exposure function
- the second entity 1032 is used to “manage externally open network data”, and the name is not limited thereto.
- the third entity 1033 is, for example, a unified data management function (UDM).
- UDM unified data management function
- the third entity 1033 is used to “perform network authentication”, and the name is not limited thereto.
- the third entity 1033 may be independent from the core network device 103 .
- the third entity 1033 may be a part of the core network device 103 .
- the fourth entity 1034 is, for example, a unified data repository (UDR).
- UDR unified data repository
- the fourth entity 1034 is used to “provide a unified data repository service”, and the name is not limited thereto.
- the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure.
- a person of ordinary skill in the art can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.
- the following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1 , or part of the subject, but are not limited thereto.
- the subjects shown in FIG1 are examples, and the communication system may include all or part of the subjects in FIG1 , or may include other subjects other than FIG1 , and the number and form of the subjects are arbitrary, and the subjects may be physical or virtual, and the connection relationship between the subjects is an example, and the subjects may be connected or disconnected, and the connection may be in any manner, and may be a direct connection or an indirect connection, and may be a wired connection or a wireless connection.
- LTE Long Term Evolution
- LTE-A LTE-Advanced
- LTE-B LTE-Beyond
- SUPER 3G IMT-Advanced
- 4G the fourth generation mobile communication system
- 5G 5G new radio
- FAA Future Radio Access
- RAT New Radio
- NR New Radio
- NX New radio access
- the present invention relates to wireless communication systems such as LTE, Wi-Fi (X), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) network, Device to Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle to Everything (V2X), systems using other communication methods, and next-generation systems expanded based on them.
- PLMN Public Land Mobile Network
- D2D Device to Device
- M2M Machine to Machine
- IoT Internet of Things
- V2X Vehicle to Everything
- systems using other communication methods and next-generation systems expanded based on them.
- next-generation systems expanded based on them.
- a combination of multiple systems for example, a combination of
- certain aspects of the Personal IoT Networks (PIN) networks supported by the 5G system may be configured by the application function AF entity through the 5G NEF.
- the application function AF entity may provide the 5GS with URSP related information of the PEGC. This procedure may be referred to as a PIN-related application guide for locating URSPs.
- a malicious AF may configure PIN-related policies for PINs that are not controlled by the AF, and the PIN elements in the victim's PIN may cause a poor user experience due to the policies provided by the malicious AF.
- the UDM to authorize the modification of the URSP, the UDM only checks whether the Single Network Slice Selection Assistance information (S-NSSAI) and/or the Data Network Name (DNN) is subscribed to by the UE or UE group, and whether the AF can modify the URSP of the specified UE/UE group. If the malicious AF is authorized to modify the URSP of a specific UE/UE group, the malicious AF can provide the authorized S-NSSAI/DNN to the UDM through the NEF. The AF provides the unmanageable PIN ID to the NEF. Since the UDM does not check the PIN ID, the 5GC will allow the malicious AF to manage any PIN. There is no existing solution that allows the 5GS to restrict the AF to the level of a specific PIN. There is no solution in this embodiment that allows the 5GS to restrict the AF to the level of a specific PIN.
- S-NSSAI Single Network Slice Selection Assistance information
- DNN Data Network Name
- FIG2 is an interactive schematic diagram of a communication processing method according to an embodiment of the present disclosure. As shown in FIG2 , the present disclosure embodiment relates to a communication processing method, and the method includes:
- Step S2101 the first entity 101 sends a first message to the second entity 102.
- the second entity 102 receives the first message.
- the first message is used to provide relevant information about a specific private IoT PIN.
- the first entity 101 is, for example, an AF entity.
- the first entity 101 is used to "provide application services", and the name is not limited thereto.
- the second entity 102 is, for example, a NEF entity.
- the second entity 102 is used to “manage externally open network data”, and the name is not limited thereto.
- the first message includes at least one of the following: an application function AF identifier; an application function AF service identifier (AF-service-identifier); a general public user identifier GPSI; and a PIN identifier (PINID).
- an application function AF identifier an application function AF service identifier
- AF-service-identifier an application function AF service identifier
- GPSI general public user identifier
- PINID PIN identifier
- the GPSI may be a GPSI corresponding to a PEGC.
- the PIN identification may be a PIN identifier corresponding to a PEGC.
- Step S2102 the second entity 102 generates a second message.
- the second entity 102 locally stores a locally stored mapping relationship table, wherein the mapping relationship table includes a mapping relationship between the S-NSSAI and/or DNN and the PIN identifier.
- the second entity 102 determines the corresponding S-NSSAI and/or DNN based on the AF service identifier in the first message.
- the second entity 102 retrieves a mapping relationship table to find an S-NSSAI and/or DNN that has a mapping relationship with the AF service identifier in the first message.
- the second message includes relevant information of at least one of the following specific PINs: AF identifier; single network slice selection assistance information S-NSSAI; data network name DNN; application function AF service identifier; general public user identifier GPSI; PIN identifier.
- Step S2103 the second entity 102 sends a second message to the third entity 103 .
- the third entity 103 receives the second message.
- the third entity 103 is, for example, a UDM entity.
- the third entity 103 is used for “performing authorization”, and the name is not limited thereto.
- Step S2104 The second entity 102 performs authorization according to the second message.
- the second entity 102 locally stores a locally stored mapping relationship table, wherein the mapping relationship table includes a mapping relationship between the S-NSSAI and/or DNN and the PIN identifier.
- the second entity 102 searches for a target PIN identifier that has a mapping relationship with the S-NSSAI and/or DNN in the second message based on a locally stored mapping relationship table.
- the second entity 102 queries the target S-NSSAI and/or target DNN that has a mapping relationship with the PIN identifier in the second message based on a locally stored mapping relationship table.
- the second entity 102 determines that there is a mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- the second entity 102 determines that there is a mapping relationship between the S-NSSAI and/or the DNN in the second message and the PIN identifier in the second message;
- the target S-NSSAI and/or target DNN are inconsistent with the S-NSSAI and/or DNN in the second message, and the second entity 102 determines that there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- the target PIN identifier is inconsistent with the PIN identifier in the second message, and the second entity 102 determines that there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- the second entity 102 if there is a mapping relationship between the S-NSSAI and/or the DNN in the second message and the PIN identifier in the second message, the second entity 102 generates a sixth message and sends the sixth message to the third entity;
- the second entity 102 if there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message, the second entity 102 generates an authorization result indicating that the authorization is not passed.
- the authorization result of authorization failure generated by the second entity 102 is carried in the fifth message, and the fifth message is sent by the second entity 102 to the first entity 101 .
- Step S2105 the second entity 102 sends a sixth message to the third entity 103 .
- the third entity 103 receives the sixth message.
- the sixth message includes at least one of the following: AF identifier; single network slice selection assistance information S-NSSAI; data network name DNN; application function AF service identifier; general public user identifier GPSI.
- Step S2106 the third entity 103 performs authorization.
- the third entity 103 performs authorization according to the second message.
- the second message includes relevant information of at least one of the following specific PINs: AF identifier; single network slice selection assistance information S-NSSAI; data network name DNN; application function AF service identifier; general public user identifier GPSI; PIN identifier.
- the third entity 103 locally stores a locally stored mapping relationship table, wherein the mapping relationship table includes a mapping relationship between the S-NSSAI and/or DNN and the PIN identifier.
- the third entity 103 obtains the corresponding user permanent identifier SUPI according to the GPSI in the second message.
- the third entity 103 searches for a target PIN identifier that has a mapping relationship with the S-NSSAI and/or DNN in the second message based on a locally stored mapping relationship table; or,
- the third entity 103 queries the target S-NSSAI and/or target DNN that has a mapping relationship with the PIN identifier in the second message based on a locally stored mapping relationship table.
- the third entity 103 determines that there is a mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- the third entity 103 determines that there is a mapping relationship between the S-NSSAI and/or the DNN in the second message and the PIN identifier in the second message;
- the target S-NSSAI and/or target DNN are inconsistent with the S-NSSAI and/or DNN in the second message, and the third entity 103 determines that there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- the target PIN identifier is inconsistent with the PIN identifier in the second message, and the third entity 103 determines that there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- the third entity 103 queries subscription information corresponding to the GPSI or SUPI, wherein the subscription information includes the target S-NSSAI and/or DNN.
- the third entity 103 queries the permission information corresponding to the AF identifier, wherein the permission information is used to indicate that the AF corresponding to the AF identifier can modify the user routing policy URSP information of the GPSI or SUPI related terminal, or that the AF corresponding to the AF identifier cannot modify the URSP information of the GPSI or SUPI related terminal.
- the third entity 103 if the S-NSSAI and/or DNN in the second message has a mapping relationship with the PIN identifier in the second message, and the S-NSSAI and/or DNN in the second message is the target S-NSSAI and/or DNN in the subscription information, and the AF corresponding to the AF identifier can modify the URSP information of the GPSI or SUPI related terminal, the third entity 103 generates an authorization result of authorization approval.
- PEGC The purpose of this is to allow PEGC to process PINE's request after obtaining URSP rules. Because PINE sends PIN ID to PEGC, PEGC needs to convert PIN ID into S-NSSAI and DNN, and establish a Protocol Data Unit (PDU) session based on this information.
- PDU Protocol Data Unit
- AF can configure S-NSSAI and/or DNN that has been subscribed by UE to a PIN ID that does not have a mapping relationship.
- Advanced result AF can configure S-NSSAI and/or DNN information for PIN ID that is not managed by itself, affecting the experience of PIN ID.
- the third entity 103 If there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message, the third entity 103 generates an authorization result indicating that the authorization is not passed;
- the third entity 103 if the S-NSSAI and/or DNN in the second message is not the target S-NSSAI or DNN in the subscription information, the third entity 103 generates an authorization result indicating that the authorization is not passed;
- the third entity 103 if the AF corresponding to the AF identifier cannot modify the URSP information of the terminal related to the GPSI or SUPI, the third entity 103 generates an authorization result indicating that the authorization is not passed.
- Step S2107 the third entity 103 sends a third message to the second entity 102 .
- the second entity 102 receives the third message.
- the authorization result generated by the third entity 103 includes authorization passed or authorization failed.
- the third message carries the authorization result.
- Step S2108 the third entity 103 sends a seventh message to the second entity 102 .
- the second entity 102 receives the seventh message.
- the third entity 103 performs authorization according to the received sixth message.
- the sixth message includes at least one of the following: AF identifier; single network slice selection assistance information S-NSSAI; data network name DNN; application function AF service identifier; general public user identifier GPSI.
- the third entity 103 queries subscription information corresponding to the GPSI or SUPI, wherein the subscription information includes the target S-NSSAI and/or DNN.
- the third entity 103 queries the permission information corresponding to the AF identifier, wherein the permission information is used to indicate that the AF corresponding to the AF identifier can modify the user routing policy URSP information of the GPSI or SUPI related terminal, or that the AF corresponding to the AF identifier cannot modify the URSP information of the GPSI or SUPI related terminal.
- the third entity 103 if the S-NSSAI and/or DNN in the second message is the target S-NSSAI and/or DNN in the subscription information, and the AF corresponding to the AF identifier can modify the URSP information of the GPSI or SUPI related terminal, the third entity 103 generates an authorization result of authorization passed;
- the third entity 103 if the S-NSSAI and/or DNN in the second message is not the target S-NSSAI or DNN in the subscription information, the third entity 103 generates an authorization result indicating that the authorization is not passed;
- the third entity 103 if the AF corresponding to the AF identifier cannot modify the URSP information of the terminal related to the GPSI or SUPI, the third entity 103 generates an authorization result indicating that the authorization is not passed.
- the authorization result generated by the third entity 103 according to the sixth message is carried by the seventh message and sent to the second entity 102.
- Step S2109 the second entity 102 sends a fourth message to the fourth entity 104 .
- the fourth entity 104 receives the fourth message.
- the fourth message is information related to a specific PIN.
- the relevant information of a specific PIN includes, but is not limited to: an application function AF identifier; an application function AF service identifier; a universal public user identifier GPSI; and a PIN identifier.
- a fourth message is sent to the fourth network element.
- sending the fourth message to the fourth network element is not performed.
- the fourth entity 104 is, for example, a UDR entity.
- the fourth entity 104 is used to “provide a unified data repository service”, and the name is not limited thereto.
- Step S2110 the second entity 102 sends a fifth message to the first entity 101 .
- the first entity 101 receives the fifth message.
- the fifth message includes an authorization result.
- the authorization result includes authorization passed or authorization failed.
- the names of information, etc. are not limited to the names recorded in the embodiments, and terms such as “information”, “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “domain”, “field”, “symbol”, “symbol”, “code element”, “codebook”, “codeword”, “codepoint”, “bit”, “data”, “program”, and “chip” can be used interchangeably.
- radio wireless
- RAN radio access network
- AN access network
- RAN-based and the like
- search space search space set
- search space configuration search space set configuration
- control resource set CORESET
- CORESET configuration control resource set
- CC component carrier
- cell cell
- frequency carrier frequency carrier
- carrier frequency carrier frequency
- obtain can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from high levels, obtaining by self-processing, autonomous implementation, etc.
- terms such as “certain”, “preset”, “preset”, “set”, “indicated”, “some”, “any”, and “first” can be interchangeable, and "specific A”, “preset A”, “preset A”, “set A”, “indicated A”, “some A”, “any A”, and “first A” can be interpreted as A pre-defined in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., and can also be interpreted as specific A, some A, any A, or first A, etc., but is not limited to this.
- not expecting to receive can be interpreted as not receiving on time domain resources and/or frequency domain resources, or as not performing subsequent processing on the data after receiving the data; "not expecting to send” can be interpreted as not sending, or as sending but not expecting the recipient to respond to the sent content.
- the communication method involved in the embodiments of the present disclosure may include at least one of steps S2101 to S2110.
- step S2101 may be implemented as an independent embodiment
- step S2102 may be implemented as an independent embodiment
- steps S2101+S2103 may be implemented as an independent embodiment
- steps S2101+S2102+S2103 may be implemented as an independent embodiment, but are not limited thereto.
- steps S2107 and S2108 may be executed in an interchangeable order or simultaneously.
- steps S2104, S2105, and S2108 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
- FIG3A is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG3A , the present disclosure embodiment relates to a communication processing method, and the method includes:
- Step S3101 sending the first message.
- step S3101 can refer to the optional implementation of step S2101 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S3102 receiving the fifth message.
- step S3102 can refer to the optional implementation of step S2110 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- step S3101 may be implemented as an independent embodiment
- step S3102 may be implemented as an independent embodiment
- step S3101+step S3102 may be implemented as independent embodiments, but are not limited thereto.
- step S3101 and step S3102 may be executed in an interchangeable order or simultaneously.
- step S3101 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
- step S3102 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
- FIG4A is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG4A , the present disclosure embodiment relates to a communication processing method, and the method includes:
- Step S4101 receiving a first message.
- step S4101 can refer to the optional implementation of step S2101 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4102 determine the corresponding S-NSSAI and/or DNN according to the AF service identifier in the first message.
- step S4102 can refer to the optional implementation of step S2102 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4103 Generate a second message based on the first message.
- step S4103 can refer to the optional implementation of step S2102 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4104 Send the second message to the third entity.
- step S4104 can refer to the optional implementation of step S2103 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4105 receiving a third message sent by a third entity.
- step S4105 can refer to the optional implementation of step S2107 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4106 In response to the third message or the seventh message indicating that the authorization is passed, a fourth message is sent to the fourth network element.
- step S4106 can refer to the optional implementation of step S2109 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4107 obtaining the mapping relationship table stored locally.
- step S4107 can refer to the optional implementation of step S2104 in FIG. 2 and the implementation involved in FIG. 2. Other related parts in the example will not be repeated here.
- Step S4108 query the target PIN identifier that has a mapping relationship with the S-NSSAI and/or DNN in the second message based on the locally stored mapping relationship table.
- step S4108 can refer to the optional implementation of step S2104 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4109 query the target S-NSSAI and/or target DNN that has a mapping relationship with the PIN identifier in the second message based on the locally stored mapping relationship table.
- step S4109 can refer to the optional implementation of step S2104 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4110 If the target PIN identifier is consistent with the PIN identifier in the second message, determine that there is a mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- step S4110 can refer to the optional implementation of step S2104 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4111 If the target S-NSSAI and/or target DNN are consistent with the S-NSSAI and/or DNN in the second message, determine that there is a mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- step S4111 can refer to the optional implementation of step S2104 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4112 If there is a mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message, a sixth message is generated.
- step S4112 can refer to the optional implementation of step S2104 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4113 Send a sixth message to the third entity 103.
- step S4113 can refer to the optional implementation of step S2105 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4114 if there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message, an authorization result of failed authorization is generated, wherein the fifth message carries the authorization result of failed authorization.
- step S4114 can refer to the optional implementation of step S2104 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- the communication method involved in the embodiment of the present disclosure may include at least one of steps S4101 to S4114.
- step S4101 may be implemented as an independent embodiment
- step S4102 may be implemented as an independent embodiment
- steps S4101+S4103 may be implemented as an independent embodiment
- steps S4101+S4102+S4103 may be implemented as an independent embodiment, but are not limited thereto.
- steps S4101 and S4104 may be executed in an interchangeable order or simultaneously.
- steps S4105 and S4106 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
- FIG4B is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG4B , the present disclosure embodiment relates to a communication processing method, and the method includes:
- Step S4201 determine the S-NSSAI and/or DNN corresponding to the AF service identifier.
- step S4201 can refer to step S2101 in Figure 2, the optional implementation of step S4102 in Figure 4A, and other related parts in the embodiments involved in Figures 2 and 4A, which will not be repeated here.
- Step S4202 sending the fourth message.
- step S4202 can refer to step S2109 in Figure 2, the optional implementation of step S4106 in Figure 4A, and other related parts in the embodiments involved in Figures 2 and 4A, which will not be repeated here.
- Step S4203 perform authorization according to the second message.
- step S4201 can refer to step S2104 in FIG. 2 , the optional implementation of steps S4107 - S4111 in FIG. 4A , and other related parts in the embodiments involved in FIG. 2 and FIG. 4A , which will not be described in detail here.
- the communication method involved in the embodiments of the present disclosure may include at least one of steps S4201 to S4203.
- step S4201 may be implemented as an independent embodiment
- step S4202 may be implemented as an independent embodiment
- steps S4201+S4203 may be implemented as an independent embodiment
- steps S4201+S4202+S4203 may be implemented as an independent embodiment, but are not limited thereto.
- steps S4201 and S4202 may be executed in an interchangeable order or simultaneously.
- step S4203 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
- FIG4C is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG4C, the present disclosure embodiment relates to And a communication processing method, the method comprising:
- Step S4301 receiving a second message sent by a second entity.
- step S4301 can refer to the optional implementation of step S2103 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4302 receive a sixth message sent by the second entity.
- step S4302 can refer to the optional implementation of step S2105 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4303 obtaining a mapping relationship table stored locally.
- step S4303 can refer to the optional implementation of step S2106 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4304 Acquire the corresponding user permanent identifier SUPI according to the GPSI.
- step S4304 can refer to the optional implementation of step S2106 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4305 query the target PIN identifier that has a mapping relationship with the S-NSSAI and/or DNN in the second message based on the locally stored mapping relationship table.
- step S4305 can refer to the optional implementation of step S2106 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4306 query the target S-NSSAI and/or target DNN that has a mapping relationship with the PIN identifier in the second message based on the locally stored mapping relationship table.
- step S4306 can refer to the optional implementation of step S2106 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4307 If the target PIN identifier is consistent with the PIN identifier in the second message, determine that there is a mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- step S4307 can refer to the optional implementation of step S2106 in FIG2 and other related parts in the embodiment involved in FIG2 , which will not be described in detail here.
- Step S4308 If the target S-NSSAI and/or target DNN are consistent with the S-NSSAI and/or DNN in the second message, determine that there is a mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- step S4308 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- Step S4309 If the target PIN identifier is inconsistent with the PIN identifier in the second message, determine that there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- step S4309 can refer to the optional implementation of step S2106 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4310 If the target S-NSSAI and/or target DNN are inconsistent with the S-NSSAI and/or DNN in the second message, determine that there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message.
- step S4310 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- Step S4311 querying the subscription information corresponding to the GPSI or SUPI.
- step S4311 can refer to the optional implementation of step S2106 in FIG2 and other related parts in the embodiment involved in FIG2 , which will not be described in detail here.
- Step S4312 query the authority information corresponding to the AF identifier.
- step S4312 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- Step S4313 If there is a mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message, and the S-NSSAI and/or DNN in the second message is the target S-NSSAI and/or DNN in the subscription information, and the AF corresponding to the AF identifier can modify the URSP information of the GPSI or SUPI-related terminal, an authorization result of authorization approval is generated.
- step S4313 can refer to the optional implementation of step S2106 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
- Step S4314 If there is no mapping relationship between the S-NSSAI and/or DNN in the second message and the PIN identifier in the second message, an authorization result indicating that the authorization is not passed is generated.
- step S4314 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- Step S4315 If the S-NSSAI and/or DNN in the second message is not the target S-NSSAI or DNN in the subscription information, an authorization result of failed authorization is generated.
- step S4315 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- Step S4316 If the AF corresponding to the AF identifier cannot modify the URSP information of the terminal related to the GPSI or SUPI, an authorization result indicating that the authorization is not passed is generated.
- step S4316 can refer to the optional implementation of step S2106 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- Step S4317 Send a seventh message to the second entity.
- step S4317 can refer to the optional implementation of step S2108 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- Step S4318 Send a third message to the second entity.
- step S4318 can refer to the optional implementation of step S2107 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.
- the communication method involved in the embodiment of the present disclosure may include at least one of steps S4301 to S4318.
- step S4101 may be implemented as an independent embodiment
- step S4302 may be implemented as an independent embodiment
- steps S4301+S4303 may be implemented as an independent embodiment
- steps S4301+S4302+S4303 may be implemented as an independent embodiment, but are not limited thereto.
- steps S4301 and S4304 may be executed in an interchangeable order or simultaneously.
- steps S4305 and S4306 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
- FIG4D is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG4D , the present disclosure embodiment relates to a communication processing method, and the method includes:
- Step S4401 Perform authorization based on relevant information in the second message.
- step S4401 can refer to step S2106 in Figure 2, the optional implementation of steps S4303-S4316 in Figure 4C, and other related parts in the embodiments involved in Figures 2 and 4C, which will not be repeated here.
- Step S4402 Perform authorization based on the relevant information in the sixth message.
- step S4402 can refer to step S2106 in Figure 2, the optional implementation of steps S4303-S4316 in Figure 4C, and other related parts in the embodiments involved in Figures 2 and 4C, which will not be repeated here.
- FIG5A is an interactive schematic diagram of a communication processing method according to an embodiment of the present disclosure. As shown in FIG5A , the present disclosure embodiment relates to a communication processing method, and the method includes:
- Step S5101 The first entity sends a first message to the second entity, wherein the first message is used to provide relevant information of a specific private IoT PIN.
- step S5101 can refer to the optional implementation of step S2101 in Figure 2, step S3101 in Figure 3, and other related parts in the embodiments involved in Figures 2, 3, and 4, which will not be repeated here.
- the above method may include the methods of the embodiments of the above communication system side, terminal side, access network equipment side, core network equipment side, first network element side, second network element side, etc., which will not be repeated here.
- Step S5102 The first entity receives a fifth message sent by the second entity, wherein the fifth message is used to indicate an authorization result, wherein the authorization result includes authorization passed or authorization failed.
- step S5102 can refer to step S2110 of FIG. 2 , the optional implementation of step S3102 of FIG. 3 , and other related parts in the embodiments involved in FIG. 2 , FIG. 3 , and FIG. 4 , which will not be described in detail here.
- Step S5103 The second entity receives the first message sent by the first entity, and generates a second message according to the first message.
- step S5103 can refer to the optional implementation of step S2102 in Figure 2, step S4103 in Figure 4, and other related parts in the embodiments involved in Figures 2, 3, and 4, which will not be repeated here.
- Step S5104 The second entity sends a fifth message to the first entity, where the fifth message is used to indicate an authorization result, where the authorization result includes authorization passed or authorization failed.
- step S5104 can refer to the optional implementation of step S2110 in Figure 2, step S4114 in Figure 4, and other related parts in the embodiments involved in Figures 2, 3, and 4, which will not be repeated here.
- Step S5105 The third entity receives the second message or the sixth message sent by the second entity.
- step S5105 can refer to the optional implementation of steps S2103 and S2105 in Figure 2, steps S4301 and S4302 in Figure 4, and other related parts in the embodiments involved in Figures 2, 3 and 4, which will not be repeated here.
- Step S5106 The third entity performs authorization based on the relevant information in the second message or the sixth message.
- step S5106 can refer to the optional implementation of step S2106 in FIG. 2 and steps S4303-S4316 in FIG. 4. Other related parts in the embodiments involved in the formula, and Figures 2, 3, and 4 will not be repeated here.
- Step S5107 The third entity sends a third message or a seventh message to the second entity, wherein the third message or the seventh message is used to indicate an authorization result.
- step S5107 can refer to the optional implementation of steps S2107 and S2108 in Figure 2, steps S4317 and S4318 in Figure 4, and other related parts in the embodiments involved in Figures 2, 3 and 4, which will not be repeated here.
- FIG6 is a schematic diagram of a communication processing method according to an embodiment of the present disclosure. As shown in FIG6 , the embodiment of the present disclosure relates to a communication processing method, and the method includes:
- Step S6101 AF sends first information to NEF.
- AF is the first entity mentioned above.
- the first information includes relevant information of a specific PIN.
- relevant information for a specific PIN includes AFID, AF-service-identifier, GPSI of PEGC and PIN ID.
- Step S6102 NEF generates second information based on the first information.
- NEF is the second entity mentioned above.
- NEF locally stores the mapping between S-NSSAI/DNN and PIN ID.
- NEF converts AF-service-identifier to a combination of DNN and S-NSSAI
- NEF searches for the S-NSSAI/DNN and PIN ID corresponding to the PIN ID based on the mapping relationship.
- NEF adds the S-NSSAI/DNN and PIN ID corresponding to the PIN ID to the second information.
- the second information includes AF identifier; S-NSSAI; DNN; AF service identifier; GPSI; and PIN ID.
- Step S6103 NEF performs mapping verification based on information related to the specific PIN.
- NEF determines whether the S-NSSAI/DNN in the second information has a mapping relationship with the PIN ID in the second information based on the mapping relationship between S-NSSAI/DNN and PIN ID.
- the S-NSSAI/DNN in the second information has a mapping relationship with the PIN ID in the second information, and a request message is sent to the UMD.
- the request information includes single network slice selection auxiliary information S-NSSAI; data network name DNN; application function AF service identifier; and general public user identifier GPSI.
- the S-NSSAI/DNN in the second information has no mapping relationship with the PIN ID in the second information, and an authorization result of authorization failure is generated and sent to AF.
- Step S6104 NEF sends a request message to UDM.
- UDM is the third entity mentioned above.
- the request information includes S-NSSAI, DNN, AFID, AF-service-identifier, and GPSI of PEGC.
- the request information includes a PINID.
- Step S6105 UDM performs authorization verification based on the request information.
- UDM performs mapping verification.
- UDM stores the mapping information between S-NSSAI/DNN and PIN ID locally.
- the mapping verification passes.
- mapping verification fails and the authorization result is failure.
- UDM performs subscription verification.
- the UDM obtains a corresponding user permanent identifier SUPI according to the GPSI in the request information.
- the UDM queries subscription information corresponding to the GPSI or SUPI, wherein the subscription information includes a target S-NSSAI and/or DNN.
- the subscription verification passes.
- the subscription verification fails and the authorization result is failed.
- UDM performs modification permission verification.
- the UDM queries the permission information corresponding to the AFID in the request information, wherein the permission information is used to indicate that the AF corresponding to the AF identifier can modify the user routing policy URSP information of the GPSI or SUPI related terminal, or that the AF corresponding to the AF identifier cannot modify the URSP information of the GPSI or SUPI related terminal.
- the modification authority check is passed.
- the modification authority check fails and the authorization result is not passed.
- mapping check if the mapping check, subscription check, and modification permission check all pass, an authorization result indicating authorization is passed is generated.
- Step S6106 UDM sends the authorization result to NEF.
- Step S6107 NEF sends relevant information of the specific PIN to UDR according to the authorization result.
- the UDR is the fourth entity mentioned above.
- this step is not performed.
- Step S6108 NEF sends the authorization result to AF.
- the communication method involved in the embodiment of the present disclosure may include at least one of steps S6101 to S6108.
- step S6101 may be implemented as an independent embodiment
- step S6102 may be implemented as an independent embodiment
- steps S6101+S6103 may be implemented as an independent embodiment
- steps S6101+S6102+S6103 may be implemented as an independent embodiment, but are not limited thereto.
- step S6107 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
- part or all of the steps and their optional implementations may be arbitrarily combined with part or all of the steps in other embodiments, or may be arbitrarily combined with optional implementations of other embodiments.
- the embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device is proposed, the above device includes a unit or module for implementing each step performed by the terminal in any of the above methods.
- a device is also proposed, including a unit or module for implementing each step performed by a network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.
- a network device such as an access network device, a core network function node, a core network device, etc.
- the division of the units or modules in the above device is only a division of logical functions, which can be fully or partially integrated into one physical entity or physically separated in actual implementation.
- the units or modules in the device can be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and instructions are stored in the memory.
- the processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory inside the device or a memory outside the device.
- CPU central processing unit
- microprocessor a microprocessor
- the units or modules in the device may be implemented in the form of hardware circuits, and the functions of some or all of the units or modules may be implemented by designing the hardware circuits.
- the hardware circuits may be understood as one or more processors; for example, in one implementation, the hardware circuits are application-specific integrated circuits (ASICs), and the functions of some or all of the above units or modules may be implemented by designing the logical relationship of the components in the circuits; for another example, in another implementation, the hardware circuits may be implemented by programmable logic devices (PLDs), and Field Programmable Gate Arrays (FPGAs) may be used as an example, which may include a large number of logic gate circuits, and the connection relationship between the logic gate circuits may be configured by configuring the configuration files, thereby implementing the functions of some or all of the above units or modules. All units or modules of the above devices may be implemented in the form of software called by the processor, or in the form of hardware circuits, or in the form of software called by the processor, and the remaining part may be implemented in
- the processor is a circuit with signal processing capability.
- the processor may be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which may be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor may implement certain functions through the logical relationship of a hardware circuit, and the logical relationship of the above hardware circuit may be fixed or reconfigurable, such as a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA.
- ASIC application-specific integrated circuit
- PLD programmable logic device
- the process of the processor loading a configuration document to implement the hardware circuit configuration may be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules.
- it can also be a hardware circuit designed for artificial intelligence, which can be understood as ASIC, such as Neural Network Processing Unit (NPU), Tensor Processing Unit (TPU), Deep Learning Processing Unit (DPU), etc.
- ASIC Neural Network Processing Unit
- NPU Neural Network Processing Unit
- TPU Tensor Processing Unit
- DPU Deep Learning Processing Unit
- FIG7A is a schematic diagram of the structure of the first entity proposed in the embodiment of the present disclosure.
- the first entity 7100 may include: at least one of a transceiver module 7101, a processing module 7102, etc.
- the transceiver module is used to perform at least one of the communication steps such as sending and/or receiving performed by the terminal 101 in any of the above methods, which will not be repeated here.
- the processing module is used to perform at least one of the other steps performed by the first entity in any of the above methods, which will not be repeated here.
- FIG7B is a schematic diagram of the structure of the second entity proposed in the embodiment of the present disclosure.
- the second entity 7200 may include: at least one of a transceiver module 7201, a processing module 7202, etc.
- the transceiver module is used to perform at least one of the communication steps such as sending and/or receiving performed by the second entity in any of the above methods, which will not be repeated here.
- the processing module is used to perform at least one of the other steps performed by the second entity in any of the above methods, which will not be repeated here.
- FIG7C is a schematic diagram of the structure of the third entity proposed in the embodiment of the present disclosure.
- the third entity 7300 may include: At least one of the transceiver module 7301, the processing module 7302, etc.
- the transceiver module is used to execute at least one of the communication steps such as sending and/or receiving executed by the third entity in any of the above methods, which will not be repeated here.
- the processing module is used to execute at least one of the other steps executed by each entity of the third entity in any of the above methods, which will not be repeated here.
- the transceiver module may include a sending module and/or a receiving module, and the sending module and the receiving module may be separate or integrated.
- the transceiver module may be interchangeable with the transceiver.
- the processing module can be a module or include multiple submodules.
- the multiple submodules respectively execute all or part of the steps required to be executed by the processing module.
- the processing module can be replaced with the processor.
- FIG8A is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure.
- the communication device 8100 may be a network device (e.g., an access network device, a core network device, etc.), or a terminal (e.g., a user device, etc.), or a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods.
- the communication device 8100 may be used to implement the method described in the above method embodiment, and the details may refer to the description in the above method embodiment.
- the communication device 8100 includes one or more processors 8101.
- the processor 8101 may be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit.
- the baseband processor may be used to process the communication protocol and the communication data
- the central processing unit may be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute a program, and process the data of the program.
- the communication device 8100 is used to execute any of the above methods.
- the communication device 8100 further includes one or more memories 8102 for storing instructions.
- the memory 8102 may also be outside the communication device 8100.
- the communication device 8100 further includes one or more transceivers 8103.
- the transceiver 8103 performs at least one of the communication steps such as sending and/or receiving in the above method, and the processor 8101 performs at least one of the other steps.
- the transceiver may include a receiver and/or a transmitter, and the receiver and the transmitter may be separate or integrated.
- the terms such as transceiver, transceiver unit, transceiver, transceiver circuit, etc. may be replaced with each other, the terms such as transmitter, transmission unit, transmitter, transmission circuit, etc. may be replaced with each other, and the terms such as receiver, receiving unit, receiver, receiving circuit, etc. may be replaced with each other.
- the communication device 8100 may include one or more interface circuits 8104.
- the interface circuit 8104 is connected to the memory 8102, and the interface circuit 8104 may be used to receive signals from the memory 8102 or other devices, and may be used to send signals to the memory 8102 or other devices.
- the interface circuit 8104 may read instructions stored in the memory 8102 and send the instructions to the processor 8101.
- the communication device 8100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8A.
- the communication device may be an independent device or may be part of a larger device.
- the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
- FIG. 8B is a schematic diagram of the structure of a chip 8200 provided in an embodiment of the present disclosure.
- the communication device 8100 may be a chip or a chip system
- the chip 8200 includes one or more processors 8201, and the chip 8200 is used to execute any of the above methods.
- the chip 8200 further includes one or more interface circuits 8202.
- the interface circuit 8202 is connected to the memory 8203.
- the interface circuit 8202 can be used to receive signals from the memory 8203 or other devices, and the interface circuit 8202 can be used to send signals to the memory 8203 or other devices.
- the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201.
- the interface circuit 8202 performs at least one of the communication steps such as sending and/or receiving in the above method, and the processor 8201 performs at least one of the other steps (but not limited to these).
- interface circuit interface circuit
- transceiver pin transceiver
- the chip 8200 further includes one or more memories 8203 for storing instructions.
- the memory 8203 may be outside the chip 8200.
- the present disclosure also proposes a storage medium, on which instructions are stored, and when the instructions are executed on the communication device 8100, the communication device 8100 executes any of the above methods.
- the storage medium is an electronic storage medium.
- the storage medium is a computer-readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices.
- the storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a temporary storage medium.
- the present disclosure also proposes a program product, which, when executed by the communication device 8100, enables the communication device 8100 to execute any of the above methods.
- the program product is a computer program product.
- the present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to execute any one of the above methods.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Databases & Information Systems (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本公开涉及通信处理方法、第一实体、第二实体、第三实体。第一实体发送第一消息至第二实体,其中,第一消息用于提供特定私有物联网PIN的相关信息;接收第二实体发送的第五消息,其中,所述第五消息用于指示授权结果,其中,所述授权结果包括授权通过或授权不通过,有效提高了通信效率。
Description
本公开涉及通信技术领域,尤其涉及通信处理方法、第一实体、第二实体、第三实体。
在无线通信中,通信系统支持的通信网络中的应用程序功能通过核心网中的功能实体来配置。
发明内容
本公开实施例提出了通信处理方法、第一实体、第二实体、第三实体,提高了通信效率。
根据本公开实施例的第一方面,提出了通信处理方法,所述方法包括:
发送第一消息至第二实体,其中,所述第一消息用于提供特定私有物联网PIN的相关信息;
接收所述第二实体发送的第五消息,其中,所述第五消息用于指示授权结果,其中,所述授权结果包括授权通过或授权不通过。
根据本公开实施例的第二方面,提出了通信处理方法,所述方法包括:
接收第一实体发送的第一消息,根据所述第一消息生成第二消息;
向所述第一实体发送第五消息,其中,所述第五消息用于指示所述授权结果,其中,所述授权结果包括授权通过或授权不通过。
根据本公开实施例的第三方面,提出了通信处理方法,所述方法包括:
接收第二实体发送的第二消息或第六消息;
基于所述第二消息或第六消息中的相关信息进行授权;
发送第三消息或第七消息至第二实体,其中,所述第三消息或第七消息用于指示授权结果。
根据本公开实施例的第四方面,提出了通信处理方法,所述方法包括:
第一实体发送第一消息至第二实体,其中,所述第一消息用于提供特定私有物联网PIN的相关信息;
所述第二实体接收第一实体发送的第一消息,根据所述第一消息生成第二消息,并将所述第二消息发送至第三实体;
所述第三实体接收第二实体发送的第二消息,并基于所述第二消息中的相关信息进行授权;
所述第三实体发送第三消息至第二实体,其中,所述第三消息用于指示授权结果;
所述第二实体接收所述第三实体发送的第三消息,并向所述第一实体发送第五消息,其中,所述第五消息用于指示所述授权结果,其中,所述授权结果包括授权通过或授权不通过;
所述第一实体接收所述第二实体发送的第五消息。
根据本公开实施例的第五方面,提出了第一实体,所述装置包括:
收发模块,用于发送第一消息至第二实体,其中,所述第一消息用于提供特定私有物联网PIN的相关信息;
收发模块,用于接收所述第二实体发送的第五消息,其中,所述第五消息用于指示授权结果,其中,所述授权结果包括授权通过或授权不通过。
根据本公开实施例的第六方面,提出了二实体,所述装置包括:
收发模块,用于接收第一实体发送的第一消息,根据所述第一消息生成第二消息;
收发模块,用于向所述第一实体发送第五消息,其中,所述第五消息用于指示所述授权结果,其中,所述授权结果包括授权通过或授权不通过。
根据本公开实施例的第七方面,提出了第三实体,所述装置包括:
收发模块,用于接收第二实体发送的第二消息或第六消息;
处理模块,用于基于所述第二消息或第六消息中的相关信息进行授权;
收发模块,用于发送第三消息或第七消息至第二实体,其中,所述第三消息或第七消息用于指示授权结果。
根据本公开实施例的第八方面,提出了第一实体,包括:
一个或多个处理器;
其中,所述第一实体用于执行第一方面中任一项所述的方法。
根据本公开实施例的第九方面,提出了第二实体,包括:
一个或多个处理器;
其中,所述第二实体用于执行第二方面中任一项所述的方法。
根据本公开实施例的第十方面,提出了第三实体,包括:
一个或多个处理器;
其中,所述第三实体用于执行第三方面中任一项所述的方法。
根据本公开实施例的第十一方面,提出了通信系统,包括第一实体、第二实体、第三实体,其中,所述第一实体被配置为实现第一方面中任一项所述的方法,所述第二实体被配置为实现第二方面中任一项所述的方法,所述第三实体被配置为实现第三方面中任一项所述的方法。
根据本公开实施例的第十二方面,提出了存储介质,所述存储介质存储有指令,当所述指令在通信设备上运行时,使得所述通信设备执行如第一方面或第二方面或第三方面中任一项所述的方法。
为了更清楚地说明本公开实施例中的技术方案,以下对实施例描述所需的附图进行介绍,以下附图仅仅是本公开的一些实施例,不对本公开的保护范围造成具体限制。
图1是根据本公开实施例提供的通信系统的架构的一个示例性示意图。
图2是根据本公开实施例提供的通信处理方法的一个示例性交互示意图。
图3A是根据本公开实施例示出的通信处理方法的流程示意图。
图4A是根据本公开实施例示出的通信处理方法的流程示意图。
图4B是根据本公开实施例示出的通信处理方法的流程示意图。
图4C是根据本公开实施例示出的通信处理方法的流程示意图。
图4D是根据本公开实施例示出的通信处理方法的流程示意图。
图5A是根据本公开实施例示出的通信处理方法的交互示意图。
图6是根据本公开实施例示出的通信处理方法的示意图。
图7A是本公开实施例提出的第一实体的结构示意图。
图7B是本公开实施例提出的第二实体的结构示意图。
图7C是本公开实施例提出的第三实体的结构示意图。
图8A是本公开实施例提出的通信设备8100的结构示意图。
图8B是本公开实施例提出的芯片8200的结构示意图。
本公开实施例提出了通信处理方法、第一实体、第二实体、第三实体、核心网设备。
第一方面,本公开实施例提出了一种通信处理方法,方法包括:
发送第一消息至第二实体,其中,第一消息用于提供特定私有物联网PIN的相关信息;
接收第二实体发送的第五消息,其中,第五消息用于指示授权结果,其中,授权结果包括授权通过或授权不通过。
在上述实施例中,通过第一消息提供特定私有物联网PIN的相关信息并对其进行授权,使5GS将AF限制在特定PIN的粒度,避免AF可以给不属于自己管理的PIN ID配置的信息影响用户的体验,提高了通信的质量。
结合第一方面的一些实施例,在一些实施例中,第一消息中包括以下至少一项:
应用功能AF标识符;
应用功能AF服务标识符;
通用公共用户标识符GPSI;
PIN标识符。
第二方面,本公开实施例提出了一种通信处理方法,方法包括:
接收第一实体发送的第一消息,根据第一消息生成第二消息;
向第一实体发送第五消息,其中,第五消息用于指示授权结果,其中,授权结果包括授权通过或授权不通过。
在上述实施例中,通过第一消息提供特定私有物联网PIN的相关信息并对其进行授权,使5GS将AF限制在特定PIN的粒度,避免AF可以给不属于自己管理的PIN ID配置的信息影响用户的体验,提高了通信的质量。
结合第二方面的一些实施例,在一些实施例中,第一消息中包括以下至少一项:
应用功能AF标识符;
AF服务标识符;
通用公共用户标识符GPSI;
PIN标识符。
结合第二方面的一些实施例,在一些实施例中,第二消息中包括以下至少一项特定PIN的相关信息:
AF标识符;
单个网络切片选择辅助信息S-NSSAI;
数据网络名称DNN;
应用功能AF服务标识符;
通用公共用户标识符GPSI;
PIN标识符。
结合第二方面的一些实施例,在一些实施例中,根据第一消息生成第二消息,包括:
根据第一消息中的AF服务标识符确定对应的S-NSSAI和/或DNN。
结合第二方面的一些实施例,在一些实施例中,方法还包括:
将第二消息发送至第三实体;
接收第三实体发送的第三消息,其中,第三消息用于指示授权结果。
结合第二方面的一些实施例,在一些实施例中,方法还包括:
响应于第三消息指示授权通过,向第四网元发送第四消息。
结合第二方面的一些实施例,在一些实施例中,方法还包括:
根据第二消息进行授权。
结合第二方面的一些实施例,在一些实施例中,根据第二消息进行授权包括:
获取本地存储的映射关系表,其中,映射关系表中包含S-NSSAI和/或DNN与PIN标识符之间的映射关系。
结合第二方面的一些实施例,在一些实施例中,方法还包括以下至少一项:
基于本地存储的映射关系表查询与第二消息中的S-NSSAI和/或DNN存在映射关系的目标PIN标识符;或,
基于本地存储的映射关系表查询与第二消息中的PIN标识符存在映射关系的目标S-NSSAI和/或目标DNN。
结合第二方面的一些实施例,在一些实施例中,方法还包括以下任意一项:
如果目标PIN标识符与第二消息中的PIN标识符一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系;
如果目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系;
否则,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系。
结合第二方面的一些实施例,在一些实施例中,方法还包括以下任意一项:
如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系,则生成第六消息,并将第六消息发送至第三实体;
如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系,则生成授权不通过的授权结果,其中,第五消息中携带授权不通过的授权结果。
结合第二方面的一些实施例,在一些实施例中,第六消息中包括以下至少一项:
AF标识符;
单个网络切片选择辅助信息S-NSSAI;
数据网络名称DNN;
应用功能AF服务标识符;
通用公共用户标识符GPSI。
根据本公开实施例的第三方面,提出了通信处理方法,方法包括:
接收第二实体发送的第二消息或第六消息;
基于第二消息或第六消息中的相关信息进行授权;
发送第三消息或第七消息至第二实体,其中,第三消息或第七消息用于指示授权结果。
在上述实施例中,通过第一消息提供特定私有物联网PIN的相关信息并对其进行授权,使5GS将AF限制在特定PIN的粒度,避免AF可以给不属于自己管理的PIN ID配置的信息影响用户的体验,提高了通信的质量。
结合第三方面的一些实施例,在一些实施例中,第二消息中包括以下至少一项特定PIN的相关信息:
AF标识符;
单个网络切片选择辅助信息S-NSSAI;
数据网络名称DNN;
应用功能AF服务标识符;
通用公共用户标识符GPSI;
PIN标识符。
结合第三方面的一些实施例,在一些实施例中,方法还包括:
获取本地存储的映射关系表,其中,映射关系表中包含S-NSSAI和/或DNN与PIN标识符之间的映射关系。
结合第三方面的一些实施例,在一些实施例中,方法还包括:
根据GPSI获取对应的用户永久标识符SUPI。
结合第三方面的一些实施例,在一些实施例中,基于第二消息中特定PIN的相关信息进行授权,包括以下至少一项:
基于本地存储的映射关系表查询与第二消息中的S-NSSAI和/或DNN存在映射关系的目标PIN标识符;或,
基于本地存储的映射关系表查询与第二消息中的PIN标识符存在映射关系的目标S-NSSAI和/或目标DNN。
结合第三方面的一些实施例,在一些实施例中,方法还包括以下任意一项:
如果目标PIN标识符与第二消息中的PIN标识符一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系;
如果目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系;
否则,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系。
结合第三方面的一些实施例,在一些实施例中,基于第二消息中特定PIN的相关信息进行授权,包括:
查询GPSI或SUPI对应的订阅信息,其中,订阅信息中包含目标S-NSSAI和/或DNN。
结合第三方面的一些实施例,在一些实施例中,基于第二消息中特定PIN的相关信息进行授权,还包括:
查询AF标识符对应的权限信息,其中,权限信息用于指示AF标识符对应的AF可以修改GPSI或SUPI相关终端的用户路由选择策略URSP信息,或,AF标识符对应的AF不可以修改GPSI或SUPI相关终端的URSP信息。
结合第三方面的一些实施例,在一些实施例中,方法还包括以下任意一项:
如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系,且第二消息中的S-NSSAI和/或DNN为订阅信息中的目标S-NSSAI和/或DNN,且AF标识符对应的AF可以修改GPSI或SUPI相关终端的URSP信息,则生成授权通过的授权结果;
如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系,则生成授权不通过的授权结果;
如果第二消息中的S-NSSAI和/或DNN不为订阅信息中的目标S-NSSAI或DNN,则生成授权不通过的授权结果;
如果AF标识符对应的AF不可以修改修改GPSI或SUPI相关终端的URSP信息,则生成授权不通过的授权结果。
结合第三方面的一些实施例,在一些实施例中,方法还包括:
接收第二实体发送的第六消息;
向第二实体发送第七消息,第七消息中包括授权结果,其中,授权结果包括授权通过或授权不通过。
结合第三方面的一些实施例,在一些实施例中,第六消息中包括以下至少一项:
AF标识符;
单个网络切片选择辅助信息S-NSSAI;
数据网络名称DNN;
应用功能AF服务标识符;
通用公共用户标识符GPSI。
结合第三方面的一些实施例,在一些实施例中,方法还包括:
根据第六消息进行授权,以生成授权结果。
根据本公开实施例的第四方面,提出了通信处理方法,方法包括:
第一实体发送第一消息至第二实体,其中,第一消息用于提供特定私有物联网PIN的相关信息;
第二实体接收第一实体发送的第一消息,根据第一消息生成第二消息或第六消息,并将第二消息或第六消息发送至第三实体;
第三实体接收第二实体发送的第二消息或第六消息,并基于第二消息或第六消息中的相关信息进行授权;
第三实体发送第三消息或第七消息至第二实体,其中,第三消息或第七消息用于指示授权结果;
第二实体接收第三实体发送的第三消息或第七消息,并向第一实体发送第五消息,其中,第五消息用于指示授权结果,其中,授权结果包括授权通过或授权不通过;
第一实体接收第二实体发送的第五消息。
根据本公开实施例的第五方面,提出了第一实体,装置包括:
收发模块,用于发送第一消息至第二实体,其中,第一消息用于提供特定私有物联网PIN的相关信息;
收发模块,用于接收第二实体发送的第五消息,其中,第五消息用于指示授权结果,其中,授权结果包括授权通过或授权不通过。
根据本公开实施例的第六方面,提出了二实体,装置包括:
收发模块,用于接收第一实体发送的第一消息,根据第一消息生成第二消息;
收发模块,用于向第一实体发送第五消息,其中,第五消息用于指示授权结果,其中,授权结果包括授权通过或授权不通过。
根据本公开实施例的第七方面,提出了第三实体,装置包括:
收发模块,用于接收第二实体发送的第二消息或第六消息;
处理模块,用于基于第二消息或第六消息中的相关信息进行授权;
收发模块,用于发送第三消息或第七消息至第二实体,其中,第三消息或第七消息用于指示授权结果。
根据本公开实施例的第八方面,提出了第一实体,包括:
一个或多个处理器;
其中,第一实体用于执行第一方面中任一项的方法。
根据本公开实施例的第九方面,提出了第二实体,包括:
一个或多个处理器;
其中,第二实体用于执行第二方面中任一项的方法。
根据本公开实施例的第十方面,提出了第三实体,包括:
一个或多个处理器;
其中,第三实体用于执行第三方面中任一项的方法。
根据本公开实施例的第十一方面,提出了通信系统,包括第一实体、第二实体、第三实体,其中,第一实体被配置为实现第一方面中任一项的方法,第二实体被配置为实现第二方面中任一项的方法,第三实体被配置为实现第三方面中任一项的方法。
根据本公开实施例的第十二方面,提出了存储介质,存储介质存储有指令,当指令在通信设备上运行时,使得通信设备执行如第一方面或第二方面或第三方面中任一项的方法。
第十三方面,本公开实施例提出了第一实体,上述第一实体包括收发模块、处理模块中的至少一者;其中,上述第一实体用于执行第一方面和第五方面的可选实现方式。
第十四方面,本公开实施例提出了第二实体,上述第二实体包括收发模块、处理模块中的至少一者;其中,上述第二实体用于执行第二方面和第六方面的可选实现方式。
第十五方面,本公开实施例提出了第三实体,上述第三实体包括收发模块、处理模块中的至少一者;其中,上述第三实体用于执行第三方面和第七方面的可选实现方式。
第十六方面,本公开实施例提出了核心网设备,上述核心网设备包括收发模块、处理模块中的至少一者;其中,上述核心网设备用于执行第四方面的可选实现方式。
第十七方面,本公开实施例提出了第一实体,上述第一实体包括:一个或多个处理器;其中,上述第一实体用于执行第一方面和第五方面的可选实现方式。
第十八方面,本公开实施例提出了第二实体,上述第二实体包括:一个或多个处理器;其中,上述第二实体用于执行第二方面和第六方面的可选实现方式。
第十九方面,本公开实施例提出了第三实体,包括:一个或多个处理器;其中,上述第三实体用于执行第三方面和第七方面的可选实现方式。
第二十方面,本公开实施例提出了核心网设备,包括:一个或多个处理器;其中,上述核心网设备用于执行第四方面的可选实现方式。
第二十一方面,本公开实施例提出了通信系统,上述通信系统包括:第一实体、第二实体、第三实体;其中,上述第一实体被配置为执行如第一方面和第五方面、第八方面和第十三方面的可选实现方式所描述的方法,上述第二实体被配置为执行如第二方面和第六方面、第九方面和第十四方面的可选实现方式所描述的方法,上述第三实体被配置为执行如第三方面和第七方面、第十方面和第十五方面的可选实现方式所描述的方法。
第二十二方面,本公开实施例提出了存储介质,上述存储介质存储有指令,当上述指令在通信设备上运行时,使得上述通信设备执行如第一方面和第二方面、第三方面和第四方面的可选实现方式所描述的方法。
第二十三方面,本公开实施例提出了程序产品,上述程序产品被通信设备执行时,使得上述通信设备执行如第一方面和第二方面、第三方面和第四方面的可选实现方式所描述的方法。
第二十四方面,本公开实施例提出了计算机程序,当其在计算机上运行时,使得计算机执行如第一方面和第二方面、第三方面和第四方面的可选实现方式所描述的方法。
第二十五方面,本公开实施例提供了一种芯片或芯片系统。该芯片或芯片系统包括处理电路,被配置为执行根据上述第一方面和第二方面、第三方面和第四方面的可选实现方式所描述的方法。
可以理解地,上述终端、接入网设备、第一网元、第二网元、核心网设备、通信系统、存储介质、程序产品、计算机程序、芯片或芯片系统均用于执行本公开实施例所提出的方法。因此,其所能达到的有益效果可以参考对应方法中的有益效果,此处不再赘述。
本公开实施例提出了通信处理方法、第一实体、第二实体、第三实体、核心网设备。在一些实施例中,通信处理方法与信息处理方法、通信方法等术语可以相互替换,通信处理装置与信息处理装置、通信装置等术语可以相互替换,信息处理系统、通信系统等术语可以相互替换。
本公开实施例并非穷举,仅为部分实施例的示意,不作为对本公开保护范围的具体限制。在不矛盾的情况下,某一实施例中的每个步骤均可以作为独立实施例来实施,且各步骤之间可以任意组合,例如,在某一实施例中去除部分步骤后的方案也可以作为独立实施例来实施,且在某一实施例中各步骤的顺序可以任意交换,另外,某一实施例中的可选实现方式可以任意组合;此外,各实施例之间可以任意组合,例如,不同实施例的部分或全部步骤可以任意组合,某一实施例可以与其他实施例的可选实现方式任意组合。
在各本公开实施例中,如果没有特殊说明以及逻辑冲突,各实施例之间的术语和/或描述具有一致性,且可以互相引用,不同实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
本公开实施例中所使用的术语只是为了描述特定实施例的目的,而并非作为对本公开的限制。
在本公开实施例中,除非另有说明,以单数形式表示的元素,如“一个”、“一种”、“该”、“上述”、“”、“前述”、“这一”等,可以表示“一个且只有一个”,也可以表示“一个或多个”、“至少一个”等。例如,在翻译中使用如英语中的“a”、“an”、“the”等冠词(article)的情况下,冠词之后的名词可以理解为单数表达形式,也可以理解为复数表达形式。
在本公开实施例中,“多个”是指两个或两个以上。
在一些实施例中,“至少一者(至少一项、至少一个)(atleastoneof)”、“一个或多个(one or more)”、“多个(a plurality of)”、“多个(multiple)等术语可以相互替换。
在一些实施例中,“A、B中的至少一者”、“A和/或B”、“在一情况下A,在另一情况下B”、“响应于一情况A,响应于另一情况B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行);在一些实施例中A和B(A和B都被执行)。当有A、B、C等更多分支时也类似上述。
在一些实施例中,“A或B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行)。当有A、B、C等更多分支时也类似上述。
本公开实施例中的“第一”、“第二”等前缀词,仅仅为了区分不同的描述对象,不对描述对象的位置、顺序、优先级、数量或内容等构成限制,对描述对象的陈述参见权利要求或实施例中上下文的描述,不应因为使用前缀词而构成多余的限制。例如,描述对象为“字段”,则“第一字段”和“第二字段”中“字段”之前的序数词并不限制“字段”之间的位置或顺序,“第一”和“第二”并不限制其修饰的“字段”是否在同一个消息中,也不限制“第一字段”和“第二字段”的先后顺序。再如,描述对象为“等级”,则“第一等级”和“第二等级”中“等级”之前的序数词并不限制“等级”之间的优先级。再如,描述对象的
数量并不受序数词的限制,可以是一个或者多个,以“第一装置”为例,其中“装置”的数量可以是一个或者多个。此外,不同前缀词修饰的对象可以相同或不同,例如,描述对象为“装置”,则“第一装置”和“第二装置”可以是相同的装置或者不同的装置,其类型可以相同或不同;再如,描述对象为“信息”,则“第一信息”和“第二信息”可以是相同的信息或者不同的信息,其内容可以相同或不同。
在一些实施例中,“包括A”、“包含A”、“用于指示A”、“携带A”,可以解释为直接携带A,也可以解释为间接指示A。
在一些实施例中,“响应于……”、“响应于确定……”、“在……的情况下”、“在……时”、“当……时”、“若……”、“如果……”等术语可以相互替换。
在一些实施例中,“大于”、“大于或等于”、“不小于”、“多于”、“多于或等于”、“不少于”、“高于”、“高于或等于”、“不低于”、“以上”等术语可以相互替换,“小于”、“小于或等于”、“不大于”、“少于”、“少于或等于”、“不多于”、“低于”、“低于或等于”、“不高于”、“以下”等术语可以相互替换。
在一些实施例中,装置和设备可以解释为实体的、也可以解释为虚拟的,其名称不限定于实施例中所记载的名称,在一些情况下也可以被理解为“设备(equipment)”、“设备(device)”、“电路”、“网元”、“节点”、“功能”、“单元”、“部件(section)”、“系统”、“网络”、“芯片”、“芯片系统”、“实体”、“主体”等。
在一些实施例中,“网络”可以解释为网络中包含的装置,例如,接入网设备、核心网设备等。
在一些实施例中,“接入网设备(access network device,AN device)”也可以被称为“无线接入网设备(radio access network device,RAN device)”、“基站(base station,BS)”、“无线基站(radio base station)”、“固定台(fixed station)”,在一些实施例中也可以被理解为“节点(node)”、“接入点(access point)”、“发送点(transmission point,TP)”、“接收点(reception point,RP)”、“发送和/或接收点(transmission/reception point,TRP)”、“面板(panel)”、“天线面板(antenna panel)”、“天线阵列(antenna array)”、“小区(cell)”、“宏小区(macro cell)”、“小型小区(small cell)”、“毫微微小区(femto cell)”、“微微小区(pico cell)”、“扇区(sector)”、“小区组(cell group)”、“服务小区”、“载波(carrier)”、“分量载波(component carrier)”、“带宽部分(bandwidth part,BWP)”等。
在一些实施例中,“终端(terminal)”或“终端设备(terminal device)”可以被称为“用户设备(user equipment,UE)”、“用户终端(user terminal)”、“移动台(mobile station,MS)”、“移动终端(mobile terminal,MT)”、订户站(subscriber station)、移动单元(mobile unit)、订户单元(subscriber unit)、无线单元(wireless unit)、远程单元(remote unit)、移动设备(mobile device)、无线设备(wireless device)、无线通信设备(wireless communication device)、远程设备(remote device)、移动订户站(mobile subscriber station)、接入终端(access terminal)、移动终端(mobile terminal)、无线终端(wireless terminal)、远程终端(remote terminal)、手持设备(handset)、用户代理(user agent)、移动客户端(mobile client)、客户端(client)等。
在一些实施例中,获取数据、信息等可以遵照所在地国家的法律法规。
在一些实施例中,可以在得到用户同意后获取数据、信息等。
此外,本公开实施例的表格中的每一元素、每一行、或每一列均可以作为独立实施例来实施,任意元素、任意行、任意列的组合也可以作为独立实施例来实施。
图1是根据本公开实施例示出的通信系统的架构示意图。如图1所示,通信系统100包括终端(terminal)101、接入网设备102、核心网设备(core network device)103。
在一些实施例中,终端101例如包括手机(mobile phone)、可穿戴设备、物联网设备、具备通信功能的汽车、智能汽车、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、工业控制(industrial control)中的无线终端设备、无人驾驶(self-driving)中的无线终端设备、远程手术(remote medical surgery)中的无线终端设备、智能电网(smart grid)中的无线终端设备、运输安全(transportation safety)中的无线终端设备、智慧城市(smart city)中的无线终端设备、智慧家庭(smart home)中的无线终端设备中的至少一者,但不限于此。
在一些实施例中,接入网设备102例如是将终端接入到无线网络的节点或设备,接入网设备可以包括5G通信系统中的演进节点B(evolved NodeB,eNB)、下一代演进节点B(next generation eNB,ng-eNB)、下一代节点B(next generation NodeB,gNB)、节点B(node B,NB)、家庭节点B(home node B,HNB)、家庭演进节点B(home evolved nodeB,HeNB)、无线回传设备、无线网络控制器(radio network controller,RNC)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、基带单元(base band unit,BBU)、移动交换中心、6G通信系统中的基
站、开放型基站(Open RAN)、云基站(Cloud RAN)、其他通信系统中的基站、Wi-Fi系统中的接入节点中的至少一者,但不限于此。
在一些实施例中,本公开的技术方案可适用于Open RAN架构,此时,本公开实施例所涉及的接入网设备间或者接入网设备内的接口可变为Open RAN的内部接口,这些内部接口之间的流程和信息交互可以通过软件或者程序实现。
在一些实施例中,接入网设备可以由集中单元(central unit,CU)与分布式单元(distributed unit,DU)组成的,其中,CU也可以称为控制单元(control unit),采用CU-DU的结构可以将接入网设备的协议层拆分开,部分协议层的功能放在CU集中控制,剩下部分或全部协议层的功能分布在DU中,由CU集中控制DU,但不限于此。
在一些实施例中,核心网设备103可以是一个设备,包括第一实体1031、第二实体1032、第三实体1033、第四实体1034等,也可以是多个设备或设备群,分别包括第一实体1031、第二实体1032、第三实体1033、第四实体1034等中的全部或部分。网元可以是虚拟的,也可以是实体的。核心网例如包括演进分组核心(Evolved Packet Core,EPC)、5G核心网络(5G Core Network,5GCN)、下一代核心(Next Generation Core,NGC)中的至少一者。
在一些实施例中,第一实体1031例如是应用功能(Application Function,AF)实体。
在一些实施例中,第一实体1031用于“提供应用服务”,名称不限于此。
在一些实施例中,第二实体1032例如是网络开放功能(Network Exposure Function,NEF)实体。
在一些实施例中,第二实体1032用于“管理对外开放网络数据”,名称不限于此。
在一些实施例中,第三实体1033例如是统一数据管理功能(Unified Data Management,UDM)。
在一些实施例中,第三实体1033用于“进行网络认证”,名称不限于此。
在一些实施例中,第三实体1033可以与核心网设备103独立。
在一些实施例中,第三实体1033可以是核心网设备103的一部分。
在一些实施例中,第四实体1034例如是统一数据存储(Unified Data Repository,UDR)
在一些实施例中,第四实体1034用于“提供统一数据存储库服务”,名称不限于此。
可以理解的是,本公开实施例描述的通信系统是为了更加清楚的说明本公开实施例的技术方案,并不构成对于本公开实施例提出的技术方案的限定,本领域普通技术人员可知,随着系统架构的演变和新业务场景的出现,本公开实施例提出的技术方案对于类似的技术问题同样适用。
下述本公开实施例可以应用于图1所示的通信系统100、或部分主体,但不限于此。图1所示的各主体是例示,通信系统可以包括图1中的全部或部分主体,也可以包括图1以外的其他主体,各主体数量和形态为任意,各主体可以是实体的也可以是虚拟的,各主体之间的连接关系是例示,各主体之间可以不连接也可以连接,其连接可以是任意方式,可以是直接连接也可以是间接连接,可以是有线连接也可以是无线连接。
本公开各实施例可以应用于长期演进(Long Term Evolution,LTE)、LTE-Advanced(LTE-A)、LTE-Beyond(LTE-B)、SUPER 3G、IMT-Advanced、第四代移动通信系统(4th generation mobile communication system,4G)、)、第五代移动通信系统(5th generation mobile communication system,5G)、5G新空口(new radio,NR)、未来无线接入(Future Radio Access,FRA)、新无线接入技术(New-Radio Access Technology,RAT)、新无线(New Radio,NR)、新无线接入(New radio access,NX)、未来一代无线接入(Future generation radio access,FX)、Global System for Mobile communications(GSM(注册商标))、CDMA2000、超移动宽带(Ultra Mobile Broadband,UMB)、IEEE 802.11(Wi-Fi(注册商标))、IEEE 802.16(WiMAX(注册商标))、IEEE 802.20、超宽带(Ultra-WideBand,UWB)、蓝牙(Bluetooth(注册商标))、陆上公用移动通信网(Public Land Mobile Network,PLMN)网络、设备到设备(Device-to-Device,D2D)系统、机器到机器(Machine to Machine,M2M)系统、物联网(Internet of Things,IoT)系统、车联网(Vehicle-to-Everything,V2X)、利用其他通信方法的系统、基于它们而扩展的下一代系统等。此外,也可以将多个系统组合(例如,LTE或者LTE-A与5G的组合等)应用。
在本申请提供的一个实施例中,5G系统(5Gsystem,5GS)支持的私有物联网(Personal IoT Networks,PIN)网络的某些方面可能由应用程序功能AF实体通过5G NEF进行配置。例如,为了使5GS能够生成与特定PIN中的特定具有网关能力的PIN单元(PIN Elements with Gateway Capability,PEGC)相关的用户路由选择策略(UE Route Selection Policy,URSP)规则,AF可以向5GS提供PEGC的URSP相关信息。本程序可称为定位URSP的PIN相关应用指南。
从安全的角度来看,授予AF的访问/操作范围需要限制在PIN级别,并且需要服从PEGC授予
的权限。否则,恶意AF可能会对不受AF控制的PIN配置与PIN相关的策略,受害者PIN中的PIN元素可能会因为恶意AF提供的策略而导致不良的用户体验。
在一种可能的实施例中,为了授权修改URSP,UDM只检查单个网络切片选择辅助信息(Single Network Slice Selection Assistance information,S-NSSAI)和/或数据网络名称(Data Network Name,DNN)是否被该UE或UE组订阅,以及AF是否可以修改指定UE/UE组的URSP。如果恶意AF被授权修改特定UE/UE组的URSP,则恶意AF可以通过NEF向UDM提供授权的S-NSSAI/DNN。AF将无法管理的PIN ID提供给NEF。由于UDM不会检查PIN ID,5GC将允许恶意AF管理任何PIN。没有现有的解决方案可以使5GS将AF限制在特定PIN的水平。本实施例中没有可以使5GS将AF限制在特定PIN的水平的方案。
图2是根据本公开实施例示出的通信处理方法的交互示意图。如图2所示,本公开实施例涉及通信处理方法,上述方法包括:
步骤S2101,第一实体101向第二实体102发送第一消息。
在一些实施例中,第二实体102接收第一消息。
在一些实施例中,第一消息用于提供特定私有物联网PIN的相关信息。
在一些实施例中,第一实体101例如是AF实体。
在一些实施例中,第一实体101用于“提供应用服务”,名称不限于此。
在一些实施例中,第二实体102例如是NEF实体。
在一些实施例中,第二实体102用于“管理对外开放网络数据”,名称不限于此。
在一些实施例中,第一消息中包括以下至少一项:应用功能AF标识符;应用功能AF服务标识符(AF-service-identifier);通用公共用户标识符GPSI;PIN标识符(PINID)。
在一些实施例中,GPSI可以是PEGC对应的GPSI。
在一些实施例中,PIN标识可以是PEGC对应的PIN标识符。
步骤S2102,第二实体102生成第二消息。
在一些实施例中,第二实体102本地储存有本地存储的映射关系表,其中,映射关系表中包含S-NSSAI和/或DNN与PIN标识符之间的映射关系。
在一些实施例中,第二实体102根据第一消息中的AF服务标识符确定对应的S-NSSAI和/或DNN。
在一些实施例中,第二实体102检索映射关系表,查找与第一消息中AF服务标识符具有映射关系的S-NSSAI和/或DNN。
在一些实施例中,第二消息中包括以下至少一项特定PIN的相关信息:AF标识符;单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI;PIN标识符。
步骤S2103,第二实体102向第三实体103发送第二消息。
在一些实施例中,第三实体103接收第二消息。
在一些实施例中,第三实体103例如是UDM实体。
在一些实施例中,第三实体103用于“进行授权”,名称不限于此。
步骤S2104,第二实体102根据第二消息进行授权。
在一些实施例中,第二实体102本地储存有本地存储的映射关系表,其中,映射关系表中包含S-NSSAI和/或DNN与PIN标识符之间的映射关系。
在一些实施例中,第二实体102基于本地存储的映射关系表查询与第二消息中的S-NSSAI和/或DNN存在映射关系的目标PIN标识符。
在一些实施例中,第二实体102基于本地存储的映射关系表查询与第二消息中的PIN标识符存在映射关系的目标S-NSSAI和/或目标DNN。
在一些实施例中,如果目标PIN标识符与第二消息中的PIN标识符一致,第二实体102确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系。
在一些实施例中,如果目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN一致,第二实体102确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系;
在一些实施例中,目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN不一致,第二实体102确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系。
在一些实施例中,目标PIN标识符与第二消息中的PIN标识符不一致,第二实体102确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系。
在一些实施例中,如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系,则第二实体102生成第六消息,并将第六消息发送至第三实体;
在一些实施例中,如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系,则第二实体102生成授权不通过的授权结果。
在一些实施例中,第二实体102生成的授权不通过的授权结果由第五消息中携带,第五消息由第二实体102向第一实体101发送。
步骤S2105,第二实体102向第三实体103发送第六消息。
在一些实施例中,第三实体103接收第六消息。
在一些实施例中,第六消息中包括以下至少一项:AF标识符;单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI。
步骤S2106,第三实体103进行授权。
在一些实施例中,第三实体103根据第二消息进行授权。
在一些实施例中,第二消息中包括以下至少一项特定PIN的相关信息:AF标识符;单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI;PIN标识符。
在一些实施例中,第三实体103本地储存有本地存储的映射关系表,其中,映射关系表中包含S-NSSAI和/或DNN与PIN标识符之间的映射关系。
在一些实施例中,第三实体103根据第二消息中的GPSI获取对应的用户永久标识符SUPI。
在一些实施例中,第三实体103基于本地存储的映射关系表查询与第二消息中的S-NSSAI和/或DNN存在映射关系的目标PIN标识符;或,
在一些实施例中,第三实体103基于本地存储的映射关系表查询与第二消息中的PIN标识符存在映射关系的目标S-NSSAI和/或目标DNN。
在一些实施例中,如果目标PIN标识符与第二消息中的PIN标识符一致,第三实体103确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系。
在一些实施例中,如果目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN一致,第三实体103确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系;
在一些实施例中,目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN不一致,第三实体103确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系。
在一些实施例中,目标PIN标识符与第二消息中的PIN标识符不一致,第三实体103确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系。
在一些实施例中,第三实体103查询GPSI或SUPI对应的订阅信息,其中,订阅信息中包含目标S-NSSAI和/或DNN。
在一些实施例中,第三实体103查询AF标识符对应的权限信息,其中,权限信息用于指示AF标识符对应的AF可以修改GPSI或SUPI相关终端的用户路由选择策略URSP信息,或,AF标识符对应的AF不可以修改GPSI或SUPI相关终端的URSP信息。
在一些实施例中,如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系,且第二消息中的S-NSSAI和/或DNN为订阅信息中的目标S-NSSAI和/或DNN,且AF标识符对应的AF可以修改GPSI或SUPI相关终端的URSP信息,则第三实体103生成授权通过的授权结果。
这样做的目的是允许PEGC获得URSP rules之后,处理PINE的请求。因为PINE给PEGC发的是PIN ID。PEGC需要将PIN ID转换为S-NSSAI和DNN,并根据这个信息建立协议数据单元(Protocol Data Unit,PDU)会话。
由于现在的核心网没有保存S-NSSAI和或DNN和PIN ID的映射关系,UDM只进行下面检查中的前两项。导致AF可以将已经被UE订阅的S-NSSAI和或DNN配置给一个不存在映射关系的PIN ID。进阶导致,AF可以给不属于自己管理的PIN ID配置S-NSSAI和或DNN信息,影响PIN ID的体验。
如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系,则第三实体103生成授权不通过的授权结果;
在一些实施例中,如果第二消息中的S-NSSAI和/或DNN不为订阅信息中的目标S-NSSAI或DNN,则第三实体103生成授权不通过的授权结果;
在一些实施例中,如果AF标识符对应的AF不可以修改修改GPSI或SUPI相关终端的URSP信息,则第三实体103生成授权不通过的授权结果。
步骤S2107,第三实体103向第二实体102发送第三消息。
在一些实施例中,第二实体102接收第三消息。
在一些实施例中,第三实体103生成的授权结果包括授权通过或授权不通过。
在一些实施例中,第三消息中携带授权结果。
步骤S2108,第三实体103向第二实体102发送第七消息。
在一些实施例中,第二实体102接收第七消息。
在一些实施例中,第三实体103根据接收的第六消息进行授权。
在一些实施例中,第六消息中包括以下至少一项:AF标识符;单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI。
在一些实施例中,第三实体103查询GPSI或SUPI对应的订阅信息,其中,订阅信息中包含目标S-NSSAI和/或DNN。
在一些实施例中,第三实体103查询AF标识符对应的权限信息,其中,权限信息用于指示AF标识符对应的AF可以修改GPSI或SUPI相关终端的用户路由选择策略URSP信息,或,AF标识符对应的AF不可以修改GPSI或SUPI相关终端的URSP信息。
在一些实施例中,如果第二消息中的S-NSSAI和/或DNN为订阅信息中的目标S-NSSAI和/或DNN,且AF标识符对应的AF可以修改GPSI或SUPI相关终端的URSP信息,则第三实体103生成授权通过的授权结果;
在一些实施例中,如果第二消息中的S-NSSAI和/或DNN不为订阅信息中的目标S-NSSAI或DNN,则第三实体103生成授权不通过的授权结果;
在一些实施例中,如果AF标识符对应的AF不可以修改修改GPSI或SUPI相关终端的URSP信息,则第三实体103生成授权不通过的授权结果。
在一些实施例中,第三实体103根据第六消息生成的授权结果由第七消息携带,并发送至第二实体102.
步骤S2109,第二实体102向第四实体104发送第四消息。
在一些实施例中,第四实体104接收第四消息。
在一些实施例中,第四消息为特定PIN的相关信息。
在一些实施例中,特定PIN的相关信息包括但不限于:应用功能AF标识符;应用功能AF服务标识符;通用公共用户标识符GPSI;PIN标识符。
在一些实施例中,响应于第三消息或第七消息指示授权通过,向第四网元发送第四消息。
在一些实施例中,响应于第三消息或第七消息指示授权不通过,则不执行向第四网元发送第四消息。
在一些实施例中,第四实体104例如是UDR实体。
在一些实施例中,第四实体104用于“提供统一数据存储库服务”,名称不限于此。
步骤S2110,第二实体102向第一实体101发送第五消息。
在一些实施例中,第一实体101接收第五消息。
在一些实施例中,第五消息中包含授权结果。可选的,授权结果包括授权通过或授权不通过
在一些实施例中,信息等的名称不限定于实施例中所记载的名称,“信息(information)”、“消息(message)”、“信号(signal)”、“信令(signaling)”、“报告(report)”、“配置(configuration)”、“指示(indication)”、“指令(instruction)”、“命令(command)”、“信道”、“参数(parameter)”、“域”、“字段”、“符号(symbol)”、“码元(symbol)”、“码本(codebook)”、“码字(codeword)”、“码点(codepoint)”、“比特(bit)”、“数据(data)”、“程序(program)”、“码片(chip)”等术语可以相互替换。
在一些实施例中,“无线(radio)”、“无线(wireless)”、“无线接入网(radio access network,RAN)”、“接入网(access network,AN)”、“基于RAN的(RAN-based)”等术语可以相互替换。
在一些实施例中,“搜索空间(search space)”、“搜索空间集(search space set)”、“搜索空间配置(search space configuration)”、“搜索空间集配置(search space set configuration)”、“控制资源集(control resource set,CORESET)”、“CORESET配置”等术语可以相互替换。
在一些实施例中,“分量载波(component carrier,CC)”、“小区(cell)”、“频率载波(frequency carrier)”、“载波频率(carrier frequency)”等术语可以相互替换。
在一些实施例中,“获取”、“获得”、“得到”、“接收”、“传输”、“双向传输”、“发送和/或接收”可以相互替换,其可以解释为从其他主体接收,从协议中获取,从高层获取,自身处理得到、自主实现等多种含义。
在一些实施例中,“发送”、“发射”、“上报”、“下发”、“传输”、“双向传输”、“发送和/或接收”等术语可以相互替换。
在一些实施例中,“特定(certain)”、“预定(preseted)”、“预设”、“设定”、“指示(indicated)”、“某一”、“任意”、“第一”等术语可以相互替换,“特定A”、“预定A”、“预设A”、“设定A”、“指示A”、“某一A”、“任意A”、“第一A”可以解释为在协议等中预先规定的A,也可以解释为通过设定、配置、或指示等得到的A,也可以解释为特定A、某一A、任意A、或第一A等,但不限于此。
在一些实施例中,“不期待接收”可以解释为不在时域资源和/或频域资源上接收,也可以解释为在接收到数据等后,不对该数据等执行后续处理;“不期待发送”可以解释为不发送,也可以解释为发送但是不期待接收方对发送的内容做出响应。
本公开实施例所涉及的通信方法可以包括步骤S2101~步骤S2110中的至少一者。例如,步骤S2101可以作为独立实施例来实施,步骤S2102可以作为独立实施例来实施,步骤S2101+S2103可以作为独立实施例来实施,步骤S2101+S2102+S2103可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S2107、S2108可以交换顺序或同时执行。
在一些实施例中,步骤S2104、S2105、S2108是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,可参见图2所对应的说明书之前或之后记载的其他可选实现方式。
图3A是根据本公开实施例示出的通信处理方法的流程示意图。如图3A所示,本公开实施例涉及通信处理方法,上述方法包括:
步骤S3101,发送第一消息。
步骤S3101的可选实现方式可以参见图2的步骤S2101的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3102,接收第五消息。
步骤S3102的可选实现方式可以参见图2的步骤S2110的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的通信方法可以包括步骤S3101~步骤S3102中的至少一者。例如,步骤S3101可以作为独立实施例来实施,步骤S3102可以作为独立实施例来实施,步骤S3101+骤S3102可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S3101、步骤S3102可以交换顺序或同时执行。
在一些实施例中,步骤S3101是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S3102是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
图4A是根据本公开实施例示出的通信处理方法的流程示意图。如图4A所示,本公开实施例涉及通信处理方法,上述方法包括:
步骤S4101,接收第一消息。
步骤S4101的可选实现方式可以参见图2的步骤S2101的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4102,根据第一消息中的AF服务标识符确定对应的S-NSSAI和/或DNN。
步骤S4102的可选实现方式可以参见图2的步骤S2102的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4103,根据第一消息生成第二消息。
步骤S4103的可选实现方式可以参见图2的步骤S2102的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4104,将第二消息发送至第三实体。
步骤S4104的可选实现方式可以参见图2的步骤S2103的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4105,接收第三实体发送的第三消息。
步骤S4105的可选实现方式可以参见图2的步骤S2107的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4106,响应于第三消息或第七消息指示授权通过,向第四网元发送第四消息。
步骤S4106的可选实现方式可以参见图2的步骤S2109的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4107,获取本地存储的映射关系表。
步骤S4107的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施
例中其他关联部分,此处不再赘述。
步骤S4108,基于本地存储的映射关系表查询与第二消息中的S-NSSAI和/或DNN存在映射关系的目标PIN标识符。
步骤S4108的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4109,基于本地存储的映射关系表查询与第二消息中的PIN标识符存在映射关系的目标S-NSSAI和/或目标DNN。
步骤S4109的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4110,如果目标PIN标识符与第二消息中的PIN标识符一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系。
步骤S4110的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4111,如果目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系。
步骤S4111的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4112,如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系,则生成第六消息。
步骤S4112的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4113,发送第六消息至第三实体103。
步骤S4113的可选实现方式可以参见图2的步骤S2105的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4114,如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系,则生成授权不通过的授权结果,其中,第五消息中携带授权不通过的授权结果.
步骤S4114的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的通信方法可以包括步骤S4101~步骤S4114中的至少一者。例如,步骤S4101可以作为独立实施例来实施,步骤S4102可以作为独立实施例来实施,步骤S4101+S4103可以作为独立实施例来实施,步骤S4101+S4102+S4103可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S4101、S4104可以交换顺序或同时执行。
在一些实施例中,步骤S4105、S4106是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
图4B是根据本公开实施例示出的通信处理方法的流程示意图。如图4B所示,本公开实施例涉及通信处理方法,上述方法包括:
步骤S4201,确定AF服务标识符对应的S-NSSAI和/或DNN。
步骤S4201的可选实现方式可以参见图2的步骤S2101、图4A中步骤S4102的可选实现方式、及图2、图4A所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4202,发送第四消息。
步骤S4202的可选实现方式可以参见图2的步骤S2109、图4A中步骤S4106的可选实现方式、及图2、图4A所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4203,根据第二消息进行授权。
步骤S4201的可选实现方式可以参见图2的步骤S2104、图4A中步骤S4107-S4111的可选实现方式、及图2、图4A所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的通信方法可以包括步骤S4201~步骤S4203中的至少一者。例如,步骤S4201可以作为独立实施例来实施,步骤S4202可以作为独立实施例来实施,步骤S4201+S4203可以作为独立实施例来实施,步骤S4201+S4202+S4203可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S4201、S4202可以交换顺序或同时执行。
在一些实施例中,步骤S4203是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
图4C是根据本公开实施例示出的通信处理方法的流程示意图。如图4C所示,本公开实施例涉
及通信处理方法,上述方法包括:
步骤S4301,接收第二实体发送的第二消息。
步骤S4301的可选实现方式可以参见图2的步骤S2103的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4302,接收第二实体发送的第六消息。
步骤S4302的可选实现方式可以参见图2的步骤S2105的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4303,获取本地存储的映射关系表。
步骤S4303的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4304,根据GPSI获取对应的用户永久标识符SUPI。
步骤S4304的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4305,基于本地存储的映射关系表查询与第二消息中的S-NSSAI和/或DNN存在映射关系的目标PIN标识符。
步骤S4305的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4306,基于本地存储的映射关系表查询与第二消息中的PIN标识符存在映射关系的目标S-NSSAI和/或目标DNN。
步骤S4306的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4307,如果目标PIN标识符与第二消息中的PIN标识符一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系。
步骤S4307的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4308,如果目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系。
步骤S4308的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4309,如果目标PIN标识符与第二消息中的PIN标识符不一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系
步骤S4309的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4310,如果目标S-NSSAI和/或目标DNN与第二消息中的S-NSSAI和/或DNN不一致,确定第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系。
步骤S4310的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4311,查询GPSI或SUPI对应的订阅信息。
步骤S4311的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4312,查询AF标识符对应的权限信息。
步骤S4312的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4313,如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符存在映射关系,且第二消息中的S-NSSAI和/或DNN为订阅信息中的目标S-NSSAI和/或DNN,且AF标识符对应的AF可以修改GPSI或SUPI相关终端的URSP信息,则生成授权通过的授权结果。
步骤S4313的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4314,如果第二消息中的S-NSSAI和/或DNN与第二消息中的PIN标识符不存在映射关系,则生成授权不通过的授权结果。
步骤S4314的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4315,如果第二消息中的S-NSSAI和/或DNN不为订阅信息中的目标S-NSSAI或DNN,则生成授权不通过的授权结果。
步骤S4315的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4316,如果AF标识符对应的AF不可以修改修改GPSI或SUPI相关终端的URSP信息,则生成授权不通过的授权结果。
步骤S4316的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4317,向第二实体发送第七消息。
步骤S4317的可选实现方式可以参见图2的步骤S2108的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4318,向第二实体发送第三消息。
步骤S4318的可选实现方式可以参见图2的步骤S2107的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的通信方法可以包括步骤S4301~步骤S4318中的至少一者。例如,步骤S4101可以作为独立实施例来实施,步骤S4302可以作为独立实施例来实施,步骤S4301+S4303可以作为独立实施例来实施,步骤S4301+S4302+S4303可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S4301、S4304可以交换顺序或同时执行。
在一些实施例中,步骤S4305、S4306是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
图4D是根据本公开实施例示出的通信处理方法的流程示意图。如图4D所示,本公开实施例涉及通信处理方法,上述方法包括:
步骤S4401,基于第二消息中的相关信息进行授权。
步骤S4401的可选实现方式可以参见图2的步骤S2106、图4C中步骤S4303-S4316的可选实现方式、及图2、图4C所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4402,基于第六消息中的相关信息进行授权。
步骤S4402的可选实现方式可以参见图2的步骤S2106、图4C中步骤S4303-S4316的可选实现方式、及图2、图4C所涉及的实施例中其他关联部分,此处不再赘述。
图5A是根据本公开实施例示出的通信处理方法的交互示意图。如图5A所示,本公开实施例涉及通信处理方法,上述方法包括:
步骤S5101,第一实体发送第一消息至第二实体,其中,第一消息用于提供特定私有物联网PIN的相关信息。
步骤S5101的可选实现方式可以参见图2的步骤S2101、图3的步骤S3101的可选实现方式、及图2、图3、图4所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,上述方法可以包括上述通信系统侧、终端侧、接入网设备侧、核心网设备侧、第一网元侧、第二网元侧等的实施例的方法,此处不再赘述。
步骤S5102,第一实体接收第二实体发送的第五消息,其中,第五消息用于指示授权结果,其中,授权结果包括授权通过或授权不通过。
步骤S5102的可选实现方式可以参见图2的步骤S2110、图3的步骤S3102的可选实现方式、及图2、图3、图4所涉及的实施例中其他关联部分,此处不再赘述。
步骤S5103,第二实体接收第一实体发送的第一消息,根据第一消息生成第二消息。
步骤S5103的可选实现方式可以参见图2的步骤S2102、图4的步骤S4103的可选实现方式、及图2、图3、图4所涉及的实施例中其他关联部分,此处不再赘述。
步骤S5104,第二实体向第一实体发送第五消息,其中,第五消息用于指示授权结果,其中,授权结果包括授权通过或授权不通过。
步骤S5104的可选实现方式可以参见图2的步骤S2110、图4的步骤S4114的可选实现方式、及图2、图3、图4所涉及的实施例中其他关联部分,此处不再赘述。
步骤S5105,第三实体接收第二实体发送的第二消息或第六消息。
步骤S5105的可选实现方式可以参见图2的步骤S2103、S2105、图4的步骤S4301、S4302的可选实现方式、及图2、图3、图4所涉及的实施例中其他关联部分,此处不再赘述。
步骤S5106,第三实体基于第二消息或第六消息中的相关信息进行授权。
步骤S5106的可选实现方式可以参见图2的步骤S2106、图4的步骤S4303-S4316的可选实现方
式、及图2、图3、图4所涉及的实施例中其他关联部分,此处不再赘述。
步骤S5107,第三实体发送第三消息或第七消息至第二实体,其中,第三消息或第七消息用于指示授权结果。
步骤S5107的可选实现方式可以参见图2的步骤S2107、S2108、图4的步骤S4317、S4318的可选实现方式、及图2、图3、图4所涉及的实施例中其他关联部分,此处不再赘述。
图6是根据本公开实施例示出的通信处理方法的示意图。如图6所示,本公开实施例涉及通信处理方法,上述方法包括:
步骤S6101,AF向NEF发送第一信息。
可选地,AF为上述第一实体。
可选地,第一信息中包含特定PIN的相关信息。
可选地,特定PIN的相关信息包含AFID、AF-service-identifier、PEGC的GPSI和PIN ID。
步骤S6102,NEF根据第一信息生成第二信息。
可选地,NEF为上述第二实体。
可选地,NEF本地储存有S-NSSAI/DNN和PIN ID之间的映射关系。
可选地,NEF将AF-service-identifier转换为DNN和S-NSSAI的组合
可选地,NEF根据映射关系查找PIN ID对应的S-NSSAI/DNN和PIN ID。
可选地,NEF将PIN ID对应的S-NSSAI/DNN和PIN ID加入第二信息中。
可选地,第二信息中包含AF标识符;S-NSSAI;DNN;AF服务标识符;GPSI;PIN ID。
步骤S6103,NEF根据特定PIN相关的信息进行映射校验。
可选地,NEF根据S-NSSAI/DNN和PIN ID之间的映射关系确定第二信息中的S-NSSAI/DNN与第二信息中的PIN ID是否具有映射关系。
可选地,第二信息中的S-NSSAI/DNN与第二信息中的PIN ID具有映射关系,向UMD发送请求信息。
可选地,请求信息中包括单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI。
可选地,第二信息中的S-NSSAI/DNN与第二信息中的PIN ID不具有映射关系,生成授权失败的授权结果并发送给AF。
步骤S6104,NEF向UDM发送请求信息。
可选地,UDM为上述第三实体。
可选地,请求信息中包含S-NSSAI、DNN、AFID、AF-service-identifier、PEGC的GPSI。
可选地,请求信息中包含PINID。
步骤S6105,UDM根据请求信息进行授权验证。
可选地,UDM进行映射校验。
可选地,UDM在本地存储S-NSSAI/DNN与PIN ID之间的映射信息。
可选地,如果请求信息中的S-NSSAI/DNN与请求信息中的PIN ID具有映射关系,则映射校验通过。
可选地,如果请求信息中的S-NSSAI/DNN与请求信息中的PIN ID不具有映射关系,则映射校验失败,授权结果为不通过。
可选地,UDM进行订阅校验。
可选地,UDM根据请求信息中的GPSI获取对应的用户永久标识符SUPI。
可选地,UDM查询GPSI或SUPI对应的订阅信息,其中,订阅信息中包含目标S-NSSAI和/或DNN。
可选地,如果请求信息中的S-NSSAI和/或DNN为订阅信息中的目标S-NSSAI和/或DNN,则订阅校验通过。
可选地,如果请求信息中的S-NSSAI和/或DNN不为订阅信息中的目标S-NSSAI和/或DNN,则订阅校验失败,授权结果为不通过。
可选地,UDM进行修改权限校验。
可选地,UDM查询请求信息中AFID对应的权限信息,其中,权限信息用于指示AF标识符对应的AF可以修改GPSI或SUPI相关终端的用户路由选择策略URSP信息,或,AF标识符对应的AF不可以修改GPSI或SUPI相关终端的URSP信息。
可选地,如果AFID对应的权限信息用于指示AF标识符对应的AF可以修改GPSI或SUPI相关终端的用户路由选择策略URSP信息,则修改权限校验通过。
可选地,如果AFID对应的权限信息用于指示AF标识符对应的AF不可以修改GPSI或SUPI相关终端的用户路由选择策略URSP信息,则修改权限校验失败,授权结果为不通过。
可选地,如果映射校验、订阅校验和修改权限校验均通过,生成授权通过的授权结果。
步骤S6106,UDM将授权结果发送至NEF。
步骤S6107,NEF根据授权结果将特定PIN的相关信息发送至UDR。
可选地,UDR为上述第四实体。
可选地,如果授权结果为不通过,则不执行本步骤。
步骤S6108,NEF将授权结果发送至AF。
本公开实施例所涉及的通信方法可以包括步骤S6101~步骤S6108中的至少一者。例如,步骤S6101可以作为独立实施例来实施,步骤S6102可以作为独立实施例来实施,步骤S6101+S6103可以作为独立实施例来实施,步骤S6101+S6102+S6103可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S6107是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在本公开实施例中,部分或全部步骤、其可选实现方式可以与其他实施例中的部分或全部步骤任意组合,也可以与其他实施例的可选实现方式任意组合。
本公开实施例还提出用于实现以上任一方法的装置,例如,提出一装置,上述装置包括用以实现以上任一方法中终端所执行的各步骤的单元或模块。再如,还提出另一装置,包括用以实现以上任一方法中网络设备(例如接入网设备、核心网功能节点、核心网设备等)所执行的各步骤的单元或模块。
应理解以上装置中各单元或模块的划分仅是一种逻辑功能的划分,在实际实现时可以全部或部分集成到一个物理实体上,也可以物理上分开。此外,装置中的单元或模块可以以处理器调用软件的形式实现:例如装置包括处理器,处理器与存储器连接,存储器中存储有指令,处理器调用存储器中存储的指令,以实现以上任一方法或实现上述装置各单元或模块的功能,其中处理器例如为通用处理器,例如中央处理单元(Central Processing Unit,CPU)或微处理器,存储器为装置内的存储器或装置外的存储器。或者,装置中的单元或模块可以以硬件电路的形式实现,可以通过对硬件电路的设计实现部分或全部单元或模块的功能,上述硬件电路可以理解为一个或多个处理器;例如,在一种实现中,上述硬件电路为专用集成电路(application-specific integrated circuit,ASIC),通过对电路内元件逻辑关系的设计,实现以上部分或全部单元或模块的功能;再如,在另一种实现中,上述硬件电路为可以通过可编程逻辑器件(programmable logic device,PLD)实现,以现场可编程门阵列(Field Programmable Gate Array,FPGA)为例,其可以包括大量逻辑门电路,通过配置文件来配置逻辑门电路之间的连接关系,从而实现以上部分或全部单元或模块的功能。以上装置的所有单元或模块可以全部通过处理器调用软件的形式实现,或全部通过硬件电路的形式实现,或部分通过处理器调用软件的形式实现,剩余部分通过硬件电路的形式实现。
在本公开实施例中,处理器是具有信号处理能力的电路,在一种实现中,处理器可以是具有指令读取与运行能力的电路,例如中央处理单元(Central Processing Unit,CPU)、微处理器、图形处理器(graphics processing unit,GPU)(可以理解为微处理器)、或数字信号处理器(digital signal processor,DSP)等;在另一种实现中,处理器可以通过硬件电路的逻辑关系实现一定功能,上述硬件电路的逻辑关系是固定的或可以重构的,例如处理器为专用集成电路(application-specific integrated circuit,ASIC)或可编程逻辑器件(programmable logic device,PLD)实现的硬件电路,例如FPGA。在可重构的硬件电路中,处理器加载配置文档,实现硬件电路配置的过程,可以理解为处理器加载指令,以实现以上部分或全部单元或模块的功能的过程。此外,还可以是针对人工智能设计的硬件电路,其可以理解为ASIC,例如神经网络处理单元(Neural Network Processing Unit,NPU)、张量处理单元(Tensor Processing Unit,TPU)、深度学习处理单元(Deep learning Processing Unit,DPU)等。
图7A是本公开实施例提出的第一实体的结构示意图。如图7A所示,第一实体7100可以包括:收发模块7101、处理模块7102等中的至少一者。可选地,上述收发模块用于执行以上任一方法中终端101执行的发送和/或接收等通信步骤中的至少一者,此处不再赘述。可选地,上述处理模块用于执行以上任一方法中第一实体执行的其他步骤中的至少一者,此处不再赘述。
图7B是本公开实施例提出的第二实体的结构示意图。如图7B所示,第二实体7200可以包括:收发模块7201、处理模块7202等中的至少一者。可选地,上述收发模块用于执行以上任一方法中第二实体执行的发送和/或接收等通信步骤中的至少一者,此处不再赘述。可选地,上述处理模块用于执行以上任一方法第二实体执行的其他步骤中的至少一者,此处不再赘述。
图7C是本公开实施例提出的第三实体的结构示意图。如图7C所示,第三实体7300可以包括:
收发模块7301、处理模块7302等中的至少一者。可选地,上述收发模块用于执行以上任一方法中第三实体执行的发送和/或接收等通信步骤中的至少一者,此处不再赘述。可选地,上述处理模块用于执行以上任一方法中第三实体各个体执行的其他步骤中的至少一者,此处不再赘述。
在一些实施例中,收发模块可以包括发送模块和/或接收模块,发送模块和接收模块可以是分离的,也可以集成在一起。可选地,收发模块可以与收发器相互替换。
在一些实施例中,处理模块可以是一个模块,也可以包括多个子模块。可选地,上述多个子模块分别执行处理模块所需执行的全部或部分步骤。可选地,处理模块可以与处理器相互替换。
图8A是本公开实施例提出的通信设备8100的结构示意图。通信设备8100可以是网络设备(例如接入网设备、核心网设备等),也可以是终端(例如用户设备等),也可以是支持网络设备实现以上任一方法的芯片、芯片系统、或处理器等,还可以是支持终端实现以上任一方法的芯片、芯片系统、或处理器等。通信设备8100可用于实现上述方法实施例中描述的方法,具体可以参见上述方法实施例中的说明。
如图8A所示,通信设备8100包括一个或多个处理器8101。处理器8101可以是通用处理器或者专用处理器等,例如可以是基带处理器或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,基站、基带芯片,终端设备、终端设备芯片,DU或CU等)进行控制,执行程序,处理程序的数据。通信设备8100用于执行以上任一方法。
在一些实施例中,通信设备8100还包括用于存储指令的一个或多个存储器8102。可选地,全部或部分存储器8102也可以处于通信设备8100之外。
在一些实施例中,通信设备8100还包括一个或多个收发器8103。在通信设备8100包括一个或多个收发器8103时,收发器8103执行上述方法中的发送和/或接收等通信步骤中的至少一者,处理器8101执行其他步骤中的至少一者。
在一些实施例中,收发器可以包括接收器和/或发送器,接收器和发送器可以是分离的,也可以集成在一起。可选地,收发器、收发单元、收发机、收发电路等术语可以相互替换,发送器、发送单元、发送机、发送电路等术语可以相互替换,接收器、接收单元、接收机、接收电路等术语可以相互替换。
在一些实施例中,通信设备8100可以包括一个或多个接口电路8104。可选地,接口电路8104与存储器8102连接,接口电路8104可用于从存储器8102或其他装置接收信号,可用于向存储器8102或其他装置发送信号。例如,接口电路8104可读取存储器8102中存储的指令,并将该指令发送给处理器8101。
以上实施例描述中的通信设备8100可以是网络设备或者终端,但本公开中描述的通信设备8100的范围并不限于此,通信设备8100的结构可以不受图8A的限制。通信设备可以是独立的设备或者可以是较大设备的一部分。例如通信设备可以是:1)独立的集成电路IC,或芯片,或,芯片系统或子系统;(2)具有一个或多个IC的集合,可选地,上述IC集合也可以包括用于存储数据,程序的存储部件;(3)ASIC,例如调制解调器(Modem);(4)可嵌入在其他设备内的模块;(5)接收机、终端设备、智能终端设备、蜂窝电话、无线设备、手持机、移动单元、车载设备、网络设备、云设备、人工智能设备等等;(6)其他等等。
图8B是本公开实施例提出的芯片8200的结构示意图。对于通信设备8100可以是芯片或芯片系统的情况,可以参见图8B所示的芯片8200的结构示意图,但不限于此。
芯片8200包括一个或多个处理器8201,芯片8200用于执行以上任一方法。
在一些实施例中,芯片8200还包括一个或多个接口电路8202。可选地,接口电路8202与存储器8203连接,接口电路8202可以用于从存储器8203或其他装置接收信号,接口电路8202可用于向存储器8203或其他装置发送信号。例如,接口电路8202可读取存储器8203中存储的指令,并将该指令发送给处理器8201。
在一些实施例中,接口电路8202执行上述方法中的发送和/或接收等通信步骤中的至少一者,处理器8201执行其他步骤,但不限于此)中的至少一者。
在一些实施例中,接口电路、接口、收发管脚、收发器等术语可以相互替换。
在一些实施例中,芯片8200还包括用于存储指令的一个或多个存储器8203。可选地,全部或部分存储器8203可以处于芯片8200之外。
本公开还提出存储介质,上述存储介质上存储有指令,当上述指令在通信设备8100上运行时,使得通信设备8100执行以上任一方法。可选地,上述存储介质是电子存储介质。可选地,上述存储介质是计算机可读存储介质,但不限于此,其也可以是其他装置可读的存储介质。可选地,上述存储介质可以是非暂时性(non-transitory)存储介质,但不限于此,其也可以是暂时性存储介质。
本公开还提出程序产品,上述程序产品被通信设备8100执行时,使得通信设备8100执行以上任一方法。可选地,上述程序产品是计算机程序产品。
本公开还提出计算机程序,当其在计算机上运行时,使得计算机执行以上任一方法。
Claims (34)
- 一种通信处理方法,其特征在于,所述方法包括:发送第一消息至第二实体,其中,所述第一消息用于提供特定私有物联网PIN的相关信息;接收所述第二实体发送的第五消息,其中,所述第五消息用于指示授权结果,其中,所述授权结果包括授权通过或授权不通过。
- 根据权利要求1所述的方法,其特征在于,所述第一消息中包括以下至少一项:应用功能AF标识符;应用功能AF服务标识符;通用公共用户标识符GPSI;PIN标识符。
- 一种通信处理方法,其特征在于,所述方法包括:接收第一实体发送的第一消息,根据所述第一消息生成第二消息;向所述第一实体发送第五消息,其中,所述第五消息用于指示所述授权结果,其中,所述授权结果包括授权通过或授权不通过。
- 根据权利要求3所述的方法,其特征在于,所述第一消息中包括以下至少一项:应用功能AF标识符;AF服务标识符;通用公共用户标识符GPSI;PIN标识符。
- 根据权利要求3所述的方法,其特征在于,所述第二消息中包括以下至少一项特定PIN的相关信息:AF标识符;单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI;PIN标识符。
- 根据权利要求4或5所述的方法,其特征在于,所述根据所述第一消息生成第二消息,包括:根据所述第一消息中的AF服务标识符确定对应的S-NSSAI和/或DNN。
- 根据权利要求3-6中任一项所述的方法,其特征在于,所述方法还包括:将所述第二消息发送至第三实体;接收所述第三实体发送的第三消息,其中,所述第三消息用于指示授权结果。
- 根据权利要求7中任一项所述的方法,其特征在于,所述方法还包括:响应于所述第三消息指示授权通过,向第四网元发送第四消息。
- 根据权利要求3-6中任一项所述的方法,其特征在于,所述方法还包括:根据所述第二消息进行授权。
- 根据权利要求9所述的方法,其特征在于,所述根据所述第二消息进行授权包括:获取本地存储的映射关系表,其中,所述映射关系表中包含S-NSSAI和/或DNN与PIN标识符之间的映射关系。
- 根据权利要求10所述的方法,其特征在于,所述方法还包括以下至少一项:基于所述本地存储的映射关系表查询与所述第二消息中的S-NSSAI和/或DNN存在映射关系的目标PIN标识符;或,基于所述本地存储的映射关系表查询与所述第二消息中的PIN标识符存在映射关系的目标 S-NSSAI和/或目标DNN。
- 根据权利要求11所述的方法,其特征在于,所述方法还包括以下任意一项:如果所述目标PIN标识符与所述第二消息中的PIN标识符一致,确定所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符存在映射关系;如果所述目标S-NSSAI和/或目标DNN与所述第二消息中的S-NSSAI和/或DNN一致,确定所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符存在映射关系;否则,确定所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符不存在映射关系。
- 根据权利要求11所述的方法,其特征在于,所述方法还包括以下任意一项:如果所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符存在映射关系,则生成第六消息,并将所述第六消息发送至第三实体;如果所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符不存在映射关系,则生成授权不通过的授权结果,其中,所述第五消息中携带所述授权不通过的授权结果。
- 根据权利要求13所述的方法,其特征在于,所述第六消息中包括以下至少一项:AF标识符;单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI。
- 一种通信处理方法,其特征在于,所述方法包括:接收第二实体发送的第二消息或第六消息;基于所述第二消息或第六消息中的相关信息进行授权;发送第三消息或第七消息至第二实体,其中,所述第三消息或第七消息用于指示授权结果。
- 根据权利要求15所述的方法,其特征在于,所述第二消息中包括以下至少一项特定PIN的相关信息:AF标识符;单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI;PIN标识符。
- 根据权利要求15或16所述的方法,其特征在于,所述方法还包括:获取本地存储的映射关系表,其中,所述映射关系表中包含S-NSSAI和/或DNN与PIN标识符之间的映射关系。
- 根据权利要求15或16所述的方法,其特征在于,所述方法还包括:根据所述GPSI获取对应的用户永久标识符SUPI。
- 根据权利要求17所述的方法,其特征在于,所述基于所述第二消息中特定PIN的相关信息进行授权,包括以下至少一项:基于所述本地存储的映射关系表查询与所述第二消息中的S-NSSAI和/或DNN存在映射关系的目标PIN标识符;或,基于所述本地存储的映射关系表查询与所述第二消息中的PIN标识符存在映射关系的目标S-NSSAI和/或目标DNN。
- 根据权利要求19所述的方法,其特征在于,所述方法还包括以下任意一项:如果所述目标PIN标识符与所述第二消息中的PIN标识符一致,确定所述第二消息中的S-NSSAI 和/或DNN与所述第二消息中的PIN标识符存在映射关系;如果所述目标S-NSSAI和/或目标DNN与所述第二消息中的S-NSSAI和/或DNN一致,确定所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符存在映射关系;否则,确定所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符不存在映射关系。
- 根据权利要求16-18中任一项所述的方法,其特征在于,所述基于所述第二消息中特定PIN的相关信息进行授权,包括:查询所述GPSI或所述SUPI对应的订阅信息,其中,所述订阅信息中包含目标S-NSSAI和/或DNN。
- 根据权利要求16-18中任一项所述的方法,其特征在于,所述基于所述第二消息中特定PIN的相关信息进行授权,还包括:查询所述AF标识符对应的权限信息,其中,所述权限信息用于指示所述AF标识符对应的AF可以修改所述GPSI或所述SUPI相关终端的用户路由选择策略URSP信息,或,所述AF标识符对应的AF不可以修改所述GPSI或所述SUPI相关终端的URSP信息。
- 根据权利要求19-22中任一项所述的方法,其特征在于,所述方法还包括以下任意一项:如果所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符存在映射关系,且所述第二消息中的S-NSSAI和/或DNN为所述订阅信息中的目标S-NSSAI和/或DNN,且所述AF标识符对应的AF可以修改GPSI或所述SUPI相关终端的URSP信息,则生成授权通过的授权结果;如果所述第二消息中的S-NSSAI和/或DNN与所述第二消息中的PIN标识符不存在映射关系,则生成授权不通过的授权结果;如果所述第二消息中的S-NSSAI和/或DNN不为所述订阅信息中的目标S-NSSAI或DNN,则生成授权不通过的授权结果;如果所述AF标识符对应的AF不可以修改所述修改GPSI或所述SUPI相关终端的URSP信息,则生成授权不通过的授权结果。
- 根据权利要求15所述的方法,其特征在于,所述方法还包括:接收第二实体发送的第六消息;向第二实体发送第七消息,所述第七消息中包括授权结果,其中,所述授权结果包括授权通过或授权不通过。
- 根据权利要求24所述的方法,其特征在于,所述第六消息中包括以下至少一项:AF标识符;单个网络切片选择辅助信息S-NSSAI;数据网络名称DNN;应用功能AF服务标识符;通用公共用户标识符GPSI。
- 根据权利要求24或25所述的方法,其特征在于,所述方法还包括:根据所述第六消息进行授权,以生成授权结果。
- 一种第一实体,其特征在于,所述装置包括:收发模块,用于发送第一消息至第二实体,其中,所述第一消息用于提供特定私有物联网PIN的相关信息;接收所述第二实体发送的第五消息,其中,所述第五消息用于指示授权结果,其中,所述授权结果包括授权通过或授权不通过。
- 一种第二实体,其特征在于,所述装置包括:收发模块,用于接收第一实体发送的第一消息,根据所述第一消息生成第二消息;向所述第一实体发送第五消息,其中,所述第五消息用于指示所述授权结果,其中,所述授权结果包括授权通过或授权不通过。
- 一种第三实体,其特征在于,所述装置包括:收发模块,用于接收第二实体发送的第二消息或第六消息;处理模块,用于基于所述第二消息或第六消息中的相关信息进行授权;其中,所述收发模块还用于发送第三消息或第七消息至第二实体,其中,所述第三消息或第七消息用于指示授权结果。
- 一种第一实体,其特征在于,包括:一个或多个处理器;其中,所述第一实体用于执行权利要求1-2中任一项所述的方法。
- 一种第二实体,其特征在于,包括:一个或多个处理器;其中,所述第二实体用于执行权利要求3-14中任一项所述的方法。
- 一种第三实体,其特征在于,包括:一个或多个处理器;其中,所述第三实体用于执行权利要求15-26中任一项所述的方法。
- 一种通信系统,其特征在于,包括第一实体、第二实体、第三实体,其中,所述第一实体被配置为实现权利要求1-2中任一项所述的方法,所述第二实体被配置为实现权利要求3-14中任一项所述的方法,所述第三实体被配置为实现权利要求15-26中任一项所述的方法。
- 一种存储介质,所述存储介质存储有指令,其特征在于,当所述指令在通信设备上运行时,使得所述通信设备执行如权利要求1-2或3-14或15-26中任一项所述的方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2023/112757 WO2025035325A1 (zh) | 2023-08-11 | 2023-08-11 | 通信处理方法、第一实体、第二实体、第三实体 |
| CN202380010587.1A CN117337583A (zh) | 2023-08-11 | 2023-08-11 | 通信处理方法、第一实体、第二实体、第三实体 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2023/112757 WO2025035325A1 (zh) | 2023-08-11 | 2023-08-11 | 通信处理方法、第一实体、第二实体、第三实体 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025035325A1 true WO2025035325A1 (zh) | 2025-02-20 |
Family
ID=89293937
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/112757 Pending WO2025035325A1 (zh) | 2023-08-11 | 2023-08-11 | 通信处理方法、第一实体、第二实体、第三实体 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN117337583A (zh) |
| WO (1) | WO2025035325A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2025231884A1 (zh) * | 2024-05-10 | 2025-11-13 | 北京小米移动软件有限公司 | 通信方法、设备、系统以及存储介质 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109511115A (zh) * | 2017-09-14 | 2019-03-22 | 华为技术有限公司 | 一种授权方法和网元 |
| KR20200116843A (ko) * | 2019-04-02 | 2020-10-13 | 한국전자통신연구원 | Nidd 인증 업데이트 방법, 연결 해제 방법 및 장치 |
| US20220086741A1 (en) * | 2019-02-07 | 2022-03-17 | Apple Inc. | Enabling uas service for identification and operation in 3gpp system |
| CN116567779A (zh) * | 2022-01-29 | 2023-08-08 | 维沃移动通信有限公司 | Pin的组建方法及设备 |
-
2023
- 2023-08-11 CN CN202380010587.1A patent/CN117337583A/zh active Pending
- 2023-08-11 WO PCT/CN2023/112757 patent/WO2025035325A1/zh active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109511115A (zh) * | 2017-09-14 | 2019-03-22 | 华为技术有限公司 | 一种授权方法和网元 |
| US20220086741A1 (en) * | 2019-02-07 | 2022-03-17 | Apple Inc. | Enabling uas service for identification and operation in 3gpp system |
| KR20200116843A (ko) * | 2019-04-02 | 2020-10-13 | 한국전자통신연구원 | Nidd 인증 업데이트 방법, 연결 해제 방법 및 장치 |
| CN116567779A (zh) * | 2022-01-29 | 2023-08-08 | 维沃移动通信有限公司 | Pin的组建方法及设备 |
Non-Patent Citations (1)
| Title |
|---|
| "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on personal IoT networks security aspects (Release 18)", 3GPP DRAFT; SP-230577, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, 6 June 2023 (2023-06-06), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France, XP052505049 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN117337583A (zh) | 2024-01-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2025000401A1 (zh) | 中继通信方法及装置、通信设备、通信系统、存储介质 | |
| WO2025010611A1 (zh) | 用户面连接建立方法及装置 | |
| WO2025007317A1 (zh) | 通信方法、物联网终端、网元、调用方、核心网设备 | |
| WO2024234313A1 (zh) | 信息处理方法及装置、通信设备、通信系统、存储介质 | |
| WO2025030337A1 (zh) | 定位方法、装置 | |
| WO2025035417A1 (zh) | 信息处理方法、装置及存储介质 | |
| WO2025035325A1 (zh) | 通信处理方法、第一实体、第二实体、第三实体 | |
| WO2025030339A1 (zh) | 通信处理方法、终端、核心网设备 | |
| EP4694238A1 (en) | Information processing method, apparatus and system, and communication device and storage medium | |
| WO2025030300A1 (zh) | 信息指示方法、第一api调用者、第一网络功能和存储介质 | |
| WO2025043723A1 (zh) | 一种信息处理方法及其装置 | |
| WO2025030450A1 (zh) | 用户面连接建立方法及装置、通信设备、通信系统、存储介质 | |
| WO2025030332A1 (zh) | 定位方法、装置 | |
| WO2025065293A1 (zh) | 信息处理方法、终端、接入网设备、通信系统及存储介质 | |
| WO2026073453A1 (zh) | 通信方法、api调用者、rof、ccf、通信系统及存储介质 | |
| WO2025148050A1 (zh) | 信息传输方法及装置、存储介质 | |
| WO2026007146A1 (zh) | 信息处理方法、通信系统及存储介质 | |
| WO2026073452A1 (zh) | 通信方法、api调用者、rof、ccf、通信系统及存储介质 | |
| WO2025054998A1 (zh) | 信息处理方法、终端、通信系统及存储介质 | |
| WO2025065292A1 (zh) | 连接建立方法、第一设备、第一实体及第二实体 | |
| WO2025236133A1 (zh) | 用户认证方法、通信设备及存储介质 | |
| WO2026091055A1 (zh) | 信息处理方法、通信系统及存储介质 | |
| WO2026060719A1 (zh) | 密钥处理方法、通信设备及存储介质 | |
| WO2025010609A1 (zh) | 通信处理方法、用户设备 | |
| WO2026055947A1 (zh) | 数据安全处理方法、通信设备、通信系统、存储介质及程序产品 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23948760 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |